Corma emerged from stealth on August 10, 2026 with $60 million in seed funding to build the first foundation model designed specifically for defending enterprise systems. The round was led by Sequoia Capital, with Khosla Ventures and Coatue participating. The announcement landed alongside a statistic that frames the entire investment thesis: in hundreds of simulations run across enterprise environments modeled on Fortune 500 networks, leading AI models succeeded in cyberattacks 88% of the time and detected threats when acting as defenders just 12% of the time.

That gap is the company Corma was built to close.

The Asymmetry Driving $60 Million in Seed Funding

General-purpose AI models have become significantly more capable at code reasoning over the past two years. They can write and refine software, identify vulnerabilities, reason through complex environments, and orchestrate tools across multi-step workflows. Those exact capabilities map directly to offensive security. Vulnerability research and exploit development are, at their core, code-reasoning problems executed against bounded targets. When combined with agentic execution, these models move from assisting attackers to autonomously carrying out full attack chains.

The implication is that the attacker population just scaled. Any organization with access to frontier AI APIs can run sophisticated, automated offensive operations at a fraction of the previous cost. The defenders, however, have no equivalent. Security teams are still largely staffed by humans using tools that were built before AI fundamentally changed what an attacker looks like.

Corma makes the case that defensive cybersecurity requires capabilities that general-purpose models are structurally poor at. Attacking a system is a code-reasoning problem. Defending one requires processing vast quantities of security telemetry, including audit logs, events, and network traffic flows, correlating weak signals across long time horizons, and maintaining extreme consistency across thousands of decisions in sequence. A model that excels at generating code does not automatically excel at those tasks. Corma’s simulation results demonstrate the gap with numbers that are hard to argue with.

How Corma Builds the Defensive Model

Corma’s training approach draws on large-scale reinforcement learning across cybersecurity environments that replicate real enterprise networks, complete with the dozens of security tools and telemetry sources a large organization typically runs. The environments are modeled after Fortune 500 networks, including the noise, complexity, and tool fragmentation that characterizes real enterprise security operations.

The training signal is clean: was the defender breached or not? That structure, a two-player, zero-sum game with a clear reward, is the same environment in which reinforcement learning and self-play have produced superhuman results in Go and chess. Corma is applying that paradigm to cybersecurity defense.

The result, according to the company and the Sequoia investment thesis published simultaneously, is a model that outperforms general-purpose frontier models on defensive cybersecurity tasks by a significant margin while also costing far less per inference. Because Corma owns the model weights, the system is also not subject to the usage restrictions that closed model labs impose on security-related applications, a practical constraint that enterprise security teams increasingly encounter when trying to use GPT-5.6 or Claude for sensitive security work.

The model can be deployed fully on-premises for organizations with sovereign data requirements, an important capability for the defense, healthcare, and critical infrastructure sectors Corma is already serving.

The Security Workforce Model

Corma does not position its product as software that replaces the security stack. It positions agents as additions to the security team. Organizations onboard a Corma agent roughly the way they would a new hire: the agent learns the environment, integrates with the tools already in place, and takes on defined security functions.

That framing has a practical advantage. It avoids the rip-and-replace sales motion that slows enterprise security adoption. Corma agents work across whatever tools an organization already runs, from SIEM and EDR platforms to cloud security posture management and identity systems. The agents handle specific roles within the security organization rather than requiring a full technology migration.

Sequoia partner Shaun Maguire described a specific deployment in the Sequoia investment announcement: a CISO was notified of a pending attack through his Garmin watch while walking his dog. With one confirmation, the agent shut the attacker down. In another deployment, a Corma agent identified, contained, and remediated an active attacker campaign that the customer’s security team had missed for 52 days.

Early performance metrics from the company’s launch deployments show threat response time reductions exceeding 94% and security coverage expansions of 15-fold across different functions. Both figures reflect the core structural advantage of always-on AI agents over shift-based human security teams.

Who Built Corma

Corma founder and CEO Alon Pluda leads a team that combines two distinct expertise areas: AI researchers from Google DeepMind and cybersecurity experts from Israel’s Unit 8200, the military intelligence unit that has produced a significant share of the global cybersecurity industry’s most accomplished practitioners.

That combination is the organizational design Sequoia’s investment thesis calls “vertical integration.” Building a foundation model for a specific domain requires people who understand both the model training pipeline and the domain well enough to define what the model actually needs to do. Generalist AI researchers often lack the security domain knowledge to design meaningful defensive training environments. Generalist security researchers often lack the model training knowledge to build a frontier-scale system. Corma is betting that the combination is the moat.

The company is headquartered in Tel Aviv and San Francisco and was founded in 2025. Corma has not disclosed its current headcount.

What This Means for Enterprise AI and Security Leaders

Corma’s emergence fits a pattern that has defined the enterprise AI security category through mid-2026. Zenity raised $125M in early August to govern AI agent behavior at the action level. Obsidian Security raised $85M to address non-human identity risk from AI agents. Hush Security raised $30M to build just-in-time permission infrastructure for AI agents.

Corma is a different layer. The others govern what agents are allowed to do within the enterprise. Corma is trying to build the AI that defends the enterprise against AI-powered attacks coming from outside it. Together, those investments describe an emerging security stack architecture that no organization has fully implemented today, and that most will need within the next two to three years.

LayerCompanyFocus
External defenseCormaDetecting and stopping AI-powered attacks
Agent runtime securityObsidian SecurityNon-human identity and agent access control
Agent behavior governanceZenityIntent-aware pre-execution control
Agent permissionsHush SecurityJust-in-time credential scoping

The practical question for enterprise security leaders is sequencing. Most organizations are still figuring out how many AI agents they are running and what credentials those agents hold. Implementing a governance stack across all four layers simultaneously is not realistic. What is realistic is treating Corma’s simulation result, 88% attack success, 12% defense detection, as a benchmark for how equipped general-purpose AI currently is to protect enterprise environments.

The implication is that the current tooling, including SIEM platforms supplemented by general-purpose AI models, is likely operating at a structural disadvantage against an attacker using purpose-built offensive AI. That gap will widen as offensive AI capabilities improve.

Enterprises building or scaling AI agent deployments can assess current security posture and discuss where the highest-priority gaps are at /book-a-call.

The Broader Signal

Corma raising $60 million at the seed stage, an unusual amount for a company six weeks old, reflects both the caliber of the Sequoia-Khosla-Coatue syndicate and the urgency of the problem they are backing. Seed rounds at that size typically accompany either extraordinary early traction or a market dislocation large enough that experienced investors are willing to fund the infrastructure before the market fully realizes it needs to exist.

In this case, both conditions appear to hold. Corma has Fortune 100 deployments in production. It also has a market that is, as Vinod Khosla framed it, facing attacks that now threaten critical infrastructure and health systems rather than just data and money. The scale of potential harm, combined with the structural inadequacy of general-purpose AI for defense, is the thesis that $60 million at seed stage is intended to solve.

Whether Corma’s foundation model delivers on that thesis at production scale will become clear as deployments expand. The enterprise security market now has a publicly funded contender specifically focused on using AI’s own training dynamics to close the gap AI has opened in offense.