
Corma raises $60 million Seed to build AI designed to fight AI-powered cyberattacks
The Israeli startup is developing a foundation model for defensive cybersecurity, arguing that general-purpose AI models are becoming increasingly effective at attacking companies but remain poorly equipped to defend them.
Corma, a developer of foundation models for defensive cybersecurity, has raised $60 million in a Seed round led by Sequoia Capital, with participation from Khosla Ventures and Coatue. The company, founded in 2025 and headquartered in Tel Aviv and San Francisco, employs 20 people in Tel Aviv and is already working with Fortune 100 and Fortune 500 companies.
In a conversation with Calcalist, Corma CEO and co-founder Alon Pluda said the company is developing AI models specifically for defensive cybersecurity. “We train language models for defensive cyber,” he said. “The models thus become much better at cyber than any other model.”
Corma is building its own foundation model from the ground up for cybersecurity defense. Rather than selling a conventional software product, the company deploys AI agents that operate across an organization's existing security tools and processes and carry out tasks from end to end.
“We don't replace anyone and we are not a product; we provide services,” Pluda said. “People need to operate cyber products today and need someone to perform the problems and fix them. Companies still have thousands of security people and pay a lot for services. I am not replacing them but making them much more successful and much stronger.”
According to Pluda, the growing volume and complexity of threats means security teams are increasingly unable to deal with everything manually. Corma's system is designed to work like another employee alongside an organization's existing security teams and AI agents. “We sell virtual human resources,” he said, with each organization determining how many it needs. “They can do almost any defensive cyber thing.”
The company says it has already deployed its AI workforce at Fortune 100 and Fortune 500 organizations across healthcare, financial services, energy, critical infrastructure, retail and other sectors. Corma said that, in early deployments, its systems reduced threat-response times by more than 94%, expanded security coverage by 15 times across different security functions and uncovered multi-stage attack campaigns that would otherwise have gone undetected.
“The Seed closed in early 2026 and we work with many leading companies and we are not in a hurry to recruit more,” Pluda said.
The company is targeting a growing imbalance in cybersecurity created by the rapid development of AI. In recent years, foundation models such as OpenAI's GPT, Anthropic's Claude and Google's Gemini have advanced rapidly, particularly in coding and software reasoning. They can now write and improve software, identify and fix bugs, reason through complex environments and operate tools across multi-step processes.
Those same capabilities can be used by attackers. Vulnerability research and exploit development are heavily dependent on understanding code and reasoning about specific targets. Combined with autonomous AI agents, these capabilities could allow attackers to move beyond using AI as an assistant and toward executing complete, end-to-end attack chains, as demonstrated by Anthropic's disclosure of its Mythos AI system.
Defensive cybersecurity, however, requires a different set of capabilities. Beyond protecting code itself, security teams must process enormous volumes of audit logs, security events and network traffic, identify weak signals that may emerge over long periods, and maintain consistency across thousands of decisions.
Corma says its research illustrates the gap. In hundreds of simulations using realistic enterprise environments modeled on Fortune 500 companies and equipped with dozens of security tools, the company tested leading AI models including OpenAI's GPT and Anthropic's Claude.
First, the models were instructed to act as attackers and plant persistent threats inside the simulated organizations. The same models were then asked to defend the environments and identify and remove the threats they had created. According to Corma, the AI attackers succeeded in 88% of the simulations, while the AI defenders detected only 12% of the threats.
The company says the results show that the same general-purpose models that are increasingly capable of carrying out sophisticated attacks remain poorly equipped to defend against them.
“The race to general intelligence in cybersecurity has already begun, and the attackers have a significant head start,” Pluda said. “It requires a complete AI-powered defensive workforce, built from the ground up for cybersecurity, that gives defenders the same speed, sophistication and generalization that AI has already given attackers.”
Corma is attempting to address that gap with a foundation model specifically trained for defensive cybersecurity. The model powers the company's AI agents, which are designed to operate across a broad range of security functions and continuously learn the environment in which they are deployed.
Corma was founded by Pluda and brings together AI researchers, including alumni of Google and DeepMind, with cybersecurity specialists from Israel's elite 8200 intelligence unit and major cybersecurity companies. The team has experience in foundation-model training, advanced AI systems, as well as offensive and defensive cybersecurity.














