A startup that emerged from stealth mode on Monday with $60 million in seed funding is betting that the future of cybersecurity defense requires an entirely new kind of artificial intelligence — one built from the ground up for the specific purpose of stopping attacks, not simply generating text or images.
Corma, headquartered in Tel Aviv and San Francisco, has raised $60 million from Sequoia Capital, Khosla Ventures, and Coatue to develop what it describes as a foundation model engineered exclusively for defensive cybersecurity operations. The company, founded in 2025 by CEO Alon Pluda, aims to close a widening gap between the speed and sophistication of AI-powered attacks and the defensive tools currently available to security teams.
The core proposition is straightforward but technically ambitious: instead of adapting general-purpose large language models or machine learning tools to cybersecurity tasks, Corma is building a model from scratch on security-specific data. That data includes system events, audit logs, network traffic, and other forms of security telemetry — the raw material that security operations centers generate in vast quantities every day but often struggle to analyze at scale.
What Makes Corma’s Foundation Model Different From General-Purpose AI
General-purpose AI models, such as those developed by OpenAI, Anthropic, and Google, are trained on enormous corpora of text, images, and code drawn from the open internet. They are designed to handle a wide range of tasks — answering questions, writing essays, generating code, analyzing images. When applied to cybersecurity, they often require fine-tuning, prompt engineering, and integration with specialized tools to perform even basic defensive functions.
Corma takes a fundamentally different approach. Its foundation model is trained exclusively on security-specific data, which means it learns the patterns, anomalies, and behaviors that are relevant to cybersecurity without the noise of general internet content. The model processes large datasets of security telemetry — system events, audit logs, network traffic — and connects subtle indicators of anomalous activity over extended timeframes. This temporal analysis is critical because sophisticated attacks, particularly multi-stage intrusions, often unfold over days or weeks, with individual events appearing innocuous in isolation.
The architecture supports automated agents that integrate directly into an organization’s existing security infrastructure. These agents operate alongside human security staff, handling a range of defensive duties while continuously adapting to the specific enterprise environments they are deployed in. Through this ongoing environmental learning, the agents can detect and neutralize threats, including complex multi-stage intrusions that might evade traditional rule-based detection systems.
The Defensive AI Gap That Corma Aims to Close
One of the most striking claims from Corma involves a direct comparison with models from OpenAI and Anthropic. In tests conducted by the company, AI models from these leading general-purpose AI developers were capable of conducting end-to-end attacks — meaning they could autonomously plan and execute offensive cybersecurity operations. However, when tasked with defending against the same types of attacks, these same models failed.
This asymmetry is at the heart of the problem Corma is trying to solve. Attackers are already using AI to automate reconnaissance, identify vulnerabilities, craft convincing phishing campaigns, and even execute multi-step intrusion chains at machine speed. Defenders, by contrast, are largely still using tools designed for a pre-AI era — rules engines, signature-based detection, and manually curated threat intelligence — augmented with general-purpose AI that was never designed for defensive operations.
Corma CEO Alon Plude framed the challenge directly: “AI-powered attacks are operating at a speed and sophistication that neither human teams, better tooling, nor general-purpose AI can match. It requires a complete AI-powered defensive workforce, built from the ground up for cybersecurity, that gives defenders the same speed, sophistication, and generalization that AI has already given attackers.”
Plude’s use of the term “workforce” is deliberate. The company envisions a future in which AI agents handle the majority of defensive cybersecurity tasks autonomously, with human security professionals focusing on strategy, investigation, and decision-making for the most critical incidents. This is a significant departure from the current model, where AI tools are typically used to augment human analysts rather than operate alongside them as semi-autonomous agents.
How Corma’s Agents Learn and Adapt to Enterprise Environments
The environmental learning capability is one of the most technically distinctive features of Corma’s approach. When deployed into an organization, the agents do not operate from a fixed set of rules or a static model. Instead, they continuously observe the normal patterns of activity within that specific environment — the typical network traffic flows, the usual sequence of system events, the normal behavior of users and applications — and build a baseline of expected behavior.
This baseline is not static. As the organization changes — new applications are deployed, users join and leave, network configurations are modified — the agents update their understanding of what constitutes normal activity. This adaptability is critical because one of the fundamental challenges in cybersecurity is that every organization’s environment is different, and static detection rules that work in one context may generate excessive false positives or miss relevant threats in another.
When the agents detect activity that deviates from the expected baseline, they can investigate further, correlate the anomaly with other events that may have occurred over a longer time period, and determine whether the activity represents a genuine threat. If it does, the agents can take defensive actions — blocking network connections, isolating affected systems, alerting human analysts — without waiting for manual intervention.
This kind of autonomous defensive response is particularly important for multi-stage intrusions, where an attacker may perform a series of seemingly unrelated actions over an extended period before executing the final stage of the attack. Traditional detection tools, which typically look for individual indicators of compromise, often miss these distributed patterns. By connecting subtle anomaly indicators over extended timeframes, Corma’s model aims to detect attacks that would otherwise go unnoticed until it is too late.
What the $60 Million Seed Round Signals for the Cybersecurity AI Market
The size of Corma’s seed round is notable. A $60 million seed investment — from three of the most prominent venture capital firms in the technology industry — signals strong conviction that the defensive cybersecurity AI market is large enough and strategically important enough to support a dedicated foundation model company. Sequoia Capital, Khosla Ventures, and Coatue collectively represent some of the most sophisticated technology investors in the world, and their willingness to back Corma at this stage suggests they see a significant market opportunity.
The investment also reflects a broader trend in the cybersecurity industry: the recognition that AI is transforming both offense and defense, and that the defensive side needs its own specialized infrastructure. Over the past year, a growing number of cybersecurity companies have raised substantial funding rounds to develop AI-powered solutions. Oligo raised $60 million for runtime security. Obsidian Security raised $85 million at a $1.1 billion valuation. Zenity raised $125 million in Series C funding. Horizon3 raised $250 million to fund continuing growth.
What distinguishes Corma from these companies is its focus on building a foundation model specifically for defensive cybersecurity, rather than developing a narrower product or application. The company’s ambition is to create a platform that can be applied across a wide range of defensive use cases, from threat detection and incident response to vulnerability management and security operations automation.
This platform approach is reminiscent of the strategy that some of the largest AI companies have pursued in other domains. OpenAI, Anthropic, and Google have all built general-purpose foundation models that can be adapted to a wide range of applications through fine-tuning, prompt engineering, and API integration. Corma is essentially applying the same strategy to the specific domain of defensive cybersecurity, building a foundation model that can be adapted to the specific needs of different organizations and use cases.
Why General-Purpose AI Models Fall Short in Defensive Cybersecurity
The failure of general-purpose AI models to defend against attacks that they themselves can execute is not surprising to cybersecurity professionals, but it highlights a fundamental limitation of these models that is often overlooked. General-purpose models are designed to be broadly capable, but they lack the specialized training, architecture, and tuning that defensive cybersecurity requires.
Defensive cybersecurity is fundamentally about detecting and responding to adversarial behavior in complex, dynamic environments. This requires an understanding of how attackers think, how they operate, and how they adapt. It also requires the ability to process large volumes of security-specific data in real time, to distinguish genuine threats from false positives, and to take appropriate defensive actions without causing collateral damage.
General-purpose models, trained primarily on text and images from the internet, do not naturally possess these capabilities. They can be fine-tuned for specific cybersecurity tasks, but this fine-tuning is often shallow — it adapts the model to the surface characteristics of the task without giving it the deep understanding of security operations that a purpose-built model could achieve.
Moreover, the data that general-purpose models are trained on includes vast amounts of information about cybersecurity — blog posts, research papers, forum discussions, threat reports — but it also includes enormous amounts of irrelevant or misleading information. A general-purpose model trained on the entire internet will learn patterns from cooking recipes, celebrity gossip, and sports news alongside patterns from cybersecurity data. A purpose-built model trained exclusively on security telemetry and threat intelligence will have a much higher signal-to-noise ratio for defensive tasks.
Corma’s approach addresses both of these limitations. By training its model exclusively on security-specific data, it ensures that every parameter of the model is optimized for cybersecurity tasks. And by designing the model’s architecture specifically for the temporal, multi-modal nature of security telemetry, it enables the kind of cross-timeframe analysis that is essential for detecting multi-stage intrusions.
The Bird’s-Eye View: A New Category of Cybersecurity Technology
The emergence of companies like Corma represents a potential inflection point in the cybersecurity industry. For most of the past two decades, cybersecurity has been a reactive discipline. Organizations deploy firewalls, antivirus software, intrusion detection systems, and security information and event management platforms, but these tools are largely designed to detect known threats based on signatures, rules, and patterns that have been observed before.
The shift to AI-powered defense has been underway for several years, but it has largely been incremental — adding machine learning capabilities to existing tools, using AI to augment human analysts, and deploying chatbots to answer security questions. Corma’s vision is more radical: replace the entire stack of defensive security tools with AI-native agents that can learn, adapt, and respond autonomously.
Whether this vision succeeds depends on several factors. The company must demonstrate that its foundation model can reliably detect and neutralize threats in real-world enterprise environments, not just in controlled tests. It must convince organizations to trust AI agents with critical defensive decisions, which requires building confidence in the agents’ reliability, transparency, and safety. And it must navigate a competitive landscape that includes both established cybersecurity vendors investing heavily in AI and well-funded startups pursuing similar goals.
But the sheer size of the seed round, the caliber of the investors, and the clarity of the technical vision suggest that Corma is a company worth watching. If it succeeds, it could fundamentally change how organizations think about cybersecurity defense — shifting from a model of tool-augmented human defenders to a model of AI-native defensive workforces operating alongside human strategists.
What Organizations Should Know About AI-Native Defensive Security
For security leaders evaluating whether AI-native defensive platforms like Corma are right for their organizations, several considerations are important. First, the technology is still early. Corma emerged from stealth mode in 2025, and while the seed funding provides substantial resources for development, the company has not yet published detailed technical specifications or independent validation of its claims.
Second, the integration requirements are significant. Corma’s agents need deep access to an organization’s security telemetry — system events, audit logs, network traffic — to build their baselines and detect anomalies. This means the organization must have the data collection infrastructure in place to feed the agents, and must be willing to grant the agents the access they need to take defensive actions.
Third, the human factors are critical. Even with autonomous AI agents handling the bulk of defensive operations, human security professionals will remain essential for strategic decision-making, incident response coordination, and oversight of the AI systems. Organizations adopting AI-native defense will need to invest in training and upskilling their security teams to work effectively alongside AI agents.
Fourth, the security of the AI system itself is paramount. A defensive AI model that is compromised by an attacker could be turned into a powerful offensive tool, capable of manipulating telemetry, hiding malicious activity, or even launching attacks against the organization it is supposed to protect. Corma will need to demonstrate that its model is resilient to adversarial manipulation and that its agents operate within robust security boundaries.
Despite these caveats, the direction that Corma represents is almost certainly where cybersecurity defense is heading. The speed and sophistication of AI-powered attacks are increasing rapidly, and traditional defensive approaches are struggling to keep pace. An AI-native defensive workforce that can learn, adapt, and respond at machine speed may not just be an advantage — it may become a necessity for organizations that want to stay ahead of the threat landscape.
Corma’s $60 million seed round, backed by Sequoia Capital, Khosla Ventures, and Coatue, provides the funding and credibility to pursue this ambitious vision. The company’s emergence from stealth marks the beginning of what could be a new chapter in cybersecurity — one in which defenders finally have AI tools that match the speed, sophistication, and generalization that attackers have already harnessed. The race between offensive and defensive AI is accelerating, and with Corma’s entry, the defensive side has a new contender.