Corma has secured $60 million in seed funding, led by Sequoia Capital, with participation from Khosla Ventures and Coatue. The company is developing a foundation model specifically for defensive cybersecurity, aiming to address the growing disparity between offensive and defensive capabilities in AI-driven security.
Corma’s research, conducted in simulated enterprise environments modeled on Fortune 500 organizations and equipped with typical security tools, indicated a significant gap. AI models tasked with attacking these environments succeeded 88% of the time, while the same models, when deployed defensively, detected only 12% of the threats they had introduced.
The company attributes this imbalance to the rapid progress of general-purpose foundation models from providers like OpenAI, Anthropic, and Google in coding and software reasoning. These skills directly translate to offensive security tasks such as vulnerability research and exploit development. In contrast, defensive cybersecurity requires analyzing vast amounts of security data, identifying subtle signals over extended periods, and maintaining consistent decision-making across numerous sequential actions—a different skill set that Corma states current models are not designed to handle effectively.
Corma’s platform is engineered to integrate similarly to a new employee, with its AI agents subsequently operating across a broad spectrum of defensive security functions. The company states that its agents are capable of continuous learning within their deployed environments and can scale according to demand in ways that human teams cannot match.
Since its launch six weeks prior, Corma’s AI workforce has been deployed in Fortune 100 and Fortune 500 organizations across sectors including healthcare, financial services, energy, critical infrastructure, and retail. These initial deployments have reportedly reduced threat response times by over 94%, expanded security coverage fifteen-fold across various functions, and identified multi-stage attack campaigns that might have otherwise gone undetected.
Alon Pluda, Co-founder and CEO of Corma, commented on the situation, stating, “The race to general intelligence in cybersecurity has already begun, and the attackers have a significant head start. AI-powered attacks are operating at a speed and sophistication that neither human teams, better tooling, nor general-purpose AI can match. It requires a complete AI-powered defensive workforce, built from the ground up for cybersecurity, that gives defenders the same speed, sophistication, and generalization that AI has already given attackers. Corma’s mission is to make sure the defenders win this race – and every challenge that comes next.”