Obsidian Security
Type: company (AI-agent / SaaS security vendor) Sector: Non-human identity and AI-agent security across third-party applications First seen: 2026-08-14 (flagged as a deferred candidate in that day’s scan note) Last updated: 2026-08-18
Created 2026-08-18 from S-2026-08-04-obsidian-security-series-d (daily AI-governance vendor-intelligence scan; primary release fetched in full). This item was deferred by the 14 August scan note as a headline seen only in a trade-press sidebar; the primary release has now been retrieved and the date corrected from 5 August to 4 August 2026.
Snapshot
Obsidian Security is a Palo Alto–based vendor governing what AI agents and non-human identities can access and do inside third-party applications — SaaS platforms, data warehouses, developer infrastructure and collaboration tools, rather than inside the model or the agent framework itself. It matters to this wiki as a further claimant to the agent-control layer that is capitalising outside the Gartner-defined AI-governance platform category, and — more specifically — as the first vendor recorded here to ship an LLM-substitution inventory, which is a model change-control primitive rather than a purely security one [S-2026-08-04-obsidian-security-series-d].
Positions / Claims they advance
- Raised an $85M Series D (4 Aug 2026) led by Crescent Cove Advisors with all existing investors participating (Greylock, Menlo Ventures, Norwest, IVP, Wing, GV); states a $1.1B valuation. Funding facts are reliable and corroborated across independent outlets; the valuation is company-stated and repeated by secondary coverage rather than filing-confirmed [S-2026-08-04-obsidian-security-series-d].
- Argues the governance problem sits at agent access to third-party applications — “that’s where the data lives, that’s where the work happens, and that’s exactly where the risk lives too” — rather than at the model or prompt layer, supporting this with unsourced statistics (over 75% of enterprise applications third-party; non-human identities outnumbering human 144:1) [S-2026-08-04-obsidian-security-series-d].
- Announced four capabilities, none with a stated availability status ⚠️: (1) agent access governance extended to Anthropic’s Claude Code and Cowork, joining existing coverage of Copilot Studio, OpenAI, Salesforce Agentforce and n8n; (2) runtime protection claiming to detect and block privilege escalation, excessive data access and policy violations “at execution time, before impact occurs”, with risk factors “aligned to OWASP standards”; (3) an MCP-server inventory mapped to invoking agents, for identifying unsanctioned MCP usage and assessing “downstream blast radius”; and (4) an LLM inventory tracking which models power which agents “to spot when models are switched or substituted” [S-2026-08-04-obsidian-security-series-d].
- Frames enforcement in the same terms this vault has been testing across the cohort: “Security cannot credibly govern agents if control only happens after misuse… governance shifts from reactive monitoring to preventative action.” The release does not say whether blocked actions generate retained per-action records ⚠️ [S-2026-08-04-obsidian-security-series-d].
- Claims 60 of the Fortune 500 including “major financial institutions”, but names only T-Mobile, Workday and S&P Global — telecoms, software and financial information/ratings respectively. No EU or UK bank, insurer or asset manager is named [S-2026-08-04-obsidian-security-series-d].
- Site footer displays an ISO/IEC 42001 badge alongside SOC 2, ISO 27701 and ISO 27001, with no certificate number, certification body, date or scope — an unverified site claim, not a recorded certification ⚠️ [S-2026-08-04-obsidian-security-series-d].
Relationships
- relates-to → AI Governance Platforms — a further capitalised claimant to the agent-control/enforcement layer forming outside the Gartner-defined category [S-2026-08-04-obsidian-security-series-d].
- relates-to → Model Risk Management and Agentic AI — the LLM-substitution inventory is a model change-detection capability, not merely an access control [inference].
- competes-with → HiddenLayer — overlapping claim on runtime agent enforcement, though HiddenLayer works at the agent harness and Obsidian at third-party application access [inference].
- competes-with → Zenity — overlapping behavioural-authorization / agent-control positioning [inference].
Tracked changes
- 2026-08-04 (logged 2026-08-18) — $85M Series D led by Crescent Cove Advisors at a stated $1.1B valuation; four AI-agent security capabilities announced (Claude Code/Cowork access governance, runtime protection, MCP-server inventory, LLM inventory). No availability status given for any capability; no EU/UK regulated-FS customer named [S-2026-08-04-obsidian-security-series-d].
Open Questions
- Does an LLM-substitution alert function as a model change-control trigger acceptable to an FS second line under SS1/23 or SR 11-7 / SR 26-2 — and does it reconcile with the firm’s model inventory of record, or create yet another parallel security-owned inventory? The release does not address reconciliation, which is the live question across this cohort [S-2026-08-04-obsidian-security-series-d].
- Does “detecting and blocking at execution time” produce retained per-action records distinguishing blocked from logged? Unstated — the second half of this vault’s standing “blocked vs merely logged” test remains unanswered [S-2026-08-04-obsidian-security-series-d].
- What is the availability status (GA / limited availability / preview) of each of the four capabilities? Unstated for all four [S-2026-08-04-obsidian-security-series-d].
- Is the footer ISO/IEC 42001 badge a genuine certification, and what is its scope — which entities, products and AI systems does the certificate actually cover? This is the scope question this vault applies to every vendor ISO 42001 claim [S-2026-08-04-obsidian-security-series-d].
- Does agent governance scoped to third-party application access address EU AI Act Art. 14 human-oversight or Art. 12 record-keeping expectations, or is it a complementary control that itself requires independent challenge? Obsidian claims no regulatory standard beyond a passing OWASP reference; the question is this vault’s [inference].
- No named EU/UK regulated-FS production reference — the standing gap across this entire category is unchanged by this item [S-2026-08-04-obsidian-security-series-d].
Sources
- S-2026-08-04-obsidian-security-series-d — $85M Series D and four AI-agent security capabilities (medium authority; primary vendor release fetched in full; funding reliable, all capability claims vendor-asserted and unverified).