Jul 30, 2026
Enterprise

Cantina $8M funding backs AI agents for vulnerability fixes

Cantina launched with $8 million led by Framework Ventures to automate vulnerability triage, remediation and proof that fixes worked.

Colin Brandt

By Colin Brandt · Enterprise Reporter

· 3 min read

Cantina $8M funding backs AI agents for vulnerability fixes
Photo: SiliconANGLE

Cantina $8M funding led by Framework Ventures is backing a new agentic security startup that says it can move vulnerability work from discovery through verified remediation. The company formally launched with a platform built to automate the work security teams do after scanners and other tools have already found a problem.

Cantina said it has now raised $16.5 million in total. It did not disclose its valuation, revenue, headcount, burn rate or customer count, leaving the round difficult to benchmark against other early-stage security companies beyond the capital raised and lead investor.

The company was founded by security researchers and engineers with experience finding flaws in widely used software and defending systems from attacks. Its pitch is aimed at a familiar constraint inside security organizations: teams can identify more issues than they can close, and the handoff from alert to owner to fix remains slow.

What does Cantina do?

Cantina runs artificial intelligence agents across a customer’s environment to handle discovery, triage, remediation coordination and verification that a fix was actually applied. In practical terms, the company is trying to automate the connective tissue between security, infrastructure and engineering teams, rather than another alert feed.

The platform is built around what Cantina calls a security memory layer. According to the company, that layer maps identities, servers, code repositories, cloud permissions, databases containing customer data and the relationships between those assets. It also adds business context such as system ownership, dependencies, recent changes and findings from earlier investigations.

Cantina says that model gives its agents enough context to decide which vulnerabilities need immediate action, identify who owns the affected systems and preserve evidence that the issue has been closed. Customers can use Cantina’s own agents, create internal agents or use agents developed by other Cantina customers, the company said. Each investigation is meant to feed back into the environment model so future work starts with more context.

Why vulnerability remediation is getting more attention

The timing reflects a shift in breach patterns. The 2026 Verizon Data Breach Investigations Report found that vulnerability exploitation overtook stolen credentials last year as the top path into a breach, after 18 previous editions in which it had not held that position. Verizon also reported that 26% of critical known-exploited vulnerabilities were fully remediated, down from 38% a year earlier.

Those figures give security vendors room to argue that remediation, not detection, is the underfunded bottleneck. Cantina’s claim is that many organizations still investigate the same vulnerabilities separately, assign ownership by hand and rebuild similar playbooks without shared context. The company has not said how much of that work is fully automated in production versus assisted by analysts and customer security teams.

Co-founder and Chief Executive Hari Mulackal said AI has accelerated attackers’ ability to find vulnerabilities and create working exploits, while many defensive workflows were designed for a slower cycle. Cantina also said it has trusted access with OpenAI Group PBC and participates in Anthropic PBC’s Cyber Verification Program, which it says gives it early insight into model capabilities affecting attack and defense.

The company said it serves customers in healthcare, financial technology and other regulated sectors, including mid-market companies and Fortune 500 enterprises. Trend Health Partners Chief Information Security Officer Matt Mock said in Cantina’s announcement that the backlog is where risk accumulates and that Cantina carries the process from finding an issue to driving the fix.

For Framework Ventures, the bet is that security teams will buy tooling that proves closure, not just prioritization. Cantina still has to show how its agents perform across messy enterprise environments where asset ownership, code changes and production approvals rarely line up cleanly.

This story draws on original reporting from SiliconANGLE.

More from Enterprise

All Enterprise →