Corma Raises $60M to Replace Static Zero Trust with Agentic AI Defense
Corma emerged from stealth this week carrying a $60 million seed round and a thesis that makes an entire generation of security architects uncomfortable: the defenders, not the attackers, need their…

Corma emerged from stealth this week carrying a $60 million seed round and a thesis that makes an entire generation of security architects uncomfortable: the defenders, not the attackers, need their own AI foundation model — and the Zero Trust edifice needs to be rebuilt around it.
According to SecurityWeek, the Tel Aviv and San Francisco–based startup raised the round from Sequoia Capital, Khosla Ventures, and Coatue to build what CEO Alon Pluda calls a defensive cybersecurity foundation model, purpose-built to sit inside an enterprise's existing security stack and reason across years of telemetry rather than minutes of it.
The bet sitting underneath the deck
The technical wager is sharp and specific. Corma's system ingests system events, audit logs, and network traffic, then stitches faint anomaly signals across long time horizons — the kind of subtle, multi-stage intrusions that human analysts routinely miss and that rule-based Zero Trust policies were never designed to catch on their own. Pluda, whose company was founded in 2025, frames it as an "AI-powered defensive workforce" running shoulder to shoulder with human staff, learning each enterprise environment continuously rather than shipping as a generic bolt-on.
It's the inverse of how most security tooling has been sold for the last decade. Zero Trust assumed the perimeter was already breached and built identity-first controls on top. Agentic AI, by contrast, assumes the attacker moves at machine speed and that only a defender trained on the same substrate — the same kind of foundation model paradigm that powers general-purpose assistants — can match them move for move.
Why the founders think the race is already lost
Corma's pitch lands hardest in a single provocative claim reported by SecurityWeek: in the company's testing, models from OpenAI and Anthropic could execute end-to-end attacks but failed to defend against equivalent attacks. Pluda cast it as a closing-of-the-gap problem, arguing that "AI-powered attacks are operating at a speed and sophistication that neither human teams, better tooling, nor general-purpose AI can match."
That framing — defense needs its own model, not a borrowed one — is what turned a defensive AI tool into a $60 million seed event. It's also why outlets like Breaking Defense and RealClearDefense are reading the same shift as agentic AI turning Zero Trust "on its head": the architectural assumption that every request must be verified still holds, but the entity doing the verifying is increasingly a fleet of purpose-tuned agents, not a human at a console.
What to watch next
The practical tell will be deployment shape. If Corma's agents slot cleanly into existing SIEM and identity stacks without forcing a rip-and-replace, the Zero Trust orthodoxy absorbs the shock and evolves. If customers discover they need to rebuild their telemetry pipelines around a defensive foundation model — as they've had to rebuild around large language models in product orgs — the bill gets ugly fast, and the "agentic defender" story quietly becomes a five-year migration. For now, the seed is closed, the framing is set, and the defenders have their own foundation-model race to run.