Armadin Secures $255.5M for Agentic Security Testing

Armadin, the cybersecurity startup founded by Mandiant creator Kevin Mandia, has raised $255.5 million in a Series B financing at a valuation of more than $2.5 billion. Andreessen Horowitz and Accel led the round, which follows a $190 million Series A completed in March.
The company has now raised more than $445 million in total. Bain Capital Ventures, Redpoint, 8VC, Ballistic Ventures, Google Ventures, In-Q-Tel, Kleiner Perkins and Menlo Ventures also participated in the Series B.
Always-on testing for the AI era
Armadin is positioning its product as an alternative to the traditional penetration-testing model. In a conventional engagement, external security specialists attempt to breach an organization’s systems and then deliver a report describing the weaknesses they identified.
Its approach uses always-on agentic swarms that attempt to chain vulnerabilities together to gain access. The stated aim is to give enterprises a way to discover and close security gaps before malicious actors can make use of them.
The company frames this as a response to the changing threat environment created by agentic technology. Its testing is intended to identify paths that attackers could use, including scenarios in which rogue agents are used against an organization.
Funding follows Mandia’s Mandiant exit
Mandia is best known for founding Mandiant, the cybersecurity company acquired by Google for $5.4 billion in 2022. Armadin’s financing gives the new company substantial backing only months after its first announced institutional round.
The investor list combines venture firms focused on enterprise software and security with Google Ventures and In-Q-Tel. Their participation underscores the scale of capital now being committed to security products designed around AI-era attack and defense techniques.
What enterprises should consider
Traditional penetration tests remain defined engagements with a report at the end, while Armadin is proposing a continuous process of testing potential attack paths. That distinction matters for teams deciding how to organize vulnerability discovery, prioritization and remediation.
For businesses, the practical implication is to evaluate whether continuous agent-based testing can fit alongside existing penetration-testing, security operations and remediation processes, with clear ownership for closing the weaknesses such testing exposes.

