Introducing Corma

Published

August 10, 2026

Corma is training domain-specific foundation models toward superintelligence for defensive cybersecurity.


We deploy these models as a superintelligent security workforce - one that will work inside every organization in the world, alongside human security teams, enabling them to combat every cyber threat in the vast and volatile cybersecurity landscape of the coming decades.


Our mission is to protect the global economy as increasingly capable AI drives a seismic shift in cybersecurity, and to mitigate its inherent cyber risks so the world can continue the exponential advancement of AI.

Why the name "Corma"

Why the name "Corma"

Corma is the word for ring in Quenya (the ancient Elvish language of Middle-earth) - as in the One Ring. The Rings of Power are neither good nor evil; they are raw power, and what they become is decided in the forging. AI is also raw power - forged one way, it becomes an attacker no human can match. Forged another, it becomes a defender no attacker can break. Corma is forging that "one ring to rule them all, one ring to find them" - this time, for the defenders.

The Defensive Gap

Cybersecurity has two sides. Offense is the art of breaking in - finding vulnerabilities and exploiting them (or reporting them for fixing). Defensive cybersecurity is everything else: the never-ending work of making sure every attack fails, carried out every day by security teams in every organization on Earth.

The Defensive Gap is the phenomenon in which general foundation models' offensive capability compounds exponentially while their defensive capability stands still.

Over the last few years, general foundation models have advanced at an extraordinary pace, particularly in coding and software reasoning. These systems can now write and refine software, identify and remediate bugs, reason through complex environments, and orchestrate tools across multi-step workflows. Those same capabilities map directly to offensive security. Vulnerability research and exploit development are, at their core, code-reasoning problems executed against bounded targets. When combined with agentic execution, these models move beyond assisting attackers to autonomously carrying out end-to-end attack chains, as demonstrated in Anthropic's Mythos disclosure. Offensive capability now compounds with every new model generation.

But defensive cybersecurity (everything outside of code security) demands a fundamentally different set of capabilities. It requires continuously analyzing massive volumes of security data, including audit logs, events, configurations, and network flows; connecting weak signals across systems and over long periods of time; and making thousands of accurate, consistent decisions every day under constantly changing conditions.

This is the root of the Defensive Gap. The same advances that are rapidly increasing AI's ability to discover vulnerabilities and execute attacks do not translate directly to the work of defending an organization. As a result, offensive capability compounds with every new model generation while defensive capability falls further behind. Hiring alone cannot close that gap. No human security team can match attackers operating at machine speed and machine scale.

Closing the Defensive Gap

Recent events have shown that building frontier AI models for defensive cybersecurity is one of the crucial unsolved problems of the AI age - and solving it is the generational mission Corma was founded on.

Building the frontier of defensive cybersecurity intelligence will not be easy. There is no path to follow, and no playbook to use. It means working where no one has worked before: rethinking model architecture from first principles, teaching machines to read the data and modalities of defense as fluently as they read language and code, extending context by orders of magnitude so models can detect the faintest anomaly signals, running adversarial self-play against the most capable attackers ever built, pioneering continuous learning so models can establish baselines over months and years - and way, way more.

This is uncharted territory. No one has solved it before us. That is precisely why we are here. It is our mission to make it work.

The Beginning

And we already are. Our foundation model has far surpassed every frontier model on defensive cybersecurity tasks. It is already on the job as a superintelligent security workforce, protecting Fortune 100 companies and some of the world's most important organizations, across healthcare, finance, critical infrastructure, retail, and more.

We are committed to remaining the frontier of defensive cybersecurity intelligence for as long as the fight lasts. This is just the beginning: we see it as our calling to protect every organization in the world that needs frontier defense.

The race to superintelligence in cybersecurity between attackers and defenders has just started. Corma exists to make sure the defenders win it - and every challenge that comes next.

Contact us

contact@corma-labs.com

Corma© 2026