Obsidian Security

Obsidian Security delivers a platform for securing the enterprise layer where SaaS applications, AI agents, and third-party integrations interact. It focuses on visibility, runtime protection, and continuous governance so security teams can understand how users, non-human identities, apps, data, and automations are connected and where risk is expanding across the business.

Its offering spans SaaS posture management, identity threat detection and response, supply chain security, shadow SaaS and shadow AI discovery, and AI agent security. Obsidian Security emphasizes agentless deployment, deep application telemetry, and a knowledge-graph-driven view of permissions, configurations, and activity so organizations can reduce attack surface, enforce least privilege, automate compliance, and respond faster to SaaS and AI threats.

Offerings, Capabilities, and Integrations

Obsidian Security correlates application configuration, user and agent activity, identity privileges, browser telemetry, and threat intelligence to expose risk inside and between enterprise applications. That model supports continuous posture management, least-privilege enforcement, threat detection, investigation, and runtime policy controls for AI agents and SaaS workflows.

The platform is built around deep integrations rather than network-only visibility. Obsidian Security offers hundreds of validated connectors across SaaS and AI platforms, supports custom connectors, and connects with SIEM and SOAR workflows so alerts, evidence, and response actions can fit into existing security operations.

Its integration coverage spans widely used enterprise applications such as Google Workspace, Microsoft 365, Salesforce, ServiceNow, Snowflake, Workday, Okta, GitHub, and Databricks, alongside AI platforms including Amazon Bedrock, Google Vertex AI, Microsoft Copilot, Microsoft Foundry, OpenAI, n8n, and Salesforce Agentforce.

Products and Services

  • AI Agent Security: Provides end-to-end security for enterprise AI agents with discovery, permission analysis, governance, and runtime protection across connected applications and tools.
  • AI Security and Posture Management (AI-SPM): Delivers continuous inventory, observability, risk scoring, and governance for AI agents and GenAI applications, including visibility into ownership, models, MCP servers, permissions, and data exposure.
  • SaaS Security Posture Management (SSPM): Continuously monitors SaaS configurations, access drift, and compliance gaps so teams can harden posture across connected business applications.
  • SaaS Supply Chain Security: Secures SaaS-to-SaaS integrations and third-party connections with visibility into scopes, permissions, behavior, and blast radius to prevent and contain supply chain risk.
  • SaaS Compliance and Governance: Helps automate SaaS control monitoring, evidence collection, and policy enforcement to streamline audit readiness and ongoing governance.
  • SaaS Privilege Identity Management: Identifies privileged and over-permissioned accounts, surfaces access drift, and supports least-privilege enforcement across SaaS environments.
  • SaaS API Integration Risk Management: Finds and evaluates risky OAuth grants, API integrations, service accounts, and app-to-app trust relationships that expand SaaS attack surface.
  • SaaS Identity Threat & Response: Detects and helps investigate identity-driven attacks targeting SaaS accounts, sessions, tokens, and non-human identities, with support for response workflows.
  • Shadow SaaS Discovery and Management: Discovers unmanaged SaaS usage across browser, email, and identity signals and helps teams review, prioritize, and reduce shadow application risk.
  • Shadow AI Discovery: Finds sanctioned and unsanctioned AI applications and shadow agents so organizations can govern adoption and reduce data exposure risk.
  • AI Agent Governance: Extends least-privilege governance to AI agents by comparing granted access with actual behavior and surfacing oversharing, privilege escalation, and stale connection risks.
  • AI Agent Runtime Security: Applies runtime guardrails to monitor or block high-risk agent executions, abnormal behavior, malicious prompts, and unsafe tool calls before impact occurs.
  • SaaS Token Compromise Detection: Detects token theft, session hijacking, and related account takeover activity across SaaS environments.

Target Customers

Obsidian Security primarily targets enterprises with large SaaS estates, business-critical application data, and growing exposure to third-party integrations, service accounts, and AI agents. Its buyers typically include security operations, identity and access, application security, governance, risk, compliance, and IT teams that need better control inside cloud applications.

The platform is well suited to organizations in regulated or integration-heavy sectors such as financial services, healthcare, telecommunications, manufacturing, software, data, and hospitality. Obsidian Security also addresses mid-sized enterprises that need faster deployment and lower operational overhead, particularly for shadow SaaS, shadow AI, and identity threat prevention use cases.

Cloud Integrations and Marketplace

  • AWS Marketplace: Obsidian Security is available for procurement through AWS Marketplace, including private offer purchasing and AWS-billed deployment.
  • Google Cloud Marketplace: Obsidian Security is available through Google Cloud Marketplace, giving Google Cloud customers a marketplace procurement path.
  • Amazon Bedrock: Obsidian Security supports governance and risk visibility for Amazon Bedrock agents, including inventory, risk assessment, and permission analysis.
  • Google Vertex AI: Obsidian Security supports Google Vertex AI agent governance with continuous inventory, connection mapping, and controls over risky access and behavior.
  • Microsoft Azure AI Foundry: Obsidian Security supports governance for agents built on Azure AI Foundry, including agent inventory, connection tracing, and controls over unsanctioned access.

Key People

  • Hasan Imam: CEO
  • Xinran Wang: Chief Technology Officer
  • Khanh Tran: Chief Product Officer
  • Matt Wolff: Co-Founder & Chief AI Officer
  • Brian Murphy: Chief Revenue Officer
  • Paul Luongo: Chief Legal Officer
  • Chithra Rajagopalan: Head of Finance
  • Priya Balakrishnan: SVP, Product Marketing
  • Tina Lei: VP of Revenue Marketing
  • Ish Cheema: Head of Service and Delivery

Key Facts

  • Headquarters: Newport Beach, California, United States
  • Employees: 256
  • Annual Revenue: $45.4M
  • Parent Company: None
  • Subsidiaries: None
  • Publicly Listed: Private

Analyst Recognitions

  • Forrester: Strong Performer in The Forrester Wave™: SaaS Security Posture Management, Q4 2023.
Obsidian

Enter a search