Why We Invested in Empirical: Building Global and Local AI Models for Cybersecurity
Empirical combines global threat intelligence with customer-specific context, taking vulnerability prioritization beyond traditional CVE scoring.
What We Believe About the Future
When we first met Empirical Security in the summer of 2025, we recognized something we rarely see: a founding team that not just understood a security problem intellectually, but one who had spent a decade living inside it. They had solved it once before at Kenna Security using data science and machine learning and are now coming back to address security problems in a far more ambitious, AI-model-centric way.
We believe the next generation of security is not a faster scanner or a better dashboard. It is unlocking domain-specific AI models. It’s an intelligence layer that combines security-specific global intelligence with local customer-specific environment context to prioritize what actually matters across multiple cybersecurity use cases. This would be a “security intelligence layer” that needs to be built by experts who understand both the statistical modeling, artificial intelligence, fine-tuning, and operational realities of enterprise security. And it requires a team like Empirical with institutional credibility to earn trusted access to a customer’s most sensitive security data to train local, custom AI security domain-models.
We are proud to announce that Brightmind Partners is leading Empirical Security's $25 million Series A. We are delighted to be joined by Costanoa Ventures, Hyde Park Angels, and a remarkable group of angel investors from across the security ecosystem. This round brings Empirical's total funding to $37 million, and we believe it is only their beginning.
The Product Itself: Global and Local AI Models
What impressed us most was Empirical architecture and the new technologies they are bringing to bear to solve countless ‘unsolved’ security problems. Effectively, the core of Empirical’s product and skillset is two concentric layers of “security AI intelligence” across their Global AI and Local AI models.
Empirical's Global AI Model is a continuously updating probabilistic scoring model. It is trained on years of highly-curated, finetuned, AI-mined, and globally-pooled data that no competitor has assembled at this depth. Scores recompute daily. And their Global Model gives customers the global “security artificial intelligence” needed to build defensible triage policies across multiple use cases.
Empirical's Local Models are where their real moat lies. Empirical trains a custom enterprise-specific cybersecurity domain model for each customer. It combines their Global Model signals with a customer’s specific telemetry. The result is a compliance-ready per-tenant Local Model that understands your specific infrastructure, based on what your assets look like, what controls you have deployed, and what activity your own telemetry shows. It’s not merely a rules engine or a workflow tool; it is a trained AI model built on your enterprise security data.
This distinction matters enormously compared to just building another prioritization tool, dashboard, or workflow engine. Empirical is the first company we’ve seen unlocking true “security AI intelligence” with a domain-model architecture that enables countless follow-on security use cases.
The Team That Invented Risk-Based Vulnerability Management Just Invented EPSS
The first problem Empirical is applying their "security AI intelligence" to is the question that Mythos and Fable-class models are forcing every modern enterprise to now answer: not just "what is vulnerable?," but "what is exploitable in my specific environment, right now, and what do I do about it?" Empirical realized while building their Global Models that CVSS is no longer enough. CVSS was a simple six-variable, static scoring system designed in 2005 to communicate severity of a vulnerability based on expert judgment. But it was never designed to predict exploitation probability.
EPSS (Exploit Prediction Scoring System) was built to solve this problem. EPSS is published openly through FIRST (Forum of Incident Response and Security Teams) and is now integrated into over 120 security platforms including CrowdStrike, Palo Alto Networks, Cisco, Tenable, Qualys, and Microsoft.
The people most responsible for building, publishing, and continuing to govern EPSS are Empirical's co-founders. Michael Roytman, Empirical's CTO, is one of the original EPSS authors. Jay Jacobs, Empirical's Chief Data Scientist, currently co-chairs the EPSS Special Interest Group at FIRST. And Ed Bellis co-founded Kenna Security in 2010, serving as CTO through Cisco's acquisition in 2021, and spent six years before that as CISO of Orbitz, giving him a practitioner lens on how security operators solve root problems. Every one of the 120+ platforms that ships EPSS as a feature is shipping a standard whose future direction is partly set by Empirical executives.
Our view is the original authors and continuing stewards of EPSS are the ones best positioned to operationalize it, particularly as Empirical’s Global and Local AI models extend beyond CVE-based scoring into use cases like cloud misconfigurations and application security findings. Overall, EPSS and Empirical’s decade-long proficiency in data science and fine-tuning is what gives Empirical the right, as a startup, to build the leading AI cyber-domain models among an industry of giants.
Anthropic's Endorsement
Further validation of Empirical’s EPSS framework and Global/Local AI model approach came from Anthropic. Upon releasing their Mythos-class models in April 2026, Anthropic published guidance for security teams preparing for AI-accelerated vulnerability discovery. They explicitly recommended patching CISA KEV vulnerabilities first, then working through CVEs based on EPSS, making EPSS the backbone of Anthropic’s recommended framework for the AI security era. This is the first time a major LLM provider has explicitly endorsed a purpose-built cybersecurity prioritization model.
Multiple Empirical customers even cited Anthropic’s endorsement as enabling their own security leadership to move forward with Empirical's platform. That kind of third-party credibility unprompted from one of the most important technology companies in the world is not something you manufacture. It is earned from fifteen years of hard work and deep insights by Empirical founding team.
We Are Proud to Lead This Round
The entire Brightmind team is excited to partner with the Empirical team to break longstanding barriers. We believe domain-specific AI models are the future of cybersecurity. And every product milestone Empirical committed to, they delivered. Every customer they said they would close, they closed. Every technical architecture they described, we were able to validate directly in our own Brightmind lab.
Empirical is building the future of domain-specific global and local AI models. And we’re incredibly grateful to be joining Empirical’s journey.