AI Start-Up Corma Raises $60 Million to Build a Cybersecurity Defence System That Never Sleeps
The Tel Aviv and San Francisco company says existing AI tools can attack but not defend. Its answer is a model built from scratch for security teams.

Key points
- Corma raised $60 million in seed funding from Sequoia Capital, Khosla Ventures, and Coatue in 2025.
- The company's AI model is built specifically for defensive cybersecurity, not adapted from a general-purpose tool.
- Corma claims tests against OpenAI and Anthropic models showed those systems could run attacks but could not reliably stop them.
- The start-up is headquartered across Tel Aviv and San Francisco and was founded in 2025 by CEO Alon Pluda.
A cybersecurity start-up called Corma stepped out of stealth mode this week with $60 million in seed funding and a claim that most AI tools are better at attacking companies than protecting them.
The money comes from three well-known venture capital firms: Sequoia Capital, Khosla Ventures, and Coatue. Corma was founded in 2025 and is split across Tel Aviv and San Francisco. Its CEO is Alon Pluda.
What does Corma actually build?
Corma builds an AI foundation model, meaning a large AI system trained on enormous amounts of data that can then perform a wide range of tasks, but designed exclusively for defence. Most AI tools in use today are general-purpose: they were built to write emails, answer questions, or generate code, then adapted for security as an afterthought.
Corma's model ingests security telemetry, which is the stream of raw signals a company's systems produce every second: records of which files were opened, which servers talked to which, who logged in from where. The model watches that stream continuously and looks for faint, slow-moving patterns that a human analyst might miss, such as a series of unusual login attempts spread across three weeks that individually look harmless but together suggest a break-in is building.
When the model spots something, it hands off to automated software agents. Think of these as digital assistants that sit inside a company's existing security tools and can take action without waiting for a person to click approve. They block a suspicious connection, isolate a compromised machine, or flag an anomaly for review.
Should security teams be worried that AI can now attack them?
Corma says yes, and it has a pointed way of putting it. The company ran tests using AI models from OpenAI and Anthropic. Both could carry out full end-to-end attacks against a target environment. Neither could reliably defend against the same attacks.
CEO Pluda framed the problem plainly: "AI-powered attacks are operating at a speed and sophistication that neither human teams, better tooling, nor general-purpose AI can match. It requires a complete AI-powered defensive workforce, built from the ground up for cybersecurity."
The argument is that attackers already use AI to move faster than humans can respond. A defence built on the same general-purpose AI they use to attack is, by definition, one step behind.
| Detail | Information |
|---|---|
| Founded | 2025 |
| Headquarters | Tel Aviv and San Francisco |
| Funding round | Seed |
| Amount raised | $60 million |
| Lead investors | Sequoia Capital, Khosla Ventures, Coatue |
Corma has not yet disclosed which organisations are using its platform or published independent test results. The claims about OpenAI and Anthropic models come from the company itself, reported by SecurityWeek, and have not been independently verified.
For security leaders reading this: the core question Corma is raising is real, even if the company's own answer is unproven. General-purpose AI tools were not built with your threat model in mind. Any vendor pitching AI for security is worth asking: trained on what data, tested against what attacks, and audited by whom?



