Corma, the cybersecurity FinTech-adjacent AI lab building defensive technology for large enterprises, has raised $60m in seed funding, with the round led by Sequoia Capital and joined by Khosla Ventures and Coatue.
The company, which already counts Fortune 100 clients among its customers, is building what it describes as the first foundation model designed specifically for defensive cybersecurity. Corma’s leadership points to a widening gap between the pace of advances in offensive AI capability and the slower progress made on the defensive side.
According to Corma, general-purpose foundation models from providers including OpenAI, Anthropic and Google have become highly capable at coding and software reasoning tasks in recent years, allowing them to write and fix software, work through complex problems and coordinate multi-step workflows. Corma notes that these same abilities translate readily into offensive security use, since finding and exploiting vulnerabilities is fundamentally a code-reasoning exercise, and when paired with autonomous agent capability, models can carry out complete attack sequences without human involvement.
Defensive cybersecurity work, by contrast, calls for a different skill set entirely, Corma says, centred on parsing huge quantities of security data such as logs, events and network traffic, linking subtle signals together over extended periods, and sustaining accuracy across large numbers of sequential judgement calls.
To illustrate the disparity, Corma built simulated enterprise environments modelled on Fortune 500 companies, each equipped with the range of security tools typically found in large organisations. It then ran numerous tests using leading AI models, including those from OpenAI and Anthropic, first tasking them with planting hidden threats inside the simulated systems, then asking the same models to detect and remove the threats they themselves had created. Corma reports that the outcome was consistent throughout: the models succeeded as attackers 88% of the time, yet managed to detect the threats as defenders only 12% of the time.
Corma’s foundation model underpins its AI agents, which the company says allow it to outperform tools built on other underlying models while covering the full range of defensive security functions. Clients bring Corma’s technology into their organisations in a manner comparable to hiring a new team member, after which its agents can work across most areas of defensive cybersecurity, adapt to their surroundings on an ongoing basis, and scale to handle workloads beyond what human teams could manage alone.
In the six weeks since its launch, Corma’s technology has already been rolled out at Fortune 100 and Fortune 500 organisations spanning healthcare, financial services, energy, critical infrastructure and retail. The company states that these early deployments have cut threat response times by more than 94%, extended security coverage fifteenfold across various security functions, and identified multi-stage attack campaigns that might otherwise have gone unnoticed.
Corma Co-founder and CEO Alon Pluda said, “The race to general intelligence in cybersecurity has already begun, and the attackers have a significant head start. AI-powered attacks are operating at a speed and sophistication that neither human teams, better tooling, nor general-purpose AI can match.
“It requires a complete AI-powered defensive workforce, built from the ground up for cybersecurity, that gives defenders the same speed, sophistication, and generalization that AI has already given attackers. Corma’s mission is to make sure the defenders win this race – and every challenge that comes next.”
Copyright © 2026 RegTech Analyst
Copyright © 2018 RegTech Analyst


