San Francisco—In an industry that often evangelizes the clean slate, three former Material Security engineers are taking a different approach. Their startup, Cotool, has raised $7.4 million in seed funding on a premise that might sound almost blasphemous in the rip-and-replace world of enterprise tech: What if companies didn't have to gut their security infrastructure to get smarter?
Andreessen Horowitz led the round, which was announced in early March and included Y Combinator, WndrCo, Homebrew, and a cluster of angel investors from Okta, Ramp, Cloudflare, Amplitude, and Sumo Logic. The pitch is deceptively simple. Deploy AI agents across the security tools already humming away in the background—SIEMs, data lakes, endpoint detection systems, identity platforms, cloud monitoring—without migrations, without rewrites, without the months-long implementation nightmares that make CISOs wince.
It's a wager that enterprises, weighed down by compliance mandates and vendor lock-in, might prefer intelligence draped over their existing mess rather than another promise of transformation.
The Material Connection
All three co-founders cut their teeth at Material Security, the email protection startup that Cloudflare snapped up in what has quietly become one of the more instructive acquisitions in recent security history. Max Pollard, now CEO, ran forward deployed engineering there, growing the team from a single engineer to eight. Logan Carmody, the CTO, was an early technical hand who built out phishing protection. Eddie Conk, who leads product and AI, spent his time training large-scale machine learning models on phishing data—work that, one imagines, involved more than a few sleepless nights staring at malicious payloads.
They went through Y Combinator's Winter 2025 batch before closing this funding. Perhaps more than the founders expected, the demo day pitch resonated.
Already Running in Production
Cotool isn't just a deck and a demo. The platform is live with teams at Ramp and Elise AI, among other world-class security teams, where it's logged north of 50,000 agent runs across detection, triage, investigation, and response workflows. That's the kind of volume that suggests the technology has moved past proof-of-concept into something resembling operational trust.

The architecture lets security teams construct both copilots—tools that suggest next steps—and fully autonomous agents that act without waiting for a human to click approve. Under the hood, there are system prompts, context management layers, structured outputs, audit trails. Automatic evaluations refine performance over time. The platform even includes detection engineering with MITRE ATT&CK framework coverage, for teams that speak that particular dialect of security operations.
It calls into ticketing systems, identity providers, and the rest of the toolchain that security teams have spent years stitching together.
Why Now?
The timing isn't accidental. A survey from Sumo Logic last year found that nearly three-quarters of security leaders were rethinking their SIEM strategies, with nine in ten prioritizing AI in whatever came next. Microsoft, smelling blood in the water, rolled out AI-powered SIEM migration tools earlier this year—a tacit acknowledgment that moving from one security platform to another remains painful enough to require its own tooling.
Cotool's approach, the company argues, neatly sidesteps the entire problem. No migration needed. No vendors to placate or contracts to renegotiate. Just a layer of intelligence that, in theory, makes everything underneath a little less noisy and a little more responsive.
For CISOs juggling budget cycles, compliance audits, and boards increasingly anxious about breach headlines, that kind of pragmatism may land differently than yet another pitch to modernize the stack.
What Comes Next
In a LinkedIn post accompanying the announcement, Pollard laid out the roadmap in characteristically straightforward terms: double down on what's working and get it into more teams, hire exceptional builders and sellers, take big bets on new product areas. The company is still small—LinkedIn suggests somewhere between two and ten employees—but seed capital has a way of accelerating those timelines.

Whether Cotool can deliver on the promise of making legacy security infrastructure smarter without requiring enterprises to burn it all down remains, of course, an open question. But in a market exhausted by transformation theater, sometimes the most radical idea is just making what you already have work a little better.
