Cantina has emerged from stealth with $8m in fresh capital as it seeks to help organisations close the widening gap between how quickly attackers exploit vulnerabilities and how slowly defenders can fix them.
The round was led by Framework Ventures and lifts Cantina’s overall funding to $16.5m. The platform is designed to help organisations uncover, rank and resolve security issues at machine speed, moving beyond detection to actually driving problems through to remediation.
The company was established by seasoned security researchers and engineers with long experience hunting vulnerabilities and protecting critical software systems. Their work exposed them to how AI was speeding up and sharpening attacks, putting defenders under mounting pressure.
Cantina now serves customers spanning healthcare, financial technology and other regulated sectors, ranging from mid-market firms to Fortune 500 enterprises. The team also holds trusted access with OpenAI and takes part in Anthropic’s Cyber Verification Programme, granting it early insight into model capabilities that are transforming both offence and defence.
The launch comes as the economics of hacking shift dramatically. Historically, exploiting a flaw demanded considerable skill and time, meaning many weaknesses were never targeted. AI has slashed that barrier.
The 2026 Verizon Data Breach Investigations Report found that vulnerability exploitation surpassed stolen credentials as the top breach entry point for the first time in the study’s 19 years. Meanwhile, just 26% of critical known-exploited vulnerabilities were fully fixed last year, a fall from 38%, and half of ransomware victims had credential exposure flagged before being hit. In short, organisations often know their weak points but cannot act fast enough.
Cantina argues that spotting a flaw is merely step one. Teams must then establish who owns the affected system, gauge the genuine risk, coordinate fixes across engineering, and verify that the issue is truly closed. Most firms still handle this manually, with thousands of security teams duplicating the same investigations and playbooks in isolation.
Cantina’s platform lets customers automate security work from discovery through to remediation using ready-made agents, bespoke agents, or proven agents shared by other customers in its community.
It constructs a continuously updated model of each customer’s environment, mapping entities such as Okta users, servers, GitHub repositories, AWS IAM roles and databases containing customer PII, alongside business context including system ownership, recent changes and prior investigation findings.
This shared context underpins how the platform decides which issues need urgent attention and gives teams a single, live view of risk. Each investigation deepens the platform’s knowledge, so accuracy improves over time rather than resetting with every alert. Rather than churning out more findings, the focus is on surfacing the issues that genuinely matter and resolving them to the standard of a staff-level security engineer.
The platform’s core capabilities include a Security Memory Layer, which maintains a dynamic digital twin of an organisation’s cybersecurity, technology and compliance environment; Risk Prioritisation, which ranks issues by business risk; Autonomous Remediation, which automates investigation, coordination and remediation workflows; and Verified Resolution, which confirms fixes have landed and keeps auditable evidence.
Cantina CEO and co-founder Hari Mulackal said, “AI has dramatically accelerated the pace of attack. Attackers can identify vulnerabilities, understand systems, and build exploits faster than ever before. Security teams cannot keep responding with workflows built for a pre-AI world. Defenders need AI that doesn’t just identify problems, but helps investigate them, coordinate remediation, validate fixes, and continuously gets smarter with every issue it resolves.”
Copyright © 2026 FinTech Global









