Home  >  Companies  >  Obsidian Security
Obsidian Security
Provides real-time visibility, governance, and runtime security for AI agents and third-party SaaS applications

Revenue

$65.00M

2026

Details
Headquarters
Palo Alto, United States
CEO
Hasan Imam
Website
Milestones
FOUNDING YEAR
2017

Revenue

Sacra estimates that Obsidian Security reached $65M in annual recurring revenue (ARR) in August 2026, up from $52M at the end of 2025.

Obsidian Security grew from $3M ARR in 2021 to $10M in 2022, $20M in 2023, and $34M in 2024. Deloitte ranked the company No. 95 on its 2025 Technology Fast 500, citing 997% fiscal-year revenue growth from 2021 through 2024.

The increase from $34M to $52M in 2025 coincided with the launch of AI security capabilities and broader agent-governance features, which opened new budget lines within existing enterprise accounts. More than 100 customers now spend over $100,000 annually, and more than 14 spend over $1 million annually, indicating that expansion within large accounts is a primary growth driver alongside new-logo volume.

Obsidian Security sells annual enterprise subscriptions priced primarily by protected users. Contract values increase as customers connect more SaaS applications, add identity and agent-governance modules, and adopt runtime enforcement. The AWS Marketplace listing shows a reference dimension of $100 per protected user on a 12-month contract, though enterprise pricing varies with deal size, module selection, and contract length.

Customer examples quantify the economics behind expansion. One Global 2000 telecommunications customer identified approximately $1.95M in redundant application-licensing savings, another reported an 85% reduction in manual SaaS security work across more than 100 tenants, and a hospitality customer operating across more than 300 cloud applications reported obtaining an initial picture of a major SaaS security event within five minutes.

Valuation & Funding

Obsidian Security raised an $85M Series D on August 4, 2026, at a $1.1B post-money valuation. Crescent Cove Advisors led the round.

The company was founded in 2017 by Ben Johnson, Glenn Chisholm, and Matt Wolff, security executives with experience at Carbon Black and Cylance. Early investors include Greylock Partners, Wing Venture Capital, GV, and DNX Ventures.

Obsidian Security raised a $90M Series C on April 14, 2022, with participation from Menlo Ventures, Norwest Venture Partners, and IVP, among others. The round brought total disclosed funding at the time to $119.5M.

Total funding raised to date is approximately $204.5M across all rounds.

Product

Obsidian Security is a cloud-hosted security platform that connects to an enterprise's third-party SaaS applications and maintains a map of the identities, permissions, integrations, and actions across them. It covers Microsoft 365, Salesforce, Workday, ServiceNow, Snowflake, GitHub, Google Workspace, Databricks, Okta, and more than 200 other enterprise applications, as well as AI and agent platforms including Microsoft Copilot, Salesforce Agentforce, Anthropic Claude, Amazon Bedrock, Google Vertex AI, and OpenAI.

Security teams deploy Obsidian by authorizing API connectors for each application, which the company says can begin in hours without endpoint agents or lengthy professional-services engagements. Obsidian ingests users, roles, entitlements, OAuth grants, tokens, service accounts, agent definitions, tool connections, configuration settings, authentication events, and application actions. Its proprietary Knowledge Graph normalizes this data, maps application-specific accounts to common identities, and models relationships among human users, non-human identities, AI agents, MCP servers, and accessible data.

The graph allows analysts to run cross-application queries that individual SaaS admin consoles cannot answer, such as which dormant service accounts retain broad access to sensitive applications or whether an employee-built AI agent uses a service account with more Salesforce access than the employee who invoked it. Obsidian versions these relationships over time, allowing security teams to reconstruct privilege and configuration changes before and during an incident.

Obsidian applies behavioral baselines, machine-learning models, and detection rules informed by more than 500 breach-response engagements through incident-response partners including Kroll, PwC, and CyberCX. The platform detects account takeover, session hijacking, token theft, MFA bypass, insider misuse, abnormal data access, privilege escalation, overly permissive OAuth grants, and configuration drift. A browser extension monitors shadow SaaS, shadow AI, browser extensions, and sensitive prompts submitted to unapproved generative-AI services, and can block data before it leaves the browser.

Runtime agent security evaluates an execution before completion by inspecting the invoking identity, agent, tools, target application, action, and data sensitivity, then blocking actions that violate policy. For example, a policy might allow an HR agent to read a limited class of Workday records while blocking bulk exports or administrative changes initiated by an unauthorized user. As of mid-2026, autonomous enforcement was live for Claude and Microsoft Copilot, with broader platform coverage on the roadmap.

An AI Assistant provides a natural-language interface to the Knowledge Graph for explaining detections, summarizing incidents, querying identities and permissions, and identifying remediation steps without using multiple application-specific consoles. A Community SDK lets customers, partners, and SaaS vendors build or customize connectors for long-tail applications. Participants built 40 integrations in the first 30 days after launch.

Business Model

Obsidian Security uses a B2B enterprise SaaS model with annual subscription contracts sold directly to CISOs and security leaders, through AWS Marketplace and Google Cloud Marketplace, and via channel partners, systems integrators, and managed security providers. Pricing is based on protected human users, although the platform monitors a larger population of non-human identities and AI agents. This gives buyers a predictable basis for contract sizing as agent counts grow.

Public pricing has three tiers: a free plan for up to 1,000 users that covers application-sprawl discovery and spear-phishing detection; a Foundations tier that adds privilege minimization and compliance mapping; and an Advanced tier that includes account-takeover detection, insider risk, runtime guardrails, AI controls, and forensic audit trails. The free tier provides a product-led entry point, while paid plans use quote-based pricing and an enterprise sales model with large six- and seven-figure contracts.

The go-to-market uses a cybersecurity land-and-expand model. Customers typically start with a specific use case, such as protecting Microsoft 365 or governing a new Copilot rollout, and evaluate the platform by identifying dormant privileged identities and risky OAuth grants within days. Expansion can include more protected users, SaaS applications, business units, or geographies, as well as modules for threat detection, supply-chain security, browser controls, agent governance, and runtime enforcement. More than 14 customers now spend over $1M annually, compared with 20 customers above $100K at the time of the 2022 Series C, indicating higher contract values within existing accounts over time.

The cost structure is heavier than pure workflow SaaS because the platform ingests and retains extensive telemetry, runs behavioral analytics, and maintains API integrations with hundreds of third-party applications whose schemas, rate limits, and authentication requirements change continuously. Cost centers include R&D for data ingestion, graph architecture, machine learning, threat research, and runtime enforcement; cloud infrastructure for processing more than 29 billion events monthly; connector development and maintenance; enterprise sales and solutions engineering; and customer success. A commissioned Forrester study modeled 192% three-year ROI for a 10,000-employee organization, while customers reported $1.95M in redundant license savings and 500 annual hours saved from manual reviews, metrics that underpin the renewal and expansion case.

Competition

Obsidian Security competes across SaaS security posture management, identity threat detection, non-human identity governance, and AI-agent runtime security. These categories are converging as enterprises deploy autonomous agents across business-critical applications.

SaaS security posture management incumbents

AppOmni is the closest traditional competitor, with application-specific security modeling for large SaaS platforms and a posture-led buying motion that now includes AI-agent discovery and AgentGuard controls. A posture-first buyer may view the two as functionally interchangeable.

Valence Security competes through broad SaaS discovery, OAuth and integration governance, and remediation workflows that distribute cleanup to application owners. Its simpler entry point targets organizations prioritizing inventory and access rationalization over advanced threat detection.

Obsidian Security combines posture management with active identity threat detection, cross-application incident investigation, and runtime enforcement, rather than limiting its product to configuration assessment.

Platform security suites

CrowdStrike presents the strongest bundling threat. Its acquisition of Adaptive Shield brought SSPM into the Falcon ecosystem, while its Pangea acquisition added prompt-layer and AI-interaction security. Falcon Guardian links an agent's prompt or decision to subsequent endpoint activity, giving CrowdStrike visibility into locally executing agents and the ability to bundle AI security into existing Falcon contracts.

Palo Alto Networks Prisma AIRS combines AI model security, AI-SPM, automated red teaming, runtime API and firewall controls, and SaaS agent security in a single platform that surpassed $100M in ARR within four quarters. Its enforcement modes and cross-selling through Prisma Cloud, Cortex, and firewalls make it a competitor for enterprise-wide AI security budgets.

SentinelOne acquired Prompt Security, adding browser-level shadow-AI discovery, real-time data redaction, AI firewalls, and agent audit trails to the endpoint, cloud, and identity signals in its Singularity platform.

Identity-centric and AI-native challengers

Cisco completed its acquisition of Astrix on June 29, 2026, adding lifecycle management for service accounts, API keys, OAuth tokens, and MCP servers, along with an Agent Control Plane for provisioning agents with short-lived, just-in-time credentials. Integration into Cisco Identity Intelligence, Secure Access, and Duo could make it an enterprise standard for agent identity.

Okta closed its acquisition of Permiso on August 26, 2026, adding identity runtime attribution that maps agent runs, sub-agents, MCP calls, and downstream actions to an initiating identity. Bundling with Okta's human and machine identity products gives it a direct route to buyers who define agent security as an identity problem.

Noma Security and Zenity compete as AI-native agent-security platforms. Noma spans AI-SPM, agent access control, adversarial testing, and runtime behavioral enforcement across cloud gateways and developer tools. Zenity focuses on agents built in Microsoft Copilot Studio, Microsoft Foundry, Power Platform, and Salesforce Agentforce, with inline runtime security near the agent's decision point.

Keycard, which governs connections between agents and APIs, and Prompt Security, now part of SentinelOne, represent specialized AI-security products that can pressure Obsidian Security on narrow use cases, while larger suites compete on breadth. Netskope competes from the SASE and SaaS-control layer with visibility, policy enforcement, and data-loss controls across cloud applications, including generative AI usage.

TAM Expansion

Obsidian Security is expanding from the bounded SaaS security posture management market into a larger category: the security layer governing human and machine activity inside third-party enterprise applications.

AI-agent governance and runtime enforcement

Agent counts across more than 50 enterprise deployments grew from fewer than 500 in late 2024 to nearly 95,000 by February 2026, and 38% of those agents had at least medium-risk factors when deployed. More than 70% of Obsidian Security's customers already allow agents to access third-party applications.

Runtime enforcement moves the company from monitoring into the transaction path for agent activity. Adjacent product opportunities include agent authorization policies, agent-to-agent security for tasks delegated through supervisor agents and sub-agents, adaptive least-privilege automation, and agent kill switches. Extending runtime controls beyond Claude and Microsoft Copilot to Agentforce, Bedrock, Vertex AI, OpenAI, n8n, and custom frameworks would increase the enforceable transaction base.

The EU AI Act became generally applicable on August 2, 2026, creating regulatory demand for authoritative agent inventories, documented ownership, access records, and runtime policy evidence that Obsidian Security could supply.

SaaS supply-chain and non-human identity security

Modern enterprises connect applications directly through OAuth grants, API keys, persistent tokens, plugins, and service accounts, allowing a breach in one service to give an attacker a durable route into another.

Obsidian Security's January 2026 supply-chain release added integration discovery, preventative restrictions, behavioral detection, and impact forensics. These capabilities allow the company to monetize machine-to-application and application-to-application trust relationships, expanding the buyer set from SaaS security teams to third-party risk management, data security, enterprise architecture, and procurement teams.

Obsidian Security surpassed 200 supported enterprise applications by May 2026, compared with more than 30,000 SaaS applications in the broader market. The Community SDK lets customers, partners, and software vendors create reusable connectors, increasing coverage beyond what internal engineering can provide. Normalized telemetry across applications can also improve behavioral baselines and cross-customer threat intelligence.

Customer base and geographic expansion

Obsidian Security serves 60 Fortune 500 companies as of August 2026, leaving room to replicate its seven-figure expansion pattern across the rest of the Fortune 500 and Global 2000. Large customers can expand from a handful of critical applications to hundreds of SaaS connectors, as well as from conventional identity monitoring to browser security, agent governance, runtime enforcement, and compliance reporting.

The company is also moving down-market. In 2025, it introduced shadow SaaS, AI application management, and threat-prevention capabilities for mid-sized enterprises and appointed a dedicated leader for mid-market expansion. A standardized, self-service package distributed through managed-security partners could address a larger customer population.

Obsidian Security already serves customers across North America, Europe, the Middle East, Southeast Asia, Australia, and New Zealand, with regional data-center availability. Local sales, sovereign hosting, local-language compliance mappings, and relationships with national systems integrators could increase penetration in continental Europe, the Gulf states, Japan, Singapore, and other highly regulated Asia-Pacific markets.

Risks

Platform bundling: CrowdStrike, Palo Alto Networks, Cisco, Okta, SentinelOne, and Microsoft are expanding into agent discovery, governance, identity, and runtime enforcement, allowing customers to buy overlapping capabilities through existing enterprise agreements at discounted or bundled pricing and potentially limiting Obsidian Security's ability to sell agent and SaaS security as an independent platform purchase.

Integration dependency: Obsidian Security depends on APIs, audit logs, and enforcement hooks controlled by hundreds of third-party SaaS and agent-platform vendors, and restrictions on API access, rate limits, telemetry depth, or enforcement actions by platform owners such as Microsoft, Salesforce, or Google could create blind spots and impede uniform runtime enforcement.

Runtime enforcement liability: Operating in the execution path for agent activity exposes Obsidian Security to false negatives that allow damaging agent actions and false positives that interrupt revenue-generating, customer-service, or financial workflows, while the platform's privileged visibility into sensitive prompts, identities, and application activity means a compromise or policy error within Obsidian Security could have an unusually large operational and data-security blast radius.

DISCLAIMERS

This report is for information purposes only and is not to be used or considered as an offer or the solicitation of an offer to sell or to buy or subscribe for securities or other financial instruments. Nothing in this report constitutes investment, legal, accounting or tax advice or a representation that any investment or strategy is suitable or appropriate to your individual circumstances or otherwise constitutes a personal trade recommendation to you.

This research report has been prepared solely by Sacra and should not be considered a product of any person or entity that makes such report available, if any.

Information and opinions presented in the sections of the report were obtained or derived from sources Sacra believes are reliable, but Sacra makes no representation as to their accuracy or completeness. Past performance should not be taken as an indication or guarantee of future performance, and no representation or warranty, express or implied, is made regarding future performance. Information, opinions and estimates contained in this report reflect a determination at its original date of publication by Sacra and are subject to change without notice.

Sacra accepts no liability for loss arising from the use of the material presented in this report, except that this exclusion of liability does not apply to the extent that liability arises under specific statutes or regulations applicable to Sacra. Sacra may have issued, and may in the future issue, other reports that are inconsistent with, and reach different conclusions from, the information presented in this report. Those reports reflect different assumptions, views and analytical methods of the analysts who prepared them and Sacra is under no obligation to ensure that such other reports are brought to the attention of any recipient of this report.

All rights reserved. All material presented in this report, unless specifically indicated otherwise is under copyright to Sacra. Sacra reserves any and all intellectual property rights in the report. All trademarks, service marks and logos used in this report are trademarks or service marks or registered trademarks or service marks of Sacra. Any modification, copying, displaying, distributing, transmitting, publishing, licensing, creating derivative works from, or selling any report is strictly prohibited. None of the material, nor its content, nor any copy of it, may be altered in any way, transmitted to, copied or distributed to any other party, without the prior express written permission of Sacra. Any unauthorized duplication, redistribution or disclosure of this report will result in prosecution.