Obsidian Security
A security tool for IT teams that answers a question most companies can't: which of the hundreds of apps and AI agents connected to our Google Workspace, Salesforce or Slack actually have access to what, and are any of them behaving suspiciously right now
🔗 Visit Obsidian SecurityDescription
Modern companies connect dozens or hundreds of third-party apps and, increasingly, AI agents to their core business systems (Microsoft 365, Salesforce, Snowflake, Slack...) — each one a potential way in for an attacker, and most security teams have no real inventory of what's connected or what it can touch. Obsidian Security exists to close that blind spot: it continuously discovers every app, integration and AI agent with access to your SaaS environment, shows exactly what data and permissions each one holds, and watches for suspicious behavior like account takeover attempts or session hijacking in real time.
Obsidian combines SaaS Security Posture Management (continuous config monitoring and privilege right-sizing) with Identity Threat Detection & Response (OAuth abuse, MFA bypass, token theft detection) and a newer layer specifically for governing AI agents connecting to enterprise systems — visibility into what agents can do, guardrails on their actions, and audit trails. It integrates directly with major AI platforms (Bedrock, Azure AI Foundry, Claude, OpenAI, Vertex AI) as well as core enterprise systems (Microsoft 365, Salesforce, Snowflake, Databricks, Workday), and is used by companies like T-Mobile, Databricks and Snowflake.
💬 Our review
The short version: Obsidian answers a question that's become urgent as AI agents get plugged into everything — "what can this thing actually access, and is that safe" — for both traditional SaaS sprawl and the newer wave of agentic AI integrations, in one platform instead of two separate tools.
The certification list (SOC 2, ISO 27001, ISO 27018, ISO 42001) and the $85M Series D signal a mature, well-capitalized vendor rather than an early bet, and the free tier up to 1,000 users is a genuinely useful way to try shadow-app discovery before paying anything. The catch is pricing opacity past that point — competitors like Varonis and Reco.ai are similarly cagey, so this isn't unusual for the category, but it does mean budgeting requires a sales conversation. For a large enterprise already juggling AI agent rollout and SaaS sprawl separately, consolidating both under one vendor is a real time saver; for anyone smaller, the Fortune-500-first positioning will likely show up in both price and onboarding complexity.
💰 Pricing
📊 Global score
🤖 AI-enriched data
Gratuit : 0 $/mois jusqu'à 1000 utilisateurs (découverte d'apps fantômes, détection de phishing). Foundations et Advanced : tarif sur devis, adoption modulaire sans bundle imposé.
Pros
Couvre à la fois la sécurité SaaS classique (SSPM) et la gouvernance des agents IA dans une seule plateforme
Certifications SOC 2, ISO 27001, ISO 27018, ISO 42001 — sérieux niveau conformité
Intégrations natives avec les principales plateformes IA (Bedrock, Azure AI Foundry, Claude, OpenAI, Vertex AI)
192% de ROI sur 3 ans et 6 mois de retour sur investissement selon une étude Forrester TEI
Cons
Tarification non publique au-delà du plan gratuit — nécessite un cycle de vente pour connaître le vrai coût
Plan gratuit limité à 1000 utilisateurs, insuffisant pour la plupart des moyennes/grandes entreprises
Positionnement très orienté grand compte (Fortune 500), moins pertinent pour une petite équipe
