AegisAI Raises $36M Series A for AI Email Security
AegisAI has raised a $36M Series A led by Battery Ventures, with returning investors Accel and Foundation Capital participating. Announced on July 23, 2026, the round brings the San Francisco-headquartered email security company's total disclosed funding to $49M.
The company was founded in 2025 by former Google security leaders Cy Khormaee, now CEO, and Ryan Luo, now CTO. AegisAI uses customized language models and coordinated defense agents to evaluate the intent, identity, behavior, links, attachments, and context behind email threats instead of relying solely on signatures and static rules.
This is a funding story about distribution, but it is also a wager on a changing security boundary. Generative AI has made personalized social engineering dramatically cheaper to produce, while the FBI's 2025 Internet Crime Report recorded $20.877B in reported losses, including $3.047B tied to business email compromise. The broader implication is straightforward: email security must understand context at machine speed because attackers increasingly do.
What Happened
The Series A arrives less than a year after AegisAI announced a $13M seed round led by Accel and Foundation Capital. Battery Ventures leads the new financing, while both seed investors returned, creating a syndicate that combines fresh conviction with investors already familiar with the product and team. The company did not disclose a valuation or announce any new board appointments.
AegisAI says the capital will support three priorities: scaling its fleet of autonomous defense agents, accelerating the general availability of Vanguard, and expanding its enterprise go-to-market efforts. Those priorities define the execution challenge behind the headline. The company must translate technical credibility into repeatable enterprise deployments, demonstrate that Vanguard can investigate malicious content beyond the inbox, and build distribution in a market already served by well-established vendors.
The company says it has deployed with dozens of customers since its public launch in September 2025, naming Mesh, LangChain, and Lokker among its users. Those customer figures are company-reported, but they establish a clear operating premise: AegisAI is raising capital to expand from early adoption into broader enterprise deployment rather than to validate market demand.
Why AI Spear Phishing Changes the Defense Model
Traditional email security relies heavily on known malicious infrastructure, signatures, domain reputation, authentication protocols, and detection rules developed after attacks emerge. Those controls remain important, but AI-generated spear phishing targets a different weakness. Modern language models can gather publicly available information about victims, imitate the writing style of trusted colleagues or vendors, and generate unique lures quickly enough that yesterday's detection patterns provide little protection.
AegisAI's State of the AI Threat in Email study says the company analyzed more than 20,000 phishing, scam, and malware emails. It reported that AI-generated spear phishing increased from 2.8% to 13.9% of observed phishing attacks during 2025, that AI-generated phishing bypassed Gmail and Microsoft filters 50.3% of the time, and that 72.6% of successful AI spear-phishing emails passed DMARC authentication. These are AegisAI research findings rather than independent benchmarks, but they illustrate the specific gap the company is attempting to address.
The FBI data provides an independent measure of the financial consequences without validating any individual vendor's detection claims. Business email compromise generated more than $3B in reported losses during 2025, while phishing and spoofing accounted for nearly $216M. Authentication can verify that a message originated through trusted infrastructure, but it cannot determine whether the sender's account has been compromised or whether the underlying intent is legitimate.
The Product Bet: Context Over Static Rules
AegisAI says its platform coordinates multiple AI agents to evaluate email the way a human security analyst would, asking what the message is attempting to accomplish, who appears to be sending it, what behavior seems unusual, and whether embedded links or attachments support the narrative. The platform integrates with Microsoft 365 and Google Workspace through APIs without requiring MX-record changes, reducing deployment friction for organizations that do not want to reroute email through another gateway.
The company's next major product is Vanguard. According to the funding announcement, Vanguard follows suspicious links and attachments beyond the inbox, investigating cloaked websites, adversarial CAPTCHAs, and weaponized documents before returning a threat assessment. That capability matters because sophisticated phishing campaigns often contain no obvious malicious payload until the recipient reaches a protected webpage or opens a document specifically designed to evade automated analysis.
The technical thesis also introduces practical tradeoffs. Context-aware agents may detect novel attacks that static rules overlook, but enterprise buyers will still expect predictable false-positive rates, explainable decisions, strong privacy controls, and evidence that automated investigations operate safely at scale. AegisAI reports up to 90% fewer false positives than traditional security tools and says its platform provides reasoning for every decision, but those company-reported claims will need to hold across a broader and more diverse enterprise customer base.
The Founders and Investor Thesis
Cy Khormaee and Ryan Luo bring direct experience from Google Safe Browsing and reCAPTCHA, technologies designed to detect abuse across billions of users and millions of websites. AegisAI's company profile says Khormaee spent five years leading teams responsible for Safe Browsing, reCAPTCHA, and Web Risk, while Luo spent nine years at Google and modernized the core Safe Browsing phishing platform. That experience does not eliminate startup risk, but it gives the founders unusually relevant expertise in building adaptive security systems.
Dharmesh Thakker, the Battery Ventures General Partner associated with the investment, described the opportunity as addressing the growing mismatch between machine-generated attacks and legacy security tools. The investment thesis is straightforward: if attackers can personalize and iterate at machine speed, defensive systems must reason at a comparable pace. Accel and Foundation Capital returning after the seed round provides a second signal that the company's early technical and commercial progress justified a significantly larger investment.
The harder question is market structure. AegisAI is entering a competitive email security market that includes both established vendors and newer AI-native platforms. The company's argument is not that email security is underserved, but that much of the industry's prevailing architecture was designed for an earlier generation of attacks. As AI lowers the cost of producing highly personalized spear-phishing campaigns, AegisAI is betting that context-aware reasoning will become more valuable than static detection models alone.
What This Signals for Enterprise Security
The Series A reflects a broader shift from AI as a product feature to AI as both attacker and defender. Security vendors can no longer treat AI-generated language as cosmetic content surrounding a familiar payload. When the message itself becomes the exploit, identity, intent, relationship context, and behavioral analysis become essential detection signals.
For security leaders, the near-term decision is less dramatic than replacing every email gateway. The more practical question is whether existing defenses can identify a highly personalized message delivered through trusted infrastructure, explain why it represents a threat, and investigate what happens after a recipient clicks. AegisAI is betting that a coordinated network of AI agents can answer those questions with less manual tuning and fewer false positives.
The $36M financing gives the company more runway to validate that thesis through Vanguard's general availability, broader enterprise adoption, and measurable customer outcomes beyond its earliest deployments. The founders have highly relevant technical experience, the investors have committed meaningful capital, and the threat landscape is well established. What remains unproven is whether AegisAI can turn those advantages into a durable security platform before incumbent vendors evolve their own products around the same contextual approach.
Cybersecurity funding, last 30 days
DevCuration's funding database tracked 11 Cybersecurity rounds totaling $1.1B in disclosed capital over the past 30 days. Recent deals we covered:
- Workstreet Lands Coalesce Capital Growth InvestmentJul 25
- Abstract Raises $25M Series A to Rewire Security OperationsSeries A Extension · $25M · Jul 25
- StrongestLayer Raises $4.1M in Seed Extension FundingSeed extension · $4.1M · Jul 23
- Cisco Invests in Zafran Security’s AI Exposure PlatformJul 23
- Pulse Security Raises $8M Seed Round Led by Foundation CapitalSeed · $8M · Jul 19
Frequently Asked Questions
How does AegisAI differ from a traditional secure email gateway?
AegisAI says it uses customized language models and coordinated agents to evaluate intent, identity, behavior, links, attachments, and context. The platform connects to Microsoft 365 and Google Workspace through APIs without requiring MX-record changes.
What will AegisAI use the $36M Series A for?
The company says the funding will scale its autonomous defense agents, accelerate Vanguard's general availability, and expand enterprise go-to-market. The round therefore supports both product development and broader distribution.
Who founded AegisAI?
AegisAI was founded in 2025 by Cy Khormaee, its CEO, and Ryan Luo, its CTO. Both previously worked on Google security products including Safe Browsing and reCAPTCHA.
Why are investors backing AI-native email security now?
Generative AI makes targeted phishing cheaper and easier to personalize. The FBI recorded $3.047B in business email compromise losses in 2025, while AegisAI's company research says AI-generated phishing increasingly bypasses conventional filters.
What does AegisAI still need to prove after the Series A?
AegisAI needs to show that its reported detection and false-positive improvements hold across a larger customer base. It also must move Vanguard into general availability and compete against established email-security vendors.









