Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Root Evidence launched on July 28, 2025, with an oversubscribed $12.5 million seed round led by Ballistic Ventures. The Boise, Idaho-based cybersecurity startup says it is building an enterprise platform that combines vulnerability scanning and attack-surface management, then prioritizes findings using evidence of exploitation, breach impact, and financial loss.
The financing gives Root Evidence substantial backing, but it does not yet establish public pricing, broad commercial availability, named customers, valuation, or independently validated product results.
What Root Evidence announced
Root Evidence said it was founded in July 2025 and launched with a $12.5 million seed financing. Ballistic Ventures led the round, with Grossman Ventures and other cybersecurity investors participating. The company’s announcement carries a July 28, 2025 dateline. Its newsroom later labels the page September 25, 2025, so those dates should not be confused with a second funding event.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Fortune independently reported the same financing, including Ballistic’s lead role and Grossman Ventures’ participation. Root Evidence described the round as oversubscribed, although it did not disclose a valuation, ownership split, revenue, or a complete investor list.
#1 Best Overall
The problem the startup is targeting
Security teams routinely receive more vulnerability findings than they can fix immediately. Conventional scoring can help organize that queue, but a high technical-severity score does not necessarily mean a weakness is reachable, exploitable in a particular environment, or likely to cause material business damage.
Root Evidence says this creates a budgeting and prioritization problem for CISOs: teams may spend scarce engineering time on theoretical risk while missing weaknesses with stronger evidence of real-world consequences. The company also points to difficulty maintaining visibility across an organization’s internet-facing assets and translating technical findings into financial terms.
That is Root Evidence’s diagnosis of the market, not an independently established conclusion about every organization. Risk still depends on asset exposure, privileges, identity controls, segmentation, business criticality, compensating controls, and the organization’s ability to remediate safely.
What “root evidence” means
“Root evidence” is the company’s own product and risk-management terminology. In its launch material, it refers to the strongest proof that a vulnerability was:
Rank #2
- exploited in the wild;
- involved in a reported breach; and
- associated with material financial loss.
The proposed model therefore looks beyond a vulnerability’s theoretical severity and asks whether there is evidence that it has produced meaningful harm. Root Evidence says well under 1% of known vulnerabilities statistically matter. That figure must be treated as a company assertion: the announcement does not define the denominator or publish the data and methodology behind it.
How the proposed platform is different
Root Evidence says it is not simply another CVSS sorter, a list of items from the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog, or a new severity-score algorithm. Its stated goal is to connect vulnerability and attack-surface findings to evidence of exploitation and estimated financial risk, so teams can focus remediation on weaknesses most likely to produce significant harm.
The company describes an integrated vulnerability-management and attack-surface-management platform that is still being developed. The public launch announcement does not document its data sources, weighting model, false-positive rate, detection approach, supported integrations, scanning cadence, or independent performance results. It also does not say that the product replaces existing scanners, CVSS, or KEV workflows entirely.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWhy an evidence-first model could help—and where it can fail
The appeal is practical. If a security team cannot patch everything, stronger evidence of exploitation or financial impact could make the remediation queue more defensible to executives and boards. A financial-risk view may also help CISOs explain why a particular control or engineering project deserves funding.
But historical evidence is backward-looking. A newly disclosed vulnerability may be dangerous before public breach records appear. Public incident reporting is incomplete, financial losses are often confidential, and a vulnerability can become important through a combination of moderate findings or an organization-specific attack path.
An evidence-first system therefore needs credible handling for zero-days, new CVEs, private incidents, supply-chain weaknesses, rapidly changing exploitability, and sensitive systems where the potential loss is unusually high even without a documented precedent. The launch announcement does not explain how Root Evidence addresses those cases.
Financial-risk claims still require scrutiny
Root Evidence says it can help organizations calculate financial risk, but it has not publicly described the model. Prospective customers and investors would reasonably want to know whether the output is a probable loss, a maximum-loss estimate, or a range; which customer inputs are required; and how the calculation treats downtime, ransom, legal exposure, notification costs, regulatory penalties, lost revenue, cyber insurance, backups, segmentation, and compensating controls.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →They would also need to know whether estimates can be audited and explained to a board, regulator, or insurer, and whether the model has been calibrated against historical incidents. No such validation data appears in the launch announcement.
Rank #4
The founding team
The named founding team is:
- Jeremiah Grossman, CEO
- Robert “RSnake” Hansen, CTO
- Heather Konold, COO
- Lex Arquette, CPO
Root Evidence presents the group as experienced cybersecurity entrepreneurs. Grossman previously co-founded WhiteHat Security, later worked at SentinelOne, and co-founded Bit Discovery. Hansen, Konold, and Arquette are also associated with the earlier WhiteHat Security and Bit Discovery teams. The announcement says Bit Discovery was acquired by Tenable in 2023; it does not mean every founder held the same role at each company.
Why Ballistic Ventures invested
Ballistic Ventures’ Roger Thornton said the firm viewed vulnerability management as an outdated market with significant room for a new approach. Thornton is identified as a Ballistic general partner and as the founder of Fortify Software and AlienVault. His comments explain the investor thesis, but they are not independent validation of Root Evidence’s product performance.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the seed capital is expected to fund
Root Evidence says the money will support product development, its roadmap, enterprise adoption, and an expanded design-partner program. The company also said it had early interest from large enterprises, including several Fortune 500 organizations.
That is not the same as having named paying customers, production deployments, disclosed contract values, or proven retention. The announcement names no customers and gives no revenue, pipeline, valuation, or allocation breakdown for the $12.5 million.
Best Value
What remains unknown
- Whether the platform is generally available or limited to design partners.
- Supported cloud, SaaS, container, identity, API, endpoint, application, and network assets.
- Authenticated, unauthenticated, agent-based, or agentless scanning methods.
- Discovery and treatment of shadow IT.
- Integrations with ticketing, SIEM, SOAR, EDR, cloud, and patch-management systems.
- Pricing, deployment options, data-handling terms, and service commitments.
- Independent measurements of prioritization accuracy, remediation speed, or reduced loss.
Organizations interested in the design-partner program were directed to [email protected]. The company’s official site is the appropriate source for later availability or pricing updates.
What the funding means for the market
The round reflects investor interest in moving vulnerability management away from raw finding counts and toward exploitability, attack paths, business impact, and remediation outcomes. Root Evidence is entering a market where established tools already collect extensive technical data, so its differentiation will depend on whether its evidence and financial modeling improve decisions in live enterprise environments.
As of August 18, 2026, the supplied public record does not establish a later funding round, acquisition, IPO, public pricing change, or named customer announcement. The seed financing is meaningful support for the company’s thesis, not proof that the thesis has been validated.
Recommended Free Tools
Frequently Asked Questions
When did Root Evidence launch?
Root Evidence announced its launch and seed financing on July 28, 2025. Its newsroom page later shows a September 25, 2025 publication label for the announcement.
Who led Root Evidence’s seed round?
Ballistic Ventures led the oversubscribed $12.5 million seed round. Grossman Ventures was also named as a participant, along with other undisclosed investors.
Does Root Evidence publish pricing or customer names?
The reviewed announcement does not disclose public pricing, a valuation, or named customers. It refers to enterprise interest and design partners, which should not be treated as proof of paying production deployments.
The Bottom Line
Bottom line: Root Evidence has a credible founding team and substantial seed backing for an evidence-based approach to vulnerability and attack-surface management. Its eventual market position will depend on showing, with transparent methodology and independent results, that its prioritization and financial-risk estimates help enterprises remediate faster and reduce measurable business risk.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

