Corma raised $60 million from Sequoia Capital and Khosla Ventures to develop and deploy AI security agents for defensive cybersecurity
Funding ● Confirmed 86% confidence first seen
Corma emerged from stealth and announced a $60 million funding round led by Sequoia Capital and Khosla Ventures to build AI for defensive cybersecurity. The company said it trained a foundation model that can deploy as an end-to-end “security workforce” agent within enterprise networks, reporting improved detection and substantially reduced threat response times in its coverage.
The deal
Corma $60 million Seed · announced 10 Aug 2026
Investors Sequoia Capital Khosla Ventures
Deal terms as reported in the coverage below.
Decision brief
- What changed
- Corma emerged from stealth and announced a $60 million funding round led by Sequoia Capital and Khosla Ventures to build AI security agents for defensive cybersecurity. The company said it has trained a cybersecurity-specific foundation model and is already deploying an end-to-end "Security Workforce" agent inside Fortune 500 and other large enterprise networks.
- Why it matters
- For enterprise leaders, this is a signal that investors and early customers are backing cybersecurity tools designed to act inside production environments, not just assist analysts with recommendations. If Corma’s reported results hold in broader use, AI-native defensive agents could change security operating models by compressing response times and automating remediation work that currently requires scarce human talent. Decision-makers should care because this points to a potential shift in security spend toward specialized, domain-trained AI agents rather than general-purpose models or purely human-led response workflows.
- Evidence
- The funding and product claims are supported by Sequoia’s own announcement and Fortune Startups’ exclusive report, with both consistently describing a $60 million round and an AI agent for end-to-end defensive cybersecurity. Performance claims cited in the coverage come from Corma and its investors, including Sequoia’s red/blue team testing example and Fortune’s report of a 94% threat-response-time reduction at adopting organizations; the coverage does not describe independent third-party validation.
- What remains uncertain
- Key assumptions remain unverified: the coverage does not specify how many enterprises deployed Corma, how the 94% improvement was measured, or whether results generalize across industries, threat types, and existing security stacks. It is also unclear how much autonomy the agent has in remediation, what governance controls are required, and what operational or legal risks come with letting AI act inside enterprise networks.
- Monitor next
- Watch for independent customer references or third-party evaluations that quantify deployment scale, false-positive rates, and response outcomes in live enterprise environments.
Analytical support, not advice — assumptions and open questions stated above.