Breaking: the scanner found it - now comes the hard part Cogent has raised $53 million since 2025 Customers choose where autonomy stops Breaking: the scanner found it - now comes the hard part Cogent has raised $53 million since 2025 Customers choose where autonomy stops
Company profile / Cybersecurity

The Security Scanner’s Most Awkward Question: Who Actually Fixes This?

Scanners became very good at finding vulnerabilities. Cogent raised $53 million on the premise that the valuable part begins one minute later - when somebody has to decide what matters, persuade an owner to fix it, and prove the danger is gone.

Started2024
Raised$53M
The jobClose the loop

A vulnerability scanner is a bit like the friend who spots smoke at a dinner party, announces it loudly, and then goes home. The finding matters. But the finding is not the fire brigade. Somebody still has to identify the burning appliance, find the person allowed to unplug it, decide whether unplugging it will take down the kitchen, schedule the work, and return later to make sure the smoke is gone.

Cogent exists for that long, uncelebrated second half. The San Francisco company connects to the scanners, cloud systems, asset inventories, ticketing software, and engineering tools an enterprise already uses. Its AI agents reconcile duplicate findings, add the missing business context, identify the likely owner, draft a remediation plan, route the work, and validate the result. The pitch is not a prettier alarm. It is an operating team made of software.

That distinction explains a lot about the company: why its founders came from both machine learning and infrastructure, why investors moved from an $11 million seed in July 2025 to a $42 million Series A seven months later, and why its most revealing product behavior is wonderfully bureaucratic. If a scanner rescan or software-bill-of-materials rebuild says a fix did not hold, Cogent reopens the work item. In this system, “done” is evidence, not etiquette.

The loop Cogent wants to close
01Detect the exposure
02Rebuild the context
03Find owner and fix
04Execute within policy
05Verify or reopen

The first thing to fail is ownership

For years, security vendors competed to find more. More assets, more configuration errors, more vulnerable packages, more alerts. The unintended result was an immaculate backlog. A critical finding could arrive without a reliable answer to three ordinary questions: Is this system reachable? Who owns it? What will break if we patch it?

The human workaround is a relay race through spreadsheets, CMDB tags, Slack messages, Jira projects, maintenance calendars, and tribal memory. A large hospitality customer described spending more than 40 hours each month building PCI reports. Its analysts pulled scanner exports, made Excel pivots, used VLOOKUP to match assets to owners, and assembled slide decks that were already aging by the time executives saw them. Cogent connected the existing systems, inferred ownership from metadata and activity, and turned the static deck into a live view.

This is the company’s sharpest observation: a vulnerability is partly a software fact and partly an organizational mystery. CVSS scores can describe technical severity. They cannot tell you whether a server runs the checkout flow, whether a compensating control blocks access, whether Tuesday is a safe maintenance window, or which engineering manager will accept the ticket. Cogent’s “reasoning engine” is built to assemble that local context before recommending action.

“I’ve got enough tech that tells me what’s wrong. I don’t have enough tech that helps me fix it.”Customer interview, SACR Market Guide 2025

Three founders and the missing half of the job

Cogent was founded in 2024 by Vineet Edupuganti, Geng Sng, and Thanos Baskous. Edupuganti, the CEO, and Sng, the CTO, had helped scale Abnormal Security. Baskous, now vice president of engineering, had led infrastructure at Coinbase and served as chief architect at Blackstone. The combination matters. The product requires model builders who can make agents reason over untidy evidence, and operators who have felt the blast radius of a badly timed infrastructure change.

Their architecture reflects those biographies. Cogent says its real-time data layer borrows lessons from systems built at Abnormal to ingest enormous streams of email. On top sit specialized agents for distinct parts of the workflow. One agent can investigate. Another can generate a role-specific fix. Another can route the work. The model is the reasoner; the surrounding platform supplies permissions, memory, evidence, and limits.

Justin Yoshimura, CEO of CSC Generation
Justin Yoshimura runs CSC Generation, where new acquisitions bring new brands, new infrastructure, and fresh places for a vulnerability to hide. Cogent assessed Sur La Table’s environment within three hours of onboarding.

The company sells enterprise software through a demo-led motion; it does not publish list pricing. There is also a free product, Cogent Community, which turns public vulnerability and exploit feeds into a searchable intelligence stream. The paid platform sits above tools such as Tenable, Qualys, and Rapid7 rather than demanding that customers throw them away. This both lowers adoption friction and gives Cogent a clean competitive line: scanners collect findings; Cogent turns them into completed work.

97%

Average reduction in critical exposure windows reported across Fortune 500 users

5×

VM team output reported by University of the Pacific

3h

Onboarding to full Sur La Table assessment

Autonomy has a dial, not a switch

In May 2026, Cogent introduced Zero Day Response and Autonomous Remediation. In July it joined those pieces as Autonomous Vulnerability Response: detection, investigation, remediation, and validation in one continuous workflow. The system can match a fresh disclosure against software inventory before conventional scanner signatures arrive, build a fix, assess its likely impact, and send it through Jira or ServiceNow. If policy permits, it can execute.

The last sentence is where the story gets interesting. Security automation is easy to admire in a diagram and harder to approve beside a production database. Cogent lets customers define autonomous zones, approval gates, time windows, and rollback paths. A test environment may receive an automatic change. Critical infrastructure may stop at a fully prepared plan awaiting a person.

That boundary was not invented in a product brainstorm. Customers made it plain. Valvoline Instant Oil Change reported roughly an 80 percent reduction in response time for zero-day, P1, and P2 incidents, while its CISO also warned that autonomy without governance is difficult to defend to boards and auditors. The University of the Pacific similarly kept a human role around patches to critical infrastructure. Speed changed their appetite for automation; accountability set the ceiling.

A security leader speaking in Cogent's customer interview series
The look of a person who has seen enough vulnerability spreadsheets for one lifetime. Cogent’s customers describe the product less as an oracle than as relief from context gathering and follow-up.

The approach also has conditions. It works best where the underlying inventory is rich enough to reason over, integrations expose trustworthy evidence, owners can be identified, and the organization is willing to encode change policy. An AI agent cannot conjure a maintenance window nobody has defined. It cannot safely automate a brittle system whose dependencies are unknown. For Cogent, better reasoning raises the value of operational hygiene; it does not abolish the need for it.

The part anyone can copy

Cogent’s platform is specific, but its operating logic travels. A security team does not need an agent workforce to stop rewarding the wrong finish line. It can borrow the company’s most useful habits:

  • Measure verified risk removal, not tickets created or findings acknowledged.
  • Attach ownership, business impact, dependencies, and evidence before handing work to engineering.
  • Separate routine changes from high-consequence systems, then automate each class to a different level.
  • Require an independent rescan or inventory rebuild before declaring victory.
  • Treat exceptions as structured, expiring decisions rather than permanent notes in a spreadsheet.

The broader bet is that vulnerability management is becoming less like analytics and more like operations. Cogent’s competitors are not only security vendors. They are the improvised systems inside enterprises: the spreadsheet, the weekly meeting, the heroic analyst who knows which Slack channel will answer, and the quiet assumption that a closed ticket means a closed hole.

That is why the company’s geometric loop is an unusually honest logo. Detection is merely the first segment. Context, ownership, approval, execution, and proof must connect before the shape closes. The scanner’s awkward question finally has an answer: the person fixes what only a person should; the agent handles the rest; and neither gets to call it finished until the evidence agrees.