Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsKevin Mandia, who founded Mandiant, launched Armadin on March 10, 2026, with $189.9 million in combined seed and Series A financing. The new company is building autonomous AI agents that continuously emulate attackers, validate exploitable attack paths and guide remediation for enterprise security teams.
Accel led the financing. GV, Kleiner Perkins, Menlo Ventures, In-Q-Tel, 8VC and Ballistic Ventures also participated. Armadin disclosed no valuation, revenue, customer count or public pricing. Armadin’s announcement and TechCrunch’s report describe the launch and financing.
What was announced
| Item | Disclosed detail |
|---|---|
| Company | Armadin |
| Announcement and launch | March 10, 2026 |
| Financing | $189.9 million, combining seed and Series A rounds |
| Lead investor | Accel |
| Other participants | GV, Kleiner Perkins, Menlo Ventures, In-Q-Tel, 8VC and Ballistic Ventures |
| Valuation | Not disclosed |
The headline figure is best described as $189.9 million in combined seed and Series A funding, rounded to $190 million. The announcement does not break out how much came from either round, say whether both closed simultaneously, or state how much equity investors received.
Armadin calls the financing the largest combined seed and Series A raise in cybersecurity history. That is a company claim, not an independently audited industry record. TechCrunch noted that individual early-stage rounds by companies such as 1Password and OneTrust reached $200 million in 2019, although those businesses were older or further along.
#1 Best Overall
Who Kevin Mandia is
Mandia founded Mandiant in 2004 as an incident-response and cyber-investigations company. FireEye acquired Mandiant in 2014 in a transaction reported at about $1 billion; Google later acquired the Mandiant business from FireEye for approximately $5.4 billion in 2022, according to TechCrunch. Mandia later became a venture investor at Ballistic Ventures before returning to operating a cybersecurity company.
Armadin lists Mandia as CEO and names Travis Lanham, Evan Peña and David Slater as co-founders. The company presents the group as a mix of experienced red-team operators, former Google security engineers and AI-system builders. Those credentials help explain investor interest, but they do not by themselves prove the new platform’s accuracy, safety or customer value. Armadin is a separate startup, not a Mandiant or Google spinoff.
What Armadin is building
Armadin describes its product as a continuous, agentic red-team and remediation platform. Its central proposition is different from a scanner that lists possible vulnerabilities: software agents are intended to reason across an environment, test whether weaknesses can be chained together and show whether an attacker can reach a meaningful objective.
1. Reconnaissance
The platform says it maps an organization’s attack surface, enumerates hosts, profiles people and analyzes defensive controls.
2. Adaptive scouting
Agents probe multiple weaknesses in parallel, learn from defensive responses and refine their routes rather than following only a fixed script.
3. Precision strike
The final phase is intended to validate attack paths toward objectives such as domain compromise, ransomware, sensitive-data access, hypervisor or backup-server compromise, and web-application compromise. The company’s platform overview describes these phases and the related safety controls.
In practical terms, Armadin sits across several categories: exposure validation, automated red teaming and autonomous offensive security. It is not simply an AI vulnerability scanner, and it is not the same as a product designed to protect AI models from prompt injection or data leakage.
Why investors may see an opportunity
Machine-speed attacks
Mandia’s thesis is that increasingly capable AI could automate reconnaissance, discovery, adaptation and attack execution, compressing the time defenders have to respond. That is Armadin’s strategic framing, not an independently established forecast. The company sets out the argument in its launch post.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Rank #3
Too many findings, too little proof
Security teams already receive vulnerability lists, alerts, configuration findings and risk scores. The harder question is whether a particular weakness is exploitable in a specific environment, against its actual controls, and connected to an objective that matters. Continuous attack simulation is intended to provide that evidence.
Limited human red-team capacity
Penetration testing and red teaming remain valuable but are periodic, expensive and constrained by scarce expertise. Armadin’s pitch is that agents can scale portions of that work continuously while human operators supervise high-risk decisions and interpret results.
A notable investor mix
Accel and other major venture firms supplied mainstream startup capital, while Ballistic Ventures brings a cybersecurity-specialist connection and In-Q-Tel signals interest from the national-security investment ecosystem. In-Q-Tel participation is not government certification or an endorsement of Armadin’s effectiveness.
What remains unproven
Armadin’s platform page reports 339,000 agents launched against real targets, zero false-positive findings and a fastest path to domain compromise of 119 seconds. These are company-published figures. The public material reviewed does not provide a detailed methodology, target definitions, sample size, customer names, independent evaluation or reproducible benchmark. They should therefore be treated as reported marketing metrics, not neutral industry measurements.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteRank #4
The financing also does not establish product-market fit. Public announcements do not disclose named customers, revenue, renewals, deployment volume, post-money valuation or commercial outcomes.
The safety problem is as important as the detection claim
A system that behaves like an attacker can create harm if it reaches the wrong asset, uses an unsafe exploit or moves laterally beyond its authorization. A serious enterprise evaluation should require clear answers on:
- How targets are authorized, scoped and verified before testing.
- Whether customers can set allowlists, denylists, time windows, rate limits and objectives.
- Which actions require human approval and how a kill switch works.
- How the platform avoids destructive actions and protects fragile production systems.
- What credentials, payloads, screenshots and sensitive data it stores.
- What audit logs, replay evidence and retention controls are available.
- How prompt injection, unsafe tool calls and model errors are contained.
- Whether deployment can run in a customer-controlled cloud or environment.
- What contractual liability, insurance and incident-response terms apply if testing causes an outage.
Armadin refers publicly to guardrails, controlled execution and scoped impact, but the available materials do not fully specify these controls. Buyers should not assume that autonomous testing is safe for every production, operational-technology or regulated environment without a documented pilot and approval process.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How this differs from adjacent security products
| Category | Primary purpose | How Armadin is positioned |
|---|---|---|
| Vulnerability scanner | Identify possible weaknesses | Attempts to validate whether weaknesses can be chained into exploitable paths |
| Breach-and-attack simulation | Repeatedly test security controls against known scenarios | Emphasizes adaptive agents that pursue objectives and respond to defenses |
| Traditional penetration test | Human-led assessment during a defined engagement | Seeks continuous software-driven testing augmented by red-team expertise |
| Exposure-management platform | Prioritize assets and risks across an environment | Focuses on proving attack paths, not only ranking exposure |
| AI-agent security product | Protect models, agents, prompts, data and permissions | Uses AI to conduct offensive testing rather than primarily securing AI applications |
Potential alternatives include established validation and exposure vendors such as Pentera, SafeBreach and XM Cyber, as well as penetration-testing firms and managed services. Pentera’s public materials emphasize agentless security-control validation and evidence of exploitable risk; its platform datasheet and Resolve datasheet do not publish prices. Public information is not sufficient to declare feature parity or superiority between these products and Armadin.
Best Value
Armadin has also announced an external attack-validation relationship with Palo Alto Networks’ Unit 42 and an integration effort with CrowdStrike under “Project QuiltWorks.” The announcements describe partnership plans, not proof that every customer can access a generally available feature. See the Unit 42 announcement and CrowdStrike announcement.
What enterprises should ask before buying
- Scope: Confirm coverage for external assets, internal networks, cloud, identity, endpoints, SaaS and applications—not just the environments shown in a demo.
- Proof: Require reproducible attack steps, timestamps, affected assets and evidence that distinguishes a real compromise path from a theoretical one.
- Autonomy: Document approval gates, boundaries, rate limits, safe modes and emergency shutdown procedures.
- Operational safety: Test how the system behaves around fragile production systems, third-party services, regulated data and segmented networks.
- Remediation: Verify that findings produce specific fixes and integrate with ticketing, vulnerability-management, SIEM, EDR and SOAR workflows.
- Data handling: Ask where credentials, exploit output and sensitive evidence are processed and retained, and whether data residency requirements are met.
- Deployment: Compare SaaS, private-cloud, customer-hosted and hybrid options.
- Commercial terms: Establish whether pricing is based on assets, environments, subscriptions, engagements or managed services. Armadin currently directs prospects to a request-a-demo page; no public price or self-serve plan is disclosed.
- Human oversight: Determine what expert red-team support is included and whether the product augments rather than replaces experienced operators.
Bottom line
Armadin has launched with exceptional early financing, a prominent founder and an ambitious thesis: autonomous agents could continuously prove which security weaknesses form real attack paths. The disclosed facts establish a $189.9 million combined seed and Series A round led by Accel, not a valuation, customer base or independently verified performance record.
For enterprises, the investment case is compelling only if Armadin can demonstrate safe authorization, reproducible evidence, useful remediation and reliable operation at scale. Until independent testing and commercial results are public, the company is best understood as a well-funded entrant in autonomous offensive security—not a proven replacement for scanners, penetration testers or security teams.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




