Cotool builds configurable AI agents to automate repetitive security investigations
Security analysts often waste hours stitching together data from disparate tools before they can assess an alert.
Cotool, a San Francisco startup founded by former Material Security engineers, is building configurable AI agents to automate those repetitive investigations.
The company emerged from Y Combinator’s Spring 2025 batch and already reports production use at firms such as Ramp and EliseAI.
CEO Max Pollard previously expanded Material Security’s forward‑deployed engineering team from one to eight engineers while working directly with security operations groups.
Co‑founder Eddie Conk led machine‑learning engineering at Material Security after a stint at Apple, and CTO Logan Carmody was an early engineer on Material’s phishing‑protection product following infrastructure work at LinkedIn.
Their combined experience informs Cotool’s focus on three pain points: duplicated investigations, fragmented tooling, and the need for documentation that captures expert judgment.
Cotool’s platform is described as an AI copilot that gathers context across security tools, a no‑code builder that turns successful investigations into reusable automations, and a report‑generation engine.
Users can describe a threat model in natural language, prompting agents to search connected environments, even those lacking centralized log visibility.
The system can also suggest or tune rules for an existing SIEM, allowing teams to keep their current detection stack intact.
How Cotool’s Agents Work
Agents can be triggered through an API, webhook, or scheduled process, giving teams flexibility in how they invoke automation.
Each agent’s prompt, underlying model, integrated tools, and output format are fully configurable by the customer.
The platform records version history, run evaluations, and structured outputs so analysts can inspect how an agent arrived at a conclusion.
These controls aim to let teams understand the provenance of an answer before they act on it.
Pollard emphasizes that fast answers are only useful when teams can verify the source of the decision.
Controls, Trust, and Early Demonstrations
In a May 2026 discussion hosted by Material Security, Pollard cited an agent that flagged unusual API calls from devices stolen from a delivery truck.
The same agent prepared a wipe command, illustrating the potential impact of an inaccurate classification.
Cotool therefore requires human review of agent findings before any automated remediation is executed.
The product’s evaluation and version‑history features let teams roll back to earlier configurations if an agent behaves unexpectedly.
While Cotool reports time‑savings for its early adopters, the company has not yet published independent benchmarks.
The claims remain self‑reported, and external validation will be needed to confirm the magnitude of efficiency gains.
Nevertheless, the ability to reuse a captured investigation as a no‑code automation could reduce the manual effort that currently dominates security operations.
Cotool’s approach differs from pure “AI‑only” solutions by allowing organizations to retain control of their existing security stack.
By integrating with tools that lack centralized logs, the agents can surface context that would otherwise be hidden.
The platform also produces AI‑generated explanatory diagrams to aid documentation, though these are not independent evidence of correctness.
Cotool’s roadmap includes extending the agent concept to detection engineering, enabling natural‑language creation of detection rules.
If successful, this could streamline the workflow between threat hunting and rule deployment.
Security teams that adopt Cotool will need to establish governance processes around prompt design, model selection, and output validation.
The company’s emphasis on auditability suggests it anticipates regulatory scrutiny of automated security actions.
As of now, Cotool’s customers are limited to a handful of early‑stage firms, and broader market adoption remains to be seen.
The startup’s progress will likely be tracked by investors watching Y Combinator alumni that aim to augment, rather than replace, human analysts.
Why This Matters the ability to convert a single analyst’s investigative workflow into a reusable, auditable AI agent could reshape how security operations balance speed with accountability.
This digest was compiled from:
Share this digest
People Also Read
- TUT Forum Urges Immediate AI Rollout Amid 62.8% Youth Joblessness
South Africa’s youth unemployment crisis spurs TUT’s Institute for the Future of Work to demand swift AI implementation and coordinated skills development.
- Satlyt Secures $8 Million Seed Round to Advance Space‑Based Virtual Data Centres
Satlyt raised $8 million to turn satellite onboard computers into virtual AI data centres, aiming to ease Africa’s data‑centre capacity shortfall.
- A months‑long probe of Kevin O’Leary’s Utah data‑center fiasco
Kevin O’Leary’s massive Utah AI data‑center plan collapsed after community backlash, a defamation lawsuit, and political opposition.
Share your thoughts
Reactions, corrections, or insights — all welcome.
