Corma has raised $60 million in seed funding to build a foundation model specifically for defensive cybersecurity, targeting a widening gap between rapidly advancing AI-powered attacks and the ability of existing security systems to detect and stop them. Sequoia Capital led the financing, with participation from Khosla Ventures and Coatue.
Founded in 2025, Corma describes itself as a frontier AI lab focused exclusively on defensive cybersecurity. The company operates from Tel Aviv and San Francisco and is already working with Fortune 100 and Fortune 500 organizations.
Corma’s central thesis is that advances in general-purpose AI have disproportionately benefited attackers.
Frontier models have become increasingly capable at coding, software reasoning, vulnerability research and multi-step tool use, capabilities that can also be applied to identifying vulnerabilities and carrying out cyberattacks.
But Corma argues that defending large enterprise environments presents a fundamentally different AI challenge.
Defensive systems must analyze enormous quantities of audit logs, security events, network flows, and other information, correlate weak signals over extended periods, and maintain consistent reasoning across thousands of decisions.
Corma conducted hundreds of simulations using realistic enterprise environments modeled after Fortune 500 organizations and incorporating the dozens of security tools commonly deployed by large companies.
Leading AI models, including systems from OpenAI and Anthropic, were first instructed to act as attackers and establish persistent threats inside the simulated enterprise environments.
The same models were subsequently asked to operate as defenders and identify and remediate the threats they had created.
According to Corma’s research, AI attackers succeeded in 88% of the simulations, while AI defenders detected only 12% of the threats.
The company said that in nearly every case, the same model capable of executing an end-to-end attack could not successfully defend against that attack when operating from the opposite side.
Corma believes that imbalance demonstrates why adapting general-purpose AI models to cybersecurity may not be enough.
Instead, the company is developing what it describes as the first foundation model purpose-built for defensive cybersecurity.
That model powers Corma’s AI agents, which are designed to generalize across a broad range of defensive security functions rather than addressing only a narrow category of alerts or vulnerabilities.
Organizations can deploy the system similarly to onboarding additional security personnel.
Once connected to an environment, Corma’s agents continuously learn about the organization’s systems and can operate across multiple defensive cybersecurity functions.
The company believes that approach can give security organizations an AI-powered workforce capable of operating at a scale that human teams alone cannot realistically match.
Corma said its technology has already been deployed across Fortune 100 and Fortune 500 companies in healthcare, financial services, energy, critical infrastructure, retail and other industries.
Those deployments began only six weeks before the funding announcement.
Corma said early customers have reduced threat response times by more than 94% while expanding security coverage by 15 times across different security functions.
The platform has also identified multi-stage attack campaigns that Corma said would otherwise have remained undetected.
The company is assembling its technology around an interdisciplinary team spanning both advanced AI research and cybersecurity.
Its workforce includes frontier AI researchers with experience at Google and DeepMind alongside cybersecurity specialists from elite groups within Israel’s Unit 8200 and major cybersecurity companies.
Corma believes that combination of expertise in AI pre-training, post-training, offensive security and defensive cybersecurity is necessary to create models capable of handling increasingly autonomous cyber threats.
The new capital gives the company significant resources at an unusually early stage to pursue that goal as AI agents become increasingly capable of performing complex digital tasks without continuous human involvement.
Corma’s investors also see the problem extending beyond traditional enterprise cybersecurity.
As autonomous cyberattacks become more capable and scalable, vulnerabilities involving critical infrastructure, healthcare, energy and essential services could carry physical, economic and national security consequences.
Corma’s broader objective is to give defenders AI systems that can operate with the same speed, sophistication and adaptability increasingly available to attackers.
KEY QUOTES:
“The race to general intelligence in cybersecurity has already begun, and the attackers have a significant head start. AI-powered attacks are operating at a speed and sophistication that neither human teams, better tooling, nor general-purpose AI can match.”
“It requires a complete AI-powered defensive workforce, built from the ground up for cybersecurity, that gives defenders the same speed, sophistication, and generalization that AI has already given attackers. Corma’s mission is to make sure the defenders win this race, and every challenge that comes next.”
Alon Pluda, Co-Founder and CEO of Corma
“Corma has trained its model for the complexity of real-world attacks and is building the intelligence layer defense actually needs. Agentic AI gives attackers a structural speed advantage, but Alon’s hacking talent paired with Corma’s frontier AI research helps companies combat these threats at scale.”
Shaun Maguire, Partner at Sequoia Capital
“AI is reshaping cybersecurity in ways that increasingly extend beyond the enterprise to national security and geopolitical stability.”
“As cyberattacks become more autonomous and scalable, the stakes move beyond data and finances to critical infrastructure, healthcare systems, and essential services where failures can have real-world consequences. That is why we need entirely new approaches to cyber defense and teams like Corma pursuing one of the hardest problems in cybersecurity.”
Vinod Khosla, Founder of Khosla Ventures

