The Venture Codex Logo

The Venture Codex

StoneMill Ventures

Arlington, VA, United States

Overview

StoneMill Ventures invests in disruptive cyber security companies, primarily at the seed stage. StoneMill are active investors and look for founding teams that can benefit from our experience building pioneering security companies.

Total investments
9
Lead investments
1
Investments · 12mo
1
Active investors
0
Visit website

Investment portfolio

  • Feroot

    Participated · Series A · Nov 2025

    Feroot offers an always-on AI-agent platform that automates discovery, analysis, and remediation of security and privacy-compliance issues across websites, payment pages, healthcare pages, iFrames, and other web or mobile applications. The system performs deep discovery and maintains a real-time single source of truth, then uses reasoning and generative AI to verify compliance and detect security gaps in seconds rather than months of manual work. Its technology addresses the growing cost of non-compliance, helping customers avoid litigation, fines, and insurance denials tied to GDPR, HIPAA, CCPA, and dozens of other laws. Feroot’s research has been cited by U.S. lawmakers examining national-security risks in apps such as TikTok and DeepSeek, and CEO Ivan Tsarynny recently testified before the US-China Economic and Security Review Commission. Current customers include Reddit, Forbes, and Xerox. The company has raised $25 million in venture funding to date and plans to use its new capital to grow the engineering team, open additional offices, and expand into the Middle East and Southeast Asia. Co-founders Ivan Tsarynny (CEO) and Vitalily Lim (CTO) lead the firm.

  • Todyl

    Participated · Series B · Mar 2024

    Todyl offers an all-in-one, cloud-first security and networking platform that uses a lightweight single agent to consolidate multiple point solutions. The platform unifies SASE, SIEM, MXDR, endpoint security (EDR/NGAV), SOAR, and GRC to provide prevention, detection, and response across SaaS, cloud, data center, office, and remote environments. Todyl follows an MSP-first, channel-only approach to reach IT professionals and SMB customers. The company recently added a SOAR module to enable rapid, automated response actions across endpoints and Microsoft 365, and positions that module as a springboard for future automation and orchestration features. The business emphasizes ease-of-use, modularity, and cost-effectiveness to level the security playing field for organizations that lack enterprise resources. The company signals plans to grow headcount, expand office locations globally, and accelerate engineering investment to advance its platform. Todyl offers a cloud-first unified security platform that combines SASE with integrated Endpoint Security (EDR/NGAV), a managed 24x7 MXDR service, SIEM, and GRC capabilities. The company launched the Todyl Security Platform with single-agent Endpoint Security, an overhauled SIEM with new reporting and dashboards, and a personalized MXDR service. Todyl targets channel partners, MSPs and MSSPs serving SMB and mid-market customers, aiming to replace stitched-together toolchains with one platform and one agent. It operates a global footprint of 29 Points of Presence (PoPs) and is expanding Security Operations Centers in the U.S. and internationally to enhance MXDR coverage. The company announced a $28 million Series A to support further development and expansion of the platform. Existing investors Tech Operators, Blu Ventures, and StoneMill Ventures increased their investments as part of the round. Todyl emphasizes simplifying operations, strengthening security posture, and reducing cost for partners as it scales operations and SOC coverage.

  • LimaCharlie

    Participated · Series A · Feb 2024

    LimaCharlie provides a SecOps cloud platform that delivers cybersecurity capabilities and infrastructure on demand in an API-first architecture designed for massive scale. The platform is used by top technological leaders in information security. Founded in 2018 and based in Covina, CA, the company emphasizes flexible, on-demand security infrastructure that enables consolidation and customization of defense tools. LimaCharlie plans to use new funding to accelerate team expansion and introduce additional capabilities to its platform. The company positions itself as promoting a paradigm shift toward a public-cloud model for cybersecurity, according to CEO Maxime Lamothe-Brassard. LimaCharlie provides API-first cybersecurity tools and infrastructure through a Security Infrastructure as a Service (SIaaS) model. Led by CEO and founder Maxime Lamothe-Brassard, the company aims to give customers an adaptable security posture. Following its latest seed financing, LimaCharlie plans to expand its engineering team to increase new technology development. The company is based in Mountain View, California. The seed round brought the company's total funding to $6.35 million and established a current valuation of $24 million. Investors in the round include Susa Ventures, Xerox Ventures, Sands Capital, Lytical Ventures, CoFound Partners and others.

  • Tidal Cyber

    Participated · Equity · Oct 2022

    Tidal Cyber offers a Threat-Led Defense platform that helps organizations measure and improve the effectiveness of their security stack against real-world threats and adversary behavior. The platform operationalizes MITRE ATT&CK and delivers independent tools and services to align security efforts to the threats that matter without vendor bias. Tidal Cyber plans to build a comprehensive CTI and adversary behavior–driven platform to shift organizations from managing intel to proactive, threat-informed defense. The company raised $10 million in Series A funding to accelerate product innovation and fuel company growth. Tidal Cyber was founded in 2022 and is based in Reston, Va. It was co-founded by three former MITRE experts — Rick Gordon, Richard Struse, and Frank Duff — who bring extensive experience in threat-informed defense and related standards and programs. Tidal Cyber offers a Threat-Informed Defense SaaS platform (Enterprise Edition) that aggregates MITRE ATT&CK®, third-party threat intelligence, and internal research to produce Tidal Confidence Scores and Coverage Maps. The platform recently integrated Breach and Attack Simulation (BAS) test results to compare tests against existing confidence scores. The company also maintains a freely available Community Edition used by over 3,000 security professionals globally. Tidal Cyber plans to use new investment to accelerate go-to-market activities, expand sales and marketing, and enhance both Community and Enterprise Editions. The company reported customer and financial growth exceeding 10x over the past year. Founded in January 2022 by threat-intelligence veterans with experience at MITRE and the U.S. Department of Homeland Security, Tidal Cyber aims to lead adoption of Threat-Informed Defense across critical infrastructure segments. Tidal Cyber offers a threat-informed defense platform that embeds the MITRE ATT&CK knowledge base to help security operations teams focus on the most relevant adversarial tactics and techniques. The platform includes a threat profile builder to identify and prioritize relevant threats, a prioritized to-do list for daily defensive actions, a map to optimize defensive tooling, and a proprietary confidence score to assess cyber posture. Tidal’s tools aim to align threats with the right defensive capabilities and streamline communication about an organization’s security program. The company is led by CEO Rick Gordon, CTO Richard Struse, and CINO Frank Duff. Tidal plans to use newly raised capital to accelerate growth of its platform. The company is based in Reston, VA. Tidal Cyber offers a SaaS-based threat-informed defense platform that maps an organization’s security capabilities to adversary tactics and techniques, including MITRE ATT&CK and additional intelligence sources. The platform includes a registry of vendor product capabilities mapped to adversary behaviors to produce actionable insight on defensive coverage, gaps, and overlaps. Tidal provides a free Community Edition that was made generally available at Black Hat USA in early August, featuring enriched technique data and the Tidal Product Registry. The company plans an enterprise edition with enhanced features, including reporting driven by a Tidal Confidence Score to help evaluate and communicate cyber risk reduction. Led by CEO Rick Gordon, Tidal intends to use the new funding to expand the platform and ramp up customer acquisition. Financially, the company raised $4M in funding to support these product and go-to-market efforts.

  • GreyNoise Intelligence

    Participated · Series A · Jun 2022

    GreyNoise positions itself as an “anti-threat intelligence” company that acts like a spam filter for security alerts by analyzing internet scanning traffic. It operates a network of 5,000 passive sensors deployed in data centers worldwide to collect, analyze and label IPs that scan the internet. Customers using GreyNoise report an average 25% reduction in security alerts, and the company has grown from seven to 50 employees with more than 100 paying customers, including the U.S. Department of Defense. GreyNoise says it was the first to detect broad exploitation of the Log4Shell vulnerability, which led CEO Andrew Morris to testify before the Department of Homeland Security and inspired new blocking functionality. The startup plans to “drastically” expand the size and scope of its data-collection efforts and build out product capabilities with new funding. Morris also said the company has no immediate headcount expansion plans and is taking a tactical approach to hiring amid broader layoffs. GreyNoise collects packets from IPs via a sensor network and monitors common internet business services to identify which alerts are relevant and which are background noise. The company helps security operations centers reduce false positives and focus on more concerning threats. It is a three-year-old startup with over 11,000 accounts, more than 1,000 daily users on its free tier, and roughly 75 enterprise customers; it is adding a few hundred users weekly. Staff headcount grew from five to 24 over the past year, and the company expects to add another 15–20 employees before year-end. In 2020 GreyNoise raised $4.8 million in seed funding led by Charles River Ventures with participation from Paladin Capital Group. Following the new partnership, GreyNoise plans to release additional open-source tools later this year, and features from the In-Q-Tel collaboration will be available to users in the next six to nine months. GreyNoise collects traffic from a distributed network of sensors in hundreds of data centers, applies rule-based automated analysis (not currently machine learning) and filters out benign scanning and crawling activity so customers see fewer irrelevant alerts. The product reduces the volume of alerts that require attention by roughly 20%. Today the company has 7 employees and about 40 customers, and it plans to hire roughly 10 more people over the next year with emphasis on sales, marketing and engineering. Roadmap items include adding machine-learning elements and building products that enable customers to collect data in exchange for subscription discounts. GreyNoise also plans partnerships with ISPs and data-center owners to expand its data collection footprint. GreyNoise Intelligence is a Washington, DC–based cybersecurity startup that identifies Internet background noise caused by benign sources which inflate the volume of security alerts. By filtering out that background noise, GreyNoise helps security operations teams streamline and prioritize threat analysis. The company was founded by Andrew Morris. It initially released a free API to access its collected data, which quickly gained thousands of followers, and later deployed an enterprise service in late 2018. GreyNoise completed a $600K seed financing and intends to use the funds to expand operations and continue development efforts.

Team

No current team members are available.