Skip to content
Rush Commerce
AI & Automation3 min read

Corma raises $60M for defensive cyber AI as attackers speed up

Sequoia led a $60M seed into models built only for cyber defense. The thesis behind it — attackers now move at agent speed — is your problem too.

Corma raised a $60 million seed led by Sequoia Capital, announced August 10, to build foundation models trained for one job: defending against cyberattacks. The company is a year old. The investment thesis is blunter than the product — agentic AI gave attackers a structural speed advantage, and human-paced defense does not close that gap. That thesis applies to your ten-person business exactly as much as it applies to the Fortune 100 logos in Corma's deck.

What actually happened

Per Fortune's exclusive, Sequoia led with participation from Khosla Ventures and Coatue. No valuation disclosed.

  • Founded in 2025 by CEO Alon Pluda, with offices in Tel Aviv and San Francisco.
  • The models are trained for defensive work specifically — reading logs and audit trails, finding the anomaly in the haystack, and staying consistent across thousands of sequential actions. Corma's argument is that these are different skills from the code-generation strength general models are optimized for.
  • The first model shipped roughly six weeks before the announcement, into Fortune 100 and 500 organizations across healthcare, financial services, energy, critical infrastructure and retail.
  • Corma says the model cut threat response times by 94% at adopting organizations. That is the company's own figure, six weeks into deployment, with no independent verification. We would not plan a budget around it.
  • Sequoia's Shaun Maguire framed the problem as agentic AI handing attackers a structural speed advantage.

Why AI-speed attackers matter for your business

You have seen the attacker side of this already. An agent worked through 460 targets autonomously. AI agents found zero-days in Redis. A Claude agent walked into a gym's booking API this week. The gap between "vulnerability disclosed" and "vulnerability exploited at scale" is now measured in hours. Nobody is buying you more time.

The affordable version of this is not a foundation model. You are not procuring frontier defensive AI. You are doing the three unglamorous things that determine whether an AI-speed attack is an incident or a disaster: patch on a schedule you actually keep, retain logs long enough to reconstruct what happened, and write down who does what in the first hour. That last one is a one-page document and almost nobody has it.

Log retention is the part that gets cut first and hurts most. Corma's whole product premise is that the answer is already in your logs and nobody can read them fast enough. If your hosting plan keeps seven days of access logs and your app writes nothing structured, then when something does happen you will be reconstructing the timeline from memory and a credit card statement. Ninety days of structured application logs costs less per month than one seat of most SaaS tools.

Watch the consolidation, not the product launch. Security tooling is getting bought and bundled fast — Cyera picked up Oasis, and the pattern repeats. Whatever defensive AI you buy in the next eighteen months, assume the vendor gets acquired. Keep your logs and detection rules somewhere you can export from.

Key takeaways

  • Corma raised $60M seed led by Sequoia, with Khosla Ventures and Coatue, announced Aug 10, 2026
  • Founded 2025 by CEO Alon Pluda; offices in Tel Aviv and San Francisco; valuation undisclosed
  • Models are trained for defensive work — log and audit analysis, consistency across long action chains
  • First model deployed about six weeks before the announcement at Fortune 100/500 organizations
  • The 94% faster threat response figure is Corma's own claim and is not independently verified
  • The premise that matters: agentic attackers move faster than human-paced defense
  • Your version is patch cadence, 90 days of structured logs, and a one-page first-hour runbook
  • Assume any security vendor you pick gets acquired — keep logs and rules exportable

Most small businesses cannot reconstruct what happened last Tuesday, let alone last quarter. We build structured logging, sane retention and boring incident runbooks into the systems we ship — before you need them. See what we build in or ask us what your stack is missing.

Sources: Fortune, Calcalist.

  • #cybersecurity
  • #ai-agents
  • #incident-response
  • #logging
  • #funding
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.