Skip to main content

đŸȘ Backed by $16.5M to build the security workforce for the security workforce. Meet the new Cantina.

The Next Chapter of Cantina

Why Cantina expanded from finding security issues to carrying security work through prioritized, remediated, and verified resolution.

Cantina 6 min read
Company news Clarion Agentic security Funding

We spent years believing we were solving one of the hardest problems in security: finding issues before attackers could.

That belief shaped everything we built.

But over time, it became clear that solving only half of the problem, finding security issues, wasn’t enough.

Today, we’re announcing new funding led by Framework Ventures, bringing Cantina’s total funding to $16.5 million, alongside the launch of Clarion and a new visual identity.

Clarion is our agentic security platform built to carry security work from discovery to verified resolution. It builds on what we started with Apex, our agentic OffSec engineer, which produces evidence-backed findings across the modern attack surface. Together, they reflect our broader belief that security cannot stop at finding the problem. The work has to be prioritized, remediated, and verified.

The funding, the product, and the new identity are all outcomes of the same shift in how we see the problem. This is the story of that shift, and how it changed Cantina.

Where It Started

Cantina began in digital assets, where a single vulnerability could result in the unrecoverable loss of millions or even billions of dollars.

Our thesis was simple: help teams find vulnerabilities before attackers did. That thesis led us to build Spearbit, a community of world-class security researchers, and later expand from one-time audits into competitions and bug bounty programs as customers asked for more continuous coverage.

The Gap We Couldn’t Ignore

Over the years, hundreds of organizations relied on us to find security issues before attackers did. We got really good at it. Our job was to find vulnerabilities. Their job was to fix them.

But the more we saw what happened after we handed over a finding, the harder it became to accept that our job ended there.

We watched the same pattern play out across the industry. In the Kaseya incident, researchers found critical vulnerabilities and worked with the company while fixes were developed and tested. Before the remaining fixes reached customers, attackers exploited the software. A few years later, Cleo released a security update, only for researchers to discover that systems running the updated version remained exploitable through a separate critical flaw. Exploitation was already underway.

Neither was a story about people ignoring security or being careless. The issues were known. The fixes were underway. In one case, the patch was already in customers’ hands. The work still wasn’t finished.

That changed how we thought about our own role. Finding the vulnerability first does not mean you stopped the attack. Until the issue is prioritized, remediated, and verified, the attacker still has a window.

A New Reality

Those incidents left us asking a different question: if defenders knew about the issue first, why did the attacker still win?

The answer was becoming clear. Discovery was getting faster, but resolution wasn’t. Teams had more alerts, findings, investigations, and remediations than they could reasonably carry. Every queue, handoff, tool pivot, and approval created more time for an attacker to move.

A year later, like most security companies, we devoured the 2026 Verizon Data Breach Investigations Report and saw numbers behind what we had already been seeing. Three findings stood out to us:

  • 71% of security incidents resulted in a confirmed breach, more than double the 32% rate in 2023.
  • For the first time in the report’s history, vulnerability exploitation overtook stolen credentials as the leading breach entry point.
  • Organizations fully remediated just 26% of critical known-exploited vulnerabilities, down from 38% the year before.

That first number isn’t a direct measure of how often incidents become breaches. The mix of incidents Verizon analyzes changes from one report to the next. But the broader picture was hard to dismiss: confirmed breaches made up a much larger share of the incidents analyzed, vulnerability exploitation has become the leading way in, and remediation was moving in the wrong direction.

The data matched what we were seeing. Teams were drowning in work.

At the same time, attackers weren’t slowing down. AI compressed the time between finding vulnerable targets and exploiting them. Security teams had no shortage of tools to find problems. What they lacked was the capacity to carry the work to completion.

We realized pretty quickly that we had to solve a security work problem, not just a vulnerability problem.

Expanding the Mission

We still believe deeply in discovery, and we continue to invest in Apex. Today, Apex ranks among the top hackers on HackerOne. Building it convinced us that AI could give security teams far more capacity to find real risk. It also reinforced something we had already learned the hard way: finding the issue first does not mean you win.

Across our customers, we kept seeing the same bottleneck. Teams had more alerts, findings, incidents, investigations, and remediations than they could reasonably handle. Even when they knew what mattered, the work still had to move through several people, tools, and queues before anything was actually fixed.

We also saw teams solving the same kinds of problems over and over. We didn’t think every security team should have to start from scratch.

We believe defenders need AI. But not as another assistant that waits for a prompt, or another tool that adds more findings to the queue. We think agents should take on the work itself.

Attackers are using AI to move faster from vulnerable code to exploitation. Defenders should be able to use it to move faster from finding an issue to resolving it, across AppSec, SecOps, and the rest of the work security teams do every day.

That is why we built Clarion. Clarion understands the environment it is operating in, including how assets, identities, systems, and security events connect. Its agents use that context to investigate issues, determine what matters, coordinate a response, remediate the problem, and verify the result.

Teams can create agents for their own environment and build on agents that have already solved similar problems. Those agents can filter false positives, escalate real issues, contain active threats, open pull requests, validate fixes, and bring people in when their judgment or approval is required.

We don’t think the future of security is another dashboard or an AI assistant waiting for instructions. We think every security team will have an agentic org chart working alongside it, with a level of autonomy the team controls. The agents take on the repetitive, time-consuming work. People stay focused on the decisions that require experience and judgment.

That is what we mean when we call Clarion the security workforce for your security workforce.

The Next Chapter

This funding allows us to keep building toward our vision. We’ll continue investing in Clarion, advancing Apex and our bug bounty offering, expanding our engineering and research teams, and pushing the boundaries of what AI can do for defenders.

As part of this next chapter, we’re also introducing a new visual identity for Cantina! It reflects the company we’ve become and where we believe security is headed.

Space exploration has always fascinated both of us (it’s why the original Cantina emoji was a planet!). The idea of stepping into new territory nobody had mapped before, of figuring out what’s out there and how best to deal with it - the whole deal. One common point that came up in our discussions was collective innovation. People didn’t get there alone. We built entirely new systems that allowed humans to do things that they never thought were possible.

That’s exactly how we think about security. AI has changed the landscape, and the old playbooks have broken down. It’s intimidating, but it’s also an opportunity to evolve. What’s going to help us get there is building the infrastructure that helps security teams explore and rise to what comes next.

To our customers, researchers, partners, employees, and investors: thank you for believing in what we’re building! Your trust has made this next chapter possible.

We’re just getting started.