Sequoia backs Cymphony’s $30m fix for AI access gaps

Cymphony

Cymphony has launched with $30m in funding led by Sequoia and Fin Capital, as it looks to help security teams close the access gaps that artificial intelligence is increasingly exposing.

The funding round was led by Sequoia and Fin Capital, giving the company fresh capital to build out its platform as it comes out of stealth.

Security practitioners are facing a sharper version of an old problem: the faster a business wants to move, the more pressure falls on the security team not to slow it down.

Generative AI has intensified that pressure considerably, since the same tools that companies want connected to their most sensitive systems, including SharePoint, Box, Snowflake and Salesforce, are also highly capable of exploiting any weaknesses in how access to those systems is controlled.

Security teams must now defend their data in an environment where access is being continually probed by AI tools, whether sanctioned or not, and by machines and autonomous agents, all while working at a faster pace than before.

Cymphony was created specifically to address this challenge at the speed it now demands. What sets the platform apart, according to the company, is that it is natively built to bring data, identity and behaviour together within a single context graph, rather than treating them as separate problems. The company positions itself less as a standalone tool and more as an ongoing partner in an organisation’s AI security effort, working alongside internal teams through to the execution of projects rather than simply handing over software.

That philosophy grew out of a lesson learned from an early customer, who drew a distinction between having security capabilities and actually creating value from them.

As the company describes it, a business can add another sophisticated scanning tool and still be left, in the words of one chief information security officer, shining “another flashlight on a problem I can’t solve”.

The real question, Cymphony argues, is not how thoroughly an organisation can catalogue its data, but whether it can identify risky access and actually reduce it.

That lesson was reinforced when one early customer, despite having a well-regarded security stack in place, connected ChatGPT to its SharePoint environment. An honest error made by an intern working in the legal department meant that, as a result, every intern at the company could query documents relating to a highly sensitive litigation matter.

It was this same customer who told Cymphony that they wanted the conversation to move away from tools and towards tangible outcomes, a comment that has since shaped how the company builds its platform.

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.