The AegisAI Series A funding round has closed at $36 million, with Battery Ventures leading and existing backers Accel and Foundation Capital returning. The raise brings the startup’s total capital to $49 million and arrives less than a year after AegisAI’s public launch, which is either a sign of genuine market pull or a very well-timed pitch deck. Probably both.
AegisAI was founded in 2025 by Cy Khormaee and Ryan Luo, both former Google security executives who spent years building the infrastructure most of us quietly rely on. According to the AegisAI company page, Khormaee led Safe Browsing, reCAPTCHA, and Web Risk teams at Google for five years, before stints as VP Product at Moovweb and founder of Contastic, both acquired. Luo, the CTO, spent nine years modernising Google’s core Safe Browsing phishing platform and built reCAPTCHA’s product-led growth strategy, driving adoption across millions of sites. He’s also a Yale Computer Science Award recipient, which the company’s website mentions with the energy of someone who just found their old trophy.
The problem they’re attacking is real and accelerating. AI lets bad actors aggregate personal data at scale: your colleagues, your current projects, your recent travel. The result is spear phishing that looks indistinguishable from a message a colleague actually sent. ‘AI-powered attacks bypass existing controls more than half the time now, which means they’re almost twice as effective as they used to be,’ Khormaee told TechCrunch. ‘They’ve researched you, they understand everything about you, and they’re targeting attacks that are perfectly bespoke to you.’
The founders’ argument is that rule-based defences, built on rigid if-then logic, can’t keep pace with threats that are themselves generated by AI. AegisAI’s Series A press release states the company builds its own large language models to defend the inbox, using sophisticated reasoning to evaluate the specific intent of a suspicious email rather than simply matching patterns from past scams. That’s a meaningful architectural distinction: intent analysis versus signature matching.
What the AegisAI Series A Funding Will Power
The $36 million will go towards scaling the company’s fleet of autonomous defence agents, accelerating general availability of its ‘Vanguard’ agent (which hunts threats beyond the inbox), and growing enterprise sales, according to Pulse 2.0. That last one is always where the real test begins.
The company claims its agents reduce false positives by up to 90% compared to traditional email security solutions, per the September 2025 seed round announcement on GlobeNewswire, when AegisAI simultaneously went public and closed a $13 million seed led by Accel and Foundation Capital. Fewer false positives matters operationally: security teams drowning in alerts tend to start ignoring them.
Customers already live on the platform include AI startup LangChain and Google-owned privacy compliance platform Lokker. The crypto payments customer is listed in the snippet as ‘Mash’; Pulse 2.0 reports the name as ‘Mesh’, both refer to the same company, with the discrepancy likely a spelling variant. At Lokker, according to Pulse 2.0, AegisAI caught an attack that originated through compromised Salesforce infrastructure, the kind of lateral-entry threat that a pattern-matching filter would almost certainly miss.
Battery Ventures general partner Dharmesh Thakker framed the investment in straightforward terms. ‘The bad guys are using email to attack us using AI at a much faster pace than we can keep up with,’ he told TechCrunch. ‘Defending against that is going to be a number one priority for a lot of companies.’ Thakker’s rationale for backing AegisAI specifically, rather than the wider field, rests on the founders’ credentials with Gmail, the world’s most widely used email system.
A Crowded Field With One Obvious Selling Point
AegisAI is not operating in a vacuum. Lightspeed-backed Ocean is chasing the same displacement thesis, going after established vendors like Proofpoint and Mimecast as well as newer entrants including Abnormal Security. The market is not short of confidence. What AegisAI has that most competitors don’t is a founding team that spent the better part of a decade, between them, building the defences that protect the world’s dominant email platform. That is a credible moat, assuming the product delivers.
The company’s ambitions extend beyond email. SecurityWeek notes the founders see email as the starting point for a broader agentic security platform. Khormaee was direct about the stakes: ‘The core idea of building customized, highly advanced agents that can do investigations is going to [determine] who becomes the next dominant security company.’
The AegisAI Series A funding gives the company enough runway to find out whether that prediction ages well. The next data point will be when enterprise renewal cycles come around and customers decide if the AI-versus-AI pitch holds up under the weight of an actual procurement decision.
