Obsidian Security has raised $85 million in Series D financing at a $1.1 billion valuation as enterprises give artificial intelligence agents greater access to business-critical applications and data. The round was led by Crescent Cove Advisors, with participation from existing investors including Greylock Partners and Menlo Ventures. Obsidian plans to use the capital to expand its platform for discovering, governing and controlling AI agents operating across third-party applications. The company says more than 70% of its customers already permit agents to interact with enterprise data, while 60 Fortune 500 companies use its security platform. The central question is whether Obsidian can turn early demand for AI-agent visibility into durable recurring revenue before large identity, cloud and cybersecurity platforms close the product gap.
How does Obsidian Security’s $85 million Series D change its financial runway and valuation case?
The Series D represents the first major disclosed funding event for Obsidian Security since its $90 million Series C in April 2022. That earlier round took total financing to $119.5 million, meaning the latest investment brings the company’s cumulative disclosed funding to approximately $204.5 million. Obsidian has not disclosed its current cash balance, the ownership percentage sold in the Series D or the economic preferences attached to the new shares, so the valuation alone does not reveal the full cost of the capital.
The more strategically important disclosure is that management expects the financing to support the business until it reaches positive cash flow. That reduces immediate dependence on another fundraising round and gives Obsidian greater flexibility to invest in engineering, integrations and enterprise sales without operating against a near-term capital deadline. It also raises the execution threshold because a company funded through to positive cash flow must eventually demonstrate that customer growth can absorb the expense of maintaining a technically demanding cybersecurity platform.
Obsidian is entering this phase with stronger commercial evidence than it had during the 2022 financing. The company ranked 95th on the 2025 Deloitte Technology Fast 500 after reporting revenue growth of close to 1,000% between 2021 and 2024. It said in November 2025 that its platform protected more than 250 organisations, with infrastructure available across North America, Europe, the Middle East, Africa and Asia-Pacific. Those figures do not provide a complete financial picture, but they indicate that the Series D is supporting an established enterprise sales operation rather than funding an untested product concept.
The $1.1 billion valuation nevertheless prices in more than continued SaaS security growth. It assumes Obsidian can become an important control layer for autonomous software agents, a category that remains early and whose long-term market boundaries are still being defined. Investors are therefore backing both the company’s existing customer base and its ability to reposition years of identity and application-security data for a new generation of machine-operated workflows.
Why is enterprise AI-agent adoption creating a new control layer inside third-party applications?
Traditional enterprise identity systems were designed mainly around human employees, defined job roles and relatively predictable access lifecycles. AI agents behave differently because they may be created dynamically, use API tokens or service accounts, act across multiple applications and disappear after completing a workflow. They can also make multi-step decisions at software speed, potentially extending an initial permission into a broader sequence of actions that was not anticipated when access was granted.
The Cloud Security Alliance has identified AI agents as a rapidly evolving class of non-human identity whose governance challenges include excessive authority, uncertain ownership, limited action attribution and fragmented controls across platforms. Unlike an employee account, an agent’s lifecycle may be tied to an application deployment or temporary workflow rather than a human-resources process. That difference makes periodic access reviews less effective because an agent can be created, modified and retired between traditional governance cycles.
Obsidian’s investment thesis is that the most important AI risks will emerge where agents connect to third-party applications rather than inside the underlying language model alone. These applications include Microsoft 365, Salesforce, Workday, ServiceNow, GitHub, Snowflake and Databricks, where companies store customer information, intellectual property, financial records and source code. An AI agent does not need to defeat a perimeter firewall when it already possesses valid credentials and permission to act inside those systems.
This explains why Obsidian is extending beyond its original SaaS Security Posture Management business. Its platform now seeks to identify which agents, models and Model Context Protocol servers are connected to enterprise applications, determine what those agents can access and block certain actions while they are being executed. The company has announced coverage spanning Microsoft Copilot Studio, Salesforce Agentforce, Anthropic Claude, OpenAI, Google Vertex AI, Amazon Bedrock and n8n.
The commercial opportunity is substantial because enterprises may deploy agents from several vendors simultaneously. A security team could otherwise face separate policies and monitoring interfaces for every model provider, application platform and workflow tool. Obsidian is positioning itself as a vendor-independent layer that can apply common governance across this fragmented environment.
That positioning is strategically attractive, but it requires deep integrations that remain reliable as application programming interfaces, permission structures and agent platforms change. A broad integration catalogue may help win enterprise evaluations, yet customers will measure value by whether the platform can accurately identify dangerous behaviour and intervene without disrupting legitimate automation.
What do Obsidian Security’s customer-spending disclosures reveal about commercial traction?
Obsidian reported that more than 100 customers now spend over $100,000 annually on its platform and that more than 14 customers spend above $1 million. Those customer bands imply a minimum annual contract-spend floor of roughly $22.6 million, assuming 14 of the customers are included within the larger group. This is a conservative Business News Today calculation rather than disclosed revenue because it excludes customers spending below $100,000 and any expenditure above the stated minimum thresholds.
The concentration of million-dollar customers is particularly important. Large cybersecurity contracts generally require lengthy procurement processes, integration testing and confidence that the supplier can support complex multinational environments. Having more than 14 customers above that spending level suggests Obsidian is moving beyond departmental deployments and into broader platform relationships.
The company also says 60 Fortune 500 businesses use its platform, with customers including T-Mobile, Workday, S&P Global, Snowflake, Seagate and AAA appearing in its recent public materials. These references strengthen the enterprise credibility of the funding story, although privately held Obsidian does not publish audited revenue, customer-retention rates, gross margins or annual recurring revenue.
The absence of those financial disclosures matters when evaluating the unicorn valuation. Customer counts can rise while implementation costs, support requirements or sales expenses remain high. Investors will need growth in large accounts to be accompanied by attractive renewals, product expansion and improving operating leverage if the company is to reach positive cash flow without another major financing.
One encouraging signal is the progression from the company’s 2022 disclosure that it had recorded fivefold growth in deals worth at least $100,000. Four years later, Obsidian reports more than 100 customers above that spending threshold. The continuity suggests that high-value enterprise contracts have remained central to the business model rather than appearing only after the AI-agent narrative gained market attention.
Can runtime governance become a durable advantage rather than another enterprise security dashboard?
Cybersecurity buyers already operate large portfolios of monitoring, identity, cloud, endpoint and data-security products. Obsidian must therefore demonstrate that AI-agent governance represents a distinct operational control rather than another source of alerts requiring manual investigation.
The company’s most consequential product claim is that it can enforce guardrails during execution. Obsidian says its runtime protection can detect and block privilege escalation, excessive data access and policy violations before an agent completes the action. It is also adding controls for Anthropic Claude Code and Cowork, including restrictions on production-data permissions, sensitive-file access and unsanctioned Model Context Protocol tools.
Runtime enforcement could create a stronger competitive position than visibility alone. Inventories of agents, tokens and connected applications are useful, but enterprises ultimately need to prevent destructive or unauthorised actions without paralysing legitimate workflows. The technical challenge is making those decisions quickly and consistently while accounting for the agent’s identity, delegated authority, target data, business context and sequence of prior actions.
False positives are therefore a material execution risk. If controls block valid transactions or interrupt revenue-generating processes, business teams may bypass the platform or restrict its enforcement role. If policies are too permissive, the product becomes an observational dashboard that identifies problems after the damage has occurred.
Obsidian will also need to provide evidence that its models can distinguish an agent performing an unusual but authorised task from one exhibiting dangerous behaviour. Useful performance indicators would include prevented policy violations, time saved during investigations, reductions in excessive permissions, deployment expansion and measurable improvements in incident response. The Cloud Security Alliance has similarly argued that automation claims involving agent identities should be supported by defined measurement targets, particularly because non-deterministic behaviour can make conventional baselines harder to validate.
How does cybersecurity consolidation raise the competitive stakes for Obsidian Security?
The AI-agent security market is attracting venture financing, acquisitions and product expansion from established cybersecurity suppliers. This creates validation for Obsidian’s strategy, but it also shortens the period in which the company can establish an independent category advantage.
Cyera’s planned acquisition of Oasis Security illustrates the direction of the market. Oasis focuses on governing non-human identities and agent access, while Cyera brings data-security context. Their proposed combination is based on the view that effective agent controls require visibility into both the identity requesting access and the sensitivity of the data being reached.
That same logic applies to Obsidian. Its historical strength lies in mapping identities, permissions and activity across third-party applications. However, identity providers, data-security platforms, cloud vendors and SaaS application companies can all expand into adjacent parts of the control stack. Microsoft, Salesforce, Google and other platform owners may also build more native agent-governance capabilities into their ecosystems.
Obsidian’s defence is its ability to operate across vendors. Large enterprises rarely standardise every workflow on a single AI model or software ecosystem, which creates demand for an independent governance layer. The value of that independence will depend on the depth of integrations and whether Obsidian can maintain consistent enforcement when platform vendors change their interfaces or introduce competing controls.
Consolidation could eventually make Obsidian an acquisition candidate, particularly for a larger identity, cloud or security provider seeking AI-agent capabilities. However, the Series D announcement does not disclose a sale process or near-term exit plan. Funding the company through its targeted positive-cash-flow point may instead allow management to preserve strategic options rather than pursuing a transaction under financing pressure.
What evidence will determine whether the $1.1 billion valuation is commercially justified?
The Series D has improved Obsidian Security’s financial flexibility, expanded its investor base and confirmed that institutional capital remains available for companies addressing AI-agent security. The company has also presented meaningful indicators of enterprise adoption, including a growing group of customers with six-figure and seven-figure annual spending.
What remains unresolved is the relationship between that commercial traction and the $1.1 billion valuation. Obsidian has not disclosed revenue, annual recurring revenue, cash burn, gross retention, net retention or the valuation of its previous round. Without those figures, external observers cannot determine whether the latest valuation represents a modest progression supported by operating results or a more aggressive expectation of future AI-security demand.
The next measurable proof point will be progress towards positive cash flow. Reaching that target while continuing to expand research, integrations and international sales would indicate that the company’s large enterprise contracts can support the operating complexity of the platform. A rising number of customers spending more than $1 million, accompanied by broader deployment of runtime controls, would further strengthen the strategic case.
The thesis would weaken if enterprise interest remains concentrated in pilot deployments, if platform vendors absorb agent governance into existing products or if customers regard Obsidian primarily as a visibility tool rather than a preventative control layer. The company must also prove that its enforcement technology can scale across rapidly changing models and applications without generating disruption or excessive manual work.
Obsidian Security’s $85 million Series D therefore represents more than another cybersecurity unicorn announcement. It is a test of whether AI agents create a sufficiently distinct and urgent control problem to support a new enterprise security platform. The decisive milestone will not be the number of agents that Obsidian can discover, but the number of organisations willing to make its runtime governance an essential part of how automated work is authorised and executed.
What are the key takeaways from Obsidian Security’s $85 million Series D funding round?
- Obsidian Security raised $85 million in a Series D led by Crescent Cove Advisors at a $1.1 billion valuation.
- Existing investors including Greylock Partners and Menlo Ventures participated in the financing.
- The round brings cumulative disclosed funding to approximately $204.5 million.
- Management expects the financing to support the company until it reaches positive cash flow.
- More than 100 customers reportedly spend over $100,000 annually, including more than 14 spending above $1 million.
- The disclosed customer bands imply a minimum annual contract-spend floor of roughly $22.6 million, not total reported revenue.
- Obsidian is expanding from SaaS security into AI-agent discovery, access governance and runtime enforcement.
- Its platform covers agents and applications associated with Microsoft, Salesforce, Anthropic, OpenAI, Google and Amazon Web Services.
- The principal execution challenge is proving that real-time controls can prevent harmful activity without disrupting authorised automation.
- Positive cash flow, additional million-dollar customers and wider runtime deployment will be the clearest tests of the unicorn valuation.
Discover more from Business-News-Today.com
Subscribe to get the latest posts sent to your email.