# Obsidian Security, Inc.
*Also known as Obsidian*

- Website: https://www.obsidiansecurity.com
- Location: Palo Alto, California, United States
- Agent profile: https://directory.haycion.ai/agents/obsidiansecurity-com

> Enterprise-grade security for AI agents, software integrations, and SaaS ecosystems.

Obsidian Security delivers enterprise-grade security for AI agents, third-party app integrations, and SaaS ecosystems. The company helps organizations gain visibility into who and what is accessing their software, enforce governance across integrations, and protect data and workloads in hybrid cloud environments. Serving large enterprises to fast-growing startups, Obsidian focuses on securing AI-enabled workflows and the connections that power modern applications.

**Mission:** To help enterprises securely adopt and operate AI and software ecosystems by providing visibility, governance, and protection across agents, integrations, and SaaS.

## Products & Services

### [Obsidian Security Platform](https://www.obsidiansecurity.com/platform-overview)
*Platform*
Enhance security and governance of AI agents and third-party applications in SaaS ecosystems.

- **Agent governance** — Streamline Agent Oversight
- **Agent runtime security** — Enforce Security Policies
- **AI agent visibility** — Real-Time Discovery
- **AI security posture management** — Centralized Security Oversight
- **Integrations hub with connectors** — Effortless Integration Deployment
- **Third-party application security** — Secure Third-Party Access
- **Real-time telemetry and threat detection** — Immediate Threat Response
- **GenAI data leakage prevention** — Mitigate Data Breaches
- **Shadow AI detection** — Identify Unapproved Applications
- **AI platform integrations** — Unified Security Governance
- **AI prompt security** — Protect Sensitive Data

### [SaaS Supply Chain Security](https://www.obsidiansecurity.com/saas-supply-chain-security)
*Solution*
Protects your SaaS ecosystem from integration and third-party application threats.

- **Governance of third-party apps** — Reduce Risk From External Apps
- **SaaS supply chain visibility** — Increase Visibility Into Your SaaS Landscape
- **Supply chain breach containment** — Minimize Impact of Breaches
- **Real-time threat detection** — Detect Threats In Real-Time
- **Tools for managing non-human identities** — Secure Non-Human Identities

### [SaaS Security Posture Management (SSPM)](https://www.obsidiansecurity.com/resource/sspm-guide-to-saas-security-posture-management)
*Product*
Mitigate SaaS security risks through continuous monitoring and remediation of misconfigurations.

- **Continuous monitoring** — Ensures Ongoing Security Awareness
- **Remediation guidance** — Provide Actionable Insights
- **Security assessment** — Identifies Potential Vulnerabilities
- **Integration visibility** — Enhances Security Oversight

### [MCP Security](https://www.obsidiansecurity.com/mcp-security)
*Solution*
Manage AI Agents Efficiently While Enhancing Security Across Your Enterprise.

- **Agent discovery** — Identify All AI Agents Instantly
- **MCP server discovery** — Map Your MCP Environment Seamlessly
- **Run-time governance** — Enforce Governance on AI Agents
- **Security posture management** — Protect SaaS Configurations

### [Third-Party App Security](https://www.obsidiansecurity.com/third-party-app-security)
*Product*
Improve security and governance of third-party apps with comprehensive visibility and risk management.

- **Integration governance** — Ensures Controlled Integrations
- **Risk management** — Mitigates External Risks
- **Visibility of third-party apps** — Enhances Operational Transparency
- **Privileged user management** — Secures Sensitive Access
- **Shadow app detection** — Discovers Unregulated Apps

## Market Segments

- **SaaS security posture management** (market size $1.0B, CAGR 19.4%): Continuous monitoring, misconfiguration detection, risk-based prioritization, and policy enforcement to improve security posture and compliance across SaaS applications and integrations.
- **Autonomous agent governance** (market size $1.0B, CAGR 30%): Capabilities to discover, permission, and enforce real-time guardrails for autonomous AI agents across environments, including agent discovery, granular read/write/execute permissions, prompt injection mitigation, and data protection in agentic workflows.
- **Third-party application security and supply chain governance** (market size $1.7B, CAGR 15%): Discovery, governance, threat detection, and containment across third-party apps and the SaaS supply chain, including connector management and breach containment.
- **Machine and non‑human identity management** (market size $11.3B, CAGR 12%): Management and protection of machine, agent, and non-employee identities, covering credential lifecycle, automated provisioning, and controls for non-human access.

## Ideal Customer Profiles

### Enterprise AI And SaaS Security Governance
Large enterprises seeking comprehensive governance for AI agents, SaaS apps, and hybrid cloud environments.
- Industry: Technology, Financial Services, Healthcare, and other large enterprises.
- Geography: Global (North America and EMEA focus)
- Pain points: Difficulty securing AI agents, managing third-party app risk, visibility gaps across SaaS and hybrid cloud.
- Business goals: Achieve end-to-end security governance, reduce data leakage, ensure policy compliance.
- Positioning: Comprehensive governance, threat detection, and protection for AI enabled workflows, third party apps, and SaaS ecosystems across hybrid clouds.

#### Persona: Chief Information Security Officer
- Needs: Comprehensive governance for AI agents, visibility across SaaS, scalable policy controls
- Goals: Minimize risk, achieve regulatory compliance, reduce incident response time
- Challenges: Siloed data, fragmented tools, slow cross system correlation
- Pain points: Disjointed security data, audit preparation burden, resource constraints
- Solution: Uses MCP Security for agent governance and Obsidian Security Platform for visibility and runtime security; SSPM and SaaS supply chain security for continuous governance.

#### Persona: Security Architect
- Needs: Granular governance across integrations, runtime security, threat detection
- Goals: Secure AI enabled workflows, reduce integration risk
- Challenges: Complex tech stack, evolving threat landscape
- Pain points: Misconfigurations across multiple tools, drift in policy enforcement
- Solution: Leverages Obsidian Security Platform for real time telemetry and AI platform integrations; Integrations hub for secure connectors.

#### Persona: IT Compliance Lead
- Needs: Audit ready reporting, policy enforcement, continuous compliance
- Goals: Pass audits, maintain compliance posture
- Challenges: Regulatory changes, audit backlog
- Pain points: Lack of centralized evidence, delayed remediation
- Solution: Uses SSPM for continuous monitoring and remediation guidance; SaaS supply chain security for governance of third party apps.

### Global SaaS And Cloud Security Leaders
Mid-to-large enterprises securing SaaS ecosystems, cloud deployments, and third party integrations.
- Industry: Technology, SaaS, Financial Services
- Geography: Global (North America and Europe focus)
- Pain points: SaaS sprawl, insecure third party apps, misconfigurations, supply chain risks
- Business goals: Improve security posture, continuous monitoring, rapid remediation
- Positioning: Comprehensive governance, threat detection, and secure integrations across SaaS and cloud deployments for AI enabled workflows.

#### Persona: Security Operations Manager
- Needs: Centralized visibility and remediation across SaaS and cloud apps
- Goals: Reduce detection to remediation time, maintain compliance
- Challenges: Fragmented tooling, alert fatigue
- Pain points: High volume of alerts, misconfigurations across apps
- Solution: Uses Obsidian Platform for real time telemetry and AI platform integrations; SSPM for continuous monitoring; SaaS Supply Chain Security for third party risk.

#### Persona: Cloud Security Architect
- Needs: Secure cloud architectures and managed integrations
- Goals: Secure cloud environments and safe third party connections
- Challenges: Keeping up with dynamic cloud changes
- Pain points: Visibility gaps, inconsistent controls
- Solution: Agent governance and runtime security to control AI agents; Real time telemetry; Integrations hub to manage connectors.

#### Persona: IT Compliance Manager
- Needs: Audit ready evidence, policy enforcement
- Goals: Pass audits, demonstrate compliance
- Challenges: Regulatory changes, complex vendor ecosystems
- Pain points: Fragmented data, slow remediation
- Solution: SSPM for continuous monitoring and remediation; Shadow AI detection; Third-Party App Security for risk management.

### Rapid Growth AI Startups
Growing companies automating AI enabled workflows need governance and threat detection across multiple SaaS tools.
- Industry: Technology, AI startups, SaaS
- Geography: Global
- Pain points: Limited security visibility, risk of data leakage, evolving AI agent governance
- Business goals: Scale securely, maintain compliance, protect data across SaaS integrations
- Positioning: Scalable security controls for AI and SaaS help growing teams keep pace with rapid innovation.

#### Persona: Security Engineer
- Needs: Visibility into AI agents and data flows, easy to deploy controls
- Goals: Reduce security risk while enabling rapid innovation
- Challenges: Resource constraints, fast changing tech
- Pain points: Time consuming manual checks, lack of automated controls
- Solution: MCP Security for agent governance, Obsidian Platform for visibility and runtime security, SSPM for monitoring, Third-Party App Security for risk.

#### Persona: DevOps Lead
- Needs: Secure CI/CD, secure integrations, policy enforcement
- Goals: Faster secure deployments
- Challenges: Balancing speed and security
- Pain points: Friction between dev and security teams
- Solution: Integrations hub with connectors for secure integrations; Real time telemetry; AI prompt security.

#### Persona: Platform Architect
- Needs: Architectural guidance for secure AI workflows
- Goals: Build scalable, secure platform
- Challenges: Governance across agents complexity
- Pain points: Governance complexity
- Solution: Agent governance, runtime security, governance across tools; Shadow AI detection.

### Regulated Industries Compliance Leaders
Enterprises in regulated sectors seeking audit ready security and vendor risk management.
- Industry: Financial Services, Healthcare, Government, Regulated Enterprises
- Geography: Global (North America and Europe focus)
- Pain points: Regulatory compliance, vendor risk, transparency, audit readiness
- Business goals: Maintain compliance, reduce audit findings, ensure secure third party integration
- Positioning: Comprehensive governance, risk controls across AI agents, SaaS apps, and third party integrations for regulated environments.

#### Persona: Chief Compliance Officer
- Needs: Audit ready evidence, vendor risk management
- Goals: Pass regulatory audits, minimize non compliance findings
- Challenges: Regulatory changes, complexity of vendor ecosystems
- Pain points: Fragmented data, slow remediation
- Solution: SSPM for continuous monitoring, SaaS Supply Chain Security for third party governance, Third-Party App Security for risk control.

#### Persona: IT Auditor
- Needs: Clear, centralized security evidence
- Goals: Complete audit package efficiently
- Challenges: Collecting data from disparate systems
- Pain points: Inadequate visibility
- Solution: Real time telemetry and audit ready reporting via Obsidian Platform; Integrations hub; Shadow AI detection.

#### Persona: Vendor Risk Manager
- Needs: Visibility into external apps, risk scoring, remediation guidance
- Goals: Reduce third party risk and governance gaps
- Challenges: Keeping track of vendor changes
- Pain points: Unclear risk ownership
- Solution: SaaS supply chain security for vendor governance, Integrations hub and threat detection.
