---
title: "Corma’s $60M Seed: Sequoia Bets on a Foundation Model for Defense, Not Offense"
description: "Sequoia led Corma’s $60M seed with Khosla and Coatue — a Tel Aviv/SF lab building defensive cybersecurity foundation models as AI attackers pull ahead."
date: 2026-08-10T00:00:00.000Z
tags: ["2026-vc-news", "startup-funding", "venture-capital", "cybersecurity", "artificial-intelligence", "sequoia"]
source: https://venturecapitaltracker.com/2026-corma-60m-seed-sequoia-defensive-cyber-ai
---

# Corma’s $60M Seed: Sequoia Bets on a Foundation Model for Defense, Not Offense

> Sequoia led Corma’s $60M seed with Khosla and Coatue — a Tel Aviv/SF lab building defensive cybersecurity foundation models as AI attackers pull ahead.

**Corma** emerged from stealth with a **$60 million seed** on **August 10, 2026**, led by **[Sequoia](/fund/sequoia)** with **[Khosla Ventures](/fund/khosla-ventures)** and **[Coatue](/fund/coatue)**. The Tel Aviv / San Francisco lab is not selling another SIEM skin — it is training a **defensive cybersecurity foundation model** because general-purpose AI already helps attackers more than defenders.

## Key facts

| Field | Detail |
| --- | --- |
| Company | Corma (Tel Aviv & San Francisco) |
| Round | $60M seed (first disclosed) |
| Date | August 10, 2026 |
| Lead / key | Sequoia Capital; Khosla Ventures; Coatue |
| Founded | 2025 (CEO Alon Pluda; DeepMind / Google AI + Unit 8200 talent mix) |
| Traction claim | Fortune 100/500 deployments in ~6 weeks; >94% faster threat response; 15× coverage expansion (company) |
| Product | Defensive cyber foundation model + agentic “AI workforce” |

## Who uses the product — and for what job

**Users:** CISOs and security operations leaders at large enterprises — especially regulated and critical-infrastructure environments.

**Job:** put an **AI-native defensive workforce** on logs, events, and network flows that general LLMs handle poorly, while attackers use those same models for exploit research and agentic attack chains.

Onboarding metaphor in the company’s materials: hire Corma like a **new team member**, not install another alert dashboard. That framing matters for buyers tired of tool sprawl.

## Why now

- Frontier models got dramatically better at **code reasoning** — which maps cleanly to vulnerability research and exploit development.
- Anthropic’s Mythos-style disclosures made boards treat **autonomous attack chains** as a near-term risk, not sci-fi.
- Company sims claim an **88% vs 12%** offense/defense success asymmetry when the same model class attacks then defends — a quotable wedge even if you treat the number as proprietary research.
- Offense-side cyber AI (continuous pentest, red-team agents) already raised mega-rounds; **defense foundation models** were the open lane.

## Why Sequoia / Khosla / Coatue — portfolio fit

| Firm | Why the check fits |
| --- | --- |
| [Sequoia](/fund/sequoia) | Shaun Maguire’s AI + hard-tech lane; wants the intelligence layer under enterprise defense |
| [Khosla Ventures](/fund/khosla-ventures) | National-security and critical-infrastructure stakes — Vinod’s quote frames cyber beyond enterprise IT |
| [Coatue](/fund/coatue) | Growth/tech crossover appetite for category-defining AI platforms early |

**Likely founder rationale:** raise a seed large enough to pre-train a domain model from a syndicate that already underwrites frontier AI compute and will not force a premature SOC-UI pivot.

## Competitive map

| Player | Lane |
| --- | --- |
| Horizon3 / NodeZero | Continuous offensive testing of *your* estate |
| Neo / Straiker / Zenity | Agent security & governance control planes |
| Classic SIEM / XDR vendors | Detection productized as dashboards; not foundation-model labs |
| General LLM wrappers on security data | Fast demos; weak long-horizon correlation |

Corma’s claim is category creation: **defensive foundation model**, not “ChatGPT for your SOC.”

## When not to model this deal

- Wrong if you treat seed ARR claims as audited — early deployments are company-reported.
- Wrong if you assume general-purpose Claude/GPT fine-tunes close the gap without domain pre-training.
- Wrong if you conflate Corma with offensive AI pentest vendors — opposite buyer job.

## Practical takeaway

- **Founders (security AI):** Prove defense on **messy enterprise telemetry**, not CTF toys; the asymmetry story is the memo.
- **Investors:** Underwrite data rights + model evals as carefully as growth — false negatives in critical infra are existential.
- **Operators:** Ask what Corma autonomously remediates vs escalates, and how it sits beside your existing SIEM/XDR stack.

### Sources

1. ACCESS Newswire / FinancialContent (Aug 10, 2026): https://www.financialcontent.com/article/accwirecq-2026-8-10-corma-the-first-frontier-defensive-cybersecurity-ai-lab-raises-60m-as-ai-supercharges-attackers
2. Tech Startups Aug 10 roundup: https://techstartups.com/2026/08/10/venture-capital-startup-funding-roundup-august-10-2026-accel-coatue-management-general-atlantic-khosla-ventures-sequoia-capital-more/
3. Related: [/startup/corma](/startup/corma) · [/fund/sequoia](/fund/sequoia) · [/fund/khosla-ventures](/fund/khosla-ventures) · [/fund/coatue](/fund/coatue)
