AegisAI: Detection Parity, Sold as a Breakthrough

A $36M Series A to read every inbound email at every customer — whose own lead seed investor concedes detection is only “on par with” Mimecast, whose alarming market statistics all originate from its own unpublished study, and whose privacy policy names zero subprocessors and zero AI vendors. Led by Battery Ventures.

ProofStory Research July 23, 2026

$36M Series A Led by Battery Ventures — July 23, 2026

API-based agentic email security for Microsoft 365 and Google Workspace. Founded 2025 by Cy Khormaee (CEO) and Ryan Luo, who led Safe Browsing, reCAPTCHA and Web Risk at Google. Accel and Foundation Capital, who co-led the September 2025 seed, both returned.

$49M
Total Raised Since Founding in 2025
104×
Abnormal Security’s Valuation vs. AegisAI’s Total Capital
0
Subprocessors or AI Vendors Named in Any Legal Document
2 of 3
Named Customers Unchanged Since the Seed Round

Three Core Questions

01

“Is the Detection Actually Better?”

By its own seed investor’s account, no. Foundation Capital’s thesis states detection is “on par with Mimecast’s detection rates” — the differentiation is a claimed 10× lower false-positive rate. That is an operations improvement, not a detection breakthrough, and it is self-measured with no published methodology.

02

“Where Do the Scary Numbers Come From?”

AegisAI. The 5× surge in AI phishing, the 72.6% authentication-bypass rate, the “more than half the time” inbox penetration — all originate in AegisAI’s own study. SiliconANGLE, covering the round, states plainly that the statistics come exclusively from the company. The vendor is sizing the problem it sells the cure for.

03

“Who Reads the Email?”

AegisAI does — every inbound message at every customer, by design. Yet its published privacy policy addresses only website visitors, names no subprocessor, names no cloud or LLM vendor, and makes no statement about whether customer email trains models. The trust center returns no retrievable content.

Key Finding: The founding team’s pedigree is genuine and rare — Safe Browsing and reCAPTCHA are exactly the right credentials for this problem. But the public customer roster has added one name in the ten months and $36M between the seed and the Series A, the performance advantage is conceded by its own investor to be false-positive rate rather than detection, and a company whose product is reading all corporate email has published no subprocessor list at all.

The Numbers

Founded
2025; emerged from stealth September 2025. HQ San Francisco, with New York presence (CONFIRMED)
Founders
Cy Khormaee (CEO) — 5+ years at Google to July 2023, director of product for Safe Browsing, reCAPTCHA and Web Risk. Ryan Luo — nearly a decade on Google Safe Browsing (CONFIRMED)
Funding
$36M Series A led by Battery Ventures; Accel and Foundation Capital returning. $49M total (CONFIRMED). Valuation not disclosed
Prior Round
$13M seed co-led by Accel and Foundation Capital, September 2025 — ten months earlier (CONFIRMED)
Product
Orchestrated AI agents evaluating inbound email on identity, authentication, sender behaviour, relationship patterns and language intent; auto-quarantine (CONFIRMED)
Deployment
API-only into Microsoft 365 and Google Workspace; no MX record change. Claimed five-minute integration, ~one week read-only observation before activation (CONFIRMED)
Headcount
Six at seed in September 2025. No current figure disclosed — no independent confirmation found
Pricing
Not published anywhere. No list price, no per-seat rate, no tier structure in any source

The Platform Is Also the Competitor

AegisAI is an API guest inside two companies that both ship the competing product themselves — one of which is the founders’ former employer.

Where the Value Actually Sits

01

The Mailbox

Microsoft 365 or Google Workspace. Owned by the two firms whose own filters AegisAI displaces.

02

The API

The sole integration path. Read access granted by the platform owner, revocable, throttleable, repriceable.

03

Inference

LLM-driven agents. No model provider named in any public document. The same class of model that writes the attacks.

04

Agent Orchestration

Specialist agents for urgency, signature scams, OAuth lures. The genuine engineering, and the real asset.

05

Quarantine

Writes back into the platform’s own quarantine surface. The action AegisAI takes is the platform’s primitive.

Microsoft bundles Defender for Office 365 into E5 and Google ships its own protections inside Workspace. Every AegisAI buyer is already paying for a competing product they cannot decline. The structural question — what happens when the platform owner closes, throttles or reprices the API, or simply narrows the gap for free — is not addressed in any AegisAI material, any investor thesis, or any coverage of either round.

Defending LLM Attacks With LLMs

AegisAI’s thesis is that rule-based “if-then” filters cannot catch AI-crafted lures, so it uses reasoning agents instead. The unexamined corollary: the attacker’s capability improves on the same curve, from the same frontier models, at the same falling cost. A defence whose advantage comes from model quality inherits the attacker’s rate of improvement rather than escaping it — and no public AegisAI document names which models it depends on, so the durability of that position cannot be assessed from outside.

Battery Ventures

Series A lead. No published thesis post on this investment found at time of research.

Foundation Capital

Seed co-lead. Its thesis post is the single most useful public document — and the source of the “on par with Mimecast” concession.

Safe Browsing & reCAPTCHA

The founders’ credential, and genuinely the right one. Both are internet-scale abuse-detection systems. Both were built at Google — now supplier, competitor and former employer.

SOC 2 Type II

Claimed on the company site. This is a controls audit, not a disclosure of who processes the data — the subprocessor list remains unpublished.

“10× Fewer False Positives”

Foundation Capital’s framing. Elsewhere stated as “up to 90% reduction” — the same claim made at seed in September 2025, unchanged after ten months of production data.

Ocean

Named by TechCrunch as a direct competitor. Raised $28M by May 2026. StrongestLayer raised $4.1M for reasoning-based email security on July 22 — the day before this round.

What “Dozens of Customers” Discloses

The gap between the seed announcement and this one is the most informative data in the file — because both are public.

01

The Reference List Barely Moved

September 2025: three paying customers, publicly naming Lokker and Mesh. July 2026: “dozens of customers,” publicly naming Lokker, Mesh and LangChain. Ten months and $36M later, two of the three named references are the same two, and the roster has grown by exactly one logo (DERIVED from the two announcements).

02

“Dozens” Is Doing Real Work

Foundation Capital’s thesis put deployment at “ten organizations.” “Dozens” is a word chosen instead of a number, and it is the only customer figure disclosed. No ARR, no seat count, no contract value, no net revenue retention, and no pricing appears in any source — and the enterprise logos in the investor thesis (SoFi, Robinhood, HP, Carlyle) are explicitly described as customer-discovery interviews, not customers.

03

The Performance Claim Never Updated

“Up to 90% reduction in false positives” was the claim in September 2025 with three customers, and remains the claim in July 2026 with dozens. A metric that does not move as the deployed base multiplies is a marketing constant, not a measurement. No methodology, sample size, or comparison baseline has ever been published.

Every alarming statistic in the announcement is AegisAI’s own. The 5× surge in AI-generated phishing (2.8% to 13.9%), the 72.6% of successful attacks passing authentication, the “more than half the time” inbox penetration — all trace to a single AegisAI study whose methodology is not published. SiliconANGLE, in its own coverage of the round, notes that the statistics come exclusively from the company and that no independent verification exists. The FBI’s $20.8B cybercrime-loss figure is real and independent; it is also not about AI spear phishing specifically.

The disclosure gap that matters most. AegisAI’s product requires read access to every inbound message at every customer — among the most sensitive data a company holds. Its published privacy policy is a website-visitor policy: it covers IP addresses, contact details and account credentials, states that the service is “hosted and operated in the United States,” and describes retention only as “as long as necessary.” It does not address customer email content, names no subprocessor, names no cloud provider, names no model vendor, and makes no statement on whether customer data is used for training. The trust center at trust.aegisai.ai returned no retrievable content. SOC 2 Type II attests that controls exist; it does not tell a buyer whose infrastructure their executives’ mail passes through.

Weaknesses & Threat Vectors

Seven structural risks that the $36M Series A does not resolve.

High

The Platform Owner Is the Competitor

API-only deployment into Microsoft 365 and Google Workspace means the supplier of the integration also ships the substitute — Defender for Office 365 is bundled into E5, and every buyer already pays for it. Platform owners can throttle, reprice or close the API, or narrow the capability gap for free. Addressed nowhere.

High

No Disclosure of Who Processes the Email

The product reads all inbound corporate mail. No subprocessor list, no named cloud, no named model vendor, no training-use statement, and an unretrievable trust center. For a security vendor this is the core purchasing artifact, and enterprise procurement will demand it before the logos AegisAI wants will sign.

High

Detection Parity Conceded by Its Own Investor

Foundation Capital’s thesis places detection “on par with Mimecast’s” and rests differentiation on false-positive rate. Operational efficiency is a real but shallow moat: it is the easiest axis for a better-capitalised incumbent to match, and it does not survive a single missed breach.

High

A Category Crowded at Every Capital Tier

Abnormal at a $5.1B valuation with ~$200M ARR and ~1,550 staff; Sublime at $243.8M raised and ~$926M; Material at $1.1B; Ocean at $28M; StrongestLayer raising the day before. AegisAI’s $49M is 104× smaller than Abnormal’s valuation (DERIVED) with no disclosed revenue to offset the gap.

Medium

Traction Disclosure Went Backwards

The seed gave a precise customer count; the Series A gives “dozens.” Two of three named references are unchanged after ten months, and the headline performance claim is identical to the one made with three customers. Vaguer disclosure against a larger round is a pattern worth pricing.

Medium

False-Positive Economics Cut Both Ways

The product auto-quarantines. One wrongly held wire instruction or board communication is a trust event that no aggregate accuracy statistic repairs, and the whole pitch is built on the false-positive axis. There is no public disclosure of override workflows, SLAs, or liability terms.

Medium

Defence and Offence Improve From the Same Curve

AegisAI’s advantage over rule-based filters comes from frontier-model reasoning. So does the attacker’s advantage over template phishing. Khormaee’s own framing — “a capable agent crafting a novel lure just for them” — describes a threat that scales with exactly the capability AegisAI depends on, from vendors AegisAI does not name. A defence indexed to model quality does not compound; it treads water faster.

Assessment Matrix

Team Credibility
High
Safe Browsing and reCAPTCHA leadership is the correct and rare pedigree for internet-scale abuse detection
Market Timing
High
AI-crafted social engineering is a genuine and growing threat, independent of AegisAI’s own statistics
Technical Differentiation
Low-Medium
Detection parity with Mimecast per its own investor; the edge is false-positive rate, self-measured
Traction Transparency
Low
“Dozens” replaces a number; two of three logos unchanged since seed; no ARR, seats or pricing anywhere
Platform Dependency Risk
High
API-only guest inside Microsoft and Google, both of which bundle the competing capability
Trust & Disclosure Posture
Low
Reads all corporate email; names no subprocessor, cloud or model vendor; trust center returns nothing
Competitive Moat
Low
Crowded at every tier from $4.1M to $5.1B; the differentiating axis is the easiest one to match
Capital Adequacy
Medium
$49M is real money for a 2025-founded company, and trivial against the incumbents it must displace
Investor Signal
High
Battery leading with Accel and Foundation both re-upping ten months after seed is a genuine inside vote

AegisAI has the right founders pointed at a real problem, and its existing investors re-upped after watching the company from the inside for ten months — the strongest signal in the file. But the round is announced on statistics the company generated about a market it sells into, a performance claim that has not changed since it had three customers, and a customer roster that has added one public name since the seed. The diligence question is not whether AI spear phishing is getting worse — it is. It is why a company whose product reads every executive email at every customer has published no list of who else touches that data, and what the business looks like the quarter Microsoft decides that closing the gap is cheaper than tolerating the ecosystem.

Research Sources

Based entirely on publicly available information, including the TechCrunch announcement of July 23, 2026. Every figure is labeled CONFIRMED, DERIVED or EST. in the body text.

  1. TechCrunch — “AegisAI, founded by former Google security execs, lands $36M to stop AI-driven spear phishing” (July 23, 2026)
  2. TechCrunch — “Google’s former security leads raise $13M to fight email threats before they reach you” (September 10, 2025); primary source for the seed-round baseline of three paying customers and six staff
  3. PR Newswire — AegisAI Series A release; source for the 5× AI-phishing figure, 72.6% authentication bypass, and “up to 90%” false-positive reduction
  4. SiliconANGLE — coverage of the round; explicitly notes the statistics originate exclusively from AegisAI’s own study with no independent verification
  5. Foundation Capital — “Our Investment in AegisAI”; source for detection “on par with Mimecast,” the “10× fewer false positives” framing, and deployment at ten organizations
  6. AegisAI company site — product, MX-free API deployment, named customers, SOC 2 Type II claim; no pricing and no vendor disclosure
  7. AegisAI privacy policy — primary source for the absence of subprocessor, cloud, model-vendor and training-use disclosure
  8. trust.aegisai.ai — fetched; returned no retrievable content at time of research
  9. CNBC and Abnormal AI — $250M Series D at $5.1B valuation; headcount and ARR estimates via third-party aggregators (EST.)
  10. Sublime Security — $150M Series C at ~$926M post-money, $243.8M raised in total, led by Georgian
  11. Material Security — $1.1B valuation from its 2022 round
  12. Ocean — $28M raised as of May 2026; named by TechCrunch as a direct AegisAI competitor
  13. SiliconANGLE — StrongestLayer’s $4.1M for reasoning-based email security, July 22, 2026
  14. FBI 2025 cybercrime report — $20.8B in losses; the one major independent market statistic cited in the announcement
  15. Searched without substantive result: G2 (403), Capterra, PeerSpot, Reddit, and any lawsuit, regulatory action, breach disclosure or critical coverage of AegisAI or its founders — no independent confirmation of any performance claim found