Onyx Security: defining cybersecurity in the agentic era
Bessemer Venture Partners leads Onyx's $113M Series B to build the secure control plane for enterprise AI agents—a category poised to produce the largest cybersecurity company yet.
Every technological revolution creates a generational security company. The internet created Palo Alto Networks. The endpoint created CrowdStrike. The cloud created Wiz. AI agents are the next revolution, and we believe the company that owns it will be bigger than any that came before. This is why we’re backing Onyx Security—the cybersecurity company building the enterprise control plane for the agentic era.
The fastest platform shift we’ve ever seen
Just a year ago, <5% of enterprise work was handled by AI agents, with 95% still needing humans in the loop. Over the next two years, and within many AI-native companies currently, that ratio is inverting: swarms of agents performing the vast majority of work, with people supervising edge cases and setting direction. What sets this shift apart from the network, cloud, and endpoint eras is that the technology itself becomes the actor. Agents aren’t users or devices; they’re autonomous, high-privilege actors that reason, call tools, move data, write and deploy code, and chain multi-step workflows on their own, at machine speed.
The agentic era is arriving faster than any shift before it. Cloud took the better part of a decade to work its way through the enterprise; agents are getting there in quarters. They're being pushed into production right now; exposure exponentially compounds before the controls to manage it even exist. And agents inherit broad, standing access by default. They act with the credentials and reach of the systems they plug into, yet almost no enterprise can say what any given agent is actually allowed to do.
Further, an agent doesn't have to be controlled by a malicious attacker to cause harm: it can accidentally delete a production database, rewrite permissions, or send sensitive data to the wrong place, simply by misreading its task. Defending the agentic enterprise means guarding against your own agents' mistakes as much as against external threats.
The incumbents, built for a world of humans and devices, can't re-platform fast enough. Swift adoption, paired with the difficulty of securing agents, creates a market ripe for a generational business.
Why are agents so hard to secure?
Agents break the assumptions on which every existing control was built:
- Their behavior is nondeterministic. Agents can take infinite paths and leverage complex reasoning to accomplish a task. The static, rule-based controls security teams rely on simply can’t anticipate the routes an agent can take, whether malicious or benign.
- You want them to have broad access. Agents are useful precisely because they reach across systems, querying databases, calling internal and third-party APIs, moving data between SaaS apps, spending money, and shipping code. Locking down permissions and identity alone defeats the purpose.
- A breach doesn’t stay small. Because an agent already holds broad, legitimate access, a single hijacked or misdirected agent can pivot, escalate, and exfiltrate across connected systems in seconds. The breach and the blast radius collapse into one step, faster than any human responder can intervene.
- The surface is everywhere, and it keeps moving. In a traditional enterprise, you can safeguard the endpoint, APIs, cloud, and deployment pipeline separately. Agents, by contrast, live across all of them at once, and they ship and run new code constantly. Observability and remediation have to keep pace in real time.
- Blocking breaks the business. Security that simply says “no” throttles the very productivity agents promise, so it gets ripped out. What’s needed is enforcement that stops the dangerous action in flight while letting the work continue.
- Pace and scale. Security teams can’t rely on humans to approve requests, review incidents, and supervise every agent-related issue. At machine volume, that's simply not feasible. The solution has to be mostly autonomous, without driving endless token cost or latency.
As we contended in our Securing AI agents roadmap, runtime, in-flight enforcement is the least-built layer of the agentic security stack, and the clearest infrastructure opportunity in cyber. Onyx is building exactly that.
Onyx’s approach to securing agents
Onyx is a secure control plane for the agentic enterprise. It helps organizations oversee agents in real time, across SaaS, cloud, endpoints, and internal infrastructure: discover every AI agent, govern what each one is allowed to do, and secure the actions they take. Every agent routes through Onyx, so nothing acts unseen. And Onyx pairs generational talent at the intersection of model training and cybersecurity, uniquely positioned to build the best-in-class solution this problem demands.
|
Model-based, not rule-based |
Where others lean on hand-written classifiers, a mesh of Onyx’s own small, purpose-trained models learns how agents actually behave across the enterprise—delivering broader coverage and far fewer false positives. Because the models are small and specialized, Onyx can sit inline on production traffic without a noticeable latency tax. Only the genuinely high-risk actions escalate to Onyx’s “Guardian Agents,” larger models and harnesses that reason over intent, authorization, and policy. |
|
Steering, instead of blocking |
When a Guardian Agent sees a risky action, it decides in the moment: approve it, block it, or redirect the agent toward a safe way to finish the job, pulling in a human only when one is truly needed. Onyx leverages its proprietary model stack to steer behavior, providing comprehensive security that keeps work flowing. |
Onyx is built natively in and for this generation of agents. That vantage point sets up a natural expansion beyond security, into observability and compliance for the entire agentic estate inside every enterprise it touches. Onyx’s edge was obvious from the first conversation, and the deeper we dug, the louder the signal to partner with them grew. Customers couldn’t stop raving: the product had exceeded their most ambitious expectations. These were sophisticated buyers who had already evaluated the best-funded players in the category. They chose Onyx anyway, citing broader visibility across agent types, far fewer false positives, and a unique approach that steers agents into the right path, instead of blocking them. For a company this young, it’s winning competitive evaluations and breaking into the Fortune 500 at a pace we’ve rarely seen.
The Onyx team and why we’re all in
These kinds of categories are only won by great teams, and Onyx’s team proves this. Co-founders Maxim Bar Kogan (CEO) and Gil Elbaz (Chief AI Officer) pair a deep security background with serious AI expertise—and a vision for the category as ambitious as any we’ve backed. They move with rare velocity, adapting to each new model and runtime as it ships, and turning that speed into design wins against far larger incumbents.
This is why we’re proud to lead Onyx’s $113 million Series B. We couldn’t be more excited to back Maxim, Gil, and the Onyx team on their mission to make the agentic enterprise safe to build on. To learn more about Onyx, or to join the team building the security company of the agentic era, visit onyx.security.
Bessemer has been a part of the cybersecurity landscape since the 90s, backing category leaders from their earliest days—often before they had product or revenue. We’ve backed the agentic era from the model layer up, and now we’re backing Onyx: how that world gets secured.






