The software vulnerability crisis has reached a tipping point—at least according to federal watchdogs—and a small Seattle startup thinks it has found a way to help companies dig out from under the mounting backlog.
Emphere, barely five people strong, announced a $2.1 million pre-seed round Thursday led by AI2 Incubator and Outsiders Fund. The company automates the remediation and patching of container vulnerabilities, a technical headache that has become increasingly difficult to manage as the volume of known security flaws spirals beyond what most engineering teams can handle manually.
The urgency is backed by numbers that are, frankly, alarming. A May 26, 2026 report from the U.S. Department of Commerce Inspector General found that the National Vulnerability Database enrichment backlog—essentially, the queue of unprocessed security flaws waiting for detailed analysis—ballooned from around 13,000 in June 2024 to more than 27,000 by the end of 2025. The report projects over 60,000 new vulnerabilities in 2026 alone, nearly ten times the volume recorded a decade ago.
For software vendors selling into banks, healthcare systems, or other heavily regulated industries, that backlog isn't just an abstract metric. It's a compliance crisis. "Remediation is going to be as important as detection," Emphere CEO Ankit Kumar told GeekWire at the announcement. "Customers' clients won't accept your software if it has a single critical vulnerability."
Kumar and co-founder Pallav Gupta—former roommates at Northeastern University who went on to secure infrastructure at Uber, CarGurus, and Twitter—spent the last year building a platform designed to patch the container images companies already rely on. That may sound incremental, but it's a meaningful departure from competitors like Chainguard, which raised $356 million at a $3.5 billion valuation in April 2025 by asking customers to adopt its own purpose-built secure images. Emphere, by contrast, works with whatever you're already running.
The technical approach is straightforward, if labor-intensive. Emphere scans base images and dependency stacks, tracking upstream releases for components like OpenSSL, Python, and NGINX. When a new version ships—often patching a newly disclosed vulnerability—the platform triggers what the company calls "cascade rebuilds," signs the updated images with cosign, and integrates with customer CI/CD pipelines. The service supports Ubuntu, Debian, Alpine Linux, Amazon Linux, and Red Hat UBI, along with hardened images for widely used services including NGINX, Redis, and RabbitMQ.

Perhaps more telling than the automation itself: Emphere employs two security researchers whose sole job is to attack the company's own patched images to confirm the fixes actually hold. It's a level of internal skepticism that speaks to how tricky vulnerability remediation can be—and how high the stakes are if a patch introduces new problems or fails to close the hole it's meant to seal.
The company has landed early revenue and a handful of signed customers, though it hasn't disclosed names. Kumar and Gupta plan to use the pre-seed capital to expand that customer base and continue platform development. Emphere claims its workflow can deliver up to 85 percent faster remediation from detection to deployment, though those figures come from the company's own marketing materials published seven months ago and haven't been independently verified.
AI2 Incubator, which launched an $80 million Fund III in October 2025, now backs roughly 70 ventures and offers portfolio companies access to up to $1 million in dedicated AI compute credits. Outsiders Fund, co-founded by Datto founder Austin McChord and based in New York, lists Emphere in its portfolio as a 2025 founding.

Whether Emphere can carve out meaningful market share in a crowded and well-capitalized security landscape remains an open question. But if federal projections hold—and vulnerability volume continues its steep climb—the company may have picked the right moment to wade in.
