Cyera: Building the Data Security Layer for the AI Era
Executive Intelligence Series · Startup Spotlight | September 26, 2026
Cyera entered a market that had plenty of AI infrastructure and frontier-model competition, but almost no way for enterprises to answer a basic question: what data do we have, where does it live, and what is AI doing with it? This Startup Spotlight examines whether Cyera can turn data security into a foundational layer of the AI-era enterprise stack — or whether it is building a category that larger platforms will absorb.
Cyera was founded in 2021 and reached a $12 billion valuation within five years. It has raised more than $2 billion, completed at least four acquisitions, and now claims to secure data and AI for 20% of the Fortune 500. Its annual recurring revenue has tripled for three consecutive years. But it has never disclosed absolute revenue figures, remains unprofitable, and its most recent round implies a multiple that only a handful of cybersecurity companies have ever justified.
The strategic question is not whether Cyera can discover and classify data. It can. The question is whether Cyera can convert early leadership in Data Security Posture Management into a durable platform for AI-era data and identity security — or whether data security becomes a feature of the cloud and identity platforms that enterprises already buy.
1. Why Data Security Is Becoming More Important
The enterprise data landscape has undergone a structural transformation over the past five years, and the pace is accelerating. Three converging forces are driving demand for a new approach to data security.
Data proliferation across distributed environments. Enterprises now store sensitive information across public clouds, private clouds, SaaS applications, on-premises systems, and data lakes built specifically for AI workloads. Traditional security tools, designed for perimeter-based architectures, were never built to track data as it moves across these environments at modern speed and scale.
AI's growing access to enterprise information. Generative AI systems and autonomous agents now read, write, and transform enterprise data in seconds. The data that fuels AI is often the most sensitive data an organization holds — customer records, intellectual property, financial data, and personal health information. IDC's FutureScape research noted that "the early wave of GenAI deployments surfaced a pattern where speed sometimes outpaced safeguards," and projects that by 2030 up to 20% of G1000 organizations will be negatively impacted by high-profile disruptions tied to poor AI agent governance.
The gap between AI adoption and security controls. Microsoft's 2026 Data Security Index found that generative AI adoption is accelerating faster than enterprise data security controls can adapt. Security leaders have responded: LLM and GenAI protection became the top security budget priority for 2026 at 59%, overtaking cloud security, which declined from 58% to 54%. The share of organizations already spending on AI security tools reached 32% in 2026, up from 23% in 2025.
The data-centric security market grew from $10.38 billion in 2025 to an estimated $13.36 billion in 2026, a CAGR of 28.7%. The DSPM segment specifically is projected to grow from $1.3 billion in 2026 to $13.9 billion by 2034. These are not niche markets — they reflect a fundamental shift in how enterprises must think about protecting their most valuable asset.
The CODEW Lens: Data security used to be a compliance exercise. In the AI era, it becomes an operational control — because AI systems cannot be trusted with data that the enterprise cannot see, classify, or govern.
2. What Cyera Does
Cyera's platform addresses a deceptively simple question that most enterprises cannot answer: What data do we have, where is it, who can access it, and what is being done with it?
The company started by classifying enterprise data — working out what an organization holds, how sensitive each piece is, and who can reach it. That foundation has expanded into a unified AI Security Platform spanning several distinct capabilities.
Data Security Posture Management (DSPM). The core offering. Continuous discovery, classification, and risk assessment across cloud, SaaS, and on-premises environments. Cyera's AI-native classification goes beyond pattern-matching to understand data context, ownership, access patterns, and exposure.
Browser Shield. Provides visibility into how AI tools are used across an organization — sanctioned applications and shadow AI alike — while inspecting prompts in real time. It evaluates each interaction based on the data being shared, the user's identity, whether the account is corporate or personal, and context from Cyera's DSPM and Omni DLP engines, then allows, alerts, or blocks inline before data reaches an external model.
Data Lineage. Maps how AI agents move, copy, and transform sensitive files throughout their lifecycle. As Cyera describes it, a single confidential PDF can be summarized by Copilot, turned into a slide deck by a specialized agent, and stored across multiple cloud storage buckets — all within minutes.
Non-human identity governance. The July 2026 acquisition of Oasis Security brought non-human identity (NHI) management into the platform. Non-human identities inside Fortune 500 companies grew nearly 500% in six months, making them the fastest-growing identity type in the enterprise. The combined platform now determines what every human, machine, and AI agent can see and do.
Agentic AI security. Agent Guardian and Endpoint track what AI agents do — not just prompts and responses, but tool calls, database queries, and the actions in between, across cloud deployments and endpoint devices. The acquisition of Ryft extends this into the data infrastructure layer where AI agents run.
The CODEW Lens: Cyera did not start as an AI security company. It started as a data classification company and expanded into AI security because classification is the prerequisite for every other control. That ordering matters — it is much harder to move from AI security backwards into data discovery than the other way around.
3. The AI Data Security Opportunity
The emergence of generative AI and autonomous agents represents both the largest opportunity and the most significant challenge for data security. Cyera's thesis is that AI changes the fundamental nature of data risk in five ways.
Data access changes. Traditional security models assumed data access was initiated by humans, with accountability mechanisms that could be applied after the fact. As Cyera CEO Yotam Segev has argued, "you can't threaten an agent, prosecute an API, or discipline a workload. Once an autonomous system has permission, it acts, continuously and without hesitation."
Data movement accelerates. Agents operate at machine speed, moving and transforming data faster than human oversight can track. A single confidential document can be summarized, converted, and distributed across multiple systems within minutes, making point-in-time data inventories obsolete.
Permissions become dynamic. Static permissions granted months ago are no longer reliable when agents can change their identity based on task, tools, and delegation chains from other agents. This is the specific gap the Oasis Security acquisition addresses.
Shadow AI creates new exposure vectors. Employees interacting with unsanctioned AI tools — often through personal accounts — insert sensitive data into prompts without enterprise visibility. Browser Shield's real-time prompt inspection is a direct response.
Governance frameworks are lagging. Cyera's own research indicates that 68% of organizations cannot distinguish between human and AI agent activity within their systems as of 2026. That visibility gap is precisely the market Cyera is selling into.
The CODEW Lens: Every AI security problem eventually resolves into a data security problem. You cannot govern what an agent does without knowing what data it touched — and most enterprises do not know that today.
4. The Business Model
Cyera operates a classic enterprise SaaS model with several distinctive characteristics: a volume-based pricing structure, a direct enterprise sales motion, and an acquisition-led platform expansion strategy.
Target customers. Large enterprises in regulated industries — financial services, healthcare, retail, media, and telecommunications. Named customers include Paramount, Chipotle, Valvoline, and ChenMed. The company claims to secure data and AI for 20% of the Fortune 500, with 353% year-over-year growth among Fortune 500 customers over the past 18 months.
Cyera's published AWS Marketplace pricing illustrates the volume-based model:
| Tier | Data Volume | 12-Month Price |
|---|---|---|
| Standard | Up to 25 TB | $50,000 |
| Business | Up to 100 TB | $100,000 |
| Enterprise | Up to 250 TB | $250,000 |
Direct pricing is custom-quoted. Enterprise engagements typically start around $2,000 per terabyte with a minimum around $50,000 per year. The model aligns with the use case: the more data an enterprise holds, the more value the platform provides.
Recurring revenue. ARR has tripled for three consecutive years, though absolute figures have not been disclosed. Subscription contracts with multi-year terms create predictable revenue and expansion potential as customer data estates grow.
Expansion opportunities. Each acquisition adds a capability layer that can be sold into the existing base — increasing average contract value and deepening platform stickiness. This is the same land-and-expand logic that defined the endpoint and cloud security platform winners of the last decade.
The CODEW Lens: Cyera's pricing is indexed to data volume, not seats or endpoints. That is a structurally better position in an AI era — because enterprise data volume only moves in one direction.
5. Funding & Capital
Cyera's funding history is remarkable for both velocity and scale. The company has raised more capital in five years than most cybersecurity companies raise in a decade.
| Round | Date | Amount | Valuation | Key Investors |
|---|---|---|---|---|
| Series C | Apr 2024 | $300M | $1.4B | Accel, Sequoia, Redpoint, Georgian, Spark, Coatue |
| Series D | Nov 2024 | $300M | $3B | Accel, Sapphire, Sequoia, Redpoint, Coatue, Georgian |
| Series F | Jan 2026 | $400M | $9B | Blackstone, Accel, Coatue, Cyberstarts, Greenoaks, Lightspeed, Sequoia, Spark |
| Series G | Jun 2026 | $600M | $12B | Evolution Equity Partners, Cyberstarts, Temasek |
| Series G Extension | Sep 2026 | $400M | $12B | Goldman Sachs Growth Equity |
Total funding now exceeds $2 billion, with $1.4 billion raised in 2026 alone. The syndicate includes many of the most prominent venture firms in enterprise software and cybersecurity, alongside strategic investors such as AT&T Ventures and Blackstone.
What the funding enables. The September 2026 Goldman Sachs investment was earmarked for three specific purposes: an AI security roadmap, a push into the federal market, and growth across EMEA and APAC. The company has grown to more than 1,500 employees across 18 countries in the past 18 months.
Capital intensity. Cyera's growth strategy is capital-intensive. It runs a direct enterprise sales motion with a global footprint, and its acquisition strategy — four acquisitions in five years, including the reported $1 billion Oasis Security deal — requires significant deployment. The company remains unprofitable, and its $12 billion valuation implies roughly an 80x ARR multiple based on reported estimates, which is aggressive even by cybersecurity standards.
The CODEW Lens: Cyera's funding trajectory is a bet on category ownership, not current economics. The company is buying speed — in product, geography, and acquisitions — because it believes the data security category will consolidate around two or three platforms.
6. The Competitive Landscape
Cyera competes across several overlapping categories, and the dynamics are fluid rather than static. The table below positions the company by category rather than by ranking.
| Category | Representative Players | Cyera's Position |
|---|---|---|
| DSPM specialists | BigID, Varonis, Proofpoint | AI-native classification; fastest expansion into AI security |
| Cloud security platforms | Wiz, Orca Security | Data-centric counter-position: cloud platforms secure infrastructure, not data content |
| Data protection incumbents | Rubrik, Commvault, Cohesity | Security built natively rather than bolted onto backup |
| Identity vendors | Okta, CyberArk, Oasis (now Cyera) | Unifying data and identity in one control plane — unproven at scale |
| Large security platforms | Microsoft Purview, Palo Alto Networks, CrowdStrike | Positions as complement and integration partner rather than replacement |
The competitive landscape is not zero-sum. Many enterprises will deploy multiple data security tools, and Cyera's integrations — with AWS Security Hub, Microsoft Purview, and Cohesity — position it as a complement to broader security platforms rather than a wholesale replacement.
The CODEW Lens: Cyera's most dangerous competitor is not BigID or Varonis. It is Microsoft — because Purview is already inside the contract, already integrated with the data, and effectively free at the margin for many enterprises.
7. Cyera's Competitive Advantage
It is important to separate what Cyera has demonstrated from what it claims or projects.
Demonstrated advantages. Cyera's AI-native classification technology has been independently validated. The company was named a Leader in The Forrester Wave™: Sensitive Data Discovery and Classification Solutions, Q2 2026, receiving the highest score in the Strategy category among 10 vendors evaluated. Forrester noted that "Cyera has a powerful vision to become a decision control layer for data" and that the company "is well-positioned to bring this vision to life quickly with its innovation strategy and well-defined roadmap."
Scale of operations provides a second demonstrated advantage. Paramount classified 51PB+ of data across 400,000+ datastores in under two weeks. ChenMed resolved 32,000+ data security issues before patient data could be exposed. A health insurance customer remediated 1.2PB of data before AI could access it, which Cyera attributes to more than $100 million in avoided AI risk. These are concrete outcomes rather than marketing claims.
Company claims and future potential. Cyera's positioning as the "trust layer for the agentic enterprise" is a strategic narrative that has not yet been proven at scale. The Oasis Security integration is recent, and the combined value proposition of unified data and identity governance remains to be validated in the market.
Similarly, the expansion into AI security through Browser Shield, Data Lineage, and Agent Guardian is a significant bet on the trajectory of enterprise AI adoption. The thesis — that securing AI requires a fundamentally new approach to data security — is compelling, but it depends on enterprises prioritizing AI security spending at the levels Cyera's valuation implies.
The CODEW Lens: The demonstrable advantage is classification accuracy and scale at cloud speed. The claimed advantage is becoming the control layer for AI. One is verified today. The other is a bet on where the market goes next.
8. Market Expansion
Cyera's trajectory suggests a deliberate strategy to expand from DSPM into a broader data and AI security platform.
AI security. The most significant expansion vector: agent monitoring, prompt protection, data lineage for AI workflows, and non-human identity management. This directly addresses the governance gap IDC expects to affect 20% of G1000 organizations by 2030.
Data governance. The Ryft acquisition brings secure, automated data lake capabilities into the platform, enabling governance at the infrastructure layer where AI workloads run.
Identity. Oasis Security transforms Cyera from a data security company into a data and identity security platform. The argument — that data and identity are the two foundational elements of every trust decision — is architecturally compelling. Whether enterprises will buy identity governance from a data security vendor rather than from Okta or CyberArk remains an open question.
Cloud security and compliance. The AWS partnership places Cyera within the cloud security ecosystem, and continuous compliance capabilities address the governance requirements of AI deployment at scale. Presence in AWS Security Hub Extended provides distribution access to a very large AWS customer base.
Federal market. The September 2026 funding explicitly earmarked capital for a federal push, signaling intent to expand beyond commercial enterprises into government and defense, where data security requirements are particularly stringent.
The CODEW Lens: Cyera is expanding along the same axis that Wiz used in cloud security, and CrowdStrike used in endpoint — start with one control point, then absorb adjacent controls. The question is whether data security has the same gravitational pull as cloud or endpoint.
9. The Risks
Competition from incumbents. Microsoft, Palo Alto Networks, and other large platforms have the resources, customer relationships, and distribution channels to compete aggressively. If incumbents successfully bundle data security into broader platforms, Cyera's standalone value proposition could face pressure.
Platform consolidation. Enterprise security buyers are consolidating vendors, seeking platforms that address multiple domains through a single contract. Cyera is expanding, but it remains a specialist relative to full-stack security vendors.
Enterprise sales cycles. Cyera's target customers — large enterprises and government agencies — have long procurement cycles. Revenue growth depends on maintaining sales velocity while moving upmarket and into new geographies.
AI market changes. The growth thesis is predicated on continued enterprise AI adoption. If AI deployment slows, or if enterprises build data security capabilities internally, the addressable market could be smaller than projected.
Execution risk. The acquisition strategy, while strategically coherent, carries integration risk. Combining four acquired companies into a unified platform — while scaling sales, expanding globally, and developing new products — is a significant operational challenge.
Customer concentration. As Cyera moves upmarket into very large enterprises, monitoring concentration and net retention will be essential to assessing revenue durability.
Valuation risk. A $12 billion valuation with undisclosed revenue and no profitability creates pressure for continued hypergrowth. A deceleration could trigger a valuation reset of the kind other high-flying cybersecurity startups have experienced.
The CODEW Lens: The biggest risk is not that Cyera fails to build a data security platform. It is that Cyera builds an excellent data security platform and still loses the category to a bundled incumbent that was already in the contract.
10. What to Watch
Revenue disclosures. Cyera has not published absolute ARR figures. Any disclosure of revenue or profitability metrics would provide critical validation of the business model.
Oasis Security integration. Whether Cyera can successfully sell unified data and identity governance will be a key indicator of its platform expansion strategy.
AI security product adoption. Adoption rates for Browser Shield, Data Lineage, and Agent Guardian will reveal whether enterprises will pay separately for AI-specific data security capabilities.
Federal market traction. The government push will test whether the platform meets the stringent requirements of public-sector buyers.
Competitive responses. How Microsoft, Wiz, and other competitors respond to Cyera's AI security positioning will shape the landscape.
Further M&A or IPO signals. With $2 billion raised and a $12 billion valuation, Cyera has capital to deploy. Additional acquisitions or IPO preparation would signal the next phase of its strategy.
Channel and cloud partnerships. Expansion of the AWS relationship — and any comparable partnerships with Microsoft or Google Cloud — would materially change distribution reach.
The CODEW Lens: The single most important data point to watch is whether Cyera's AI security products are sold as standalone line items or bundled into existing DSPM contracts. Standalone pricing would validate a genuinely new budget category.
The CODEW Take: Can Cyera Become the Data Security Layer for the AI Era?
Can Cyera become a critical data security layer as enterprises increasingly use AI, cloud platforms,s and distributed data environments?
The answer is likely yes — but the company that emerges will be judged on two things it has not yet proven: whether enterprises will treat data security as a distinct budget category, and whether Cyera can win that category against incumbents already inside the contract.
Cyera has built something genuinely difficult: an AI-native classification engine that operates at cloud scale, validated by a Forrester Leader position and by customer deployments measured in petabytes. That foundation is real, and it is the prerequisite for everything else — you cannot protect, govern, or govern AI's use of data you cannot see.
The expansion into AI security and non-human identity management is strategically logical. Data and identity are the two control points that determine what any agent can reach. If Cyera owns both, it becomes a decision layer rather than a discovery tool. That is a much more defensible position — and a much larger market.
But the risks are structural. Cyera's valuation assumes continued hypergrowth and eventual profitability, with no public revenue figures to validate either. Its most formidable competitor, Microsoft, already has distribution, integration, and pricing advantages that Cyera cannot match. And the AI security market it is betting on could consolidate around the model providers themselves.
The CODEW verdict: Cyera is the most credible independent challenger in data security today, with the technology, capital, and customer proof points to become a foundational layer of the AI-era security stack. The open question is not capability — it is category. Data security must become a first-class enterprise budget line, not a feature of cloud or identity platforms. If it does, Cyera is positioned to define it. If it does not, Cyera becomes an acquisition target rather than a platform.
The three sources of potential advantage — classification depth, AI-native architecture, and an expanding control surface across data and identity — are all present. The question is whether they compound into a platform or dissolve into a collection of expensive capabilities that a larger vendor bundles for free. The next 24 months will tell.
The CODEW Lens: Cyera is not betting on being the best data security tool. It is betting that in an AI-driven enterprise, whoever controls the map of the data controls the security stack. Owning the map is a more durable position than owning any single control built on top of it.
The Cyera Glossary
DSPM (Data Security Posture Management) — Continuous discovery, classification, and risk assessment of data across cloud, SaaS, and on-premises environments.
NHI (Non-Human Identity) — An identity assigned to a machine, service, API, workload, or AI agent rather than a person. NHIs grew nearly 500% in six months inside Fortune 500 companies, according to Cyera.
AI Agent — An autonomous system that can read, write, and act on enterprise data and systems with limited human supervision.
Shadow AI — Use of unsanctioned AI tools, often through personal accounts, that inserts enterprise data into external models without IT visibility.
DLP (Data Loss Prevention) — Controls that detect and block the unauthorized movement of sensitive data. Cyera's Omni DLP engine extends this to AI prompts and agent actions.
Data Lineage — A trace of how data moves, is copied, and is transformed over time, including by AI agents.
Data Classification — The process of identifying what data exists and how sensitive it is, the foundation for every downstream security control.
Inline Prompt Inspection — Evaluating AI prompts in real time — before they reach an external model — to decide whether to allow, alert, or block.
Agentic AI — AI systems that execute multi-step tasks and tool calls autonomously rather than simply generating responses.
ARR (Annualized Recurring Revenue) — Annualized run rate of subscription revenue. Cyera's ARR has tripled for three consecutive years, but absolute figures are undisclosed.
AI Security Posture Management — The emerging discipline of assessing and controlling risk across AI models, agents, and the data they touch.
Data Security Platform — A consolidated system spanning discovery, classification, posture management, DLP, and access governance, as distinct from a single-purpose tool.
FAQ
Q: What does Cyera actually do?
Cyera discovers and classifies enterprise data across cloud, SaaS, and on-premises environments, then uses that classification to manage risk — including exposure, access, data loss prevention, and AI-related risk such as prompt inspection and agent monitoring. It has expanded into non-human identity governance through its Oasis Security acquisition.
Q: How much has Cyera raised, and at what valuation?
Cyera has raised more than $2 billion in total, including $1.4 billion in 2026 alone. Its Series G in June 2026 raised $600 million at a $12 billion valuation, followed by a $400 million extension in September 2026 led by Goldman Sachs Growth Equity. Investors include Accel, Sequoia, Coatue, Georgian, Redpoint, Sapphire, Blackstone, Cyberstarts, Lightspeed, Greenoaks, Evolution Equity Partners, Temasek, and AT&T Ventures.
Q: Is Cyera profitable?
Cyera has not disclosed profitability, and its capital intensity — global enterprise sales, four acquisitions, and rapid headcount growth to more than 1,500 employees across 18 countries — suggests the company is prioritizing growth over near-term margin. It remains unprofitable based on the information available.
Q: Who are Cyera's main competitors?
In DSPM, the closest competitors are BigID, Varonis, and Proofpoint. Beyond DSPM, Cyera competes with cloud security platforms such as Wiz, data protection incumbents such as Rubrik and Commvault, identity vendors such as Okta and CyberArk, and large security platforms including Microsoft Purview, Palo Alto Networks, and CrowdStrike.
Q: What are Cyera's biggest risks?
The biggest risks are competition from bundled incumbents — particularly Microsoft — platform consolidation by enterprise buyers, long enterprise sales cycles, integration risk from four acquisitions, dependence on continued enterprise AI adoption, undisclosed revenue against a $12 billion valuation, and the possibility that data security does not become a standalone budget category.
Q: Why does Cyera matter for the AI era specifically?
Because AI agents act on enterprise data autonomously and at machine speed. Cyera's argument is that you cannot govern AI without knowing what data exists, how sensitive it is, who and what can reach it, and how it moves. If that argument holds, data security becomes foundational AI infrastructure rather than a compliance overlay.
The CODEW Stat
$2B+ raised · $12B valuation · 20% of the Fortune 500 Cyera has raised more than $2 billion in five years, reached a $12 billion valuation, and claims to secure data and AI for 20% of the Fortune 500 — with ARR tripling for three consecutive years and no disclosed revenue figure. The capital is real. The customer footprint is real. What remains unproven is whether data security becomes a first-class enterprise budget line rather than a feature of the platforms enterprises already own. That is the central question of the Cyera thesis.
Reviewed by Erwin Castro
on
Saturday, September 26, 2026
Rating:
