Cathedral
DOGE Alumni Build AI Cyber Platform for the US Military; a16z and Sequoia Bet $160M at a $1.4B Valuation
Cathedral pairs elite-investor backing and unusual founder access to the US defense-cyber buyer with an extraordinary $1.4B pre-revenue valuation and acute political, execution, and verification risk.
Cover facts
Company profile
Cathedral is a stealth defense-technology company founded in 2025 by four former Department of Government Efficiency (DOGE) staffers to apply AI to US military cyber operations, spanning both offensive capabilities (vulnerability discovery and exploitation against adversary systems) and defensive capabilities (protecting US military networks). In the weeks before a 22 July 2026 Reuters report it closed a $160 million round at a $1.4 billion post-money valuation co-led by Andreessen Horowitz and Sequoia Capital, both of which took board seats. The company has no disclosed product, revenue, or contracts, and its valuation reflects investor conviction in the founding team's recent senior government access rather than any commercial track record.
- Founded
- 2025-01-01
- Founders
- Gavin Kliger, Luke Farritor, Marko Elez, Jack Stein
- Founding location
- United States
- Headquarters
- United States (undisclosed)
- Product
- AI-driven platform (undisclosed and presumptively classified) intended to support US military cyber operations, combining offensive vulnerability discovery and exploitation with defensive threat detection and response; the company is also seeking dedicated data-center compute to run those operations.
- Customers
- US Department of Defense, US Cyber Command, the NSA, and the broader intelligence community, with adversary systems (notably China) as the operational target set.
- Business model
- US government contracts (expected via SBIR/STTR, OTA, and direct/program-of-record vehicles) for AI-powered offensive and defensive cyber tools and services.
- Stage
- Seed / Series A (early-stage, pre-revenue)
- Funding status
- $160 million round at a $1.4 billion post-money valuation, co-led by Andreessen Horowitz and Sequoia Capital, closed in the weeks before 22 July 2026; both firms took board seats.
Executive summary
Top strengths
- Tier-one investor endorsement from a16z and Sequoia, both taking board seats, at a $1.4B valuation
- Founding team with recent senior government access, including a former Pentagon chief data officer, in a market that prizes buyer relationships
- Well-timed entry into a surging defense-tech and AI-cyber market backed by explicit administration priority signals such as the White House Gold Eagle clearinghouse
Top risks
- Extraordinary $1.4B valuation with no disclosed revenue, product, or contracts
- Concentrated DOGE-revolving-door and conflict-of-interest exposure that invites congressional, ethics, and reputational scrutiny and is sensitive to political change
- Capability and traction claims are largely classified and cannot be independently verified, compounding key-person and execution risk in a young team
Open gaps
- No disclosed revenue, contract awards, backlog, burn rate, or runway to underwrite the pre-revenue premium
- No official company disclosure (website, product docs, customer or headcount data); nearly all facts trace to a single Reuters report and its syndications
- No independent verification of offensive/defensive cyber capability or of any DoD procurement traction
Contents
01Company Overview
1.1 Identity, stage, and business model
Cathedral is visible in the public record as a stealth AI-powered military cybersecurity company rather than as a conventional launched software vendor. Reuters’ David Jeans, republished by U.S. News, and follow-on coverage from The Next Web, Hoodline, Gizmodo, and Cyber Daily consistently describe a company formed by former DOGE operators to expand U.S. military cyber capabilities. The supportable business model is therefore narrow but important: win U.S. government contracts for AI-driven offensive and defensive cyber operations, potentially with dedicated compute supplied by an acquisition or data-center partnership. The headquarters is not disclosed in the reviewed sources; the strongest geographic signal is Washington/Pentagon proximity, not a corporate address. I use 2025 as the founding year with medium confidence because the July 2026 Reuters account says the company launched in recent months after the founders’ 2025 DOGE tenure. Stage should be recorded as stealth/private-undisclosed: the round is large, but product documentation, customers, revenue, and headcount are absent.[CO001, CO002, CO003, CO004, CO005, CO018]
| Metric | Value / status | Date | Confidence | Source / gap |
|---|---|---|---|---|
| Company identity | Stealth AI-powered military cybersecurity startup | 2026-07 | high | Reuters syndication, TNW, Hoodline, Cyber Daily |
| Founding year | 2025 inferred from “launched in recent months” after DOGE tenure | 2025 | medium | Reuters syndication and run-date logic |
| Headquarters | Not disclosed publicly; Washington/Pentagon proximity only | 2026-07-24 | low | Evidence gap |
| Latest round | $160 million | 2026-07 | high | Reuters syndication plus follow-on coverage |
| Post-money valuation | $1.4 billion | 2026-07 | high | Reuters syndication plus follow-on coverage |
| Revenue / ARR | null; no public revenue or ARR disclosed | 2026-07-24 | medium | Reviewed public source gap |
| Customers / contracts | null; seeking U.S. government contracts, none disclosed | 2026-07-24 | medium | Reviewed public source gap |
| Headcount | null; no public employee count disclosed | 2026-07-24 | medium | Reviewed public source gap |
Null means no usable public disclosure was found in fetched sources as of the run date, not that the metric is zero.
[CO001, CO002, CO011, CO012, CO015, CO016]The investability logic runs from DOGE-linked founders to military cyber contracts, dedicated compute, and political scrutiny.
[CO001, CO003, CO004, CO005, CO013, CO014]1.2 Founders, leadership, and key-person risk
The named leadership bench is concentrated in four founders: Gavin Kliger, Luke Farritor, Marko Elez, and Jack Stein. Public diligence should treat that enumeration as complete only for founders reported by Reuters, not as a full management or board list. Kliger is the most strategically important public figure because he was reported as the Pentagon chief data officer and as involved in the Department of Defense’s dispute with Anthropic over how Claude would be used by the military. Farritor brings DOGE/GSA cost-cutting and SpaceX intern context, while Elez brings both technical pedigree and a material reputational/control-risk history from Treasury access and the social-media-post episode. Stein is named, but the reviewed free public record gives less role detail. This creates founder-market fit and key-person dependence at the same time: Cathedral’s access story is valuable precisely because it is also politically sensitive and difficult to diligence through company-authored materials.[CO006, CO007, CO008, CO009, CO010, CO021]
| Person | Current Cathedral role | DOGE / prior background | Founder-market fit or risk | Key-person dependency |
|---|---|---|---|---|
| Gavin Kliger | Cofounder | Former Pentagon chief data officer; involved in Anthropic/Claude military-use dispute | Strong national-security access; high political and AI-governance exposure | Confirm current role, equity, security clearance posture, and succession depth |
| Luke Farritor | Cofounder | Former DOGE staffer; Reuters says SpaceX intern and GSA cost-cutting operator | Operational cost-cutting story fits DOGE narrative but commercial cyber role is not yet documented | Confirm functional ownership and technical contribution |
| Marko Elez | Cofounder | Former SpaceX and DOGE/Treasury operator | Technical/government-system access signal with material reputation and security-control baggage | Confirm access controls, compliance oversight, and customer-facing role |
| Jack Stein | Cofounder | Former DOGE staffer named by Reuters and follow-on coverage | Founder presence corroborated; role depth less public than Kliger/Elez | Confirm responsibilities, background, and decision rights |
Founder list is based on the public Reuters-origin source pack; it is not a complete executive roster or board list.
[CO006, CO007, CO008, CO009, CO010, CO021]1.3 Funding, governance, and stakeholder map
Chapter 1 owns the core funding facts. The ground-truth public financing record is a $160 million round closed shortly before July 22, 2026, at a $1.4 billion post-money valuation. Andreessen Horowitz and Sequoia Capital led the round and both took board seats. No earlier Cathedral financing was found, so $160 million is the disclosed total raised, not a verified lifetime total if undisclosed pre-seed capital exists. Governance disclosure is thinner than the valuation implies: the public file names the four founders and the two lead-investor board seats, but not a complete board, voting rights, option pool, founder ownership, secondaries, or observer rights. The stakeholder map therefore includes investors, founders, U.S. government buyers, potential compute providers, and the political/regulatory environment. a16z’s American Dynamism materials and Sequoia’s AI programming make the investor fit plausible, yet the absence of company confirmation keeps governance transparency a major diligence ask.[CO011, CO012, CO013, CO014, CO020, CO031]
| Stakeholder | Role | Control or economic importance | Evidence status | Diligence ask |
|---|---|---|---|---|
| Gavin Kliger / founder group | Founders and likely operating control center | Government-access story and key-person risk concentrate in founders | Multi-source reporting | Request cap table, voting rights, employment agreements, and security-control policy |
| Andreessen Horowitz | Lead investor and board-seat holder | Signals American Dynamism fit and venture validation | Reuters-origin reporting plus official a16z context | Confirm board representative, ownership, reserves, and information rights |
| Sequoia Capital | Lead investor and board-seat holder | Top-tier AI investor with governance seat | Reuters-origin reporting plus official Sequoia context | Confirm board representative, ownership, and protective provisions |
| U.S. government / Pentagon buyers | Target customer and contract path | Revenue thesis depends on government contracting, not disclosed commercial customers | Reuters-origin reporting and AI-government context | Request pipeline, contract vehicle, procurement status, and conflict review |
| Data-center provider or acquisition target | Potential dedicated-compute dependency | Could shift Cathedral from pure software to capital-intensive infrastructure execution | Reuters-origin reporting | Request make/buy analysis, cost model, and counterparty identity |
| DOGE / Trump-administration network | Political and reputational context | Access advantage may become contract-scrutiny risk if control of Congress changes | Reuters-origin and adverse DOGE coverage | Request ethics review, recusals, lobbying disclosures, and government-relations policy |
This stakeholder map intentionally mixes economic owners, prospective customers, infrastructure dependencies, and political context because all affect Cathedral’s investability.
[CO013, CO014, CO025, CO031, CO032, CO037]The only hard KPIs are financing metrics; operating metrics remain deliberate nulls pending company evidence.
[CO011, CO012, CO013, CO014, CO015, CO016]1.4 Cover metrics, gaps, and valuation context
The cover metrics should be explicit rather than embellished: valuation is $1.4 billion; disclosed capital raised is $160 million; revenue, ARR, customer count, contracts, pilots, headquarters, and headcount are null in the reviewed public record. That gap is not a trivial private-company nuisance because Cathedral is already priced like a breakout defense-AI company while remaining stealth on commercial proof. The $1.4 billion valuation can be contextualized against Anduril’s 2026 $5 billion Series H at a $61 billion valuation, but the comparison cuts both ways. It shows investor willingness to pay premium prices for defense technology, while also highlighting Cathedral’s much earlier evidence base: no disclosed contracts, no product documentation, no operating metrics, and no official company announcement. Later chapters should not infer traction from financing alone. The right diligence path is management-provided pipeline detail, contract status, revenue recognition policy, compute strategy, security controls, and hiring plan.[CO012, CO015, CO016, CO017, CO018, CO033]
1.5 Milestones and policy context
The chronology is inseparable from DOGE, defense procurement, and AI-cyber policy. DOGE was created by executive order in January 2025, became associated with aggressive federal cost-cutting and more than 250,000 workforce exits, and ended on July 4, 2026. Cathedral then surfaced publicly weeks later as a DOGE-alumni company with defense-cyber ambitions and large venture backing. The same period included the Anthropic-Pentagon dispute, where Kliger’s reported involvement matters because it shows proximity to AI-use rules for military systems, and Gold Eagle, the White House’s July 2026 AI-enabled vulnerability coordination clearinghouse. Those facts do not prove Cathedral has a contract, but they explain why investors may believe the timing is unusually favorable. They also create adverse risk: the DOGE revolving-door narrative, Elez’s prior controversy, and potential congressional scrutiny of future contracts all belong in the overview rather than being deferred to a later risk chapter.[CO019, CO025, CO026, CO027, CO028, CO029]
| Date | Event | Type | Amount / valuation / status | Participants / source | Why it matters |
|---|---|---|---|---|---|
| 2025-01 | DOGE established by executive order | regulatory | U.S. Digital Service renamed/reorganized around DOGE agenda | White House / DOGE | Sets the government context that produced the founding team |
| 2025 | DOGE cost-cutting tenure | adverse | Reuters reports 250,000+ left federal workforce | Reuters / GovExec / Nextgov | Creates the revolving-door and public-sector disruption backdrop |
| 2026-04 | DOGE Treasury access controls criticized | adverse | GAO-reported security-control gaps | GovExec / Reuters context | Material to Elez and future cyber trust diligence |
| 2026-04 to 2026-07 | Anthropic-Pentagon fight over military AI use escalates | governance | Government pressure and contractor purge deadlines reported | TNW / CNBC / Politico / Breaking Defense | Explains why Kliger’s reported involvement is strategically relevant |
| 2026-05 | Anduril mega-round closes | financing | $5B Series H at $61B valuation | TechCrunch / Forbes | Defense-tech valuation benchmark for Cathedral’s premium pricing |
| 2026-06 | Special, another DOGE-alumni startup, surfaces | financing | a16z-backed private-sector cost-cutting startup | Reuters / TNW / Atlantic | Shows investor appetite for DOGE-alumni companies and adverse skepticism |
| 2026-07-01 | Gold Eagle launched | regulatory | AI-enabled vulnerability coordination clearinghouse | White House / SecurityWeek / CSO | Policy tailwind for AI-cyber vulnerability coordination |
| 2026-07-04 | DOGE officially ends | governance | Self-imposed termination date reached | Yahoo / Fiscal Times | Marks transition from federal role to alumni venture activity |
| 2026-07-22 | Cathedral funding reported | financing | $160M round at $1.4B post-money valuation | Reuters syndication / TNW / Hoodline / Cyber Daily | Core financing fact for the whole report |
| 2026-07-22 | Cathedral mission and compute plan reported | product | AI offensive/defensive cyber; exploring dedicated compute | Reuters syndication / TNW / Hoodline | Defines product thesis and infrastructure dependency |
This is the single chronology of record for Chapter 1 and combines company events with the policy and comparable-financing events needed to interpret them.
[CO002, CO005, CO011, CO012, CO026, CO027]Cathedral’s public emergence follows DOGE, AI-military governance conflict, and a rapid venture-financing signal.
[CO002, CO005, CO011, CO012, CO026, CO027]1.6 Exhibits
02Market Analysis
2.1 Market boundary and status-quo substitutes
Cathedral should be sized inside a narrow national-security cyber market: AI-enabled defensive and offensive cyber tools, vulnerability discovery, workflow software, and related services sold to DoD and intelligence-community operators. That boundary intentionally excludes broad enterprise security, consumer cybersecurity, generic federal IT services, and physical defense hardware, even though those categories create context and comparable valuations. The core user problem is not simply buying another SOC tool; it is accelerating cyber operations against nation-state adversaries while satisfying classified-network, zero-trust, and command-authority requirements. The strongest substitutes are therefore internal Cyber Command and NSA capability, incumbent defense contractors, manual red-team or penetration-testing teams, and civilian CISA-style practices for defensive hygiene. This framing keeps Cathedral’s opportunity tied to mission cyber workflows rather than a generic cybersecurity TAM.[CM001, CM002, CM005, CM006, CM007, CM021]
| Segment/category | Included spend | Excluded spend | Buyer/payer | Relevance |
|---|---|---|---|---|
| AI cyber operations tooling | Autonomous vulnerability discovery, cyber mission workflow, defensive automation, operator copilots | Generic endpoint security sold to civilian enterprises | DoD program offices, Cyber Command, IC buyers | Core Cathedral SAM |
| Mission cyber services | Specialized implementation, red-team automation, classified-network deployment support | Broad systems integration not tied to cyber operations | Service cyber components and mission owners | Core but services-heavy |
| Offensive cyber / cyber warfare | Sensitive tools and support where legally authorized and budgeted | Unlawful activity, export-controlled sales outside U.S. government authority | Highly restricted DoD/IC sponsors | Adjacent; public data gap |
| Federal civilian cyber | CISA-aligned automation and zero-trust support when product generalizes | Routine helpdesk, commodity IT, consumer security | CISA and civilian agencies | Adjacent option, not canonical focus |
| Broad cybersecurity market | Context only for valuation and threat trends | Most enterprise, consumer, MSP, and compliance spend | Commercial CISOs and agencies | Too broad for TAM |
| Physical defense hardware | None except where bundled into cyber mission systems | Drones, sensors, weapons platforms, factories | Services and prime contractors | Excluded; Anduril comp caveat |
Boundary table separates Cathedral’s AI cyber mission wedge from broad cybersecurity and defense hardware; rows are a partial taxonomy for diligence, not an exhaustive NAICS market census.
[CM001, CM005, CM006, CM007, CM021, CM025]The addressable market narrows from broad federal cyber and cybersecurity context to military AI cyber operations sold to DoD and IC buyers.
Pyramid is a market-boundary lens, not an additive dollar waterfall; only the top federal context and analyst rows are public-number backed.
[CM001, CM003, CM021, CM025, CM026, CM037]2.2 Multiple market-sizing lenses
No single public TAM number is decision-grade for Cathedral. The broadest lens is U.S. federal cybersecurity spending, which provides at least a roughly $26 billion annual context but includes civilian and infrastructure spend that Cathedral should not count as core SAM. A second lens is DoD and mission cyber spend, but public budget books do not fully isolate classified offensive cyber programs. A third lens is military AI: MarketsandMarkets and Grand View both show a multibillion-dollar market but differ sharply on growth rate and endpoint, so a range is more honest than a point estimate. A fourth lens is cyber-warfare market research, where Mordor’s 2026-to-2031 estimate is closer to Cathedral’s job-to-be-done but still mixes products, services, and end users. The SOM lens should remain contract-pipeline based until Cathedral discloses revenue or awards.[CM003, CM004, CM016, CM017, CM018, CM019]
| Publisher | Year | Geography | Value | CAGR | Methodology | Confidence | Limitation |
|---|---|---|---|---|---|---|---|
| OMB / federal budget lens | 2026 | United States federal | ~$26B+ annual cyber budget context | n/a | Top-down federal cyber budget context | medium | Includes civilian and infrastructure spend outside Cathedral core |
| DoD budget lens | 2026 | U.S. defense | Low-teens $B cyber/mission context; exact line items partly classified | n/a | Defense budget materials plus public mission mapping | low | Cannot isolate offensive or classified cyber programs |
| MarketsandMarkets military AI | 2023-2028 | Global | USD 9.2B to USD 38.8B | 33.3% | Analyst market forecast | medium | Military AI is broader than cyber operations |
| Grand View military AI | 2024-2030 | Global | USD 9.31B to USD 19.29B | 13.0% | Analyst market forecast | medium | Different endpoint and CAGR than MarketsandMarkets |
| Mordor cyber warfare | 2026-2031 | Global | USD 40.13B to USD 52.27B | 5.43% | Analyst market forecast | medium | Mixes products, services, and end users |
| Grand View cybersecurity | 2026-2033 | Global | Very large broad cybersecurity market | not used | Broad industry context | low | Overstates Cathedral SAM by including enterprise and consumer security |
| Cathedral public SOM | 2026 | U.S. defense | No verified public revenue or contracts | n/a | Diligence-gap anchor | high | Requires company pipeline, awards, or customer proof |
Values are rounded and deliberately kept as separate lenses because analyst scopes, horizons, and inclusion criteria are not interchangeable.
[CM003, CM004, CM016, CM017, CM018, CM019]Public estimates support a multibillion-dollar opportunity but vary materially by scope and forecast horizon.
All rows use USD billions, but they are not directly additive; the figure compares public sizing lenses and one verified-public SOM anchor.
[CM003, CM016, CM017, CM018, CM019, CM037]2.3 Buyer, user, payer, and adoption path
The buyer map is multi-party. DoD program offices and service cyber components are likely budget owners; Cyber Command, NSA collaborators, and mission teams are likely users and technical evaluators; contracting officers and security authorities can determine whether a pilot becomes real spend. Cathedral’s most plausible adoption path is not a consumer-style launch but a staged government sale: SBIR or DIU-style entry, prototype work under Other Transaction authority or similar mechanisms, then conversion into a FAR contract or program of record if mission value, security controls, and funding line up. That path creates upside because a successful tool can become embedded in mission workflows, but it also makes public traction hard to observe. SAM.gov, USAspending, and DoD contract releases are useful monitors, not complete truth for classified cyber work.[CM011, CM012, CM013, CM014, CM015, CM029]
| Segment | Buyer | User | Payer | Workflow | Budget owner | Adoption trigger |
|---|---|---|---|---|---|---|
| DoD cyber program office | Program manager | Mission cyber operators | DoD appropriation line or program office | Procure and integrate cyber capability | Service or defense agency PEO/PM | Funded requirement plus security approval |
| Cyber Command unit | Operational command | Cyber mission force | DoD operational budget or sponsor program | Plan and execute operations | Command or supporting service component | Operational need for speed and scale |
| NSA / intelligence collaboration | Technical sponsor | Analysts and cyber defenders | IC or joint sponsor | Threat intelligence, vulnerability, collaboration | Agency mission owner | Foreign-threat requirement |
| Service cyber component | Service leadership or PEO | Service cyber teams | Army/Navy/Air Force/Space Force cyber budget | Deploy tools into service networks | Service component or PEO | Exercise, incident, or modernization gap |
| Civilian federal adjacent | CISA or agency CISO | Civilian security teams | Agency IT/cyber budget | Defensive automation and zero trust | Agency CIO/CISO | Compliance and resilience requirement |
| Innovation-channel pilot | DIU/SBIR sponsor | Pilot users | Prototype or R&D funds | Evaluate commercial technology | Innovation office plus mission partner | Successful demo or urgent operational need |
Buyer, user, and payer often diverge in defense cyber procurement; rows are a segmentation map rather than a customer list.
[CM002, CM011, CM012, CM013, CM014, CM015]Defense cyber sales require aligning mission users, budget owners, and contracting authorities.
[CM002, CM011, CM012, CM030, CM039, CM040]The military cyber adoption path narrows sharply from market interest to verified recurring Cathedral revenue.
[CM011, CM012, CM013, CM014, CM030, CM031]2.4 Growth drivers
The demand case rests on four drivers. First, China and other nation-state cyber threats make speed and scale in cyber operations strategically important. Second, DARPA’s AI Cyber Challenge validates the specific idea that AI can automate vulnerability discovery and remediation, which is close to Cathedral’s claimed mission space. Third, defense-tech venture investors have already rewarded companies that promise national-security modernization, with Anduril serving as the category’s most visible comp even though its autonomy and hardware profile differs from Cathedral’s cyber-software wedge. Fourth, a government efficiency push could favor software and AI products that substitute automation for scarce cleared labor. These drivers support a large opportunity narrative, but they are not proof of procurement conversion, repeat usage, or willingness to authorize autonomous offensive cyber workflows.[CM010, CM022, CM023, CM024, CM032, CM033]
| Driver/constraint | Direction | Timing | Implication | Diligence ask |
|---|---|---|---|---|
| Nation-state cyber threat and China competition | up | current | Raises urgency for military cyber speed and automation | Identify funded programs tied to priority threats |
| AI vulnerability discovery and remediation | up | current | Supports Cathedral product thesis | Verify product capability and safety controls |
| Defense-tech venture appetite | up | current | Supports capital availability and high valuation comps | Separate cyber software comps from hardware autonomy comps |
| Efficiency push and cleared-labor scarcity | up | near term | Favors automation if trusted | Test buyer willingness to replace manual workflows |
| Procurement and contract conversion | down | 18-24mo+ risk | Delays revenue and raises burn | Map SBIR/OTA/FAR path by named office |
| ATO, zero trust, NIST and AI governance | down | current | Can block deployment despite pilot interest | Confirm accreditation path and classified environment |
| Classification and clearance limits | down | current | Reduces public evidence and slows onboarding | Review cleared staff, facility, and sponsor evidence |
| Incumbent contractor lock-in | down | current | Raises partnering or displacement hurdle | Check prime relationships and recompete windows |
Timing entries are diligence assumptions derived from public procurement and compliance evidence; they should be replaced by Cathedral-specific pipeline evidence when available.
[CM008, CM010, CM022, CM023, CM029, CM031]2.5 Constraints, adverse view, and diligence gaps
The adverse market view is straightforward: Cathedral may be valued like a once-in-a-generation defense-tech platform while competing for a much smaller, slower, and more classified spend pool than headline TAMs imply. Procurement cycles can stretch 18-24 months or longer once ATO, zero-trust alignment, security clearances, data handling, and contracting mechanics are included. Incumbent contractors also have award history, cleared personnel, and contracting infrastructure that a stealth startup must either build or partner around. Public sources do not yet verify Cathedral revenue, customers, contracts, authority-to-operate status, or classified deployment footprint. The next diligence step is therefore account-level: identify funded program offices, active solicitations, sponsor users, security accreditation path, and whether the company is selling tools, services, or mission outcomes.[CM008, CM027, CM031, CM036, CM037, CM044]
2.6 Exhibits
03Competitors
3.1 Competitive landscape map
Cathedral enters a defense-AI and cyber market where the relevant competitor set is broader than startups that literally say “military cybersecurity.” The first ring is defense-tech AI software and autonomy companies: Anduril, Palantir, Shield AI, Rebellion Defense, Vannevar Labs, and Two Six Technologies compete for defense modernization budgets, national-security credibility, and AI-native mission workflows. The second ring is cyber-specific: Horizon3.ai, XBOW, Dreadnode, RunSafe, IronNet as a failed precedent, and the exploit-broker ecosystem. The third ring is incumbent government contractors—Booz Allen, Leidos, SAIC, CACI, Peraton, ManTech, and Parsons—that already hold contract vehicles, cleared staff, and program relationships. Cathedral’s reported wedge is the combination of ex-DOGE government access and an offensive-plus-defensive AI cyber mission; the weakness is that public sources show plans rather than demonstrated contracts.[CP001, CP002, CP003, CP004, CP005, CP039]
| Company | Category | Scale / funding signal | Offensive vs defensive focus | DoD / government relationship | Differentiation vs Cathedral |
|---|---|---|---|---|---|
| Anduril | Defense-tech AI startup | ~$61B valuation after $5B Series H | Defense autonomy / command-and-control, not cyber-only | Battle-management and defense contracts reported | Far larger manufacturing and Lattice platform; less cyber-pure |
| Palantir | Public defense AI platform | 2024 revenue $2.9B; 55% government | AIP/Gotham decision and data platforms | Longstanding defense, intelligence, and allied-government use | Deep incumbency and audit controls; less startup-speed mystique |
| Shield AI | Defense autonomy startup | Reported $12.7B valuation in 2026 | Autonomy and AI pilot for aircraft | Hivemind used with U.S. and allied forces | Mission-proven autonomy; less direct cyber overlap |
| Rebellion Defense | Defense AI / critical asset software | No reliable current valuation in reviewed pack | AI fusion and asset protection | Defense positioning but unclear contract depth | Adjacent intelligence-shield positioning; status remains less transparent |
| Vannevar Labs | Defense AI software | Private; no public valuation retained | National-security software / deterrence | Targets warfighters and federal users | Adjacent intelligence workflow rather than explicit cyber ops |
| Two Six Technologies | Defense AI and cyber contractor | Private contractor; $4B DTRA IDIQ award participant | Cyber, information operations, agentic AI | Names DoD, SOCOM, Cyber Command, DARPA | More customer proof and contract posture; less stealth-venture upside |
| Horizon3.ai | Autonomous pentesting startup | 5,200+ organizations claimed in 2026 | Defensive validation via offensive testing | Government and critical-infrastructure use cases claimed | More public product proof; less military offensive mission framing |
| XBOW | Autonomous offensive-security startup | >$1B valuation after $120M Series C | Offensive security and continuous testing | Enterprise/partner route via Accenture | Closest AI-offensive cyber startup; less explicit DoD access |
| Dreadnode | Offensive AI security startup | ~$14M Series A in 2025 | AI red-team infrastructure and research | Government potential but not proven in reviewed pack | AI-native offensive research; much smaller scale |
| RunSafe Security | Cyber resilience startup | $12M Series B in 2024 | Defensive hardening / memory safety | Critical infrastructure and safety-critical framing | Defensive niche; lower overlap with offensive mission |
| Booz Allen / Leidos / SAIC / CACI / Peraton / ManTech / Parsons | Incumbent contractors | Top federal contractor rankings and multi-year cyber vehicles | Offensive, defensive, resilience, and systems integration | Established federal contract vehicles and program relationships | Distribution and trust advantage; less AI-native startup DNA |
| Exploit brokers / offensive-cyber vendors | Specialized supply chain | Opaque market; prices and supply not transparent | Offensive exploit development and brokerage | Government customers can buy specific capabilities | Substitute for components of Cathedral’s mission, not a platform peer |
Scale signals use the strongest reviewed public datapoint for each competitor; private-company valuations are not inferred when not directly supported.
[CP006, CP008, CP009, CP011, CP012, CP013]Cathedral sits in the AI-native/offensive-defense quadrant but below incumbents on DoD incumbency and below cyber specialists on product proof.
Ordinal placement based on public positioning, contract evidence, and product focus; no source reports these coordinates.
[CP003, CP005, CP006, CP008, CP011, CP016]3.2 Defense-tech AI peers
The defense-tech AI peer set is not a clean one-to-one product comparison, but it sets the bar Cathedral must clear. Anduril is the venture-backed scale outlier after a $5 billion Series H and a $61 billion valuation, with public reporting tying Lattice to missile-defense battle management. Palantir is even more institutionally embedded: its 10-K describes Gotham, AIP, Foundry, and Apollo, with Gotham serving defense and intelligence users for over a decade and government customers accounting for most 2024 revenue. Shield AI is autonomy-first rather than cyber-first, but its Hivemind AI pilot and 2026 valuation step-up show how quickly mission-proven AI systems can command capital. Rebellion and Vannevar show adjacent defense-software positioning, while Two Six is a smaller but highly relevant mission contractor because it names U.S. Cyber Command, DARPA, and DoD among its customer set.[CP006, CP007, CP008, CP009, CP010, CP011]
| Peer | Primary product center | Funding / public scale | DoD or allied proof | Cathedral implication |
|---|---|---|---|---|
| Anduril | Lattice-enabled defense systems and autonomy | $5B Series H at $61B valuation | Army and missile-defense reporting | Sets venture-scale benchmark Cathedral cannot match yet |
| Palantir | AIP, Gotham, Foundry, Apollo | $2.9B 2024 revenue; 55% government | Decade-plus defense and intelligence use | Hardest software-incumbency comparator |
| Shield AI | Hivemind AI pilot and autonomous aircraft | $12.7B reported 2026 valuation | U.S. and allied forces; Air Force-related deal | Shows mission proof can re-rate valuation fast |
| Rebellion Defense | Critical-asset intelligence shield | Private; no retained scale datapoint | Public defense positioning only | Needs verification before treating as dead or acquired |
| Vannevar Labs | National-security software and deterrence | Private; no retained scale datapoint | Defense and federal-user positioning | Adjacent budget competitor |
| Two Six Technologies | AI command, cyber, information operations | Private; DTRA IDIQ participant | DoD, SOCOM, Cyber Command, DARPA named | Closer to services/product hybrid Cathedral may face |
This matrix separates defense-AI budget competitors from cyber-specific product competitors; not every company sells the same workflow.
[CP006, CP007, CP008, CP009, CP010, CP011]Defense AI peers differ most on product maturity, government proof, and cyber specificity.
Qualitative values summarize retained source evidence and mark unknowns rather than guessing.
[CP001, CP003, CP006, CP008, CP009, CP011]3.3 Cyber-specific competitors and exploit-market context
Cyber-specific competitors are more product-adjacent to Cathedral than most defense platforms. Horizon3.ai’s NodeZero offers autonomous pentesting with public adoption claims, XBOW has raised large 2026 capital around autonomous offensive security and has a strategic Accenture relationship, and Dreadnode is building AI infrastructure for security agents and offensive AI research. RunSafe is a different defensive-hardening rival focused on memory safety and critical infrastructure rather than offensive cyber operations. Exploit brokers and offensive-cyber intermediaries are not conventional SaaS competitors, but they matter because a government buyer can source tools, talent, and capabilities through opaque supply chains instead of buying a new platform. Cathedral’s biggest product-level risk is therefore not one clone; it is a bundle of automated pentesting, exploit supply, red-team tooling, and internal cyber teams that can substitute for pieces of its promised mission.[CP014, CP015, CP016, CP017, CP018, CP019]
| Company / substitute | Category | Offensive capability | Defensive capability | Public traction signal | Differentiation vs Cathedral |
|---|---|---|---|---|---|
| Horizon3.ai NodeZero | Autonomous pentesting | Uses offensive testing to find exploitable paths | Validation and remediation workflows | 5,200+ organizations claimed | Product proof stronger; military access less clear |
| XBOW | Autonomous offensive security | Core autonomous hacking / testing focus | Exposure management through partner route | >$1B valuation; Accenture investment | Closest offensive AI peer |
| Dreadnode | Offensive AI security infrastructure | AI security agents and offensive research | AI model and security testing infrastructure | $14M Series A reported | More research-native and smaller |
| RunSafe Security | Cyber resilience / memory safety | Limited direct offensive overlap | Memory safety and attack-surface reduction | $12M Series B reported | Defensive niche, potential complement |
| IronNet | Defunct collective-defense cyber startup | Historical cyber threat analytics pitch | Collective defense | Bankruptcy and shutdown | Cautionary failure precedent |
| Exploit brokers | Offensive cyber supply chain | Zero-day/exploit acquisition | None directly; enables operations | Opaque market and intermediary risk | Component substitute for offensive missions |
| Internal cyber teams | Status quo / internal build | Organic offensive cyber operations | Organic defense and SOC functions | Classified / not public | Can build or buy pieces without Cathedral |
| Prime-contractor task orders | Status quo / outsourced incumbent | Can staff cyber operations programs | Managed defense, compliance, integration | Navy, Army, Alliant-type vehicles | Default procurement path Cathedral must displace |
Capability cells summarize reviewed public positioning, not a technical benchmark; classified offensive capabilities are necessarily under-observed.
[CP014, CP015, CP016, CP017, CP018, CP019]Cyber startups cover different slices of the offensive-to-defensive continuum, leaving Cathedral to prove integration breadth.
Matrix is qualitative because public sources do not disclose classified defense cyber capability depth.
[CP003, CP016, CP019, CP021, CP022, CP024]3.4 Incumbent contractors and distribution power
The incumbent contractor threat is distribution-led. Booz Allen, Leidos, SAIC, CACI, Peraton, ManTech, and Parsons all market cyber capabilities, and public contract coverage shows the same names appearing around Navy cyberspace operations support, Army cyber-warfare work, and GSA Alliant 3. This matters because the buyer Cathedral wants—the U.S. military and adjacent national-security agencies—already has pathways to procure cyber operations, systems integration, AI, and managed services without waiting for a new stealth startup to mature. Cathedral can still win if it provides a step-function AI advantage or if founders convert relationships into rapid pilots, but the practical sales hurdle is severe: incumbents know compliance, cleared staffing, recompetes, protests, and program-office rhythms. A new entrant must either partner with them, displace them inside a narrow workflow, or become a prime fast enough to survive procurement latency.[CP027, CP028, CP029, CP030, CP031, CP032]
| Incumbent | Public cyber / AI cue | Contract relationship cue | Competitive danger to Cathedral | Likely Cathedral response |
|---|---|---|---|---|
| Booz Allen | AI-speed cyber-defense framing | Army cyber-warfare recompete and Top 100 scale context | Very high | Partner or attack narrow AI-cyber workflow first |
| Leidos | Offensive, defensive, and cyber-resilience language | Federal cyber partnerships and Top 100 scale context | High | Show differentiated AI capability that primes cannot staff quickly |
| SAIC | Federal cybersecurity and IT modernization | GAO IT/cyber modernization and Top 100 scale context | Medium-high | Compete where startup speed matters more than broad integration |
| CACI | AI/ML-enabled cyber operations | Top 100 and federal cyber positioning | High | Prove better model performance or mission automation |
| Peraton | National cyber mission positioning | Navy cyberspace options; Army cyber dispute | High | Use founder access to get pilot before recompete cycle |
| ManTech | Cyber mission support positioning | Army cyber dispute; Top 100 context | Medium-high | Differentiate on AI-native product, not labor hours |
| Parsons | Cybersecurity for critical infrastructure and events | Navy cyberspace options and Top 100 context | Medium | Avoid broad infrastructure cyber markets initially |
Danger ratings are qualitative assessments of distribution power, not head-to-head product superiority.
[CP027, CP028, CP029, CP030, CP031, CP032]Contract vehicles and incumbent rankings show why Cathedral’s go-to-market hurdle is as important as product capability.
[CP004, CP009, CP030, CP031, CP032, CP033]3.5 Differentiation durability verdict
Cathedral’s differentiation is plausible but unproven. The bull case is that an AI-native team with recent government operating access can combine offensive and defensive cyber workflows faster than legacy contractors, while avoiding the narrower product definitions of autonomous pentest vendors or memory-safety tools. The bear case is stronger on evidence today: the company has no disclosed revenue, no named contracts, no public product demos, and no operating history comparable to Palantir, Anduril, Shield AI, or the primes. IronNet shows that elite government pedigrees and cyber ambition can still fail when product-market fit and revenue quality do not materialize. The right diligence stance is therefore to treat founder access as an entry ticket, not a moat. The moat becomes real only if Cathedral proves cleared deployments, repeatable government procurement, and defensible proprietary cyber-AI capability.[CP004, CP005, CP014, CP040, CP041, CP043]
| Moat hypothesis | Supporting evidence | Threat | Severity | Diligence ask |
|---|---|---|---|---|
| Founder government access | Reuters reports Pentagon and national-security ties | Access may be scrutinized or decay with political change | High | List signed pilots, contracting route, sponsor, and procurement authority |
| AI-native offensive plus defensive cyber platform | Reported mission spans offensive and defensive cyber ops | No public product, benchmark, or deployment proof | High | Demonstrate live workflow and technical evaluation against XBOW/Horizon3 |
| Defense buyer urgency | Large cyber and AI contract vehicles exist across incumbents | Urgency can flow to primes instead of startups | High | Identify budget line and why existing vehicle cannot solve it |
| Offensive cyber capability supply | Exploit/intermediary market exists | Opaque supply chain, legal risk, and procurement inefficiency | High | Explain make/buy policy, authorities, and compliance controls |
| Potential speed versus incumbents | Startup can iterate faster than systems integrators | Incumbents have 20-year relationships and cleared staff | High | Show deployment timeline and clearance plan |
| Brand and capital from elite investors | $160M raise with a16z and Sequoia leadership | IronNet shows prestige does not equal durable revenue | Medium-high | Require revenue quality and renewal evidence before valuation credit |
This register intentionally weights evidence gaps as risks because Cathedral is stealth and has no disclosed contracts or revenue.
[CP001, CP002, CP003, CP004, CP005, CP034]Founder access and AI-native mission score well, but public product proof and contract proof are the key gaps.
[CP001, CP003, CP004, CP005, CP014, CP041]3.6 Exhibits
04Financials
4.1 Capital structure and current financial state
Cathedral’s finance chapter starts with a simple but unusually aggressive capital structure: the reviewed July 2026 coverage reports a $160 million primary financing at a $1.4 billion post-money valuation, led by Andreessen Horowitz and Sequoia Capital. On a pure primary-round basis, that implies roughly 11.4% new-money dilution and a pre-money valuation around $1.24 billion. The important underwriting point is not the arithmetic; it is the sequencing. Public sources describe Cathedral as a stealth military cyber startup founded by four former DOGE staffers, but they do not disclose revenue, ARR, recognized backlog, gross margin, paying customers, or awarded contracts. Therefore this chapter treats revenueRunRate and ARR as null, not small. The $160 million round is enough to fund a serious product-and-capture campaign, but the valuation is being carried by founder access, investor conviction, and defense-AI market appetite rather than by disclosed financial traction.[CI001, CI002, CI003, CI004, CI005, CI006]
| Item | Public value / status | Derived financial read | Quality | Diligence ask |
|---|---|---|---|---|
| Primary financing | $160M July 2026 round | Only disclosed capital raised in reviewed pack | high | Confirm gross versus net proceeds and any secondary component |
| Post-money valuation | $1.4B | Late-stage-like valuation despite no disclosed revenue | high | Request cap table and fully diluted share count |
| Implied new-money dilution | ~11.4% | $160M / $1.4B before option-pool or secondary adjustments | medium | Confirm option-pool expansion and investor preferences |
| Implied pre-money valuation | ~$1.24B | $1.4B minus $160M primary proceeds | medium | Confirm whether valuation was post-money on fully diluted basis |
| Total disclosed raised | $160M | No prior disclosed Cathedral round found in retained sources | medium | Ask for SAFE/convertible history and founder equity grants |
| Revenue run rate / ARR | Pre-revenue from public-evidence standpoint | medium | Request current ARR, pilots, deferred revenue and backlog | |
| Disclosed contracts | No named awarded contract, OTA, SBIR, CRADA or customer surfaced | medium | Request pipeline and award documents by agency |
Null cells mean no public disclosure in the fetched source pack, not zero economic value. Dilution and pre-money rows are derived from reported round terms.
[CI001, CI002, CI003, CI004, CI005, CI006]| Missing metric | Why it matters | Current public status | Severity | Diligence path |
|---|---|---|---|---|
| ARR / revenue run rate | Determines whether valuation has revenue support | blocking | Request recognized revenue, ARR, pilots and deferred revenue schedule | |
| Named contracts / customers | Validates path from access to procurement | blocking | Request award documents, OTAs, SBIRs, CRADAs and agency sponsors | |
| Gross margin by vehicle | Separates software-like upside from services or compute resale | material | Request projected gross margin by FFP, cost-plus, OTA and subscription lines | |
| Monthly burn and cash balance | Converts $160M proceeds into runway | material | Request post-close cash, payroll, compute, security and capture spend | |
| Compute commitments | Determines whether data-center strategy is capex or opex heavy | material | Request data-center LOIs, capex budget, lease terms and minimum commitments | |
| Pipeline conversion timing | Needed for CAC/payback proxy in defense sales | material | Request pipeline by agency, stage, vehicle and expected award date |
All nulls are explicit evidence gaps. They should not be converted into zero values in report metadata or valuation models.
[CI007, CI008, CI010, CI011, CI022, CI023]The reported round math bridges from a $1.24B implied pre-money valuation to $1.4B post-money after $160M of primary capital.
Waterfall uses reported round terms only and does not model preferences, secondary proceeds, warrants or option-pool changes.
[CI001, CI004, CI005, CI006]4.2 Path to revenue and contract economics
The most realistic path to revenue is staged rather than SaaS-linear. Cathedral can pursue non-dilutive SBIR or STTR awards, prototype work through OTA-style channels, CRADA collaboration with federal labs, DIU-style commercial-technology solicitations, and eventually IDIQ task orders or program-of-record procurement. Each route has different unit-economics consequences. Firm-fixed-price work can create better upside if Cathedral productizes cyber-AI capabilities and controls delivery cost, but it also pushes cost overrun risk onto the contractor. Cost-reimbursement work can de-risk early R&D cash conversion, yet it usually limits margin upside and is less proof of product repeatability. IDIQ vehicles and task orders can create sticky revenue once a mission owner standardizes around a tool, but the order flow is not automatic. With no disclosed pipeline, CAC and payback should be proxied through procurement-cycle duration, proposal burden, security accreditation effort, and conversion from prototype to production.[CI012, CI013, CI014, CI015, CI016, CI017]
| Vehicle / model | Revenue mechanism | Margin / cash-flow implication | Likely Cathedral use | Disclosure status |
|---|---|---|---|---|
| SBIR / STTR | Non-dilutive R&D funding and commercialization bridge | Helpful for early validation; not proof of scalable ARR | Prototype cyber-AI work before production awards | No Cathedral award disclosed |
| OTA / prototype pathway | Prototype agreement outside standard FAR contract pattern | Can accelerate adoption but still needs production transition | Mission prototype or rapid capability test | No Cathedral OTA disclosed |
| CRADA | Federal lab collaboration with non-federal entity | Validation without government funding to the company | Technical collaboration or test environment | No Cathedral CRADA disclosed |
| Firm-fixed-price | Fixed price for deliverables or services | Higher upside if productized; contractor bears cost-overrun risk | Future packaged cyber tool or managed capability | No pricing disclosed |
| Cost-reimbursement | Payment of allowable incurred costs within a ceiling | Lower loss risk but lower margin upside and weaker product proof | Early R&D or bespoke defense work | No contract disclosed |
| IDIQ / task orders | Umbrella vehicle with orders for defined work | Sticky if task orders recur; revenue arrives only as orders are placed | Program-of-record or agency-wide cyber vehicle | No vehicle disclosed |
The table describes financially relevant contract paths, not Cathedral contracts. Each row is a potential path because no public Cathedral award is disclosed.
[CI012, CI013, CI014, CI015, CI016, CI017]Cathedral’s likely financial path runs from prototype validation to contract vehicles before any durable program revenue can be underwritten.
[CI017, CI018, CI019, CI020, CI021, CI041]4.3 Capital intensity, burn, and runway
The compute strategy is the biggest financial swing factor. CityBiz, EquityPandit, and Startup Fortune all report that Cathedral is exploring acquiring or partnering with a data center, which moves the company away from a purely variable-cloud-cost profile. Broader AI infrastructure sources support taking that seriously: Goldman Sachs expects AI to drive a large increase in data-center power demand, DOE expects domestic data-center energy use to double or triple by 2028, and Epoch AI estimates frontier training compute has been growing by roughly 4x to 5x annually. None of those sources gives Cathedral’s actual compute bill, so the chapter uses scenarios rather than pretending precision. A $160 million round can last about 40 months at $4 million of monthly burn, about 20 months at $8 million, and roughly 13 months at $12 million; a single $40 million compute outlay would materially shorten every case.[CI009, CI033, CI034, CI036, CI037, CI038]
| Scenario | Monthly burn / outlay assumption | Runway from $160M | What must be true | Risk note |
|---|---|---|---|---|
| Lean stealth build | $4M monthly burn | ~40 months | Small team, rented cloud, limited capture spend | May understate cyber-cleared hiring and compute |
| Base defense-AI build | $8M monthly burn | ~20 months | Meaningful engineering, security, capture and cloud spend | Needs visible contract conversion before next raise |
| Heavy compute / capture | $12M monthly burn | ~13 months | Large cleared team plus model training and proposal burden | Fast next-round trigger if revenue is delayed |
| Dedicated compute shock | $40M one-time outlay plus $8M monthly burn | ~15 months after outlay | Data-center acquisition/partnership requires cash commitment | Materially changes runway without revenue |
| Anduril-style scale reference | Large facilities and projected operating loss at scale | Not directly comparable | Revenue and contracts can coexist with heavy losses | Shows capital intensity persists even after scale |
Runway rows are scenario math from reported proceeds, not company guidance. They exclude taxes, financing costs, working-capital timing and any debt/project-finance structure.
[CI009, CI029, CI031, CI033, CI034, CI036]The $160M round can imply multiyear runway or barely a year depending on monthly burn and compute commitments.
Ranges are illustrative and use simple cash divided by burn; they are not company guidance.
[CI036, CI037, CI038, CI039, CI040, CI045]4.4 Defense-tech comparables and revenue trajectory
The better comparable lesson is that defense-tech revenue can scale, but usually after years of productization, procurement wins, and facility buildout. Palantir is the mature public software comparator: its SEC filings show multibillion-dollar revenue and major government contribution, including 2025 growth in government revenue and significant U.S. government revenue. Anduril is the private defense-tech scale comparator: Sacra estimates it reached $2.2 billion of 2025 revenue, projects $4.3 billion for 2026, and reports a $5 billion Series H at a $61 billion valuation alongside a projected 2026 operating loss. Shield AI is a smaller but relevant autonomous-systems comparator with Sacra-estimated revenue around $300 million for the year ending March 2025. Cathedral is much earlier than all three: its valuation resembles a late-stage defense-tech premium, while its disclosed revenue base resembles a seed-stage evidence gap.[CI025, CI026, CI027, CI028, CI029, CI030]
| Company | Latest public / analyst revenue marker | Valuation / funding marker | Financial lesson for Cathedral | Gap versus Cathedral |
|---|---|---|---|---|
| Cathedral | $160M raised at $1.4B post-money | Large balance sheet before disclosed revenue | No ARR, contracts, gross margin or backlog disclosed | |
| Anduril | Sacra estimates $2.2B 2025 revenue and $4.3B projected 2026 revenue | $5B Series H at $61B valuation per Sacra | Defense-tech valuations can be supported by large revenue and contracts | Cathedral lacks equivalent revenue proof |
| Palantir | $4.48B approximate 2025 revenue; government revenue up 53% in 2025 | Public company filing-grade financials | Government software can scale to multibillion revenue | Cathedral lacks segment revenue and public filings |
| Shield AI | Sacra estimates ~$300M revenue for year ending March 2025 and >=$540M implied 2026 revenue | $2.3B valuation marker per Sacra | Autonomous-defense startups can show revenue before IPO scale | Cathedral remains pre-revenue publicly |
| Anduril capex lens | Revenue scale coexists with projected 2026 operating loss and $1B Long Beach complex | Capital-intensive growth can require huge primary capital | Compute/facilities may shorten runway despite large raise | Cathedral compute commitment undisclosed |
Sacra values are analyst estimates, Palantir values come from SEC filings, and Cathedral values are reported financing facts. Cathedral revenue cells are intentionally null.
[CI001, CI007, CI025, CI026, CI027, CI028]Cathedral has no disclosed revenue while Palantir, Anduril and Shield AI show the scale of financial proof later-stage defense-tech comparables have produced.
Cathedral is charted at 0 solely to visualize absence of disclosure; the report treats Cathedral revenueRunRate and ARR as null.
[CI025, CI026, CI028, CI029, CI030, CI046]4.5 Financial verdict and diligence blockers
The financial verdict is track-with-caution: the balance sheet is strong for a newly formed stealth startup, but the underwriting file is thin. Cathedral has enough primary capital to recruit, build, clear security hurdles, and chase early defense programs, yet there is no public evidence of revenue quality, margin path, contract backlog, customer concentration, or sales efficiency. The most important diligence blockers are therefore precise and obtainable: current cash balance after round expenses; monthly burn by payroll, compute, security, and capture; committed data-center capex or minimum take-or-pay obligations; pipeline by agency and contract vehicle; and any letter, award, OTA, CRADA, SBIR, or classified sponsor that explains why a $1.4 billion valuation is rational before revenue. Until those items are produced, investors should underwrite the round as a well-financed option on government cyber-AI adoption rather than as a revenue-backed defense software company.[CI007, CI008, CI010, CI011, CI022, CI023]
4.6 Exhibits
05Product & Technology
5.1 Product surface and evidence boundary
Cathedral’s product should be underwritten as a classified or near-classified cyber-operations platform, not as a publicly documented SaaS product. The public record supports only a mission-level definition: AI-driven military cyber operations for U.S. government buyers, spanning both offensive and defensive capabilities against adversaries such as China. No reviewed source provides Cathedral product names, screenshots, API documentation, deployment diagrams, performance claims, ATO status, or named users. Therefore the chapter treats the offensive and defensive modules below as inferred capability buckets derived from public reporting and comparable systems, while marking Cathedral-specific maturity as stealth. The likely customer workflow starts with an authorized mission or network-defense requirement, moves through AI-assisted discovery and analysis, and ends with human approval, remediation, or mission packaging. That evidence boundary is not a footnote; it is the central product risk.[CE001, CE002, CE003, CE004, CE036, CE045]
| Capability bucket | User / buyer job | Cathedral maturity label | Evidence status | Diligence ask |
|---|---|---|---|---|
| Offensive reconnaissance | Mission team scopes targets and exposed surfaces | plausible prototype | Inferred from offensive cyber reporting and AIxCC/Project Naptime analogues | Show authorized workflow, target constraints, and audit logs |
| Autonomous vulnerability discovery | Find exploitable flaws before adversaries | plausible but unverified | Supported by AIxCC and frontier-model analogues, not Cathedral docs | Provide benchmark suite, true-positive rate, and reproduction process |
| Exploit generation / validation | Turn vulnerability into tested exploit path | highest-risk inferred | Analogues show progress and limits; Cathedral evidence absent | Show sandbox design, legal approvals, kill switches, and human review |
| Mission packaging / operator handoff | Prepare action plan for cyber operators | speculative | No public Cathedral workflow or C2 boundary | Provide rules of engagement and approval chain |
| Threat detection and triage | Prioritize alerts, vulnerabilities, and exploit evidence | nearer-term inferred | Gold Eagle, Anthropic defenders, and OpenAI misuse monitoring support the pattern | Show telemetry sources, detection precision, and analyst UX |
| Incident-response automation | Recommend containment and remediation steps | plausible but unverified | NIST/RMF and defensive-agent analogues support need | Show rollback controls and tested playbooks |
| Network monitoring / exposure management | Continuously map exploitable paths | commercially proven by analogues | NodeZero/HackerOne analogues; Cathedral proof absent | Show agent deployment model and environment coverage |
| Classified compute enclave | Train/evaluate on restricted cyber data | reported strategy, not verified build | Data-center plan and Claude Gov/JWCC context support need | Show facility, accreditation, clearance, and data-boundary evidence |
Rows are capability hypotheses for a stealth company; Cathedral-specific maturity is not verified unless the row says reported.
[CE001, CE002, CE003, CE004, CE007, CE009]The likely workflow splits into offensive and defensive paths, both requiring human authorization and controlled evidence capture.
Pipeline is inferred from public mission claims and analogues; Cathedral has not published a workflow diagram.
[CE001, CE002, CE003, CE004, CE009, CE016]5.2 Architecture stack and compute model
The most plausible architecture is an agentic stack wrapped by classified data controls: model orchestration, cyber tool use, security-data retrieval, sandboxed exploit testing, operator review, and deployment connectors into government environments. Cathedral’s reported interest in a data-center acquisition or partnership is unusually important because offensive cyber AI cannot be evaluated only in commodity cloud terms. Training corpora may contain vulnerability intelligence, exploit artifacts, telemetry from sensitive networks, or classified mission context; inference may generate exploit chains or remediation instructions that cannot leave accredited boundaries. Kliger’s reported Pentagon chief data officer role and Anthropic/Claude-in-DoD exposure add founder-market context, but they do not prove Cathedral has solved model governance. The architecture table therefore separates inferred layers from verified dependencies and flags where management must produce diagrams, model cards, isolation controls, logging plans, and evaluation results.[CE005, CE006, CE007, CE008, CE019, CE040]
| Layer / component | Likely role | Dependency | Principal risk | Evidence status |
|---|---|---|---|---|
| Frontier model layer | Reason over code, logs, configurations, and mission context | LLMs or specialist cyber models; classified fine-tuning data | Hallucinated findings or unsafe exploit suggestions | Inferred from mission and analogues |
| Agent orchestration | Plan tasks, call tools, persist state, and branch investigations | Tool sandbox, planner, memory, retrieval, policy engine | Prompt/tool injection and runaway automation | Inferred |
| Security-data retrieval | Search CVEs, code, telemetry, vulnerability intel, and prior incidents | Licensed threat intel and government data rights | Data poisoning, stale intelligence, classification spillage | Inferred |
| Exploit sandbox | Compile, run, and validate exploit or patch hypotheses | Isolated labs, emulators, fuzzers, CTF-style ranges | Escapes, invalid proofs, or unsafe dual-use output | Inferred from offensive scope |
| Defensive workflow connectors | Feed SIEM/SOAR, ticketing, patch, and monitoring workflows | DoD network APIs, identity, logging, and change control | Integration breaks in classified enclaves | Inferred |
| Classified compute / enclave | Host models and data for restricted missions | Dedicated data center, cleared staff, ATO boundary | Capital intensity and accreditation schedule | Reported intent, unverified execution |
| Compliance evidence system | Maintain SSP, controls, tests, model evals, and audit trails | FedRAMP/RMF/SP 800-53/CMMC evidence | ATO delay or inherited-control mismatch | Required by deployment context |
Architecture is externally inferred; the table intentionally avoids claiming access to Cathedral private system diagrams.
[CE003, CE004, CE006, CE007, CE008, CE019]A military AI cyber platform would need model, agent, data, sandbox, integration, and compliance layers inside a restricted compute boundary.
[CE007, CE008, CE019, CE026, CE028, CE031]5.3 Analogues and capability benchmarks
Public analogues make Cathedral technically plausible while also narrowing what should not be assumed. DARPA AIxCC shows that autonomous cyber reasoning systems can compete on vulnerability discovery and repair in controlled open-source settings. Horizon3.ai NodeZero and Dreadnode show that autonomous pentesting and offensive-security-agent tooling are already product categories. Anthropic, OpenAI, and Google show that frontier models can assist cyber work, but their materials also emphasize safety boundaries, misuse monitoring, and benchmark limitations. HackerOne and arXiv sources are especially useful adverse checks: they suggest AI can multiply offensive work, but fully autonomous real-world exploitation remains unreliable and needs human validation. Cathedral’s differentiation, if real, would come from classified data, mission integration, and cleared compute rather than from the generic fact of using LLM agents.[CE010, CE011, CE012, CE013, CE014, CE015]
| Analogue | Relevant capability | What it proves | Limit when applying to Cathedral | Evidence status |
|---|---|---|---|---|
| DARPA AIxCC | Autonomous cyber reasoning for open-source vulnerabilities | AI systems can find and repair vulnerabilities in controlled competition settings | Competition success does not prove classified operational readiness | Primary and developer-signal evidence |
| XBOW validation benchmarks | Autonomous offensive-security benchmarking | Public benchmark infrastructure exists for AI security agents | Benchmarks can saturate and may not predict real zero-day performance | Developer-signal evidence |
| Horizon3.ai NodeZero | Commercial autonomous penetration testing | There is a market pattern for continuous self-directed pentesting | Enterprise exposure management differs from military offensive missions | Official and docs evidence |
| Dreadnode | Security-agent infrastructure and evaluations | Teams are building platforms to evaluate and deploy offensive agents | Infrastructure tooling is not equivalent to government ATO or mission authority | Official and docs evidence |
| HackerOne Hai / AI red teaming | Human-plus-agent vulnerability validation | Hybrid workflows may compress exploitability validation time | HackerOne itself warns AI alone is insufficient | Company and adverse review evidence |
| Anthropic Claude cyber / Claude Gov | Frontier-model cyber capability and classified-model packaging | Frontier vendors can support national-security environments and cyber evals | Anthropic emphasizes safety boundaries and remaining limitations | Official research evidence |
| OpenAI threat-actor disruption | Monitoring malicious AI use | Model providers can detect and disrupt misuse patterns | Does not prove offensive automation is safe for military use | Official adverse-use evidence |
| Palantir AIP | Operational AI workflow integration | AI can be embedded in mission workflows with controls | AIP is broader operating software, not a cyber exploit engine | Official analogue evidence |
Analogue rows frame capability plausibility and risk; none is direct Cathedral product proof.
[CE010, CE011, CE012, CE013, CE014, CE015]Defensive triage is the most supportable near-term path; autonomous exploit generation is the least verified and highest-risk bucket.
Ordinal scores are qualitative and source-backed; no private Cathedral evidence was available.
[CE010, CE011, CE014, CE015, CE016, CE019]5.4 Deployment, integration, and compliance surface
The deployment surface is likely harder than the model demo. A military cyber product touching NIPR, SIPR, JWICS, mission clouds, or tactical DDIL environments would need identity, logging, enclave, data-labeling, export-control, vulnerability-disclosure, and operator-authorization controls. FedRAMP and DoD impact-level assessment matter if Cathedral ships a cloud service; NIST RMF and SP 800-53 matter for ATO; CMMC matters for defense-contractor CUI; NIAP may matter if evaluated endpoint or appliance components appear. DefenseScoop’s JWCC reporting shows the Pentagon is seeking AI and ML across classifications and impact levels, but that is a demand signal, not Cathedral authorization. The diligence ask is concrete: request the system security plan, inherited-control matrix, deployment boundary diagram, clearance roster, red-team reports, model-evaluation protocol, and any sponsor or authorizing official correspondence.[CE026, CE027, CE028, CE029, CE030, CE031]
| Requirement / control family | Why it matters | Likely Cathedral status | Evidence needed | Primary diligence owner |
|---|---|---|---|---|
| FedRAMP or equivalent cloud authorization | Government cloud services require authorized control inheritance | Not publicly disclosed | FedRAMP package, boundary diagram, inherited controls | Security / compliance lead |
| DoD impact-level assessment (IL4/IL5/IL6 as applicable) | CUI, mission data, and classified workloads map to different control depths | Not publicly disclosed | Impact-level target, DISA or sponsor assessment path | Cloud architect |
| RMF / Authority to Operate | Operational use on DoD systems requires risk acceptance | Not publicly disclosed | SSP, SAR, POA&M, authorizing official path | Program security officer |
| NIST SP 800-53 controls | Baseline security and privacy controls for federal systems | Not publicly disclosed | Control matrix and test evidence | GRC lead |
| CMMC | Defense-contractor CUI handling can require certification or assessment | Not publicly disclosed | CUI boundary and assessment status | Contracting / compliance |
| NIAP / Common Criteria | Evaluated products may be needed for some security components | Conditional / unknown | Product component list and protection-profile mapping | Product security |
| Security clearances and classified facility access | Model training, evaluation, and operations may touch classified material | Implied but unverified | Clearance roster, facility sponsorship, need-to-know process | People / facilities security |
| Model safety and misuse controls | Offensive AI creates dual-use and escalation risk | Not publicly disclosed | Eval protocol, refusal/override policy, human authorization logs | AI safety / mission lead |
The table is a requirements map, not a claim that Cathedral has obtained any authorization or certification.
[CE019, CE026, CE027, CE028, CE029, CE030]The heaviest burden sits at classified operations, ATO, and impact-level cloud boundaries rather than model development alone.
1–5 burden score is a qualitative diligence ranking, not a regulatory metric.
[CE026, CE027, CE028, CE029, CE030, CE031]Cathedral’s inferred product depends on compute, clearance, model, data, ATO, and mission-buyer dependencies converging.
[CE007, CE008, CE019, CE031, CE032, CE033]5.5 Roadmap and technical risk
The credible roadmap is incremental rather than magical autonomy. A sane sequence would start with analyst copilots and vulnerability triage, then move to sandboxed exploit validation, classified compute accreditation, controlled defensive pilots, and only later tightly authorized offensive mission support. The core technical risks are model hallucination, invalid exploit chains, adversarial prompt and tool manipulation, evaluation on classified data that outsiders cannot reproduce, and governance failures when offensive recommendations look plausible but are wrong. Gold Eagle and defensive-agent analogues suggest near-term value in vulnerability coordination and remediation prioritization. The riskiest claims are autonomous exploit generation and C2-adjacent automation, because they combine safety, legality, reliability, and escalation concerns. Until Cathedral releases evidence or customers validate deployments under clearance, the product verdict is high-upside but unproven.[CE009, CE016, CE017, CE018, CE020, CE034]
| Roadmap stage / feature | Public status | Technical risk | Verification artifact | Priority |
|---|---|---|---|---|
| Analyst copilot for vulnerability triage | Inferred, not disclosed | False positives and weak prioritization | Side-by-side analyst evaluation on real tickets | High |
| Autonomous vulnerability discovery | Plausible, not disclosed | Benchmark overfit and low real-world recall | Blind benchmark with reproduction package | High |
| Sandboxed exploit validation | Plausible, not disclosed | Hallucinated exploit chains and unsafe tool use | Isolated range logs and human approval workflow | High |
| Defensive remediation automation | Plausible, not disclosed | Bad patch or containment recommendation | Rollback-tested playbooks and change-control integration | Medium |
| Classified compute enclave | Reported intent only | ATO delay, capex, and data-boundary failures | Facility plan, SSP, clearance evidence | High |
| DoD network integration | No public proof | Identity/logging/API mismatch across NIPR/SIPR/JWICS | Boundary and connector architecture | High |
| Autonomous offensive mission support | Speculative | Escalation, legal authority, and reliability failures | Rules-of-engagement controls and red-team evidence | Blocking |
Roadmap labels are diligence hypotheses; no Cathedral source has released a dated product roadmap.
[CE003, CE004, CE007, CE016, CE017, CE018]5.6 Exhibits
06Customers
6.1 Addressable buyer set, not disclosed customers
Cathedral’s customer chapter has to start with an evidence boundary: public sources support a large addressable national-security buyer set, but they do not support any named Cathedral customer. Reuters describes the company as a recently launched stealth military cybersecurity startup trying to secure U.S. government contracts for AI-driven offensive and defensive cyber operations, and other 2026 coverage repeats the military-cyber mission without adding customers, deployments, pilots, or contract IDs. The most direct buyer is U.S. Cyber Command, with NSA and service cyber components as natural mission owners; CISA, CIA, DIA, and close allied defense ministries are plausible adjacent surfaces. That is market access, not adoption. For diligence, the active-customer count, production-deployment count, NRR, churn, renewal rate, and revenue concentration should remain null until Cathedral provides award documents or customer references.[CU001, CU002, CU005, CU008, CU009, CU010]
| Segment | Buyer / user / payer | Mission need | Likely procurement vehicle | Access difficulty | Evidence gap |
|---|---|---|---|---|---|
| USCYBERCOM / Cyber National Mission Force | Combatant command and mission teams | AI-assisted offensive and defensive cyber operations | Classified program, OTA prototype, SBIR transition | Very high | No Cathedral pilot or sponsor named |
| NSA Cybersecurity Collaboration Center | NSA mission and DIB cybersecurity teams | Intel-driven defense of the defense industrial base | Partnership, classified contract, OTA, CRADA-like collaboration | Very high | No technical integration disclosed |
| Navy Fleet Cyber / 10th Fleet | Service cyber component and Navy networks | Fleet network operations, cyber mission force support | Service contract, OTA, GSA, program office | High | No Navy evaluation disclosed |
| 16th Air Force | Air Force cyber, ISR, and cryptologic organizations | Operate and defend networks; cyber effects support | AFWERX SBIR/STTR, service OTA, program office | High | No Air Force sponsor disclosed |
| MARFORCYBER | Marine Corps cyberspace component | Marine cyber operations aligned with USCYBERCOM | Service cyber contract, OTA, innovation hub | High | No Marine Corps use case named |
| Space Force cyber organizations | Space Delta and space mission-system defenders | Protect satellite and ground-system mission infrastructure | SpaceWERX/AFWERX, classified contract, program office | High | No space-mission authorization disclosed |
| Intelligence community | CIA, DIA, NSA mission owners | Foreign military intelligence and sensitive cyber operations | Classified contract, cleared facility, program office | Very high | Classified demand may be invisible publicly |
| Civilian and allied cyber agencies | CISA, DHS components, UK/Five Eyes allies | Critical-infrastructure defense and allied military AI modernization | GSA, DHS vehicle, bilateral allied procurement | Medium-high | No non-DoD customer evidence disclosed |
This is an addressable-buyer map, not a customer list; Cathedral has no public named customers as of the run date.
[CU001, CU005, CU009, CU010, CU011, CU012]| Proof category | Public value | Evidence read | Interpretation | Diligence ask |
|---|---|---|---|---|
| Named paying customer | No customer named in Reuters, TNW, Gizmodo, or Cyber Daily coverage | Treat customer count as null | Ask company for customer list by classification level | |
| Production deployment | No production use case or deployment outcome disclosed | No adoption trajectory can be quantified | Request pilot-to-production status and deployment dates | |
| Awarded contract | USAspending, SAM.gov, and DoD contract pages are the public search surfaces; no cited public award names Cathedral | Public evidence does not prove revenue | Request award IDs, vehicle, prime/sub role, and classification caveats | |
| Pilot or prototype sponsor | No DIU, SBIR, service, or IC sponsor was publicly identified | Pipeline may exist privately but is unverified | Request sponsor letters, evaluation memos, and contracting officer contacts |
Null means undisclosed in the reviewed public source set; classified or not-yet-announced awards could exist but cannot be assumed.
[CU005, CU006, CU008, CU040, CU045]Public evidence is strongest on addressable buyer fit and weakest on actual customers and retention.
Scores are ordinal evidence-visibility judgments, not operating KPIs.
[CU005, CU007, CU031, CU037, CU040, CU041]6.2 Buying process and procurement vehicles
The most plausible first sale is not a conventional enterprise SaaS close; it is a defense procurement sequence. DIU, SBIR/STTR, AFWERX, SOFWERX, DEFENSEWERX, and OTA pathways can make a prototype possible before Cathedral is mature enough for a program-of-record competition. DIU explicitly invites commercial entities, including first-time government sellers, to submit solution briefs, while SBIR/STTR offers non-dilutive prototype funding and transition language. OTAs are especially relevant because they can fund prototypes and follow-on production outside standard procurement contracts, but GAO also notes planning and consortia discipline issues. GSA schedules and public contract portals matter later, once product scope, pricing, compliance, and agency demand are clearer. A realistic sales-cycle model is therefore twelve to twenty-four months from first mission conversation to meaningful revenue, and longer for classified scale.[CU018, CU019, CU020, CU021, CU022, CU023]
| Vehicle | Best fit for Cathedral | Typical entry point | Scale path | Key friction |
|---|---|---|---|---|
| DIU Commercial Solutions Opening | Commercial AI cyber prototype with urgent mission pull | Solution brief to DIU solicitation | Prototype OT or transition to DoD sponsor | Requires mission owner and operational evaluation |
| SBIR/STTR | Non-dilutive R&D for eligible small business | Topic proposal and Phase I award | Phase II, transition, commercialization | Eligibility, topic fit, and transition funding |
| Other Transaction Authority | Prototype or follow-on production outside standard FAR contract | Service, DIU, or consortium OTA | Follow-on production if statutory conditions met | Planning, consortium fees, and transition discipline |
| GSA Multiple Award Schedule | Later repeat buying for less-classified software/services | Schedule award and agency ordering | Multi-agency ordering surface | Not ideal before product, pricing, and compliance mature |
| AFWERX / SpaceWERX | Air Force or Space Force cyber and AI pilots | SBIR/STTR open topic or challenge | Program office or Space Force transition | Pilot-to-program handoff risk |
| SOFWERX / DEFENSEWERX | SOCOM or service problem discovery | Challenge, prize, assessment, demo event | Sponsor-funded prototype or OTA | Often pre-procurement and non-binding |
| Program of record | Enduring budget and scaled deployment | Requirement, acquisition strategy, competition | Multi-year sustainment and expansion | Slowest path; requires proof, budget, and compliance |
Vehicles are ordered roughly from entry-friendly experimentation to durable program scale; actual path depends on classified sponsor demand.
[CU018, CU019, CU020, CU021, CU022, CU023]Cathedral’s likely customer path begins with access and mission fit, but revenue requires procurement, compliance, and deployment proof.
Journey is inferred from public procurement and compliance pathways, not from a disclosed Cathedral sale.
[CU007, CU018, CU020, CU023, CU026, CU029]Each stage narrows the account set from broad addressable demand to disclosed, durable revenue evidence.
Values are evidence-visibility counts from this chapter, not Cathedral operating metrics.
[CU005, CU008, CU018, CU020, CU023, CU025]6.3 Compliance and classified-access gates
Compliance is likely to be as important as model quality for Cathedral’s customer conversion. A cyber capability delivered into federal or DoD environments can face FedRAMP, DoD impact-level, ATO, CMMC, product assurance, and classified-access gates. DCSA’s facility-clearance language is particularly important: any entity providing goods or services involving classified information generally needs facility clearance before performance. Microsoft’s DoD IL5 documentation also illustrates that DoD cloud authorization adds requirements beyond ordinary commercial hosting. Cathedral has not publicly disclosed any FedRAMP listing, ATO, DoD IL authorization, CMMC posture, NIAP validation, facility clearance, TS/SCI-cleared staffing base, or classified program access. That absence should not be over-read for a stealth company, but it is a gating diligence package before investors can underwrite deployability.[CU026, CU027, CU028, CU029, CU030, CU031]
| Requirement | Why it matters for Cathedral | Likely evidence needed | Current public status | GTM implication |
|---|---|---|---|---|
| FedRAMP | Cloud services used by federal agencies usually need authorization | Marketplace listing, agency ATO package, assessor evidence | No Cathedral listing disclosed | Blocks unclassified SaaS-style deployment until solved |
| DoD Impact Levels IL4/IL5/IL6 | DoD cloud workloads require impact-level posture and provisional authorization | DoD SRG mapping, PA/ATO evidence, hosting boundary | No public DoD IL evidence | May force GovCloud/DoD cloud architecture early |
| Authority to Operate | Mission systems generally need customer authorization before operational use | System security plan, controls, testing, authorizing official | No ATO disclosed | Can add months after prototype selection |
| CMMC / DIB cyber hygiene | Defense contractors handling CUI face cybersecurity self-assessment or certification obligations | SPRS/CMMC records, policy scope, assessor outputs | No Cathedral status disclosed | Diligence ask before any CUI work |
| NIAP / Common Criteria | Security products may face product-assurance expectations in national-security environments | Protection profile mapping or evaluated-products status | No validation disclosed | May matter for endpoint/network products |
| Facility clearance and FOCI | Classified contract performance requires cleared entity vetting | DCSA facility clearance and FOCI clearance | No FCL disclosed | Hard gate for classified programs |
| Personnel clearances / TS/SCI | Operators and engineers may need access to classified networks and data | Cleared personnel roster and program access approvals | No public staffing detail | Limits how fast pilots can become classified deployments |
Rows are compliance gates likely to apply to a defense cyber vendor; null public status is a diligence gap, not proof the control is absent.
[CU026, CU027, CU028, CU029, CU030, CU031]The go-to-market flow has parallel buyer, contracting, and security tracks before a classified cyber tool can scale.
Flow is a procurement model derived from public DoD mechanisms.
[CU018, CU020, CU023, CU026, CU029, CU030]6.4 Founder access advantage and revolving-door critique
Cathedral’s unusual go-to-market advantage is also its most obvious adverse diligence angle. Reuters reported that the founding team has deep ties to the Trump administration and national-security officials, including the Pentagon, and those relationships could reduce the cost of finding a mission owner. In defense technology, that access is valuable because the hardest early step is often getting a real sponsor to define an urgent, funded problem. The same fact pattern creates a revolving-door and conflict-of-interest risk: critical coverage has already framed the ex-DOGE transition into military technology as controversial, and Reuters warned that government-contract scrutiny could intensify if political control changes. The diligence ask is not only whether Cathedral can get meetings; it is whether those meetings can survive ethics review, contracting-office scrutiny, protests, congressional oversight, and changes in administration.[CU003, CU007, CU041, CU042, CU043]
| Metric / risk | Public value | Implication | Investor diligence path |
|---|---|---|---|
| Customer count | No denominator for adoption, retention, or concentration | Request active customers, pilots, and funded contracts split by classification | |
| NRR / GRR / churn | Durability cannot be underwritten from public data | Request cohort retention, renewal rates, and lost-pilot reasons | |
| Top-customer concentration | A single classified sponsor could dominate early revenue | Request revenue concentration by customer and program | |
| Land-and-expand path | Prototype to OTA to program of record | Expansion is plausible but depends on compliance and mission proof | Ask for funded milestones and transition sponsor |
| Revolving-door scrutiny | Material adverse risk | Government access could accelerate sales or trigger oversight backlash | Review ethics opinions, recusals, cooling-off rules, and communications logs |
This table intentionally preserves null customer metrics instead of fabricating early traction.
[CU037, CU038, CU040, CU041, CU042, CU043]6.5 Comparable adoption lessons
Anduril, Palantir, and Shield AI show what Cathedral must eventually prove. Shield AI’s valuation step-up after a U.S. Air Force deal suggests that mission validation can unlock private financing, but it also shows that a named service relationship is the proof point investors want. Anduril’s $5 billion Series H and manufacturing expansion show the scale of capital and production credibility that defense buyers reward once a company moves beyond demos. Palantir is the durability benchmark: its Form 10-K describes Gotham serving defense and intelligence users for over a decade and discloses more than $1 billion of government revenue for 2024. Cathedral has none of that customer proof yet. Its near-term customer story is therefore a high-access pipeline thesis, not a validated adoption thesis.[CU032, CU033, CU034, CU035, CU036, CU037]
| Comparable | Early DoD customer proof | How adoption scaled | Lesson for Cathedral | Limitation of analogy |
|---|---|---|---|---|
| Shield AI | Reported U.S. Air Force deal preceded a $12.7B valuation | Mission-specific autonomous aircraft validation drew large financing | A named service deal can re-rate a defense AI startup | Autonomy aircraft is not cyber operations |
| Anduril | Public reporting shows massive financing and defense manufacturing expansion | Scaled hardware/software programs and facilities reinforced credibility | DoD adoption tends to require production capacity, not only pitch access | Anduril has a longer operating history |
| Palantir | 10-K says Gotham served defense and intelligence users for over a decade | Government revenue exceeded $1B in 2024 after long embedding cycle | Deep government software accounts can become durable and large | Palantir’s path took many years |
| UK MOD AI partnership | UK official source shows allied defense ministries seeking strategic AI modernization | Allied AI modernization creates later expansion surfaces | Five Eyes expansion is plausible after U.S. validation | No Cathedral allied customer evidence |
Comparables show adoption patterns and proof thresholds; none are evidence that Cathedral has won a customer.
[CU032, CU033, CU034, CU035, CU017, CU020]6.6 Exhibits
07Risks
7.1 Political, reputational, and ethics risk
Cathedral’s highest-risk issue is not simply that its founders know government; it is that the company’s public identity is built around the DOGE-to-defense pipeline. Reuters, Vanity Fair, WIRED, AP, CREW, and GovExec collectively create an adverse record that investors cannot treat as noise: DOGE alumni held sensitive roles, accessed government systems, became politically salient, then moved into venture-backed businesses that may sell back to the same government. That raises three diligence questions at once. First, did any founder obtain nonpublic knowledge of classified or procurement-sensitive requirements that could create an unfair competitive advantage? Second, will contracting officers and ethics officials be comfortable with awards so soon after DOGE service? Third, will a post-2028 administration or a Democratic Congress turn Cathedral into a test case for DOGE-related oversight? The mitigant is narrow: independent ethics review, recusals, cooling-off compliance, clean-room product requirements, and board-level documentation before any bid.[CR006, CR007, CR009, CR010, CR013, CR014]
| Risk | Category | Likelihood | Impact | Evidence | Mitigation | Residual exposure |
|---|---|---|---|---|---|---|
| DOGE revolving-door scrutiny | Political / reputational | High | High | Adverse reporting ties Cathedral to DOGE alumni selling into defense | Independent ethics review, clean-room requirements, recusals | High until first nonpolitical awards are visible |
| Insider-knowledge / conflict challenge | Legal / procurement | Medium-high | High | Former Pentagon and agency roles overlap with target buyer needs | OCI counsel memo, bid firewall, procurement-integrity training | High |
| Post-2028 administration shift | Political / budget | Medium | High | Reuters and Vanity Fair identify political-change scrutiny risk | Win through normal contracting channels and diversify sponsors | Medium-high |
| Founder conduct and Marko Elez controversy | Key-person / reputation | High | Medium-high | AP and Reuters report resignation after racist posts and rehire support | Founder code of conduct, board oversight, succession options | Medium-high |
| AI offensive-cyber escalation | Ethics / legal | Medium | High | Lawfare and CSIS identify liability, scope, deterrence, and escalation concerns | Rules of engagement, legal review, human authorization gates | High |
| Export-control limits on expansion | Regulatory | Medium | High | ITAR, EAR, and Wassenaar can constrain technical-data or tool transfer | Classification matrix, licensing roadmap, cleared counsel | Medium-high |
| No disclosed revenue or contracts | Commercial | High | High | Public reporting discloses financing but not revenue, customers, or awards | Require signed awards and funded pilots before valuation step-up | High |
| Single-buyer U.S. government concentration | Commercial / dependency | High | High | Mission is to secure U.S. government cyber contracts | Multi-agency pipeline and allied path only after export review | High |
Likelihood and impact are analyst-scored from cited adverse reporting, legal sources, and procurement context; values are qualitative, not actuarial.
[CR006, CR007, CR008, CR009, CR010, CR020]Cathedral’s residual risk clusters in political scrutiny, commercial proof, single-buyer concentration, and offensive-cyber oversight.
Qualitative scoring uses public evidence only; no internal risk register was available.
[CR006, CR007, CR020, CR028, CR035, CR039]7.2 Founder and key-person risk
Cathedral’s key-person risk is unusually high for a unicorn-priced company because the investment case is inseparable from four young founders’ access, credibility, and execution. Public reporting identifies Gavin Kliger, Luke Farritor, Marko Elez, and Jack Stein as ex-DOGE staffers, but it does not show a seasoned management bench, revenue leadership, program-management leadership, cleared contracting leadership, or a public track record of delivering classified cyber programs. Kliger’s Pentagon AI proximity may help product discovery, but it also concentrates political and ethics exposure. Elez adds a separate reputational tail risk: AP reported his resignation after racist posts were linked to him, followed by support for his return from Musk, Vance, and Trump. In defense procurement, where trust, security-clearance judgment, and congressional optics matter, that controversy can become a contract diligence issue rather than a mere HR footnote. The mitigation is a credible operating bench, independent security leadership, founder-conduct covenants, and succession planning.[CR002, CR011, CR020, CR021, CR022, CR023]
| Person / role | Known public signal | Risk | Likelihood | Impact | Mitigation / diligence ask |
|---|---|---|---|---|---|
| Gavin Kliger / CEO | Reported former Pentagon chief data officer near AI and Anthropic issues | Insider-knowledge optics and buyer concentration | Medium-high | High | Review cooling-off compliance, OCI memo, and communications logs |
| Luke Farritor / founder | Reported ex-DOGE and former SpaceX intern; WIRED identified him among young engineers | Thin senior government operating record | Medium | Medium-high | Assess program-management bench and cleared contracting leadership |
| Marko Elez / founder | AP and Reuters report racist-post controversy, resignation, and rehire support | Reputation, judgment, clearance, and contract protest risk | High | High | Board conduct covenant, security review, and customer acceptability checks |
| Jack Stein / founder | Reported ex-DOGE co-founder with limited public operating detail | Founder concentration and limited independent track record | Medium | Medium | Request role scope, prior delivery evidence, and succession plan |
| Four-founder group | Investment case centers on access and recent government context | Execution and relationship concentration | High | High | Hire experienced defense GM, CISO, GC, capture lead, and program managers |
The table separates reported founder facts from diligence conclusions; public evidence does not yet show a deep executive bench.
[CR002, CR011, CR020, CR021, CR025, CR026]Commercial proof and political scrutiny score highest because both can independently impair financing and procurement.
Scores are ordinal 1-10 diligence severity values, not probabilities.
[CR001, CR005, CR008, CR013, CR020, CR028]7.3 Offensive-cyber ethics and escalation risk
Cathedral’s reported mission—AI-enabled offensive and defensive military cyber operations—sits in a domain where private contractors can create state effects without the same visibility as conventional weapons programs. Lawfare’s framework is directly relevant: before private firms participate in offensive cyber activity, policymakers need to define objectives, permissible actions, target scope, legal authority, liability, and responsibility for harms to innocent third parties. The Atlantic Council adds that offensive cyber supply chains are opaque, fragmented, and strategically sensitive, especially where zero-day exploits, AI-enabled vulnerability discovery, and China competition overlap. CSIS further warns that below-threshold cyber activity can evade deterrence logic, while autonomy-policy commentary shows that even DOD insiders can misunderstand where human control and cyber exemptions fit. Cathedral can mitigate this only with rigorous rules of engagement, audit logs, legal review, human authorization boundaries, vulnerability-equities governance, and red-team oversight independent from growth incentives.[CR003, CR028, CR029, CR030, CR031, CR032]
Political, legal, cyber-ethics, and commercial risks transmit into award timing, valuation confidence, and buyer trust.
Flow is causal synthesis from public evidence rather than a measured process map.
[CR009, CR010, CR013, CR020, CR028, CR029]7.4 Regulatory, export-control, and verification risk
The regulatory risk is broader than ordinary cybersecurity compliance. If Cathedral builds tools, services, models, or operational support for U.S. military cyber missions, counsel must map ITAR, EAR, Wassenaar, procurement-integrity, post-employment, and classified-contracting constraints before the company hires abroad, shares technical data, partners with a data center, sells to allies, or accepts non-U.S. strategic investors. ITAR and EAR analysis is not optional if cyber capabilities become defense articles, defense services, controlled technical data, advanced computing items, or dual-use controlled technology. The verification risk is equally important: the very secrecy that protects national-security work also prevents outside investors from independently validating contract scope, operational performance, legal authorizations, and customer acceptance. A clean diligence process therefore needs a secure data room, counsel memo, export-control classification matrix, facility-clearance roadmap, contracting-history evidence, and a protocol for investors to verify classified claims through cleared counsel rather than press narratives.[CR013, CR014, CR015, CR016, CR017, CR034]
| Rule / issue | Jurisdiction | Status | Likelihood | Severity | Residual exposure | Diligence path |
|---|---|---|---|---|---|---|
| Post-employment restrictions | United States / former federal officials | Active rules | Medium | High | High if founders communicate with former agencies inside restricted windows | Counsel memo mapping covered positions, contacts, and one-year cooling-off obligations |
| Organizational conflicts of interest | Federal procurement | Active FAR regime | Medium-high | High | High if prior nonpublic requirements shape bids | Independent OCI review and clean-room product-requirements process |
| Procurement integrity | Federal procurement | Active FAR regime | Medium | High | Medium-high around any source-selection or bid information | Training, certifications, and bid-team firewalls |
| Use of public office for private gain | Federal ethics | Active ethics regime | Medium | Medium-high | Medium where DOGE affiliation drives customer or investor claims | Marketing review and prohibition on implying official endorsement |
| DOGE transparency / FOIA scrutiny | Federal oversight | Active watchdog inquiries | High | Medium-high | High reputationally if records show weak controls | Monitor CREW, GAO, IG, and congressional requests |
| Treasury / sensitive-system access aftereffects | Federal oversight and courts | Historical but still politically salient | Medium-high | High | High for Elez and DOGE-alumni narrative | Assess security findings, clearance implications, and customer objections |
This is not a legal opinion; it flags regimes for counsel and contracting-officer validation before any bid.
[CR013, CR014, CR015, CR016, CR017, CR018]| Control area | Why Cathedral may trigger it | Likelihood | Impact | Mitigation | Open verification item |
|---|---|---|---|---|---|
| ITAR / USML | Military cyber tools or defense services may involve controlled defense articles, services, or technical data | Medium | High | Formal commodity-jurisdiction / classification analysis | Which components are defense articles or defense services? |
| EAR / advanced computing | AI models, compute, software, or technical data transfers may fall under Commerce controls | Medium | High | ECCN review, deemed-export controls, license screening | What model weights, exploit tooling, or compute access are export controlled? |
| Wassenaar dual-use controls | Dual-use cyber and intrusion-related technology may face multilateral control expectations | Medium | Medium-high | Country-by-country control matrix | Which allied deployments are legally possible? |
| Classified contracting | National-security cyber work may be classified and hard for investors to verify | High | High | Cleared counsel and secure data-room process | Can investors validate awards and performance without public disclosure? |
| Data-center / compute partnership | Dedicated compute can introduce facility, export, security, and dependency constraints | Medium | Medium-high | Security review, supply-chain review, contractual audit rights | Who controls compute, logs, model isolation, and incident response? |
Rows are diligence hypotheses derived from public mission reporting and export-control authorities, not determinations that a specific item is controlled.
[CR003, CR034, CR035, CR036, CR037, CR038]7.5 Commercial, concentration, and procurement risk
Commercially, Cathedral has the risk profile of a pre-revenue government-market option priced like a proven defense-tech platform. Reuters and follow-on coverage establish the financing, mission, investors, and founder access, but the public record reviewed here does not establish revenue, signed contracts, production users, renewal behavior, or mission outcomes. The buyer universe is also concentrated: Cathedral is explicitly pursuing U.S. government contracts, while export controls and classified work constrain rapid international diversification. Even if the Pentagon wants faster commercial adoption, procurement still favors incumbents with contract vehicles, past performance, cleared workforces, program managers, and agency relationships. Booz Allen, Leidos, Palantir, Anduril, and Washington Technology’s government-contractor ranking illustrate the competitive asymmetry. Cathedral’s mitigants are real only when evidenced: signed pilots, funded awards, contracting vehicles, security authorizations, referenceable program sponsors, and nonpolitical procurement wins that survive leadership changes.[CR001, CR004, CR005, CR008, CR039, CR040]
| Risk | Monitorable trigger | Threshold / event | Action implication |
|---|---|---|---|
| Political / DOGE scrutiny | Congressional, GAO, IG, or FOIA activity names Cathedral or a founder | Formal inquiry, subpoena, award pause, or negative contracting-officer finding | Suspend valuation step-up and require legal remediation plan |
| Conflict-of-interest challenge | Competitor protest or agency ethics review challenges access to nonpublic information | Any sustained OCI or procurement-integrity finding | Treat as thesis-breaking until bids are restructured |
| Founder conduct risk | Customer security office or clearance process raises Elez or other founder concerns | Denied clearance, sponsor objection, or board investigation | Require role change or governance remedy before investing |
| Offensive-cyber oversight failure | Product roadmap lacks legal authorization, logging, human authorization, or target-scope controls | No documented ROE or customer-authority chain | Block deployment-dependent revenue underwriting |
| Export-control blocker | Counsel cannot classify tools/data or license path for planned foreign work | No usable ITAR/EAR matrix before non-U.S. transfer | Assume U.S.-only TAM and reduce upside case |
| Commercial proof gap | No signed funded government award or referenceable pilot by next financing milestone | Only press/investor narrative supports traction | Do not underwrite $1.4B+ mark without a deep discount |
| Incumbent displacement failure | Pipeline loses to primes or lacks contract vehicle access | No credible vehicle, sponsor, or integration path | Reframe as acquisition/partner target rather than standalone platform |
| Single-buyer concentration | Revenue, if any, depends on one office, one administration, or one classified program | Top customer or sponsor effectively controls survival | Require multi-program pipeline and budget-line visibility |
Kill criteria convert broad risks into observable diligence triggers for an investment committee or later refresh.
[CR005, CR007, CR010, CR013, CR020, CR028]7.6 Exhibits
08Valuation
8.1 The mark and the recommendation
Cathedral’s valuation chapter starts with unusually clean round math and unusually weak operating proof. The reported $160 million financing at a $1.4 billion post-money valuation implies about $1.24 billion pre-money and roughly 11.4% primary dilution. That is an extraordinary price for a company founded around 2025 with no disclosed revenue, no disclosed ARR and no disclosed contract wins. Because the denominator is missing, no revenue multiple or ARR multiple can be computed; using zero would be misleading, so the correct field is null. The investment stance is therefore research-more with low confidence, high risk and an expensive valuation stance. The mark can be explained by the founders’ DOGE-linked government access, elite investor sponsorship, and defense-tech market heat, but public evidence does not yet support a fundamentals-backed buy recommendation.[CV001, CV002, CV003, CV004, CV005, CV006]
| Metric | Value | Interpretation | Evidence status |
|---|---|---|---|
| New capital raised | $160 million | Large institutional round for a company founded around 2025 | Reported by multiple news sources |
| Post-money valuation | $1.4 billion | Extraordinary founding-stage mark | Reported by multiple news sources |
| Implied pre-money valuation | $1.24 billion | $1.4B post minus $160M new money | Calculated from reported round terms |
| Implied ownership sold | 11.4% | $160M divided by $1.4B post-money | Calculated from reported round terms |
| Disclosed revenue | No public revenue or ARR, so no revenue multiple is computable | Evidence gap / negative finding | |
| Disclosed contracts | No public government contract wins cited in fetched sources | Evidence gap / negative finding | |
| Valuation stance | expensive | Price reflects team, access and market heat more than fundamentals | Analyst conclusion |
| Recommendation | research-more | Do not buy until contract and product evidence catches up with the mark | Analyst conclusion |
Null cells indicate unavailable public evidence, not zero revenue or zero contracts.
[CV001, CV002, CV003, CV004, CV005, CV034]8.2 Comparable companies and multiples
The comparable set shows why Cathedral is both plausible and alarming. Anduril and Shield AI prove that private defense-tech winners can command very large valuations in 2026, but both are much further along than Cathedral. Anduril’s reported $61 billion valuation sits on public revenue scale and a visible product footprint, while Shield AI’s 2026 round is tied to autonomous aircraft and Air Force-related traction. Palantir is even less stage-comparable, but it is useful as the public-market upper-bound because its high multiple is backed by SEC filings, revenue disclosure and government growth. Rebellion Defense is a private software reference, not a valuation anchor, because the fetched sources do not provide a clean current multiple. Against seed and Series A benchmarks, Cathedral’s founding-stage mark remains an extreme outlier.[CV011, CV012, CV013, CV014, CV015, CV016]
| Comparable | Valuation / status | Revenue or contract proof | Implied revenue multiple | Relevance to Cathedral | Key limitation |
|---|---|---|---|---|---|
| Cathedral | $1.4B post-money; $1.24B pre-money | No disclosed revenue; no disclosed contracts | Direct subject and current mark | Multiple cannot be computed | |
| Anduril | $61B valuation after 2026 $5B Series H | Reported 2025 revenue about $2.2B | ~27.7x trailing revenue | Shows defense-tech winners can command software-like marks | Much more mature with revenue and product proof |
| Shield AI | $12.7B 2026 post-money; $5.3B 2025 prior mark | Coverage ties valuation to autonomous aircraft and Air Force-related traction | Shows late-stage autonomous defense premium | Revenue not publicly disclosed in fetched sources | |
| Palantir | Public company; market cap around $300B+ in 2026 market-data frame | SEC and company filings disclose revenue and government growth | Public P/S observable; very high upper-bound software reference | Government software valuation ceiling reference | Public, profitable-scale company; not a startup comp |
| Rebellion Defense | Private defense-software reference; current public valuation not disclosed | Website describes product positioning for critical-asset intelligence | Useful as private defense-software context | No comparable round multiple in fetched sources | |
| Seed-stage benchmarks | Typical seed marks are far below $1.4B | Usually pre-revenue or very early revenue | Shows Cathedral founding mark is exceptional | Generic benchmarks, not defense-cyber-specific | |
| Series A benchmarks | Typical Series A marks are far below $1.24B pre-money | Usually require pilots, LOIs or revenue evidence | Shows even later early-stage comps are much lower | Generic benchmarks vary by sector and team | |
| Defense-tech bubble critique | Warns that capital can outrun contracts and revenue | Highlights procurement and patience risk | Adverse calibration for pre-revenue premium | Critique is sector-wide rather than Cathedral-specific |
Multiples are approximate; null means the fetched sources do not disclose revenue for that comparable or for Cathedral.
[CV004, CV005, CV011, CV012, CV013, CV015]Cathedral is far below late-stage defense winners in absolute value but far above normal founding-stage benchmarks.
Benchmark bars use high-end representative ranges from fetched benchmark sources.
[CV001, CV011, CV015, CV016, CV023, CV024]Cathedral sits in the high-valuation-risk / low-proof quadrant compared with more mature defense-tech references.
Axes are qualitative scores: x=public proof, y=valuation risk.
[CV004, CV011, CV014, CV017, CV018, CV019]8.3 Grow-in scenarios and sensitivity
The cleanest way to underwrite a pre-revenue mark is to ask what future contract revenue must arrive for the price to become ordinary. At a 10x revenue multiple, Cathedral needs roughly $140 million of annual revenue to support $1.4 billion; at 5x, it needs about $280 million; even at an aggressive 15x, it needs roughly $93 million. That frames the 18-to-24-month test. The bull case requires rapid conversion of access into paid military-cyber programs and repeatable software economics. The base case is a well-funded product and pilot buildout that still leaves the current valuation hard to defend. The bear case is a procurement or political delay that forces dilution, down-round pricing, or a long period where the valuation is merely a narrative mark.[CV026, CV027, CV028, CV029, CV030, CV031]
| Scenario | 18-24 month contract/revenue assumption | Valuation logic | Probability signal | Downside trigger |
|---|---|---|---|---|
| Bull | Converts access into $100M-$150M+ annualized contract revenue or equivalent funded programs | At 10x-15x revenue, $93M-$140M supports the current mark | Only plausible if paid government work arrives quickly | No paid pilot or program path by month 24 |
| Base | Builds team and pilots but has limited revenue visibility | Current $1.4B remains hard to justify until revenue approaches $140M at 10x | Most consistent with public evidence today | Pilot activity stays unpaid or procurement slips |
| Bear | Political scrutiny or procurement drag blocks meaningful contracts | Valuation reprices toward early-stage defense benchmarks or requires heavy dilution | Supported by adverse bubble and no-traction evidence | Round becomes an access story without technical proof |
| Low-multiple grow-in | Needs about $280M revenue at 5x | Implies a very steep ramp for a new cyber company | Unlikely without major multi-year awards | Budget or accreditation delays |
| High-multiple grow-in | Needs about $93M revenue at 15x | Requires Palantir/Anduril-like software premium before public proof | Possible only with exceptional strategic contract capture | Multiple compression in defense tech |
Ranges are what-if underwriting math, not management guidance; revenue remains undisclosed.
[CV026, CV027, CV028, CV029, CV030, CV031]The current mark can be justified only in the bull path; base and bear cases argue for waiting or repricing.
Ranges are scenario heuristics anchored on grow-in revenue math and public comps.
[CV026, CV027, CV028, CV029, CV030, CV031]8.4 Premium decomposition and risks to the mark
The valuation premium decomposes into four positive pieces and one large negative offset. Team premium is real because the founders’ government experience may reduce procurement friction. Investor-signal premium is also real because a16z and Sequoia leading with board seats changes market perception. Market premium is supported by Anduril, Shield AI, Palantir enthusiasm, and a16z’s American Dynamism thesis. Scarcity premium reflects the small number of visible AI-native military cyber teams. The offset is the largest diligence problem: no public product, revenue, or contract evidence. Adverse defense-tech-bubble commentary is directly relevant because it warns that venture prices can run ahead of procurement reality. Political scrutiny, future dilution, data-center or compliance capex, and comparison with more mature comps are the main ways the $1.4 billion mark can fail.[CV007, CV008, CV009, CV010, CV032, CV033]
| Component | Indicative contribution to $1.4B story | Evidence basis | Investment implication |
|---|---|---|---|
| Team / access premium | Very high | Founders are reported former DOGE staffers with government ties | Real signal but politically fragile |
| Investor-signal premium | High | a16z and Sequoia led and took board seats | Validates opportunity but can amplify price |
| Defense-AI market premium | High | Anduril, Shield AI and sector funding boom show strong demand | Supports category enthusiasm |
| Scarcity premium | Medium | Few AI-native military cyber startups with this access profile are visible | May fade as more teams enter |
| Traction discount | Large negative | No public revenue, no public contracts, and no product disclosure | Prevents a fundamentals-backed buy call |
| Dilution / preference overhang | Negative | Large upfront round may precede expensive infrastructure and compliance spend | Future financing terms matter before entry |
Qualitative decomposition only; it explains the mark but does not prove fair value.
[CV007, CV008, CV009, CV010, CV033, CV039]| Argument | Evidence supporting it | What would change the view |
|---|---|---|
| Thesis: elite team can navigate government cyber demand | Reported DOGE alumni founders and military-cyber focus | Verified technical leadership and classified-capable delivery team |
| Thesis: investors are underwriting a real defense-tech boom | Anduril, Shield AI and a16z American Dynamism support category tailwinds | Evidence that Cathedral wins differentiated programs, not just attention |
| Thesis: cyber operations can scale faster than hardware defense | Software/cyber focus could avoid some hardware manufacturing constraints | Proof of deployable product and accreditation path |
| Anti-thesis: valuation precedes traction | No disclosed revenue, contracts, or product page | Signed paid pilots or program-of-record path |
| Anti-thesis: political access is not durable moat | DOGE/Trump ties could invite scrutiny or change with politics | Bipartisan customer pull and career-government sponsorship |
| Anti-thesis: defense-tech bubble risk | Adverse sources warn capital may outrun procurement reality | Reasonable entry price or independently validated contract backlog |
The anti-thesis is valuation-specific; it does not deny that defense cyber demand is real.
[CV006, CV007, CV008, CV010, CV032, CV040]The valuation story adds team, investor and market premiums, then subtracts a major traction discount.
Waterfall values are illustrative decomposition, not independent appraisals.
[CV008, CV009, CV025, CV032, CV041, CV042]8.5 Final diligence asks and thesis-break triggers
The IC should not treat Cathedral as uninvestable forever; it should treat the current price as unproven. A credible path to justify the mark exists if the company can show paid government cyber demand, defensible technical capability, an accreditation path, and software-like economics. The required diligence package is therefore specific: contract pipeline and bid status, customer conversations where permissible, product demonstrations, security and deployment architecture, cap-table preferences, data-center economics, and ethics controls around political relationships. The thesis breaks if no paid pilot or government contracting path emerges within 18 to 24 months, if the business depends mostly on political access, or if future rounds reveal that the upfront valuation created a preference overhang. Until those checks clear, the right conclusion is research-more, not buy.[CV034, CV035, CV036, CV037, CV038, CV039]
| Diligence topic | Missing evidence | Why it matters | Thesis-break threshold |
|---|---|---|---|
| Contract pipeline | Named agencies, bid stages, paid pilots, award probability and timing | Determines whether $140M+ revenue can become plausible | No credible paid path within 18-24 months |
| Revenue model | Pricing, contract type, gross margin and services/software mix | Determines fair multiple and cash needs | Only bespoke services with weak margin profile |
| Technical proof | Demo evidence, cyber capability boundaries, accreditation and security controls | Separates capability from access narrative | No independently validated product capability |
| Cap table and preferences | Liquidation preferences, option pool, pro-rata and governance terms | Large round may create preference overhang | Terms make common or later entry unattractive |
| Political / procurement risk | Ethics review, conflict controls and bipartisan customer sponsorship | Access can become liability under scrutiny | Contracts appear dependent on political relationships |
| Infrastructure plan | Data-center partner, compute cost and classified deployment plan | Capital needs can drive dilution | Compute or compliance cost overwhelms budget |
These asks define the path from research-more to investable; each is currently private evidence.
[CV035, CV036, CV038, CV039, CV040, CV043]8.6 Exhibits
Disclaimer
This report is for informational purposes only, relies on limited public sources about a stealth defense company, and does not constitute investment advice.
Evidence index
| ID | Statement | Confidence | Sources |
|---|---|---|---|
| CO001 | Cathedral is a stealth AI-powered military cybersecurity startup focused on U.S. military cyber capabilities. | High | SO001, SO002, SO004, SO006 |
| CO002 | Cathedral should be treated as founded in 2025 because Reuters reported in July 2026 that it launched in recent months and the founders came out of 2025 DOGE roles. | Medium | SO001, SO002, SO013 |
| CO003 | Cathedral plans to seek U.S. government contracts for AI-driven military cyber operations. | High | SO001, SO002, SO004, SO006 |
| CO004 | Cathedral’s described mission includes both offensive and defensive cyber capabilities against U.S. adversaries such as China. | High | SO001, SO002, SO004, SO006 |
| CO005 | Cathedral is exploring acquiring a data center or partnering with a data-center provider for dedicated compute power. | High | SO001, SO002, SO004 |
| CO006 | The public founder set consists of Gavin Kliger, Luke Farritor, Marko Elez, and Jack Stein, all former DOGE staffers. | High | SO001, SO002, SO004, SO006 |
| CO007 | Gavin Kliger was reported as a Cathedral cofounder and former Pentagon chief data officer. | High | SO001, SO004, SO006 |
| CO008 | Luke Farritor was reported as a Cathedral cofounder, former SpaceX intern, and DOGE operator involved in GSA cost cutting. | High | SO001, SO004, SO006 |
| CO009 | Marko Elez was reported as a Cathedral cofounder who previously worked at SpaceX and DOGE/Treasury. | High | SO001, SO004, SO006, SO014 |
| CO010 | Jack Stein was reported as a Cathedral cofounder and former DOGE staffer. | High | SO001, SO002, SO006 |
| CO011 | Cathedral closed a $160 million funding round in the weeks before the July 22, 2026 Reuters report. | High | SO001, SO002, SO004, SO005 |
| CO012 | Cathedral’s 2026 financing valued the company at a $1.4 billion post-money valuation. | High | SO001, SO002, SO004, SO005, SO006 |
| CO013 | Andreessen Horowitz and Sequoia Capital led Cathedral’s funding round. | High | SO001, SO002, SO004 |
| CO014 | Andreessen Horowitz and Sequoia Capital both took board seats in connection with the round. | High | SO001, SO002, SO004 |
| CO015 | No Cathedral revenue, ARR, or revenue run rate was disclosed in the reviewed public sources. | Medium | SO001, SO002, SO004, SO006 |
| CO016 | No Cathedral customer count, named customer, government contract, or pilot was disclosed in the reviewed public sources. | Medium | SO001, SO002, SO004, SO006 |
| CO017 | No Cathedral headcount number was disclosed in the reviewed public sources. | Medium | SO001, SO002, SO004, SO006 |
| CO018 | No official Cathedral website, newsroom announcement, or product documentation was found in the reviewed source pack. | Medium | SO001, SO002, SO024, SO026 |
| CO019 | Reuters reported that Cathedral’s valuation, name, mission, and Elez’s involvement had not previously been reported. | High | SO001, SO002 |
| CO020 | A Cathedral spokesperson declined to comment, and Andreessen Horowitz and Sequoia did not respond to Reuters requests for comment. | Medium | SO001 |
| CO021 | Kliger was reported as involved in the Pentagon’s highly publicized legal fight with Anthropic over military use of Claude. | High | SO001, SO019, SO020, SO021, SO023 |
| CO022 | The Anthropic-Pentagon dispute created a live AI military-governance backdrop for Cathedral’s founding team. | High | SO001, SO019, SO020, SO021, SO022, SO023 |
| CO023 | Elez’s prior Treasury access raised security-control concerns, including GAO-reported control gaps around DOGE system access. | High | SO001, SO014 |
| CO024 | Elez quit DOGE after racist social-media posts were reported and was later rehired after Trump and Vice President JD Vance advocated reinstatement. | High | SO001, SO005 |
| CO025 | Reuters framed Cathedral as exposed to scrutiny over government contracts if political control changes after the 2026 midterm elections. | High | SO001, SO005 |
| CO026 | DOGE was established by White House executive order in January 2025. | High | SO013, SO012 |
| CO027 | DOGE officially ended on July 4, 2026 according to independent reporting. | Medium | SO017, SO018 |
| CO028 | Reuters reported that DOGE cost-cutting operations were associated with more than 250,000 people leaving the federal workforce. | High | SO001, SO015, SO016 |
| CO029 | Andreessen Horowitz also backed Special, another DOGE-alumni startup pursuing private-sector cost-cutting. | High | SO001, SO010, SO011 |
| CO030 | The Atlantic’s coverage of Special was skeptical of DOGE alumni entering complex industries with scant qualifications. | High | SO011, SO010 |
| CO031 | Andreessen Horowitz’s American Dynamism practice publicly focuses on companies serving national-interest markets. | High | SO024, SO025 |
| CO032 | Sequoia’s official materials show continued AI ecosystem engagement through its AI Ascent programming and company portfolio. | High | SO026, SO027 |
| CO033 | Anduril raised a $5 billion Series H at a $61 billion valuation in 2026, giving a defense-technology valuation benchmark. | High | SO008, SO009 |
| CO034 | The White House launched Gold Eagle in July 2026 as an AI-enabled cybersecurity vulnerability coordination clearinghouse. | High | SO007, SO028, SO030 |
| CO035 | Gold Eagle coverage described a public-private mechanism for faster vulnerability detection, prioritization, and patching. | High | SO007, SO028, SO030, SO031 |
| CO036 | Dark Reading argued that Gold Eagle targets a real vulnerability-coordination gap but left implementation details unclear. | Medium | SO029, SO030 |
| CO037 | Cathedral’s governance disclosure is limited to four named founders and two investor board-seat holders, not a complete board or control-rights package. | Medium | SO001, SO002, SO004, SO024, SO026 |
| CO038 | The founder roster creates key-person dependence because public evidence centers government access, Pentagon ties, and DOGE backgrounds rather than a broader operating bench. | Medium | SO001, SO004, SO014, SO019 |
| CO039 | The data-center plan would add infrastructure execution and capital-intensity risk to a software-like cyber startup story if pursued directly. | Medium | SO001, SO002, SO004, SO008 |
| CO040 | Cathedral’s stage is best described as stealth/private-undisclosed despite a mega-round because product, customer, revenue, and headcount details remain unavailable. | Medium | SO001, SO002, SO004, SO006 |
| CO041 | The round gives Cathedral at least $160 million of disclosed total funding because no earlier financing was found in the reviewed public record. | Medium | SO001, SO002, SO004 |
| CO042 | Cathedral’s investor map combines lead investors, founder-control risk, prospective U.S. government customers, and infrastructure partners because those are the stakeholder dependencies visible in public evidence. | Medium | SO001, SO002, SO024, SO026 |
| CO043 | Gizmodo and Hoodline covered the Cathedral round with a skeptical tone around DOGE alumni monetizing controversial government roles. | Medium | SO004, SO005 |
| CO044 | Cyber Daily corroborated that Cathedral intends to bolster U.S. military cyber defense and operations through AI. | Medium | SO006, SO001, SO002 |
| CO045 | The Reuters-origin page itself was not accessible as readable text during the fetch and was recorded as JavaScript-blocked. | High | SO003, SO001 |
| CM001 | Cathedral’s relevant market is AI-enabled cyber tooling and services for U.S. military and national-security operators, not all enterprise cybersecurity or physical defense hardware. | High | SM002, SM003, SM004 |
| CM002 | Cyber Command and the NSA represent distinct operational and collaboration nodes in the U.S. military cyber ecosystem. | High | SM003, SM004 |
| CM003 | The U.S. federal cyber budget context is at least approximately $26 billion annually in the 2026 planning frame, but that top-down number includes spend outside Cathedral’s core wedge. | Medium | SM001, SM020, SM021 |
| CM004 | DoD budget materials are the primary public anchor for defense-wide cyber and IT spend, but they do not isolate every classified offensive cyber line item. | Medium | SM002 |
| CM005 | U.S. Cyber Command’s mission language makes in-house military cyber capability a direct status-quo substitute for startup software. | Medium | SM003 |
| CM006 | NSA’s Cybersecurity Collaboration Center shows that government-industry cyber collaboration is part of the operating model for national-security cyber work. | Medium | SM004 |
| CM007 | CISA frames federal cybersecurity as a national risk-management function, making civilian-agency cyber spend adjacent but not core to Cathedral’s military wedge. | Medium | SM020, SM021 |
| CM008 | GAO keeps federal information security and cybersecurity on its high-risk agenda, which supports demand but also signals implementation difficulty. | Medium | SM005, SM006 |
| CM009 | CRS procurement reporting reinforces that public contract data is a partial view of how DoD spends and reports contracting dollars. | Medium | SM007 |
| CM010 | DARPA’s AI Cyber Challenge is official evidence that automated AI vulnerability discovery and remediation is a current U.S. government priority. | Medium | SM008 |
| CM011 | Defense SBIR/STTR and SBIR.gov describe a public entry route for small businesses seeking defense R&D funding. | Medium | SM009, SM026 |
| CM012 | DIU’s solution and work-with-us pages show a commercial-solutions channel intended to pull private-sector technology into DoD missions. | Medium | SM024, SM025 |
| CM013 | FAR Part 16 documents the contract-type machinery that later-stage defense software vendors must eventually fit. | Medium | SM019 |
| CM014 | DAU and GAO materials show that Other Transactions are a relevant DoD acquisition instrument but also carry planning and governance risks. | Medium | SM031, SM032 |
| CM015 | USAspending.gov, SAM.gov, and DoD contract releases are useful public award windows but are insufficient to reveal classified cyber programs. | Medium | SM016, SM017, SM018 |
| CM016 | MarketsandMarkets estimates the artificial intelligence in military market at $9.2 billion in 2023 and $38.8 billion by 2028, a 33.3% CAGR. | Medium | SM011 |
| CM017 | Grand View Research estimates artificial intelligence in military at $9.31 billion in 2024 and $19.29 billion by 2030, a 13.0% CAGR. | Medium | SM012 |
| CM018 | The difference between the MarketsandMarkets and Grand View military-AI forecasts is large enough to require a range rather than a single TAM point estimate. | Medium | SM011, SM012 |
| CM019 | Mordor Intelligence projects the cyberwarfare market at $40.13 billion in 2026 and $52.27 billion by 2031, a 5.43% CAGR. | Medium | SM014 |
| CM020 | MarketsandMarkets maintains a cyber-warfare market category covering threat intelligence, data protection, vulnerability management, identity, managed security, and resilience solutions. | Medium | SM013 |
| CM021 | Grand View’s broad cybersecurity market estimate is useful context but is too wide to equal Cathedral’s TAM because it includes civilian, consumer, and enterprise spend. | Medium | SM015, SM021 |
| CM022 | American Dynamism materials from a16z show investor interest in companies positioned around the national interest and defense modernization. | Medium | SM010 |
| CM023 | Anduril is the most visible venture-backed defense-tech comparable for Cathedral, but its hardware-heavy autonomy stack is not a direct cyber-software TAM proxy. | Medium | SM029, SM030 |
| CM024 | Canonical run facts place Anduril’s latest comparable financing at $5 billion raised and a $61 billion valuation, underscoring the valuation ceiling investors may reference. | Low | SM029, SM030 |
| CM025 | Cathedral’s core included spend should be AI cyber tools, vulnerability discovery, mission workflow software, and services sold into DoD or intelligence-community cyber operators. | Medium | SM003, SM004, SM008 |
| CM026 | Broad IT services, general FedRAMP SaaS, consumer cybersecurity, and physical defense hardware should be excluded from the core Cathedral SAM. | Medium | SM019, SM021, SM030 |
| CM027 | Offensive cyber and cyber-weapons spending is likely material but hard to size publicly because operations, authorities, and program lines are sensitive. | Medium | SM003, SM004, SM014 |
| CM028 | The most important status-quo alternatives are internal Cyber Command capability, NSA collaboration, incumbent contractors, and manual penetration-testing workflows. | Medium | SM003, SM004, SM018, SM021 |
| CM029 | Incumbent contractors have an advantage because public awards, FAR contract types, and program-of-record conversion favor vendors that can survive long procurement cycles. | Medium | SM016, SM018, SM019 |
| CM030 | A plausible defense startup path is SBIR or DIU entry, prototype or Other Transaction work, and later conversion into a FAR contract or program of record. | Medium | SM009, SM024, SM025, SM031, SM019 |
| CM031 | Security controls, zero-trust alignment, and NIST-style cybersecurity frameworks are adoption constraints for mission cyber software. | Medium | SM022, SM023, SM027 |
| CM032 | AI risk-management expectations from NIST make autonomous cyber tools a trust and governance sale, not only a capability sale. | Medium | SM028, SM008 |
| CM033 | China and nation-state cyber competition increase urgency for AI-accelerated defensive and offensive cyber operations. | Medium | SM003, SM004, SM008 |
| CM034 | Post-Ukraine cyber priority and the broader move toward software-defined warfare support budget attention, but the public source pack does not isolate a Cathedral-specific spend pool. | Low | SM002, SM003, SM015 |
| CM035 | A DOGE-style efficiency push would favor automation and smaller teams, but public diligence still needs proof that DoD buyers will trust a stealth startup with classified cyber workflows. | Low | SM006, SM008, SM028 |
| CM036 | Procurement, authority-to-operate, classified-network deployment, and security-clearance requirements make 18-24 month adoption cycles a reasonable diligence assumption rather than a verified Cathedral fact. | Low | SM019, SM022, SM023, SM032 |
| CM037 | No public source in this chapter verifies Cathedral revenue, customers, or signed government contracts, so SOM should be framed as zero verified public traction rather than a modeled share. | Low | |
| CM038 | The narrowest public SOM proxy available before customer diligence is a pipeline-conversion view from SBIR/DIU opportunities to public awards, not a revenue run-rate. | Medium | SM009, SM016, SM017, SM024 |
| CM039 | The federal buyer map separates budget owners from end users because cyber operators, program offices, and contracting officers can be different organizations. | Medium | SM003, SM017, SM019 |
| CM040 | DoD program offices and service cyber components are likely payers, while Cyber Command, NSA, and mission teams are likely users or technical evaluators. | Medium | SM002, SM003, SM004, SM018 |
| CM041 | CISA and civilian agencies are adjacent buyers for defensive cyber automation, but the canonical Cathedral mission points primarily at military and adversary-facing operations. | Medium | SM020, SM021, SM003 |
| CM042 | Manual red-teaming and penetration testing remain substitutes when buyers are not ready to authorize autonomous AI cyber operations. | Medium | SM021, SM027, SM028 |
| CM043 | The market opportunity is valuation-relevant because defense-tech venture investors have recently rewarded mission-critical national-security platforms even before public revenue disclosure. | Medium | SM010, SM029, SM030 |
| CM044 | The main adverse market view is that broad federal and analyst cyber numbers can dramatically overstate Cathedral’s attainable market while procurement and classification delay conversion. | Medium | SM005, SM006, SM019, SM032 |
| CM045 | The correct diligence next step is to replace top-down TAM estimates with named program offices, authority path, security accreditation status, and contract-stage evidence. | Medium | SM016, SM017, SM019, SM023 |
| CM046 | The matrix view adds a distinct coordination lens because defense cyber adoption depends on the interaction among buyer, user, payer, and contracting authority rather than on segment labels alone. | Medium | SM017, SM019, SM025 |
| CP001 | Cathedral is a stealth AI defense and military cybersecurity startup founded by ex-DOGE staffers Gavin Kliger, Luke Farritor, Marko Elez, and Jack Stein. | High | SP001, SP002, SP003 |
| CP002 | Cathedral raised $160 million at a $1.4 billion post-money valuation in July 2026 in a round led by Andreessen Horowitz and Sequoia. | High | SP001, SP002, SP003 |
| CP003 | Cathedral’s reported mission is AI-enabled offensive and defensive cyber operations for U.S. military and national-security customers. | High | SP001, SP002 |
| CP004 | Reviewed public sources describe Cathedral as planning to secure U.S. government contracts rather than disclosing signed revenue or contracts. | Medium | SP001, SP003 |
| CP005 | Cathedral’s likely initial differentiation is founder access to Pentagon and national-security networks rather than public product proof. | Medium | SP001, SP003 |
| CP006 | Anduril raised a $5 billion Series H at a $61 billion valuation and had reported $2.2 billion of 2025 revenue, making it a much larger defense-tech benchmark than Cathedral. | Medium | SP004 |
| CP007 | Anduril’s Lattice platform is tied to battle-management software and joint missile-defense data analysis in public reporting. | Medium | SP004 |
| CP008 | Palantir’s 10-K identifies Gotham, Foundry, Apollo, and AIP as its four principal platforms and says Gotham has served global defense agencies and the intelligence community for over a decade. | Medium | SP005 |
| CP009 | Palantir generated $2.9 billion of 2024 revenue, with 55% from government customers, giving it a scale and incumbency advantage Cathedral lacks. | Medium | SP005 |
| CP010 | The UK Ministry of Defence announced a strategic partnership with Palantir intended to unlock military AI and innovation, reinforcing Palantir’s allied-defense presence. | Medium | SP006 |
| CP011 | Shield AI’s Hivemind is an AI pilot for autonomous aircraft and has operated alongside U.S. and allied forces. | Medium | SP007 |
| CP012 | Shield AI was reported by TechCrunch to have reached a $12.7 billion valuation in 2026 after a U.S. Air Force-related deal, far above the older $2.8 billion benchmark. | Medium | SP008, SP009 |
| CP013 | Rebellion Defense’s currently reviewed website positions it around an intelligence shield for critical assets, radar, AI fusion, and operational support rather than public evidence of a completed acquisition or shutdown. | Medium | SP010 |
| CP014 | IronNet is an adverse precedent because reporting says the never-profitable cyber startup shut down and fired employees after running out of money. | Medium | SP011, SP012 |
| CP015 | IronNet’s Stretto bankruptcy case page corroborates that IronNet entered formal bankruptcy proceedings in 2023. | Medium | SP012 |
| CP016 | Horizon3.ai’s NodeZero is marketed as an autonomous pentesting platform that finds, fixes, and validates exploitable paths. | Medium | SP013, SP015 |
| CP017 | Horizon3.ai reported more than 5,200 organizations worldwide relying on NodeZero and 125% net dollar retention in 2026. | Medium | SP013 |
| CP018 | Horizon3.ai announced 2026 investment from Prosperity7 Ventures to protect AI datacenters and critical infrastructure. | Medium | SP014 |
| CP019 | XBOW raised $120 million in Series C financing in 2026 and was valued at more than $1 billion, according to Business Wire. | Medium | SP016 |
| CP020 | XBOW and Accenture announced a 2026 partnership to scale continuous AI-driven security testing and exposure management. | Medium | SP017 |
| CP021 | XBOW positions itself as autonomous offensive security, directly overlapping Cathedral’s offensive-cyber part more than most defense-platform companies. | Medium | SP016, SP017 |
| CP022 | Dreadnode builds AI infrastructure for security agents and publishes offensive-security research, making it an AI-native red-team adjacency rather than a traditional services prime. | Medium | SP018, SP019 |
| CP023 | Dreadnode captured $14 million of Series A funding in 2025 for offensive AI security capabilities. | Medium | SP020 |
| CP024 | RunSafe targets memory safety and cyber resilience for critical infrastructure and safety-critical systems, which is more defensive-hardening than Cathedral’s reported offensive-and-defensive mission. | Medium | SP021, SP022, SP023 |
| CP025 | Two Six Technologies states that it supports Department of Defense, U.S. Cyber Command, DARPA, intelligence-community, and civilian-agency customers. | Medium | SP024 |
| CP026 | Two Six’s Sentr positioning emphasizes AI-driven command of the information environment and agentic bridging of legacy systems. | Medium | SP025 |
| CP027 | Booz Allen’s cyber page explicitly frames the problem as cyberattacks moving at AI speed and cyber defense needing to do the same. | Medium | SP026 |
| CP028 | Leidos markets offensive, defensive, and resilience-oriented cyber capabilities across mission environments. | Medium | SP027 |
| CP029 | CACI markets AI/ML-enabled cyber operations, while Peraton, ManTech, Parsons, SAIC, and other incumbents maintain public cybersecurity offerings. | Medium | SP028, SP029, SP030, SP031, SP032 |
| CP030 | The Navy awarded eight companies $1.86 billion in cyberspace operations support contract options, illustrating incumbent access to large multi-year cyber vehicles. | Medium | SP033 |
| CP031 | Washington Technology’s 2026 Top 100 ranking is based on federal spending for IT, systems integration, telecom, professional services, and high-tech needs, making it a useful scale proxy for incumbents. | Medium | SP034 |
| CP032 | GSA’s Alliant 3 Phase 1 awards cover a major federal IT modernization vehicle that includes AI and cybersecurity-relevant contractors. | Medium | SP035 |
| CP033 | An Army cyber-warfare contract dispute involving Booz Allen, Peraton, and ManTech shows that prime contractors already fight over the specific offensive and defensive cyber mission space Cathedral wants. | Medium | SP036 |
| CP034 | Atlantic Council research describes offensive cyber capability markets as relying on intermediaries and opaque supply chains, which complicates Cathedral’s potential offensive-cyber sourcing model. | Medium | SP037, SP038 |
| CP035 | Atlantic Council reported that zero-day exploitation is becoming more difficult, opaque, and expensive, creating feast-or-famine cycles in offensive-cyber contracting. | Medium | SP038 |
| CP036 | Lawfare analysis argues that private-sector involvement in offensive cyber operations creates legal, policy, and escalation risks. | Medium | SP039 |
| CP037 | Cyber Defense Review describes exploit brokers as suppliers whose customers can include government agencies, reinforcing that exploit supply is a specialized market Cathedral may need to navigate. | Medium | SP040 |
| CP038 | Vannevar Labs positions itself around restoring deterrence and reclaiming advantage for national-security users, making it an adjacent defense-AI software competitor. | Medium | SP041 |
| CP039 | The most direct cyber-specific Cathedral substitutes are Horizon3.ai, XBOW, Dreadnode, RunSafe, and exploit-market vendors, because they focus on automated pentesting, offensive security, AI red teaming, hardening, or exploit supply. | Medium | SP013, SP015, SP016, SP018, SP021, SP038, SP040 |
| CP040 | Cathedral’s two-sided offensive-plus-defensive cyber framing is rarer than the one-sided positions of many cyber startups, but public sources do not prove it has product depth yet. | Medium | SP001, SP013, SP016, SP021 |
| CP041 | Incumbents’ durable advantage is distribution through government contract vehicles, security clearances, procurement history, and program relationships rather than necessarily superior AI-native product design. | Medium | SP024, SP030, SP031, SP032, SP033, SP034, SP035, SP036 |
| CP042 | Defense-tech AI startups such as Anduril, Palantir, Shield AI, Rebellion, Vannevar, and Two Six compete with Cathedral mostly for mission budget and AI-defense credibility, not necessarily for the exact same cyber product. | Medium | SP004, SP005, SP007, SP010, SP024, SP041 |
| CP043 | Cyber-specific AI companies have stronger product proof in autonomous testing than Cathedral has publicly disclosed, while Cathedral may have stronger founder access to federal decision makers. | Medium | SP001, SP013, SP016, SP017, SP018 |
| CP044 | The status-quo alternative for defense buyers includes internal government cyber teams, existing prime-contractor task orders, and classified exploit-procurement channels. | Medium | SP024, SP033, SP036, SP037, SP040 |
| CP045 | IronNet’s collapse is a caution that ex-government credibility and cyber branding do not by themselves create durable revenue, margins, or procurement traction. | Medium | SP011, SP012, SP003 |
| CI001 | Cathedral raised $160 million in a July 2026 financing at a reported $1.4 billion post-money valuation. | Medium | SI001, SI002, SI003, SI004 |
| CI002 | Andreessen Horowitz and Sequoia Capital led Cathedral’s $160 million financing, with coverage reporting board-seat involvement. | Medium | SI002, SI003, SI004 |
| CI003 | Cathedral was founded by former DOGE staffers Gavin Kliger, Luke Farritor, Marko Elez, and Jack Stein. | Medium | SI002, SI003, SI004 |
| CI004 | The July 2026 financing is the only publicly disclosed Cathedral financing round in the reviewed source pack, so disclosed total raised is $160 million. | Medium | SI001, SI002, SI003, SI004 |
| CI005 | A $160 million primary round at a $1.4 billion post-money valuation implies roughly 11.4% new-money dilution before any option-pool or secondary adjustments. | Medium | SI001, SI002, SI003 |
| CI006 | The same round implies a roughly $1.24 billion pre-money valuation if the reported $1.4 billion post-money valuation and $160 million primary proceeds are taken at face value. | Medium | SI001, SI002, SI003 |
| CI007 | No reviewed source disclosed Cathedral revenue, ARR, revenue run rate, gross margin, or customer count. | Medium | SI001, SI002, SI003, SI004 |
| CI008 | No reviewed source disclosed a named paying Cathedral contract, OTA, SBIR award, CRADA, or program-of-record sponsor. | Medium | SI001, SI002, SI003, SI020, SI021, SI022 |
| CI009 | Cathedral is reported to be exploring acquiring or partnering with a data center to secure dedicated compute capacity. | Medium | SI002, SI003, SI004 |
| CI010 | Startup Fortune framed Cathedral’s financing as unicorn money for a company with almost no public footprint, no product launch, and no customer announcement. | Medium | SI002 |
| CI011 | The strongest current adverse financial issue is not churn or margin compression but valuation-before-revenue combined with an undisclosed contract pipeline. | Medium | SI002, SI007, SI020, SI021 |
| CI012 | Firm-fixed-price contracts place maximum risk and responsibility for costs and profit or loss on the contractor. | High | SI005, SI006 |
| CI013 | Cost-reimbursement contracts provide payment of allowable incurred costs and establish a ceiling the contractor may not exceed without approval. | High | SI005, SI007 |
| CI014 | Incentive contracts can tie contractor profit or fee to cost, delivery, or technical-performance outcomes. | High | SI005, SI008 |
| CI015 | IDIQ vehicles provide for an indefinite quantity within stated limits and convert into revenue through specific orders that define supplies or services. | High | SI009, SI010 |
| CI016 | Best-value negotiated acquisitions can vary the relative importance of cost or price, which makes mission fit and technical evaluation central to sales efficiency. | High | SI011, SI035 |
| CI017 | SBIR and STTR programs offer equity-free or non-dilutive funding for small businesses pursuing federal R&D and commercialization. | High | SI012, SI015 |
| CI018 | Defense SBIR/STTR describes a staged path from eligibility and proposal through award, Phase II, transition, and commercialization. | High | SI013, SI014 |
| CI019 | CRADAs can support R&D collaboration between a federal laboratory and a non-federal entity, but the government may not provide funding to non-federal entities under a CRADA. | Medium | SI016 |
| CI020 | Other Transaction Authority is a flexible DOD pathway used alongside the department’s large annual acquisition base for goods, services, and R&D. | High | SI017, SI018 |
| CI021 | DIU presents a commercial-technology pathway in which any commercial entity can respond to solicitations for military adoption. | High | SI018, SI019 |
| CI022 | USAspending is the official federal spending source for awards such as contracts, grants, and loans, making it a relevant check for public award evidence. | Medium | SI020 |
| CI023 | SAM.gov contract opportunities and the Defense Department contracts page are relevant public surfaces for future Cathedral solicitations and award notices. | High | SI021, SI022 |
| CI024 | Government contracting risk is not only timing risk: GAO has documented DOD procurement-fraud exposure and recommended stronger department-wide risk management. | Medium | SI036 |
| CI025 | Palantir’s 2025 Form 10-K says revenue increased by about $1.6 billion, or 56%, from 2024 to 2025. | High | SI023, SI025 |
| CI026 | Palantir reported that revenue from government customers increased by $832.7 million, or 53%, in 2025 and that U.S. government revenue was $1.9 billion. | High | SI023, SI024 |
| CI027 | Palantir’s public product materials explicitly position the platform for governments as well as commercial organizations, supporting its use as a government-software comparable. | High | SI026, SI023 |
| CI028 | Sacra estimates Anduril generated $2.2 billion of 2025 revenue, up from $1.0 billion in 2024, and projects $4.3 billion of 2026 revenue. | Medium | SI027 |
| CI029 | Sacra reports Anduril closed a $5 billion Series H at a $61 billion valuation and projects an approximately $1.2 billion operating loss in 2026. | Medium | SI027 |
| CI030 | Sacra estimates Shield AI reached about $300 million of revenue for the year ending March 2025 and implies at least $540 million of 2026 revenue from management targets. | Medium | SI028 |
| CI031 | The Los Angeles Times reported Anduril is developing a new $1 billion Long Beach complex that includes offices, labs, and prototype manufacturing facilities. | Medium | SI029 |
| CI032 | GeekWire reported Anduril was quietly building autonomous warships at a Seattle shipyard, reinforcing the physical-facility intensity of scaled defense technology. | Medium | SI030 |
| CI033 | Goldman Sachs estimates AI could drive a 160% increase in data-center power demand, while DOE expects domestic data-center energy usage to double or triple by 2028. | High | SI031, SI032 |
| CI034 | Epoch AI estimates frontier-model training compute has grown by roughly 4x to 5x per year, which supports treating dedicated compute as a material burn driver. | Medium | SI033 |
| CI035 | Andreessen Horowitz’s American Dynamism thesis supports startups serving national-interest markets, giving context for a16z’s appetite for defense-oriented companies. | Medium | SI034 |
| CI036 | A reasonable Cathedral base-case runway lens divides the $160 million raise by estimated monthly burn rather than by revenue because no revenue has been disclosed. | Medium | SI001, SI002, SI031, SI033 |
| CI037 | At $4 million of monthly burn, $160 million supports roughly 40 months of runway before financing costs, working capital swings, or data-center capex. | Medium | SI001, SI002 |
| CI038 | At $8 million of monthly burn, $160 million supports roughly 20 months of runway before any large up-front data-center purchase. | Medium | SI001, SI002, SI031 |
| CI039 | At $12 million of monthly burn, $160 million supports roughly 13 months of runway, making contract conversion or a follow-on financing trigger more urgent. | Medium | SI001, SI002, SI033 |
| CI040 | A hypothetical $40 million dedicated-compute or data-center outlay would reduce deployable cash to $120 million and shorten the $8 million-burn runway lens to about 15 months. | Medium | SI001, SI009, SI031, SI032 |
| CI041 | Cathedral’s revenue recognition will likely depend on the future contract vehicle: FFP can defer upside until delivery, cost-reimbursement can lower loss risk but cap margin, and IDIQ orders create revenue only when task orders arrive. | Medium | SI006, SI007, SI009, SI010 |
| CI042 | The path to revenue is likely pilot or prototype funding first, then OTA/SBIR/CRADA validation, then IDIQ or program-of-record ordering if mission owners adopt the product. | Medium | SI013, SI014, SI016, SI017, SI018, SI019 |
| CI043 | High stickiness is plausible only after Cathedral lands in classified workflows or mission systems; before that, stickiness remains a thesis rather than a disclosed financial metric. | Medium | SI002, SI021, SI026 |
| CI044 | Cathedral’s current financial model is pre-revenue from a public-evidence standpoint, so ARR, gross margin, CAC payback, net revenue retention, and recognized revenue should be null rather than estimated as operating metrics. | Medium | SI001, SI002, SI003, SI004 |
| CI045 | The practical next-round trigger is likely one of three events: named government contract conversion, material dedicated-compute capex, or evidence that cyber-AI development burn exceeds the $160 million round’s runway. | Medium | SI002, SI003, SI031, SI033 |
| CI046 | The comparable set shows Cathedral is being valued before the financial proof points that Anduril, Shield AI, and Palantir use to support later-stage defense-tech valuations. | Medium | SI002, SI023, SI027, SI028 |
| CE001 | Cathedral is publicly described as a stealth AI-powered military cybersecurity startup seeking U.S. government contracts. | High | SE001, SE002, SE003, SE004 |
| CE002 | The only public product definition is AI-driven cyber operations; no public source reviewed disclosed Cathedral SKU names, architecture diagrams, benchmarks, or product documentation. | High | SE001, SE002, SE003, SE004 |
| CE003 | Cathedral’s public offensive scope maps most plausibly to AI-assisted reconnaissance, vulnerability discovery, exploit generation, validation, and operator-approved mission packaging. | Medium | SE001, SE002, SE023, SE035, SE036 |
| CE004 | Cathedral’s public defensive scope maps most plausibly to AI-assisted threat detection, vulnerability prioritization, triage, remediation planning, and incident-response automation. | Medium | SE001, SE005, SE006, SE021, SE022 |
| CE005 | Public reporting names Gavin Kliger, Luke Farritor, Marko Elez, and Jack Stein as Cathedral founders and former DOGE staffers. | High | SE001, SE002, SE004 |
| CE006 | Kliger’s reported Pentagon chief data officer role and involvement in the Anthropic/Pentagon AI dispute are directly relevant to Cathedral’s model-governance and military-buyer context. | High | SE002, SE019, SE032 |
| CE007 | Cathedral is reported to be exploring acquiring or partnering with a data-center provider for dedicated compute for classified work. | High | SE001, SE002, SE003, SE004 |
| CE008 | A dedicated compute strategy is technically coherent for offensive military AI because classified data, exploit chains, telemetry, and model weights may need isolation from ordinary commercial SaaS environments. | Medium | SE019, SE026, SE028, SE031, SE033 |
| CE009 | Gold Eagle is a relevant federal analogue because it coordinates AI-assisted vulnerability intake, prioritization, and remediation across government and critical infrastructure. | High | SE005, SE006, SE007 |
| CE010 | DARPA’s AI Cyber Challenge asks competitors to design novel AI systems that secure critical software. | High | SE008, SE009 |
| CE011 | AIxCC demonstrated autonomous AI cyber reasoning systems that found and repaired synthetic open-source vulnerabilities at competition scale. | High | SE008, SE009, SE010 |
| CE012 | The AIxCC Finals GitHub organization exposes OSS-Fuzz-related repositories, providing a developer-signal analogue for autonomous vulnerability-reasoning infrastructure. | Medium | SE010 |
| CE013 | XBOW’s public validation-benchmarks repository is a developer-signal analogue for autonomous offensive-security benchmarking, but its own warning says the benchmarks were saturated by mid-2026. | Medium | SE011 |
| CE014 | Horizon3.ai NodeZero is a commercial analogue for autonomous penetration testing because it runs self-directed pentests, identifies exploitable paths, guides remediation, and verifies fixes. | High | SE012, SE013 |
| CE015 | Dreadnode is a commercial analogue for building, evaluating, and deploying offensive security agents. | High | SE014, SE015 |
| CE016 | HackerOne’s benchmark write-up is an adverse reliability analogue because it says agentic AI can scale offensive operations but cannot yet replace human penetration testers alone. | Medium | SE016 |
| CE017 | HackerOne states that frontier models are compressing the historical gap between vulnerability discovery and exploitation. | Medium | SE017 |
| CE018 | HackerOne’s red-team guidance warns that AI red teaming remains primarily human-driven and should not be confused with fully automated red-team operations. | Medium | SE018 |
| CE019 | Anthropic says Claude Gov models are deployed for U.S. national-security customers at classified levels, showing that frontier-model vendors can package models for restricted government environments. | Medium | SE019 |
| CE020 | Anthropic’s Claude 4 cyber evaluation reports improvements in vulnerability identification and multi-step attack chains while emphasizing remaining limitations. | Medium | SE020 |
| CE021 | Anthropic’s cyber-defender work explicitly avoided enhancements that clearly favor advanced exploitation or malware, underscoring the safety boundary Cathedral would have to govern differently for offensive missions. | Medium | SE021 |
| CE022 | OpenAI reported disrupting malicious state-affiliated uses of AI for cyber research, scripting, and phishing content, which shows both defensive monitoring practices and adversarial misuse patterns. | Medium | SE022 |
| CE023 | Google Project Zero’s Project Naptime frames LLM offensive-security evaluation as dual-use because AI may help defenders find vulnerabilities while also helping attackers develop offensive capabilities. | Medium | SE023 |
| CE024 | Google’s AI-powered fuzzing work is a concrete analogue for using AI to expand bug-finding workflows before production deployment. | Medium | SE024 |
| CE025 | Palantir AIP is an operating-model analogue for embedding AI into mission workflows rather than shipping a stand-alone chat product. | Medium | SE025 |
| CE026 | FedRAMP is a necessary cloud-authorization reference point if Cathedral delivers any cloud service to U.S. government customers. | Medium | SE026 |
| CE027 | NIST’s AI RMF and 2026 critical-infrastructure profile are relevant controls references for AI-enabled cyber systems operating in high-consequence environments. | Medium | SE027 |
| CE028 | NIST SP 800-53 Rev. 5 is a baseline control catalog Cathedral would likely map to during federal security authorization. | Medium | SE028 |
| CE029 | NIAP/Common Criteria could become relevant if Cathedral ships evaluated endpoint, enclave, or security appliance components into controlled government environments. | Medium | SE029 |
| CE030 | CMMC is relevant because defense contractors handling controlled unclassified information must meet DoD cyber-assurance expectations. | Medium | SE030 |
| CE031 | NIST RMF provides the process backbone for ATO work by integrating security, privacy, and cyber supply-chain risk into the system life cycle. | Medium | SE031 |
| CE032 | DefenseScoop reported that the Pentagon’s JWCC follow-on seeks AI and machine-learning capabilities across classification and impact levels including DDIL environments. | Medium | SE033 |
| CE033 | DefenseScoop’s tactical data-center coverage shows DoD buyers already value cloud-grade compute, storage, and AI capability in remote or connectivity-degraded environments. | Medium | SE034 |
| CE034 | The LLM-agent zero-day paper is an adverse benchmark because it reports that agents still perform poorly on real-world vulnerabilities unknown to the agent ahead of time. | Medium | SE035 |
| CE035 | Cybench frames autonomous vulnerability discovery and exploit execution as capable of real-world impact and therefore requiring measurement and risk controls. | Medium | SE036 |
| CE036 | Cathedral’s actual product maturity is undisclosed; the defensible outside label is stealth prototype-to-early-platform rather than production-proven system. | Medium | SE001, SE002, SE003, SE004 |
| CE037 | Public evidence supports treating vulnerability discovery as a plausible Cathedral module but not as a verified production capability. | Medium | SE001, SE009, SE020, SE023, SE035 |
| CE038 | Exploit-generation and C2-adjacent automation are the highest-risk inferred modules because hallucinated exploit logic, legal boundaries, and operator authorization errors can create mission and safety failures. | Medium | SE016, SE018, SE020, SE023, SE035, SE036 |
| CE039 | Defensive triage and remediation assistance appear nearer-term than fully autonomous offensive action because public analogues emphasize vulnerability intake, code review, fuzzing, and human-guided validation. | Medium | SE005, SE006, SE021, SE024, SE031 |
| CE040 | Any Cathedral deployment into NIPR, SIPR, JWICS, or mission enclaves would likely require RMF/ATO mapping plus cloud, identity, logging, and data-boundary controls before operational use. | Medium | SE026, SE028, SE031, SE032, SE033 |
| CE041 | Building or operating in classified national-security environments implies cleared personnel, restricted model access, enclave-aware telemetry handling, and classified evaluation data. | Medium | SE019, SE031, SE033 |
| CE042 | The compliance surface likely spans FedRAMP or equivalent cloud authorization, DoD impact-level assessment, RMF/ATO packages, CMMC for contractor data, and possibly NIAP for evaluated components. | Medium | SE026, SE028, SE029, SE030, SE031, SE033 |
| CE043 | Model reliability is a material risk because leading public evidence emphasizes evaluation limits, benchmark saturation, human oversight, and incomplete zero-day performance. | Medium | SE011, SE016, SE018, SE020, SE035, SE036 |
| CE044 | The most plausible roadmap is staged: human-in-loop agent prototypes, classified compute buildout, defensive pilots, ATO packages, and only then broader autonomous offensive mission support. | Low | SE001, SE007, SE019, SE031, SE033, SE034 |
| CE045 | The central diligence gap is that Cathedral has no reviewed public website, product documentation, named deployments, certification package, benchmark report, or compliance artifact. | Medium | SE001, SE002, SE003, SE004 |
| CU001 | Cathedral is publicly described as a stealth military cybersecurity startup aiming to use AI to expand U.S. military cyber capabilities. | High | SU001, SU002 |
| CU002 | Reuters reported that Cathedral launched in recent months with a plan to secure U.S. government contracts for offensive and defensive cyber operations against adversaries such as China. | Medium | SU001 |
| CU003 | Cathedral was reported to be co-founded by Gavin Kliger, Luke Farritor, Marko Elez, and Jack Stein, all former DOGE staffers. | High | SU001, SU002 |
| CU004 | Cathedral reportedly closed a $160 million financing at a $1.4 billion valuation led by Andreessen Horowitz and Sequoia. | High | SU001, SU002 |
| CU005 | The reviewed 2026 Cathedral news sources do not name any paying customer, production deployment, pilot customer, contract award, or partnership customer. | Medium | SU001, SU002, SU003, SU004 |
| CU006 | Cathedral’s own spokesperson declined to comment in the Reuters report, reinforcing the company’s stealth disclosure profile. | Medium | SU001 |
| CU007 | Reuters reported that Cathedral’s founding team maintains deep ties to the Trump administration and national-security officials, including at the Pentagon. | High | SU001, SU003 |
| CU008 | USAspending, SAM.gov, and the DoD contracts page are public official channels an investor can use to look for federal award or opportunity evidence, but those public surfaces do not substitute for classified-award diligence. | Medium | SU005, SU006, SU007 |
| CU009 | U.S. Cyber Command is the most direct target buyer because its mission is to direct, synchronize, and coordinate cyberspace planning and operations to defend and advance national interests. | Medium | SU008 |
| CU010 | NSA’s Cybersecurity Collaboration Center is an adjacent buyer or partner surface because it scales intel-driven cybersecurity through industry, interagency, and international partnerships. | Medium | SU009 |
| CU011 | Fleet Cyber Command / 10th Fleet is a naval cyber component with more than 13,000 billets and many Cyber Mission Force units. | Medium | SU010 |
| CU012 | The 16th Air Force is an Air Force cyber and ISR component responsible for cryptologic activities and operating and defending Department networks. | Medium | SU011 |
| CU013 | Marine Corps Forces Cyberspace Command aligns Marine cyberspace operations with U.S. Cyber Command objectives. | Medium | SU012 |
| CU014 | Space Force cyber organizations such as Space Delta 6 operate and maintain space mission systems, creating a service-specific cyber-infrastructure buyer surface. | Medium | SU026 |
| CU015 | CISA is a plausible civilian adjacent account because it coordinates critical-infrastructure security and works with partners to manage cyber and physical infrastructure risk. | Medium | SU013 |
| CU016 | CIA and DIA are plausible intelligence-community stakeholders because CIA provides national-security intelligence and DIA provides intelligence on foreign militaries and operating environments. | Medium | SU014, SU015 |
| CU017 | Five Eyes allied demand is plausible but secondary because the UK Ministry of Defence is actively pursuing strategic partnerships to boost military AI and innovation. | Medium | SU035 |
| CU018 | DIU allows individual or commercial entities to submit solution briefs, including first-time government sellers with applicable commercial solutions. | High | SU016, SU017 |
| CU019 | DIU frames commercial defense demand as access to a market exceeding $100 billion, which supports a startup-first outreach path before a full program office sale. | Medium | SU017 |
| CU020 | Defense SBIR/STTR provides a structured path from eligibility and registration through proposal submission, Phase II, transition, and commercialization. | High | SU018, SU019 |
| CU021 | SBIR provides equity-free funding through federal agencies to small businesses, making it a possible non-dilutive prototype route for Cathedral. | Medium | SU019 |
| CU022 | GSA’s Multiple Award Schedule is a later-stage purchasing path for listed products and services once a vendor has an approved schedule position. | Medium | SU020 |
| CU023 | DoD Other Transactions are legally binding non-FAR instruments for research, prototype projects, and follow-on production when statutory requirements are met. | High | SU021, SU030 |
| CU024 | GAO notes that OTAs are more flexible than traditional contracts and can allow DoD to work with contractors it has not worked with before. | Medium | SU030 |
| CU025 | AFWERX, SOFWERX, and DEFENSEWERX are relevant innovation intermediaries for Cathedral because they package service or special-operations problems into startup-accessible entry points. | Medium | SU027, SU028, SU029 |
| CU026 | FedRAMP is a likely baseline gate for cloud-delivered cyber capability because the FedRAMP Marketplace tracks certified cloud services, authorizing agencies, and assessors. | Medium | SU022 |
| CU027 | Current CMMC posture remains a defense-industrial-base diligence item even though DoD announced suspension of Phase II requirements while retaining Phase I self-assessment requirements. | Medium | SU023 |
| CU028 | NIAP/Common Criteria appears in the compliance stack as a product-assurance diligence topic for security technology sold into national-security environments. | Low | SU024 |
| CU029 | DCSA states that entities handling classified information for the U.S. government must first obtain facility clearance, making FCL/FOCI a hard gate for classified Cathedral work. | Medium | SU025 |
| CU030 | DoD IL5 documentation describes DISA cloud security requirements and provisional authorization decisions, so Impact Level and ATO readiness are material deployment gates. | High | SU036, SU022 |
| CU031 | Cathedral has not publicly disclosed FedRAMP, DoD impact-level authorization, CMMC status, NIAP validation, facility clearance, personnel clearances, or classified program access. | Medium | SU001, SU002, SU023, SU025, SU036 |
| CU032 | Shield AI’s reported U.S. Air Force deal before a $12.7 billion valuation illustrates how mission validation can precede large private defense-tech financing. | Medium | SU031 |
| CU033 | Anduril’s $5 billion Series H at a $61 billion valuation shows the defense-tech market rewards companies that can convert government demand into scaled programs and facilities. | High | SU032, SU033 |
| CU034 | Palantir’s 2024 Form 10-K says Gotham has served defense agencies and the intelligence community for over a decade, demonstrating a long sales-and-embedding arc. | Medium | SU034 |
| CU035 | Palantir disclosed $1.071 billion of government revenue for 2024, illustrating the scale possible once a defense-software vendor is embedded in government accounts. | Medium | SU034 |
| CU036 | Incumbent and scaled peers create adoption barriers because government buyers can procure cyber, AI, or mission software through existing contract vehicles and proven vendors rather than a stealth startup. | Medium | SU007, SU020, SU034 |
| CU037 | A realistic Cathedral customer journey is multi-stage: classified relationship access may open doors, but public procurement still tends to move from prototype or SBIR-style work to OTA, schedule, or program-of-record scale. | Medium | SU016, SU018, SU021, SU030 |
| CU038 | A 12-to-24-month enterprise-defense sales-cycle assumption is reasonable for underwriting because the public path includes solicitation, proposal, evaluation, award, security authorization, and transition gates. | Medium | SU016, SU018, SU021, SU022, SU025 |
| CU039 | The absence of named customers is not dispositive for classified cyber work because facility clearance and classified-information rules can limit what vendors can market publicly. | Medium | SU025, SU008, SU009 |
| CU040 | Cathedral’s current customer count should be recorded as null because no public source reviewed discloses accounts, deployments, production users, pilots, NRR, GRR, churn, or renewal metrics. | Medium | SU001, SU002, SU003, SU004 |
| CU041 | Cathedral’s founder access is a go-to-market advantage because recent senior government roles plausibly shorten introductions to Pentagon and national-security buyers. | Medium | SU001 |
| CU042 | The same access is an adverse revolving-door risk because critical coverage frames the move from DOGE into a military-tech startup as controversial and Reuters notes potential scrutiny over government contracts. | High | SU001, SU003 |
| CU043 | Budget timing is an adoption barrier because public procurement channels require a funded requirement, a solicitation or vehicle, and an award path before revenue recognition. | Medium | SU006, SU007, SU020 |
| CU044 | The prototype-to-program valley of death is a material risk because SBIR and OTA mechanisms can fund experiments while still requiring transition and commercialization into enduring procurement. | Medium | SU018, SU021, SU030 |
| CU045 | The buyer set is addressable rather than evidenced: Cathedral’s public record supports mission fit and access, not customer adoption. | Medium | SU001, SU004, SU008, SU009 |
| CR001 | Cathedral closed a $160 million round at a reported $1.4 billion valuation in July 2026. | High | SR001, SR002, SR003 |
| CR002 | Cathedral was co-founded by former DOGE staffers Gavin Kliger, Luke Farritor, Marko Elez, and Jack Stein. | High | SR001, SR002 |
| CR003 | Public reporting describes Cathedral’s mission as AI-driven U.S. military cyber operations with both offensive and defensive capabilities. | High | SR001, SR002 |
| CR004 | Andreessen Horowitz and Sequoia Capital reportedly led Cathedral’s round and both took board seats. | Medium | SR001, SR010 |
| CR005 | No reviewed public source disclosed Cathedral revenue, production customers, or awarded government contracts. | Medium | SR001, SR002, SR042, SR043 |
| CR006 | Cathedral’s founding team has close reported ties to the Trump administration and national security officials. | Medium | SR001, SR005 |
| CR007 | Reuters reported that Cathedral could face scrutiny over government contracts if Democrats gained congressional power after the midterms. | Medium | SR001 |
| CR008 | Startup Fortune characterized Cathedral’s valuation as a bet on access and founder knowledge rather than inspectable revenue. | Medium | SR002 |
| CR009 | Vanity Fair described DOGE as an expedited revolving door into defense contracting and venture-backed government-facing startups. | Medium | SR005, SR004 |
| CR010 | Vanity Fair quoted watchdog and investor concerns that weak ethics restrictions and conflict-of-interest issues could hinder DOGE-alumni startups. | Medium | SR005 |
| CR011 | Kliger was reported to have served until recently as the Pentagon chief data officer and to have worked near military AI issues. | Medium | SR001, SR005 |
| CR012 | Vanity Fair reported Kliger worked on GenAI.mil and AI-related Pentagon contracting efforts, increasing perceived insider-knowledge risk. | Medium | SR005 |
| CR013 | A Defense Department official told Vanity Fair that Kliger is subject to a one-year cooling-off period, while federal post-employment regulations govern certain communications and appearances. | High | SR005, SR025 |
| CR014 | FAR Subpart 9.5 addresses organizational conflicts of interest, including unfair competitive advantage concerns. | Medium | SR023 |
| CR015 | FAR 3.104 establishes procurement-integrity restrictions around contractor bid or proposal information and source-selection information. | Medium | SR024 |
| CR016 | Federal post-employment rules create restrictions that can matter when former officials communicate back to their prior agencies. | Medium | SR025 |
| CR017 | Federal ethics rules prohibit using public office for private gain, including implying government sanction of private activity. | Medium | SR026 |
| CR018 | CREW says DOGE’s structure, staffing, budget, and operations lack clarity and require public records scrutiny. | Medium | SR047 |
| CR019 | CREW has sought DOGE records to test compliance with ethics, transparency, legal-authority, funding, and records-preservation obligations. | Medium | SR047 |
| CR020 | AP reported that Marko Elez resigned after being linked to racist social-media posts and that Musk said he would bring him back. | High | SR011, SR001 |
| CR021 | Reuters reported Elez worked at Treasury during DOGE and raised concerns from a judge after accessing highly sensitive material. | Medium | SR001, SR011 |
| CR022 | AP reported Elez was among DOGE employees at the center of a Treasury payment-system access controversy. | Medium | SR011, SR015, SR016 |
| CR023 | GovExec reported GAO found Treasury missed security controls in providing DOGE system access and did not always enforce protocols. | Medium | SR017 |
| CR024 | GovExec reported GAO findings that Elez sent unencrypted USAID payment information to DOGE associates without agency approval. | Medium | SR017 |
| CR025 | WIRED identified several DOGE engineers, including Farritor and Kliger, as young and having little or no government experience when put into important roles. | Medium | SR012 |
| CR026 | WIRED reported concerns that DOGE-affiliated personnel had access to sensitive government systems and could bypass normal controls. | Medium | SR012 |
| CR027 | WIRED reported that DOGE may have misused Social Security data, adding to the adverse data-access narrative around DOGE alumni. | Medium | SR014 |
| CR028 | Lawfare argues private-sector offensive cyber participation requires defining objectives, scope, targets, legal authorities, and liability. | Medium | SR027 |
| CR029 | Lawfare warns policymakers should mitigate escalation and diplomatic-fallout risks before expanding private-sector cyber-offense roles. | Medium | SR027 |
| CR030 | The Atlantic Council describes the zero-day and offensive-cyber supply chain as opaque, fragmented, expensive, and strategically sensitive. | Medium | SR031 |
| CR031 | The Atlantic Council reports private firms often create offensive cyber capabilities for governments and that China’s offensive cyber industry is increasingly integrated with AI institutions. | Medium | SR031 |
| CR032 | CSIS argues harmful cyber activity can occur below the use-of-force threshold, limiting the usefulness of deterrence alone. | Medium | SR029 |
| CR033 | CSIS notes DOD autonomy policy is widely misunderstood and that cyber weapons systems are exempted from some autonomous-weapons review pathways. | Medium | SR030 |
| CR034 | CSIS says government cyber collaboration faces information-sharing, classification, and liability constraints. | Medium | SR028 |
| CR035 | ITAR regulations define controlled defense articles and defense services and place the United States Munitions List in 22 CFR Part 121. | High | SR032, SR033 |
| CR036 | BIS and EAR sources show export controls can apply to advanced computing and other controlled items beyond traditional weapons. | High | SR034, SR035 |
| CR037 | The Wassenaar Arrangement maintains control lists for conventional arms and dual-use goods and technologies, reinforcing international export-control constraints. | Medium | SR036 |
| CR038 | Because Cathedral’s reported work is military cyber operations, export-control review is a gating diligence item before any foreign customer, investor, data-center, or personnel expansion. | Medium | SR001, SR032, SR034, SR036 |
| CR039 | Classification and stealth limit independent verification because public reporting discloses Cathedral’s mission and financing but not product specifications, contracts, revenue, or performance data. | Medium | SR001, SR002, SR042, SR043 |
| CR040 | Booz Allen, Leidos, Palantir, and Anduril all have public cyber, defense, or platform proof that Cathedral has not yet matched publicly. | Medium | SR037, SR038, SR039, SR040 |
| CR041 | Washington Technology’s 2026 Top 100 ranking illustrates the scale and durability of established government contractors competing for federal technology work. | Medium | SR041 |
| CR042 | SAM.gov and USAspending.gov are core public procurement and spending surfaces, but public reporting rather than those portals currently anchors Cathedral’s public contract story. | Medium | SR042, SR043, SR001 |
| CR043 | SBIR and DIU materials show official pathways for commercial technology vendors, but those pathways do not by themselves prove revenue or procurement success for Cathedral. | Medium | SR044, SR045 |
| CR044 | Cathedral’s reported plan to secure U.S. government contracts creates single-buyer concentration until commercial, allied, or multi-agency revenue is disclosed. | Medium | SR001, SR038, SR042, SR043 |
| CR045 | The combination of a $1.4 billion valuation, no disclosed revenue, and entrenched incumbents makes valuation fragility a high-impact commercial risk. | Medium | SR001, SR002, SR037, SR041 |
| CR046 | Bulletin coverage of cyber norms underscores that cyber operations remain an international-norms problem, not merely a domestic procurement issue. | Medium | SR046 |
| CR047 | The White House executive order established DOGE inside the Executive Office of the President, making Cathedral’s DOGE-alumni identity politically legible rather than incidental. | Medium | SR018, SR019 |
| CR048 | Cathedral’s reported search for dedicated compute or a data-center partnership adds an infrastructure dependency to its cyber-operations plan. | Medium | SR001, SR002 |
| CV001 | Cathedral raised $160 million at a $1.4 billion post-money valuation in July 2026. | High | SV001, SV002, SV003, SV004 |
| CV002 | The $160 million round at a $1.4 billion post-money valuation implies approximately $1.24 billion of pre-money value. | Medium | SV001, SV002 |
| CV003 | The same round implies that new investors bought roughly 11.4% of Cathedral on a post-money basis. | Medium | SV001, SV002 |
| CV004 | Cathedral has no disclosed revenue or ARR, so a revenue or ARR valuation multiple cannot be computed from public evidence. | High | SV001, SV002 |
| CV005 | Cathedral has no disclosed government contract wins as of the fetched public reporting. | High | SV001, SV002 |
| CV006 | Public reporting frames Cathedral as a stealth military cyber and AI startup seeking U.S. government contracts, not as a company with proven commercial traction. | High | SV001, SV003, SV004 |
| CV007 | Reuters reported that Cathedral's $1.4 billion valuation reflects investor confidence in the founding team's government relationships rather than any product track record. | High | SV001, SV002, SV003 |
| CV008 | The valuation appears to price government-access and team-signal scarcity more than currently observable product or revenue traction. | Medium | SV001, SV002, SV021 |
| CV009 | Andreessen Horowitz and Sequoia led the Cathedral financing and both took board seats, which is a meaningful signaling premium for a new stealth company. | High | SV001, SV002, SV003 |
| CV010 | a16z’s American Dynamism platform publicly emphasizes national-interest sectors, helping explain why a defense-cyber startup can receive thematic investor support before revenue. | Medium | SV027, SV001 |
| CV011 | Anduril raised $5 billion at roughly a $61 billion valuation in 2026. | High | SV005, SV006, SV007, SV008 |
| CV012 | Anduril had publicly reported revenue scale, including reporting that revenue doubled in 2025 to about $2.2 billion. | High | SV005, SV008 |
| CV013 | Anduril’s $61 billion valuation on about $2.2 billion of reported 2025 revenue implies a trailing revenue multiple near 27.7x. | Medium | SV005, SV008 |
| CV014 | Anduril is a more mature comp than Cathedral because it has public product breadth, revenue scale, facilities expansion, and a late-stage funding profile. | High | SV008, SV029, SV030 |
| CV015 | Shield AI raised a 2026 Series G at a $12.7 billion post-money valuation after defense aircraft and autonomy traction. | High | SV009, SV010 |
| CV016 | Shield AI previously reached a $5.3 billion valuation in 2025 after a $240 million financing. | Medium | SV011, SV012 |
| CV017 | Shield AI is a stronger proof-stage comp than Cathedral because public coverage ties its valuation to autonomous aircraft programs and U.S. Air Force-related traction. | High | SV009, SV010, SV012 |
| CV018 | Palantir’s 2026 public-market frame is a high-multiple government and commercial software reference rather than an early-stage startup comp. | High | SV014, SV016, SV020 |
| CV019 | Palantir reported Q1 2026 revenue growth and U.S. government revenue growth, showing that its valuation is supported by operating revenue disclosure. | High | SV014, SV015, SV016 |
| CV020 | CompaniesMarketCap and Stock Analysis provide observable Palantir market-cap, revenue, and P/S context, unlike Cathedral where revenue is undisclosed. | Medium | SV013, SV018, SV019, SV020 |
| CV021 | Palantir’s public price-to-sales multiple can serve as an aggressive upper-bound reference, but it should not be mechanically applied to Cathedral before contracts and revenue exist. | Medium | SV016, SV020, SV002 |
| CV022 | Rebellion Defense is relevant only as a private defense-software reference because public sources do not provide an equivalent current valuation or revenue multiple. | Medium | SV028, SV002 |
| CV023 | Typical seed-stage valuation benchmarks are far below Cathedral’s $1.4 billion post-money mark. | Medium | SV023, SV024, SV026 |
| CV024 | Typical Series A benchmark discussions also sit far below Cathedral’s $1.24 billion implied pre-money valuation. | Medium | SV024, SV025, SV026 |
| CV025 | Even if defense AI deserves a premium, Cathedral’s valuation at founding is an outlier against ordinary seed and Series A pricing ranges. | High | SV001, SV023, SV024, SV025 |
| CV026 | At a 10x revenue multiple, Cathedral would need roughly $140 million of annual revenue to support a $1.4 billion valuation. | Medium | SV001, SV020 |
| CV027 | At a 5x revenue multiple, Cathedral would need roughly $280 million of annual revenue to support a $1.4 billion valuation. | Medium | SV001, SV020 |
| CV028 | At a 15x revenue multiple, Cathedral would still need roughly $93 million of annual revenue to support a $1.4 billion valuation. | Medium | SV001, SV013, SV020 |
| CV029 | A bull case requires Cathedral to convert founder access into material U.S. government cyber contract value within roughly 18 to 24 months. | Medium | SV001, SV021, SV022 |
| CV030 | A base case is that Cathedral raises enough capital to build product and pursue pilots but remains overvalued until contract evidence appears. | Medium | SV001, SV002, SV021 |
| CV031 | A bear case is that procurement, politics, or overvaluation pressure prevent Cathedral from growing into the mark before dilution or repricing. | Medium | SV001, SV002, SV021, SV022 |
| CV032 | The defense-tech bubble critique directly applies to Cathedral because it has a large mark before public revenue, contracts, or product disclosure. | Medium | SV002, SV021, SV022 |
| CV033 | Defense-tech investors can still rationally underwrite the category because geopolitical demand and American Dynamism themes create durable budget tailwinds. | Medium | SV005, SV021, SV027 |
| CV034 | The appropriate recommendation is research-more rather than buy because the valuation is already priced like a scaled winner while public traction is absent. | High | SV001, SV002, SV021 |
| CV035 | Confidence should be low because the decisive diligence inputs—revenue, contract pipeline, product capability, security clearances, and procurement path—are private or undisclosed. | Medium | SV001, SV002 |
| CV036 | Risk rating should be high because the mark combines pre-revenue pricing, political exposure, procurement uncertainty, and future dilution risk. | High | SV001, SV002, SV021, SV022 |
| CV037 | Valuation stance should be expensive because public evidence does not yet support a $1.4 billion post-money price on fundamentals. | High | SV001, SV002, SV023, SV024 |
| CV038 | A plausible exit path requires Cathedral to become a durable cyber-defense software supplier with multi-year government contracts, not merely a team premium story. | Medium | SV001, SV014, SV016, SV029 |
| CV039 | Future rounds could dilute early investors if the company must finance data-center capacity, compliance, and long procurement cycles before revenue scales. | Medium | SV001, SV021, SV022 |
| CV040 | Political risk matters because reporting identifies Cathedral’s ties to DOGE and the Trump administration as potential sources of scrutiny if control of Congress shifts. | High | SV001, SV002 |
| CV041 | The premium decomposition is best understood as team premium plus investor-signal premium plus defense-AI market premium plus scarcity premium, offset by a traction discount. | Medium | SV001, SV002, SV021, SV027 |
| CV042 | The largest single negative adjustment should be a traction discount because revenue and contract value are both undisclosed. | High | SV001, SV002 |
| CV043 | Diligence should request contract pipeline, bid status, security and accreditation path, technical proof, data-center economics, and cap-table preference terms before any investment decision. | Medium | SV001, SV002, SV021 |
| CV044 | A thesis-break trigger would be no credible paid pilot or government contracting path within 18 to 24 months after the round. | Medium | SV001, SV021, SV022 |
| CV045 | Another thesis-break trigger would be disclosure that the valuation rests mostly on political access rather than proprietary technical capability. | Medium | SV001, SV002, SV022 |
| CV046 | The IC debate should balance a real defense-tech boom and elite investor signal against an unusually high pre-revenue mark with no public product, revenue, or contract proof. | High | SV001, SV002, SV005, SV021, SV027 |
| ID | Publisher | Title | Quote |
|---|---|---|---|
| SO001 | U.S. News & World Report / Reuters | Exclusive-DOGE Alumni Launch Military Cyber Startup With $1.4 Billion Valuation | A team of former DOGE employees raised a major funding round for a startup that aims to use AI to expand U.S. military cyber capabilities. |
| SO002 | The Next Web | Four former DOGE staffers raised $160 million at a $1.4 billion valuation for an AI military cyber startup | Cathedral, a stealth military cybersecurity startup founded by four former Department of Government Efficiency staffers, has raised $160 million at a $1.4 billion valuation. |
| SO003 | Reuters | DOGE alumni launch military cyber startup with $1.4 billion valuation | Origin page required JavaScript and ad-block disabling during fetch; Reuters text was available through the U.S. News syndication source. |
| SO004 | Hoodline | Cathedral: Ex-DOGE Engineers Launch $1.4B Military Cyber Startup | Three former engineers from Elon Musk's controversial DOGE initiative have quietly spun out of Washington and into the venture spotlight with Cathedral. |
| SO005 | Gizmodo | DOGE Guys Who Didn’t Save Us Any Money Rake in Cash With New Military Tech Startup | DOGE Guys Who Didn’t Save Us Any Money Rake in Cash With New Military Tech Startup. |
| SO006 | Cyber Daily | Ex-DOGE engineers launch new AI firm to bolster US military cyber | Ex-DOGE engineers Gavin Kliger, Luke Farritor, Marko Elez and Jack Stein formed Cathedral. |
| SO007 | The White House | White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination | President Trump’s bold vision to secure and accelerate American artificial intelligence innovation is being actioned through the creation of GOLD EAGLE. |
| SO008 | TechCrunch | Anduril raises $5B, doubles valuation to $61B | Anduril has raised a $5 billion Series H round at a $61 billion valuation. |
| SO009 | Forbes | Anduril’s $61 Billion Valuation Is A Bet On Pentagon Speed | The Washington Post reported that Anduril raised $5 billion at a $61 billion valuation. |
| SO010 | The Next Web | Musk allies back a private-sector DOGE as ex-staffers launch Special | Special is launching with the backing of Andreessen Horowitz and other Musk-adjacent investors. |
| SO011 | The Atlantic | The DOGE Bros Want Another Shot | DOGE alumni make splashy announcements about entering complex industries with scant qualifications while promising to root out waste. |
| SO012 | DOGE | Work | DOGE: Department of Government Efficiency | The people voted for major reform. |
| SO013 | The White House | Establishing And Implementing The President's Department Of Government Efficiency | This Executive Order establishes the Department of Government Efficiency to implement the President’s DOGE Agenda. |
| SO014 | Government Executive | Treasury missed security controls in giving DOGE system access, GAO finds | Treasury missed security controls in giving DOGE system access, GAO finds. |
| SO015 | Government Executive | What DOGE taught us about AI and federal workers | DOGE abruptly shut down USAID and pushed generative AI uses across federal operations. |
| SO016 | Nextgov/FCW | What DOGE taught us about AI and federal workers | DOGE’s use of AI in federal workforce changes became a lesson in governance and institutional trust. |
| SO017 | Yahoo News | DOGE officially shuts down | The Department of Government Efficiency shut down operations on July 4. |
| SO018 | The Fiscal Times | DOGE Is Officially Done | The Department of Government Efficiency came to an official end this past weekend. |
| SO019 | The Next Web | The emails that broke Anthropic and the Pentagon apart | For months, the fight between Anthropic and the Pentagon had been escalating. |
| SO020 | CNBC | Trump admin allows Anthropic to release Mythos AI model to some companies, government agencies | The Trump administration has agreed to allow Anthropic to release its new Claude Mythos 5 model to some companies and government agencies. |
| SO021 | Politico | Trump picked a fight with Anthropic. Now the administration is backing off. | Trump picked a fight with Anthropic. Now the administration is backing off. |
| SO022 | Breaking Defense | Air Force pushing contractors to purge Anthropic by Sept. 1: Memo | The Air Force Research Laboratory is pushing its contractors to purge all Anthropic products from their systems by Sept. 1. |
| SO023 | eWeek | Anthropic vs Washington: A Timeline of Claude’s Collision With the US Government | The dispute over AI guardrails grew into a confrontation between a frontier AI company and the US government. |
| SO024 | Andreessen Horowitz | American Dynamism: Supporting the National Interest | American Dynamism supports founders and companies that serve the national interest. |
| SO025 | Andreessen Horowitz | Portfolio | Andreessen Horowitz | Andreessen Horowitz lists AI and American Dynamism among portfolio focus areas. |
| SO026 | Sequoia Capital | Our Companies | Sequoia lists its company portfolio and investment stages on its official site. |
| SO027 | Sequoia Capital | AI Ascent 2026 | Sequoia hosted more than 150 leading founders and researchers in AI at AI Ascent IV. |
| SO028 | SecurityWeek | White House Launches AI-Driven Gold Eagle Vulnerability Coordination Initiative | Gold Eagle is a coordination mechanism intended to speed detection, prioritization and patching of vulnerabilities. |
| SO029 | Dark Reading | Gold Eagle Clearinghouse Targets Real Gap, but How Is Unclear | Gold Eagle targets a real gap, but how is unclear. |
| SO030 | CSO Online | White House launches AI-driven vulnerability clearinghouse to speed cyber remediation | The White House is launching a program to help government agencies and critical infrastructure operators identify, prioritize, and remediate vulnerabilities. |
| SO031 | GovCon Wire | The White House’s Gold Eagle Initiative: Strengthening Public-Private Partnerships to Safeguard Critical Infrastructure in the AI Era | The Gold Eagle Initiative is framed as strengthening public-private partnerships to safeguard critical infrastructure in the AI era. |
| SM001 | Office of Management and Budget | President’s Budget | |
| SM002 | Office of the Under Secretary of Defense Comptroller | Budget Materials | |
| SM003 | U.S. Cyber Command | Mission and Vision | |
| SM004 | National Security Agency | Cybersecurity Collaboration Center | |
| SM005 | U.S. Government Accountability Office | High Risk List | |
| SM006 | U.S. Government Accountability Office | Cybersecurity: OMB Should Improve Information Security Performance Metrics | |
| SM007 | Congressional Research Service | Defense Acquisitions: How and Where DOD Spends and Reports Its Contracting Dollars | |
| SM008 | DARPA | AI Cyber Challenge | |
| SM009 | Defense SBIR/STTR | SBIR/STTR Programs | |
| SM010 | Andreessen Horowitz | American Dynamism | |
| SM011 | MarketsandMarkets | Artificial Intelligence in Military Market | |
| SM012 | Grand View Research | Artificial Intelligence in Military Market Report | |
| SM013 | MarketsandMarkets | Cyber Warfare Market | |
| SM014 | Mordor Intelligence | Cyber Warfare Market Report | |
| SM015 | Grand View Research | Cybersecurity Market Size and Share Report, 2026-2033 | |
| SM016 | USAspending.gov | USAspending.gov | |
| SM017 | SAM.gov | Contract Opportunities | |
| SM018 | U.S. Department of Defense | Contracts | |
| SM019 | Acquisition.gov | FAR Part 16 - Types of Contracts | |
| SM020 | CISA | About CISA | |
| SM021 | CISA | Cybersecurity Best Practices | |
| SM022 | CISA | Zero Trust Maturity Model | |
| SM023 | Department of Defense CIO | DoD Zero Trust Strategy | |
| SM024 | Defense Innovation Unit | Solutions | |
| SM025 | Defense Innovation Unit | Work With Us | |
| SM026 | SBIR.gov | About SBIR and STTR | |
| SM027 | NIST | Cybersecurity Framework | |
| SM028 | NIST | Artificial Intelligence | |
| SM029 | Sacra | Anduril company profile | |
| SM030 | Los Angeles Times | Anduril to invest another $1 billion in California with new Long Beach campus | |
| SM031 | DAU Adaptive Acquisition Framework | Other Transactions | |
| SM032 | U.S. Government Accountability Office | Other Transaction Agreements: DOD Can Improve Planning for Consortia Awards | |
| SP001 | Reuters via U.S. News | Exclusive-DOGE Alumni Launch Military Cyber Startup With $1.4 Billion Valuation | Cathedral closed on a $160 million funding round that valued the company at $1.4 billion. |
| SP002 | The Next Web | Four former DOGE staffers raised $160 million at a $1.4 billion valuation for an AI military cyber startup | |
| SP003 | Startup Fortune | Four DOGE alumni raise at a $1.4 billion valuation for Cathedral, a stealth military cybersecurity startup backed by a16z and Sequoia | Cathedral has raised the money. Now it has to show whether DOGE access converts into signed Pentagon work. |
| SP004 | TechCrunch | Anduril raises $5B, doubles valuation to $61B | Anduril has raised a $5 billion Series H round at a $61 billion valuation. |
| SP005 | U.S. Securities and Exchange Commission | Palantir Technologies Inc. 2024 Form 10-K | We have built four principal software platforms, Palantir Gotham, Palantir Foundry, Palantir Apollo, and Palantir Artificial Intelligence Platform. |
| SP006 | UK Ministry of Defence | New strategic partnership to unlock billions and boost military AI and innovation | |
| SP007 | Shield AI | Hivemind | Since piloting the first fully autonomous combat mission in 2018, Hivemind has become the trusted AI pilot operating alongside U.S. and allied forces. |
| SP008 | Shield AI | Shield AI raises $240M at $5.3B valuation to scale Hivemind Enterprise | |
| SP009 | TechCrunch | Defense startup Shield AI lands $12.7B valuation, up 140%, after US Air Force deal | |
| SP010 | Rebellion Defense | Rebellion homepage | An INTELLIGENCE SHIELD for critical assets combining next-gen radar, AI fusion, and full operational software and support. |
| SP011 | Associated Press via Inc. | Inside the Collapse of Security Experts’ Cyber Startup IronNet | The never-profitable company announced it was shutting down and firing its employees after running out of money. |
| SP012 | Stretto | IronNet, Inc., et al. bankruptcy case | |
| SP013 | Horizon3.ai | NodeZero: The World’s Most Experienced AI Hacker | More than 5,200 organizations worldwide relying on NodeZero. |
| SP014 | Business Wire | Horizon3.ai Secures Investment from Prosperity7 Ventures to Protect AI Datacenters and Critical Infrastructure | |
| SP015 | Horizon3.ai | The NodeZero Platform | NodeZero transforms how organizations secure their environments by running unlimited pentests. |
| SP016 | Business Wire | XBOW Raises $120M to Scale its Autonomous Hacker | Valued at over $1B, XBOW is Accelerating AI-powered Offensive Security to Help Defenders Outpace Modern Attackers. |
| SP017 | Accenture | Accenture Invests in XBOW to Advance Continuous Offensive Security Testing and Exposure Management | New partnership will scale continuous, AI-driven security testing and exposure management. |
| SP018 | Dreadnode | Dreadnode — AI Infrastructure for Security Agents | AI-native security can’t happen without infrastructure. |
| SP019 | Dreadnode | Research | |
| SP020 | FinTech Global | Dreadnode captures $14m to fortify offensive AI security capabilities | Dreadnode, an emerging startup specializing in offensive AI security, has recently secured a $14m Series A funding round. |
| SP021 | RunSafe Security | CISA’s 2026 Memory Safety Deadline | CISA has made memory safety a key focus of its Secure by Design initiatives. |
| SP022 | PR Newswire | RunSafe Security Raises $12 Million in Series B Funding | |
| SP023 | Help Net Security | RunSafe Security raises $12 million to reduce attack surface in critical infrastructure | |
| SP024 | Two Six Technologies | Two Six Technologies Captures Strategic Win with Award on $4 Billion DTRA Contract | Two Six supports national security customers across the Department of Defense, including U.S. Special Operations Command, U.S. Cyber Command and DARPA. |
| SP025 | Two Six Technologies | Sentr — Command the Information Environment | AI-driven command of the information environment — sense, plan, and coordinate effects at scale. |
| SP026 | Booz Allen Hamilton | Cybersecurity | Cyberattacks move at AI speed. Cyber defense must too. |
| SP027 | Leidos | Cybersecurity | Offensive, defensive, and cyber resilience across every mission. |
| SP028 | SAIC | SAIC Cybersecurity | |
| SP029 | CACI | Cyber | CACI advances automation and AI/ML across operations to purposefully accelerate mission success. |
| SP030 | Peraton | Cyber | |
| SP031 | ManTech | ACTP | |
| SP032 | Parsons | Cybersecurity For Global Events | |
| SP033 | GovConWire | 8 Companies Awarded $1.9B in Navy Cyberspace Operations Support Contract Options | The U.S. Navy has awarded eight companies contract options worth $1.86 billion combined. |
| SP034 | Washington Technology | 2026 Top 100 | Our annual rankings are based on an analysis of federal spending on IT, systems integration, telecommunications, professional services and other high-tech needs. |
| SP035 | GovConWire | GSA Unveils 43 Phase 1 Awardees for Alliant 3 GWAC | The General Services Administration has unveiled the first phase of awards under the Alliant 3 governmentwide acquisition contract. |
| SP036 | Washington Technology | Battle for $245M cyber warfare contract gets new start | The Army has agreed to re-evaluate proposals submitted by Booz Allen Hamilton, Peraton and ManTech. |
| SP037 | Atlantic Council | Mythical Beasts: Investigating the role of intermediaries in the proliferation of offensive cyber capabilities | |
| SP038 | Atlantic Council | Crash (exploit) and burn: Securing the offensive cyber supply chain to counter China in cyberspace | Zero-day exploitation is becoming more difficult, opaque, and expensive, leading to feast-or-famine contract cycles. |
| SP039 | Lawfare | Partners or Provocateurs? Private-Sector Involvement in Offensive Cyber Operations | |
| SP040 | Cyber Defense Review | Exploit Brokers and Offensive Cyber Operations | |
| SP041 | Vannevar Labs | Restoring Deterrence, Reclaiming Advantage | |
| SI001 | ExecutiveBiz | Cyber Startup Cathedral Raises $160M at $1.4B Valuation | Cathedral has secured $160 million in a funding round ... valued the company at $1.4 billion. |
| SI002 | Startup Fortune | Four DOGE alumni raise at a $1.4 billion valuation for Cathedral | Not a product launch. Not a customer announcement. A company with almost no public footprint has raised unicorn money. |
| SI003 | citybiz | Andreessen Horowitz, Sequoia Capital Lead $160M Round for Former DOGE Staff’s Venture | The company ... was valued at $1.4 billion in the financing, which was led by Andreessen Horowitz and Sequoia Capital. |
| SI004 | EquityPandit | Former DOGE Officials Launch AI Defense Startup Cathedral | The company has raised $160 million in a funding round led by venture capital firms Andreessen Horowitz and Sequoia Capital. |
| SI005 | Acquisition.GOV | Part 16 - Types of Contracts | Part 16 describes contract types and ordering rules for federal acquisitions. |
| SI006 | Acquisition.GOV | 16.202-1 Description | A firm-fixed-price contract provides for a price that is not subject to adjustment based on contractor cost experience. |
| SI007 | Acquisition.GOV | 16.301-1 Description | Cost-reimbursement types of contracts provide for payment of allowable incurred costs. |
| SI008 | Acquisition.GOV | 16.401 General | Incentive contracts relate the amount of profit or fee payable to the contractor’s performance. |
| SI009 | Acquisition.GOV | 16.504 Indefinite-quantity contracts | An indefinite-quantity contract provides for an indefinite quantity, within stated limits, of supplies or services during a fixed period. |
| SI010 | Acquisition.GOV | 16.505 Ordering | Orders shall clearly describe all services to be performed or supplies to be delivered. |
| SI011 | Acquisition.GOV | 15.101 Best value continuum | An agency can obtain best value in negotiated acquisitions through source selection approaches where cost or price importance may vary. |
| SI012 | SBIR.gov | About | SBIR provides equity free funding through federal agencies to American small businesses. |
| SI013 | Defense SBIR/STTR | DoW Office for Small Business Innovation | The Defense SBIR/STTR flow runs from eligibility and proposal to post-contract award, Phase II, transition and commercialization. |
| SI014 | Defense SBIR/STTR | Defense SBIR/STTR - Funding Opportunities | DoW uses the Broad Agency Announcement funding mechanism to procure basic and applied research. |
| SI015 | General Services Administration | Small Business Innovation Research and Small Business Technology Transfer | The SBIR and STTR programs are highly competitive programs that encourage domestic small businesses to engage in federal R&D. |
| SI016 | Department of Homeland Security | CRADAs | A CRADA is a written agreement that facilitates R&D collaboration between federal laboratories and non-federal entities. |
| SI017 | Congressional Research Service | Department of Defense Use of Other Transaction Authority | The Department of Defense obligates more than $300 billion annually to buy goods and services and support R&D. |
| SI018 | Defense Innovation Unit | About DIU | DIU accelerates the adoption of leading commercial technology throughout the military. |
| SI019 | Defense Innovation Unit | Tap Into a $100+ Billion Market | Any individual or commercial entity is eligible to respond to a DIU solicitation. |
| SI020 | USAspending.gov | Government Spending Open Data | USAspending is the official open data source of federal spending information, including contracts, grants, and loans. |
| SI021 | SAM.gov | Contract Opportunities | SAM.gov is the federal contract opportunities surface for government solicitations. |
| SI022 | U.S. Department of Defense | Contracts | The Defense Department publishes contract award notices on its official contracts page. |
| SI023 | Securities and Exchange Commission | Palantir Technologies 2025 Form 10-K | Revenue increased by $1.6 billion, or 56%, for the year ended December 31, 2025 compared to 2024. |
| SI024 | Securities and Exchange Commission | Palantir Technologies Q1 2026 Form 10-Q | Revenue from government customers and U.S. customers remained a meaningful source of revenue growth. |
| SI025 | Securities and Exchange Commission | Palantir Technologies 2024 Form 10-K | Revenue from government customers increased by $347.4 million, or 28%, for the year ended December 31, 2024 compared to 2023. |
| SI026 | Palantir | Getting started with Palantir | The Palantir platform is used by organizations from startups to multinational companies to governments around the world. |
| SI027 | Sacra | Anduril revenue, valuation & funding | Sacra estimates that Anduril hit $2.2B in revenue in 2025, up 120% from $1B in 2024. |
| SI028 | Sacra | Shield AI revenue, valuation & funding | Sacra estimates that Shield AI hit approximately $300M in revenue for the year ending March 2025. |
| SI029 | Los Angeles Times | Anduril to invest another $1 billion in California with new Long Beach campus | Anduril Industries ... will expand in Long Beach with a new $1-billion complex near the city’s airport. |
| SI030 | GeekWire | Defense giant Anduril is quietly building autonomous warships on Seattle’s historic ship canal | Anduril Industries is building a new class of autonomous warships on Seattle’s historic ship canal. |
| SI031 | Goldman Sachs | AI is poised to drive 160% increase in data center power demand | Goldman Sachs Research estimates that data center power demand will grow 160% by 2030. |
| SI032 | U.S. Department of Energy | DOE Releases New Report Evaluating Increase in Electricity Demand from Data Centers | Domestic energy usage from data centers is expected to double or triple by 2028. |
| SI033 | Epoch AI | Training compute of frontier AI models grows by 4-5x per year | Training compute of frontier AI models grows by 4-5x per year. |
| SI034 | Andreessen Horowitz | American Dynamism: Supporting the National Interest | American Dynamism supports companies serving the national interest. |
| SI035 | Small Business Administration | Federal Contracting | The SBA explains the federal contracting path for small businesses. |
| SI036 | Government Accountability Office | DOD Fraud Risk Management | DOD spent about $422 billion on contracts in FY 2020 and has been the target of contracting-related fraud schemes. |
| SE001 | U.S. News & World Report / Reuters | Exclusive-DOGE Alumni Launch Military Cyber Startup With $1.4 Billion Valuation | plans to secure U.S. government contracts to bolster AI-driven cyber operations, including offensive and defensive capabilities |
| SE002 | The Next Web | Four former DOGE staffers raised $160 million at a $1.4 billion valuation for an AI military cyber startup | The company plans to secure US government contracts for AI-driven offensive and defensive cyber operations against adversaries including China. |
| SE003 | Hoodline | Cathedral: Ex-DOGE Engineers Launch $1.4B Military Cyber Startup | exploring either a purchase of or partnership with a data-center provider to secure dedicated compute |
| SE004 | Cyber Daily | Ex-DOGE engineers launch new AI firm to bolster US military cyber | former Department of Government Efficiency (DOGE) engineers have formed a new AI cyber start-up for military defence and cyber operations |
| SE005 | The White House | White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination | GOLD EAGLE, a clearinghouse that enables unprecedented cybersecurity vulnerability coordination |
| SE006 | SecurityWeek | White House Launches AI-Driven Gold Eagle Vulnerability Coordination Initiative | speed up the detection, prioritization, and patching of vulnerabilities in critical infrastructure |
| SE007 | Dark Reading | Gold Eagle Clearinghouse Targets Real Gap, But How Is Unclear | Gold Eagle targets a real gap, but how is unclear. |
| SE008 | DARPA | AIxCC | DARPA | AIxCC will ask competitors to design novel AI systems to secure the software critical to all Americans. |
| SE009 | AI Cyber Challenge | DARPA’s AI Cyber Challenge | AIxCC Competitors successfully demonstrated the ability of novel autonomous systems using AI to secure the open-source software |
| SE010 | GitHub | AIxCC Finals | oss-fuzz-aixcc Public Apache-2.0 |
| SE011 | GitHub | XBOW Validation Benchmarks | As of mid-2026, these benchmarks are saturated |
| SE012 | Horizon3.ai | The NodeZero Platform | running unlimited pentests that uncover exploitable paths, guide remediation, and immediately verify that your fixes are effective |
| SE013 | Horizon3.ai Docs | HORIZON3 Documentation | deploy, configure, and maximize the effectiveness of NodeZero, our autonomous penetration testing platform |
| SE014 | Dreadnode | Dreadnode — AI Infrastructure for Security Agents | Build, evaluate, and deploy security agents with confidence. |
| SE015 | Dreadnode Docs | Dreadnode Documentation | building, evaluating, and deploying offensive security agents |
| SE016 | HackerOne | Why Hybrid Offensive Security Beats Agentic AI Alone | AI can now scale offensive operations in ways that were unimaginable a year ago, but on its own, it cannot deliver |
| SE017 | HackerOne | Prove Exploitability Faster With New Hai Agents | Discovery and exploitation are starting to happen on the same timeline |
| SE018 | HackerOne | AI Red Teaming Explained by AI Red Teamers | AI red teaming is primarily a human driven activity |
| SE019 | Anthropic | Claude Gov models for U.S. national security customers | deployed by agencies at the highest level of U.S. national security |
| SE020 | Anthropic | Cyber evaluations of Claude 4 | significant improvement in vulnerability identification and executing complex multi-step attack chains |
| SE021 | Anthropic | Building AI for cyber defenders | We deliberately avoided enhancements that clearly favor offensive work—such as advanced exploitation or writing malware. |
| SE022 | OpenAI | Disrupting malicious uses of AI by state-affiliated threat actors | state-affiliated threat actors used our services to research various companies and cybersecurity tools |
| SE023 | Google Project Zero | Project Naptime: Evaluating Offensive Security Capabilities of Large Language Models | helping attackers more quickly develop offensive capabilities |
| SE024 | Google Security Blog | AI-Powered Fuzzing: Breaking the Bug Hunting Barrier | AI-Powered Fuzzing: Breaking the Bug Hunting Barrier |
| SE025 | Palantir | Palantir Artificial Intelligence Platform | Palantir Artificial Intelligence Platform |
| SE026 | FedRAMP | FedRAMP | FedRAMP.gov | FedRAMP Marketplace is a searchable database of FedRAMP certified cloud services |
| SE027 | NIST | AI Risk Management Framework | AI RMF Profile on Trustworthy AI in Critical Infrastructure |
| SE028 | NIST CSRC | NIST SP 800-53 Rev. 5, Security and Privacy Controls | Security and Privacy Controls for Information Systems and Organizations |
| SE029 | NIAP | NIAP | NIAP |
| SE030 | DoD CIO | CIO - Cybersecurity Maturity Model Certification | Cybersecurity Maturity Model Certification |
| SE031 | NIST CSRC | About the RMF - NIST Risk Management Framework | Risk Management Framework provides a process that integrates security, privacy, and cyber supply chain risk management activities |
| SE032 | DefenseScoop | Amid concerns sparked by Mythos, the Pentagon’s cyber policy chief sees huge opportunity with frontier AI models | vulnerabilities recently discovered by Anthropic’s new Claude Mythos Preview artificial intelligence model |
| SE033 | DefenseScoop | Pentagon’s JWCC follow-on would create cloud marketplace, expand AI and edge computing | AI and machine learning capabilities across all classification and impact levels, including for DDIL environments |
| SE034 | DefenseScoop | AWS, Anduril debut new tactical data center offering listed on DOD’s cloud marketplace | cloud-grade computing, storage and AI capabilities in remote areas |
| SE035 | arXiv | Teams of LLM Agents can Exploit Zero-Day Vulnerabilities | agents still perform poorly on real-world vulnerabilities that are unknown to the agent ahead of time |
| SE036 | arXiv | Cybench: A Framework for Evaluating Cybersecurity Capabilities and Risks of Language Models | autonomously identifying vulnerabilities and executing exploits have potential to cause real-world impact |
| SU001 | U.S. News & World Report / Reuters | Exclusive-DOGE Alumni Launch Military Cyber Startup With $1.4 Billion Valuation | Cathedral was launched in recent months with a plan to secure U.S. government contracts to bolster AI-driven cyber operations, including offensive and defensive capabilities. |
| SU002 | The Next Web | Four former DOGE staffers raised $160 million at a $1.4 billion valuation for an AI military cyber startup | Cathedral, a stealth military cybersecurity startup founded by four former DOGE staffers, raised $160 million at a $1.4 billion valuation. |
| SU003 | Gizmodo | DOGE Guys Who Didn’t Save Us Any Money Rake in Cash With New Military Tech Startup | The story framed the ex-DOGE team’s move into a military-tech startup as controversial and criticized the public-service-to-defense-tech arc. |
| SU004 | Cyber Daily | Ex-DOGE engineers launch new AI firm to bolster US military cyber | Former DOGE engineers formed Cathedral, a company that plans to harness AI to bolster the cyber capabilities of the US military. |
| SU005 | USAspending.gov | Government Spending Open Data | USAspending | USAspending is the official open data source of federal spending information, including information about federal awards such as contracts, grants, and loans. |
| SU006 | SAM.gov | Contract Opportunities | SAM.gov | SAM.gov hosts federal contract opportunities and includes warnings that the system contains Controlled Unclassified Information. |
| SU007 | U.S. Department of Defense | Contracts | The Department of Defense contracts page is an official U.S. government source for public contract announcements. |
| SU008 | U.S. Cyber Command | Mission and Vision | USCYBERCOM directs, synchronizes, and coordinates cyberspace planning and operations to defend and advance national interests. |
| SU009 | National Security Agency | Cybersecurity Collaboration Center | The NSA Cybersecurity Collaboration Center scales intel-driven cybersecurity through open, collaborative partnerships. |
| SU010 | U.S. Fleet Cyber Command / U.S. 10th Fleet | U.S. Fleet Cyber Command / Commander, U.S. 10th Fleet | Fleet Cyber Command / 10th Fleet is an operational force with more than 13,000 billets and many Cyber Mission Force units. |
| SU011 | Sixteenth Air Force | About Us | The 16th Air Force is responsible for ISR, cryptologic activities, and operating and defending Department networks. |
| SU012 | Marine Corps Forces Cyberspace Command | About Us | MARFORCYBER’s mission aligns Marine cyberspace operations with U.S. Cyber Command objectives. |
| SU013 | CISA | About CISA | CISA | CISA works with partners to identify and manage risk to the cyber and physical infrastructure Americans rely on. |
| SU014 | Central Intelligence Agency | Organization - CIA | CIA is responsible for providing national security intelligence to senior U.S. policymakers. |
| SU015 | Defense Intelligence Agency | Home | DIA’s mission is to provide intelligence on foreign militaries to prevent and decisively win wars. |
| SU016 | Defense Innovation Unit | Work With Us | Any individual or commercial entity is eligible to respond to a DIU solicitation. |
| SU017 | Defense Innovation Unit | Tap Into a $100+ Billion Market | DIU invites commercial entities, including first-time sellers to government, to submit solution briefs. |
| SU018 | Defense SBIR/STTR | DoW Office for Small Business Innovation | Defense SBIR/STTR describes steps from eligibility and registration through Phase II, transition, and commercialization. |
| SU019 | SBIR.gov | About | SBIR provides equity-free funding through federal agencies to American small businesses. |
| SU020 | General Services Administration | Multiple Award Schedule | GSA’s Multiple Award Schedule lists products and services that agencies can buy through the program. |
| SU021 | Defense Acquisition University | Other Transactions | Adaptive Acquisition Framework | Other Transactions are legally binding instruments other than standard procurement contracts, grants, or cooperative agreements. |
| SU022 | FedRAMP | FedRAMP | FedRAMP.gov | The FedRAMP Marketplace is a searchable database of FedRAMP certified cloud services, authorizing agencies, and assessors. |
| SU023 | Department of Defense CIO | CIO - About CMMC | DoD announced the suspension of CMMC Phase II requirements while Phase I self-assessment requirements remain in place. |
| SU024 | NIAP | NIAP | NIAP is the U.S. public program surface for Common Criteria evaluation information. |
| SU025 | Defense Counterintelligence and Security Agency | Entity Vetting, Facility Clearances & FOCI | Entities providing goods or services to the U.S. government involving access to or creation of classified information will first need a facility clearance. |
| SU026 | United States Space Force | United States Space Force > About Us | Space Delta 6 and related units operate and maintain satellite and ground systems supporting joint and interagency operations. |
| SU027 | AFWERX | SBIR/STTR | AFWERX maintains SBIR/STTR pathways for Air Force and Space Force innovation funding. |
| SU028 | SOFWERX | SOFWERX: Collaborative Solutions for Warfighter Challenges | SOFWERX serves as an innovation platform for United States Special Operations Command. |
| SU029 | DEFENSEWERX | DEFENSEWERX | Innovation & Collaboration | Niceville, FL | DEFENSEWERX enables agile innovation for government partners through innovation hubs across the country. |
| SU030 | U.S. Government Accountability Office | Other Transaction Agreements: DOD Can Improve Planning for Consortia Awards | GAO said OTAs allow more flexibility than traditional contracts and let DOD partner with contractors it has not worked with before. |
| SU031 | TechCrunch | Defense startup Shield AI lands $12.7B valuation, up 140%, after US Air Force deal | Shield AI announced a large Series G after a U.S. Air Force deal. |
| SU032 | TechCrunch | Anduril raises $5B, doubles valuation to $61B | Anduril raised a $5 billion Series H at a $61 billion valuation. |
| SU033 | Los Angeles Times | Anduril to invest another $1 billion in California with new Long Beach campus | Anduril is developing drones, missiles, robotic submarines, and autonomous fighter jets and expanding with a $1 billion Long Beach complex. |
| SU034 | U.S. Securities and Exchange Commission | Palantir Technologies Inc. 2024 Form 10-K | Palantir said Gotham has served global defense agencies and the intelligence community for over a decade and disclosed $1.071 billion of government revenue. |
| SU035 | UK Ministry of Defence | New strategic partnership to unlock billions and boost military AI and innovation | The UK Ministry of Defence described a strategic partnership intended to unlock billions and boost military AI and innovation. |
| SU036 | Microsoft Learn | Department of Defense Impact Level 5 - Azure Compliance | The DoD Cloud Computing SRG defines baseline security requirements used to assess cloud service offerings and support provisional authorization decisions. |
| SR001 | U.S. News / Reuters | Exclusive-DOGE Alumni Launch Military Cyber Startup With $1.4 Billion Valuation | Reuters reported Cathedral raised $160 million at a $1.4 billion valuation and plans AI-driven offensive and defensive military cyber operations. |
| SR002 | Startup Fortune | Four DOGE alumni raise at a $1.4 billion valuation for Cathedral, a stealth military cybersecurity startup backed by a16z and Sequoia | A $1.4 billion valuation at this stage is a bet on access and founder knowledge - not yet on revenue anyone can inspect. |
| SR003 | The Next Web | Four former DOGE staffers raised $160 million at a $1.4 billion valuation for an AI military startup | Former DOGE staffers raised $160 million at a $1.4 billion valuation for an AI military startup. |
| SR004 | WIRED | The DOGE Boys Get VC Funding to Support Their Latest Enterprise | DOGE appeared to have worked as an employment conveyor belt for many of the organization’s affiliates. |
| SR005 | Vanity Fair | Meet Your New Defense Contractors: The DOGE Boys | In some ways, DOGE acted as an expedited revolving door. |
| SR006 | Gizmodo | DOGE Guys Who Didn’t Save Us Any Money Rake in Cash With New Military Tech Startup | DOGE guys who did not save money are raising cash for a new military technology startup. |
| SR007 | NewsNation | Former DOGE staff start AI military company | Former DOGE staff started an AI military company. |
| SR008 | Cyber Daily | Ex-DOGE engineers launch new AI firm to bolster US military cyber | The firm is intended to bolster US military cyber capabilities. |
| SR009 | ExecutiveBiz | Cyber Startup Cathedral Raises $160M at $1.4B Valuation | Cyber startup Cathedral raised $160 million at a $1.4 billion valuation. |
| SR010 | CityBiz | Andreessen Horowitz, Sequoia Capital Lead $160M Round for Former DOGE Staff’s Venture | Andreessen Horowitz and Sequoia Capital led the funding round. |
| SR011 | Associated Press | Musk says he will bring back DOGE staffer who resigned after a report of racist postings | Marko Elez resigned after the Wall Street Journal linked him to racist social media posts and Musk said he would bring him back. |
| SR012 | WIRED | The Young, Inexperienced Engineers Aiding Elon Musk’s Government Takeover | WIRED identified six young men, apparently between 19 and 24, with little to no government experience playing critical DOGE roles. |
| SR013 | WIRED | Where the DOGE Operatives Are Now | Where DOGE operatives went after leaving government. |
| SR014 | WIRED | DOGE May Have Misused Social Security Data, DOJ Admits | DOGE may have misused Social Security data, according to the article title and reporting. |
| SR015 | Associated Press | DOGE was tasked with stopping Treasury payments to USAID, AP sources say | DOGE was tasked with stopping Treasury payments to USAID, according to AP sources. |
| SR016 | Associated Press | Treasury watchdog begins audit of Musk DOGE team’s access to the US government’s payment system | The Treasury inspector general began an audit of the DOGE team’s access to the government payment system. |
| SR017 | GovExec / Nextgov | Treasury missed security controls in giving DOGE system access, GAO finds | GAO found Treasury missed security controls in giving DOGE system access. |
| SR018 | The White House | Establishing And Implementing The President’s Department Of Government Efficiency | The executive order established the United States DOGE Service in the Executive Office of the President. |
| SR019 | Department of Government Efficiency | Work | DOGE: Department of Government Efficiency | DOGE publishes its own work page and savings claims. |
| SR020 | U.S. Government Accountability Office | High Risk List | GAO maintains a High Risk List for areas vulnerable to waste, fraud, abuse, or needing transformation. |
| SR021 | U.S. Government Accountability Office | DOD Fraud Risk Management: Actions Needed to Enhance Department-Wide Approach | GAO recommended actions to enhance DOD-wide fraud risk management. |
| SR022 | U.S. Government Accountability Office | Cybersecurity High-Risk Series: Challenges in Establishing a Comprehensive Cybersecurity Strategy and Performing Effective Oversight | GAO identified challenges in establishing comprehensive cybersecurity strategy and oversight. |
| SR023 | Acquisition.GOV | Subpart 9.5 - Organizational and Consultant Conflicts of Interest | FAR Subpart 9.5 addresses organizational and consultant conflicts of interest. |
| SR024 | Acquisition.GOV | 3.104 Procurement integrity | FAR 3.104 covers procurement integrity restrictions. |
| SR025 | Legal Information Institute | 5 CFR Part 2641 - Post-Employment Conflict of Interest Restrictions | 5 CFR Part 2641 sets post-employment conflict-of-interest restrictions. |
| SR026 | Legal Information Institute | 5 CFR § 2635.702 - Use of public office for private gain | Federal ethics regulations prohibit use of public office for private gain. |
| SR027 | Lawfare | Partners or Provocateurs? Private-Sector Involvement in Offensive Cyber Operations | Private-sector offensive cyber participation requires clarifying objectives, scope, legal authority, and liability before changing rules. |
| SR028 | CSIS | Redefining Cybersecurity as International Security, Not Just National Security | Cyber collaboration beyond borders can deepen ties but faces information-sharing and classified-information constraints. |
| SR029 | CSIS | Deterrence and Cyber Strategy | There is ample space for harmful cyber action below the use-of-force threshold. |
| SR030 | CSIS | DOD Is Updating Its Decade-Old Autonomous Weapons Policy, but Confusion Remains Widespread | CSIS argued DOD autonomy policy remains misunderstood and needs greater clarity. |
| SR031 | Atlantic Council | Crash (exploit) and burn: Securing the offensive cyber supply chain to counter China in cyberspace | The private-sector zero-day exploit market is opaque, fragmented, and strategically important. |
| SR032 | Legal Information Institute | 22 CFR Part 120 - Purpose and Definitions | 22 CFR Part 120 provides ITAR purpose and definitions. |
| SR033 | Legal Information Institute | 22 CFR Part 121 - The United States Munitions List | 22 CFR Part 121 contains the United States Munitions List. |
| SR034 | Bureau of Industry and Security | Homepage | Bureau of Industry and Security | BIS links to the Export Administration Regulations and advanced computing license guidance. |
| SR035 | Legal Information Institute | 15 CFR Part 734 - Scope of the Export Administration Regulations | 15 CFR Part 734 describes the scope of the Export Administration Regulations. |
| SR036 | The Wassenaar Arrangement | Control lists | Wassenaar publishes control lists for conventional arms and dual-use goods and technologies. |
| SR037 | Booz Allen Hamilton | Cybersecurity | Booz Allen markets cybersecurity services to government and enterprise customers. |
| SR038 | Leidos | Cybersecurity | Leidos markets cybersecurity capabilities. |
| SR039 | Palantir | Palantir Foundry documentation overview | Palantir publishes documentation for its Foundry platform. |
| SR040 | Anduril | Transforming U.S. Defense Capabilities with Advanced Technology | Anduril publicly markets advanced defense technology capabilities. |
| SR041 | Washington Technology | 2026 Top 100 | Washington Technology publishes a Top 100 government contractors ranking. |
| SR042 | SAM.gov | Contract Opportunities | SAM.gov is the U.S. government contract-opportunities portal. |
| SR043 | USAspending.gov | Government Spending Open Data | USAspending.gov publishes U.S. government spending open data. |
| SR044 | SBIR.gov | About | SBIR describes federal small-business innovation funding programs. |
| SR045 | Defense Innovation Unit | Tap Into a $100+ Billion Market | DIU describes pathways for commercial technology firms to work with defense customers. |
| SR046 | Bulletin of the Atomic Scientists | The quest for cyber norms | The article addresses the quest for cyber norms. |
| SR047 | Citizens for Responsibility and Ethics in Washington | CREW requests records on DOGE | CREW says DOGE continues to operate with no clarity on its structure, staffing, budget, or operations. |
| SV001 | U.S. News / Reuters | Exclusive: DOGE alumni launch military cyber startup with $1.4 billion valuation | Reuters reported Cathedral raised $160 million at a $1.4 billion valuation and is seeking U.S. government cyber contracts. |
| SV002 | StartupFortune | Four DOGE alumni raise at a $1.4 billion valuation for Cathedral | The article says Cathedral has no known customers, no published product page, no public contract wins, and no inspectable revenue. |
| SV003 | Economic Times ETCISO | DOGE alumni launch military cyber startup with $1.4 billion valuation | |
| SV004 | Traders Union | Cathedral raises funding for U.S. military cyber push at $1.4 billion valuation | |
| SV005 | CNBC | Anduril doubles valuation as defense tech funding boom continues | |
| SV006 | Forbes | Anduril’s $61 Billion Valuation Is A Bet On Pentagon Speed | |
| SV007 | Analytics Insight | Anduril valuation reaches $61 billion after $5 billion Series H funding round | |
| SV008 | TechCrunch | Anduril raises $5B, doubles valuation to $61B | |
| SV009 | TechCrunch | Defense startup Shield AI lands $12.7B valuation after U.S. Air Force deal | |
| SV010 | Tech in Asia | US defense AI startup Shield AI raises $2b at $12.7b value | |
| SV011 | TechFundingNews | Shield AI locks $240M and hits $5.3B valuation | |
| SV012 | DroneDJ | Shield AI lands $240M to expand drone autonomy tech | |
| SV013 | Stock Analysis | Palantir Technologies revenue 2018-2026 | |
| SV014 | Palantir Investor Relations | Palantir reports Q1 2026 U.S. revenue growth and raises guidance | |
| SV015 | Business Wire | Palantir reports Q1 2026 revenue growth | |
| SV016 | U.S. Securities and Exchange Commission | Palantir Technologies Form 10-Q for quarter ended March 31, 2026 | |
| SV017 | Last10K | Palantir Technologies SEC filings page | |
| SV018 | CompaniesMarketCap | Palantir market capitalization | |
| SV019 | CompaniesMarketCap | Palantir revenue | |
| SV020 | CompaniesMarketCap | Palantir P/S ratio | |
| SV021 | Yahoo Finance | The defense tech boom has become a bubble—or it will be soon | The piece argues that defense-tech capital is stampeding into companies whose valuations can run ahead of public products, contracts, and revenue. |
| SV022 | AIN Ventures | Is Defense Technology in a Bubble? | |
| SV023 | 409A Valuation | 409A valuation benchmarks for seed-stage startups | |
| SV024 | ValueAddVC | Average pre-seed, seed and Series A round sizes | |
| SV025 | Zeni | Series A valuations in 2026: what founders need to know | |
| SV026 | IdeaProof | Startup fundraising benchmarks 2026 | |
| SV027 | Andreessen Horowitz | American Dynamism | |
| SV028 | Rebellion Defense | Rebellion Defense company website | |
| SV029 | Anduril | Anduril company website | |
| SV030 | Los Angeles Times | Anduril to invest another $1 billion in California with Long Beach campus |