Third-party apps and AI agents are where your business runs. We make sure they're not where it breaks.
by brining trust and control across every
third-party application agents touch.
Security teams have been handed an impossible brief: defend actions by identities they can barely enumerate, across apps they didn't build, on infrastructure they don't control.
We give our customers the visibility into what's connected, controls to enforce what's allowed, and clarity on what needs to change.

Every AI application and agent connected to your enterprise inherits the permissions and trust misconfigurations that already existed in enterprise applications.
At Obsidian, we spent years mapping every identity, permission, and data flow across the third-party enterprise application estate. That foundation is what protects enterprises in the AI era.
Identity and SaaS apps were the new attack surface. Nobody was watching them. We committed to solving it.
Security teams at large financial services and technology companies adopted Obsidian to detect account takeovers, SaaS threats and privilege misuse.
Backed by IVP, Norwest, and GV. Expanded to cover SaaS integrations. Launched threat detection across the full SaaS estate.
As third party apps started connecting to each other, we pioneered securing NHI access across them, guarding a layer that was left exposed.
As enterprises connected AI tools and agents to sensitive data, we built the visibility layer to detect risks before they became breaches.
As AI agents began inheriting access across third party apps, we built the first system to map their real permissions and block high risk actions at runtime.
Led by Crescent Cove Advisors, and backed by all existing investors to scale trust across every third-party app agents touch.








