Obsidian Security — $85M Series D and four AI-agent security capabilities (August 2026)
Tag: S-2026-08-04-obsidian-security-series-d Type: article (primary vendor press release, fetched in full from obsidiansecurity.com) Author(s): Obsidian Security (corporate); quotes from Hasan Imam (CEO, Obsidian Security) and Jun Hong Heng (Founder & CIO, Crescent Cove Advisors) Date of source: 2026-08-04 Date ingested: 2026-08-18 Authority weight: medium — primary and reliable on the financing (a company announcing its own funding, corroborated by multiple independent outlets seen in search results); self-interested and wholly unverified on every capability claim, and unsourced on all market statistics Raw file: /_raw_sources/S-2026-08-04-obsidian-security-series-d.md
What it claims
Obsidian Security announced on 4 August 2026 an $85 million Series D led by Crescent Cove Advisors with participation from all existing investors (Greylock, Menlo Ventures, Norwest, IVP, Wing, GV), and states a $1.1B valuation. Traction claims: more than 100 customers spending over $100K annually, over 14 spending more than $1M, and “60 of the Fortune 500… including major financial institutions, social media networks and top telecom providers”; the only named customers are T-Mobile, Workday and S&P Global.
The company’s thesis is that AI agents create risk primarily through their access to third-party applications — data warehouses (Databricks, Snowflake), developer infrastructure (GitHub, GitLab), CRM and collaboration tools — which “hold source code, regulated data, and intellectual property”, where “an unsecured agent can leak, modify, or delete that data at machine speed”. It cites three recurring security-team concerns (destructive or irreversible agent actions; unsanctioned agents connecting to critical systems; agents reaching data they were never meant to access) and three unattributed incident examples, including an agent that “circumvented an application’s native guardrails to delete a company’s production database and backups”.
Alongside the funding, Obsidian announced four capabilities:
- Agent Access Governance for Anthropic’s Claude Code and Cowork — extending existing coverage (Copilot Studio, OpenAI, Salesforce Agentforce, n8n) to “discover, govern, and enforce what Claude Code and Cowork agents can access and do”, including restricting permissions to production data, managing access to sensitive files, right-sizing excessive access, controlling unsanctioned MCP and tool usage, and preventing destructive actions at runtime.
- Runtime Protection for AI Agents — real-time guardrails “detecting and blocking privilege escalation, excessive data access, and policy violations at execution time, before impact occurs, based on risk factors aligned to OWASP standards and industry best practices”, framed as shifting governance “from reactive monitoring to preventative action”.
- MCP Server Inventory — visibility into every MCP server “mapped to the agents that invoke them”, to identify unsanctioned MCP usage and “assess the downstream blast radius of agentic connections to backend systems”.
- LLM Inventory — tracking every model powering agents “to spot when models are switched or substituted, giving security and compliance teams continuous assurance that only sanctioned models drive enterprise agents”.
Supporting market statistics offered without source: over 75% of enterprise applications are third-party; non-human identities outnumber human identities 144:1; and “more than 70% of our customers already let agents into third-party apps”.
Notable quotes
- “AI agents gravitate toward third-party applications. That’s where the data lives, that’s where the work happens, and that’s exactly where the risk lives too.” (Hasan Imam, CEO)
- “Security cannot credibly govern agents if control only happens after misuse. With real-time enforcement from Obsidian, governance shifts from reactive monitoring to preventative action.” (release body, Runtime Protection section)
- “Track every large language model powering agents in the environment to spot when models are switched or substituted, giving security and compliance teams continuous assurance that only sanctioned models drive enterprise agents.” (release body, LLM Inventory section)
- “Non-human identities outnumber human identities 144 to 1 inside third-party applications.” (release body — unsourced)
- “…an agent that circumvented an application’s native guardrails to delete a company’s production database and backups.” (release body — unattributed incident)
What’s speculative vs. asserted
Asserted and reasonably firm: the $85M Series D, its 4 August 2026 date, Crescent Cove Advisors as lead, and the participating-investor list. These are corroborated across independent outlets surfaced in search (SiliconANGLE, Axios Pro, BankInfoSecurity), though only the primary release was fetched.
Reported but not filing-grade: the $1.1B valuation (stated by the company in its own summary bullet and repeated by secondary coverage) and the ”>$200M total raised” figure, which came from search-result summaries rather than the fetched release.
Vendor assertion, entirely unverified: all four capability descriptions; the “leading platform” positioning; the customer-spend tiers; the “60 of the Fortune 500” and “major financial institutions” claims; and all three market statistics, none of which carries a methodology or citation. Critically, no availability status is given for any of the four capabilities — whether each is generally available, in limited availability, or in preview is unstated throughout.
Unverifiable as presented: the three cited incidents are described without naming organisations, dates or sources and cannot be relied on or cited onward.
Notably absent: no named EU or UK regulated-FS customer (T-Mobile is telecoms; Workday is software; S&P Global is financial information and ratings — regulated, but not a bank, insurer or asset manager). OWASP is the only standard named anywhere, and only as loose alignment; there is no EU AI Act, ISO/IEC 42001, SS1/23, SR 11-7 or DORA claim in the release body. Nothing is said about evidence retention, log immutability, record format, or whether blocked actions generate retained per-action records — the “blocked vs merely logged” test this vault applies across the agent-harness cohort is left unanswered in its second half.
Site-claim caveat: the page footer carries an ISO/IEC 42001 badge image alongside SOC 2, ISO 27701 and ISO 27001, but with no certificate number, certification body, issue date or scope statement. This cannot be recorded as a verified certification.
Topics this feeds
- AI Governance Platforms — extends the agent-control-layer capital and enforcement-locus threads.
- Obsidian Security — new company page created from this source.
- Model Risk Management and Agentic AI — the LLM-substitution inventory bears on model change-control.
Open questions raised
- Does an LLM-substitution alert constitute a model change-control trigger acceptable to an FS second line under SS1/23 or SR 11-7/SR 26-2 — and does it reconcile with the model inventory of record, or create a parallel security-owned inventory? The release does not address reconciliation.
- Does “detecting and blocking… at execution time” produce retained per-action records of what was blocked versus merely logged? Unstated — the same evidentiary gap recorded against the rest of this cohort.
- What is the availability status of each of the four capabilities? Unstated for all four.
- Is the footer ISO/IEC 42001 badge a genuine certification, and if so what is its scope (entities, products, AI systems covered)? Unverified — scope is the assurance question this vault applies to all ISO 42001 vendor claims.
- Does agent governance sitting in the security stack, scoped to third-party application access, meet EU AI Act Art. 14 human-oversight or Art. 12 record-keeping expectations, or is it a complementary control that itself requires independent challenge? No regulatory standard is claimed by the vendor; the question is this vault’s [inference].
- Obsidian’s coverage now includes agent platforms used by this vault’s own operator (Claude Code, Cowork) — noted as a factual detail of the release, with no bearing on the assessment.