Corma Raises $60M to Build Cyber Defense Foundation Models
Data Breach TodayArchived Aug 13, 2026✓ Full text saved
Corma Says General-Purpose Models Aren't Optimized for Defensive Security San Francisco-based Corma raised a $60 million Sequoia-led seed round to train foundation models for enterprise cyber defense, using security telemetry, adversarial training and millions of simulated scenarios to automate threat detection, investigation and response.
Full text archived locally
✦ AI Summary· Claude Sonnet
Corma Raises $60M to Build Cyber Defense Foundation Models
Corma Says General-Purpose Models Aren't Optimized for Defensive Security
Michael Novinson (MichaelNovinson) • August 12, 2026
Credit Eligible
Get Permission
Alon Pluda, co-founder and CEO, Corma (Image: Corma)
A frontier artificial intelligence lab for defensive cybersecurity led by a longtime member of the Israeli Military Intelligence raised $60 million to train domain-specific foundation models.
See Also: Open-Weight Model Antares Delivers Stronger Code Security
The Sequoia Capital-led seed funding will help San Francisco-based Corma develop increasingly capable generations of its defensive cybersecurity models, said co-founder and CEO Alon Pluda. Enterprise defense involves substantially different data and workflows from software development and vulnerability research needed for offensive security, Pluda said.
"We now have this race between offensive security and defensive security and their capabilities," Pluda told ISMG. "So, the defenders need to have the AI capabilities that will enhance them just as much as the AI currently enhances the attackers, and they need to have it ASAP."
Corma, founded in September 2025, has been led since its inception by Pluda, who spent more than six years in the Israeli Military Intelligence, culminating in a role as a cybersecurity specialist. Defensive security teams must analyze network flows, audit logs, configurations, security events and other forms of telemetry while searching for small but important signals in enormous volumes of information.
How Corma Trains Foundation Models for Cyber Defense
They also need to follow complex decision paths consistently. Pluda said general-purpose foundation models aren't optimized for these tasks, creating the need for models trained specifically around the modalities and operational requirements of defensive cybersecurity.
"The vast majority of enterprise defensive security work doesn't even have to do anything with code," Pluda said. "It's about looking at a lot of logs, audit, configuration, network flows. These are not language, and these are not exactly code. And it's about finding these signals in a vast amount of nodes, and it's about being extremely consistent across gigantic decision trees."
A security model must operate existing tools, construct queries, examine dashboards and execute workflows while producing dependable results, Pluda said. Creativity or variability can become a liability when an organization expects the same evidence to lead to the same security decision. Pluda said Corma's main goal is repeatability.
"Be very consistent. Be very reliable," Pluda said. "You don't want it to be too creative in some sense. But you want it to be very, very reliable. If you run it 100 times, you want to get 100 times the same result. All of these things are just examples of things that general foundation models are not optimized for, and our model is optimized for."
During pre-training, Corma exposes models to modalities and knowledge that may be underrepresented in the training data of general-purpose models. Pluda said post-training includes reinforcement learning across different security tools and tasks. Corma also uses adversarial training in realistic enterprise environments, enabling models to operate against one another as attacker and defender, Pluda said.
"By the first time that the model first hits an enterprise, it's already been trained on millions and millions of different scenarios across different tools, across different settings and different complexity levels and different organizations and different sizes," Pluda said. "And so, it's seen it all already."
How Corma Works Alongside Human Security Analysts
Network security, cloud security, security operations, threat hunting, incident response, identity and access management, and data security are areas of evaluation. The company examines accuracy and consistency as well as whether the model catches true positives, distinguishes false positives, selects the appropriate response, completes work quickly and covers enough of the environment, Pluda said.
"We measure it with end-to-end results, accuracy, consistency, the ability to never miss any true positive, the ability to understand what's a false positive and what's not, the ability to call for the right actions after you have the full picture of what happened, how quick it was able to do it and how much ground it was able to cover when doing all of that," Pluda said.
Corma's AI operates the organization's existing security and IT tools and interacts with human analysts through Microsoft Teams, Slack and ticketing platforms. The model can perform work, document findings, tag or notify employees and escalate issues within existing workflows. This design allows AI to work alongside security personnel rather than forcing teams to move into a separate environment.
"The only one thing that we offer for enterprises is end-to-end security workforce, working alongside your human security team and supercharging them to be orders of magnitude more powerful, more accurate, quicker, cover more ground, understand things differently, make sure that they never miss anything," Pluda said.
Customers can begin by delegating mundane, repetitive work that consumes analysts' time and then give the system greater autonomy as they develop confidence in its performance. In some cases, Corma can identify suspicious activity and request human approval before taking action. Other organizations can authorize the system to respond directly, including taking actions such as quarantining hosts, he said.
"Some organizations just already give it the delegation," Pluda said. "They're seeing that it's so accurate and so persistent, and they can actually trust it, so they just give it the ability to act end to end and do anything around responding in real time for events, quarantine hosts, all these kind of things."