Developers love their new AI coding assistants. Security teams? Not so much.
That tension—between the breakneck speed of AI-assisted development and the compliance bureaucracy that still moves at a human pace—is what a small team in Malmö, Sweden, thinks it can resolve. Oplane, an eight-person startup with deep roots in threat modeling, just closed a €4.5 million seed round (roughly $5.2 million) to build what it calls an "automated security architect" for companies drowning in AI-generated code.
The round, announced June 2, 2026, was led by Seed Capital, Denmark's largest seed-stage venture firm, with participation from Helsinki's Icebreaker.vc and a cluster of angel investors who know their way around both enterprise security and complex systems. Among them: Emil Eifrem, who co-founded and still runs Neo4j, and Robert Lagerström and Joakim Nydrén, the duo behind Foreseeti, a threat modeling platform Google Cloud eventually acquired.
That investor roster isn't accidental. Oplane's founding team spent the better part of two decades in cybersecurity before deciding the old playbooks weren't cutting it anymore.
When the Code Writes Itself, Who's Watching?
CEO Emil Kvarnhammar logged over 15 years in threat modeling and cybersecurity, including a stretch as deputy CEO at TrueSec. CTO Oscar Andersson has a similar pedigree and ranks among Stack Overflow's top contributors—a detail that matters more than it sounds, given how much trust developers place in community-vetted expertise. CPO Anders Söderling previously co-founded Position Green, which Norvestor acquired in 2021.
The pitch is straightforward, if ambitious: as tools like Cursor, GitHub Copilot, and Claude Code become standard issue for engineering teams, someone needs to make sure the architecture underneath all that generated code doesn't become a compliance nightmare. Or a security one.
Oplane's platform continuously maps application architecture, runs threat modeling at both the repository and pull request level, and surfaces findings directly in developers' workflows. One-click fixes, inline comments, the works. It's less about flagging individual vulnerabilities line by line—traditional static analysis tools do that already—and more about modeling architecture-level threats and tying them to the compliance frameworks that keep CISOs up at night: FDA/MDR, PCI DSS, SOC 2, ISO 27001, DORA.
The language Oplane uses is telling. "Audit-ready evidence." "24/7 governance." These aren't phrases meant for developers. They're aimed at the executives navigating the awkward intersection of AI velocity and enterprise risk management, where moving fast and breaking things is no longer an option.
A Category Taking Shape

Perhaps the timing is more deliberate than it appears. In December, security researchers disclosed over 30 vulnerabilities across major AI coding platforms, some enabling data exfiltration and remote code execution. GitGuardian's 2026 annual report pegged 29 million secrets leaked on GitHub in 2025, with AI adoption flagged as an accelerant. Meanwhile, OWASP formalized its Top 10 risks for LLM applications and updated the list again in May, a sign that frameworks for AI system security are hardening faster than anyone expected a year ago.
Oplane lists production deployments at collaboration platform Miro and healthcare technology firm Tandem Health, where adoption reportedly scaled from a handful of repositories to several hundred over a matter of months, with thousands of threat models generated along the way. Miro's CISO, Mark Strande, appears on Oplane's enterprise solutions page, though the specifics of his endorsement weren't detailed in available materials. The company also names Remotive Labs and Lightbringer as customers, though the extent of those deployments is less clear.
What's evident is that Oplane is building for regulated industries—places where evidence trails and audit documentation matter as much as shipping velocity. Maybe more.
Room to Grow, and Competition

The threat modeling space has seen movement. ThreatModeler raised $60 million from Invictus Growth in mid-2024 and acquired competitor IriusRisk in early January. Microsoft continues to invest in its open-source Threat Modeling Tool, with a release last November. But Oplane is betting that a new category of tooling is emerging for teams that have already crossed the threshold into agentic, AI-first development—where the old approaches don't quite map.
The seed capital will fund go-to-market expansion across Europe and deeper integrations with Claude Code, Cursor, and GitHub Copilot. The company is hiring across engineering, cybersecurity, quality assurance, and sales roles. Eight people is a small crew for automating what has traditionally been a painstaking, manual process. Then again, most startups betting on AI infrastructure are.
Whether Oplane can scale fast enough to stay ahead of both the technology and the competition remains an open question. But for now, at least, the founders seem convinced that someone needs to be watching while the code writes itself.
