Cathedral
DOGE 校友为美国军方打造 AI 网络平台;a16z 和 Sequoia 以 $1.4B 估值下注 $160M
Cathedral 同时拥有顶级投资人背书和创始团队触达美国防务网络安全买方的罕见通道;但收入前估值高达 $1.4B,政治、执行和验证风险都很尖锐。
封面要素
公司概况
Cathedral 是一家隐身国防科技公司,2025 年由四名前政府效率部(DOGE)工作人员创立,目标是把 AI 用于美国军方网络行动,同时覆盖进攻能力(发现并利用对手系统漏洞)和防御能力(保护美国军方网络)。在 Reuters 2026 年 7 月 22 日报道前数周,公司完成 $160 million 融资,投后估值 $1.4 billion,由 Andreessen Horowitz 和 Sequoia Capital 共同领投,两家均获得董事席位。公司没有披露产品、收入或合同,估值押注的是创始团队近期接触美国政府高层的能力,而不是任何商业化记录。
- 成立时间
- 2025-01-01
- 创始人
- Gavin Kliger, Luke Farritor, Marko Elez, Jack Stein
- 创立地点
- United States
- 总部
- United States (undisclosed)
- 产品
- AI 驱动的平台(未披露,且大概率涉密),拟支持美国军方网络行动,把进攻性漏洞发现和利用、防御性威胁检测和响应结合起来;公司也在寻求专用数据中心算力来运行这些行动。
- 客户
- 美国国防部、美国网络司令部、NSA 以及更广泛的情报共同体;作战目标集则是对手系统,尤其是中国。
- 商业模式
- 面向 AI 驱动的进攻和防御网络工具与服务,获取美国政府合同,预计路径包括 SBIR/STTR、OTA 以及直接合同 / 正式项目合同工具。
- 阶段
- Seed / Series A (early-stage, pre-revenue)
- 融资情况
- 在 2026 年 7 月 22 日前数周完成 $160 million 融资,投后估值 $1.4 billion,由 Andreessen Horowitz 和 Sequoia Capital 共同领投;两家均获得董事席位。
执行摘要
主要优势
- a16z 和 Sequoia 两家一线投资人背书,并都拿到董事会席位,估值 $1.4B
- 创始团队近期接触过政府高层,包括一名前 Pentagon 首席数据官;在重视买方关系的市场里,这种通道有价值
- 切入时点正好踩中升温的 defense-tech 和 AI-cyber 市场,White House Gold Eagle clearinghouse 等明确信号显示本届政府把它列为优先事项
主要风险
- 估值高达 $1.4B,但收入、产品和合同均未披露
- DOGE 旋转门和利益冲突暴露集中,容易引来国会、伦理和声誉审查,也高度敏感于政治变化
- 能力和牵引力主张大多涉密,无法独立验证;团队年轻,关键人和执行风险被进一步放大
未决问题
- 收入、授标合同、积压订单、烧钱速度和现金跑道均未披露,无法承销收入前溢价
- 公司没有官方披露(网站、产品文档、客户或员工数数据);几乎所有事实都追溯到一篇 Reuters 报道及其转载
- 进攻 / 防御网络能力,以及任何 DoD 采购牵引力,都没有独立验证
目录
01公司概览
1.1 身份、阶段与商业模式
公开记录里,Cathedral 更像一家隐身的 AI 军事网络安全公司,而不是一家常规已发布的软件供应商。Reuters 的 David Jeans 经 U.S. News 转载的报道,以及 The Next Web、Hoodline、Gizmodo、Cyber Daily 的后续报道,都一致描述这家公司由前 DOGE 执行人员创立,目标是扩展美国军方网络能力。因此,可支撑的商业模式很窄但重要:为 AI 驱动的进攻和防御网络行动赢得美国政府合同,潜在还要靠收购或数据中心合作拿到专用算力。受审阅来源没有披露总部;最强地理信号是靠近 Washington / Pentagon,而不是公司地址。我以中等置信度把 2025 年作为成立年份,因为 2026 年 7 月 Reuters 报道称,公司是在创始人 2025 年 DOGE 任期之后的近几个月启动。阶段应记录为隐身 / 私有未披露:融资规模很大,但产品文档、客户、收入和员工人数都缺席。[CO001, CO002, CO003, CO004, CO005, CO018]
| 指标 | 数值 / 状态 | 日期 | 置信度 | 来源 / 缺口 |
|---|---|---|---|---|
| 公司身份 | 隐身阶段 AI 驱动军事网络安全初创公司 | 2026-07 | 高 | Reuters 分发报道、TNW、Hoodline、Cyber Daily |
| 创立年份 | 根据 DOGE 任期后“近几个月推出”推断为 2025 年 | 2025 | 中 | Reuters 分发报道和报告生成日期逻辑 |
| 总部 | 未公开披露;仅有华盛顿 / 五角大楼邻近线索 | 2026-07-24 | 低 | 证据缺口 |
| 最新轮次 | $160 million | 2026-07 | 高 | Reuters 分发报道加后续报道 |
| 投后估值 | $1.4 billion | 2026-07 | 高 | Reuters 分发报道加后续报道 |
| 收入 / ARR | null;未披露公开收入或 ARR | 2026-07-24 | 中 | 已审阅公开来源缺口 |
| 客户 / 合同 | null;正寻求美国政府合同,未披露任何合同 | 2026-07-24 | 中 | 已审阅公开来源缺口 |
| 员工人数 | null;未披露公开员工人数 | 2026-07-24 | 中 | 已审阅公开来源缺口 |
Null 表示截至运行日期,抓取来源中未找到可用公开披露,不代表该指标为零。
[CO001, CO002, CO011, CO012, CO015, CO016]可投资性逻辑从 DOGE 相关创始人延伸到军事网络合同、专用算力和政治审查。
[CO001, CO003, CO004, CO005, CO013, CO014]1.2 创始人、领导层与关键人风险
公开点名的领导层集中在四位创始人:Gavin Kliger、Luke Farritor、Marko Elez 和 Jack Stein。公开尽调应把这份名单只视为 Reuters 报道过的创始人清单,而不是完整管理层或董事会名单。Kliger 是公开人物里战略重要性最高的一位,因为报道称他曾任五角大楼首席数据官,并参与美国国防部与 Anthropic 围绕 Claude 军事使用方式的争议。Farritor 带来 DOGE / GSA 降本经验和 SpaceX 实习背景;Elez 同时带来技术履历,以及来自财政部访问权限和社交媒体发帖事件的实质声誉 / 控制风险。Stein 被点名,但受审阅的免费公开记录给出的角色细节更少。这让 Cathedral 同时拥有创始人-市场匹配和关键人依赖:Cathedral 的准入故事之所以有价值,正因为它政治上敏感,也很难通过公司自有材料尽调。[CO006, CO007, CO008, CO009, CO010, CO021]
| 人物 | Cathedral 当前角色 | DOGE / 此前背景 | 创始人-市场匹配或风险 | 关键人物依赖 |
|---|---|---|---|---|
| Gavin Kliger | 联合创始人 | 前五角大楼首席数据官;卷入 Anthropic/Claude 军事用途争议 | 国家安全通道强;政治与 AI 治理风险暴露高 | 确认当前角色、股权、安全许可状态和继任深度 |
| Luke Farritor | 联合创始人 | 前 DOGE 员工;Reuters 称其曾任 SpaceX 实习生和 GSA 降本执行者 | 运营降本履历契合 DOGE 叙事,但商业网络安全角色尚无文件证明 | 确认职能归属和技术贡献 |
| Marko Elez | 联合创始人 | 前 SpaceX 与 DOGE/财政部执行者 | 技术和政府系统通道信号明确,但声誉和安全控制包袱重大 | 确认访问控制、合规监督和面向客户的角色 |
| Jack Stein | 联合创始人 | Reuters 及后续报道点名的前 DOGE 员工 | 创始人身份已获交叉印证;角色深度不如 Kliger/Elez 公开 | 确认职责、背景和决策权 |
创始人名单基于公开的 Reuters 来源包;不是完整高管名册或董事会名单。
[CO006, CO007, CO008, CO009, CO010, CO021]1.3 融资、治理与利益相关方图谱
第一章承载核心融资事实。最可靠的公开融资记录是:公司在 2026 年 7 月 22 日前不久完成 $160 million 融资,投后估值 $1.4 billion。Andreessen Horowitz 和 Sequoia Capital 领投,且均获得董事席位。没有发现 Cathedral 更早融资,因此 $160 million 是已披露累计融资额;如果存在未披露的 pre-seed 资本,它不等于经验证的生命周期总融资。治理披露比估值暗示的要薄:公开文件点名四位创始人和两位领投方董事席位,但没有完整董事会、投票权、期权池、创始人持股、老股转让或观察员权利。利益相关方图谱因此包括投资人、创始人、美国政府买方、潜在算力提供方以及政治 / 监管环境。a16z 的 American Dynamism 材料和 Sequoia 的 AI 布局让投资人匹配显得合理,但缺少公司确认,治理透明度仍是重大尽调问题。[CO011, CO012, CO013, CO014, CO020, CO031]
| 利益相关方 | 角色 | 控制权或经济重要性 | 证据状态 | 尽调要求 |
|---|---|---|---|---|
| Gavin Kliger / 创始人群体 | 创始人,且可能是运营控制中心 | 政府通道叙事和关键人物风险集中在创始人 | 多来源报道 | 索取股权结构表、投票权、雇佣协议和安全控制政策 |
| Andreessen Horowitz | 领投方并持有董事会席位 | 释放 American Dynamism 适配和风投验证信号 | Reuters 源头报道加官方 a16z 背景 | 确认董事代表、持股比例、后续储备和信息权 |
| Sequoia Capital | 领投方并持有董事会席位 | 顶级 AI 投资人,并拥有治理席位 | Reuters 源头报道加官方 Sequoia 背景 | 确认董事代表、持股比例和保护性条款 |
| 美国政府 / 五角大楼买方 | 目标客户和合同路径 | 收入论点依赖政府合同,而不是已披露的商业客户 | Reuters 源头报道和 AI 政府背景 | 索取管线、合同载体、采购状态和冲突审查 |
| 数据中心供应商或收购目标 | 潜在专用算力依赖 | 可能把 Cathedral 从纯软件推向资本密集型基础设施执行 | Reuters 源头报道 | 索取自建 / 外购分析、成本模型和交易对手身份 |
| DOGE / Trump 政府网络 | 政治和声誉背景 | 若国会控制权变化,通道优势可能变成合同审查风险 | Reuters 源头报道和负面 DOGE 报道 | 索取伦理审查、回避安排、游说披露和政府关系政策 |
这张利益相关方图谱有意混合经济所有者、潜在客户、基础设施依赖和政治背景,因为它们都会影响 Cathedral 是否可投。
[CO013, CO014, CO025, CO031, CO032, CO037]唯一硬 KPI 是融资指标;运营指标仍刻意留空,等待公司证据。
[CO011, CO012, CO013, CO014, CO015, CO016]1.4 封面指标、缺口与估值背景
封面指标要直白,不要修饰:估值是 $1.4 billion;已披露融资是 $160 million;收入、ARR、客户数、合同、试点、总部和员工人数在受审阅公开记录中均为 null。这个缺口不是普通私营公司的小麻烦,因为 Cathedral 已经按爆发式防务 AI 公司定价,却仍在商业证明上保持隐身。$1.4 billion 估值可以放在 Anduril 2026 年 $5 billion Series H、$61 billion 估值旁边看,但这个比较两面都成立。它说明投资人愿意为国防科技支付溢价,也凸显 Cathedral 的证据基础早得多:没有披露合同、没有产品文档、没有运营指标,也没有官方公司公告。后续章节不应只凭融资推断牵引力。正确的尽调路径是拿到管理层提供的管线细节、合同状态、收入确认政策、算力策略、安全控制和招聘计划。[CO012, CO015, CO016, CO017, CO018, CO033]
1.5 里程碑与政策背景
这条时间线离不开 DOGE、国防采购和 AI 网络政策。DOGE 由 2025 年 1 月行政令创建,随后与激进的联邦降本和超过 250,000 名员工离职联系在一起,并于 2026 年 7 月 4 日终止。几周后,Cathedral 以 DOGE 校友公司身份公开浮出水面,带着国防网络雄心和大额风险资本。同一时期还包括 Anthropic-Pentagon 争议,Kliger 被报道参与其中,这一点重要,因为它显示他靠近军用系统 AI 使用规则;还包括 Gold Eagle,即白宫 2026 年 7 月推出的 AI 赋能漏洞协调清算平台。这些事实不能证明 Cathedral 已有合同,但解释了为什么投资人可能相信时点异常有利。反过来,它们也制造反向风险:DOGE 旋转门叙事、Elez 过往争议,以及未来合同可能遭遇国会审查,都应该放进概览,而不是推迟到后面的风险章节。[CO019, CO025, CO026, CO027, CO028, CO029]
| 日期 | 事件 | 类型 | 金额 / 估值 / 状态 | 参与方 / 来源 | 重要性 |
|---|---|---|---|---|---|
| 2025-01 | DOGE 由行政令设立 | 监管 | U.S. Digital Service 围绕 DOGE 议程更名 / 重组 | 白宫 / DOGE | 奠定孕育创始团队的政府背景 |
| 2025 | DOGE 降本任期 | 负面 | Reuters 报道 250,000+ 人离开联邦雇员队伍 | Reuters / GovExec / Nextgov | 形成旋转门和公共部门扰动背景 |
| 2026-04 | DOGE 在财政部的访问控制遭批评 | 负面 | GAO 报告的安全控制缺口 | GovExec / Reuters 背景 | 对 Elez 和未来网络信任尽调具有实质意义 |
| 2026-04 to 2026-07 | Anthropic 与 Pentagon 关于军事 AI 使用的冲突升级 | 治理 | 据报道出现政府施压和承包商清退期限 | TNW、CNBC、Politico 与 Breaking Defense | 解释 Kliger 据报参与为何具有战略意义 |
| 2026-05 | Anduril 巨额轮次完成 | 融资 | $5B Series H,估值 $61B | TechCrunch / Forbes | Cathedral 溢价定价的防务科技估值基准 |
| 2026-06 | Special 这家 DOGE 校友初创公司浮出水面 | 融资 | a16z 支持的私营部门降本初创公司 | Reuters / TNW / Atlantic | 显示投资人对 DOGE 校友公司的兴趣以及负面怀疑 |
| 2026-07-01 | Gold Eagle 推出 | 监管 | AI 驱动的漏洞协调清算平台 | 白宫 / SecurityWeek / CSO | AI 网络漏洞协调的政策顺风 |
| 2026-07-04 | DOGE 正式结束 | 治理 | 到达自设终止日期 | Yahoo / Fiscal Times | 标志从联邦角色转向校友创业活动 |
| 2026-07-22 | Cathedral 融资被报道 | 融资 | $160M 轮次,投后估值 $1.4B | Reuters 分发报道 / TNW / Hoodline / Cyber Daily | 整个报告的核心融资事实 |
| 2026-07-22 | Cathedral 使命与算力计划被报道 | 产品 | AI 进攻 / 防御网络能力;探索专用算力 | Reuters 分发报道 / TNW / Hoodline | 定义产品论点和基础设施依赖 |
这是第一章的唯一正式时间线,把公司事件与解读这些事件所需的政策和可比融资事件合并呈现。
[CO002, CO005, CO011, CO012, CO026, CO027]Cathedral 的公开亮相接在 DOGE、AI 军事治理冲突和快速风投融资信号之后。
[CO002, CO005, CO011, CO012, CO026, CO027]1.6 图表
02市场分析
2.1 市场边界与现状替代方案
Cathedral 的规模测算应放在狭义国家安全网络市场里:面向 DoD 和情报共同体操作人员销售的 AI 赋能防御和进攻网络工具、漏洞发现、工作流软件及相关服务。这个边界有意排除广义企业安全、消费者网络安全、通用联邦 IT 服务和实体国防硬件,尽管这些类别能提供背景和可比估值。核心用户问题不是再买一个 SOC 工具,而是在满足涉密网络、零信任和指挥授权要求的同时,加速针对国家级对手的网络行动。因此,最强替代方案是内部 Cyber Command 和 NSA 能力、既有国防承包商、人工红队或渗透测试团队,以及 CISA 式民用防御卫生实践。这样的框架把 Cathedral 的机会绑定在任务网络工作流上,而不是泛化的网络安全 TAM。[CM001, CM002, CM005, CM006, CM007, CM021]
| 细分 / 类别 | 纳入支出 | 排除支出 | 买方 / 付款方 | 相关性 |
|---|---|---|---|---|
| AI 网络行动工具 | 自主漏洞发现、网络任务工作流、防御自动化、操作员 copilot | 面向民用企业销售的通用端点安全 | DoD 项目办公室、Cyber Command、IC 买方 | Cathedral 核心 SAM |
| 任务网络服务 | 专项实施、红队自动化、涉密网络部署支持 | 与网络行动无关的宽泛系统集成 | 军种网络组成部门和任务负责人 | 核心,但服务占比高 |
| 进攻性网络 / 网络战 | 依法授权且有预算的敏感工具和支持 | 非法活动、美国政府授权之外的出口管制销售 | 高度受限的 DoD/IC 赞助方 | 相邻;公开数据缺口 |
| 联邦民用网络安全 | 当产品可泛化时的 CISA 对齐自动化和零信任支持 | 常规 helpdesk、大宗 IT、消费者安全 | CISA 和民用机构 | 相邻选项,不是标准焦点 |
| 广义网络安全市场 | 仅作为估值和威胁趋势背景 | 大多数企业、消费者、MSP 和合规支出 | 商业 CISO 和机构 | 对 TAM 过宽 |
| 实体防务硬件 | 除打包进网络任务系统外,不纳入 | 无人机、传感器、武器平台、工厂 | 服务商和主承包商 | 排除;Anduril 可比项需打折 |
边界表把 Cathedral 的 AI 网络任务切口同广义网络安全和防务硬件分开;这些行是尽调用的部分分类,不是穷尽的 NAICS 市场普查。
[CM001, CM005, CM006, CM007, CM021, CM025]可寻址市场从宽泛的联邦网络和网络安全背景,收窄到向 DoD 和 IC 买家销售的军事 AI 网络作战产品。
金字塔只是市场边界口径,不是可相加的金额瀑布;只有顶部联邦背景和分析师估算行有公开数字支撑。
[CM001, CM003, CM021, CM025, CM026, CM037]2.2 多重市场规模测算口径
没有单一公开 TAM 数字足以支撑 Cathedral 的投资决策。最宽口径是美国联邦网络安全支出,它至少提供约 $26 billion 年度背景,但包含民用和基础设施支出,Cathedral 不应把这些算进核心 SAM。第二个口径是 DoD 和任务网络支出,但公开预算书无法完全拆出涉密进攻性网络项目。第三个口径是军用 AI:MarketsandMarkets 和 Grand View 都显示这是一个数十亿美元市场,但增长率和终点差异很大,因此区间比点估计更诚实。第四个口径是网络战市场研究,Mordor 的 2026 至 2031 年估算更接近 Cathedral 的待完成任务,但仍混合了产品、服务和终端用户。在 Cathedral 披露收入或中标前,SOM 口径应继续以合同管线为基础。[CM003, CM004, CM016, CM017, CM018, CM019]
| 发布方 | 年份 | 地理范围 | 数值 | CAGR | 方法论 | 置信度 | 局限 |
|---|---|---|---|---|---|---|---|
| OMB / 联邦预算口径 | 2026 | 美国联邦 | 年度网络预算背景:~$26B+ | n/a | 自上而下的联邦网络预算背景 | 中 | 包含 Cathedral 核心之外的民用和基础设施支出 |
| DoD 预算口径 | 2026 | 美国国防 | 低十几 $B 的网络 / 任务预算背景;精确科目部分涉密 | n/a | 国防预算材料加公开任务映射 | 低 | 无法隔离进攻性或涉密网络项目 |
| MarketsandMarkets 军事 AI | 2023-2028 | 全球 | USD 9.2B 至 USD 38.8B | 33.3% | 分析师市场预测 | 中 | 军事 AI 比网络行动更宽 |
| Grand View 军事 AI | 2024-2030 | 全球 | USD 9.31B 至 USD 19.29B | 13.0% | 分析师市场预测 | 中 | 终点值和 CAGR 不同于 MarketsandMarkets |
| Mordor 网络战 | 2026-2031 | 全球 | USD 40.13B 至 USD 52.27B | 5.43% | 分析师市场预测 | 中 | 混合产品、服务和终端用户 |
| Grand View 网络安全 | 2026-2033 | 全球 | 规模很大的广义网络安全市场 | 未使用 | 广义行业背景 | 低 | 纳入企业和消费者安全,夸大 Cathedral SAM |
| Cathedral 公开 SOM | 2026 | 美国国防 | 无已核验公开收入或合同 | n/a | 尽调缺口锚点 | 高 | 需要公司管线、授标或客户证明 |
数值做了四舍五入,并有意保留为不同口径,因为分析师范围、时间跨度和纳入标准不可互换。
[CM003, CM004, CM016, CM017, CM018, CM019]公开估算支撑数十亿美元级机会,但范围和预测年限差异很大。
所有行均以 USD 十亿计,但不能直接相加;图表比较公开市场规模口径和一个经公开验证的 SOM 锚点。
[CM003, CM016, CM017, CM018, CM019, CM037]2.3 买方、用户、付款方与采用路径
买方图谱是多方结构。DoD 项目办公室和各军种网络组件可能掌握预算;Cyber Command、NSA 合作方和任务团队可能是用户和技术评估方;合同官和安全授权方决定试点能否变成真实支出。Cathedral 最可能的采用路径不是消费者式发布,而是分阶段政府销售:通过 SBIR 或 DIU 式入口切入,在其他交易授权(OTA) 或类似机制下做原型,再在任务价值、安全控制和资金都对齐后转成 FAR 合同或正式项目。这条路径有上行空间,因为成功工具可以嵌入任务工作流;但它也让公开牵引力很难观察。SAM.gov、USAspending 和 DoD 合同发布是有用监测器,却不是涉密网络工作的完整真相。[CM011, CM012, CM013, CM014, CM015, CM029]
| 细分 | 买方 | 用户 | 付款方 | 工作流 | 预算所有者 | 采用触发因素 |
|---|---|---|---|---|---|---|
| DoD 网络项目办公室 | 项目经理 | 任务网络操作员 | DoD 拨款科目或项目办公室 | 采购并集成网络能力 | 军种或国防机构 PEO/PM | 有资金的需求加安全审批 |
| Cyber Command 单元 | 作战司令部 | 网络任务部队 | DoD 作战预算或赞助项目 | 规划并执行行动 | 司令部或支援军种组成部门 | 速度和规模上的作战需求 |
| NSA / 情报协作 | 技术发起方 | 分析人员和网络防御人员 | IC 或联合发起方 | 威胁情报、漏洞、协作 | 机构任务负责人 | 外国威胁需求 |
| 军种网络单位 | 军种领导层或 PEO | 军种网络团队 | 陆军 / 海军 / 空军 / 太空军网络预算 | 将工具部署到军种网络 | 军种单位或 PEO | 演习、事件或现代化缺口 |
| 联邦民用相邻客户 | CISA 或机构 CISO | 民用机构安全团队 | 机构 IT / 网络预算 | 防御自动化和零信任 | 机构 CIO / CISO | 合规和韧性要求 |
| 创新渠道试点 | DIU / SBIR 发起方 | 试点用户 | 原型或 R&D 资金 | 评估商业技术 | 创新办公室和任务伙伴 | 成功演示或紧急作战需求 |
国防网络采购里,买方、用户和付款方常常不是同一方;各行是分群地图,不是客户清单。
[CM002, CM011, CM012, CM013, CM014, CM015]国防网络销售需要对齐任务用户、预算持有人和签约权限方。
[CM002, CM011, CM012, CM030, CM039, CM040]军事网络采用路径从市场兴趣到经验证的 Cathedral 经常性收入,收窄得很快。
[CM011, CM012, CM013, CM014, CM030, CM031]2.4 增长驱动因素
需求故事靠四个驱动因素支撑。第一,中国和其他国家级网络威胁让网络行动的速度和规模具有战略重要性。第二,DARPA 的 AI Cyber Challenge 验证了 AI 可以自动化漏洞发现和修复的具体想法,这与 Cathedral 声称的任务空间接近。第三,国防科技风险投资人已经奖励那些承诺国家安全现代化的公司,Anduril 是该类别最显眼的可比公司,尽管它的自治和硬件画像不同于 Cathedral 的网络软件切口。第四,政府效率推进可能偏好用软件和 AI 自动化替代稀缺持证劳动力。这些驱动因素支撑了大机会叙事,但不能证明采购转化、重复使用,或买方愿意授权自主进攻性网络工作流。[CM010, CM022, CM023, CM024, CM032, CM033]
| 驱动因素 / 约束 | 方向 | 时点 | 影响 | 尽调问题 |
|---|---|---|---|---|
| 国家级网络威胁和中国竞争 | 上行 | 当前 | 推高军方对网络速度和自动化的紧迫感 | 找出与优先威胁挂钩的已获资助项目 |
| AI 漏洞发现和修复 | 上行 | 当前 | 支撑 Cathedral 产品论点 | 验证产品能力和安全控制 |
| 国防科技创投热度 | 上行 | 当前 | 说明资本可得,且有高估值可比项 | 将网络软件可比公司与硬件自主系统可比公司分开 |
| 效率压力和有密级资质人才短缺 | 上行 | 近期 | 只要可信,就利好自动化 | 测试买方替换人工流程的意愿 |
| 采购和合同转化 | 下行 | 18-24 个月以上风险 | 延后收入、抬高烧钱速度 | 按具名办公室梳理 SBIR / OTA / FAR 路径 |
| ATO、零信任、NIST 和 AI 治理 | 下行 | 当前 | 即便有试点兴趣,也可能卡住部署 | 确认认证路径和涉密环境 |
| 密级和许可限制 | 下行 | 当前 | 减少公开证据,拖慢上线 | 审查有密级资质人员、设施和发起方证据 |
| 既有承包商锁定 | 下行 | 当前 | 抬高合作或替换门槛 | 核查主承包商关系和重新竞标窗口 |
时点条目是基于公开采购和合规证据得出的尽调假设;一旦拿到 Cathedral 特定管线证据,应予替换。
[CM008, CM010, CM022, CM023, CM029, CM031]2.5 约束、反向观点与尽调缺口
反向市场观点很直接:Cathedral 可能按一代一遇的国防科技平台估值,却在争夺一个比表层 TAM 暗示更小、更慢、更涉密的支出池。把 ATO、零信任对齐、安全许可、数据处理和合同机制纳入后,采购周期可能拉长到 18-24 个月甚至更久。既有承包商也有中标历史、持证人员和合同基础设施;隐身初创公司要么自己搭建,要么围绕它们合作。公开来源尚未验证 Cathedral 的收入、客户、合同、ATO 状态或涉密部署足迹。因此下一步尽调应落到账户层面:识别有资金的项目办公室、活跃招标、赞助用户、安全认证路径,以及公司销售的是工具、服务还是任务结果。[CM008, CM027, CM031, CM036, CM037, CM044]
2.6 图表
03竞争格局
3.1 竞争版图
Cathedral 进入的是国防 AI 和网络市场,相关竞争集比字面上说“军事网络安全”的初创公司更宽。第一圈是国防科技 AI 软件和自主系统公司:Anduril、Palantir、Shield AI、Rebellion Defense、Vannevar Labs 和 Two Six Technologies,它们争夺国防现代化预算、国家安全可信度和 AI 原生任务工作流。第二圈是网络垂直公司:Horizon3.ai、XBOW、Dreadnode、RunSafe、作为失败先例的 IronNet,以及漏洞交易生态。第三圈是既有政府承包商——Booz Allen、Leidos、SAIC、CACI、Peraton、ManTech 和 Parsons——它们已经握有合同工具、持证员工和项目关系。Cathedral 被报道的切口,是前 DOGE 政府准入与进攻加防御 AI 网络任务的组合;弱点在于公开来源展示的是计划,而不是已证明的合同。[CP001, CP002, CP003, CP004, CP005, CP039]
| 公司 | 类别 | 规模 / 融资信号 | 攻防重点 | DoD / 政府关系 | 相对 Cathedral 的差异 |
|---|---|---|---|---|---|
| Anduril | 国防科技 AI 初创公司 | $5B Series H 后估值约 $61B | 国防自主系统 / 指挥控制,不只做网络 | 报道显示有战场管理和国防合同 | 制造能力和 Lattice 平台大得多;网络纯度较低 |
| Palantir | 上市国防 AI 平台 | 2024 年收入 $2.9B;政府业务占 55% | AIP / Gotham 决策和数据平台 | 国防、情报和盟国政府长期使用 | 既有地位和审计控制很深;初创速度光环较弱 |
| Shield AI | 国防自主系统初创公司 | 据报道 2026 年估值 $12.7B | 飞机自主系统和 AI 驾驶员 | Hivemind 已被美国及盟军使用 | 自主系统有任务验证;与网络直接重叠较少 |
| Rebellion Defense | 国防 AI / 关键资产软件 | 审阅材料中没有可靠当前估值 | AI 融合和资产保护 | 定位国防市场,但合同深度不清 | 邻近情报护盾定位;状态仍不够透明 |
| Vannevar Labs | 国防 AI 软件 | 私营;未保留公开估值 | 国家安全软件 / 威慑 | 面向作战人员和联邦用户 | 更像相邻情报工作流,而非明确网络行动 |
| Two Six Technologies | 国防 AI 和网络承包商 | 私营承包商;参与 $4B DTRA IDIQ 授标 | 网络、信息行动、智能体式 AI | 点名 DoD、SOCOM、Cyber Command、DARPA | 客户证明更足、合同站位更稳;隐身创业叙事的上行空间较小 |
| Horizon3.ai | 自主渗透测试初创公司 | 2026 年声称覆盖 5,200+ 家组织 | 靠攻击性测试做防御验证 | 声称有政府和关键基础设施用例 | 公开产品证明更多;军事攻击任务叙事较弱 |
| XBOW | 自主攻击安全初创公司 | $120M Series C 后估值 >$1B | 攻击安全和持续测试 | 通过 Accenture 走企业 / 伙伴路线 | 最接近的 AI 攻击网络初创公司;DoD 通道不够明确 |
| Dreadnode | 攻击型 AI 安全初创公司 | 2025 年 Series A 约 $14M | AI 红队基础设施和研究 | 有政府潜力,但审阅材料未证明 | AI 原生攻击研究;规模小得多 |
| RunSafe Security | 网络韧性初创公司 | 2024 年 Series B $12M | 防御加固 / 内存安全 | 关键基础设施和安全关键型叙事 | 防御细分市场;与攻击任务重叠较低 |
| Booz Allen、Leidos、SAIC、CACI、Peraton、ManTech 与 Parsons | 既有承包商 | 联邦头部承包商排名和多年期网络合同工具 | 攻击、防御、韧性和系统集成 | 已建立的联邦合同工具和项目关系 | 渠道和信任占优;AI 原生初创 DNA 较弱 |
| 漏洞利用经纪商 / 攻击网络供应商 | 专业化供应链 | 市场不透明;价格和供给看不清 | 攻击性漏洞利用开发和经纪 | 政府客户可购买特定能力 | 可替代 Cathedral 任务中的部分组件,不是平台同业 |
规模信号采用每个竞争对手已审阅公开信息中最强的数据点;未获得直接支持时,不推断私营公司估值。
[CP006, CP008, CP009, CP011, CP012, CP013]Cathedral 落在 AI 原生 / 攻防一体象限,但 DoD 既有项目地位弱于在位厂商,产品证据也落后于网络安全专精玩家。
序数位置基于公开定位、合同证据和产品重心;未见任何来源报告这些坐标。
[CP003, CP005, CP006, CP008, CP011, CP016]3.2 国防科技 AI 同类公司
国防科技 AI 同类公司并不是干净的一对一产品比较,但它设定了 Cathedral 必须越过的门槛。Anduril 在 $5 billion Series H 和 $61 billion 估值之后,是风险资本支持的规模异类,公开报道把 Lattice 与导弹防御战斗管理联系起来。Palantir 嵌入体制更深:其 10-K 描述 Gotham、AIP、Foundry 和 Apollo,Gotham 服务国防和情报用户超过十年,政府客户贡献了 2024 年大部分收入。Shield AI 先做自主系统而不是先做网络,但其 Hivemind AI 飞行员和 2026 年估值跃升说明,一旦 AI 系统获得任务验证,资本定价可以多快抬升。Rebellion 和 Vannevar 展示相邻国防软件定位;Two Six 规模更小却高度相关,因为它在客户集中点名 U.S. Cyber Command、DARPA 和 DoD。[CP006, CP007, CP008, CP009, CP010, CP011]
| 同业 | 主要产品重心 | 融资 / 公开规模 | DoD 或盟军证明 | Cathedral 启示 |
|---|---|---|---|---|
| Anduril | 基于 Lattice 的国防系统和自主能力 | $5B Series H,估值 $61B | 陆军和导弹防御报道 | 设定 Cathedral 目前无法匹配的创投规模标杆 |
| Palantir | AIP、Gotham、Foundry、Apollo | 2024 年收入 $2.9B;政府占 55% | 国防和情报使用超过十年 | 最强的软件既有势力对照 |
| Shield AI | Hivemind AI 驾驶员和自主飞机 | 据报道 2026 年估值 $12.7B | 美国及盟军;涉及空军的交易 | 说明任务证明能迅速抬高估值 |
| Rebellion Defense | 关键资产情报护盾 | 私营;未保留规模数据点 | 只有公开国防定位 | 在判断其已经停摆或被收购前,需要验证 |
| Vannevar Labs | 国家安全软件和威慑 | 私营;未保留规模数据点 | 国防和联邦用户定位 | 相邻预算竞争者 |
| Two Six Technologies | AI 指挥、网络、信息行动 | 私营;DTRA IDIQ 参与者 | 点名 DoD、SOCOM、Cyber Command、DARPA | 更接近 Cathedral 可能遭遇的服务 / 产品混合体 |
该矩阵把国防 AI 预算竞争者与网络专项产品竞争者分开;不是每家公司都销售同一工作流。
[CP006, CP007, CP008, CP009, CP010, CP011]防务 AI 同行之间差异最大的是产品成熟度、政府验证和网络安全针对性。
定性值汇总已审阅来源证据;未知项明确标注,不靠猜测填补。
[CP001, CP003, CP006, CP008, CP009, CP011]3.3 网络安全垂直竞争者与漏洞利用市场背景
网络安全垂直竞争者比多数国防平台更贴近 Cathedral 的产品。Horizon3.ai 的 NodeZero 提供自主渗透测试,并公开宣称采用情况;XBOW 围绕自主进攻性安全在 2026 年拿到大额资本,并与 Accenture 建立战略关系;Dreadnode 正在为安全智能体和进攻性 AI 研究构建 AI 基础设施。RunSafe 是另一类防御加固对手,聚焦内存安全和关键基础设施,而不是进攻性网络行动。漏洞经纪商和进攻性网络中介并非常规 SaaS 竞争者,但它们重要,因为政府买方可以通过不透明供应链获取工具、人才和能力,而不是购买一个新平台。因此,Cathedral 最大的产品层面风险不是某一个克隆者,而是一组自动化渗透测试、漏洞供给、红队工具和内部网络团队,可以替代其承诺任务中的若干部分。[CP014, CP015, CP016, CP017, CP018, CP019]
| 公司 / 替代项 | 类别 | 攻击能力 | 防御能力 | 公开牵引信号 | 相对 Cathedral 的差异 |
|---|---|---|---|---|---|
| Horizon3.ai NodeZero 产品 | 自主渗透测试 | 用攻击性测试找到可利用路径 | 验证和修复工作流 | 声称覆盖 5,200+ 家组织 | 产品证明更强;军事通道不够清晰 |
| XBOW | 自主攻击安全 | 核心聚焦自主黑客 / 测试 | 通过伙伴路线做暴露面管理 | 估值 >$1B;Accenture 投资 | 最接近的攻击型 AI 同业 |
| Dreadnode | 攻击型 AI 安全基础设施 | AI 安全智能体和攻击研究 | AI 模型和安全测试基础设施 | 据报道 Series A $14M | 更偏研究原生,规模更小 |
| RunSafe Security | 网络韧性 / 内存安全 | 直接攻击重叠有限 | 内存安全和攻击面缩减 | 据报道 Series B $12M | 防御细分市场,可能互补 |
| IronNet | 已倒闭的集体防御网络初创公司 | 历史上的网络威胁分析卖点 | 集体防御 | 破产并关闭 | 警示性失败先例 |
| 漏洞利用经纪商 | 攻击网络供应链 | 零日 / 漏洞利用采购 | 无直接能力;支持行动 | 市场不透明且有中介风险 | 攻击任务的组件替代项 |
| 内部网络团队 | 现状 / 内部自建 | 内生攻击网络行动 | 内生防御和 SOC 职能 | 涉密 / 不公开 | 可在没有 Cathedral 的情况下自建或采购组件 |
| 主承包商任务单 | 现状 / 外包给既有承包商 | 可为网络行动项目配员 | 托管防御、合规、集成 | 海军、陆军、Alliant 类合同工具 | Cathedral 必须替换的默认采购路径 |
能力单元格概括已审阅公开定位,不是技术基准;涉密攻击能力必然观察不足。
[CP014, CP015, CP016, CP017, CP018, CP019]网络安全初创公司覆盖攻防连续谱的不同切片,Cathedral 仍需证明自己的集成广度。
矩阵为定性判断,因为公开来源不披露机密防务网络能力深度。
[CP003, CP016, CP019, CP021, CP022, CP024]3.4 既有承包商与分发能力
既有承包商威胁由分发主导。Booz Allen、Leidos、SAIC、CACI、Peraton、ManTech 和 Parsons 都营销网络能力,公开合同报道也显示这些名字出现在海军网络空间行动支持、陆军网络战工作和 GSA Alliant 3 周围。这一点重要,因为 Cathedral 想要的买方——美国军方及相邻国家安全机构——已经有路径采购网络行动、系统集成、AI 和托管服务,不必等一家新的隐身初创公司成熟。Cathedral 仍可胜出,只要它提供阶跃式 AI 优势,或创始人把关系转化为快速试点;但现实销售门槛很高:既有厂商懂合规、持证人员配置、续标、抗议和项目办公室节奏。新进入者要么与它们合作,要么在狭窄工作流内替代它们,要么足够快成为主承包商,撑过采购延迟。[CP027, CP028, CP029, CP030, CP031, CP032]
| 既有承包商 | 公开网络 / AI 线索 | 合同关系线索 | 对 Cathedral 的竞争危险 | Cathedral 可能回应 |
|---|---|---|---|---|
| Booz Allen | 网络防御提速到 AI 速度的叙事 | 陆军网络战重新竞标和 Top 100 规模背景 | 很高 | 先合作,或先攻窄 AI 网络工作流 |
| Leidos | 攻击、防御和网络韧性表述 | 联邦网络合作伙伴关系和 Top 100 规模背景 | 高 | 证明主承包商无法快速配员的差异化 AI 能力 |
| SAIC | 联邦网络安全和 IT 现代化 | GAO IT / 网络现代化和 Top 100 规模背景 | 中高 | 在初创速度比广泛集成更重要的场景竞争 |
| CACI | AI / ML 赋能的网络行动 | Top 100 和联邦网络定位 | 高 | 证明更好的模型性能或任务自动化 |
| Peraton | 国家网络任务定位 | 海军网络空间选项;陆军网络争议 | 高 | 借创始人通道,在重新竞标周期前拿到试点 |
| ManTech | 网络任务支持定位 | 陆军网络争议;Top 100 背景 | 中高 | 用 AI 原生产品而非人力工时做差异化 |
| Parsons | 关键基础设施和活动网络安全 | 海军网络空间选项和 Top 100 背景 | 中 | 初期避开宽泛基础设施网络市场 |
危险评级评估的是渠道力量,不代表一对一产品优劣。
[CP027, CP028, CP029, CP030, CP031, CP032]合同载体和在位厂商排名说明,Cathedral 的进入市场门槛和产品能力一样关键。
[CP004, CP009, CP030, CP031, CP032, CP033]3.5 差异化耐久性判断
Cathedral 的差异化可信但未证实。多头情形是,一个 AI 原生团队带着近期政府运营准入,能比传统承包商更快把进攻和防御网络工作流结合起来,同时避开自主渗透测试供应商或内存安全工具较窄的产品定义。空头情形在今天的证据上更强:公司没有披露收入、没有点名合同、没有公开产品演示,也没有可与 Palantir、Anduril、Shield AI 或主承包商相比的运营历史。IronNet 说明,即使有顶级政府履历和网络雄心,产品-市场匹配和收入质量没有兑现时仍会失败。因此,正确尽调姿态是把创始人准入视为入场券,而不是护城河。只有当 Cathedral 证明经安全许可的部署、可重复政府采购和可防御的专有网络 AI 能力,护城河才成立。[CP004, CP005, CP014, CP040, CP041, CP043]
| 护城河假设 | 支持证据 | 威胁 | 严重性 | 尽调问题 |
|---|---|---|---|---|
| 创始人政府通道 | Reuters 报道其与 Pentagon 和国家安全圈有联系 | 通道可能受到审视,也可能随政治变化衰减 | 高 | 列出已签试点、合同路径、牵头方和采购权限 |
| AI 原生攻防一体网络平台 | 报道中的使命覆盖进攻与防御网络行动 | 没有公开产品、基准或部署证明 | 高 | 展示实时工作流,并给出相对 XBOW/Horizon3 的技术评估 |
| 国防买家紧迫性 | 大型网络与 AI 合同载体已掌握在传统承包商手中 | 紧迫需求可能流向主承包商,而不是创业公司 | 高 | 指明预算科目,并说明现有合同载体为何解决不了 |
| 进攻性网络能力供给 | 漏洞利用 / 中介市场存在 | 供应链不透明、法律风险和采购效率低 | 高 | 说明自研 / 外采政策、授权和合规控制 |
| 相对传统承包商的潜在速度 | 创业公司迭代可能快过系统集成商 | 老牌承包商有 20 年关系和持证人员 | 高 | 展示部署时间表和保密资质计划 |
| 顶级投资人的品牌和资本 | 由 a16z 和 Sequoia 领投的 $160M 融资 | IronNet 说明声望不等于可持续收入 | 中高 | 给估值信用前,要求收入质量和续约证据 |
Cathedral 仍处隐身状态,且没有披露合同或收入,因此本风险登记表有意把证据缺口按风险加权。
[CP001, CP002, CP003, CP004, CP005, CP034]创始人资源和 AI 原生任务得分较高,但公开产品证据和合同证据是关键缺口。
[CP001, CP003, CP004, CP005, CP014, CP041]3.6 图表
04财务
4.1 资本结构与当前财务状态
Cathedral 的财务章节从一个简单但异常激进的资本结构开始:受审阅的 2026 年 7 月报道显示,公司以 $1.4 billion 投后估值完成 $160 million 主融资,由 Andreessen Horowitz 和 Sequoia Capital 领投。按纯主融资轮计算,这意味着约 11.4% 新钱稀释,投前估值约 $1.24 billion。关键承销点不是算术,而是顺序。公开来源把 Cathedral 描述为由四名前 DOGE 工作人员创立的隐身军事网络初创公司,但没有披露收入、ARR、已确认积压订单、毛利率、付费客户或已授予合同。因此,本章把 revenueRunRate 和 ARR 视为 null,而不是很小。$160 million 融资足以资助严肃的产品开发和项目捕获,但估值靠的是创始人准入、投资人信念和国防 AI 市场胃口,而非已披露财务牵引力。[CI001, CI002, CI003, CI004, CI005, CI006]
| 项目 | 公开数值 / 状态 | 衍生财务判断 | 质量 | 尽调要求 |
|---|---|---|---|---|
| 一级融资 | 2026 年 7 月 $160M 融资 | 所审阅材料中唯一披露的融资额 | 高 | 确认总募资额与净到账额,以及是否包含老股转让 |
| 投后估值 | $1.4B | 未披露收入,却给出近似后期项目的估值 | 高 | 索取股权结构表和完全稀释股数 |
| 隐含新钱稀释 | ~11.4% | 在期权池或老股调整前,$160M / $1.4B | 中 | 确认期权池扩张和投资人优先权 |
| 隐含投前估值 | ~$1.24B | $1.4B 减去 $160M 一级融资所得 | 中 | 确认估值是否按完全稀释口径的投后估值 |
| 已披露融资总额 | $160M | 保留来源中未找到 Cathedral 既往融资披露 | 中 | 询问 SAFE / 可转债历史和创始人股权授予 |
| 收入运行率 / ARR | 从公开证据看仍属收入前阶段 | 中 | 索取当前 ARR、试点、递延收入和在手订单 | |
| 已披露合同 | 未发现具名已授予合同、OTA、SBIR、CRADA 或客户 | 中 | 按机构索取管线和授标文件 |
null 单元格表示抓取来源包中没有公开披露,不代表经济价值为零。稀释和投前估值行由报道的融资条款推算。
[CI001, CI002, CI003, CI004, CI005, CI006]| 缺失指标 | 重要性 | 当前公开状态 | 严重程度 | 尽调路径 |
|---|---|---|---|---|
| ARR / 收入运行率 | 判断估值是否有收入支撑 | 阻断项 | 索取已确认收入、ARR、试点和递延收入明细 | |
| 具名合同 / 客户 | 验证从接触到采购的路径 | 阻断项 | 索取授标文件、OTA、SBIR、CRADA 和机构牵头方 | |
| 按合同载体拆分的毛利率 | 区分软件式上行与服务或算力转售 | 重大 | 索取 FFP、成本加成、OTA 和订阅线的预计毛利率 | |
| 月度消耗与现金余额 | 将 $160M 融资所得换算成现金跑道 | 重大 | 索取交割后现金、薪酬、算力、安全和投标拓展支出 | |
| 算力承诺 | 判断数据中心策略更偏资本开支还是运营开支 | 重大 | 索取数据中心意向书、资本开支预算、租约条款和最低承诺 | |
| 管线转化时间 | 国防销售中测算 CAC / 回本替代指标所必需 | 重大 | 按机构、阶段、载体和预计授标日期索取管线 |
所有 null 都是明确证据缺口。不应在报告元数据或估值模型中把它们转成零值。
[CI007, CI008, CI010, CI011, CI022, CI023]据报道的轮次数学从 $1.24B 隐含投前估值,加上 $160M 新股融资,桥接到 $1.4B 投后估值。
瀑布图仅使用报道的轮次条款,不建模清算优先权、老股交易、认股权证或期权池变化。
[CI001, CI004, CI005, CI006]4.2 收入路径与合同经济性
最现实的收入路径是分阶段推进,而不是 SaaS 线性增长。Cathedral 可以争取非稀释性 SBIR 或 STTR 资助,通过 OTA 式渠道做原型,与联邦实验室开展 CRADA 合作,参与 DIU 式商业技术征集,最终进入 IDIQ 任务订单或正式项目采购。每条路径都会带来不同的单位经济性后果。若 Cathedral 把网络 AI 能力产品化并控制交付成本,固定总价工作可以带来更好上行空间,但也把成本超支风险压到承包商身上。成本补偿型工作能降低早期 R&D 现金转化风险,却通常限制利润率上行,也较难证明产品可重复性。一旦任务所有者围绕某个工具标准化,IDIQ 工具和任务订单可以产生黏性收入,但订单流不会自动到来。没有披露管线时,CAC 和回本周期应通过采购周期长度、投标负担、安全认证工作量,以及从原型转生产的转化率来代理。[CI012, CI013, CI014, CI015, CI016, CI017]
| 合同载体 / 模式 | 收入机制 | 毛利 / 现金流影响 | Cathedral 可能用途 | 披露状态 |
|---|---|---|---|---|
| SBIR / STTR | 非稀释性研发资金和商业化桥梁 | 有助早期验证;不是可规模化 ARR 的证明 | 量产授标前的网络 AI 原型工作 | Cathedral 未披露授标 |
| OTA / 原型路径 | 标准 FAR 合同模式之外的原型协议 | 可加快采用,但仍需转入生产合同 | 任务原型或快速能力测试 | Cathedral 未披露 OTA |
| CRADA | 联邦实验室与非联邦实体合作 | 在不给公司政府资金的情况下获得验证 | 技术合作或测试环境 | Cathedral 未披露 CRADA |
| 固定总价 | 交付物或服务按固定价格付款 | 产品化后上行更大;承包商承担成本超支风险 | 未来打包网络工具或托管能力 | 未披露定价 |
| 成本补偿 | 在上限内报销可允许已发生成本 | 亏损风险更低,但毛利上行有限,产品证明也更弱 | 早期研发或定制国防项目 | 未披露合同 |
| IDIQ / 任务订单 | 伞形合同载体,下设具体工作订单 | 任务订单反复出现则粘性强;收入只在下单后到来 | 正式立项项目或全机构网络合同载体 | 未披露合同载体 |
该表描述与财务相关的合同路径,不是 Cathedral 已有合同。每一行都只是潜在路径,因为 Cathedral 没有公开披露任何授标。
[CI012, CI013, CI014, CI015, CI016, CI017]Cathedral 的可能财务路径,要先从原型验证走到合同载体,之后才有可承销的可持续项目收入。
[CI017, CI018, CI019, CI020, CI021, CI041]4.3 资本强度、烧钱速度与资金续航
算力策略是最大的财务摆动因素。CityBiz、EquityPandit 和 Startup Fortune 都报道 Cathedral 正在探索收购或合作建设数据中心,这会让公司偏离纯可变云成本画像。更广泛的 AI 基础设施来源也支持认真看待这一点:Goldman Sachs 预计 AI 将大幅推高数据中心电力需求,DOE 预计国内数据中心能耗到 2028 年翻倍或增至三倍,Epoch AI 估算前沿训练算力约以每年 4x 到 5x 增长。没有任何来源给出 Cathedral 实际算力账单,所以本章采用情景,而不是假装精确。$160 million 融资在每月烧钱 $4 million 时可支撑约 40 个月,在 $8 million 时约 20 个月,在 $12 million 时约 13 个月;单笔 $40 million 算力支出会显著缩短每一种情形。[CI009, CI033, CI034, CI036, CI037, CI038]
| 情景 | 月度消耗 / 支出假设 | $160M 可支撑现金跑道 | 必须成立的前提 | 风险备注 |
|---|---|---|---|---|
| 精简隐身开发 | 月度消耗 $4M | 约 40 个月 | 小团队、租用云、有限投标拓展支出 | 可能低估持网络保密资质招聘和算力开销 |
| 基准国防 AI 开发 | 月度消耗 $8M | 约 20 个月 | 工程、安全、投标拓展和云开销均有一定规模 | 下一轮融资前需要看到合同转化 |
| 重算力 / 重投标拓展 | 月度消耗 $12M | 约 13 个月 | 大规模持证团队,加上模型训练和投标负担 | 收入延后会快速触发下一轮融资需求 |
| 专用算力冲击 | 一次性支出 $40M,加月度消耗 $8M | 支出后约 15 个月 | 数据中心收购 / 合作需要现金承诺 | 没有收入时会实质改变现金跑道 |
| Anduril 式规模参照 | 大型设施和规模化后的预计经营亏损 | 不可直接比 | 收入、合同可与重度亏损并存 | 说明规模化后资本强度仍会持续 |
现金跑道各行是基于报道融资所得做的情景测算,不是公司指引。测算排除了税费、融资成本、营运资本时点以及任何债务 / 项目融资结构。
[CI009, CI029, CI031, CI033, CI034, CI036]$160M 轮次可能意味着多年现金跑道,也可能在月烧钱和算力承诺不同的情况下只够一年多。
范围仅为示意,用现金简单除以烧钱速度;并非公司指引。
[CI036, CI037, CI038, CI039, CI040, CI045]4.4 国防科技可比公司与收入轨迹
更好的可比经验是,国防科技收入可以扩张,但通常要经历多年产品化、采购胜利和设施建设。Palantir 是成熟上市软件可比公司:其 SEC 文件显示收入达到数十亿美元,并有重大政府贡献,包括 2025 年政府收入增长和显著美国政府收入。Anduril 是私营国防科技规模可比公司:Sacra 估算其 2025 年收入达到 $2.2 billion,预计 2026 年达到 $4.3 billion,并报道其以 $61 billion 估值完成 $5 billion Series H,同时预计 2026 年经营亏损。Shield AI 规模更小但相关,是自主系统可比公司;Sacra 估算其截至 2025 年 3 月年度收入约 $300 million。Cathedral 比这三家公司都早得多:其估值像后期国防科技溢价,已披露收入基础却像种子期证据缺口。[CI025, CI026, CI027, CI028, CI029, CI030]
| 公司 | 最新公开 / 分析师收入指标 | 估值 / 融资指标 | 对 Cathedral 的财务启示 | 与 Cathedral 的差距 |
|---|---|---|---|---|
| Cathedral | 以 $1.4B 投后估值融资 $160M | 未披露收入前先拿到大额资金 | 未披露 ARR、合同、毛利或在手订单 | |
| Anduril | Sacra 估计 2025 年收入 $2.2B,并预测 2026 年收入 $4.3B | 据 Sacra,H 轮融资 $5B,估值 $61B | 国防科技估值可由大额收入和合同支撑 | Cathedral 缺少同等收入证明 |
| Palantir | 2025 年收入约 $4.48B;政府业务收入 2025 年增长 53% | 上市公司申报级财务披露 | 政府软件可扩至数十亿美元收入 | Cathedral 缺少分部收入和公开申报 |
| Shield AI | Sacra 估计截至 2025 年 3 月年度收入约 $300M,隐含 2026 年收入 >=$540M | Sacra 给出的估值指标为 $2.3B | 自主国防创业公司在 IPO 规模前也能拿出收入 | 公开层面 Cathedral 仍属收入前 |
| Anduril 资本开支视角 | 收入规模与 2026 年预计经营亏损、$1B Long Beach 综合设施并存 | 重资本增长可能需要巨额一级资本 | 即便完成大额融资,算力 / 设施也可能缩短现金跑道 | Cathedral 未披露算力承诺 |
Sacra 数据为分析师估算,Palantir 数据来自 SEC 文件,Cathedral 数据为报道中的融资事实。Cathedral 收入单元格有意保留为 null。
[CI001, CI007, CI025, CI026, CI027, CI028]Cathedral 未披露收入;Palantir、Anduril 和 Shield AI 则显示,后期防务科技可比公司已经拿出的财务证据规模。
Cathedral 仅为可视化披露缺失而按 0 绘制;报告仍把 Cathedral 的 revenueRunRate 和 ARR 视为 null。
[CI025, CI026, CI028, CI029, CI030, CI046]4.5 财务结论与尽调卡点
财务结论是谨慎跟踪:对一家新成立的隐身初创公司而言,资产负债表很强,但承销文件很薄。Cathedral 有足够主融资去招聘、建设、跨过安全门槛并争取早期国防项目,却没有公开证据证明收入质量、利润率路径、合同积压、客户集中度或销售效率。因此,最重要的尽调卡点具体且可取得:扣除融资费用后的当前现金余额;按薪酬、算力、安全和项目捕获 拆分的月度烧钱;已承诺的数据中心资本开支或最低照付不议义务;按机构和合同工具拆分的管线;以及任何信函、中标、OTA、CRADA、SBIR 或涉密赞助方,能够解释为什么收入前 $1.4 billion 估值是合理的。在拿出这些材料前,投资人应把这轮融资承销为一个资金充足的政府网络 AI 采用期权,而不是一家收入支撑的国防软件公司。[CI007, CI008, CI010, CI011, CI022, CI023]
4.6 图表
05产品与技术
5.1 产品范围与证据边界
Cathedral 的产品应按涉密或近涉密网络行动平台承销,而不是按公开文档齐全的 SaaS 产品承销。公开记录只支持一个任务级定义:面向美国政府买方的 AI 驱动军事网络行动,同时覆盖针对中国等对手的进攻和防御能力。没有受审阅来源提供 Cathedral 产品名称、截图、API 文档、部署图、性能声明、ATO 状态或点名用户。因此,本章把下文进攻和防御模块视为由公开报道和可比系统推导出的能力桶,同时把 Cathedral 特定成熟度标记为隐身。可能的客户工作流从授权任务或网络防御要求开始,经过 AI 辅助发现和分析,最后到人类批准、修复或任务打包。这个证据边界不是脚注,而是核心产品风险。[CE001, CE002, CE003, CE004, CE036, CE045]
| 能力类别 | 用户 / 买家任务 | Cathedral 成熟度标签 | 证据状态 | 尽调要求 |
|---|---|---|---|---|
| 进攻侦察 | 任务团队界定目标和暴露面 | 可能已有原型 | 由进攻网络报道以及 AIxCC / Project Naptime 类比推断 | 展示授权工作流、目标约束和审计日志 |
| 自主漏洞发现 | 抢在对手前找到可利用缺陷 | 可能成立但未验证 | 有 AIxCC 和前沿模型类比支撑,但没有 Cathedral 文件 | 提供基准套件、真阳性率和复现流程 |
| 漏洞利用生成 / 验证 | 将漏洞转成已测试的利用路径 | 推断中风险最高 | 类比案例显示进展和边界;Cathedral 证据缺失 | 展示沙箱设计、法律批准、熔断开关和人工复核 |
| 任务封装 / 移交操作员 | 为网络操作员准备行动方案 | 推测性 | 没有公开 Cathedral 工作流或 C2 边界 | 提供交战规则和审批链 |
| 威胁检测与分诊 | 对告警、漏洞和利用证据排序 | 推断更接近短期落地 | Gold Eagle、Anthropic 防御方和 OpenAI 滥用监控支撑这种模式 | 展示遥测来源、检测精度和分析师体验 |
| 事件响应自动化 | 推荐遏制和修复步骤 | 可能成立但未验证 | NIST/RMF 和防御型智能体类比支撑需求 | 展示回滚控制和经过测试的处置手册 |
| 网络监控 / 暴露面管理 | 持续绘制可利用路径 | 类比公司已商业验证 | NodeZero / HackerOne 类比;Cathedral 证明缺失 | 展示智能体部署模型和环境覆盖 |
| 涉密计算隔离区 | 在受限网络数据上训练 / 评估 | 报道中的策略,未验证建成 | 数据中心计划和 Claude Gov / JWCC 背景支撑需求 | 展示设施、认证、保密资质和数据边界证据 |
各行是对一家隐身公司的能力假设;除非该行标注为「报道中」,否则 Cathedral 特定成熟度均未验证。
[CE001, CE002, CE003, CE004, CE007, CE009]可能工作流分为进攻和防御两条路径,两者都需要人工授权和受控证据捕获。
流程依据公开任务主张和类比推断;Cathedral 尚未发布工作流图。
[CE001, CE002, CE003, CE004, CE009, CE016]5.2 架构栈与算力模型
最可能的架构,是在涉密数据控制包裹下的智能体栈:模型编排、网络工具使用、安全数据检索、沙箱化漏洞利用测试、操作员复核,以及接入政府环境的部署连接器。Cathedral 被报道有意收购或合作数据中心,这一点异常重要,因为进攻性网络 AI 不能只按商品云来评估。训练语料可能包含漏洞情报、漏洞利用工件、敏感网络遥测或涉密任务背景;推理可能生成漏洞利用链或修复指令,不能离开经认证边界。Kliger 被报道担任五角大楼首席数据官,并接触 Anthropic / Claude 在 DoD 的使用场景,增加了创始人-市场背景,但不能证明 Cathedral 已解决模型治理。因此,架构表把推断层和已验证依赖拆开,并标记管理层必须拿出架构图、模型卡、隔离控制、日志计划和评估结果的位置。[CE005, CE006, CE007, CE008, CE019, CE040]
| 层 / 组件 | 可能角色 | 依赖 | 主要风险 | 证据状态 |
|---|---|---|---|---|
| 前沿模型层 | 对代码、日志、配置和任务背景做推理 | LLM 或专业网络模型;涉密微调数据 | 幻觉式发现或不安全利用建议 | 由任务和类比推断 |
| 智能体编排 | 规划任务、调用工具、持久化状态并分支调查 | 工具沙箱、规划器、记忆、检索、策略引擎 | 提示词 / 工具注入和自动化失控 | 推断 |
| 安全数据检索 | 搜索 CVE、代码、遥测、漏洞情报和历史事件 | 授权威胁情报和政府数据权利 | 数据投毒、情报过期、密级泄漏 | 推断 |
| 漏洞利用沙箱 | 编译、运行并验证利用或补丁假设 | 隔离实验室、模拟器、fuzzer、CTF 式靶场 | 逃逸、无效证明或不安全双用途输出 | 由进攻范围推断 |
| 防御工作流连接器 | 接入 SIEM/SOAR、工单、补丁和监控工作流 | DoD 网络 API、身份、日志和变更控制 | 涉密隔离区内集成中断 | 推断 |
| 涉密计算 / 隔离区 | 承载受限任务的模型和数据 | 专用数据中心、持证人员、ATO 边界 | 资本强度和认证周期 | 报道中有意图,执行未验证 |
| 合规证据系统 | 维护 SSP、控制、测试、模型评估和审计轨迹 | FedRAMP / RMF / SP 800-53 / CMMC 证据 | ATO 延迟或继承控制不匹配 | 部署环境要求 |
架构由外部推断;该表有意避免声称掌握 Cathedral 私有系统图。
[CE003, CE004, CE006, CE007, CE008, CE019]军用 AI 网络安全平台需要在受限算力边界内,拼起模型、智能体、数据、沙盒、集成和合规层。
[CE007, CE008, CE019, CE026, CE028, CE031]5.3 类比对象与能力基准
公开类比对象让 Cathedral 在技术上显得可信,同时也收窄了不该假设的内容。DARPA AIxCC 表明,自主网络推理系统可以在受控开源环境中竞争漏洞发现和修复。Horizon3.ai NodeZero 和 Dreadnode 表明,自主渗透测试和进攻性安全智能体工具已经是产品类别。Anthropic、OpenAI 和 Google 表明前沿模型可以辅助网络工作,但它们的材料也强调安全边界、滥用监控和基准限制。HackerOne 和 arXiv 来源尤其适合做反向校验:它们提示 AI 可以放大进攻性工作,但完全自主的真实世界漏洞利用仍不可靠,需要人类验证。如果 Cathedral 的差异化真实存在,它更可能来自涉密数据、任务集成和持证算力,而不是“使用 LLM 智能体”这个泛化事实。[CE010, CE011, CE012, CE013, CE014, CE015]
| 类比对象 | 可借鉴能力 | 能证明什么 | 套用于 Cathedral 的边界 | 证据状态 |
|---|---|---|---|---|
| DARPA AIxCC | 面向开源漏洞的自主网络推理 | AI 系统能在受控竞赛环境中发现并修复漏洞 | 竞赛成绩不证明已具备涉密实战就绪度 | 一手证据和开发者信号证据 |
| XBOW 验证基准 | 自主进攻安全基准测试 | AI 安全智能体已有公开基准基础设施 | 基准可能被刷满,也未必预测真实零日表现 | 开发者信号证据 |
| Horizon3.ai NodeZero 产品 | 商业自主渗透测试 | 持续自驱渗透测试已有市场范式 | 企业暴露面管理不同于军事进攻任务 | 官方和文档证据 |
| Dreadnode | 安全智能体基础设施和评估 | 有团队在搭建用于评估和部署进攻智能体的平台 | 基础设施工具不等于政府 ATO 或任务授权 | 官方和文档证据 |
| HackerOne Hai / AI 红队 | 人类加智能体的漏洞验证 | 混合流程可能压缩可利用性验证时间 | HackerOne 自身警告,单靠 AI 不够 | 公司材料和反向评测证据 |
| Anthropic Claude 网络能力 / Claude Gov | 前沿模型网络能力和涉密模型封装 | 前沿模型厂商能支持国家安全环境和网络评估 | Anthropic 强调安全边界和仍然存在的限制 | 官方研究证据 |
| OpenAI 威胁行为者阻断 | 监测恶意 AI 使用 | 模型提供商能发现并阻断滥用模式 | 不能证明进攻自动化可安全用于军事场景 | 官方滥用证据 |
| Palantir AIP | 任务 AI 工作流集成 | AI 能带着控制嵌入任务工作流 | AIP 是更宽的操作系统软件,不是网络漏洞利用引擎 | 官方类比证据 |
类比行用于框定能力可行性和风险;没有一项能直接证明 Cathedral 产品。
[CE010, CE011, CE012, CE013, CE014, CE015]防御分诊是近期最有支撑的路径;自主漏洞利用生成最缺验证、风险最高。
序数评分为定性且有来源支撑;没有可用的 Cathedral 私有证据。
[CE010, CE011, CE014, CE015, CE016, CE019]5.4 部署、集成与合规面
部署面很可能比模型演示更难。触达 NIPR、SIPR、JWICS、任务云或战术 DDIL 环境的军事网络产品,需要身份、日志、飞地、数据标注、出口管制、漏洞披露和操作员授权控制。若 Cathedral 交付云服务,FedRAMP 和 DoD 影响级别评估重要;ATO 需要 NIST RMF 和 SP 800-53;防务承包商 CUI 需要 CMMC;若出现经评估的端点或设备组件,NIAP 可能重要。DefenseScoop 关于 JWCC 的报道显示,五角大楼正在跨密级和影响级别寻求 AI 和 ML,但那只是需求信号,不是 Cathedral 授权。尽调要求很具体:索取系统安全计划、继承控制矩阵、部署边界图、许可人员名单、红队报告、模型评估协议,以及任何赞助方或授权官员往来。[CE026, CE027, CE028, CE029, CE030, CE031]
| 要求 / 控制族 | 重要性 | Cathedral 可能状态 | 所需证据 | 主要尽调负责人 |
|---|---|---|---|---|
| FedRAMP 或同等云授权 | 政府云服务需要获授权的控制继承 | 未公开披露 | FedRAMP 包、边界图、继承控制 | 安全 / 合规负责人 |
| DoD 影响等级评估(IL4/IL5/IL6,视情况而定) | CUI、任务数据和涉密工作负载对应不同控制深度 | 未公开披露 | 影响等级目标、DISA 或牵头方评估路径 | 云架构师 |
| RMF / 运行授权 | 在 DoD 系统上投入运行需要风险接受 | 未公开披露 | SSP、SAR、POA&M、授权官路径 | 项目安全官 |
| NIST SP 800-53 控制项 | 联邦系统安全和隐私控制基线 | 未公开披露 | 控制矩阵和测试证据 | GRC 负责人 |
| CMMC | 国防承包商处理 CUI 可能需要认证或评估 | 未公开披露 | CUI 边界和评估状态 | 合同 / 合规 |
| NIAP / 通用准则 | 部分安全组件可能需要通过评估的产品 | 有条件 / 未知 | 产品组件清单和保护轮廓映射 | 产品安全 |
| 安全许可和涉密设施访问 | 模型训练、评估和运行可能接触涉密材料 | 有暗示但未经验证 | 许可人员名单、设施担保、知情必要流程 | 人员 / 设施安全 |
| 模型安全和滥用控制 | 进攻性 AI 带来双重用途和升级风险 | 未公开披露 | 评估协议、拒绝 / 覆盖政策、人工授权日志 | AI 安全 / 任务负责人 |
该表是需求映射,不声称 Cathedral 已取得任何授权或认证。
[CE019, CE026, CE027, CE028, CE029, CE030]最重的负担不在模型开发本身,而在机密行动、ATO 和影响级云边界。
1–5 负担评分是定性尽调排序,不是监管指标。
[CE026, CE027, CE028, CE029, CE030, CE031]根据推断,Cathedral 产品要跑通,算力、涉密资质、模型、数据、ATO 和任务买方依赖都要同时到位。
[CE007, CE008, CE019, CE031, CE032, CE033]5.5 路线图与技术风险
可信路线图是渐进式,而不是魔法般的自治。合理顺序应从分析师副驾驶工具和漏洞分诊开始,再推进到沙箱化漏洞利用验证、涉密算力认证、受控防御试点,最后才是严格授权的进攻性任务支持。核心技术风险包括模型幻觉、无效漏洞利用链、对抗性提示和工具操纵、外部无法复现的涉密数据评估,以及当进攻性建议看似可信却实际错误时的治理失败。Gold Eagle 和防御智能体类比显示,短期价值在漏洞协调和修复优先级排序。风险最高的主张是自主漏洞利用生成和接近 C2 的自动化,因为它们把安全、合法性、可靠性和升级担忧叠在一起。在 Cathedral 发布证据或客户在许可环境下验证部署之前,产品结论是高上行、未证实。[CE009, CE016, CE017, CE018, CE020, CE034]
| 路线图阶段 / 功能 | 公开状态 | 技术风险 | 验证材料 | 优先级 |
|---|---|---|---|---|
| 漏洞分诊分析师副驾 | 推断存在,未披露 | 误报和优先级排序偏弱 | 基于真实工单的分析师并排评估 | 高 |
| 自主漏洞发现 | 合理推测,未披露 | 基准过拟合、真实场景召回率低 | 带复现包的盲测基准 | 高 |
| 沙箱化漏洞利用验证 | 合理推测,未披露 | 幻觉式利用链和不安全工具使用 | 隔离靶场日志和人工审批流程 | 高 |
| 防御性修复自动化 | 合理推测,未披露 | 补丁质量差或遏制建议不当 | 通过回滚测试的剧本和变更控制集成 | 中 |
| 涉密计算隔离区 | 仅有意向报道 | ATO 延误、资本开支和数据边界失效 | 设施计划、SSP、许可证据 | 高 |
| DoD 网络集成 | 无公开证据 | NIPR/SIPR/JWICS 之间的身份、日志、API 不匹配 | 边界和连接器架构 | 高 |
| 自主进攻任务支持 | 推测性 | 升级、法律授权和可靠性失效 | 交战规则控制和红队证据 | 阻断 |
路线图标签是尽调假设;Cathedral 未公开发布过任何带日期的产品路线图。
[CE003, CE004, CE007, CE016, CE017, CE018]5.6 图表
06客户
6.1 可触达买方群体,而非已披露客户
Cathedral 的客户章节必须从证据边界开始:公开来源支持一个庞大的可触达国家安全买方群体,但不支持任何点名 Cathedral 客户。Reuters 把公司描述为一家近期启动的隐身军事网络安全初创公司,正试图为 AI 驱动的进攻和防御网络行动获取美国政府合同;其他 2026 年报道重复了军事网络任务,但没有增加客户、部署、试点或合同 ID。最直接买方是 U.S. Cyber Command,NSA 和各军种网络组件是自然任务所有者;CISA、CIA、DIA 和亲密盟友国防部是合理相邻面。这是市场准入,不是采用。尽调中,活跃客户数、生产部署数、NRR、流失率、续约率和收入集中度,在 Cathedral 提供中标文件或客户推荐前都应保持 null。[CU001, CU002, CU005, CU008, CU009, CU010]
| 分层 | 买方 / 用户 / 付款方 | 任务需求 | 可能采购路径 | 进入难度 | 证据缺口 |
|---|---|---|---|---|---|
| USCYBERCOM / Cyber National Mission Force 任务方 | 作战司令部和任务团队 | AI 辅助的进攻和防御网络行动 | 涉密项目、OTA 原型、SBIR 转化 | 极高 | 未点名 Cathedral 试点或赞助方 |
| NSA Cybersecurity Collaboration Center | NSA 任务团队和 DIB 网络安全团队 | 由情报驱动,防御国防工业基础 | 合作、涉密合同、OTA、类 CRADA 协作 | 极高 | 未披露技术集成 |
| Navy Fleet Cyber / 第 10 舰队 | 军种网络组成部队和海军网络 | 舰队网络运行、支持网络任务部队 | 军种合同、OTA、GSA、项目办公室 | 高 | 未披露海军评估 |
| 第 16 空军 | 空军网络、ISR 和密码组织 | 运行并防御网络;支持网络效果 | AFWERX SBIR/STTR、军种 OTA、项目办公室 | 高 | 未披露空军赞助方 |
| MARFORCYBER | 海军陆战队网络空间组成部队 | 与 USCYBERCOM 对齐的海军陆战队网络行动 | 军种网络合同、OTA、创新中心 | 高 | 未点名海军陆战队用例 |
| Space Force 网络组织 | Space Delta 和太空任务系统防御团队 | 保护卫星和地面系统任务基础设施 | SpaceWERX/AFWERX、涉密合同、项目办公室 | 高 | 未披露太空任务授权 |
| 情报界 | CIA、DIA、NSA 任务所有者 | 外国军事情报和敏感网络行动 | 涉密合同、持证设施、项目办公室 | 极高 | 涉密需求可能在公开渠道不可见 |
| 民用和盟友网络机构 | CISA、DHS 组件、英国 / Five Eyes 盟友 | 关键基础设施防御和盟友军事 AI 现代化 | GSA、DHS 采购渠道、双边盟友采购 | 中高 | 未披露非 DoD 客户证据 |
这是可触达买方地图,不是客户名单;截至运行日,Cathedral 没有公开具名客户。
[CU001, CU005, CU009, CU010, CU011, CU012]| 证明类别 | 公开值 | 证据读法 | 解读 | 尽调要求 |
|---|---|---|---|---|
| 具名付费客户 | Reuters、TNW、Gizmodo 或 Cyber Daily 报道均未点名客户 | 将客户数量按空值处理 | 要求公司按密级提供客户名单 | |
| 生产部署 | 未披露生产用例或部署结果 | 无法量化采用轨迹 | 要求提供从试点到投产的状态和部署日期 | |
| 已授予合同 | USAspending、SAM.gov 和 DoD 合同页面是公开检索入口;引用的公开授标记录没有点名 Cathedral | 公开证据不能证明收入 | 要求提供授标 ID、合同工具、主承包 / 分包角色和涉密限制说明 | |
| 试点或原型赞助方 | 未公开识别出 DIU、SBIR、军种或 IC 赞助方 | 管线可能私下存在,但尚未核实 | 要求提供赞助方函件、评估备忘录和合同官联系人 |
null 表示所审阅公开来源集未披露;涉密或尚未公布的授标可能存在,但不能假定其存在。
[CU005, CU006, CU008, CU040, CU045]公开证据最能支持可服务买方匹配,最缺真实客户和留存证据。
分数是序数型证据可见度判断,不是运营 KPI。
[CU005, CU007, CU031, CU037, CU040, CU041]6.2 采购流程与采购工具
最可能的第一笔销售不是常规企业 SaaS 成单,而是一段国防采购序列。DIU、SBIR/STTR、AFWERX、SOFWERX、DEFENSEWERX 和 OTA 路径可以在 Cathedral 成熟到参与正式项目竞争前,让原型成为可能。DIU 明确邀请商业实体提交解决方案简报,包括首次向政府销售的公司;SBIR/STTR 提供非稀释性原型资金和转化语言。OTA 尤其相关,因为它们可以在标准采购合同之外资助原型和后续生产,但 GAO 也指出了规划和联盟纪律问题。GSA 采购目录和公开合同门户在后期重要,前提是产品范围、定价、合规和机构需求更清晰。因此,现实销售周期模型应是从首次任务对话到有意义收入需要 12 至 24 个月,涉密规模化会更久。[CU018, CU019, CU020, CU021, CU022, CU023]
| 渠道 | Cathedral 最适配场景 | 典型切入点 | 规模化路径 | 关键摩擦 |
|---|---|---|---|---|
| DIU 商业解决方案征集 | 有紧急任务牵引的商业 AI 网络原型 | 向 DIU 招标提交方案简报 | 原型 OT,或转给 DoD 赞助方 | 需要任务所有者和作战评估 |
| SBIR/STTR | 符合条件小企业的非稀释研发资金 | 课题提案和 Phase I 奖项 | Phase II、转化、商业化 | 资格、课题匹配和转化资金 |
| 其他交易授权 | 标准 FAR 合同之外的原型或后续生产 | 军种、DIU 或联盟 OTA | 符合法定条件时进入后续生产 | 规划、联盟费用和转化纪律 |
| GSA 多重授予目录 | 后期面向低涉密软件 / 服务的重复采购 | 拿到 Schedule 资格,由机构下单 | 多机构订购入口 | 产品、定价和合规成熟前并不理想 |
| AFWERX / SpaceWERX | 空军或 Space Force 网络与 AI 试点 | SBIR/STTR 开放课题或挑战 | 项目办公室或 Space Force 转化 | 从试点交接到项目的风险 |
| SOFWERX / DEFENSEWERX | SOCOM 或军种问题发现 | 挑战、奖金、评估、演示活动 | 赞助方出资原型或 OTA | 往往处在采购前,且不具约束力 |
| 正式列装项目 | 长期预算和规模化部署 | 需求、采办策略、竞标 | 多年持续保障和扩张 | 最慢路径;需要证据、预算和合规 |
这些渠道大致按从易进入的试验到可持续项目规模排序;实际路径取决于 涉密赞助方需求。
[CU018, CU019, CU020, CU021, CU022, CU023]Cathedral 可能先靠关系触达和任务匹配切入客户,但收入要等采购、合规和部署证据跑通。
旅程来自公开采购和合规路径推断,并非来自 Cathedral 已披露销售。
[CU007, CU018, CU020, CU023, CU026, CU029]每一阶段都会收窄账户集合:从广义可服务需求,缩到已披露、可持续的收入证据。
数值是本章证据可见度计数,不是 Cathedral 运营指标。
[CU005, CU008, CU018, CU020, CU023, CU025]6.3 合规与涉密访问门槛
对 Cathedral 的客户转化而言,合规很可能与模型质量一样重要。交付到联邦或 DoD 环境的网络能力,可能面临 FedRAMP、DoD 影响级别、ATO、CMMC、产品保证和涉密访问门槛。DCSA 的设施许可表述尤其重要:任何提供涉及涉密信息的商品或服务的实体,通常在履约前需要设施许可。Microsoft 的 DoD IL5 文档也说明,DoD 云授权在普通商业托管之外增加了要求。Cathedral 没有公开披露任何 FedRAMP 名单、ATO、DoD IL 授权、CMMC 姿态、NIAP 验证、设施许可、TS/SCI 持证人员基础或涉密项目访问。隐身公司缺少这些信息不应被过度解读,但这是投资人承销可部署性之前必须拿到的门槛型尽调包。[CU026, CU027, CU028, CU029, CU030, CU031]
| 要求 | 为什么影响 Cathedral | 可能需要的证据 | 当前公开状态 | GTM 影响 |
|---|---|---|---|---|
| FedRAMP | 联邦机构使用的云服务通常需要授权 | 云市场上架、机构 ATO 包、评估方证据 | 未披露 Cathedral 上架信息 | 解决前会挡住非涉密 SaaS 式部署 |
| DoD 影响等级 IL4/IL5/IL6 | DoD 云工作负载需要影响等级姿态和临时授权 | DoD SRG 映射、PA/ATO 证据、托管边界 | 无公开 DoD IL 证据 | 可能迫使公司及早采用 GovCloud/DoD 云架构 |
| 运行授权 | 任务系统投入运行前通常需要客户授权 | 系统安全计划、控制项、测试、授权官 | 未披露 ATO | 原型入选后可能再增加数月 |
| CMMC / DIB 网络卫生 | 处理 CUI 的国防承包商面临网络安全自评或认证义务 | SPRS/CMMC 记录、政策范围、评估方输出 | 未披露 Cathedral 状态 | 任何 CUI 工作前的尽调必问 |
| NIAP / 通用准则 | 国家安全环境可能要求安全产品满足产品保障预期 | 保护轮廓映射或已评估产品状态 | 未披露验证 | 可能影响端点 / 网络产品 |
| 设施许可和 FOCI | 执行涉密合同需要对持证实体进行审查 | DCSA 设施许可和 FOCI 审查 | 未披露 FCL | 涉密项目硬门槛 |
| 人员许可 / TS/SCI | 操作人员和工程师可能需要访问涉密网络和数据 | 持证人员名单和项目访问批准 | 无公开人员配置细节 | 限制试点转为涉密部署的速度 |
这些行是国防网络供应商可能遇到的合规门槛;公开状态为空是尽调缺口,不 证明控制项不存在。
[CU026, CU027, CU028, CU029, CU030, CU031]涉密网络工具放量前,GTM 流程要同时推进买方、合同和安全三条线。
流程是由公开 DoD 机制推导出的采购模型。
[CU018, CU020, CU023, CU026, CU029, CU030]6.4 创始人准入优势与旋转门批评
Cathedral 不寻常的进入市场优势,也是最明显的反向尽调角度。Reuters 报道称,创始团队与 Trump 政府和国家安全官员关系深,包括五角大楼;这些关系可能降低找到任务所有者的成本。在国防科技里,这种准入有价值,因为早期最难的一步往往是让真实赞助方定义一个紧迫且有资金的问题。同一组事实也制造旋转门和利益冲突风险:批评性报道已经把前 DOGE 人员转入军事技术框定为争议,Reuters 警告称,如果政治控制权变化,政府合同审查可能加剧。尽调问题不只是 Cathedral 能否拿到会面,而是这些会面能否经受伦理审查、合同办公室审视、抗议、国会监督和政府换届。[CU003, CU007, CU041, CU042, CU043]
| 指标 / 风险 | 公开值 | 含义 | 投资人尽调路径 |
|---|---|---|---|
| 客户数量 | 缺少衡量采用、留存或集中度的分母 | 要求按密级拆分活跃客户、试点和已获资金合同 | |
| NRR / GRR / 流失率 | 公开数据不足以承销持续性 | 要求提供队列留存、续约率和试点流失原因 | |
| 头部客户集中度 | 单个涉密赞助方可能主导早期收入 | 要求按客户和项目提供收入集中度 | |
| 先落地后扩张路径 | 原型 → OTA → 正式采办项目 | 扩张有可能,但要看合规和任务验证能否跑通 | 要求提供已获资金里程碑和转入正式项目的赞助方 |
| 旋转门审查 | 重大不利风险 | 政府关系可能加速销售,也可能引发监督反噬 | 审查伦理意见、回避安排、冷静期规则和沟通日志 |
本表刻意保留 null 客户指标,不编造早期牵引力。
[CU037, CU038, CU040, CU041, CU042, CU043]6.5 可比公司的采用经验
Anduril、Palantir 和 Shield AI 展示了 Cathedral 最终必须证明什么。Shield AI 在美国空军交易后估值跃升,说明任务验证可以打开私募融资;但它也说明投资人要看的证明点,是点名军种关系。Anduril 的 $5 billion Series H 和制造扩张,展示国防买方在公司越过演示阶段后会奖励的资本规模和生产可信度。Palantir 是耐久性基准:其 Form 10-K 描述 Gotham 服务国防和情报用户超过十年,并披露 2024 年政府收入超过 $1 billion。Cathedral 还没有任何这类客户证明。因此,近期客户故事是高准入管线论,而不是已验证采用论。[CU032, CU033, CU034, CU035, CU036, CU037]
| 可比对象 | 早期 DoD 客户证明 | 采用如何放大 | 给 Cathedral 的启示 | 类比局限 |
|---|---|---|---|---|
| Shield AI | 据报道,美国空军交易早于 $12.7B 估值 | 面向任务的自主飞机验证拉动大额融资 | 具名军种交易能重估一家国防 AI 初创公司 | 自主飞机不是网络行动 |
| Anduril | 公开报道显示其大规模融资和国防制造扩张 | 规模化硬件 / 软件项目和设施强化了可信度 | DoD 采用往往需要生产能力,不只是推介渠道 | Anduril 运营历史更长 |
| Palantir | 10-K 称 Gotham 服务国防和情报用户已超过十年 | 长期嵌入之后,2024 年政府收入超过 $1B | 深度政府软件账户可以变得持久且庞大 | Palantir 的路径花了多年 |
| UK MOD AI 合作 | 英国官方来源显示,盟友国防部正在寻求战略性 AI 现代化 | 盟友 AI 现代化打开后续扩张面 | 美国验证之后,向 Five Eyes 扩张具备可能性 | 没有 Cathedral 盟友客户证据 |
可比对象展示采用模式和证明门槛;没有一项能证明 Cathedral 已赢得客户。
[CU032, CU033, CU034, CU035, CU017, CU020]6.6 图表
07风险
7.1 政治、声誉与伦理风险
Cathedral 风险最高的问题,不只是创始人认识政府,而是公司的公开身份围绕 DOGE 到国防这条管线建立。Reuters、Vanity Fair、WIRED、AP、CREW 和 GovExec 共同构成一份反向记录,投资人不能把它当噪音:DOGE 校友曾担任敏感角色、访问政府系统、成为政治焦点,然后进入风险资本支持、可能再卖回同一政府的业务。这同时提出三个尽调问题。第一,是否有创始人获得过非公开的涉密或采购敏感需求知识,从而形成不公平竞争优势?第二,在 DOGE 任职后这么快授予合同,合同官和伦理官员是否会接受?第三,2028 年后的政府或民主党国会是否会把 Cathedral 变成 DOGE 相关监督的测试案例?缓释手段很窄:独立伦理审查、回避、冷却期合规、洁净室式产品需求,以及投标前的董事会级文件记录。[CR006, CR007, CR009, CR010, CR013, CR014]
| 风险 | 类别 | 可能性 | 影响 | 证据 | 缓释措施 | 剩余暴露 |
|---|---|---|---|---|---|---|
| DOGE 旋转门审查 | 政治 / 声誉 | 高 | 高 | 负面报道把 Cathedral 与向国防体系销售的 DOGE 前成员联系起来 | 独立伦理审查、洁净室要求、回避安排 | 首批非政治性授标可见前仍为高 |
| 内部知识 / 冲突质疑 | 法律 / 采购 | 中高 | 高 | 前美国国防部和联邦机构职务与目标买方需求重叠 | OCI 法律备忘录、投标防火墙、采购诚信培训 | 高 |
| 2028 年后政府换届 | 政治 / 预算 | 中 | 高 | Reuters 和 Vanity Fair 点出政权更替带来的审查风险 | 靠正常承包渠道赢单,并分散赞助方 | 中高 |
| 创始人行为和 Marko Elez 争议 | 关键人 / 声誉 | 高 | 中高 | AP 和 Reuters 报道,其因种族主义帖子辞职,并获得再雇支持 | 创始人行为准则、董事会监督、接班选项 | 中高 |
| AI 攻击性网络行动升级 | 伦理 / 法律 | 中 | 高 | Lawfare 和 CSIS 点出责任、范围、威慑和升级顾虑 | 交战规则、法律审查、人工授权关口 | 高 |
| 出口管制限制扩张 | 监管 | 中 | 高 | ITAR、EAR 和 Wassenaar 可能约束技术数据或工具转移 | 分类矩阵、许可路线图、具备资质的法律顾问 | 中高 |
| 未披露收入或合同 | 商业 | 高 | 高 | 公开报道披露融资,但未披露收入、客户或授标 | 估值上调前,要求看到已签授标和已获资金试点 | 高 |
| 美国政府单一买方集中 | 商业 / 依赖 | 高 | 高 | 使命是拿下美国政府网络安全合同 | 出口审查通过后,才看多机构管线和盟友市场路径 | 高 |
可能性和影响由分析师基于引用的负面报道、法律来源和采购语境打分;这些值是定性判断,不是精算结果。
[CR006, CR007, CR008, CR009, CR010, CR020]Cathedral 的残余风险集中在政治审视、商业证据、单一买方集中和进攻性网络监管。
定性评分只使用公开证据;没有可用的内部风险登记册。
[CR006, CR007, CR020, CR028, CR035, CR039]7.2 创始人与关键人风险
对一家按独角兽定价的公司而言,Cathedral 的关键人风险异常高,因为投资逻辑离不开四位年轻创始人的准入、可信度和执行力。公开报道确认 Gavin Kliger、Luke Farritor、Marko Elez 和 Jack Stein 是前 DOGE 工作人员,但没有显示成熟管理班底、收入负责人、项目管理负责人、持证合同负责人,或交付涉密网络项目的公开记录。Kliger 靠近五角大楼 AI 可能帮助产品发现,但也集中政治和伦理暴露。Elez 还带来单独的声誉尾部风险:AP 报道称,种族主义帖文与他相关后他辞职,随后 Musk、Vance 和 Trump 支持他回归。在信任、安全许可判断和国会观感都重要的国防采购中,这场争议可能成为合同尽调问题,而不只是 HR 脚注。缓释需要可信运营班底、独立安全领导、创始人行为契约和继任计划。[CR002, CR011, CR020, CR021, CR022, CR023]
| 人物 / 角色 | 已知公开信号 | 风险 | 可能性 | 影响 | 缓释措施 / 尽调要求 |
|---|---|---|---|---|---|
| Gavin Kliger / CEO | 报道称其曾任美国国防部首席数据官,职责贴近 AI 与 Anthropic 事项 | 内部知识观感和买方集中 | 中高 | 高 | 审查冷静期合规、OCI 备忘录和沟通日志 |
| Luke Farritor / 创始人 | 报道称其曾在 DOGE 任职、曾是 SpaceX 实习生;WIRED 将其列入年轻工程师群体 | 高级政府运营履历偏薄 | 中 | 中高 | 评估项目管理梯队和具备资质的承包负责人 |
| Marko Elez / 创始人 | AP 和 Reuters 报道种族主义帖子争议、辞职及再雇支持 | 声誉、判断力、安保审查和合同抗议风险 | 高 | 高 | 董事会行为约定、安全审查和客户可接受性检查 |
| Jack Stein / 创始人 | 报道称其为前 DOGE 人员兼联合创始人,公开运营细节有限 | 创始人集中和独立履历有限 | 中 | 中 | 要求说明角色范围、过往交付证据和接班计划 |
| 四名创始人团队 | 投资逻辑围绕政府入口和近期政府背景展开 | 执行与关系集中 | 高 | 高 | 聘请有经验的国防业务 GM、CISO、GC、获标负责人和项目经理 |
本表把报道中的创始人事实与尽调结论分开;公开证据还未显示出深厚的高管梯队。
[CR002, CR011, CR020, CR021, CR025, CR026]商业证据和政治审视得分最高,因为二者都可能单独拖累融资和采购。
分数是 1–10 的序数型尽调严重度值,不是概率。
[CR001, CR005, CR008, CR013, CR020, CR028]7.3 进攻性网络行动的伦理与升级风险
Cathedral 披露的使命——用 AI 支撑进攻和防御性的军事网络行动——落在一个敏感领域:私营承包商即便不像常规武器项目那样透明, 也可能制造国家层面的效果。Lawfare 的框架直接切中要害:私营公司参与进攻性网络活动前,政策制定者必须先界定目标、可做动作、目标范围、法律授权、 责任,以及对无辜第三方损害的归责。Atlantic Council 进一步指出,进攻性网络供应链不透明、碎片化且具战略敏感性; 当零日漏洞、AI 驱动的漏洞发现和对华竞争交叠时尤其如此。CSIS 还警告,低于门槛的网络活动可能绕开威慑逻辑; 关于自主性政策的评论也显示,即便 DOD 内部人士也可能误解人类控制和网络豁免的边界。Cathedral 只有靠严格的交战规则、审计日志、法律审查、 人类授权边界、漏洞权益治理,以及独立于增长激励的红队监督,才能缓释风险。[CR003, CR028, CR029, CR030, CR031, CR032]
政治、法律、网络伦理和商业风险,会传导到授标节奏、估值信心和买方信任。
流程是基于公开证据的因果综合,不是实测流程图。
[CR009, CR010, CR013, CR020, CR028, CR029]7.4 监管、出口管制与核验风险
监管风险远不止普通网络安全合规。若 Cathedral 为美国军事网络任务打造工具、服务、模型或运营支持,法律顾问必须先梳理 ITAR、EAR、 Wassenaar、采购诚信、离职后限制和涉密合同约束,再让公司在海外招聘、共享技术数据、与数据中心合作、向盟友销售,或接受非美国战略投资者。 一旦网络能力构成防务物项、防务服务、受控技术数据、先进计算物项或军民两用受控技术,ITAR 和 EAR 分析就不是可选项。 核验风险同样关键:保护国家安全工作的保密性,也会阻止外部投资者独立验证合同范围、运营表现、法律授权和客户验收。 干净的尽调流程因此需要安全数据室、法律顾问备忘录、出口管制分类矩阵、设施许可路线图、签约历史证据, 以及让投资者借助具备涉密资质的法律顾问核验涉密主张的协议,而不是依赖媒体叙事。[CR013, CR014, CR015, CR016, CR017, CR034]
| 规则 / 议题 | 管辖范围 | 状态 | 可能性 | 严重性 | 剩余暴露 | 尽调路径 |
|---|---|---|---|---|---|---|
| 离职后限制 | 美国 / 前联邦官员 | 现行规则 | 中 | 高 | 若创始人在限制窗口内与原任机构沟通,风险为高 | 法律顾问备忘录,列明受约束职位、接触对象和一年冷静期义务 |
| 组织性利益冲突 | 联邦采购 | 现行 FAR 制度 | 中高 | 高 | 若过往非公开需求影响投标,风险为高 | 独立 OCI 审查和洁净室产品需求流程 |
| 采购诚信 | 联邦采购 | 现行 FAR 制度 | 中 | 高 | 涉及任何来源选择或投标信息时为中高 | 培训、认证和投标团队防火墙 |
| 利用公职谋取私利 | 联邦伦理 | 现行伦理制度 | 中 | 中高 | 若 DOGE 关联驱动客户或投资人说法,风险为中 | 营销审查,并禁止暗示官方背书 |
| DOGE 透明度 / FOIA 审查 | 联邦监督 | 监督机构调查进行中 | 高 | 中高 | 若记录显示控制薄弱,声誉风险为高 | 跟踪 CREW、GAO、IG 和国会请求 |
| 美国财政部 / 敏感系统访问后续影响 | 联邦监督和法院 | 已成历史,但政治上仍敏感 | 中高 | 高 | Elez 与 DOGE 前成员叙事下风险为高 | 评估安全调查发现、安保审查影响和客户异议 |
本表不是法律意见;任何投标前,法律顾问和合同官都需要验证所列制度。
[CR013, CR014, CR015, CR016, CR017, CR018]| 管制领域 | Cathedral 为何可能触发 | 可能性 | 影响 | 缓释措施 | 待核实事项 |
|---|---|---|---|---|---|
| ITAR / USML | 军事网络工具或国防服务可能涉及受控国防物项、服务或技术数据 | 中 | 高 | 正式商品管辖 / 分类分析 | 哪些组件属于国防物项或国防服务? |
| EAR / 高级计算 | AI 模型、算力、软件或技术数据转移可能落入美国商务部管制 | 中 | 高 | ECCN 审查、视同出口控制、许可筛查 | 哪些模型权重、漏洞利用工具或算力访问受出口管制? |
| Wassenaar 两用管制 | 两用网络和入侵相关技术可能面临多边管制预期 | 中 | 中高 | 按国家拆分的管制矩阵 | 哪些盟友部署在法律上可行? |
| 涉密承包 | 国家安全网络工作可能涉密,投资人难以核验 | 高 | 高 | 具备资质的法律顾问和安全数据室流程 | 没有公开披露时,投资人能否验证授标和履约? |
| 数据中心 / 算力合作 | 专用算力会带来设施、出口、安全和依赖约束 | 中 | 中高 | 安全审查、供应链审查、合同审计权 | 谁控制算力、日志、模型隔离和事件响应? |
各行是从公开使命报道和出口管制主管机关推导出的尽调假设,并非认定某个具体项目受管制。
[CR003, CR034, CR035, CR036, CR037, CR038]7.5 商业、集中度与采购风险
商业上,Cathedral 的风险画像更像一个尚无收入的政府市场期权,却按已验证的防务科技平台定价。Reuters 及后续报道可以坐实融资、 使命、投资人和创始人的政府通道,但本报告审阅的公开记录尚未坐实收入、已签合同、生产环境用户、续约行为或任务结果。 买方范围也高度集中:Cathedral 明确追逐美国政府合同,而出口管制和涉密工作限制它快速走向国际多元化。 即便 Pentagon 希望更快采用商业技术,采购仍然偏向已有合同载体、过往业绩、涉密资质员工、项目经理和机构关系的既有承包商。 Booz Allen、Leidos、Palantir、Anduril,以及 Washington Technology 的政府承包商排名,都说明这种竞争不对称。 Cathedral 的缓释项只有在有证据时才成立:已签试点、有资金支持的授标、合同载体、安全授权、可背书的项目赞助方, 以及能经受领导层更替的非政治性采购胜利。[CR001, CR004, CR005, CR008, CR039, CR040]
| 风险 | 可监测触发项 | 阈值 / 事件 | 行动含义 |
|---|---|---|---|
| 政治 / DOGE 审查 | 国会、GAO、IG 或 FOIA 活动点名 Cathedral 或某位创始人 | 正式调查、传票、授标暂停,或合同官作出负面认定 | 暂停估值上调,并要求法律整改计划 |
| 利益冲突质疑 | 竞争者抗议或机构伦理审查质疑其接触非公开信息 | 任何成立的 OCI 或采购诚信认定 | 投标重组前,视为打破投资逻辑 |
| 创始人行为风险 | 客户安全办公室或安保审查流程对 Elez 或其他创始人提出担忧 | 安保许可被拒、赞助方反对,或董事会调查 | 投资前要求调整角色或治理补救 |
| 攻击性网络行动监督失效 | 产品路线图缺少法律授权、日志、人工授权或目标范围控制 | 没有成文 ROE 或客户授权链 | 阻止以部署为前提的收入承销 |
| 出口管制障碍 | 法律顾问无法判定工具 / 数据分类,或无法拿出计划中海外工作的许可路径 | 非美国转移前没有可用 ITAR/EAR 矩阵 | 假设 TAM 仅限美国,并下调上行情景 |
| 商业证明缺口 | 到下一融资里程碑仍没有已签、已获资金的政府授标或可背书试点 | 只有媒体 / 投资人叙事支撑牵引力 | 没有大幅折价,不要按 $1.4B+ 估值承销 |
| 替代在位厂商失败 | 管线输给主承包商,或拿不到合同工具入口 | 没有可信的合同工具、赞助方或集成路径 | 改按并购 / 合作标的看待,而非独立平台 |
| 单一买方集中 | 若有收入,也依赖单一办公室、单届政府或单个涉密项目 | 头部客户或赞助方实际控制公司生存 | 要求多项目管线和预算科目可见性 |
否决标准把宽泛风险转成投资委员会或后续更新可观察的尽调触发项。
[CR005, CR007, CR010, CR013, CR020, CR028]7.6 附录
08估值
8.1 估值与建议
Cathedral 的估值章节从两点开始:融资轮次计算异常干净,运营证据异常薄弱。已报道的 $160 million 融资、$1.4 billion 投后估值, 意味着约 $1.24 billion 投前估值和约 11.4% 的主融资稀释。对于一家 2025 年左右创立、未披露收入、 ARR 或合同胜利的公司,这是极高价格。分母缺失,无法计算收入倍数或 ARR 倍数;用零会误导,因此正确字段是 null。 投资立场因此是继续研究,信心低、风险高,估值立场偏贵。这个估值可由创始人与 DOGE 关联的政府通道、顶级投资人背书和防务科技市场热度解释, 但公开证据尚不足以支持由基本面兜底的买入建议。[CV001, CV002, CV003, CV004, CV005, CV006]
| 指标 | 值 | 解读 | 证据状态 |
|---|---|---|---|
| 新增融资 | $160 million | 约 2025 年创立的公司拿到大型机构轮融资 | 多家新闻来源报道 |
| 投后估值 | $1.4 billion | 创立初期估值异常高 | 多家新闻来源报道 |
| 隐含投前估值 | $1.24 billion | $1.4B 投后估值减去 $160M 新资金 | 根据报道轮次条款计算 |
| 隐含出售股权 | 11.4% | $160M 除以 $1.4B 投后估值 | 根据报道轮次条款计算 |
| 已披露收入 | 没有公开收入或 ARR,因此无法计算收入倍数 | 证据缺口 / 负面发现 | |
| 已披露合同 | 已检索来源未引用公开政府合同中标记录 | 证据缺口 / 负面发现 | |
| 估值立场 | 偏贵 | 价格反映团队、入口和市场热度,多过基本面 | 分析师结论 |
| 建议 | 继续研究 | 合同和产品证据追上估值前,不要买入 | 分析师结论 |
null 单元格表示公开证据不可得,不代表零收入或零合同。
[CV001, CV002, CV003, CV004, CV005, CV034]8.2 可比公司与倍数
可比公司组合解释了 Cathedral 为什么既合理又令人警惕。Anduril 和 Shield AI 证明,2026 年的私营防务科技赢家可以拿到很高估值, 但两家公司都比 Cathedral 走得远得多。Anduril 据报 $61 billion 的估值,有公开收入规模和可见产品足迹支撑; Shield AI 的 2026 年轮次则绑定自主飞行器和空军相关进展。Palantir 的阶段可比性更低,但可作为公开市场上限, 因为其高倍数背后有 SEC 文件、收入披露和政府业务增长。Rebellion Defense 是私营软件参照,不是估值锚, 因为抓取来源没有给出干净的当前倍数。相对于种子轮和 Series A 基准,Cathedral 的创始期估值仍是极端离群点。[CV011, CV012, CV013, CV014, CV015, CV016]
| 可比对象 | 估值 / 状态 | 收入或合同证明 | 隐含收入倍数 | 与 Cathedral 的相关性 | 关键限制 |
|---|---|---|---|---|---|
| Cathedral | $1.4B 投后;$1.24B 投前 | 未披露收入;未披露合同 | 直接标的与当前估值锚点 | 无法计算倍数 | |
| Anduril | 2026 年 $5B Series H 后估值 $61B | 2025 年收入据称约 $2.2B | ~27.7x 往绩收入 | 说明国防科技赢家能拿到近似软件公司的估值 | 成熟得多,已有收入和产品证明 |
| Shield AI | 2026 年投后 $12.7B;2025 年此前估值 $5.3B | 报道将估值与自主飞行器及空军相关进展挂钩 | 说明后期自主国防资产有溢价 | 已获取来源未公开披露收入 | |
| Palantir | 上市公司;按 2026 年市场数据口径,市值约 $300B+ | SEC 和公司文件披露收入及政府业务增长 | 公开 P/S 可观察;极高的软件估值上限参照 | 政府软件估值天花板参照 | 上市且已有盈利规模;不是创业公司可比样本 |
| Rebellion Defense | 私有国防软件参照;当前公开估值未披露 | 网站描述其面向关键资产情报的产品定位 | 可作为私有国防软件背景 | 已获取来源没有可比轮次倍数 | |
| 种子轮基准 | 典型种子轮估值远低于 $1.4B | 通常尚无收入或收入极早期 | 说明 Cathedral 创立期估值异常高 | 通用基准,并非国防网络安全专项 | |
| Series A 轮基准 | 典型 Series A 轮估值远低于投前 $1.24B | 通常需要试点、LOI 或收入证据 | 说明更靠后的早期可比样本仍低得多 | 通用基准会随赛道和团队变化 | |
| 国防科技泡沫批评 | 警告资本可能跑在合同和收入前面 | 突出采购节奏和耐心风险 | 对未有收入阶段溢价形成反向校准 | 批评面向整个赛道,并非专指 Cathedral |
倍数为近似值;null 表示已获取来源未披露该可比公司或 Cathedral 的收入。
[CV004, CV005, CV011, CV012, CV013, CV015]按绝对估值,Cathedral 远低于后期国防赢家;但相较常规创立阶段基准又高出很多。
基准条使用已抓取基准来源中的高端代表区间。
[CV001, CV011, CV015, CV016, CV023, CV024]与更成熟的国防科技参照相比,Cathedral 落在高估值风险 / 低证据象限。
轴为定性评分:x=公开证据,y=估值风险。
[CV004, CV011, CV014, CV017, CV018, CV019]8.3 增长消化场景与敏感性
承销一个尚无收入的估值,最干净的方法是反推未来需要多少合同收入,当前价格才会变得普通。按 10x 收入倍数,Cathedral 需要约 $140 million 年收入才能支撑 $1.4 billion;按 5x,需要约 $280 million;即便按激进的 15x,也需要约 $93 million。这划出了 18 至 24 个月的测试窗口。乐观情形要求公司迅速把通道转成付费军事网络项目,并跑出可重复的软件经济性。 基准情形是资金充足地建设产品和试点,但当前估值仍难自圆其说。悲观情形是采购或政治延误迫使公司稀释、降价融资, 或长期停留在仅靠叙事支撑估值的阶段。[CV026, CV027, CV028, CV029, CV030, CV031]
| 情景 | 18-24 个月合同 / 收入假设 | 估值逻辑 | 概率信号 | 下行触发点 |
|---|---|---|---|---|
| 乐观 | 将资源入口转成 $100M-$150M+ 年化合同收入,或等值的已获经费项目 | 按 10x-15x 收入倍数,$93M-$140M 收入即可支撑当前估值 | 只有付费政府项目很快落地才说得通 | 24 个月内没有付费试点或项目路径 |
| 基准 | 搭起团队和试点,但收入可见度有限 | 在收入按 10x 倍数接近 $140M 之前,当前 $1.4B 仍难解释 | 最符合今天的公开证据 | 试点仍未付费,或采购延期 |
| 悲观 | 政治审查或采购拖延挡住实质性合同 | 估值向早期国防基准重定价,或需要大幅稀释 | 泡沫反向证据和缺少牵引力证据支撑该情景 | 融资轮变成没有技术证明的资源入口故事 |
| 低倍数长入 | 按 5x 需要约 $280M 收入 | 意味着一家新网络安全公司要爬出很陡的收入曲线 | 没有大型多年期合同则不太可能 | 预算或认证延期 |
| 高倍数长入 | 按 15x 需要约 $93M 收入 | 在公开证明前就需要 Palantir / Anduril 式软件溢价 | 只有拿下异常强的战略合同才可能 | 国防科技倍数压缩 |
区间只是情景承销测算,不是管理层指引;收入仍未披露。
[CV026, CV027, CV028, CV029, CV030, CV031]当前估值只有在乐观路径下才说得通;基准和悲观情形都指向等待或重定价。
区间是情景启发式估算,锚定成长兑现收入测算和公开可比公司。
[CV026, CV027, CV028, CV029, CV030, CV031]8.4 溢价拆解与估值风险
估值溢价可拆成四个正项和一个巨大负项。团队溢价真实存在,因为创始人的政府经验可能降低采购摩擦。 投资人信号溢价也真实存在,因为 a16z 和 Sequoia 领投并拿到董事会席位,会改变市场感知。市场溢价由 Anduril、Shield AI、 Palantir 热度,以及 a16z 的 American Dynamism 论点支撑。稀缺性溢价来自可见的 AI 原生军事网络团队数量很少。 抵消项才是最大尽调问题:没有公开产品、收入或合同证据。关于防务科技泡沫的负面评论直接相关,因为它警告风险投资价格可能跑在采购现实前面。 政治审视、未来稀释、数据中心或合规资本开支,以及同更成熟可比公司的比较,是 $1.4 billion 估值失守的主要路径。[CV007, CV008, CV009, CV010, CV032, CV033]
| 组成项 | 对 $1.4B 故事的指示性贡献 | 证据依据 | 投资含义 |
|---|---|---|---|
| 团队 / 资源入口溢价 | 很高 | 创始人据报道是有政府关系的前 DOGE 员工 | 信号真实,但政治上脆弱 |
| 投资人信号溢价 | 高 | a16z 和 Sequoia 领投并取得董事席位 | 验证机会,也可能放大价格 |
| 国防 AI 市场溢价 | 高 | Anduril、Shield AI 与赛道融资热说明需求强 | 支撑品类热度 |
| 稀缺性溢价 | 中 | 具备这种资源入口的 AI 原生军事网络安全创业公司很少公开可见 | 更多团队进入后可能消退 |
| 牵引力折价 | 大幅负向 | 没有公开收入、公开合同或产品披露 | 无法给出基本面支撑的买入结论 |
| 稀释 / 优先权压力 | 负向 | 大额前置融资后面可能跟着昂贵的基础设施和合规支出 | 入场前必须看后续融资条款 |
仅作定性拆解;它解释估值标记,但不证明公允价值。
[CV007, CV008, CV009, CV010, CV033, CV039]| 论点 | 支持证据 | 哪些证据会改变判断 |
|---|---|---|
| 正方:精英团队能撬动政府网络安全需求 | 据报道,创始人为 DOGE 前成员,方向聚焦军事网络安全 | 技术负责人经过验证,交付团队具备涉密能力 |
| 正方:投资人在押注真实的国防科技景气 | Anduril、Shield AI 和 a16z American Dynamism 支撑品类顺风 | 证据显示 Cathedral 拿到差异化项目,而不只是获得关注 |
| 正方:网络作战比硬件国防更容易快速扩张 | 软件 / 网络安全方向可能避开部分硬件制造约束 | 可部署产品和认证路径的证明 |
| 反方:估值跑在牵引力前面 | 未披露收入、合同或产品页 | 签约付费试点或正式列装项目路径 |
| 反方:政治资源入口不是持久护城河 | DOGE / Trump 关系可能招致审查,也可能随政治风向变化 | 两党客户拉力和职业政府官员背书 |
| 反方:国防科技存在泡沫风险 | 反向来源警告资本可能跑在采购现实前面 | 合理入场价,或独立验证的合同储备 |
反方论点聚焦估值,并不否认国防网络安全需求真实存在。
[CV006, CV007, CV008, CV010, CV032, CV040]估值叙事先加上团队、投资人和市场溢价,再扣掉大额业务牵引折价。
瀑布图数值是示意性拆解,不是独立估值。
[CV008, CV009, CV025, CV032, CV041, CV042]8.5 最终尽调要求与论点破裂触发器
投资委员会不应把 Cathedral 永久视为不可投;它应把当前价格视为尚未被证明。若公司能展示付费政府网络需求、可防守的技术能力、认证路径和软件式经济性, 估值就存在可信的辩护路径。因此,所需尽调材料包很具体:合同管线和投标状态、在允许范围内的客户访谈、产品演示、安全和部署架构、 股权结构中的优先权、数据中心经济性,以及围绕政治关系的伦理控制。若 18 至 24 个月内没有付费试点或政府合同路径浮现, 若业务主要依赖政治通道,或若未来轮次显示前期估值造成了清算优先权悬垂,投资论点就会破裂。在这些检查通过前,正确结论是继续研究,而不是买入。[CV034, CV035, CV036, CV037, CV038, CV039]
| 尽调议题 | 缺失证据 | 重要性 | 推翻论点的阈值 |
|---|---|---|---|
| 合同管线 | 具名机构、投标阶段、付费试点、中标概率与时间 | 决定 $140M+ 收入是否可能成立 | 18-24 个月内没有可信付费路径 |
| 收入模式 | 定价、合同类型、毛利率以及服务 / 软件组合 | 决定公允倍数和现金需求 | 只有定制服务,毛利结构弱 |
| 技术证明 | 演示证据、网络能力边界、认证与安全控制 | 把真实能力与资源入口叙事分开 | 没有独立验证的产品能力 |
| 股权结构和优先权 | 清算优先权、期权池、按比例认购权和治理条款 | 大额融资轮可能形成优先权压力 | 条款让普通股或后续入场没有吸引力 |
| 政治 / 采购风险 | 伦理审查、冲突控制和两党客户背书 | 资源入口在审查下可能变成负债 | 合同看起来依赖政治关系 |
| 基础设施计划 | 数据中心合作方、算力成本和涉密部署计划 | 资本需求可能推高稀释 | 算力或合规成本压垮预算 |
这些问题定义了从继续研究走向可投资的路径;每一项目前都只能靠私有证据回答。
[CV035, CV036, CV038, CV039, CV040, CV043]8.6 附录
免责声明
本报告仅供参考,基于一家尚处隐身状态的国防公司的有限公开来源,不构成投资建议。
证据索引
| 编号 | 陈述 | 可信度 | 来源 |
|---|---|---|---|
| CO001 | Cathedral is a stealth AI-powered military cybersecurity startup focused on U.S. military cyber capabilities. | 高 | SO001, SO002, SO004, SO006 |
| CO002 | Cathedral should be treated as founded in 2025 because Reuters reported in July 2026 that it launched in recent months and the founders came out of 2025 DOGE roles. | 中 | SO001, SO002, SO013 |
| CO003 | Cathedral plans to seek U.S. government contracts for AI-driven military cyber operations. | 高 | SO001, SO002, SO004, SO006 |
| CO004 | Cathedral’s described mission includes both offensive and defensive cyber capabilities against U.S. adversaries such as China. | 高 | SO001, SO002, SO004, SO006 |
| CO005 | Cathedral is exploring acquiring a data center or partnering with a data-center provider for dedicated compute power. | 高 | SO001, SO002, SO004 |
| CO006 | The public founder set consists of Gavin Kliger, Luke Farritor, Marko Elez, and Jack Stein, all former DOGE staffers. | 高 | SO001, SO002, SO004, SO006 |
| CO007 | Gavin Kliger was reported as a Cathedral cofounder and former Pentagon chief data officer. | 高 | SO001, SO004, SO006 |
| CO008 | Luke Farritor was reported as a Cathedral cofounder, former SpaceX intern, and DOGE operator involved in GSA cost cutting. | 高 | SO001, SO004, SO006 |
| CO009 | Marko Elez was reported as a Cathedral cofounder who previously worked at SpaceX and DOGE/Treasury. | 高 | SO001, SO004, SO006, SO014 |
| CO010 | Jack Stein was reported as a Cathedral cofounder and former DOGE staffer. | 高 | SO001, SO002, SO006 |
| CO011 | Cathedral closed a $160 million funding round in the weeks before the July 22, 2026 Reuters report. | 高 | SO001, SO002, SO004, SO005 |
| CO012 | Cathedral’s 2026 financing valued the company at a $1.4 billion post-money valuation. | 高 | SO001, SO002, SO004, SO005, SO006 |
| CO013 | Andreessen Horowitz and Sequoia Capital led Cathedral’s funding round. | 高 | SO001, SO002, SO004 |
| CO014 | Andreessen Horowitz and Sequoia Capital both took board seats in connection with the round. | 高 | SO001, SO002, SO004 |
| CO015 | No Cathedral revenue, ARR, or revenue run rate was disclosed in the reviewed public sources. | 中 | SO001, SO002, SO004, SO006 |
| CO016 | No Cathedral customer count, named customer, government contract, or pilot was disclosed in the reviewed public sources. | 中 | SO001, SO002, SO004, SO006 |
| CO017 | No Cathedral headcount number was disclosed in the reviewed public sources. | 中 | SO001, SO002, SO004, SO006 |
| CO018 | No official Cathedral website, newsroom announcement, or product documentation was found in the reviewed source pack. | 中 | SO001, SO002, SO024, SO026 |
| CO019 | Reuters reported that Cathedral’s valuation, name, mission, and Elez’s involvement had not previously been reported. | 高 | SO001, SO002 |
| CO020 | A Cathedral spokesperson declined to comment, and Andreessen Horowitz and Sequoia did not respond to Reuters requests for comment. | 中 | SO001 |
| CO021 | Kliger was reported as involved in the Pentagon’s highly publicized legal fight with Anthropic over military use of Claude. | 高 | SO001, SO019, SO020, SO021, SO023 |
| CO022 | The Anthropic-Pentagon dispute created a live AI military-governance backdrop for Cathedral’s founding team. | 高 | SO001, SO019, SO020, SO021, SO022, SO023 |
| CO023 | Elez’s prior Treasury access raised security-control concerns, including GAO-reported control gaps around DOGE system access. | 高 | SO001, SO014 |
| CO024 | Elez quit DOGE after racist social-media posts were reported and was later rehired after Trump and Vice President JD Vance advocated reinstatement. | 高 | SO001, SO005 |
| CO025 | Reuters framed Cathedral as exposed to scrutiny over government contracts if political control changes after the 2026 midterm elections. | 高 | SO001, SO005 |
| CO026 | DOGE was established by White House executive order in January 2025. | 高 | SO013, SO012 |
| CO027 | DOGE officially ended on July 4, 2026 according to independent reporting. | 中 | SO017, SO018 |
| CO028 | Reuters reported that DOGE cost-cutting operations were associated with more than 250,000 people leaving the federal workforce. | 高 | SO001, SO015, SO016 |
| CO029 | Andreessen Horowitz also backed Special, another DOGE-alumni startup pursuing private-sector cost-cutting. | 高 | SO001, SO010, SO011 |
| CO030 | The Atlantic’s coverage of Special was skeptical of DOGE alumni entering complex industries with scant qualifications. | 高 | SO011, SO010 |
| CO031 | Andreessen Horowitz’s American Dynamism practice publicly focuses on companies serving national-interest markets. | 高 | SO024, SO025 |
| CO032 | Sequoia’s official materials show continued AI ecosystem engagement through its AI Ascent programming and company portfolio. | 高 | SO026, SO027 |
| CO033 | Anduril raised a $5 billion Series H at a $61 billion valuation in 2026, giving a defense-technology valuation benchmark. | 高 | SO008, SO009 |
| CO034 | The White House launched Gold Eagle in July 2026 as an AI-enabled cybersecurity vulnerability coordination clearinghouse. | 高 | SO007, SO028, SO030 |
| CO035 | Gold Eagle coverage described a public-private mechanism for faster vulnerability detection, prioritization, and patching. | 高 | SO007, SO028, SO030, SO031 |
| CO036 | Dark Reading argued that Gold Eagle targets a real vulnerability-coordination gap but left implementation details unclear. | 中 | SO029, SO030 |
| CO037 | Cathedral’s governance disclosure is limited to four named founders and two investor board-seat holders, not a complete board or control-rights package. | 中 | SO001, SO002, SO004, SO024, SO026 |
| CO038 | The founder roster creates key-person dependence because public evidence centers government access, Pentagon ties, and DOGE backgrounds rather than a broader operating bench. | 中 | SO001, SO004, SO014, SO019 |
| CO039 | The data-center plan would add infrastructure execution and capital-intensity risk to a software-like cyber startup story if pursued directly. | 中 | SO001, SO002, SO004, SO008 |
| CO040 | Cathedral’s stage is best described as stealth/private-undisclosed despite a mega-round because product, customer, revenue, and headcount details remain unavailable. | 中 | SO001, SO002, SO004, SO006 |
| CO041 | The round gives Cathedral at least $160 million of disclosed total funding because no earlier financing was found in the reviewed public record. | 中 | SO001, SO002, SO004 |
| CO042 | Cathedral’s investor map combines lead investors, founder-control risk, prospective U.S. government customers, and infrastructure partners because those are the stakeholder dependencies visible in public evidence. | 中 | SO001, SO002, SO024, SO026 |
| CO043 | Gizmodo and Hoodline covered the Cathedral round with a skeptical tone around DOGE alumni monetizing controversial government roles. | 中 | SO004, SO005 |
| CO044 | Cyber Daily corroborated that Cathedral intends to bolster U.S. military cyber defense and operations through AI. | 中 | SO006, SO001, SO002 |
| CO045 | The Reuters-origin page itself was not accessible as readable text during the fetch and was recorded as JavaScript-blocked. | 高 | SO003, SO001 |
| CM001 | Cathedral’s relevant market is AI-enabled cyber tooling and services for U.S. military and national-security operators, not all enterprise cybersecurity or physical defense hardware. | 高 | SM002, SM003, SM004 |
| CM002 | Cyber Command and the NSA represent distinct operational and collaboration nodes in the U.S. military cyber ecosystem. | 高 | SM003, SM004 |
| CM003 | The U.S. federal cyber budget context is at least approximately $26 billion annually in the 2026 planning frame, but that top-down number includes spend outside Cathedral’s core wedge. | 中 | SM001, SM020, SM021 |
| CM004 | DoD budget materials are the primary public anchor for defense-wide cyber and IT spend, but they do not isolate every classified offensive cyber line item. | 中 | SM002 |
| CM005 | U.S. Cyber Command’s mission language makes in-house military cyber capability a direct status-quo substitute for startup software. | 中 | SM003 |
| CM006 | NSA’s Cybersecurity Collaboration Center shows that government-industry cyber collaboration is part of the operating model for national-security cyber work. | 中 | SM004 |
| CM007 | CISA frames federal cybersecurity as a national risk-management function, making civilian-agency cyber spend adjacent but not core to Cathedral’s military wedge. | 中 | SM020, SM021 |
| CM008 | GAO keeps federal information security and cybersecurity on its high-risk agenda, which supports demand but also signals implementation difficulty. | 中 | SM005, SM006 |
| CM009 | CRS procurement reporting reinforces that public contract data is a partial view of how DoD spends and reports contracting dollars. | 中 | SM007 |
| CM010 | DARPA’s AI Cyber Challenge is official evidence that automated AI vulnerability discovery and remediation is a current U.S. government priority. | 中 | SM008 |
| CM011 | Defense SBIR/STTR and SBIR.gov describe a public entry route for small businesses seeking defense R&D funding. | 中 | SM009, SM026 |
| CM012 | DIU’s solution and work-with-us pages show a commercial-solutions channel intended to pull private-sector technology into DoD missions. | 中 | SM024, SM025 |
| CM013 | FAR Part 16 documents the contract-type machinery that later-stage defense software vendors must eventually fit. | 中 | SM019 |
| CM014 | DAU and GAO materials show that Other Transactions are a relevant DoD acquisition instrument but also carry planning and governance risks. | 中 | SM031, SM032 |
| CM015 | USAspending.gov, SAM.gov, and DoD contract releases are useful public award windows but are insufficient to reveal classified cyber programs. | 中 | SM016, SM017, SM018 |
| CM016 | MarketsandMarkets estimates the artificial intelligence in military market at $9.2 billion in 2023 and $38.8 billion by 2028, a 33.3% CAGR. | 中 | SM011 |
| CM017 | Grand View Research estimates artificial intelligence in military at $9.31 billion in 2024 and $19.29 billion by 2030, a 13.0% CAGR. | 中 | SM012 |
| CM018 | The difference between the MarketsandMarkets and Grand View military-AI forecasts is large enough to require a range rather than a single TAM point estimate. | 中 | SM011, SM012 |
| CM019 | Mordor Intelligence projects the cyberwarfare market at $40.13 billion in 2026 and $52.27 billion by 2031, a 5.43% CAGR. | 中 | SM014 |
| CM020 | MarketsandMarkets maintains a cyber-warfare market category covering threat intelligence, data protection, vulnerability management, identity, managed security, and resilience solutions. | 中 | SM013 |
| CM021 | Grand View’s broad cybersecurity market estimate is useful context but is too wide to equal Cathedral’s TAM because it includes civilian, consumer, and enterprise spend. | 中 | SM015, SM021 |
| CM022 | American Dynamism materials from a16z show investor interest in companies positioned around the national interest and defense modernization. | 中 | SM010 |
| CM023 | Anduril is the most visible venture-backed defense-tech comparable for Cathedral, but its hardware-heavy autonomy stack is not a direct cyber-software TAM proxy. | 中 | SM029, SM030 |
| CM024 | Canonical run facts place Anduril’s latest comparable financing at $5 billion raised and a $61 billion valuation, underscoring the valuation ceiling investors may reference. | 低 | SM029, SM030 |
| CM025 | Cathedral’s core included spend should be AI cyber tools, vulnerability discovery, mission workflow software, and services sold into DoD or intelligence-community cyber operators. | 中 | SM003, SM004, SM008 |
| CM026 | Broad IT services, general FedRAMP SaaS, consumer cybersecurity, and physical defense hardware should be excluded from the core Cathedral SAM. | 中 | SM019, SM021, SM030 |
| CM027 | Offensive cyber and cyber-weapons spending is likely material but hard to size publicly because operations, authorities, and program lines are sensitive. | 中 | SM003, SM004, SM014 |
| CM028 | The most important status-quo alternatives are internal Cyber Command capability, NSA collaboration, incumbent contractors, and manual penetration-testing workflows. | 中 | SM003, SM004, SM018, SM021 |
| CM029 | Incumbent contractors have an advantage because public awards, FAR contract types, and program-of-record conversion favor vendors that can survive long procurement cycles. | 中 | SM016, SM018, SM019 |
| CM030 | A plausible defense startup path is SBIR or DIU entry, prototype or Other Transaction work, and later conversion into a FAR contract or program of record. | 中 | SM009, SM024, SM025, SM031, SM019 |
| CM031 | Security controls, zero-trust alignment, and NIST-style cybersecurity frameworks are adoption constraints for mission cyber software. | 中 | SM022, SM023, SM027 |
| CM032 | AI risk-management expectations from NIST make autonomous cyber tools a trust and governance sale, not only a capability sale. | 中 | SM028, SM008 |
| CM033 | China and nation-state cyber competition increase urgency for AI-accelerated defensive and offensive cyber operations. | 中 | SM003, SM004, SM008 |
| CM034 | Post-Ukraine cyber priority and the broader move toward software-defined warfare support budget attention, but the public source pack does not isolate a Cathedral-specific spend pool. | 低 | SM002, SM003, SM015 |
| CM035 | A DOGE-style efficiency push would favor automation and smaller teams, but public diligence still needs proof that DoD buyers will trust a stealth startup with classified cyber workflows. | 低 | SM006, SM008, SM028 |
| CM036 | Procurement, authority-to-operate, classified-network deployment, and security-clearance requirements make 18-24 month adoption cycles a reasonable diligence assumption rather than a verified Cathedral fact. | 低 | SM019, SM022, SM023, SM032 |
| CM037 | No public source in this chapter verifies Cathedral revenue, customers, or signed government contracts, so SOM should be framed as zero verified public traction rather than a modeled share. | 低 | |
| CM038 | The narrowest public SOM proxy available before customer diligence is a pipeline-conversion view from SBIR/DIU opportunities to public awards, not a revenue run-rate. | 中 | SM009, SM016, SM017, SM024 |
| CM039 | The federal buyer map separates budget owners from end users because cyber operators, program offices, and contracting officers can be different organizations. | 中 | SM003, SM017, SM019 |
| CM040 | DoD program offices and service cyber components are likely payers, while Cyber Command, NSA, and mission teams are likely users or technical evaluators. | 中 | SM002, SM003, SM004, SM018 |
| CM041 | CISA and civilian agencies are adjacent buyers for defensive cyber automation, but the canonical Cathedral mission points primarily at military and adversary-facing operations. | 中 | SM020, SM021, SM003 |
| CM042 | Manual red-teaming and penetration testing remain substitutes when buyers are not ready to authorize autonomous AI cyber operations. | 中 | SM021, SM027, SM028 |
| CM043 | The market opportunity is valuation-relevant because defense-tech venture investors have recently rewarded mission-critical national-security platforms even before public revenue disclosure. | 中 | SM010, SM029, SM030 |
| CM044 | The main adverse market view is that broad federal and analyst cyber numbers can dramatically overstate Cathedral’s attainable market while procurement and classification delay conversion. | 中 | SM005, SM006, SM019, SM032 |
| CM045 | The correct diligence next step is to replace top-down TAM estimates with named program offices, authority path, security accreditation status, and contract-stage evidence. | 中 | SM016, SM017, SM019, SM023 |
| CM046 | The matrix view adds a distinct coordination lens because defense cyber adoption depends on the interaction among buyer, user, payer, and contracting authority rather than on segment labels alone. | 中 | SM017, SM019, SM025 |
| CP001 | Cathedral is a stealth AI defense and military cybersecurity startup founded by ex-DOGE staffers Gavin Kliger, Luke Farritor, Marko Elez, and Jack Stein. | 高 | SP001, SP002, SP003 |
| CP002 | Cathedral raised $160 million at a $1.4 billion post-money valuation in July 2026 in a round led by Andreessen Horowitz and Sequoia. | 高 | SP001, SP002, SP003 |
| CP003 | Cathedral’s reported mission is AI-enabled offensive and defensive cyber operations for U.S. military and national-security customers. | 高 | SP001, SP002 |
| CP004 | Reviewed public sources describe Cathedral as planning to secure U.S. government contracts rather than disclosing signed revenue or contracts. | 中 | SP001, SP003 |
| CP005 | Cathedral’s likely initial differentiation is founder access to Pentagon and national-security networks rather than public product proof. | 中 | SP001, SP003 |
| CP006 | Anduril raised a $5 billion Series H at a $61 billion valuation and had reported $2.2 billion of 2025 revenue, making it a much larger defense-tech benchmark than Cathedral. | 中 | SP004 |
| CP007 | Anduril’s Lattice platform is tied to battle-management software and joint missile-defense data analysis in public reporting. | 中 | SP004 |
| CP008 | Palantir’s 10-K identifies Gotham, Foundry, Apollo, and AIP as its four principal platforms and says Gotham has served global defense agencies and the intelligence community for over a decade. | 中 | SP005 |
| CP009 | Palantir generated $2.9 billion of 2024 revenue, with 55% from government customers, giving it a scale and incumbency advantage Cathedral lacks. | 中 | SP005 |
| CP010 | The UK Ministry of Defence announced a strategic partnership with Palantir intended to unlock military AI and innovation, reinforcing Palantir’s allied-defense presence. | 中 | SP006 |
| CP011 | Shield AI’s Hivemind is an AI pilot for autonomous aircraft and has operated alongside U.S. and allied forces. | 中 | SP007 |
| CP012 | Shield AI was reported by TechCrunch to have reached a $12.7 billion valuation in 2026 after a U.S. Air Force-related deal, far above the older $2.8 billion benchmark. | 中 | SP008, SP009 |
| CP013 | Rebellion Defense’s currently reviewed website positions it around an intelligence shield for critical assets, radar, AI fusion, and operational support rather than public evidence of a completed acquisition or shutdown. | 中 | SP010 |
| CP014 | IronNet is an adverse precedent because reporting says the never-profitable cyber startup shut down and fired employees after running out of money. | 中 | SP011, SP012 |
| CP015 | IronNet’s Stretto bankruptcy case page corroborates that IronNet entered formal bankruptcy proceedings in 2023. | 中 | SP012 |
| CP016 | Horizon3.ai’s NodeZero is marketed as an autonomous pentesting platform that finds, fixes, and validates exploitable paths. | 中 | SP013, SP015 |
| CP017 | Horizon3.ai reported more than 5,200 organizations worldwide relying on NodeZero and 125% net dollar retention in 2026. | 中 | SP013 |
| CP018 | Horizon3.ai announced 2026 investment from Prosperity7 Ventures to protect AI datacenters and critical infrastructure. | 中 | SP014 |
| CP019 | XBOW raised $120 million in Series C financing in 2026 and was valued at more than $1 billion, according to Business Wire. | 中 | SP016 |
| CP020 | XBOW and Accenture announced a 2026 partnership to scale continuous AI-driven security testing and exposure management. | 中 | SP017 |
| CP021 | XBOW positions itself as autonomous offensive security, directly overlapping Cathedral’s offensive-cyber part more than most defense-platform companies. | 中 | SP016, SP017 |
| CP022 | Dreadnode builds AI infrastructure for security agents and publishes offensive-security research, making it an AI-native red-team adjacency rather than a traditional services prime. | 中 | SP018, SP019 |
| CP023 | Dreadnode captured $14 million of Series A funding in 2025 for offensive AI security capabilities. | 中 | SP020 |
| CP024 | RunSafe targets memory safety and cyber resilience for critical infrastructure and safety-critical systems, which is more defensive-hardening than Cathedral’s reported offensive-and-defensive mission. | 中 | SP021, SP022, SP023 |
| CP025 | Two Six Technologies states that it supports Department of Defense, U.S. Cyber Command, DARPA, intelligence-community, and civilian-agency customers. | 中 | SP024 |
| CP026 | Two Six’s Sentr positioning emphasizes AI-driven command of the information environment and agentic bridging of legacy systems. | 中 | SP025 |
| CP027 | Booz Allen’s cyber page explicitly frames the problem as cyberattacks moving at AI speed and cyber defense needing to do the same. | 中 | SP026 |
| CP028 | Leidos markets offensive, defensive, and resilience-oriented cyber capabilities across mission environments. | 中 | SP027 |
| CP029 | CACI markets AI/ML-enabled cyber operations, while Peraton, ManTech, Parsons, SAIC, and other incumbents maintain public cybersecurity offerings. | 中 | SP028, SP029, SP030, SP031, SP032 |
| CP030 | The Navy awarded eight companies $1.86 billion in cyberspace operations support contract options, illustrating incumbent access to large multi-year cyber vehicles. | 中 | SP033 |
| CP031 | Washington Technology’s 2026 Top 100 ranking is based on federal spending for IT, systems integration, telecom, professional services, and high-tech needs, making it a useful scale proxy for incumbents. | 中 | SP034 |
| CP032 | GSA’s Alliant 3 Phase 1 awards cover a major federal IT modernization vehicle that includes AI and cybersecurity-relevant contractors. | 中 | SP035 |
| CP033 | An Army cyber-warfare contract dispute involving Booz Allen, Peraton, and ManTech shows that prime contractors already fight over the specific offensive and defensive cyber mission space Cathedral wants. | 中 | SP036 |
| CP034 | Atlantic Council research describes offensive cyber capability markets as relying on intermediaries and opaque supply chains, which complicates Cathedral’s potential offensive-cyber sourcing model. | 中 | SP037, SP038 |
| CP035 | Atlantic Council reported that zero-day exploitation is becoming more difficult, opaque, and expensive, creating feast-or-famine cycles in offensive-cyber contracting. | 中 | SP038 |
| CP036 | Lawfare analysis argues that private-sector involvement in offensive cyber operations creates legal, policy, and escalation risks. | 中 | SP039 |
| CP037 | Cyber Defense Review describes exploit brokers as suppliers whose customers can include government agencies, reinforcing that exploit supply is a specialized market Cathedral may need to navigate. | 中 | SP040 |
| CP038 | Vannevar Labs positions itself around restoring deterrence and reclaiming advantage for national-security users, making it an adjacent defense-AI software competitor. | 中 | SP041 |
| CP039 | The most direct cyber-specific Cathedral substitutes are Horizon3.ai, XBOW, Dreadnode, RunSafe, and exploit-market vendors, because they focus on automated pentesting, offensive security, AI red teaming, hardening, or exploit supply. | 中 | SP013, SP015, SP016, SP018, SP021, SP038, SP040 |
| CP040 | Cathedral’s two-sided offensive-plus-defensive cyber framing is rarer than the one-sided positions of many cyber startups, but public sources do not prove it has product depth yet. | 中 | SP001, SP013, SP016, SP021 |
| CP041 | Incumbents’ durable advantage is distribution through government contract vehicles, security clearances, procurement history, and program relationships rather than necessarily superior AI-native product design. | 中 | SP024, SP030, SP031, SP032, SP033, SP034, SP035, SP036 |
| CP042 | Defense-tech AI startups such as Anduril, Palantir, Shield AI, Rebellion, Vannevar, and Two Six compete with Cathedral mostly for mission budget and AI-defense credibility, not necessarily for the exact same cyber product. | 中 | SP004, SP005, SP007, SP010, SP024, SP041 |
| CP043 | Cyber-specific AI companies have stronger product proof in autonomous testing than Cathedral has publicly disclosed, while Cathedral may have stronger founder access to federal decision makers. | 中 | SP001, SP013, SP016, SP017, SP018 |
| CP044 | The status-quo alternative for defense buyers includes internal government cyber teams, existing prime-contractor task orders, and classified exploit-procurement channels. | 中 | SP024, SP033, SP036, SP037, SP040 |
| CP045 | IronNet’s collapse is a caution that ex-government credibility and cyber branding do not by themselves create durable revenue, margins, or procurement traction. | 中 | SP011, SP012, SP003 |
| CI001 | Cathedral raised $160 million in a July 2026 financing at a reported $1.4 billion post-money valuation. | 中 | SI001, SI002, SI003, SI004 |
| CI002 | Andreessen Horowitz and Sequoia Capital led Cathedral’s $160 million financing, with coverage reporting board-seat involvement. | 中 | SI002, SI003, SI004 |
| CI003 | Cathedral was founded by former DOGE staffers Gavin Kliger, Luke Farritor, Marko Elez, and Jack Stein. | 中 | SI002, SI003, SI004 |
| CI004 | The July 2026 financing is the only publicly disclosed Cathedral financing round in the reviewed source pack, so disclosed total raised is $160 million. | 中 | SI001, SI002, SI003, SI004 |
| CI005 | A $160 million primary round at a $1.4 billion post-money valuation implies roughly 11.4% new-money dilution before any option-pool or secondary adjustments. | 中 | SI001, SI002, SI003 |
| CI006 | The same round implies a roughly $1.24 billion pre-money valuation if the reported $1.4 billion post-money valuation and $160 million primary proceeds are taken at face value. | 中 | SI001, SI002, SI003 |
| CI007 | No reviewed source disclosed Cathedral revenue, ARR, revenue run rate, gross margin, or customer count. | 中 | SI001, SI002, SI003, SI004 |
| CI008 | No reviewed source disclosed a named paying Cathedral contract, OTA, SBIR award, CRADA, or program-of-record sponsor. | 中 | SI001, SI002, SI003, SI020, SI021, SI022 |
| CI009 | Cathedral is reported to be exploring acquiring or partnering with a data center to secure dedicated compute capacity. | 中 | SI002, SI003, SI004 |
| CI010 | Startup Fortune framed Cathedral’s financing as unicorn money for a company with almost no public footprint, no product launch, and no customer announcement. | 中 | SI002 |
| CI011 | The strongest current adverse financial issue is not churn or margin compression but valuation-before-revenue combined with an undisclosed contract pipeline. | 中 | SI002, SI007, SI020, SI021 |
| CI012 | Firm-fixed-price contracts place maximum risk and responsibility for costs and profit or loss on the contractor. | 高 | SI005, SI006 |
| CI013 | Cost-reimbursement contracts provide payment of allowable incurred costs and establish a ceiling the contractor may not exceed without approval. | 高 | SI005, SI007 |
| CI014 | Incentive contracts can tie contractor profit or fee to cost, delivery, or technical-performance outcomes. | 高 | SI005, SI008 |
| CI015 | IDIQ vehicles provide for an indefinite quantity within stated limits and convert into revenue through specific orders that define supplies or services. | 高 | SI009, SI010 |
| CI016 | Best-value negotiated acquisitions can vary the relative importance of cost or price, which makes mission fit and technical evaluation central to sales efficiency. | 高 | SI011, SI035 |
| CI017 | SBIR and STTR programs offer equity-free or non-dilutive funding for small businesses pursuing federal R&D and commercialization. | 高 | SI012, SI015 |
| CI018 | Defense SBIR/STTR describes a staged path from eligibility and proposal through award, Phase II, transition, and commercialization. | 高 | SI013, SI014 |
| CI019 | CRADAs can support R&D collaboration between a federal laboratory and a non-federal entity, but the government may not provide funding to non-federal entities under a CRADA. | 中 | SI016 |
| CI020 | Other Transaction Authority is a flexible DOD pathway used alongside the department’s large annual acquisition base for goods, services, and R&D. | 高 | SI017, SI018 |
| CI021 | DIU presents a commercial-technology pathway in which any commercial entity can respond to solicitations for military adoption. | 高 | SI018, SI019 |
| CI022 | USAspending is the official federal spending source for awards such as contracts, grants, and loans, making it a relevant check for public award evidence. | 中 | SI020 |
| CI023 | SAM.gov contract opportunities and the Defense Department contracts page are relevant public surfaces for future Cathedral solicitations and award notices. | 高 | SI021, SI022 |
| CI024 | Government contracting risk is not only timing risk: GAO has documented DOD procurement-fraud exposure and recommended stronger department-wide risk management. | 中 | SI036 |
| CI025 | Palantir’s 2025 Form 10-K says revenue increased by about $1.6 billion, or 56%, from 2024 to 2025. | 高 | SI023, SI025 |
| CI026 | Palantir reported that revenue from government customers increased by $832.7 million, or 53%, in 2025 and that U.S. government revenue was $1.9 billion. | 高 | SI023, SI024 |
| CI027 | Palantir’s public product materials explicitly position the platform for governments as well as commercial organizations, supporting its use as a government-software comparable. | 高 | SI026, SI023 |
| CI028 | Sacra estimates Anduril generated $2.2 billion of 2025 revenue, up from $1.0 billion in 2024, and projects $4.3 billion of 2026 revenue. | 中 | SI027 |
| CI029 | Sacra reports Anduril closed a $5 billion Series H at a $61 billion valuation and projects an approximately $1.2 billion operating loss in 2026. | 中 | SI027 |
| CI030 | Sacra estimates Shield AI reached about $300 million of revenue for the year ending March 2025 and implies at least $540 million of 2026 revenue from management targets. | 中 | SI028 |
| CI031 | The Los Angeles Times reported Anduril is developing a new $1 billion Long Beach complex that includes offices, labs, and prototype manufacturing facilities. | 中 | SI029 |
| CI032 | GeekWire reported Anduril was quietly building autonomous warships at a Seattle shipyard, reinforcing the physical-facility intensity of scaled defense technology. | 中 | SI030 |
| CI033 | Goldman Sachs estimates AI could drive a 160% increase in data-center power demand, while DOE expects domestic data-center energy usage to double or triple by 2028. | 高 | SI031, SI032 |
| CI034 | Epoch AI estimates frontier-model training compute has grown by roughly 4x to 5x per year, which supports treating dedicated compute as a material burn driver. | 中 | SI033 |
| CI035 | Andreessen Horowitz’s American Dynamism thesis supports startups serving national-interest markets, giving context for a16z’s appetite for defense-oriented companies. | 中 | SI034 |
| CI036 | A reasonable Cathedral base-case runway lens divides the $160 million raise by estimated monthly burn rather than by revenue because no revenue has been disclosed. | 中 | SI001, SI002, SI031, SI033 |
| CI037 | At $4 million of monthly burn, $160 million supports roughly 40 months of runway before financing costs, working capital swings, or data-center capex. | 中 | SI001, SI002 |
| CI038 | At $8 million of monthly burn, $160 million supports roughly 20 months of runway before any large up-front data-center purchase. | 中 | SI001, SI002, SI031 |
| CI039 | At $12 million of monthly burn, $160 million supports roughly 13 months of runway, making contract conversion or a follow-on financing trigger more urgent. | 中 | SI001, SI002, SI033 |
| CI040 | A hypothetical $40 million dedicated-compute or data-center outlay would reduce deployable cash to $120 million and shorten the $8 million-burn runway lens to about 15 months. | 中 | SI001, SI009, SI031, SI032 |
| CI041 | Cathedral’s revenue recognition will likely depend on the future contract vehicle: FFP can defer upside until delivery, cost-reimbursement can lower loss risk but cap margin, and IDIQ orders create revenue only when task orders arrive. | 中 | SI006, SI007, SI009, SI010 |
| CI042 | The path to revenue is likely pilot or prototype funding first, then OTA/SBIR/CRADA validation, then IDIQ or program-of-record ordering if mission owners adopt the product. | 中 | SI013, SI014, SI016, SI017, SI018, SI019 |
| CI043 | High stickiness is plausible only after Cathedral lands in classified workflows or mission systems; before that, stickiness remains a thesis rather than a disclosed financial metric. | 中 | SI002, SI021, SI026 |
| CI044 | Cathedral’s current financial model is pre-revenue from a public-evidence standpoint, so ARR, gross margin, CAC payback, net revenue retention, and recognized revenue should be null rather than estimated as operating metrics. | 中 | SI001, SI002, SI003, SI004 |
| CI045 | The practical next-round trigger is likely one of three events: named government contract conversion, material dedicated-compute capex, or evidence that cyber-AI development burn exceeds the $160 million round’s runway. | 中 | SI002, SI003, SI031, SI033 |
| CI046 | The comparable set shows Cathedral is being valued before the financial proof points that Anduril, Shield AI, and Palantir use to support later-stage defense-tech valuations. | 中 | SI002, SI023, SI027, SI028 |
| CE001 | Cathedral is publicly described as a stealth AI-powered military cybersecurity startup seeking U.S. government contracts. | 高 | SE001, SE002, SE003, SE004 |
| CE002 | The only public product definition is AI-driven cyber operations; no public source reviewed disclosed Cathedral SKU names, architecture diagrams, benchmarks, or product documentation. | 高 | SE001, SE002, SE003, SE004 |
| CE003 | Cathedral’s public offensive scope maps most plausibly to AI-assisted reconnaissance, vulnerability discovery, exploit generation, validation, and operator-approved mission packaging. | 中 | SE001, SE002, SE023, SE035, SE036 |
| CE004 | Cathedral’s public defensive scope maps most plausibly to AI-assisted threat detection, vulnerability prioritization, triage, remediation planning, and incident-response automation. | 中 | SE001, SE005, SE006, SE021, SE022 |
| CE005 | Public reporting names Gavin Kliger, Luke Farritor, Marko Elez, and Jack Stein as Cathedral founders and former DOGE staffers. | 高 | SE001, SE002, SE004 |
| CE006 | Kliger’s reported Pentagon chief data officer role and involvement in the Anthropic/Pentagon AI dispute are directly relevant to Cathedral’s model-governance and military-buyer context. | 高 | SE002, SE019, SE032 |
| CE007 | Cathedral is reported to be exploring acquiring or partnering with a data-center provider for dedicated compute for classified work. | 高 | SE001, SE002, SE003, SE004 |
| CE008 | A dedicated compute strategy is technically coherent for offensive military AI because classified data, exploit chains, telemetry, and model weights may need isolation from ordinary commercial SaaS environments. | 中 | SE019, SE026, SE028, SE031, SE033 |
| CE009 | Gold Eagle is a relevant federal analogue because it coordinates AI-assisted vulnerability intake, prioritization, and remediation across government and critical infrastructure. | 高 | SE005, SE006, SE007 |
| CE010 | DARPA’s AI Cyber Challenge asks competitors to design novel AI systems that secure critical software. | 高 | SE008, SE009 |
| CE011 | AIxCC demonstrated autonomous AI cyber reasoning systems that found and repaired synthetic open-source vulnerabilities at competition scale. | 高 | SE008, SE009, SE010 |
| CE012 | The AIxCC Finals GitHub organization exposes OSS-Fuzz-related repositories, providing a developer-signal analogue for autonomous vulnerability-reasoning infrastructure. | 中 | SE010 |
| CE013 | XBOW’s public validation-benchmarks repository is a developer-signal analogue for autonomous offensive-security benchmarking, but its own warning says the benchmarks were saturated by mid-2026. | 中 | SE011 |
| CE014 | Horizon3.ai NodeZero is a commercial analogue for autonomous penetration testing because it runs self-directed pentests, identifies exploitable paths, guides remediation, and verifies fixes. | 高 | SE012, SE013 |
| CE015 | Dreadnode is a commercial analogue for building, evaluating, and deploying offensive security agents. | 高 | SE014, SE015 |
| CE016 | HackerOne’s benchmark write-up is an adverse reliability analogue because it says agentic AI can scale offensive operations but cannot yet replace human penetration testers alone. | 中 | SE016 |
| CE017 | HackerOne states that frontier models are compressing the historical gap between vulnerability discovery and exploitation. | 中 | SE017 |
| CE018 | HackerOne’s red-team guidance warns that AI red teaming remains primarily human-driven and should not be confused with fully automated red-team operations. | 中 | SE018 |
| CE019 | Anthropic says Claude Gov models are deployed for U.S. national-security customers at classified levels, showing that frontier-model vendors can package models for restricted government environments. | 中 | SE019 |
| CE020 | Anthropic’s Claude 4 cyber evaluation reports improvements in vulnerability identification and multi-step attack chains while emphasizing remaining limitations. | 中 | SE020 |
| CE021 | Anthropic’s cyber-defender work explicitly avoided enhancements that clearly favor advanced exploitation or malware, underscoring the safety boundary Cathedral would have to govern differently for offensive missions. | 中 | SE021 |
| CE022 | OpenAI reported disrupting malicious state-affiliated uses of AI for cyber research, scripting, and phishing content, which shows both defensive monitoring practices and adversarial misuse patterns. | 中 | SE022 |
| CE023 | Google Project Zero’s Project Naptime frames LLM offensive-security evaluation as dual-use because AI may help defenders find vulnerabilities while also helping attackers develop offensive capabilities. | 中 | SE023 |
| CE024 | Google’s AI-powered fuzzing work is a concrete analogue for using AI to expand bug-finding workflows before production deployment. | 中 | SE024 |
| CE025 | Palantir AIP is an operating-model analogue for embedding AI into mission workflows rather than shipping a stand-alone chat product. | 中 | SE025 |
| CE026 | FedRAMP is a necessary cloud-authorization reference point if Cathedral delivers any cloud service to U.S. government customers. | 中 | SE026 |
| CE027 | NIST’s AI RMF and 2026 critical-infrastructure profile are relevant controls references for AI-enabled cyber systems operating in high-consequence environments. | 中 | SE027 |
| CE028 | NIST SP 800-53 Rev. 5 is a baseline control catalog Cathedral would likely map to during federal security authorization. | 中 | SE028 |
| CE029 | NIAP/Common Criteria could become relevant if Cathedral ships evaluated endpoint, enclave, or security appliance components into controlled government environments. | 中 | SE029 |
| CE030 | CMMC is relevant because defense contractors handling controlled unclassified information must meet DoD cyber-assurance expectations. | 中 | SE030 |
| CE031 | NIST RMF provides the process backbone for ATO work by integrating security, privacy, and cyber supply-chain risk into the system life cycle. | 中 | SE031 |
| CE032 | DefenseScoop reported that the Pentagon’s JWCC follow-on seeks AI and machine-learning capabilities across classification and impact levels including DDIL environments. | 中 | SE033 |
| CE033 | DefenseScoop’s tactical data-center coverage shows DoD buyers already value cloud-grade compute, storage, and AI capability in remote or connectivity-degraded environments. | 中 | SE034 |
| CE034 | The LLM-agent zero-day paper is an adverse benchmark because it reports that agents still perform poorly on real-world vulnerabilities unknown to the agent ahead of time. | 中 | SE035 |
| CE035 | Cybench frames autonomous vulnerability discovery and exploit execution as capable of real-world impact and therefore requiring measurement and risk controls. | 中 | SE036 |
| CE036 | Cathedral’s actual product maturity is undisclosed; the defensible outside label is stealth prototype-to-early-platform rather than production-proven system. | 中 | SE001, SE002, SE003, SE004 |
| CE037 | Public evidence supports treating vulnerability discovery as a plausible Cathedral module but not as a verified production capability. | 中 | SE001, SE009, SE020, SE023, SE035 |
| CE038 | Exploit-generation and C2-adjacent automation are the highest-risk inferred modules because hallucinated exploit logic, legal boundaries, and operator authorization errors can create mission and safety failures. | 中 | SE016, SE018, SE020, SE023, SE035, SE036 |
| CE039 | Defensive triage and remediation assistance appear nearer-term than fully autonomous offensive action because public analogues emphasize vulnerability intake, code review, fuzzing, and human-guided validation. | 中 | SE005, SE006, SE021, SE024, SE031 |
| CE040 | Any Cathedral deployment into NIPR, SIPR, JWICS, or mission enclaves would likely require RMF/ATO mapping plus cloud, identity, logging, and data-boundary controls before operational use. | 中 | SE026, SE028, SE031, SE032, SE033 |
| CE041 | Building or operating in classified national-security environments implies cleared personnel, restricted model access, enclave-aware telemetry handling, and classified evaluation data. | 中 | SE019, SE031, SE033 |
| CE042 | The compliance surface likely spans FedRAMP or equivalent cloud authorization, DoD impact-level assessment, RMF/ATO packages, CMMC for contractor data, and possibly NIAP for evaluated components. | 中 | SE026, SE028, SE029, SE030, SE031, SE033 |
| CE043 | Model reliability is a material risk because leading public evidence emphasizes evaluation limits, benchmark saturation, human oversight, and incomplete zero-day performance. | 中 | SE011, SE016, SE018, SE020, SE035, SE036 |
| CE044 | The most plausible roadmap is staged: human-in-loop agent prototypes, classified compute buildout, defensive pilots, ATO packages, and only then broader autonomous offensive mission support. | 低 | SE001, SE007, SE019, SE031, SE033, SE034 |
| CE045 | The central diligence gap is that Cathedral has no reviewed public website, product documentation, named deployments, certification package, benchmark report, or compliance artifact. | 中 | SE001, SE002, SE003, SE004 |
| CU001 | Cathedral is publicly described as a stealth military cybersecurity startup aiming to use AI to expand U.S. military cyber capabilities. | 高 | SU001, SU002 |
| CU002 | Reuters reported that Cathedral launched in recent months with a plan to secure U.S. government contracts for offensive and defensive cyber operations against adversaries such as China. | 中 | SU001 |
| CU003 | Cathedral was reported to be co-founded by Gavin Kliger, Luke Farritor, Marko Elez, and Jack Stein, all former DOGE staffers. | 高 | SU001, SU002 |
| CU004 | Cathedral reportedly closed a $160 million financing at a $1.4 billion valuation led by Andreessen Horowitz and Sequoia. | 高 | SU001, SU002 |
| CU005 | The reviewed 2026 Cathedral news sources do not name any paying customer, production deployment, pilot customer, contract award, or partnership customer. | 中 | SU001, SU002, SU003, SU004 |
| CU006 | Cathedral’s own spokesperson declined to comment in the Reuters report, reinforcing the company’s stealth disclosure profile. | 中 | SU001 |
| CU007 | Reuters reported that Cathedral’s founding team maintains deep ties to the Trump administration and national-security officials, including at the Pentagon. | 高 | SU001, SU003 |
| CU008 | USAspending, SAM.gov, and the DoD contracts page are public official channels an investor can use to look for federal award or opportunity evidence, but those public surfaces do not substitute for classified-award diligence. | 中 | SU005, SU006, SU007 |
| CU009 | U.S. Cyber Command is the most direct target buyer because its mission is to direct, synchronize, and coordinate cyberspace planning and operations to defend and advance national interests. | 中 | SU008 |
| CU010 | NSA’s Cybersecurity Collaboration Center is an adjacent buyer or partner surface because it scales intel-driven cybersecurity through industry, interagency, and international partnerships. | 中 | SU009 |
| CU011 | Fleet Cyber Command / 10th Fleet is a naval cyber component with more than 13,000 billets and many Cyber Mission Force units. | 中 | SU010 |
| CU012 | The 16th Air Force is an Air Force cyber and ISR component responsible for cryptologic activities and operating and defending Department networks. | 中 | SU011 |
| CU013 | Marine Corps Forces Cyberspace Command aligns Marine cyberspace operations with U.S. Cyber Command objectives. | 中 | SU012 |
| CU014 | Space Force cyber organizations such as Space Delta 6 operate and maintain space mission systems, creating a service-specific cyber-infrastructure buyer surface. | 中 | SU026 |
| CU015 | CISA is a plausible civilian adjacent account because it coordinates critical-infrastructure security and works with partners to manage cyber and physical infrastructure risk. | 中 | SU013 |
| CU016 | CIA and DIA are plausible intelligence-community stakeholders because CIA provides national-security intelligence and DIA provides intelligence on foreign militaries and operating environments. | 中 | SU014, SU015 |
| CU017 | Five Eyes allied demand is plausible but secondary because the UK Ministry of Defence is actively pursuing strategic partnerships to boost military AI and innovation. | 中 | SU035 |
| CU018 | DIU allows individual or commercial entities to submit solution briefs, including first-time government sellers with applicable commercial solutions. | 高 | SU016, SU017 |
| CU019 | DIU frames commercial defense demand as access to a market exceeding $100 billion, which supports a startup-first outreach path before a full program office sale. | 中 | SU017 |
| CU020 | Defense SBIR/STTR provides a structured path from eligibility and registration through proposal submission, Phase II, transition, and commercialization. | 高 | SU018, SU019 |
| CU021 | SBIR provides equity-free funding through federal agencies to small businesses, making it a possible non-dilutive prototype route for Cathedral. | 中 | SU019 |
| CU022 | GSA’s Multiple Award Schedule is a later-stage purchasing path for listed products and services once a vendor has an approved schedule position. | 中 | SU020 |
| CU023 | DoD Other Transactions are legally binding non-FAR instruments for research, prototype projects, and follow-on production when statutory requirements are met. | 高 | SU021, SU030 |
| CU024 | GAO notes that OTAs are more flexible than traditional contracts and can allow DoD to work with contractors it has not worked with before. | 中 | SU030 |
| CU025 | AFWERX, SOFWERX, and DEFENSEWERX are relevant innovation intermediaries for Cathedral because they package service or special-operations problems into startup-accessible entry points. | 中 | SU027, SU028, SU029 |
| CU026 | FedRAMP is a likely baseline gate for cloud-delivered cyber capability because the FedRAMP Marketplace tracks certified cloud services, authorizing agencies, and assessors. | 中 | SU022 |
| CU027 | Current CMMC posture remains a defense-industrial-base diligence item even though DoD announced suspension of Phase II requirements while retaining Phase I self-assessment requirements. | 中 | SU023 |
| CU028 | NIAP/Common Criteria appears in the compliance stack as a product-assurance diligence topic for security technology sold into national-security environments. | 低 | SU024 |
| CU029 | DCSA states that entities handling classified information for the U.S. government must first obtain facility clearance, making FCL/FOCI a hard gate for classified Cathedral work. | 中 | SU025 |
| CU030 | DoD IL5 documentation describes DISA cloud security requirements and provisional authorization decisions, so Impact Level and ATO readiness are material deployment gates. | 高 | SU036, SU022 |
| CU031 | Cathedral has not publicly disclosed FedRAMP, DoD impact-level authorization, CMMC status, NIAP validation, facility clearance, personnel clearances, or classified program access. | 中 | SU001, SU002, SU023, SU025, SU036 |
| CU032 | Shield AI’s reported U.S. Air Force deal before a $12.7 billion valuation illustrates how mission validation can precede large private defense-tech financing. | 中 | SU031 |
| CU033 | Anduril’s $5 billion Series H at a $61 billion valuation shows the defense-tech market rewards companies that can convert government demand into scaled programs and facilities. | 高 | SU032, SU033 |
| CU034 | Palantir’s 2024 Form 10-K says Gotham has served defense agencies and the intelligence community for over a decade, demonstrating a long sales-and-embedding arc. | 中 | SU034 |
| CU035 | Palantir disclosed $1.071 billion of government revenue for 2024, illustrating the scale possible once a defense-software vendor is embedded in government accounts. | 中 | SU034 |
| CU036 | Incumbent and scaled peers create adoption barriers because government buyers can procure cyber, AI, or mission software through existing contract vehicles and proven vendors rather than a stealth startup. | 中 | SU007, SU020, SU034 |
| CU037 | A realistic Cathedral customer journey is multi-stage: classified relationship access may open doors, but public procurement still tends to move from prototype or SBIR-style work to OTA, schedule, or program-of-record scale. | 中 | SU016, SU018, SU021, SU030 |
| CU038 | A 12-to-24-month enterprise-defense sales-cycle assumption is reasonable for underwriting because the public path includes solicitation, proposal, evaluation, award, security authorization, and transition gates. | 中 | SU016, SU018, SU021, SU022, SU025 |
| CU039 | The absence of named customers is not dispositive for classified cyber work because facility clearance and classified-information rules can limit what vendors can market publicly. | 中 | SU025, SU008, SU009 |
| CU040 | Cathedral’s current customer count should be recorded as null because no public source reviewed discloses accounts, deployments, production users, pilots, NRR, GRR, churn, or renewal metrics. | 中 | SU001, SU002, SU003, SU004 |
| CU041 | Cathedral’s founder access is a go-to-market advantage because recent senior government roles plausibly shorten introductions to Pentagon and national-security buyers. | 中 | SU001 |
| CU042 | The same access is an adverse revolving-door risk because critical coverage frames the move from DOGE into a military-tech startup as controversial and Reuters notes potential scrutiny over government contracts. | 高 | SU001, SU003 |
| CU043 | Budget timing is an adoption barrier because public procurement channels require a funded requirement, a solicitation or vehicle, and an award path before revenue recognition. | 中 | SU006, SU007, SU020 |
| CU044 | The prototype-to-program valley of death is a material risk because SBIR and OTA mechanisms can fund experiments while still requiring transition and commercialization into enduring procurement. | 中 | SU018, SU021, SU030 |
| CU045 | The buyer set is addressable rather than evidenced: Cathedral’s public record supports mission fit and access, not customer adoption. | 中 | SU001, SU004, SU008, SU009 |
| CR001 | Cathedral closed a $160 million round at a reported $1.4 billion valuation in July 2026. | 高 | SR001, SR002, SR003 |
| CR002 | Cathedral was co-founded by former DOGE staffers Gavin Kliger, Luke Farritor, Marko Elez, and Jack Stein. | 高 | SR001, SR002 |
| CR003 | Public reporting describes Cathedral’s mission as AI-driven U.S. military cyber operations with both offensive and defensive capabilities. | 高 | SR001, SR002 |
| CR004 | Andreessen Horowitz and Sequoia Capital reportedly led Cathedral’s round and both took board seats. | 中 | SR001, SR010 |
| CR005 | No reviewed public source disclosed Cathedral revenue, production customers, or awarded government contracts. | 中 | SR001, SR002, SR042, SR043 |
| CR006 | Cathedral’s founding team has close reported ties to the Trump administration and national security officials. | 中 | SR001, SR005 |
| CR007 | Reuters reported that Cathedral could face scrutiny over government contracts if Democrats gained congressional power after the midterms. | 中 | SR001 |
| CR008 | Startup Fortune characterized Cathedral’s valuation as a bet on access and founder knowledge rather than inspectable revenue. | 中 | SR002 |
| CR009 | Vanity Fair described DOGE as an expedited revolving door into defense contracting and venture-backed government-facing startups. | 中 | SR005, SR004 |
| CR010 | Vanity Fair quoted watchdog and investor concerns that weak ethics restrictions and conflict-of-interest issues could hinder DOGE-alumni startups. | 中 | SR005 |
| CR011 | Kliger was reported to have served until recently as the Pentagon chief data officer and to have worked near military AI issues. | 中 | SR001, SR005 |
| CR012 | Vanity Fair reported Kliger worked on GenAI.mil and AI-related Pentagon contracting efforts, increasing perceived insider-knowledge risk. | 中 | SR005 |
| CR013 | A Defense Department official told Vanity Fair that Kliger is subject to a one-year cooling-off period, while federal post-employment regulations govern certain communications and appearances. | 高 | SR005, SR025 |
| CR014 | FAR Subpart 9.5 addresses organizational conflicts of interest, including unfair competitive advantage concerns. | 中 | SR023 |
| CR015 | FAR 3.104 establishes procurement-integrity restrictions around contractor bid or proposal information and source-selection information. | 中 | SR024 |
| CR016 | Federal post-employment rules create restrictions that can matter when former officials communicate back to their prior agencies. | 中 | SR025 |
| CR017 | Federal ethics rules prohibit using public office for private gain, including implying government sanction of private activity. | 中 | SR026 |
| CR018 | CREW says DOGE’s structure, staffing, budget, and operations lack clarity and require public records scrutiny. | 中 | SR047 |
| CR019 | CREW has sought DOGE records to test compliance with ethics, transparency, legal-authority, funding, and records-preservation obligations. | 中 | SR047 |
| CR020 | AP reported that Marko Elez resigned after being linked to racist social-media posts and that Musk said he would bring him back. | 高 | SR011, SR001 |
| CR021 | Reuters reported Elez worked at Treasury during DOGE and raised concerns from a judge after accessing highly sensitive material. | 中 | SR001, SR011 |
| CR022 | AP reported Elez was among DOGE employees at the center of a Treasury payment-system access controversy. | 中 | SR011, SR015, SR016 |
| CR023 | GovExec reported GAO found Treasury missed security controls in providing DOGE system access and did not always enforce protocols. | 中 | SR017 |
| CR024 | GovExec reported GAO findings that Elez sent unencrypted USAID payment information to DOGE associates without agency approval. | 中 | SR017 |
| CR025 | WIRED identified several DOGE engineers, including Farritor and Kliger, as young and having little or no government experience when put into important roles. | 中 | SR012 |
| CR026 | WIRED reported concerns that DOGE-affiliated personnel had access to sensitive government systems and could bypass normal controls. | 中 | SR012 |
| CR027 | WIRED reported that DOGE may have misused Social Security data, adding to the adverse data-access narrative around DOGE alumni. | 中 | SR014 |
| CR028 | Lawfare argues private-sector offensive cyber participation requires defining objectives, scope, targets, legal authorities, and liability. | 中 | SR027 |
| CR029 | Lawfare warns policymakers should mitigate escalation and diplomatic-fallout risks before expanding private-sector cyber-offense roles. | 中 | SR027 |
| CR030 | The Atlantic Council describes the zero-day and offensive-cyber supply chain as opaque, fragmented, expensive, and strategically sensitive. | 中 | SR031 |
| CR031 | The Atlantic Council reports private firms often create offensive cyber capabilities for governments and that China’s offensive cyber industry is increasingly integrated with AI institutions. | 中 | SR031 |
| CR032 | CSIS argues harmful cyber activity can occur below the use-of-force threshold, limiting the usefulness of deterrence alone. | 中 | SR029 |
| CR033 | CSIS notes DOD autonomy policy is widely misunderstood and that cyber weapons systems are exempted from some autonomous-weapons review pathways. | 中 | SR030 |
| CR034 | CSIS says government cyber collaboration faces information-sharing, classification, and liability constraints. | 中 | SR028 |
| CR035 | ITAR regulations define controlled defense articles and defense services and place the United States Munitions List in 22 CFR Part 121. | 高 | SR032, SR033 |
| CR036 | BIS and EAR sources show export controls can apply to advanced computing and other controlled items beyond traditional weapons. | 高 | SR034, SR035 |
| CR037 | The Wassenaar Arrangement maintains control lists for conventional arms and dual-use goods and technologies, reinforcing international export-control constraints. | 中 | SR036 |
| CR038 | Because Cathedral’s reported work is military cyber operations, export-control review is a gating diligence item before any foreign customer, investor, data-center, or personnel expansion. | 中 | SR001, SR032, SR034, SR036 |
| CR039 | Classification and stealth limit independent verification because public reporting discloses Cathedral’s mission and financing but not product specifications, contracts, revenue, or performance data. | 中 | SR001, SR002, SR042, SR043 |
| CR040 | Booz Allen, Leidos, Palantir, and Anduril all have public cyber, defense, or platform proof that Cathedral has not yet matched publicly. | 中 | SR037, SR038, SR039, SR040 |
| CR041 | Washington Technology’s 2026 Top 100 ranking illustrates the scale and durability of established government contractors competing for federal technology work. | 中 | SR041 |
| CR042 | SAM.gov and USAspending.gov are core public procurement and spending surfaces, but public reporting rather than those portals currently anchors Cathedral’s public contract story. | 中 | SR042, SR043, SR001 |
| CR043 | SBIR and DIU materials show official pathways for commercial technology vendors, but those pathways do not by themselves prove revenue or procurement success for Cathedral. | 中 | SR044, SR045 |
| CR044 | Cathedral’s reported plan to secure U.S. government contracts creates single-buyer concentration until commercial, allied, or multi-agency revenue is disclosed. | 中 | SR001, SR038, SR042, SR043 |
| CR045 | The combination of a $1.4 billion valuation, no disclosed revenue, and entrenched incumbents makes valuation fragility a high-impact commercial risk. | 中 | SR001, SR002, SR037, SR041 |
| CR046 | Bulletin coverage of cyber norms underscores that cyber operations remain an international-norms problem, not merely a domestic procurement issue. | 中 | SR046 |
| CR047 | The White House executive order established DOGE inside the Executive Office of the President, making Cathedral’s DOGE-alumni identity politically legible rather than incidental. | 中 | SR018, SR019 |
| CR048 | Cathedral’s reported search for dedicated compute or a data-center partnership adds an infrastructure dependency to its cyber-operations plan. | 中 | SR001, SR002 |
| CV001 | Cathedral raised $160 million at a $1.4 billion post-money valuation in July 2026. | 高 | SV001, SV002, SV003, SV004 |
| CV002 | The $160 million round at a $1.4 billion post-money valuation implies approximately $1.24 billion of pre-money value. | 中 | SV001, SV002 |
| CV003 | The same round implies that new investors bought roughly 11.4% of Cathedral on a post-money basis. | 中 | SV001, SV002 |
| CV004 | Cathedral has no disclosed revenue or ARR, so a revenue or ARR valuation multiple cannot be computed from public evidence. | 高 | SV001, SV002 |
| CV005 | Cathedral has no disclosed government contract wins as of the fetched public reporting. | 高 | SV001, SV002 |
| CV006 | Public reporting frames Cathedral as a stealth military cyber and AI startup seeking U.S. government contracts, not as a company with proven commercial traction. | 高 | SV001, SV003, SV004 |
| CV007 | Reuters reported that Cathedral's $1.4 billion valuation reflects investor confidence in the founding team's government relationships rather than any product track record. | 高 | SV001, SV002, SV003 |
| CV008 | The valuation appears to price government-access and team-signal scarcity more than currently observable product or revenue traction. | 中 | SV001, SV002, SV021 |
| CV009 | Andreessen Horowitz and Sequoia led the Cathedral financing and both took board seats, which is a meaningful signaling premium for a new stealth company. | 高 | SV001, SV002, SV003 |
| CV010 | a16z’s American Dynamism platform publicly emphasizes national-interest sectors, helping explain why a defense-cyber startup can receive thematic investor support before revenue. | 中 | SV027, SV001 |
| CV011 | Anduril raised $5 billion at roughly a $61 billion valuation in 2026. | 高 | SV005, SV006, SV007, SV008 |
| CV012 | Anduril had publicly reported revenue scale, including reporting that revenue doubled in 2025 to about $2.2 billion. | 高 | SV005, SV008 |
| CV013 | Anduril’s $61 billion valuation on about $2.2 billion of reported 2025 revenue implies a trailing revenue multiple near 27.7x. | 中 | SV005, SV008 |
| CV014 | Anduril is a more mature comp than Cathedral because it has public product breadth, revenue scale, facilities expansion, and a late-stage funding profile. | 高 | SV008, SV029, SV030 |
| CV015 | Shield AI raised a 2026 Series G at a $12.7 billion post-money valuation after defense aircraft and autonomy traction. | 高 | SV009, SV010 |
| CV016 | Shield AI previously reached a $5.3 billion valuation in 2025 after a $240 million financing. | 中 | SV011, SV012 |
| CV017 | Shield AI is a stronger proof-stage comp than Cathedral because public coverage ties its valuation to autonomous aircraft programs and U.S. Air Force-related traction. | 高 | SV009, SV010, SV012 |
| CV018 | Palantir’s 2026 public-market frame is a high-multiple government and commercial software reference rather than an early-stage startup comp. | 高 | SV014, SV016, SV020 |
| CV019 | Palantir reported Q1 2026 revenue growth and U.S. government revenue growth, showing that its valuation is supported by operating revenue disclosure. | 高 | SV014, SV015, SV016 |
| CV020 | CompaniesMarketCap and Stock Analysis provide observable Palantir market-cap, revenue, and P/S context, unlike Cathedral where revenue is undisclosed. | 中 | SV013, SV018, SV019, SV020 |
| CV021 | Palantir’s public price-to-sales multiple can serve as an aggressive upper-bound reference, but it should not be mechanically applied to Cathedral before contracts and revenue exist. | 中 | SV016, SV020, SV002 |
| CV022 | Rebellion Defense is relevant only as a private defense-software reference because public sources do not provide an equivalent current valuation or revenue multiple. | 中 | SV028, SV002 |
| CV023 | Typical seed-stage valuation benchmarks are far below Cathedral’s $1.4 billion post-money mark. | 中 | SV023, SV024, SV026 |
| CV024 | Typical Series A benchmark discussions also sit far below Cathedral’s $1.24 billion implied pre-money valuation. | 中 | SV024, SV025, SV026 |
| CV025 | Even if defense AI deserves a premium, Cathedral’s valuation at founding is an outlier against ordinary seed and Series A pricing ranges. | 高 | SV001, SV023, SV024, SV025 |
| CV026 | At a 10x revenue multiple, Cathedral would need roughly $140 million of annual revenue to support a $1.4 billion valuation. | 中 | SV001, SV020 |
| CV027 | At a 5x revenue multiple, Cathedral would need roughly $280 million of annual revenue to support a $1.4 billion valuation. | 中 | SV001, SV020 |
| CV028 | At a 15x revenue multiple, Cathedral would still need roughly $93 million of annual revenue to support a $1.4 billion valuation. | 中 | SV001, SV013, SV020 |
| CV029 | A bull case requires Cathedral to convert founder access into material U.S. government cyber contract value within roughly 18 to 24 months. | 中 | SV001, SV021, SV022 |
| CV030 | A base case is that Cathedral raises enough capital to build product and pursue pilots but remains overvalued until contract evidence appears. | 中 | SV001, SV002, SV021 |
| CV031 | A bear case is that procurement, politics, or overvaluation pressure prevent Cathedral from growing into the mark before dilution or repricing. | 中 | SV001, SV002, SV021, SV022 |
| CV032 | The defense-tech bubble critique directly applies to Cathedral because it has a large mark before public revenue, contracts, or product disclosure. | 中 | SV002, SV021, SV022 |
| CV033 | Defense-tech investors can still rationally underwrite the category because geopolitical demand and American Dynamism themes create durable budget tailwinds. | 中 | SV005, SV021, SV027 |
| CV034 | The appropriate recommendation is research-more rather than buy because the valuation is already priced like a scaled winner while public traction is absent. | 高 | SV001, SV002, SV021 |
| CV035 | Confidence should be low because the decisive diligence inputs—revenue, contract pipeline, product capability, security clearances, and procurement path—are private or undisclosed. | 中 | SV001, SV002 |
| CV036 | Risk rating should be high because the mark combines pre-revenue pricing, political exposure, procurement uncertainty, and future dilution risk. | 高 | SV001, SV002, SV021, SV022 |
| CV037 | Valuation stance should be expensive because public evidence does not yet support a $1.4 billion post-money price on fundamentals. | 高 | SV001, SV002, SV023, SV024 |
| CV038 | A plausible exit path requires Cathedral to become a durable cyber-defense software supplier with multi-year government contracts, not merely a team premium story. | 中 | SV001, SV014, SV016, SV029 |
| CV039 | Future rounds could dilute early investors if the company must finance data-center capacity, compliance, and long procurement cycles before revenue scales. | 中 | SV001, SV021, SV022 |
| CV040 | Political risk matters because reporting identifies Cathedral’s ties to DOGE and the Trump administration as potential sources of scrutiny if control of Congress shifts. | 高 | SV001, SV002 |
| CV041 | The premium decomposition is best understood as team premium plus investor-signal premium plus defense-AI market premium plus scarcity premium, offset by a traction discount. | 中 | SV001, SV002, SV021, SV027 |
| CV042 | The largest single negative adjustment should be a traction discount because revenue and contract value are both undisclosed. | 高 | SV001, SV002 |
| CV043 | Diligence should request contract pipeline, bid status, security and accreditation path, technical proof, data-center economics, and cap-table preference terms before any investment decision. | 中 | SV001, SV002, SV021 |
| CV044 | A thesis-break trigger would be no credible paid pilot or government contracting path within 18 to 24 months after the round. | 中 | SV001, SV021, SV022 |
| CV045 | Another thesis-break trigger would be disclosure that the valuation rests mostly on political access rather than proprietary technical capability. | 中 | SV001, SV002, SV022 |
| CV046 | The IC debate should balance a real defense-tech boom and elite investor signal against an unusually high pre-revenue mark with no public product, revenue, or contract proof. | 高 | SV001, SV002, SV005, SV021, SV027 |
| 编号 | 出版方 | 标题 | 引文 |
|---|---|---|---|
| SO001 | U.S. News & World Report / Reuters | Exclusive-DOGE Alumni Launch Military Cyber Startup With $1.4 Billion Valuation | A team of former DOGE employees raised a major funding round for a startup that aims to use AI to expand U.S. military cyber capabilities. |
| SO002 | The Next Web | Four former DOGE staffers raised $160 million at a $1.4 billion valuation for an AI military cyber startup | Cathedral, a stealth military cybersecurity startup founded by four former Department of Government Efficiency staffers, has raised $160 million at a $1.4 billion valuation. |
| SO003 | Reuters | DOGE alumni launch military cyber startup with $1.4 billion valuation | Origin page required JavaScript and ad-block disabling during fetch; Reuters text was available through the U.S. News syndication source. |
| SO004 | Hoodline | Cathedral: Ex-DOGE Engineers Launch $1.4B Military Cyber Startup | Three former engineers from Elon Musk's controversial DOGE initiative have quietly spun out of Washington and into the venture spotlight with Cathedral. |
| SO005 | Gizmodo | DOGE Guys Who Didn’t Save Us Any Money Rake in Cash With New Military Tech Startup | DOGE Guys Who Didn’t Save Us Any Money Rake in Cash With New Military Tech Startup. |
| SO006 | Cyber Daily | Ex-DOGE engineers launch new AI firm to bolster US military cyber | Ex-DOGE engineers Gavin Kliger, Luke Farritor, Marko Elez and Jack Stein formed Cathedral. |
| SO007 | The White House | White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination | President Trump’s bold vision to secure and accelerate American artificial intelligence innovation is being actioned through the creation of GOLD EAGLE. |
| SO008 | TechCrunch | Anduril raises $5B, doubles valuation to $61B | Anduril has raised a $5 billion Series H round at a $61 billion valuation. |
| SO009 | Forbes | Anduril’s $61 Billion Valuation Is A Bet On Pentagon Speed | The Washington Post reported that Anduril raised $5 billion at a $61 billion valuation. |
| SO010 | The Next Web | Musk allies back a private-sector DOGE as ex-staffers launch Special | Special is launching with the backing of Andreessen Horowitz and other Musk-adjacent investors. |
| SO011 | The Atlantic | The DOGE Bros Want Another Shot | DOGE alumni make splashy announcements about entering complex industries with scant qualifications while promising to root out waste. |
| SO012 | DOGE | Work | DOGE: Department of Government Efficiency | The people voted for major reform. |
| SO013 | The White House | Establishing And Implementing The President's Department Of Government Efficiency | This Executive Order establishes the Department of Government Efficiency to implement the President’s DOGE Agenda. |
| SO014 | Government Executive | Treasury missed security controls in giving DOGE system access, GAO finds | Treasury missed security controls in giving DOGE system access, GAO finds. |
| SO015 | Government Executive | What DOGE taught us about AI and federal workers | DOGE abruptly shut down USAID and pushed generative AI uses across federal operations. |
| SO016 | Nextgov/FCW | What DOGE taught us about AI and federal workers | DOGE’s use of AI in federal workforce changes became a lesson in governance and institutional trust. |
| SO017 | Yahoo News | DOGE officially shuts down | The Department of Government Efficiency shut down operations on July 4. |
| SO018 | The Fiscal Times | DOGE Is Officially Done | The Department of Government Efficiency came to an official end this past weekend. |
| SO019 | The Next Web | The emails that broke Anthropic and the Pentagon apart | For months, the fight between Anthropic and the Pentagon had been escalating. |
| SO020 | CNBC | Trump admin allows Anthropic to release Mythos AI model to some companies, government agencies | The Trump administration has agreed to allow Anthropic to release its new Claude Mythos 5 model to some companies and government agencies. |
| SO021 | Politico | Trump picked a fight with Anthropic. Now the administration is backing off. | Trump picked a fight with Anthropic. Now the administration is backing off. |
| SO022 | Breaking Defense | Air Force pushing contractors to purge Anthropic by Sept. 1: Memo | The Air Force Research Laboratory is pushing its contractors to purge all Anthropic products from their systems by Sept. 1. |
| SO023 | eWeek | Anthropic vs Washington: A Timeline of Claude’s Collision With the US Government | The dispute over AI guardrails grew into a confrontation between a frontier AI company and the US government. |
| SO024 | Andreessen Horowitz | American Dynamism: Supporting the National Interest | American Dynamism supports founders and companies that serve the national interest. |
| SO025 | Andreessen Horowitz | Portfolio | Andreessen Horowitz | Andreessen Horowitz lists AI and American Dynamism among portfolio focus areas. |
| SO026 | Sequoia Capital | Our Companies | Sequoia lists its company portfolio and investment stages on its official site. |
| SO027 | Sequoia Capital | AI Ascent 2026 | Sequoia hosted more than 150 leading founders and researchers in AI at AI Ascent IV. |
| SO028 | SecurityWeek | White House Launches AI-Driven Gold Eagle Vulnerability Coordination Initiative | Gold Eagle is a coordination mechanism intended to speed detection, prioritization and patching of vulnerabilities. |
| SO029 | Dark Reading | Gold Eagle Clearinghouse Targets Real Gap, but How Is Unclear | Gold Eagle targets a real gap, but how is unclear. |
| SO030 | CSO Online | White House launches AI-driven vulnerability clearinghouse to speed cyber remediation | The White House is launching a program to help government agencies and critical infrastructure operators identify, prioritize, and remediate vulnerabilities. |
| SO031 | GovCon Wire | The White House’s Gold Eagle Initiative: Strengthening Public-Private Partnerships to Safeguard Critical Infrastructure in the AI Era | The Gold Eagle Initiative is framed as strengthening public-private partnerships to safeguard critical infrastructure in the AI era. |
| SM001 | Office of Management and Budget | President’s Budget | |
| SM002 | Office of the Under Secretary of Defense Comptroller | Budget Materials | |
| SM003 | U.S. Cyber Command | Mission and Vision | |
| SM004 | National Security Agency | Cybersecurity Collaboration Center | |
| SM005 | U.S. Government Accountability Office | High Risk List | |
| SM006 | U.S. Government Accountability Office | Cybersecurity: OMB Should Improve Information Security Performance Metrics | |
| SM007 | Congressional Research Service | Defense Acquisitions: How and Where DOD Spends and Reports Its Contracting Dollars | |
| SM008 | DARPA | AI Cyber Challenge | |
| SM009 | Defense SBIR/STTR | SBIR/STTR Programs | |
| SM010 | Andreessen Horowitz | American Dynamism | |
| SM011 | MarketsandMarkets | Artificial Intelligence in Military Market | |
| SM012 | Grand View Research | Artificial Intelligence in Military Market Report | |
| SM013 | MarketsandMarkets | Cyber Warfare Market | |
| SM014 | Mordor Intelligence | Cyber Warfare Market Report | |
| SM015 | Grand View Research | Cybersecurity Market Size and Share Report, 2026-2033 | |
| SM016 | USAspending.gov | USAspending.gov | |
| SM017 | SAM.gov | Contract Opportunities | |
| SM018 | U.S. Department of Defense | Contracts | |
| SM019 | Acquisition.gov | FAR Part 16 - Types of Contracts | |
| SM020 | CISA | About CISA | |
| SM021 | CISA | Cybersecurity Best Practices | |
| SM022 | CISA | Zero Trust Maturity Model | |
| SM023 | Department of Defense CIO | DoD Zero Trust Strategy | |
| SM024 | Defense Innovation Unit | Solutions | |
| SM025 | Defense Innovation Unit | Work With Us | |
| SM026 | SBIR.gov | About SBIR and STTR | |
| SM027 | NIST | Cybersecurity Framework | |
| SM028 | NIST | Artificial Intelligence | |
| SM029 | Sacra | Anduril company profile | |
| SM030 | Los Angeles Times | Anduril to invest another $1 billion in California with new Long Beach campus | |
| SM031 | DAU Adaptive Acquisition Framework | Other Transactions | |
| SM032 | U.S. Government Accountability Office | Other Transaction Agreements: DOD Can Improve Planning for Consortia Awards | |
| SP001 | Reuters via U.S. News | Exclusive-DOGE Alumni Launch Military Cyber Startup With $1.4 Billion Valuation | Cathedral closed on a $160 million funding round that valued the company at $1.4 billion. |
| SP002 | The Next Web | Four former DOGE staffers raised $160 million at a $1.4 billion valuation for an AI military cyber startup | |
| SP003 | Startup Fortune | Four DOGE alumni raise at a $1.4 billion valuation for Cathedral, a stealth military cybersecurity startup backed by a16z and Sequoia | Cathedral has raised the money. Now it has to show whether DOGE access converts into signed Pentagon work. |
| SP004 | TechCrunch | Anduril raises $5B, doubles valuation to $61B | Anduril has raised a $5 billion Series H round at a $61 billion valuation. |
| SP005 | U.S. Securities and Exchange Commission | Palantir Technologies Inc. 2024 Form 10-K | We have built four principal software platforms, Palantir Gotham, Palantir Foundry, Palantir Apollo, and Palantir Artificial Intelligence Platform. |
| SP006 | UK Ministry of Defence | New strategic partnership to unlock billions and boost military AI and innovation | |
| SP007 | Shield AI | Hivemind | Since piloting the first fully autonomous combat mission in 2018, Hivemind has become the trusted AI pilot operating alongside U.S. and allied forces. |
| SP008 | Shield AI | Shield AI raises $240M at $5.3B valuation to scale Hivemind Enterprise | |
| SP009 | TechCrunch | Defense startup Shield AI lands $12.7B valuation, up 140%, after US Air Force deal | |
| SP010 | Rebellion Defense | Rebellion homepage | An INTELLIGENCE SHIELD for critical assets combining next-gen radar, AI fusion, and full operational software and support. |
| SP011 | Associated Press via Inc. | Inside the Collapse of Security Experts’ Cyber Startup IronNet | The never-profitable company announced it was shutting down and firing its employees after running out of money. |
| SP012 | Stretto | IronNet, Inc., et al. bankruptcy case | |
| SP013 | Horizon3.ai | NodeZero: The World’s Most Experienced AI Hacker | More than 5,200 organizations worldwide relying on NodeZero. |
| SP014 | Business Wire | Horizon3.ai Secures Investment from Prosperity7 Ventures to Protect AI Datacenters and Critical Infrastructure | |
| SP015 | Horizon3.ai | The NodeZero Platform | NodeZero transforms how organizations secure their environments by running unlimited pentests. |
| SP016 | Business Wire | XBOW Raises $120M to Scale its Autonomous Hacker | Valued at over $1B, XBOW is Accelerating AI-powered Offensive Security to Help Defenders Outpace Modern Attackers. |
| SP017 | Accenture | Accenture Invests in XBOW to Advance Continuous Offensive Security Testing and Exposure Management | New partnership will scale continuous, AI-driven security testing and exposure management. |
| SP018 | Dreadnode | Dreadnode — AI Infrastructure for Security Agents | AI-native security can’t happen without infrastructure. |
| SP019 | Dreadnode | Research | |
| SP020 | FinTech Global | Dreadnode captures $14m to fortify offensive AI security capabilities | Dreadnode, an emerging startup specializing in offensive AI security, has recently secured a $14m Series A funding round. |
| SP021 | RunSafe Security | CISA’s 2026 Memory Safety Deadline | CISA has made memory safety a key focus of its Secure by Design initiatives. |
| SP022 | PR Newswire | RunSafe Security Raises $12 Million in Series B Funding | |
| SP023 | Help Net Security | RunSafe Security raises $12 million to reduce attack surface in critical infrastructure | |
| SP024 | Two Six Technologies | Two Six Technologies Captures Strategic Win with Award on $4 Billion DTRA Contract | Two Six supports national security customers across the Department of Defense, including U.S. Special Operations Command, U.S. Cyber Command and DARPA. |
| SP025 | Two Six Technologies | Sentr — Command the Information Environment | AI-driven command of the information environment — sense, plan, and coordinate effects at scale. |
| SP026 | Booz Allen Hamilton | Cybersecurity | Cyberattacks move at AI speed. Cyber defense must too. |
| SP027 | Leidos | Cybersecurity | Offensive, defensive, and cyber resilience across every mission. |
| SP028 | SAIC | SAIC Cybersecurity | |
| SP029 | CACI | Cyber | CACI advances automation and AI/ML across operations to purposefully accelerate mission success. |
| SP030 | Peraton | Cyber | |
| SP031 | ManTech | ACTP | |
| SP032 | Parsons | Cybersecurity For Global Events | |
| SP033 | GovConWire | 8 Companies Awarded $1.9B in Navy Cyberspace Operations Support Contract Options | The U.S. Navy has awarded eight companies contract options worth $1.86 billion combined. |
| SP034 | Washington Technology | 2026 Top 100 | Our annual rankings are based on an analysis of federal spending on IT, systems integration, telecommunications, professional services and other high-tech needs. |
| SP035 | GovConWire | GSA Unveils 43 Phase 1 Awardees for Alliant 3 GWAC | The General Services Administration has unveiled the first phase of awards under the Alliant 3 governmentwide acquisition contract. |
| SP036 | Washington Technology | Battle for $245M cyber warfare contract gets new start | The Army has agreed to re-evaluate proposals submitted by Booz Allen Hamilton, Peraton and ManTech. |
| SP037 | Atlantic Council | Mythical Beasts: Investigating the role of intermediaries in the proliferation of offensive cyber capabilities | |
| SP038 | Atlantic Council | Crash (exploit) and burn: Securing the offensive cyber supply chain to counter China in cyberspace | Zero-day exploitation is becoming more difficult, opaque, and expensive, leading to feast-or-famine contract cycles. |
| SP039 | Lawfare | Partners or Provocateurs? Private-Sector Involvement in Offensive Cyber Operations | |
| SP040 | Cyber Defense Review | Exploit Brokers and Offensive Cyber Operations | |
| SP041 | Vannevar Labs | Restoring Deterrence, Reclaiming Advantage | |
| SI001 | ExecutiveBiz | Cyber Startup Cathedral Raises $160M at $1.4B Valuation | Cathedral has secured $160 million in a funding round ... valued the company at $1.4 billion. |
| SI002 | Startup Fortune | Four DOGE alumni raise at a $1.4 billion valuation for Cathedral | Not a product launch. Not a customer announcement. A company with almost no public footprint has raised unicorn money. |
| SI003 | citybiz | Andreessen Horowitz, Sequoia Capital Lead $160M Round for Former DOGE Staff’s Venture | The company ... was valued at $1.4 billion in the financing, which was led by Andreessen Horowitz and Sequoia Capital. |
| SI004 | EquityPandit | Former DOGE Officials Launch AI Defense Startup Cathedral | The company has raised $160 million in a funding round led by venture capital firms Andreessen Horowitz and Sequoia Capital. |
| SI005 | Acquisition.GOV | Part 16 - Types of Contracts | Part 16 describes contract types and ordering rules for federal acquisitions. |
| SI006 | Acquisition.GOV | 16.202-1 Description | A firm-fixed-price contract provides for a price that is not subject to adjustment based on contractor cost experience. |
| SI007 | Acquisition.GOV | 16.301-1 Description | Cost-reimbursement types of contracts provide for payment of allowable incurred costs. |
| SI008 | Acquisition.GOV | 16.401 General | Incentive contracts relate the amount of profit or fee payable to the contractor’s performance. |
| SI009 | Acquisition.GOV | 16.504 Indefinite-quantity contracts | An indefinite-quantity contract provides for an indefinite quantity, within stated limits, of supplies or services during a fixed period. |
| SI010 | Acquisition.GOV | 16.505 Ordering | Orders shall clearly describe all services to be performed or supplies to be delivered. |
| SI011 | Acquisition.GOV | 15.101 Best value continuum | An agency can obtain best value in negotiated acquisitions through source selection approaches where cost or price importance may vary. |
| SI012 | SBIR.gov | About | SBIR provides equity free funding through federal agencies to American small businesses. |
| SI013 | Defense SBIR/STTR | DoW Office for Small Business Innovation | The Defense SBIR/STTR flow runs from eligibility and proposal to post-contract award, Phase II, transition and commercialization. |
| SI014 | Defense SBIR/STTR | Defense SBIR/STTR - Funding Opportunities | DoW uses the Broad Agency Announcement funding mechanism to procure basic and applied research. |
| SI015 | General Services Administration | Small Business Innovation Research and Small Business Technology Transfer | The SBIR and STTR programs are highly competitive programs that encourage domestic small businesses to engage in federal R&D. |
| SI016 | Department of Homeland Security | CRADAs | A CRADA is a written agreement that facilitates R&D collaboration between federal laboratories and non-federal entities. |
| SI017 | Congressional Research Service | Department of Defense Use of Other Transaction Authority | The Department of Defense obligates more than $300 billion annually to buy goods and services and support R&D. |
| SI018 | Defense Innovation Unit | About DIU | DIU accelerates the adoption of leading commercial technology throughout the military. |
| SI019 | Defense Innovation Unit | Tap Into a $100+ Billion Market | Any individual or commercial entity is eligible to respond to a DIU solicitation. |
| SI020 | USAspending.gov | Government Spending Open Data | USAspending is the official open data source of federal spending information, including contracts, grants, and loans. |
| SI021 | SAM.gov | Contract Opportunities | SAM.gov is the federal contract opportunities surface for government solicitations. |
| SI022 | U.S. Department of Defense | Contracts | The Defense Department publishes contract award notices on its official contracts page. |
| SI023 | Securities and Exchange Commission | Palantir Technologies 2025 Form 10-K | Revenue increased by $1.6 billion, or 56%, for the year ended December 31, 2025 compared to 2024. |
| SI024 | Securities and Exchange Commission | Palantir Technologies Q1 2026 Form 10-Q | Revenue from government customers and U.S. customers remained a meaningful source of revenue growth. |
| SI025 | Securities and Exchange Commission | Palantir Technologies 2024 Form 10-K | Revenue from government customers increased by $347.4 million, or 28%, for the year ended December 31, 2024 compared to 2023. |
| SI026 | Palantir | Getting started with Palantir | The Palantir platform is used by organizations from startups to multinational companies to governments around the world. |
| SI027 | Sacra | Anduril revenue, valuation & funding | Sacra estimates that Anduril hit $2.2B in revenue in 2025, up 120% from $1B in 2024. |
| SI028 | Sacra | Shield AI revenue, valuation & funding | Sacra estimates that Shield AI hit approximately $300M in revenue for the year ending March 2025. |
| SI029 | Los Angeles Times | Anduril to invest another $1 billion in California with new Long Beach campus | Anduril Industries ... will expand in Long Beach with a new $1-billion complex near the city’s airport. |
| SI030 | GeekWire | Defense giant Anduril is quietly building autonomous warships on Seattle’s historic ship canal | Anduril Industries is building a new class of autonomous warships on Seattle’s historic ship canal. |
| SI031 | Goldman Sachs | AI is poised to drive 160% increase in data center power demand | Goldman Sachs Research estimates that data center power demand will grow 160% by 2030. |
| SI032 | U.S. Department of Energy | DOE Releases New Report Evaluating Increase in Electricity Demand from Data Centers | Domestic energy usage from data centers is expected to double or triple by 2028. |
| SI033 | Epoch AI | Training compute of frontier AI models grows by 4-5x per year | Training compute of frontier AI models grows by 4-5x per year. |
| SI034 | Andreessen Horowitz | American Dynamism: Supporting the National Interest | American Dynamism supports companies serving the national interest. |
| SI035 | Small Business Administration | Federal Contracting | The SBA explains the federal contracting path for small businesses. |
| SI036 | Government Accountability Office | DOD Fraud Risk Management | DOD spent about $422 billion on contracts in FY 2020 and has been the target of contracting-related fraud schemes. |
| SE001 | U.S. News & World Report / Reuters | Exclusive-DOGE Alumni Launch Military Cyber Startup With $1.4 Billion Valuation | plans to secure U.S. government contracts to bolster AI-driven cyber operations, including offensive and defensive capabilities |
| SE002 | The Next Web | Four former DOGE staffers raised $160 million at a $1.4 billion valuation for an AI military cyber startup | The company plans to secure US government contracts for AI-driven offensive and defensive cyber operations against adversaries including China. |
| SE003 | Hoodline | Cathedral: Ex-DOGE Engineers Launch $1.4B Military Cyber Startup | exploring either a purchase of or partnership with a data-center provider to secure dedicated compute |
| SE004 | Cyber Daily | Ex-DOGE engineers launch new AI firm to bolster US military cyber | former Department of Government Efficiency (DOGE) engineers have formed a new AI cyber start-up for military defence and cyber operations |
| SE005 | The White House | White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination | GOLD EAGLE, a clearinghouse that enables unprecedented cybersecurity vulnerability coordination |
| SE006 | SecurityWeek | White House Launches AI-Driven Gold Eagle Vulnerability Coordination Initiative | speed up the detection, prioritization, and patching of vulnerabilities in critical infrastructure |
| SE007 | Dark Reading | Gold Eagle Clearinghouse Targets Real Gap, But How Is Unclear | Gold Eagle targets a real gap, but how is unclear. |
| SE008 | DARPA | AIxCC | DARPA | AIxCC will ask competitors to design novel AI systems to secure the software critical to all Americans. |
| SE009 | AI Cyber Challenge | DARPA’s AI Cyber Challenge | AIxCC Competitors successfully demonstrated the ability of novel autonomous systems using AI to secure the open-source software |
| SE010 | GitHub | AIxCC Finals | oss-fuzz-aixcc Public Apache-2.0 |
| SE011 | GitHub | XBOW Validation Benchmarks | As of mid-2026, these benchmarks are saturated |
| SE012 | Horizon3.ai | The NodeZero Platform | running unlimited pentests that uncover exploitable paths, guide remediation, and immediately verify that your fixes are effective |
| SE013 | Horizon3.ai Docs | HORIZON3 Documentation | deploy, configure, and maximize the effectiveness of NodeZero, our autonomous penetration testing platform |
| SE014 | Dreadnode | Dreadnode — AI Infrastructure for Security Agents | Build, evaluate, and deploy security agents with confidence. |
| SE015 | Dreadnode Docs | Dreadnode Documentation | building, evaluating, and deploying offensive security agents |
| SE016 | HackerOne | Why Hybrid Offensive Security Beats Agentic AI Alone | AI can now scale offensive operations in ways that were unimaginable a year ago, but on its own, it cannot deliver |
| SE017 | HackerOne | Prove Exploitability Faster With New Hai Agents | Discovery and exploitation are starting to happen on the same timeline |
| SE018 | HackerOne | AI Red Teaming Explained by AI Red Teamers | AI red teaming is primarily a human driven activity |
| SE019 | Anthropic | Claude Gov models for U.S. national security customers | deployed by agencies at the highest level of U.S. national security |
| SE020 | Anthropic | Cyber evaluations of Claude 4 | significant improvement in vulnerability identification and executing complex multi-step attack chains |
| SE021 | Anthropic | Building AI for cyber defenders | We deliberately avoided enhancements that clearly favor offensive work—such as advanced exploitation or writing malware. |
| SE022 | OpenAI | Disrupting malicious uses of AI by state-affiliated threat actors | state-affiliated threat actors used our services to research various companies and cybersecurity tools |
| SE023 | Google Project Zero | Project Naptime: Evaluating Offensive Security Capabilities of Large Language Models | helping attackers more quickly develop offensive capabilities |
| SE024 | Google Security Blog | AI-Powered Fuzzing: Breaking the Bug Hunting Barrier | AI-Powered Fuzzing: Breaking the Bug Hunting Barrier |
| SE025 | Palantir | Palantir Artificial Intelligence Platform | Palantir Artificial Intelligence Platform |
| SE026 | FedRAMP | FedRAMP | FedRAMP.gov | FedRAMP Marketplace is a searchable database of FedRAMP certified cloud services |
| SE027 | NIST | AI Risk Management Framework | AI RMF Profile on Trustworthy AI in Critical Infrastructure |
| SE028 | NIST CSRC | NIST SP 800-53 Rev. 5, Security and Privacy Controls | Security and Privacy Controls for Information Systems and Organizations |
| SE029 | NIAP | NIAP | NIAP |
| SE030 | DoD CIO | CIO - Cybersecurity Maturity Model Certification | Cybersecurity Maturity Model Certification |
| SE031 | NIST CSRC | About the RMF - NIST Risk Management Framework | Risk Management Framework provides a process that integrates security, privacy, and cyber supply chain risk management activities |
| SE032 | DefenseScoop | Amid concerns sparked by Mythos, the Pentagon’s cyber policy chief sees huge opportunity with frontier AI models | vulnerabilities recently discovered by Anthropic’s new Claude Mythos Preview artificial intelligence model |
| SE033 | DefenseScoop | Pentagon’s JWCC follow-on would create cloud marketplace, expand AI and edge computing | AI and machine learning capabilities across all classification and impact levels, including for DDIL environments |
| SE034 | DefenseScoop | AWS, Anduril debut new tactical data center offering listed on DOD’s cloud marketplace | cloud-grade computing, storage and AI capabilities in remote areas |
| SE035 | arXiv | Teams of LLM Agents can Exploit Zero-Day Vulnerabilities | agents still perform poorly on real-world vulnerabilities that are unknown to the agent ahead of time |
| SE036 | arXiv | Cybench: A Framework for Evaluating Cybersecurity Capabilities and Risks of Language Models | autonomously identifying vulnerabilities and executing exploits have potential to cause real-world impact |
| SU001 | U.S. News & World Report / Reuters | Exclusive-DOGE Alumni Launch Military Cyber Startup With $1.4 Billion Valuation | Cathedral was launched in recent months with a plan to secure U.S. government contracts to bolster AI-driven cyber operations, including offensive and defensive capabilities. |
| SU002 | The Next Web | Four former DOGE staffers raised $160 million at a $1.4 billion valuation for an AI military cyber startup | Cathedral, a stealth military cybersecurity startup founded by four former DOGE staffers, raised $160 million at a $1.4 billion valuation. |
| SU003 | Gizmodo | DOGE Guys Who Didn’t Save Us Any Money Rake in Cash With New Military Tech Startup | The story framed the ex-DOGE team’s move into a military-tech startup as controversial and criticized the public-service-to-defense-tech arc. |
| SU004 | Cyber Daily | Ex-DOGE engineers launch new AI firm to bolster US military cyber | Former DOGE engineers formed Cathedral, a company that plans to harness AI to bolster the cyber capabilities of the US military. |
| SU005 | USAspending.gov | Government Spending Open Data | USAspending | USAspending is the official open data source of federal spending information, including information about federal awards such as contracts, grants, and loans. |
| SU006 | SAM.gov | Contract Opportunities | SAM.gov | SAM.gov hosts federal contract opportunities and includes warnings that the system contains Controlled Unclassified Information. |
| SU007 | U.S. Department of Defense | Contracts | The Department of Defense contracts page is an official U.S. government source for public contract announcements. |
| SU008 | U.S. Cyber Command | Mission and Vision | USCYBERCOM directs, synchronizes, and coordinates cyberspace planning and operations to defend and advance national interests. |
| SU009 | National Security Agency | Cybersecurity Collaboration Center | The NSA Cybersecurity Collaboration Center scales intel-driven cybersecurity through open, collaborative partnerships. |
| SU010 | U.S. Fleet Cyber Command / U.S. 10th Fleet | U.S. Fleet Cyber Command / Commander, U.S. 10th Fleet | Fleet Cyber Command / 10th Fleet is an operational force with more than 13,000 billets and many Cyber Mission Force units. |
| SU011 | Sixteenth Air Force | About Us | The 16th Air Force is responsible for ISR, cryptologic activities, and operating and defending Department networks. |
| SU012 | Marine Corps Forces Cyberspace Command | About Us | MARFORCYBER’s mission aligns Marine cyberspace operations with U.S. Cyber Command objectives. |
| SU013 | CISA | About CISA | CISA | CISA works with partners to identify and manage risk to the cyber and physical infrastructure Americans rely on. |
| SU014 | Central Intelligence Agency | Organization - CIA | CIA is responsible for providing national security intelligence to senior U.S. policymakers. |
| SU015 | Defense Intelligence Agency | Home | DIA’s mission is to provide intelligence on foreign militaries to prevent and decisively win wars. |
| SU016 | Defense Innovation Unit | Work With Us | Any individual or commercial entity is eligible to respond to a DIU solicitation. |
| SU017 | Defense Innovation Unit | Tap Into a $100+ Billion Market | DIU invites commercial entities, including first-time sellers to government, to submit solution briefs. |
| SU018 | Defense SBIR/STTR | DoW Office for Small Business Innovation | Defense SBIR/STTR describes steps from eligibility and registration through Phase II, transition, and commercialization. |
| SU019 | SBIR.gov | About | SBIR provides equity-free funding through federal agencies to American small businesses. |
| SU020 | General Services Administration | Multiple Award Schedule | GSA’s Multiple Award Schedule lists products and services that agencies can buy through the program. |
| SU021 | Defense Acquisition University | Other Transactions | Adaptive Acquisition Framework | Other Transactions are legally binding instruments other than standard procurement contracts, grants, or cooperative agreements. |
| SU022 | FedRAMP | FedRAMP | FedRAMP.gov | The FedRAMP Marketplace is a searchable database of FedRAMP certified cloud services, authorizing agencies, and assessors. |
| SU023 | Department of Defense CIO | CIO - About CMMC | DoD announced the suspension of CMMC Phase II requirements while Phase I self-assessment requirements remain in place. |
| SU024 | NIAP | NIAP | NIAP is the U.S. public program surface for Common Criteria evaluation information. |
| SU025 | Defense Counterintelligence and Security Agency | Entity Vetting, Facility Clearances & FOCI | Entities providing goods or services to the U.S. government involving access to or creation of classified information will first need a facility clearance. |
| SU026 | United States Space Force | United States Space Force > About Us | Space Delta 6 and related units operate and maintain satellite and ground systems supporting joint and interagency operations. |
| SU027 | AFWERX | SBIR/STTR | AFWERX maintains SBIR/STTR pathways for Air Force and Space Force innovation funding. |
| SU028 | SOFWERX | SOFWERX: Collaborative Solutions for Warfighter Challenges | SOFWERX serves as an innovation platform for United States Special Operations Command. |
| SU029 | DEFENSEWERX | DEFENSEWERX | Innovation & Collaboration | Niceville, FL | DEFENSEWERX enables agile innovation for government partners through innovation hubs across the country. |
| SU030 | U.S. Government Accountability Office | Other Transaction Agreements: DOD Can Improve Planning for Consortia Awards | GAO said OTAs allow more flexibility than traditional contracts and let DOD partner with contractors it has not worked with before. |
| SU031 | TechCrunch | Defense startup Shield AI lands $12.7B valuation, up 140%, after US Air Force deal | Shield AI announced a large Series G after a U.S. Air Force deal. |
| SU032 | TechCrunch | Anduril raises $5B, doubles valuation to $61B | Anduril raised a $5 billion Series H at a $61 billion valuation. |
| SU033 | Los Angeles Times | Anduril to invest another $1 billion in California with new Long Beach campus | Anduril is developing drones, missiles, robotic submarines, and autonomous fighter jets and expanding with a $1 billion Long Beach complex. |
| SU034 | U.S. Securities and Exchange Commission | Palantir Technologies Inc. 2024 Form 10-K | Palantir said Gotham has served global defense agencies and the intelligence community for over a decade and disclosed $1.071 billion of government revenue. |
| SU035 | UK Ministry of Defence | New strategic partnership to unlock billions and boost military AI and innovation | The UK Ministry of Defence described a strategic partnership intended to unlock billions and boost military AI and innovation. |
| SU036 | Microsoft Learn | Department of Defense Impact Level 5 - Azure Compliance | The DoD Cloud Computing SRG defines baseline security requirements used to assess cloud service offerings and support provisional authorization decisions. |
| SR001 | U.S. News / Reuters | Exclusive-DOGE Alumni Launch Military Cyber Startup With $1.4 Billion Valuation | Reuters reported Cathedral raised $160 million at a $1.4 billion valuation and plans AI-driven offensive and defensive military cyber operations. |
| SR002 | Startup Fortune | Four DOGE alumni raise at a $1.4 billion valuation for Cathedral, a stealth military cybersecurity startup backed by a16z and Sequoia | A $1.4 billion valuation at this stage is a bet on access and founder knowledge - not yet on revenue anyone can inspect. |
| SR003 | The Next Web | Four former DOGE staffers raised $160 million at a $1.4 billion valuation for an AI military startup | Former DOGE staffers raised $160 million at a $1.4 billion valuation for an AI military startup. |
| SR004 | WIRED | The DOGE Boys Get VC Funding to Support Their Latest Enterprise | DOGE appeared to have worked as an employment conveyor belt for many of the organization’s affiliates. |
| SR005 | Vanity Fair | Meet Your New Defense Contractors: The DOGE Boys | In some ways, DOGE acted as an expedited revolving door. |
| SR006 | Gizmodo | DOGE Guys Who Didn’t Save Us Any Money Rake in Cash With New Military Tech Startup | DOGE guys who did not save money are raising cash for a new military technology startup. |
| SR007 | NewsNation | Former DOGE staff start AI military company | Former DOGE staff started an AI military company. |
| SR008 | Cyber Daily | Ex-DOGE engineers launch new AI firm to bolster US military cyber | The firm is intended to bolster US military cyber capabilities. |
| SR009 | ExecutiveBiz | Cyber Startup Cathedral Raises $160M at $1.4B Valuation | Cyber startup Cathedral raised $160 million at a $1.4 billion valuation. |
| SR010 | CityBiz | Andreessen Horowitz, Sequoia Capital Lead $160M Round for Former DOGE Staff’s Venture | Andreessen Horowitz and Sequoia Capital led the funding round. |
| SR011 | Associated Press | Musk says he will bring back DOGE staffer who resigned after a report of racist postings | Marko Elez resigned after the Wall Street Journal linked him to racist social media posts and Musk said he would bring him back. |
| SR012 | WIRED | The Young, Inexperienced Engineers Aiding Elon Musk’s Government Takeover | WIRED identified six young men, apparently between 19 and 24, with little to no government experience playing critical DOGE roles. |
| SR013 | WIRED | Where the DOGE Operatives Are Now | Where DOGE operatives went after leaving government. |
| SR014 | WIRED | DOGE May Have Misused Social Security Data, DOJ Admits | DOGE may have misused Social Security data, according to the article title and reporting. |
| SR015 | Associated Press | DOGE was tasked with stopping Treasury payments to USAID, AP sources say | DOGE was tasked with stopping Treasury payments to USAID, according to AP sources. |
| SR016 | Associated Press | Treasury watchdog begins audit of Musk DOGE team’s access to the US government’s payment system | The Treasury inspector general began an audit of the DOGE team’s access to the government payment system. |
| SR017 | GovExec / Nextgov | Treasury missed security controls in giving DOGE system access, GAO finds | GAO found Treasury missed security controls in giving DOGE system access. |
| SR018 | The White House | Establishing And Implementing The President’s Department Of Government Efficiency | The executive order established the United States DOGE Service in the Executive Office of the President. |
| SR019 | Department of Government Efficiency | Work | DOGE: Department of Government Efficiency | DOGE publishes its own work page and savings claims. |
| SR020 | U.S. Government Accountability Office | High Risk List | GAO maintains a High Risk List for areas vulnerable to waste, fraud, abuse, or needing transformation. |
| SR021 | U.S. Government Accountability Office | DOD Fraud Risk Management: Actions Needed to Enhance Department-Wide Approach | GAO recommended actions to enhance DOD-wide fraud risk management. |
| SR022 | U.S. Government Accountability Office | Cybersecurity High-Risk Series: Challenges in Establishing a Comprehensive Cybersecurity Strategy and Performing Effective Oversight | GAO identified challenges in establishing comprehensive cybersecurity strategy and oversight. |
| SR023 | Acquisition.GOV | Subpart 9.5 - Organizational and Consultant Conflicts of Interest | FAR Subpart 9.5 addresses organizational and consultant conflicts of interest. |
| SR024 | Acquisition.GOV | 3.104 Procurement integrity | FAR 3.104 covers procurement integrity restrictions. |
| SR025 | Legal Information Institute | 5 CFR Part 2641 - Post-Employment Conflict of Interest Restrictions | 5 CFR Part 2641 sets post-employment conflict-of-interest restrictions. |
| SR026 | Legal Information Institute | 5 CFR § 2635.702 - Use of public office for private gain | Federal ethics regulations prohibit use of public office for private gain. |
| SR027 | Lawfare | Partners or Provocateurs? Private-Sector Involvement in Offensive Cyber Operations | Private-sector offensive cyber participation requires clarifying objectives, scope, legal authority, and liability before changing rules. |
| SR028 | CSIS | Redefining Cybersecurity as International Security, Not Just National Security | Cyber collaboration beyond borders can deepen ties but faces information-sharing and classified-information constraints. |
| SR029 | CSIS | Deterrence and Cyber Strategy | There is ample space for harmful cyber action below the use-of-force threshold. |
| SR030 | CSIS | DOD Is Updating Its Decade-Old Autonomous Weapons Policy, but Confusion Remains Widespread | CSIS argued DOD autonomy policy remains misunderstood and needs greater clarity. |
| SR031 | Atlantic Council | Crash (exploit) and burn: Securing the offensive cyber supply chain to counter China in cyberspace | The private-sector zero-day exploit market is opaque, fragmented, and strategically important. |
| SR032 | Legal Information Institute | 22 CFR Part 120 - Purpose and Definitions | 22 CFR Part 120 provides ITAR purpose and definitions. |
| SR033 | Legal Information Institute | 22 CFR Part 121 - The United States Munitions List | 22 CFR Part 121 contains the United States Munitions List. |
| SR034 | Bureau of Industry and Security | Homepage | Bureau of Industry and Security | BIS links to the Export Administration Regulations and advanced computing license guidance. |
| SR035 | Legal Information Institute | 15 CFR Part 734 - Scope of the Export Administration Regulations | 15 CFR Part 734 describes the scope of the Export Administration Regulations. |
| SR036 | The Wassenaar Arrangement | Control lists | Wassenaar publishes control lists for conventional arms and dual-use goods and technologies. |
| SR037 | Booz Allen Hamilton | Cybersecurity | Booz Allen markets cybersecurity services to government and enterprise customers. |
| SR038 | Leidos | Cybersecurity | Leidos markets cybersecurity capabilities. |
| SR039 | Palantir | Palantir Foundry documentation overview | Palantir publishes documentation for its Foundry platform. |
| SR040 | Anduril | Transforming U.S. Defense Capabilities with Advanced Technology | Anduril publicly markets advanced defense technology capabilities. |
| SR041 | Washington Technology | 2026 Top 100 | Washington Technology publishes a Top 100 government contractors ranking. |
| SR042 | SAM.gov | Contract Opportunities | SAM.gov is the U.S. government contract-opportunities portal. |
| SR043 | USAspending.gov | Government Spending Open Data | USAspending.gov publishes U.S. government spending open data. |
| SR044 | SBIR.gov | About | SBIR describes federal small-business innovation funding programs. |
| SR045 | Defense Innovation Unit | Tap Into a $100+ Billion Market | DIU describes pathways for commercial technology firms to work with defense customers. |
| SR046 | Bulletin of the Atomic Scientists | The quest for cyber norms | The article addresses the quest for cyber norms. |
| SR047 | Citizens for Responsibility and Ethics in Washington | CREW requests records on DOGE | CREW says DOGE continues to operate with no clarity on its structure, staffing, budget, or operations. |
| SV001 | U.S. News / Reuters | Exclusive: DOGE alumni launch military cyber startup with $1.4 billion valuation | Reuters reported Cathedral raised $160 million at a $1.4 billion valuation and is seeking U.S. government cyber contracts. |
| SV002 | StartupFortune | Four DOGE alumni raise at a $1.4 billion valuation for Cathedral | The article says Cathedral has no known customers, no published product page, no public contract wins, and no inspectable revenue. |
| SV003 | Economic Times ETCISO | DOGE alumni launch military cyber startup with $1.4 billion valuation | |
| SV004 | Traders Union | Cathedral raises funding for U.S. military cyber push at $1.4 billion valuation | |
| SV005 | CNBC | Anduril doubles valuation as defense tech funding boom continues | |
| SV006 | Forbes | Anduril’s $61 Billion Valuation Is A Bet On Pentagon Speed | |
| SV007 | Analytics Insight | Anduril valuation reaches $61 billion after $5 billion Series H funding round | |
| SV008 | TechCrunch | Anduril raises $5B, doubles valuation to $61B | |
| SV009 | TechCrunch | Defense startup Shield AI lands $12.7B valuation after U.S. Air Force deal | |
| SV010 | Tech in Asia | US defense AI startup Shield AI raises $2b at $12.7b value | |
| SV011 | TechFundingNews | Shield AI locks $240M and hits $5.3B valuation | |
| SV012 | DroneDJ | Shield AI lands $240M to expand drone autonomy tech | |
| SV013 | Stock Analysis | Palantir Technologies revenue 2018-2026 | |
| SV014 | Palantir Investor Relations | Palantir reports Q1 2026 U.S. revenue growth and raises guidance | |
| SV015 | Business Wire | Palantir reports Q1 2026 revenue growth | |
| SV016 | U.S. Securities and Exchange Commission | Palantir Technologies Form 10-Q for quarter ended March 31, 2026 | |
| SV017 | Last10K | Palantir Technologies SEC filings page | |
| SV018 | CompaniesMarketCap | Palantir market capitalization | |
| SV019 | CompaniesMarketCap | Palantir revenue | |
| SV020 | CompaniesMarketCap | Palantir P/S ratio | |
| SV021 | Yahoo Finance | The defense tech boom has become a bubble—or it will be soon | The piece argues that defense-tech capital is stampeding into companies whose valuations can run ahead of public products, contracts, and revenue. |
| SV022 | AIN Ventures | Is Defense Technology in a Bubble? | |
| SV023 | 409A Valuation | 409A valuation benchmarks for seed-stage startups | |
| SV024 | ValueAddVC | Average pre-seed, seed and Series A round sizes | |
| SV025 | Zeni | Series A valuations in 2026: what founders need to know | |
| SV026 | IdeaProof | Startup fundraising benchmarks 2026 | |
| SV027 | Andreessen Horowitz | American Dynamism | |
| SV028 | Rebellion Defense | Rebellion Defense company website | |
| SV029 | Anduril | Anduril company website | |
| SV030 | Los Angeles Times | Anduril to invest another $1 billion in California with Long Beach campus |