<img src="https://ad.doubleclick.net/ddm/activity/src=11631230;type=pagevw0;cat=pw_allpg;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=;tfua=;npa=;gdpr=${GDPR};gdpr_consent=${GDPR_CONSENT_755};ord=1;num=1?" width="1" height="1" alt="">

Cymphony, AI Agents, and the Case for Security That Travels With Data

Nick Michael
By Nick Michael

TABLE OF CONTENTS

    See Virtru In Action

    Sequoia’s continued investment in Cymphony highlights an important shift in enterprise security: AI agents are now a part of the workforce, and organizations need visibility into what those agents can access and do.

    Cymphony is addressing a critical part of this challenge by helping security teams map access across humans and AI agents, identify excessive permissions, and remediate risky exposure. This latest funding round is a positive signal for the broader market, and recognition that identity and access models must evolve as agents operate across enterprise systems at machine speed.

    But the rise of agentic AI also raises a related question: What happens to security controls once sensitive data leaves its original system?

    Moving security closer to the data

    Most enterprise security controls are tied to infrastructure: an application, identity provider, repository, network, or cloud environment. These controls determine who can enter a system and what information they can access while they are there.

    That model becomes less reliable when data is downloaded, copied, shared, or introduced into an AI workflow. The original system’s permissions may no longer apply, even though the data remains sensitive.

    Object-level security addresses this gap by applying protection directly to an individual piece of data —such as a document, email, dataset, or model input. The object is encrypted, and policies governing its use remain attached to it as it moves between users, systems, and environments.

    Instead of relying entirely on the security of each system that handles the data, access can be evaluated whenever someone—or some agent—attempts to use it. That policy might consider identity, role, purpose, location, time, or other attributes. Access can also expire or be revoked after the object has been shared.

    This creates a complementary layer for agentic AI; one where posture and identity controls help determine what an agent should be able to access, and object-level controls help ensure the data remains protected wherever the agent encounters or moves it.

    Completing the Agentic AI Security Model

    Object-level security is the foundation of Virtru’s philosophy. Virtru applies encryption and policy directly to sensitive data using the Trusted Data Format, an open standard created by Virtru Co-Founder, Will Ackerly.

    For agentic systems, this means governance does not have to end when information leaves its original repository or enters a new workflow. By utilizing TDF, organizations can retain control over which people, applications, and agents are authorized to use protected data—even across organizational and infrastructure boundaries.

    Cymphony’s momentum is another example of the growing importance of understanding and governing the agentic workforce. Object-level security addresses an equally significant part of the same challenge: ensuring that the data those agents use remains protected throughout its lifecycle.

    As agentic AI matures, enterprises will need both. Security must govern access at the identity and system layers while also traveling with the data itself.

    Nick Michael

    Nick Michael

    Nick is the Communications Manager at Virtru. With 8 years of experience in tech-focused public relations and media content, he has a passion for news analysis and finding the story behind the story.

    View more posts by Nick Michael

    See Virtru In Action