Aiceberg

Security for AI acquired also known as AIceberg

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software.
Founded 2022
Funding $10M
Last updated 2026-08-25

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Aiceberg sold software that screened prompts, model responses and agent actions for enterprises and public-sector organizations. It no longer runs as an independent company. Cranium AI acquired it in May 2026, said every employee would transition, and made Aiceberg’s chief executive, Alex Schlager, its chief technology officer. Independent coverage credits Aiceberg with arguing that models built for detection, rather than a large language model, should judge AI traffic, and Cranium’s own Observe page now carries the same argument. A request to aiceberg.ai returns Cranium’s homepage. AWS Marketplace still lists Aiceberg at annual prices from $60,000 to $680,000 by token volume. No named customer appears in the reviewed sources, so how far the product sold stays unclear.

Sourced Details

Description AI firewall and gateway that monitors prompts, responses, and agent actions in real time, using purpose-built non-generative machine learning to detect attacks and redact sensitive data. Cranium AI acquired the company in May 2026. [f1]
Acquisition Cranium AI, announced 2026-05-21 [f2]
Founded 2022 [f3]
HQ New York, NY [f1]
Funding $10M total [f1]
Latest funding Seed, $10 million (March 2025) [f4]

Products

Product What it does
Aiceberg Guardian Agent Real-time screening of prompts, model responses, and agent actions across five risk layers, blocking or redacting policy violations and recording an inspectable reason for every decision.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Aiceberg Guardian Agent examines prompts, model responses, and agent activity in real time, blocking or redacting policy violations with explainable machine-learning risk signals. These capabilities are mapped to the AI Defense Matrix. [f5]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 25 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Independent coverage names the buyer, enterprises and public-sector organizations putting generative and agentic AI into production, and an independent 2026 survey of 517 security leaders reports 36% of them naming prompt-level data leakage as their hardest data-protection problem. That quantifies the category rather than this vendor’s segment, and the buyer description in the record stays broad, so the persona-plus-quantification pairing the next level asks for is not on the page. [s8, s10, s14]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 The documentation portal sets out five analytical layers, an in-line mode in which the application routes every request through Aiceberg before its own model, and a trace view exposing the samples, labels and relevance scores behind each classification. No third-party technical evaluation, inspectable code, or customer technical writeup appears in the reviewed sources, so only vendor-authored material supports the accuracy claims. [s4, s5, s6]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 4/5 Buyer-side demand shows in more than one place. ETR’s March 2026 survey of 517 security leaders puts protection for large language models and generative AI ahead of cloud security for planned budget growth, with 59% planning to increase spending, an analyst database places the product in a named guardrail category, and the EU AI Act’s obligations for general-purpose AI models became applicable in August 2025. An acquisition is a supply-side event, so the May 2026 sale does not evidence buyer demand. [s14, s10, s15]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 Verizon’s own site records Alex Schlager as its executive director of security services, a senior in-domain role, and the acquirer named him chief technology officer of the combined company. The reviewed sources document no prior exit, no sustained publication record, and no independent recognition for the team, so the public evidence stops at verifiable senior experience. [s19, s11, s18]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 AWS Marketplace lists the product as software-as-a-service sold by Aiceberg, with a free trial and published 12-month contract tiers, which is the marketplace signal this level names. No named customer or partnership appears in the reviewed sources, so scale stays uncorroborated. [s7]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 A $10 million seed matched the stage, and the documentation portal records dated releases running from June 2025 to April 2026, which is visible shipping. No revenue, margin or customer-growth figure appears and the reviewed announcements give no consideration, so output per dollar stays unconfirmed. [s8, s3, s11]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 An analyst database assigns the product to a guardrail category inside an AI security segment, and independent press describes it as an AI firewall and gateway for AI traffic. That is a single independent categorization rather than the multiple placements the next level asks for. [s10, s9, s8]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 Some documented friction slows absorption. In enforce mode an application sends every request to Aiceberg before its own model sees it, and the screening runs against the profile settings and policies a security team configures. The documented integration surface is an interface for prompts and responses plus one connector to a customer’s alert system, and the record names no data asset a platform vendor could not reach by bundling, so the friction slows absorption rather than blocking it. [s4, s21]
Business Risks Cranium could withdraw the Aiceberg listing from AWS Marketplace and sell the screening capability only inside its own platform, leaving no separately purchasable product…
  • Cranium could withdraw the Aiceberg listing from AWS Marketplace and sell the screening capability only inside its own platform, leaving no separately purchasable product.
  • Platform and model vendors could ship equivalent runtime screening natively, shrinking the standalone market the capability sells into.
  • The Aiceberg documentation portal could stay frozen at its April 2026 release, leaving buyers who evaluate the marketplace listing reading material that no longer matches the product.
  • Buyers that require a vendor attestation could rule the product out until the acquirer's compliance program covers it.
  • ETR reports a shift toward vendor consolidation, so a screening capability sold as a standalone line could lose budget to a platform that already holds the account.
Problem & Market Aiceberg sold to enterprises and public-sector organizations putting generative and agentic AI into production…

Aiceberg sold to enterprises and public-sector organizations putting generative and agentic AI into production. SecurityWeek describes a platform built to help governments and enterprises adopt AI safely, securely and compliantly, and the analyst database IT-Harvest states the same mission. SecurityWeek names prompt injection, prompt leaking and jailbreaking as the vectors it detects, and IT-Harvest names jailbreaks, prompt injection and unsanctioned model use.

An independent survey now puts numbers on that pain. ETR's 2026 State of Security report, drawn from 517 security leaders, finds 36% of respondents naming the prevention of sensitive data entering AI prompts as their hardest data-protection problem, twice the rate of the next concern, and it names shadow AI outside sanctioned tools as their top perceived data-exposure risk. Both name problems the reviewed sources say the product addresses, sensitive data in prompts and unsanctioned model use.

What the record does not carry is a measurement of that pain inside Aiceberg's own segment. The survey measures the category, and the buyer description in the reviewed sources stays broad. [s8, s10, s14, s7]

Product Capabilities Aiceberg screens prompts, model responses and agent actions in real time…

Aiceberg screens prompts, model responses and agent actions in real time. Its documentation sets out five analytical layers named context, information, content, instruction and alignment. The information layer extracts named entities to identify personal, health and payment data, and the instruction layer classifies jailbreaking and prompt injection.

Detection runs on non-generative models rather than on a large language model. IT-Harvest records the company emphasizing non-generative models for risk detection rather than relying on large language models to protect large language models, and SiliconANGLE describes the same design as delivering traceable oversight.

The trace view is where that argument becomes checkable. The documentation shows the samples used to classify an input, the labels attached to them, and the relevance the model assigned each one, and it ranks those samples by the weight the model gave them. No third-party technical evaluation, inspectable code, or customer technical writeup appears in the reviewed sources, so only vendor-authored material supports the accuracy claims. [s4, s5, s6, s9, s10, s17]

Competitive Positioning Aiceberg competed in the runtime AI guardrail category…

Aiceberg competed in the runtime AI guardrail category. IT-Harvest assigns the product to a guardrail category inside an AI security segment, and independent press describes it as an AI firewall and gateway that monitors user prompts and model responses for risk signals.

IT-Harvest names explainability and auditability as what the company emphasized. It frames the choice as using non-generative models for risk detection instead of relying on large language models to protect large language models.

Aiceberg's run as an independent company ended with the acquisition. Cranium AI announced the acquisition on May 21, 2026 and described a combined platform covering the AI lifecycle from development through autonomous agents. Cranium's own Observe page now describes deterministic classifiers, and it says every verdict can justify itself by showing the samples, labels and relevance scores behind each decision, which is the design Aiceberg argued for. [s10, s9, s11, s16]

Go-to-Market & Traction Public traction evidence is thin and indirect…

Public traction evidence is thin and indirect. AWS Marketplace lists the product as software-as-a-service sold by Aiceberg, with a free trial and 12-month contracts from $60,000 for customers using up to a billion tokens a year to $680,000 for up to 80 billion, plus a usage charge for tokens beyond the contract. No named customer, case study or partnership appears in the reviewed sources.

The sale is the last dated commercial event in the record. Cranium AI acquired the company in May 2026, fourteen months after the March 2025 platform launch on a seed round SecurityWeek reported at $10 million from SYN Ventures and Sprout & Oak. The SEC Form D signed on February 19, 2025 records an equity offering of $7,522,240, fully sold to three investors. Neither the acquisition announcement nor its press coverage gives a purchase price, so the record does not show what the traction was worth. [s7, s8, s11, s13, s12]

Team & Credibility Alex Schlager ran Aiceberg as its chief executive and signed its SEC Form D…

Alex Schlager ran Aiceberg as its chief executive and signed its SEC Form D. Verizon's own site records him as its executive director of security services, which is the one role outside Aiceberg and Cranium that the reviewed sources document for him. Cranium named him chief technology officer of the combined company and said he would oversee the technical roadmap and the merging of the two technology stacks.

Cranium also said every Aiceberg employee would move across, crediting expertise in AI security, data science, engineering and go-to-market. The reviewed sources document no prior exit and no sustained publication record for the team, so the public evidence stays at verifiable senior experience. [s13, s19, s11, s12, s18]

Trust Readiness No compliance attestation for the Aiceberg product appears in the reviewed sources, so a buyer that requires one finds nothing published to check…

No compliance attestation for the Aiceberg product appears in the reviewed sources, so a buyer that requires one finds nothing published to check. The acquirer's trust center asks a visitor to request access, so a product-level answer is not on the public web.

What the product offers instead is traceable decisions. Its documentation shows the samples and relevance scores behind each classification, which a security reviewer can inspect, and that is a property of the software rather than an audit of the company. The reviewed sources do not settle which compliance program now covers the product, and the marketplace listing still names Aiceberg as the seller. [s20, s6, s7]

Competitors Lakera, CalypsoAI, WitnessAI, Prompt Security…
Company Relationship Note Compare
Lakera competes with Competes for the same runtime screening budget in LLM and agent applications. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
CalypsoAI competes with Competes for the same inference-layer security budget, the closest capability overlap this catalog tracks. N/AWe scored these companies at different scopes, so the totals measure different things.
WitnessAI competes with Competes for the budget covering visibility into and policy over employee and application AI use. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Prompt Security competes with Competes for the same AI traffic screening budget across employees, applications and agents. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.

Add analyzed competitors to compare them side by side with Aiceberg.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Exposed 12 /21 Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software. pivot urgently

Aiceberg sold configurable software, and the reviewed record shows no asset a funded rival would struggle to rebuild. Its screening runs on purpose-built classifiers, and the product shows the samples behind each decision, which is hard engineering rather than a moat. No certification for the product, no named regulated customer, and no dataset or licensed content the vendor retains appears in the reviewed sources. A customer connects through the product’s interface and one link to their alert system, so a replacement rebuilds a short list of connections. What Aiceberg held was the method and the people who built it, and Cranium bought both in May 2026. Cranium said every employee would transition, and Aiceberg’s chief executive now holds the acquirer’s technology role.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Aiceberg delivers software the customer wires in and configures, priced on AWS Marketplace by annual token volume, and the customer’s own team operates it and owns the outcomes. The reviewed record documents no human service layer that accepts accountability for a screening decision.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Leaving means re-pointing prompt and response calls at a replacement, rebuilding the profiles and use cases a team configured, and reconnecting a SIEM, which is friction of the data-history, integration and learned-workflow kind. The cited record documents no mechanism beyond that and does not size the migration.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 No certification, authorization or retained liability for this product appears in the reviewed sources, and a funded competitor could assume the same obligations through ordinary enterprise-market preparation. The audit-readiness the product markets is a property of its traceable decisions rather than an artifact a replacement would have to reproduce.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Real-time classification across five analytical layers, with inputs semantically chunked for parallel processing and each verdict backed by the weighted samples that produced it, is machine-learning and real-time-systems work. The documentation describes the mechanism in enough detail to show it took specialized expertise to build.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 The reviewed sources name no regulated or government customer, so the record shows who the company aimed at rather than who bought. Its published marketplace tiers run from a starter package for teams beginning to explore AI up to organizations with advanced adoption, a spread that stops short of the documented procurement-gated buyer the top level requires.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 In enforce mode an application sends every prompt to Aiceberg before its own model sees it, so an application wired that way depends on it while it runs. The product also ships its own monitoring and playground interfaces, and the reviewed record documents no application or customer built on top of it, so the evidenced position is a platform with application features.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 The cited record describes purpose-built non-generative classifiers as a method in use rather than an accumulated asset the vendor keeps, and it names no dataset, content licence or granted patent. Sample-based classification with per-decision traceability is engineering a funded rival could rebuild.
Strategic Market Segmentation Aiceberg aimed at enterprises and public-sector organizations…

Aiceberg aimed at enterprises and public-sector organizations. IT-Harvest states the mission as enabling those organizations to deploy generative and agentic AI safely, transparently and compliantly, and the product's traceable decisions are built for that requirement.

The marketplace price list encodes how the company sorted its buyers. Twelve-month contracts scale by annual token volume, from a starter package for customers using up to a billion tokens a year at $60,000 up to $680,000 for organizations with advanced adoption running up to 80 billion. That sorts buyers by how much AI traffic they run.

The reviewed sources name no customer in any of those tiers. So the record shows who the company aimed at rather than who bought.

Product Capabilities & AI Advantages The core capability is real-time classification of AI traffic…

The core capability is real-time classification of AI traffic. Aiceberg's documentation sets out five analytical layers named context, information, content, instruction and alignment. The information layer extracts named entities to identify personal, health and payment data, the instruction layer classifies jailbreaking and prompt injection, and the alignment layer checks that an agent's actions match the instructions it was given.

The AI advantage is a deliberate refusal to use a large language model in the detection path. IT-Harvest records the company emphasizing non-generative models for risk detection rather than relying on large language models to protect large language models, and SiliconANGLE describes the same design as delivering traceable oversight through explainable models.

The explainability claim is checkable in the documentation, and no independent source tests it. The documentation shows the samples used to classify an input, the labels attached to them, and the weight the model gave each one. No third-party technical evaluation, inspectable code, or customer technical writeup appears in the reviewed sources, so only vendor-authored material supports the accuracy claims.

Sales Engagement & Go-to-Market One public path to purchase ran through cloud procurement…

One public path to purchase ran through cloud procurement. AWS Marketplace lists the product as software-as-a-service sold by Aiceberg, with a free trial and published 12-month contract prices, so a buyer can evaluate and transact inside an existing AWS relationship.

How far that motion converted is not publicly measurable. No named customer, reseller or partnership appears in the reviewed sources, so a prospective buyer has no public reference to check. The acquisition settled the question a different way. Cranium said every Aiceberg employee would transition, crediting expertise in AI security, data science, engineering and go-to-market.

Pricing Model Aiceberg published a price list…

Aiceberg published a price list. The AWS Marketplace listing carries 12-month contract tiers keyed to annual token consumption, running from $60,000 for customers using up to a billion tokens a year to $680,000 for those using up to 80 billion, with a separate charge for tokens beyond the contract.

The unit says what the vendor believed buyers pay for, which is screened AI traffic. Billing by token volume ties the invoice to the volume of prompts and responses the product inspects. A buyer whose AI usage grows therefore pays more without renegotiating what the product does.

Product Delivery & Operations Delivery is software-as-a-service with two operating modes…

Delivery is software-as-a-service with two operating modes. In enforce mode Aiceberg sits between the customer's AI tool and its model, evaluating every request against the profile's signal settings and blocking, modifying or allowing it. In listen mode the same traffic is copied to Aiceberg for classification while the model call proceeds untouched, which gives a record and a recommended action without an inline dependency.

Inline screening makes availability part of the product promise. An application in enforce mode calls the Aiceberg interface before its own model sees the prompt, so every prompt the application sends waits for Aiceberg to answer. The reviewed documentation does not say what happens to that prompt when Aiceberg is unavailable, so a buyer would have to ask how the product fails. The documented way in is narrow. A customer submits prompts and responses through an interface, and alerts leave through a single SIEM connection at a time.

Earning Customers' Trust No compliance attestation for the Aiceberg product appears in the reviewed sources, so a buyer that requires one finds nothing published to check…

No compliance attestation for the Aiceberg product appears in the reviewed sources, so a buyer that requires one finds nothing published to check. The acquirer's trust center asks a visitor to request access, so a product-level answer is not on the public web.

What the product offers instead is a traceable decision. Its documentation shows the samples and weights behind each classification, which a security reviewer can inspect and an auditor can follow, and that is a property of the software rather than an audit of the company that ships it. The reviewed sources do not settle which compliance program now covers the product, and the marketplace listing still names Aiceberg as the seller.

Platform Strategy & Ecosystem Positioning Aiceberg positioned itself as a screening layer that sits beside whatever AI stack a customer runs…

Aiceberg positioned itself as a screening layer that sits beside whatever AI stack a customer runs. Its listing in the Cloud Security Alliance startup registry describes coverage of deployments on GPT, Claude and Llama and of applications built with frameworks such as CrewAI and LangChain, and its documentation adds a SIEM connection so alerts land in the customer's existing monitoring.

Aiceberg's independence as a standalone vendor ended with the acquisition. Cranium describes a combined platform covering the AI lifecycle from development through autonomous agents, and its Observe page now describes deterministic classifiers that show the samples, labels and relevance scores behind each decision. The Aiceberg documentation portal is still online and its release notes run from June 2025 to April 2026, with no entry after the acquisition month, so a buyer reading it sees the product as it stood before the deal.

Team & Execution Capability Alex Schlager ran Aiceberg as its chief executive and signed the company's SEC Form D in that title…

Alex Schlager ran Aiceberg as its chief executive and signed the company's SEC Form D in that title. Verizon's own site records him as its executive director of security services, which is the one role outside Aiceberg and Cranium that the reviewed sources document for him. Cranium named him chief technology officer of the combined company and said he would oversee the technical roadmap and the merging of the two technology stacks.

The team was the visible part of the purchase. Cranium said every Aiceberg employee would transition, crediting expertise in AI security, data science, engineering and go-to-market. The reviewed sources document no prior exit and no sustained publication record for that team, so the public evidence stays at verifiable senior experience rather than a track record buyers would recognize.

Sources

Company Detail Sources (5)
Id Source Tier Accessed
f1 SecurityWeek: AIceberg Gets $10 Million in Seed Funding for AI Security Platform press 2026-08-25
f2 ROI-NJ: Cranium AI acquires Aiceberg, creates robust security for AI ecosystems press 2026-08-25
f3 SEC EDGAR: AIceberg Inc. Form D, year of incorporation regulatory 2026-08-25
f4 SiliconANGLE: AIceberg introduces new AI trust platform with $10M in new funding press 2026-08-25
f5 AI Defense Matrix Catalog: Aiceberg Guardian Agent product entry official 2026-08-25
Profile Analysis Sources (21)
Id Source Tier Accessed
s1 Aiceberg site probe (2026-08-25): a request to aiceberg.ai returns the Cranium AI homepage
“Cranium – Secure & Govern Enterprise AI”
official 2026-08-25
s2 Aiceberg Docs: documentation portal home
“At Aiceberg, we created this documentation to help you regain clarity and confidence. Here, you’ll find everything you need to secure, monitor, and scale your AI agents without slowing down innovation.”
official 2026-08-25
s3 Aiceberg Docs: Release Notes page
“April 27, 2026”
official 2026-08-25
s4 Aiceberg Docs: Listen vs Enforce, the two profile modes
“When enabled, Aiceberg sits between your AI tool and your LLM. Any prompts or other requests are forwarded to Aiceberg, evaluated for Signals and against your Profile settings, and acted upon based on your policies. Aiceberg may block, modify, or allow the content to proceed to your LLM.”
official 2026-08-25
s5 Aiceberg Docs: What are Risk Signals, the five-layer risk monitoring framework
“AIceberg employs a comprehensive, multi-layered approach to AI risk monitoring that operates through five distinct analytical layers, each serving a specific purpose in ensuring safe, secure, and compliant AI interactions.”
official 2026-08-25
s6 Aiceberg Docs: The TRACE Function, per-decision explainability
“Every logged input/output analysis can be traced, inspected and explained.”
official 2026-08-25
s7 AWS Marketplace: Aiceberg, Risk Management and Detection and Response for AI Enabled Apps
“Aiceberg is a natural language firewall that secures and safeguards generative- and agentic ai powered applications and workflows in real-time.”
official 2026-08-25
s8 SecurityWeek: AIceberg Gets $10 Million in Seed Funding for AI Security Platform
“Founded in 2022, the New York-based company has developed a platform designed to help governments and enterprises with the safe, secure and compliant adoption of AI, specifically generative AI and agentic AI”
press 2026-08-25
s9 SiliconANGLE: AIceberg introduces new AI trust platform with $10M in new funding
“working as an AI firewall and gateway that monitors user prompts and model/agent responses for risk signals and enforces security and organizational policies”
press 2026-08-25
s10 IT-Harvest: Aiceberg vendor profile, AI Firewall for Real-Time GenAI Security and Compliance
“It emphasizes using non-generative models for risk detection (rather than relying on LLMs to protect LLMs), aiming for explainability and auditability.”
research 2026-08-25
s11 Cranium AI: press release announcing the acquisition of Aiceberg
“Short Hills, NJ, May 21, 2026 — Cranium AI, the leading end-to-end AI Security and Governance platform, today announced the acquisition of Aiceberg, an Agentic AI security and risk management company.”
official 2026-08-25
s12 ROI-NJ: Cranium AI acquires Aiceberg, creates robust security for AI ecosystems
“In conjunction with the acquisition, Aiceberg CEO Alex Schlager will join Cranium AI as chief technology officer. In this role, he will oversee the technical roadmap and the seamless merging of the two technology stacks.”
press 2026-08-25
s13 SEC EDGAR: AIceberg Inc. Form D, signature date 2025-02-19
“Within Last Five Years (Specify Year) 2022”
regulatory 2026-08-25
s14 ETR: announcement of the 2026 Annual State of Security report, dated March 25, 2026
“For the first time in ETR’s annual survey, LLM and generative AI protection ranks as the leading area for planned security budget growth, surpassing cloud security.”
research 2026-08-25
s15 European Commission: AI Act regulatory framework page, application dates
“The AI Act entered into force on 1 August 2024 and became applicable on 2 August 2026, with some exceptions:”
regulatory 2026-08-25
s16 Cranium AI: Observe platform page
“Verdicts come from purpose-built, deterministic classifiers, and every one can justify itself: Trace shows the actual samples, labels and relevance scores behind each decision.”
official 2026-08-25
s17 Cloud Security Alliance: Startup Showcase registry, Aiceberg listing
“At the core of Aiceberg is a Guardian Agent—a real-time, explainable security layer purpose-built for agentic and generative AI.”
official 2026-08-25
s18 Cranium AI: leadership team page
“Leads the technology behind the AI Trust Loop, bringing 20+ years of cybersecurity and enterprise AI expertise.”
official 2026-08-25
s19 Verizon Business: Q and A article with Alex Schlager on cybersecurity and 5G
“we recently spoke with Alex Schlager, Verizon’s Executive Director of Security Services.”
official 2026-08-25
s20 Trust-surface probe (2026-08-25): aiceberg.ai trust and security subdomains do not resolve, and the acquirer trust center requires requesting access
“Cranium's Trust Center”
official 2026-08-25
s21 Aiceberg Docs: What are Integrations, connecting a SIEM
“Integrations allow you to connect Aiceberg to other software systems in your security and identity infrastructure. Currently, you can connect to SIEM platforms to receive security alerts.”
official 2026-08-25
Deep-Dive Sources (21)
Id Source Tier Accessed
s1 Aiceberg site probe (2026-08-25): a request to aiceberg.ai returns the Cranium AI homepage
“Cranium – Secure & Govern Enterprise AI”
official 2026-08-25
s2 Aiceberg Docs: documentation portal home
“At Aiceberg, we created this documentation to help you regain clarity and confidence. Here, you’ll find everything you need to secure, monitor, and scale your AI agents without slowing down innovation.”
official 2026-08-25
s3 Aiceberg Docs: Release Notes page
“April 27, 2026”
official 2026-08-25
s4 Aiceberg Docs: Listen vs Enforce, the two profile modes
“When enabled, Aiceberg sits between your AI tool and your LLM. Any prompts or other requests are forwarded to Aiceberg, evaluated for Signals and against your Profile settings, and acted upon based on your policies. Aiceberg may block, modify, or allow the content to proceed to your LLM.”
official 2026-08-25
s5 Aiceberg Docs: What are Risk Signals, the five-layer risk monitoring framework
“AIceberg employs a comprehensive, multi-layered approach to AI risk monitoring that operates through five distinct analytical layers, each serving a specific purpose in ensuring safe, secure, and compliant AI interactions.”
official 2026-08-25
s6 Aiceberg Docs: The TRACE Function, per-decision explainability
“Every logged input/output analysis can be traced, inspected and explained.”
official 2026-08-25
s7 AWS Marketplace: Aiceberg, Risk Management and Detection and Response for AI Enabled Apps
“Aiceberg is a natural language firewall that secures and safeguards generative- and agentic ai powered applications and workflows in real-time.”
official 2026-08-25
s8 SecurityWeek: AIceberg Gets $10 Million in Seed Funding for AI Security Platform
“Founded in 2022, the New York-based company has developed a platform designed to help governments and enterprises with the safe, secure and compliant adoption of AI, specifically generative AI and agentic AI”
press 2026-08-25
s9 SiliconANGLE: AIceberg introduces new AI trust platform with $10M in new funding
“working as an AI firewall and gateway that monitors user prompts and model/agent responses for risk signals and enforces security and organizational policies”
press 2026-08-25
s10 IT-Harvest: Aiceberg vendor profile, AI Firewall for Real-Time GenAI Security and Compliance
“It emphasizes using non-generative models for risk detection (rather than relying on LLMs to protect LLMs), aiming for explainability and auditability.”
research 2026-08-25
s11 Cranium AI: press release announcing the acquisition of Aiceberg
“Short Hills, NJ, May 21, 2026 — Cranium AI, the leading end-to-end AI Security and Governance platform, today announced the acquisition of Aiceberg, an Agentic AI security and risk management company.”
official 2026-08-25
s12 ROI-NJ: Cranium AI acquires Aiceberg, creates robust security for AI ecosystems
“In conjunction with the acquisition, Aiceberg CEO Alex Schlager will join Cranium AI as chief technology officer. In this role, he will oversee the technical roadmap and the seamless merging of the two technology stacks.”
press 2026-08-25
s13 SEC EDGAR: AIceberg Inc. Form D, signature date 2025-02-19
“Within Last Five Years (Specify Year) 2022”
regulatory 2026-08-25
s14 ETR: announcement of the 2026 Annual State of Security report, dated March 25, 2026
“For the first time in ETR’s annual survey, LLM and generative AI protection ranks as the leading area for planned security budget growth, surpassing cloud security.”
research 2026-08-25
s15 European Commission: AI Act regulatory framework page, application dates
“The AI Act entered into force on 1 August 2024 and became applicable on 2 August 2026, with some exceptions:”
regulatory 2026-08-25
s16 Cranium AI: Observe platform page
“Verdicts come from purpose-built, deterministic classifiers, and every one can justify itself: Trace shows the actual samples, labels and relevance scores behind each decision.”
official 2026-08-25
s17 Cloud Security Alliance: Startup Showcase registry, Aiceberg listing
“At the core of Aiceberg is a Guardian Agent—a real-time, explainable security layer purpose-built for agentic and generative AI.”
official 2026-08-25
s18 Cranium AI: leadership team page
“Leads the technology behind the AI Trust Loop, bringing 20+ years of cybersecurity and enterprise AI expertise.”
official 2026-08-25
s19 Verizon Business: Q and A article with Alex Schlager on cybersecurity and 5G
“we recently spoke with Alex Schlager, Verizon’s Executive Director of Security Services.”
official 2026-08-25
s20 Trust-surface probe (2026-08-25): aiceberg.ai trust and security subdomains do not resolve, and the acquirer trust center requires requesting access
“Cranium's Trust Center”
official 2026-08-25
s21 Aiceberg Docs: What are Integrations, connecting a SIEM
“Integrations allow you to connect Aiceberg to other software systems in your security and identity infrastructure. Currently, you can connect to SIEM platforms to receive security alerts.”
official 2026-08-25

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.