Key Takeaways

  • Corma emerged from stealth with a $60 million seed round led by Sequoia Capital, with participation from Khosla Ventures and Coatue.
  • The startup is developing AI models for defensive security work such as analyzing logs, reviewing audits, and coordinating investigations.
  • Corma reported its first model is already deployed at Fortune 100 and Fortune 500 organizations, significantly reducing threat response times.

Corma has emerged from stealth with one of the larger seed rounds in cybersecurity, securing $60 million to develop AI models designed specifically for defense. Sequoia Capital led the financing, while Khosla Ventures and Coatue also participated. Corma did not disclose its valuation.

The funding reflects a widening race to give security teams AI systems capable of operating closer to machine speed. Attackers can use broadly available models to automate research, refine malicious code, identify vulnerabilities, and coordinate multistage campaigns. Human analysts, meanwhile, still spend significant time collecting evidence, reviewing alerts, and moving between security products.

Corma, founded in 2025, operates from Tel Aviv and San Francisco. According to Fortune, the startup recently deployed its first model at Fortune 100 and Fortune 500 organizations spanning healthcare, financial services, energy, critical infrastructure, and retail. That early enterprise adoption gives Corma a useful proving ground, although the company has not identified the specific customers.

The company's chief executive argues that general-purpose models from OpenAI, Anthropic, and Google possess capabilities that map naturally to offensive security. They can write and revise code, find software bugs, and reason through a sequence of technical steps. Corma is taking a different route, training its models around defensive tasks that often involve interpreting logs, examining audits, recognizing anomalies, and applying a consistent investigative method across thousands of actions.

Writing code is only one part of security operations. A large share of defensive work is contextual. Analysts need to determine whether an unusual login matters, connect activity across systems, understand which assets are exposed, and decide what should happen next. That makes reliability and traceability at least as important as raw model capability.

Corma reported that its model has significantly reduced threat response times among adopting organizations. Although the company has not disclosed the specific methodology, baseline response times, or number of deployments behind the claim, response time remains a practical metric for prospective buyers. A model that produces convincing summaries but does not shorten investigation and containment cycles may add another interface rather than concrete operational capacity.

The startup enters a crowded market. Microsoft Security Copilot, CrowdStrike, and Palo Alto Networks are all incorporating generative or agentic AI into security operations. Corma’s wager is that a foundation model trained primarily for defensive cybersecurity can provide deeper investigative capability than an assistant layered onto an established product portfolio. Can that specialization outweigh the distribution, telemetry, and customer relationships held by larger vendors? That is likely to become the central commercial test.

Coverage from Calcalistech and a company profile from StartupHub.ai place Corma within a broader cluster of AI-native security startups seeking to automate more of the analyst workflow. The distinction between a copilot and an autonomous defensive agent matters here. Copilots typically recommend or summarize. Agents may investigate, prioritize, and initiate actions, which raises tougher questions about permissions, audit trails, false positives, and human approval.

Governance will therefore matter alongside performance. Enterprise customers will want evidence showing how Corma handles sensitive telemetry, limits model access, records decisions, and responds when evidence is incomplete. Frameworks such as NIST AI RMF 1.0 and NIST Cybersecurity Framework 2.0 offer useful reference points, particularly around governing risk and measuring system behavior.

Corma will use the financing to expand the data and training behind its models and hire across defensive security, AI, and research. The capital provides room to pursue an ambitious technical agenda. It also increases the pressure to demonstrate that specialized defensive models can move beyond impressive pilots and become dependable infrastructure inside high-stakes security operations.