Corma, an AI lab founded in 2025 with offices in Tel Aviv and San Francisco, said on Monday it has raised a $60 million seed round led by Sequoia Capital, with Khosla Ventures and Coatue participating. That is a large seed by any measure. It is not the number that earns the round.
Before raising, Corma ran hundreds of simulations inside enterprise environments modelled on Fortune 500 companies, each wired with dozens of real security tools. It pointed leading general-purpose models — OpenAI’s GPT and Anthropic’s Claude among them — at those environments and told them to attack: get in, plant persistent threats, stay there. Then it moved the same models into the defender’s seat and asked them to find what they had just buried.
By Corma’s count, the attackers succeeded in 88% of runs. The defenders caught 12% of the threats. Same models, same environments, opposite chairs.
The gap is structural, not a tuning problem
Offence and defence look symmetrical. They are not. Attacking is a coding and reasoning problem — read the target, find the flaw, write the exploit, chain the steps — and coding and reasoning are precisely what every frontier lab has spent three years optimising. Defence is a different job: chew through audit logs and network traffic at volume, hold a weak signal in mind long enough for it to become a signal, and make the same judgement call consistently across thousands of decisions at 3am. Nobody is training a flagship model on that, because it does not demo well.
That asymmetry is not theoretical. OpenAI spent last Friday telling the world it could no longer rule out that an unreleased model had reached the Critical cyber threshold on its own risk scale. A worm that reached 440 npm packages used AI coding assistant configs as its persistence layer. The offensive side is compounding in public. The defensive side is running the same models with a different system prompt.
The product is headcount, not software
“We don’t replace anyone and we are not a product,” chief executive and co-founder Alon Pluda told Calcalist. “We sell virtual human resources.” Each customer decides how many it wants. The agents run on top of the security tools a company already owns and take tasks end to end, rather than generating another queue of alerts for a human to work through.
Corma says it has already deployed at Fortune 100 and Fortune 500 organisations across healthcare, financial services, energy, critical infrastructure and retail, and that early deployments cut threat-response times by more than 94% and widened security coverage fifteenfold. Those figures are the company’s own, unaudited, and supplied by a firm selling the cure. The round itself closed in early 2026 — Monday was the announcement, not the event. The team pairs AI researchers including Google and DeepMind alumni with operators out of Israel’s Unit 8200 and the large security vendors.
Our take: Discount the 88/12 split for what it is — a marketing asset built by the company selling defence. The direction still holds, because everything else on the tape points the same way. The genuinely interesting bet is not the model, it is the budget line. Security software gets cut in a bad quarter. Security headcount is a vacancy nobody can fill, and a vacancy is easier to sell into than a renewal. Pricing AI as staff rather than seats is the move to watch here, and it will not stay confined to cyber.
What to watch
- Whether a named customer ever publishes the 94% and 15x figures under its own logo. Metrics that never pick up a customer’s name usually stay vendor-supplied.
- Whether a purpose-built defensive model holds its edge through the next general-model release, or gets absorbed the way most vertical fine-tunes have been.
- How it is priced. “Virtual human resources” only escapes the software budget if the invoice genuinely looks like a salary line rather than a per-seat licence.
- Whether the incumbent platforms answer with defence-tuned models or simply buy one — the standard ending for a well-funded security seed.
- Who carries liability when an autonomous defender misses something. That question is unanswered across the whole agent-permissions category, and it lands hardest in security.
