Dossier · Private startup · 5 independent sources
Corma Labs
Last updated: Aug 31, 2026
Corma Labs, operating publicly as Corma, is an Israeli defensive-cybersecurity AI startup building foundation models and an AI workforce for security teams. Its stated aim is to give defenders specialized, scalable assistance across investigation and response as offensive AI increases the speed and volume of attacks.
Visit WebsiteCompany Overview
**Product and problem.** Corma is building a specialized defensive-cybersecurity AI workforce rather than another point product for endpoint, identity, or vulnerability management. The company says its foundation models work alongside human security teams, generalize across defensive tasks, and operate through the security stack that a customer already uses. The concrete problem is an asymmetry in cyber operations: automated offense can search, exploit, and persist at machine speed, while defense still depends heavily on people correlating logs, events, configurations, alerts, and business context under time pressure. Corma’s proposed answer is a model that can perform more of the investigative and operational workload end to end, helping a small security team cover more systems and incidents without requiring every workflow to be redesigned around a new console. Public materials do not enumerate the complete product surface, supported tools, or customer-specific action permissions, so the record should treat “AI workforce” as the company’s product framing rather than as proof of unrestricted autonomous remediation.
**Core technology and operating model.** Corma publicly describes a foundation model built from the ground up for defensive cybersecurity. Its materials emphasize that defensive work is not simply code generation: it involves interpreting noisy telemetry, forming and testing hypotheses, finding anomalous behavior in a large normal environment, and deciding whether and how to act. The model is intended to power agents that can use existing security tools and assist with investigation, containment, and remediation. Sequoia’s announcement describes Corma’s training direction as applying reinforcement learning and self-play to a two-player cyber-defense setting, but that account comes from the lead investor and the company has not publicly disclosed model size, training corpus, data-rights posture, reward design, or independent benchmark methodology. Corma claims materially stronger defensive performance and much lower cost and latency than general-purpose models. Its stated deployment options include fully on-premises operation and post-training on a customer’s security data and context. Those are strategically important capabilities, but diligence still needs reproducible task-level evaluations, false-positive rates, tool-use guardrails, audit trails, and evidence that local adaptation improves outcomes without leaking sensitive information.
**Market, customers, and go-to-market.** The initial market is enterprise security operations, where CISOs already purchase telemetry, detection, response, identity, cloud, and managed-security products but remain constrained by analyst capacity. Corma’s “works where the human team already works” positioning suggests an integration-led enterprise motion: add specialized agents to existing workflows and data sources, then expand as the workforce proves useful across more defensive tasks. CTech reported that the company was already working with Fortune 100 and Fortune 500 organizations, while Sequoia described engagements across healthcare, finance, critical infrastructure, retail, and other large enterprises. The official site says important organizations already use the workforce, but it does not name customers, publish contracts, or disclose revenue, retention, deployment counts, or average time to value. Public evidence therefore supports early enterprise access and credible buyer interest, not yet repeatable product-market fit. Procurement will depend on least-privilege integrations, security review, data residency, human approval policies, and a clear economic case against adding more analysts or buying bundled AI from an incumbent platform.
**Traction, financing, and third-party validation.** Corma was founded in 2025 and emerged publicly in August 2026 with a $60 million seed round led by Sequoia Capital, with Khosla Ventures and Coatue participating, according to CTech and Fortune. Startup Nation Finder lists the same financing, an August 2026 date, approximately 20 employees, and Alon Pluda as founder; CTech likewise reported 20 employees in Tel Aviv. Sequoia’s portfolio record marks the company as founded in 2025 and partnered in 2026, and its partner announcement confirms that the fund is backing Corma’s defensive-cybersecurity foundation-model thesis. Corma has also published a research report comparing frontier-model offense and defense in a controlled enterprise range. That report describes 241 scored engagements and reports persistent backdoors in 85% of attack runs versus detection of 19% by general-purpose defenders; it is useful evidence of a serious evaluation program, but it is company research and should not be treated as an independent product benchmark. Investor-reported customer anecdotes are encouraging, yet named references and independently audited operating metrics remain absent from the public record.
**Founders and team.** Alon Pluda is publicly identified as Corma’s founder and CEO by Sequoia and CTech. The available public record presents the team as an interdisciplinary combination of advanced-AI researchers and highly capable cybersecurity practitioners, which is the right talent mix for a company attempting to train models around operational defense rather than merely fine-tune a chat interface. However, the public company page names only Pluda, and broad biographical claims about other employees, prior employers, military units, or individual research accomplishments are not sufficiently documented in the sources used for this record. The reported Tel Aviv team of about 20 people is a meaningful early hiring base, with the company also maintaining a San Francisco presence, but it is too small to assume mature 24/7 support, evaluation, security engineering, sales engineering, and government-procurement capacity. Team diligence should verify who owns model research, cyber-range design, customer deployment, trust and safety, and enterprise integrations, as well as whether the company can retain scarce security and frontier-model talent after a highly visible seed round.
**Competitive dynamics.** Corma competes with several different categories rather than one direct peer. CrowdStrike, Microsoft Security, Palo Alto Networks, Google Security Operations, and SentinelOne all have large telemetry footprints and can add increasingly capable AI assistants to established detection and response platforms. Tines competes through security workflow automation, while AI-native SOC vendors such as Prophet Security and Dropzone AI compete for analyst augmentation and investigation budgets. Corma’s possible advantage is the combination of a model trained specifically for defensive cyber reasoning, agents that generalize across a customer’s existing tools, and sovereign deployment for organizations that cannot place sensitive security context in a standard multitenant service. The tradeoff is execution risk: incumbents have distribution, data, integrations, and procurement trust, while narrower AI competitors may move faster on a defined SOC workflow. Corma must show that a vertically trained model produces better defended environments and lower total operating cost, not simply stronger marketing language. Its likely competitive edges are (1) domain-specific training objectives, (2) end-to-end workforce behavior, and (3) on-premises adaptability.
**Defense, security, and resilience relevance.** Dual-use relevance is direct because cyber defense is simultaneously a commercial necessity and a national-security mission. The same agents that investigate identity abuse, cloud compromise, malware persistence, or suspicious network activity for a bank or hospital could support government networks, defense contractors, communications providers, energy operators, and other critical infrastructure. On-premises deployment and customer-specific post-training are especially relevant to sovereign, classified-adjacent, or data-residency-constrained environments where telemetry cannot be sent to a public cloud. Corma’s own defensive-gap research also addresses a strategically important question: whether general AI is scaling offensive capability faster than defensive capability. That supports the resilience thesis, but it does not prove fielded military capability. No public source used here establishes a defense contract, classified authorization, government customer, or certification. The responsible strategic interpretation is therefore a high-relevance defensive technology with plausible deployment into defense and critical infrastructure, subject to accreditation, isolation, supply-chain, model-governance, and human-override requirements.
**Stage, trajectory, and diligence risks.** Corma is best classified as early stage: it has a 2025 founding date, a very large seed financing, a reported 20-person Tel Aviv team, and evidence of early enterprise work, but limited public operating history. The financing gives it unusual runway to train models, build cyber-range evaluation infrastructure, and recruit scarce talent. The principal diligence risks are substantial: (1) public performance claims may not transfer from controlled ranges to messy production networks; (2) an agent with access to security tools can cause material damage through hallucination, overreaction, or a compromised integration; (3) training and post-training on security data raises privacy, provenance, retention, and cross-tenant isolation questions; (4) model inference and on-premises deployment may be expensive to operate at enterprise scale; (5) Microsoft, Google, CrowdStrike, Palo Alto Networks, and other incumbents can bundle adjacent capabilities; and (6) public customer, revenue, retention, safety, and certification evidence is still thin. The trajectory is compelling, but the next proof points should be independent efficacy tests, production references, measurable analyst-time savings, renewal data, safe-action controls, and a credible path through regulated and sovereign procurement.
Dual-Use Assessment
Corma's core product is credibly dual-use because defensive cyber operations protect both commercial organizations and defense, government, and critical-infrastructure networks. Its foundation-model agents could assist with threat hunting, investigation, containment, and response in hospitals, financial institutions, utilities, defense contractors, and public-sector environments. Fully on-premises deployment and post-training on local security context strengthen the sovereign-resilience case. Public sources establish the technology thesis and enterprise activity, but do not establish a military contract, classified deployment, or government certification, so those remain diligence questions rather than assumed traction.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Corma merits a high legacy priority signal because it targets a strategically urgent bottleneck: defensive cybersecurity has not scaled as quickly as automated offense, and enterprise security teams are already overloaded. The $60M seed led by Sequoia, with Khosla Ventures and Coatue, provides credible financing and recruiting capacity, while the reported Fortune 100/500 work and published cyber-range research indicate access to serious validation environments. This is not an investment recommendation. Strategic diligence should test whether the model improves production detection and response, whether customers renew, how much human review remains necessary, and whether on-premises economics and security controls can support regulated and sovereign deployments. 1. Upside: specialized model objectives, AI workforce behavior, and meaningful initial capitalization. 2. Constraints: limited public operating history, no named customers or audited revenue, and strong incumbent distribution. 3. Decision signal: prioritize technical and customer-reference diligence, not a conclusion based on financing alone.
Strategic Value to U.S.-Israel Alliance
Corma has unusually direct strategic value for a resilience-oriented technology thesis. A defensive model that can reason over security telemetry and operate through existing tools could expand the effective capacity of national SOCs, defense suppliers, hospitals, utilities, and communications operators during incidents. On-premises deployment is important where security data must remain under national or organizational control, and customer-specific post-training could improve relevance to local infrastructure. The strategic value remains conditional on measurable efficacy, safe autonomy, explainability, supply-chain assurance, and integration into incident-command processes. Public evidence supports strong relevance, but not yet fielded military or classified adoption.
Key Technologies
- Foundation model trained specifically for defensive cybersecurity reasoning
- Agentic security investigation and response workflows
- Integration with existing enterprise security stacks and operator tools
- Cyber-range evaluation using attacker-defender engagements and ground-truth state changes
- On-premises foundation-model deployment for sovereign or sensitive environments
- Post-training on customer security data and operational context
Use Cases & Applications
- Autonomous or analyst-supervised investigation of active enterprise intrusions
- Threat hunting across endpoint, identity, cloud, and network telemetry
- Containment and remediation of persistent backdoors and attacker campaigns
- Security operations augmentation for healthcare and financial institutions
- Cyber resilience for energy, water, communications, and other critical infrastructure
- Defense-contractor and government-network monitoring in private or on-premises environments
- Continuous defensive evaluation against AI-assisted offensive techniques
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 7 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- Corma official website Official product positioning, defensive-cybersecurity foundation-model thesis, AI workforce description, existing-stack integration, on-premises deployment, and customer-specific post-training claims.
- Measuring the AI offense-defense gap on a live network Corma's published cyber-range methodology and reported results for attacker-defender engagements, including 241 scored engagements and ground-truth disk-state validation.
- Corma | Sequoia Capital portfolio Sequoia's portfolio description, Corma's defensive foundation-model mission, 2025 founding year, 2026 partnership, and Alon Pluda team listing.
- Partnering with Corma: Closing the Defensive Cybersecurity Gap Lead-investor account of the $60M seed partnership, Alon Pluda's founder and CEO role, the defensive-model training thesis, enterprise work, and the investor's description of reinforcement learning and self-play.
- Exclusive: Corma raises $60M from Sequoia, Khosla Ventures for AI trained to defend against cyberattacks CTech reporting on the August 2026 $60M seed, participating investors, 2025 founding, Tel Aviv and San Francisco presence, approximately 20 Tel Aviv employees, and Fortune 100/500 activity.
- Corma Labs | Startup Nation Finder Israeli ecosystem profile corroborating the company name, May 2025 founding date, Tel Aviv headquarters, approximately 20 employees, official website, founder, and $60M August 2026 seed financing.
- Exclusive: Corma raises $60M for defensive cybersecurity AI Fortune reporting on Corma's emergence from stealth, the Sequoia-led $60M seed with Khosla Ventures and Coatue, and the company's specialization in defensive cybersecurity models.
- Profile update timestamp Last updated in the Claw & Talon database on Aug 31, 2026.
Investor Lens
What this entry is
Private startup
Why it may matter
Corma Labs may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.
How an independent investor should read this
Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.
Evidence to verify
- Verify current status
- Verify traction
- Verify cap table/funding
- Verify technical claims
- Verify regulatory/export-control issues
- Verify customer concentration
Main investor questions
- Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
- What customer, revenue, product, and technical evidence supports the company story?
- What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
- Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
- What evidence would change the thesis or show that the profile is stale?
What not to infer
- Inclusion does not imply endorsement.
- Inclusion does not imply allocation availability or current fundraising.
- Scores do not indicate investment suitability or expected returns.
- Strategic importance does not automatically imply venture return potential.
Diligence questions
- What evidence verifies Corma Labs's current customer traction, deployment status, and revenue concentration?
- Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
- Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
- How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
- What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.
Related companies
Need a diligence readout?
Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.