Obsidian Security
A real category-defining position in AI agent governance and a confirmed $1.1B unicorn mark, but a valuation resting on estimated rather than disclosed ARR inside a fast-crowding market.
Obsidian has genuine category leadership in the emerging AI-agent-governance market and a confirmed $1.1B unicorn mark, but the valuation rests on estimated rather than disclosed ARR in a rapidly crowding field, supporting continued tracking over conviction pricing.
Cover facts
Company profile
Obsidian Security is a Palo Alto, California-based cybersecurity company founded in 2017 that has evolved from SaaS security posture management (SSPM) into runtime governance and security for AI agents and non-human identities operating inside enterprise third-party SaaS applications such as Microsoft 365, Salesforce, and Workday. In August 2026 it raised an $85 million Series D at a $1.1 billion post-money valuation led by Crescent Cove Advisors, bringing lifetime funding above $200 million. Company-reported traction includes more than 100 customers spending over $100,000 per year, more than 14 spending over $1 million, and 60 Fortune 500 customers, though current revenue, ARR, margins, retention, and headcount are not publicly disclosed.
- Website
- www.obsidiansecurity.com
- Founded
- 2017-01-01
- Founders
- Glenn Chisholm, Ben Johnson, Matt Wolff
- Founding location
- Newport Beach, California, USA
- Headquarters
- Palo Alto, California, USA
- Product
- Obsidian sells a platform that discovers and governs non-human identities and AI agents inside third-party SaaS applications, providing runtime governance that detects and blocks privilege escalation, excessive data access, and policy violations, plus MCP inventory, model registry, SaaS supply-chain security, and breach clarity/forensics.
- Customers
- Large enterprises and Fortune 500 organizations—especially financial institutions, social media, and telecom—running many third-party SaaS applications with growing populations of AI agents and non-human identities.
- Business model
- Recurring enterprise SaaS subscriptions priced by scope of protected identities and applications, with customer spend tiered from six figures to seven figures per year.
- Stage
- Late-stage private (Series D unicorn)
- Funding status
- Latest priced round is the August 4, 2026 Series D of $85 million at a $1.1 billion post-money valuation led by Crescent Cove Advisors with participation from existing investors including Greylock Partners and Menlo Ventures; lifetime funding exceeds $200 million across five rounds. Hasan Imam serves as CEO and is not one of the disclosed founders.
Executive summary
Top strengths
- Obsidian holds an early, differentiated position in runtime AI-agent and non-human-identity governance across major third-party SaaS platforms, a category with large and fast-growing market forecasts.
- Disclosed traction is strong for its stage—more than 100 customers spending over $100K/year, more than 14 over $1M/year, and 60 Fortune 500 customers—backed by named references such as Snowflake.
- The company is well capitalized after an $85M Series D at a $1.1B valuation, with a blue-chip investor syndicate (Crescent Cove, Greylock, Menlo, Norwest, IVP) and over $200M raised.
Top risks
- The $1.1B valuation implies roughly 22x on an estimated $50M ARR and about 46x on the disclosed ~$24M spend floor, so pricing depends on an unverified growth-premium ARR assumption.
- Competition is intensifying, led by direct rival Zenity ($125M raised one day earlier) plus Grip, Push, Nudge, Valence, and AppOmni, compressing differentiation and pricing power.
- Platform commoditization risk is material as Microsoft, Salesforce, and Google embed native agent-security controls that could erode Obsidian's standalone value.
- The AI-agent-governance category is nascent and adoption timing is uncertain, so the SSPM-to-agent pivot is a bet on a market that may mature more slowly than forecasts imply.
Open gaps
- Need audited ARR, revenue run-rate, growth rate, and an ARR bridge from the disclosed customer-spend tiers.
- Need gross margin, net revenue retention, churn, and customer-concentration data to prove durable recurring economics.
- Need burn, runway, and headcount disclosure to assess capital efficiency and execution capacity.
- Need confirmation of headquarters (Palo Alto vs. legacy Newport Beach) and clearer named Fortune 500 customer evidence beyond aggregate counts.
Contents
01Company Overview
1.1 Identity, Headquarters, and Category Positioning
Obsidian Security is best anchored as a Palo Alto, California-based private cybersecurity company founded in 2017 and currently positioned around runtime governance for AI agents and non-human identities inside enterprise third-party SaaS applications. The Palo Alto headquarters should be treated as the current canonical field because the freshest August 2026 financing coverage repeatedly uses California/Palo Alto framing; legacy profile surfaces that imply Newport Beach are not ignored, but they are weaker and stale enough to become an explicit evidence gap rather than the primary identity. The business model has also moved beyond its earlier SSPM narrative. Current official and independent coverage presents Obsidian as helping security teams inventory AI agents, MCP servers, models, non-human identities, and policy violations before actions take effect. That makes the company a late-stage AI-agent governance vendor, not merely an older SaaS posture-management tool.[CO001, CO002, CO003, CO009, CO010, CO028]
| Metric | Value / Status | Date | Confidence | Gap |
|---|---|---|---|---|
| Company identity | Obsidian Security, Inc.; private cybersecurity vendor | 2026-08-05 | High | Legal entity documents not in public source set |
| Headquarters | Palo Alto, California | 2026-08-04 | High | Legacy Newport Beach discrepancy requires reconciliation |
| Founded | 2017 | 2017 | Medium | Incorporation certificate not in public source set |
| Stage | Private Series D unicorn | 2026-08-04 | High | No public cap table or preference terms |
| Latest round | $85M Series D | 2026-08-04 | High | No secondary/debt detail disclosed |
| Latest valuation | $1.1B post-money | 2026-08-04 | High | No revenue multiple can be verified |
| Total raised | More than $200M across five rounds | 2026-08-04 | High | Exact cumulative total above $200M not disclosed |
| Customers spending $100K+ | 100+ customers | 2026-08-04 | High | Company-reported, not audited |
| Customers spending $1M+ | 14+ customers | 2026-08-04 | High | Potential customer concentration unknown |
| Fortune 500 customers | 60 | 2026-08-04 | High | Named logo list not fully public |
| NHI ratio | 144:1 non-human to human identities in third-party apps | 2026-08-04 | High | Methodology and sample not disclosed |
| Revenue / ARR | 2026-08-05 | Medium | Not publicly disclosed; only an inferred ~$24M floor is supportable | |
| Headcount | 2026-08-05 | Medium | Not publicly disclosed |
Snapshot uses exact public numbers from the August 2026 source set; null means no public disclosure, and the only ARR datapoint is a narrow estimate, not reported ARR.
[CO001, CO002, CO003, CO011, CO012, CO015]The business logic connects SaaS visibility, NHI inventory, runtime enforcement, enterprise traction, and growth capital.
[CO009, CO022, CO027, CO028, CO034, CO046]The public KPI surface establishes late-stage traction while leaving revenue, ARR, and headcount undisclosed.
The ~$24M ARR floor is a calculation from disclosed spend thresholds, not reported ARR, and no other revenue value is used in this chapter.
[CO011, CO012, CO015, CO019, CO020, CO021]1.2 Founders, Leadership, and Governance Disclosure
The founder set is Glenn Chisholm, Ben Johnson, and Matt Wolff; Hasan Imam should not be described as a founder. The distinction matters because the diligence story is founder-heavy in product and technical credibility but operator-led in the CEO seat. Chisholm remains visible as Co-Founder, Chairman, and Chief Product Officer, while Johnson and Wolff supply the CTO and chief-scientist lineage tied to Carbon Black and Cylance experience. Imam brings go-to-market and customer-leadership background from Shape Security, which Norwest connects to a roughly $1 billion F5 exit, and he is the executive quoted in the latest Series D narrative. Public leadership directories support the current CEO field but do not resolve board composition, observer rights, committee structure, or investor control. That leaves governance diligence centered on board materials, succession planning, and whether founder product authority and non-founder CEO authority are cleanly allocated.[CO004, CO005, CO006, CO007, CO008, CO029]
| Person | Role | Background | Functional coverage | Key-person dependency | Evidence basis |
|---|---|---|---|---|---|
| Glenn Chisholm | Co-Founder, Chairman & Chief Product Officer | Ex-CTO of Cylance; first CISO of Telstra | Product vision, SaaS/AI-security narrative, founder credibility | High | StartupHub plus ownership/profile sources |
| Ben Johnson | Co-Founder & CTO | Carbon Black co-founder before VMware acquisition | Technical architecture and endpoint/security founder-market fit | High | Ownership/profile sources plus company profile context |
| Matt Wolff | Co-Founder & Chief Scientist | Former Chief Data Scientist at Cylance | Data science, behavioral analytics, and detection science | Medium-high | StartupHub/ownership profile context |
| Hasan Imam | Chief Executive Officer, not founder | Former Chief Revenue/Customer Officer at Shape Security before F5 exit | Go-to-market scaling, enterprise customer operations, fundraising voice | High | Series D announcement, Craft, and Norwest |
| Public board | Not fully disclosed | Investor representatives and observers not publicly enumerated | Governance oversight, controls, and succession planning | Unknown | Absence across retained public sources |
Leadership enumeration is partial because public sources verify the founder/CEO facts but do not disclose a complete board or full org chart.
[CO003, CO004, CO005, CO006, CO007, CO008]1.3 Funding History, Investor Base, and Scale Metrics
The capital-formation record is strong but still disclosure-limited. Greylock led the earliest Series A, Norwest led the June 2021 Series B-1, and Menlo Ventures, Norwest, and IVP led the April 2022 $90 million Series C, when total funding reached $119.5 million. The August 4, 2026 Series D added $85 million at a $1.1 billion valuation, was led by Crescent Cove Advisors, and included existing investors Greylock, Menlo, Norwest, IVP, Wing, and GV. Post-round, Obsidian reports more than $200 million raised across five rounds. The scale evidence is similarly impressive but company-reported: more than 100 customers spend over $100,000 per year, more than 14 spend over $1 million, and 60 Fortune 500 companies are customers. Those thresholds are useful because they establish a real enterprise-spend floor, yet they still do not reveal logo concentration, discounting, renewal quality, expansion cohorts, or gross retention. Revenue, ARR, NRR, gross margin, burn, runway, and headcount remain undisclosed, so the only ARR figure here is a deliberately narrow estimated floor of roughly $24 million from disclosed spend thresholds.[CO011, CO012, CO013, CO014, CO015, CO016]
| Stakeholder | Role | Control or economic importance | Diligence ask | Evidence basis |
|---|---|---|---|---|
| Crescent Cove Advisors / Jun Hong Heng | Series D lead | New lead investor at $1.1B valuation and likely latest preference terms | Request term sheet, liquidation preference, pro rata, and board/observer rights | Company announcement plus independent Series D coverage |
| Greylock Partners | Series A lead and repeat investor | Earliest institutional validation and continued participation | Confirm initial ownership, reserves, and board history | Greylock portfolio plus Series D participation reports |
| Norwest Venture Partners | Series B-1 lead and Series C co-lead | Longitudinal investor with CEO relationship and round history | Clarify current governance role and follow-on economics | Norwest blog plus Series D coverage |
| Menlo Ventures | Series C co-lead and repeat investor | Late-stage cyber/SaaS validation before 2026 pivot | Review Series C terms and current ownership | Series C coverage plus Series D participation reports |
| IVP | Series C co-lead and repeat investor | Growth-stage syndicate signal for eventual exit optionality | Confirm board/observer involvement and pro rata status | Series C and Series D coverage |
| Wing and GV | Existing investors in latest syndicate | Strategic/venture credibility around enterprise security and AI infrastructure | Understand ownership, strategic rights, and customer/channel value | Series D coverage and investor-list reports |
| Fortune 500 customer base | Commercial stakeholder group | 60 Fortune 500 customers and 14+ seven-figure accounts can drive concentration risk | Request logo list, ARR bridge, renewal cohorts, and concentration schedule | Series D coverage and company claims |
This is not a cap table; it maps economically material stakeholders whose exact ownership, preferences, and control rights are not publicly disclosed.
[CO013, CO014, CO016, CO017, CO018, CO019]1.4 Milestone Chronology and Competitive Context
The chronology shows a company that used SSPM-era investor validation to reach the AI-agent governance moment quickly. The durable foundation is the 2017 founding, followed by a June 2021 Norwest-led Series B-1 and an April 2022 $90 million Series C that still described the company as an SSPM leader. The 2026 evidence resets the narrative around AI agents, MCP inventory, runtime controls, Fortune 500 penetration, and a unicorn Series D. The adverse caveat is not an internal scandal; it is competitive timing. Zenity, a direct AI-agent security competitor, announced a larger $125 million round one day before Obsidian disclosed its own $85 million raise. That does not negate Obsidian's customer and syndicate signals, but it means the milestone record should be read as participation in an intensifying category land-grab rather than as solitary category ownership. That distinction should carry into later market, product, customer, financial, risk, and valuation chapters as shared ground truth.[CO031, CO032, CO034, CO045, CO046, CO047]
| Date | Event | Type | Amount / valuation / status | Participants | Implication |
|---|---|---|---|---|---|
| 2017 | Obsidian Security founded | founding | Operating founding year | Glenn Chisholm; Ben Johnson; Matt Wolff | Establishes the founder set and age of company |
| 2021-06 | Series B-1 led by Norwest | financing | Amount not publicly specified in retained source set | Norwest Venture Partners; Obsidian | Marks institutional SSPM-era growth financing |
| 2022-04 | Series C closed | financing | $90M; total funding $119.5M | Menlo Ventures; Norwest; IVP; Greylock; Wing; GV | Establishes pre-pivot late-stage SSPM credibility |
| 2026-08-03 | Zenity announces larger AI-agent security financing | adverse | $125M competitor round | Zenity; Norwest-led syndicate in competitor coverage | Shows the category was already intensely funded before Obsidian's announcement |
| 2026-08-04 | Series D announced | financing | $85M at $1.1B valuation | Crescent Cove; existing investors | Creates unicorn status and >$200M raised narrative |
| 2026-08-04 | Enterprise scale metrics disclosed | scale | 100+ $100K customers; 14+ $1M customers; 60 Fortune 500 | Obsidian customer base | Shows traction but also concentration questions |
| 2026-08-04 | Product narrative extends from SSPM to AI-agent runtime governance | product | AI agents, NHI governance, Claude Code/Cowork extension | Obsidian product and security teams | Reframes category and use-of-proceeds thesis |
| 2026-08-05 | OWASP-aligned runtime governance coverage appears | regulatory | MCP inventory, model registry, runtime blocking, OWASP criteria | FinTech Global; Obsidian | Connects product controls to emerging AI-agent security standards |
Chronology is exhaustive for the material public milestones in the authorized CH1/shared source set; private launches and undisclosed financings may be absent.
[CO003, CO011, CO012, CO013, CO014, CO015]Obsidian moved from 2017 founding through SSPM financings into a 2026 AI-agent governance unicorn raise amid direct competitive funding pressure.
[CO003, CO011, CO012, CO016, CO017, CO031]1.5 Exhibits
02Market Analysis
2.1 Market Boundary and Included Spend
Obsidian should not be sized against every cybersecurity or posture-management dollar that can be labeled AI. The working boundary is enterprise third-party SaaS and AI-agent governance: runtime controls for autonomous agents, non-human identity security, SSPM, SaaS-to-SaaS integration risk, and selected ITDR-like identity-detection workflows. Included spend is therefore the budget used to discover agents and integrations, map permissions, monitor behavior, block excessive data access, and prove policy compliance across SaaS applications. Excluded spend is broad cloud posture management, endpoint security, generic data posture management, and native platform controls that never touch third-party SaaS agents. Status quo matters because many enterprises still use manual SaaS reviews, IdP-native controls, spreadsheet approvals, or the built-in settings of Microsoft, Salesforce, and other application platforms. The market is attractive because Obsidian can point to 144 non-human identities for every human identity and more than 35,000 third-party apps, but the same breadth requires discipline in not counting every adjacent SPM dollar as serviceable market.[CM005, CM006, CM007, CM021, CM022, CM023]
| Segment / category | Included spend | Excluded spend | Buyer / payer | Relevance |
|---|---|---|---|---|
| AI-agent runtime governance | Agent inventory, policy design, runtime blocking, model/tool visibility | Generic AI productivity software without security control | CISO, AI platform owner, security operations | Core Obsidian category and primary TAM link |
| Non-human identity security | Discovery, entitlement review, secrets/service-account controls, privileged NHI monitoring | Human-only IAM, workforce SSO seats without NHI scope | Identity security, IAM, CISO | Primary SAM anchor because NHIs are the operating entities |
| SSPM / SaaS governance | Misconfiguration detection, SaaS-to-SaaS integration controls, app-permission posture | Cloud infrastructure posture and endpoint posture outside SaaS | SaaS app owners, security engineering | Legacy Obsidian base and current buyer bridge |
| ITDR adjacency | Identity threat detection, suspicious identity behavior, response workflows | Full IAM replacement or endpoint detection unrelated to SaaS identities | SOC, IAM, threat detection teams | Budget adjacency but not fully countable as SAM |
| Broad SPM adjacency | CSPM, DSPM, ISPM, DSPM-like posture analytics when connected to SaaS agents | Posture categories with no third-party SaaS or agent execution path | CISO, cloud security, data security | Useful context but excluded from direct SAM |
| Status quo substitutes | Manual access reviews, IdP-native rules, spreadsheets, native platform governance | Dedicated third-party runtime agent-control platform | Security operations, application admins | Constrains adoption and pricing until risk is urgent |
Boundary rows define Obsidian-relevant spend; broad SPM is intentionally shown as an adjacency rather than fully serviceable market.
[CM021, CM022, CM023, CM028, CM035, CM036]2.2 TAM, SAM, and SOM Sizing Lenses
The most defensible top-of-funnel TAM is the 2026 AI Agent Security estimate of roughly $26 billion, because Obsidian is explicitly selling security and runtime governance for AI agents. That number should not flow directly into revenue assumptions. A narrower SAM should be anchored in NHI Security and SSPM, because those categories map to identities, SaaS permissions, third-party integrations, and governance workflows. Using NHI Security at about $8.22 billion and SSPM at about $3.69 billion, while discounting overlap, produces a practical 2026 SAM range of approximately $8 billion to $12 billion. The narrow Agentic AI Security estimate of $1.65 billion is a useful lower-bound lens for nascent agent-specific controls, while ITDR at $3.42 billion is an adjacency rather than a direct add-on. SOM is far smaller: disclosed customers imply an ARR floor of about $24 million and a plausible current ARR range of roughly $40 million to $70 million, so near-term obtainable market should be framed as approximately $50 million to $150 million until management provides ARR, NRR, segment mix, and pipeline conversion.[CM001, CM002, CM003, CM008, CM009, CM010]
| Publisher / lens | Year | Geography | Value | CAGR | Methodology / caveat | Confidence | Limitation |
|---|---|---|---|---|---|---|---|
| SNS Insider AI Agent Security | 2026 | Global | ~$26.0B | 39.1% to 2035 | Broad AI-agent security TAM; best headline category for Obsidian positioning | Medium | Commercial analyst taxonomy may include controls Obsidian does not sell |
| MarketsandMarkets Agentic AI Security | 2026 | Global | ~$1.65B | 42% to 2032 | Narrow agentic-security lens; useful lower-bound for agent-specific controls | Medium | Likely excludes broader NHI and SSPM spend |
| Mordor Intelligence NHI Security | 2026 | Global | ~$8.22B | 22.78% to 2031 | Identity-centric security for machine and service identities | Medium | Not all NHI spend happens inside third-party SaaS apps |
| Research and Markets SSPM | 2026 | Global | ~$3.69B | 12.6% to 2032 | SaaS-security posture management software lens | Medium | Conflicts with Frost baseline and may include non-agent SSPM |
| Frost & Sullivan SSPM | 2025→2030 | Global | $0.484B → $3.53B | 48.7% | Much smaller baseline but faster growth; adverse uncertainty input | Medium | Paywalled source and different taxonomy from Research and Markets |
| Mordor Intelligence ITDR | 2026→2031 | Global | $3.42B → $10.51B | 25.17% | Identity-threat detection adjacency to runtime identity security | Medium | Adjacent, not fully serviceable by Obsidian |
| InsightAce broad SPM | 2025/2026 | Global | ~$26.35B | n/a | Broad security-posture-management adjacency across multiple posture classes | Low-medium | Overstates Obsidian if CSPM/DSPM are counted wholesale |
| Internal SAM lens | 2026 | Global / enterprise SaaS weighted | ~$8B–$12B | n/a | NHI plus SSPM and narrow agentic overlap, with double-counting discounted | Low | Requires management product mix and buyer-budget data |
| Internal SOM lens | 2026 near term | Enterprise accounts | ~$50M–$150M | n/a | Derived from 100+ customers at $100K+, 14+ at $1M+, and inferred ARR range | Low | ARR, NRR, churn, and pipeline conversion not disclosed |
All values are USD unless noted; SAM and SOM rows are diligence derivations from cited market and customer disclosures, not publisher forecasts.
[CM008, CM009, CM010, CM011, CM012, CM013]A $26B AI-agent-security TAM narrows to an estimated $8B–$12B SAM and a $50M–$150M near-term Obsidian SOM.
SAM and SOM are diligence estimates; only TAM, NHI, SSPM, and narrow agentic-security inputs are publisher-reported.
[CM008, CM009, CM010, CM011, CM015, CM016]The same Obsidian opportunity ranges from narrow agentic security to broad AI-agent security depending on taxonomy.
Rows use a consistent USD-billions unit; midpoints and high/low combinations are diligence transformations, not publisher-provided confidence intervals.
[CM008, CM009, CM010, CM011, CM016, CM017]2.3 Buyer Segments, Budget Owners, and Adoption Path
The buying center is cross-functional because the operational problem crosses AI, identity, SaaS administration, and security operations. CISOs and security operations teams care about attack surface and policy enforcement; identity teams care about NHI sprawl and privileged grants; SaaS application owners care about business-process continuity; and AI platform or transformation teams care about deploying agents without losing control of tools and data. Obsidian's disclosed 60 Fortune 500 customers and 100-plus six-figure customers support enterprise budget capacity, but they do not identify budget owner or product-line split. Adoption likely starts with inventory of SaaS apps, integrations, agents, and MCP servers; moves into risk scoring and policy design; and then becomes runtime blocking when agents attempt privilege escalation, excessive data access, or unsanctioned tool use. The 70% customer agent-adoption figure makes this a current 2026 purchasing problem rather than a long-dated scenario, although procurement will still require proof that runtime controls avoid false positives and integrate with SOC workflows.[CM002, CM003, CM004, CM024, CM025, CM026]
| Segment | Buyer | User | Payer / budget owner | Workflow | Adoption trigger | Diligence ask |
|---|---|---|---|---|---|---|
| Fortune 500 enterprise | CISO / security operations | SOC analysts and SaaS security engineers | Security and risk budget | Discover agents, NHIs, SaaS permissions, and policy violations | Existing AI agents in production SaaS apps | Who owns renewal and expansion budget? |
| Identity-first organization | IAM leader / identity security | Identity governance team | IAM or zero-trust budget | NHI inventory, entitlement review, privileged action monitoring | NHI count and audit pressure exceed manual review capacity | How much spend is incremental vs IAM replacement? |
| SaaS application estate owner | Business-app owner plus security partner | Salesforce, Workday, M365, ServiceNow administrators | Application, IT, or security shared budget | SaaS-to-SaaS integration and permission posture | Third-party app count and OAuth sprawl become unmanageable | Which apps drive initial deployment? |
| AI transformation program | AI platform owner with CISO approval | Agent builders and platform operations | AI transformation plus security budget | Agent build, tool approval, MCP server inventory, runtime controls | Copilot/Agentforce/n8n/Claude Code adoption | What false-positive tolerance is acceptable? |
| Developer-agent environment | Engineering security and DevSecOps | Developers using autonomous coding agents | Engineering productivity and security budget | Restrict production-data access and unsanctioned tools | Autonomous developer agents touch sensitive repositories | Does Obsidian sell directly into developer workflows? |
Buyer map is inferred from Obsidian product scope and customer disclosures; management should verify budget-owner distribution.
[CM002, CM003, CM004, CM024, CM025, CM026]The buying center shifts by entry point, but every segment ultimately crosses security, identity, SaaS ownership, and AI governance.
Matrix is an inferred buyer model from public product and customer evidence; management should verify pipeline mix.
[CM002, CM003, CM004, CM024, CM025, CM026]Adoption moves from inventory to runtime enforcement only after buyers trust coverage, policies, and workflow integrations.
Funnel values are illustrative adoption-stage indices, not conversion rates; labels are sourced from product evidence and customer disclosures.
[CM004, CM005, CM006, CM026, CM027, CM028]2.4 Growth Drivers, Constraints, and Sizing Gaps
The demand case is driven by enterprise agent adoption, the extreme 144-to-1 NHI ratio, SaaS application sprawl, and the need to block agent actions before data exposure occurs. The constraint case is equally important. First, the SSPM market-size evidence conflicts: Research and Markets reports a $3.69 billion 2026 SSPM market with 12.6% CAGR, while Frost starts from only $484.4 million in 2025 and reaches $3.53 billion by 2030 at 48.7% CAGR. That disagreement is an adverse market-sizing signal, not a rounding error. Second, direct competitor Zenity raised $125 million one day before Obsidian's Series D, implying category validation but also a capitalized rival fighting for the same enterprise agent-security budgets. Third, broad SPM at $26.35 billion can inflate the story if CSPM, DSPM, or generic posture products are counted as addressable without a SaaS-agent workflow. The diligence answer is to preserve the funnel, ask management for ARR and revenue mix, and test customer budgets by buyer persona instead of underwriting the headline TAM.[CM012, CM013, CM020, CM031, CM032, CM036]
| Driver / constraint | Direction | Timing | Implication | Diligence ask |
|---|---|---|---|---|
| 144:1 non-human-to-human identity ratio | Positive driver | Current | Expands identity-governance need faster than human headcount growth | Validate measured ratio across Obsidian customers, not just aggregate claim |
| 35,000+ third-party application surface | Positive driver | Current | Creates long-tail SaaS permissions and integration sprawl | Quantify average apps and integrations in won deals |
| 70%+ customers already permitting AI agents | Positive driver | Current 2026 | Moves category from future budget to active risk remediation | Ask what percentage bought agent-specific modules |
| Runtime blocking before agent actions take effect | Positive driver | Current | Supports ROI narrative versus alert-only tools | Review false-positive rates and blocked-action case studies |
| Fortune 500 and Global 2000 expansion | Positive driver | Near term | Raises ACV and enterprise credibility if sales cycles convert | Request pipeline by enterprise tier and vertical |
| Research and Markets vs Frost SSPM conflict | Negative constraint | Current | Undermines single-number TAM precision and valuation narratives | Normalize SSPM taxonomies before underwriting SAM |
| Well-funded Zenity competition | Negative constraint | Current 2026 | Could compress win rates, pricing, and narrative ownership | Request competitive win/loss data against Zenity |
| Native platform controls and status quo | Mixed constraint | Current / medium term | Can either validate need or commoditize parts of governance | Map which controls Obsidian performs better than native platforms |
Rows intentionally mix drivers and constraints so market growth is tied to adoption timing and diligence asks rather than headline TAM alone.
[CM004, CM005, CM006, CM027, CM028, CM029]2.5 Exhibits
03Competitors
3.1 Landscape Shape and Competitive Peer Set
The competitive landscape is no longer a simple SSPM shortlist. Obsidian now competes for the enterprise job of governing AI agents, non-human identities, and SaaS-to-SaaS activity inside third-party applications. That puts it against direct AI-agent governance vendors such as Zenity, SaaS and shadow-IT control vendors such as Grip, Nudge, and Push, SaaS-to-SaaS mesh specialists such as Valence, established SSPM platforms such as AppOmni, status quo controls from IdP/SaaS administrators, and internal governance builds. Zenity is the most important direct rival because it raised $125 million one day before Obsidian's Series D and publicly frames itself around securing AI agents across enterprise agent-building surfaces. Obsidian's counter-positioning is different: runtime governance that can detect and block risky actions before execution, paired with an NHI graph and enterprise SaaS context. The category therefore looks attractive but contested, with buyers likely to segment by where they want controls inserted: agent development, browser telemetry, shadow-SaaS discovery, SaaS mesh governance, or runtime enforcement.[CP001, CP002, CP003, CP006, CP007, CP011]
| Competitor | Focus/category | Funding or stage signal | Differentiator | Overlap with Obsidian | Source basis |
|---|---|---|---|---|---|
| Obsidian Security | Runtime SaaS security, AI-agent governance, and NHI control | $85M Series D on Aug 4, 2026; $1.1B valuation; more than $200M total raised | Blocks risky agent actions before execution; NHI graph; 60 Fortune 500 customers | Baseline company; overlaps every agent/SaaS governance category | SP001; SP002; SP005 |
| Zenity | Direct AI-agent security and agent-development governance | $125M Series C on Aug 3, 2026; total roughly $180M-$185M; 230+ staff | Strong build-time/agent-builder focus across Copilot Studio, Agentforce, and similar surfaces | Closest direct AI-agent governance rival, especially before runtime handoff | SP006; SP012; SP018; SP021 |
| Grip Security | SaaS and AI control, shadow SaaS/AI discovery, identity governance | About $41M Series B in 2023 per fact sheet context | Vendor claims deeper shadow-SaaS/AI discovery and remediation than Obsidian | Competes for discovery, remediation, and SaaS identity governance workflows | SP008; SP009; SP013 |
| Push Security | Browser-based identity, SaaS, and AI-era security | About $15M Series A in 2023 per fact sheet context | In-browser telemetry and controls near user sessions | Competes when buyer wants browser-layer prevention rather than SaaS control-plane breadth | SP010; SP014 |
| Nudge Security | SaaS and AI discovery with behavioral nudges | About $12.5M Series A in 2022 per fact sheet context | Fast discovery and employee-guided remediation model | Competes in shadow SaaS/AI inventory and lightweight governance | SP010; SP011; SP015 |
| Valence Security | SaaS-to-SaaS and AI security for the agentic era | About $25M Series A in 2023 per fact sheet context | Focus on connected SaaS mesh and non-human/agentic interactions | Overlaps strongly in SaaS-to-SaaS and NHI-risk workflows | SP011; SP016 |
| AppOmni | Established enterprise SSPM and SaaS security | About $70M Series C in 2023 and about $123M total per fact sheet context | Broad SSPM credibility and enterprise SaaS posture heritage | Competes where buyers frame the problem as SSPM rather than agent runtime control | SP007; SP017 |
Funding/stage values for non-Zenity peers come from the canonical fact sheet and public competitor/source surfaces; row source-basis cells provide at least two cited sources where available.
[CP001, CP002, CP003, CP004, CP005, CP007]Obsidian and Zenity occupy the high-value AI-agent governance zone, but with different control-plane emphases.
X-axis is runtime SaaS/NHI governance breadth; y-axis is AI-agent development/governance focus. Scores are ordinal from public positioning, not lab benchmarks.
[CP006, CP007, CP011, CP012, CP013, CP014]3.2 Zenity and Direct AI-Agent Governance Pressure
Zenity is the closest like-for-like threat, but the rivalry is not identical feature for feature. Public coverage describes Zenity as a fast-scaling AI-agent security company with 230-plus staff, New York headquarters, Tel Aviv R&D, founders Ben Kliger and Michael Bargury, and a $125 million Series C led by Norwest on August 3, 2026. That matters because the round was larger than Obsidian's $85 million Series D and arrived one day earlier, giving Zenity a strong narrative in the same news cycle. Its public pitch emphasizes securing AI agents everywhere and agent-development ecosystems such as Microsoft Copilot Studio and Salesforce Agentforce. Obsidian, by contrast, should not overclaim parity on Zenity's build-time/developer workflow. Its more honest differentiation is runtime SaaS governance: mapping non-human identities, watching the third-party application context, and blocking policy violations before an agent action takes effect. That runtime posture is valuable precisely because agent permissions, connected MCP servers, and model substitutions can change after design-time review.[CP004, CP005, CP007, CP008, CP009, CP010]
| Buying criterion | Obsidian | Zenity | Grip | Push | Nudge | Valence | AppOmni | Evidence caveat |
|---|---|---|---|---|---|---|---|---|
| Runtime policy enforcement before action | Strong public claim | Not the primary public emphasis | Remediation emphasis, runtime depth unclear | Browser-session controls rather than SaaS runtime | Nudges more than hard blocking | SaaS mesh control, runtime depth unclear | SSPM controls, AI-agent runtime unclear | No lab benchmark in public source set |
| Agent-builder governance | Covers Copilot Studio, Agentforce, n8n, developer agents, Claude Code, and Cowork per Obsidian sources | Strong; core positioning across enterprise agent builders | Mentions SaaS and AI control | Adjacent through browser identity layer | Adjacent discovery and behavioral controls | Agentic-era SaaS security positioning | Adjacent SSPM positioning | Platform coverage is vendor-claimed unless corroborated by news |
| NHI / SaaS-to-SaaS graph | Strong; 144:1 NHI ratio and SaaS graph are central to pitch | AI-agent graph implied, NHI depth not independently benchmarked | Identity governance is central | Less central; browser identity telemetry | SaaS inventory is central | Strong overlap via SaaS-to-SaaS mesh | Strong SaaS posture heritage | Depth requires product demo and API coverage review |
| Shadow SaaS / AI discovery | Present through SaaS estate visibility | Agent estate visibility emphasized | Strong adversarial claim from Grip | Strong browser-based discovery | Strong lightweight discovery | Present through connected SaaS visibility | Present in SSPM workflows | Vendor pages use different definitions |
| Enterprise trust and scale proof | Strong disclosed proof: 60 Fortune 500 and high-ACV customer counts | Strong capital/headcount signal; customer count less disclosed in sources | Moderate public proof in retained sources | Early-stage proof signal | Early-stage proof signal | Early-stage proof signal | Established SSPM vendor signal | Public customer/win-rate data are incomplete |
| Pricing transparency | Not consistently public in allowed source set | Not consistently public in allowed source set | Not consistently public in allowed source set | Not consistently public in allowed source set | Not consistently public in allowed source set | Not consistently public in allowed source set | Not consistently public in allowed source set | Treat pricing as a diligence gap, not a claim |
Matrix values are directional evidence-backed positioning summaries, not technical test results or price quotes.
[CP006, CP011, CP012, CP013, CP014, CP015]Obsidian's strongest wedge is runtime SaaS/NHI governance, while peers specialize in agent development, browser telemetry, discovery, SaaS mesh, or SSPM.
High/medium/low ratings reflect public product positioning and retained comparison pages; unsupported claims are treated as medium or low rather than inferred strong.
[CP006, CP011, CP012, CP013, CP014, CP015]3.3 Pricing, Packaging, Distribution, and Switching Friction
Public pricing is the weakest evidence surface in this chapter. The retained competitor sources show product packaging and positioning, but not standardized list prices, realized ASPs, discounting, renewal rates, or win/loss data. For underwriting, that means competitive pricing power has to be inferred from packaging breadth, procurement trust, and operational lock-in rather than observed quotes. Obsidian's public proof points are stronger than many younger peers: more than 100 customers spending at least $100,000 annually, more than 14 customers spending at least $1 million annually, and 60 Fortune 500 customers. Those disclosures suggest the product can reach enterprise ACVs and procurement trust. Still, switching friction is not absolute. Buyers can multi-home: deploy Obsidian for runtime SaaS governance, Zenity for agent-development review, Push for browser telemetry, Grip or Nudge for shadow SaaS, and AppOmni for conventional SSPM. The decisive question is whether Obsidian becomes the operating control plane for agents and NHIs rather than a point module around SaaS posture.[CP003, CP012, CP013, CP014, CP015, CP016]
| Pricing or packaging dimension | Obsidian read-through | Competitor read-through | Implication for buyer choice | Diligence ask |
|---|---|---|---|---|
| Public price availability | No standardized public list price retained in allowed source set | Competitor pages mostly expose positioning rather than comparable price cards | Procurement teams will rely on quotes, proof, and fit rather than public price tables | Collect live same-scope quotes from Obsidian, Zenity, Grip, Push, Nudge, Valence, and AppOmni |
| Enterprise packaging breadth | AI-agent runtime governance, NHI graph, SaaS integration security, ITDR, and breach clarity can support platform packaging | Zenity packages agent security; AppOmni packages SSPM; Push, Nudge, Grip, and Valence package narrower control points | Breadth can raise ACV, but point tools may win departmental or faster deployments | Request module attach rates and expansion cohorts by product area |
| Proof-based pricing power | 100+ customers above $100K, 14+ above $1M, and 60 Fortune 500 create premium evidence | Zenity's $125M round and 230+ staff create credibility even without disclosed valuation | The shortlist may become Obsidian versus Zenity for large agent programs | Verify renewal, NRR, and competitive displacement rates |
| Lowest-friction entry point | API/agentless SaaS onboarding and runtime control can appeal to central security teams | Push enters through browser extension; Nudge through discovery; Grip through shadow SaaS/AI; Valence through SaaS mesh | Competitors can land before Obsidian if the buyer pain is narrower than runtime governance | Map buyer workflow, initial trigger, and time-to-value in reference calls |
| Bundle/commoditization risk | Runtime enforcement is differentiated only if it reliably blocks policy violations across enough SaaS/agent surfaces | SSPM, browser, identity, and native platform controls can commoditize discovery and posture checks | Obsidian must prove runtime efficacy and coverage breadth, not just category labels | Run red-team scenarios across Copilot Studio, Agentforce, n8n, Claude Code, and MCP-enabled workflows |
Public price and discount data were not available in the allowed source block, so this table separates observed packaging from required commercial diligence.
[CP003, CP006, CP011, CP012, CP013, CP014]3.4 Moat Durability, Commoditization Risk, and Obsidian Differentiation
Obsidian's competitive defense has four pillars: runtime blocking, the non-human identity graph, disclosed enterprise traction, and breadth of agent-platform coverage. The strongest of these is runtime governance because it addresses the moment when an agent, integration, or MCP-connected workflow tries to act in SaaS. That is a clearer wedge than generic SSPM posture and more differentiated from Zenity's agent-build focus. The NHI graph also benefits from the 144:1 ratio Obsidian cites for non-human to human identities inside third-party applications. Enterprise proof matters too: 60 Fortune 500 customers and many high-ACV accounts can shorten buyer trust cycles. The risk is that this moat is still proving durability in a nascent market. Zenity has fresh capital and headcount, Grip attacks with an adverse comparison page, and incumbents or internal teams can commoditize pieces of discovery, posture, and policy. Obsidian should therefore be diligence-underwritten on runtime efficacy, integration breadth, customer expansion, and competitive-loss evidence, not on category momentum alone.[CP001, CP002, CP003, CP004, CP006, CP011]
| Moat or risk | Direction | Why it matters | Competitive pressure | Monitoring signal |
|---|---|---|---|---|
| Runtime blocking before action | Moat | Moves Obsidian beyond static posture into active governance of agent behavior | Zenity if it expands deeper into runtime; native platforms if controls become bundled | Block-rate efficacy, false positives, and coverage across critical SaaS actions |
| Non-human identity graph | Moat | The cited 144:1 NHI-to-human ratio creates a large graph problem that point tools may miss | Valence, Grip, AppOmni, and IdP-native controls | Number of mapped NHIs, SaaS-to-SaaS integrations, MCP servers, and risky permission paths per customer |
| Enterprise reference base | Moat | 60 Fortune 500 customers and high-ACV accounts support procurement trust | Zenity's capital/headcount, AppOmni's SSPM maturity, and incumbent platforms | F500 logo retention, expansion, and competitive win rates |
| Zenity capital and category narrative | Risk | A $125M Series C one day earlier can pull talent, mindshare, and budget into a direct rival | Zenity, its Norwest-led syndicate, and agent-builder ecosystem partners | Head-to-head loss rate, analyst mentions, and agent-platform partnership announcements |
| Shadow SaaS/browser discovery wedge | Risk | Push, Nudge, and Grip can land earlier if the buyer starts with discovery or browser-layer control | Push, Nudge, Grip, and lightweight internal controls | Source-of-lead analysis and module attach after initial SaaS discovery projects |
| SSPM commoditization | Risk | AppOmni and native SaaS controls can reduce willingness to pay for posture-only capabilities | AppOmni, Microsoft/native controls, IdP workflows, and internal build | Percent of ACV tied to runtime agent governance versus legacy SSPM modules |
Risk severity is qualitative because public sources do not disclose Obsidian win/loss rates, retention, NRR, or realized ASP by module.
[CP001, CP002, CP003, CP004, CP007, CP011]Obsidian's public durability signals are real, but most commercial-strength measures remain private.
KPI values intentionally mix customer counts, ratios, and funding because standardized competitor ARR, NRR, and win-rate data are not public.
[CP002, CP003, CP004, CP005, CP007, CP008]3.5 Exhibits
04Financials
4.1 Disclosure Baseline and Capital Capacity
Obsidian’s financial record is unusually strong on financing and customer-spend thresholds, but thin on operating statements. The company and several independent outlets converge on the same current anchor: an $85 million Series D announced August 4, 2026, a $1.1 billion valuation, Crescent Cove as lead, and participation by the existing syndicate. The same evidence says lifetime capital raised now exceeds $200 million across five rounds, while historical sources identify the Series C, Series B-1, and earliest Series A backers. That is enough to build a local financing chronology and a capital-adequacy view, but not enough to model cash. Cash on hand before the round, monthly burn, runway months, debt, and project-finance obligations are not publicly disclosed. The right interpretation is therefore capacity-with-unknown-consumption: the new round clearly extends strategic options, yet no public source can verify how many months it buys or which operating milestones would trigger another financing.[CI001, CI002, CI005, CI006, CI007, CI008]
| Round / event | Disclosed amount or valuation | Timing | At least two-source basis | Financial implication |
|---|---|---|---|---|
| Series A / earliest institutional round | Amount not publicly disclosed | Historical; first partnered at Series A | Greylock portfolio; Unite.AI Series D recap | Earliest institutional validation, but no amount for model inputs |
| Series B-1 | Amount not publicly disclosed | June 2021 | Norwest blog; Unite.AI five-round recap | Named prior financing, but sparse economics require diligence |
| Series C | $90M; total funding $119.5M at the time | April 2022 | Pulse 2.0 Series C; Unite.AI Series D recap | Major pre-pivot SSPM scale-up capital |
| Unspecified prior / reconciling round | Not separately disclosed publicly | Before Series D | Unite.AI five-round statement; Seedtable Series D datapoint | At least one round is not described enough for a full cap-table timeline |
| Series D | $85M; $1.1B valuation; total raised >$200M | August 4, 2026 | Obsidian official release; Yahoo Finance / Business Wire; Unite.AI | Fresh capital and unicorn mark, but no cash balance or runway disclosure |
Enumeration is partial because public sources state five rounds but do not disclose every round amount or term; each row cites at least two named source bases in the table and local claims.
[CI001, CI002, CI006, CI007, CI008]| Metric / obligation | Public value | Confidence | Why it matters | Diligence path |
|---|---|---|---|---|
| Cash on hand | null | Low | Determines true post-round runway | Request balance sheet immediately before and after Series D |
| Monthly burn | null | Low | Converts the $85M raise into runway months | Request monthly P&L and hiring plan by function |
| Runway months | null | Low | Shows timing of next financing dependency | Calculate from cash, burn, and committed spend |
| Gross margin | null | Low | Tests whether valuation deserves software multiples | Request gross margin by product, cloud cost, support, and services |
| NRR / retention | null | Low | Validates revenue quality and expansion economics | Request cohort retention and expansion by customer segment |
| CAC payback / sales efficiency | null | Low | Determines whether enterprise growth is capital efficient | Request bookings, CAC, payback, and sales-cycle data |
| Debt / credit facilities | No public evidence | Low | Hidden obligations can shorten runway | Request debt schedule and off-balance-sheet obligations |
| Use of funds | R&D plus Fortune 500 / Global 2000 expansion | Medium | Explains capital allocation, not runway | Tie budget to product milestones and bookings targets |
Null means no public source in the retained set discloses the metric; the table is intentionally a gap register, not a forecast.
[CI005, CI009, CI025, CI026, CI028, CI029]Obsidian looks software-heavy rather than capex-heavy, but private burn and margin data determine actual capital intensity.
Matrix entries are qualitative because the public source set lacks financial statements or balance-sheet detail.
[CI005, CI027, CI028, CI029, CI033, CI043]4.2 Revenue Signals and ARR Inference
Revenue and ARR are not publicly disclosed, so this chapter treats every revenue number as either a disclosed spend threshold or a clearly labeled estimate. The cleanest hard signal is customer spend: more than 100 customers over $100,000 annually and more than 14 over $1 million. Following the chapter instruction, the implied ARR floor is calculated as 100 times $100,000 plus 14 times $1 million, or approximately $24 million. That is not reported ARR, and it may not capture overlap or discounting perfectly; it is a floor derived from public statements. A plausible analyst estimate of $40 million to $70 million ARR is used only for sensitivity work, with $50 million as the base case. The commercial quality appears enterprise-skewed because the company cites 60 Fortune 500 customers and many seven-figure accounts, but the revenue mix, net retention, expansion rate, and customer concentration remain private.[CI003, CI004, CI009, CI010, CI011, CI022]
| Input / scenario | Public or estimated status | Calculation | ARR signal (USD M) | Diligence interpretation |
|---|---|---|---|---|
| 100+ customers over $100K | Company-claimed spend threshold | 100 x $0.1M | >=10 | Hard floor component from public statement |
| 14+ customers over $1M | Company-claimed spend threshold | 14 x $1.0M | >=14 | Seven-figure account component and concentration signal |
| Instructional implied floor | Estimated from disclosed spend | >=10 + >=14 | >=24 | Use only as floor, not reported ARR |
| Low estimate case | Analyst estimate | Management data unavailable | 40 | Plausible lower scenario above the spend floor |
| Base estimate case | Analyst estimate | Management data unavailable | 50 | Used for headline 22x sensitivity only |
| High estimate case | Analyst estimate | Management data unavailable | 70 | Needed to approach private-cyber benchmark multiples |
ARR values above the spend floor are analyst estimates; public sources do not disclose ARR, revenue, NRR, discounting, or overlap among spend cohorts.
[CI003, CI009, CI010, CI011, CI040]Obsidian converts enterprise SaaS and AI-agent risk into subscription revenue, but ARR and realized pricing remain private.
Flow nodes are evidence-backed mechanics; ARR and gross profit are not disclosed and therefore remain qualitative.
[CI019, CI020, CI021, CI022, CI023, CI042]Estimated ARR must be near the high end of the range for the $1.1B valuation to screen near private cyber benchmarks.
Ranges are analyst estimates derived from public customer-spend thresholds and valuation benchmarks; they are not disclosed ARR.
[CI010, CI011, CI017, CI018, CI044]4.3 Pricing, GTM, and Unit Economics
Public pricing evidence is directional rather than underwritable. Cyberse cites a free tier to 1,000 users and an AWS Marketplace reference price near $100 per user per year, while third-party profiles also point to free trials or custom enterprise pricing above the entry tier. This supports a headcount-based subscription model, but it is list-price evidence, not realized ACV, discounting, renewal, or margin evidence. The GTM motion appears enterprise-led: the company talks about Global 2000 expansion, seven-figure customers, and custom governance for complex SaaS estates rather than transactional self-serve revenue. Unit economics are therefore the core diligence gap. CAC payback, sales cycle, gross margin, cloud cost, support burden, implementation services, NRR, logo retention, and churn are all undisclosed. The most defensible model treats these cells as null, then asks management for cohort and margin cuts before assigning software-like economics.[CI019, CI020, CI021, CI025, CI026, CI027]
| Tier / price signal | Unit / contract model | Public value or status | List vs realized read | Diligence ask |
|---|---|---|---|---|
| Free tier | Users | Up to 1,000 users | Entry / trial, not paid ARR | Conversion, activation, and free-to-paid cohort data |
| AWS Marketplace reference | Per user per year | ~$100/user/year | Directional list-price signal | Actual realized ASP after discounts and bundles |
| Enterprise plan | Headcount / quote-based | Custom quote above free threshold | Likely negotiated ACV | Contract sizes, multi-year terms, and discount bands |
| Seven-figure accounts | Annual account spend | 14+ customers >$1M | Real enterprise spend signal | Revenue concentration and expansion paths |
| Six-figure accounts | Annual account spend | 100+ customers >$100K | Broad enterprise floor | Logo distribution and ACV by segment |
| Implementation / support | Services or bundled success | Not disclosed | Cannot separate recurring and services revenue | Services attach, support cost, and recognition policy |
Pricing is public-list and third-party reference evidence only; realized price, discounting, renewals, services, and revenue recognition remain private.
[CI003, CI019, CI020, CI021, CI039, CI040]The unit-economics bridge shows which public signals exist and where diligence must replace nulls.
All unavailable metrics are kept as null or qualitative nodes to avoid false precision.
[CI025, CI026, CI027, CI030, CI033, CI043]4.4 Valuation Sensitivity and Financial Verdict
The valuation risk is a function of the ARR denominator. At the approximately $24 million disclosed-spend floor, the $1.1 billion valuation implies roughly 46 times ARR. At the $50 million base estimate, it implies about 22 times. At the $70 million high estimate, it falls to roughly 16 times, near the private-cyber benchmark range cited by Finro and SaaS Mag. The adverse read is that Finro’s private median around 15.4 times ARR and down-round compression range of roughly 10 to 13 times imply Obsidian’s true ARR must be very high, or revenue quality must be unusually strong, to justify the mark. Competitive funding from Zenity reinforces the need to invest aggressively, while broader cyber funding data show a supportive but selective market. The verdict is track, not underwrite blindly: Obsidian has better public traction than most private companies, but retention, margin, burn, and concentration evidence must arrive before the valuation can be treated as fair. This sensitivity should be refreshed immediately if management provides ARR, NRR, cash, or cohort data.[CI012, CI013, CI014, CI015, CI016, CI017]
| ARR assumption (USD M) | Status | Implied revenue multiple | Benchmark comparison | Risk read |
|---|---|---|---|---|
| 24 | Disclosed-spend floor estimate | ~46x | Well above Finro private average / median frame | Stretched unless spend floor misses large undisclosed revenue |
| 40 | Analyst low estimate | ~28x | Above typical private cyber averages | Requires exceptional growth and retention |
| 50 | Analyst base estimate | ~22x | Around high-end cloud / AI security premium territory | Rich but potentially defensible if NRR and margins are strong |
| 70 | Analyst high estimate | ~16x | Near Finro / SaaS Mag private cyber benchmarks | Closest to benchmark support, but still needs proof |
| 71 | Benchmark-implied ARR | ~15.4x | Approximate ARR needed at Finro private 15.4x | Just above the plausible band high end |
| 85 | Compressed downside ARR need | ~13x | Upper end of adverse down-round compression range | Implies materially higher ARR than public floor |
| 110 | Compressed downside ARR need | ~10x | Lower end of adverse down-round compression range | Would require very large undisclosed ARR |
Multiples divide the $1.1B valuation by ARR assumptions; ARR assumptions other than disclosed spend thresholds are estimates, not company-reported metrics.
[CI012, CI013, CI014, CI015, CI016, CI017]4.5 Exhibits
05Product & Technology
5.1 Runtime Governance Product Map
Obsidian Security is best understood as an SSPM company that has rebuilt its product narrative around runtime governance for AI agents and non-human identities inside third-party SaaS. The customer job is not merely to find an excessive permission after a quarterly posture scan; it is to discover which agents, MCP servers, integrations, service accounts, and models can touch sensitive SaaS data, then stop an unsafe action before it happens. That is a technically sharper value proposition because it requires inventory, identity context, behavioral baselines, policy evaluation, and enforcement in the transaction path. The same foundation also explains why legacy Salesforce, Workday, and Microsoft 365 SSPM experience matters: those systems are where new Copilot Studio, Agentforce, Workday, n8n, Claude Code, Cowork, and SaaS-to-SaaS automation risks show up in production.[CE001, CE003, CE004, CE006, CE008, CE013]
| Module / asset | Primary user | Status / maturity | Differentiation | Diligence gap |
|---|---|---|---|---|
| AI agent runtime governance | Security, identity, and SaaS platform teams | Current strategic flagship | Pre-action blocking of privilege escalation, excessive access, and policy violations | Need independent runtime efficacy and false-positive data |
| MCP security inventory and model registry | AI governance, AppSec, platform engineering | New category module | Maps MCP servers to invoking agents and tracks underlying models | Need schema detail and substitution-detection evidence |
| AI agent identity management / NHI governance | IAM, security operations, SaaS owners | Current product surface | Connects probabilistic agents and over-permissioned NHIs to SaaS controls | Need NHI discovery precision and ownership workflow metrics |
| SaaS supply-chain security | SaaS security and third-party risk teams | Launched January 2026 | Targets SaaS-to-SaaS integrations and agentic connection paths | Need connector coverage and remediation automation proof |
| Breach clarity across SaaS | SOC, incident response, CISO office | Current forensic module | Aims to reduce mean time to innocence after SaaS identity incidents | Need before/after investigation-cycle benchmarks |
| SSPM / ITDR foundation | SaaS app owners, IAM, security posture teams | Established base product | Existing Salesforce, Workday, and Microsoft 365 posture roots give agent controls context | Need current split between legacy SSPM and agent-governance revenue |
Rows synthesize the public product surfaces; Obsidian does not publish a complete SKU catalog or module-level adoption mix.
[CE004, CE008, CE009, CE011, CE012, CE019]| Platform / surface | Risk governed | Evidence signal | Limit / diligence ask |
|---|---|---|---|
| Microsoft 365 / Copilot Studio | Agent access to enterprise documents and SaaS identity context | Series D and product coverage cite Microsoft/Copilot agent-governance scope | Verify exact APIs, tenant permissions, and supported Copilot Studio actions |
| Salesforce / Agentforce | Customer-data access, privilege escalation, and SaaS-to-SaaS connected-app abuse | Public coverage names Salesforce/Agentforce roots in agent-governance coverage | Confirm packaged controls for Agentforce versus generic Salesforce posture |
| Workday | HR and identity-sensitive SaaS workflow exposure | SSPM roots include Workday in the third-party SaaS control plane | Confirm current connector depth for Workday AI or automation flows |
| n8n | Workflow automation tool usage and unsanctioned MCP/tool calls | Product coverage includes n8n as an agent-building platform | Test policy enforcement against multi-step automation chains |
| Claude Code | Autonomous developer-agent access to sensitive files and production data | August 2026 announcement says governance is extending to Claude Code | Validate sensitive-file controls, production-data restrictions, and developer workflow friction |
| Cowork | Developer or autonomous-agent production-data access | August 2026 announcement names Cowork alongside Claude Code | Verify launch maturity, beta status, and customer deployment proof |
Coverage is public-source coverage, not a certified compatibility matrix; each row needs management confirmation of depth and launch status.
[CE013, CE014, CE017, CE018, CE039]Obsidian's public architecture reads as a SaaS identity and agent-governance stack layered over third-party applications and agent tools.
Synthesized from public product pages and funding coverage; Obsidian does not publish a single canonical architecture diagram.
[CE004, CE009, CE011, CE012, CE013, CE018]5.2 Architecture and Runtime Data Path
The architecture implied by public sources is a graph-backed control plane. API-based or agentless onboarding discovers SaaS applications, non-human identities, integrations, MCP servers, models, and agent relationships. A knowledge graph then correlates entitlements, data sensitivity, normal behavior, and tool invocation context. At runtime, an agent request is evaluated for privilege escalation, excessive data access, policy violations, model switching, and unsanctioned MCP or tool usage; the control decision can block before the action takes effect. That is materially different from a passive audit dashboard. The core diligence question is whether Obsidian can keep enough context in the decision loop without creating unacceptable latency, false positives, or connector fragility across many SaaS APIs and agent platforms.[CE005, CE009, CE010, CE011, CE012, CE018]
| Layer / process | Role | Dependency | Risk |
|---|---|---|---|
| API-based / agentless onboarding | Discovers SaaS apps, integrations, NHIs, agents, and MCP surfaces | SaaS APIs, permissions, and connector reliability | Coverage gaps or API changes can weaken visibility |
| Knowledge graph | Correlates users, NHIs, agents, apps, data sensitivity, and privileges | Identity data, app metadata, and behavior telemetry | Incorrect graph edges can create missed blocks or false positives |
| MCP inventory | Tracks connected MCP servers and maps them to invoking agents | MCP server discovery and agent telemetry | Protocol immaturity and unmanaged local servers can evade inventory |
| Model registry | Tracks underlying models behind agent workflows | Model identity and invocation metadata | Model switching/substitution detection needs reliable provenance |
| Runtime policy engine | Evaluates and blocks risky actions before execution | Low-latency policy decisions and enforcement hooks | Latency, false positives, and bypasses are key diligence tests |
| Forensics / breach clarity | Separates affected from unaffected SaaS activity after suspected abuse | Audit logs, graph history, and incident timelines | MTTI benefits are unquantified publicly |
Architecture is reconstructed from product pages and coverage; no single canonical public system diagram or benchmark exists.
[CE005, CE009, CE010, CE011, CE012, CE018]The key product claim is a pre-action loop from discovery and graph context into runtime policy decision and post-event clarity.
Flow describes the most supportable public control loop; actual latency and implementation details are not disclosed.
[CE005, CE009, CE010, CE011, CE012, CE018]The runtime-governance thesis depends on third-party SaaS APIs, agent platforms, standards, and quality of graph context.
DAG is limited to externally visible dependencies; internal infrastructure and data vendors are not public.
[CE013, CE014, CE018, CE023, CE025, CE029]5.3 Standards, Trust, and Risk Controls
The strongest external validation for the product thesis comes from standards bodies rather than independent product benchmarks. OWASP and CSA describe an MCP threat model dominated by prompt injection, tool poisoning, least-privilege failures, OAuth and authorization mistakes, and unsafe server or tool design. Obsidian's public claims map well to that control language because inventory, model registry, and pre-action policy enforcement are exactly the primitives that a runtime guardrail needs. The adverse read is equally important: PipeLab's 2026 MCP-security assessment describes thousands of MCP CVEs, which means Obsidian is building into an immature and volatile protocol ecosystem. The opportunity is large, but so is the product-efficacy burden; security buyers will need proof that controls work against advanced agent attacks, not only marketing claims about governance coverage.[CE023, CE024, CE025, CE026, CE027, CE028]
| Control / standard | Relevant requirement | Obsidian-facing status | Gap |
|---|---|---|---|
| OWASP MCP Security Cheat Sheet | Address prompt injection, tool poisoning, authorization, and least privilege | Strong conceptual fit with inventory and pre-action runtime governance | Need proof of attack-specific detection and blocking outcomes |
| OWASP secure MCP server guide | Secure server design, inputs, tool definitions, and trust boundaries | Useful benchmark for assessing Obsidian-managed or monitored MCP servers | Need clarity on whether Obsidian validates server implementation quality |
| CSA agentic MCP best practices | Identity-aware governance, constrained tool access, and secure agent-tool flows | Maps to NHI governance, MCP inventory, and policy enforcement | Need customer policy templates and exception-management evidence |
| OAuth 2.1 / least privilege | Tight scopes and revocation for agentic SaaS access | Core to Salesforce, Microsoft 365, Workday, and SaaS integration governance | Need supported OAuth-app controls by SaaS platform |
| SOC 2 / GDPR posture | Enterprise assurance and privacy/control evidence | FACTS.md and company surfaces indicate SOC 2/GDPR posture | Need current report, scope, subprocessor list, and audit exceptions |
Standards rows are alignment checks, not certifications that Obsidian has been formally assessed against these frameworks.
[CE023, CE024, CE025, CE026, CE038, CE037]Maturity is strongest where SSPM/NHI context transfers into agent governance, and weakest where public benchmarks are absent.
Qualitative diligence scoring from public evidence; no independent product benchmark normalizes these capabilities.
[CE008, CE019, CE023, CE027, CE037, CE038]5.4 Roadmap, Maturity, and Diligence Gaps
Product maturity looks credible but incomplete from public evidence. The January 2026 SaaS supply-chain security launch shows Obsidian extending from posture into integration risk. The August 2026 Series D announcement then tied fresh capital to R&D, Fortune 500 expansion, and native governance for Claude Code and Cowork. Those milestones are consistent with the market shift toward agentic SaaS workflows. However, the source set does not expose enough hard engineering evidence: there is no public block-rate benchmark, false-positive rate, model-registry schema, uptime history, connector coverage list by application, or detailed support SLA. Developer-signal is also weak; a vendor wiki is only a proxy, not a substitute for an open SDK, public changelog, or active community. Diligence should therefore test runtime efficacy, SaaS-connector reliability, and policy-governance operations before treating the architecture as fully proven. A final product diligence track should therefore test the control plane in adversarial, production-like scenarios: sanctioned versus unsanctioned MCP servers, a model substitution attempt, an agent requesting sensitive HR or sales records, a service account with stale OAuth scope, and a developer agent touching production data. Those tests would convert the public architecture from a plausible graph-and-policy thesis into measurable security evidence and would also reveal whether Obsidian's SSPM heritage creates enough context to avoid noisy runtime blocks. The remaining diligence should be evidence-led, not roadmap-led. Management should also show policy-change audit trails, exception approval records, and customer support escalations for blocked agent actions.[CE019, CE020, CE029, CE030, CE031, CE032]
| Date / stage | Feature or milestone | Status | Implication | Source |
|---|---|---|---|---|
| Pre-2026 base | SSPM and ITDR across third-party SaaS such as Salesforce, Workday, and Microsoft 365 | Established foundation | Provides the graph and SaaS-identity context for agent governance | Unite.AI + Norwest |
| 2026-01-22 | End-to-end SaaS supply-chain security for SaaS-to-SaaS integrations | Launched | Expands from posture to integration and agentic connection risk | Help Net Security + SiliconANGLE |
| 2026 current | MCP inventory and model registry | Current product surface | Turns unmanaged MCP servers and model substitution into governance objects | Obsidian MCP page + FinTech Global |
| 2026-08-04 | Series D ties $85M funding to R&D and Fortune 500 / Global 2000 expansion | Funded roadmap | Improves capacity to deepen platform coverage | Obsidian announcement + Unite.AI |
| 2026-08-04 | Native governance extension to Claude Code and Cowork | Announced expansion | Moves the control plane into autonomous developer-agent workflows | Obsidian announcement |
Roadmap evidence is announcement-driven; a detailed multi-quarter product roadmap and GA/beta split are not public.
[CE017, CE019, CE029, CE039, CE014]5.5 Exhibits
06Customers
6.1 Enterprise Traction and Segmentation
Obsidian’s customer proof starts with scale disclosures that are unusually concrete for a private cybersecurity vendor. The company-reported 2026 Series D corpus says it has 100+ customers spending more than $100,000 per year, 14+ customers spending more than $1,000,000 per year, and 60 Fortune 500 customers across major financial institutions, social media networks, and telecom providers. Those facts support real enterprise adoption, not just pilots, because the disclosed spend thresholds imply production-budget ownership and at least some multi-stakeholder procurement. The segmentation still needs care: finance has the strongest external proof because an anonymous Fortune 500 bank director appears in a customer-reference corpus; telecom has a named logo in T-Mobile through CB Insights; social media is disclosed only as a category; Snowflake supplies a high-quality data-platform case. Obsidian’s product positioning around AI agents, non-human identities, and third-party SaaS applications explains why security, identity, and SaaS owners are likely buyers, users, and payers, but the public record does not yet map every disclosed segment to contract size, renewal status, or production scope.[CU001, CU002, CU003, CU017, CU018, CU019]
| Segment | Buyer / user / payer | Use case | Scale signal | Revenue / strategic value | Gap |
|---|---|---|---|---|---|
| Fortune 500 enterprises | CISO, identity, SaaS security, procurement | Runtime governance for AI agents and non-human identities in third-party SaaS apps | 60 Fortune 500 customers | High strategic value; supports Global 2000 expansion plan | Named logos and production scope largely undisclosed |
| Financial institutions / banks | Security, risk, compliance, identity leaders | SaaS posture, breach clarity, AI-agent controls, application discovery | Major financial institutions plus F500 bank director testimonial | Likely high willingness to pay because SaaS risk and regulatory scrutiny converge | Bank reference is anonymous; no ARR or renewal disclosed |
| Social media networks | Platform security and SaaS owners | Control third-party app access, agent permissions, and data exposure | Vertical named in Series D customer disclosure | Strategic proof of internet-scale SaaS environments | No named social-media logo in retained sources |
| Telecom providers | CISO, identity, SaaS app security teams | Secure distributed third-party SaaS estates and non-human identities | Telecom vertical named; T-Mobile listed by CB Insights | Large enterprise complexity and possible seven-figure spend | T-Mobile use case and contract depth undisclosed |
| Data platforms / SaaS ecosystems | Security engineering and cloud/SaaS platform teams | Integration-risk governance and engineering-hours reduction | Snowflake case: 3,000 integrations and 800+ hours saved monthly | Strong reference quality and concrete ROI proxy | No contract size, renewal, or expansion history disclosed |
| Marketplaces and digital commerce | Security, IT, app owners | SaaS discovery, posture, identity and agent controls across broad app estates | Upwork, Trade Me, BigCommerce listed by CB Insights | Shows adoption beyond regulated security buyers | Logo-list evidence without deployment detail |
Segmentation combines company-reported verticals, customer-reference surfaces, and named-logo lists; rows are not a management CRM export.
[CU001, CU002, CU017, CU018, CU024, CU031]| Metric | Value | Date | Source | Confidence | Implication | Missing denominator |
|---|---|---|---|---|---|---|
| Large-account customers | 100+ customers spending >$100,000 per year | 2026-08-04 | Series D coverage and company announcement | High | Production-budget adoption across a meaningful enterprise base | Total active customers and historical cohort not disclosed |
| Seven-figure customers | 14+ customers spending >$1,000,000 per year | 2026-08-04 | Series D coverage and company announcement | High | Expansion into large accounts is real | Revenue concentration and renewal timing undisclosed |
| Fortune 500 reach | 60 of the Fortune 500 are customers | 2026-08-04 | Series D coverage and company announcement | High | Enterprise validation across large organizations | Specific Fortune 500 logos mostly undisclosed |
| AI-agent exposure in base | 70%+ of customers already allow AI agents into third-party apps | 2026-08-04 | CEO quote in Series D coverage | High | Current customers have an active agent-governance problem | No split by production agent use versus pilots |
| Snowflake integration scale | 3,000 integrations | 2026 | Snowflake customer story | Medium | Deployment context is large enough to be production-relevant | No pre/post incident or risk baseline |
| Snowflake efficiency KPI | 800+ engineering hours saved per month | 2026 | Snowflake customer story | Medium | Quantified operating-value proof | No contract value or payback period disclosed |
| Forrester TEI ROI | Up to 192% ROI for $9B revenue / 10k employee composite | 2026 | Forrester TEI | Medium | Enterprise value proposition has modeled ROI support | Composite model is not a disclosed live customer cohort |
| Review-platform satisfaction | ~4.9/5 from ~22 Gartner reviews | 2026 | Gartner Peer Insights | Medium | Positive satisfaction signal among reviewers | Small sample and no renewal link |
Values use canonical FACTS.md metrics and source-manifest descriptions; percentages and customer counts are company-reported unless explicitly third-party modeled.
[CU001, CU003, CU005, CU006, CU012, CU014]The quantified public funnel narrows from broad enterprise customers to Fortune 500 accounts, seven-figure customers, and named high-quality references.
The 100+ and 14+ thresholds are shown at their minimum disclosed values; the named/reference count reflects this chapter’s retained public corpus, not total customers.
[CU001, CU004, CU009, CU010, CU024, CU027]6.2 Named Customer Proof and Value Outcomes
The best named proof is Snowflake because it combines a recognizable enterprise, named senior security stakeholders, a concrete deployment context, and measurable operational impact. Obsidian says Snowflake uses the platform across 3,000 integrations and saves more than 800 engineering hours per month; Security MEA separately covered the integration, making the story stronger than a single vendor page. CB Insights adds T-Mobile, Upwork, Trade Me, and BigCommerce to the public logo set, while FeaturedCustomers adds an unnamed Fortune 500 bank director and a CSO describing discovery of hundreds of SaaS apps in days. These references widen the customer map across telecom, marketplaces, commerce, banking, and large SaaS estates. The limitation is that most logos outside Snowflake are not tied to published deployment depth, outcome metrics, retention, or contract economics. For diligence, that means the customer list should be treated as adoption proof and pipeline evidence, not as proof of durability or account-level expansion until management provides reference calls, renewal history, and top-account economics.[CU004, CU005, CU006, CU007, CU008, CU009]
| Customer / reference | Segment | Deployment / use case | Production vs pilot | Outcome / proof quality | Limitation |
|---|---|---|---|---|---|
| Snowflake | Data cloud / enterprise SaaS ecosystem | Obsidian integration governance across 3,000 integrations | Production customer story | 800+ engineering hours saved monthly; named CISO and VP Security quotes | No contract size, renewal, or cohort history disclosed |
| T-Mobile | Telecom / Fortune-scale enterprise | Listed by CB Insights as an Obsidian customer | Known logo; deployment status undisclosed | Supports telecom vertical claim when combined with Series D vertical disclosure | No use case, buyer, outcome, or ARR band public |
| Upwork | Workforce marketplace / SaaS estate | Listed by CB Insights as an Obsidian customer | Known logo; deployment status undisclosed | Shows adoption in marketplace-style enterprise outside classic banking | No production evidence beyond customer list |
| Trade Me | Marketplace / digital commerce | Listed by CB Insights as an Obsidian customer | Known logo; deployment status undisclosed | Adds geographic and marketplace diversity to named-logo proof | No public case study or quantified outcome |
| BigCommerce | Commerce SaaS / digital commerce | Listed by CB Insights as an Obsidian customer | Known logo; deployment status undisclosed | Indicates relevance to commerce-platform SaaS environments | No module, renewal, or expansion detail |
| Fortune 500 bank director | Financial institution | FeaturedCustomers testimonial from bank director | Customer reference, anonymous production scope | Corroborates financial-institution segment and CISO-level relevance | Logo withheld; cannot verify economics or deployment breadth |
| Unnamed CSO reference | Large SaaS application estate | Discovery of hundreds of SaaS applications in days | Customer reference, anonymous production scope | Outcome aligns with SaaS discovery and posture-management workflows | Reference is selected and anonymous |
Enumeration is a partial public-logo/reference list from CH6 sources; it excludes undisclosed members of the 60 Fortune 500 and any private customer roster.
[CU004, CU005, CU006, CU007, CU008, CU009]Obsidian’s customer path moves from SaaS/AI-agent risk discovery into production governance, quantified outcomes, and possible multi-module expansion.
Journey synthesized from customer stories, product surfaces, and Series D traction disclosures rather than a disclosed conversion funnel.
[CU003, CU004, CU006, CU011, CU019, CU020]Customer proof is strongest where a named account is paired with quantified outcomes and weakest where the evidence is logo-only or anonymous.
Matrix entries are qualitative evidence-quality judgments based only on public source specificity.
[CU004, CU008, CU009, CU010, CU011, CU027]6.3 Satisfaction, ROI, and Durability Signals
The satisfaction and value evidence is positive, but it is not the same as retention evidence. Gartner Peer Insights shows roughly 4.9 out of 5 from about 22 reviews, and PeerSpot supplies another enterprise review surface. Forrester’s TEI calculator reports up to 192% ROI for a composite organization with $9 billion in revenue and 10,000 employees. Those signals matter because they triangulate buyer-perceived value outside Obsidian’s own customer pages, and the Forrester model is directionally consistent with Snowflake’s engineering-hours savings. The caveat is that none of these sources discloses Obsidian’s NRR, GRR, churn, renewal rate, contract length, or true customer cohort behavior. The planned retention cohort therefore has to be displayed as a disclosure map rather than an actual retention curve: public sources can identify a current spend cohort and a current named deployment, but they do not reveal whether the same accounts renew after six or twelve months. This is the central unresolved customer-quality gap.[CU012, CU013, CU014, CU023, CU030, CU036]
| Metric | Value / null | Segment | Confidence | Diligence ask |
|---|---|---|---|---|
| Public NRR | null | All customer cohorts | Low | Request NRR by initial module, ARR band, and Fortune 500 status |
| Public GRR / churn | null | All customer cohorts | Low | Request logo retention, dollar retention, churn reasons, and renewal calendar |
| Contract length / renewal rate | null | >$100K and >$1M customers | Low | Request contract terms and renewal outcomes for large accounts |
| Gartner Peer Insights rating | ~4.9/5 from ~22 reviews | Reviewer sample | Medium | Request review distribution, recency, and verified-customer segmentation |
| PeerSpot review surface | Enterprise review presence | Enterprise security buyers | Medium | Compare sentiment themes with Gartner and reference calls |
| Forrester TEI ROI | Up to 192% ROI for composite $9B revenue / 10k employees | Large-enterprise composite | Medium | Request model assumptions and actual customer payback examples |
| Snowflake operating KPI | 800+ engineering hours saved per month | Named enterprise customer | Medium | Validate baseline, measured period, and renewal/expansion outcome |
| Adverse fit: cloud posture | No IaaS/PaaS posture per Work-Management.org | Buyers wanting broad cloud posture | Medium | Probe whether customers need separate CSPM/CWPP tooling |
| Adverse fit: dashboards | Dashboard flexibility limitations per Work-Management.org | Security operations and executive reporting | Medium | Probe whether customization limits renewal or executive reporting adoption |
Nulls are deliberate: no retained public source discloses retention cohorts, NRR, GRR, churn, contract length, or renewal rates.
[CU012, CU013, CU014, CU015, CU016, CU023]No actual retention cohort is public, so the disclosed cohort map shows 0% public renewal visibility after initial proof for each customer group.
Cells are public retention-visibility percentages, not Obsidian’s actual customer retention; actual NRR/GRR/churn cohorts are not disclosed.
[CU001, CU004, CU009, CU023, CU024, CU025]6.4 Expansion, Concentration, and Fit Risks
Obsidian’s expansion story is credible because the 2026 financing narrative explicitly says the company will fund R&D and extend deeper into the Fortune 500 and Global 2000, while product surfaces such as MCP security, breach clarity, SaaS supply-chain security, and AI-agent identity management create multiple cross-sell paths. The same evidence also creates underwriting risk. Fourteen-plus $1M customers indicate real account expansion, but they also raise concentration questions if those accounts dominate revenue. The 60 Fortune 500 claim proves enterprise reach, yet specific named Fortune 500 logos are mostly undisclosed, so investors cannot independently assess renewal quality, deployment breadth, or reference diversity. Adverse review evidence from Work-Management.org adds a customer-fit boundary: buyers looking for one platform across SaaS, IaaS, and PaaS posture may view Obsidian as incomplete, and dashboard flexibility limitations may matter to teams with customized reporting needs. The bottom line is strong adoption proof with material disclosure gaps, not a clean retention-underwriting package.[CU015, CU016, CU020, CU021, CU022, CU025]
| Expansion driver | Concentration risk | Impact | Diligence path |
|---|---|---|---|
| Move 100+ $100K customers toward seven-figure scope | 14+ $1M customers may dominate revenue | Positive expansion proof can also hide top-account concentration | Request top-10 revenue share and account-level ARR bands |
| Deeper Fortune 500 / Global 2000 penetration after Series D | Specific F500 logos mostly undisclosed | Enterprise reach is real but hard to independently underwrite | Request logo-permission list or anonymized customer schedule by vertical |
| Snowflake quantified outcome as reference selling | One excellent case may overrepresent median value | Strong sales proof, but not proof every account saves hundreds of hours | Request median ROI and reference-call notes across non-Snowflake accounts |
| AI-agent runtime governance cross-sell to existing SaaS base | Category may still be budgeted as emerging control layer | Potential upsell, but adoption velocity depends on customer agent maturity | Request pipeline conversion for customers already allowing AI agents |
| Breach clarity, MCP security, SaaS supply-chain add-ons | Module sprawl could obscure attach rates | Expansion story plausible but unquantified | Request product attach rates by cohort and net expansion bridge |
| Finance, social, telecom vertical breadth | Vertical proof may cluster in a few marquee accounts | A broad-sounding vertical list can mask concentration | Request ARR split by vertical and largest account exposure |
| SaaS-specific depth versus cloud-suite breadth | No IaaS/PaaS posture coverage may constrain platform consolidation wins | Could limit share of wallet in cloud-security-standardization projects | Test against customers that also run Wiz, CSPM, CNAPP, or EASM tools |
| Executive reporting and dashboard adoption | Dashboard flexibility limits may affect renewal among reporting-heavy buyers | Can slow operational rollout even after technical win | Ask references about dashboard customization and board-reporting workflows |
Risks are commercial transmission paths from public customer evidence; they are not claims that any named customer has churned.
[CU015, CU016, CU020, CU021, CU025, CU026]6.5 Exhibits
07Risks
7.1 Competition, Platform Risk, and Market Timing
Obsidian is raising into a market that looks urgent but not yet settled. The strongest competitive warning is Zenity: it raised $125 million on 2026-08-03, one day before Obsidian announced its $85 million Series D, and it is explicitly positioned around securing autonomous AI agents. The broader field is also crowded, with Grip, Push, Nudge, Valence, AppOmni, and identity/security-platform incumbents competing for overlapping SSPM, SaaS discovery, browser identity, and agent-governance budgets. That crowding matters because Obsidian’s pivot is not a clean greenfield move from SSPM into a monopoly category; it is a bet that runtime AI-agent governance becomes a budget line large enough to support a unicorn valuation. Microsoft’s native agent-security work is the sharper platform risk. If Copilot, Defender, Salesforce, Google, or SaaS platforms embed enough governance controls directly into enterprise suites, Obsidian could remain technically useful but lose pricing power and strategic urgency. Market timing is the linked risk: 70%+ customer agent exposure and a 144:1 NHI ratio support the problem statement, but public sources do not yet prove renewal durability, standalone AI-governance willingness to pay, or how quickly budgets shift from SSPM to agent runtime controls. A further diligence concern is buyer education: security teams may agree that agents are risky while still postponing a new platform purchase until internal pilots create a breach, audit finding, or board-level mandate.[CR001, CR002, CR003, CR010, CR015, CR020]
| Dependency / pressure | Counterparty | Role | Concentration | Failure scenario | Severity | Mitigation | Residual exposure |
|---|---|---|---|---|---|---|---|
| Native agent-security controls | Microsoft | Copilot/Defender platform owner and security incumbent | High strategic dependency | Controls bundled into suites reduce third-party budget | High | Cross-SaaS independence and deeper runtime governance | Margin and relevance compression |
| Direct AI-agent-security competitor | Zenity | Well-funded competitor in autonomous-agent security | High in category narrative | Zenity wins enterprise mindshare after $125M raise | High | Differentiate on SaaS graph, NHI telemetry, and Fortune 500 proof | Sales-cycle pressure and valuation-comparison risk |
| SSPM and SaaS-governance crowding | Grip / Push / Nudge / Valence / AppOmni | Adjacent vendors competing for SaaS and AI governance budgets | Medium-High | Buyers consolidate around simpler discovery/remediation tools | Medium-High | Sell runtime blocking plus NHI depth | Feature commoditization and pricing pressure |
| Customer SaaS environments | Salesforce / Snowflake / AWS and third-party apps | Primary data and workflow surfaces to protect | High | Breach or API changes constrain monitoring and response | High | Agentless API onboarding and breach-clarity workflows | Platform permissions and customer configuration remain outside full control |
| AI-agent frameworks and MCP servers | Microsoft Semantic Kernel / MCP ecosystem | Execution layer where prompts, tools, and models interact | Medium-High | Framework CVE or tool poisoning creates exploit path | High | MCP inventory, model registry, least privilege | Coverage gaps and fast-moving open ecosystem |
| Capital-market comparables | Cyber SaaS investors and M&A buyers | Set valuation, down-round, and exit benchmarks | Medium | Cyber multiples compress or revenue proof disappoints | High | Raise with strong syndicate and disclose durable KPIs | Down-round or flat-round exposure at $1.1B |
This table merges partner dependency and competitive-pressure risks because platform owners and funded competitors are the main external constraints on Obsidian’s risk-adjusted upside.
[CR002, CR010, CR011, CR014, CR020, CR022]Obsidian’s residual risk depends on platforms, agent frameworks, competitors, capital providers, and enterprise buyers as much as on internal product execution.
Map includes only externally visible dependencies and named competitor groups from cited sources.
[CR002, CR010, CR011, CR020, CR025, CR033]7.2 Technical, Legal, and Threat-Landscape Risk
The same threat environment that validates Obsidian also raises the risk that the product under-delivers in high-stakes settings. Prompt injection is repeatedly framed by 2026 adverse sources as the leading enterprise AI-agent risk, and Microsoft’s RCE research shows how agent-framework behavior can turn prompt manipulation into shell-level consequences. The Salesloft/Drift OAuth incident is particularly relevant because it shows how an AI-chat-agent or OAuth/NHI compromise can cascade through Salesforce, AWS, and Snowflake surfaces—the exact kind of SaaS environment where Obsidian says it can govern identities and actions. MCP vulnerability coverage and OWASP MCP guidance add another layer: inventory, least privilege, model registry, and runtime blocking are necessary, but they are becoming expected baseline controls. Legal and regulatory exposure is therefore indirect but material. Public sources do not show a current Obsidian lawsuit or enforcement action, yet enterprise buyers will treat false negatives, over-permissioned agents, and SaaS data exposure as contractual, privacy, and incident-response risks. The burden is to prove that Obsidian blocks advanced attacks before actions execute, not merely that it monitors a scary category. The risk is asymmetrical because one missed exploit in a flagship customer can weaken trust faster than many quiet blocks can build it, especially when incident narratives spread through security communities.[CR004, CR005, CR006, CR007, CR008, CR009]
| Rule / case | Jurisdiction | Status | Likelihood | Severity | Mitigation | Residual exposure | Diligence path |
|---|---|---|---|---|---|---|---|
| OAuth/NHI breach privacy and contractual exposure | US / global SaaS customers | Threat evidenced by Salesloft/Drift; no public Obsidian proceeding | Medium | High | Runtime governance, NHI visibility, breach-clarity positioning | False negatives could become customer-notification, privacy, or contract disputes | Request DPA terms, incident playbooks, and customer-notification history |
| Prompt-injection-to-RCE liability | Global enterprise agent frameworks | Microsoft 2026 RCE research validates class | Medium | High | Pre-action blocking, OWASP-aligned controls, MCP inventory | Customers may treat agent framework compromise as vendor control failure | Review red-team results against RCE/prompt-injection chains |
| MCP/CVE vulnerability governance | Enterprise AI-agent stacks | CVE-2026-2256 and OWASP MCP guidance show active risk | Medium-High | High | Inventory every MCP server and map models/agents | Baseline standards may rise faster than Obsidian proves differentiation | Request MCP vulnerability-management SLAs and exception reporting |
| Company-specific litigation or enforcement | US / global | No public source cited identifies an Obsidian action | Low today | Medium | Legal diligence and standard enterprise contracts | Unknown private disputes or customer claims remain possible | Run legal docket search and request management legal-dispute schedule |
| Native-platform security-control displacement | Microsoft / Salesforce / Google ecosystems | Microsoft native controls already shipping guidance | High | High | Differentiate on cross-SaaS runtime visibility and third-party independence | Embedded controls can pressure margin and contract scope | Compare feature-by-feature against Microsoft/Salesforce/Google roadmaps |
Rows are ordered by residual severity; legal and regulatory exposure is mostly indirect because public sources show threat patterns rather than an Obsidian enforcement matter.
[CR004, CR005, CR006, CR010, CR018, CR022]| Failure mode | Likelihood | Severity | Mitigation maturity | Residual exposure | Unresolved gap |
|---|---|---|---|---|---|
| Prompt injection bypasses runtime policy | High | High | Partial — product claims blocking but public false-negative data absent | High | Need independent red-team results and production block-rate metrics |
| RCE in agent frameworks defeats governance assumptions | Medium | High | Partial — Obsidian maps MCP/agents but framework security varies | High | Need framework coverage matrix and exploit-chain testing |
| OAuth/NHI credential compromise cascades across SaaS apps | Medium-High | High | Improving — NHI and SaaS integration security is core positioning | High | Need token revocation, blast-radius, and customer incident evidence |
| MCP server / tool poisoning vulnerability | Medium-High | Medium-High | Partial — MCP inventory and OWASP controls cited | Medium-High | Need inventory accuracy, owner mapping, and policy-exception evidence |
| Breach-clarity or forensics response disappoints during customer incident | Medium | Medium-High | Partial — breach-clarity product exists | Medium | Need post-incident references and time-to-identify proof |
| Threat marketing outruns actual product scope | Medium | High | Unknown — public claims are broad but test data private | High | Need proof that runtime blocks occur before high-risk actions execute |
Threat rows combine adverse 2026 incident evidence with Obsidian’s stated mitigation surface; severity is qualitative, not an internal incident probability.
[CR006, CR007, CR008, CR009, CR019, CR026]Highest residual severity clusters where likelihood and impact both remain high: platform commoditization, prompt-injection/RCE efficacy, and valuation opacity.
Qualitative matrix based on cited public sources; no internal loss data or probability model was available.
[CR006, CR008, CR014, CR018, CR023, CR041]7.3 Valuation, Financial, People, and Execution Risk
Valuation risk is high because the $1.1 billion post-money price is attached to undisclosed ARR, gross margin, NRR, burn, runway, and headcount. The disclosed spend metrics are meaningful—100+ customers above $100,000 annually, 14+ above $1 million, and 60 Fortune 500 customers—but they only establish a floor. Using the canonical fact-sheet method, ARR is at least about $24 million and plausibly $40 million to $70 million, which puts the valuation in a wide estimated 15x to 45x revenue band. That band can be acceptable for a category leader with durable expansion, but public sources do not prove renewal quality or revenue concentration. Execution risk is therefore central. Obsidian has strong founder and technical credentials and a non-founder CEO with Shape Security go-to-market experience, yet it must manage a category pivot, enterprise platform partnerships, advanced threat research, and intense competition simultaneously. The right investment posture is not to dismiss the company; it is to make price, disclosure, and proof-of-blocking gates explicit. If private diligence cannot connect product-specific expansion to the latest disclosed customer thresholds, investors should treat the Series D as strategic validation rather than full proof of durable economics.[CR012, CR013, CR014, CR016, CR017, CR021]
| Role / function | Dependency or gap | Likelihood | Severity | Mitigation | Diligence path |
|---|---|---|---|---|---|
| CEO / go-to-market leadership | Hasan Imam must convert AI-agent risk urgency into durable Global 2000 contracts | Medium | High | Prior Shape Security go-to-market background | Review pipeline conversion, ASP, win/loss, and sales-cycle by segment |
| Founder technical leadership | Chisholm, Johnson, and Wolff remain central to product credibility | Medium | Medium-High | Deep Cylance, Carbon Black, and data-science backgrounds | Assess succession depth and product decision rights |
| Threat-research and red-team function | Must keep pace with prompt injection, RCE, MCP, and OAuth/NHI attacks | High | High | Security research and product expansion toward runtime controls | Request red-team cadence, false-negative trend, and exploit coverage |
| Platform partnership and integration teams | Need broad third-party SaaS coverage despite platform API and permission differences | Medium-High | High | Agentless onboarding and SaaS integration security positioning | Inspect coverage by app, API limits, and exception backlog |
| Finance and investor-relations discipline | Must substantiate $1.1B valuation despite undisclosed ARR and headcount | Medium | High | High-quality syndicate and $85M new capital | Request audited ARR bridge, retention cohorts, burn, runway, and headcount plan |
Execution risks are ordered by their ability to affect valuation or renewal quality within the next financing cycle.
[CR012, CR014, CR017, CR021, CR038, CR039]| Risk | Monitorable trigger | Threshold / event | Action implication |
|---|---|---|---|
| Native-platform commoditization | Microsoft/Salesforce/Google bundle comparable runtime controls | Controls cover core Obsidian use cases in enterprise licenses | Cut pricing assumptions and treat differentiation as unproven |
| Product-efficacy failure | Independent red-team or customer incident shows prompt-injection/RCE bypass | Material bypass without rapid remediation and customer proof | Move recommendation toward research-more or avoid until fixed |
| Valuation / disclosure risk | ARR, NRR, burn, or gross margin remains undisclosed in diligence | Cannot substantiate $40-70M ARR range or retention quality | Demand price reset, structure, or pass |
| Market-timing risk | AI-agent governance pipeline does not convert from pilots to annual contracts | Low paid conversion or weak renewal attach after 2-3 quarters | Lower growth case and delay investment |
| Competitive share loss | Zenity or SSPM peers repeatedly win Fortune 500 bake-offs | Losses tied to product gaps rather than price only | Reassess moat and sales productivity assumptions |
| Customer concentration | 14+ $1M accounts represent excessive ARR share or one account churns | Top-customer concentration exceeds diligence threshold | Increase discount rate and require customer-reference checks |
Kill criteria are observable diligence or post-close events that would directly change the risk rating or valuation stance.
[CR016, CR017, CR022, CR023, CR027, CR033]Technical, platform, financial, and execution risks converge on renewal trust, margin, and the $1.1B valuation case.
DAG is directional; it does not quantify causal weights.
[CR024, CR025, CR038, CR039, CR042]7.4 Exhibits
08Valuation
8.1 Series D Price and Implied Multiple
Obsidian’s August 4, 2026 Series D gives the valuation chapter a clear headline and an unclear denominator. The numerator is well supported: the company announced an $85 million raise led by Crescent Cove Advisors at a $1.1 billion post-money valuation, with existing investors returning and total capital raised now above $200 million. The denominator is the hard part. Obsidian discloses 100+ customers spending at least $100,000 annually, 14+ spending at least $1 million, and 60 Fortune 500 customers, but it does not disclose ARR, growth, margins, retention, burn, runway, or headcount. Using the canonical public-floor method from the financial chapter, the disclosed spend tiers imply about $24 million of ARR, while the plausible underwriting range remains roughly $40-70 million. That range makes the $1.1 billion price highly sensitive: about 46x at the floor, 22x at $50 million, and 15.7x at $70 million. The valuation is therefore not nonsensical, but it is explicitly price-sensitive and evidence-sensitive.[CV001, CV002, CV003, CV004, CV007, CV008]
| Dimension | Current stance | Decision implication |
|---|---|---|
| Recommendation | Track / research-more | Advance only if management proves ARR scale and clean terms; do not buy the headline price blindly. |
| Confidence | Medium | Enough public evidence exists for a range, not for point valuation conviction. |
| Risk rating | High | The price depends on private ARR, growth, retention, margin, and cap-table evidence. |
| Valuation stance | Stretched | Defensible only if ARR is already high; stretched if ARR is near the disclosed-spend floor. |
| Decision implication | Price- and evidence-disciplined follow-up | Use diligence gates rather than the unicorn label as the investment trigger. |
Recommendation reflects public evidence as of 2026-08-05 and treats undisclosed ARR as the controlling valuation uncertainty.
[CV030, CV031, CV032, CV033, CV044]| Side | Argument | What would strengthen it | What would change the view |
|---|---|---|---|
| Thesis | AI-agent and NHI security is a large, urgent control-plane problem, and Obsidian shows Fortune 500 traction. | Audited ARR above $50M, strong NRR/GRR, and proof that agent-governance revenue is growing quickly. | Weak retention, slow budget conversion, or platform-native controls absorbing the market. |
| Thesis | The Series D syndicate and existing-investor participation reduce financing-quality concern. | Clean preference stack and insider pro rata behavior that confirms conviction rather than rescue financing. | Heavy preferences, structured terms, or investor fatigue in follow-on rounds. |
| Anti-thesis | The $1.1B price may be ahead of public financial proof. | Company-provided ARR bridge from disclosed customer spend to contracted recurring revenue. | Audited ARR below $40M or evidence that the $24M floor is close to reality. |
| Anti-thesis | Zenity and platform vendors weaken scarcity premium in a nascent category. | Clear win/loss proof against Zenity and Microsoft-native controls. | Large enterprise budgets standardize on platform controls rather than independent vendors. |
The table separates company-quality arguments from price-support arguments because the valuation call is explicitly price-sensitive.
[CV023, CV028, CV029, CV037, CV040]| Scenario | Assumptions | Valuation / return logic | Probability signal |
|---|---|---|---|
| Bull | ARR near $70M+, growth remains premium, agent-governance revenue scales, and cyber premium comps stay open. | About $1.3B-$1.8B support at roughly 19-25x ARR; the $1.1B entry could work. | Requires private proof not yet public. |
| Base | ARR around $40M-$50M, strong logos but incomplete margin/retention proof, and investors apply opacity discount. | About $0.6B-$1.1B support at roughly 15-22x ARR; current price is top-of-range. | Most supportable on public evidence. |
| Bear | ARR close to the $24M floor, category adoption slows, or comps compress toward 8-13x. | About $0.2B-$0.5B support; downside from $1.1B is material. | Cannot be dismissed because ARR is not disclosed. |
| Froth case | Private cyber financing keeps clearing at exceptional multiples despite losses. | Cyera-like 80x ARR data could temporarily validate high marks but increases correction risk. | Adverse signal, not a base underwriting case. |
Ranges are simple ARR-times-multiple scenarios in USD enterprise-value billions; they are not management guidance or a DCF.
[CV010, CV011, CV012, CV018, CV022, CV034]The recommendation moves from strong category evidence to a stretched, evidence-gated valuation stance.
Flow is an underwriting logic map, not a company operating process.
[CV024, CV028, CV029, CV030, CV033, CV044]The football-field view shows a narrow defensible lane around the Series D unless ARR is already high.
Ranges are USD billions and represent simple multiple scenarios, not an official valuation opinion.
[CV001, CV010, CV011, CV012, CV034, CV035]8.2 Comparable Multiple Frame
The comparable frame argues for a split verdict. Windsor Drake’s 2026 cyber work puts ordinary public cybersecurity nearer 6-8x NTM revenue, cloud or AI-native leaders around 14-22x, private cyber around 15.2x, and top cloud M&A as high as 35x. Public comps show dispersion rather than a single answer: CrowdStrike sits at about 25.1x on $4.81 billion of FY26 revenue and $5.25 billion of ARR, Zscaler at about 11.7x on roughly $3.17 billion of TTM revenue and about $25 billion of market capitalization, Palo Alto around 15x, Cloudflare around 31.5x, Fortinet around 8.7x, and Okta around 5x. Private and M&A references are even more volatile. Wiz supports a strategic scarcity premium at $32 billion and $1 billion-plus ARR, while Cyera’s 80x ARR discussion despite operating losses is an adverse froth warning. NinjaOne shows investors will still pay up when fast growth comes with profitability. Obsidian deserves to be compared to the premium set only if diligence verifies high ARR and durable growth.[CV013, CV014, CV015, CV016, CV017, CV018]
| Comparable | Metric base | Multiple / value | Relevance | Limitation | Source refs |
|---|---|---|---|---|---|
| CrowdStrike | FY26 revenue $4.81B; ARR $5.25B | ~25.1x EV/Revenue | Premium cyber leader benchmark for best-in-class growth durability. | Much larger, public, and financially transparent. | SV002; SV003; SV005 |
| Zscaler | TTM revenue ~$3.17B; mcap ~$25B | ~11.7x EV/Revenue | Cloud-security reference below the premium leader band. | Public scale and disclosures exceed Obsidian’s. | SV002; SV004 |
| Palo Alto Networks | Public platform cyber comp | ~15x EV/Revenue | Large strategic platform reference for security consolidation. | Mature multi-product platform, not a private agent-security specialist. | SV001; SV002 |
| Cloudflare | Public cloud/edge-security comp | ~31.5x EV/Revenue | Shows how high markets can pay for cloud-native scarcity. | Business model and scale differ from Obsidian. | SV001; SV002 |
| Fortinet | Public network-security comp | ~8.7x EV/Revenue | Lower multiple warns against assuming a universal cyber premium. | Hardware/software mix and maturity differ. | SV001; SV002 |
| Okta | Public identity comp | ~5x EV/Revenue | Identity-adjacent lower-bound reference for sentiment risk. | Growth and category perception differ from AI-agent security. | SV001; SV002 |
Each row uses at least two retained sources; public multiples are reference bands, not direct fairness opinions for a private company.
[CV013, CV014, CV015, CV016, CV033]| Comparable | Valuation / status | Metric or multiple | Relevance | Limitation | Source refs |
|---|---|---|---|---|---|
| Wiz / Google | Google closed $32B acquisition | Wiz had $1B+ ARR by 2025, roughly 30x reference | Strategic scarcity comp for cloud security exits. | Far larger ARR scale and strategic platform fit. | SV006; SV009; SV010 |
| Cyera | Reportedly eyed $12B valuation | 80x ARR despite operating losses | Adverse froth signal for private cyber marks. | Data-security category and loss profile differ from Obsidian. | SV007; SV001; SV030 |
| NinjaOne | About $12.3B private valuation | ~70% growth plus profitability | Shows premium private pricing can be supported by fundamentals. | IT-management model differs from agent/NHI security. | SV008; SV001 |
| PANW / CyberArk | Palo Alto-CyberArk $25B reference | Strategic identity-security consolidation | Supports exit demand for identity/security control planes. | Not a direct private growth-round comp. | SV010; SV009; SV011 |
| Obsidian Series D | $1.1B post-money after $85M raise | ~22x if ARR ~$50M; ~46x at ~$24M floor | Subject company; tests whether price sits inside supportable cyber bands. | ARR and terms are private. | SV012; SV013; SV001 |
Private and M&A comps are deliberately heterogeneous; they bracket exit appetite and froth risk rather than define one direct peer multiple.
[CV017, CV018, CV019, CV020, CV044]Obsidian sits near premium public bands only if ARR is high and near frothy territory if ARR is near the floor.
Values are EV/Revenue or ARR multiples; Obsidian values are inferred from disclosed spend tiers and valuation.
[CV010, CV011, CV012, CV013, CV014, CV015]8.3 Scenario Recommendation and KPIs
The recommendation is to track, not buy unconditionally, because the Series D price is rich while public evidence is incomplete. The thesis is attractive: a large AI-agent/NHI security market, Fortune 500 proof, strong syndicate support, and runtime governance capabilities that align with a new enterprise control plane. The anti-thesis is equally important: category timing is young, Zenity raised $125 million one day earlier, Microsoft and other platforms can absorb pieces of the workflow, and the revenue denominator is private. The bull case needs ARR near $70 million, high growth, and premium public-comparable tolerance; the base case assumes $40-50 million ARR and an opacity discount; the bear case uses the $24 million floor and compressed multiples. Those cases translate to a stretched valuation stance with medium confidence and high risk. The IC should monitor market size, customer proof, moat, economics, competition, valuation, and evidence quality rather than treating the unicorn headline as its own proof.[CV023, CV024, CV025, CV026, CV027, CV028]
Obsidian scores highest on market pull and customer proof, and lowest on valuation support and financial transparency.
Scores are qualitative IC ratings derived from public evidence, not company-reported KPIs.
[CV021, CV024, CV027, CV028, CV031, CV032]8.4 Exit Readiness and Final Diligence
Exit optionality is real but not yet enough to erase valuation risk. Cybersecurity M&A activity, Google/Wiz, and Palo Alto/CyberArk all support strategic appetite for scarce security control planes, and Obsidian’s move into AI-agent governance gives it a plausible strategic narrative. However, a $1.1 billion entry price requires diligence evidence that public sources do not provide. The buyer or investor needs audited ARR, an ARR bridge from customer tiers, gross margin, burn, NRR, GRR, cohort retention, customer concentration, headcount, and clear cap-table terms. The most important kill triggers are ARR below about $40 million, evidence that the $24 million floor is close to reality, concentration inside the 14 million-dollar accounts, platform-vendor budget capture, or broad cyber multiple compression. If management proves high ARR and clean preferences, the valuation can be defended as a growth-premium cyber round. If not, the Series D looks stretched on estimated ARR and should be approached only with price protection.[CV021, CV037, CV038, CV039, CV040, CV041]
| Trigger | Threshold / event | Transmission to thesis | Action implication |
|---|---|---|---|
| ARR proof miss | Audited ARR below ~$40M or close to the ~$24M floor. | Implied multiple becomes far above normal public/private cyber bands. | Do not underwrite at $1.1B without major price protection. |
| Retention or concentration risk | Weak NRR/GRR or concentration inside the 14 $1M+ customers. | Customer proof stops translating into durable revenue quality. | Lower multiple and require cohort-level evidence. |
| Platform commoditization | Microsoft or another platform absorbs agent-governance budget. | Scarcity premium and independent-vendor pricing power compress. | Reassess category share and sales-cycle assumptions. |
| Multiple compression | Public cyber/private cyber medians fall below underwriting bands. | Exit values decline even if operations execute. | Use lower exit multiple and revisit ownership math. |
| Structured terms | Heavy preferences, participation, or anti-dilution appear in the Series D stack. | Headline valuation overstates common-equity return. | Model liquidation stack before proceeding. |
Kill triggers are tied to observable diligence outputs or market data rather than generic risk language.
[CV038, CV039, CV040, CV041, CV043]| Topic | Missing evidence | Why it matters | Diligence path |
|---|---|---|---|
| ARR bridge | Contracted ARR, revenue, and bridge from customer-spend tiers. | Determines whether 22x or 46x is the right implied multiple. | Request CFO-certified ARR schedule and customer-tier rollforward. |
| Growth and retention | Revenue growth, NRR, GRR, churn, expansion, and cohort retention. | Premium multiples require durable expansion, not only customer logos. | Request board KPI pack and cohort tables. |
| Economics and burn | Gross margin, contribution margin, burn, runway, and headcount. | Cyera-style operating losses would increase froth risk at high multiples. | Request monthly financials and operating plan. |
| Customer concentration | Top-10 customer share and concentration among the 14 $1M+ accounts. | Large accounts can support ARR or create fragility. | Request anonymized customer concentration schedule and references. |
| Cap table and preferences | Liquidation preferences, participation, option pool, side letters, and pro rata rights. | Investor return can differ from enterprise value. | Review financing documents and capitalization model. |
| Competitive proof | Win/loss versus Zenity, Microsoft-native controls, and incumbent cyber platforms. | Determines whether valuation deserves a scarcity premium. | Run customer calls and review pipeline conversion by competitor. |
These asks are the minimum package needed to move from a public-evidence range to an investable price.
[CV037, CV042, CV043, CV044]8.5 Exhibits
Disclaimer
This report is based on publicly available information as of 2026-08-05 and is an analytical diligence artifact, not investment advice.
Evidence index
| ID | Statement | Confidence | Sources |
|---|---|---|---|
| CO001 | Current August 2026 coverage identifies Obsidian Security as Palo Alto, California-based, so Palo Alto is the canonical headquarters for this run. | High | SO001, SO010, SO013 |
| CO002 | Some legacy third-party profile surfaces still point to Newport Beach or otherwise conflict with the Palo Alto headquarters evidence, creating a headquarters reconciliation gap rather than a new canonical HQ. | Medium | SO017, SO019 |
| CO003 | Obsidian Security was founded in 2017 by Glenn Chisholm, Ben Johnson, and Matt Wolff. | Medium | SO015, SO019, SO020 |
| CO004 | Glenn Chisholm is publicly described as Co-Founder, Chairman, and Chief Product Officer with prior CTO experience at Cylance and first-CISO experience at Telstra. | Medium | SO015, SO019 |
| CO005 | Ben Johnson is described in the canonical fact sheet and ownership profiles as a co-founder and CTO with Carbon Black founder experience before VMware acquired Carbon Black. | Medium | SO019, SO020 |
| CO006 | Matt Wolff is part of the 2017 founder set and is positioned as Chief Scientist with data-science roots from Cylance. | Medium | SO015, SO019 |
| CO007 | Hasan Imam is the current CEO quoted in the August 2026 Series D narrative and is not part of the disclosed founder set. | High | SO001, SO002, SO018, SO022 |
| CO008 | Norwest describes Imam as a former Chief Revenue and Customer Officer at Shape Security, a company later acquired by F5 for about $1 billion. | Medium | SO022, SO025 |
| CO009 | Obsidian sells runtime governance and security for AI agents and non-human identities operating inside enterprise third-party SaaS applications. | High | SO002, SO004, SO005, SO020 |
| CO010 | The company has pivoted from SaaS Security Posture Management toward AI-agent governance and runtime controls for non-human identities. | Medium | SO001, SO005, SO021, SO022 |
| CO011 | Obsidian announced an $85 million Series D on August 4, 2026. | High | SO001, SO002, SO003, SO007, SO010 |
| CO012 | The August 2026 Series D valued Obsidian at $1.1 billion post-money, making it a private Series D unicorn. | High | SO001, SO002, SO009, SO010, SO011 |
| CO013 | Crescent Cove Advisors led the Series D, with founder and CIO Jun Hong Heng named in the financing coverage. | High | SO001, SO002, SO008, SO010 |
| CO014 | Existing investors Greylock, Menlo Ventures, Norwest Venture Partners, IVP, Wing, and GV participated in the Series D. | High | SO001, SO002, SO010, SO023 |
| CO015 | After the Series D, Obsidian has raised more than $200 million across five rounds. | High | SO001, SO002, SO007, SO009 |
| CO016 | Obsidian closed a $90 million Series C in April 2022 led by Menlo Ventures, Norwest Venture Partners, and IVP, with total funding at that time reaching $119.5 million. | Medium | SO001, SO021, SO022 |
| CO017 | Norwest led Obsidian's Series B-1 in June 2021. | Medium | SO022, SO025 |
| CO018 | Greylock led Obsidian's earliest institutional Series A round, making it a foundational investor rather than only a late-stage participant. | Medium | SO016, SO024 |
| CO019 | Series D coverage reports that more than 100 Obsidian customers each spend over $100,000 per year. | High | SO001, SO002, SO003, SO010 |
| CO020 | Series D coverage reports that more than 14 Obsidian customers each spend over $1 million per year. | High | SO001, SO002, SO003, SO010 |
| CO021 | Series D coverage reports that 60 Fortune 500 companies are Obsidian customers. | High | SO001, SO002, SO003, SO010 |
| CO022 | The company states that non-human identities outnumber human identities 144:1 inside third-party applications. | High | SO001, SO002, SO020 |
| CO023 | The CEO said more than 70% of customers already permit AI agents into third-party applications. | High | SO001, SO002 |
| CO024 | Obsidian does not publicly disclose revenue or ARR in the retained 2026 source set. | Medium | |
| CO025 | Obsidian does not publicly disclose current headcount in the retained 2026 source set. | Medium | |
| CO026 | A narrow inferred ARR floor is approximately $24 million, calculated as 100 customers at $100,000 plus 14 customers at $1 million; it is an estimate, not disclosed ARR. | Medium | SO001, SO002, SO010 |
| CO027 | The Series D proceeds are intended to fund research and development and deepen Obsidian's reach across Fortune 500 and Global 2000 accounts. | High | SO001, SO002, SO008, SO023 |
| CO028 | The company page frames the mission around securing non-human identities and AI adoption across more than 35,000 third-party applications. | High | SO020, SO004 |
| CO029 | Public sources do not disclose a complete current board roster, observer rights, secondaries, debt facilities, or control terms. | Medium | |
| CO030 | The latest investor group combines a new lead investor, Crescent Cove, with repeat venture investors from earlier rounds. | High | SO001, SO002, SO016, SO022, SO023 |
| CO031 | Zenity raised $125 million on August 3, 2026, one day before Obsidian's Series D announcement, creating a competitive-context caveat for AI-agent governance fundraising momentum. | Medium | SO006 |
| CO032 | The April 2022 Series C positioned Obsidian as an SSPM leader before the 2026 narrative centered on agent runtime governance. | Medium | SO021, SO022, SO001 |
| CO033 | Obsidian's homepage tagline, Secure AI and Fearless Innovation, aligns the current brand around AI-security enablement rather than only SaaS posture hygiene. | High | SO004, SO020 |
| CO034 | FinTech Global describes Obsidian capabilities around MCP inventory, model registry visibility, runtime governance, and OWASP-aligned controls for rogue AI agents. | Medium | SO005, SO002 |
| CO035 | Craft lists Hasan Imam as CEO and provides an executive roster, but the public source set still does not amount to a complete governance org chart. | Medium | SO018, SO001 |
| CO036 | StartupHub and ownership-profile sources support Glenn Chisholm's public founder identity and reinforce the three-founder founding narrative. | Medium | SO015, SO019 |
| CO037 | Yahoo Finance coverage corroborates the Series D amount, valuation, and investor syndicate with a high-reputation independent source. | High | SO010, SO001, SO002 |
| CO038 | StartupRise describes Obsidian as California-based in its Series D coverage, consistent with the current Palo Alto headquarters evidence. | Medium | SO013, SO001 |
| CO039 | Seedtable records the August 2026 Series D as a funding-round datapoint, providing an independent database-style check on the news flow. | Medium | SO014, SO001 |
| CO040 | The druce.ai vendor profile is useful as a third-party profile surface but is lower-reputation and should not override fresher 2026 Series D identity evidence. | Medium | SO017, SO001 |
| CO041 | The combination of founder-heavy product leadership and non-founder CEO leadership creates a key-person diligence item rather than a proof of governance weakness. | Medium | SO015, SO018, SO022 |
| CO042 | The latest disclosed scale metrics are company-reported customer-spend thresholds and Fortune 500 penetration, not audited revenue, retention, or margin figures. | Medium | SO001, SO002, SO010 |
| CO043 | The snapshot should present $1.1 billion valuation, more than $200 million raised, 100-plus six-figure customers, 14-plus seven-figure customers, and 60 Fortune 500 customers while showing ARR, revenue, and headcount as null. | Medium | SO001, SO002, SO010 |
| CO044 | Obsidian's public profile is best interpreted as a late-stage private cybersecurity company with strong financing validation but incomplete financial disclosure. | Medium | SO001, SO002, SO010, SO024, SO025 |
| CO045 | The milestone sequence shows a compressed category pivot: SSPM financing in 2021-2022, an AI-agent competitive funding shock on August 3, 2026, and Obsidian's unicorn Series D one day later. | Medium | SO006, SO001, SO021, SO022 |
| CO046 | The operating model links SaaS application telemetry, non-human-identity inventory, runtime policy enforcement, Fortune 500 demand, and growth capital into one AI-agent governance platform story. | Medium | SO001, SO002, SO005, SO020 |
| CO047 | The KPI set is mature enough to establish late-stage traction but insufficient to underwrite valuation without management-provided ARR, NRR, gross margin, burn, and headcount data. | Medium | SO001, SO002, SO010 |
| CM001 | Obsidian announced an $85 million Series D on August 4, 2026 at a $1.1 billion post-money valuation, confirming unicorn-stage market validation rather than a seed-stage category experiment. | High | SM001, SM002, SM003, SM010 |
| CM002 | Obsidian disclosed more than 100 customers spending at least $100,000 annually and more than 14 customers spending at least $1 million annually. | High | SM001, SM002 |
| CM003 | Obsidian reported 60 Fortune 500 customers, giving the market analysis a buyer base anchored in enterprise security budgets rather than SMB experimentation. | High | SM001, SM002 |
| CM004 | Chief Executive Hasan Imam said more than 70% of Obsidian customers already allow AI agents into third-party applications. | Medium | SM001, SM002 |
| CM005 | Obsidian states that non-human identities outnumber human identities 144 to 1 inside third-party applications. | High | SM001, SM002, SM017 |
| CM006 | Obsidian frames its mission around securing AI adoption across more than 35,000 third-party applications used by enterprises. | Medium | SM017 |
| CM007 | Obsidian positions its product as runtime governance and security for AI agents and non-human identities operating inside enterprise SaaS applications. | High | SM002, SM004, SM005 |
| CM008 | SNS Insider sizes the AI Agent Security market at approximately $26 billion in 2026, growing at roughly 39.1% CAGR toward about $507 billion by 2035. | Medium | SM018 |
| CM009 | MarketsandMarkets sizes the narrower Agentic AI Security market at approximately $1.65 billion in 2026 with roughly 42% CAGR to about $13.5 billion by 2032. | Medium | SM022 |
| CM010 | Mordor Intelligence sizes the Non-Human Identity Security market at approximately $8.22 billion in 2026 with 22.78% CAGR through 2031. | Medium | SM019 |
| CM011 | Research and Markets sizes the SSPM software market at approximately $3.69 billion in 2026 with a 12.6% CAGR to 2032. | Medium | SM020 |
| CM012 | Frost & Sullivan reports a materially smaller SSPM baseline of about $484.4 million in 2025, growing to about $3.53 billion by 2030 at 48.7% CAGR. | Medium | SM023, SM024 |
| CM013 | InsightAce Analytic sizes the broader Security Posture Management market at about $26.35 billion, a broad adjacency that includes more than third-party SaaS governance. | Medium | SM021 |
| CM014 | Mordor Intelligence sizes the Identity Threat Detection and Response market at about $3.42 billion in 2026, growing to about $10.51 billion by 2031 at 25.17% CAGR. | Medium | SM025 |
| CM015 | The most defensible TAM for Obsidian is the approximately $26 billion 2026 AI Agent Security market, because the product is explicitly positioned around securing autonomous agents in enterprise environments. | Medium | SM004, SM005, SM018 |
| CM016 | A defensible 2026 SAM is approximately $8 billion to $12 billion, bounded by NHI Security at $8.22 billion plus SSPM at $3.69 billion while discounting overlap across identity and SaaS-posture budgets. | Medium | SM019, SM020, SM022 |
| CM017 | A near-term Obsidian SOM of approximately $50 million to $150 million is an estimate that extends from disclosed high-ACV customer counts rather than from public ARR disclosure. | Medium | SM001, SM002 |
| CM018 | The disclosed customer thresholds imply a minimum annual recurring revenue floor of about $24 million, calculated as 100 customers at $100,000 plus 14 customers at $1 million. | Medium | SM001, SM002 |
| CM019 | A plausible current ARR range of about $40 million to $70 million is an inference from the disclosed customer mix and should not be presented as reported revenue. | Medium | SM001, SM002 |
| CM020 | The Research and Markets and Frost SSPM estimates conflict materially on baseline size and growth rate, so SSPM should be treated as an uncertainty band rather than a single precise market-size input. | Medium | SM020, SM023, SM024 |
| CM021 | Obsidian-relevant spend includes AI-agent runtime controls, non-human-identity governance, SSPM, SaaS-to-SaaS integration security, and ITDR-like identity detection workflows. | Medium | SM004, SM005, SM019, SM020, SM025 |
| CM022 | Broad CSPM, DSPM, ISPM, and generic security posture management spend should be excluded from Obsidian SAM unless it directly protects third-party SaaS, agent identities, or SaaS-integrated workflows. | Medium | SM021, SM017 |
| CM023 | Status-quo substitutes include manual SaaS reviews, IdP-native controls, spreadsheet access approvals, doing nothing, and native platform governance from the SaaS or AI platform owner. | Medium | SM017, SM005 |
| CM024 | The buyer set spans CISOs, security-operations teams, identity owners, SaaS application owners, and AI-platform governance teams because the protected workflow crosses identity, apps, and autonomous execution. | Medium | SM002, SM005, SM017 |
| CM025 | Fortune 500 penetration indicates payer capacity in large security and identity budgets, but it does not disclose whether spend comes from CISO, IAM, SaaS owner, or AI-transformation budget lines. | Medium | SM001, SM002 |
| CM026 | Obsidian extends governance to agent-building platforms and autonomous developer agents, which places adoption in the path of Microsoft Copilot Studio, Salesforce Agentforce, n8n, Claude Code, and similar workflows. | Medium | SM002, SM005 |
| CM027 | Obsidian describes MCP inventory and model-registry visibility as part of the control plane for tracking which agents invoke which external tools and models. | Medium | SM005 |
| CM028 | The 144-to-1 NHI ratio creates an identity-governance driver because automated actors expand faster than human headcount and can hold privileged app access. | Medium | SM001, SM002, SM019 |
| CM029 | The more-than-35,000 third-party-app surface creates a SaaS-governance driver because each app can accumulate integrations, agents, OAuth grants, and over-permissioned non-human identities. | Medium | SM017, SM005 |
| CM030 | The reported 70% customer agent-adoption rate is a near-term demand driver but also implies Obsidian must prove controls work in live deployments rather than merely future roadmaps. | Medium | SM001, SM002 |
| CM031 | Zenity raised $125 million one day before Obsidian's Series D, which validates investor interest in AI-agent security while creating a well-funded direct competitive constraint. | Medium | SM006 |
| CM032 | Well-funded direct competition can reduce Obsidian's obtainable market share if buyers compare agent-governance platforms rather than treating Obsidian as a category default. | Medium | SM006, SM001 |
| CM033 | Obsidian says new capital will fund R&D and deeper expansion into Fortune 500 and Global 2000 accounts, aligning growth investment with the enterprise SAM rather than consumer or SMB demand. | Medium | SM001, SM002, SM008 |
| CM034 | MarketsandMarkets indicates North America accounts for more than 40% of Agentic AI Security demand, supporting an initial enterprise go-to-market centered on large North American accounts. | Medium | SM022 |
| CM035 | The ITDR market creates an adjacent identity-security budget path for Obsidian, but ITDR is not identical to agent runtime governance and should not be fully counted as SAM. | Medium | SM025, SM005 |
| CM036 | The broad $26.35 billion Security Posture Management lens is useful for adjacency context but overstates Obsidian's directly serviceable market because it includes posture-management categories outside SaaS and agents. | Medium | SM021, SM017 |
| CM037 | The SSPM estimate disagreement spans roughly $0.48 billion in 2025 to $3.69 billion in 2026 depending on source and taxonomy, making market-size uncertainty an adverse underwriting input. | Medium | SM020, SM023, SM024 |
| CM038 | Every market-size value used in this chapter is an analyst estimate or diligence derivation, not observed Obsidian revenue or contractual bookings. | Medium | SM018, SM019, SM020, SM022, SM025 |
| CM039 | Obsidian's disclosed high-ACV customers de-risk willingness to pay, but the lack of public ARR, NRR, churn, and headcount prevents a precise SOM conversion. | Medium | SM001, SM002 |
| CM040 | No cited public source discloses a management-grade revenue split by product line, customer segment, budget owner, or geography. | Medium | SM001, SM002, SM017 |
| CP001 | Obsidian positions itself around securing AI adoption and third-party SaaS applications rather than only legacy SaaS posture management. | High | SP002, SP004 |
| CP002 | Obsidian announced an $85 million Series D on August 4, 2026 at a $1.1 billion valuation. | High | SP001, SP002, SP003 |
| CP003 | Obsidian disclosed more than 100 customers spending at least $100,000 annually, more than 14 customers spending at least $1 million annually, and 60 Fortune 500 customers. | High | SP001, SP002 |
| CP004 | Obsidian says more than 70% of its customers already allow AI agents into third-party applications. | High | SP001, SP002 |
| CP005 | Obsidian cites a 144:1 ratio of non-human to human identities inside third-party applications. | High | SP001, SP002 |
| CP006 | Obsidian's runtime-governance claim is that it can detect and block privilege escalation, excessive data access, and policy violations before agent actions take effect. | High | SP002, SP005 |
| CP007 | Zenity raised a $125 million Series C led by Norwest on August 3, 2026, one day before Obsidian's Series D. | High | SP006, SP018, SP021, SP023 |
| CP008 | Zenity publicly disclosed 230-plus staff, New York headquarters, Tel Aviv R&D, and founders Ben Kliger and Michael Bargury. | High | SP018, SP021 |
| CP009 | Zenity's Series C syndicate included Norwest, SoftBank Vision Fund 2, Qumra, Hitachi Ventures, LG Tech Ventures, Vertex, Third Point, DTCP, and Intel Capital. | Medium | SP018, SP020, SP023 |
| CP010 | Zenity says it secures AI agents across enterprise agent-building surfaces such as Copilot Studio and Salesforce Agentforce. | Medium | SP006, SP012, SP021 |
| CP011 | Obsidian's public platform coverage includes Microsoft Copilot Studio, Salesforce Agentforce, n8n, autonomous developer agents, Claude Code, and Cowork. | High | SP002, SP005 |
| CP012 | Grip Security directly claims Obsidian lacks some shadow SaaS, shadow AI, and automated-remediation capabilities that Grip provides. | Medium | SP008 |
| CP013 | Grip positions itself around complete SaaS and AI control, making it a competitor in discovery, identity governance, and remediation workflows. | Medium | SP008, SP009, SP013 |
| CP014 | Push Security positions itself as browser security for the AI era, implying a differentiated browser-layer telemetry and control point. | Medium | SP010, SP014 |
| CP015 | Nudge Security positions around SaaS and AI security discovery and behavioral nudges rather than deep runtime blocking. | Medium | SP010, SP011, SP015 |
| CP016 | Valence Security positions around SaaS and AI security for the agentic era, creating overlap with Obsidian's SaaS-to-SaaS and NHI governance story. | Medium | SP011, SP016 |
| CP017 | AppOmni remains an established enterprise SaaS security and SSPM competitor, especially when buyers define the problem as SaaS posture rather than AI-agent runtime control. | Medium | SP007, SP017 |
| CP018 | UpGuard's competitor page describes Obsidian as ITDR and knowledge-graph oriented while noting gaps such as EASM or external security ratings. | Medium | SP007 |
| CP019 | SpotSaaS places Nudge, Obsidian, and Push in a direct comparison set, supporting the view that buyers compare SaaS and AI security products across different control layers. | Medium | SP010 |
| CP020 | CloudEagle's Nudge-alternatives page includes Valence and other SaaS-management or SaaS-security vendors, showing adjacent pressure around discovery and SaaS workflow control. | Medium | SP011 |
| CP021 | CB Insights' Grip alternatives page confirms that SaaS and identity-security buyers have a broader set of substitute vendors beyond Obsidian and Zenity. | Medium | SP009 |
| CP022 | Zenity has publicly reported revenue tripling for two consecutive years, a growth signal that intensifies direct competition for AI-agent security budgets. | Medium | SP006, SP018, SP022 |
| CP023 | Zenity's 230-plus employee disclosure is a stronger public headcount signal than Obsidian's public disclosures, because Obsidian has not disclosed headcount. | Medium | SP001, SP018 |
| CP024 | The honest differentiation versus Zenity is Obsidian's runtime SaaS governance and NHI graph versus Zenity's stronger public build-time and agent-development focus. | Medium | SP002, SP005, SP006, SP012, SP018, SP021 |
| CP025 | The named CH3 peer set contains at least six material alternatives to Obsidian: Zenity, Grip, Push, Nudge, Valence, and AppOmni. | Medium | SP007, SP008, SP010, SP011, SP012, SP013, SP014, SP015, SP016, SP017 |
| CP026 | The allowed competitor source set does not provide standardized list pricing, realized ASPs, discounting, or renewal data across Obsidian and the named peers. | Medium | SP007, SP008, SP010, SP012, SP013, SP014, SP015, SP016, SP017 |
| CP027 | Obsidian's disclosed high-ACV customer counts imply enterprise pricing power, but they do not reveal ARR, net revenue retention, or realized module-level pricing. | Medium | SP001, SP002 |
| CP028 | Zenity's $125 million Series C exceeds Obsidian's $85 million Series D in fresh capital amount, increasing the risk of share-of-voice and talent competition. | Medium | SP001, SP006, SP018, SP021 |
| CP029 | Buyers can multi-home across Obsidian, Zenity, Push, Nudge, Grip, Valence, and AppOmni because each emphasizes a different control layer. | Medium | SP008, SP010, SP012, SP013, SP014, SP015, SP016, SP017 |
| CP030 | Obsidian's ability to become a durable control plane depends on attach rates and expansion into runtime agent governance, not merely initial SaaS discovery. | Medium | SP001, SP002, SP005, SP008, SP013 |
| CP031 | SNS Insider sizes the AI Agent Security market at about $26 billion in 2026 with roughly 39% CAGR to about $507 billion by 2035. | Medium | SP024 |
| CP032 | Mordor Intelligence sizes the Non-Human Identity Security market at about $8.22 billion in 2026 with about 22.78% CAGR through 2031. | Medium | SP025 |
| CP033 | Status quo and internal-build alternatives remain credible because buyers can combine SaaS-admin controls, identity controls, browser controls, and manual governance rather than buying one platform. | Medium | SP007, SP010, SP014, SP017 |
| CP034 | Obsidian's breadth of platform coverage is a competitive moat only if coverage works across both business-agent surfaces and developer-agent surfaces such as Claude Code and Cowork. | Medium | SP002, SP005 |
| CP035 | Obsidian is competitively credible but not unassailable because direct AI-agent rivals, discovery-first products, SSPM incumbents, native controls, and internal builds can each attack part of the value proposition. | Medium | SP001, SP006, SP007, SP008, SP010, SP011, SP012, SP013, SP014, SP015, SP016, SP017 |
| CI001 | Obsidian announced an $85 million Series D on August 4, 2026 at a $1.1 billion valuation, led by Crescent Cove Advisors with all existing investors participating. | High | SI009, SI010, SI011, SI015, SI016, SI017, SI018 |
| CI002 | The latest round took Obsidian’s disclosed lifetime capital raised to more than $200 million across five rounds. | High | SI009, SI010, SI015, SI018, SI019 |
| CI003 | The company disclosed that more than 100 customers each spend over $100,000 annually and more than 14 customers each spend over $1 million today. | High | SI010, SI009, SI018 |
| CI004 | Obsidian also disclosed 60 Fortune 500 customers, including large financial institutions, social media networks, and telecom providers. | High | SI010, SI009 |
| CI005 | Obsidian said the Series D proceeds will fund R&D and expand its reach deeper into the Fortune 500 and Global 2000. | High | SI010, SI009, SI016 |
| CI006 | Obsidian’s April 2022 Series C raised $90 million and brought total funding at that time to $119.5 million. | Medium | SI024, SI009 |
| CI007 | Norwest says it led Obsidian’s Series B-1 in June 2021 and then invested again in the $90 million Series C alongside Menlo, Greylock, Wing, IVP, and GV. | Medium | SI022, SI024 |
| CI008 | Greylock’s portfolio page lists Obsidian as first partnered at Series A and still active, supporting Greylock’s role as an early institutional backer. | Medium | SI021, SI009 |
| CI009 | Public sources cited for this chapter do not disclose Obsidian’s revenue, ARR, gross margin, free cash flow, monthly burn, or runway. | Medium | SI009, SI010, SI001, SI019 |
| CI010 | Using the disclosed spend thresholds as instructed, 100 customers at at least $100,000 plus 14 customers at at least $1 million implies a public spend floor of approximately $24 million. | Medium | SI010, SI009 |
| CI011 | The $40 million to $70 million ARR band used in this chapter is an analyst estimate, not a disclosed company metric. | Medium | SI010, SI009, SI001 |
| CI012 | At the $24 million implied floor, a $1.1 billion valuation equals roughly 46 times ARR. | Medium | SI010, SI009 |
| CI013 | At the $50 million base-case ARR estimate, a $1.1 billion valuation equals roughly 22 times ARR. | Medium | SI010, SI009 |
| CI014 | At the $70 million high-case ARR estimate, a $1.1 billion valuation equals roughly 16 times ARR. | Medium | SI010, SI009 |
| CI015 | Finro’s Q2 2026 cybersecurity dataset reports a private-market average of about 15.4 times revenue, so Obsidian needs ARR near or above the high end of the estimate band to screen near that private benchmark. | Medium | SI007 |
| CI016 | Finro also warns that medians and stage compression matter, with many outcomes below headline private averages; that makes a 22x to 46x implied multiple a valuation-risk flag unless revenue quality is exceptional. | Medium | SI007 |
| CI017 | A $1.1 billion valuation divided by Finro’s 15.4 times private benchmark implies about $71 million of ARR would be needed to justify the mark at that benchmark. | Medium | SI007, SI009 |
| CI018 | A 10 times to 13 times compressed private-cyber multiple would require roughly $85 million to $110 million of ARR to support a $1.1 billion valuation. | Medium | SI007, SI009 |
| CI019 | Cyberse reports a free tier for up to 1,000 users and an AWS Marketplace reference price of about $100 per user per year. | Medium | SI001 |
| CI020 | SaaS Tools Info also lists a free tier and free trial, corroborating a low-friction entry path before enterprise conversion. | Medium | SI003, SI001 |
| CI021 | Ciphers Security describes Obsidian as headcount-based and custom-quoted above the free threshold, making the public per-user figure list-price directional rather than realized-price evidence. | Medium | SI002, SI001 |
| CI022 | The visible monetization model is enterprise subscription software around SaaS security, identity threat detection, and AI-agent governance, not GMV, hardware, or project-finance revenue. | Medium | SI012, SI023, SI001, SI002 |
| CI023 | Obsidian’s GTM motion screens as enterprise-led because the company highlights Fortune 500 and Global 2000 expansion, custom enterprise quotes, and multiple seven-figure accounts. | Medium | SI010, SI001, SI002 |
| CI024 | The 14 customers above $1 million create useful enterprise validation but also a possible revenue-concentration risk that public sources do not quantify. | Medium | SI010, SI009 |
| CI025 | No public evidence in the retained source set discloses customer acquisition cost, sales-cycle length, CAC payback, net revenue retention, logo retention, or churn. | Medium | |
| CI026 | No public evidence in the retained source set discloses gross margin, contribution margin, cloud hosting cost, support cost, or services attach cost. | Medium | |
| CI027 | The cost structure is likely dominated by R&D, sales and customer success, cloud/software delivery, security operations, and support rather than capex-heavy manufacturing. | Medium | SI010, SI012, SI023 |
| CI028 | The Series D provides $85 million of fresh capital, but cash on hand before the round, monthly burn, and resulting runway months remain undisclosed. | Medium | SI010, SI009 |
| CI029 | The retained sources do not disclose debt, credit facilities, project-finance obligations, or other non-equity financing obligations. | Medium | |
| CI030 | With more than $200 million raised and a $1.1 billion valuation, Obsidian has created less than 5.5 dollars of headline equity value per dollar of disclosed capital raised, before considering any unreported secondary or option-pool effects. | Medium | SI009, SI010 |
| CI031 | Crunchbase reported $10.6 billion of H1 2026 cybersecurity and privacy startup funding but also a Q2 pullback of about 30%, so the financing backdrop is supportive but not indiscriminately euphoric. | Medium | SI004 |
| CI032 | SaaS Mag reports public cyber companies at about 7.8 times revenue, private cyber startups around 15.2 times, and M&A medians around 16.3 times, broadly corroborating the private-premium frame. | Medium | SI008, SI007 |
| CI033 | SaaS Mag argues the premium profile depends on software-like markers such as high gross margins, strong NRR, a defensible data graph, and platform consolidation fit; Obsidian has not disclosed those financial markers publicly. | Medium | SI008, SI010 |
| CI034 | TechNews180 cautions that unicorn status means a private valuation above $1 billion, not proof that a company has $1 billion of cash or a fully proven business. | Medium | SI006 |
| CI035 | Failory lists dozens of cyber unicorns globally, reinforcing that a unicorn mark is a competitive category signal rather than a unique proof of financial durability. | Medium | SI005, SI006 |
| CI036 | SiliconANGLE and FinTech Global frame AI-agent activity inside third-party applications as a new attack surface, supporting the strategic rationale for R&D investment in runtime governance. | Medium | SI011, SI013, SI010 |
| CI037 | Zenity raised $125 million one day before Obsidian’s Series D, indicating direct competitive capital intensity in AI-agent security. | Medium | SI014, SI009 |
| CI038 | Cyberse notes Obsidian’s SSPM focus does not extend to IaaS or PaaS cloud posture, which could limit budget capture versus broader platform-security vendors. | Medium | SI001, SI002 |
| CI039 | The free tier can improve product-led discovery and trial conversion, but it also means public user counts or discovery usage would not automatically equal paid ARR. | Medium | SI001, SI003 |
| CI040 | The combination of 100-plus six-figure customers and 14-plus seven-figure customers implies a skew toward enterprise ACVs, but public evidence does not reveal average contract value or discounting. | Medium | SI010, SI009 |
| CI041 | The 60-Fortune-500 signal improves logo quality but does not disclose renewal behavior, expansion rate, or whether revenue is concentrated in a few very large accounts. | Medium | SI010, SI009 |
| CI042 | Obsidian’s pricing evidence supports annual per-user subscription mechanics, but revenue recognition, multi-year prepayments, implementation fees, and services mix remain unavailable. | Medium | SI001, SI002, SI003 |
| CI043 | Because ARR and burn are undisclosed, the cash runway table must carry nulls for cash on hand, monthly burn, runway months, gross margin, NRR, and CAC payback rather than false precision. | Medium | SI009, SI010, SI001 |
| CI044 | The financial verdict is that Obsidian has unusually strong enterprise spend signals for a private cybersecurity company, but the $1.1 billion mark is stretched until management verifies ARR, retention, gross margin, burn, and concentration. | Medium | SI010, SI009, SI007, SI008 |
| CE001 | Obsidian Security positions its product as runtime governance and security for AI agents and non-human identities operating inside enterprise third-party SaaS applications. | High | SE001, SE011, SE012, SE015 |
| CE002 | The company homepage anchors the product message on securing AI adoption rather than only remediating static SaaS misconfigurations. | Medium | SE014, SE017 |
| CE003 | Series D coverage reports that more than 70% of Obsidian customers already allow AI agents into third-party applications. | Medium | SE011, SE012 |
| CE004 | The public product map spans MCP security, AI agent identity management, NHI governance, SaaS supply-chain security, breach clarity, and the earlier SSPM/ITDR base. | High | SE001, SE006, SE007, SE008, SE009, SE010 |
| CE005 | The customer workflow implied by public sources starts with discovering NHIs and connected MCP servers, maps them to a graph, evaluates agent actions at runtime, and then supports post-incident clarity. | Medium | SE001, SE006, SE008, SE009, SE015 |
| CE006 | Obsidian reports that non-human identities outnumber human identities by 144:1 inside third-party applications. | Medium | SE011, SE017 |
| CE007 | The company page frames its mission across 35,000-plus third-party applications, indicating that the technical scope is a broad SaaS control plane rather than a single application connector. | Medium | SE017 |
| CE008 | Public coverage describes a category evolution from SaaS Security Posture Management into AI agent governance and runtime control for non-human identities. | High | SE011, SE012, SE015, SE020 |
| CE009 | Obsidian says runtime governance detects and blocks privilege escalation, excessive data access, and policy violations before an agent action takes effect. | High | SE001, SE015 |
| CE010 | The runtime-enforcement claim is designed to move agent governance from after-the-fact posture reporting to pre-action policy enforcement. | Medium | SE001, SE009, SE015 |
| CE011 | Obsidian's MCP security surface maintains an inventory of every MCP server connected across an organization and maps those servers to the agents invoking them. | High | SE001, SE015 |
| CE012 | The MCP product also includes a model registry intended to detect model switching or substitution beneath an agent workflow. | High | SE001, SE015 |
| CE013 | The product coverage includes Microsoft Copilot Studio, Salesforce Agentforce, n8n, and autonomous developer agents as agent-building or autonomous-agent surfaces. | Medium | SE001, SE012, SE015 |
| CE014 | Obsidian is extending native governance to Anthropic Claude Code and Cowork for permission restriction, sensitive-file access management, and runtime blocking of unsanctioned MCP or tool usage. | Medium | SE012, SE011 |
| CE015 | Obsidian's NHI education material distinguishes AI agents from other non-human identities because agents are probabilistic and often over-permissioned. | Medium | SE008 |
| CE016 | The AI agent identity product page is explicitly framed around governing every non-human identity rather than only human user accounts. | Medium | SE009 |
| CE017 | Obsidian's earlier SSPM motion addressed misconfigurations, over-privileged accounts, and insider threats across Salesforce, Workday, and Microsoft 365 before expanding into agent governance. | Medium | SE011, SE020 |
| CE018 | The operating model combines API-based or agentless onboarding, a knowledge graph, behavioral analytics and machine learning, SIEM/SOAR integration, and SOC 2/GDPR-oriented compliance posture. | Medium | SE014, SE017, SE020, SE025 |
| CE019 | Obsidian launched end-to-end SaaS supply-chain security for SaaS-to-SaaS integrations on January 22, 2026. | High | SE007, SE010 |
| CE020 | The January 2026 integration-security coverage frames SaaS integrations and agentic connections as rising attack paths that require end-to-end visibility. | Medium | SE007, SE010 |
| CE021 | The breach clarity product page focuses on forensics across SaaS environments after identity or integration abuse. | Medium | SE006 |
| CE022 | Breach clarity is positioned to reduce mean time to innocence by helping teams separate affected from unaffected SaaS activity after a suspected incident. | Medium | SE006 |
| CE023 | The OWASP MCP Security Cheat Sheet identifies prompt injection, tool poisoning, and authorization weaknesses as core MCP risks that runtime governance must account for. | High | SE002, SE003, SE004 |
| CE024 | OWASP GenAI guidance for secure MCP server development reinforces that server-side tool definitions, input handling, and trust boundaries need explicit security design. | High | SE003, SE002 |
| CE025 | Cloud Security Alliance agentic MCP best practices emphasize least privilege, constrained tool access, and identity-aware governance for agentic tool use. | High | SE004, SE002 |
| CE026 | OWASP and CSA guidance make OAuth 2.1, authorization boundaries, and least-privilege scopes central requirements for safe MCP and agent-tool deployments. | High | SE002, SE004 |
| CE027 | PipeLab's 2026 state-of-MCP-security source describes thousands of MCP CVEs, making MCP immaturity an adverse technical risk for any vendor promising runtime protection. | Medium | SE005 |
| CE028 | Zenity raised $125 million for autonomous AI-agent security one day before Obsidian's Series D announcement, underscoring that the product category is competitive and fast-moving. | Medium | SE016 |
| CE029 | Obsidian's Series D use of proceeds is to fund R&D and extend deeper into the Fortune 500 and Global 2000. | High | SE011, SE012 |
| CE030 | The disclosed traction base includes 100-plus customers spending $100,000-plus per year, 14-plus customers spending $1 million-plus per year, and 60 Fortune 500 customers. | Medium | SE011, SE012 |
| CE031 | The founding team includes Glenn Chisholm, Ben Johnson, and Matt Wolff, giving the product organization a security-founder lineage from Cylance, Telstra, and Carbon Black backgrounds. | Medium | SE018, SE020, SE021 |
| CE032 | Craft lists Hasan Imam as current CEO, while the product and technical founder roles remain visible through Chisholm, Johnson, and Wolff. | Medium | SE019, SE018 |
| CE033 | Mordor Intelligence sizes the non-human identity security market at about $8.22 billion in 2026, supporting NHI governance as a real category lens for the product. | Medium | SE022 |
| CE034 | Research and Markets sizes the SSPM software market at about $3.69 billion in 2026, making the SSPM-to-agent-governance transition a category expansion rather than a category abandonment. | Medium | SE023 |
| CE035 | MarketsandMarkets sizes the agentic AI security market at about $1.65 billion in 2026, giving the newer agent-security wedge a narrower but high-growth category lens. | Medium | SE024 |
| CE036 | A practitioner vendor wiki provides a weak but usable public developer-signal proxy because Obsidian has no prominent open-source developer surface in this source set. | Low | SE025 |
| CE037 | Public sources support the existence of security and privacy-oriented controls, but they do not publish a module-level false-positive rate, block-rate benchmark, uptime history, or detailed policy-engine architecture. | Medium | |
| CE038 | The strongest standards fit is between Obsidian's pre-action controls and OWASP/CSA guidance on prompt-injection resilience, tool poisoning defense, least privilege, and OAuth-aware authorization. | High | SE001, SE002, SE003, SE004, SE015 |
| CE039 | The public roadmap is event-driven: SaaS supply-chain security launched in January 2026, then Series D messaging in August 2026 highlighted Claude Code and Cowork expansion. | Medium | SE007, SE010, SE011, SE012 |
| CE040 | Obsidian's product differentiation depends on connecting SaaS identity posture, agent runtime policy, MCP inventory, model registry, and breach forensics into one graph-backed control plane. | High | SE001, SE006, SE008, SE009, SE015, SE017 |
| CU001 | Obsidian publicly reports enterprise-scale traction with 100+ customers spending more than $100,000 per year, 14+ customers spending more than $1,000,000 per year, and 60 of the Fortune 500 as customers. | High | SU009, SU010, SU011, SU016 |
| CU002 | The disclosed customer base includes major financial institutions, social media networks, and telecom providers, giving at least three named vertical categories even where most logos remain undisclosed. | High | SU009, SU010, SU016 |
| CU003 | More than 70% of Obsidian customers already allow AI agents into third-party applications, which makes agent governance an active installed-base need rather than only a future-market pitch. | High | SU009, SU010, SU011 |
| CU004 | Snowflake is the strongest named customer proof in the public set because the case study gives a named customer, named security executives, a concrete use case, and quantified operating outcomes. | Medium | SU001, SU002 |
| CU005 | Snowflake uses Obsidian against an environment of 3,000 integrations, making the deployment relevant to large SaaS-to-SaaS and AI Data Cloud ecosystems rather than a small pilot. | Medium | SU001, SU002 |
| CU006 | Snowflake says Obsidian saved more than 800 engineering hours per month, one of the clearest public value-proof metrics in the customer corpus. | Medium | SU001 |
| CU007 | The Snowflake story quotes CISO Brad Jones and VP Security Mario Duarte, improving reference quality because the customer voices are senior security leaders rather than anonymous marketing blurbs. | Medium | SU001 |
| CU008 | Security MEA independently covered the Obsidian-Snowflake integration around Snowflake AI Data Cloud, providing external corroboration that the relationship is not only a private logo claim. | Medium | SU002 |
| CU009 | CB Insights lists T-Mobile, Upwork, Trade Me, and BigCommerce among Obsidian customers, adding externally curated named-logo evidence beyond the Snowflake case study. | Medium | SU003 |
| CU010 | FeaturedCustomers includes an Obsidian testimonial from a Fortune 500 bank director, supporting the financial-institution segment while also showing that some large customer identities remain anonymized. | Medium | SU004 |
| CU011 | FeaturedCustomers also cites a CSO reference describing discovery of hundreds of SaaS applications in days, a customer outcome aligned with SaaS-security-posture and application-discovery workflows. | Medium | SU004 |
| CU012 | Gartner Peer Insights shows Obsidian around 4.9 out of 5 from roughly 22 reviews, a positive satisfaction signal but one with a modest review count. | Medium | SU005 |
| CU013 | PeerSpot provides an additional enterprise review surface for Obsidian, but it does not disclose cohort retention, expansion, or customer revenue concentration. | Medium | SU008 |
| CU014 | Forrester TEI cites up to 192% ROI for a composite organization with $9 billion of revenue and 10,000 employees, making the ROI proof relevant to large-enterprise buyers but not a direct customer-specific retention metric. | Medium | SU007 |
| CU015 | Work-Management.org is an adverse customer-fit source because it says Obsidian does not cover IaaS or PaaS security posture, limiting fit for buyers seeking one platform across SaaS and cloud infrastructure. | Medium | SU006 |
| CU016 | Work-Management.org also notes dashboard flexibility limitations, an adoption risk when security teams need customized executive, operational, or compliance reporting. | Medium | SU006 |
| CU017 | Obsidian positions its product around securing AI, non-human identities, and third-party SaaS applications, which explains why enterprise security, identity, and SaaS owners are the natural buyer and user personas. | High | SU012, SU018, SU025 |
| CU018 | The company page frames the opportunity around AI adoption across more than 35,000 third-party applications, supporting the relevance of SaaS-application breadth to customer adoption. | Medium | SU018 |
| CU019 | The MCP security page says Obsidian maintains inventories of MCP servers and model usage and applies runtime governance, a concrete use case for enterprises already allowing agent access to SaaS tools. | High | SU022, SU013 |
| CU020 | Obsidian breach-clarity and forensics positioning gives a post-incident customer workflow in addition to preventive posture management, widening the possible expansion surface inside existing accounts. | Medium | SU023 |
| CU021 | Help Net Security reported Obsidian launched end-to-end SaaS supply-chain security in January 2026, supporting an integration-security expansion path for customers with many SaaS-to-SaaS connections. | Medium | SU024 |
| CU022 | Review and pricing aggregators such as Cyberse, Ciphers Security, and SaaS Tools Info show buyer-research visibility, but they are weaker proof than customer stories because they do not verify deployments or outcomes. | Medium | SU019, SU020, SU021 |
| CU023 | Obsidian has not publicly disclosed net revenue retention, gross revenue retention, churn, renewal rates, average contract length, or top-customer revenue concentration in the retained source corpus. | Medium | |
| CU024 | The specific Fortune 500 logos behind the 60-customer claim are largely undisclosed, so the public record proves enterprise reach better than it proves logo-by-logo deployment breadth. | Medium | SU003, SU004, SU009, SU010 |
| CU025 | Fourteen-plus customers spending more than $1,000,000 per year is strong expansion proof but also creates a diligence question around how much revenue depends on a small set of large accounts. | Medium | SU009, SU010, SU016 |
| CU026 | Obsidian says the Series D capital will fund R&D and extend deeper into the Fortune 500 and Global 2000, tying the financing narrative directly to enterprise-account expansion. | High | SU009, SU010, SU015, SU016 |
| CU027 | The named public evidence is uneven: Snowflake includes quantified outcomes, while T-Mobile, Upwork, Trade Me, and BigCommerce are mainly logo-list evidence without public deployment details in the retained source set. | Medium | SU001, SU003 |
| CU028 | The Fortune 500 bank director testimonial is useful customer proof but remains anonymous, preventing investors from independently checking production scope, renewal status, or account economics. | Medium | SU004 |
| CU029 | An inferred ARR floor of at least about $24 million follows from 100 customers at more than $100,000 annually plus 14 customers at more than $1,000,000 annually, while a $40-70 million range remains only analyst-estimated. | Medium | SU009, SU010, SU016 |
| CU030 | The customer proof supports real adoption across multiple segments, but it is much better at proving presence and outcomes than retention durability. | Medium | SU001, SU003, SU004, SU005, SU007, SU009 |
| CU031 | Financial institutions are the most explicitly valuable disclosed segment because they appear in the 60-Fortune-500 vertical list and in the FeaturedCustomers bank testimonial. | Medium | SU004, SU009, SU010 |
| CU032 | Telecom customer proof is directionally supported by the company-reported vertical list and by CB Insights naming T-Mobile, but public deployment scope remains undisclosed. | Medium | SU003, SU009, SU010 |
| CU033 | Social-media-network customer proof is weaker than finance and telecom proof because the vertical is company-reported but no specific social-media customer is named in the retained sources. | Medium | SU009, SU010 |
| CU034 | Snowflake, T-Mobile, Upwork, Trade Me, BigCommerce, and the anonymous Fortune 500 bank together indicate that adoption spans data platforms, telecom, workforce marketplaces, marketplaces, commerce, and banking. | Medium | SU001, SU003, SU004 |
| CU035 | The adverse Work-Management findings do not negate Obsidian customer traction, but they bound it to SaaS and AI-agent governance rather than broad cloud security posture. | Medium | SU006, SU012, SU022, SU025 |
| CU036 | Gartner and Forrester are independent, high-reputation customer-value signals, but one is a small review sample and the other is a composite model rather than disclosed account-level economics. | Medium | SU005, SU007 |
| CU037 | Snowflake saving 800+ engineering hours per month is the strongest quantified operating KPI, while 100+ $100K customers and 14+ $1M customers are the strongest monetization KPIs. | Medium | SU001, SU009, SU010 |
| CU038 | Competitive pressure from Zenity raising $125 million one day earlier could make enterprise customer acquisition more expensive or contested despite Obsidian’s disclosed Fortune 500 traction. | Medium | SU014, SU009 |
| CU039 | Hasan Imam’s background as former Chief Revenue and Customer Officer at Shape Security supports credibility for enterprise go-to-market execution, though leadership pedigree is not a substitute for retention metrics. | Medium | SU017 |
| CU040 | Overall customer quality is strong enough to validate adoption proof, but unresolved disclosure gaps around named Fortune 500 logos, retention cohorts, and concentration remain material to underwriting. | Medium | SU001, SU003, SU004, SU009, SU010, SU006 |
| CR001 | Obsidian’s top risk stack combines direct competition, native-platform commoditization, market timing, threat-model difficulty, valuation opacity, and execution dependence. | High | SR001, SR002, SR006, SR035 |
| CR002 | Zenity raised $125 million on 2026-08-03, one day before Obsidian’s $85 million Series D announcement, making direct AI-agent-security competition unusually visible at the same financing moment. | High | SR006, SR023, SR024 |
| CR003 | Obsidian’s own 2026 materials emphasize runtime governance, MCP inventory, model registry, and blocking before agent actions take effect, which are credible differentiators if they outperform platform-native controls. | High | SR002, SR005, SR026 |
| CR004 | The Salesloft/Drift OAuth breach showed that AI-chat-agent and OAuth/NHI compromise can cascade into Salesforce, AWS, and Snowflake environments, which is directly relevant to Obsidian’s SaaS and NHI security thesis. | Medium | SR030, SR032 |
| CR005 | No cited source in this chapter identifies a public lawsuit, enforcement action, or regulatory sanction against Obsidian Security itself as of the 2026-08-05 run date. | Medium | |
| CR006 | Microsoft’s 2026 research showed that prompts can become shells through RCE vulnerabilities in AI-agent frameworks, so prompt-injection defense is a product-efficacy and legal-exposure issue rather than only a market tailwind. | High | SR034, SR033 |
| CR007 | The operational failure modes most relevant to Obsidian are false negatives against prompt injection, RCE in agent frameworks, OAuth/NHI compromise, MCP-server weakness, and breach-response credibility. | Medium | SR027, SR030, SR031, SR033, SR034, SR036, SR037 |
| CR008 | Prompt injection is treated by multiple 2026 adverse sources as a leading enterprise AI-agent risk, increasing the bar for Obsidian to prove blocking efficacy against adaptive attacks. | Medium | SR033, SR037, SR036 |
| CR009 | Obsidian’s MCP and runtime-governance pages claim inventory, model registry, and pre-action blocking capabilities, but public sources do not expose independent red-team false-negative rates. | Medium | SR005, SR026, SR027 |
| CR010 | Microsoft is a platform dependency and a competitive platform risk because Copilot Studio, Defender, and native agent-security controls can absorb governance functions that third-party vendors monetize. | High | SR035, SR034 |
| CR011 | SaaS platforms and customer systems such as Salesforce, Snowflake, AWS, and third-party applications are not merely integrations; they are the environments where Obsidian must prove detection, response, and governance value. | Medium | SR001, SR029, SR030 |
| CR012 | Obsidian has not disclosed ARR, gross margin, NRR, burn, runway, or headcount publicly, leaving material underwriting risk around revenue durability and operating leverage. | Medium | |
| CR013 | The disclosed customer-spend floor implies at least about $24 million of ARR, while the fact sheet’s plausible inferred range is $40 million to $70 million; both figures are estimates, not company disclosures. | Medium | SR001, SR002 |
| CR014 | At a $1.1 billion post-money valuation, Obsidian implies roughly 15x to 45x revenue depending on the ARR assumption, creating down-round exposure if growth, retention, or category adoption disappoints. | Medium | SR001, SR025 |
| CR015 | AI-agent governance is nascent, and market reports range from broad AI-agent-security TAM to narrower agentic-AI and NHI lenses, so adoption timing is a central model risk. | Medium | SR013, SR014, SR015, SR016 |
| CR016 | The clearest kill criteria are independent proof of weak product efficacy, native-platform displacement, poor ARR/NRR disclosure, stalled enterprise adoption, or valuation reset below the Series D price. | Medium | SR025, SR035, SR026 |
| CR017 | Diligence should request ARR, NRR, gross margin, burn, runway, headcount, product efficacy tests, incident-response proof, and customer concentration before treating the $1.1 billion price as de-risked. | Medium | SR001, SR025, SR026, SR029 |
| CR018 | The regulatory and legal risk register should rank privacy/OAuth breach exposure and agent-framework vulnerabilities above generic litigation risk because public evidence supports the threat pattern but not a current Obsidian legal proceeding. | Medium | SR030, SR034, SR036 |
| CR019 | The threat-landscape table should prioritize prompt injection, RCE, MCP weakness, OAuth/NHI compromise, and native-control displacement because each is evidenced by 2026 sources and maps to Obsidian’s claimed control surface. | Medium | SR027, SR030, SR033, SR034, SR035, SR036, SR037 |
| CR020 | Partner and competitive pressure includes Microsoft native controls, Zenity, Grip, Push, Nudge, Valence, AppOmni, Salesforce/Snowflake exposure, and dependence on SaaS application APIs. | Medium | SR006, SR018, SR019, SR020, SR021, SR022, SR035 |
| CR021 | Public leadership evidence verifies founder-heavy technical depth from Glenn Chisholm, Ben Johnson, and Matt Wolff plus a non-founder CEO, Hasan Imam, with Shape Security go-to-market background. | Medium | SR009, SR010, SR012 |
| CR022 | A monitorable trigger is Microsoft or Salesforce bundling sufficient native controls into enterprise seats to make third-party runtime governance a feature rather than a platform budget line. | Medium | SR035, SR005 |
| CR023 | The risk heatmap should place native-platform commoditization, valuation opacity, and prompt-injection/RCE efficacy in the high-impact band because each can affect revenue relevance and valuation simultaneously. | Medium | SR025, SR033, SR034, SR035 |
| CR024 | Threat and platform risks transmit into valuation through customer trust, enterprise procurement, gross margin, renewal durability, and follow-on financing terms. | Medium | SR001, SR025, SR029, SR030, SR035 |
| CR025 | The dependency map should include Microsoft, Salesforce/Snowflake/AWS environments, Zenity and adjacent vendors, AI-agent frameworks, MCP servers, investors, and Fortune 500 enterprise buyers. | Medium | SR001, SR006, SR023, SR026, SR030, SR035 |
| CR026 | Obsidian reports 100+ customers spending at least $100,000 annually, 14+ customers spending at least $1 million annually, and 60 Fortune 500 customers. | High | SR001, SR002, SR003 |
| CR027 | The same disclosed spend metrics imply customer concentration risk because at least 14 large accounts can account for a material share of estimated ARR. | Medium | SR001, SR002 |
| CR028 | Obsidian says 70%+ of its customers already allow AI agents into third-party applications, supporting market urgency but also indicating that adoption risk sits at governance maturity rather than agent awareness alone. | Medium | SR001, SR002 |
| CR029 | Obsidian cites a 144:1 ratio of non-human identities to human identities in third-party applications, which underpins the NHI-risk thesis and the risk of unmanaged OAuth/application credentials. | Medium | SR001, SR011 |
| CR030 | Obsidian’s January 2026 SaaS supply-chain security launch shows the company broadened from SSPM into SaaS-to-SaaS integration protection before emphasizing AI-agent governance in August 2026. | Medium | SR028, SR002 |
| CR031 | Grip’s competitive material claims broader shadow-SaaS and automated remediation capability versus Obsidian, which is adverse evidence for differentiation in SaaS governance. | Medium | SR019 |
| CR032 | Comparison sources place Push, Nudge, Grip, and Obsidian in overlapping SaaS and identity-security buying conversations, so category crowding is already visible outside AI-agent-only messaging. | Medium | SR018, SR020, SR021, SR022 |
| CR033 | Zenity’s disclosed 230+ employees and $125 million Series C create execution-pressure risk because it can fund enterprise sales, research, and platform partnerships aggressively. | Medium | SR023, SR006 |
| CR034 | Microsoft’s native security blog frames AI tools as moving from reading to acting, and that framing competes with Obsidian’s attempt to own runtime enforcement vocabulary. | High | SR035, SR005 |
| CR035 | OWASP’s MCP guidance treats prompt injection, tool poisoning, OAuth 2.1, and least privilege as baseline controls, which may commoditize parts of Obsidian’s control narrative over time. | Medium | SR027, SR026 |
| CR036 | Beam AI’s 2026 breach examples and Token Security’s OAuth breach analysis both show that incident stories are plentiful, but customers will still require proof that a specific vendor can stop them in production. | Medium | SR030, SR031 |
| CR037 | Security Boulevard’s CISO playbook confirms buyer awareness around AI-agent identity management, but awareness does not by itself prove budget timing or renewal quality for Obsidian. | Medium | SR032, SR013, SR014 |
| CR038 | The $85 million Series D led by Crescent Cove with all existing investors participating reduces near-term financing risk but also raises the performance hurdle implied by unicorn pricing. | High | SR001, SR002, SR008 |
| CR039 | Founder-heavy product and technical leadership is a strength, but it creates key-person and roadmap-prioritization risk if the pivot from SSPM to AI-agent governance requires different sales and platform-execution muscles. | Medium | SR009, SR010, SR012, SR030 |
| CR040 | Snowflake’s customer story supports enterprise credibility, but public customer proof does not disclose renewal rates, NRR, contract concentration, or willingness to pay specifically for AI-agent governance. | Medium | SR029, SR001 |
| CR041 | State-of-Surveillance’s CVE-2026-2256 coverage and Microsoft’s RCE research make MCP and agent-framework vulnerability management a current 2026 risk rather than a hypothetical future issue. | Medium | SR036, SR034 |
| CR042 | Overall residual risk remains high because Obsidian’s market driver and product test are the same: enterprises face severe agent/NHI threats, but Obsidian must prove it can block them better than platforms and peers. | Medium | SR001, SR006, SR030, SR033, SR034, SR035 |
| CV001 | Obsidian announced an $85 million Series D on 2026-08-04 at a $1.1 billion post-money valuation led by Crescent Cove Advisors. | High | SV012, SV013, SV019 |
| CV002 | All existing investors participated in the Series D, including Greylock Partners, Menlo Ventures, Norwest Venture Partners, IVP, Wing, and GV. | High | SV012, SV013, SV019, SV021 |
| CV003 | The Series D was a priced primary round with existing investors returning alongside new lead Crescent Cove, a financing structure that shapes dilution, preference-overhang, and entry-discipline analysis for a late-stage buyer. | High | SV012, SV013, SV023 |
| CV004 | The company reported 100+ customers spending at least $100,000 annually, 14+ customers spending at least $1 million annually, and 60 Fortune 500 customers. | High | SV012, SV013, SV018 |
| CV005 | Obsidian also reported that more than 70% of its customers already permit AI agents into third-party applications. | High | SV012, SV013, SV016 |
| CV006 | Obsidian says non-human identities outnumber human identities 144:1 inside third-party applications. | High | SV012, SV013, SV022 |
| CV007 | Public sources do not disclose Obsidian ARR, revenue, gross margin, NRR, burn, runway, or headcount. | Medium | SV012, SV013, SV020, SV029 |
| CV008 | Using the canonical disclosed spend floor of 100 customers at $100,000 plus 14 customers at $1 million implies at least about $24 million of ARR, but this is an analyst inference rather than company disclosure. | Medium | SV012, SV013, SV018 |
| CV009 | A plausible underwriting range of roughly $40 million to $70 million ARR remains an estimate because the company has not publicly bridged customer counts to contracted recurring revenue. | Medium | SV012, SV013, SV030 |
| CV010 | At $50 million of estimated ARR, the $1.1 billion valuation implies about 22.0x ARR. | Medium | SV001, SV012, SV013 |
| CV011 | At the approximately $24 million ARR floor, the $1.1 billion valuation implies about 45.8x ARR, rounded to roughly 46x. | Medium | SV001, SV012, SV013 |
| CV012 | At $70 million of estimated ARR, the $1.1 billion valuation implies about 15.7x ARR. | Medium | SV001, SV012, SV013 |
| CV013 | Windsor Drake frames public cyber software at roughly 6-8x NTM revenue, cloud or AI-native leaders at roughly 14-22x, private cyber around 15.2x, and cloud M&A as high as 35x. | Medium | SV001, SV002 |
| CV014 | CrowdStrike is cited at about 25.1x EV/Revenue, with FY26 revenue of about $4.81 billion and ARR of about $5.25 billion. | High | SV002, SV003, SV005 |
| CV015 | Zscaler is cited at about 11.7x EV/Revenue, with TTM revenue of about $3.17 billion and market capitalization around $25 billion. | High | SV002, SV004 |
| CV016 | The same public comp set cites Palo Alto Networks around 15x, Cloudflare around 31.5x, Fortinet around 8.7x, and Okta around 5x EV/Revenue. | Medium | SV001, SV002 |
| CV017 | Google closed its $32 billion acquisition of Wiz in March 2026, and Wiz had more than $1 billion of ARR by 2025. | High | SV006, SV009, SV010 |
| CV018 | Cyera reportedly eyed a $12 billion valuation at an 80x ARR multiple despite operating losses, making it the clearest adverse froth signal in the comparable set. | High | SV007, SV001, SV030 |
| CV019 | NinjaOne reached a roughly $12.3 billion private valuation while reportedly combining about 70% growth with profitability, making it a premium-growth comp with stronger fundamentals framing. | Medium | SV008, SV001 |
| CV020 | Palo Alto Networks and CyberArk created a $25 billion strategic M&A reference point for identity-security consolidation. | Medium | SV010, SV009, SV011 |
| CV021 | Cybersecurity M&A reached roughly $92-96 billion in 2025, and 2026 consolidation coverage cited more than 190 cyber M&A deals by mid-year. | Medium | SV009, SV010, SV011 |
| CV022 | Finro-type valuation framing warns that private cyber medians near 15.4x ARR and down-round compression near 10-13x expose Obsidian to ARR-gap risk. | Medium | SV030, SV001 |
| CV023 | Zenity raised $125 million one day before Obsidian, which supports category demand but weakens scarcity-premium arguments for Obsidian. | Medium | SV017, SV029 |
| CV024 | AI Agent Security is estimated around $26 billion in 2026 with about 39% CAGR to 2035, supporting a large-market leg of the bull case. | Medium | SV025, SV028 |
| CV025 | NHI security is estimated around $8.22 billion in 2026, while agentic AI security is estimated around $1.65 billion in 2026, showing both broad and narrow TAM lenses. | Medium | SV026, SV028 |
| CV026 | Research and Markets puts SSPM at about $3.69 billion in 2026, which reinforces the legacy SaaS-security part of Obsidian’s addressable market. | Medium | SV027, SV026 |
| CV027 | Obsidian’s runtime governance, MCP inventory, and AI-agent permission controls support a thesis that it is moving beyond legacy SSPM into AI-agent governance. | High | SV013, SV015, SV016 |
| CV028 | The investment thesis is that Obsidian combines a newly urgent AI-agent/NHI security problem, visible Fortune 500 traction, and a strong investor syndicate. | Medium | SV012, SV013, SV021, SV025 |
| CV029 | The anti-thesis is that the company is private and financially opaque, the category is nascent, Zenity is well funded, and platform vendors may compress pricing power. | Medium | SV017, SV030, SV012, SV013 |
| CV030 | The most supportable recommendation is track rather than buy because product and market evidence are strong, but public financial evidence does not yet support unconditional conviction at $1.1 billion. | Medium | SV012, SV013, SV030, SV001 |
| CV031 | Confidence should be medium because the chapter can bracket valuation ranges, but cannot verify ARR, growth, margin, retention, or cap-table rights from public evidence. | Medium | SV012, SV013, SV020, SV030 |
| CV032 | Risk rating should be high because the valuation depends on a growth-premium ARR assumption in a competitive and still-forming category. | Medium | SV017, SV025, SV030, SV001 |
| CV033 | The valuation stance is stretched because the Series D price is near premium cloud/AI leader bands if ARR is high and far above median or down-round bands if ARR is near the floor. | Medium | SV001, SV007, SV030, SV012 |
| CV034 | A bull case can defend roughly $1.3-1.8 billion if ARR is near $70 million, growth remains high, and investors accept premium 19-25x cyber multiples. | Medium | SV001, SV002, SV012, SV013 |
| CV035 | A base case supports roughly $0.6-1.1 billion if ARR is around $40-50 million and investors use a 15-22x range after applying an opacity discount. | Medium | SV001, SV030, SV012, SV013 |
| CV036 | A bear case supports roughly $0.2-0.5 billion if ARR is near the $24 million floor and the relevant multiple compresses toward 8-13x. | Medium | SV001, SV030, SV012, SV013 |
| CV037 | A buy case would require proof that ARR is already above roughly $50 million, revenue growth is durable, gross margin is software-like, retention is strong, and preferences are not punitive. | Medium | SV001, SV012, SV013, SV030 |
| CV038 | The first thesis-break trigger is audited ARR below roughly $40 million or evidence that the $24 million floor is close to current reality. | Medium | SV012, SV013, SV030 |
| CV039 | The second thesis-break trigger is evidence that top customers, especially the 14 accounts above $1 million, create concentration or renewal risk that undermines premium multiple support. | Medium | SV012, SV013, SV030 |
| CV040 | The third thesis-break trigger is AI-agent security budget consolidation toward Microsoft or another platform vendor rather than independent vendors such as Obsidian. | Medium | SV017, SV016, SV025 |
| CV041 | The fourth thesis-break trigger is public or private cybersecurity multiple compression below the median bands used to justify the Series D mark. | Medium | SV001, SV002, SV030 |
| CV042 | Final diligence should request audited ARR, ARR bridge from disclosed customer tiers, gross margin, burn, NRR, GRR, cohort retention, headcount, and customer concentration. | Medium | SV012, SV013, SV030 |
| CV043 | Final diligence should also request the capitalization table, liquidation preferences, participation rights, option-pool changes, pro rata rights, and side letters before modeling investor return. | Medium | SV019, SV020, SV030 |
| CV044 | The bottom-line valuation judgment is rich but defensible only if ARR is already high; otherwise the $1.1 billion Series D is stretched relative to public and private cyber comps. | Medium | SV001, SV002, SV007, SV012, SV030 |