Back to directory
AI & ML · AI infrastructure / MLOps / evals

Corma

Superintelligence for defensive cybersecurity

1.0K followers
TLVC Rating
Hook
Editing / Creativity
Copy
Sentiment of launch
Distribution strategy
Community Rating
No ratings yet
Your rating
Sign in to rate this launch.

About

Corma is a foundation model lab focused on defensive cybersecurity, launching out of stealth with an AI workforce that plugs into an enterprise security team's existing stack and takes on the work that sits outside code. That work looks like sifting through audit logs, events, and network flows, correlating weak signals across long time horizons, and staying consistent across thousands of sequential decisions. Early customers span Fortune 100 and Fortune 500 organizations across healthcare, financial services, energy, critical infrastructure, and retail, with the first model deployed roughly six weeks before launch. The timing reflects a widening gap the company has tried to quantify. In internal simulations run against realistic Fortune 500 environments using models like OpenAI's GPT and Anthropic's Claude, AI attackers succeeded 88 percent of the time while AI defenders detected only 12 percent, meaning the same model that could carry out an end-to-end intrusion typically could not catch itself. Corma is pitching a purpose-built alternative it says outperforms general-purpose models on defensive tasks, runs faster and cheaper, and can be deployed fully on-prem and post-trained on a customer's own security data. The company, based in Tel Aviv and San Francisco and founded in 2025, is led by co-founder and CEO Alon Pluda, who previously served in Israeli military intelligence. It is announcing a $60M seed round led by Sequoia Capital with Khosla Ventures and Coatue also participating. The name comes from Tolkien's Elvish word for "ring," which Pluda frames as a tool built this time for the defenders.
Tags
<500KSeedProduct launchB2BGlobalAI-generatedUSVertical AI
Comments (13)
Sign in to join the discussion.
Priya Rangarajan2d ago

Was in the room when the deck clicked. Defensive foundation models is one of those categories where the second-place team still ends up worth a fortune.

Dmitri K.2d ago

The tweet buries the actual thesis under the funding number. Lead with why offense is outpacing defense, then hit us with the round.

Kenji Park2d ago

The video cuts are way too fast for a security pitch. I want to feel like the founder has been paged at 3am, not like I'm watching a Nike ad.

fenwick2d ago

Curious what corpus you're pretraining on. Public CVE data plus honeypot telemetry only gets you so far before the model starts hallucinating IOCs.

Tomás Queiroz2d ago

Genuine question from someone new to this space: if the model is defensive, does it also need to simulate offense internally to train on? Feels like a chicken and egg thing.

Aisha Bello2d ago

Superintelligence is doing a lot of work in that sentence. Show me the SOC integration path before I believe any of it.

Luca Burnside2d ago

Every defensive AI company pitches the same asymmetric threat story. What's actually novel about your architecture versus stacking a good detection model on top of an LLM?

Mei-Lin Shroff2d ago

The defensive market is not shrinking but it is consolidating into three buyers who all want to build this in house. Good luck threading that needle.

Noah F.2d ago

Foundation model economics on defensive security is going to be brutal. Training runs don't care that your customer signed a three year contract.

Sveta Marković2d ago

The Corma wordmark has one letter doing all the heavy lifting and the rest look like they showed up late. Kerning between the r and the m is off.

Ravi Menon2d ago

How many people did you have when you closed this? I keep hearing about lean security teams shipping foundation models and I don't buy it yet.

Hanna Bekele2d ago

Is there an API day one or is this an enterprise-sales-only situation. Devrel person wants to know before I get excited.

Yusuf Al-Amin2d ago

Tweet engagement is stacked which usually means Sequoia's comms team was locked and loaded before the post went live. Nicely orchestrated.