Corma Raises $60M for Defensive Cybersecurity AI

Corma launched on August 10, 2026, with a $60 million seed round to build a foundation model for defensive cybersecurity. Sequoia Capital led the round, with Khosla Ventures and Coatue participating, according to VentureBurn and The Next Web. Corma reports that early enterprise deployments reduced threat-response times by more than 94%, a company-reported result that has not been independently benchmarked in the cited coverage.
Corma has raised $60 million in seed funding to develop a foundation model and autonomous agents for defensive cybersecurity, according to SiliconANGLE, Fortune, VentureBurn, and The Next Web. VentureBurn and The Next Web report that Sequoia Capital led the round, with participation from Khosla Ventures and Coatue.
Founded in 2025, Corma operates from Tel Aviv and San Francisco. SiliconANGLE reports that the startup is building its technology around defensive security work: processing audit logs, security events, and network flows; correlating weak signals over time; and carrying out response decisions through agents integrated with existing security tools.
Corma CEO and co-founder Alon Pluda told SiliconANGLE, "The race to general intelligence in cybersecurity has already begun, and the attackers have a significant head start." In a separate quote reported by The Next Web from Calcalist, Pluda described the offering as "virtual human resources," rather than a conventional product.
Corma's reported attacker-defender gap
SiliconANGLE and The Next Web report that Corma ran hundreds of simulations modeled on Fortune 500-style enterprise environments containing dozens of security tools. The company first tasked leading models from OpenAI and Anthropic with attacking the simulated networks and planting persistent threats, then asked the same models to identify and remove those threats.
According to Corma's reported simulation results, AI attackers succeeded in 88% of cases, while defenders detected threats in 12%. These are company-run tests rather than an independently published benchmark, so the cited reports do not establish how the results generalize across models, enterprise telemetry stacks, or operational security workflows.
The reported distinction is technically material. Offensive tasks can often center on code understanding, vulnerability discovery, and exploit development. Defensive operations also require long-horizon correlation across endpoint, identity, cloud, network, and application data, together with evidence preservation and controls around automated response. In comparable security-automation deployments, evaluation typically depends on false-positive rates, time to containment, analyst override behavior, and the safety of actions taken against production systems, not detection rates alone.
Enterprise deployments and research hiring
SiliconANGLE reports that Corma began deployments six weeks before the announcement and that its agents are running at Fortune 100 and Fortune 500 organizations in healthcare, financial services, energy, critical infrastructure, and retail. The company reports that early customers reduced threat-response times by more than 94% and expanded security coverage by 15x, according to SiliconANGLE and The Next Web. Those performance figures are self-reported in the cited coverage.
VentureBurn reports that Corma intends to use the funding to expand its interdisciplinary research team and invest in pre-training, post-training, and cybersecurity research. The Next Web describes the team as including frontier AI researchers from Google and DeepMind alongside cybersecurity specialists from Israel's Unit 8200.
For ML and security practitioners, the startup's premise reflects an increasingly important technical question: whether general-purpose models can reliably operate over enterprise security telemetry, or whether security-specific training, tools, and evaluation environments produce meaningfully better defensive behavior. Public evidence of reproducible benchmarks, deployment guardrails, and independently validated operational outcomes would be important measures for assessing systems built around that premise.
Key Points
- 1Corma raised $60 million to develop cybersecurity-specific defensive models and agents, placing a large seed bet on security automation.
- 2Corma's simulations reported 88% attacker success versus 12% defender detection, but the company-run tests lack independent validation in cited coverage.
- 3Security-agent evaluation commonly requires telemetry integration, constrained response actions, and operational metrics beyond detection performance alone.
Scoring Rationale
A $60 million seed round led by Sequoia is a notable financing event for an AI-native cybersecurity startup. The story is especially relevant to practitioners working on security agents and domain-specific model evaluation, although the reported deployment and simulation performance has not been independently validated in the cited coverage.
Sources
Public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems
