Corma Secures $60 Million for AI-Powered Cybersecurity Defense Models
AI startup Corma has raised $60 million in seed funding to develop specialized foundation models for cybersecurity defense, aiming to enhance enterprise security operations.

Corma, a new artificial intelligence lab focused on defensive cybersecurity, has announced a significant $60 million in seed funding, led by Sequoia Capital. The company's mission is to build domain-specific foundation models tailored for the unique demands of enterprise security, differentiating itself from general-purpose AI models that may not be optimized for defensive tasks.
Alon Pluda, co-founder and CEO of Corma, emphasized the critical need for AI capabilities that can match the advancements being made by attackers. "We now have this race between offensive security and defensive security and their capabilities," Pluda stated. "So, the defenders need to have the AI capabilities that will enhance them just as much as the AI currently enhances the attackers, and they need to have it ASAP."
Founded in September 2025, Corma is led by Pluda, who brings extensive experience from over six years in Israeli Military Intelligence, specializing in cybersecurity. He highlighted that defensive security operations involve analyzing vast amounts of telemetry, such as network flows, audit logs, and configurations, to identify subtle but critical signals. This process requires consistency and the ability to navigate complex decision paths, tasks that general-purpose AI models are not inherently designed for.
Pluda explained that Corma's models are trained on modalities and knowledge often underrepresented in general AI training data. The training process includes reinforcement learning across various security tools and tasks, as well as adversarial training within simulated enterprise environments. This approach ensures the models are exposed to millions of scenarios across different tools, settings, and organizational complexities before deployment.
"The vast majority of enterprise defensive security work doesn't even have to do anything with code," Pluda noted. "It's about looking at a lot of logs, audit, configuration, network flows. These are not language, and these are not exactly code. And it's about finding these signals in a vast amount of nodes, and it's about being extremely consistent across gigantic decision trees."
Corma's AI is designed to operate existing security and IT tools, integrating seamlessly with human analysts through platforms like Microsoft Teams and Slack. The models can perform tasks, document findings, notify personnel, and escalate issues within established workflows. This collaborative approach aims to augment security teams, making them more efficient and effective.
Customers can start by delegating routine and repetitive tasks to Corma's AI, gradually increasing its autonomy as trust grows. The system can identify suspicious activity and request human approval before taking action, or, with authorization, respond directly to threats, such as quarantining compromised hosts. Corma's focus on repeatability and reliability ensures that security decisions are consistent and dependable.
The company's evaluation metrics include end-to-end results, accuracy, consistency, the ability to detect true positives without missing any, distinguishing false positives, and selecting appropriate responses. Corma's AI aims to cover a significant portion of the environment while operating quickly and comprehensively, supercharging human security teams to be "orders of magnitude more powerful, more accurate, quicker, cover more ground, understand things differently, make sure that they never miss anything."