Internal raises $5M seed round from David Sacks' Craft Ventures to help companies deploy consoles to manage employee access to sensitive customer data
Context & Ripple Effects
Internal's seed arrives at the start of what became a sustained venture lane around controlling who touches customer data: within months, Very Good Security pulled a $43.5M-total Series B for protecting customers' data, showing investors were already paying up in the adjacent category.
Six years on, the same problem has scaled with the workforce it governs — Cyberhaven raised a $100M Series D at a $1B+ valuation for detecting unauthorized employee data use, and Keycard just raised seed and Series A rounds for managing AI-agent access to internal systems. For Craft Ventures, the check lands while the firm is reportedly targeting about $1 billion for a new fund.
First-order effects
- Internal gains $5M to productize its consoles for governing employee access to sensitive customer data, entering a market where Very Good Security is already raising growth-stage capital.
- Craft Ventures adds an early enterprise-access position to its portfolio while reportedly courting roughly $1B for its next fund.
Second-order effects
- Companies selling customer-data protection and internal-tooling infrastructure — Very Good Security, Cortex's internal developer portal business — face a funded rival converging on the same buyer: teams securing internal systems at scale.
- As later rounds show (Cyberhaven's $100M Series D, Keycard's paired seed and Series A), pricing power in this niche shifts toward whoever can govern not just humans but automated actors touching company systems.
Third-order effects
- If the pattern holds, access management evolves from employee-permission consoles into agent-identity infrastructure — Keycard's AI-agent focus suggests the buying category Internal seeded now extends to non-human principals.
- Sustained large rounds across Cyberhaven, Console's IT-ticket automation, and Keycard indicate identity-and-access governance is consolidating into a durable enterprise software layer rather than a point solution.
The trend: Access-control startups are riding a funding arc that stretches the definition of 'user' from employees to AI agents, turning internal permissioning into core enterprise infrastructure.