Most security teams face the same problem. There are far more flaws than anyone can fix, and no clear way to know which ones matter. Empirical Security wants to predict the answer.
The Chicago startup’s Series A was led by Brightmind Partners, chief executive Ed Bellis told Axios, which first reported the round. It takes total funding to $37 million. Earlier backers Costanoa Ventures and Hyde Park Angels returned for the round.
Unfinished business
The pitch has history. Bellis and his chief technology officer, Michael Roytman, built Kenna Security, the firm that helped popularise risk-based vulnerability management. The idea was simple: stop treating every flaw the same, and focus on the ones most likely to be exploited.
It helped, but the job was never done. The backlog kept growing as cloud, SaaS, APIs, and third-party code piled on new exposure. Bellis calls Empirical his “unfinished business.” He has brought in Jay Jacobs, co-creator of the widely used EPSS exploit-scoring system.
Two models
Empirical sells two predictive models. Foundation is the global one. It watches more than 18,000 CVEs with real exploitation activity, tracking what attackers are actually using across the internet.
Radiant is the local one. It trains on a single organisation’s own assets, telemetry, and cloud setup, then predicts the threats most relevant to that environment. Foundation tells you what is happening globally, Bellis says, and Radiant tells you what is likely to matter to you.
Why now
The timing is not an accident. AI is speeding up the pace at which attackers find and exploit weaknesses, and the window to respond keeps shrinking. It can even run breaches on its own.
Attackers now turn newly disclosed flaws into working exploits faster than ever. Bellis argues the defence has only just caught up. Three years ago the data was too fragmented and the modelling too immature to try this properly.
That has changed. Security data lakes now pool telemetry that once sat in separate systems. Better AI can mine and reason over huge volumes of signal, and models can be trained against real-world exploitation rather than static severity scores.
A crowded field
Empirical is not alone in selling AI-driven defence. A steady run of security startups has raised on the promise of taming AI-era risk, part of a wider scramble to secure the AI-agent era. Exposure management is a crowded market, and $25 million is modest by its standards.
The performance claims, for now, are the company’s own. One customer says its engineers are “addicted” to checking the tool daily, a nice line that still needs independent proof. The bet is that prediction, tuned to each organisation, beats another generic risk score.
Prediction, Bellis argues, has become a requirement for modern defence, not a luxury.
Get the TNW newsletter
Get the most important tech news in your inbox each week.
