The cybersecurity startup is betting that companies racing to deploy artificial intelligence will need help keeping track of it all—and perhaps even more urgently, keeping it under control.
ArmorCode, which builds what it describes as a governance platform for security teams, pulled in $16 million in new funding this week, led by Cheyenne Ventures. The Palo Alto company has now raised $81 million total since its founding, a trajectory that mirrors the growing anxiety among chief information security officers about visibility into their technology stacks.
The round included a familiar cast of enterprise security investors: Ballistic Ventures, Highland Capital, Sierra Ventures, NGP Capital, Harmonic Growth Partners, Tau Ventures, and Cervin Ventures all participated. But the timing—and what ArmorCode chose to announce alongside the capital—tells a more interesting story.
When AI Adoption Outpaces Oversight
On the same day it disclosed the funding, ArmorCode launched what it's calling an AI Exposure Management module. The idea is straightforward, if not exactly simple: give enterprises a way to actually see what AI systems are running across their organizations, who owns them, and whether they comply with internal policies.
It's a problem that sounds almost quaint until you consider the scale. CEO Nikhil Gupta cited projections of five trillion AI agents by 2030—a number that feels both staggering and somehow plausible given the velocity at which companies are experimenting with generative AI tools, coding assistants, and automated workflows.
"The need for independent governance has never been more critical," Gupta said, leaning into language that suggests enterprises may have gotten slightly ahead of themselves.
Security and compliance teams certainly seem to think so. As organizations spin up AI applications across departments—sometimes with IT's blessing, often without—the question of what's actually running where has become urgent. ArmorCode's pitch is that its 350-plus integrations can inventory those deployments and provide the audit trails that regulators and board members increasingly expect to see.
Whether that's enough to solve what is fundamentally a cultural and organizational challenge, not just a technical one, remains to be seen.
A CISO Who's Seen It All Before
ArmorCode also added Phil Venables to its board, a move that carries weight in security circles. Venables spent years as CISO at Google Cloud and, before that, Goldman Sachs—institutions where the intersection of innovation and risk management isn't theoretical. He's now a venture partner at Ballistic Ventures, which has backed ArmorCode since its Series A.
"ArmorCode is uniquely positioned to navigate the intersection of AI innovation and enterprise risk," Venables said, though one imagines he's also seen enough product pitches to know that positioning and execution are different things.
Still, the appointment signals something about where ArmorCode wants to be taken seriously: not just as another application security vendor, but as a governance layer for an increasingly complex technology environment.
Growth, But in a Crowded Market

The company says it's doubled revenue year-over-year and now processes more than 200 billion security findings annually. That's the kind of number that sounds impressive in a funding announcement—though it's worth noting that "processing findings" is not the same as resolving vulnerabilities or preventing breaches.
ArmorCode's platform combines application security posture management (ASPM) with unified vulnerability management, aiming to serve as what Gupta calls an "independent control plane" for security operations. The company was named a Leader in IDC's ASPM vendor assessment last fall, competing against players like Cycode and Apiiro in a market that has attracted considerable venture attention.
The new capital will go toward accelerating what ArmorCode describes as its "Agentic AI Platform," expanding sales efforts globally, and continuing product development around AI security and lifecycle management. In other words, the standard post-funding playbook: build faster, sell harder.
A Founder's Second Act
Gupta founded ArmorCode in 2020 with Anant Misra, not long after selling his previous company, Avid Secure, to Sophos in 2019. It's a track record that venture investors tend to like—a founder who's been through an acquisition and comes back for another swing.
The company maintains offices in Palo Alto and Bengaluru, India, and has pursued a channel-first go-to-market strategy, distributing through AWS, ServiceNow, and CrowdStrike marketplaces. Chief Product Officer Mark Lambert has driven much of the product strategy around what the company calls agentic AI, though the term itself has become something of a catchall in enterprise software circles.
ArmorCode's funding history traces a fairly rapid ascent: an $11 million seed in early 2022, a $14 million Series A later that year led by Ballistic Ventures, then a $40 million Series B in late 2023 from HighlandX. The latest round, while smaller than the B, suggests the company is being selective about dilution—or perhaps that the funding environment has cooled enough that strategic capital matters more than headline valuation.
Either way, ArmorCode is betting that enterprises overwhelmed by the pace of AI adoption will need help governing what they've built. Whether that bet pays off likely depends less on the platform's technical capabilities and more on whether organizations can muster the discipline to actually use governance tools before things go sideways.
In cybersecurity, that's always the harder problem to solve.
