Brightmind Partners Research
Investment Thesis
Brightmind Partners is an early-stage venture firm backing cybersecurity and AI founders, positioned around the claim that great founders "see the world differently" and need operators, not just capital. The firm was founded by operators with deep cybersecurity backgrounds (CISOs, security leaders, and a former Insight Partners cyber investment team) who position themselves as "blue-collar elite": practitioners who reverse-engineer and stress-test portfolio products themselves rather than critique from the sidelines. Brightmind runs a "home lab" where the team builds and tests AI systems and security products directly, and it leans on custom internal automation and AI-driven market intelligence to source and diligence deals. The firm explicitly targets founders solving structural, adversary-relevant problems in cybersecurity and, increasingly, in AI agent trust/safety infrastructure — treating AI security as a natural extension of the cyber category rather than a separate vertical.
Sector Focus
Two anchor areas dominate the portfolio:
- Cybersecurity: identity and access security (SGNL, Aryon, Act Security), AI-native SIEM/SecOps (Artemis), endpoint security (Origin), application security/GRC (Pi Security), exposure management (Onit, Empirical Security), and several undisclosed "stealth" cyber startups in remediation, data access intelligence, compliance automation, and identity audit.
- AI trust/security infrastructure: platforms securing and governing AI agents for the enterprise (vijil), and AI-native vulnerability/exploit prediction models (Empirical Security, which builds on the EPSS framework its founders co-created).
Stage Focus
Brightmind invests at Seed and Series A, describing itself as "purpose-built for the earliest stages" with the "first check in, first phone call after" a founder engages them. The portfolio confirms a Seed/Series A split roughly evenly across the 14 disclosed companies.
Check Size
No explicit check-size range is published on the site. Given a $251M Fund I deploying across 14+ Seed/Series A cyber and AI companies (including a $25M lead check into Empirical Security's Series A), typical checks likely span roughly $1M–$10M+, but this is an inference rather than a stated figure — treat check size as unconfirmed.
Lead Tendency
Brightmind explicitly leads rounds where it has conviction. It led Empirical Security's $25M Series A ("We are proud to announce that Brightmind Partners is leading Empirical Security's $25 million Series A") and frames itself throughout its content as the founder's "single most helpful and important investor," consistent with a lead/co-lead posture rather than a passive-check strategy.
Recent Activity
Brightmind has been actively deploying from Fund I ($251M) since at least early 2025:
- July 2026: Led Empirical Security's $25M Series A (AI-driven vulnerability/exploit-prediction models), joined by Costanoa Ventures and Hyde Park Angels.
- June 2026: Backed Aryon (Series A, proactive cloud security policy enforcement) and Pi Security (Seed, AI-native AppSec/GRC).
- April 2026: Backed Artemis (Seed, AI-native SIEM) and Onit Security (Seed, decision-based exposure management); published industry analysis on AI-driven vulnerability discovery ("Mythos and Project Glasswing").
- January 2026: Backed vijil (Series A, AI agent trust infrastructure); portfolio company SGNL was announced as an acquisition target by CrowdStrike.
- February 2025: Invested in SGNL (identity/privileged access security), one of the firm's earliest and most visible bets.
- September 2026: Published an H1 2026 private cybersecurity market briefing.
Fund status reads as actively deploying, with a steady cadence of new investments and thought-leadership content through September 2026.
Portfolio Highlights
Fourteen disclosed cyber/AI companies, split across Seed and Series A, including one notable exit:
- SGNL — identity/privileged access management; agreed to be acquired by CrowdStrike (announced ~January 2026) to combine identity threat detection with access management ("threat-driven continuous identity").
- Empirical Security — AI-native vulnerability prioritization built by the co-creators of EPSS (Exploit Prediction Scoring System); $25M Series A led by Brightmind; endorsed indirectly via Anthropic's recommended patching framework.
- vijil — AI agent trust/safety infrastructure; customers include DigitalOcean, SmartRecruiters, and DuploCloud; named a Gartner Cool Vendor for AI Security and a CB Insights Top 100 AI Startup.
- Aryon, Act Security — cloud security policy enforcement and access-sprawl elimination (both Israel-based).
- Artemis — AI-native SIEM (New York).
- Origin — endpoint security (New York).
- Pi Security, Onit, QueryStory — Seed-stage AppSec/GRC, exposure management, and data-access tooling.
- Four additional stealth-stage companies spanning remediation automation, data access intelligence, compliance automation, and identity audit/assurance.
Co-investors across the portfolio include Sequoia Capital, Insight Partners, Felicis, Third Point Ventures, Mayfield, Gradient, Costanoa Ventures, M12, Cisco Investments, Hetz Ventures, Datadog Ventures, Blumberg Capital, Cowboy Ventures, Viola Ventures, Team8, Bessemer Venture Partners, and Notable Capital — a strong signal of syndicate access with top-tier enterprise/security-focused funds.
Team
- Stephen Ward — Managing Partner. 25 years in security: CISO at The Home Depot and TIAA, security operations at JPMorgan Chase, early career in the U.S. Secret Service cyber division, veteran of the U.S. Coast Guard. Joined Insight Partners in 2021 as Managing Director leading its cybersecurity portfolio before co-founding Brightmind. Sits on public and private boards (including Abnormal AI's, per founder testimonials).
- Sven Wollschlaeger — Principal. Co-founded a startup deployed across U.S. universities out of his dorm room; worked at public tech companies and pre-IPO unicorns; briefly at a16z; spent three years at Insight Partners alongside Jeff Horing and Stephen Ward leading seed/Series A security investments and Gen AI and dev/data infrastructure growth rounds (e.g., Anaconda).
- Iva Messy — Chief Operating Officer.
- Jamie Mneimneh — Chief Technology Officer & CISO.
- Taylor Cleveland — Chief of Staff.
The firm also maintains a bench of venture partners and advisors described as "Fortune 50 CISOs, exited founders, and practitioners" who take founder calls directly, plus a dedicated advisory practice for M&A exit timing, valuation, and strategic-buyer introductions (recent tracked outcomes from August 2025 through August 2026).
Decision Process
Small, operator-led partnership (Managing Partner + Principal driving investment decisions, supported by COO/CTO/Chief of Staff functions) rather than a large investment committee. The firm emphasizes direct, hands-on founder engagement ("no detail too small") over process-heavy governance.
Founder Preferences
Brightmind explicitly targets technical, security-native founders — operators who have "hunted hackers, secured the Fortune 50, and coded their own infrastructure" — and favors founding teams with deep domain credibility (e.g., Empirical's founders literally created the EPSS standard; SGNL's founders previously built and sold identity companies to Google). Founder testimonials repeatedly cite Brightmind's willingness to jump into customer conversations, product testing, and go-to-market execution alongside the team, not just governance.
Geographic Focus
US-centric with a meaningful Israel cluster: portfolio companies are based in San Francisco, New York, Chicago, and across Israel (Aryon, Act Security, Onit, and at least one stealth company). No explicit international expansion focus beyond the US/Israel security corridor is stated.