初创公司尽调
尽调报告 cybersecurity (defense tech) Seed / Series A (early-stage, pre-revenue) 2026-07-24

Cathedral

DOGE 校友为美国军方打造 AI 网络平台;a16z 和 Sequoia 以 $1.4B 估值下注 $160M

Cathedral 同时拥有顶级投资人背书和创始团队触达美国防务网络安全买方的罕见通道;但收入前估值高达 $1.4B,政治、执行和验证风险都很尖锐。

封面要素

融资额 01
$160M [CO011]
估值 02
$1.4B post-money [CO012]
领投方 03
a16z, Sequoia [CO013]
成立时间 04
2025 [CO002]
创始人 05
4 ex-DOGE staffers [CO006]
收入 / 合同 06
None disclosed [CO011]

公司概况

Cathedral 是一家隐身国防科技公司,2025 年由四名前政府效率部(DOGE)工作人员创立,目标是把 AI 用于美国军方网络行动,同时覆盖进攻能力(发现并利用对手系统漏洞)和防御能力(保护美国军方网络)。在 Reuters 2026 年 7 月 22 日报道前数周,公司完成 $160 million 融资,投后估值 $1.4 billion,由 Andreessen Horowitz 和 Sequoia Capital 共同领投,两家均获得董事席位。公司没有披露产品、收入或合同,估值押注的是创始团队近期接触美国政府高层的能力,而不是任何商业化记录。

成立时间
2025-01-01
创始人
Gavin Kliger, Luke Farritor, Marko Elez, Jack Stein
创立地点
United States
总部
United States (undisclosed)
产品
AI 驱动的平台(未披露,且大概率涉密),拟支持美国军方网络行动,把进攻性漏洞发现和利用、防御性威胁检测和响应结合起来;公司也在寻求专用数据中心算力来运行这些行动。
客户
美国国防部、美国网络司令部、NSA 以及更广泛的情报共同体;作战目标集则是对手系统,尤其是中国。
商业模式
面向 AI 驱动的进攻和防御网络工具与服务,获取美国政府合同,预计路径包括 SBIR/STTR、OTA 以及直接合同 / 正式项目合同工具。
阶段
Seed / Series A (early-stage, pre-revenue)
融资情况
在 2026 年 7 月 22 日前数周完成 $160 million 融资,投后估值 $1.4 billion,由 Andreessen Horowitz 和 Sequoia Capital 共同领投;两家均获得董事席位。
[CO002, CO006, CO011, CO012, CO013]

执行摘要

主要优势

  • a16z 和 Sequoia 两家一线投资人背书,并都拿到董事会席位,估值 $1.4B
  • 创始团队近期接触过政府高层,包括一名前 Pentagon 首席数据官;在重视买方关系的市场里,这种通道有价值
  • 切入时点正好踩中升温的 defense-tech 和 AI-cyber 市场,White House Gold Eagle clearinghouse 等明确信号显示本届政府把它列为优先事项

主要风险

  • 估值高达 $1.4B,但收入、产品和合同均未披露
  • DOGE 旋转门和利益冲突暴露集中,容易引来国会、伦理和声誉审查,也高度敏感于政治变化
  • 能力和牵引力主张大多涉密,无法独立验证;团队年轻,关键人和执行风险被进一步放大

未决问题

  • 收入、授标合同、积压订单、烧钱速度和现金跑道均未披露,无法承销收入前溢价
  • 公司没有官方披露(网站、产品文档、客户或员工数数据);几乎所有事实都追溯到一篇 Reuters 报道及其转载
  • 进攻 / 防御网络能力,以及任何 DoD 采购牵引力,都没有独立验证

目录

Chapter 01

01公司概览

1.1 身份、阶段与商业模式

公开记录里,Cathedral 更像一家隐身的 AI 军事网络安全公司,而不是一家常规已发布的软件供应商。Reuters 的 David Jeans 经 U.S. News 转载的报道,以及 The Next Web、Hoodline、Gizmodo、Cyber Daily 的后续报道,都一致描述这家公司由前 DOGE 执行人员创立,目标是扩展美国军方网络能力。因此,可支撑的商业模式很窄但重要:为 AI 驱动的进攻和防御网络行动赢得美国政府合同,潜在还要靠收购或数据中心合作拿到专用算力。受审阅来源没有披露总部;最强地理信号是靠近 Washington / Pentagon,而不是公司地址。我以中等置信度把 2025 年作为成立年份,因为 2026 年 7 月 Reuters 报道称,公司是在创始人 2025 年 DOGE 任期之后的近几个月启动。阶段应记录为隐身 / 私有未披露:融资规模很大,但产品文档、客户、收入和员工人数都缺席。[CO001, CO002, CO003, CO004, CO005, CO018]

Cathedral 概览 KPI 表
指标数值 / 状态日期置信度来源 / 缺口
公司身份隐身阶段 AI 驱动军事网络安全初创公司2026-07Reuters 分发报道、TNW、Hoodline、Cyber Daily
创立年份根据 DOGE 任期后“近几个月推出”推断为 2025 年2025Reuters 分发报道和报告生成日期逻辑
总部未公开披露;仅有华盛顿 / 五角大楼邻近线索2026-07-24证据缺口
最新轮次$160 million2026-07Reuters 分发报道加后续报道
投后估值$1.4 billion2026-07Reuters 分发报道加后续报道
收入 / ARRnull;未披露公开收入或 ARR2026-07-24已审阅公开来源缺口
客户 / 合同null;正寻求美国政府合同,未披露任何合同2026-07-24已审阅公开来源缺口
员工人数null;未披露公开员工人数2026-07-24已审阅公开来源缺口

Null 表示截至运行日期,抓取来源中未找到可用公开披露,不代表该指标为零。

[CO001, CO002, CO011, CO012, CO015, CO016]
FO002: 公司快照逻辑

可投资性逻辑从 DOGE 相关创始人延伸到军事网络合同、专用算力和政治审查。

[CO001, CO003, CO004, CO005, CO013, CO014]

1.2 创始人、领导层与关键人风险

公开点名的领导层集中在四位创始人:Gavin Kliger、Luke Farritor、Marko Elez 和 Jack Stein。公开尽调应把这份名单只视为 Reuters 报道过的创始人清单,而不是完整管理层或董事会名单。Kliger 是公开人物里战略重要性最高的一位,因为报道称他曾任五角大楼首席数据官,并参与美国国防部与 Anthropic 围绕 Claude 军事使用方式的争议。Farritor 带来 DOGE / GSA 降本经验和 SpaceX 实习背景;Elez 同时带来技术履历,以及来自财政部访问权限和社交媒体发帖事件的实质声誉 / 控制风险。Stein 被点名,但受审阅的免费公开记录给出的角色细节更少。这让 Cathedral 同时拥有创始人-市场匹配和关键人依赖:Cathedral 的准入故事之所以有价值,正因为它政治上敏感,也很难通过公司自有材料尽调。[CO006, CO007, CO008, CO009, CO010, CO021]

领导层与创始人表
人物Cathedral 当前角色DOGE / 此前背景创始人-市场匹配或风险关键人物依赖
Gavin Kliger联合创始人前五角大楼首席数据官;卷入 Anthropic/Claude 军事用途争议国家安全通道强;政治与 AI 治理风险暴露高确认当前角色、股权、安全许可状态和继任深度
Luke Farritor联合创始人前 DOGE 员工;Reuters 称其曾任 SpaceX 实习生和 GSA 降本执行者运营降本履历契合 DOGE 叙事,但商业网络安全角色尚无文件证明确认职能归属和技术贡献
Marko Elez联合创始人前 SpaceX 与 DOGE/财政部执行者技术和政府系统通道信号明确,但声誉和安全控制包袱重大确认访问控制、合规监督和面向客户的角色
Jack Stein联合创始人Reuters 及后续报道点名的前 DOGE 员工创始人身份已获交叉印证;角色深度不如 Kliger/Elez 公开确认职责、背景和决策权

创始人名单基于公开的 Reuters 来源包;不是完整高管名册或董事会名单。

[CO006, CO007, CO008, CO009, CO010, CO021]

1.3 融资、治理与利益相关方图谱

第一章承载核心融资事实。最可靠的公开融资记录是:公司在 2026 年 7 月 22 日前不久完成 $160 million 融资,投后估值 $1.4 billion。Andreessen Horowitz 和 Sequoia Capital 领投,且均获得董事席位。没有发现 Cathedral 更早融资,因此 $160 million 是已披露累计融资额;如果存在未披露的 pre-seed 资本,它不等于经验证的生命周期总融资。治理披露比估值暗示的要薄:公开文件点名四位创始人和两位领投方董事席位,但没有完整董事会、投票权、期权池、创始人持股、老股转让或观察员权利。利益相关方图谱因此包括投资人、创始人、美国政府买方、潜在算力提供方以及政治 / 监管环境。a16z 的 American Dynamism 材料和 Sequoia 的 AI 布局让投资人匹配显得合理,但缺少公司确认,治理透明度仍是重大尽调问题。[CO011, CO012, CO013, CO014, CO020, CO031]

利益相关方或投资人图谱
利益相关方角色控制权或经济重要性证据状态尽调要求
Gavin Kliger / 创始人群体创始人,且可能是运营控制中心政府通道叙事和关键人物风险集中在创始人多来源报道索取股权结构表、投票权、雇佣协议和安全控制政策
Andreessen Horowitz领投方并持有董事会席位释放 American Dynamism 适配和风投验证信号Reuters 源头报道加官方 a16z 背景确认董事代表、持股比例、后续储备和信息权
Sequoia Capital领投方并持有董事会席位顶级 AI 投资人,并拥有治理席位Reuters 源头报道加官方 Sequoia 背景确认董事代表、持股比例和保护性条款
美国政府 / 五角大楼买方目标客户和合同路径收入论点依赖政府合同,而不是已披露的商业客户Reuters 源头报道和 AI 政府背景索取管线、合同载体、采购状态和冲突审查
数据中心供应商或收购目标潜在专用算力依赖可能把 Cathedral 从纯软件推向资本密集型基础设施执行Reuters 源头报道索取自建 / 外购分析、成本模型和交易对手身份
DOGE / Trump 政府网络政治和声誉背景若国会控制权变化,通道优势可能变成合同审查风险Reuters 源头报道和负面 DOGE 报道索取伦理审查、回避安排、游说披露和政府关系政策

这张利益相关方图谱有意混合经济所有者、潜在客户、基础设施依赖和政治背景,因为它们都会影响 Cathedral 是否可投。

[CO013, CO014, CO025, CO031, CO032, CO037]
FO003: 快照 KPI

唯一硬 KPI 是融资指标;运营指标仍刻意留空,等待公司证据。

[CO011, CO012, CO013, CO014, CO015, CO016]

1.4 封面指标、缺口与估值背景

封面指标要直白,不要修饰:估值是 $1.4 billion;已披露融资是 $160 million;收入、ARR、客户数、合同、试点、总部和员工人数在受审阅公开记录中均为 null。这个缺口不是普通私营公司的小麻烦,因为 Cathedral 已经按爆发式防务 AI 公司定价,却仍在商业证明上保持隐身。$1.4 billion 估值可以放在 Anduril 2026 年 $5 billion Series H、$61 billion 估值旁边看,但这个比较两面都成立。它说明投资人愿意为国防科技支付溢价,也凸显 Cathedral 的证据基础早得多:没有披露合同、没有产品文档、没有运营指标,也没有官方公司公告。后续章节不应只凭融资推断牵引力。正确的尽调路径是拿到管理层提供的管线细节、合同状态、收入确认政策、算力策略、安全控制和招聘计划。[CO012, CO015, CO016, CO017, CO018, CO033]

1.5 里程碑与政策背景

这条时间线离不开 DOGE、国防采购和 AI 网络政策。DOGE 由 2025 年 1 月行政令创建,随后与激进的联邦降本和超过 250,000 名员工离职联系在一起,并于 2026 年 7 月 4 日终止。几周后,Cathedral 以 DOGE 校友公司身份公开浮出水面,带着国防网络雄心和大额风险资本。同一时期还包括 Anthropic-Pentagon 争议,Kliger 被报道参与其中,这一点重要,因为它显示他靠近军用系统 AI 使用规则;还包括 Gold Eagle,即白宫 2026 年 7 月推出的 AI 赋能漏洞协调清算平台。这些事实不能证明 Cathedral 已有合同,但解释了为什么投资人可能相信时点异常有利。反过来,它们也制造反向风险:DOGE 旋转门叙事、Elez 过往争议,以及未来合同可能遭遇国会审查,都应该放进概览,而不是推迟到后面的风险章节。[CO019, CO025, CO026, CO027, CO028, CO029]

里程碑表
日期事件类型金额 / 估值 / 状态参与方 / 来源重要性
2025-01DOGE 由行政令设立监管U.S. Digital Service 围绕 DOGE 议程更名 / 重组白宫 / DOGE奠定孕育创始团队的政府背景
2025DOGE 降本任期负面Reuters 报道 250,000+ 人离开联邦雇员队伍Reuters / GovExec / Nextgov形成旋转门和公共部门扰动背景
2026-04DOGE 在财政部的访问控制遭批评负面GAO 报告的安全控制缺口GovExec / Reuters 背景对 Elez 和未来网络信任尽调具有实质意义
2026-04 to 2026-07Anthropic 与 Pentagon 关于军事 AI 使用的冲突升级治理据报道出现政府施压和承包商清退期限TNW、CNBC、Politico 与 Breaking Defense解释 Kliger 据报参与为何具有战略意义
2026-05Anduril 巨额轮次完成融资$5B Series H,估值 $61BTechCrunch / ForbesCathedral 溢价定价的防务科技估值基准
2026-06Special 这家 DOGE 校友初创公司浮出水面融资a16z 支持的私营部门降本初创公司Reuters / TNW / Atlantic显示投资人对 DOGE 校友公司的兴趣以及负面怀疑
2026-07-01Gold Eagle 推出监管AI 驱动的漏洞协调清算平台白宫 / SecurityWeek / CSOAI 网络漏洞协调的政策顺风
2026-07-04DOGE 正式结束治理到达自设终止日期Yahoo / Fiscal Times标志从联邦角色转向校友创业活动
2026-07-22Cathedral 融资被报道融资$160M 轮次,投后估值 $1.4BReuters 分发报道 / TNW / Hoodline / Cyber Daily整个报告的核心融资事实
2026-07-22Cathedral 使命与算力计划被报道产品AI 进攻 / 防御网络能力;探索专用算力Reuters 分发报道 / TNW / Hoodline定义产品论点和基础设施依赖

这是第一章的唯一正式时间线,把公司事件与解读这些事件所需的政策和可比融资事件合并呈现。

[CO002, CO005, CO011, CO012, CO026, CO027]
FO001: 公司里程碑时间线

Cathedral 的公开亮相接在 DOGE、AI 军事治理冲突和快速风投融资信号之后。

[CO002, CO005, CO011, CO012, CO026, CO027]

1.6 图表

Chapter 02

02市场分析

2.1 市场边界与现状替代方案

Cathedral 的规模测算应放在狭义国家安全网络市场里:面向 DoD 和情报共同体操作人员销售的 AI 赋能防御和进攻网络工具、漏洞发现、工作流软件及相关服务。这个边界有意排除广义企业安全、消费者网络安全、通用联邦 IT 服务和实体国防硬件,尽管这些类别能提供背景和可比估值。核心用户问题不是再买一个 SOC 工具,而是在满足涉密网络、零信任和指挥授权要求的同时,加速针对国家级对手的网络行动。因此,最强替代方案是内部 Cyber Command 和 NSA 能力、既有国防承包商、人工红队或渗透测试团队,以及 CISA 式民用防御卫生实践。这样的框架把 Cathedral 的机会绑定在任务网络工作流上,而不是泛化的网络安全 TAM。[CM001, CM002, CM005, CM006, CM007, CM021]

市场定义表
细分 / 类别纳入支出排除支出买方 / 付款方相关性
AI 网络行动工具自主漏洞发现、网络任务工作流、防御自动化、操作员 copilot面向民用企业销售的通用端点安全DoD 项目办公室、Cyber Command、IC 买方Cathedral 核心 SAM
任务网络服务专项实施、红队自动化、涉密网络部署支持与网络行动无关的宽泛系统集成军种网络组成部门和任务负责人核心,但服务占比高
进攻性网络 / 网络战依法授权且有预算的敏感工具和支持非法活动、美国政府授权之外的出口管制销售高度受限的 DoD/IC 赞助方相邻;公开数据缺口
联邦民用网络安全当产品可泛化时的 CISA 对齐自动化和零信任支持常规 helpdesk、大宗 IT、消费者安全CISA 和民用机构相邻选项,不是标准焦点
广义网络安全市场仅作为估值和威胁趋势背景大多数企业、消费者、MSP 和合规支出商业 CISO 和机构对 TAM 过宽
实体防务硬件除打包进网络任务系统外,不纳入无人机、传感器、武器平台、工厂服务商和主承包商排除;Anduril 可比项需打折

边界表把 Cathedral 的 AI 网络任务切口同广义网络安全和防务硬件分开;这些行是尽调用的部分分类,不是穷尽的 NAICS 市场普查。

[CM001, CM005, CM006, CM007, CM021, CM025]
FM001: 市场规模测算口径

可寻址市场从宽泛的联邦网络和网络安全背景,收窄到向 DoD 和 IC 买家销售的军事 AI 网络作战产品。

金字塔只是市场边界口径,不是可相加的金额瀑布;只有顶部联邦背景和分析师估算行有公开数字支撑。

[CM001, CM003, CM021, CM025, CM026, CM037]

2.2 多重市场规模测算口径

没有单一公开 TAM 数字足以支撑 Cathedral 的投资决策。最宽口径是美国联邦网络安全支出,它至少提供约 $26 billion 年度背景,但包含民用和基础设施支出,Cathedral 不应把这些算进核心 SAM。第二个口径是 DoD 和任务网络支出,但公开预算书无法完全拆出涉密进攻性网络项目。第三个口径是军用 AI:MarketsandMarkets 和 Grand View 都显示这是一个数十亿美元市场,但增长率和终点差异很大,因此区间比点估计更诚实。第四个口径是网络战市场研究,Mordor 的 2026 至 2031 年估算更接近 Cathedral 的待完成任务,但仍混合了产品、服务和终端用户。在 Cathedral 披露收入或中标前,SOM 口径应继续以合同管线为基础。[CM003, CM004, CM016, CM017, CM018, CM019]

TAM/SAM/SOM 或规模测算口径表
发布方年份地理范围数值CAGR方法论置信度局限
OMB / 联邦预算口径2026美国联邦年度网络预算背景:~$26B+n/a自上而下的联邦网络预算背景包含 Cathedral 核心之外的民用和基础设施支出
DoD 预算口径2026美国国防低十几 $B 的网络 / 任务预算背景;精确科目部分涉密n/a国防预算材料加公开任务映射无法隔离进攻性或涉密网络项目
MarketsandMarkets 军事 AI2023-2028全球USD 9.2B 至 USD 38.8B33.3%分析师市场预测军事 AI 比网络行动更宽
Grand View 军事 AI2024-2030全球USD 9.31B 至 USD 19.29B13.0%分析师市场预测终点值和 CAGR 不同于 MarketsandMarkets
Mordor 网络战2026-2031全球USD 40.13B 至 USD 52.27B5.43%分析师市场预测混合产品、服务和终端用户
Grand View 网络安全2026-2033全球规模很大的广义网络安全市场未使用广义行业背景纳入企业和消费者安全,夸大 Cathedral SAM
Cathedral 公开 SOM2026美国国防无已核验公开收入或合同n/a尽调缺口锚点需要公司管线、授标或客户证明

数值做了四舍五入,并有意保留为不同口径,因为分析师范围、时间跨度和纳入标准不可互换。

[CM003, CM004, CM016, CM017, CM018, CM019]
FM002: 市场估算区间

公开估算支撑数十亿美元级机会,但范围和预测年限差异很大。

所有行均以 USD 十亿计,但不能直接相加;图表比较公开市场规模口径和一个经公开验证的 SOM 锚点。

[CM003, CM016, CM017, CM018, CM019, CM037]

2.3 买方、用户、付款方与采用路径

买方图谱是多方结构。DoD 项目办公室和各军种网络组件可能掌握预算;Cyber Command、NSA 合作方和任务团队可能是用户和技术评估方;合同官和安全授权方决定试点能否变成真实支出。Cathedral 最可能的采用路径不是消费者式发布,而是分阶段政府销售:通过 SBIR 或 DIU 式入口切入,在其他交易授权(OTA) 或类似机制下做原型,再在任务价值、安全控制和资金都对齐后转成 FAR 合同或正式项目。这条路径有上行空间,因为成功工具可以嵌入任务工作流;但它也让公开牵引力很难观察。SAM.gov、USAspending 和 DoD 合同发布是有用监测器,却不是涉密网络工作的完整真相。[CM011, CM012, CM013, CM014, CM015, CM029]

细分 / 买方图谱
细分买方用户付款方工作流预算所有者采用触发因素
DoD 网络项目办公室项目经理任务网络操作员DoD 拨款科目或项目办公室采购并集成网络能力军种或国防机构 PEO/PM有资金的需求加安全审批
Cyber Command 单元作战司令部网络任务部队DoD 作战预算或赞助项目规划并执行行动司令部或支援军种组成部门速度和规模上的作战需求
NSA / 情报协作技术发起方分析人员和网络防御人员IC 或联合发起方威胁情报、漏洞、协作机构任务负责人外国威胁需求
军种网络单位军种领导层或 PEO军种网络团队陆军 / 海军 / 空军 / 太空军网络预算将工具部署到军种网络军种单位或 PEO演习、事件或现代化缺口
联邦民用相邻客户CISA 或机构 CISO民用机构安全团队机构 IT / 网络预算防御自动化和零信任机构 CIO / CISO合规和韧性要求
创新渠道试点DIU / SBIR 发起方试点用户原型或 R&D 资金评估商业技术创新办公室和任务伙伴成功演示或紧急作战需求

国防网络采购里,买方、用户和付款方常常不是同一方;各行是分群地图,不是客户清单。

[CM002, CM011, CM012, CM013, CM014, CM015]
FM003: 买家 / 分部地图

国防网络销售需要对齐任务用户、预算持有人和签约权限方。

[CM002, CM011, CM012, CM030, CM039, CM040]
FM004: 采用漏斗或价值链地图

军事网络采用路径从市场兴趣到经验证的 Cathedral 经常性收入,收窄得很快。

[CM011, CM012, CM013, CM014, CM030, CM031]

2.4 增长驱动因素

需求故事靠四个驱动因素支撑。第一,中国和其他国家级网络威胁让网络行动的速度和规模具有战略重要性。第二,DARPA 的 AI Cyber Challenge 验证了 AI 可以自动化漏洞发现和修复的具体想法,这与 Cathedral 声称的任务空间接近。第三,国防科技风险投资人已经奖励那些承诺国家安全现代化的公司,Anduril 是该类别最显眼的可比公司,尽管它的自治和硬件画像不同于 Cathedral 的网络软件切口。第四,政府效率推进可能偏好用软件和 AI 自动化替代稀缺持证劳动力。这些驱动因素支撑了大机会叙事,但不能证明采购转化、重复使用,或买方愿意授权自主进攻性网络工作流。[CM010, CM022, CM023, CM024, CM032, CM033]

增长驱动与约束表
驱动因素 / 约束方向时点影响尽调问题
国家级网络威胁和中国竞争上行当前推高军方对网络速度和自动化的紧迫感找出与优先威胁挂钩的已获资助项目
AI 漏洞发现和修复上行当前支撑 Cathedral 产品论点验证产品能力和安全控制
国防科技创投热度上行当前说明资本可得,且有高估值可比项将网络软件可比公司与硬件自主系统可比公司分开
效率压力和有密级资质人才短缺上行近期只要可信,就利好自动化测试买方替换人工流程的意愿
采购和合同转化下行18-24 个月以上风险延后收入、抬高烧钱速度按具名办公室梳理 SBIR / OTA / FAR 路径
ATO、零信任、NIST 和 AI 治理下行当前即便有试点兴趣,也可能卡住部署确认认证路径和涉密环境
密级和许可限制下行当前减少公开证据,拖慢上线审查有密级资质人员、设施和发起方证据
既有承包商锁定下行当前抬高合作或替换门槛核查主承包商关系和重新竞标窗口

时点条目是基于公开采购和合规证据得出的尽调假设;一旦拿到 Cathedral 特定管线证据,应予替换。

[CM008, CM010, CM022, CM023, CM029, CM031]

2.5 约束、反向观点与尽调缺口

反向市场观点很直接:Cathedral 可能按一代一遇的国防科技平台估值,却在争夺一个比表层 TAM 暗示更小、更慢、更涉密的支出池。把 ATO、零信任对齐、安全许可、数据处理和合同机制纳入后,采购周期可能拉长到 18-24 个月甚至更久。既有承包商也有中标历史、持证人员和合同基础设施;隐身初创公司要么自己搭建,要么围绕它们合作。公开来源尚未验证 Cathedral 的收入、客户、合同、ATO 状态或涉密部署足迹。因此下一步尽调应落到账户层面:识别有资金的项目办公室、活跃招标、赞助用户、安全认证路径,以及公司销售的是工具、服务还是任务结果。[CM008, CM027, CM031, CM036, CM037, CM044]

2.6 图表

Chapter 03

03竞争格局

3.1 竞争版图

Cathedral 进入的是国防 AI 和网络市场,相关竞争集比字面上说“军事网络安全”的初创公司更宽。第一圈是国防科技 AI 软件和自主系统公司:Anduril、Palantir、Shield AI、Rebellion Defense、Vannevar Labs 和 Two Six Technologies,它们争夺国防现代化预算、国家安全可信度和 AI 原生任务工作流。第二圈是网络垂直公司:Horizon3.ai、XBOW、Dreadnode、RunSafe、作为失败先例的 IronNet,以及漏洞交易生态。第三圈是既有政府承包商——Booz Allen、Leidos、SAIC、CACI、Peraton、ManTech 和 Parsons——它们已经握有合同工具、持证员工和项目关系。Cathedral 被报道的切口,是前 DOGE 政府准入与进攻加防御 AI 网络任务的组合;弱点在于公开来源展示的是计划,而不是已证明的合同。[CP001, CP002, CP003, CP004, CP005, CP039]

竞争对手画像表
公司类别规模 / 融资信号攻防重点DoD / 政府关系相对 Cathedral 的差异
Anduril国防科技 AI 初创公司$5B Series H 后估值约 $61B国防自主系统 / 指挥控制,不只做网络报道显示有战场管理和国防合同制造能力和 Lattice 平台大得多;网络纯度较低
Palantir上市国防 AI 平台2024 年收入 $2.9B;政府业务占 55%AIP / Gotham 决策和数据平台国防、情报和盟国政府长期使用既有地位和审计控制很深;初创速度光环较弱
Shield AI国防自主系统初创公司据报道 2026 年估值 $12.7B飞机自主系统和 AI 驾驶员Hivemind 已被美国及盟军使用自主系统有任务验证;与网络直接重叠较少
Rebellion Defense国防 AI / 关键资产软件审阅材料中没有可靠当前估值AI 融合和资产保护定位国防市场,但合同深度不清邻近情报护盾定位;状态仍不够透明
Vannevar Labs国防 AI 软件私营;未保留公开估值国家安全软件 / 威慑面向作战人员和联邦用户更像相邻情报工作流,而非明确网络行动
Two Six Technologies国防 AI 和网络承包商私营承包商;参与 $4B DTRA IDIQ 授标网络、信息行动、智能体式 AI点名 DoD、SOCOM、Cyber Command、DARPA客户证明更足、合同站位更稳;隐身创业叙事的上行空间较小
Horizon3.ai自主渗透测试初创公司2026 年声称覆盖 5,200+ 家组织靠攻击性测试做防御验证声称有政府和关键基础设施用例公开产品证明更多;军事攻击任务叙事较弱
XBOW自主攻击安全初创公司$120M Series C 后估值 >$1B攻击安全和持续测试通过 Accenture 走企业 / 伙伴路线最接近的 AI 攻击网络初创公司;DoD 通道不够明确
Dreadnode攻击型 AI 安全初创公司2025 年 Series A 约 $14MAI 红队基础设施和研究有政府潜力,但审阅材料未证明AI 原生攻击研究;规模小得多
RunSafe Security网络韧性初创公司2024 年 Series B $12M防御加固 / 内存安全关键基础设施和安全关键型叙事防御细分市场;与攻击任务重叠较低
Booz Allen、Leidos、SAIC、CACI、Peraton、ManTech 与 Parsons既有承包商联邦头部承包商排名和多年期网络合同工具攻击、防御、韧性和系统集成已建立的联邦合同工具和项目关系渠道和信任占优;AI 原生初创 DNA 较弱
漏洞利用经纪商 / 攻击网络供应商专业化供应链市场不透明;价格和供给看不清攻击性漏洞利用开发和经纪政府客户可购买特定能力可替代 Cathedral 任务中的部分组件,不是平台同业

规模信号采用每个竞争对手已审阅公开信息中最强的数据点;未获得直接支持时,不推断私营公司估值。

[CP006, CP008, CP009, CP011, CP012, CP013]
FP001: 竞争定位图

Cathedral 落在 AI 原生 / 攻防一体象限,但 DoD 既有项目地位弱于在位厂商,产品证据也落后于网络安全专精玩家。

序数位置基于公开定位、合同证据和产品重心;未见任何来源报告这些坐标。

[CP003, CP005, CP006, CP008, CP011, CP016]

3.2 国防科技 AI 同类公司

国防科技 AI 同类公司并不是干净的一对一产品比较,但它设定了 Cathedral 必须越过的门槛。Anduril 在 $5 billion Series H 和 $61 billion 估值之后,是风险资本支持的规模异类,公开报道把 Lattice 与导弹防御战斗管理联系起来。Palantir 嵌入体制更深:其 10-K 描述 Gotham、AIP、Foundry 和 Apollo,Gotham 服务国防和情报用户超过十年,政府客户贡献了 2024 年大部分收入。Shield AI 先做自主系统而不是先做网络,但其 Hivemind AI 飞行员和 2026 年估值跃升说明,一旦 AI 系统获得任务验证,资本定价可以多快抬升。Rebellion 和 Vannevar 展示相邻国防软件定位;Two Six 规模更小却高度相关,因为它在客户集中点名 U.S. Cyber Command、DARPA 和 DoD。[CP006, CP007, CP008, CP009, CP010, CP011]

国防科技 AI 同业矩阵
同业主要产品重心融资 / 公开规模DoD 或盟军证明Cathedral 启示
Anduril基于 Lattice 的国防系统和自主能力$5B Series H,估值 $61B陆军和导弹防御报道设定 Cathedral 目前无法匹配的创投规模标杆
PalantirAIP、Gotham、Foundry、Apollo2024 年收入 $2.9B;政府占 55%国防和情报使用超过十年最强的软件既有势力对照
Shield AIHivemind AI 驾驶员和自主飞机据报道 2026 年估值 $12.7B美国及盟军;涉及空军的交易说明任务证明能迅速抬高估值
Rebellion Defense关键资产情报护盾私营;未保留规模数据点只有公开国防定位在判断其已经停摆或被收购前,需要验证
Vannevar Labs国家安全软件和威慑私营;未保留规模数据点国防和联邦用户定位相邻预算竞争者
Two Six TechnologiesAI 指挥、网络、信息行动私营;DTRA IDIQ 参与者点名 DoD、SOCOM、Cyber Command、DARPA更接近 Cathedral 可能遭遇的服务 / 产品混合体

该矩阵把国防 AI 预算竞争者与网络专项产品竞争者分开;不是每家公司都销售同一工作流。

[CP006, CP007, CP008, CP009, CP010, CP011]
FP002: 防务 AI 同行能力图

防务 AI 同行之间差异最大的是产品成熟度、政府验证和网络安全针对性。

定性值汇总已审阅来源证据;未知项明确标注,不靠猜测填补。

[CP001, CP003, CP006, CP008, CP009, CP011]

3.3 网络安全垂直竞争者与漏洞利用市场背景

网络安全垂直竞争者比多数国防平台更贴近 Cathedral 的产品。Horizon3.ai 的 NodeZero 提供自主渗透测试,并公开宣称采用情况;XBOW 围绕自主进攻性安全在 2026 年拿到大额资本,并与 Accenture 建立战略关系;Dreadnode 正在为安全智能体和进攻性 AI 研究构建 AI 基础设施。RunSafe 是另一类防御加固对手,聚焦内存安全和关键基础设施,而不是进攻性网络行动。漏洞经纪商和进攻性网络中介并非常规 SaaS 竞争者,但它们重要,因为政府买方可以通过不透明供应链获取工具、人才和能力,而不是购买一个新平台。因此,Cathedral 最大的产品层面风险不是某一个克隆者,而是一组自动化渗透测试、漏洞供给、红队工具和内部网络团队,可以替代其承诺任务中的若干部分。[CP014, CP015, CP016, CP017, CP018, CP019]

网络专项与替代能力表
公司 / 替代项类别攻击能力防御能力公开牵引信号相对 Cathedral 的差异
Horizon3.ai NodeZero 产品自主渗透测试用攻击性测试找到可利用路径验证和修复工作流声称覆盖 5,200+ 家组织产品证明更强;军事通道不够清晰
XBOW自主攻击安全核心聚焦自主黑客 / 测试通过伙伴路线做暴露面管理估值 >$1B;Accenture 投资最接近的攻击型 AI 同业
Dreadnode攻击型 AI 安全基础设施AI 安全智能体和攻击研究AI 模型和安全测试基础设施据报道 Series A $14M更偏研究原生,规模更小
RunSafe Security网络韧性 / 内存安全直接攻击重叠有限内存安全和攻击面缩减据报道 Series B $12M防御细分市场,可能互补
IronNet已倒闭的集体防御网络初创公司历史上的网络威胁分析卖点集体防御破产并关闭警示性失败先例
漏洞利用经纪商攻击网络供应链零日 / 漏洞利用采购无直接能力;支持行动市场不透明且有中介风险攻击任务的组件替代项
内部网络团队现状 / 内部自建内生攻击网络行动内生防御和 SOC 职能涉密 / 不公开可在没有 Cathedral 的情况下自建或采购组件
主承包商任务单现状 / 外包给既有承包商可为网络行动项目配员托管防御、合规、集成海军、陆军、Alliant 类合同工具Cathedral 必须替换的默认采购路径

能力单元格概括已审阅公开定位,不是技术基准;涉密攻击能力必然观察不足。

[CP014, CP015, CP016, CP017, CP018, CP019]
FP003: 网络安全专项功能广度图

网络安全初创公司覆盖攻防连续谱的不同切片,Cathedral 仍需证明自己的集成广度。

矩阵为定性判断,因为公开来源不披露机密防务网络能力深度。

[CP003, CP016, CP019, CP021, CP022, CP024]

3.4 既有承包商与分发能力

既有承包商威胁由分发主导。Booz Allen、Leidos、SAIC、CACI、Peraton、ManTech 和 Parsons 都营销网络能力,公开合同报道也显示这些名字出现在海军网络空间行动支持、陆军网络战工作和 GSA Alliant 3 周围。这一点重要,因为 Cathedral 想要的买方——美国军方及相邻国家安全机构——已经有路径采购网络行动、系统集成、AI 和托管服务,不必等一家新的隐身初创公司成熟。Cathedral 仍可胜出,只要它提供阶跃式 AI 优势,或创始人把关系转化为快速试点;但现实销售门槛很高:既有厂商懂合规、持证人员配置、续标、抗议和项目办公室节奏。新进入者要么与它们合作,要么在狭窄工作流内替代它们,要么足够快成为主承包商,撑过采购延迟。[CP027, CP028, CP029, CP030, CP031, CP032]

既有承包商渠道表
既有承包商公开网络 / AI 线索合同关系线索对 Cathedral 的竞争危险Cathedral 可能回应
Booz Allen网络防御提速到 AI 速度的叙事陆军网络战重新竞标和 Top 100 规模背景很高先合作,或先攻窄 AI 网络工作流
Leidos攻击、防御和网络韧性表述联邦网络合作伙伴关系和 Top 100 规模背景证明主承包商无法快速配员的差异化 AI 能力
SAIC联邦网络安全和 IT 现代化GAO IT / 网络现代化和 Top 100 规模背景中高在初创速度比广泛集成更重要的场景竞争
CACIAI / ML 赋能的网络行动Top 100 和联邦网络定位证明更好的模型性能或任务自动化
Peraton国家网络任务定位海军网络空间选项;陆军网络争议借创始人通道,在重新竞标周期前拿到试点
ManTech网络任务支持定位陆军网络争议;Top 100 背景中高用 AI 原生产品而非人力工时做差异化
Parsons关键基础设施和活动网络安全海军网络空间选项和 Top 100 背景初期避开宽泛基础设施网络市场

危险评级评估的是渠道力量,不代表一对一产品优劣。

[CP027, CP028, CP029, CP030, CP031, CP032]
FP004: 在位厂商渠道压力 KPI

合同载体和在位厂商排名说明,Cathedral 的进入市场门槛和产品能力一样关键。

[CP004, CP009, CP030, CP031, CP032, CP033]

3.5 差异化耐久性判断

Cathedral 的差异化可信但未证实。多头情形是,一个 AI 原生团队带着近期政府运营准入,能比传统承包商更快把进攻和防御网络工作流结合起来,同时避开自主渗透测试供应商或内存安全工具较窄的产品定义。空头情形在今天的证据上更强:公司没有披露收入、没有点名合同、没有公开产品演示,也没有可与 Palantir、Anduril、Shield AI 或主承包商相比的运营历史。IronNet 说明,即使有顶级政府履历和网络雄心,产品-市场匹配和收入质量没有兑现时仍会失败。因此,正确尽调姿态是把创始人准入视为入场券,而不是护城河。只有当 Cathedral 证明经安全许可的部署、可重复政府采购和可防御的专有网络 AI 能力,护城河才成立。[CP004, CP005, CP014, CP040, CP041, CP043]

护城河持久性 / 竞争风险登记表
护城河假设支持证据威胁严重性尽调问题
创始人政府通道Reuters 报道其与 Pentagon 和国家安全圈有联系通道可能受到审视,也可能随政治变化衰减列出已签试点、合同路径、牵头方和采购权限
AI 原生攻防一体网络平台报道中的使命覆盖进攻与防御网络行动没有公开产品、基准或部署证明展示实时工作流,并给出相对 XBOW/Horizon3 的技术评估
国防买家紧迫性大型网络与 AI 合同载体已掌握在传统承包商手中紧迫需求可能流向主承包商,而不是创业公司指明预算科目,并说明现有合同载体为何解决不了
进攻性网络能力供给漏洞利用 / 中介市场存在供应链不透明、法律风险和采购效率低说明自研 / 外采政策、授权和合规控制
相对传统承包商的潜在速度创业公司迭代可能快过系统集成商老牌承包商有 20 年关系和持证人员展示部署时间表和保密资质计划
顶级投资人的品牌和资本由 a16z 和 Sequoia 领投的 $160M 融资IronNet 说明声望不等于可持续收入中高给估值信用前,要求收入质量和续约证据

Cathedral 仍处隐身状态,且没有披露合同或收入,因此本风险登记表有意把证据缺口按风险加权。

[CP001, CP002, CP003, CP004, CP005, CP034]
FP005: Cathedral 差异化记分卡

创始人资源和 AI 原生任务得分较高,但公开产品证据和合同证据是关键缺口。

[CP001, CP003, CP004, CP005, CP014, CP041]

3.6 图表

Chapter 04

04财务

4.1 资本结构与当前财务状态

Cathedral 的财务章节从一个简单但异常激进的资本结构开始:受审阅的 2026 年 7 月报道显示,公司以 $1.4 billion 投后估值完成 $160 million 主融资,由 Andreessen Horowitz 和 Sequoia Capital 领投。按纯主融资轮计算,这意味着约 11.4% 新钱稀释,投前估值约 $1.24 billion。关键承销点不是算术,而是顺序。公开来源把 Cathedral 描述为由四名前 DOGE 工作人员创立的隐身军事网络初创公司,但没有披露收入、ARR、已确认积压订单、毛利率、付费客户或已授予合同。因此,本章把 revenueRunRate 和 ARR 视为 null,而不是很小。$160 million 融资足以资助严肃的产品开发和项目捕获,但估值靠的是创始人准入、投资人信念和国防 AI 市场胃口,而非已披露财务牵引力。[CI001, CI002, CI003, CI004, CI005, CI006]

融资与资本结构表
项目公开数值 / 状态衍生财务判断质量尽调要求
一级融资2026 年 7 月 $160M 融资所审阅材料中唯一披露的融资额确认总募资额与净到账额,以及是否包含老股转让
投后估值$1.4B未披露收入,却给出近似后期项目的估值索取股权结构表和完全稀释股数
隐含新钱稀释~11.4%在期权池或老股调整前,$160M / $1.4B确认期权池扩张和投资人优先权
隐含投前估值~$1.24B$1.4B 减去 $160M 一级融资所得确认估值是否按完全稀释口径的投后估值
已披露融资总额$160M保留来源中未找到 Cathedral 既往融资披露询问 SAFE / 可转债历史和创始人股权授予
收入运行率 / ARR从公开证据看仍属收入前阶段索取当前 ARR、试点、递延收入和在手订单
已披露合同未发现具名已授予合同、OTA、SBIR、CRADA 或客户按机构索取管线和授标文件

null 单元格表示抓取来源包中没有公开披露,不代表经济价值为零。稀释和投前估值行由报道的融资条款推算。

[CI001, CI002, CI003, CI004, CI005, CI006]
公开财务缺口表
缺失指标重要性当前公开状态严重程度尽调路径
ARR / 收入运行率判断估值是否有收入支撑阻断项索取已确认收入、ARR、试点和递延收入明细
具名合同 / 客户验证从接触到采购的路径阻断项索取授标文件、OTA、SBIR、CRADA 和机构牵头方
按合同载体拆分的毛利率区分软件式上行与服务或算力转售重大索取 FFP、成本加成、OTA 和订阅线的预计毛利率
月度消耗与现金余额将 $160M 融资所得换算成现金跑道重大索取交割后现金、薪酬、算力、安全和投标拓展支出
算力承诺判断数据中心策略更偏资本开支还是运营开支重大索取数据中心意向书、资本开支预算、租约条款和最低承诺
管线转化时间国防销售中测算 CAC / 回本替代指标所必需重大按机构、阶段、载体和预计授标日期索取管线

所有 null 都是明确证据缺口。不应在报告元数据或估值模型中把它们转成零值。

[CI007, CI008, CI010, CI011, CI022, CI023]
FI001: 投后估值桥接瀑布图

据报道的轮次数学从 $1.24B 隐含投前估值,加上 $160M 新股融资,桥接到 $1.4B 投后估值。

瀑布图仅使用报道的轮次条款,不建模清算优先权、老股交易、认股权证或期权池变化。

[CI001, CI004, CI005, CI006]

4.2 收入路径与合同经济性

最现实的收入路径是分阶段推进,而不是 SaaS 线性增长。Cathedral 可以争取非稀释性 SBIR 或 STTR 资助,通过 OTA 式渠道做原型,与联邦实验室开展 CRADA 合作,参与 DIU 式商业技术征集,最终进入 IDIQ 任务订单或正式项目采购。每条路径都会带来不同的单位经济性后果。若 Cathedral 把网络 AI 能力产品化并控制交付成本,固定总价工作可以带来更好上行空间,但也把成本超支风险压到承包商身上。成本补偿型工作能降低早期 R&D 现金转化风险,却通常限制利润率上行,也较难证明产品可重复性。一旦任务所有者围绕某个工具标准化,IDIQ 工具和任务订单可以产生黏性收入,但订单流不会自动到来。没有披露管线时,CAC 和回本周期应通过采购周期长度、投标负担、安全认证工作量,以及从原型转生产的转化率来代理。[CI012, CI013, CI014, CI015, CI016, CI017]

单位经济性与合同载体表
合同载体 / 模式收入机制毛利 / 现金流影响Cathedral 可能用途披露状态
SBIR / STTR非稀释性研发资金和商业化桥梁有助早期验证;不是可规模化 ARR 的证明量产授标前的网络 AI 原型工作Cathedral 未披露授标
OTA / 原型路径标准 FAR 合同模式之外的原型协议可加快采用,但仍需转入生产合同任务原型或快速能力测试Cathedral 未披露 OTA
CRADA联邦实验室与非联邦实体合作在不给公司政府资金的情况下获得验证技术合作或测试环境Cathedral 未披露 CRADA
固定总价交付物或服务按固定价格付款产品化后上行更大;承包商承担成本超支风险未来打包网络工具或托管能力未披露定价
成本补偿在上限内报销可允许已发生成本亏损风险更低,但毛利上行有限,产品证明也更弱早期研发或定制国防项目未披露合同
IDIQ / 任务订单伞形合同载体,下设具体工作订单任务订单反复出现则粘性强;收入只在下单后到来正式立项项目或全机构网络合同载体未披露合同载体

该表描述与财务相关的合同路径,不是 Cathedral 已有合同。每一行都只是潜在路径,因为 Cathedral 没有公开披露任何授标。

[CI012, CI013, CI014, CI015, CI016, CI017]
FI004: 收入路径流程图

Cathedral 的可能财务路径,要先从原型验证走到合同载体,之后才有可承销的可持续项目收入。

[CI017, CI018, CI019, CI020, CI021, CI041]

4.3 资本强度、烧钱速度与资金续航

算力策略是最大的财务摆动因素。CityBiz、EquityPandit 和 Startup Fortune 都报道 Cathedral 正在探索收购或合作建设数据中心,这会让公司偏离纯可变云成本画像。更广泛的 AI 基础设施来源也支持认真看待这一点:Goldman Sachs 预计 AI 将大幅推高数据中心电力需求,DOE 预计国内数据中心能耗到 2028 年翻倍或增至三倍,Epoch AI 估算前沿训练算力约以每年 4x 到 5x 增长。没有任何来源给出 Cathedral 实际算力账单,所以本章采用情景,而不是假装精确。$160 million 融资在每月烧钱 $4 million 时可支撑约 40 个月,在 $8 million 时约 20 个月,在 $12 million 时约 13 个月;单笔 $40 million 算力支出会显著缩短每一种情形。[CI009, CI033, CI034, CI036, CI037, CI038]

消耗与现金跑道情景表
情景月度消耗 / 支出假设$160M 可支撑现金跑道必须成立的前提风险备注
精简隐身开发月度消耗 $4M约 40 个月小团队、租用云、有限投标拓展支出可能低估持网络保密资质招聘和算力开销
基准国防 AI 开发月度消耗 $8M约 20 个月工程、安全、投标拓展和云开销均有一定规模下一轮融资前需要看到合同转化
重算力 / 重投标拓展月度消耗 $12M约 13 个月大规模持证团队,加上模型训练和投标负担收入延后会快速触发下一轮融资需求
专用算力冲击一次性支出 $40M,加月度消耗 $8M支出后约 15 个月数据中心收购 / 合作需要现金承诺没有收入时会实质改变现金跑道
Anduril 式规模参照大型设施和规模化后的预计经营亏损不可直接比收入、合同可与重度亏损并存说明规模化后资本强度仍会持续

现金跑道各行是基于报道融资所得做的情景测算,不是公司指引。测算排除了税费、融资成本、营运资本时点以及任何债务 / 项目融资结构。

[CI009, CI029, CI031, CI033, CI034, CI036]
FI003: 现金跑道情景范围

$160M 轮次可能意味着多年现金跑道,也可能在月烧钱和算力承诺不同的情况下只够一年多。

范围仅为示意,用现金简单除以烧钱速度;并非公司指引。

[CI036, CI037, CI038, CI039, CI040, CI045]

4.4 国防科技可比公司与收入轨迹

更好的可比经验是,国防科技收入可以扩张,但通常要经历多年产品化、采购胜利和设施建设。Palantir 是成熟上市软件可比公司:其 SEC 文件显示收入达到数十亿美元,并有重大政府贡献,包括 2025 年政府收入增长和显著美国政府收入。Anduril 是私营国防科技规模可比公司:Sacra 估算其 2025 年收入达到 $2.2 billion,预计 2026 年达到 $4.3 billion,并报道其以 $61 billion 估值完成 $5 billion Series H,同时预计 2026 年经营亏损。Shield AI 规模更小但相关,是自主系统可比公司;Sacra 估算其截至 2025 年 3 月年度收入约 $300 million。Cathedral 比这三家公司都早得多:其估值像后期国防科技溢价,已披露收入基础却像种子期证据缺口。[CI025, CI026, CI027, CI028, CI029, CI030]

可比公司财务表
公司最新公开 / 分析师收入指标估值 / 融资指标对 Cathedral 的财务启示与 Cathedral 的差距
Cathedral以 $1.4B 投后估值融资 $160M未披露收入前先拿到大额资金未披露 ARR、合同、毛利或在手订单
AndurilSacra 估计 2025 年收入 $2.2B,并预测 2026 年收入 $4.3B据 Sacra,H 轮融资 $5B,估值 $61B国防科技估值可由大额收入和合同支撑Cathedral 缺少同等收入证明
Palantir2025 年收入约 $4.48B;政府业务收入 2025 年增长 53%上市公司申报级财务披露政府软件可扩至数十亿美元收入Cathedral 缺少分部收入和公开申报
Shield AISacra 估计截至 2025 年 3 月年度收入约 $300M,隐含 2026 年收入 >=$540MSacra 给出的估值指标为 $2.3B自主国防创业公司在 IPO 规模前也能拿出收入公开层面 Cathedral 仍属收入前
Anduril 资本开支视角收入规模与 2026 年预计经营亏损、$1B Long Beach 综合设施并存重资本增长可能需要巨额一级资本即便完成大额融资,算力 / 设施也可能缩短现金跑道Cathedral 未披露算力承诺

Sacra 数据为分析师估算,Palantir 数据来自 SEC 文件,Cathedral 数据为报道中的融资事实。Cathedral 收入单元格有意保留为 null。

[CI001, CI007, CI025, CI026, CI027, CI028]
FI002: 可比公司收入标尺

Cathedral 未披露收入;Palantir、Anduril 和 Shield AI 则显示,后期防务科技可比公司已经拿出的财务证据规模。

Cathedral 仅为可视化披露缺失而按 0 绘制;报告仍把 Cathedral 的 revenueRunRate 和 ARR 视为 null。

[CI025, CI026, CI028, CI029, CI030, CI046]

4.5 财务结论与尽调卡点

财务结论是谨慎跟踪:对一家新成立的隐身初创公司而言,资产负债表很强,但承销文件很薄。Cathedral 有足够主融资去招聘、建设、跨过安全门槛并争取早期国防项目,却没有公开证据证明收入质量、利润率路径、合同积压、客户集中度或销售效率。因此,最重要的尽调卡点具体且可取得:扣除融资费用后的当前现金余额;按薪酬、算力、安全和项目捕获 拆分的月度烧钱;已承诺的数据中心资本开支或最低照付不议义务;按机构和合同工具拆分的管线;以及任何信函、中标、OTA、CRADA、SBIR 或涉密赞助方,能够解释为什么收入前 $1.4 billion 估值是合理的。在拿出这些材料前,投资人应把这轮融资承销为一个资金充足的政府网络 AI 采用期权,而不是一家收入支撑的国防软件公司。[CI007, CI008, CI010, CI011, CI022, CI023]

4.6 图表

Chapter 05

05产品与技术

5.1 产品范围与证据边界

Cathedral 的产品应按涉密或近涉密网络行动平台承销,而不是按公开文档齐全的 SaaS 产品承销。公开记录只支持一个任务级定义:面向美国政府买方的 AI 驱动军事网络行动,同时覆盖针对中国等对手的进攻和防御能力。没有受审阅来源提供 Cathedral 产品名称、截图、API 文档、部署图、性能声明、ATO 状态或点名用户。因此,本章把下文进攻和防御模块视为由公开报道和可比系统推导出的能力桶,同时把 Cathedral 特定成熟度标记为隐身。可能的客户工作流从授权任务或网络防御要求开始,经过 AI 辅助发现和分析,最后到人类批准、修复或任务打包。这个证据边界不是脚注,而是核心产品风险。[CE001, CE002, CE003, CE004, CE036, CE045]

能力矩阵:公开证据与推断成熟度
能力类别用户 / 买家任务Cathedral 成熟度标签证据状态尽调要求
进攻侦察任务团队界定目标和暴露面可能已有原型由进攻网络报道以及 AIxCC / Project Naptime 类比推断展示授权工作流、目标约束和审计日志
自主漏洞发现抢在对手前找到可利用缺陷可能成立但未验证有 AIxCC 和前沿模型类比支撑,但没有 Cathedral 文件提供基准套件、真阳性率和复现流程
漏洞利用生成 / 验证将漏洞转成已测试的利用路径推断中风险最高类比案例显示进展和边界;Cathedral 证据缺失展示沙箱设计、法律批准、熔断开关和人工复核
任务封装 / 移交操作员为网络操作员准备行动方案推测性没有公开 Cathedral 工作流或 C2 边界提供交战规则和审批链
威胁检测与分诊对告警、漏洞和利用证据排序推断更接近短期落地Gold Eagle、Anthropic 防御方和 OpenAI 滥用监控支撑这种模式展示遥测来源、检测精度和分析师体验
事件响应自动化推荐遏制和修复步骤可能成立但未验证NIST/RMF 和防御型智能体类比支撑需求展示回滚控制和经过测试的处置手册
网络监控 / 暴露面管理持续绘制可利用路径类比公司已商业验证NodeZero / HackerOne 类比;Cathedral 证明缺失展示智能体部署模型和环境覆盖
涉密计算隔离区在受限网络数据上训练 / 评估报道中的策略,未验证建成数据中心计划和 Claude Gov / JWCC 背景支撑需求展示设施、认证、保密资质和数据边界证据

各行是对一家隐身公司的能力假设;除非该行标注为「报道中」,否则 Cathedral 特定成熟度均未验证。

[CE001, CE002, CE003, CE004, CE007, CE009]
FE001: AI 网络行动流程

可能工作流分为进攻和防御两条路径,两者都需要人工授权和受控证据捕获。

流程依据公开任务主张和类比推断;Cathedral 尚未发布工作流图。

[CE001, CE002, CE003, CE004, CE009, CE016]

5.2 架构栈与算力模型

最可能的架构,是在涉密数据控制包裹下的智能体栈:模型编排、网络工具使用、安全数据检索、沙箱化漏洞利用测试、操作员复核,以及接入政府环境的部署连接器。Cathedral 被报道有意收购或合作数据中心,这一点异常重要,因为进攻性网络 AI 不能只按商品云来评估。训练语料可能包含漏洞情报、漏洞利用工件、敏感网络遥测或涉密任务背景;推理可能生成漏洞利用链或修复指令,不能离开经认证边界。Kliger 被报道担任五角大楼首席数据官,并接触 Anthropic / Claude 在 DoD 的使用场景,增加了创始人-市场背景,但不能证明 Cathedral 已解决模型治理。因此,架构表把推断层和已验证依赖拆开,并标记管理层必须拿出架构图、模型卡、隔离控制、日志计划和评估结果的位置。[CE005, CE006, CE007, CE008, CE019, CE040]

技术栈与依赖表
层 / 组件可能角色依赖主要风险证据状态
前沿模型层对代码、日志、配置和任务背景做推理LLM 或专业网络模型;涉密微调数据幻觉式发现或不安全利用建议由任务和类比推断
智能体编排规划任务、调用工具、持久化状态并分支调查工具沙箱、规划器、记忆、检索、策略引擎提示词 / 工具注入和自动化失控推断
安全数据检索搜索 CVE、代码、遥测、漏洞情报和历史事件授权威胁情报和政府数据权利数据投毒、情报过期、密级泄漏推断
漏洞利用沙箱编译、运行并验证利用或补丁假设隔离实验室、模拟器、fuzzer、CTF 式靶场逃逸、无效证明或不安全双用途输出由进攻范围推断
防御工作流连接器接入 SIEM/SOAR、工单、补丁和监控工作流DoD 网络 API、身份、日志和变更控制涉密隔离区内集成中断推断
涉密计算 / 隔离区承载受限任务的模型和数据专用数据中心、持证人员、ATO 边界资本强度和认证周期报道中有意图,执行未验证
合规证据系统维护 SSP、控制、测试、模型评估和审计轨迹FedRAMP / RMF / SP 800-53 / CMMC 证据ATO 延迟或继承控制不匹配部署环境要求

架构由外部推断;该表有意避免声称掌握 Cathedral 私有系统图。

[CE003, CE004, CE006, CE007, CE008, CE019]
FE002: 产品架构图

军用 AI 网络安全平台需要在受限算力边界内,拼起模型、智能体、数据、沙盒、集成和合规层。

[CE007, CE008, CE019, CE026, CE028, CE031]

5.3 类比对象与能力基准

公开类比对象让 Cathedral 在技术上显得可信,同时也收窄了不该假设的内容。DARPA AIxCC 表明,自主网络推理系统可以在受控开源环境中竞争漏洞发现和修复。Horizon3.ai NodeZero 和 Dreadnode 表明,自主渗透测试和进攻性安全智能体工具已经是产品类别。Anthropic、OpenAI 和 Google 表明前沿模型可以辅助网络工作,但它们的材料也强调安全边界、滥用监控和基准限制。HackerOne 和 arXiv 来源尤其适合做反向校验:它们提示 AI 可以放大进攻性工作,但完全自主的真实世界漏洞利用仍不可靠,需要人类验证。如果 Cathedral 的差异化真实存在,它更可能来自涉密数据、任务集成和持证算力,而不是“使用 LLM 智能体”这个泛化事实。[CE010, CE011, CE012, CE013, CE014, CE015]

类比系统对照表
类比对象可借鉴能力能证明什么套用于 Cathedral 的边界证据状态
DARPA AIxCC面向开源漏洞的自主网络推理AI 系统能在受控竞赛环境中发现并修复漏洞竞赛成绩不证明已具备涉密实战就绪度一手证据和开发者信号证据
XBOW 验证基准自主进攻安全基准测试AI 安全智能体已有公开基准基础设施基准可能被刷满,也未必预测真实零日表现开发者信号证据
Horizon3.ai NodeZero 产品商业自主渗透测试持续自驱渗透测试已有市场范式企业暴露面管理不同于军事进攻任务官方和文档证据
Dreadnode安全智能体基础设施和评估有团队在搭建用于评估和部署进攻智能体的平台基础设施工具不等于政府 ATO 或任务授权官方和文档证据
HackerOne Hai / AI 红队人类加智能体的漏洞验证混合流程可能压缩可利用性验证时间HackerOne 自身警告,单靠 AI 不够公司材料和反向评测证据
Anthropic Claude 网络能力 / Claude Gov前沿模型网络能力和涉密模型封装前沿模型厂商能支持国家安全环境和网络评估Anthropic 强调安全边界和仍然存在的限制官方研究证据
OpenAI 威胁行为者阻断监测恶意 AI 使用模型提供商能发现并阻断滥用模式不能证明进攻自动化可安全用于军事场景官方滥用证据
Palantir AIP任务 AI 工作流集成AI 能带着控制嵌入任务工作流AIP 是更宽的操作系统软件,不是网络漏洞利用引擎官方类比证据

类比行用于框定能力可行性和风险;没有一项能直接证明 Cathedral 产品。

[CE010, CE011, CE012, CE013, CE014, CE015]
FE003: 能力成熟度与证据矩阵

防御分诊是近期最有支撑的路径;自主漏洞利用生成最缺验证、风险最高。

序数评分为定性且有来源支撑;没有可用的 Cathedral 私有证据。

[CE010, CE011, CE014, CE015, CE016, CE019]

5.4 部署、集成与合规面

部署面很可能比模型演示更难。触达 NIPR、SIPR、JWICS、任务云或战术 DDIL 环境的军事网络产品,需要身份、日志、飞地、数据标注、出口管制、漏洞披露和操作员授权控制。若 Cathedral 交付云服务,FedRAMP 和 DoD 影响级别评估重要;ATO 需要 NIST RMF 和 SP 800-53;防务承包商 CUI 需要 CMMC;若出现经评估的端点或设备组件,NIAP 可能重要。DefenseScoop 关于 JWCC 的报道显示,五角大楼正在跨密级和影响级别寻求 AI 和 ML,但那只是需求信号,不是 Cathedral 授权。尽调要求很具体:索取系统安全计划、继承控制矩阵、部署边界图、许可人员名单、红队报告、模型评估协议,以及任何赞助方或授权官员往来。[CE026, CE027, CE028, CE029, CE030, CE031]

合规与 ATO 要求表
要求 / 控制族重要性Cathedral 可能状态所需证据主要尽调负责人
FedRAMP 或同等云授权政府云服务需要获授权的控制继承未公开披露FedRAMP 包、边界图、继承控制安全 / 合规负责人
DoD 影响等级评估(IL4/IL5/IL6,视情况而定)CUI、任务数据和涉密工作负载对应不同控制深度未公开披露影响等级目标、DISA 或牵头方评估路径云架构师
RMF / 运行授权在 DoD 系统上投入运行需要风险接受未公开披露SSP、SAR、POA&M、授权官路径项目安全官
NIST SP 800-53 控制项联邦系统安全和隐私控制基线未公开披露控制矩阵和测试证据GRC 负责人
CMMC国防承包商处理 CUI 可能需要认证或评估未公开披露CUI 边界和评估状态合同 / 合规
NIAP / 通用准则部分安全组件可能需要通过评估的产品有条件 / 未知产品组件清单和保护轮廓映射产品安全
安全许可和涉密设施访问模型训练、评估和运行可能接触涉密材料有暗示但未经验证许可人员名单、设施担保、知情必要流程人员 / 设施安全
模型安全和滥用控制进攻性 AI 带来双重用途和升级风险未公开披露评估协议、拒绝 / 覆盖政策、人工授权日志AI 安全 / 任务负责人

该表是需求映射,不声称 Cathedral 已取得任何授权或认证。

[CE019, CE026, CE027, CE028, CE029, CE030]
FE004: 按部署层划分的合规负担

最重的负担不在模型开发本身,而在机密行动、ATO 和影响级云边界。

1–5 负担评分是定性尽调排序,不是监管指标。

[CE026, CE027, CE028, CE029, CE030, CE031]
FE005: 关键依赖图

根据推断,Cathedral 产品要跑通,算力、涉密资质、模型、数据、ATO 和任务买方依赖都要同时到位。

[CE007, CE008, CE019, CE031, CE032, CE033]

5.5 路线图与技术风险

可信路线图是渐进式,而不是魔法般的自治。合理顺序应从分析师副驾驶工具和漏洞分诊开始,再推进到沙箱化漏洞利用验证、涉密算力认证、受控防御试点,最后才是严格授权的进攻性任务支持。核心技术风险包括模型幻觉、无效漏洞利用链、对抗性提示和工具操纵、外部无法复现的涉密数据评估,以及当进攻性建议看似可信却实际错误时的治理失败。Gold Eagle 和防御智能体类比显示,短期价值在漏洞协调和修复优先级排序。风险最高的主张是自主漏洞利用生成和接近 C2 的自动化,因为它们把安全、合法性、可靠性和升级担忧叠在一起。在 Cathedral 发布证据或客户在许可环境下验证部署之前,产品结论是高上行、未证实。[CE009, CE016, CE017, CE018, CE020, CE034]

路线图和技术风险表
路线图阶段 / 功能公开状态技术风险验证材料优先级
漏洞分诊分析师副驾推断存在,未披露误报和优先级排序偏弱基于真实工单的分析师并排评估
自主漏洞发现合理推测,未披露基准过拟合、真实场景召回率低带复现包的盲测基准
沙箱化漏洞利用验证合理推测,未披露幻觉式利用链和不安全工具使用隔离靶场日志和人工审批流程
防御性修复自动化合理推测,未披露补丁质量差或遏制建议不当通过回滚测试的剧本和变更控制集成
涉密计算隔离区仅有意向报道ATO 延误、资本开支和数据边界失效设施计划、SSP、许可证据
DoD 网络集成无公开证据NIPR/SIPR/JWICS 之间的身份、日志、API 不匹配边界和连接器架构
自主进攻任务支持推测性升级、法律授权和可靠性失效交战规则控制和红队证据阻断

路线图标签是尽调假设;Cathedral 未公开发布过任何带日期的产品路线图。

[CE003, CE004, CE007, CE016, CE017, CE018]

5.6 图表

Chapter 06

06客户

6.1 可触达买方群体,而非已披露客户

Cathedral 的客户章节必须从证据边界开始:公开来源支持一个庞大的可触达国家安全买方群体,但不支持任何点名 Cathedral 客户。Reuters 把公司描述为一家近期启动的隐身军事网络安全初创公司,正试图为 AI 驱动的进攻和防御网络行动获取美国政府合同;其他 2026 年报道重复了军事网络任务,但没有增加客户、部署、试点或合同 ID。最直接买方是 U.S. Cyber Command,NSA 和各军种网络组件是自然任务所有者;CISA、CIA、DIA 和亲密盟友国防部是合理相邻面。这是市场准入,不是采用。尽调中,活跃客户数、生产部署数、NRR、流失率、续约率和收入集中度,在 Cathedral 提供中标文件或客户推荐前都应保持 null。[CU001, CU002, CU005, CU008, CU009, CU010]

目标客户分层图
分层买方 / 用户 / 付款方任务需求可能采购路径进入难度证据缺口
USCYBERCOM / Cyber National Mission Force 任务方作战司令部和任务团队AI 辅助的进攻和防御网络行动涉密项目、OTA 原型、SBIR 转化极高未点名 Cathedral 试点或赞助方
NSA Cybersecurity Collaboration CenterNSA 任务团队和 DIB 网络安全团队由情报驱动,防御国防工业基础合作、涉密合同、OTA、类 CRADA 协作极高未披露技术集成
Navy Fleet Cyber / 第 10 舰队军种网络组成部队和海军网络舰队网络运行、支持网络任务部队军种合同、OTA、GSA、项目办公室未披露海军评估
第 16 空军空军网络、ISR 和密码组织运行并防御网络;支持网络效果AFWERX SBIR/STTR、军种 OTA、项目办公室未披露空军赞助方
MARFORCYBER海军陆战队网络空间组成部队与 USCYBERCOM 对齐的海军陆战队网络行动军种网络合同、OTA、创新中心未点名海军陆战队用例
Space Force 网络组织Space Delta 和太空任务系统防御团队保护卫星和地面系统任务基础设施SpaceWERX/AFWERX、涉密合同、项目办公室未披露太空任务授权
情报界CIA、DIA、NSA 任务所有者外国军事情报和敏感网络行动涉密合同、持证设施、项目办公室极高涉密需求可能在公开渠道不可见
民用和盟友网络机构CISA、DHS 组件、英国 / Five Eyes 盟友关键基础设施防御和盟友军事 AI 现代化GSA、DHS 采购渠道、双边盟友采购中高未披露非 DoD 客户证据

这是可触达买方地图,不是客户名单;截至运行日,Cathedral 没有公开具名客户。

[CU001, CU005, CU009, CU010, CU011, CU012]
具名客户证明表
证明类别公开值证据读法解读尽调要求
具名付费客户Reuters、TNW、Gizmodo 或 Cyber Daily 报道均未点名客户将客户数量按空值处理要求公司按密级提供客户名单
生产部署未披露生产用例或部署结果无法量化采用轨迹要求提供从试点到投产的状态和部署日期
已授予合同USAspending、SAM.gov 和 DoD 合同页面是公开检索入口;引用的公开授标记录没有点名 Cathedral公开证据不能证明收入要求提供授标 ID、合同工具、主承包 / 分包角色和涉密限制说明
试点或原型赞助方未公开识别出 DIU、SBIR、军种或 IC 赞助方管线可能私下存在,但尚未核实要求提供赞助方函件、评估备忘录和合同官联系人

null 表示所审阅公开来源集未披露;涉密或尚未公布的授标可能存在,但不能假定其存在。

[CU005, CU006, CU008, CU040, CU045]
FU004: 客户证据可见度条形图

公开证据最能支持可服务买方匹配,最缺真实客户和留存证据。

分数是序数型证据可见度判断,不是运营 KPI。

[CU005, CU007, CU031, CU037, CU040, CU041]

6.2 采购流程与采购工具

最可能的第一笔销售不是常规企业 SaaS 成单,而是一段国防采购序列。DIU、SBIR/STTR、AFWERX、SOFWERX、DEFENSEWERX 和 OTA 路径可以在 Cathedral 成熟到参与正式项目竞争前,让原型成为可能。DIU 明确邀请商业实体提交解决方案简报,包括首次向政府销售的公司;SBIR/STTR 提供非稀释性原型资金和转化语言。OTA 尤其相关,因为它们可以在标准采购合同之外资助原型和后续生产,但 GAO 也指出了规划和联盟纪律问题。GSA 采购目录和公开合同门户在后期重要,前提是产品范围、定价、合规和机构需求更清晰。因此,现实销售周期模型应是从首次任务对话到有意义收入需要 12 至 24 个月,涉密规模化会更久。[CU018, CU019, CU020, CU021, CU022, CU023]

采购渠道表
渠道Cathedral 最适配场景典型切入点规模化路径关键摩擦
DIU 商业解决方案征集有紧急任务牵引的商业 AI 网络原型向 DIU 招标提交方案简报原型 OT,或转给 DoD 赞助方需要任务所有者和作战评估
SBIR/STTR符合条件小企业的非稀释研发资金课题提案和 Phase I 奖项Phase II、转化、商业化资格、课题匹配和转化资金
其他交易授权标准 FAR 合同之外的原型或后续生产军种、DIU 或联盟 OTA符合法定条件时进入后续生产规划、联盟费用和转化纪律
GSA 多重授予目录后期面向低涉密软件 / 服务的重复采购拿到 Schedule 资格,由机构下单多机构订购入口产品、定价和合规成熟前并不理想
AFWERX / SpaceWERX空军或 Space Force 网络与 AI 试点SBIR/STTR 开放课题或挑战项目办公室或 Space Force 转化从试点交接到项目的风险
SOFWERX / DEFENSEWERXSOCOM 或军种问题发现挑战、奖金、评估、演示活动赞助方出资原型或 OTA往往处在采购前,且不具约束力
正式列装项目长期预算和规模化部署需求、采办策略、竞标多年持续保障和扩张最慢路径;需要证据、预算和合规

这些渠道大致按从易进入的试验到可持续项目规模排序;实际路径取决于 涉密赞助方需求。

[CU018, CU019, CU020, CU021, CU022, CU023]
FU001: 国防客户旅程图

Cathedral 可能先靠关系触达和任务匹配切入客户,但收入要等采购、合规和部署证据跑通。

旅程来自公开采购和合规路径推断,并非来自 Cathedral 已披露销售。

[CU007, CU018, CU020, CU023, CU026, CU029]
FU002: 原型到项目漏斗

每一阶段都会收窄账户集合:从广义可服务需求,缩到已披露、可持续的收入证据。

数值是本章证据可见度计数,不是 Cathedral 运营指标。

[CU005, CU008, CU018, CU020, CU023, CU025]

6.3 合规与涉密访问门槛

对 Cathedral 的客户转化而言,合规很可能与模型质量一样重要。交付到联邦或 DoD 环境的网络能力,可能面临 FedRAMP、DoD 影响级别、ATO、CMMC、产品保证和涉密访问门槛。DCSA 的设施许可表述尤其重要:任何提供涉及涉密信息的商品或服务的实体,通常在履约前需要设施许可。Microsoft 的 DoD IL5 文档也说明,DoD 云授权在普通商业托管之外增加了要求。Cathedral 没有公开披露任何 FedRAMP 名单、ATO、DoD IL 授权、CMMC 姿态、NIAP 验证、设施许可、TS/SCI 持证人员基础或涉密项目访问。隐身公司缺少这些信息不应被过度解读,但这是投资人承销可部署性之前必须拿到的门槛型尽调包。[CU026, CU027, CU028, CU029, CU030, CU031]

合规要求表
要求为什么影响 Cathedral可能需要的证据当前公开状态GTM 影响
FedRAMP联邦机构使用的云服务通常需要授权云市场上架、机构 ATO 包、评估方证据未披露 Cathedral 上架信息解决前会挡住非涉密 SaaS 式部署
DoD 影响等级 IL4/IL5/IL6DoD 云工作负载需要影响等级姿态和临时授权DoD SRG 映射、PA/ATO 证据、托管边界无公开 DoD IL 证据可能迫使公司及早采用 GovCloud/DoD 云架构
运行授权任务系统投入运行前通常需要客户授权系统安全计划、控制项、测试、授权官未披露 ATO原型入选后可能再增加数月
CMMC / DIB 网络卫生处理 CUI 的国防承包商面临网络安全自评或认证义务SPRS/CMMC 记录、政策范围、评估方输出未披露 Cathedral 状态任何 CUI 工作前的尽调必问
NIAP / 通用准则国家安全环境可能要求安全产品满足产品保障预期保护轮廓映射或已评估产品状态未披露验证可能影响端点 / 网络产品
设施许可和 FOCI执行涉密合同需要对持证实体进行审查DCSA 设施许可和 FOCI 审查未披露 FCL涉密项目硬门槛
人员许可 / TS/SCI操作人员和工程师可能需要访问涉密网络和数据持证人员名单和项目访问批准无公开人员配置细节限制试点转为涉密部署的速度

这些行是国防网络供应商可能遇到的合规门槛;公开状态为空是尽调缺口,不 证明控制项不存在。

[CU026, CU027, CU028, CU029, CU030, CU031]
FU003: 客户触达与合规流程

涉密网络工具放量前,GTM 流程要同时推进买方、合同和安全三条线。

流程是由公开 DoD 机制推导出的采购模型。

[CU018, CU020, CU023, CU026, CU029, CU030]

6.4 创始人准入优势与旋转门批评

Cathedral 不寻常的进入市场优势,也是最明显的反向尽调角度。Reuters 报道称,创始团队与 Trump 政府和国家安全官员关系深,包括五角大楼;这些关系可能降低找到任务所有者的成本。在国防科技里,这种准入有价值,因为早期最难的一步往往是让真实赞助方定义一个紧迫且有资金的问题。同一组事实也制造旋转门和利益冲突风险:批评性报道已经把前 DOGE 人员转入军事技术框定为争议,Reuters 警告称,如果政治控制权变化,政府合同审查可能加剧。尽调问题不只是 Cathedral 能否拿到会面,而是这些会面能否经受伦理审查、合同办公室审视、抗议、国会监督和政府换届。[CU003, CU007, CU041, CU042, CU043]

留存、扩张和集中度尽调表
指标 / 风险公开值含义投资人尽调路径
客户数量缺少衡量采用、留存或集中度的分母要求按密级拆分活跃客户、试点和已获资金合同
NRR / GRR / 流失率公开数据不足以承销持续性要求提供队列留存、续约率和试点流失原因
头部客户集中度单个涉密赞助方可能主导早期收入要求按客户和项目提供收入集中度
先落地后扩张路径原型 → OTA → 正式采办项目扩张有可能,但要看合规和任务验证能否跑通要求提供已获资金里程碑和转入正式项目的赞助方
旋转门审查重大不利风险政府关系可能加速销售,也可能引发监督反噬审查伦理意见、回避安排、冷静期规则和沟通日志

本表刻意保留 null 客户指标,不编造早期牵引力。

[CU037, CU038, CU040, CU041, CU042, CU043]

6.5 可比公司的采用经验

Anduril、Palantir 和 Shield AI 展示了 Cathedral 最终必须证明什么。Shield AI 在美国空军交易后估值跃升,说明任务验证可以打开私募融资;但它也说明投资人要看的证明点,是点名军种关系。Anduril 的 $5 billion Series H 和制造扩张,展示国防买方在公司越过演示阶段后会奖励的资本规模和生产可信度。Palantir 是耐久性基准:其 Form 10-K 描述 Gotham 服务国防和情报用户超过十年,并披露 2024 年政府收入超过 $1 billion。Cathedral 还没有任何这类客户证明。因此,近期客户故事是高准入管线论,而不是已验证采用论。[CU032, CU033, CU034, CU035, CU036, CU037]

可比公司采用路径表
可比对象早期 DoD 客户证明采用如何放大给 Cathedral 的启示类比局限
Shield AI据报道,美国空军交易早于 $12.7B 估值面向任务的自主飞机验证拉动大额融资具名军种交易能重估一家国防 AI 初创公司自主飞机不是网络行动
Anduril公开报道显示其大规模融资和国防制造扩张规模化硬件 / 软件项目和设施强化了可信度DoD 采用往往需要生产能力,不只是推介渠道Anduril 运营历史更长
Palantir10-K 称 Gotham 服务国防和情报用户已超过十年长期嵌入之后,2024 年政府收入超过 $1B深度政府软件账户可以变得持久且庞大Palantir 的路径花了多年
UK MOD AI 合作英国官方来源显示,盟友国防部正在寻求战略性 AI 现代化盟友 AI 现代化打开后续扩张面美国验证之后,向 Five Eyes 扩张具备可能性没有 Cathedral 盟友客户证据

可比对象展示采用模式和证明门槛;没有一项能证明 Cathedral 已赢得客户。

[CU032, CU033, CU034, CU035, CU017, CU020]

6.6 图表

Chapter 07

07风险

7.1 政治、声誉与伦理风险

Cathedral 风险最高的问题,不只是创始人认识政府,而是公司的公开身份围绕 DOGE 到国防这条管线建立。Reuters、Vanity Fair、WIRED、AP、CREW 和 GovExec 共同构成一份反向记录,投资人不能把它当噪音:DOGE 校友曾担任敏感角色、访问政府系统、成为政治焦点,然后进入风险资本支持、可能再卖回同一政府的业务。这同时提出三个尽调问题。第一,是否有创始人获得过非公开的涉密或采购敏感需求知识,从而形成不公平竞争优势?第二,在 DOGE 任职后这么快授予合同,合同官和伦理官员是否会接受?第三,2028 年后的政府或民主党国会是否会把 Cathedral 变成 DOGE 相关监督的测试案例?缓释手段很窄:独立伦理审查、回避、冷却期合规、洁净室式产品需求,以及投标前的董事会级文件记录。[CR006, CR007, CR009, CR010, CR013, CR014]

总体风险登记表
风险类别可能性影响证据缓释措施剩余暴露
DOGE 旋转门审查政治 / 声誉负面报道把 Cathedral 与向国防体系销售的 DOGE 前成员联系起来独立伦理审查、洁净室要求、回避安排首批非政治性授标可见前仍为高
内部知识 / 冲突质疑法律 / 采购中高前美国国防部和联邦机构职务与目标买方需求重叠OCI 法律备忘录、投标防火墙、采购诚信培训
2028 年后政府换届政治 / 预算Reuters 和 Vanity Fair 点出政权更替带来的审查风险靠正常承包渠道赢单,并分散赞助方中高
创始人行为和 Marko Elez 争议关键人 / 声誉中高AP 和 Reuters 报道,其因种族主义帖子辞职,并获得再雇支持创始人行为准则、董事会监督、接班选项中高
AI 攻击性网络行动升级伦理 / 法律Lawfare 和 CSIS 点出责任、范围、威慑和升级顾虑交战规则、法律审查、人工授权关口
出口管制限制扩张监管ITAR、EAR 和 Wassenaar 可能约束技术数据或工具转移分类矩阵、许可路线图、具备资质的法律顾问中高
未披露收入或合同商业公开报道披露融资,但未披露收入、客户或授标估值上调前,要求看到已签授标和已获资金试点
美国政府单一买方集中商业 / 依赖使命是拿下美国政府网络安全合同出口审查通过后,才看多机构管线和盟友市场路径

可能性和影响由分析师基于引用的负面报道、法律来源和采购语境打分;这些值是定性判断,不是精算结果。

[CR006, CR007, CR008, CR009, CR010, CR020]
FR001: 风险热力图

Cathedral 的残余风险集中在政治审视、商业证据、单一买方集中和进攻性网络监管。

定性评分只使用公开证据;没有可用的内部风险登记册。

[CR006, CR007, CR020, CR028, CR035, CR039]

7.2 创始人与关键人风险

对一家按独角兽定价的公司而言,Cathedral 的关键人风险异常高,因为投资逻辑离不开四位年轻创始人的准入、可信度和执行力。公开报道确认 Gavin Kliger、Luke Farritor、Marko Elez 和 Jack Stein 是前 DOGE 工作人员,但没有显示成熟管理班底、收入负责人、项目管理负责人、持证合同负责人,或交付涉密网络项目的公开记录。Kliger 靠近五角大楼 AI 可能帮助产品发现,但也集中政治和伦理暴露。Elez 还带来单独的声誉尾部风险:AP 报道称,种族主义帖文与他相关后他辞职,随后 Musk、Vance 和 Trump 支持他回归。在信任、安全许可判断和国会观感都重要的国防采购中,这场争议可能成为合同尽调问题,而不只是 HR 脚注。缓释需要可信运营班底、独立安全领导、创始人行为契约和继任计划。[CR002, CR011, CR020, CR021, CR022, CR023]

关键人与创始人风险表
人物 / 角色已知公开信号风险可能性影响缓释措施 / 尽调要求
Gavin Kliger / CEO报道称其曾任美国国防部首席数据官,职责贴近 AI 与 Anthropic 事项内部知识观感和买方集中中高审查冷静期合规、OCI 备忘录和沟通日志
Luke Farritor / 创始人报道称其曾在 DOGE 任职、曾是 SpaceX 实习生;WIRED 将其列入年轻工程师群体高级政府运营履历偏薄中高评估项目管理梯队和具备资质的承包负责人
Marko Elez / 创始人AP 和 Reuters 报道种族主义帖子争议、辞职及再雇支持声誉、判断力、安保审查和合同抗议风险董事会行为约定、安全审查和客户可接受性检查
Jack Stein / 创始人报道称其为前 DOGE 人员兼联合创始人,公开运营细节有限创始人集中和独立履历有限要求说明角色范围、过往交付证据和接班计划
四名创始人团队投资逻辑围绕政府入口和近期政府背景展开执行与关系集中聘请有经验的国防业务 GM、CISO、GC、获标负责人和项目经理

本表把报道中的创始人事实与尽调结论分开;公开证据还未显示出深厚的高管梯队。

[CR002, CR011, CR020, CR021, CR025, CR026]
FR002: 各风险残余严重度评分

商业证据和政治审视得分最高,因为二者都可能单独拖累融资和采购。

分数是 1–10 的序数型尽调严重度值,不是概率。

[CR001, CR005, CR008, CR013, CR020, CR028]

7.3 进攻性网络行动的伦理与升级风险

Cathedral 披露的使命——用 AI 支撑进攻和防御性的军事网络行动——落在一个敏感领域:私营承包商即便不像常规武器项目那样透明, 也可能制造国家层面的效果。Lawfare 的框架直接切中要害:私营公司参与进攻性网络活动前,政策制定者必须先界定目标、可做动作、目标范围、法律授权、 责任,以及对无辜第三方损害的归责。Atlantic Council 进一步指出,进攻性网络供应链不透明、碎片化且具战略敏感性; 当零日漏洞、AI 驱动的漏洞发现和对华竞争交叠时尤其如此。CSIS 还警告,低于门槛的网络活动可能绕开威慑逻辑; 关于自主性政策的评论也显示,即便 DOD 内部人士也可能误解人类控制和网络豁免的边界。Cathedral 只有靠严格的交战规则、审计日志、法律审查、 人类授权边界、漏洞权益治理,以及独立于增长激励的红队监督,才能缓释风险。[CR003, CR028, CR029, CR030, CR031, CR032]

FR003: 风险传导流程

政治、法律、网络伦理和商业风险,会传导到授标节奏、估值信心和买方信任。

流程是基于公开证据的因果综合,不是实测流程图。

[CR009, CR010, CR013, CR020, CR028, CR029]

7.4 监管、出口管制与核验风险

监管风险远不止普通网络安全合规。若 Cathedral 为美国军事网络任务打造工具、服务、模型或运营支持,法律顾问必须先梳理 ITAR、EAR、 Wassenaar、采购诚信、离职后限制和涉密合同约束,再让公司在海外招聘、共享技术数据、与数据中心合作、向盟友销售,或接受非美国战略投资者。 一旦网络能力构成防务物项、防务服务、受控技术数据、先进计算物项或军民两用受控技术,ITAR 和 EAR 分析就不是可选项。 核验风险同样关键:保护国家安全工作的保密性,也会阻止外部投资者独立验证合同范围、运营表现、法律授权和客户验收。 干净的尽调流程因此需要安全数据室、法律顾问备忘录、出口管制分类矩阵、设施许可路线图、签约历史证据, 以及让投资者借助具备涉密资质的法律顾问核验涉密主张的协议,而不是依赖媒体叙事。[CR013, CR014, CR015, CR016, CR017, CR034]

监管 / 法律风险登记表
规则 / 议题管辖范围状态可能性严重性剩余暴露尽调路径
离职后限制美国 / 前联邦官员现行规则若创始人在限制窗口内与原任机构沟通,风险为高法律顾问备忘录,列明受约束职位、接触对象和一年冷静期义务
组织性利益冲突联邦采购现行 FAR 制度中高若过往非公开需求影响投标,风险为高独立 OCI 审查和洁净室产品需求流程
采购诚信联邦采购现行 FAR 制度涉及任何来源选择或投标信息时为中高培训、认证和投标团队防火墙
利用公职谋取私利联邦伦理现行伦理制度中高若 DOGE 关联驱动客户或投资人说法,风险为中营销审查,并禁止暗示官方背书
DOGE 透明度 / FOIA 审查联邦监督监督机构调查进行中中高若记录显示控制薄弱,声誉风险为高跟踪 CREW、GAO、IG 和国会请求
美国财政部 / 敏感系统访问后续影响联邦监督和法院已成历史,但政治上仍敏感中高Elez 与 DOGE 前成员叙事下风险为高评估安全调查发现、安保审查影响和客户异议

本表不是法律意见;任何投标前,法律顾问和合同官都需要验证所列制度。

[CR013, CR014, CR015, CR016, CR017, CR018]
监管和出口管制表
管制领域Cathedral 为何可能触发可能性影响缓释措施待核实事项
ITAR / USML军事网络工具或国防服务可能涉及受控国防物项、服务或技术数据正式商品管辖 / 分类分析哪些组件属于国防物项或国防服务?
EAR / 高级计算AI 模型、算力、软件或技术数据转移可能落入美国商务部管制ECCN 审查、视同出口控制、许可筛查哪些模型权重、漏洞利用工具或算力访问受出口管制?
Wassenaar 两用管制两用网络和入侵相关技术可能面临多边管制预期中高按国家拆分的管制矩阵哪些盟友部署在法律上可行?
涉密承包国家安全网络工作可能涉密,投资人难以核验具备资质的法律顾问和安全数据室流程没有公开披露时,投资人能否验证授标和履约?
数据中心 / 算力合作专用算力会带来设施、出口、安全和依赖约束中高安全审查、供应链审查、合同审计权谁控制算力、日志、模型隔离和事件响应?

各行是从公开使命报道和出口管制主管机关推导出的尽调假设,并非认定某个具体项目受管制。

[CR003, CR034, CR035, CR036, CR037, CR038]

7.5 商业、集中度与采购风险

商业上,Cathedral 的风险画像更像一个尚无收入的政府市场期权,却按已验证的防务科技平台定价。Reuters 及后续报道可以坐实融资、 使命、投资人和创始人的政府通道,但本报告审阅的公开记录尚未坐实收入、已签合同、生产环境用户、续约行为或任务结果。 买方范围也高度集中:Cathedral 明确追逐美国政府合同,而出口管制和涉密工作限制它快速走向国际多元化。 即便 Pentagon 希望更快采用商业技术,采购仍然偏向已有合同载体、过往业绩、涉密资质员工、项目经理和机构关系的既有承包商。 Booz Allen、Leidos、Palantir、Anduril,以及 Washington Technology 的政府承包商排名,都说明这种竞争不对称。 Cathedral 的缓释项只有在有证据时才成立:已签试点、有资金支持的授标、合同载体、安全授权、可背书的项目赞助方, 以及能经受领导层更替的非政治性采购胜利。[CR001, CR004, CR005, CR008, CR039, CR040]

缓释措施和否决标准表
风险可监测触发项阈值 / 事件行动含义
政治 / DOGE 审查国会、GAO、IG 或 FOIA 活动点名 Cathedral 或某位创始人正式调查、传票、授标暂停,或合同官作出负面认定暂停估值上调,并要求法律整改计划
利益冲突质疑竞争者抗议或机构伦理审查质疑其接触非公开信息任何成立的 OCI 或采购诚信认定投标重组前,视为打破投资逻辑
创始人行为风险客户安全办公室或安保审查流程对 Elez 或其他创始人提出担忧安保许可被拒、赞助方反对,或董事会调查投资前要求调整角色或治理补救
攻击性网络行动监督失效产品路线图缺少法律授权、日志、人工授权或目标范围控制没有成文 ROE 或客户授权链阻止以部署为前提的收入承销
出口管制障碍法律顾问无法判定工具 / 数据分类,或无法拿出计划中海外工作的许可路径非美国转移前没有可用 ITAR/EAR 矩阵假设 TAM 仅限美国,并下调上行情景
商业证明缺口到下一融资里程碑仍没有已签、已获资金的政府授标或可背书试点只有媒体 / 投资人叙事支撑牵引力没有大幅折价,不要按 $1.4B+ 估值承销
替代在位厂商失败管线输给主承包商,或拿不到合同工具入口没有可信的合同工具、赞助方或集成路径改按并购 / 合作标的看待,而非独立平台
单一买方集中若有收入,也依赖单一办公室、单届政府或单个涉密项目头部客户或赞助方实际控制公司生存要求多项目管线和预算科目可见性

否决标准把宽泛风险转成投资委员会或后续更新可观察的尽调触发项。

[CR005, CR007, CR010, CR013, CR020, CR028]

7.6 附录

Chapter 08

08估值

8.1 估值与建议

Cathedral 的估值章节从两点开始:融资轮次计算异常干净,运营证据异常薄弱。已报道的 $160 million 融资、$1.4 billion 投后估值, 意味着约 $1.24 billion 投前估值和约 11.4% 的主融资稀释。对于一家 2025 年左右创立、未披露收入、 ARR 或合同胜利的公司,这是极高价格。分母缺失,无法计算收入倍数或 ARR 倍数;用零会误导,因此正确字段是 null。 投资立场因此是继续研究,信心低、风险高,估值立场偏贵。这个估值可由创始人与 DOGE 关联的政府通道、顶级投资人背书和防务科技市场热度解释, 但公开证据尚不足以支持由基本面兜底的买入建议。[CV001, CV002, CV003, CV004, CV005, CV006]

估值摘要表
指标解读证据状态
新增融资$160 million约 2025 年创立的公司拿到大型机构轮融资多家新闻来源报道
投后估值$1.4 billion创立初期估值异常高多家新闻来源报道
隐含投前估值$1.24 billion$1.4B 投后估值减去 $160M 新资金根据报道轮次条款计算
隐含出售股权11.4%$160M 除以 $1.4B 投后估值根据报道轮次条款计算
已披露收入没有公开收入或 ARR,因此无法计算收入倍数证据缺口 / 负面发现
已披露合同已检索来源未引用公开政府合同中标记录证据缺口 / 负面发现
估值立场偏贵价格反映团队、入口和市场热度,多过基本面分析师结论
建议继续研究合同和产品证据追上估值前,不要买入分析师结论

null 单元格表示公开证据不可得,不代表零收入或零合同。

[CV001, CV002, CV003, CV004, CV005, CV034]

8.2 可比公司与倍数

可比公司组合解释了 Cathedral 为什么既合理又令人警惕。Anduril 和 Shield AI 证明,2026 年的私营防务科技赢家可以拿到很高估值, 但两家公司都比 Cathedral 走得远得多。Anduril 据报 $61 billion 的估值,有公开收入规模和可见产品足迹支撑; Shield AI 的 2026 年轮次则绑定自主飞行器和空军相关进展。Palantir 的阶段可比性更低,但可作为公开市场上限, 因为其高倍数背后有 SEC 文件、收入披露和政府业务增长。Rebellion Defense 是私营软件参照,不是估值锚, 因为抓取来源没有给出干净的当前倍数。相对于种子轮和 Series A 基准,Cathedral 的创始期估值仍是极端离群点。[CV011, CV012, CV013, CV014, CV015, CV016]

可比估值表
可比对象估值 / 状态收入或合同证明隐含收入倍数与 Cathedral 的相关性关键限制
Cathedral$1.4B 投后;$1.24B 投前未披露收入;未披露合同直接标的与当前估值锚点无法计算倍数
Anduril2026 年 $5B Series H 后估值 $61B2025 年收入据称约 $2.2B~27.7x 往绩收入说明国防科技赢家能拿到近似软件公司的估值成熟得多,已有收入和产品证明
Shield AI2026 年投后 $12.7B;2025 年此前估值 $5.3B报道将估值与自主飞行器及空军相关进展挂钩说明后期自主国防资产有溢价已获取来源未公开披露收入
Palantir上市公司;按 2026 年市场数据口径,市值约 $300B+SEC 和公司文件披露收入及政府业务增长公开 P/S 可观察;极高的软件估值上限参照政府软件估值天花板参照上市且已有盈利规模;不是创业公司可比样本
Rebellion Defense私有国防软件参照;当前公开估值未披露网站描述其面向关键资产情报的产品定位可作为私有国防软件背景已获取来源没有可比轮次倍数
种子轮基准典型种子轮估值远低于 $1.4B通常尚无收入或收入极早期说明 Cathedral 创立期估值异常高通用基准,并非国防网络安全专项
Series A 轮基准典型 Series A 轮估值远低于投前 $1.24B通常需要试点、LOI 或收入证据说明更靠后的早期可比样本仍低得多通用基准会随赛道和团队变化
国防科技泡沫批评警告资本可能跑在合同和收入前面突出采购节奏和耐心风险对未有收入阶段溢价形成反向校准批评面向整个赛道,并非专指 Cathedral

倍数为近似值;null 表示已获取来源未披露该可比公司或 Cathedral 的收入。

[CV004, CV005, CV011, CV012, CV013, CV015]
FV001: 可比估值条形图

按绝对估值,Cathedral 远低于后期国防赢家;但相较常规创立阶段基准又高出很多。

基准条使用已抓取基准来源中的高端代表区间。

[CV001, CV011, CV015, CV016, CV023, CV024]
FV004: 证据与估值风险象限

与更成熟的国防科技参照相比,Cathedral 落在高估值风险 / 低证据象限。

轴为定性评分:x=公开证据,y=估值风险。

[CV004, CV011, CV014, CV017, CV018, CV019]

8.3 增长消化场景与敏感性

承销一个尚无收入的估值,最干净的方法是反推未来需要多少合同收入,当前价格才会变得普通。按 10x 收入倍数,Cathedral 需要约 $140 million 年收入才能支撑 $1.4 billion;按 5x,需要约 $280 million;即便按激进的 15x,也需要约 $93 million。这划出了 18 至 24 个月的测试窗口。乐观情形要求公司迅速把通道转成付费军事网络项目,并跑出可重复的软件经济性。 基准情形是资金充足地建设产品和试点,但当前估值仍难自圆其说。悲观情形是采购或政治延误迫使公司稀释、降价融资, 或长期停留在仅靠叙事支撑估值的阶段。[CV026, CV027, CV028, CV029, CV030, CV031]

乐观 / 基准 / 悲观情景与敏感性表
情景18-24 个月合同 / 收入假设估值逻辑概率信号下行触发点
乐观将资源入口转成 $100M-$150M+ 年化合同收入,或等值的已获经费项目按 10x-15x 收入倍数,$93M-$140M 收入即可支撑当前估值只有付费政府项目很快落地才说得通24 个月内没有付费试点或项目路径
基准搭起团队和试点,但收入可见度有限在收入按 10x 倍数接近 $140M 之前,当前 $1.4B 仍难解释最符合今天的公开证据试点仍未付费,或采购延期
悲观政治审查或采购拖延挡住实质性合同估值向早期国防基准重定价,或需要大幅稀释泡沫反向证据和缺少牵引力证据支撑该情景融资轮变成没有技术证明的资源入口故事
低倍数长入按 5x 需要约 $280M 收入意味着一家新网络安全公司要爬出很陡的收入曲线没有大型多年期合同则不太可能预算或认证延期
高倍数长入按 15x 需要约 $93M 收入在公开证明前就需要 Palantir / Anduril 式软件溢价只有拿下异常强的战略合同才可能国防科技倍数压缩

区间只是情景承销测算,不是管理层指引;收入仍未披露。

[CV026, CV027, CV028, CV029, CV030, CV031]
FV002: 乐观 / 基准 / 悲观估值区间

当前估值只有在乐观路径下才说得通;基准和悲观情形都指向等待或重定价。

区间是情景启发式估算,锚定成长兑现收入测算和公开可比公司。

[CV026, CV027, CV028, CV029, CV030, CV031]

8.4 溢价拆解与估值风险

估值溢价可拆成四个正项和一个巨大负项。团队溢价真实存在,因为创始人的政府经验可能降低采购摩擦。 投资人信号溢价也真实存在,因为 a16z 和 Sequoia 领投并拿到董事会席位,会改变市场感知。市场溢价由 Anduril、Shield AI、 Palantir 热度,以及 a16z 的 American Dynamism 论点支撑。稀缺性溢价来自可见的 AI 原生军事网络团队数量很少。 抵消项才是最大尽调问题:没有公开产品、收入或合同证据。关于防务科技泡沫的负面评论直接相关,因为它警告风险投资价格可能跑在采购现实前面。 政治审视、未来稀释、数据中心或合规资本开支,以及同更成熟可比公司的比较,是 $1.4 billion 估值失守的主要路径。[CV007, CV008, CV009, CV010, CV032, CV033]

溢价拆解表
组成项对 $1.4B 故事的指示性贡献证据依据投资含义
团队 / 资源入口溢价很高创始人据报道是有政府关系的前 DOGE 员工信号真实,但政治上脆弱
投资人信号溢价a16z 和 Sequoia 领投并取得董事席位验证机会,也可能放大价格
国防 AI 市场溢价Anduril、Shield AI 与赛道融资热说明需求强支撑品类热度
稀缺性溢价具备这种资源入口的 AI 原生军事网络安全创业公司很少公开可见更多团队进入后可能消退
牵引力折价大幅负向没有公开收入、公开合同或产品披露无法给出基本面支撑的买入结论
稀释 / 优先权压力负向大额前置融资后面可能跟着昂贵的基础设施和合规支出入场前必须看后续融资条款

仅作定性拆解;它解释估值标记,但不证明公允价值。

[CV007, CV008, CV009, CV010, CV033, CV039]
正方 / 反方论点表
论点支持证据哪些证据会改变判断
正方:精英团队能撬动政府网络安全需求据报道,创始人为 DOGE 前成员,方向聚焦军事网络安全技术负责人经过验证,交付团队具备涉密能力
正方:投资人在押注真实的国防科技景气Anduril、Shield AI 和 a16z American Dynamism 支撑品类顺风证据显示 Cathedral 拿到差异化项目,而不只是获得关注
正方:网络作战比硬件国防更容易快速扩张软件 / 网络安全方向可能避开部分硬件制造约束可部署产品和认证路径的证明
反方:估值跑在牵引力前面未披露收入、合同或产品页签约付费试点或正式列装项目路径
反方:政治资源入口不是持久护城河DOGE / Trump 关系可能招致审查,也可能随政治风向变化两党客户拉力和职业政府官员背书
反方:国防科技存在泡沫风险反向来源警告资本可能跑在采购现实前面合理入场价,或独立验证的合同储备

反方论点聚焦估值,并不否认国防网络安全需求真实存在。

[CV006, CV007, CV008, CV010, CV032, CV040]
FV003: 溢价构成瀑布图

估值叙事先加上团队、投资人和市场溢价,再扣掉大额业务牵引折价。

瀑布图数值是示意性拆解,不是独立估值。

[CV008, CV009, CV025, CV032, CV041, CV042]

8.5 最终尽调要求与论点破裂触发器

投资委员会不应把 Cathedral 永久视为不可投;它应把当前价格视为尚未被证明。若公司能展示付费政府网络需求、可防守的技术能力、认证路径和软件式经济性, 估值就存在可信的辩护路径。因此,所需尽调材料包很具体:合同管线和投标状态、在允许范围内的客户访谈、产品演示、安全和部署架构、 股权结构中的优先权、数据中心经济性,以及围绕政治关系的伦理控制。若 18 至 24 个月内没有付费试点或政府合同路径浮现, 若业务主要依赖政治通道,或若未来轮次显示前期估值造成了清算优先权悬垂,投资论点就会破裂。在这些检查通过前,正确结论是继续研究,而不是买入。[CV034, CV035, CV036, CV037, CV038, CV039]

最终尽调问题与论点破裂触发点
尽调议题缺失证据重要性推翻论点的阈值
合同管线具名机构、投标阶段、付费试点、中标概率与时间决定 $140M+ 收入是否可能成立18-24 个月内没有可信付费路径
收入模式定价、合同类型、毛利率以及服务 / 软件组合决定公允倍数和现金需求只有定制服务,毛利结构弱
技术证明演示证据、网络能力边界、认证与安全控制把真实能力与资源入口叙事分开没有独立验证的产品能力
股权结构和优先权清算优先权、期权池、按比例认购权和治理条款大额融资轮可能形成优先权压力条款让普通股或后续入场没有吸引力
政治 / 采购风险伦理审查、冲突控制和两党客户背书资源入口在审查下可能变成负债合同看起来依赖政治关系
基础设施计划数据中心合作方、算力成本和涉密部署计划资本需求可能推高稀释算力或合规成本压垮预算

这些问题定义了从继续研究走向可投资的路径;每一项目前都只能靠私有证据回答。

[CV035, CV036, CV038, CV039, CV040, CV043]

8.6 附录

免责声明

本报告仅供参考,基于一家尚处隐身状态的国防公司的有限公开来源,不构成投资建议。

证据索引

结论
编号陈述可信度来源
CO001 Cathedral is a stealth AI-powered military cybersecurity startup focused on U.S. military cyber capabilities. SO001, SO002, SO004, SO006
CO002 Cathedral should be treated as founded in 2025 because Reuters reported in July 2026 that it launched in recent months and the founders came out of 2025 DOGE roles. SO001, SO002, SO013
CO003 Cathedral plans to seek U.S. government contracts for AI-driven military cyber operations. SO001, SO002, SO004, SO006
CO004 Cathedral’s described mission includes both offensive and defensive cyber capabilities against U.S. adversaries such as China. SO001, SO002, SO004, SO006
CO005 Cathedral is exploring acquiring a data center or partnering with a data-center provider for dedicated compute power. SO001, SO002, SO004
CO006 The public founder set consists of Gavin Kliger, Luke Farritor, Marko Elez, and Jack Stein, all former DOGE staffers. SO001, SO002, SO004, SO006
CO007 Gavin Kliger was reported as a Cathedral cofounder and former Pentagon chief data officer. SO001, SO004, SO006
CO008 Luke Farritor was reported as a Cathedral cofounder, former SpaceX intern, and DOGE operator involved in GSA cost cutting. SO001, SO004, SO006
CO009 Marko Elez was reported as a Cathedral cofounder who previously worked at SpaceX and DOGE/Treasury. SO001, SO004, SO006, SO014
CO010 Jack Stein was reported as a Cathedral cofounder and former DOGE staffer. SO001, SO002, SO006
CO011 Cathedral closed a $160 million funding round in the weeks before the July 22, 2026 Reuters report. SO001, SO002, SO004, SO005
CO012 Cathedral’s 2026 financing valued the company at a $1.4 billion post-money valuation. SO001, SO002, SO004, SO005, SO006
CO013 Andreessen Horowitz and Sequoia Capital led Cathedral’s funding round. SO001, SO002, SO004
CO014 Andreessen Horowitz and Sequoia Capital both took board seats in connection with the round. SO001, SO002, SO004
CO015 No Cathedral revenue, ARR, or revenue run rate was disclosed in the reviewed public sources. SO001, SO002, SO004, SO006
CO016 No Cathedral customer count, named customer, government contract, or pilot was disclosed in the reviewed public sources. SO001, SO002, SO004, SO006
CO017 No Cathedral headcount number was disclosed in the reviewed public sources. SO001, SO002, SO004, SO006
CO018 No official Cathedral website, newsroom announcement, or product documentation was found in the reviewed source pack. SO001, SO002, SO024, SO026
CO019 Reuters reported that Cathedral’s valuation, name, mission, and Elez’s involvement had not previously been reported. SO001, SO002
CO020 A Cathedral spokesperson declined to comment, and Andreessen Horowitz and Sequoia did not respond to Reuters requests for comment. SO001
CO021 Kliger was reported as involved in the Pentagon’s highly publicized legal fight with Anthropic over military use of Claude. SO001, SO019, SO020, SO021, SO023
CO022 The Anthropic-Pentagon dispute created a live AI military-governance backdrop for Cathedral’s founding team. SO001, SO019, SO020, SO021, SO022, SO023
CO023 Elez’s prior Treasury access raised security-control concerns, including GAO-reported control gaps around DOGE system access. SO001, SO014
CO024 Elez quit DOGE after racist social-media posts were reported and was later rehired after Trump and Vice President JD Vance advocated reinstatement. SO001, SO005
CO025 Reuters framed Cathedral as exposed to scrutiny over government contracts if political control changes after the 2026 midterm elections. SO001, SO005
CO026 DOGE was established by White House executive order in January 2025. SO013, SO012
CO027 DOGE officially ended on July 4, 2026 according to independent reporting. SO017, SO018
CO028 Reuters reported that DOGE cost-cutting operations were associated with more than 250,000 people leaving the federal workforce. SO001, SO015, SO016
CO029 Andreessen Horowitz also backed Special, another DOGE-alumni startup pursuing private-sector cost-cutting. SO001, SO010, SO011
CO030 The Atlantic’s coverage of Special was skeptical of DOGE alumni entering complex industries with scant qualifications. SO011, SO010
CO031 Andreessen Horowitz’s American Dynamism practice publicly focuses on companies serving national-interest markets. SO024, SO025
CO032 Sequoia’s official materials show continued AI ecosystem engagement through its AI Ascent programming and company portfolio. SO026, SO027
CO033 Anduril raised a $5 billion Series H at a $61 billion valuation in 2026, giving a defense-technology valuation benchmark. SO008, SO009
CO034 The White House launched Gold Eagle in July 2026 as an AI-enabled cybersecurity vulnerability coordination clearinghouse. SO007, SO028, SO030
CO035 Gold Eagle coverage described a public-private mechanism for faster vulnerability detection, prioritization, and patching. SO007, SO028, SO030, SO031
CO036 Dark Reading argued that Gold Eagle targets a real vulnerability-coordination gap but left implementation details unclear. SO029, SO030
CO037 Cathedral’s governance disclosure is limited to four named founders and two investor board-seat holders, not a complete board or control-rights package. SO001, SO002, SO004, SO024, SO026
CO038 The founder roster creates key-person dependence because public evidence centers government access, Pentagon ties, and DOGE backgrounds rather than a broader operating bench. SO001, SO004, SO014, SO019
CO039 The data-center plan would add infrastructure execution and capital-intensity risk to a software-like cyber startup story if pursued directly. SO001, SO002, SO004, SO008
CO040 Cathedral’s stage is best described as stealth/private-undisclosed despite a mega-round because product, customer, revenue, and headcount details remain unavailable. SO001, SO002, SO004, SO006
CO041 The round gives Cathedral at least $160 million of disclosed total funding because no earlier financing was found in the reviewed public record. SO001, SO002, SO004
CO042 Cathedral’s investor map combines lead investors, founder-control risk, prospective U.S. government customers, and infrastructure partners because those are the stakeholder dependencies visible in public evidence. SO001, SO002, SO024, SO026
CO043 Gizmodo and Hoodline covered the Cathedral round with a skeptical tone around DOGE alumni monetizing controversial government roles. SO004, SO005
CO044 Cyber Daily corroborated that Cathedral intends to bolster U.S. military cyber defense and operations through AI. SO006, SO001, SO002
CO045 The Reuters-origin page itself was not accessible as readable text during the fetch and was recorded as JavaScript-blocked. SO003, SO001
CM001 Cathedral’s relevant market is AI-enabled cyber tooling and services for U.S. military and national-security operators, not all enterprise cybersecurity or physical defense hardware. SM002, SM003, SM004
CM002 Cyber Command and the NSA represent distinct operational and collaboration nodes in the U.S. military cyber ecosystem. SM003, SM004
CM003 The U.S. federal cyber budget context is at least approximately $26 billion annually in the 2026 planning frame, but that top-down number includes spend outside Cathedral’s core wedge. SM001, SM020, SM021
CM004 DoD budget materials are the primary public anchor for defense-wide cyber and IT spend, but they do not isolate every classified offensive cyber line item. SM002
CM005 U.S. Cyber Command’s mission language makes in-house military cyber capability a direct status-quo substitute for startup software. SM003
CM006 NSA’s Cybersecurity Collaboration Center shows that government-industry cyber collaboration is part of the operating model for national-security cyber work. SM004
CM007 CISA frames federal cybersecurity as a national risk-management function, making civilian-agency cyber spend adjacent but not core to Cathedral’s military wedge. SM020, SM021
CM008 GAO keeps federal information security and cybersecurity on its high-risk agenda, which supports demand but also signals implementation difficulty. SM005, SM006
CM009 CRS procurement reporting reinforces that public contract data is a partial view of how DoD spends and reports contracting dollars. SM007
CM010 DARPA’s AI Cyber Challenge is official evidence that automated AI vulnerability discovery and remediation is a current U.S. government priority. SM008
CM011 Defense SBIR/STTR and SBIR.gov describe a public entry route for small businesses seeking defense R&D funding. SM009, SM026
CM012 DIU’s solution and work-with-us pages show a commercial-solutions channel intended to pull private-sector technology into DoD missions. SM024, SM025
CM013 FAR Part 16 documents the contract-type machinery that later-stage defense software vendors must eventually fit. SM019
CM014 DAU and GAO materials show that Other Transactions are a relevant DoD acquisition instrument but also carry planning and governance risks. SM031, SM032
CM015 USAspending.gov, SAM.gov, and DoD contract releases are useful public award windows but are insufficient to reveal classified cyber programs. SM016, SM017, SM018
CM016 MarketsandMarkets estimates the artificial intelligence in military market at $9.2 billion in 2023 and $38.8 billion by 2028, a 33.3% CAGR. SM011
CM017 Grand View Research estimates artificial intelligence in military at $9.31 billion in 2024 and $19.29 billion by 2030, a 13.0% CAGR. SM012
CM018 The difference between the MarketsandMarkets and Grand View military-AI forecasts is large enough to require a range rather than a single TAM point estimate. SM011, SM012
CM019 Mordor Intelligence projects the cyberwarfare market at $40.13 billion in 2026 and $52.27 billion by 2031, a 5.43% CAGR. SM014
CM020 MarketsandMarkets maintains a cyber-warfare market category covering threat intelligence, data protection, vulnerability management, identity, managed security, and resilience solutions. SM013
CM021 Grand View’s broad cybersecurity market estimate is useful context but is too wide to equal Cathedral’s TAM because it includes civilian, consumer, and enterprise spend. SM015, SM021
CM022 American Dynamism materials from a16z show investor interest in companies positioned around the national interest and defense modernization. SM010
CM023 Anduril is the most visible venture-backed defense-tech comparable for Cathedral, but its hardware-heavy autonomy stack is not a direct cyber-software TAM proxy. SM029, SM030
CM024 Canonical run facts place Anduril’s latest comparable financing at $5 billion raised and a $61 billion valuation, underscoring the valuation ceiling investors may reference. SM029, SM030
CM025 Cathedral’s core included spend should be AI cyber tools, vulnerability discovery, mission workflow software, and services sold into DoD or intelligence-community cyber operators. SM003, SM004, SM008
CM026 Broad IT services, general FedRAMP SaaS, consumer cybersecurity, and physical defense hardware should be excluded from the core Cathedral SAM. SM019, SM021, SM030
CM027 Offensive cyber and cyber-weapons spending is likely material but hard to size publicly because operations, authorities, and program lines are sensitive. SM003, SM004, SM014
CM028 The most important status-quo alternatives are internal Cyber Command capability, NSA collaboration, incumbent contractors, and manual penetration-testing workflows. SM003, SM004, SM018, SM021
CM029 Incumbent contractors have an advantage because public awards, FAR contract types, and program-of-record conversion favor vendors that can survive long procurement cycles. SM016, SM018, SM019
CM030 A plausible defense startup path is SBIR or DIU entry, prototype or Other Transaction work, and later conversion into a FAR contract or program of record. SM009, SM024, SM025, SM031, SM019
CM031 Security controls, zero-trust alignment, and NIST-style cybersecurity frameworks are adoption constraints for mission cyber software. SM022, SM023, SM027
CM032 AI risk-management expectations from NIST make autonomous cyber tools a trust and governance sale, not only a capability sale. SM028, SM008
CM033 China and nation-state cyber competition increase urgency for AI-accelerated defensive and offensive cyber operations. SM003, SM004, SM008
CM034 Post-Ukraine cyber priority and the broader move toward software-defined warfare support budget attention, but the public source pack does not isolate a Cathedral-specific spend pool. SM002, SM003, SM015
CM035 A DOGE-style efficiency push would favor automation and smaller teams, but public diligence still needs proof that DoD buyers will trust a stealth startup with classified cyber workflows. SM006, SM008, SM028
CM036 Procurement, authority-to-operate, classified-network deployment, and security-clearance requirements make 18-24 month adoption cycles a reasonable diligence assumption rather than a verified Cathedral fact. SM019, SM022, SM023, SM032
CM037 No public source in this chapter verifies Cathedral revenue, customers, or signed government contracts, so SOM should be framed as zero verified public traction rather than a modeled share.
CM038 The narrowest public SOM proxy available before customer diligence is a pipeline-conversion view from SBIR/DIU opportunities to public awards, not a revenue run-rate. SM009, SM016, SM017, SM024
CM039 The federal buyer map separates budget owners from end users because cyber operators, program offices, and contracting officers can be different organizations. SM003, SM017, SM019
CM040 DoD program offices and service cyber components are likely payers, while Cyber Command, NSA, and mission teams are likely users or technical evaluators. SM002, SM003, SM004, SM018
CM041 CISA and civilian agencies are adjacent buyers for defensive cyber automation, but the canonical Cathedral mission points primarily at military and adversary-facing operations. SM020, SM021, SM003
CM042 Manual red-teaming and penetration testing remain substitutes when buyers are not ready to authorize autonomous AI cyber operations. SM021, SM027, SM028
CM043 The market opportunity is valuation-relevant because defense-tech venture investors have recently rewarded mission-critical national-security platforms even before public revenue disclosure. SM010, SM029, SM030
CM044 The main adverse market view is that broad federal and analyst cyber numbers can dramatically overstate Cathedral’s attainable market while procurement and classification delay conversion. SM005, SM006, SM019, SM032
CM045 The correct diligence next step is to replace top-down TAM estimates with named program offices, authority path, security accreditation status, and contract-stage evidence. SM016, SM017, SM019, SM023
CM046 The matrix view adds a distinct coordination lens because defense cyber adoption depends on the interaction among buyer, user, payer, and contracting authority rather than on segment labels alone. SM017, SM019, SM025
CP001 Cathedral is a stealth AI defense and military cybersecurity startup founded by ex-DOGE staffers Gavin Kliger, Luke Farritor, Marko Elez, and Jack Stein. SP001, SP002, SP003
CP002 Cathedral raised $160 million at a $1.4 billion post-money valuation in July 2026 in a round led by Andreessen Horowitz and Sequoia. SP001, SP002, SP003
CP003 Cathedral’s reported mission is AI-enabled offensive and defensive cyber operations for U.S. military and national-security customers. SP001, SP002
CP004 Reviewed public sources describe Cathedral as planning to secure U.S. government contracts rather than disclosing signed revenue or contracts. SP001, SP003
CP005 Cathedral’s likely initial differentiation is founder access to Pentagon and national-security networks rather than public product proof. SP001, SP003
CP006 Anduril raised a $5 billion Series H at a $61 billion valuation and had reported $2.2 billion of 2025 revenue, making it a much larger defense-tech benchmark than Cathedral. SP004
CP007 Anduril’s Lattice platform is tied to battle-management software and joint missile-defense data analysis in public reporting. SP004
CP008 Palantir’s 10-K identifies Gotham, Foundry, Apollo, and AIP as its four principal platforms and says Gotham has served global defense agencies and the intelligence community for over a decade. SP005
CP009 Palantir generated $2.9 billion of 2024 revenue, with 55% from government customers, giving it a scale and incumbency advantage Cathedral lacks. SP005
CP010 The UK Ministry of Defence announced a strategic partnership with Palantir intended to unlock military AI and innovation, reinforcing Palantir’s allied-defense presence. SP006
CP011 Shield AI’s Hivemind is an AI pilot for autonomous aircraft and has operated alongside U.S. and allied forces. SP007
CP012 Shield AI was reported by TechCrunch to have reached a $12.7 billion valuation in 2026 after a U.S. Air Force-related deal, far above the older $2.8 billion benchmark. SP008, SP009
CP013 Rebellion Defense’s currently reviewed website positions it around an intelligence shield for critical assets, radar, AI fusion, and operational support rather than public evidence of a completed acquisition or shutdown. SP010
CP014 IronNet is an adverse precedent because reporting says the never-profitable cyber startup shut down and fired employees after running out of money. SP011, SP012
CP015 IronNet’s Stretto bankruptcy case page corroborates that IronNet entered formal bankruptcy proceedings in 2023. SP012
CP016 Horizon3.ai’s NodeZero is marketed as an autonomous pentesting platform that finds, fixes, and validates exploitable paths. SP013, SP015
CP017 Horizon3.ai reported more than 5,200 organizations worldwide relying on NodeZero and 125% net dollar retention in 2026. SP013
CP018 Horizon3.ai announced 2026 investment from Prosperity7 Ventures to protect AI datacenters and critical infrastructure. SP014
CP019 XBOW raised $120 million in Series C financing in 2026 and was valued at more than $1 billion, according to Business Wire. SP016
CP020 XBOW and Accenture announced a 2026 partnership to scale continuous AI-driven security testing and exposure management. SP017
CP021 XBOW positions itself as autonomous offensive security, directly overlapping Cathedral’s offensive-cyber part more than most defense-platform companies. SP016, SP017
CP022 Dreadnode builds AI infrastructure for security agents and publishes offensive-security research, making it an AI-native red-team adjacency rather than a traditional services prime. SP018, SP019
CP023 Dreadnode captured $14 million of Series A funding in 2025 for offensive AI security capabilities. SP020
CP024 RunSafe targets memory safety and cyber resilience for critical infrastructure and safety-critical systems, which is more defensive-hardening than Cathedral’s reported offensive-and-defensive mission. SP021, SP022, SP023
CP025 Two Six Technologies states that it supports Department of Defense, U.S. Cyber Command, DARPA, intelligence-community, and civilian-agency customers. SP024
CP026 Two Six’s Sentr positioning emphasizes AI-driven command of the information environment and agentic bridging of legacy systems. SP025
CP027 Booz Allen’s cyber page explicitly frames the problem as cyberattacks moving at AI speed and cyber defense needing to do the same. SP026
CP028 Leidos markets offensive, defensive, and resilience-oriented cyber capabilities across mission environments. SP027
CP029 CACI markets AI/ML-enabled cyber operations, while Peraton, ManTech, Parsons, SAIC, and other incumbents maintain public cybersecurity offerings. SP028, SP029, SP030, SP031, SP032
CP030 The Navy awarded eight companies $1.86 billion in cyberspace operations support contract options, illustrating incumbent access to large multi-year cyber vehicles. SP033
CP031 Washington Technology’s 2026 Top 100 ranking is based on federal spending for IT, systems integration, telecom, professional services, and high-tech needs, making it a useful scale proxy for incumbents. SP034
CP032 GSA’s Alliant 3 Phase 1 awards cover a major federal IT modernization vehicle that includes AI and cybersecurity-relevant contractors. SP035
CP033 An Army cyber-warfare contract dispute involving Booz Allen, Peraton, and ManTech shows that prime contractors already fight over the specific offensive and defensive cyber mission space Cathedral wants. SP036
CP034 Atlantic Council research describes offensive cyber capability markets as relying on intermediaries and opaque supply chains, which complicates Cathedral’s potential offensive-cyber sourcing model. SP037, SP038
CP035 Atlantic Council reported that zero-day exploitation is becoming more difficult, opaque, and expensive, creating feast-or-famine cycles in offensive-cyber contracting. SP038
CP036 Lawfare analysis argues that private-sector involvement in offensive cyber operations creates legal, policy, and escalation risks. SP039
CP037 Cyber Defense Review describes exploit brokers as suppliers whose customers can include government agencies, reinforcing that exploit supply is a specialized market Cathedral may need to navigate. SP040
CP038 Vannevar Labs positions itself around restoring deterrence and reclaiming advantage for national-security users, making it an adjacent defense-AI software competitor. SP041
CP039 The most direct cyber-specific Cathedral substitutes are Horizon3.ai, XBOW, Dreadnode, RunSafe, and exploit-market vendors, because they focus on automated pentesting, offensive security, AI red teaming, hardening, or exploit supply. SP013, SP015, SP016, SP018, SP021, SP038, SP040
CP040 Cathedral’s two-sided offensive-plus-defensive cyber framing is rarer than the one-sided positions of many cyber startups, but public sources do not prove it has product depth yet. SP001, SP013, SP016, SP021
CP041 Incumbents’ durable advantage is distribution through government contract vehicles, security clearances, procurement history, and program relationships rather than necessarily superior AI-native product design. SP024, SP030, SP031, SP032, SP033, SP034, SP035, SP036
CP042 Defense-tech AI startups such as Anduril, Palantir, Shield AI, Rebellion, Vannevar, and Two Six compete with Cathedral mostly for mission budget and AI-defense credibility, not necessarily for the exact same cyber product. SP004, SP005, SP007, SP010, SP024, SP041
CP043 Cyber-specific AI companies have stronger product proof in autonomous testing than Cathedral has publicly disclosed, while Cathedral may have stronger founder access to federal decision makers. SP001, SP013, SP016, SP017, SP018
CP044 The status-quo alternative for defense buyers includes internal government cyber teams, existing prime-contractor task orders, and classified exploit-procurement channels. SP024, SP033, SP036, SP037, SP040
CP045 IronNet’s collapse is a caution that ex-government credibility and cyber branding do not by themselves create durable revenue, margins, or procurement traction. SP011, SP012, SP003
CI001 Cathedral raised $160 million in a July 2026 financing at a reported $1.4 billion post-money valuation. SI001, SI002, SI003, SI004
CI002 Andreessen Horowitz and Sequoia Capital led Cathedral’s $160 million financing, with coverage reporting board-seat involvement. SI002, SI003, SI004
CI003 Cathedral was founded by former DOGE staffers Gavin Kliger, Luke Farritor, Marko Elez, and Jack Stein. SI002, SI003, SI004
CI004 The July 2026 financing is the only publicly disclosed Cathedral financing round in the reviewed source pack, so disclosed total raised is $160 million. SI001, SI002, SI003, SI004
CI005 A $160 million primary round at a $1.4 billion post-money valuation implies roughly 11.4% new-money dilution before any option-pool or secondary adjustments. SI001, SI002, SI003
CI006 The same round implies a roughly $1.24 billion pre-money valuation if the reported $1.4 billion post-money valuation and $160 million primary proceeds are taken at face value. SI001, SI002, SI003
CI007 No reviewed source disclosed Cathedral revenue, ARR, revenue run rate, gross margin, or customer count. SI001, SI002, SI003, SI004
CI008 No reviewed source disclosed a named paying Cathedral contract, OTA, SBIR award, CRADA, or program-of-record sponsor. SI001, SI002, SI003, SI020, SI021, SI022
CI009 Cathedral is reported to be exploring acquiring or partnering with a data center to secure dedicated compute capacity. SI002, SI003, SI004
CI010 Startup Fortune framed Cathedral’s financing as unicorn money for a company with almost no public footprint, no product launch, and no customer announcement. SI002
CI011 The strongest current adverse financial issue is not churn or margin compression but valuation-before-revenue combined with an undisclosed contract pipeline. SI002, SI007, SI020, SI021
CI012 Firm-fixed-price contracts place maximum risk and responsibility for costs and profit or loss on the contractor. SI005, SI006
CI013 Cost-reimbursement contracts provide payment of allowable incurred costs and establish a ceiling the contractor may not exceed without approval. SI005, SI007
CI014 Incentive contracts can tie contractor profit or fee to cost, delivery, or technical-performance outcomes. SI005, SI008
CI015 IDIQ vehicles provide for an indefinite quantity within stated limits and convert into revenue through specific orders that define supplies or services. SI009, SI010
CI016 Best-value negotiated acquisitions can vary the relative importance of cost or price, which makes mission fit and technical evaluation central to sales efficiency. SI011, SI035
CI017 SBIR and STTR programs offer equity-free or non-dilutive funding for small businesses pursuing federal R&D and commercialization. SI012, SI015
CI018 Defense SBIR/STTR describes a staged path from eligibility and proposal through award, Phase II, transition, and commercialization. SI013, SI014
CI019 CRADAs can support R&D collaboration between a federal laboratory and a non-federal entity, but the government may not provide funding to non-federal entities under a CRADA. SI016
CI020 Other Transaction Authority is a flexible DOD pathway used alongside the department’s large annual acquisition base for goods, services, and R&D. SI017, SI018
CI021 DIU presents a commercial-technology pathway in which any commercial entity can respond to solicitations for military adoption. SI018, SI019
CI022 USAspending is the official federal spending source for awards such as contracts, grants, and loans, making it a relevant check for public award evidence. SI020
CI023 SAM.gov contract opportunities and the Defense Department contracts page are relevant public surfaces for future Cathedral solicitations and award notices. SI021, SI022
CI024 Government contracting risk is not only timing risk: GAO has documented DOD procurement-fraud exposure and recommended stronger department-wide risk management. SI036
CI025 Palantir’s 2025 Form 10-K says revenue increased by about $1.6 billion, or 56%, from 2024 to 2025. SI023, SI025
CI026 Palantir reported that revenue from government customers increased by $832.7 million, or 53%, in 2025 and that U.S. government revenue was $1.9 billion. SI023, SI024
CI027 Palantir’s public product materials explicitly position the platform for governments as well as commercial organizations, supporting its use as a government-software comparable. SI026, SI023
CI028 Sacra estimates Anduril generated $2.2 billion of 2025 revenue, up from $1.0 billion in 2024, and projects $4.3 billion of 2026 revenue. SI027
CI029 Sacra reports Anduril closed a $5 billion Series H at a $61 billion valuation and projects an approximately $1.2 billion operating loss in 2026. SI027
CI030 Sacra estimates Shield AI reached about $300 million of revenue for the year ending March 2025 and implies at least $540 million of 2026 revenue from management targets. SI028
CI031 The Los Angeles Times reported Anduril is developing a new $1 billion Long Beach complex that includes offices, labs, and prototype manufacturing facilities. SI029
CI032 GeekWire reported Anduril was quietly building autonomous warships at a Seattle shipyard, reinforcing the physical-facility intensity of scaled defense technology. SI030
CI033 Goldman Sachs estimates AI could drive a 160% increase in data-center power demand, while DOE expects domestic data-center energy usage to double or triple by 2028. SI031, SI032
CI034 Epoch AI estimates frontier-model training compute has grown by roughly 4x to 5x per year, which supports treating dedicated compute as a material burn driver. SI033
CI035 Andreessen Horowitz’s American Dynamism thesis supports startups serving national-interest markets, giving context for a16z’s appetite for defense-oriented companies. SI034
CI036 A reasonable Cathedral base-case runway lens divides the $160 million raise by estimated monthly burn rather than by revenue because no revenue has been disclosed. SI001, SI002, SI031, SI033
CI037 At $4 million of monthly burn, $160 million supports roughly 40 months of runway before financing costs, working capital swings, or data-center capex. SI001, SI002
CI038 At $8 million of monthly burn, $160 million supports roughly 20 months of runway before any large up-front data-center purchase. SI001, SI002, SI031
CI039 At $12 million of monthly burn, $160 million supports roughly 13 months of runway, making contract conversion or a follow-on financing trigger more urgent. SI001, SI002, SI033
CI040 A hypothetical $40 million dedicated-compute or data-center outlay would reduce deployable cash to $120 million and shorten the $8 million-burn runway lens to about 15 months. SI001, SI009, SI031, SI032
CI041 Cathedral’s revenue recognition will likely depend on the future contract vehicle: FFP can defer upside until delivery, cost-reimbursement can lower loss risk but cap margin, and IDIQ orders create revenue only when task orders arrive. SI006, SI007, SI009, SI010
CI042 The path to revenue is likely pilot or prototype funding first, then OTA/SBIR/CRADA validation, then IDIQ or program-of-record ordering if mission owners adopt the product. SI013, SI014, SI016, SI017, SI018, SI019
CI043 High stickiness is plausible only after Cathedral lands in classified workflows or mission systems; before that, stickiness remains a thesis rather than a disclosed financial metric. SI002, SI021, SI026
CI044 Cathedral’s current financial model is pre-revenue from a public-evidence standpoint, so ARR, gross margin, CAC payback, net revenue retention, and recognized revenue should be null rather than estimated as operating metrics. SI001, SI002, SI003, SI004
CI045 The practical next-round trigger is likely one of three events: named government contract conversion, material dedicated-compute capex, or evidence that cyber-AI development burn exceeds the $160 million round’s runway. SI002, SI003, SI031, SI033
CI046 The comparable set shows Cathedral is being valued before the financial proof points that Anduril, Shield AI, and Palantir use to support later-stage defense-tech valuations. SI002, SI023, SI027, SI028
CE001 Cathedral is publicly described as a stealth AI-powered military cybersecurity startup seeking U.S. government contracts. SE001, SE002, SE003, SE004
CE002 The only public product definition is AI-driven cyber operations; no public source reviewed disclosed Cathedral SKU names, architecture diagrams, benchmarks, or product documentation. SE001, SE002, SE003, SE004
CE003 Cathedral’s public offensive scope maps most plausibly to AI-assisted reconnaissance, vulnerability discovery, exploit generation, validation, and operator-approved mission packaging. SE001, SE002, SE023, SE035, SE036
CE004 Cathedral’s public defensive scope maps most plausibly to AI-assisted threat detection, vulnerability prioritization, triage, remediation planning, and incident-response automation. SE001, SE005, SE006, SE021, SE022
CE005 Public reporting names Gavin Kliger, Luke Farritor, Marko Elez, and Jack Stein as Cathedral founders and former DOGE staffers. SE001, SE002, SE004
CE006 Kliger’s reported Pentagon chief data officer role and involvement in the Anthropic/Pentagon AI dispute are directly relevant to Cathedral’s model-governance and military-buyer context. SE002, SE019, SE032
CE007 Cathedral is reported to be exploring acquiring or partnering with a data-center provider for dedicated compute for classified work. SE001, SE002, SE003, SE004
CE008 A dedicated compute strategy is technically coherent for offensive military AI because classified data, exploit chains, telemetry, and model weights may need isolation from ordinary commercial SaaS environments. SE019, SE026, SE028, SE031, SE033
CE009 Gold Eagle is a relevant federal analogue because it coordinates AI-assisted vulnerability intake, prioritization, and remediation across government and critical infrastructure. SE005, SE006, SE007
CE010 DARPA’s AI Cyber Challenge asks competitors to design novel AI systems that secure critical software. SE008, SE009
CE011 AIxCC demonstrated autonomous AI cyber reasoning systems that found and repaired synthetic open-source vulnerabilities at competition scale. SE008, SE009, SE010
CE012 The AIxCC Finals GitHub organization exposes OSS-Fuzz-related repositories, providing a developer-signal analogue for autonomous vulnerability-reasoning infrastructure. SE010
CE013 XBOW’s public validation-benchmarks repository is a developer-signal analogue for autonomous offensive-security benchmarking, but its own warning says the benchmarks were saturated by mid-2026. SE011
CE014 Horizon3.ai NodeZero is a commercial analogue for autonomous penetration testing because it runs self-directed pentests, identifies exploitable paths, guides remediation, and verifies fixes. SE012, SE013
CE015 Dreadnode is a commercial analogue for building, evaluating, and deploying offensive security agents. SE014, SE015
CE016 HackerOne’s benchmark write-up is an adverse reliability analogue because it says agentic AI can scale offensive operations but cannot yet replace human penetration testers alone. SE016
CE017 HackerOne states that frontier models are compressing the historical gap between vulnerability discovery and exploitation. SE017
CE018 HackerOne’s red-team guidance warns that AI red teaming remains primarily human-driven and should not be confused with fully automated red-team operations. SE018
CE019 Anthropic says Claude Gov models are deployed for U.S. national-security customers at classified levels, showing that frontier-model vendors can package models for restricted government environments. SE019
CE020 Anthropic’s Claude 4 cyber evaluation reports improvements in vulnerability identification and multi-step attack chains while emphasizing remaining limitations. SE020
CE021 Anthropic’s cyber-defender work explicitly avoided enhancements that clearly favor advanced exploitation or malware, underscoring the safety boundary Cathedral would have to govern differently for offensive missions. SE021
CE022 OpenAI reported disrupting malicious state-affiliated uses of AI for cyber research, scripting, and phishing content, which shows both defensive monitoring practices and adversarial misuse patterns. SE022
CE023 Google Project Zero’s Project Naptime frames LLM offensive-security evaluation as dual-use because AI may help defenders find vulnerabilities while also helping attackers develop offensive capabilities. SE023
CE024 Google’s AI-powered fuzzing work is a concrete analogue for using AI to expand bug-finding workflows before production deployment. SE024
CE025 Palantir AIP is an operating-model analogue for embedding AI into mission workflows rather than shipping a stand-alone chat product. SE025
CE026 FedRAMP is a necessary cloud-authorization reference point if Cathedral delivers any cloud service to U.S. government customers. SE026
CE027 NIST’s AI RMF and 2026 critical-infrastructure profile are relevant controls references for AI-enabled cyber systems operating in high-consequence environments. SE027
CE028 NIST SP 800-53 Rev. 5 is a baseline control catalog Cathedral would likely map to during federal security authorization. SE028
CE029 NIAP/Common Criteria could become relevant if Cathedral ships evaluated endpoint, enclave, or security appliance components into controlled government environments. SE029
CE030 CMMC is relevant because defense contractors handling controlled unclassified information must meet DoD cyber-assurance expectations. SE030
CE031 NIST RMF provides the process backbone for ATO work by integrating security, privacy, and cyber supply-chain risk into the system life cycle. SE031
CE032 DefenseScoop reported that the Pentagon’s JWCC follow-on seeks AI and machine-learning capabilities across classification and impact levels including DDIL environments. SE033
CE033 DefenseScoop’s tactical data-center coverage shows DoD buyers already value cloud-grade compute, storage, and AI capability in remote or connectivity-degraded environments. SE034
CE034 The LLM-agent zero-day paper is an adverse benchmark because it reports that agents still perform poorly on real-world vulnerabilities unknown to the agent ahead of time. SE035
CE035 Cybench frames autonomous vulnerability discovery and exploit execution as capable of real-world impact and therefore requiring measurement and risk controls. SE036
CE036 Cathedral’s actual product maturity is undisclosed; the defensible outside label is stealth prototype-to-early-platform rather than production-proven system. SE001, SE002, SE003, SE004
CE037 Public evidence supports treating vulnerability discovery as a plausible Cathedral module but not as a verified production capability. SE001, SE009, SE020, SE023, SE035
CE038 Exploit-generation and C2-adjacent automation are the highest-risk inferred modules because hallucinated exploit logic, legal boundaries, and operator authorization errors can create mission and safety failures. SE016, SE018, SE020, SE023, SE035, SE036
CE039 Defensive triage and remediation assistance appear nearer-term than fully autonomous offensive action because public analogues emphasize vulnerability intake, code review, fuzzing, and human-guided validation. SE005, SE006, SE021, SE024, SE031
CE040 Any Cathedral deployment into NIPR, SIPR, JWICS, or mission enclaves would likely require RMF/ATO mapping plus cloud, identity, logging, and data-boundary controls before operational use. SE026, SE028, SE031, SE032, SE033
CE041 Building or operating in classified national-security environments implies cleared personnel, restricted model access, enclave-aware telemetry handling, and classified evaluation data. SE019, SE031, SE033
CE042 The compliance surface likely spans FedRAMP or equivalent cloud authorization, DoD impact-level assessment, RMF/ATO packages, CMMC for contractor data, and possibly NIAP for evaluated components. SE026, SE028, SE029, SE030, SE031, SE033
CE043 Model reliability is a material risk because leading public evidence emphasizes evaluation limits, benchmark saturation, human oversight, and incomplete zero-day performance. SE011, SE016, SE018, SE020, SE035, SE036
CE044 The most plausible roadmap is staged: human-in-loop agent prototypes, classified compute buildout, defensive pilots, ATO packages, and only then broader autonomous offensive mission support. SE001, SE007, SE019, SE031, SE033, SE034
CE045 The central diligence gap is that Cathedral has no reviewed public website, product documentation, named deployments, certification package, benchmark report, or compliance artifact. SE001, SE002, SE003, SE004
CU001 Cathedral is publicly described as a stealth military cybersecurity startup aiming to use AI to expand U.S. military cyber capabilities. SU001, SU002
CU002 Reuters reported that Cathedral launched in recent months with a plan to secure U.S. government contracts for offensive and defensive cyber operations against adversaries such as China. SU001
CU003 Cathedral was reported to be co-founded by Gavin Kliger, Luke Farritor, Marko Elez, and Jack Stein, all former DOGE staffers. SU001, SU002
CU004 Cathedral reportedly closed a $160 million financing at a $1.4 billion valuation led by Andreessen Horowitz and Sequoia. SU001, SU002
CU005 The reviewed 2026 Cathedral news sources do not name any paying customer, production deployment, pilot customer, contract award, or partnership customer. SU001, SU002, SU003, SU004
CU006 Cathedral’s own spokesperson declined to comment in the Reuters report, reinforcing the company’s stealth disclosure profile. SU001
CU007 Reuters reported that Cathedral’s founding team maintains deep ties to the Trump administration and national-security officials, including at the Pentagon. SU001, SU003
CU008 USAspending, SAM.gov, and the DoD contracts page are public official channels an investor can use to look for federal award or opportunity evidence, but those public surfaces do not substitute for classified-award diligence. SU005, SU006, SU007
CU009 U.S. Cyber Command is the most direct target buyer because its mission is to direct, synchronize, and coordinate cyberspace planning and operations to defend and advance national interests. SU008
CU010 NSA’s Cybersecurity Collaboration Center is an adjacent buyer or partner surface because it scales intel-driven cybersecurity through industry, interagency, and international partnerships. SU009
CU011 Fleet Cyber Command / 10th Fleet is a naval cyber component with more than 13,000 billets and many Cyber Mission Force units. SU010
CU012 The 16th Air Force is an Air Force cyber and ISR component responsible for cryptologic activities and operating and defending Department networks. SU011
CU013 Marine Corps Forces Cyberspace Command aligns Marine cyberspace operations with U.S. Cyber Command objectives. SU012
CU014 Space Force cyber organizations such as Space Delta 6 operate and maintain space mission systems, creating a service-specific cyber-infrastructure buyer surface. SU026
CU015 CISA is a plausible civilian adjacent account because it coordinates critical-infrastructure security and works with partners to manage cyber and physical infrastructure risk. SU013
CU016 CIA and DIA are plausible intelligence-community stakeholders because CIA provides national-security intelligence and DIA provides intelligence on foreign militaries and operating environments. SU014, SU015
CU017 Five Eyes allied demand is plausible but secondary because the UK Ministry of Defence is actively pursuing strategic partnerships to boost military AI and innovation. SU035
CU018 DIU allows individual or commercial entities to submit solution briefs, including first-time government sellers with applicable commercial solutions. SU016, SU017
CU019 DIU frames commercial defense demand as access to a market exceeding $100 billion, which supports a startup-first outreach path before a full program office sale. SU017
CU020 Defense SBIR/STTR provides a structured path from eligibility and registration through proposal submission, Phase II, transition, and commercialization. SU018, SU019
CU021 SBIR provides equity-free funding through federal agencies to small businesses, making it a possible non-dilutive prototype route for Cathedral. SU019
CU022 GSA’s Multiple Award Schedule is a later-stage purchasing path for listed products and services once a vendor has an approved schedule position. SU020
CU023 DoD Other Transactions are legally binding non-FAR instruments for research, prototype projects, and follow-on production when statutory requirements are met. SU021, SU030
CU024 GAO notes that OTAs are more flexible than traditional contracts and can allow DoD to work with contractors it has not worked with before. SU030
CU025 AFWERX, SOFWERX, and DEFENSEWERX are relevant innovation intermediaries for Cathedral because they package service or special-operations problems into startup-accessible entry points. SU027, SU028, SU029
CU026 FedRAMP is a likely baseline gate for cloud-delivered cyber capability because the FedRAMP Marketplace tracks certified cloud services, authorizing agencies, and assessors. SU022
CU027 Current CMMC posture remains a defense-industrial-base diligence item even though DoD announced suspension of Phase II requirements while retaining Phase I self-assessment requirements. SU023
CU028 NIAP/Common Criteria appears in the compliance stack as a product-assurance diligence topic for security technology sold into national-security environments. SU024
CU029 DCSA states that entities handling classified information for the U.S. government must first obtain facility clearance, making FCL/FOCI a hard gate for classified Cathedral work. SU025
CU030 DoD IL5 documentation describes DISA cloud security requirements and provisional authorization decisions, so Impact Level and ATO readiness are material deployment gates. SU036, SU022
CU031 Cathedral has not publicly disclosed FedRAMP, DoD impact-level authorization, CMMC status, NIAP validation, facility clearance, personnel clearances, or classified program access. SU001, SU002, SU023, SU025, SU036
CU032 Shield AI’s reported U.S. Air Force deal before a $12.7 billion valuation illustrates how mission validation can precede large private defense-tech financing. SU031
CU033 Anduril’s $5 billion Series H at a $61 billion valuation shows the defense-tech market rewards companies that can convert government demand into scaled programs and facilities. SU032, SU033
CU034 Palantir’s 2024 Form 10-K says Gotham has served defense agencies and the intelligence community for over a decade, demonstrating a long sales-and-embedding arc. SU034
CU035 Palantir disclosed $1.071 billion of government revenue for 2024, illustrating the scale possible once a defense-software vendor is embedded in government accounts. SU034
CU036 Incumbent and scaled peers create adoption barriers because government buyers can procure cyber, AI, or mission software through existing contract vehicles and proven vendors rather than a stealth startup. SU007, SU020, SU034
CU037 A realistic Cathedral customer journey is multi-stage: classified relationship access may open doors, but public procurement still tends to move from prototype or SBIR-style work to OTA, schedule, or program-of-record scale. SU016, SU018, SU021, SU030
CU038 A 12-to-24-month enterprise-defense sales-cycle assumption is reasonable for underwriting because the public path includes solicitation, proposal, evaluation, award, security authorization, and transition gates. SU016, SU018, SU021, SU022, SU025
CU039 The absence of named customers is not dispositive for classified cyber work because facility clearance and classified-information rules can limit what vendors can market publicly. SU025, SU008, SU009
CU040 Cathedral’s current customer count should be recorded as null because no public source reviewed discloses accounts, deployments, production users, pilots, NRR, GRR, churn, or renewal metrics. SU001, SU002, SU003, SU004
CU041 Cathedral’s founder access is a go-to-market advantage because recent senior government roles plausibly shorten introductions to Pentagon and national-security buyers. SU001
CU042 The same access is an adverse revolving-door risk because critical coverage frames the move from DOGE into a military-tech startup as controversial and Reuters notes potential scrutiny over government contracts. SU001, SU003
CU043 Budget timing is an adoption barrier because public procurement channels require a funded requirement, a solicitation or vehicle, and an award path before revenue recognition. SU006, SU007, SU020
CU044 The prototype-to-program valley of death is a material risk because SBIR and OTA mechanisms can fund experiments while still requiring transition and commercialization into enduring procurement. SU018, SU021, SU030
CU045 The buyer set is addressable rather than evidenced: Cathedral’s public record supports mission fit and access, not customer adoption. SU001, SU004, SU008, SU009
CR001 Cathedral closed a $160 million round at a reported $1.4 billion valuation in July 2026. SR001, SR002, SR003
CR002 Cathedral was co-founded by former DOGE staffers Gavin Kliger, Luke Farritor, Marko Elez, and Jack Stein. SR001, SR002
CR003 Public reporting describes Cathedral’s mission as AI-driven U.S. military cyber operations with both offensive and defensive capabilities. SR001, SR002
CR004 Andreessen Horowitz and Sequoia Capital reportedly led Cathedral’s round and both took board seats. SR001, SR010
CR005 No reviewed public source disclosed Cathedral revenue, production customers, or awarded government contracts. SR001, SR002, SR042, SR043
CR006 Cathedral’s founding team has close reported ties to the Trump administration and national security officials. SR001, SR005
CR007 Reuters reported that Cathedral could face scrutiny over government contracts if Democrats gained congressional power after the midterms. SR001
CR008 Startup Fortune characterized Cathedral’s valuation as a bet on access and founder knowledge rather than inspectable revenue. SR002
CR009 Vanity Fair described DOGE as an expedited revolving door into defense contracting and venture-backed government-facing startups. SR005, SR004
CR010 Vanity Fair quoted watchdog and investor concerns that weak ethics restrictions and conflict-of-interest issues could hinder DOGE-alumni startups. SR005
CR011 Kliger was reported to have served until recently as the Pentagon chief data officer and to have worked near military AI issues. SR001, SR005
CR012 Vanity Fair reported Kliger worked on GenAI.mil and AI-related Pentagon contracting efforts, increasing perceived insider-knowledge risk. SR005
CR013 A Defense Department official told Vanity Fair that Kliger is subject to a one-year cooling-off period, while federal post-employment regulations govern certain communications and appearances. SR005, SR025
CR014 FAR Subpart 9.5 addresses organizational conflicts of interest, including unfair competitive advantage concerns. SR023
CR015 FAR 3.104 establishes procurement-integrity restrictions around contractor bid or proposal information and source-selection information. SR024
CR016 Federal post-employment rules create restrictions that can matter when former officials communicate back to their prior agencies. SR025
CR017 Federal ethics rules prohibit using public office for private gain, including implying government sanction of private activity. SR026
CR018 CREW says DOGE’s structure, staffing, budget, and operations lack clarity and require public records scrutiny. SR047
CR019 CREW has sought DOGE records to test compliance with ethics, transparency, legal-authority, funding, and records-preservation obligations. SR047
CR020 AP reported that Marko Elez resigned after being linked to racist social-media posts and that Musk said he would bring him back. SR011, SR001
CR021 Reuters reported Elez worked at Treasury during DOGE and raised concerns from a judge after accessing highly sensitive material. SR001, SR011
CR022 AP reported Elez was among DOGE employees at the center of a Treasury payment-system access controversy. SR011, SR015, SR016
CR023 GovExec reported GAO found Treasury missed security controls in providing DOGE system access and did not always enforce protocols. SR017
CR024 GovExec reported GAO findings that Elez sent unencrypted USAID payment information to DOGE associates without agency approval. SR017
CR025 WIRED identified several DOGE engineers, including Farritor and Kliger, as young and having little or no government experience when put into important roles. SR012
CR026 WIRED reported concerns that DOGE-affiliated personnel had access to sensitive government systems and could bypass normal controls. SR012
CR027 WIRED reported that DOGE may have misused Social Security data, adding to the adverse data-access narrative around DOGE alumni. SR014
CR028 Lawfare argues private-sector offensive cyber participation requires defining objectives, scope, targets, legal authorities, and liability. SR027
CR029 Lawfare warns policymakers should mitigate escalation and diplomatic-fallout risks before expanding private-sector cyber-offense roles. SR027
CR030 The Atlantic Council describes the zero-day and offensive-cyber supply chain as opaque, fragmented, expensive, and strategically sensitive. SR031
CR031 The Atlantic Council reports private firms often create offensive cyber capabilities for governments and that China’s offensive cyber industry is increasingly integrated with AI institutions. SR031
CR032 CSIS argues harmful cyber activity can occur below the use-of-force threshold, limiting the usefulness of deterrence alone. SR029
CR033 CSIS notes DOD autonomy policy is widely misunderstood and that cyber weapons systems are exempted from some autonomous-weapons review pathways. SR030
CR034 CSIS says government cyber collaboration faces information-sharing, classification, and liability constraints. SR028
CR035 ITAR regulations define controlled defense articles and defense services and place the United States Munitions List in 22 CFR Part 121. SR032, SR033
CR036 BIS and EAR sources show export controls can apply to advanced computing and other controlled items beyond traditional weapons. SR034, SR035
CR037 The Wassenaar Arrangement maintains control lists for conventional arms and dual-use goods and technologies, reinforcing international export-control constraints. SR036
CR038 Because Cathedral’s reported work is military cyber operations, export-control review is a gating diligence item before any foreign customer, investor, data-center, or personnel expansion. SR001, SR032, SR034, SR036
CR039 Classification and stealth limit independent verification because public reporting discloses Cathedral’s mission and financing but not product specifications, contracts, revenue, or performance data. SR001, SR002, SR042, SR043
CR040 Booz Allen, Leidos, Palantir, and Anduril all have public cyber, defense, or platform proof that Cathedral has not yet matched publicly. SR037, SR038, SR039, SR040
CR041 Washington Technology’s 2026 Top 100 ranking illustrates the scale and durability of established government contractors competing for federal technology work. SR041
CR042 SAM.gov and USAspending.gov are core public procurement and spending surfaces, but public reporting rather than those portals currently anchors Cathedral’s public contract story. SR042, SR043, SR001
CR043 SBIR and DIU materials show official pathways for commercial technology vendors, but those pathways do not by themselves prove revenue or procurement success for Cathedral. SR044, SR045
CR044 Cathedral’s reported plan to secure U.S. government contracts creates single-buyer concentration until commercial, allied, or multi-agency revenue is disclosed. SR001, SR038, SR042, SR043
CR045 The combination of a $1.4 billion valuation, no disclosed revenue, and entrenched incumbents makes valuation fragility a high-impact commercial risk. SR001, SR002, SR037, SR041
CR046 Bulletin coverage of cyber norms underscores that cyber operations remain an international-norms problem, not merely a domestic procurement issue. SR046
CR047 The White House executive order established DOGE inside the Executive Office of the President, making Cathedral’s DOGE-alumni identity politically legible rather than incidental. SR018, SR019
CR048 Cathedral’s reported search for dedicated compute or a data-center partnership adds an infrastructure dependency to its cyber-operations plan. SR001, SR002
CV001 Cathedral raised $160 million at a $1.4 billion post-money valuation in July 2026. SV001, SV002, SV003, SV004
CV002 The $160 million round at a $1.4 billion post-money valuation implies approximately $1.24 billion of pre-money value. SV001, SV002
CV003 The same round implies that new investors bought roughly 11.4% of Cathedral on a post-money basis. SV001, SV002
CV004 Cathedral has no disclosed revenue or ARR, so a revenue or ARR valuation multiple cannot be computed from public evidence. SV001, SV002
CV005 Cathedral has no disclosed government contract wins as of the fetched public reporting. SV001, SV002
CV006 Public reporting frames Cathedral as a stealth military cyber and AI startup seeking U.S. government contracts, not as a company with proven commercial traction. SV001, SV003, SV004
CV007 Reuters reported that Cathedral's $1.4 billion valuation reflects investor confidence in the founding team's government relationships rather than any product track record. SV001, SV002, SV003
CV008 The valuation appears to price government-access and team-signal scarcity more than currently observable product or revenue traction. SV001, SV002, SV021
CV009 Andreessen Horowitz and Sequoia led the Cathedral financing and both took board seats, which is a meaningful signaling premium for a new stealth company. SV001, SV002, SV003
CV010 a16z’s American Dynamism platform publicly emphasizes national-interest sectors, helping explain why a defense-cyber startup can receive thematic investor support before revenue. SV027, SV001
CV011 Anduril raised $5 billion at roughly a $61 billion valuation in 2026. SV005, SV006, SV007, SV008
CV012 Anduril had publicly reported revenue scale, including reporting that revenue doubled in 2025 to about $2.2 billion. SV005, SV008
CV013 Anduril’s $61 billion valuation on about $2.2 billion of reported 2025 revenue implies a trailing revenue multiple near 27.7x. SV005, SV008
CV014 Anduril is a more mature comp than Cathedral because it has public product breadth, revenue scale, facilities expansion, and a late-stage funding profile. SV008, SV029, SV030
CV015 Shield AI raised a 2026 Series G at a $12.7 billion post-money valuation after defense aircraft and autonomy traction. SV009, SV010
CV016 Shield AI previously reached a $5.3 billion valuation in 2025 after a $240 million financing. SV011, SV012
CV017 Shield AI is a stronger proof-stage comp than Cathedral because public coverage ties its valuation to autonomous aircraft programs and U.S. Air Force-related traction. SV009, SV010, SV012
CV018 Palantir’s 2026 public-market frame is a high-multiple government and commercial software reference rather than an early-stage startup comp. SV014, SV016, SV020
CV019 Palantir reported Q1 2026 revenue growth and U.S. government revenue growth, showing that its valuation is supported by operating revenue disclosure. SV014, SV015, SV016
CV020 CompaniesMarketCap and Stock Analysis provide observable Palantir market-cap, revenue, and P/S context, unlike Cathedral where revenue is undisclosed. SV013, SV018, SV019, SV020
CV021 Palantir’s public price-to-sales multiple can serve as an aggressive upper-bound reference, but it should not be mechanically applied to Cathedral before contracts and revenue exist. SV016, SV020, SV002
CV022 Rebellion Defense is relevant only as a private defense-software reference because public sources do not provide an equivalent current valuation or revenue multiple. SV028, SV002
CV023 Typical seed-stage valuation benchmarks are far below Cathedral’s $1.4 billion post-money mark. SV023, SV024, SV026
CV024 Typical Series A benchmark discussions also sit far below Cathedral’s $1.24 billion implied pre-money valuation. SV024, SV025, SV026
CV025 Even if defense AI deserves a premium, Cathedral’s valuation at founding is an outlier against ordinary seed and Series A pricing ranges. SV001, SV023, SV024, SV025
CV026 At a 10x revenue multiple, Cathedral would need roughly $140 million of annual revenue to support a $1.4 billion valuation. SV001, SV020
CV027 At a 5x revenue multiple, Cathedral would need roughly $280 million of annual revenue to support a $1.4 billion valuation. SV001, SV020
CV028 At a 15x revenue multiple, Cathedral would still need roughly $93 million of annual revenue to support a $1.4 billion valuation. SV001, SV013, SV020
CV029 A bull case requires Cathedral to convert founder access into material U.S. government cyber contract value within roughly 18 to 24 months. SV001, SV021, SV022
CV030 A base case is that Cathedral raises enough capital to build product and pursue pilots but remains overvalued until contract evidence appears. SV001, SV002, SV021
CV031 A bear case is that procurement, politics, or overvaluation pressure prevent Cathedral from growing into the mark before dilution or repricing. SV001, SV002, SV021, SV022
CV032 The defense-tech bubble critique directly applies to Cathedral because it has a large mark before public revenue, contracts, or product disclosure. SV002, SV021, SV022
CV033 Defense-tech investors can still rationally underwrite the category because geopolitical demand and American Dynamism themes create durable budget tailwinds. SV005, SV021, SV027
CV034 The appropriate recommendation is research-more rather than buy because the valuation is already priced like a scaled winner while public traction is absent. SV001, SV002, SV021
CV035 Confidence should be low because the decisive diligence inputs—revenue, contract pipeline, product capability, security clearances, and procurement path—are private or undisclosed. SV001, SV002
CV036 Risk rating should be high because the mark combines pre-revenue pricing, political exposure, procurement uncertainty, and future dilution risk. SV001, SV002, SV021, SV022
CV037 Valuation stance should be expensive because public evidence does not yet support a $1.4 billion post-money price on fundamentals. SV001, SV002, SV023, SV024
CV038 A plausible exit path requires Cathedral to become a durable cyber-defense software supplier with multi-year government contracts, not merely a team premium story. SV001, SV014, SV016, SV029
CV039 Future rounds could dilute early investors if the company must finance data-center capacity, compliance, and long procurement cycles before revenue scales. SV001, SV021, SV022
CV040 Political risk matters because reporting identifies Cathedral’s ties to DOGE and the Trump administration as potential sources of scrutiny if control of Congress shifts. SV001, SV002
CV041 The premium decomposition is best understood as team premium plus investor-signal premium plus defense-AI market premium plus scarcity premium, offset by a traction discount. SV001, SV002, SV021, SV027
CV042 The largest single negative adjustment should be a traction discount because revenue and contract value are both undisclosed. SV001, SV002
CV043 Diligence should request contract pipeline, bid status, security and accreditation path, technical proof, data-center economics, and cap-table preference terms before any investment decision. SV001, SV002, SV021
CV044 A thesis-break trigger would be no credible paid pilot or government contracting path within 18 to 24 months after the round. SV001, SV021, SV022
CV045 Another thesis-break trigger would be disclosure that the valuation rests mostly on political access rather than proprietary technical capability. SV001, SV002, SV022
CV046 The IC debate should balance a real defense-tech boom and elite investor signal against an unusually high pre-revenue mark with no public product, revenue, or contract proof. SV001, SV002, SV005, SV021, SV027
来源
编号出版方标题引文
SO001 U.S. News & World Report / Reuters Exclusive-DOGE Alumni Launch Military Cyber Startup With $1.4 Billion Valuation A team of former DOGE employees raised a major funding round for a startup that aims to use AI to expand U.S. military cyber capabilities.
SO002 The Next Web Four former DOGE staffers raised $160 million at a $1.4 billion valuation for an AI military cyber startup Cathedral, a stealth military cybersecurity startup founded by four former Department of Government Efficiency staffers, has raised $160 million at a $1.4 billion valuation.
SO003 Reuters DOGE alumni launch military cyber startup with $1.4 billion valuation Origin page required JavaScript and ad-block disabling during fetch; Reuters text was available through the U.S. News syndication source.
SO004 Hoodline Cathedral: Ex-DOGE Engineers Launch $1.4B Military Cyber Startup Three former engineers from Elon Musk's controversial DOGE initiative have quietly spun out of Washington and into the venture spotlight with Cathedral.
SO005 Gizmodo DOGE Guys Who Didn’t Save Us Any Money Rake in Cash With New Military Tech Startup DOGE Guys Who Didn’t Save Us Any Money Rake in Cash With New Military Tech Startup.
SO006 Cyber Daily Ex-DOGE engineers launch new AI firm to bolster US military cyber Ex-DOGE engineers Gavin Kliger, Luke Farritor, Marko Elez and Jack Stein formed Cathedral.
SO007 The White House White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination President Trump’s bold vision to secure and accelerate American artificial intelligence innovation is being actioned through the creation of GOLD EAGLE.
SO008 TechCrunch Anduril raises $5B, doubles valuation to $61B Anduril has raised a $5 billion Series H round at a $61 billion valuation.
SO009 Forbes Anduril’s $61 Billion Valuation Is A Bet On Pentagon Speed The Washington Post reported that Anduril raised $5 billion at a $61 billion valuation.
SO010 The Next Web Musk allies back a private-sector DOGE as ex-staffers launch Special Special is launching with the backing of Andreessen Horowitz and other Musk-adjacent investors.
SO011 The Atlantic The DOGE Bros Want Another Shot DOGE alumni make splashy announcements about entering complex industries with scant qualifications while promising to root out waste.
SO012 DOGE Work | DOGE: Department of Government Efficiency The people voted for major reform.
SO013 The White House Establishing And Implementing The President's Department Of Government Efficiency This Executive Order establishes the Department of Government Efficiency to implement the President’s DOGE Agenda.
SO014 Government Executive Treasury missed security controls in giving DOGE system access, GAO finds Treasury missed security controls in giving DOGE system access, GAO finds.
SO015 Government Executive What DOGE taught us about AI and federal workers DOGE abruptly shut down USAID and pushed generative AI uses across federal operations.
SO016 Nextgov/FCW What DOGE taught us about AI and federal workers DOGE’s use of AI in federal workforce changes became a lesson in governance and institutional trust.
SO017 Yahoo News DOGE officially shuts down The Department of Government Efficiency shut down operations on July 4.
SO018 The Fiscal Times DOGE Is Officially Done The Department of Government Efficiency came to an official end this past weekend.
SO019 The Next Web The emails that broke Anthropic and the Pentagon apart For months, the fight between Anthropic and the Pentagon had been escalating.
SO020 CNBC Trump admin allows Anthropic to release Mythos AI model to some companies, government agencies The Trump administration has agreed to allow Anthropic to release its new Claude Mythos 5 model to some companies and government agencies.
SO021 Politico Trump picked a fight with Anthropic. Now the administration is backing off. Trump picked a fight with Anthropic. Now the administration is backing off.
SO022 Breaking Defense Air Force pushing contractors to purge Anthropic by Sept. 1: Memo The Air Force Research Laboratory is pushing its contractors to purge all Anthropic products from their systems by Sept. 1.
SO023 eWeek Anthropic vs Washington: A Timeline of Claude’s Collision With the US Government The dispute over AI guardrails grew into a confrontation between a frontier AI company and the US government.
SO024 Andreessen Horowitz American Dynamism: Supporting the National Interest American Dynamism supports founders and companies that serve the national interest.
SO025 Andreessen Horowitz Portfolio | Andreessen Horowitz Andreessen Horowitz lists AI and American Dynamism among portfolio focus areas.
SO026 Sequoia Capital Our Companies Sequoia lists its company portfolio and investment stages on its official site.
SO027 Sequoia Capital AI Ascent 2026 Sequoia hosted more than 150 leading founders and researchers in AI at AI Ascent IV.
SO028 SecurityWeek White House Launches AI-Driven Gold Eagle Vulnerability Coordination Initiative Gold Eagle is a coordination mechanism intended to speed detection, prioritization and patching of vulnerabilities.
SO029 Dark Reading Gold Eagle Clearinghouse Targets Real Gap, but How Is Unclear Gold Eagle targets a real gap, but how is unclear.
SO030 CSO Online White House launches AI-driven vulnerability clearinghouse to speed cyber remediation The White House is launching a program to help government agencies and critical infrastructure operators identify, prioritize, and remediate vulnerabilities.
SO031 GovCon Wire The White House’s Gold Eagle Initiative: Strengthening Public-Private Partnerships to Safeguard Critical Infrastructure in the AI Era The Gold Eagle Initiative is framed as strengthening public-private partnerships to safeguard critical infrastructure in the AI era.
SM001 Office of Management and Budget President’s Budget
SM002 Office of the Under Secretary of Defense Comptroller Budget Materials
SM003 U.S. Cyber Command Mission and Vision
SM004 National Security Agency Cybersecurity Collaboration Center
SM005 U.S. Government Accountability Office High Risk List
SM006 U.S. Government Accountability Office Cybersecurity: OMB Should Improve Information Security Performance Metrics
SM007 Congressional Research Service Defense Acquisitions: How and Where DOD Spends and Reports Its Contracting Dollars
SM008 DARPA AI Cyber Challenge
SM009 Defense SBIR/STTR SBIR/STTR Programs
SM010 Andreessen Horowitz American Dynamism
SM011 MarketsandMarkets Artificial Intelligence in Military Market
SM012 Grand View Research Artificial Intelligence in Military Market Report
SM013 MarketsandMarkets Cyber Warfare Market
SM014 Mordor Intelligence Cyber Warfare Market Report
SM015 Grand View Research Cybersecurity Market Size and Share Report, 2026-2033
SM016 USAspending.gov USAspending.gov
SM017 SAM.gov Contract Opportunities
SM018 U.S. Department of Defense Contracts
SM019 Acquisition.gov FAR Part 16 - Types of Contracts
SM020 CISA About CISA
SM021 CISA Cybersecurity Best Practices
SM022 CISA Zero Trust Maturity Model
SM023 Department of Defense CIO DoD Zero Trust Strategy
SM024 Defense Innovation Unit Solutions
SM025 Defense Innovation Unit Work With Us
SM026 SBIR.gov About SBIR and STTR
SM027 NIST Cybersecurity Framework
SM028 NIST Artificial Intelligence
SM029 Sacra Anduril company profile
SM030 Los Angeles Times Anduril to invest another $1 billion in California with new Long Beach campus
SM031 DAU Adaptive Acquisition Framework Other Transactions
SM032 U.S. Government Accountability Office Other Transaction Agreements: DOD Can Improve Planning for Consortia Awards
SP001 Reuters via U.S. News Exclusive-DOGE Alumni Launch Military Cyber Startup With $1.4 Billion Valuation Cathedral closed on a $160 million funding round that valued the company at $1.4 billion.
SP002 The Next Web Four former DOGE staffers raised $160 million at a $1.4 billion valuation for an AI military cyber startup
SP003 Startup Fortune Four DOGE alumni raise at a $1.4 billion valuation for Cathedral, a stealth military cybersecurity startup backed by a16z and Sequoia Cathedral has raised the money. Now it has to show whether DOGE access converts into signed Pentagon work.
SP004 TechCrunch Anduril raises $5B, doubles valuation to $61B Anduril has raised a $5 billion Series H round at a $61 billion valuation.
SP005 U.S. Securities and Exchange Commission Palantir Technologies Inc. 2024 Form 10-K We have built four principal software platforms, Palantir Gotham, Palantir Foundry, Palantir Apollo, and Palantir Artificial Intelligence Platform.
SP006 UK Ministry of Defence New strategic partnership to unlock billions and boost military AI and innovation
SP007 Shield AI Hivemind Since piloting the first fully autonomous combat mission in 2018, Hivemind has become the trusted AI pilot operating alongside U.S. and allied forces.
SP008 Shield AI Shield AI raises $240M at $5.3B valuation to scale Hivemind Enterprise
SP009 TechCrunch Defense startup Shield AI lands $12.7B valuation, up 140%, after US Air Force deal
SP010 Rebellion Defense Rebellion homepage An INTELLIGENCE SHIELD for critical assets combining next-gen radar, AI fusion, and full operational software and support.
SP011 Associated Press via Inc. Inside the Collapse of Security Experts’ Cyber Startup IronNet The never-profitable company announced it was shutting down and firing its employees after running out of money.
SP012 Stretto IronNet, Inc., et al. bankruptcy case
SP013 Horizon3.ai NodeZero: The World’s Most Experienced AI Hacker More than 5,200 organizations worldwide relying on NodeZero.
SP014 Business Wire Horizon3.ai Secures Investment from Prosperity7 Ventures to Protect AI Datacenters and Critical Infrastructure
SP015 Horizon3.ai The NodeZero Platform NodeZero transforms how organizations secure their environments by running unlimited pentests.
SP016 Business Wire XBOW Raises $120M to Scale its Autonomous Hacker Valued at over $1B, XBOW is Accelerating AI-powered Offensive Security to Help Defenders Outpace Modern Attackers.
SP017 Accenture Accenture Invests in XBOW to Advance Continuous Offensive Security Testing and Exposure Management New partnership will scale continuous, AI-driven security testing and exposure management.
SP018 Dreadnode Dreadnode — AI Infrastructure for Security Agents AI-native security can’t happen without infrastructure.
SP019 Dreadnode Research
SP020 FinTech Global Dreadnode captures $14m to fortify offensive AI security capabilities Dreadnode, an emerging startup specializing in offensive AI security, has recently secured a $14m Series A funding round.
SP021 RunSafe Security CISA’s 2026 Memory Safety Deadline CISA has made memory safety a key focus of its Secure by Design initiatives.
SP022 PR Newswire RunSafe Security Raises $12 Million in Series B Funding
SP023 Help Net Security RunSafe Security raises $12 million to reduce attack surface in critical infrastructure
SP024 Two Six Technologies Two Six Technologies Captures Strategic Win with Award on $4 Billion DTRA Contract Two Six supports national security customers across the Department of Defense, including U.S. Special Operations Command, U.S. Cyber Command and DARPA.
SP025 Two Six Technologies Sentr — Command the Information Environment AI-driven command of the information environment — sense, plan, and coordinate effects at scale.
SP026 Booz Allen Hamilton Cybersecurity Cyberattacks move at AI speed. Cyber defense must too.
SP027 Leidos Cybersecurity Offensive, defensive, and cyber resilience across every mission.
SP028 SAIC SAIC Cybersecurity
SP029 CACI Cyber CACI advances automation and AI/ML across operations to purposefully accelerate mission success.
SP030 Peraton Cyber
SP031 ManTech ACTP
SP032 Parsons Cybersecurity For Global Events
SP033 GovConWire 8 Companies Awarded $1.9B in Navy Cyberspace Operations Support Contract Options The U.S. Navy has awarded eight companies contract options worth $1.86 billion combined.
SP034 Washington Technology 2026 Top 100 Our annual rankings are based on an analysis of federal spending on IT, systems integration, telecommunications, professional services and other high-tech needs.
SP035 GovConWire GSA Unveils 43 Phase 1 Awardees for Alliant 3 GWAC The General Services Administration has unveiled the first phase of awards under the Alliant 3 governmentwide acquisition contract.
SP036 Washington Technology Battle for $245M cyber warfare contract gets new start The Army has agreed to re-evaluate proposals submitted by Booz Allen Hamilton, Peraton and ManTech.
SP037 Atlantic Council Mythical Beasts: Investigating the role of intermediaries in the proliferation of offensive cyber capabilities
SP038 Atlantic Council Crash (exploit) and burn: Securing the offensive cyber supply chain to counter China in cyberspace Zero-day exploitation is becoming more difficult, opaque, and expensive, leading to feast-or-famine contract cycles.
SP039 Lawfare Partners or Provocateurs? Private-Sector Involvement in Offensive Cyber Operations
SP040 Cyber Defense Review Exploit Brokers and Offensive Cyber Operations
SP041 Vannevar Labs Restoring Deterrence, Reclaiming Advantage
SI001 ExecutiveBiz Cyber Startup Cathedral Raises $160M at $1.4B Valuation Cathedral has secured $160 million in a funding round ... valued the company at $1.4 billion.
SI002 Startup Fortune Four DOGE alumni raise at a $1.4 billion valuation for Cathedral Not a product launch. Not a customer announcement. A company with almost no public footprint has raised unicorn money.
SI003 citybiz Andreessen Horowitz, Sequoia Capital Lead $160M Round for Former DOGE Staff’s Venture The company ... was valued at $1.4 billion in the financing, which was led by Andreessen Horowitz and Sequoia Capital.
SI004 EquityPandit Former DOGE Officials Launch AI Defense Startup Cathedral The company has raised $160 million in a funding round led by venture capital firms Andreessen Horowitz and Sequoia Capital.
SI005 Acquisition.GOV Part 16 - Types of Contracts Part 16 describes contract types and ordering rules for federal acquisitions.
SI006 Acquisition.GOV 16.202-1 Description A firm-fixed-price contract provides for a price that is not subject to adjustment based on contractor cost experience.
SI007 Acquisition.GOV 16.301-1 Description Cost-reimbursement types of contracts provide for payment of allowable incurred costs.
SI008 Acquisition.GOV 16.401 General Incentive contracts relate the amount of profit or fee payable to the contractor’s performance.
SI009 Acquisition.GOV 16.504 Indefinite-quantity contracts An indefinite-quantity contract provides for an indefinite quantity, within stated limits, of supplies or services during a fixed period.
SI010 Acquisition.GOV 16.505 Ordering Orders shall clearly describe all services to be performed or supplies to be delivered.
SI011 Acquisition.GOV 15.101 Best value continuum An agency can obtain best value in negotiated acquisitions through source selection approaches where cost or price importance may vary.
SI012 SBIR.gov About SBIR provides equity free funding through federal agencies to American small businesses.
SI013 Defense SBIR/STTR DoW Office for Small Business Innovation The Defense SBIR/STTR flow runs from eligibility and proposal to post-contract award, Phase II, transition and commercialization.
SI014 Defense SBIR/STTR Defense SBIR/STTR - Funding Opportunities DoW uses the Broad Agency Announcement funding mechanism to procure basic and applied research.
SI015 General Services Administration Small Business Innovation Research and Small Business Technology Transfer The SBIR and STTR programs are highly competitive programs that encourage domestic small businesses to engage in federal R&D.
SI016 Department of Homeland Security CRADAs A CRADA is a written agreement that facilitates R&D collaboration between federal laboratories and non-federal entities.
SI017 Congressional Research Service Department of Defense Use of Other Transaction Authority The Department of Defense obligates more than $300 billion annually to buy goods and services and support R&D.
SI018 Defense Innovation Unit About DIU DIU accelerates the adoption of leading commercial technology throughout the military.
SI019 Defense Innovation Unit Tap Into a $100+ Billion Market Any individual or commercial entity is eligible to respond to a DIU solicitation.
SI020 USAspending.gov Government Spending Open Data USAspending is the official open data source of federal spending information, including contracts, grants, and loans.
SI021 SAM.gov Contract Opportunities SAM.gov is the federal contract opportunities surface for government solicitations.
SI022 U.S. Department of Defense Contracts The Defense Department publishes contract award notices on its official contracts page.
SI023 Securities and Exchange Commission Palantir Technologies 2025 Form 10-K Revenue increased by $1.6 billion, or 56%, for the year ended December 31, 2025 compared to 2024.
SI024 Securities and Exchange Commission Palantir Technologies Q1 2026 Form 10-Q Revenue from government customers and U.S. customers remained a meaningful source of revenue growth.
SI025 Securities and Exchange Commission Palantir Technologies 2024 Form 10-K Revenue from government customers increased by $347.4 million, or 28%, for the year ended December 31, 2024 compared to 2023.
SI026 Palantir Getting started with Palantir The Palantir platform is used by organizations from startups to multinational companies to governments around the world.
SI027 Sacra Anduril revenue, valuation & funding Sacra estimates that Anduril hit $2.2B in revenue in 2025, up 120% from $1B in 2024.
SI028 Sacra Shield AI revenue, valuation & funding Sacra estimates that Shield AI hit approximately $300M in revenue for the year ending March 2025.
SI029 Los Angeles Times Anduril to invest another $1 billion in California with new Long Beach campus Anduril Industries ... will expand in Long Beach with a new $1-billion complex near the city’s airport.
SI030 GeekWire Defense giant Anduril is quietly building autonomous warships on Seattle’s historic ship canal Anduril Industries is building a new class of autonomous warships on Seattle’s historic ship canal.
SI031 Goldman Sachs AI is poised to drive 160% increase in data center power demand Goldman Sachs Research estimates that data center power demand will grow 160% by 2030.
SI032 U.S. Department of Energy DOE Releases New Report Evaluating Increase in Electricity Demand from Data Centers Domestic energy usage from data centers is expected to double or triple by 2028.
SI033 Epoch AI Training compute of frontier AI models grows by 4-5x per year Training compute of frontier AI models grows by 4-5x per year.
SI034 Andreessen Horowitz American Dynamism: Supporting the National Interest American Dynamism supports companies serving the national interest.
SI035 Small Business Administration Federal Contracting The SBA explains the federal contracting path for small businesses.
SI036 Government Accountability Office DOD Fraud Risk Management DOD spent about $422 billion on contracts in FY 2020 and has been the target of contracting-related fraud schemes.
SE001 U.S. News & World Report / Reuters Exclusive-DOGE Alumni Launch Military Cyber Startup With $1.4 Billion Valuation plans to secure U.S. government contracts to bolster AI-driven cyber operations, including offensive and defensive capabilities
SE002 The Next Web Four former DOGE staffers raised $160 million at a $1.4 billion valuation for an AI military cyber startup The company plans to secure US government contracts for AI-driven offensive and defensive cyber operations against adversaries including China.
SE003 Hoodline Cathedral: Ex-DOGE Engineers Launch $1.4B Military Cyber Startup exploring either a purchase of or partnership with a data-center provider to secure dedicated compute
SE004 Cyber Daily Ex-DOGE engineers launch new AI firm to bolster US military cyber former Department of Government Efficiency (DOGE) engineers have formed a new AI cyber start-up for military defence and cyber operations
SE005 The White House White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination GOLD EAGLE, a clearinghouse that enables unprecedented cybersecurity vulnerability coordination
SE006 SecurityWeek White House Launches AI-Driven Gold Eagle Vulnerability Coordination Initiative speed up the detection, prioritization, and patching of vulnerabilities in critical infrastructure
SE007 Dark Reading Gold Eagle Clearinghouse Targets Real Gap, But How Is Unclear Gold Eagle targets a real gap, but how is unclear.
SE008 DARPA AIxCC | DARPA AIxCC will ask competitors to design novel AI systems to secure the software critical to all Americans.
SE009 AI Cyber Challenge DARPA’s AI Cyber Challenge AIxCC Competitors successfully demonstrated the ability of novel autonomous systems using AI to secure the open-source software
SE010 GitHub AIxCC Finals oss-fuzz-aixcc Public Apache-2.0
SE011 GitHub XBOW Validation Benchmarks As of mid-2026, these benchmarks are saturated
SE012 Horizon3.ai The NodeZero Platform running unlimited pentests that uncover exploitable paths, guide remediation, and immediately verify that your fixes are effective
SE013 Horizon3.ai Docs HORIZON3 Documentation deploy, configure, and maximize the effectiveness of NodeZero, our autonomous penetration testing platform
SE014 Dreadnode Dreadnode — AI Infrastructure for Security Agents Build, evaluate, and deploy security agents with confidence.
SE015 Dreadnode Docs Dreadnode Documentation building, evaluating, and deploying offensive security agents
SE016 HackerOne Why Hybrid Offensive Security Beats Agentic AI Alone AI can now scale offensive operations in ways that were unimaginable a year ago, but on its own, it cannot deliver
SE017 HackerOne Prove Exploitability Faster With New Hai Agents Discovery and exploitation are starting to happen on the same timeline
SE018 HackerOne AI Red Teaming Explained by AI Red Teamers AI red teaming is primarily a human driven activity
SE019 Anthropic Claude Gov models for U.S. national security customers deployed by agencies at the highest level of U.S. national security
SE020 Anthropic Cyber evaluations of Claude 4 significant improvement in vulnerability identification and executing complex multi-step attack chains
SE021 Anthropic Building AI for cyber defenders We deliberately avoided enhancements that clearly favor offensive work—such as advanced exploitation or writing malware.
SE022 OpenAI Disrupting malicious uses of AI by state-affiliated threat actors state-affiliated threat actors used our services to research various companies and cybersecurity tools
SE023 Google Project Zero Project Naptime: Evaluating Offensive Security Capabilities of Large Language Models helping attackers more quickly develop offensive capabilities
SE024 Google Security Blog AI-Powered Fuzzing: Breaking the Bug Hunting Barrier AI-Powered Fuzzing: Breaking the Bug Hunting Barrier
SE025 Palantir Palantir Artificial Intelligence Platform Palantir Artificial Intelligence Platform
SE026 FedRAMP FedRAMP | FedRAMP.gov FedRAMP Marketplace is a searchable database of FedRAMP certified cloud services
SE027 NIST AI Risk Management Framework AI RMF Profile on Trustworthy AI in Critical Infrastructure
SE028 NIST CSRC NIST SP 800-53 Rev. 5, Security and Privacy Controls Security and Privacy Controls for Information Systems and Organizations
SE029 NIAP NIAP NIAP
SE030 DoD CIO CIO - Cybersecurity Maturity Model Certification Cybersecurity Maturity Model Certification
SE031 NIST CSRC About the RMF - NIST Risk Management Framework Risk Management Framework provides a process that integrates security, privacy, and cyber supply chain risk management activities
SE032 DefenseScoop Amid concerns sparked by Mythos, the Pentagon’s cyber policy chief sees huge opportunity with frontier AI models vulnerabilities recently discovered by Anthropic’s new Claude Mythos Preview artificial intelligence model
SE033 DefenseScoop Pentagon’s JWCC follow-on would create cloud marketplace, expand AI and edge computing AI and machine learning capabilities across all classification and impact levels, including for DDIL environments
SE034 DefenseScoop AWS, Anduril debut new tactical data center offering listed on DOD’s cloud marketplace cloud-grade computing, storage and AI capabilities in remote areas
SE035 arXiv Teams of LLM Agents can Exploit Zero-Day Vulnerabilities agents still perform poorly on real-world vulnerabilities that are unknown to the agent ahead of time
SE036 arXiv Cybench: A Framework for Evaluating Cybersecurity Capabilities and Risks of Language Models autonomously identifying vulnerabilities and executing exploits have potential to cause real-world impact
SU001 U.S. News & World Report / Reuters Exclusive-DOGE Alumni Launch Military Cyber Startup With $1.4 Billion Valuation Cathedral was launched in recent months with a plan to secure U.S. government contracts to bolster AI-driven cyber operations, including offensive and defensive capabilities.
SU002 The Next Web Four former DOGE staffers raised $160 million at a $1.4 billion valuation for an AI military cyber startup Cathedral, a stealth military cybersecurity startup founded by four former DOGE staffers, raised $160 million at a $1.4 billion valuation.
SU003 Gizmodo DOGE Guys Who Didn’t Save Us Any Money Rake in Cash With New Military Tech Startup The story framed the ex-DOGE team’s move into a military-tech startup as controversial and criticized the public-service-to-defense-tech arc.
SU004 Cyber Daily Ex-DOGE engineers launch new AI firm to bolster US military cyber Former DOGE engineers formed Cathedral, a company that plans to harness AI to bolster the cyber capabilities of the US military.
SU005 USAspending.gov Government Spending Open Data | USAspending USAspending is the official open data source of federal spending information, including information about federal awards such as contracts, grants, and loans.
SU006 SAM.gov Contract Opportunities | SAM.gov SAM.gov hosts federal contract opportunities and includes warnings that the system contains Controlled Unclassified Information.
SU007 U.S. Department of Defense Contracts The Department of Defense contracts page is an official U.S. government source for public contract announcements.
SU008 U.S. Cyber Command Mission and Vision USCYBERCOM directs, synchronizes, and coordinates cyberspace planning and operations to defend and advance national interests.
SU009 National Security Agency Cybersecurity Collaboration Center The NSA Cybersecurity Collaboration Center scales intel-driven cybersecurity through open, collaborative partnerships.
SU010 U.S. Fleet Cyber Command / U.S. 10th Fleet U.S. Fleet Cyber Command / Commander, U.S. 10th Fleet Fleet Cyber Command / 10th Fleet is an operational force with more than 13,000 billets and many Cyber Mission Force units.
SU011 Sixteenth Air Force About Us The 16th Air Force is responsible for ISR, cryptologic activities, and operating and defending Department networks.
SU012 Marine Corps Forces Cyberspace Command About Us MARFORCYBER’s mission aligns Marine cyberspace operations with U.S. Cyber Command objectives.
SU013 CISA About CISA | CISA CISA works with partners to identify and manage risk to the cyber and physical infrastructure Americans rely on.
SU014 Central Intelligence Agency Organization - CIA CIA is responsible for providing national security intelligence to senior U.S. policymakers.
SU015 Defense Intelligence Agency Home DIA’s mission is to provide intelligence on foreign militaries to prevent and decisively win wars.
SU016 Defense Innovation Unit Work With Us Any individual or commercial entity is eligible to respond to a DIU solicitation.
SU017 Defense Innovation Unit Tap Into a $100+ Billion Market DIU invites commercial entities, including first-time sellers to government, to submit solution briefs.
SU018 Defense SBIR/STTR DoW Office for Small Business Innovation Defense SBIR/STTR describes steps from eligibility and registration through Phase II, transition, and commercialization.
SU019 SBIR.gov About SBIR provides equity-free funding through federal agencies to American small businesses.
SU020 General Services Administration Multiple Award Schedule GSA’s Multiple Award Schedule lists products and services that agencies can buy through the program.
SU021 Defense Acquisition University Other Transactions | Adaptive Acquisition Framework Other Transactions are legally binding instruments other than standard procurement contracts, grants, or cooperative agreements.
SU022 FedRAMP FedRAMP | FedRAMP.gov The FedRAMP Marketplace is a searchable database of FedRAMP certified cloud services, authorizing agencies, and assessors.
SU023 Department of Defense CIO CIO - About CMMC DoD announced the suspension of CMMC Phase II requirements while Phase I self-assessment requirements remain in place.
SU024 NIAP NIAP NIAP is the U.S. public program surface for Common Criteria evaluation information.
SU025 Defense Counterintelligence and Security Agency Entity Vetting, Facility Clearances & FOCI Entities providing goods or services to the U.S. government involving access to or creation of classified information will first need a facility clearance.
SU026 United States Space Force United States Space Force > About Us Space Delta 6 and related units operate and maintain satellite and ground systems supporting joint and interagency operations.
SU027 AFWERX SBIR/STTR AFWERX maintains SBIR/STTR pathways for Air Force and Space Force innovation funding.
SU028 SOFWERX SOFWERX: Collaborative Solutions for Warfighter Challenges SOFWERX serves as an innovation platform for United States Special Operations Command.
SU029 DEFENSEWERX DEFENSEWERX | Innovation & Collaboration | Niceville, FL DEFENSEWERX enables agile innovation for government partners through innovation hubs across the country.
SU030 U.S. Government Accountability Office Other Transaction Agreements: DOD Can Improve Planning for Consortia Awards GAO said OTAs allow more flexibility than traditional contracts and let DOD partner with contractors it has not worked with before.
SU031 TechCrunch Defense startup Shield AI lands $12.7B valuation, up 140%, after US Air Force deal Shield AI announced a large Series G after a U.S. Air Force deal.
SU032 TechCrunch Anduril raises $5B, doubles valuation to $61B Anduril raised a $5 billion Series H at a $61 billion valuation.
SU033 Los Angeles Times Anduril to invest another $1 billion in California with new Long Beach campus Anduril is developing drones, missiles, robotic submarines, and autonomous fighter jets and expanding with a $1 billion Long Beach complex.
SU034 U.S. Securities and Exchange Commission Palantir Technologies Inc. 2024 Form 10-K Palantir said Gotham has served global defense agencies and the intelligence community for over a decade and disclosed $1.071 billion of government revenue.
SU035 UK Ministry of Defence New strategic partnership to unlock billions and boost military AI and innovation The UK Ministry of Defence described a strategic partnership intended to unlock billions and boost military AI and innovation.
SU036 Microsoft Learn Department of Defense Impact Level 5 - Azure Compliance The DoD Cloud Computing SRG defines baseline security requirements used to assess cloud service offerings and support provisional authorization decisions.
SR001 U.S. News / Reuters Exclusive-DOGE Alumni Launch Military Cyber Startup With $1.4 Billion Valuation Reuters reported Cathedral raised $160 million at a $1.4 billion valuation and plans AI-driven offensive and defensive military cyber operations.
SR002 Startup Fortune Four DOGE alumni raise at a $1.4 billion valuation for Cathedral, a stealth military cybersecurity startup backed by a16z and Sequoia A $1.4 billion valuation at this stage is a bet on access and founder knowledge - not yet on revenue anyone can inspect.
SR003 The Next Web Four former DOGE staffers raised $160 million at a $1.4 billion valuation for an AI military startup Former DOGE staffers raised $160 million at a $1.4 billion valuation for an AI military startup.
SR004 WIRED The DOGE Boys Get VC Funding to Support Their Latest Enterprise DOGE appeared to have worked as an employment conveyor belt for many of the organization’s affiliates.
SR005 Vanity Fair Meet Your New Defense Contractors: The DOGE Boys In some ways, DOGE acted as an expedited revolving door.
SR006 Gizmodo DOGE Guys Who Didn’t Save Us Any Money Rake in Cash With New Military Tech Startup DOGE guys who did not save money are raising cash for a new military technology startup.
SR007 NewsNation Former DOGE staff start AI military company Former DOGE staff started an AI military company.
SR008 Cyber Daily Ex-DOGE engineers launch new AI firm to bolster US military cyber The firm is intended to bolster US military cyber capabilities.
SR009 ExecutiveBiz Cyber Startup Cathedral Raises $160M at $1.4B Valuation Cyber startup Cathedral raised $160 million at a $1.4 billion valuation.
SR010 CityBiz Andreessen Horowitz, Sequoia Capital Lead $160M Round for Former DOGE Staff’s Venture Andreessen Horowitz and Sequoia Capital led the funding round.
SR011 Associated Press Musk says he will bring back DOGE staffer who resigned after a report of racist postings Marko Elez resigned after the Wall Street Journal linked him to racist social media posts and Musk said he would bring him back.
SR012 WIRED The Young, Inexperienced Engineers Aiding Elon Musk’s Government Takeover WIRED identified six young men, apparently between 19 and 24, with little to no government experience playing critical DOGE roles.
SR013 WIRED Where the DOGE Operatives Are Now Where DOGE operatives went after leaving government.
SR014 WIRED DOGE May Have Misused Social Security Data, DOJ Admits DOGE may have misused Social Security data, according to the article title and reporting.
SR015 Associated Press DOGE was tasked with stopping Treasury payments to USAID, AP sources say DOGE was tasked with stopping Treasury payments to USAID, according to AP sources.
SR016 Associated Press Treasury watchdog begins audit of Musk DOGE team’s access to the US government’s payment system The Treasury inspector general began an audit of the DOGE team’s access to the government payment system.
SR017 GovExec / Nextgov Treasury missed security controls in giving DOGE system access, GAO finds GAO found Treasury missed security controls in giving DOGE system access.
SR018 The White House Establishing And Implementing The President’s Department Of Government Efficiency The executive order established the United States DOGE Service in the Executive Office of the President.
SR019 Department of Government Efficiency Work | DOGE: Department of Government Efficiency DOGE publishes its own work page and savings claims.
SR020 U.S. Government Accountability Office High Risk List GAO maintains a High Risk List for areas vulnerable to waste, fraud, abuse, or needing transformation.
SR021 U.S. Government Accountability Office DOD Fraud Risk Management: Actions Needed to Enhance Department-Wide Approach GAO recommended actions to enhance DOD-wide fraud risk management.
SR022 U.S. Government Accountability Office Cybersecurity High-Risk Series: Challenges in Establishing a Comprehensive Cybersecurity Strategy and Performing Effective Oversight GAO identified challenges in establishing comprehensive cybersecurity strategy and oversight.
SR023 Acquisition.GOV Subpart 9.5 - Organizational and Consultant Conflicts of Interest FAR Subpart 9.5 addresses organizational and consultant conflicts of interest.
SR024 Acquisition.GOV 3.104 Procurement integrity FAR 3.104 covers procurement integrity restrictions.
SR025 Legal Information Institute 5 CFR Part 2641 - Post-Employment Conflict of Interest Restrictions 5 CFR Part 2641 sets post-employment conflict-of-interest restrictions.
SR026 Legal Information Institute 5 CFR § 2635.702 - Use of public office for private gain Federal ethics regulations prohibit use of public office for private gain.
SR027 Lawfare Partners or Provocateurs? Private-Sector Involvement in Offensive Cyber Operations Private-sector offensive cyber participation requires clarifying objectives, scope, legal authority, and liability before changing rules.
SR028 CSIS Redefining Cybersecurity as International Security, Not Just National Security Cyber collaboration beyond borders can deepen ties but faces information-sharing and classified-information constraints.
SR029 CSIS Deterrence and Cyber Strategy There is ample space for harmful cyber action below the use-of-force threshold.
SR030 CSIS DOD Is Updating Its Decade-Old Autonomous Weapons Policy, but Confusion Remains Widespread CSIS argued DOD autonomy policy remains misunderstood and needs greater clarity.
SR031 Atlantic Council Crash (exploit) and burn: Securing the offensive cyber supply chain to counter China in cyberspace The private-sector zero-day exploit market is opaque, fragmented, and strategically important.
SR032 Legal Information Institute 22 CFR Part 120 - Purpose and Definitions 22 CFR Part 120 provides ITAR purpose and definitions.
SR033 Legal Information Institute 22 CFR Part 121 - The United States Munitions List 22 CFR Part 121 contains the United States Munitions List.
SR034 Bureau of Industry and Security Homepage | Bureau of Industry and Security BIS links to the Export Administration Regulations and advanced computing license guidance.
SR035 Legal Information Institute 15 CFR Part 734 - Scope of the Export Administration Regulations 15 CFR Part 734 describes the scope of the Export Administration Regulations.
SR036 The Wassenaar Arrangement Control lists Wassenaar publishes control lists for conventional arms and dual-use goods and technologies.
SR037 Booz Allen Hamilton Cybersecurity Booz Allen markets cybersecurity services to government and enterprise customers.
SR038 Leidos Cybersecurity Leidos markets cybersecurity capabilities.
SR039 Palantir Palantir Foundry documentation overview Palantir publishes documentation for its Foundry platform.
SR040 Anduril Transforming U.S. Defense Capabilities with Advanced Technology Anduril publicly markets advanced defense technology capabilities.
SR041 Washington Technology 2026 Top 100 Washington Technology publishes a Top 100 government contractors ranking.
SR042 SAM.gov Contract Opportunities SAM.gov is the U.S. government contract-opportunities portal.
SR043 USAspending.gov Government Spending Open Data USAspending.gov publishes U.S. government spending open data.
SR044 SBIR.gov About SBIR describes federal small-business innovation funding programs.
SR045 Defense Innovation Unit Tap Into a $100+ Billion Market DIU describes pathways for commercial technology firms to work with defense customers.
SR046 Bulletin of the Atomic Scientists The quest for cyber norms The article addresses the quest for cyber norms.
SR047 Citizens for Responsibility and Ethics in Washington CREW requests records on DOGE CREW says DOGE continues to operate with no clarity on its structure, staffing, budget, or operations.
SV001 U.S. News / Reuters Exclusive: DOGE alumni launch military cyber startup with $1.4 billion valuation Reuters reported Cathedral raised $160 million at a $1.4 billion valuation and is seeking U.S. government cyber contracts.
SV002 StartupFortune Four DOGE alumni raise at a $1.4 billion valuation for Cathedral The article says Cathedral has no known customers, no published product page, no public contract wins, and no inspectable revenue.
SV003 Economic Times ETCISO DOGE alumni launch military cyber startup with $1.4 billion valuation
SV004 Traders Union Cathedral raises funding for U.S. military cyber push at $1.4 billion valuation
SV005 CNBC Anduril doubles valuation as defense tech funding boom continues
SV006 Forbes Anduril’s $61 Billion Valuation Is A Bet On Pentagon Speed
SV007 Analytics Insight Anduril valuation reaches $61 billion after $5 billion Series H funding round
SV008 TechCrunch Anduril raises $5B, doubles valuation to $61B
SV009 TechCrunch Defense startup Shield AI lands $12.7B valuation after U.S. Air Force deal
SV010 Tech in Asia US defense AI startup Shield AI raises $2b at $12.7b value
SV011 TechFundingNews Shield AI locks $240M and hits $5.3B valuation
SV012 DroneDJ Shield AI lands $240M to expand drone autonomy tech
SV013 Stock Analysis Palantir Technologies revenue 2018-2026
SV014 Palantir Investor Relations Palantir reports Q1 2026 U.S. revenue growth and raises guidance
SV015 Business Wire Palantir reports Q1 2026 revenue growth
SV016 U.S. Securities and Exchange Commission Palantir Technologies Form 10-Q for quarter ended March 31, 2026
SV017 Last10K Palantir Technologies SEC filings page
SV018 CompaniesMarketCap Palantir market capitalization
SV019 CompaniesMarketCap Palantir revenue
SV020 CompaniesMarketCap Palantir P/S ratio
SV021 Yahoo Finance The defense tech boom has become a bubble—or it will be soon The piece argues that defense-tech capital is stampeding into companies whose valuations can run ahead of public products, contracts, and revenue.
SV022 AIN Ventures Is Defense Technology in a Bubble?
SV023 409A Valuation 409A valuation benchmarks for seed-stage startups
SV024 ValueAddVC Average pre-seed, seed and Series A round sizes
SV025 Zeni Series A valuations in 2026: what founders need to know
SV026 IdeaProof Startup fundraising benchmarks 2026
SV027 Andreessen Horowitz American Dynamism
SV028 Rebellion Defense Rebellion Defense company website
SV029 Anduril Anduril company website
SV030 Los Angeles Times Anduril to invest another $1 billion in California with Long Beach campus