Obsidian Security
Obsidian Security delivers a unified SaaS and AI security platform built on a proprietary Knowledge Graph that maps identity, permissions, integrations, and AI agent activity. It serves Fortune 1000 and Global 2000 enterprises with SSPM, ITDR, SaaS supply chain, and AI-SPM capabilities.
- Company typePrivate
- Founded2018
- HeadquartersNewport Beach, United States
- Headcount101–250
- GTM typeB2B
- OfferingSoftware
What Obsidian Security does
Obsidian Security is a Palo Alto-based, venture-backed SaaS and AI security company that provides a unified platform for enterprises to secure business-critical SaaS applications and the AI agents that operate on top of them. The company's product portfolio is organized around four core modules — SaaS Security Posture Management (SSPM), SaaS Supply Chain Security, Identity Threat Detection and Response (ITDR), and AI Security Posture Management (AI-SPM) — all of which share an underlying Obsidian Knowledge Graph that unifies and normalizes user identities, permissions, OAuth scopes, configuration data, and activity events across more than 200 enterprise applications. Differentiated technical components include self-learning AI detection models, a browser extension that visually analyzes rendered pages to detect adversary-in-the-middle phishing kits (Mamba 2FA, Tycoon 2FA, Evilginx) behind Cloudflare turnstiles, and an Obsidian AI Assistant that uses the Knowledge Graph for natural-language investigations. A Community SDK extends connector coverage through partner-built integrations, and an original-research function produces the annual SaaS Security Threat Report and disclosures of vulnerabilities such as the UNC6395 Salesloft-Drift breach investigation, LiteLLM CVEs, and Flowise CVE-2026-40933.
The company operates a hybrid go-to-market combining an enterprise field-sales motion targeting Fortune 1000 and Global 2000 customers (named logos include Snowflake, T-Mobile, AAA, Seagate, S&P Global, Databricks, BigCommerce, Algolia, Upwork, Trade Me, and Wyndham) with a self-serve/product-led growth motion for mid-market via a freemium browser-extension tier (Detect free up to 1,000 users, with paid Detect and Warn + Block tiers). Revenue is generated primarily through multi-year enterprise subscription contracts (quote-based, available on AWS, Google Cloud, and CrowdStrike Marketplaces), supplemented by professional/advisory services including incident-response retainers. The company raised a $90 million Series C in April 2022 led by Menlo Ventures, Norwest Venture Partners, and IVP, and was recognized on the 2025 Deloitte Technology Fast 500 with nearly 1000% three-year growth. Operating geographies span the United States (HQ), EMEA (Frankfurt data center), and Asia Pacific (Sydney data center), with a planned Saudi Arabia region and a partner-led 100% channel commitment program anchored by NORMA Cyber in EMEA.
Obsidian Security firmographics
Firmographics- Name
- Obsidian Security
- Legal name
- Obsidian Security, Inc.
- Website
- https://obsidiansecurity.com
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- Obsidian Security delivers a unified SaaS and AI security platform built on a proprietary Knowledge Graph that maps identity, permissions, integrations, and AI agent activity. It serves Fortune 1000 and Global 2000 enterprises with SSPM, ITDR, SaaS supply chain, and AI-SPM capabilities.
- Ownership category
- akta.pro rank
Obsidian Security industry classification
Industry- Product category
- SaaS Security
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Programming Services (7371)
- akta.pro primary industry
- Attack Detection & Response for Cloud/SaaS (SOC for Cloud) (HDADAGAJ)
- akta.pro secondary industries
- SaaS Security Posture Management (SSPM) (HDADADAI), Security Operations Center (SOC) as a Service (BPAEADAB)
Keywords
Where Obsidian Security is headquartered
LocationHeadquarters
- HQ city
- Newport Beach
- HQ country
- United States
- HQ region
- North America
Offices5 records
Markets served
Obsidian Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- Enterprise SaaS Security Subscription: Recurring subscription-based licensing of the unified SaaS + AI security platform (SSPM, ITDR, supply chain, AI-SPM) sold to large enterprises; Forrester TEI reports 192% 3-year ROI and payback in under 6 months for enterprise customers.
- Mid-Market Freemium / Tiered Subscription: Free 'Detect' tier up to 1,000 users converts into paid 'Detect' (over 1K users) and 'Warn + Block' subscriptions; deployed as browser extension, creating a land-and-expand PLG motion.
- Professional / Advisory Services: Expert-driven SaaS and AI risk assessments, incident response retainers (e.g., for Salesloft-Drift / UNC6395 breach response), and tailored remediation engagements delivered by an in-house research team.
- Marketplace Channel Sales: Purchase of Obsidian offerings through AWS Marketplace, Google Cloud Marketplace, and the CrowdStrike Marketplace, enabling consumption against committed cloud/security spend.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Annual | Detect – Free up to 1K users |
| Subscription | Annual | Detect – Over 1K users |
| Subscription | Annual | Warn + Block – All users |
| Subscription | Multi-year contract | Enterprise Platform |
Go-to-market motion1 record
Distribution channels7 records
Marketing channels9 records
Obsidian Security product offering
Product offeringCore offering
Obsidian Security delivers a unified SaaS and AI security platform built on its proprietary Knowledge Graph. The platform combines SaaS Security Posture Management (SSPM), Identity Threat Detection and Response (ITDR), SaaS Supply Chain Security, and AI Security Posture Management (AI-SPM) into a single offering for large enterprises, with a separate browser-extension-based mid-market product for phishing prevention and shadow SaaS discovery.
Product overview
Obsidian Security delivers a single, unified AI-and-SaaS security platform organized around four core modules — SaaS Security Posture Management (SSPM), SaaS Supply Chain Security / Resilience, Identity Threat Detection and Response (ITDR) and AI Security Posture Management (AI-SPM) — that all share the underlying Obsidian Knowledge Graph and are surfaced through the Obsidian AI Assistant and Community SDK. On top of this enterprise platform, the company ships a Mid-Market Solution (Obsidian Browser Extension) for in-browser spear-phishing prevention, shadow SaaS and GenAI policy enforcement. Specialized use-case products (Shadow SaaS Discovery, SaaS Compliance & Governance, SaaS Privilege Identity Management, SaaS API Integration Risk Management, SaaS Token Compromise Detection, AI Agent Security covering Agent Visibility, Governance and Runtime Security, Shadow AI Discovery, MCP Security, AI Prompt Security, GenAI Data Leakage, and AI Phishing Detection) are sold as modular add-ons that plug into the core platform. The portfolio is rounded out by free SaaS Risk Assessments and an annual SaaS Security Threat Report.
Differentiator
Problem solved
Functional benefit
Products and services
- SaaS Security Posture Management (SSPM) Continuously monitors SaaS applications for misconfigurations, access drift, compliance gaps, and excessive privileges; provides a consolidated view of identity, posture, and data across the SaaS estate for enterprise security teams.
- Identity Threat Detection and Response (ITDR) Detects and responds to identity-based threats across the enterprise application stack, including compromised accounts, token abuse, session hijacking, and lateral movement between connected SaaS applications.
- SaaS Supply Chain Security / Resilience End-to-end protection for SaaS-to-SaaS integrations, OAuth grants, webhooks, and connected apps; delivers visibility, early breach detection, customizable supply-chain breach notifications, and rapid incident containment for enterprise security teams.
- AI Security Posture Management (AI-SPM) Provides visibility, governance, and runtime security for every AI agent and GenAI application in the enterprise; maps agent access, behavior, and data exposure across SaaS and AI systems including Microsoft Copilot, ChatGPT Enterprise, and Salesforce Agentforce.
- Obsidian AI Assistant Generative-AI-powered assistant that uses the Obsidian Knowledge Graph to summarize identity context, surface risks, and accelerate SaaS and AI security investigations and operations for security analysts.
- Obsidian Browser Extension (Mid-Market Solution) Lightweight browser extension for Chrome, Firefox, and Edge delivering in-browser spear-phishing prevention (AiTM detection), shadow SaaS discovery, and GenAI policy enforcement, packaged as a freemium product for mid-sized enterprises.
- SaaS Risk Assessment (Free Assessment)
Companies that use Obsidian Security
Customer profileNamed customers12 records
Segments5 records
Ideal customer profiles4 records
Obsidian Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration22 records
AI capability13 records
Feature6 records
Obsidian Security partnerships and signals
Strategic signalPartnerships
14 partnerships are on record, tiered flagship and core.
- Databricks Unity AI Gateway Partner EcosystemflagshipObsidian Security announced as one of 14 launch partners in Databricks' Unity AI Gateway partner ecosystem at Data + AI Summit 2026 (alongside CrowdStrike, Cyera, HiddenLayer, Netskope, Noma Security, Openlayer, Palo Alto Networks, Zscaler, Okta, Ping Identity, SailPoint, Saviynt, Alice).
- Microsoft (Sentinel)flagshipIntegration with Microsoft Sentinel to bolster enterprise SaaS security; Obsidian also supports securing Microsoft Copilot, Microsoft 365, and Microsoft Azure DevOps as supported platforms.
- SnowflakeflagshipAchieved Snowflake technology validation; advances security capabilities for the AI Data Cloud and consolidates security visibility at scale for joint customers (Snowflake also a customer of Obsidian).
- CrowdStrikeflagshipIntegration with CrowdStrike Falcon Next-Gen SIEM to accelerate SaaS threat detection and response; also available on the CrowdStrike Marketplace for joint procurement and channel reach.
- SentinelOnecorePartners with SentinelOne to deliver unified threat protection across endpoint and SaaS, consolidating endpoint and SaaS telemetry for joint customers.
- DatabricksflagshipProud partner of Databricks' Lakewatch Ecosystem; integration announced for SaaS data governance and Unity AI Gateway for AI security, identity governance, observability, and agent governance across 14 partners (announced June 17, 2026).
- NORMA CybercoreLaunched EMEA CIO Advisory Board in partnership with NORMA Cyber to build upon accelerating traction in the EMEA market.
- WiprocorePartnership-supported innovation: Wipro incident response engagements feed Obsidian's SaaS breach repository; Wipro shown as a featured integration partner on the technology page.
- GuidePointcoreJoint incident response work informing Obsidian's SaaS breach data repository alongside GuidePoint, Wipro, and Kroll.
- KrollcoreJoint incident response engagements feed the SaaS breach repository that powers Obsidian's threat intelligence, alongside Wipro and GuidePoint.
- AWS (Amazon Web Services)coreAvailable on AWS Marketplace; regional SaaS data centers (Sydney, Frankfurt, Oregon, planned Saudi Arabia) are hosted on AWS.
- Google CloudcoreAvailable on Google Cloud Marketplace; supports SaaS security for Google Workspace integrations.
- SalesforceflagshipDeep integration with Salesforce and Salesforce Agentforce; targeted jointly by threat actors (ShinyHunters, Scattered Spider, UNC6395 Salesloft-Drift) and a core area of Obsidian detection and posture capabilities.
- OktacoreIntegration partner for SaaS identity threat detection and phishing (AiTM) defense targeting Okta login flows.
Scale indicators8 records
Recent moves8 records
Expansion highlights8 records
Obsidian Security competitors and assessment
Company assessmentDirect peers
- AppOmni: AppOmni is a direct SSPM and SaaS security peer offering SaaS Security Posture Management, identity threat detection, and integration risk management for enterprise SaaS estates — the same core use cases as Obsidian's SSPM, ITDR, and SaaS Supply Chain modules.
- Adaptive Shield (CrowdStrike): Adaptive Shield built SSPM and SaaS security posture management before being acquired by CrowdStrike; it is Obsidian's closest product competitor, with overlapping coverage of SaaS misconfigurations, identity, and now AI/agent posture.
- Reco: Reco is an SSPM and SaaS security startup focused on configuration posture, identity governance, and AI/LLM usage monitoring across SaaS applications — directly comparable to Obsidian's SaaS and AI Security Posture Management offerings.
- Grip Security: Grip Security provides SaaS security posture management and shadow SaaS discovery for enterprises, including SaaS-to-SaaS access visibility and identity controls — overlapping significantly with Obsidian's SSPM and Shadow SaaS Discovery use cases.
Emerging players
- Nudge Security: Nudge Security is an early-stage SaaS security startup delivering SaaS discovery, shadow SaaS management, and SaaS governance for modern enterprises — a narrower competitor focused on the Shadow SaaS / SaaS asset inventory layer that Obsidian also covers.
Broad incumbents
- Palo Alto Networks (Prisma SaaS): Palo Alto Networks' Prisma SaaS (formerly known as Redlock/Oinsky) is a CASB and SaaS security posture offering within a broader enterprise security platform, competing with Obsidian on SSPM and SaaS threat detection from a much larger incumbent position.
- Microsoft (Defender for Cloud Apps): Microsoft Defender for Cloud Apps is the hyperscaler-native CASB/SSPM offering deeply integrated with Microsoft 365, Entra, and Sentinel — directly competing with Obsidian's Microsoft 365 and broader SSPM coverage, particularly for Microsoft-centric enterprises.
- Netskope: Netskope's SASE/SSE platform includes SSPM, CASB, and SaaS security posture capabilities that overlap with Obsidian's SSPM and ITDR, positioning Netskope as a broader cloud-security incumbent competing for similar enterprise security budgets.
- Zscaler: Zscaler's Zero Trust Exchange includes SaaS security posture and risk assessment capabilities (via its Posture Control / SSPM offerings) as part of a broad SASE platform — a large incumbent competing with Obsidian on SSPM and SaaS threat detection.
- CrowdStrike: CrowdStrike is both a strategic integration partner (Falcon Next-Gen SIEM, Marketplace) and a direct competitor following its Adaptive Shield acquisition, with growing SSPM, ITDR, and now AI-agent capabilities that increasingly overlap with Obsidian's platform.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Obsidian Security social profiles
Digital presenceObsidian Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Obsidian Security leadership team
Management profileNumber of profiles
Profiles11 records
Obsidian Security funding detail
Funding detailFunding overview
Funding rounds4 records
Investors9 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Obsidian Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Obsidian Security
What does Obsidian Security do?
Obsidian Security delivers a unified SaaS and AI security platform built on its proprietary Knowledge Graph. The platform combines SaaS Security Posture Management (SSPM), Identity Threat Detection and Response (ITDR), SaaS Supply Chain Security, and AI Security Posture Management (AI-SPM) into a single offering for large enterprises, with a separate browser-extension-based mid-market product for phishing prevention and shadow SaaS discovery.
Is Obsidian Security a public or private company?
Obsidian Security is a private company. It is classified as venture growth investor backed and is currently operating.
When was Obsidian Security founded?
Obsidian Security was founded in 2018. It employs 101 to 250 people.
Where is Obsidian Security based?
Obsidian Security is headquartered in Newport Beach, United States, in the North America region.
How does Obsidian Security make money?
Four revenue lines are on record. Enterprise SaaS Security Subscription is the primary driver. The others are mid-Market Freemium / Tiered Subscription, professional / Advisory Services and marketplace Channel Sales.
Who are Obsidian Security's main competitors?
Direct peers on record are AppOmni, Adaptive Shield (CrowdStrike), Reco and Grip Security. Nudge Security is listed as an emerging player. Broad incumbents are Palo Alto Networks (Prisma SaaS), Microsoft (Defender for Cloud Apps), Netskope, Zscaler and CrowdStrike.
Does Obsidian Security have an API?
No public API is recorded for Obsidian Security.
What industry is Obsidian Security in?
Obsidian Security's product category is SaaS Security. Its primary akta.pro industry code is HDADAGAJ, Attack Detection & Response for Cloud/SaaS (SOC for Cloud), with a secondary code of HDADADAI, SaaS Security Posture Management (SSPM). Its NAICS code is 54151 and its SIC code is 7371.