A Tel Aviv and San Francisco startup has closed a $60 million seed round to build what it describes as the first frontier artificial intelligence lab focused exclusively on defensive cybersecurity. Sequoia led the investment in Corma, with participation from Khosla Ventures and Coatue, according to reporting published by Fortune. The company is building a foundation model trained not on code but on security logs, audit records, and pattern recognition — the unglamorous work that CEO Alon Pluda argues generative AI typically ignores.
Corma reports that early installations at Fortune 100 and Fortune 500 clients slashed threat response times by more than 94 percent while simultaneously multiplying security coverage across different functions by a factor of 15. The model has been put to work in organizations spanning healthcare, financial services, energy, critical infrastructure, and retail, the company says. Pluda is operating the firm from dual headquarters in Tel Aviv and San Francisco, and the company went into deployment just six weeks before the fundraise was announced.
According to Pluda, the real challenge in cybersecurity isn't producing more secure code but rather "looking at logs, audits, [and] finding the needle in a haystack." Sequoia partner Shaun Maguire framed the problem as structural: "agentic AI gives attackers a structural speed advantage," he told Fortune, positioning Corma's research as the defensive response. The report notes that a $60 million seed round for a company only six weeks into product deployment signals that backers believe they're funding a category, not just a single business.
The investment arrives amid a broader wave of concern around offensive AI capabilities. The report situates the Corma announcement within 324 cybersecurity stories tracked over the past 90 days, including recent coverage of OpenAI flagging its Astra model at the "critical" cyber capability level and Israeli red-team research lab Irregular working with OpenAI, Anthropic, and Meta. If frontier AI's offensive potential is being treated as critical, a well-funded defensive counterpart was overdue, the analysis suggests. The shape of the wager is clear: if security operations center teams begin pricing agentic attacks as live operational threats rather than academic exercises, a heavily capitalized defensive lab with named Fortune 100 pilot programs is positioned to become the first call those teams make.
The report does acknowledge reasons for caution. Every performance figure comes directly from Corma itself, with no third-party benchmarks or named reference customers available for verification. The piece names only Pluda; technical co-founders and specifics of the underlying model architecture remain undisclosed. For regulated buyers, routing live logs and audit trails into a young lab's foundation model represents a decision that press releases alone can't settle. Still, institutions facing what they perceive as an asymmetric speed disadvantage may find the trade-off between risk and response time increasingly difficult to ignore. For enterprises weighing defensive posture against competitive necessity, the calculus will turn less on vendor maturity and more on whether sitting out the next generation of security tooling proves costlier than adopting it early.

