Detection asks what happened. Governance decides what is allowed.
Corma is building a foundation model for defensive cybersecurity, deployed as agents across the security tools an enterprise already runs. Agentomy governs what agents are permitted to do and proves what they did. They are not the same control, and an organisation running theirs has more to govern, not less.
The number in their own pitch is the argument for governance
Corma reports that in its own simulations AI attackers succeeded in 88% of attempts while AI defenders detected 12% of threats. That figure is theirs, from their own testing, and the reporting that carried it did not independently verify it. Take it at face value anyway, because it is the most interesting thing either of us has published.
If the best available detection catches roughly one threat in eight, then detection is necessary and it is not sufficient. The remaining seven are not caught by looking harder. They are survived by what the attacker was permitted to do once inside: whether an action was authorized before it executed, whether there is a record that cannot be edited afterwards, and whether one command stops everything.
Better detection narrows the window. Agentomy closes it. Every action is authorized before it executes, written to a record that cannot be edited afterwards, and stoppable across the entire fleet on one command. That is the control that decides how far something gets, whether or not anything ever detected it.
Where each of us sits
| Corma | Agentomy | |
|---|---|---|
| Primary question answered | Is something malicious happening in my environment? | Is this agent allowed to do this, and can I prove what it did? |
| Shape of the product | A foundation model plus agents deployed across existing security tools | A governance layer between any agent and everything it touches |
| Per-action authorization, enforced server-side | Not described publicly | Tier-gated, escalation via request body refused |
| Tamper-evident record of decisions | Not described publicly | Hash-linked, stamped with the policy version in force |
| Kill switch across the fleet | Not described publicly | Fleet-wide or a scoped subset, survives restart |
| Behavioral monitoring | Threat detection across security telemetry | Per-agent baselines, drift and anomaly detection, 40 detectors |
| Population-scope detection: the group, not the agent | Not described publicly | Undeclared inheritance, shared write surfaces, coordination reconstitution |
| Reproducible public benchmark | Internal simulations, figures published by the company | GovernanceBench and VIGIL, open, run it yourself |
| Deployment model | Deployed into the enterprise security stack | Self-hosted, bring your own key, never holds your keys or data |
| What it is sold as | Virtual security personnel, in the company's own words | Infrastructure, not headcount |
"Not described publicly" means exactly that. Corma is a young company that has published little detail, and we are not going to tell you what is missing from a product we have not run. Every Agentomy row is a shipped capability you can exercise against a running instance.
An enterprise running Corma has more to govern, not less
Corma's own description of the product is that it deploys AI agents across an organization's existing security tools, and its CEO describes what it sells as virtual human resources rather than a product. Read that as an operator rather than as a buyer: it means a fleet of autonomous agents, with broad reach across security infrastructure, running in healthcare, financial services, energy and retail environments.
That is the exact shape this platform exists to govern. Agents with real privileges, acting continuously, in regulated industries where somebody eventually has to answer for what they did. The questions do not change because the agents are defensive ones: what was this agent authorized to do, what did it actually do, who approved the escalation, and can I stop it in under a second and prove the whole sequence to an auditor.
Security tooling has always been high-privilege software. Making it autonomous does not lower the bar for governing it. It raises it.
Reporting on what happened, or deciding what may happen
A detection model reports. It raises the odds that an intrusion is noticed, and it improves the throughput of the analysts reading the alerts you already collect. What it produces is a finding, after the fact.
Agentomy decides. It authorizes each action before it runs, proves what happened in a record an auditor can verify, and halts the fleet on command. Detection tells you what got through; governance determines what could get through at all. That is the stronger position to hold, and it applies to every agent in the estate, including the ones bought to defend it.
Run the benchmark against your own platform · See what the governance layer does
Sources
- Funding, investors, founding year, locations and team background: reporting on Corma's 2026 seed round.
- The 88% and 12% simulation figures, the 94% response-time reduction and the fifteenfold coverage expansion: Corma's own statements, carried by that reporting and not independently verified by it.
- "We don't replace anyone and we are not a product... we sell virtual human resources": Corma's chief executive, quoted in that reporting.
- There is an unrelated company also called Corma, founded in Paris in 2023, working on SaaS licence management and access reviews. This page is not about that company.