The $4.5M Bet on Rewriting How Security Gets Done

Published
September 1, 2026
Written by
Share
The $4.5M Bet on Rewriting How Security Gets Done
Contents

Security has spent the last twenty years adding more.

More tools. More dashboards. More alerts. More people staring at all of them.

And somehow, the work keeps piling up.

That is the problem we saw when we looked at Secure.com. Not a lack of security software. A lack of security capacity.

So Disrupt.com led a $4.5 million pre seed round in Secure.com.

We are backing a simple but fundamental shift in how security gets done.

The work moves to AI Teammates. Control stays with the team.

Secure.com calls it Governed Defense, Powered by Offense.

And we think it points to where cybersecurity is going next.

Security does not have a tooling problem

Most security teams already have plenty of tools.

SIEM. EDR. Cloud security. Identity. Vulnerability scanners. Code repositories. Ticketing systems.

The problem is everything that happens between them.

A signal appears. Someone has to investigate it. Someone has to understand the context. Someone has to decide whether it matters. Someone has to open the ticket, chase the fix, gather the evidence, close the loop, then prove the risk actually went away.

That work compounds.

A four person security team feels it because there are never enough hands.

A hundred person team feels it because the work gets lost between tools, teams, specialists, queues, and handoffs.

Different scale. Same problem.

Security has a capacity problem.

And AI is making the other side of the equation worse.

Attackers can increasingly automate discovery, research, targeting, and exploitation. Offense is starting to scale like software.

Defense cannot respond by simply hiring people at the same rate.

It needs a different operating model.

What if the software did the work?

That is the idea behind Secure.com.

Its AI Teammates do not just surface information for a human to deal with later. They take responsibility for defined security work across Red Teaming, SOC, AppSec, Cloud Security, and GRC.

They investigate.

They correlate.

They follow through.

They gather evidence.

They support remediation.

They keep going until the work is done, or until a decision reaches a point where a human should take over.

That distinction matters.

This is not about giving AI uncontrolled access to your security environment. Each Teammate operates inside customer defined scope, permissions, policies, approvals, escalation paths, and evidence controls.

The work moves.

Authority does not.

That is why we believe the word governed matters as much as the word AI.

Security doesn't have a talent problem. It has a capacity problem. The goal is to move repetitive work to AI Teammates so people can spend their time on the judgment, architecture, and risk decisions that actually need them. — Uzair Gadit, Founder and CEO, Secure.com

Governed Defense, Powered by Offense

This is where Secure.com gets particularly interesting.

Most offensive security ends with a finding.

A vulnerability is discovered. A report gets produced. Another ticket enters another backlog.

Secure.com closes the loop.

The Red Teammate tests the environment like an attacker, inside an approved scope, and validates what is actually exploitable.

Not what might be vulnerable.

What can actually be attacked.

That evidence then moves directly into defense.

The SOC Teammate can sharpen detection and response. The Cloud Security Teammate can harden the exposed configuration. The AppSec Teammate can trace the weakness into code and support the fix. GRC can carry the resulting evidence into assurance and control workflows.

Then the environment gets tested again.

Attack. Harden. Prove. Repeat.

That is Governed Defense, Powered by Offense.

Offense is no longer a separate exercise that produces a report every few months. It becomes part of a continuous system for making defense stronger.

Every attack creates information.

Every fix improves the environment.

Every new test proves whether it worked.

Then the cycle starts again.

Above the Stack, Not Another Stack

This was another important part of the thesis for us.

Enterprises do not need another cybersecurity migration project.

They have already invested heavily in their existing stack. Secure.com is designed to work above it.

Its AI Teammates connect signals, context, decisions, actions, and evidence across the tools already in place.

Because the bottleneck is rarely the absence of telemetry.

The bottleneck is the work between telemetry and a decision.

Between a decision and an action.

Between an action and proof.

That is where human capacity disappears.

Secure.com puts AI Teammates into those gaps.

The existing stack stays.

The work starts moving.

The key to a teammate that actually delivers is twofold. It must be able to work independently, which means getting the balance of agency and oversight right. And it must slot easily into how teams already work. — Omer Bhutta, Head of AI and ML, Secure.com

Fewer alerts is not the goal

Security has talked about alert fatigue for years.

The obvious answer is to reduce the number of alerts reaching analysts. But there is a dangerous version of that idea: make the queue smaller by hiding more things.

Secure.com takes a different approach.

The queue gets smaller because more work happens before something reaches a human.

AI Teammates can assess signals, correlate them with surrounding activity, connect them to assets, identities, vulnerabilities and business context, then preserve the evidence behind what they did.

Attack Paths push this further.

Instead of treating every vulnerability as an isolated item with a severity score, Secure.com can connect vulnerabilities, identities, configurations, and exposures into potential routes toward critical systems.

Then the Red Teammate can test which routes actually work.

That changes the question from:

What looks dangerous?

to:

What can actually hurt us?

And that is a much better question.

Cutting noise becomes a problem when nobody looks at what disappears. With an AI Teammate doing the groundwork, signals can still be assessed and recorded before they leave the analyst's queue. Responders act faster not because visibility disappeared, but because the work has already been done. The queue gets smaller. The evidence trail does not. Asad Tariq, Founding Member and Security Leader, Secure.com

Humans should do the human work

There is a lazy version of the AI conversation that turns everything into a debate about replacing people.

That is not what interests us here.

Security teams contain expensive, highly trained people spending extraordinary amounts of time on work that does not require their best judgment.

Evidence chasing. Console stitching. Case follow through. Audit preparation. Routine investigation. Repetitive remediation.

AI should eat that work.

Humans should spend more time on architecture, threat strategy, risk, judgment, and the decisions where accountability actually matters.

Secure.com is not removing humans from security.

It is moving them up the stack.

Routine work can move inside policy. Consequential actions can stop at the human gate.

AI gets agency.

The customer keeps authority.

Why we made the bet

At Disrupt, the companies that interest us most are not using AI to make an existing workflow slightly faster.

They are asking a more uncomfortable question.

What if the workflow itself is now wrong?

That is the question Secure.com is asking about cybersecurity.

For years, the industry has built better tools for humans to operate.

Secure.com is building AI Teammates that can operate those environments alongside them.

That is a structural change.

And structural changes are where we like to build.

Secure.com isn't adding another tool to a stack that's already drowning in tools. It's changing where the work gets done. That's the kind of structural bet we make for every category we build at Disrupt.com. — Ali Samir Oosman

We believe the next era of cybersecurity will not be defined by how many alerts a team can see.

It will be defined by how much security work can actually get done.

Without scaling headcount in a straight line.

Without replacing the stack.

Without handing uncontrolled authority to AI.

Governed Defense, Powered by Offense.

The work moves to AI Teammates.

Control stays with the team.

And every cycle makes the defense stronger.