Security Strongly positive 7

Onyx Raises $113M to Bring AI Agent Governance to SaaS Stacks

Onyx Security's $113 million funding will drive development of a platform that discovers and controls AI agents embedded in SaaS applications, cloud services, and endpoints. For SaaS operators, the solution promises a unified layer to enforce policy and compliance across sprawling AI integrations.

· 4 min read · Verified by 2 sources ·

SaaS briefing

Key takeaways

7 impact
Strongly positivesentiment
2sources
4min read
  1. Onyx Security's $113 million funding will drive development of a platform that discovers and controls AI agents embedded in SaaS applications, cloud services, and endpoints.
  2. For SaaS operators, the solution promises a unified layer to enforce policy and compliance across sprawling AI integrations.
Drawn from
  • SecurityWeek
  • ventureburn.com

In this briefing

Mentioned

Key Intelligence

Key Facts

  1. 1Onyx Security raised $113 million in a Series B round led by Bessemer Venture Partners, with participation from Cyberstarts, TCV, Conviction, FirstMark, Vintage, QuantumLight, and G Squared.
  2. 2The new funding brings total capital raised to $153 million and values the company at an estimated $640 million, according to reports.
  3. 3The company, founded two years ago in Israel, offers a centralized platform to monitor, control, and enforce policy on AI agents across SaaS, cloud, and endpoint environments.
  4. 4The platform uses proprietary models to track AI agent decision-making in real time, enabling automatic intervention against unintended, malicious, or non-compliant actions.
  5. 5The funding will be used to train proprietary models further and scale go-to-market efforts globally.
  6. 6Investor Hila Zigman of Cyberstarts believes the category of AI agent governance will become 'one of the defining security categories of the coming decade.'

Who's Affected

Enterprise SaaS platforms (Salesforce, Workday, etc.)
technologyPositive
Cloud infrastructure providers (AWS, Azure, GCP)
companyPositive
Cybersecurity incumbents (CrowdStrike, Palo Alto)
companyNegative
SaaS AI Security Market

Analysis

As every major SaaS vendor — from Salesforce to ServiceNow — rolls out AI copilots and agents, the operational surface area for security teams has exploded. Onyx Security’s platform specifically targets this gap, offering real-time monitoring of AI agent behavior within SaaS workflows. For CIOs and CISOs at SaaS-heavy enterprises, the ability to discover shadow AI, block prompt injections, and ensure every agent action aligns with policy is no longer optional — it’s the difference between safe acceleration and an unmanageable risk crisis. The $113 million infusion means the platform will likely expand its integrations deeper into the SaaS ecosystem, becoming a crucial control plane.

Onyx Security, an Israeli startup, has closed a $113 million Series B funding round, bringing its total capital raised to $153 million and reportedly valuing the company at an estimated $640 million. The round was led by Bessemer Venture Partners, with strong participation from Cyberstarts, TCV, Conviction, FirstMark, Vintage, QuantumLight, and G Squared — a syndicate that blends top-tier security-focused VCs with growth-stage generalists. The funding marks a pivotal moment for the emerging market of AI agent governance, as enterprises increasingly deploy autonomous AI agents that interact with sensitive corporate systems but lack inherent accountability or oversight.

Onyx Security, an Israeli startup, has closed a $113 million Series B funding round, bringing its total capital raised to $153 million and reportedly valuing the company at an estimated $640 million.

The core challenge Onyx addresses is the proliferation of “shadow AI” — unsanctioned or unmonitored AI tools creeping into enterprise environments, from SaaS applications to cloud infrastructure. These AI agents, while boosting productivity, can introduce severe risks: they may execute unintended actions, fall victim to prompt injection attacks, or violate regulatory mandates like GDPR or sector-specific compliance rules. Onyx’s platform acts as a control layer, continuously monitoring AI agent decision-making steps across SaaS, cloud, and endpoint environments. By leveraging proprietary models, it can trace an agent’s reasoning in real time, detect anomalous or policy-violating behavior, and intervene automatically — much like a guardrail system for highly autonomous software.

The timing is strategic. Enterprise AI adoption is accelerating, with agentic architectures topping CIO priority lists, yet security frameworks remain nascent. Traditional endpoint detection and response (EDR) or identity tools are ill-equipped to govern a copilot that books travel or a coding agent that pushes repos. Onyx positions itself as the missing infrastructure, effectively redefining the security stack for the AI era. The involvement of Cyberstarts — a firm known for backing foundational cybersecurity categories — signals investor conviction that AI agent control could become as ubiquitous as cloud access security brokers (CASBs) became in the last decade.

From a market perspective, the $113 million raise is one of the largest Series B rounds in the cybersecurity sector this year, and it follows a Series A that closed in 2024. The valuation of $640 million implies strong revenue multiples, likely predicated on early enterprise traction. While Onyx hasn't disclosed customer count or revenue, the willingness of Bessemer and TCV to co-invest suggests significant pipeline visibility. TCV’s presence in particular hints at potential for a near-term IPO path, given the firm’s track record of backing pre-IPO enterprise companies.

What to Watch

The product narrative will resonate with CISOs grappling with the “agent sprawl” problem. Onyx’s approach to shadow AI discovery, real-time safeguards, and compliance alignment addresses both operational security and board-level risk management. This could accelerate adoption among heavily regulated industries like finance, healthcare, and critical infrastructure. However, competition is likely to intensify: incumbents like CrowdStrike and new entrants like Mate Security (which recently raised $35 million for agentic SOC) are circling similar turf. Onyx’s advantage lies in its model-agnostic, environment-spanning architecture and its proprietary AI models that claim to understand decision chains, not just signatures.

Looking ahead, the funding will fuel two key areas: training those proprietary models to stay ahead of evolving AI threats, and scaling go-to-market teams globally. The Israeli startup now has the capital to expand beyond early adopters and capture market share before the inevitable wave of consolidation. If executed well, Onyx could define the category, much like Okta did for identity. The broader implication is that AI governance is no longer a niche — it is a boardroom imperative, and investors are betting on platforms that can bridge the chasm between AI innovation and enterprise safety.

Source cluster

Primary reporting

2articles

Cite This Page

"Onyx Raises $113M to Bring AI Agent Governance to SaaS Stacks." SaaS Intelligence Brief, July 30, 2026. https://getsaasbrief.com/story/onyx-security-113m-ai-governance-saas-platform

How we covered this story

Every story in our saas coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the saas space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.