There's a familiar scene playing out in corporate security offices: spreadsheets sprawling across multiple monitors, Slack channels pinging with the latest CVE alerts, auditors asking for evidence that was supposedly gathered six months ago. Mike Armistead has seen it enough times to know the problem isn't a lack of tools—it's that security chiefs are drowning in them.
So he's building what he calls an operating system for CISOs instead.
Pulse Security, the Los Altos startup Armistead co-founded with Robert Hipps, came out of stealth on July 15 with $8 million in seed funding led by Foundation Capital and joined by Zetta Venture Partners. The company's pitch is straightforward, if ambitious: deploy AI agents that can actually run the program-level workflows that consume a security leader's day—tracking control coverage, drafting board narratives, gathering audit evidence, reconciling vendor risks. Not just flag issues. Actually handle them.
It's a bold claim in a market that's seen plenty of "AI-powered" security tools amount to little more than rebranded dashboards. But Armistead and Hipps have done this before, which is perhaps why investors are paying attention.
The Respond Reunion
The founding team reads like a reunion of Respond Software, the security orchestration company that FireEye (later Mandiant) acquired in November 2020 for approximately $186 million in cash and stock. Armistead was CEO there too. Hipps, now president at Pulse, ran Mandiant Engineering through its eventual acquisition by Google and later led generative AI efforts across Google Cloud Security.
Nick Gilligan, Pulse's VP of Engineering, was Respond's first engineer before becoming a tech lead for Google Threat Intelligence, working on GenAI and personalization. For his go-to-market chief, Armistead pulled in Dan Lamorena, who spent two decades across Google, Mandiant, Respond, and Symantec—most recently helping launch Gemini for Google Cloud.
Before Respond, Armistead had co-founded Fortify Software, which HP acquired in 2010. The pattern suggests a team that knows how to build security companies that end up on acquirers' shopping lists.
But repeating that success means solving a different problem than the one they tackled at Respond. Back then, it was about orchestrating alerts. Now it's about operating an entire security program under conditions that have arguably become untenable.
The Volume Crisis

Consider the numbers. NIST reported a 263% increase in CVE submissions between 2020 and 2025, with the announcement made in April 2026. VulnCheck's Exploit Intelligence Report from earlier this year found that nearly 29% of the 884 vulnerabilities exploited for the first time in 2025 were already weaponized on or before their official CVE publication date.
Which means security teams are not only facing more vulnerabilities—they're facing vulnerabilities that are exploitable before they even know what they're called.
Pulse's bet is that this isn't a problem you solve with another point tool. You need, in the company's framing, a different kind of infrastructure entirely.
Context Graphs and Agentic Procedures

Here's where things get technical, and also where Pulse's approach starts to sound either visionary or a little too clever by half, depending on your tolerance for buzzwords.
The platform is built around what the company calls a "context graph"—essentially a unified data model that stitches together everything from risk registers and tech stack inventories to regulatory obligations, organizational priorities, and even unstructured data like communications. Think of it as a living map of what a security organization actually looks like, rather than what the org chart says it should.
Layered on top of that: AI agents running what Pulse terms "agentic-based procedures." These aren't chatbots answering questions. They're meant to autonomously execute workflows—reconcile which controls are actually deployed versus which ones are just documented, track exceptions that need board-level sign-off, pull evidence from disparate sources for auditors.
The company is targeting four use cases out of the gate. Security program health tracking. Continuous assessments against frameworks like NIST's Cybersecurity Framework. Vendor risk management. And then something more unusual: "Mythos readiness."
That last one refers to tracking risk exposure from Anthropic's Claude Mythos 5 model, which has apparently driven significant vulnerability discovery in controlled research programs since its limited rollout in mid-2026. The implication—though Pulse doesn't state this explicitly—is that AI-assisted vulnerability research is about to make the volume problem considerably worse. Better to be ready.
The company's website claims it can pull evidence from communications, structured data sources, security tools, and unstructured repositories to slash audit prep time and generate board-ready reporting. Whether it actually does this remains to be seen. Pulse isn't naming customers yet, though its launch blog post references "world-class design partners" across industries. Standard early-stage vagueness.
Why Investors Bit
Foundation Capital has been public about its thesis on "context graphs" as the missing infrastructure layer for agentic AI. The firm published thinking on this in January. Partner Sid Trivedi's statement in the press release hits the expected notes about operational chaos and intelligent automation.
Zetta Venture Partners Managing Director Apoorva Pandhi emphasized the team's track record—not an unreasonable thing to bet on, given the Respond exit.
The funding environment for AI-meets-security has been fairly active recently, though not frothy. ZeroDrift raised $10 million for what it calls a compliance firewall for AI systems in early June. Ocean pulled in $28 million in May for agentic email security. QIZ Security announced $17 million just days before Pulse for post-quantum cryptography posture management. Willow, focused on AI agent governance, raised $7 million in June.
There's clearly appetite for the category. Whether the category actually works is still being determined.
What Comes Next

Pulse plans to deploy the capital toward engineering and go-to-market expansion, naturally. The company is headquartered in Los Altos, California, and LinkedIn pegs headcount at 11 to 50 employees—a range wide enough to be almost meaningless, but likely skewing toward the lower end for a seed-stage company.
The team is also running something called the Security Impact Circle, a community for CISOs and security leaders that held sessions at RSA Conference earlier this year. Community building as a go-to-market motion isn't new, but it signals the company understands that selling to security chiefs often means building trust before you ever talk about contracts.
Valuation, prior funding if any, and revenue details remain undisclosed. Standard operating procedure for a company at this stage.
What's less standard is the central argument Pulse is making: that the CISO role has become unworkable under current conditions, and the solution isn't to hire more analysts or buy more tools. It's to fundamentally change how security programs operate.
Armistead and his team believe security leaders should function less like perpetual crisis managers juggling spreadsheets and more like executives with an intelligent layer that can ingest the chaos—vulnerabilities, audit requirements, vendor questionnaires, compliance obligations—and then autonomously act on it.
Bold? Certainly. Plausible? Perhaps more so than it would have been five years ago, before large language models made this kind of automation at least theoretically possible.
Whether Pulse can actually deliver on that vision is the $8 million question—or, more accurately, the question its investors are betting $8 million will eventually have a much larger answer.
