Lean SuperIntelligence raises an undisclosed pre-seed for on-prem cyber models

Founder Chandra Khatri is pairing offensive vulnerability discovery with defensive threat response; LSI says a limited group of design partners can test the models now.

By · Published

Primary source: PR Newswire

Why it matters

LSI is making customer-controlled deployment part of its technical thesis: a paired attacker-defender system trained on private code and telemetry. Its benchmark claims and financing details remain too thin to establish performance or investor conviction, so design-partner results will carry the proof.

Lean SuperIntelligence’s on-prem cyber models are represented by a compact server rack as a technician checks and secures its network cables.

Lean SuperIntelligence (LSI) says it has closed a pre-seed round and opened limited access to two on-prem cybersecurity models, betting that enterprises will want AI security tools trained on their own code and telemetry. The October 9th announcement describes LSI-Offense-1, which finds and validates vulnerabilities, and LSI-Defense-1, which detects and responds to threats.

The bet comes from Chandra Khatri (@chandra_pkhatri), LSI's founder and CEO, whose career has moved through several attempts to bring AI into real products. He worked on conversational AI at Amazon's Alexa group, led AI work at Uber, and co-founded Got It AI, where he developed enterprise language-model and hallucination-detection products. Before LSI, he was founding head of AI at Krutrim, where LSI's announcement says he built India's first sovereign LLM in 2023. His personal site also describes work at eBay and the Alexa Prize.

That background makes LSI's deployment choice central to its pitch. Khatri says customers should be able to run customizable models inside their own networks, including in air-gapped environments, instead of sending sensitive software and security telemetry to a cloud provider. "You cannot defend against an attack you have never seen. So we trained the Offense LLM first," he said in LSI's announcement. LSI says discoveries from the offense model become training lessons for the defense model, while successful defenses push the offense model to find new attack paths.

Diagram of LSI's stated feedback loop: LSI-Offense-1 findings become training lessons for LSI-Defense-1, while successful defenses lead the offense model to seek new attack paths.
LSI says its offense and defense models improve through a feedback loop; the announcement provides no independent results to verify the claim — AI explanatory diagram, not documentary evidence. RuntimeWire · AI-generated diagram.

The offense-defense loop is the product claim

LSI is trying to combine two security jobs that are often bought separately: offensive testing that searches for exploitable weaknesses, and defensive systems that triage alerts and support incident response. LSI says LSI-Offense-1 can scan software changes continuously, while LSI-Defense-1 can investigate threats and return verdicts in seconds. LSI describes both as available to a limited set of security vendors, managed security service providers, selected large enterprises, and government teams. Those are design-partner deployments, not evidence of broad commercial use.

The release also says the models outperform frontier systems on independent offensive benchmarks and public defensive benchmarks, naming Claude Mythos, GPT-6, and Gemini-3.8-Cyber as comparison points. It provides no benchmark names, scores, datasets, model configurations, or model sizes. The performance and cost advantages therefore remain LSI's claims; the announcement does not give readers enough information to reproduce the comparisons or judge how much of the result comes from the models versus their testing setup.

The funding announcement has a similar gap. LSI calls the financing an initial pre-seed round but gives no amount or valuation and does not identify a lead investor or a complete list of participants. The release says its backers include investors and angels with leadership experience at OpenAI, CrowdStrike, SentinelOne, Zscaler, Commvault, and Gruve AI. Lu Zhang, Fusion Fund's founder and managing partner, praises Khatri in the announcement; that endorsement alone does not establish Fusion Fund as a named round participant.

A crowded market for autonomous testing

LSI enters a market where companies are already selling AI-assisted offensive security. XBOW announced a $120 million Series C in March 2026 for its autonomous offensive-security business. Horizon3 announced a $250 million Series E in August at a valuation above $2 billion, describing a platform that autonomously tests customer environments. Those companies establish that investors are funding automated security testing at scale. LSI's proposed distinction is the linked defense model and customer-controlled deployment, not simply an AI system that looks for vulnerabilities.

For Khatri, the move extends a recurring focus on building AI systems around the data and workflows customers already have. At Alexa and Uber, the work centered on conversational products; at Krutrim, it involved sovereign AI infrastructure and foundation models. LSI carries that control thesis into security, where source code and telemetry can expose much more than routine business data. The design is appealing to enterprises that cannot readily send that information to an external service, but on-premise delivery also puts the burden on LSI to show that its models can be installed, maintained, and updated effectively within varied customer environments.

The next proof point is practical: whether design partners can use the paired models to find vulnerabilities that matter and improve defensive response without generating costly false alarms. LSI's announcement offers broad benchmark conclusions, but no scores or customer results with which to test them. The initial financing funds a founder's attempt to make security AI both adversarial and customer-owned; the technical evidence and deployment record will determine whether that architecture earns a place in security teams' budgets.

Reader comments

Conversation for this story loads after sign-in.