Sequoia-Backed Corma Raises $60M to Build AI That Defends Against AI Attacks
Corma, a Tel Aviv and San Francisco-based cybersecurity startup, has secured $60 million in seed funding led by Sequoia Capital to build a specialized artificial intelligence model designed specifically for defending enterprise systems against AI-powered attacks. The company argues that general-purpose AI models like OpenAI's GPT and Anthropic's Claude have created a dangerous imbalance, making it easier for attackers to automate exploits while defenders struggle to keep pace.
Why Is Cybersecurity-Specific AI Becoming Critical?
The cybersecurity landscape has shifted dramatically as artificial intelligence capabilities have advanced. Modern AI systems excel at software development and code reasoning, skills that attackers can weaponize for vulnerability research and multi-step cyberattacks. Meanwhile, defensive security requires a fundamentally different approach: analyzing massive volumes of data from audit logs, network traffic, and security tools while connecting signals across extended time periods to identify threats.
Corma's research illustrates the severity of this imbalance. In simulations modeling large enterprise environments with dozens of security tools, the company tested leading AI systems in both offensive and defensive roles. The results were stark: AI attackers successfully executed their objectives 88% of the time, while AI defenders detected only 12% of the threats. These figures, based on Corma's own testing methodology, form the central investment thesis for why organizations may need security-specific AI architectures.
"The race to general intelligence in cybersecurity has already begun, and the attackers have a significant head start," said Alon Pluda, co-founder and CEO of Corma.
Alon Pluda, Co-founder and CEO of Corma
How Does Corma's Approach Differ From Existing Solutions?
Rather than building another application on top of third-party AI systems, Corma is developing its own foundation model, a large-scale AI system trained from the ground up for cybersecurity tasks. The company's foundation model powers a set of AI agents that can be deployed across an organization's security environment. These agents continuously learn about the systems in which they operate and can work across multiple defensive security functions, rather than automating a single narrow task.
The funding round includes participation from Khosla Ventures and Coatue, alongside Sequoia Capital. Khosla Ventures founder Vinod Khosla framed the opportunity beyond traditional enterprise security, citing potential consequences for critical infrastructure, healthcare, and other essential systems as cyberattacks become more autonomous.
What Early Results Has Corma Achieved?
Despite launching just six weeks before the funding announcement, Corma has already secured deployments at Fortune 100 and Fortune 500 organizations spanning healthcare, financial services, energy, critical infrastructure, and retail. Early enterprise traction is significant for a seed-stage company, as large organizations typically operate complicated cybersecurity environments built around multiple security products and internal systems, creating a demanding testing ground for autonomous security technology.
According to the company, customer deployments have reduced threat-response times by more than 94% and expanded security coverage across different functions by 15 times. Corma also claims its technology has identified multi-stage attack campaigns that otherwise would have gone undetected. These performance figures are based on early deployments and have not been independently verified.
Steps to Understanding Corma's Competitive Positioning
- Foundation Model Development: Corma is building a cybersecurity-specific foundation model rather than relying solely on general-purpose AI systems, allowing it to optimize for defensive security tasks that general models struggle with.
- Enterprise Deployment Focus: The company is targeting large organizations with complex security environments, providing a demanding but credible testing ground that validates the technology's real-world effectiveness.
- Team Expertise: Corma has assembled employees including former Google and DeepMind AI researchers as well as cybersecurity specialists with experience at Israel's Unit 8200 and established security companies, combining AI expertise with deep security knowledge.
Sequoia partner Shaun Maguire pointed to the increasing speed advantage that agentic AI can provide attackers as a driver of demand for more scalable defensive technology. "Corma has trained its model for the complexity of real-world attacks and is building the intelligence layer defense actually needs," Maguire stated.
With the $60 million seed round, Corma is positioning itself in an increasingly competitive cybersecurity AI market by focusing on the underlying model rather than another application built entirely on third-party AI systems. The company's growth strategy now depends on translating early enterprise deployments into a scalable security platform capable of handling the complexity and reliability requirements of large organizations.