AI Start-Up Corma Raises $60 Million to Build a Cybersecurity Defence System That Never Sleeps
The Tel Aviv and San Francisco company says existing AI tools can attack but not defend. Its answer is a model built from scratch for security teams.

Key points
- Corma raised $60 million in seed funding from Sequoia Capital and Khosla Ventures and Coatue in 2025.
- The company's AI model is built specifically for defensive cybersecurity, not adapted from a general-purpose tool.
- Corma claims tests against OpenAI and Anthropic models showed those systems could run attacks but couldn't reliably stop them.
- The start-up is headquartered across Tel Aviv and San Francisco and was founded in 2025 by CEO Alon Pluda.
A cybersecurity start-up called Corma stepped out of stealth mode this week with $60 million in seed funding and a claim that most AI tools are better at attacking companies than protecting them.
The money comes from Sequoia Capital, Khosla Ventures and Coatue. Corma was founded in 2025 and operates across Tel Aviv and San Francisco. Its CEO is Alon Pluda.
What does Corma actually build?
Corma builds an AI foundation model, a large AI system trained on enormous amounts of data that can perform tasks across a specific domain, designed exclusively for defence. Most AI tools in use today are general-purpose: built to write code or answer questions, then adapted for security as an afterthought.
Corma's model ingests security telemetry, the stream of raw signals a company's systems produce every second: records of file access, server-to-server traffic, login locations. It watches that stream continuously and looks for faint, slow-moving patterns a human analyst might miss, such as unusual login attempts spread across three weeks that individually look harmless but together suggest a breach is building.
When the model spots something, it hands off to automated software agents. These sit inside a company's existing security tools and can act without waiting for a person to approve: blocking a suspicious connection, isolating a compromised machine, or flagging an anomaly for review.
Should security teams be worried that AI can now attack them?
Corma says yes. The company ran tests using AI models from OpenAI and Anthropic. Both could carry out full end-to-end attacks against a target environment. Neither could reliably defend against the same attacks.
CEO Pluda put it plainly, in remarks reported by SecurityWeek: "AI-powered attacks are operating at a speed and sophistication that neither human teams, better tooling, nor general-purpose AI can match. It requires a complete AI-powered defensive workforce, built from the ground up for cybersecurity."
Attackers already use AI to move faster than humans can respond. A defence built on the same general-purpose tools they use to attack is, by design, one step behind. We covered similar reasoning at Mate Security's $35 million raise on 29 July, where the argument was also that defenders need models trained on their own environment, not borrowed from elsewhere.
| Detail | Information |
|---|---|
| Founded | 2025 |
| Headquarters | Tel Aviv and San Francisco |
| Funding round | Seed |
| Amount raised | $60 million |
| Lead investors | Sequoia Capital, Khosla Ventures, Coatue |
Corma hasn't disclosed which organisations are using its platform or published independent test results. The claims about OpenAI and Anthropic models come from the company itself and haven't been independently verified.
For security leaders, the core question Corma is raising is real even if the company's answer isn't proven yet. General-purpose AI tools weren't built with your threat model in mind. Any vendor pitching AI for security is worth pressing: trained on what data, tested against what attacks, audited by whom?



