
Foundation model built for defensive cybersecurity, powering agents that work alongside SOC teams
Corma was founded in 2025 with offices in Tel Aviv and San Francisco, and emerged publicly in August 2026 with a $60M seed round led by Sequoia Capital, with Khosla Ventures and Coatue participating. Alon Pluda is chief executive. The founding team combines AI researchers, including alumni of Google and DeepMind, with operators from Israel's Unit 8200 and established cybersecurity vendors. The company's stated premise is that general-purpose models are being used effectively by attackers while defenders adapt the same models to a task they were never trained for, and that the asymmetry needs a model built for defense.
The model is trained on security telemetry rather than on general web text, and is designed to hold context across long windows so that an intrusion assembled from individually unremarkable events can be recognized as a single campaign. It generalizes across defensive tasks rather than being tuned to one function, which is what allows it to drive agents covering detection, triage, investigation, and response instead of a single playbook. Those agents integrate into existing security infrastructure and continue post-training on the environment they run in, so behavior specific to a particular estate becomes part of what the model expects. On-premises deployment is available where data sovereignty rules out a hosted model. The company says its technology is in use at Fortune 100 and Fortune 500 organizations across healthcare, financial services, energy, critical infrastructure, and retail.



