Corma came out of stealth with $60 million in seed funding led by Sequoia Capital, Khosla Ventures and Coatue. Founded 2025, offices in Tel Aviv and San Francisco, CEO Alon Pluda.
A $60m seed is a Series A in everything but name, and the investor list is the same one writing the AI cheques. Valuation was not disclosed.
The claim the round is built on
Corma says it is building an AI foundation model engineered exclusively for defensive cybersecurity operations — analysing security telemetry, system events, audit logs and network traffic, to detect anomalies over extended timeframes.
The argument for why that needs a separate model is a test result, and it is the most interesting sentence in the announcement. Testing OpenAI and Anthropic models, the company found they were capable of conducting end-to-end attacks but failed to defend against the same type of attacks.
Pluda's framing:
AI-powered attacks are operating at a speed and sophistication that neither human teams, better tooling, nor general-purpose AI can match
Why the asymmetry is plausible
Take the claim seriously for a moment, because there is a structural reason it might be true.
An attack is a generation problem. There is a goal, a large space of possible paths, and success is one path that works. Language models are good at that shape.
Defence is a discrimination problem over a very unbalanced dataset. Almost everything is benign, the signal is spread across weeks of logs from systems that do not agree on time or identity, and the cost of a false positive is an analyst's afternoon. Nothing about that resembles the task a chat model was trained on.
"Extended timeframes" is doing real work in Corma's description. Most detection is evaluated on a window — an alert, a session, a day. The intrusions that matter are the ones that look normal at every point and only resolve into a pattern across weeks. That is a genuinely different problem, and it is not one that a bigger context window solves by itself.
The timing is not a coincidence
This lands the same week OpenAI shipped GPT-5.6-Cyber, a model tuned to refuse far less on exploit development and gated behind an access tier.
One company's pitch is that general models are dangerously good at offence. The other has just shipped a model that is deliberately better at it. Both can be right, and if they are, the gap Corma is naming widens rather than closes.
What is missing from the announcement
Being precise about what was not said:
- No customers named
- No headcount
- No valuation
- No benchmark published for the offence-versus-defence test — the claim is the company's own, on its own evaluation, with the compared models unnamed
None of that is unusual for a stealth exit, and all of it is the difference between a thesis and a result.
We wrote earlier this year that cybersecurity funding is being carried by a small number of very large rounds while deal counts fall, and that the same firms writing AI cheques are the ones writing security cheques. A $60m seed from Sequoia, Khosla and Coatue into a company with no public customers is that pattern in one line.
What to watch
- Whether the offence/defence benchmark gets published. It is the entire argument. If it holds up independently it is an important result; if it stays internal it is positioning.
- Whether "foundation model" means trained or fine-tuned. Those are very different capital requirements and $60m is light for the first.
- First named customers. Defensive AI sells on evidence, and detection products are judged on false-positive rate more than on anything in a launch post.
- What happens to SOC headcount claims. Every generation of detection tooling has promised to replace analysts and has instead changed what they do.