Empirical Security has raised $25 million in Series A funding to expand its predictive cybersecurity platform for exposure and vulnerability management. Brightmind Partners led the round, bringing the company’s total funding to $37 million following earlier backing from Costanoa Ventures, Hyde Park Angels and other investors.
The Chicago-based company plans to use the new capital to accelerate the development and deployment of its Foundation and Radiant products. Empirical Security builds AI and machine learning models intended to help organizations identify which software vulnerabilities are most likely to be exploited within their specific environments.
Foundation is a global predictive model that monitors more than 18,000 exploited Common Vulnerabilities and Exposures, or CVEs. It is designed to help security teams understand broader exploitation trends and distinguish active threats from vulnerabilities that present less immediate risk.
Radiant is a customized predictive engine developed and fine-tuned for each customer. The product combines threat intelligence with information about the organization’s technology environment, risk thresholds and security priorities to identify the exposures most relevant to that business.
Empirical Security is targeting a challenge faced by companies managing large volumes of vulnerabilities with limited security personnel. Traditional exposure management tools often use generalized scores that may not account for how attackers behave or whether a vulnerability is likely to be exploited in a particular environment.
The company’s models are intended to provide more localized and evidence-based risk forecasts. This can help security teams prioritize remediation work, explain their decisions to executives and reduce the time spent addressing vulnerabilities that are unlikely to create meaningful exposure.
Empirical Security expects demand for predictive vulnerability intelligence to increase as artificial intelligence allows attackers to identify and exploit weaknesses more quickly. The company primarily works with enterprises in technology, healthcare and financial services, where security teams must manage sensitive systems and large attack surfaces.
The company is led by CEO Ed Bellis, CTO Michael Roytman and Chief Data Scientist Jay Jacobs. The founders previously worked together on risk-based vulnerability management and predictive security technologies.
Bellis co-founded Kenna Security and served as its chief technology officer through the company’s acquisition by Cisco. Roytman previously served as Kenna Security’s chief data scientist, while Jacobs co-created the Exploit Prediction Scoring System.
The Exploit Prediction Scoring System, commonly known as EPSS, estimates the likelihood that a software vulnerability will be exploited. Its scores are published daily and are available for public use, with the model embedded in products from companies including Tenable, Qualys, CrowdStrike, Microsoft and Wiz.
Empirical Security said vulnerability exploitation is becoming an increasingly important path into corporate networks. The company cited Verizon’s 2026 Data Breach Investigations Report, which found that vulnerability exploitation had surpassed stolen credentials as the leading initial access method for data breaches.
According to the report, exploited software vulnerabilities were involved in 31% of confirmed breaches, up from 20% during the previous year. Empirical Security contributed analysis to the report and believes the findings reinforce the need for organizations to move beyond static vulnerability rankings.
Brightmind Partners said the company’s founding team combines experience building established cybersecurity platforms with a new approach to exposure management. Empirical Security plans to use the financing to bring its products to more enterprise customers while continuing to improve its predictive models.
KEY QUOTES:
“I had unfinished business from my time building and selling Kenna Security. We helped pioneer the category of risk-based vulnerability management, but it became clear that defending against AI-driven threats and the growing volume of potential exploits would require a fundamentally new approach.”
“Today, we finally have the technology to give security teams predictive capabilities that weren’t possible before, and we came together to build that future.”
Ed Bellis, Co-Founder and CEO of Empirical Security
“Brightmind wants to work with visionary founders solving old problems with a generationally new approach. Ed, Michael, and Jay checked all those boxes, and we’re excited to accelerate Empirical Security’s journey to market at a time when their prospects and customers are faced with the biggest crisis in the history of exposure management.”
Stephen Ward, Founder and General Partner of Brightmind Partners

