Cantina Raises $8 Million to Let AI Agents Hunt and Fix Security Flaws Automatically
A New York startup wants to replace slow, manual vulnerability management with software agents that find problems, investigate them, and patch them without waiting for a human to file a ticket.

Key points
- Cantina raised $8 million in a new funding round led by Framework Ventures, bringing its total funding to $16.5 million.
- The startup emerged from stealth mode today after operating quietly while building its product.
- Cantina's platform uses autonomous AI agents, meaning software programs that act independently, to find, rank, and fix security weaknesses across a company's systems.
- Customers can share agents they have built with other Cantina users, creating a community library of ready-made security tools.
- The platform maintains a live digital twin, a constantly updated virtual map of a company's entire technology environment, to track risks in real time.
A New York cybersecurity startup called Cantina stepped out of stealth mode today, meaning it revealed itself publicly for the first time after raising money and building its product behind closed doors.
The company announced $8 million in new investment, led by venture firm Framework Ventures. That brings the total amount Cantina has raised to $16.5 million since it was founded.
What does Cantina actually do?
Cantina sells a platform that uses AI agents to manage vulnerability management, which is the ongoing process of finding security weaknesses in a company's systems before criminals do. The core idea is automation: instead of security engineers manually reviewing alerts one by one, software agents do the legwork.
Those agents scan across an organisation's cloud servers, identity systems (the tools that control who can log in to what), code repositories, and databases. The platform then maps everything it finds, applies context about how important each system is to the business, and surfaces a ranked list of what needs fixing first.
In practice, this is the part of security operations that most teams quietly drown in. Alerts pile up faster than people can review them. The failure mode here is not that threats go undetected; it is that they go uninvestigated because no one had four hours to dig in.
Cantina claims its platform learns from each investigation, getting sharper over time. It also verifies that a fix was actually applied correctly, which is the step most organisations skip and then regret at postmortem time.
What is the community angle?
Organisations using the platform can share agents they have built with other Cantina customers, and pick up agents others have published. Think of it like an app store for security automation: one company solves a tricky detection problem, packages their solution as an agent, and the whole user base can deploy it immediately.
Cantina co-founder and CEO Hari Mulackal framed the problem bluntly: "Attackers can identify vulnerabilities, understand systems, and build exploits faster than ever before. Security teams cannot keep responding with workflows built for a pre-AI world."
He is not wrong. The tooling gap between attackers who have adopted AI and defenders still running ticket-driven processes is real and widening.
Should ordinary people care about this?
Directly, no. Cantina sells to businesses, not consumers. But the companies protecting your medical records, bank account, or online orders are exactly who this product targets. Better automated vulnerability management means fewer of the misconfigurations and unpatched flaws that end up as breach headlines six months later.
One thing the post-mortem will say, if Cantina's agents ever miss something big: the platform ranked it low priority.
Operational takeaway: Automation surfaces more than humans can review; your prioritisation logic is now your biggest single point of failure.



