July 23, 2026

Why We Invested in Empirical: Building Global and Local AI Models for Cybersecurity

By:
Brightmind Partners
Empirical Security is building domain-specific AI models for cybersecurity, founded on the belief that the next generation of security is not a faster scanner or a better dashboard but a security intelligence layer combining global threat intelligence with local, customer-specific environment context. The platform operates through two concentric layers: a Global AI Model, a continuously updating probabilistic scoring model trained on years of curated, globally-pooled data with scores recomputing daily, and per-tenant Local Models, custom enterprise-specific cybersecurity domain models trained on each customer's own telemetry, assets, and controls, which constitute the company's real moat. The first applied use case is exploitation prioritization, answering not just what is vulnerable but what is exploitable in a specific environment right now, extending beyond CVE-based scoring into cloud misconfigurations and application security findings. The founding team invented risk-based vulnerability management and EPSS itself: CTO Michael Roytman is an original EPSS author, Chief Data Scientist Jay Jacobs co-chairs the EPSS Special Interest Group at FIRST, and Ed Bellis co-founded Kenna Security, serving as CTO through Cisco's 2021 acquisition after six years as CISO of Orbitz. EPSS is now integrated into over 120 security platforms and was explicitly endorsed by Anthropic in its April 2026 guidance for AI-accelerated vulnerability discovery, the first time a major LLM provider has backed a purpose-built cybersecurity prioritization model. Brightmind Partners is leading Empirical's $25 million Series A alongside Costanoa Ventures, Hyde Park Angels, and angel investors from across the security ecosystem, bringing total funding to $37 million.

Empirical: Building Global and Local AI Models for Cybersecurity

What We Believe About the Future

When we first met Empirical Security in the summer of 2025, we recognized something we rarely see: a founding team that not just understood a security problem intellectually, but one who had spent a decade living inside it.  They had solved it once before at Kenna Security using data science and machine learning and are now coming back to address security problems in a far more ambitious, AI-model-centric way.

We believe the next generation of security is not a faster scanner or a better dashboard.  It is unlocking domain-specific AI models.  It’s an intelligence layer that combines security-specific global intelligence with local customer-specific environment context to prioritize what actually matters across multiple cybersecurity use cases.  This would be a “security intelligence layer” that needs to be built by experts who understand both the statistical modeling, artificial intelligence, fine-tuning, and operational realities of enterprise security. And it requires a team like Empirical with institutional credibility to earn trusted access to a customer’s most sensitive security data to train local, custom AI security domain-models.

We are proud to announce that Brightmind Partners is leading Empirical Security's $25 million Series A.  We are delighted to be joined by Costanoa Ventures, Hyde Park Angels, and a remarkable group of angel investors from across the security ecosystem.  This round brings Empirical's total funding to $37 million, and we believe it is only their beginning.

The Product Itself: Global and Local AI Models

What impressed us most was Empirical architecture and the new technologies they are bringing to bear to solve countless ‘unsolved’ security problems. Effectively, the core of Empirical’s product and skillset is two concentric layers of “security AI intelligence” across their Global AI and Local AI models.

Empirical's Global AI Model is a continuously updating probabilistic scoring model.  It is trained on years of highly-curated, finetuned, AI-mined, and globally-pooled data that no competitor has assembled at this depth.  Scores recompute daily.  And their Global Model gives customers the global “security artificial intelligence” needed to build defensible triage policies across multiple use cases.

Empirical's Local Models are where their real moat lies.  Empirical trains a custom enterprise-specific cybersecurity domain model for each customer.  It combines their Global Model signals with a customer’s specific telemetry. The result is a compliance-ready per-tenant Local Model that understands your specific infrastructure, based on what your assets look like, what controls you have deployed, and what activity your own telemetry shows.  It’s not merely a rules engine or a workflow tool; it is a trained AI model built on your enterprise security data.

This distinction matters enormously compared to just building another prioritization tool, dashboard, or workflow engine.  Empirical is the first company we’ve seen unlocking true “security AI intelligence” with a domain-model architecture that enables countless follow-on security use cases.

The Team That Invented Risk-Based Vulnerability Management Just Invented EPSS

The first problem Empirical is applying their "security AI intelligence" to is the question that Mythos and Fable-class models are forcing every modern enterprise to now answer:  not just "what is vulnerable?," but "what is exploitable in my specific environment, right now, and what do I do about it?" Empirical realized while building their Global Models that CVSS is no longer enough.  CVSS was a simple six-variable, static scoring system designed in 2005 to communicate severity of a vulnerability based on expert judgment.  But it was never designed to predict exploitation probability.

EPSS (Exploit Prediction Scoring System) was built to solve this problem.  EPSS is published openly through FIRST (Forum of Incident Response and Security Teams) and is now integrated into over 120security platforms including CrowdStrike, Palo Alto Networks, Cisco, Tenable, Qualys, and Microsoft.  

The people most responsible for building, publishing, and continuing to govern EPSS are Empirical's co-founders.  Michael Roytman, Empirical's CTO, is one of the original EPSS authors.  Jay Jacobs, Empirical's Chief Data Scientist, currently co-chairs the EPSS Special Interest Group at FIRST.  And Ed Bellis co-founded Kenna Security in2010, serving as CTO through Cisco's acquisition in 2021, and spent six years before that as CISO of Orbitz, giving him a practitioner lens on how security operators solve root problems.  Every one of the120+ platforms that ships EPSS as a feature is shipping a standard whose future direction is partly set by Empirical executives.

Our view is the original authors and continuing stewards of EPSS are the ones best positioned to operationalize it, particularly as Empirical’s Global and Local AI models extend beyond CVE-based scoring into use cases like cloud misconfigurations and application security findings.  Overall, EPSS and Empirical’s decade-long proficiency in data science and fine-tuning is what gives Empirical the right, as a startup, to build the leading AI cyber-domain models among an industry of giants.

Anthropic's Endorsement

Further validation of Empirical’s EPSS framework and Global/Local AI model approach came from Anthropic.  Upon releasing their Mythos-class models in April 2026, Anthropic published guidance for security teams preparing for AI-accelerated vulnerability discovery.  They explicitly recommended patching CISA KEV vulnerabilities first, then working through CVEs based on EPSS, making EPSS the backbone of Anthropic’s recommended framework for the AI security era.  This is the first time a major LLM provider has explicitly endorsed a purpose-built cybersecurity prioritization model.

Multiple Empirical customers even cited Anthropic’s endorsement as enabling their own security leadership to move forward with Empirical's platform.  That kind of third-party credibility unprompted from one of the most important technology companies in the world is not something you manufacture.  It is earned from fifteen years of hard work and deep insights by Empirical founding team.

We Are Proud to Lead This Round

The entire Brightmind team is excited to partner with the Empirical team to break longstanding barriers.  We believe domain-specific AI models are the future of cybersecurity.  And every product milestone Empirical committed to, they delivered.  Every customer they said they would close, they closed.  Every technical architecture they described, we were able to validate directly in our own Brightmind lab.

Empirical is building the future of domain-specific global and local AI models.  And we’re incredibly grateful to be joining Empirical’s journey.

Let's Secure Tomorrow, Together.

We're always looking for the next generation of cybersecurity innovators. Reach out to our team to start the conversation.

Start the Conversation