Somewhere in the last few days, a venture capital term sheet did something the public stock market hasn’t: it put a number on how urgently companies need to know what their own data is doing.
A four-year-old private startup called Cyera is reportedly in talks to raise new funding at a $12 billion valuation. Sacra estimates Cyera’s annual recurring revenue at roughly $150 million. That works out to close to 80 times revenue — a number that would make even the giddiest 2021 SaaS multiple blush.
Nobody’s writing “AI infrastructure” headlines about this. The chips, the power plants, the data centers — that’s the story everyone already knows how to tell. This is the quieter layer underneath it: once a company plugs an AI agent or a Copilot into its email, its file servers, its cloud storage, something has to know exactly what sensitive data that agent can now touch, and stop it from wandering somewhere it shouldn’t. That job has a name — data security posture management, or DSPM — and in the last two years it’s gone from a niche compliance checkbox to one of the fastest-growing line items in enterprise security budgets.
Here’s the part that doesn’t add up cleanly. Enterprises adopting AI agents didn’t just create a problem for four-year-old startups to solve. They created it for whoever already had a decade of infrastructure mapping who can see what, inside nearly every major company’s Microsoft 365 tenant, Salesforce instance, and file server. That kind of institutional depth is hard to build from scratch, and expensive to buy your way past.
Private markets have apparently decided that depth is worth chasing at almost any price. Public markets, so far, have decided something very different about the company that already has it.
That gap — what venture capital is paying for the promise of this category versus what public investors are paying for a company already living inside it — is where this story gets interesting.


