Securing the Agentic Workforce: Our Investment in Onyx Security
Social Sharing
07.29.2026
FirstMark
The largest new companies in cyber are created when a shift in how knowledge work gets done intersects with a new security model. When business software moved to the web, Palo Alto built a firewall that could secure traffic at the application layer. As endpoints reached critical mass, CrowdStrike introduced a cloud native sensor. As cloud adoption accelerated with remote work during Covid, Wiz introduced a graph-first CNAPP that provided much needed visibility & protection. Every prior shift changed how we work. Agents do the work, making them harder to secure than any vector before them, and the opportunity in their wake proportionally larger.
For agents to work on behalf of humans, they need similar permissions and access. This ultimately leads to a highly permissioned, highly capable threat vector that is acting at superhuman velocity. Humans have long been considered the most vulnerable security element, but in this new world, agents are more powerful, operating at a greater scale, and will require an entirely new control plane. Cofounders Maxim & Gil anticipated this problem years ago and we couldn’t be more excited to invest in Onyx’s $113m Series B, alongside our friends at Bessemer, Cyberstarts, Conviction, and TCV.
Why Maxim & Gil?
Maxim & Gil are incredible engineers, hugely ambitious, and had a prescient insight into the need for agent security well before “agents” hit the market. As we’ve gotten to know the team over the last year, it’s been clear this foresight stems from their backgrounds building at the technical frontier. Maxim won national coding and math competitions as a teenager, served in an elite cyber unit of Israeli intelligence, and built a company to 9 figures in revenue. Gil has spent his entire career in AI, starting with AI algorithms in the Israeli Air Force before founding Datagen and ultimately building agentic infrastructure in the NVIDIA CTO office.
As AI adoption began to surge, initial security efforts were focused on data loss prevention and securing chat interfaces against prompt injections, but Maxim & Gil were already thinking about this looming problem of secure agency. They have stayed ahead of the curve since, and they move at breakneck speed. While still in stealth, they assembled a best-in-class product and team that has already landed large deals with Fortune 500 customers and AI forward orgs. In just 4 months since they launched, things have only accelerated.
The Hardest Problem in Security Right Now
Security has always lagged adoption. With AI, boards are mandating adoption faster than security posture can keep up. Over the last year, agent building has been folded into the leading platforms. Any employee can now deploy his or her own agents, and their subsequent waterfall of security risks. Every company is becoming a manager of agents, and many are already managing more agents than employees. No existing tool can see across that surface: software, cloud, endpoint, and customer facing environments.
While visibility is initially top of mind, it is even more challenging to govern and secure agentic actions in real time. Security tools were built to watch deterministic software or operator led workflows that moved at human speed. With agents, behavior is shaped by a non-deterministic model, live context, and inputs that aren’t vetted in advance. The same capabilities that let agents handle edge cases and objections also make them vulnerable.
Since agents have a set of tools and autonomy to decide what sequence of actions is necessary, it’s incredibly difficult to cover the full potential action space. This chain of dynamic actions opens up endless attack vectors, whether it’s prompt injection buried in a document or an email, an over-scoped credential that turns one compromised agent into lateral movement across every system, or a chain of individually authorized actions that quietly exfiltrates sensitive data. A security tool may see a segment of this chain, but agents operate across modalities and no single product today has the context to govern the whole workflow.
The dollars are already following the risk. In our diligence, we heard enterprise security teams are ranking agent security as a top 3 budget item, alongside foundational security primitives covering endpoint, network, and cloud.
Investing in Onyx
With a large new market, there are unsurprisingly a number of players, incumbents and startups, aggressively attacking the space. Onyx has made a bold bet early that we believe has separated them from the rest of the field. Instead of applying traditional, deterministic security techniques to agent behavior, Onyx has trained proprietary models that sit in the runtime path. Agentic actions have a wider behavior distribution than any previous security vector, and using AI is the only way to scalably govern this behavior. These models inspect every action and, when necessary, block or redirect it before it ever reaches a downstream system. This only works if it’s fast and accurate at once, and Onyx has built both: sub-100 millisecond decisions.
What’s Next
Within a few years, the typical company will manage an army of agents orders of magnitude larger than its employee base. Securing that workforce is the largest new market opportunity in cyber, and the responsibility for governing it reaches well beyond security into how the entire business runs. Onyx has already begun to expand into model orchestration, ROI tracking, and more, giving CISOs, CTOs, and CIOs a way to measure the value of every agent they deploy and ensure they are working on intended tasks. We couldn’t be more excited to partner with Maxim, Gil, and the entire Onyx team as they build the secure control plane for the AI era.