Startup Spotlight: Cotool turns security investigations into reusable AI agents

Cotool, founded by former Material Security operators, builds configurable agents for security teams. It raised a $7.4M seed led by a16z in March 2026.

By · Published

Primary source: Y Combinator

Why it matters

Cotool's founders are turning direct security-operations experience into configurable agents that fit around existing tools. Early customer use is company-reported; the time-savings claims still need clearer measurement and independent validation.

Startup Spotlight: Cotool turns security investigations into reusable AI agents — Founded by former Material Security operators, Cotool gives security teams configurable agents across detection and response, backed by a $7.4M seed raised…

Max Pollard and his co-founders built Cotool around a security team's familiar bottleneck: analysts spend hours gathering context across tools before they can decide whether an alert matters. The San Francisco startup turns those investigations into configurable AI agents that can be reused across detection and response. Cotool says the product is in production at companies including Ramp and EliseAI. Its Y Combinator profile describes the company as an active Spring 2025 batch startup; its product site presents the platform as a way to automate repeated security work without requiring teams to surrender control of their workflows.

Pollard, Cotool's CEO, previously led forward-deployed engineering at Material Security, where Y Combinator says he grew the team from one engineer to eight while working directly with security organizations. His co-founders bring adjacent parts of the stack: CPO Eddie Conk led machine-learning engineering at Material Security after an ML engineering role at Apple, and CTO Logan Carmody was an early engineer and technical lead on Material's phishing-protection product after working on infrastructure at LinkedIn. Cotool's YC launch post says the three had worked together for years before starting the company in 2025.

The founders draw on different parts of that experience: Pollard worked with security teams, Conk worked on models for detecting phishing, and Carmody helped build detection infrastructure and tools. Their pitch is grounded in those jobs: security work is full of repeated investigations, disconnected tools and documentation that consumes the time of experienced practitioners. Cotool is trying to package that accumulated practitioner judgment into software its customers can configure themselves.

From investigation to reusable workflow

Cotool's initial product description focused on three jobs: an AI copilot that gathers context across security tools, a no-code agent builder that turns successful investigations into repeatable automations, and report generation. The company's detection product description now extends that idea to detection engineering. A user can describe a threat model in natural language, and Cotool says its agents can search across connected environments, including tools without centralized log visibility. The system can also help create and tune rules for an existing SIEM, so a security team doesn't have to replace its detection stack.

Diagram of Cotool’s described copilot-to-automation process, with report generation shown as a separate product job.
Cotool describes a copilot for gathering context, a builder for turning successful investigations into repeatable automations, and report generation — AI explanatory diagram, not documentary evidence. RuntimeWire · AI-generated diagram.

On the response side, Cotool's agent controls let customers choose an agent's prompt, model, tools and output format, and trigger it through an API, webhook or scheduled process. The product also describes run evaluations, version history and structured outputs intended to help teams inspect how agents performed and restore earlier configurations. These are capabilities Cotool describes, not an independent assessment of agent accuracy. The controls address a harder problem in security operations: a fast answer is useful only if a team can understand what produced it and decide when to trust it.

Pollard has described that restraint as a product requirement. In a May 2026 discussion hosted by Material Security, he gave an example of an agent identifying unusual API calls from devices stolen from a delivery truck and preparing to wipe them. The same action could cause serious damage if the affected device were miscategorized. Teams therefore need to review an agent's findings and keep consequential actions within their approval process. Cotool's response page describes configurable behavior and structured outputs; the account of the stolen devices came from the event host, not an independently audited product test.

Cotool centers its product on the agent, not a new dashboard. A successful investigation can become a repeatable process; a detection gap can become a new rule or agent; and a low-performing run can be reviewed and used to adjust a later version. That workflow gives security practitioners a role in shaping what the software does. It also leaves customers responsible for evaluating whether the automation is dependable enough for their environment.

The founders' first proof point is time saved

Cotool's Y Combinator profile says early users cut time spent on investigation and detection engineering by 70%. Its original YC launch description made a separate claim: early users reduced investigation time by 90%. The figures cover different activities, and the published descriptions do not give a sample size, baseline or measurement window that would allow readers to compare them. They should be treated as company-reported indicators of early use, not as independently verified productivity results.

In its March 5th, 2026 seed announcement, Cotool said its agents had completed more than 50,000 runs and were in production with teams at Ramp and EliseAI. Run volume shows that software has been used; it does not by itself establish how many customers deployed it, how often humans overrode an agent, or whether the runs improved security outcomes. Cotool has not paired that total with revenue, customer counts or a public accuracy measure in the cited materials.

A vendor-published customer account adds operational detail. In a March 11th, 2026 case study, EliseAI security engineers described Cotool as investigating alerts, assembling context and routing cases for human review. Senior Security Engineer Jake Skinner said, "By the time an alert reaches us, Cotool has already investigated, built the context, and triaged it. We make the final call." Winston Laoh, also a senior security engineer, said the system helped the team add tools without the same monitoring and configuration burden. The account describes a specific use case: first-pass investigation and detection coverage for a growing security team. It does not include independently measured time savings or a before-and-after error rate.

A security buyer can test an agent against a defined queue of investigations and judge whether it saves analysts time. Trusting it to take remediation actions requires a different threshold. A missed clue may prolong an investigation; an incorrect action such as disabling an account or wiping a device can interrupt business operations. Cotool's emphasis on configurable controls and reviewable runs addresses that adoption problem, while leaving customers to determine the level of autonomy appropriate for each workflow.

A product built to fit around existing tools

Cotool's product positioning has widened from investigation assistance to detection, response and threat hunting. Its detection page says agents can work alongside existing SIEM rules and map coverage gaps against the MITRE ATT&CK framework. The response page describes connections to security and business tools and permits teams to define the models and tools an agent can access. Cotool is asking buyers to add an agent layer across existing systems, while keeping the systems that collect logs, generate alerts or manage tickets.

Diagram showing Cotool’s agent layer alongside existing SIEM rules and systems, with connections to security and business tools and detection coverage mapped against MITRE ATT&CK.
Cotool describes an agent layer that works with existing systems and SIEM rules rather than replacing them — AI explanatory diagram, not documentary evidence. RuntimeWire · AI-generated diagram.

That can ease adoption in security organizations, where changing core monitoring systems can be difficult. It also gives Cotool a demanding integration and reliability task: assembling accurate context from multiple tools, maintaining appropriate permissions, and keeping agents useful as customer workflows change. A no-code builder can lower the barrier to adapting automation, but security teams still need to test agent behavior and own the consequences of the permissions they grant.

On March 5th, 2026, Cotool announced a $7.4M seed led by Andreessen Horowitz, with participation from WndrCo and angel investors. Cotool's site also lists Y Combinator and Homebrew among its backers. The round's valuation was not stated in the announcement. The financing gives the founders capital to build a product for enterprise security environments, where integrations, evaluation and customer trust are part of the core engineering job.

Cotool is entering a market where larger vendors are also spending heavily to expand agent-based security operations. Torq announced a $140M Series D in January 2026 and said the round valued it at $1.2B. Cotool and Torq differ in scale and product history, so the comparison does not measure Cotool's prospects. It does show that Cotool is competing for attention in a well-funded market where vendors commonly promise to automate the security operations center. Cotool's pitch centers on practitioner-configured agents with controls to inspect and improve their work, and the founders' experience building security products and working alongside security teams.

The founders' bet

The founders' central bet is that security teams can expand coverage by teaching software how to investigate and act within their own environments, instead of buying another fixed set of workflows. Their experience at Material Security informs that idea: the three had worked across customer engineering, machine-learning detection and security-product infrastructure. Cotool's configurable agents put that experience into software, while Cotool's customer references suggest teams are using it for live alert handling and detection work.

Teams will need to measure agent reliability across many runs before safely widening what agents are allowed to do. Cotool's product pages describe evaluations and run histories as part of the system, and its customer case study shows human review remaining part of the process. Publicly reported performance evidence is still early and Cotool-supplied. The work ahead for Pollard, Conk and Carmody is to turn their experience around security teams into a product whose outputs teams can verify and whose automation earns more responsibility over time.

Reader comments

Conversation for this story loads after sign-in.