Cantina’s $8m bet on agentic security remediation

Cantina

Cantina has emerged from stealth with $8m in fresh funding as it looks to help organisations close the widening gap between finding vulnerabilities and actually fixing them.

The round was led by Framework Ventures and lifts the company’s overall funding to $16.5m. Cantina’s platform is designed to let organisations discover, rank and resolve security issues at machine speed, moving faster than attackers who are increasingly armed with AI.

The company was established by experienced security researchers and engineers with long track records of hunting vulnerabilities and protecting critical software systems. Their experience showed them how AI was making attacks quicker and more sophisticated, leaving defenders struggling to match the tempo.

Its customer base now spans healthcare, FinTech and other regulated sectors, ranging from mid-market firms through to Fortune 500 enterprises. Cantina also holds trusted access with OpenAI and takes part in Anthropic’s Cyber Verification Program, granting it early insight into the model capabilities transforming both offence and defence.

The urgency behind the launch is clear from the data. The 2026 Verizon Data Breach Investigations Report found that vulnerability exploitation had surpassed stolen credentials as the top breach entry point for the first time in the report’s 19 years.

Despite this, just 26% of critical known-exploited vulnerabilities were fully fixed last year, a fall from 38%, while half of ransomware victims had credential exposure flagged before being hit. In short, organisations often know where their weaknesses lie but cannot act on them before adversaries strike.

Compounding the issue, most security teams still lean on manual workflows to assign ownership, judge risk, coordinate fixes and confirm resolution, with thousands of teams duplicating the same investigations rather than sharing lessons learned.

Cantina’s answer is what it describes as the first autonomous security workforce. Customers can deploy ready-made agents, build their own, or draw on proven agents contributed by other users of the platform. The system constructs a living map of each customer’s environment, connecting entities such as Okta users, servers, GitHub repositories, AWS IAM roles and databases containing customer PII, and overlays business context including system ownership, recent changes and prior investigation findings.

That context allows it to flag which problems require urgent attention while giving teams a single, up-to-date view of risk, and each investigation makes the platform sharper over time.

Its capabilities span a Security Memory Layer that maintains a dynamic digital twin of the organisation’s cybersecurity, technology and compliance estate; risk prioritisation that ranks issues by business impact; autonomous remediation of investigation and coordination workflows; and verified resolution with auditable evidence that fixes have landed.

Cantina CEO and co-founder Hari Mulackal said, “AI has dramatically accelerated the pace of attack. Attackers can identify vulnerabilities, understand systems, and build exploits faster than ever before. Security teams cannot keep responding with workflows built for a pre-AI world. Defenders need AI that doesn’t just identify problems, but helps investigate them, coordinate remediation, validate fixes, and continuously gets smarter with every issue it resolves.”

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2018 RegTech Analyst

Investors

The following investor(s) were tagged in this article.