investors
Why VigilArch, and where it stands today.
the thesis
The next generation of security architecture tooling collapses two categories into one.
Security architecture and vulnerability management have grown up as separate categories, priced and sold separately, maintained on separate cadences. CSPM tools tell you what's misconfigured; threat modeling tools tell you what's theoretically at risk; neither tells you both, tied to the same live picture of your environment.
VigilArch's bet is that the next generation of security architecture tooling collapses these into one continuously-updated model — and that AI-assisted review is what finally makes “continuous” operationally realistic instead of aspirational.
market context
A large, growing adjacent market — with real spread in how firms size it.
Estimates vary meaningfully by research firm, but the CSPM market — the closest existing analog category — is broadly sized in the mid-single-digit billions for 2026. CASM, as a category that layers architecture and threat modeling on top of posture management, represents an adjacent and largely unaddressed expansion of that spend.
Fortune Business Insights
$3.8B
2026 estimate
→ $21.3B by 2034 (24% CAGR)
Mordor Intelligence
$6.0B
2026 estimate
→ $12.1B by 2031 (15% CAGR)
why demand is growing, not just the category's own size
Multi-cloud is now the default, not the exception
Every additional cloud account and on-prem segment is another real place architecture can drift from what a diagram claims — the exact gap CASM exists to close.
Compliance pressure keeps compounding
SOC 2, customer security questionnaires, and internal architecture review are now standing requirements for most B2B software companies, not one-time hurdles.
AI-assisted review makes 'continuous' operationally realistic
Manually re-threat-modeling an environment every time it changes was never realistic at scale — the same shift making AI-assisted code review normal is what makes AI-assisted architecture review normal too.
tam / sam / som
Built bottom-up from real inputs, not sliced from an already-uncertain top-down number.
Sourced figures and team assumptions are labeled separately at each stage below.
TAM
$340M
17,000 US B2B SaaS companies × $20K blended ACV
17,000 is a real, cited figure (see sources below). $20K is a deliberately conservative blended average — below real, comparable CSPM/CNAPP mid-market pricing ($50K–$200K/year) — since it's averaged across the full company-size distribution, not just mid-market.
SAM — 30% of TAM
$102M
The ~30% of TAM with real multi-cloud/hybrid infrastructure and active compliance pressure
30% is the team's own explicit estimate, not a cited statistic — the real, addressable segment matches this site's own "Who it's for" (multi-cloud/hybrid orgs facing SOC 2, customer security review, or internal architecture review requirements).
SOM — 1.5% of SAM
~$1.5M ARR
1.5% of SAM captured within 3 years
A realistic, not aggressive, early-stage penetration target — in line with typical seed-to-Series-A ARR benchmarks for a well-executed B2B security startup, not a best-case scenario.
Sources: US B2B SaaS company count from Ascendix/Demandsage industry data (2026). Comparable CSPM/CNAPP pricing from vCSO.ai and TrustRadius vendor pricing analysis (2026). The 30% SAM segment estimate and the 1.5% 3-year SOM capture rate are this team's own assumptions, not third-party figures — revisit both directly against real pipeline data once it exists.
product status
What's actually built, not what's planned.
- ✓Production deployment on a multi-tenant architecture (FastAPI/SQLModel/MySQL backend, Next.js/React/TypeScript frontend, containerized deployment)
- ✓Multi-cloud asset discovery across AWS, Azure, and GCP
- ✓On-prem connector infrastructure covering firewall/network platforms including Cisco ASA and Check Point
- ✓STRIDE threat modeling workbench, including guided bulk analysis with review-and-apply controls
- ✓Vulnerability–exposure correlation using architecture diagram signals, including a cross-domain risk graph spanning vendors, systems, AI systems, and capabilities
- ✓CoPilot AI assistant integrated across multiple model providers with streaming responses and structured provenance citations
- ✓Public API, outbound webhooks, and an external auditor access portal for read-only, time-boxed sharing of approved documents
- ✓2,300+ passing automated backend tests, with CI enforcing test, migration-integrity, and lint/typecheck gates on every change
team
Who's building this.
Chris Treece
Co-Founder
Justin Haire
Co-Founder
the ask
Raising a Seed round.
To build the team and the platform — going from a working, tested product to a real company with the engineering, security, and go-to-market capacity to bring CASM to the teams who need it.