Obsidian Security
Obsidian 在 AI 智能体治理里已经站到真正有望定义品类的位置,也拿到了 $1.1B 独角兽估值;但在竞争快速拥挤的市场里,这个估值靠的是估算 ARR,而不是已披露 ARR。
Obsidian 在新兴 AI 智能体治理市场有真实品类领先地位,也已确认 $1.1B 独角兽估值;但估值依赖估计而非披露 ARR,赛道又快速拥挤,因此更适合继续观察,而不是按高信心价格出手。
封面要素
公司概况
Obsidian Security 是一家总部位于加州 Palo Alto 的网络安全公司,成立于 2017 年,已从 SaaS 安全态势管理(SSPM)延伸到面向企业第三方 SaaS 应用中的 AI 智能体和非人身份的运行时治理与安全,覆盖 Microsoft 365、Salesforce、Workday 等。2026 年 8 月,公司完成由 Crescent Cove Advisors 领投的 $85 million Series D,投后估值 $1.1 billion,累计融资超过 $200 million。公司披露的商业化进展包括超过 100 个年付超过 $100,000 的客户、超过 14 个年付超过 $1 million 的客户,以及 60 个 Fortune 500 客户,但当前收入、ARR、利润率、留存和员工数未公开。
- 成立时间
- 2017-01-01
- 创始人
- Glenn Chisholm, Ben Johnson, Matt Wolff
- 创立地点
- Newport Beach, California, USA
- 总部
- Palo Alto, California, USA
- 产品
- Obsidian 销售的平台可发现并治理第三方 SaaS 应用中的非人身份和 AI 智能体,提供运行时治理,检测并阻断权限升级、过度数据访问和策略违规;还覆盖 MCP 资产清点、模型注册表、SaaS 供应链安全以及入侵厘清/取证。
- 客户
- 大型企业和 Fortune 500 组织,尤其是金融机构、社交媒体和电信公司;这些客户运行大量第三方 SaaS 应用,AI 智能体和非人身份快速增加。
- 商业模式
- 按受保护身份和应用范围计价的经常性企业 SaaS 订阅,客户年付额从六位数到七位数分层。
- 阶段
- Late-stage private (Series D unicorn)
- 融资情况
- 最新定价轮是 2026 年 8 月 4 日的 $85 million Series D,投后估值 $1.1 billion,由 Crescent Cove Advisors 领投,Greylock Partners、Menlo Ventures 等既有投资人参投;公司五轮累计融资超过 $200 million。Hasan Imam 担任 CEO,并非已披露创始人之一。
执行摘要
主要优势
- Obsidian 在第三方 SaaS 平台上的运行时 AI 智能体与非人身份治理起步早、差异化明确;这是一个市场预测规模大、增长快的新品类。
- 公司披露的阶段性牵引力很强:100 多家客户年花费超过 $100K,14 多家超过 $1M,另有 60 家 Fortune 500 客户,并有 Snowflake 等具名背书。
- 公司完成估值 $1.1B 的 $85M Series D 后资本充足,投资方包括 Crescent Cove、Greylock、Menlo、Norwest、IVP 等蓝筹机构,累计融资超过 $200M。
主要风险
- $1.1B 估值大约对应估计 $50M ARR 的 22 倍、披露约 $24M 消费下限的 46 倍,因此定价依赖未经验证的高增长 ARR 假设。
- 竞争正在升温:直接对手 Zenity 早一天宣布累计融资 $125M,Grip、Push、Nudge、Valence、AppOmni 等也在挤压差异化和定价权。
- Microsoft、Salesforce、Google 正在内嵌原生智能体安全控制,平台商品化风险不小,可能侵蚀 Obsidian 独立产品价值。
- AI 智能体治理品类还很早,采用节奏并不确定;从 SSPM 转向智能体,是押注一个可能比预测更慢成熟的市场。
未决问题
- 需要审计 ARR、收入运行率、增长率,以及从已披露客户消费分层推导 ARR 的桥接。
- 需要毛利率、净收入留存率、流失率和客户集中度数据,以证明可持续的经常性收入经济性。
- 需要披露烧钱速度、现金跑道和员工数,以评估资本效率和执行能力。
- 需要确认总部(Palo Alto 还是旧 Newport Beach),并在总量统计之外提供更清晰的具名 Fortune 500 客户证据。
目录
01公司概览
1.1 身份、总部与品类定位
Obsidian Security 最适合被锚定为一家总部位于加州 Palo Alto、成立于 2017 年的私营网络安全公司;当前定位是为企业第三方 SaaS 应用中的 AI 智能体和非人身份提供运行时治理。Palo Alto 总部应作为当前标准字段,因为最新的 2026 年 8 月融资报道反复使用 California/Palo Alto 口径;暗示 Newport Beach 的旧资料并非完全忽略,但证据更弱且明显过时,应作为显性证据缺口,而不是主要身份信息。商业模式也已越过早期 SSPM 叙事。当前官方和独立报道都把 Obsidian 描述为帮助安全团队盘点 AI 智能体、MCP 服务器、模型、非人身份和策略违规,并在动作生效前介入。也就是说,公司是后期 AI 智能体治理供应商,而不是一款旧式 SaaS 态势管理工具。[CO001, CO002, CO003, CO009, CO010, CO028]
| 指标 | 数值 / 状态 | 日期 | 置信度 | 缺口 |
|---|---|---|---|---|
| 公司身份 | Obsidian Security, Inc.;非上市网络安全厂商 | 2026-08-05 | 高 | 公开来源集中没有法律实体文件 |
| 总部 | Palo Alto, California | 2026-08-04 | 高 | 早期 Newport Beach 差异需要核对 |
| 成立时间 | 2017 | 2017 | 中 | 公开来源集中没有注册证书 |
| 阶段 | 非上市 Series D 轮独角兽 | 2026-08-04 | 高 | 没有公开股权结构或优先权条款 |
| 最新轮次 | $85M Series D 轮 | 2026-08-04 | 高 | 未披露二级交易 / 债务细节 |
| 最新估值 | $1.1B 投后 | 2026-08-04 | 高 | 无法验证收入倍数 |
| 累计融资 | 五轮融资合计超过 $200M | 2026-08-04 | 高 | 超过 $200M 的精确累计金额未披露 |
| 支出 $100K+ 的客户 | 100+ 个客户 | 2026-08-04 | 高 | 公司披露,未审计 |
| 支出 $1M+ 的客户 | 14+ 个客户 | 2026-08-04 | 高 | 潜在客户集中度未知 |
| Fortune 500 客户 | 60 | 2026-08-04 | 高 | 具名客户列表未完全公开 |
| NHI 比例 | 第三方应用中非人类与人类身份比例为 144:1 | 2026-08-04 | 高 | 方法论和样本未披露 |
| 收入 / ARR | 2026-08-05 | 中 | 未公开披露;只能支撑推导出的约 $24M 下限 | |
| 员工数 | 2026-08-05 | 中 | 未公开披露 |
快照使用 2026 年 8 月来源集中的准确公开数字;null 表示没有公开披露,唯一 ARR 数据点是窄口径估算,不是公司披露的 ARR。
[CO001, CO002, CO003, CO011, CO012, CO015]商业逻辑把 SaaS 可见性、NHI 清单、运行时执行、企业牵引和增长资本串起来。
[CO009, CO022, CO027, CO028, CO034, CO046]公开 KPI 呈现出后期牵引力,但收入、ARR 和员工数仍未披露。
~$24M ARR 下限来自披露支出门槛的计算,不是报告 ARR;本章未使用其他收入值。
[CO011, CO012, CO015, CO019, CO020, CO021]1.2 创始人、领导层与治理披露
创始人是 Glenn Chisholm、Ben Johnson 和 Matt Wolff;Hasan Imam 不应被描述为创始人。这个区分重要,因为尽调故事在产品和技术可信度上由创始人支撑,但 CEO 席位由职业运营者主导。Chisholm 仍以联合创始人、董事长兼首席产品官身份露出;Johnson 和 Wolff 则提供与 Carbon Black、Cylance 经历相连的 CTO 和首席科学家血统。Imam 带来 Shape Security 的商业化和客户领导经验,Norwest 将其关联到约 $1 billion 的 F5 退出,他也是最新 Series D 叙事中被引用的高管。公开领导层目录支持当前 CEO 字段,但没有解决董事会构成、观察员权利、委员会结构或投资人控制。因此,治理尽调应盯住董事会材料、继任计划,以及创始人的产品权和非创始人 CEO 权限是否划分清楚。[CO004, CO005, CO006, CO007, CO008, CO029]
| 人物 | 职位 | 背景 | 职能覆盖 | 关键人依赖 | 证据基础 |
|---|---|---|---|---|---|
| Glenn Chisholm | 联合创始人、董事长兼首席产品官 | Cylance 前 CTO;Telstra 首任 CISO | 产品愿景、SaaS / AI 安全叙事、创始人可信度 | 高 | StartupHub 及所有权 / 个人资料来源 |
| Ben Johnson | 联合创始人兼 CTO | Carbon Black 联合创始人,后被 VMware 收购 | 技术架构和端点安全领域的创始人-市场匹配 | 高 | 所有权 / 个人资料来源及公司简介背景 |
| Matt Wolff | 联合创始人兼首席科学家 | Cylance 前首席数据科学家 | 数据科学、行为分析和检测科学 | 中高 | StartupHub / 所有权资料背景 |
| Hasan Imam | 首席执行官,非创始人 | F5 退出交易前,曾任 Shape Security 首席营收 / 客户官 | 商业化扩张、企业客户运营、融资发声 | 高 | D 轮公告、Craft 和 Norwest |
| 公开董事会 | 未完全披露 | 投资人代表和观察员未公开逐一列明 | 治理监督、控制和接班规划 | Unknown | 留存公开来源均未覆盖 |
领导层枚举不完整,因为公开来源能验证创始人 / CEO 事实,但没有披露完整董事会或完整组织架构。
[CO003, CO004, CO005, CO006, CO007, CO008]1.3 融资历史、投资人基础与规模指标
融资记录很强,但披露仍有限。Greylock 领投最早的 Series A,Norwest 领投 2021 年 6 月 Series B-1;Menlo Ventures、Norwest 和 IVP 领投 2022 年 4 月 $90 million Series C,当时累计融资达到 $119.5 million。2026 年 8 月 4 日 Series D 新增 $85 million,估值 $1.1 billion,由 Crescent Cove Advisors 领投,并包括 Greylock、Menlo、Norwest、IVP、Wing、GV 等既有投资人。轮后,Obsidian 披露五轮累计融资超过 $200 million。规模证据同样亮眼,但来自公司自述:超过 100 个客户年付超过 $100,000,超过 14 个客户年付超过 $1 million,60 家 Fortune 500 公司为客户。这些门槛有用,因为它们建立了真实企业付费下限,但仍未揭示客户集中度、折扣、续约质量、扩张队列或总留存。收入、ARR、NRR、毛利率、现金消耗、资金可支撑月数和员工数均未披露,所以这里唯一的 ARR 数字,是根据已披露付费门槛刻意保守估出的约 $24 million 下限。[CO011, CO012, CO013, CO014, CO015, CO016]
| 利益相关方 | 角色 | 控制权或经济重要性 | 尽调要求 | 证据基础 |
|---|---|---|---|---|
| Crescent Cove Advisors 与 Jun Hong Heng | Series D 领投方 | 以 $1.1B 估值进入的新领投人,可能持有最新优先权条款 | 索取投资条款清单、清算优先权、按比例跟投权、董事 / 观察员权利 | 公司公告及独立 D 轮报道 |
| Greylock Partners | Series A 领投方和重复投资人 | 最早的机构验证和持续参与 | 确认初始持股、储备金和董事会历史 | Greylock 投资组合及 D 轮参与报道 |
| Norwest Venture Partners | Series B-1 领投方和 Series C 共同领投方 | 与 CEO 有关系且有多轮历史的长期投资人 | 厘清当前治理角色和跟投经济权益 | Norwest 博客及 D 轮报道 |
| Menlo Ventures | Series C 共同领投方和重复投资人 | 2026 转向前的后期网络安全 / SaaS 验证 | 复核 Series C 条款和当前持股 | Series C 报道及 D 轮参与报道 |
| IVP | Series C 共同领投方和重复投资人 | 成长阶段财团信号,支撑未来退出可选性 | 确认董事 / 观察员参与和按比例跟投状态 | Series C 和 Series D 报道 |
| Wing 和 GV | 最新财团中的现有投资人 | 围绕企业安全和 AI 基础设施的战略 / VC 可信度 | 了解持股、战略权利和客户 / 渠道价值 | D 轮报道和投资人名单报道 |
| Fortune 500 客户群 | 商业利益相关方群体 | 60 家 Fortune 500 客户和 14+ 个七位数账户可能带来集中度风险 | 索取客户标识列表、ARR 桥、续约同期群和集中度明细表 | D 轮报道和公司声明 |
这不是股权结构表;它映射经济上重要的利益相关方,这些主体的确切持股、优先权和控制权未公开披露。
[CO013, CO014, CO016, CO017, CO018, CO019]1.4 里程碑时间线与竞争背景
时间线显示,公司借 SSPM 时代的投资人背书,快速切到 AI 智能体治理窗口。耐久基础是 2017 年创立,随后是 2021 年 6 月 Norwest 领投的 Series B-1,以及 2022 年 4 月 $90 million Series C;彼时公司仍被描述为 SSPM 领导者。2026 年证据把叙事重置到 AI 智能体、MCP 资产清点、运行时控制、Fortune 500 渗透和独角兽 Series D。反向提示不是内部丑闻,而是竞争时点。直接的 AI 智能体安全竞争者 Zenity,在 Obsidian 披露自身 $85 million 融资前一天宣布了更大的 $125 million 轮次。这不抵消 Obsidian 的客户和投资人信号,但意味着里程碑记录应读作参与一场正在升温的品类抢地,而不是独占品类。这个区分应作为共同事实,贯穿后续市场、产品、客户、财务、风险和估值章节。[CO031, CO032, CO034, CO045, CO046, CO047]
| 日期 | 事件 | 类型 | 金额 / 估值 / 状态 | 参与方 | 含义 |
|---|---|---|---|---|---|
| 2017 | Obsidian Security 创立 | 创立 | 经营层面创立年份 | Glenn Chisholm、Ben Johnson 和 Matt Wolff | 确立创始人组合和公司年龄 |
| 2021-06 | Norwest 领投 Series B-1 | 融资 | 留存来源集中未公开具体金额 | Norwest Venture Partners;Obsidian | 标志着 SSPM 时代的机构化增长融资 |
| 2022-04 | Series C 完成 | 融资 | $90M;累计融资 $119.5M | Menlo Ventures、Norwest、IVP、Greylock、Wing 和 GV | 确立转向前的后期 SSPM 可信度 |
| 2026-08-03 | Zenity 宣布更大规模 AI 智能体安全融资 | 反向 | $125M 竞争对手轮次 | Zenity;竞争对手报道中的 Norwest 领投财团 | 说明在 Obsidian 公布前,该品类已获得密集融资 |
| 2026-08-04 | Series D 公布 | 融资 | $85M,估值 $1.1B | Crescent Cove;现有投资人 | 形成独角兽状态和 >$200M 融资叙事 |
| 2026-08-04 | 企业级规模指标披露 | 规模 | 100+ 个 $100K 客户;14+ 个 $1M 客户;60 家 Fortune 500 | Obsidian 客户群 | 显示牵引力,也提出集中度问题 |
| 2026-08-04 | 产品叙事从 SSPM 延伸到 AI 智能体运行时治理 | 产品 | AI 智能体、NHI 治理、Claude Code / Cowork 扩展 | Obsidian 产品和安全团队 | 重塑品类和募资用途论点 |
| 2026-08-05 | 与 OWASP 对齐的运行时治理覆盖出现 | 监管 | MCP 清单、模型注册表、运行时阻断、OWASP 标准 | FinTech Global;Obsidian | 把产品控制项连接到新兴 AI 智能体安全标准 |
时间线覆盖授权 CH1 / 共享来源集中的重要公开里程碑;私有发布和未披露融资可能缺席。
[CO003, CO011, CO012, CO013, CO014, CO015]Obsidian 从 2017 年成立、SSPM 融资一路走到 2026 年 AI 智能体治理独角兽融资;同一时期, 直接竞争对手融资压力逼近。
[CO003, CO011, CO012, CO016, CO017, CO031]1.5 图表
02市场分析
2.1 市场边界与纳入支出
不应把所有可贴上 AI 标签的网络安全或态势管理支出都计入 Obsidian 的市场规模。工作边界是企业第三方 SaaS 与 AI 智能体治理:自动化智能体的运行时控制、非人身份安全、SSPM、SaaS-to-SaaS 集成风险,以及部分类似 ITDR 的身份检测工作流。纳入的支出,是用于发现智能体和集成、映射权限、监控行为、阻断过度数据访问,并证明跨 SaaS 应用策略合规的预算。排除的支出包括广义云态势管理、端点安全、通用数据态势管理,以及从不触达第三方 SaaS 智能体的原生平台控制。现状很重要,因为许多企业仍靠人工 SaaS 审查、IdP 原生控制、表格审批,或 Microsoft、Salesforce 等应用平台内置设置。市场有吸引力,因为 Obsidian 可以指向每 1 个人类身份对应 144 个非人身份、以及超过 35,000 个第三方应用;但正因为范围很宽,更需要纪律,不能把每一美元相邻 SPM 支出都算作可服务市场。[CM005, CM006, CM007, CM021, CM022, CM023]
| 细分 / 品类 | 纳入支出 | 排除支出 | 买方 / 付款方 | 相关性 |
|---|---|---|---|---|
| AI 智能体运行时治理 | 智能体清单、策略设计、运行时阻断、模型 / 工具可见性 | 没有安全控制的通用 AI 生产力软件 | CISO、AI 平台负责人、安全运营 | Obsidian 核心品类和主要 TAM 链接 |
| 非人类身份安全 | 发现、权限审查、密钥 / 服务账户控制、特权 NHI 监控 | 仅面向人的 IAM、没有 NHI 范围的员工 SSO 席位 | 身份安全、IAM、CISO | 主要 SAM 锚点,因为 NHI 是运行实体 |
| SSPM / SaaS 治理 | 错误配置检测、SaaS 到 SaaS 集成控制、应用权限态势 | SaaS 之外的云基础设施态势和端点态势 | SaaS 应用负责人、安全工程 | Obsidian 传统基础和当前买方桥梁 |
| ITDR 邻近市场 | 身份威胁检测、可疑身份行为、响应工作流 | 完整 IAM 替换或与 SaaS 身份无关的端点检测 | SOC、IAM、威胁检测团队 | 预算邻近,但不能完全计入 SAM |
| 广义 SPM 邻近市场 | CSPM、DSPM、ISPM,以及连接到 SaaS 智能体时的 DSPM 类态势分析 | 没有第三方 SaaS 或智能体执行路径的态势品类 | CISO、云安全、数据安全 | 有助于理解背景,但排除在直接 SAM 外 |
| 现状替代方案 | 手工访问审查、IdP 原生规则、电子表格、原生平台治理 | 专用第三方运行时智能体控制平台 | 安全运营、应用管理员 | 在风险变急前限制采用和定价 |
边界行定义与 Obsidian 相关的支出;广义 SPM 有意作为邻近市场呈现,而不是完全可服务市场。
[CM021, CM022, CM023, CM028, CM035, CM036]2.2 TAM、SAM 与 SOM 测算口径
最有防守性的漏斗顶端 TAM,是 2026 年 AI Agent Security 约 $26 billion 的估算,因为 Obsidian 明确销售 AI 智能体安全和运行时治理。但这个数字不应直接进入收入假设。更窄的 SAM 应锚定 NHI Security 和 SSPM,因为这些品类对应身份、SaaS 权限、第三方集成和治理工作流。以约 $8.22 billion 的 NHI Security 和约 $3.69 billion 的 SSPM 为基础,并扣除重叠后,2026 年实际 SAM 区间约为 $8 billion–$12 billion。$1.65 billion 的窄口径 Agentic AI Security 估算,可作为新生智能体专项控制的下限视角;$3.42 billion 的 ITDR 是相邻项,而不是可直接相加项。SOM 小得多:已披露客户意味着约 $24 million ARR 下限,当前 ARR 合理区间约为 $40 million–$70 million。因此,在管理层提供 ARR、NRR、细分结构和销售管线转化前,近期可获得市场应框定在约 $50 million–$150 million。[CM001, CM002, CM003, CM008, CM009, CM010]
| 发布方 / 视角 | 年份 | 地理范围 | 数值 | CAGR | 方法论 / 注意事项 | 置信度 | 局限 |
|---|---|---|---|---|---|---|---|
| SNS Insider AI 智能体安全 | 2026 | 全球 | ~$26.0B | 39.1% 至 2035 年 | 广义 AI 智能体安全 TAM;最适合 Obsidian 定位的标题品类 | 中 | 商业分析机构分类法可能包含 Obsidian 不销售的控制项 |
| MarketsandMarkets 智能体式 AI 安全 | 2026 | 全球 | ~$1.65B | 42% 至 2032 年 | 较窄的智能体安全视角;可作为智能体专用控制项的下限 | 中 | 可能排除更广的 NHI 和 SSPM 支出 |
| Mordor Intelligence NHI 安全 | 2026 | 全球 | ~$8.22B | 22.78% 至 2031 年 | 面向机器和服务身份的身份中心安全 | 中 | 并非所有 NHI 支出都发生在第三方 SaaS 应用内 |
| Research and Markets 的 SSPM 预测 | 2026 | 全球 | ~$3.69B | 12.6% 至 2032 年 | SaaS 安全态势管理软件视角 | 中 | 与 Frost 基线冲突,且可能包含非智能体 SSPM |
| Frost & Sullivan SSPM | 2025→2030 | 全球 | $0.484B → $3.53B | 48.7% | 基线小得多但增长更快;反向不确定性输入 | 中 | 付费墙来源,分类法不同于 Research and Markets |
| Mordor Intelligence ITDR | 2026→2031 | 全球 | $3.42B → $10.51B | 25.17% | 运行时身份安全的身份威胁检测邻近市场 | 中 | 邻近市场,Obsidian 不能完全服务 |
| InsightAce 广义 SPM | 2025/2026 | 全球 | ~$26.35B | n/a | 跨多个态势类别的广义安全态势管理邻近市场 | 低中 | 如果把 CSPM / DSPM 全量计入,会高估 Obsidian |
| 内部 SAM 视角 | 2026 | 全球 / 企业级 SaaS 加权 | ~$8B–$12B | n/a | NHI 加 SSPM 与窄口径智能体重叠,并扣除重复计算 | 低 | 需要管理层提供产品组合和买方预算数据 |
| 内部 SOM 视角 | 2026 年近期 | 企业客户 | ~$50M–$150M | n/a | 由 100+ 个 $100K 客户、14+ 个 $1M 客户和推导 ARR 区间得出 | 低 | ARR、NRR、流失和管线转化未披露 |
除非另有说明,所有数值均为美元;SAM 和 SOM 行是基于引用市场与客户披露作出的尽调推导,不是发布方预测。
[CM008, CM009, CM010, CM011, CM012, CM013]$26B 的 AI 智能体安全 TAM 收窄为估算 $8B–$12B SAM,以及 Obsidian 近期可获得的 $50M–$150M SOM。
SAM 和 SOM 是尽调估算;只有 TAM、NHI、SSPM 和狭义智能体安全输入来自出版方报告。
[CM008, CM009, CM010, CM011, CM015, CM016]按不同分类法,同一个 Obsidian 机会可从狭义智能体安全扩展到广义 AI 智能体安全。
各行统一使用十亿美元单位;中点及高 / 低组合是尽调转换,不是出版方提供的置信区间。
[CM008, CM009, CM010, CM011, CM016, CM017]2.3 买方分层、预算责任人与采用路径
购买中心是跨职能的,因为运营问题横跨 AI、身份、SaaS 管理和安全运营。CISO 和安全运营团队关心攻击面和策略执行;身份团队关心 NHI 蔓延和高权限授予;SaaS 应用负责人关心业务流程连续性;AI 平台或转型团队关心在不失去工具和数据控制的情况下部署智能体。Obsidian 披露的 60 家 Fortune 500 客户和 100 多个六位数付费客户,支持企业预算容量,但没有说明预算负责人或产品线拆分。采用路径可能从盘点 SaaS 应用、集成、智能体和 MCP 服务器开始;再进入风险评分和策略设计;当智能体尝试权限升级、过度访问数据或使用未经批准工具时,最终变成运行时阻断。70% 的客户智能体采用率让这成为 2026 年当下的采购问题,而不是遥远场景;但采购仍会要求证明运行时控制能避免误报,并接入 SOC 工作流。[CM002, CM003, CM004, CM024, CM025, CM026]
| 细分 | 买方 | 使用者 | 付款方 / 预算负责人 | 工作流 | 采用触发点 | 尽调问题 |
|---|---|---|---|---|---|---|
| Fortune 500 企业 | CISO / 安全运营 | SOC 分析师和 SaaS 安全工程师 | 安全和风险预算 | 发现智能体、NHI、SaaS 权限和策略违规 | 生产 SaaS 应用里已有 AI 智能体 | 续约和扩张预算由谁负责? |
| 身份优先型组织 | IAM 负责人 / 身份安全 | 身份治理团队 | IAM 或零信任预算 | NHI 盘点、权限审查、特权操作监控 | NHI 数量和审计压力超出人工审查能力 | 新增支出有多少,IAM 替代又占多少? |
| SaaS 应用资产负责人 | 业务应用负责人加安全合作方 | Salesforce、Workday、M365、ServiceNow 管理员 | 应用、IT 或安全共享预算 | SaaS-to-SaaS 集成和权限态势 | 第三方应用数量和 OAuth 蔓延变得不可控 | 哪些应用拉动首次部署? |
| AI 转型项目 | AI 平台负责人,需 CISO 批准 | 智能体构建者和平台运营 | AI 转型预算加安全预算 | 智能体构建、工具批准、MCP 服务器盘点、运行时控制 | Copilot/Agentforce/n8n/Claude Code 采用 | 可接受的误报容忍度是多少? |
| 开发者智能体环境 | 工程安全和 DevSecOps | 使用自主编码智能体的开发者 | 工程效率和安全预算 | 限制生产数据访问和未经批准的工具 | 自主开发者智能体接触敏感代码库 | Obsidian 是否直接切入开发者工作流销售? |
买方版图由 Obsidian 产品范围和客户披露推断;管理层应核实预算负责人分布。
[CM002, CM003, CM004, CM024, CM025, CM026]切入点不同,采购中心也会变化,但每个细分市场最终都会交叉到安全、身份、SaaS 所有权和 AI 治理。
矩阵是基于公开产品和客户证据推断的买方模型;管理层应验证销售管线构成。
[CM002, CM003, CM004, CM024, CM025, CM026]买方信任覆盖范围、策略和工作流集成之后,采用才会从清单盘点推进到运行时执行。
漏斗数值是示意性的采用阶段指数,不是转化率;标签来自产品证据和客户披露。
[CM004, CM005, CM006, CM026, CM027, CM028]2.4 增长驱动、约束与测算缺口
需求由企业采用智能体、极端的 144:1 NHI 比例、SaaS 应用蔓延,以及在数据暴露前阻断智能体动作的需求驱动。约束同样关键。第一,SSPM 市场规模证据互相冲突:Research and Markets 称 2026 年 SSPM 市场为 $3.69 billion、CAGR 12.6%;Frost 则从 2025 年仅 $484.4 million 起步,到 2030 年以 48.7% CAGR 达到 $3.53 billion。这个分歧是反向市场测算信号,不是四舍五入误差。第二,直接竞争者 Zenity 在 Obsidian Series D 前一天融资 $125 million,说明品类被验证,也说明一个资本充足的对手在争夺同一批企业智能体安全预算。第三,如果把 CSPM、DSPM 或通用态势产品在没有 SaaS 智能体工作流的情况下计入可寻址市场,$26.35 billion 的广义 SPM 会抬高故事。尽调答案是保留漏斗,向管理层索取 ARR 和收入结构,并按买方画像测试客户预算,而不是直接承接总量 TAM。[CM012, CM013, CM020, CM031, CM032, CM036]
| 驱动 / 约束 | 方向 | 时点 | 含义 | 尽调问题 |
|---|---|---|---|---|
| 144:1 非人类 / 人类身份比例 | 正向驱动 | 当前 | 身份治理需求扩张快过员工人数增长 | 验证该比例是否覆盖 Obsidian 客户实测,而不只是总体口径 |
| 35,000+ 第三方应用攻击面 | 正向驱动 | 当前 | 拉出长尾 SaaS 权限和集成蔓延 | 量化已赢订单中的平均应用和集成数量 |
| 70%+ 客户已允许 AI 智能体 | 正向驱动 | 当前 2026 | 品类从未来预算转为主动风险修复 | 询问购买智能体专用模块的客户占比 |
| 智能体动作生效前的运行时阻断 | 正向驱动 | 当前 | 相比只告警工具,更能支撑 ROI 叙事 | 复核误报率和阻断动作案例 |
| Fortune 500 和 Global 2000 扩张 | 正向驱动 | 近期 | 销售周期若能转化,将抬高 ACV 和企业可信度 | 索取按企业层级和垂直行业拆分的销售管线 |
| Research and Markets 与 Frost 的 SSPM 口径冲突 | 负向约束 | 当前 | 削弱单一 TAM 数字精度和估值叙事 | 承销 SAM 前先统一 SSPM 分类口径 |
| 资金充足的 Zenity 竞争 | 负向约束 | 当前 2026 | 可能挤压赢单率、定价和品类叙事主导权 | 索取对 Zenity 的竞争赢 / 输数据 |
| 原生平台控制和现状惯性 | 混合约束 | 当前 / 中期 | 既可能验证需求,也可能让部分治理能力商品化 | 梳理 Obsidian 哪些控制优于原生平台 |
各行有意混合驱动和约束,把市场增长同采用时点和尽调问题绑定,而不是只看标题 TAM。
[CM004, CM005, CM006, CM027, CM028, CM029]2.5 图表
03竞争对手
3.1 竞争格局与可比对手集合
竞争格局已不再是简单的 SSPM 短名单。Obsidian 现在竞争的是企业内部治理 AI 智能体、非人身份和第三方应用中 SaaS-to-SaaS 活动的任务。这让它面对 Zenity 等直接 AI 智能体治理厂商,Grip、Nudge、Push 等 SaaS 和影子 IT 控制厂商,Valence 等 SaaS-to-SaaS 网状治理专家,AppOmni 等成熟 SSPM 平台,来自 IdP/SaaS 管理员的现状控制,以及内部治理自建。Zenity 是最重要的直接对手,因为它在 Obsidian Series D 前一天融资 $125 million,并公开把自己定位为覆盖企业智能体构建场景的 AI 智能体安全公司。Obsidian 的反向定位不同:它提供可在执行前检测并阻断风险动作的运行时治理,并配套 NHI 图谱和企业 SaaS 上下文。因此,品类有吸引力但竞争激烈,买方可能按控制插入位置分层:智能体开发、浏览器遥测、影子 SaaS 发现、SaaS 网状治理或运行时执行。[CP001, CP002, CP003, CP006, CP007, CP011]
| 竞争对手 | 聚焦领域 / 品类 | 融资或阶段信号 | 差异点 | 与 Obsidian 的重叠 | 来源依据 |
|---|---|---|---|---|---|
| Obsidian Security | 运行时 SaaS 安全、AI 智能体治理和 NHI 控制 | 2026 年 8 月 4 日完成 $85M Series D 轮;估值 $1.1B;累计融资超过 $200M | 高风险智能体动作执行前即阻断;NHI 图谱;60 家 Fortune 500 客户 | 基准公司;覆盖每个智能体 / SaaS 治理品类 | SP001; SP002; SP005 |
| Zenity | 直接 AI 智能体安全和智能体开发治理 | 2026 年 8 月 3 日完成 $125M Series C 轮;累计约 $180M-$185M;230+ 员工 | 强调构建期 / 智能体构建者,覆盖 Copilot Studio、Agentforce 等界面 | 最接近的直接 AI 智能体治理对手,尤其在运行时交接之前 | SP006; SP012; SP018; SP021 |
| Grip Security | SaaS 和 AI 控制、影子 SaaS/AI 发现、身份治理 | 按事实表语境,2023 年 Series B 约 $41M | 厂商称影子 SaaS/AI 发现和修复深度超过 Obsidian | 在发现、修复和 SaaS 身份治理工作流上竞争 | SP008; SP009; SP013 |
| Push Security | 基于浏览器的身份、SaaS 和 AI 时代安全 | 按事实表语境,2023 年 Series A 约 $15M | 浏览器内遥测和贴近用户会话的控制 | 买方想要浏览器层预防、而非 SaaS 控制面广度时形成竞争 | SP010; SP014 |
| Nudge Security | 带行为提示的 SaaS 和 AI 发现 | 按事实表语境,2022 年 Series A 约 $12.5M | 快速发现和员工引导式修复模型 | 在影子 SaaS/AI 盘点和轻量治理上竞争 | SP010; SP011; SP015 |
| Valence Security | 面向智能体时代的 SaaS-to-SaaS 和 AI 安全 | 按事实表语境,2023 年 Series A 约 $25M | 聚焦互联 SaaS 网格和非人类 / 智能体交互 | 在 SaaS-to-SaaS 和 NHI 风险工作流上高度重叠 | SP011; SP016 |
| AppOmni | 成熟的企业 SSPM 和 SaaS 安全 | 按事实表语境,2023 年 Series C 约 $70M,累计约 $123M | 广泛 SSPM 可信度和企业 SaaS 态势积累 | 买方把问题定义为 SSPM、而非智能体运行时控制时形成竞争 | SP007; SP017 |
非 Zenity 同行的融资 / 阶段数值来自规范事实表和公开竞争对手 / 来源页面;如有可用依据,各行来源依据单元格至少给出两个引用来源。
[CP001, CP002, CP003, CP004, CP005, CP007]Obsidian 和 Zenity 位于高价值 AI 智能体治理区,但控制平面重点不同。
X 轴是运行时 SaaS/NHI 治理广度;Y 轴是 AI 智能体开发 / 治理聚焦度。分数按公开定位做序数判断, 不是实验室基准。
[CP006, CP007, CP011, CP012, CP013, CP014]3.2 Zenity 与直接 AI 智能体治理压力
Zenity 是最接近的同类威胁,但双方并非逐项功能一致。公开报道把 Zenity 描述为一家高速扩张的 AI 智能体安全公司,员工超过 230 人,总部位于 New York,研发在 Tel Aviv,创始人为 Ben Kliger 和 Michael Bargury,并于 2026 年 8 月 3 日完成 Norwest 领投的 $125 million Series C。这个时点重要,因为该轮规模大于 Obsidian 的 $85 million Series D,且早一天落地,让 Zenity 在同一新闻周期里拿到强叙事。它的公开卖点强调保护无处不在的 AI 智能体,以及 Microsoft Copilot Studio、Salesforce Agentforce 等智能体开发生态。相比之下,Obsidian 不应过度声称与 Zenity 在构建期/开发者工作流上完全对等。更诚实的差异化是运行时 SaaS 治理:映射非人身份、观察第三方应用上下文,并在智能体动作生效前阻断策略违规。这种运行时姿态之所以有价值,正是因为智能体权限、已连接 MCP 服务器和模型替换都可能在设计期审查之后变化。[CP004, CP005, CP007, CP008, CP009, CP010]
| 购买标准 | Obsidian | Zenity | Grip | Push | Nudge | Valence | AppOmni | 证据提示 |
|---|---|---|---|---|---|---|---|---|
| 动作前运行时策略执行 | 公开主张强 | 不是公开叙事的首要重点 | 强调修复,运行时深度不清 | 浏览器会话控制,而非 SaaS 运行时 | 提示多于硬阻断 | SaaS 网格控制,运行时深度不清 | SSPM 控制,AI 智能体运行时不清 | 公开来源集中没有实验室基准 |
| 智能体构建者治理 | 按 Obsidian 来源,覆盖 Copilot Studio、Agentforce、n8n、开发者智能体、Claude Code 和 Cowork | 强;围绕企业智能体构建者形成核心定位 | 提到 SaaS 和 AI 控制 | 通过浏览器身份层相邻 | 发现和行为控制相邻 | 智能体时代 SaaS 安全定位 | SSPM 定位相邻 | 平台覆盖来自厂商主张,除非新闻证实 |
| NHI / SaaS-to-SaaS 图谱 | 强;144:1 NHI 比例和 SaaS 图谱是核心卖点 | 暗示 AI 智能体图谱,NHI 深度未被独立基准验证 | 身份治理是核心 | 不太核心;浏览器身份遥测 | SaaS 盘点是核心 | 通过 SaaS-to-SaaS 网格高度重叠 | SaaS 态势积累强 | 深度需要产品演示和 API 覆盖复核 |
| 影子 SaaS / AI 发现 | 通过 SaaS 资产可见性实现 | 强调智能体资产可见性 | Grip 提出强竞争主张 | 强浏览器发现 | 强轻量发现 | 通过互联 SaaS 可见性实现 | 存在于 SSPM 工作流 | 厂商页面定义不同 |
| 企业信任和规模证明 | 披露证据强:60 家 Fortune 500 和高 ACV 客户数量 | 资本 / 员工数信号强;来源中客户数披露较少 | 保留来源中的公开证明中等 | 早期阶段证明信号 | 早期阶段证明信号 | 早期阶段证明信号 | 成熟 SSPM 厂商信号 | 公开客户 / 赢单率数据不完整 |
| 定价透明度 | 允许来源集中未稳定公开 | 允许来源集中未稳定公开 | 允许来源集中未稳定公开 | 允许来源集中未稳定公开 | 允许来源集中未稳定公开 | 允许来源集中未稳定公开 | 允许来源集中未稳定公开 | 把定价视为尽调缺口,而不是主张 |
矩阵数值是有方向、由证据支撑的定位摘要,不是技术测试结果或价格报价。
[CP006, CP011, CP012, CP013, CP014, CP015]Obsidian 最强切入点是运行时 SaaS/NHI 治理;同行分别专注智能体开发、浏览器遥测、发现、SaaS 网格或 SSPM。
高 / 中 / 低评级反映公开产品定位和留存的对比页面;缺乏支撑的主张按中或低处理,而不是推断为强。
[CP006, CP011, CP012, CP013, CP014, CP015]3.3 定价、包装、分销与切换摩擦
公开定价是本章最弱的证据面。保留的竞品来源展示了产品包装和定位,但没有标准价目表、实际 ASP、折扣、续约率或赢单/丢单数据。对投资论证而言,竞争定价权只能从包装广度、采购信任和运营锁定推断,而不是从已观察报价读取。Obsidian 的公开证明点强于许多更年轻的同行:超过 100 个客户年付至少 $100,000,超过 14 个客户年付至少 $1 million,60 家 Fortune 500 客户。这些披露说明产品能达到企业级 ACV 和采购信任。但切换摩擦并非绝对。买方可以多栖:用 Obsidian 做运行时 SaaS 治理,用 Zenity 做智能体开发审查,用 Push 做浏览器遥测,用 Grip 或 Nudge 做影子 SaaS,用 AppOmni 做传统 SSPM。决定性问题是,Obsidian 能否成为智能体和 NHI 的运营控制平面,而不是 SaaS 态势周边的一个点状模块。[CP003, CP012, CP013, CP014, CP015, CP016]
| 定价或包装维度 | Obsidian 推读 | 竞争对手推读 | 对买方选择的含义 | 尽调问题 |
|---|---|---|---|---|
| 公开价格可得性 | 允许来源集中没有保留标准化公开标价 | 竞争对手页面大多展示定位,而非可比价格卡 | 采购团队会依赖报价、证明和适配度,而不是公开价格表 | 收集 Obsidian、Zenity、Grip、Push、Nudge、Valence 和 AppOmni 同范围实时报价 |
| 企业包装广度 | AI 智能体运行时治理、NHI 图谱、SaaS 集成安全、ITDR 和入侵清晰度可支撑平台化包装 | Zenity 包装智能体安全;AppOmni 包装 SSPM;Push、Nudge、Grip 和 Valence 包装更窄的控制点 | 广度可以抬高 ACV,但点工具可能拿下部门级或更快部署 | 按产品领域索取模块附加购买率和扩张客群 |
| 基于证明的定价权 | 100+ 客户超过 $100K、14+ 超过 $1M,外加 60 家 Fortune 500,构成溢价证据 | Zenity 的 $125M 融资和 230+ 员工带来可信度,即便未披露估值 | 大型智能体项目的候选名单可能变成 Obsidian 对 Zenity | 验证续约、NRR 和竞争替换率 |
| 摩擦最低的切入点 | API / 无代理 SaaS 接入和运行时控制可吸引中央安全团队 | Push 通过浏览器扩展切入;Nudge 通过发现切入;Grip 通过影子 SaaS/AI 切入;Valence 通过 SaaS 网格切入 | 若买方痛点窄于运行时治理,竞争对手可先于 Obsidian 落地 | 在客户访谈中梳理买方工作流、初始触发点和价值兑现时间 |
| 捆绑 / 商品化风险 | 只有能在足够多 SaaS / 智能体界面可靠阻断策略违规,运行时执行才有差异化 | SSPM、浏览器、身份和原生平台控制可能让发现和态势检查商品化 | Obsidian 必须证明运行时效果和覆盖广度,而不只是品类标签 | 在 Copilot Studio、Agentforce、n8n、Claude Code 和启用 MCP 的工作流中跑红队场景 |
允许来源块中没有公开价格和折扣数据,因此本表把已观察到的包装同必要商业尽调分开。
[CP003, CP006, CP011, CP012, CP013, CP014]3.4 护城河耐久性、商品化风险与 Obsidian 差异化
Obsidian 的竞争防线有四根柱子:运行时阻断、非人身份图谱、已披露企业客户进展,以及智能体平台覆盖广度。其中最强的是运行时治理,因为它处理的是智能体、集成或 MCP 连接工作流试图在 SaaS 中行动的那一刻。这比通用 SSPM 态势更像清晰切口,也比 Zenity 的智能体构建侧重点更有差异。NHI 图谱还受益于 Obsidian 所称第三方应用内非人身份与人类身份 144:1 的比例。企业证明同样重要:60 家 Fortune 500 客户和多个高 ACV 账号,可以缩短买方信任周期。风险在于,这条护城河仍在新生市场中证明耐久性。Zenity 有新资金和团队规模,Grip 用反向对比页进攻,既有平台或内部团队也可能把发现、态势和策略的一部分商品化。因此,Obsidian 的尽调定价应落在运行时有效性、集成广度、客户扩张和竞争丢单证据上,而不是只看品类动能。[CP001, CP002, CP003, CP004, CP006, CP011]
| 护城河或风险 | 方向 | 重要性 | 竞争压力 | 监测信号 |
|---|---|---|---|---|
| 动作前运行时阻断 | 护城河 | 让 Obsidian 从静态态势进入智能体行为的主动治理 | Zenity 若更深切入运行时;原生平台若把控制打包 | 阻断率效果、误报和关键 SaaS 动作覆盖 |
| 非人类身份图谱 | 护城河 | 引用的 144:1 NHI / 人类身份比例形成大规模图谱问题,点工具可能漏掉 | Valence、Grip、AppOmni 和 IdP 原生控制 | 每客户已映射 NHI、SaaS-to-SaaS 集成、MCP 服务器和高风险权限路径数量 |
| 企业客户参照基础 | 护城河 | 60 家 Fortune 500 客户和高 ACV 账户支撑采购信任 | Zenity 的资本 / 员工数、AppOmni 的 SSPM 成熟度和既有平台 | F500 标识留存、扩张和竞争赢单率 |
| Zenity 资本和品类叙事 | 风险 | 早一天完成的 $125M Series C 轮可能把人才、心智和预算拉向直接对手 | Zenity、其 Norwest 领投财团和智能体构建者生态伙伴 | 正面对阵输单率、分析师提及和智能体平台合作公告 |
| 影子 SaaS / 浏览器发现楔子 | 风险 | 买方若先从发现或浏览器层控制入手,Push、Nudge 和 Grip 可更早落地 | Push、Nudge、Grip 和轻量内部控制 | 线索来源分析,以及初始 SaaS 发现项目后的模块附加购买 |
| SSPM 商品化 | 风险 | AppOmni 和原生 SaaS 控制可降低买方为仅态势能力付费的意愿 | AppOmni、Microsoft / 原生控制、IdP 工作流和内部自建 | 与运行时智能体治理相关的 ACV 占比,相比传统 SSPM 模块 |
风险严重度为定性判断,因为公开来源没有披露 Obsidian 赢 / 输率、留存、NRR 或按模块实现的 ASP。
[CP001, CP002, CP003, CP004, CP007, CP011]Obsidian 公开的耐久性信号真实存在,但大多数商业强度指标仍未公开。
KPI 数值有意混合客户数量、比例和融资,因为标准化的竞争对手 ARR、NRR 和胜率数据未公开。
[CP002, CP003, CP004, CP005, CP007, CP008]3.5 图表
04财务
4.1 披露基线与资本容量
Obsidian 的财务记录在融资和客户付费门槛上异常强,但经营报表很薄。公司和几家独立媒体都指向同一个当前锚点:2026 年 8 月 4 日宣布的 $85 million Series D、$1.1 billion 估值、Crescent Cove 领投、既有投资人参投。同一组证据称,公司目前五轮累计融资超过 $200 million;历史来源还能识别 Series C、Series B-1 和最早 Series A 的支持者。这足以拼出融资时间线和资本充足度判断,但不足以建现金模型。轮前现金、月度现金消耗、资金可支撑月数、债务和项目融资义务均未公开。正确解读是“有容量,但消耗未知”:新一轮显然拉长了战略选项,却没有公开来源能验证它买来多少个月,或哪些经营里程碑会触发下一轮融资。[CI001, CI002, CI005, CI006, CI007, CI008]
| 轮次 / 事件 | 披露金额或估值 | 时点 | 至少两个来源依据 | 财务含义 |
|---|---|---|---|---|
| Series A 轮 / 最早机构轮 | 金额未公开披露 | 历史;Series A 轮首次合作 | Greylock 投资组合;Unite.AI Series D 轮回顾 | 最早机构验证,但模型输入没有金额 |
| Series B-1 轮 | 金额未公开披露 | June 2021 | Norwest 博客;Unite.AI 五轮融资回顾 | 已命名的既往融资,但经济条款稀疏,需要尽调 |
| Series C 轮 | $90M;当时累计融资 $119.5M | April 2022 | Pulse 2.0 Series C 轮报道;Unite.AI Series D 轮回顾 | 转向前 SSPM 规模化的重要资本 |
| 未指明既往 / 对账轮次 | 未单独公开披露 | Series D 轮前 | Unite.AI 五轮融资说法;Seedtable Series D 轮数据点 | 至少一轮描述不足,无法完整还原股权结构时间线 |
| Series D 轮 | $85M;估值 $1.1B;累计融资 >$200M | August 4, 2026 | Obsidian 官方发布;Yahoo Finance / Business Wire;Unite.AI | 新融资和独角兽估值已确认,但未披露现金余额或现金跑道 |
因公开资料称公司完成五轮融资,却未披露每轮金额或条款,表格只列出部分轮次; 每行至少引用表内和本地 claims 中两个具名来源依据。
[CI001, CI002, CI006, CI007, CI008]| 指标 / 义务 | 公开数值 | 置信度 | 重要性 | 尽调路径 |
|---|---|---|---|---|
| 账面现金 | null | 低 | 决定融资后真实现金跑道 | 索取 Series D 前后资产负债表 |
| 月度烧钱 | null | 低 | 把 $85M 融资换算成可支撑月数 | 索取月度 P&L 和按职能拆分的招聘计划 |
| 现金跑道月数 | null | 低 | 显示下一轮融资依赖的时间点 | 用现金、烧钱和已承诺支出测算 |
| 毛利率 | null | 低 | 检验估值是否配得上软件倍数 | 索取按产品拆分的毛利率、云成本、支持和服务数据 |
| NRR / 留存 | null | 低 | 验证收入质量和扩张经济性 | 索取按客户分层拆分的队列留存和扩张 |
| CAC 回本周期 / 销售效率 | null | 低 | 判断企业客户增长是否资本高效 | 索取 bookings、CAC、回本周期和销售周期数据 |
| 债务 / 信贷额度 | 无公开证据 | 低 | 隐藏义务会缩短现金跑道 | 索取债务明细和表外义务 |
| 资金用途 | 研发,以及 Fortune 500 / Global 2000 扩张 | 中 | 解释资金投向,但不说明现金跑道 | 把预算与产品里程碑和 bookings 目标对齐 |
表中的 null 表示保留资料里的公开来源未披露该指标;本表有意作为缺口登记表, 而不是预测。
[CI005, CI009, CI025, CI026, CI028, CI029]Obsidian 看起来更偏软件,而不是重资本开支;实际资本强度仍取决于未公开的现金消耗和利润率数据。
矩阵条目是定性判断,因为公开来源缺少财务报表或资产负债表细节。
[CI005, CI027, CI028, CI029, CI033, CI043]4.2 收入信号与 ARR 推断
收入和 ARR 未公开披露,因此本章把每个收入数字都视为已披露付费门槛,或明确标注的估算。最干净的硬信号是客户付费:超过 100 个客户年付超过 $100,000,超过 14 个客户年付超过 $1 million。按本章要求,隐含 ARR 下限计算为 100 乘以 $100,000,加上 14 乘以 $1 million,约 $24 million。它不是报告 ARR,也可能无法完美处理重叠或折扣;它只是从公开表述推导出的下限。$40 million–$70 million ARR 的合理分析师估算仅用于敏感性分析,并以 $50 million 作为基准情景。公司称有 60 家 Fortune 500 客户和多个七位数账号,商业质量看起来偏企业级;但收入结构、净留存、扩张率和客户集中度仍是私有信息。[CI003, CI004, CI009, CI010, CI011, CI022]
| 输入 / 情景 | 公开或估计状态 | 计算 | ARR 信号(USD M) | 尽调解读 |
|---|---|---|---|---|
| 100+ 家客户支出超过 $100K | 公司声称的支出门槛 | 100 x $0.1M | >=10 | 公开表述给出的硬底线组成项 |
| 14+ 家客户支出超过 $1M | 公司声称的支出门槛 | 14 x $1.0M | >=14 | 七位数账户组成项,也是集中度信号 |
| 说明性隐含底线 | 按披露支出估计 | >=10 + >=14 | >=24 | 只能当作底线,不是公司披露 ARR |
| 低估计情景 | 分析师估计 | 管理层数据不可得 | 40 | 高于支出底线的合理低位情景 |
| 基准估计情景 | 分析师估计 | 管理层数据不可得 | 50 | 仅用于标题 22x 敏感性 |
| 高估计情景 | 分析师估计 | 管理层数据不可得 | 70 | 需要该情景才接近私有网络安全公司基准倍数 |
支出底线以上的 ARR 数值均为分析师估计;公开资料未披露 ARR、收入、NRR、折扣, 或各支出队列之间的重叠情况。
[CI003, CI009, CI010, CI011, CI040]Obsidian 将企业 SaaS 和 AI 智能体风险转化为订阅收入,但 ARR 和实际定价仍未公开。
流程节点是有证据支撑的机制;ARR 和毛利未披露,因此仍为定性判断。
[CI019, CI020, CI021, CI022, CI023, CI042]只有估算 ARR 靠近区间高端,$1.1B 估值看起来才接近私营网络安全公司基准。
区间是分析师根据公开客户支出门槛和估值基准推导的估算,不是公司披露的 ARR。
[CI010, CI011, CI017, CI018, CI044]4.3 定价、GTM 与单位经济
公开定价证据只有方向性,不能直接承接。Cyberse 提到面向 1,000 名用户的免费层,以及 AWS Marketplace 上接近每用户每年 $100 的参考价;第三方资料也指向免费试用,或入门层之上的定制企业定价。这支持按员工数计价的订阅模型,但它是标价证据,不是实际 ACV、折扣、续约或毛利率证据。GTM 看起来由企业销售驱动:公司谈的是 Global 2000 扩张、七位数客户,以及复杂 SaaS 资产的定制治理,而不是交易型自助收入。因此,单位经济是核心尽调缺口。CAC 回收期、销售周期、毛利率、云成本、支持负担、实施服务、NRR、客户留存和流失率均未披露。最可防守的模型应把这些单元格视为 null,再向管理层索取队列和毛利率切片,之后再赋予软件式经济假设。[CI019, CI020, CI021, CI025, CI026, CI027]
| 层级 / 价格信号 | 计费单位 / 合同模式 | 公开数值或状态 | 标价与实际成交解读 | 尽调问题 |
|---|---|---|---|---|
| 免费层 | 用户 | 最高 1,000 名用户 | 入口 / 试用,不计入付费 ARR | 转化、激活和免费转付费队列数据 |
| AWS Marketplace 参考价 | 每用户每年 | ~$100/user/year | 方向性标价信号 | 折扣和捆绑后的实际成交 ASP |
| 企业计划 | 按员工数 / 报价制 | 超过免费门槛后定制报价 | ACV 可能需谈判 | 合同规模、多年期条款和折扣区间 |
| 七位数账户 | 账户年支出 | 14+ 家客户 >$1M | 真实企业支出信号 | 收入集中度和扩张路径 |
| 六位数账户 | 账户年支出 | 100+ 家客户 >$100K | 广泛企业底线 | 客户 logo 分布和分层 ACV |
| 实施 / 支持 | 服务或捆绑客户成功 | 未披露 | 无法拆分经常性收入与服务收入 | 服务附加率、支持成本和收入确认政策 |
定价只有公开标价和第三方参考证据;实际成交价、折扣、续约、服务和收入确认仍未公开。
[CI003, CI019, CI020, CI021, CI039, CI040]单位经济模型桥接显示哪些公开信号存在,以及哪些空白必须由尽调补上。
所有不可得指标都保留为 null 或定性节点,避免虚假精确。
[CI025, CI026, CI027, CI030, CI033, CI043]4.4 估值敏感性与财务结论
估值风险取决于 ARR 分母。在约 $24 million 的已披露付费下限上,$1.1 billion 估值隐含约 46 倍 ARR;在 $50 million 基准估算上约 22 倍;在 $70 million 高位估算上约 16 倍,接近 Finro 和 SaaS Mag 引用的私营网络安全基准区间。反向读法是,Finro 约 15.4 倍 ARR 的私营公司中位数,以及约 10–13 倍的降估值融资压缩区间,意味着 Obsidian 的真实 ARR 必须很高,或收入质量必须异常强,才能支撑这个估值。Zenity 的竞争融资强化了激进投入的必要性;更广泛的网络安全融资数据则显示市场支持但挑剔。结论是跟踪,不要盲目承接:Obsidian 的公开商业化证据强于多数私营公司,但留存、毛利率、现金消耗和集中度证据到位前,不能把估值视为公平。若管理层提供 ARR、NRR、现金或队列数据,应立即刷新这组敏感性。[CI012, CI013, CI014, CI015, CI016, CI017]
| ARR 假设(USD M) | 状态 | 隐含收入倍数 | 基准对比 | 风险解读 |
|---|---|---|---|---|
| 24 | 披露支出底线估计 | ~46x | 显著高于 Finro 私有公司平均 / 中位框架 | 除非支出底线漏掉大量未披露收入,否则估值偏高 |
| 40 | 分析师低估计 | ~28x | 高于典型私有网络安全公司平均水平 | 需要异常强的增长和留存 |
| 50 | 分析师基准估计 | ~22x | 接近高端云 / AI 安全溢价区间 | 估值偏贵;若 NRR 和利润率强,仍可能站得住 |
| 70 | 分析师高估计 | ~16x | 接近 Finro / SaaS Mag 私有网络安全基准 | 最接近基准支撑,但仍需证据 |
| 71 | 基准隐含 ARR | ~15.4x | 按 Finro 私有公司 15.4x 需要的大致 ARR | 略高于合理区间上沿 |
| 85 | 下行情景压缩所需 ARR | ~13x | 不利降轮压缩区间上沿 | 意味着 ARR 明显高于公开底线 |
| 110 | 下行情景压缩所需 ARR | ~10x | 不利降轮压缩区间下沿 | 需要非常大的未披露 ARR |
倍数用 $1.1B 估值除以 ARR 假设;除披露支出门槛外,ARR 假设都是估计值, 不是公司披露指标。
[CI012, CI013, CI014, CI015, CI016, CI017]4.5 图表
05产品与技术
5.1 运行时治理产品地图
Obsidian Security 最适合被理解为一家 SSPM 公司,它围绕第三方 SaaS 内 AI 智能体和非人身份的运行时治理,重建了产品叙事。客户要完成的任务,不只是季度态势扫描后发现某个过高权限;而是发现哪些智能体、MCP 服务器、集成、服务账号和模型能触达敏感 SaaS 数据,并在危险动作发生前拦下。这是技术上更锋利的价值主张,因为它要求资产清点、身份上下文、行为基线、策略评估和交易路径上的执行能力。同一基础也解释了为什么早期 Salesforce、Workday 和 Microsoft 365 SSPM 经验重要:新的 Copilot Studio、Agentforce、Workday、n8n、Claude Code、Cowork 以及 SaaS-to-SaaS 自动化风险,正是在这些系统里进入生产。[CE001, CE003, CE004, CE006, CE008, CE013]
| 模块 / 资产 | 主要用户 | 状态 / 成熟度 | 差异化 | 尽调缺口 |
|---|---|---|---|---|
| AI 智能体运行时治理 | 安全、身份和 SaaS 平台团队 | 当前战略旗舰模块 | 在动作执行前阻断权限提升、过度访问和策略违规 | 需要独立验证运行时效果和误报数据 |
| MCP 安全清单和模型注册表 | AI 治理、AppSec、平台工程 | 新类别模块 | 把 MCP 服务器映射到调用它们的智能体,并跟踪底层模型 | 需要 schema 细节和替换检测证据 |
| AI 智能体身份管理 / NHI 治理 | IAM、安全运营、SaaS 负责人 | 当前产品覆盖面 | 把概率型智能体、过度授权的 NHI 接到 SaaS 控制 | 需要 NHI 发现精度和归属工作流指标 |
| SaaS 供应链安全 | SaaS 安全和第三方风险团队 | 2026 年 1 月发布 | 瞄准 SaaS-to-SaaS 集成和智能体连接路径 | 需要连接器覆盖和修复自动化证据 |
| 跨 SaaS 入侵厘清 | SOC、事件响应、CISO 办公室 | 当前取证模块 | 目标是在 SaaS 身份事件后缩短排除嫌疑平均时间 | 需要调查周期前后对比基准 |
| SSPM / ITDR 基础 | SaaS 应用负责人、IAM、安全态势团队 | 成熟基础产品 | 既有 Salesforce、Workday 和 Microsoft 365 态势根基为智能体控制提供上下文 | 需要当前旧 SSPM 与智能体治理收入拆分 |
各行综合公开产品覆盖面;Obsidian 未发布完整 SKU 目录或模块级采用结构。
[CE004, CE008, CE009, CE011, CE012, CE019]| 平台 / 覆盖面 | 治理风险 | 证据信号 | 限制 / 尽调问题 |
|---|---|---|---|
| Microsoft 365 / Copilot Studio | 智能体访问企业文档和 SaaS 身份上下文 | Series D 和产品资料提到 Microsoft / Copilot 智能体治理范围 | 核实具体 API、tenant 权限和支持的 Copilot Studio 动作 |
| Salesforce / Agentforce | 客户数据访问、权限提升和 SaaS-to-SaaS 互联应用滥用 | 公开资料点名 Salesforce / Agentforce 是智能体治理覆盖的根基 | 确认 Agentforce 专用打包控制,而不只是通用 Salesforce 态势 |
| Workday | HR 和身份敏感 SaaS 工作流暴露 | SSPM 根基把 Workday 纳入第三方 SaaS 控制平面 | 确认当前对 Workday AI 或自动化流程的连接器深度 |
| n8n | 工作流自动化工具使用和未获批准的 MCP / 工具调用 | 产品资料将 n8n 列为智能体构建平台 | 测试对多步骤自动化链的策略执行 |
| Claude Code | 自治开发者智能体访问敏感文件和生产数据 | 2026 年 8 月公告称治理正在扩展到 Claude Code | 验证敏感文件控制、生产数据限制和开发者工作流摩擦 |
| Cowork | 开发者或自治智能体访问生产数据 | 2026 年 8 月公告将 Cowork 与 Claude Code 并列点名 | 核实发布成熟度、beta 状态和客户部署证据 |
覆盖来自公开资料,不是经认证的兼容矩阵;每行都需要管理层确认深度和发布状态。
[CE013, CE014, CE017, CE018, CE039]从公开架构看,Obsidian 是一套 SaaS 身份与智能体治理栈,叠在第三方应用和智能体工具之上。
根据公开产品页和融资报道综合而成;Obsidian 未发布单一权威架构图。
[CE004, CE009, CE011, CE012, CE013, CE018]5.2 架构与运行时数据路径
公开来源暗示的架构是图谱支撑的控制平面。API 式或无代理接入发现 SaaS 应用、非人身份、集成、MCP 服务器、模型和智能体关系。知识图谱随后关联权限、数据敏感性、正常行为和工具调用上下文。运行时,系统评估智能体请求是否涉及权限升级、过度数据访问、策略违规、模型切换,以及未经批准的 MCP 或工具使用;控制决策可在动作生效前阻断。这与被动审计看板有实质差异。核心尽调问题是,Obsidian 能否在决策回路中保留足够上下文,同时不在大量 SaaS API 和智能体平台之间制造不可接受的延迟、误报或连接器脆弱性。[CE005, CE009, CE010, CE011, CE012, CE018]
| 层 / 流程 | 作用 | 依赖 | 风险 |
|---|---|---|---|
| 基于 API / 无代理接入 | 发现 SaaS 应用、集成、NHI、智能体和 MCP 覆盖面 | SaaS API、权限和连接器可靠性 | 覆盖缺口或 API 变化会削弱可见性 |
| 知识图谱 | 关联用户、NHI、智能体、应用、数据敏感性和权限 | 身份数据、应用元数据和行为遥测 | 图谱边错误会导致漏拦或误报 |
| MCP 清单 | 跟踪已连接的 MCP 服务器,并映射到调用智能体 | MCP 服务器发现和智能体遥测 | 协议不成熟和未托管本地服务器可能逃过清单 |
| 模型注册表 | 跟踪智能体工作流背后的底层模型 | 模型身份和调用元数据 | 模型切换 / 替换检测需要可靠溯源 |
| 运行时策略引擎 | 执行前评估并阻断高风险动作 | 低延迟策略决策和执行钩子 | 延迟、误报和绕过是关键尽调测试 |
| 取证 / 入侵厘清 | 疑似滥用后区分受影响与未受影响的 SaaS 活动 | 审计日志、图谱历史和事件时间线 | MTTI 收益公开资料未量化 |
架构根据产品页面和报道重建;公开资料没有单一权威系统图或基准。
[CE005, CE009, CE010, CE011, CE012, CE018]关键产品主张,是把发现和图谱上下文接入行动前的运行时策略决策,再延伸到事后厘清。
该流程描述公开证据最能支持的控制闭环;实际延迟和实现细节未披露。
[CE005, CE009, CE010, CE011, CE012, CE018]运行时治理逻辑依赖第三方 SaaS API、智能体平台、标准,以及图谱上下文质量。
DAG 仅覆盖外部可见依赖;内部基础设施和数据供应商不公开。
[CE013, CE014, CE018, CE023, CE025, CE029]5.3 标准、信任与风险控制
产品论点最强的外部验证来自标准机构,而不是独立产品基准。OWASP 和 CSA 描述的 MCP 威胁模型,主要由提示词注入、工具投毒、最小权限失效、OAuth 和授权错误、不安全服务器或工具设计构成。Obsidian 的公开主张与这套控制语言贴合,因为资产清点、模型注册表和行动前策略执行,正是运行时护栏需要的基础能力。反向读法同样重要:PipeLab 的 2026 年 MCP 安全评估提到数千个 MCP CVE,意味着 Obsidian 正在一个不成熟且波动很大的协议生态里建设。机会很大,产品有效性负担也很重;安全买家需要看到控制能对抗高级智能体攻击,而不只是治理覆盖的营销说法。[CE023, CE024, CE025, CE026, CE027, CE028]
| 控制 / 标准 | 适用要求 | Obsidian 侧状态 | 缺口 |
|---|---|---|---|
| OWASP MCP Security Cheat Sheet(安全速查表) | 应对提示注入、工具投毒、授权和最小权限 | 与清单和动作前运行时治理高度契合 | 需要攻击类型级检测和阻断结果证据 |
| OWASP 安全 MCP 服务器指南 | 安全服务器设计、输入、工具定义和信任边界 | 可作为评估 Obsidian 托管或监控 MCP 服务器的基准 | 需要说明 Obsidian 是否验证服务器实现质量 |
| CSA 智能体 MCP 最佳实践 | 身份感知治理、受限工具访问和安全的智能体-工具流 | 映射到 NHI 治理、MCP 清单和策略执行 | 需要客户策略模板和例外管理证据 |
| OAuth 2.1 / 最小权限 | 智能体 SaaS 访问需要收紧 scope 并支持撤销 | 这是 Salesforce、Microsoft 365、Workday 和 SaaS 集成治理的核心 | 需要按 SaaS 平台列出支持的 OAuth 应用控制 |
| SOC 2 / GDPR 态势 | 企业级保证和隐私 / 控制证据 | FACTS.md 和公司公开页面显示其具备 SOC 2/GDPR 态势 | 需要当前报告、范围、子处理方清单和审计例外 |
标准行只是对齐检查,不代表 Obsidian 已接受这些框架的正式评估。
[CE023, CE024, CE025, CE026, CE038, CE037]SSPM/NHI 上下文能迁移到智能体治理的领域,成熟度最强;缺少公开基准的领域最弱。
基于公开证据的定性尽调评分;没有独立产品基准对这些能力做归一化比较。
[CE008, CE019, CE023, CE027, CE037, CE038]5.4 路线图、成熟度与尽调缺口
从公开证据看,产品成熟度可信但不完整。2026 年 1 月 SaaS 供应链安全发布,显示 Obsidian 从态势延伸到集成风险。2026 年 8 月 Series D 公告随后把新资金与 R&D、Fortune 500 扩张,以及面向 Claude Code 和 Cowork 的原生治理相连。这些里程碑与市场转向智能体化 SaaS 工作流一致。但是,来源集合没有暴露足够硬的工程证据:没有公开阻断率基准、误报率、模型注册表结构定义、正常运行历史、按应用列出的连接器覆盖清单或详细支持 SLA。开发者信号也弱;供应商维基只是替代指标,不能替代开放 SDK、公开变更日志或活跃社区。因此,尽调应先测试运行时有效性、SaaS 连接器可靠性和策略治理运营,再把架构视为完全已证。最后一条产品尽调线应在对抗性、接近生产的场景中测试控制平面:已批准与未批准 MCP 服务器、一次模型替换尝试、智能体请求敏感 HR 或销售记录、带有陈旧 OAuth 授权范围的服务账号,以及开发者智能体触碰生产数据。这些测试会把公开架构从可信的图谱加策略论点,转化为可度量的安全证据;也会揭示 Obsidian 的 SSPM 底座是否提供了足够上下文,避免运行时阻断噪声。剩余尽调应由证据牵引,而不是由路线图牵引。管理层还应展示策略变更审计轨迹、例外审批记录,以及被阻断智能体动作的客户支持升级记录。[CE019, CE020, CE029, CE030, CE031, CE032]
| 日期 / 阶段 | 功能或里程碑 | 状态 | 影响 | 来源 |
|---|---|---|---|---|
| 2026 前基础 | 覆盖 Salesforce、Workday、Microsoft 365 等第三方 SaaS 的 SSPM 和 ITDR | 成熟基础 | 为智能体治理提供图谱和 SaaS 身份上下文 | Unite.AI + Norwest |
| 2026-01-22 | 面向 SaaS-to-SaaS 集成的端到端 SaaS 供应链安全 | 已发布 | 从态势扩展到集成和智能体连接风险 | Help Net Security + SiliconANGLE |
| 2026 当前 | MCP 清单和模型注册表 | 当前产品覆盖面 | 把未托管 MCP 服务器和模型替换纳入治理对象 | Obsidian MCP 页面 + FinTech Global |
| 2026-08-04 | Series D 将 $85M 融资投向研发和 Fortune 500 / Global 2000 扩张 | 已获资金支持的路线图 | 增强深化平台覆盖的能力 | Obsidian 公告 + Unite.AI |
| 2026-08-04 | 原生治理扩展到 Claude Code 和 Cowork | 已公告扩展 | 把控制平面推进自治开发者智能体工作流 | Obsidian 公告 |
路线图证据主要来自公告;详细的多季度产品路线图和 GA / beta 拆分并未公开。
[CE017, CE019, CE029, CE039, CE014]5.5 图表
06客户
6.1 企业牵引力与分层
Obsidian 的客户证明先来自规模披露;对私营网络安全厂商来说,这些披露异常具体。公司披露的 2026 年 Series D 资料称,其有 100+ 个年付超过 $100,000 的客户、14+ 个年付超过 $1,000,000 的客户,以及 60 家 Fortune 500 客户,覆盖大型金融机构、社交媒体网络和电信提供商。这些事实支持真实企业采用,而不只是试点,因为披露的付费门槛意味着生产预算归属,以及至少一定程度的多利益相关方采购。分层仍需谨慎:金融外部证明最强,因为一个匿名 Fortune 500 银行董事出现在客户参考语料中;电信有 CB Insights 提供的 T-Mobile 具名客户 logo;社交媒体只披露为类别;Snowflake 提供高质量数据平台案例。Obsidian 围绕 AI 智能体、非人身份和第三方 SaaS 应用的产品定位,解释了为什么安全、身份和 SaaS 负责人可能是买方、用户和付款方;但公开记录还没有把每个已披露分层映射到合同规模、续约状态或生产范围。[CU001, CU002, CU003, CU017, CU018, CU019]
| 分层 | 买方 / 用户 / 付款方 | 用例 | 规模信号 | 收入 / 战略价值 | 缺口 |
|---|---|---|---|---|---|
| Fortune 500 企业 | CISO、身份、SaaS 安全、采购 | 第三方 SaaS 应用中,AI 智能体和非人类身份的运行时治理 | 60 家 Fortune 500 客户 | 战略价值高;支撑 Global 2000 扩张计划 | 具名客户标识和生产范围大多未披露 |
| 金融机构 / 银行 | 安全、风险、合规、身份负责人 | SaaS 态势、泄露厘清、AI 智能体控制、应用发现 | 大型金融机构,以及 F500 银行总监评价 | SaaS 风险与监管审视叠加,付费意愿可能较高 | 银行案例匿名;ARR 和续约未披露 |
| 社交媒体网络 | 平台安全和 SaaS 负责人 | 控制第三方应用访问、智能体权限和数据暴露 | Series D 客户披露点名该垂直行业 | 证明其能进入互联网规模的 SaaS 环境 | 已纳入来源中没有具名社交媒体客户标识 |
| 电信运营商 | CISO、身份、SaaS 应用安全团队 | 保护分布式第三方 SaaS 资产和非人类身份 | 公司点名电信垂直行业;CB Insights 列出 T-Mobile | 大型企业复杂度高,可能对应七位数支出 | T-Mobile 用例和合同深度未披露 |
| 数据平台 / SaaS 生态 | 安全工程和云 / SaaS 平台团队 | 集成风险治理和工程工时节省 | Snowflake 案例:3,000 个集成,每月节省 800+ 小时 | 参考案例质量强,ROI 代理指标具体 | 合同规模、续约或扩张历史未披露 |
| 市场平台和数字商务 | 安全、IT、应用负责人 | 覆盖广泛应用资产的 SaaS 发现、态势、身份和智能体控制 | CB Insights 列出 Upwork、Trade Me、BigCommerce | 说明采用面超出受监管安全买家 | 只有客户标识列表证据,缺少部署细节 |
分层结合公司披露的垂直行业、客户参考材料和具名客户标识列表;这些行并非管理层导出的 CRM 表。
[CU001, CU002, CU017, CU018, CU024, CU031]| 指标 | 值 | 日期 | 来源 | 置信度 | 含义 | 缺失分母 |
|---|---|---|---|---|---|---|
| 大客户 | 100+ 家客户年支出 >$100,000 | 2026-08-04 | Series D 报道和公司公告 | 高 | 相当规模的企业客户已拿出生产预算采用 | 活跃客户总数和历史队列未披露 |
| 七位数客户 | 14+ 家客户年支出 >$1,000,000 | 2026-08-04 | Series D 报道和公司公告 | 高 | 大客户扩张真实存在 | 收入集中度和续约时间未披露 |
| Fortune 500 覆盖 | Fortune 500 中 60 家是客户 | 2026-08-04 | Series D 报道和公司公告 | 高 | 获得大型组织的企业级验证 | 具体 Fortune 500 客户标识大多未披露 |
| 现有客户的 AI 智能体暴露面 | 70%+ 客户已允许 AI 智能体进入第三方应用 | 2026-08-04 | Series D 报道中的 CEO 引述 | 高 | 现有客户已经有现实的智能体治理问题 | 未区分生产环境智能体使用和试点 |
| Snowflake 集成规模 | 3,000 个集成 | 2026 | Snowflake 客户故事 | 中 | 部署场景足够大,具备生产相关性 | 没有事前 / 事后事件或风险基线 |
| Snowflake 效率 KPI | 每月节省 800+ 个工程小时 | 2026 | Snowflake 客户故事 | 中 | 有量化的运营价值证明 | 合同金额和回本周期未披露 |
| Forrester TEI ROI | 针对收入 $9B / 10k 员工的复合模型,ROI 最高 192% | 2026 | Forrester TEI | 中 | 企业价值主张有模型化 ROI 支撑 | 复合模型不是已披露的真实客户队列 |
| 评论平台满意度 | 来自 ~22 条 Gartner 评论,~4.9/5 | 2026 | Gartner Peer Insights | 中 | 评论者满意度信号正面 | 样本小,且未关联续约 |
数值采用 FACTS.md 规范指标和来源清单描述;除非明确为第三方建模,百分比和客户数均为公司披露。
[CU001, CU003, CU005, CU006, CU012, CU014]公开量化漏斗从广泛企业客户收窄到 Fortune 500 账户、七位数客户和具名高质量背书。
100+ 和 14+ 门槛按披露下限展示;具名 / 背书数量反映本章保留的公开语料,不代表客户总数。
[CU001, CU004, CU009, CU010, CU024, CU027]6.2 具名客户证明与价值结果
最好的具名证明是 Snowflake,因为它同时具备可识别企业、具名高级安全负责人、具体部署语境和可衡量运营影响。Obsidian 称 Snowflake 在 3,000 个集成中使用该平台,每月节省超过 800 个工程小时;Security MEA 另行报道了该集成,使这个故事强于单一供应商页面。CB Insights 将 T-Mobile、Upwork、Trade Me 和 BigCommerce 加入公开客户 logo 集;FeaturedCustomers 又加入了一位匿名 Fortune 500 银行董事,以及一位 CSO 对“数日内发现数百个 SaaS 应用”的描述。这些引用把客户图谱扩展到电信、交易平台、电商、银行和大型 SaaS 资产。限制在于,除 Snowflake 外,大多数客户 logo 没有绑定已发布的部署深度、结果指标、留存或合同经济性。对尽调而言,客户列表应被视为采用证明和销售管线证据;在管理层提供客户访谈、续约历史和头部账号经济性之前,不能把它视为耐久性或账号级扩张的证明。[CU004, CU005, CU006, CU007, CU008, CU009]
| 客户 / 参考 | 细分 | 部署 / 用例 | 生产 / 试点 | 成果 / 证据质量 | 局限 |
|---|---|---|---|---|---|
| Snowflake | 数据云 / 企业 SaaS 生态 | Obsidian 对 3,000 个集成做集成治理 | 生产环境客户案例 | 每月节省 800+ 个工程小时;具名 CISO 和安全副总裁引述 | 合同规模、续约或队列历史未披露 |
| T-Mobile | 电信 / Fortune 级大型企业 | CB Insights 将其列为 Obsidian 客户 | 已知客户标识;部署状态未披露 | 结合 Series D 垂直行业披露,支撑电信行业主张 | 用例、买方、结果或 ARR 区间均未公开 |
| Upwork | 人力市场平台 / SaaS 资产 | CB Insights 将其列为 Obsidian 客户 | 已知客户标识;部署状态未披露 | 说明传统银行之外,市场平台型企业也在采用 | 除客户名单外,没有生产证据 |
| Trade Me | 市场平台 / 数字商务 | CB Insights 将其列为 Obsidian 客户 | 已知客户标识;部署状态未披露 | 为具名客户标识证据增加地域和市场平台多样性 | 没有公开案例研究或量化成果 |
| BigCommerce | 商务 SaaS / 数字商务 | CB Insights 将其列为 Obsidian 客户 | 已知客户标识;部署状态未披露 | 说明产品适用于商务平台型 SaaS 环境 | 模块、续约或扩张细节未披露 |
| Fortune 500 银行总监 | 金融机构 | FeaturedCustomers 上的银行总监评价 | 客户参考案例,生产范围匿名 | 印证金融机构细分和 CISO 层相关性 | 客户标识未披露;无法核验经济性或部署广度 |
| 匿名 CSO 参考 | 大型 SaaS 应用资产 | 数天内发现数百个 SaaS 应用 | 客户参考案例,生产范围匿名 | 结果契合 SaaS 发现和态势管理工作流 | 案例经过筛选且匿名 |
列举的是 CH6 来源中的部分公开客户标识 / 参考列表;不包括 60 家 Fortune 500 中未披露的成员,也不包括任何私有客户名册。
[CU004, CU005, CU006, CU007, CU008, CU009]Obsidian 的客户路径从 SaaS / AI 智能体风险发现,走向生产治理、量化结果和可能的多模块扩张。
旅程根据客户故事、产品触点和 Series D 业务牵引力披露综合而成,而非披露的转化漏斗。
[CU003, CU004, CU006, CU011, CU019, CU020]具名账户叠加量化结果时,客户证明最强;只有客户标识或匿名证据时最弱。
矩阵条目仅基于公开来源具体度做定性证据质量判断。
[CU004, CU008, CU009, CU010, CU011, CU027]6.3 满意度、ROI 与耐久性信号
满意度和价值证据为正,但它不等于留存证据。Gartner Peer Insights 显示约 22 条评价、评分约 4.9/5;PeerSpot 也提供另一个企业评价面。Forrester 的 TEI 计算器显示,一个收入 $9 billion、员工 10,000 人的综合组织最高可达 192% ROI。这些信号重要,因为它们在 Obsidian 自有客户页面之外交叉验证了买方感知价值;Forrester 模型方向上也与 Snowflake 节省工程小时的说法一致。问题是,这些来源都不披露 Obsidian 的 NRR、GRR、流失、续约率、合同期限或真实客户队列行为。因此,计划中的留存队列必须呈现为披露地图,而不是实际留存曲线:公开来源能识别当前付费队列和当前具名部署,但无法揭示同一批账号在 6 个月或 12 个月后是否续约。这是核心未解客户质量缺口。[CU012, CU013, CU014, CU023, CU030, CU036]
| 指标 | 值 / 空值 | 细分 | 置信度 | 尽调请求 |
|---|---|---|---|---|
| 公开 NRR | null | 所有客户队列 | 低 | 要求按初始模块、ARR 区间和 Fortune 500 状态提供 NRR |
| 公开 GRR / 流失 | null | 所有客户队列 | 低 | 要求提供客户标识留存、金额留存、流失原因和续约日历 |
| 合同期限 / 续约率 | null | >$100K 和 >$1M 客户 | 低 | 要求提供大客户合同条款和续约结果 |
| Gartner Peer Insights 评分 | 来自 ~22 条评论,~4.9/5 | 评论者样本 | 中 | 要求提供评论分布、时效性和已验证客户分层 |
| PeerSpot 评论覆盖面 | 企业评论存在感 | 企业安全买家 | 中 | 将情绪主题与 Gartner 和客户访谈对比 |
| Forrester TEI ROI | 收入 $9B / 10k 员工复合模型的 ROI 最高 192% | 大型企业复合模型 | 中 | 要求提供模型假设和实际客户回本案例 |
| Snowflake 运营 KPI | 每月节省 800+ 个工程小时 | 具名企业客户 | 中 | 验证基线、测量周期和续约 / 扩张结果 |
| 不利匹配:云态势 | Work-Management.org 称不覆盖 IaaS/PaaS 态势 | 需要广泛云态势的买家 | 中 | 探查客户是否需要单独的 CSPM/CWPP 工具 |
| 不利匹配:仪表盘 | Work-Management.org 称仪表盘灵活性有限 | 安全运营和高管汇报 | 中 | 探查定制限制是否影响续约或高管汇报采用 |
空值是刻意留空:纳入的公开来源均未披露留存队列、NRR、GRR、流失、合同期限或续约率。
[CU012, CU013, CU014, CU015, CU016, CU023]实际留存队列未公开,所以披露队列图显示:每个客户组在初始证明之后,公开续约可见度都是 0%。
这些单元格是公开留存可见度百分比,不是 Obsidian 实际客户留存;实际 NRR / GRR / 流失队列未披露。
[CU001, CU004, CU009, CU023, CU024, CU025]6.4 扩张、集中度与适配风险
Obsidian 的扩张故事可信,因为 2026 年融资叙事明确称,公司将投入 R&D,并更深入扩展到 Fortune 500 和 Global 2000;MCP 安全、入侵厘清、SaaS 供应链安全、AI 智能体身份管理等产品面,也创造了多条交叉销售路径。同一证据也带来投资风险。14+ 个 $1M 客户说明真实账号扩张,但如果这些账号主导收入,也会引发集中度问题。60 家 Fortune 500 的说法证明企业触达;但具名 Fortune 500 客户 logo 大多未披露,因此投资人无法独立评估续约质量、部署广度或客户参考多样性。Work-Management.org 的反向评价证据增加了一条客户适配边界:若买方想要一个同时覆盖 SaaS、IaaS 和 PaaS 态势的平台,可能会认为 Obsidian 不完整;看板灵活性限制也可能影响有定制报表需求的团队。底线是强采用证明叠加重大披露缺口,而不是一套干净的留存承接材料。[CU015, CU016, CU020, CU021, CU022, CU025]
| 扩张驱动 | 集中度风险 | 影响 | 尽调路径 |
|---|---|---|---|
| 将 100+ 家 $100K+ 客户推向七位数合同范围 | 14+ 家 $1M 客户可能主导收入 | 正面的扩张证据也可能掩盖头部客户集中 | 要求提供前 10 大客户收入占比和账户级 ARR 区间 |
| Series D 后更深打入 Fortune 500 / Global 2000 | 具体 F500 客户标识大多未披露 | 企业覆盖真实存在,但难以独立支撑投资判断 | 要求提供可披露客户标识清单,或按垂直行业匿名的客户明细表 |
| 将 Snowflake 量化成果用于参考销售 | 一个优秀案例可能高估中位数价值 | 销售证明很强,但不能证明每个账户都能节省数百小时 | 要求提供非 Snowflake 账户的中位 ROI 和客户访谈记录 |
| 向现有 SaaS 客群交叉销售 AI 智能体运行时治理 | 该品类可能仍被按新兴控制层编预算 | 有增购潜力,但采用速度取决于客户智能体成熟度 | 要求提供已允许 AI 智能体客户的管道转化 |
| 泄露厘清、MCP 安全、SaaS 供应链附加模块 | 模块扩张可能模糊附加率 | 扩张故事可信,但未量化 | 要求按队列提供产品附加率和净扩张桥接 |
| 金融、社交、电信垂直行业广度 | 垂直行业证据可能集中在少数明星账户 | 听起来很广的垂直行业列表可能掩盖集中度 | 要求提供按垂直行业拆分的 ARR 和最大客户暴露 |
| SaaS 专项深度与云套件广度的取舍 | 不覆盖 IaaS/PaaS 态势,可能限制平台整合项目胜率 | 可能限制其在云安全标准化项目中的钱包份额 | 对同时使用 Wiz、CSPM、CNAPP 或 EASM 工具的客户做验证 |
| 高管汇报和仪表盘采用 | 仪表盘灵活性限制可能影响重汇报买家的续约 | 即使技术胜出,也会拖慢运营落地 | 向参考客户询问仪表盘定制和董事会汇报工作流 |
这些风险来自公开客户证据向商业结果传导的路径;并不声称任何具名客户已经流失。
[CU015, CU016, CU020, CU021, CU025, CU026]6.5 图表
07风险
7.1 竞争、平台风险与市场时点
Obsidian 在一个看似紧迫但尚未定型的市场里融资。最强竞争警示是 Zenity:它于 2026-08-03 融资 $125 million,比 Obsidian 宣布 $85 million Series D 早一天,并且明确定位于保护自主 AI 智能体。更广泛的赛道也很拥挤,Grip、Push、Nudge、Valence、AppOmni,以及身份/安全平台既有玩家,都在争夺重叠的 SSPM、SaaS 发现、浏览器身份和智能体治理预算。这种拥挤很重要,因为 Obsidian 的转向不是从 SSPM 进入一个垄断品类的干净空白市场动作;它押注的是运行时 AI 智能体治理能成为足够大的预算线,从而支撑独角兽估值。Microsoft 原生智能体安全工作是更尖锐的平台风险。如果 Copilot、Defender、Salesforce、Google 或 SaaS 平台把足够多的治理控制直接嵌进企业套件,Obsidian 可能仍有技术价值,却失去定价权和战略紧迫性。市场时点是相连风险:70%+ 客户智能体暴露和 144:1 NHI 比例支持问题表述,但公开来源尚未证明续约耐久性、独立 AI 治理的付费意愿,或预算从 SSPM 转向智能体运行时控制的速度。进一步尽调还要关注买方教育:安全团队可能认同智能体有风险,却仍会推迟购买新平台,直到内部试点引发事件、审计发现或董事会级要求。[CR001, CR002, CR003, CR010, CR015, CR020]
| 依赖 / 压力 | 对手方 | 角色 | 集中度 | 失效情景 | 严重性 | 缓释措施 | 剩余暴露 |
|---|---|---|---|---|---|---|---|
| 平台原生智能体安全控制 | Microsoft | Copilot / Defender 平台所有者,安全领域既有厂商 | 高战略依赖 | 控制能力打包进套件,挤压第三方预算 | 高 | 跨 SaaS 独立性和更深的运行时治理 | 利润率与战略相关性被压缩 |
| 直接 AI 智能体安全竞争对手 | Zenity | 自主智能体安全领域资金充足的竞争对手 | 品类叙事中集中度高 | Zenity 融资 $125M 后赢得企业心智 | 高 | 用 SaaS 图谱、NHI 遥测和 Fortune 500 证据拉开差异 | 销售周期承压,估值对标风险上升 |
| SSPM 与 SaaS 治理拥挤 | Grip / Push / Nudge / Valence / AppOmni 等邻近厂商 | 相邻厂商争抢 SaaS 与 AI 治理预算 | 中高 | 买方围绕更简单的发现 / 修复工具做整合 | 中高 | 主打运行时拦截和 NHI 深度 | 功能商品化和定价压力 |
| 客户 SaaS 环境 | Salesforce / Snowflake / AWS 和第三方应用 | 要保护的核心数据和工作流表面 | 高 | 入侵或 API 变更限制监测与响应 | 高 | 无代理 API 接入和入侵厘清工作流 | 平台权限和客户配置仍无法完全掌控 |
| AI 智能体框架和 MCP 服务器 | Microsoft Semantic Kernel / MCP 生态 | 提示、工具和模型交互的执行层 | 中高 | 框架 CVE 或工具投毒打出利用路径 | 高 | MCP 清单、模型注册表、最小权限 | 覆盖缺口和高速演进的开放生态 |
| 资本市场可比对象 | 网络安全 SaaS 投资者和 M&A 买方 | 设定估值、估值下调轮和退出基准 | 中 | 网络安全倍数压缩,或收入证据不及预期 | 高 | 借强大投资方阵容融资,并披露可持续 KPI | 在 $1.1B 估值上面临降价轮或平轮风险 |
本表合并合作伙伴依赖与竞争压力风险,因为平台所有者和已融资竞争对手,是 Obsidian 风险调整后上行空间的主要外部约束。
[CR002, CR010, CR011, CR014, CR020, CR022]Obsidian 的剩余风险不只由内部产品执行决定,也被平台、智能体框架、竞争对手、资本提供方和企业买方左右。
该图只纳入引用来源中外部可见的依赖项和具名竞争者群体。
[CR002, CR010, CR011, CR020, CR025, CR033]7.2 技术、法律与威胁态势风险
同一威胁环境既验证了 Obsidian,也提高了产品在高风险场景中交付不足的风险。2026 年反向来源反复把提示词注入列为企业 AI 智能体首要风险;Microsoft 的 RCE 研究则显示,智能体框架行为可把提示操纵转化为 shell 级后果。Salesloft/Drift OAuth 事件尤其相关,因为它说明 AI 聊天智能体或 OAuth/NHI 被攻破后,影响会沿 Salesforce、AWS 和 Snowflake 表面级联——这正是 Obsidian 称自己能治理身份和动作的 SaaS 环境。MCP 漏洞覆盖和 OWASP MCP 指南又加上一层:资产清点、最小权限、模型注册表和运行时阻断是必要能力,但正在变成预期中的基线控制。因此,法律和监管暴露是间接但实质的。公开来源没有显示 Obsidian 当前有诉讼或执法行动,但企业买方会把漏报、权限过大的智能体和 SaaS 数据暴露视为合同、隐私和事件响应风险。Obsidian 的负担是证明它能在动作执行前阻断高级攻击,而不只是监控一个听起来吓人的品类。风险是不对称的,因为一个旗舰客户错过的漏洞,削弱信任的速度会快过许多安静阻断建立信任的速度,尤其是当事件叙事在安全社区传播时。[CR004, CR005, CR006, CR007, CR008, CR009]
| 规则 / 案例 | 管辖区 | 状态 | 可能性 | 严重性 | 缓释措施 | 残余暴露 | 尽调路径 |
|---|---|---|---|---|---|---|---|
| OAuth/NHI 泄露带来的隐私和合同暴露 | 美国 / 全球 SaaS 客户 | Salesloft/Drift 证明该威胁存在;未见针对 Obsidian 的公开法律程序 | 中 | 高 | 运行时治理、NHI 可见性、泄露厘清定位 | 假阴性可能演变为客户通知、隐私或合同纠纷 | 要求提供 DPA 条款、事件处置手册和客户通知历史 |
| 提示注入至 RCE 的责任 | 全球企业智能体框架 | Microsoft 2026 RCE 研究验证该类别 | 中 | 高 | 行动前拦截、对齐 OWASP 的控制、MCP 资产清单 | 客户可能将智能体框架沦陷视为供应商控制失效 | 审查针对 RCE / 提示注入链的红队结果 |
| MCP/CVE 漏洞治理 | 企业 AI 智能体技术栈 | CVE-2026-2256 和 OWASP MCP 指南显示风险活跃 | 中高 | 高 | 盘点每台 MCP 服务器,并映射模型 / 智能体 | 基线标准上升速度可能快于 Obsidian 证明差异化的速度 | 要求提供 MCP 漏洞管理 SLA 和例外报告 |
| 公司特定诉讼或执法 | 美国 / 全球 | 引用的公开来源未发现 Obsidian 诉讼或执法行动 | 目前低 | 中 | 法律尽调和标准企业合同 | 未知私人纠纷或客户索赔仍有可能 | 检索法律案卷,并要求管理层提供法律纠纷清单 |
| 原生平台安全控制替代 | Microsoft / Salesforce / Google 生态 | Microsoft 原生控制已在发布指南 | 高 | 高 | 以跨 SaaS 运行时可见性和第三方独立性做差异化 | 内嵌控制可能挤压利润率和合同范围 | 与 Microsoft/Salesforce/Google 路线图逐项功能对比 |
行按残余严重性排序;法律和监管暴露大多是间接的,因为公开来源显示的是威胁模式,而不是 Obsidian 的执法事项。
[CR004, CR005, CR006, CR010, CR018, CR022]| 失败模式 | 可能性 | 严重性 | 缓释成熟度 | 残余暴露 | 未解决缺口 |
|---|---|---|---|---|---|
| 提示注入绕过运行时策略 | 高 | 高 | 部分——产品声称可拦截,但缺少公开假阴性数据 | 高 | 需要独立红队结果和生产拦截率指标 |
| 智能体框架中的 RCE 推翻治理假设 | 中 | 高 | 部分——Obsidian 可映射 MCP/智能体,但框架安全性不一 | 高 | 需要框架覆盖矩阵和利用链测试 |
| OAuth / NHI 凭据失陷跨 SaaS 应用级联 | 中高 | 高 | 改善中——NHI 与 SaaS 集成安全是核心定位 | 高 | 需令牌吊销、爆炸半径和客户事件证据 |
| MCP 服务器 / 工具投毒漏洞 | 中高 | 中高 | 部分覆盖——已引用 MCP 清单和 OWASP 控制 | 中高 | 需清单准确性、负责人映射和策略例外证据 |
| 客户事件中,入侵厘清或取证响应不及预期 | 中 | 中高 | 部分覆盖——已有入侵厘清产品 | 中 | 需事后客户证言和识别用时证明 |
| 威胁叙事跑在实际产品范围前面 | 中 | 高 | 未知——公开主张很宽,但测试数据未公开 | 高 | 需证明运行时拦截发生在高风险动作执行前 |
威胁项把 2026 年反向事件证据与 Obsidian 声称的缓释面放在一起看;严重性是定性判断,不是内部事件发生概率。
[CR006, CR007, CR008, CR009, CR019, CR026]最高剩余严重性集中在可能性和影响都高的区域:平台商品化、提示注入 / RCE 有效性,以及估值不透明。
定性矩阵基于引用的公开来源;没有内部损失数据或概率模型可用。
[CR006, CR008, CR014, CR018, CR023, CR041]7.3 估值、财务、人员与执行风险
估值风险高,因为 $1.1 billion 投后价格对应的是未披露的 ARR、毛利率、NRR、现金消耗、资金可支撑月数和员工数。已披露付费指标有意义——100+ 个年付超过 $100,000 的客户、14+ 个年付超过 $1 million 的客户、60 家 Fortune 500 客户——但它们只建立下限。按标准事实表方法,ARR 至少约 $24 million,合理可能在 $40 million–$70 million;这把估值放进约 15x–45x 收入的宽估算区间。若公司是一个有耐久扩张的品类领导者,这个区间可以接受;但公开来源没有证明续约质量或收入集中度。因此,执行风险居中。Obsidian 拥有强创始人和技术履历,也有一位具备 Shape Security 商业化经验的非创始人 CEO;但它必须同时管理品类转向、企业平台伙伴关系、高级威胁研究和激烈竞争。正确的投资姿态不是否定公司,而是把价格、披露和阻断证明门槛说清楚。如果私有尽调不能把产品专属扩张与最新披露的客户门槛连接起来,投资人应把 Series D 视为战略验证,而不是耐久经济性的完整证明。[CR012, CR013, CR014, CR016, CR017, CR021]
| 角色 / 职能 | 依赖或缺口 | 发生可能性 | 严重性 | 缓释措施 | 尽调路径 |
|---|---|---|---|---|---|
| CEO / 商业化领导力 | Hasan Imam 必须把 AI 智能体风险紧迫感转成可持续的 Global 2000 合同 | 中 | 高 | 过往 Shape Security 商业化背景 | 按客群复核销售漏斗转化率、ASP、赢单 / 输单和销售周期 |
| 创始人技术领导力 | Chisholm、Johnson 和 Wolff 仍是产品可信度的核心 | 中 | 中高 | 有深厚 Cylance、Carbon Black 和数据科学背景 | 评估继任梯队深度和产品决策权 |
| 威胁研究与红队职能 | 必须跟上提示注入、RCE、MCP 和 OAuth / NHI 攻击节奏 | 高 | 高 | 安全研究,并把产品扩展到运行时控制 | 索取红队节奏、漏报趋势和漏洞利用覆盖 |
| 平台合作与集成团队 | 平台 API 和权限差异再大,也需要广泛覆盖第三方 SaaS | 中高 | 高 | 无代理接入和 SaaS 集成安全定位 | 按应用检查覆盖范围、API 限制和例外积压 |
| 财务与投资者关系纪律 | 即便 ARR 和员工数未披露,也必须支撑 $1.1B 估值 | 中 | 高 | 高质量投资银团和 $85M 新资金 | 索取经审计 ARR 桥接、留存队列、烧钱速度、现金跑道和员工数计划 |
执行风险按未来一轮融资周期内影响估值或续约质量的能力排序。
[CR012, CR014, CR017, CR021, CR038, CR039]| 风险 | 可监测触发项 | 阈值 / 事件 | 行动含义 |
|---|---|---|---|
| 原生平台商品化 | Microsoft / Salesforce / Google 打包可比运行时控制 | 企业许可证已覆盖 Obsidian 核心用例 | 下调定价假设,把差异化视为尚未证明 |
| 产品有效性失败 | 独立红队或客户事件显示提示注入 / RCE 可绕过 | 重大绕过没有快速修复和客户证据 | 建议转向继续研究或回避,直到修复 |
| 估值 / 披露风险 | 尽调中 ARR、NRR、烧钱速度或毛利率仍未披露 | 无法支撑 $40-70M ARR 区间或留存质量 | 要求重设价格、加结构,或放弃 |
| 市场时机风险 | AI 智能体治理商机管线未能从试点转为年度合同 | 2-3 个季度后付费转化低,或续约附加弱 | 下调增长情景,推迟投资 |
| 竞争份额流失 | Zenity 或 SSPM 同行反复赢下 Fortune 500 比选 | 失单源于产品缺口,而不只是价格 | 重估护城河和销售效率假设 |
| 客户集中度 | 14+ 个 $1M 账户占 ARR 过高,或有一个账户流失 | 头部客户集中度超过尽调阈值 | 提高折现率,并要求客户访谈核验 |
否决标准是可观察的尽调或投后事件,会直接改变风险评级或估值立场。
[CR016, CR017, CR022, CR023, CR027, CR033]技术、平台、财务和执行风险最终汇入续约信任、利润率和 $1.1B 估值叙事。
DAG 只表示方向;不量化因果权重。
[CR024, CR025, CR038, CR039, CR042]7.4 图表
08估值
8.1 D 轮价格与隐含倍数
Obsidian 2026 年 8 月 4 日的 D 轮融资,让估值章节有了明确标题,也留下了模糊分母。分子证据充分:公司宣布由 Crescent Cove Advisors 领投,以 $1.1B 投后估值融资 $85M,老股东继续跟进,累计融资已超过 $200M。难点在分母。Obsidian 披露有 100+ 个客户每年支出至少 $100,000,14+ 个客户支出至少 $1M,另有 60 家 Fortune 500 客户,但没有披露 ARR、增长、利润率、留存、现金消耗、续航期或员工数。沿用财务章节的公开下限法,已披露支出层级推导出约 $24M ARR;合理承销区间仍约为 $40M–$70M。这个区间让 $1.1B 价格高度敏感:按下限约 46x,按 $50M 为 22x,按 $70M 为 15.7x。因此,这一估值并非讲不通,但对价格和证据都极其敏感。[CV001, CV002, CV003, CV004, CV007, CV008]
| 维度 | 当前立场 | 决策含义 |
|---|---|---|
| 投资建议 | 观察 / 继续研究 | 只有管理层证明 ARR 规模和条款干净后才推进;不要盲目接受表面价格。 |
| 置信度 | 中 | 公开证据足以给出区间,不足以形成单点估值确信。 |
| 风险评级 | 高 | 价格取决于未公开 ARR、增长、留存、利润率和股权结构证据。 |
| 估值立场 | 偏高 | 只有 ARR 已经较高才说得通;若 ARR 接近已披露支出下限,估值偏高。 |
| 决策含义 | 围绕价格和证据严格推进后续跟进 | 不要把独角兽标签当成投资触发器,要看尽调门槛。 |
建议反映截至 2026-08-05 的公开证据,并把未披露 ARR 视为主导估值不确定性的变量。
[CV030, CV031, CV032, CV033, CV044]| 立场 | 论点 | 什么会强化 | 什么会改变判断 |
|---|---|---|---|
| 投资逻辑 | AI 智能体和 NHI 安全是庞大且紧迫的控制平面问题,Obsidian 已显示 Fortune 500 牵引力。 | 经审计 ARR 高于 $50M,NRR / GRR 强劲,并证明智能体治理收入快速增长。 | 留存偏弱、预算转化慢,或平台原生控制吸走市场。 |
| 投资逻辑 | D 轮投资方阵容和老股东参与,降低融资质量疑虑。 | 优先股堆叠干净,内部投资者按比例跟投,显示这是信心而非救助融资。 | 沉重优先权、结构化条款,或后续轮投资者疲劳。 |
| 反向逻辑 | $1.1B 价格可能跑在公开财务证据前面。 | 公司提供从已披露客户支出到合同经常性收入的 ARR 桥接。 | 经审计 ARR 低于 $40M,或有证据显示 $24M 下限接近现实。 |
| 反向逻辑 | Zenity 和平台厂商削弱新兴品类的稀缺性溢价。 | 提供对 Zenity 和 Microsoft 原生控制的清晰赢单 / 输单证据。 | 大型企业预算标准化到平台控制,而非独立厂商。 |
本表把公司质量论点与价格支撑论点分开,因为估值判断明确对价格敏感。
[CV023, CV028, CV029, CV037, CV040]| 情景 | 假设 | 估值 / 回报逻辑 | 概率信号 |
|---|---|---|---|
| 乐观 | ARR 接近 $70M+,增长仍享受溢价,智能体治理收入放量,网络安全溢价可比对象窗口仍在。 | 约 $1.3B-$1.8B 支撑,对应约 19-25x ARR;$1.1B 入场价可能跑通。 | 需要尚未公开的私有证据。 |
| 基准 | ARR 约 $40M-$50M,标杆客户强,但利润率 / 留存证据不完整,投资者打入不透明折价。 | 约 $0.6B-$1.1B 支撑,对应约 15-22x ARR;当前价格在区间顶部。 | 最能被公开证据支撑。 |
| 悲观 | ARR 接近 $24M 下限,品类采用放慢,或可比倍数压缩至 8-13x。 | 约 $0.2B-$0.5B 支撑;相对 $1.1B 的下行很大。 | ARR 未披露,不能排除。 |
| 泡沫情景 | 尽管仍在亏损,私有网络安全融资仍以异常倍数成交。 | 类似 Cyera 的 80x ARR 数据可能暂时验证高估值,但也抬高修正风险。 | 这是反向信号,不是基准承销情景。 |
区间是简单的 ARR 乘倍数情景,单位为美元企业价值十亿;不是管理层指引,也不是 DCF。
[CV010, CV011, CV012, CV018, CV022, CV034]推荐结论从强品类证据出发,最终收束到估值偏高、必须拿证据过关。
该流程展示投资判断逻辑,不代表公司运营流程。
[CV024, CV028, CV029, CV030, CV033, CV044]估值区间图显示,除非 ARR 已在高位,Series D 轮附近能站住的合理区间很窄。
区间单位为十亿美元,只表示简单倍数情景,不是正式估值意见。
[CV001, CV010, CV011, CV012, CV034, CV035]8.2 可比倍数框架
可比框架给出的是分裂结论。Windsor Drake 2026 年网络安全研究显示,普通上市网络安全公司接近 6–8x NTM 收入,云或 AI 原生头部公司约 14–22x,非上市网络安全公司约 15.2x,顶级云 M&A 最高可到 35x。上市可比公司呈现的是离散分布,而不是单一答案:CrowdStrike 按 FY26 收入 $4.81B 和 ARR $5.25B 约 25.1x;Zscaler 按约 $3.17B TTM 收入和约 $25B 市值约 11.7x;Palo Alto 约 15x,Cloudflare 约 31.5x,Fortinet 约 8.7x,Okta 约 5x。私有交易和 M&A 参考更不稳定。Wiz 以 $32B 估值和 $1B+ ARR 支撑战略稀缺性溢价;Cyera 即便亏损仍被讨论 80x ARR,则是泡沫过热的反向提醒。NinjaOne 表明,只要高速增长同时带来盈利,投资人仍愿意付高价。只有尽调验证 ARR 高、增长可持续,Obsidian 才配进入溢价组比较。[CV013, CV014, CV015, CV016, CV017, CV018]
| 可比对象 | 指标基数 | 倍数 / 价值 | 相关性 | 限制 | 来源引用 |
|---|---|---|---|---|---|
| CrowdStrike | FY26 收入 $4.81B;ARR $5.25B | 约 25.1x EV/Revenue | 优质网络安全龙头标杆,用来衡量一流增长韧性。 | 规模大得多,已上市,财务透明。 | SV002; SV003; SV005 |
| Zscaler | TTM 收入约 $3.17B;市值约 $25B | 约 11.7x EV/Revenue | 低于优质龙头区间的云安全参照。 | 上市公司规模和披露都超过 Obsidian。 | SV002; SV004 |
| Palo Alto Networks | 上市平台型网络安全可比对象 | 约 15x EV/Revenue | 大型战略平台参照,衡量安全整合需求。 | 成熟多产品平台,不是私有智能体安全专门厂商。 | SV001; SV002 |
| Cloudflare | 上市云 / 边缘安全可比对象 | 约 31.5x EV/Revenue | 显示市场可为云原生稀缺性付出多高价格。 | 商业模式和规模不同于 Obsidian。 | SV001; SV002 |
| Fortinet | 上市网络安全可比对象 | 约 8.7x EV/Revenue | 较低倍数提醒:不能假设所有网络安全标的都有溢价。 | 硬件 / 软件组合和成熟度不同。 | SV001; SV002 |
| Okta | 上市身份安全可比对象 | 约 5x EV/Revenue | 身份相邻赛道的下限参照,用来衡量情绪风险。 | 增长和品类认知不同于 AI 智能体安全。 | SV001; SV002 |
每行至少使用两个保留来源;上市公司倍数是参照区间,不是针对私有公司的直接公平性意见。
[CV013, CV014, CV015, CV016, CV033]| 可比对象 | 估值 / 状态 | 指标或倍数 | 相关性 | 限制 | 来源引用 |
|---|---|---|---|---|---|
| Wiz / Google | Google 已完成 $32B 收购 | Wiz 到 2025 年 ARR 超过 $1B,约 30x 参照 | 云安全退出的战略稀缺性可比对象。 | ARR 规模大得多,且更契合战略平台。 | SV006; SV009; SV010 |
| Cyera | 据报道寻求 $12B 估值 | 尽管经营亏损,仍为 80x ARR | 私有网络安全估值标记的反向泡沫信号。 | 数据安全品类和亏损画像不同于 Obsidian。 | SV007; SV001; SV030 |
| NinjaOne | 私有估值约 $12.3B | 约 70% 增长且已盈利 | 显示高端私有定价可以由基本面支撑。 | IT 管理模式不同于智能体 / NHI 安全。 | SV008; SV001 |
| PANW / CyberArk | Palo Alto-CyberArk $25B 参照 | 战略身份安全整合 | 支撑身份 / 安全控制平面的退出需求。 | 不是直接的私有成长轮可比对象。 | SV010; SV009; SV011 |
| Obsidian D 轮 | $85M 融资后的投后估值 $1.1B | 若 ARR 约 $50M,则约 22x;按约 $24M 下限则约 46x | 标的公司;检验价格是否落在可支撑的网络安全区间内。 | ARR 和条款未公开。 | SV012; SV013; SV001 |
私募和 M&A 可比对象刻意保持异质;它们框定退出胃纳和泡沫风险,而不是定义一个直接同业倍数。
[CV017, CV018, CV019, CV020, CV044]只有 ARR 已处高位,Obsidian 才接近高溢价上市公司区间;若 ARR 贴近下限,就会落入泡沫化区域。
数值为 EV/Revenue 或 ARR 倍数;Obsidian 数值由披露支出层级和估值推算。
[CV010, CV011, CV012, CV013, CV014, CV015]8.3 情景建议与 KPI
建议是跟踪,而不是无条件买入,因为 D 轮价格偏贵,公开证据不完整。正向论点有吸引力:AI 智能体 / NHI 安全市场很大,Fortune 500 客户已验证,财团支持强,运行时治理能力也契合新的企业控制平面。反向论点同样重要:品类时点仍早,Zenity 早一天融资 $125M,Microsoft 和其他平台可能吸收部分工作流,收入分母仍是私有信息。牛市情景需要 ARR 接近 $70M、高增长,且市场能容忍上市可比公司的溢价倍数;基准情景假设 ARR 为 $40M–$50M,且给予不透明折价;熊市情景采用 $24M 下限和压缩倍数。这些情景对应的是估值偏紧、信心中等、风险较高。IC 应持续观察市场规模、客户证据、护城河、经济性、竞争、估值和证据质量,而不是把独角兽头衔本身当成证明。[CV023, CV024, CV025, CV026, CV027, CV028]
Obsidian 在市场拉力和客户验证上得分最高,在估值支撑和财务透明度上最低。
评分是基于公开证据推导的 IC 定性评级,不是公司披露的 KPI。
[CV021, CV024, CV027, CV028, CV031, CV032]8.4 退出准备度与最终尽调
退出可选性真实存在,但还不足以抹平估值风险。网络安全 M&A 活跃度、Google / Wiz、Palo Alto / CyberArk,都说明市场对稀缺安全控制平面有战略胃口;Obsidian 切入 AI 智能体治理,也给了它一个说得通的战略叙事。不过,以 $1.1B 入场,需要公开来源没有提供的尽调证据。买方或投资人需要审计后的 ARR、基于客户层级的 ARR 桥接表、毛利率、现金消耗、NRR、GRR、同期群留存、客户集中度、员工数和清晰的股权结构条款。最重要的否决触发点包括:ARR 低于约 $40M、$24M 下限接近真实情况的证据、14 个百万美元级账户内部集中、平台厂商捕获预算,或网络安全倍数整体压缩。如果管理层证明 ARR 高且优先权条款干净,这一估值可以作为增长溢价型网络安全轮次来辩护;否则,D 轮按估算 ARR 看偏紧,只应在有价格保护时接近。[CV021, CV037, CV038, CV039, CV040, CV041]
| 触发项 | 阈值 / 事件 | 传导到投资判断 | 行动含义 |
|---|---|---|---|
| ARR 证据不达标 | 经审计 ARR 低于 ~$40M,或接近 ~$24M 底线。 | 隐含倍数会远高于上市 / 私有网络安全公司的常规区间。 | 若没有重大价格保护,不要按 $1.1B 投资测算。 |
| 留存或集中度风险 | NRR/GRR 偏弱,或 14 个 $1M+ 客户内部集中度偏高。 | 客户证明无法支撑收入质量的可持续性。 | 下调倍数,并要求提供队列层面的证据。 |
| 平台商品化 | Microsoft 或其他平台吞掉智能体治理预算。 | 稀缺性溢价和独立供应商定价权受到挤压。 | 重新评估品类份额和销售周期假设。 |
| 倍数压缩 | 上市 / 私有网络安全公司估值中位数跌破投资测算区间。 | 即使经营兑现,退出价值也会下降。 | 使用更低退出倍数,并重新核算持股比例和回报。 |
| 结构性条款 | Series D 条款栈里出现高额清算优先权、参与分配权或反稀释。 | 名义估值高估普通股回报。 | 推进前先建模清算瀑布。 |
否决触发条件锚定可观察的尽调产出或市场数据,而不是泛泛的风险表述。
[CV038, CV039, CV040, CV041, CV043]| 主题 | 缺失证据 | 重要性 | 尽调路径 |
|---|---|---|---|
| ARR 桥接 | 合同 ARR、收入,以及从客户支出层级推导的桥接。 | 决定隐含倍数应是 22x 还是 46x。 | 要求提供 CFO 签认的 ARR 明细表和客户层级滚动表。 |
| 增长与留存 | 收入增长、NRR、GRR、流失、扩张和队列留存。 | 高溢价倍数需要持续扩张,而不只是客户名单。 | 要求提供董事会 KPI 包和队列表。 |
| 经济模型与现金消耗 | 毛利率、贡献利润率、现金消耗、现金跑道和员工数。 | 若出现 Cyera 式经营亏损,高倍数下泡沫风险会放大。 | 要求提供月度财务报表和经营计划。 |
| 客户集中度 | 前十大客户收入占比,以及 14 个 $1M+ 账户中的集中度。 | 大客户既能支撑 ARR,也可能带来脆弱性。 | 要求提供匿名化客户集中度明细和客户背调名单。 |
| 股权结构和优先权 | 清算优先权、参与分配权、期权池、附函和按比例认购权。 | 投资人回报可能不同于企业价值。 | 审阅融资文件和股权结构模型。 |
| 竞争证据 | 与 Zenity、Microsoft 原生控制和既有网络安全平台相比的赢单 / 输单。 | 决定估值是否配得上稀缺性溢价。 | 开展客户访谈,并按竞争对手审阅销售管线转化。 |
这些问题是从公开证据区间走到可投资价格所需的最低材料包。
[CV037, CV042, CV043, CV044]8.5 展项
免责声明
本报告基于截至 2026-08-05 的公开信息,是分析性尽调材料,不构成投资建议。
证据索引
| 编号 | 陈述 | 可信度 | 来源 |
|---|---|---|---|
| CO001 | Current August 2026 coverage identifies Obsidian Security as Palo Alto, California-based, so Palo Alto is the canonical headquarters for this run. | 高 | SO001, SO010, SO013 |
| CO002 | Some legacy third-party profile surfaces still point to Newport Beach or otherwise conflict with the Palo Alto headquarters evidence, creating a headquarters reconciliation gap rather than a new canonical HQ. | 中 | SO017, SO019 |
| CO003 | Obsidian Security was founded in 2017 by Glenn Chisholm, Ben Johnson, and Matt Wolff. | 中 | SO015, SO019, SO020 |
| CO004 | Glenn Chisholm is publicly described as Co-Founder, Chairman, and Chief Product Officer with prior CTO experience at Cylance and first-CISO experience at Telstra. | 中 | SO015, SO019 |
| CO005 | Ben Johnson is described in the canonical fact sheet and ownership profiles as a co-founder and CTO with Carbon Black founder experience before VMware acquired Carbon Black. | 中 | SO019, SO020 |
| CO006 | Matt Wolff is part of the 2017 founder set and is positioned as Chief Scientist with data-science roots from Cylance. | 中 | SO015, SO019 |
| CO007 | Hasan Imam is the current CEO quoted in the August 2026 Series D narrative and is not part of the disclosed founder set. | 高 | SO001, SO002, SO018, SO022 |
| CO008 | Norwest describes Imam as a former Chief Revenue and Customer Officer at Shape Security, a company later acquired by F5 for about $1 billion. | 中 | SO022, SO025 |
| CO009 | Obsidian sells runtime governance and security for AI agents and non-human identities operating inside enterprise third-party SaaS applications. | 高 | SO002, SO004, SO005, SO020 |
| CO010 | The company has pivoted from SaaS Security Posture Management toward AI-agent governance and runtime controls for non-human identities. | 中 | SO001, SO005, SO021, SO022 |
| CO011 | Obsidian announced an $85 million Series D on August 4, 2026. | 高 | SO001, SO002, SO003, SO007, SO010 |
| CO012 | The August 2026 Series D valued Obsidian at $1.1 billion post-money, making it a private Series D unicorn. | 高 | SO001, SO002, SO009, SO010, SO011 |
| CO013 | Crescent Cove Advisors led the Series D, with founder and CIO Jun Hong Heng named in the financing coverage. | 高 | SO001, SO002, SO008, SO010 |
| CO014 | Existing investors Greylock, Menlo Ventures, Norwest Venture Partners, IVP, Wing, and GV participated in the Series D. | 高 | SO001, SO002, SO010, SO023 |
| CO015 | After the Series D, Obsidian has raised more than $200 million across five rounds. | 高 | SO001, SO002, SO007, SO009 |
| CO016 | Obsidian closed a $90 million Series C in April 2022 led by Menlo Ventures, Norwest Venture Partners, and IVP, with total funding at that time reaching $119.5 million. | 中 | SO001, SO021, SO022 |
| CO017 | Norwest led Obsidian's Series B-1 in June 2021. | 中 | SO022, SO025 |
| CO018 | Greylock led Obsidian's earliest institutional Series A round, making it a foundational investor rather than only a late-stage participant. | 中 | SO016, SO024 |
| CO019 | Series D coverage reports that more than 100 Obsidian customers each spend over $100,000 per year. | 高 | SO001, SO002, SO003, SO010 |
| CO020 | Series D coverage reports that more than 14 Obsidian customers each spend over $1 million per year. | 高 | SO001, SO002, SO003, SO010 |
| CO021 | Series D coverage reports that 60 Fortune 500 companies are Obsidian customers. | 高 | SO001, SO002, SO003, SO010 |
| CO022 | The company states that non-human identities outnumber human identities 144:1 inside third-party applications. | 高 | SO001, SO002, SO020 |
| CO023 | The CEO said more than 70% of customers already permit AI agents into third-party applications. | 高 | SO001, SO002 |
| CO024 | Obsidian does not publicly disclose revenue or ARR in the retained 2026 source set. | 中 | |
| CO025 | Obsidian does not publicly disclose current headcount in the retained 2026 source set. | 中 | |
| CO026 | A narrow inferred ARR floor is approximately $24 million, calculated as 100 customers at $100,000 plus 14 customers at $1 million; it is an estimate, not disclosed ARR. | 中 | SO001, SO002, SO010 |
| CO027 | The Series D proceeds are intended to fund research and development and deepen Obsidian's reach across Fortune 500 and Global 2000 accounts. | 高 | SO001, SO002, SO008, SO023 |
| CO028 | The company page frames the mission around securing non-human identities and AI adoption across more than 35,000 third-party applications. | 高 | SO020, SO004 |
| CO029 | Public sources do not disclose a complete current board roster, observer rights, secondaries, debt facilities, or control terms. | 中 | |
| CO030 | The latest investor group combines a new lead investor, Crescent Cove, with repeat venture investors from earlier rounds. | 高 | SO001, SO002, SO016, SO022, SO023 |
| CO031 | Zenity raised $125 million on August 3, 2026, one day before Obsidian's Series D announcement, creating a competitive-context caveat for AI-agent governance fundraising momentum. | 中 | SO006 |
| CO032 | The April 2022 Series C positioned Obsidian as an SSPM leader before the 2026 narrative centered on agent runtime governance. | 中 | SO021, SO022, SO001 |
| CO033 | Obsidian's homepage tagline, Secure AI and Fearless Innovation, aligns the current brand around AI-security enablement rather than only SaaS posture hygiene. | 高 | SO004, SO020 |
| CO034 | FinTech Global describes Obsidian capabilities around MCP inventory, model registry visibility, runtime governance, and OWASP-aligned controls for rogue AI agents. | 中 | SO005, SO002 |
| CO035 | Craft lists Hasan Imam as CEO and provides an executive roster, but the public source set still does not amount to a complete governance org chart. | 中 | SO018, SO001 |
| CO036 | StartupHub and ownership-profile sources support Glenn Chisholm's public founder identity and reinforce the three-founder founding narrative. | 中 | SO015, SO019 |
| CO037 | Yahoo Finance coverage corroborates the Series D amount, valuation, and investor syndicate with a high-reputation independent source. | 高 | SO010, SO001, SO002 |
| CO038 | StartupRise describes Obsidian as California-based in its Series D coverage, consistent with the current Palo Alto headquarters evidence. | 中 | SO013, SO001 |
| CO039 | Seedtable records the August 2026 Series D as a funding-round datapoint, providing an independent database-style check on the news flow. | 中 | SO014, SO001 |
| CO040 | The druce.ai vendor profile is useful as a third-party profile surface but is lower-reputation and should not override fresher 2026 Series D identity evidence. | 中 | SO017, SO001 |
| CO041 | The combination of founder-heavy product leadership and non-founder CEO leadership creates a key-person diligence item rather than a proof of governance weakness. | 中 | SO015, SO018, SO022 |
| CO042 | The latest disclosed scale metrics are company-reported customer-spend thresholds and Fortune 500 penetration, not audited revenue, retention, or margin figures. | 中 | SO001, SO002, SO010 |
| CO043 | The snapshot should present $1.1 billion valuation, more than $200 million raised, 100-plus six-figure customers, 14-plus seven-figure customers, and 60 Fortune 500 customers while showing ARR, revenue, and headcount as null. | 中 | SO001, SO002, SO010 |
| CO044 | Obsidian's public profile is best interpreted as a late-stage private cybersecurity company with strong financing validation but incomplete financial disclosure. | 中 | SO001, SO002, SO010, SO024, SO025 |
| CO045 | The milestone sequence shows a compressed category pivot: SSPM financing in 2021-2022, an AI-agent competitive funding shock on August 3, 2026, and Obsidian's unicorn Series D one day later. | 中 | SO006, SO001, SO021, SO022 |
| CO046 | The operating model links SaaS application telemetry, non-human-identity inventory, runtime policy enforcement, Fortune 500 demand, and growth capital into one AI-agent governance platform story. | 中 | SO001, SO002, SO005, SO020 |
| CO047 | The KPI set is mature enough to establish late-stage traction but insufficient to underwrite valuation without management-provided ARR, NRR, gross margin, burn, and headcount data. | 中 | SO001, SO002, SO010 |
| CM001 | Obsidian announced an $85 million Series D on August 4, 2026 at a $1.1 billion post-money valuation, confirming unicorn-stage market validation rather than a seed-stage category experiment. | 高 | SM001, SM002, SM003, SM010 |
| CM002 | Obsidian disclosed more than 100 customers spending at least $100,000 annually and more than 14 customers spending at least $1 million annually. | 高 | SM001, SM002 |
| CM003 | Obsidian reported 60 Fortune 500 customers, giving the market analysis a buyer base anchored in enterprise security budgets rather than SMB experimentation. | 高 | SM001, SM002 |
| CM004 | Chief Executive Hasan Imam said more than 70% of Obsidian customers already allow AI agents into third-party applications. | 中 | SM001, SM002 |
| CM005 | Obsidian states that non-human identities outnumber human identities 144 to 1 inside third-party applications. | 高 | SM001, SM002, SM017 |
| CM006 | Obsidian frames its mission around securing AI adoption across more than 35,000 third-party applications used by enterprises. | 中 | SM017 |
| CM007 | Obsidian positions its product as runtime governance and security for AI agents and non-human identities operating inside enterprise SaaS applications. | 高 | SM002, SM004, SM005 |
| CM008 | SNS Insider sizes the AI Agent Security market at approximately $26 billion in 2026, growing at roughly 39.1% CAGR toward about $507 billion by 2035. | 中 | SM018 |
| CM009 | MarketsandMarkets sizes the narrower Agentic AI Security market at approximately $1.65 billion in 2026 with roughly 42% CAGR to about $13.5 billion by 2032. | 中 | SM022 |
| CM010 | Mordor Intelligence sizes the Non-Human Identity Security market at approximately $8.22 billion in 2026 with 22.78% CAGR through 2031. | 中 | SM019 |
| CM011 | Research and Markets sizes the SSPM software market at approximately $3.69 billion in 2026 with a 12.6% CAGR to 2032. | 中 | SM020 |
| CM012 | Frost & Sullivan reports a materially smaller SSPM baseline of about $484.4 million in 2025, growing to about $3.53 billion by 2030 at 48.7% CAGR. | 中 | SM023, SM024 |
| CM013 | InsightAce Analytic sizes the broader Security Posture Management market at about $26.35 billion, a broad adjacency that includes more than third-party SaaS governance. | 中 | SM021 |
| CM014 | Mordor Intelligence sizes the Identity Threat Detection and Response market at about $3.42 billion in 2026, growing to about $10.51 billion by 2031 at 25.17% CAGR. | 中 | SM025 |
| CM015 | The most defensible TAM for Obsidian is the approximately $26 billion 2026 AI Agent Security market, because the product is explicitly positioned around securing autonomous agents in enterprise environments. | 中 | SM004, SM005, SM018 |
| CM016 | A defensible 2026 SAM is approximately $8 billion to $12 billion, bounded by NHI Security at $8.22 billion plus SSPM at $3.69 billion while discounting overlap across identity and SaaS-posture budgets. | 中 | SM019, SM020, SM022 |
| CM017 | A near-term Obsidian SOM of approximately $50 million to $150 million is an estimate that extends from disclosed high-ACV customer counts rather than from public ARR disclosure. | 中 | SM001, SM002 |
| CM018 | The disclosed customer thresholds imply a minimum annual recurring revenue floor of about $24 million, calculated as 100 customers at $100,000 plus 14 customers at $1 million. | 中 | SM001, SM002 |
| CM019 | A plausible current ARR range of about $40 million to $70 million is an inference from the disclosed customer mix and should not be presented as reported revenue. | 中 | SM001, SM002 |
| CM020 | The Research and Markets and Frost SSPM estimates conflict materially on baseline size and growth rate, so SSPM should be treated as an uncertainty band rather than a single precise market-size input. | 中 | SM020, SM023, SM024 |
| CM021 | Obsidian-relevant spend includes AI-agent runtime controls, non-human-identity governance, SSPM, SaaS-to-SaaS integration security, and ITDR-like identity detection workflows. | 中 | SM004, SM005, SM019, SM020, SM025 |
| CM022 | Broad CSPM, DSPM, ISPM, and generic security posture management spend should be excluded from Obsidian SAM unless it directly protects third-party SaaS, agent identities, or SaaS-integrated workflows. | 中 | SM021, SM017 |
| CM023 | Status-quo substitutes include manual SaaS reviews, IdP-native controls, spreadsheet access approvals, doing nothing, and native platform governance from the SaaS or AI platform owner. | 中 | SM017, SM005 |
| CM024 | The buyer set spans CISOs, security-operations teams, identity owners, SaaS application owners, and AI-platform governance teams because the protected workflow crosses identity, apps, and autonomous execution. | 中 | SM002, SM005, SM017 |
| CM025 | Fortune 500 penetration indicates payer capacity in large security and identity budgets, but it does not disclose whether spend comes from CISO, IAM, SaaS owner, or AI-transformation budget lines. | 中 | SM001, SM002 |
| CM026 | Obsidian extends governance to agent-building platforms and autonomous developer agents, which places adoption in the path of Microsoft Copilot Studio, Salesforce Agentforce, n8n, Claude Code, and similar workflows. | 中 | SM002, SM005 |
| CM027 | Obsidian describes MCP inventory and model-registry visibility as part of the control plane for tracking which agents invoke which external tools and models. | 中 | SM005 |
| CM028 | The 144-to-1 NHI ratio creates an identity-governance driver because automated actors expand faster than human headcount and can hold privileged app access. | 中 | SM001, SM002, SM019 |
| CM029 | The more-than-35,000 third-party-app surface creates a SaaS-governance driver because each app can accumulate integrations, agents, OAuth grants, and over-permissioned non-human identities. | 中 | SM017, SM005 |
| CM030 | The reported 70% customer agent-adoption rate is a near-term demand driver but also implies Obsidian must prove controls work in live deployments rather than merely future roadmaps. | 中 | SM001, SM002 |
| CM031 | Zenity raised $125 million one day before Obsidian's Series D, which validates investor interest in AI-agent security while creating a well-funded direct competitive constraint. | 中 | SM006 |
| CM032 | Well-funded direct competition can reduce Obsidian's obtainable market share if buyers compare agent-governance platforms rather than treating Obsidian as a category default. | 中 | SM006, SM001 |
| CM033 | Obsidian says new capital will fund R&D and deeper expansion into Fortune 500 and Global 2000 accounts, aligning growth investment with the enterprise SAM rather than consumer or SMB demand. | 中 | SM001, SM002, SM008 |
| CM034 | MarketsandMarkets indicates North America accounts for more than 40% of Agentic AI Security demand, supporting an initial enterprise go-to-market centered on large North American accounts. | 中 | SM022 |
| CM035 | The ITDR market creates an adjacent identity-security budget path for Obsidian, but ITDR is not identical to agent runtime governance and should not be fully counted as SAM. | 中 | SM025, SM005 |
| CM036 | The broad $26.35 billion Security Posture Management lens is useful for adjacency context but overstates Obsidian's directly serviceable market because it includes posture-management categories outside SaaS and agents. | 中 | SM021, SM017 |
| CM037 | The SSPM estimate disagreement spans roughly $0.48 billion in 2025 to $3.69 billion in 2026 depending on source and taxonomy, making market-size uncertainty an adverse underwriting input. | 中 | SM020, SM023, SM024 |
| CM038 | Every market-size value used in this chapter is an analyst estimate or diligence derivation, not observed Obsidian revenue or contractual bookings. | 中 | SM018, SM019, SM020, SM022, SM025 |
| CM039 | Obsidian's disclosed high-ACV customers de-risk willingness to pay, but the lack of public ARR, NRR, churn, and headcount prevents a precise SOM conversion. | 中 | SM001, SM002 |
| CM040 | No cited public source discloses a management-grade revenue split by product line, customer segment, budget owner, or geography. | 中 | SM001, SM002, SM017 |
| CP001 | Obsidian positions itself around securing AI adoption and third-party SaaS applications rather than only legacy SaaS posture management. | 高 | SP002, SP004 |
| CP002 | Obsidian announced an $85 million Series D on August 4, 2026 at a $1.1 billion valuation. | 高 | SP001, SP002, SP003 |
| CP003 | Obsidian disclosed more than 100 customers spending at least $100,000 annually, more than 14 customers spending at least $1 million annually, and 60 Fortune 500 customers. | 高 | SP001, SP002 |
| CP004 | Obsidian says more than 70% of its customers already allow AI agents into third-party applications. | 高 | SP001, SP002 |
| CP005 | Obsidian cites a 144:1 ratio of non-human to human identities inside third-party applications. | 高 | SP001, SP002 |
| CP006 | Obsidian's runtime-governance claim is that it can detect and block privilege escalation, excessive data access, and policy violations before agent actions take effect. | 高 | SP002, SP005 |
| CP007 | Zenity raised a $125 million Series C led by Norwest on August 3, 2026, one day before Obsidian's Series D. | 高 | SP006, SP018, SP021, SP023 |
| CP008 | Zenity publicly disclosed 230-plus staff, New York headquarters, Tel Aviv R&D, and founders Ben Kliger and Michael Bargury. | 高 | SP018, SP021 |
| CP009 | Zenity's Series C syndicate included Norwest, SoftBank Vision Fund 2, Qumra, Hitachi Ventures, LG Tech Ventures, Vertex, Third Point, DTCP, and Intel Capital. | 中 | SP018, SP020, SP023 |
| CP010 | Zenity says it secures AI agents across enterprise agent-building surfaces such as Copilot Studio and Salesforce Agentforce. | 中 | SP006, SP012, SP021 |
| CP011 | Obsidian's public platform coverage includes Microsoft Copilot Studio, Salesforce Agentforce, n8n, autonomous developer agents, Claude Code, and Cowork. | 高 | SP002, SP005 |
| CP012 | Grip Security directly claims Obsidian lacks some shadow SaaS, shadow AI, and automated-remediation capabilities that Grip provides. | 中 | SP008 |
| CP013 | Grip positions itself around complete SaaS and AI control, making it a competitor in discovery, identity governance, and remediation workflows. | 中 | SP008, SP009, SP013 |
| CP014 | Push Security positions itself as browser security for the AI era, implying a differentiated browser-layer telemetry and control point. | 中 | SP010, SP014 |
| CP015 | Nudge Security positions around SaaS and AI security discovery and behavioral nudges rather than deep runtime blocking. | 中 | SP010, SP011, SP015 |
| CP016 | Valence Security positions around SaaS and AI security for the agentic era, creating overlap with Obsidian's SaaS-to-SaaS and NHI governance story. | 中 | SP011, SP016 |
| CP017 | AppOmni remains an established enterprise SaaS security and SSPM competitor, especially when buyers define the problem as SaaS posture rather than AI-agent runtime control. | 中 | SP007, SP017 |
| CP018 | UpGuard's competitor page describes Obsidian as ITDR and knowledge-graph oriented while noting gaps such as EASM or external security ratings. | 中 | SP007 |
| CP019 | SpotSaaS places Nudge, Obsidian, and Push in a direct comparison set, supporting the view that buyers compare SaaS and AI security products across different control layers. | 中 | SP010 |
| CP020 | CloudEagle's Nudge-alternatives page includes Valence and other SaaS-management or SaaS-security vendors, showing adjacent pressure around discovery and SaaS workflow control. | 中 | SP011 |
| CP021 | CB Insights' Grip alternatives page confirms that SaaS and identity-security buyers have a broader set of substitute vendors beyond Obsidian and Zenity. | 中 | SP009 |
| CP022 | Zenity has publicly reported revenue tripling for two consecutive years, a growth signal that intensifies direct competition for AI-agent security budgets. | 中 | SP006, SP018, SP022 |
| CP023 | Zenity's 230-plus employee disclosure is a stronger public headcount signal than Obsidian's public disclosures, because Obsidian has not disclosed headcount. | 中 | SP001, SP018 |
| CP024 | The honest differentiation versus Zenity is Obsidian's runtime SaaS governance and NHI graph versus Zenity's stronger public build-time and agent-development focus. | 中 | SP002, SP005, SP006, SP012, SP018, SP021 |
| CP025 | The named CH3 peer set contains at least six material alternatives to Obsidian: Zenity, Grip, Push, Nudge, Valence, and AppOmni. | 中 | SP007, SP008, SP010, SP011, SP012, SP013, SP014, SP015, SP016, SP017 |
| CP026 | The allowed competitor source set does not provide standardized list pricing, realized ASPs, discounting, or renewal data across Obsidian and the named peers. | 中 | SP007, SP008, SP010, SP012, SP013, SP014, SP015, SP016, SP017 |
| CP027 | Obsidian's disclosed high-ACV customer counts imply enterprise pricing power, but they do not reveal ARR, net revenue retention, or realized module-level pricing. | 中 | SP001, SP002 |
| CP028 | Zenity's $125 million Series C exceeds Obsidian's $85 million Series D in fresh capital amount, increasing the risk of share-of-voice and talent competition. | 中 | SP001, SP006, SP018, SP021 |
| CP029 | Buyers can multi-home across Obsidian, Zenity, Push, Nudge, Grip, Valence, and AppOmni because each emphasizes a different control layer. | 中 | SP008, SP010, SP012, SP013, SP014, SP015, SP016, SP017 |
| CP030 | Obsidian's ability to become a durable control plane depends on attach rates and expansion into runtime agent governance, not merely initial SaaS discovery. | 中 | SP001, SP002, SP005, SP008, SP013 |
| CP031 | SNS Insider sizes the AI Agent Security market at about $26 billion in 2026 with roughly 39% CAGR to about $507 billion by 2035. | 中 | SP024 |
| CP032 | Mordor Intelligence sizes the Non-Human Identity Security market at about $8.22 billion in 2026 with about 22.78% CAGR through 2031. | 中 | SP025 |
| CP033 | Status quo and internal-build alternatives remain credible because buyers can combine SaaS-admin controls, identity controls, browser controls, and manual governance rather than buying one platform. | 中 | SP007, SP010, SP014, SP017 |
| CP034 | Obsidian's breadth of platform coverage is a competitive moat only if coverage works across both business-agent surfaces and developer-agent surfaces such as Claude Code and Cowork. | 中 | SP002, SP005 |
| CP035 | Obsidian is competitively credible but not unassailable because direct AI-agent rivals, discovery-first products, SSPM incumbents, native controls, and internal builds can each attack part of the value proposition. | 中 | SP001, SP006, SP007, SP008, SP010, SP011, SP012, SP013, SP014, SP015, SP016, SP017 |
| CI001 | Obsidian announced an $85 million Series D on August 4, 2026 at a $1.1 billion valuation, led by Crescent Cove Advisors with all existing investors participating. | 高 | SI009, SI010, SI011, SI015, SI016, SI017, SI018 |
| CI002 | The latest round took Obsidian’s disclosed lifetime capital raised to more than $200 million across five rounds. | 高 | SI009, SI010, SI015, SI018, SI019 |
| CI003 | The company disclosed that more than 100 customers each spend over $100,000 annually and more than 14 customers each spend over $1 million today. | 高 | SI010, SI009, SI018 |
| CI004 | Obsidian also disclosed 60 Fortune 500 customers, including large financial institutions, social media networks, and telecom providers. | 高 | SI010, SI009 |
| CI005 | Obsidian said the Series D proceeds will fund R&D and expand its reach deeper into the Fortune 500 and Global 2000. | 高 | SI010, SI009, SI016 |
| CI006 | Obsidian’s April 2022 Series C raised $90 million and brought total funding at that time to $119.5 million. | 中 | SI024, SI009 |
| CI007 | Norwest says it led Obsidian’s Series B-1 in June 2021 and then invested again in the $90 million Series C alongside Menlo, Greylock, Wing, IVP, and GV. | 中 | SI022, SI024 |
| CI008 | Greylock’s portfolio page lists Obsidian as first partnered at Series A and still active, supporting Greylock’s role as an early institutional backer. | 中 | SI021, SI009 |
| CI009 | Public sources cited for this chapter do not disclose Obsidian’s revenue, ARR, gross margin, free cash flow, monthly burn, or runway. | 中 | SI009, SI010, SI001, SI019 |
| CI010 | Using the disclosed spend thresholds as instructed, 100 customers at at least $100,000 plus 14 customers at at least $1 million implies a public spend floor of approximately $24 million. | 中 | SI010, SI009 |
| CI011 | The $40 million to $70 million ARR band used in this chapter is an analyst estimate, not a disclosed company metric. | 中 | SI010, SI009, SI001 |
| CI012 | At the $24 million implied floor, a $1.1 billion valuation equals roughly 46 times ARR. | 中 | SI010, SI009 |
| CI013 | At the $50 million base-case ARR estimate, a $1.1 billion valuation equals roughly 22 times ARR. | 中 | SI010, SI009 |
| CI014 | At the $70 million high-case ARR estimate, a $1.1 billion valuation equals roughly 16 times ARR. | 中 | SI010, SI009 |
| CI015 | Finro’s Q2 2026 cybersecurity dataset reports a private-market average of about 15.4 times revenue, so Obsidian needs ARR near or above the high end of the estimate band to screen near that private benchmark. | 中 | SI007 |
| CI016 | Finro also warns that medians and stage compression matter, with many outcomes below headline private averages; that makes a 22x to 46x implied multiple a valuation-risk flag unless revenue quality is exceptional. | 中 | SI007 |
| CI017 | A $1.1 billion valuation divided by Finro’s 15.4 times private benchmark implies about $71 million of ARR would be needed to justify the mark at that benchmark. | 中 | SI007, SI009 |
| CI018 | A 10 times to 13 times compressed private-cyber multiple would require roughly $85 million to $110 million of ARR to support a $1.1 billion valuation. | 中 | SI007, SI009 |
| CI019 | Cyberse reports a free tier for up to 1,000 users and an AWS Marketplace reference price of about $100 per user per year. | 中 | SI001 |
| CI020 | SaaS Tools Info also lists a free tier and free trial, corroborating a low-friction entry path before enterprise conversion. | 中 | SI003, SI001 |
| CI021 | Ciphers Security describes Obsidian as headcount-based and custom-quoted above the free threshold, making the public per-user figure list-price directional rather than realized-price evidence. | 中 | SI002, SI001 |
| CI022 | The visible monetization model is enterprise subscription software around SaaS security, identity threat detection, and AI-agent governance, not GMV, hardware, or project-finance revenue. | 中 | SI012, SI023, SI001, SI002 |
| CI023 | Obsidian’s GTM motion screens as enterprise-led because the company highlights Fortune 500 and Global 2000 expansion, custom enterprise quotes, and multiple seven-figure accounts. | 中 | SI010, SI001, SI002 |
| CI024 | The 14 customers above $1 million create useful enterprise validation but also a possible revenue-concentration risk that public sources do not quantify. | 中 | SI010, SI009 |
| CI025 | No public evidence in the retained source set discloses customer acquisition cost, sales-cycle length, CAC payback, net revenue retention, logo retention, or churn. | 中 | |
| CI026 | No public evidence in the retained source set discloses gross margin, contribution margin, cloud hosting cost, support cost, or services attach cost. | 中 | |
| CI027 | The cost structure is likely dominated by R&D, sales and customer success, cloud/software delivery, security operations, and support rather than capex-heavy manufacturing. | 中 | SI010, SI012, SI023 |
| CI028 | The Series D provides $85 million of fresh capital, but cash on hand before the round, monthly burn, and resulting runway months remain undisclosed. | 中 | SI010, SI009 |
| CI029 | The retained sources do not disclose debt, credit facilities, project-finance obligations, or other non-equity financing obligations. | 中 | |
| CI030 | With more than $200 million raised and a $1.1 billion valuation, Obsidian has created less than 5.5 dollars of headline equity value per dollar of disclosed capital raised, before considering any unreported secondary or option-pool effects. | 中 | SI009, SI010 |
| CI031 | Crunchbase reported $10.6 billion of H1 2026 cybersecurity and privacy startup funding but also a Q2 pullback of about 30%, so the financing backdrop is supportive but not indiscriminately euphoric. | 中 | SI004 |
| CI032 | SaaS Mag reports public cyber companies at about 7.8 times revenue, private cyber startups around 15.2 times, and M&A medians around 16.3 times, broadly corroborating the private-premium frame. | 中 | SI008, SI007 |
| CI033 | SaaS Mag argues the premium profile depends on software-like markers such as high gross margins, strong NRR, a defensible data graph, and platform consolidation fit; Obsidian has not disclosed those financial markers publicly. | 中 | SI008, SI010 |
| CI034 | TechNews180 cautions that unicorn status means a private valuation above $1 billion, not proof that a company has $1 billion of cash or a fully proven business. | 中 | SI006 |
| CI035 | Failory lists dozens of cyber unicorns globally, reinforcing that a unicorn mark is a competitive category signal rather than a unique proof of financial durability. | 中 | SI005, SI006 |
| CI036 | SiliconANGLE and FinTech Global frame AI-agent activity inside third-party applications as a new attack surface, supporting the strategic rationale for R&D investment in runtime governance. | 中 | SI011, SI013, SI010 |
| CI037 | Zenity raised $125 million one day before Obsidian’s Series D, indicating direct competitive capital intensity in AI-agent security. | 中 | SI014, SI009 |
| CI038 | Cyberse notes Obsidian’s SSPM focus does not extend to IaaS or PaaS cloud posture, which could limit budget capture versus broader platform-security vendors. | 中 | SI001, SI002 |
| CI039 | The free tier can improve product-led discovery and trial conversion, but it also means public user counts or discovery usage would not automatically equal paid ARR. | 中 | SI001, SI003 |
| CI040 | The combination of 100-plus six-figure customers and 14-plus seven-figure customers implies a skew toward enterprise ACVs, but public evidence does not reveal average contract value or discounting. | 中 | SI010, SI009 |
| CI041 | The 60-Fortune-500 signal improves logo quality but does not disclose renewal behavior, expansion rate, or whether revenue is concentrated in a few very large accounts. | 中 | SI010, SI009 |
| CI042 | Obsidian’s pricing evidence supports annual per-user subscription mechanics, but revenue recognition, multi-year prepayments, implementation fees, and services mix remain unavailable. | 中 | SI001, SI002, SI003 |
| CI043 | Because ARR and burn are undisclosed, the cash runway table must carry nulls for cash on hand, monthly burn, runway months, gross margin, NRR, and CAC payback rather than false precision. | 中 | SI009, SI010, SI001 |
| CI044 | The financial verdict is that Obsidian has unusually strong enterprise spend signals for a private cybersecurity company, but the $1.1 billion mark is stretched until management verifies ARR, retention, gross margin, burn, and concentration. | 中 | SI010, SI009, SI007, SI008 |
| CE001 | Obsidian Security positions its product as runtime governance and security for AI agents and non-human identities operating inside enterprise third-party SaaS applications. | 高 | SE001, SE011, SE012, SE015 |
| CE002 | The company homepage anchors the product message on securing AI adoption rather than only remediating static SaaS misconfigurations. | 中 | SE014, SE017 |
| CE003 | Series D coverage reports that more than 70% of Obsidian customers already allow AI agents into third-party applications. | 中 | SE011, SE012 |
| CE004 | The public product map spans MCP security, AI agent identity management, NHI governance, SaaS supply-chain security, breach clarity, and the earlier SSPM/ITDR base. | 高 | SE001, SE006, SE007, SE008, SE009, SE010 |
| CE005 | The customer workflow implied by public sources starts with discovering NHIs and connected MCP servers, maps them to a graph, evaluates agent actions at runtime, and then supports post-incident clarity. | 中 | SE001, SE006, SE008, SE009, SE015 |
| CE006 | Obsidian reports that non-human identities outnumber human identities by 144:1 inside third-party applications. | 中 | SE011, SE017 |
| CE007 | The company page frames its mission across 35,000-plus third-party applications, indicating that the technical scope is a broad SaaS control plane rather than a single application connector. | 中 | SE017 |
| CE008 | Public coverage describes a category evolution from SaaS Security Posture Management into AI agent governance and runtime control for non-human identities. | 高 | SE011, SE012, SE015, SE020 |
| CE009 | Obsidian says runtime governance detects and blocks privilege escalation, excessive data access, and policy violations before an agent action takes effect. | 高 | SE001, SE015 |
| CE010 | The runtime-enforcement claim is designed to move agent governance from after-the-fact posture reporting to pre-action policy enforcement. | 中 | SE001, SE009, SE015 |
| CE011 | Obsidian's MCP security surface maintains an inventory of every MCP server connected across an organization and maps those servers to the agents invoking them. | 高 | SE001, SE015 |
| CE012 | The MCP product also includes a model registry intended to detect model switching or substitution beneath an agent workflow. | 高 | SE001, SE015 |
| CE013 | The product coverage includes Microsoft Copilot Studio, Salesforce Agentforce, n8n, and autonomous developer agents as agent-building or autonomous-agent surfaces. | 中 | SE001, SE012, SE015 |
| CE014 | Obsidian is extending native governance to Anthropic Claude Code and Cowork for permission restriction, sensitive-file access management, and runtime blocking of unsanctioned MCP or tool usage. | 中 | SE012, SE011 |
| CE015 | Obsidian's NHI education material distinguishes AI agents from other non-human identities because agents are probabilistic and often over-permissioned. | 中 | SE008 |
| CE016 | The AI agent identity product page is explicitly framed around governing every non-human identity rather than only human user accounts. | 中 | SE009 |
| CE017 | Obsidian's earlier SSPM motion addressed misconfigurations, over-privileged accounts, and insider threats across Salesforce, Workday, and Microsoft 365 before expanding into agent governance. | 中 | SE011, SE020 |
| CE018 | The operating model combines API-based or agentless onboarding, a knowledge graph, behavioral analytics and machine learning, SIEM/SOAR integration, and SOC 2/GDPR-oriented compliance posture. | 中 | SE014, SE017, SE020, SE025 |
| CE019 | Obsidian launched end-to-end SaaS supply-chain security for SaaS-to-SaaS integrations on January 22, 2026. | 高 | SE007, SE010 |
| CE020 | The January 2026 integration-security coverage frames SaaS integrations and agentic connections as rising attack paths that require end-to-end visibility. | 中 | SE007, SE010 |
| CE021 | The breach clarity product page focuses on forensics across SaaS environments after identity or integration abuse. | 中 | SE006 |
| CE022 | Breach clarity is positioned to reduce mean time to innocence by helping teams separate affected from unaffected SaaS activity after a suspected incident. | 中 | SE006 |
| CE023 | The OWASP MCP Security Cheat Sheet identifies prompt injection, tool poisoning, and authorization weaknesses as core MCP risks that runtime governance must account for. | 高 | SE002, SE003, SE004 |
| CE024 | OWASP GenAI guidance for secure MCP server development reinforces that server-side tool definitions, input handling, and trust boundaries need explicit security design. | 高 | SE003, SE002 |
| CE025 | Cloud Security Alliance agentic MCP best practices emphasize least privilege, constrained tool access, and identity-aware governance for agentic tool use. | 高 | SE004, SE002 |
| CE026 | OWASP and CSA guidance make OAuth 2.1, authorization boundaries, and least-privilege scopes central requirements for safe MCP and agent-tool deployments. | 高 | SE002, SE004 |
| CE027 | PipeLab's 2026 state-of-MCP-security source describes thousands of MCP CVEs, making MCP immaturity an adverse technical risk for any vendor promising runtime protection. | 中 | SE005 |
| CE028 | Zenity raised $125 million for autonomous AI-agent security one day before Obsidian's Series D announcement, underscoring that the product category is competitive and fast-moving. | 中 | SE016 |
| CE029 | Obsidian's Series D use of proceeds is to fund R&D and extend deeper into the Fortune 500 and Global 2000. | 高 | SE011, SE012 |
| CE030 | The disclosed traction base includes 100-plus customers spending $100,000-plus per year, 14-plus customers spending $1 million-plus per year, and 60 Fortune 500 customers. | 中 | SE011, SE012 |
| CE031 | The founding team includes Glenn Chisholm, Ben Johnson, and Matt Wolff, giving the product organization a security-founder lineage from Cylance, Telstra, and Carbon Black backgrounds. | 中 | SE018, SE020, SE021 |
| CE032 | Craft lists Hasan Imam as current CEO, while the product and technical founder roles remain visible through Chisholm, Johnson, and Wolff. | 中 | SE019, SE018 |
| CE033 | Mordor Intelligence sizes the non-human identity security market at about $8.22 billion in 2026, supporting NHI governance as a real category lens for the product. | 中 | SE022 |
| CE034 | Research and Markets sizes the SSPM software market at about $3.69 billion in 2026, making the SSPM-to-agent-governance transition a category expansion rather than a category abandonment. | 中 | SE023 |
| CE035 | MarketsandMarkets sizes the agentic AI security market at about $1.65 billion in 2026, giving the newer agent-security wedge a narrower but high-growth category lens. | 中 | SE024 |
| CE036 | A practitioner vendor wiki provides a weak but usable public developer-signal proxy because Obsidian has no prominent open-source developer surface in this source set. | 低 | SE025 |
| CE037 | Public sources support the existence of security and privacy-oriented controls, but they do not publish a module-level false-positive rate, block-rate benchmark, uptime history, or detailed policy-engine architecture. | 中 | |
| CE038 | The strongest standards fit is between Obsidian's pre-action controls and OWASP/CSA guidance on prompt-injection resilience, tool poisoning defense, least privilege, and OAuth-aware authorization. | 高 | SE001, SE002, SE003, SE004, SE015 |
| CE039 | The public roadmap is event-driven: SaaS supply-chain security launched in January 2026, then Series D messaging in August 2026 highlighted Claude Code and Cowork expansion. | 中 | SE007, SE010, SE011, SE012 |
| CE040 | Obsidian's product differentiation depends on connecting SaaS identity posture, agent runtime policy, MCP inventory, model registry, and breach forensics into one graph-backed control plane. | 高 | SE001, SE006, SE008, SE009, SE015, SE017 |
| CU001 | Obsidian publicly reports enterprise-scale traction with 100+ customers spending more than $100,000 per year, 14+ customers spending more than $1,000,000 per year, and 60 of the Fortune 500 as customers. | 高 | SU009, SU010, SU011, SU016 |
| CU002 | The disclosed customer base includes major financial institutions, social media networks, and telecom providers, giving at least three named vertical categories even where most logos remain undisclosed. | 高 | SU009, SU010, SU016 |
| CU003 | More than 70% of Obsidian customers already allow AI agents into third-party applications, which makes agent governance an active installed-base need rather than only a future-market pitch. | 高 | SU009, SU010, SU011 |
| CU004 | Snowflake is the strongest named customer proof in the public set because the case study gives a named customer, named security executives, a concrete use case, and quantified operating outcomes. | 中 | SU001, SU002 |
| CU005 | Snowflake uses Obsidian against an environment of 3,000 integrations, making the deployment relevant to large SaaS-to-SaaS and AI Data Cloud ecosystems rather than a small pilot. | 中 | SU001, SU002 |
| CU006 | Snowflake says Obsidian saved more than 800 engineering hours per month, one of the clearest public value-proof metrics in the customer corpus. | 中 | SU001 |
| CU007 | The Snowflake story quotes CISO Brad Jones and VP Security Mario Duarte, improving reference quality because the customer voices are senior security leaders rather than anonymous marketing blurbs. | 中 | SU001 |
| CU008 | Security MEA independently covered the Obsidian-Snowflake integration around Snowflake AI Data Cloud, providing external corroboration that the relationship is not only a private logo claim. | 中 | SU002 |
| CU009 | CB Insights lists T-Mobile, Upwork, Trade Me, and BigCommerce among Obsidian customers, adding externally curated named-logo evidence beyond the Snowflake case study. | 中 | SU003 |
| CU010 | FeaturedCustomers includes an Obsidian testimonial from a Fortune 500 bank director, supporting the financial-institution segment while also showing that some large customer identities remain anonymized. | 中 | SU004 |
| CU011 | FeaturedCustomers also cites a CSO reference describing discovery of hundreds of SaaS applications in days, a customer outcome aligned with SaaS-security-posture and application-discovery workflows. | 中 | SU004 |
| CU012 | Gartner Peer Insights shows Obsidian around 4.9 out of 5 from roughly 22 reviews, a positive satisfaction signal but one with a modest review count. | 中 | SU005 |
| CU013 | PeerSpot provides an additional enterprise review surface for Obsidian, but it does not disclose cohort retention, expansion, or customer revenue concentration. | 中 | SU008 |
| CU014 | Forrester TEI cites up to 192% ROI for a composite organization with $9 billion of revenue and 10,000 employees, making the ROI proof relevant to large-enterprise buyers but not a direct customer-specific retention metric. | 中 | SU007 |
| CU015 | Work-Management.org is an adverse customer-fit source because it says Obsidian does not cover IaaS or PaaS security posture, limiting fit for buyers seeking one platform across SaaS and cloud infrastructure. | 中 | SU006 |
| CU016 | Work-Management.org also notes dashboard flexibility limitations, an adoption risk when security teams need customized executive, operational, or compliance reporting. | 中 | SU006 |
| CU017 | Obsidian positions its product around securing AI, non-human identities, and third-party SaaS applications, which explains why enterprise security, identity, and SaaS owners are the natural buyer and user personas. | 高 | SU012, SU018, SU025 |
| CU018 | The company page frames the opportunity around AI adoption across more than 35,000 third-party applications, supporting the relevance of SaaS-application breadth to customer adoption. | 中 | SU018 |
| CU019 | The MCP security page says Obsidian maintains inventories of MCP servers and model usage and applies runtime governance, a concrete use case for enterprises already allowing agent access to SaaS tools. | 高 | SU022, SU013 |
| CU020 | Obsidian breach-clarity and forensics positioning gives a post-incident customer workflow in addition to preventive posture management, widening the possible expansion surface inside existing accounts. | 中 | SU023 |
| CU021 | Help Net Security reported Obsidian launched end-to-end SaaS supply-chain security in January 2026, supporting an integration-security expansion path for customers with many SaaS-to-SaaS connections. | 中 | SU024 |
| CU022 | Review and pricing aggregators such as Cyberse, Ciphers Security, and SaaS Tools Info show buyer-research visibility, but they are weaker proof than customer stories because they do not verify deployments or outcomes. | 中 | SU019, SU020, SU021 |
| CU023 | Obsidian has not publicly disclosed net revenue retention, gross revenue retention, churn, renewal rates, average contract length, or top-customer revenue concentration in the retained source corpus. | 中 | |
| CU024 | The specific Fortune 500 logos behind the 60-customer claim are largely undisclosed, so the public record proves enterprise reach better than it proves logo-by-logo deployment breadth. | 中 | SU003, SU004, SU009, SU010 |
| CU025 | Fourteen-plus customers spending more than $1,000,000 per year is strong expansion proof but also creates a diligence question around how much revenue depends on a small set of large accounts. | 中 | SU009, SU010, SU016 |
| CU026 | Obsidian says the Series D capital will fund R&D and extend deeper into the Fortune 500 and Global 2000, tying the financing narrative directly to enterprise-account expansion. | 高 | SU009, SU010, SU015, SU016 |
| CU027 | The named public evidence is uneven: Snowflake includes quantified outcomes, while T-Mobile, Upwork, Trade Me, and BigCommerce are mainly logo-list evidence without public deployment details in the retained source set. | 中 | SU001, SU003 |
| CU028 | The Fortune 500 bank director testimonial is useful customer proof but remains anonymous, preventing investors from independently checking production scope, renewal status, or account economics. | 中 | SU004 |
| CU029 | An inferred ARR floor of at least about $24 million follows from 100 customers at more than $100,000 annually plus 14 customers at more than $1,000,000 annually, while a $40-70 million range remains only analyst-estimated. | 中 | SU009, SU010, SU016 |
| CU030 | The customer proof supports real adoption across multiple segments, but it is much better at proving presence and outcomes than retention durability. | 中 | SU001, SU003, SU004, SU005, SU007, SU009 |
| CU031 | Financial institutions are the most explicitly valuable disclosed segment because they appear in the 60-Fortune-500 vertical list and in the FeaturedCustomers bank testimonial. | 中 | SU004, SU009, SU010 |
| CU032 | Telecom customer proof is directionally supported by the company-reported vertical list and by CB Insights naming T-Mobile, but public deployment scope remains undisclosed. | 中 | SU003, SU009, SU010 |
| CU033 | Social-media-network customer proof is weaker than finance and telecom proof because the vertical is company-reported but no specific social-media customer is named in the retained sources. | 中 | SU009, SU010 |
| CU034 | Snowflake, T-Mobile, Upwork, Trade Me, BigCommerce, and the anonymous Fortune 500 bank together indicate that adoption spans data platforms, telecom, workforce marketplaces, marketplaces, commerce, and banking. | 中 | SU001, SU003, SU004 |
| CU035 | The adverse Work-Management findings do not negate Obsidian customer traction, but they bound it to SaaS and AI-agent governance rather than broad cloud security posture. | 中 | SU006, SU012, SU022, SU025 |
| CU036 | Gartner and Forrester are independent, high-reputation customer-value signals, but one is a small review sample and the other is a composite model rather than disclosed account-level economics. | 中 | SU005, SU007 |
| CU037 | Snowflake saving 800+ engineering hours per month is the strongest quantified operating KPI, while 100+ $100K customers and 14+ $1M customers are the strongest monetization KPIs. | 中 | SU001, SU009, SU010 |
| CU038 | Competitive pressure from Zenity raising $125 million one day earlier could make enterprise customer acquisition more expensive or contested despite Obsidian’s disclosed Fortune 500 traction. | 中 | SU014, SU009 |
| CU039 | Hasan Imam’s background as former Chief Revenue and Customer Officer at Shape Security supports credibility for enterprise go-to-market execution, though leadership pedigree is not a substitute for retention metrics. | 中 | SU017 |
| CU040 | Overall customer quality is strong enough to validate adoption proof, but unresolved disclosure gaps around named Fortune 500 logos, retention cohorts, and concentration remain material to underwriting. | 中 | SU001, SU003, SU004, SU009, SU010, SU006 |
| CR001 | Obsidian’s top risk stack combines direct competition, native-platform commoditization, market timing, threat-model difficulty, valuation opacity, and execution dependence. | 高 | SR001, SR002, SR006, SR035 |
| CR002 | Zenity raised $125 million on 2026-08-03, one day before Obsidian’s $85 million Series D announcement, making direct AI-agent-security competition unusually visible at the same financing moment. | 高 | SR006, SR023, SR024 |
| CR003 | Obsidian’s own 2026 materials emphasize runtime governance, MCP inventory, model registry, and blocking before agent actions take effect, which are credible differentiators if they outperform platform-native controls. | 高 | SR002, SR005, SR026 |
| CR004 | The Salesloft/Drift OAuth breach showed that AI-chat-agent and OAuth/NHI compromise can cascade into Salesforce, AWS, and Snowflake environments, which is directly relevant to Obsidian’s SaaS and NHI security thesis. | 中 | SR030, SR032 |
| CR005 | No cited source in this chapter identifies a public lawsuit, enforcement action, or regulatory sanction against Obsidian Security itself as of the 2026-08-05 run date. | 中 | |
| CR006 | Microsoft’s 2026 research showed that prompts can become shells through RCE vulnerabilities in AI-agent frameworks, so prompt-injection defense is a product-efficacy and legal-exposure issue rather than only a market tailwind. | 高 | SR034, SR033 |
| CR007 | The operational failure modes most relevant to Obsidian are false negatives against prompt injection, RCE in agent frameworks, OAuth/NHI compromise, MCP-server weakness, and breach-response credibility. | 中 | SR027, SR030, SR031, SR033, SR034, SR036, SR037 |
| CR008 | Prompt injection is treated by multiple 2026 adverse sources as a leading enterprise AI-agent risk, increasing the bar for Obsidian to prove blocking efficacy against adaptive attacks. | 中 | SR033, SR037, SR036 |
| CR009 | Obsidian’s MCP and runtime-governance pages claim inventory, model registry, and pre-action blocking capabilities, but public sources do not expose independent red-team false-negative rates. | 中 | SR005, SR026, SR027 |
| CR010 | Microsoft is a platform dependency and a competitive platform risk because Copilot Studio, Defender, and native agent-security controls can absorb governance functions that third-party vendors monetize. | 高 | SR035, SR034 |
| CR011 | SaaS platforms and customer systems such as Salesforce, Snowflake, AWS, and third-party applications are not merely integrations; they are the environments where Obsidian must prove detection, response, and governance value. | 中 | SR001, SR029, SR030 |
| CR012 | Obsidian has not disclosed ARR, gross margin, NRR, burn, runway, or headcount publicly, leaving material underwriting risk around revenue durability and operating leverage. | 中 | |
| CR013 | The disclosed customer-spend floor implies at least about $24 million of ARR, while the fact sheet’s plausible inferred range is $40 million to $70 million; both figures are estimates, not company disclosures. | 中 | SR001, SR002 |
| CR014 | At a $1.1 billion post-money valuation, Obsidian implies roughly 15x to 45x revenue depending on the ARR assumption, creating down-round exposure if growth, retention, or category adoption disappoints. | 中 | SR001, SR025 |
| CR015 | AI-agent governance is nascent, and market reports range from broad AI-agent-security TAM to narrower agentic-AI and NHI lenses, so adoption timing is a central model risk. | 中 | SR013, SR014, SR015, SR016 |
| CR016 | The clearest kill criteria are independent proof of weak product efficacy, native-platform displacement, poor ARR/NRR disclosure, stalled enterprise adoption, or valuation reset below the Series D price. | 中 | SR025, SR035, SR026 |
| CR017 | Diligence should request ARR, NRR, gross margin, burn, runway, headcount, product efficacy tests, incident-response proof, and customer concentration before treating the $1.1 billion price as de-risked. | 中 | SR001, SR025, SR026, SR029 |
| CR018 | The regulatory and legal risk register should rank privacy/OAuth breach exposure and agent-framework vulnerabilities above generic litigation risk because public evidence supports the threat pattern but not a current Obsidian legal proceeding. | 中 | SR030, SR034, SR036 |
| CR019 | The threat-landscape table should prioritize prompt injection, RCE, MCP weakness, OAuth/NHI compromise, and native-control displacement because each is evidenced by 2026 sources and maps to Obsidian’s claimed control surface. | 中 | SR027, SR030, SR033, SR034, SR035, SR036, SR037 |
| CR020 | Partner and competitive pressure includes Microsoft native controls, Zenity, Grip, Push, Nudge, Valence, AppOmni, Salesforce/Snowflake exposure, and dependence on SaaS application APIs. | 中 | SR006, SR018, SR019, SR020, SR021, SR022, SR035 |
| CR021 | Public leadership evidence verifies founder-heavy technical depth from Glenn Chisholm, Ben Johnson, and Matt Wolff plus a non-founder CEO, Hasan Imam, with Shape Security go-to-market background. | 中 | SR009, SR010, SR012 |
| CR022 | A monitorable trigger is Microsoft or Salesforce bundling sufficient native controls into enterprise seats to make third-party runtime governance a feature rather than a platform budget line. | 中 | SR035, SR005 |
| CR023 | The risk heatmap should place native-platform commoditization, valuation opacity, and prompt-injection/RCE efficacy in the high-impact band because each can affect revenue relevance and valuation simultaneously. | 中 | SR025, SR033, SR034, SR035 |
| CR024 | Threat and platform risks transmit into valuation through customer trust, enterprise procurement, gross margin, renewal durability, and follow-on financing terms. | 中 | SR001, SR025, SR029, SR030, SR035 |
| CR025 | The dependency map should include Microsoft, Salesforce/Snowflake/AWS environments, Zenity and adjacent vendors, AI-agent frameworks, MCP servers, investors, and Fortune 500 enterprise buyers. | 中 | SR001, SR006, SR023, SR026, SR030, SR035 |
| CR026 | Obsidian reports 100+ customers spending at least $100,000 annually, 14+ customers spending at least $1 million annually, and 60 Fortune 500 customers. | 高 | SR001, SR002, SR003 |
| CR027 | The same disclosed spend metrics imply customer concentration risk because at least 14 large accounts can account for a material share of estimated ARR. | 中 | SR001, SR002 |
| CR028 | Obsidian says 70%+ of its customers already allow AI agents into third-party applications, supporting market urgency but also indicating that adoption risk sits at governance maturity rather than agent awareness alone. | 中 | SR001, SR002 |
| CR029 | Obsidian cites a 144:1 ratio of non-human identities to human identities in third-party applications, which underpins the NHI-risk thesis and the risk of unmanaged OAuth/application credentials. | 中 | SR001, SR011 |
| CR030 | Obsidian’s January 2026 SaaS supply-chain security launch shows the company broadened from SSPM into SaaS-to-SaaS integration protection before emphasizing AI-agent governance in August 2026. | 中 | SR028, SR002 |
| CR031 | Grip’s competitive material claims broader shadow-SaaS and automated remediation capability versus Obsidian, which is adverse evidence for differentiation in SaaS governance. | 中 | SR019 |
| CR032 | Comparison sources place Push, Nudge, Grip, and Obsidian in overlapping SaaS and identity-security buying conversations, so category crowding is already visible outside AI-agent-only messaging. | 中 | SR018, SR020, SR021, SR022 |
| CR033 | Zenity’s disclosed 230+ employees and $125 million Series C create execution-pressure risk because it can fund enterprise sales, research, and platform partnerships aggressively. | 中 | SR023, SR006 |
| CR034 | Microsoft’s native security blog frames AI tools as moving from reading to acting, and that framing competes with Obsidian’s attempt to own runtime enforcement vocabulary. | 高 | SR035, SR005 |
| CR035 | OWASP’s MCP guidance treats prompt injection, tool poisoning, OAuth 2.1, and least privilege as baseline controls, which may commoditize parts of Obsidian’s control narrative over time. | 中 | SR027, SR026 |
| CR036 | Beam AI’s 2026 breach examples and Token Security’s OAuth breach analysis both show that incident stories are plentiful, but customers will still require proof that a specific vendor can stop them in production. | 中 | SR030, SR031 |
| CR037 | Security Boulevard’s CISO playbook confirms buyer awareness around AI-agent identity management, but awareness does not by itself prove budget timing or renewal quality for Obsidian. | 中 | SR032, SR013, SR014 |
| CR038 | The $85 million Series D led by Crescent Cove with all existing investors participating reduces near-term financing risk but also raises the performance hurdle implied by unicorn pricing. | 高 | SR001, SR002, SR008 |
| CR039 | Founder-heavy product and technical leadership is a strength, but it creates key-person and roadmap-prioritization risk if the pivot from SSPM to AI-agent governance requires different sales and platform-execution muscles. | 中 | SR009, SR010, SR012, SR030 |
| CR040 | Snowflake’s customer story supports enterprise credibility, but public customer proof does not disclose renewal rates, NRR, contract concentration, or willingness to pay specifically for AI-agent governance. | 中 | SR029, SR001 |
| CR041 | State-of-Surveillance’s CVE-2026-2256 coverage and Microsoft’s RCE research make MCP and agent-framework vulnerability management a current 2026 risk rather than a hypothetical future issue. | 中 | SR036, SR034 |
| CR042 | Overall residual risk remains high because Obsidian’s market driver and product test are the same: enterprises face severe agent/NHI threats, but Obsidian must prove it can block them better than platforms and peers. | 中 | SR001, SR006, SR030, SR033, SR034, SR035 |
| CV001 | Obsidian announced an $85 million Series D on 2026-08-04 at a $1.1 billion post-money valuation led by Crescent Cove Advisors. | 高 | SV012, SV013, SV019 |
| CV002 | All existing investors participated in the Series D, including Greylock Partners, Menlo Ventures, Norwest Venture Partners, IVP, Wing, and GV. | 高 | SV012, SV013, SV019, SV021 |
| CV003 | The Series D was a priced primary round with existing investors returning alongside new lead Crescent Cove, a financing structure that shapes dilution, preference-overhang, and entry-discipline analysis for a late-stage buyer. | 高 | SV012, SV013, SV023 |
| CV004 | The company reported 100+ customers spending at least $100,000 annually, 14+ customers spending at least $1 million annually, and 60 Fortune 500 customers. | 高 | SV012, SV013, SV018 |
| CV005 | Obsidian also reported that more than 70% of its customers already permit AI agents into third-party applications. | 高 | SV012, SV013, SV016 |
| CV006 | Obsidian says non-human identities outnumber human identities 144:1 inside third-party applications. | 高 | SV012, SV013, SV022 |
| CV007 | Public sources do not disclose Obsidian ARR, revenue, gross margin, NRR, burn, runway, or headcount. | 中 | SV012, SV013, SV020, SV029 |
| CV008 | Using the canonical disclosed spend floor of 100 customers at $100,000 plus 14 customers at $1 million implies at least about $24 million of ARR, but this is an analyst inference rather than company disclosure. | 中 | SV012, SV013, SV018 |
| CV009 | A plausible underwriting range of roughly $40 million to $70 million ARR remains an estimate because the company has not publicly bridged customer counts to contracted recurring revenue. | 中 | SV012, SV013, SV030 |
| CV010 | At $50 million of estimated ARR, the $1.1 billion valuation implies about 22.0x ARR. | 中 | SV001, SV012, SV013 |
| CV011 | At the approximately $24 million ARR floor, the $1.1 billion valuation implies about 45.8x ARR, rounded to roughly 46x. | 中 | SV001, SV012, SV013 |
| CV012 | At $70 million of estimated ARR, the $1.1 billion valuation implies about 15.7x ARR. | 中 | SV001, SV012, SV013 |
| CV013 | Windsor Drake frames public cyber software at roughly 6-8x NTM revenue, cloud or AI-native leaders at roughly 14-22x, private cyber around 15.2x, and cloud M&A as high as 35x. | 中 | SV001, SV002 |
| CV014 | CrowdStrike is cited at about 25.1x EV/Revenue, with FY26 revenue of about $4.81 billion and ARR of about $5.25 billion. | 高 | SV002, SV003, SV005 |
| CV015 | Zscaler is cited at about 11.7x EV/Revenue, with TTM revenue of about $3.17 billion and market capitalization around $25 billion. | 高 | SV002, SV004 |
| CV016 | The same public comp set cites Palo Alto Networks around 15x, Cloudflare around 31.5x, Fortinet around 8.7x, and Okta around 5x EV/Revenue. | 中 | SV001, SV002 |
| CV017 | Google closed its $32 billion acquisition of Wiz in March 2026, and Wiz had more than $1 billion of ARR by 2025. | 高 | SV006, SV009, SV010 |
| CV018 | Cyera reportedly eyed a $12 billion valuation at an 80x ARR multiple despite operating losses, making it the clearest adverse froth signal in the comparable set. | 高 | SV007, SV001, SV030 |
| CV019 | NinjaOne reached a roughly $12.3 billion private valuation while reportedly combining about 70% growth with profitability, making it a premium-growth comp with stronger fundamentals framing. | 中 | SV008, SV001 |
| CV020 | Palo Alto Networks and CyberArk created a $25 billion strategic M&A reference point for identity-security consolidation. | 中 | SV010, SV009, SV011 |
| CV021 | Cybersecurity M&A reached roughly $92-96 billion in 2025, and 2026 consolidation coverage cited more than 190 cyber M&A deals by mid-year. | 中 | SV009, SV010, SV011 |
| CV022 | Finro-type valuation framing warns that private cyber medians near 15.4x ARR and down-round compression near 10-13x expose Obsidian to ARR-gap risk. | 中 | SV030, SV001 |
| CV023 | Zenity raised $125 million one day before Obsidian, which supports category demand but weakens scarcity-premium arguments for Obsidian. | 中 | SV017, SV029 |
| CV024 | AI Agent Security is estimated around $26 billion in 2026 with about 39% CAGR to 2035, supporting a large-market leg of the bull case. | 中 | SV025, SV028 |
| CV025 | NHI security is estimated around $8.22 billion in 2026, while agentic AI security is estimated around $1.65 billion in 2026, showing both broad and narrow TAM lenses. | 中 | SV026, SV028 |
| CV026 | Research and Markets puts SSPM at about $3.69 billion in 2026, which reinforces the legacy SaaS-security part of Obsidian’s addressable market. | 中 | SV027, SV026 |
| CV027 | Obsidian’s runtime governance, MCP inventory, and AI-agent permission controls support a thesis that it is moving beyond legacy SSPM into AI-agent governance. | 高 | SV013, SV015, SV016 |
| CV028 | The investment thesis is that Obsidian combines a newly urgent AI-agent/NHI security problem, visible Fortune 500 traction, and a strong investor syndicate. | 中 | SV012, SV013, SV021, SV025 |
| CV029 | The anti-thesis is that the company is private and financially opaque, the category is nascent, Zenity is well funded, and platform vendors may compress pricing power. | 中 | SV017, SV030, SV012, SV013 |
| CV030 | The most supportable recommendation is track rather than buy because product and market evidence are strong, but public financial evidence does not yet support unconditional conviction at $1.1 billion. | 中 | SV012, SV013, SV030, SV001 |
| CV031 | Confidence should be medium because the chapter can bracket valuation ranges, but cannot verify ARR, growth, margin, retention, or cap-table rights from public evidence. | 中 | SV012, SV013, SV020, SV030 |
| CV032 | Risk rating should be high because the valuation depends on a growth-premium ARR assumption in a competitive and still-forming category. | 中 | SV017, SV025, SV030, SV001 |
| CV033 | The valuation stance is stretched because the Series D price is near premium cloud/AI leader bands if ARR is high and far above median or down-round bands if ARR is near the floor. | 中 | SV001, SV007, SV030, SV012 |
| CV034 | A bull case can defend roughly $1.3-1.8 billion if ARR is near $70 million, growth remains high, and investors accept premium 19-25x cyber multiples. | 中 | SV001, SV002, SV012, SV013 |
| CV035 | A base case supports roughly $0.6-1.1 billion if ARR is around $40-50 million and investors use a 15-22x range after applying an opacity discount. | 中 | SV001, SV030, SV012, SV013 |
| CV036 | A bear case supports roughly $0.2-0.5 billion if ARR is near the $24 million floor and the relevant multiple compresses toward 8-13x. | 中 | SV001, SV030, SV012, SV013 |
| CV037 | A buy case would require proof that ARR is already above roughly $50 million, revenue growth is durable, gross margin is software-like, retention is strong, and preferences are not punitive. | 中 | SV001, SV012, SV013, SV030 |
| CV038 | The first thesis-break trigger is audited ARR below roughly $40 million or evidence that the $24 million floor is close to current reality. | 中 | SV012, SV013, SV030 |
| CV039 | The second thesis-break trigger is evidence that top customers, especially the 14 accounts above $1 million, create concentration or renewal risk that undermines premium multiple support. | 中 | SV012, SV013, SV030 |
| CV040 | The third thesis-break trigger is AI-agent security budget consolidation toward Microsoft or another platform vendor rather than independent vendors such as Obsidian. | 中 | SV017, SV016, SV025 |
| CV041 | The fourth thesis-break trigger is public or private cybersecurity multiple compression below the median bands used to justify the Series D mark. | 中 | SV001, SV002, SV030 |
| CV042 | Final diligence should request audited ARR, ARR bridge from disclosed customer tiers, gross margin, burn, NRR, GRR, cohort retention, headcount, and customer concentration. | 中 | SV012, SV013, SV030 |
| CV043 | Final diligence should also request the capitalization table, liquidation preferences, participation rights, option-pool changes, pro rata rights, and side letters before modeling investor return. | 中 | SV019, SV020, SV030 |
| CV044 | The bottom-line valuation judgment is rich but defensible only if ARR is already high; otherwise the $1.1 billion Series D is stretched relative to public and private cyber comps. | 中 | SV001, SV002, SV007, SV012, SV030 |