Backing the founders securing AI.

Chispa is an operator-led seed fund in San Francisco. We invest early in Security for AI: the control layer enterprises need to safely deploy AI systems, agents, and workflows.

Every platform shift creates a new attack surface. AI is the next one.

We saw it in mobile, then in cloud and identity. Each time, security arrived after adoption. This time, enterprises are deploying AI agents and workflows before the control layer is mature. That gap is where the next defining cybersecurity category gets built.

Security for AI is not security tools that happen to use AI. It is the security of AI itself: the identity, permissions, integrity, and audit layer around models, agents, and the workflows they run. The control plane lives in the harness around the model, not in the model. The market is early, messy, and not yet settled, which is exactly when categories get created.

What we back

  • Securing AI systemsModels, agents, workflows, and the infrastructure they run on: who can act, what they can touch, and proof of what happened.
  • Making AI use safe and compliantThe data, privacy, and governance controls that let an enterprise adopt AI without leaking what it cannot afford to lose.
  • Defending against AI-enabled attackersSynthetic identity, automated intrusion, and the problems AI creates or accelerates for the security team that already exists.

Those lanes are broad on purpose. If you are securing something AI touches and do not see yourself here, send it anyway.

Operators first. Investors second.

We built, sold, and scaled security companies through three platform shifts: mobile at Appthority, cloud at Symantec/Broadcom, identity at Incode. We have lived the messy parts founders leave out of the deck: the first customers, the positioning pivots, the fundraising pressure, the category confusion. That is where we try to help.

What we look for

A founding team with the technical depth to build it and the drive to sell it. A real product in market, with early revenue or strong enterprise pull; earlier than that only when the founders have done it before. A wedge a security buyer will fund this year, with a platform story behind it.

What we bring

Positioning, category narrative, and ICP definition. Technical and product-security diligence from people who have shipped it. Enterprise go-to-market from decades in the seller's seat, and introductions where they help.

We may not be the largest check. We aim to be the most helpful.

Founders, technologists, and go-to-market operators in enterprise security.

Domingo Guerra

Founder and Managing Partner

Cybersecurity founder, operator, and investor. Co-founded Appthority, winner of RSA Conference's Most Innovative Company award in 2012 and later acquired by Symantec. Former EVP of Trust and GM North America at Incode, and earlier the go-to-market lead for Symantec/Broadcom's enterprise security portfolio. Forbes Top 50 Angel Investor in Latin America.

LinkedIn

Kevin Watkins

Venture Partner, Technical Diligence and Product Security

Cybersecurity technologist and Appthority co-founder. Former CTO, security researcher, and inventor on 15+ security patents, with experience across Appthority, Symantec/Broadcom, and McAfee Labs. Author of Deadly Sins of Mobile Applications.

LinkedIn

Jill Richards

Venture Partner, Commercial Strategy and Growth

Go-to-market leader with 25+ years across cybersecurity, data, and complex B2B technology. Seven-time CMO, including at Appthority through its Symantec exit, with a long track record advising founders on positioning, category narrative, ICP definition, and enterprise go-to-market.

LinkedIn

Companies we have backed.

Earlier investments

Building in Security for AI?

Send us what you are building, who is asking for it, and where you are in market. A short note is enough.

or write to