Key Takeaways
- Corma raised a $60 million Seed round led by Sequoia Capital, with Khosla Ventures and Coatue participating.
- Founded in 2025, the Tel Aviv‑ and San Francisco‑based startup employs 20 people in Tel Aviv and already serves Fortune 100 and Fortune 500 clients across healthcare, finance, energy, critical infrastructure, retail, and other sectors.
- Rather than selling a traditional software product, Corma delivers AI‑powered “virtual human resources”—agents that work alongside existing security teams to perform end‑to‑end defensive cyber tasks.
- Early deployments have cut threat‑response times by more than 94 %, expanded security coverage 15‑fold, and revealed multi‑stage attack campaigns that would otherwise remain hidden.
- Internal research shows that general‑purpose foundation models (e.g., GPT, Claude) succeed as attackers in 88 % of simulations but detect only 12 % of the threats they create, highlighting a significant defender‑attacker capability gap.
- Corma is building a proprietary foundation model trained exclusively for defensive cybersecurity, which powers its continuously learning AI agents.
- The team combines AI experts from Google/DeepMind with cybersecurity veterans from Israel’s elite Unit 8200 and leading security firms, giving Corma deep expertise in both foundation‑model training and offensive/defensive operations.
Company Overview and Funding
Corma, a developer of foundation models tailored for defensive cybersecurity, announced a $60 million Seed round in early 2026. The round was led by Sequoia Capital, with notable participation from Khosla Ventures and Coatue. The capital infusion will support product development, talent acquisition, and scaling of its AI‑driven security services. Despite the fresh funding, CEO Alon Pluda indicated that the company is not in a rush to hire aggressively, preferring to first solidify its technology and customer base.
Founding Vision and Leadership
Founded in 2025 by Alon Pluda, who serves as CEO and co‑founder, Corma operates dual headquarters in Tel Aviv and San Francisco. The firm currently employs roughly 20 engineers and researchers in its Tel Aviv office. Pluda’s vision centers on creating AI that augments, rather than replaces, human security analysts. He emphasizes that organizations still rely on large security teams and costly managed services; Corma aims to make those teams far more effective by providing AI agents that handle repetitive, data‑intensive tasks.
Approach: AI Agents as Virtual Workforce
Unlike conventional cybersecurity vendors that sell software licenses or appliances, Corma positions itself as a service provider of “virtual human resources.” Its AI agents are designed to operate across an organization’s existing security toolchain—SIEMs, EDRs, firewalls, vulnerability scanners, and more—carrying out end‑to‑end defensive workflows such as alert triage, threat hunting, incident response, and remediation. Each customer decides how many virtual agents to deploy, effectively scaling its security workforce on demand. Pluda stresses that the agents do not replace people; they empower analysts to focus on higher‑order strategy and decision‑making.
Early Deployments and Performance Metrics
Corma reports that its AI workforce is already active in multiple Fortune 100 and Fortune 500 enterprises spanning healthcare, financial services, energy, critical infrastructure, retail, and other verticals. In these early production environments, the system has delivered striking results: threat‑response times have dropped by more than 94 %, security coverage across various functions has expanded by roughly 15 times, and the agents have uncovered sophisticated, multi‑stage attack campaigns that would have evaded conventional detection methods. These metrics underscore the potential of AI‑driven automation to close operational gaps that manual processes struggle to address.
Strategic Timing and Market Context
The company’s launch coincides with a rapid acceleration in the capabilities of general‑purpose foundation models such as OpenAI’s GPT, Anthropic’s Claude, and Google’s Gemini. These models have become proficient at coding, software reasoning, bug identification, and multi‑step tool operation—skills that attackers can readily repurpose for vulnerability research, exploit development, and autonomous attack chains. Anthropic’s disclosure of its Mythos AI system illustrates how offensive AI can move beyond assistance to fully autonomous threat execution. Consequently, defenders face an asymmetry: attackers gain powerful AI‑augmented capabilities while many security teams still rely on legacy tools and manual analysis.
The Attacker‑Defender Capability Gap
To quantify this disparity, Corma conducted hundreds of simulations using realistic enterprise environments modeled after Fortune 500 companies, complete with dozens of security tools. In each simulation, the same leading foundation models were first instructed to act as attackers, planting persistent threats. The same models were then asked to defend the environment, identify, and remove the threats they had just created. The results were stark: the AI attackers succeeded in 88 % of the scenarios, whereas the AI defenders detected only 12 % of the threats. Pluda interpreted this as evidence that the “race to general intelligence in cybersecurity” has already begun, with attackers holding a significant head start unless defenders adopt purpose‑built AI.
Corma’s Defensive‑Focused Foundation Model
In response to the gap, Corma is training a foundation model from the ground up specifically for defensive cybersecurity tasks. Unlike generic language models that optimize for broad textual understanding, Corma’s model ingests vast quantities of security‑relevant data—audit logs, network traffic, threat intelligence feeds, vulnerability reports, and incident‑response playbooks—to learn the nuances of defensive operations. The model powers the company’s AI agents, enabling them to continuously learn the specific environment in which they are deployed, adapt to evolving threats, and reason across multi‑step security workflows with a depth that general‑purpose models lack.
Team Composition and Expertise
Corma’s founding team blends deep AI research credentials with elite cybersecurity experience. Alon Pluda recruited alumni from Google and DeepMind who possess extensive background in foundation‑model training and large‑scale AI systems. Complementing this AI expertise are cybersecurity veterans drawn from Israel’s renowned Unit 8200 intelligence unit and major commercial security firms. This hybrid skill set enables Corma to bridge the theoretical advances in generative AI with the practical demands of defending complex, heterogeneous enterprise networks.
Future Outlook and Growth Strategy
Having closed its Seed round and secured early enterprise customers, Corma plans to use the new capital to refine its defensive foundation model, expand the breadth of security functions its agents can automate, and deepen integrations with leading security platforms. While the company is not aggressively scaling headcount at present, it intends to grow its research and engineering teams deliberately as product‑market fit is validated. Pluda envisions a market where organizations treat AI‑driven virtual security staff as a standard component of their cyber‑risk management strategy, much like they currently rely on managed security service providers.
Conclusion
Corma’s $60 million Seed financing marks a significant vote of confidence in the notion that defensive cybersecurity requires AI purpose‑built for the task. By delivering AI agents that act as virtual human resources, the company aims to close the widening gap between attacker‑enabled AI capabilities and the often‑manual defenses of today’s enterprises. Early performance gains—dramatically faster response times, vastly expanded coverage, and detection of hidden multi‑stage attacks—suggest that a foundation model trained explicitly for defense can deliver tangible security advantages. With a team that combines top‑tier AI researchers and seasoned cybersecurity operatives, Corma is positioned to shape the next generation of AI‑augmented security operations, potentially turning the tide in the evolving cyber‑arms race.

