Key takeaways
- Cyera secured an additional $400 million investment from Goldman Sachs Alternatives, extending its Series G round.
- The extension sustains Cyera’s private market valuation at over $12 billion, following a $600 million tranche in June 2026.
- The company has raised $1.4 billion in 2026 and more than $2 billion to date, solidifying its position among top cybersecurity unicorns.
- Funds will accelerate development of Agent Guardian, Cyera Endpoint, and integrated non-human identity governance from its $1 billion Oasis Security acquisition.
- Cyera plans to expand deeper into U.S. federal government accounts while scaling commercial operations across EMEA and APAC.
Enterprise data security startup Cyera Ltd. has secured an additional $400 million in funding from Goldman Sachs Alternatives to accelerate its push into AI agent security. The investment serves as an extension to Cyera’s Series G round closed in June 2026, sustaining its private market valuation at over $12 billion. As autonomous software agents and Model Context Protocol (MCP) integrations proliferate across corporate environments, Cyera is expanding its data security posture management platform to govern non-human identities, track agent data access, and enforce execution guardrails across cloud databases and employee workstations.
The fresh injection of capital follows an aggressive expansion year for the Tel Aviv- and New York-based cybersecurity vendor. Cyera has now raised $1.4 billion across multiple rounds in 2026 alone, lifting its cumulative venture funding beyond $2 billion and positioning it among the most heavily capitalized private security firms globally. According to reporting from SiliconANGLE, the new funds will support product engineering for runtime AI defenses and finance targeted expansion across international enterprise markets and government agencies.
Goldman Sachs backs $12B agentic security push
The $400 million commitment from Goldman Sachs Alternatives expands the $600 million Series G round that Cyera closed in June 2026, which was led by Evolution Equity Partners with participation from Cyberstarts and Temasek. Rather than repricing the company under a separate financing series, the extension preserves the $12 billion baseline valuation established during the summer. Cyera’s valuation trajectory has escalated steeply from $3 billion in 2024 to $6 billion in 2025, reaching $9 billion in January 2026 before hitting the $12 billion mark.
For institutional investors like Goldman Sachs, the investment reflects a broader reallocation of enterprise security capital. As organizations shift workloads into autonomous workflows, conventional perimeter defenses struggle to keep pace with machine-to-machine interactions. Enterprise technology buyers are grappling with an explosion of programmatic queries, automated pipeline orchestrations, and background agent routines that bypass human approval loops.
“AI infrastructure is moving faster than the security architecture around it,” said Cyera co-founder and Chief Executive Officer Yotam Segev, who established the company alongside Tamar Bar-Ilan and Yonatan Itay. “This investment accelerates our work to bring data and identity together, so enterprises can give agents access with confidence and keep that access aligned with business intent.”
Bridging data posture and non-human identities

Cyera initially built its market footprint in Data Security Posture Management (DSPM). The company’s platform connects to sprawling multi-cloud environments—including AWS, Microsoft Azure, Google Cloud, and SaaS repositories—to locate misplaced records, classify sensitive information, identify exposure vulnerabilities, and map which human users maintain access rights. However, the rise of agentic architectures has altered enterprise threat surfaces by transferring data access from human operators to automated services.
Autonomous agents do not interact with corporate software through interactive logins. Instead, they operate via non-human identities (NHIs)—a category encompassing API keys, service accounts, OAuth tokens, and system credentials. Industry telemetry indicates that NHIs within large enterprises have grown by several hundred percent over the past year, far outpacing human identity accounts. When security teams lack visibility into which agent uses which credential, access governance breaks down entirely.
To address this architectural blind spot, Cyera completed a $1 billion acquisition of Israeli startup Oasis Security Ltd. in early September 2026. Oasis, which now operates as a dedicated division named Cyera Identity, provides discovery and governance across enterprise non-human identities. By binding data sensitivity metrics with machine identity permissions, Cyera enables security architects to see not only where critical files reside, but precisely which automated agent tokens hold read or write privileges over them.
This integration is critical for enterprise security leaders reassessing legacy isolation strategies. Relying on network segmentation or hidden microservice endpoints is ineffective against automated systems capable of recursive enumeration. As modern infrastructure teams have documented, security through obscurity is dead when autonomous tools and agent frameworks can systematically parse infrastructure configurations to uncover unmonitored endpoints.
| Security Domain | Primary Target | Core Functionality | Operational Enforcement |
|---|---|---|---|
| Data Security Posture (DSPM) | Multi-cloud object stores, structured databases, SaaS apps | Automated discovery, sensitive data classification, risk exposure mapping | Continuous posture alerting and permission right-sizing |
| Identity Governance (Cyera Identity) | Non-human identities (NHIs), API keys, OAuth tokens, service accounts | Credential inventory, account ownership mapping, overprivilege detection | Credential lifecycle management and automated token revocation |
| Agent Defense (Agent Guardian) | Autonomous AI agents, runtime workflows, Model Context Protocol servers | Agent discovery, tool-call vulnerability scanning, prompt injection defense | Real-time tool-call interception and agent quarantine |
| Device Governance (Cyera Endpoint) | Developer workstations, local coding agents, CLI tools (Cursor, Claude Code) | Local AI application discovery, unauthorized prompt monitoring, file egress tracking | Device-level policy enforcement and data exfiltration blocking |
Securing agent execution from cloud MCPs to the endpoint
To operationalize agent governance, Cyera introduced two dedicated products in August 2026: Agent Guardian and Cyera Endpoint. Together, the tools address security vulnerabilities that emerge during active agent execution, spanning centralized cloud services down to local developer machines.
Agent Guardian functions as a runtime control plane for autonomous software. The system builds an automated inventory of all AI agents querying enterprise data lakes and application APIs. Crucially, it audits agent-connected tools and servers running the Model Context Protocol (MCP)—an emerging open standard that connects language models to external tools and databases. When an MCP server or integrated utility exposes unnecessary system rights, Agent Guardian flags the vulnerability before an adversary can manipulate the model.
Furthermore, Agent Guardian establishes behavioral policies that define allowed actions for each agent workload. If an agent attempts to execute a tool call outside its approved mandate—such as an automated support bot attempting to extract bulk financial ledger tables—the platform intercepts the instruction in real time. For persistent behavioral anomalies or suspected prompt injection compromises, security administrators can immediately quarantine the agent from the corporate network.
Cyera Endpoint targets the opposite end of the infrastructure spectrum: employee workstations. Software developers and data analysts frequently deploy local coding assistants, terminal-based AI agents, and desktop models that operate beyond the perimeter of corporate proxy gateways. Cyera Endpoint acts as a lightweight host monitor that discovers local AI runtimes, prevents employees from piping proprietary source code into unauthorized personal agents, and blocks unapproved file transfers before records leave the physical machine.
What happens next
Cyera will allocate the $400 million investment to expand its core AI security engineering groups, build automated red-teaming utilities for agent verification, and accelerate compliance workflows aligned with frameworks such as the EU AI Act. On the commercial side, the company is ramping up sales operations targeting the U.S. federal government and expanding its enterprise go-to-market teams across Europe, the Middle East, Africa, and the Asia-Pacific region.
For enterprise IT leaders and CISOs, Cyera’s funding signals that AI agent governance has moved from an experimental priority to a core budget item. As autonomous agents take on higher-privilege operational roles, security teams must move beyond static identity management and adopt continuous, data-aware runtime monitoring. Enterprise technology buyers should prioritize auditing non-human identities, inventorying MCP server connections, and establishing strict tool-call policies across both cloud pipelines and local endpoints.


