CalypsoAI

Security for AI acquired

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software.
Funding $40M
Last updated 2026-09-11

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

F5 bought CalypsoAI in 2025 at an announced $180 million and sells the product as F5 AI Guardrails. The product is real-time security for AI models, applications, and agents at enterprises deploying AI. It combines guardrails against prompt injection, jailbreaks, and data leakage with red teaming that simulates attacks on AI systems. It includes audit templates for GDPR, HIPAA, and the EU AI Act and runs on-premises or air-gapped. Founded in 2018, CalypsoAI raised over $40 million from investors including Paladin Capital Group, Lockheed Martin Ventures, and Hakluyt Capital. Its named customers are Palantir and SGK. F5 says the attack library behind the red teaming grows by over 10,000 attack patterns a month. That library is the part of the product a rival would take longest to reproduce.

Sourced Details

Description F5 AI Guardrails helps enterprises deploy data security, threat management, and governance for their AI models, apps, and agents, defending against attacks such as prompt injection and jailbreaks. [f1]
Acquisition F5, announced 2025-09-11 [f2]
Funding $40M total [f3]
Latest funding Acquired by F5 for $180M (2025), primarily cash [f3]
Deployment SaaS, Self-hosted [f4]

Products

Product What it does
CalypsoAI Inference-layer AI security pairing runtime guardrails against prompt injection, jailbreaks, and data leakage with red teaming at scale.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

CalypsoAI is inference-layer AI security that pairs runtime guardrails against prompt injection, jailbreaks, and data leakage with red teaming at scale. It is mapped to the AI Defense Matrix. [f5]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 25 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 The line names enterprises deploying generative and agentic AI and the inference-layer attack surface of prompt injection, jailbreaks, and data leakage, but the pain is corroborated through the category M&A wave rather than quantified, so the grounding shows market interest more than independently measured buyer pain. [s1, s3, s5, s9]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 F5 pages detail AI Red Team attack-pattern swarms and AI Guardrails governance presets, and the OWASP GenAI Security Project independently lists the CalypsoAI Inference Platform in its AI security solutions landscape. The line still carries no public efficacy benchmark or open-source code, so capability rests on vendor description and a third-party listing rather than measured detection results. [s2, s1, s4, s11, s9]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 4/5 Across 2025 platform vendors acquired runtime AI-security companies including Protect AI, Lakera, Prompt Security, and Aim, multiple corroborated signals of category heat, but this reads as acquirer conviction rather than independently established accelerating buyer demand, so it supports a strong score short of the top. [s5, s7, s8, s3, s4]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 CalypsoAI earned third-party recognition as a 2025 RSAC Innovation Sandbox Top-Two Finalist and a Fast Company Most Innovative Company in AI for 2025, and it shipped real adversarial-testing depth since founding in 2018. The cited record does not establish prior security exits by the founders, and the team now folds into F5, so its standing comes from the product and the honors rather than a named founder track record. [s6, s4]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 F5's release names Palantir and SGK as customers, a vendor-stated claim with no independent scale corroboration, and the $180 million headline purchase is acquirer conviction the line's own traction cannot claim, since F5 called the revenue immaterial and left it undisclosed. [s6, s3, s4, s9]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 CalypsoAI raised over $40 million and was acquired by F5 at a $180 million headline price, but F5 characterized the revenue as immaterial, so the exit reflects acquirer conviction in the asset rather than confirmed commercial output per dollar for the line. [s6, s3, s4, s9]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Analysts at CB Insights include CalypsoAI in six analyst-curated technology collections and the OWASP solutions landscape lists its platform, but the labels stay contested across guardrails, red teaming, and runtime defense without a single settled budget label, so the category sits in an emerging slot rather than an established budget line. [s5, s3, s1, s10, s11]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 Folding into the F5 Application Delivery and Security Platform gives the line distribution into F5's existing enterprise base, a structural factor that did not exist standalone. That same scale also makes F5 the incumbent: runtime guardrails is the capability platform vendors bundle fastest, so the line's moat sits at adequate rather than strong despite the new distribution. [s2, s3]
Business Risks F5 could see the runtime-guardrails half absorbed as a commodity feature by hyperscaler AI gateways, leaving AI Red Team's research engine as the durable differentiator…
  • F5 could see the runtime-guardrails half absorbed as a commodity feature by hyperscaler AI gateways, leaving AI Red Team's research engine as the durable differentiator.
  • The acquired team that built the adversarial-research engine could disperse inside F5, slowing the 10,000-patterns-a-month cadence the line's depth claim rests on.
  • Standalone enterprise demand may stay unproven: F5 called the deal immaterial to revenue, so the timing thesis could outrun actual disclosed adoption.
  • Competing platforms (Check Point with Lakera, SentinelOne with Prompt Security) could out-distribute F5 to the same enterprise AI buyer through their own bundled runtime stacks.
  • Public efficacy evidence is thin: without third-party benchmarks, buyers cannot yet compare F5 AI Guardrails detection against rival runtime defenses.
Problem & Market The line addresses a buyer that emerged fast: enterprises putting generative and agentic AI into production and discovering the inference layer is an attack surface their firewalls do not cover…

The line addresses a buyer that emerged fast: enterprises putting generative and agentic AI into production and discovering the inference layer is an attack surface their firewalls do not cover. F5's own framing names prompt injection, jailbreaks, and data leakage as the threats, and positions the work as defending AI models, applications, and agents in real time.

The pain is not only vendor-asserted. Through 2025 a series of platform vendors paid to acquire runtime AI-security companies, which prices the budget line at enterprise scale rather than early-adopter scale. CTech reported a consolidation wave that Palo Alto opened with its Protect AI deal, and F5's CalypsoAI purchase fits that same pattern.

What the public record does not show is the size of the buyer population paying for this specifically, as opposed to evaluating it. The category's validation so far runs through acquirers more than through disclosed customer counts. [s1, s5, s3, s9]

Product Capabilities The line splits into two halves that F5 now brands as AI Guardrails and AI Red Team…

The line splits into two halves that F5 now brands as AI Guardrails and AI Red Team. AI Guardrails inspects how AI interacts with users and data in real time, enforces data-flow policy, and ships audit-ready governance with compliance presets for GDPR, HIPAA, and the EU AI Act.

AI Red Team is the offensive half. F5 describes it as unleashing swarms of autonomous agents that simulate thousands of attack patterns and hunt vulnerabilities, drawing on a vulnerability database the company says grows by more than 10,000 new attack patterns each month. Findings translate into active guardrail policy, linking the testing and runtime halves.

The vendor describes the underlying CalypsoAI platform as a full-lifecycle, inference-layer system using what it trademarks as Agentic Warfare. The OWASP GenAI Security Project, an independent security community, lists the CalypsoAI Inference Platform in its AI security solutions landscape, a third-party catalog entry rather than a measured benchmark. Public technical depth otherwise stops at product and blog pages, and independent benchmarks of detection efficacy are not yet visible. [s1, s2, s11, s9]

Competitive Positioning The line competes in runtime AI security and AI red teaming against both independents and the platform vendors moving into the same slot…

The line competes in runtime AI security and AI red teaming against both independents and the platform vendors moving into the same slot. Prompt Security, which SentinelOne acquired, and Lakera, which Check Point announced it would acquire in September 2025, cover overlapping runtime guarding and red teaming for the same enterprise AI buyer, and both now sit inside larger platforms the way CalypsoAI sits inside F5.

The strategic shift is that CalypsoAI is no longer an independent. As a line inside the F5 Application Delivery and Security Platform, it competes platform against platform, where buyers increasingly pick the runtime AI security that ships with infrastructure they already run. That cuts both ways: F5's distribution is an advantage the standalone company lacked, and F5 itself is now the kind of incumbent that can bundle a guardrails feature into a deal an enterprise already signs.

The durable separation, if one holds, is the adversarial-research engine behind AI Red Team, which a bundled competitor cannot reproduce quickly. Whether that engine keeps its edge inside F5 is the open question. [s2, s7, s3, s5]

Go-to-Market & Traction The strongest disclosed go-to-market signals predate the acquisition…

The strongest disclosed go-to-market signals predate the acquisition. F5's press release states CalypsoAI is trusted by global enterprises including Palantir and SGK, a vendor-stated claim rather than independently confirmed references, and the company held a Top-Two Finalist slot in the 2025 RSAC Innovation Sandbox plus a Fast Company innovation honor.

The $180 million headline price is best read as an acquirer's conviction in the asset, not as a measure of the line's sales. F5 told investors the transaction would be immaterial to its revenue and operating results, which means CalypsoAI's standalone enterprise pull was not large enough to move F5's numbers and was not separately disclosed. A regulatory filing with the SEC records the deal closing in September 2025 for $145.2 million in cash, below the $180 million headline consideration, with CalypsoAI becoming a wholly-owned subsidiary of F5. CB Insights includes CalypsoAI in several of its curated technology collections.

Going forward the go-to-market motion becomes F5's: the line reaches F5's installed enterprise base through the application platform rather than through CalypsoAI's own sales effort. Whether that distribution converts the settled market timing into disclosed adoption is the signal to watch. [s6, s3, s5, s9, s10]

Team & Credibility The team's clearest public assets are third-party honors and shipped product depth…

The team's clearest public assets are third-party honors and shipped product depth. CalypsoAI was named a Top-Two Finalist in the 2025 RSAC Innovation Sandbox and one of Fast Company's Most Innovative Companies in AI for 2025, both outside validations of a company founded in 2018.

The cited public record does not establish prior security-company exits by the founders, so the credibility read rests on the recognition and the product rather than on a named founder track record. CEO Donnchadh Casey led the company into the F5 deal, and F5 CEO François Locoh-Donou framed the acquisition around defending the AI attack surface.

The acquisition also reshapes the team question. The group that built the adversarial-research engine now disperses into F5's larger organization, so the line's future depth depends on F5's roadmap and retention rather than on the independent team that earned the honors. [s6, s4, s3]

Trust Readiness The distribution-and-procurement story now runs through F5, a public company (NASDAQ: FFIV) with three decades of enterprise security operating history and an established procurement and compliance posture…

The distribution-and-procurement story now runs through F5, a public company (NASDAQ: FFIV) with three decades of enterprise security operating history and an established procurement and compliance posture. For a security buyer, an acquirer of that standing eases vendor-viability questions about the company behind the line, separate from what the line itself has attested.

On the product side, AI Guardrails markets audit-ready observability, scanning, and logging with ready-made compliance presets for GDPR, HIPAA, and the EU AI Act, which speaks directly to a procurement reviewer's regulatory checklist.

The F5 product page documents full functionality in on-prem and fully air-gapped deployments, which addresses buyers that cannot route AI traffic to a vendor cloud. What is not yet public for the rebranded line is its own product-level certification and attestation set, as opposed to F5's corporate posture. Those product-level independent certifications remain undocumented in the cited record, and they are the artifacts a security review would ask to see next. [s1, s3, s12]

Competitors Lakera, Prompt Security, NeuralTrust, Aim Security, Cloudflare…
Company Relationship Note Compare
Lakera competes with Runtime AI guarding plus red teaming for the same enterprise buyer, which Check Point announced it would acquire in September 2025, a same-asset-into-platform move that parallels CalypsoAI landing inside F5.
Prompt Security competes with Runtime AI protection and red teaming for the enterprise GenAI buyer, acquired by SentinelOne, a platform-bundled rival on the same slot.
NeuralTrust competes with AI gateway, runtime firewall, and automated red teaming, overlapping the line's runtime guardrails and offensive-testing halves. N/AWe scored these companies at different scopes, so the totals measure different things.
Aim Security competes with Guards runtime LLM traffic and models for the enterprise AI buyer, acquired by Cato Networks in September 2025, another platform absorbing the runtime slot. N/AWe scored these companies at different scopes, so the totals measure different things.
Cloudflare adjacent Ships an AI gateway that routes and screens LLM traffic, the platform-bundled egress layer that can commoditize the guardrails half. N/AWe scored these companies at different scopes, so the totals measure different things.

Add analyzed competitors to compare them side by side with CalypsoAI.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Exposed 12 /21 Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software. pivot urgently

The line's strengths are the problem and the buyer, and its weaknesses are the missing locks. Adversarial red teaming at scale, drawing on a library F5 says grows by over 10,000 attack patterns a month, is a hard problem. Its buyers are regulated enterprises whose replacement norms the record does not detail. Replacement may mean recreating configured guardrail policy and audit records, friction the record does not size, and a rival AI gateway inspects the same traffic. The cited record identifies no certification gate blocking that swap. The attack library is vendor research a funded entrant could assemble, and F5 sells the line as a product rather than infrastructure other applications depend on. F5's distribution belongs to the parent, so it does not make the line harder to replace.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 F5 sells the line as real-time protection and audit-ready governance, assessment and enforcement software the customer team operates and whose outcomes it owns, with the vendor-maintained attack library as product content rather than an accountability layer.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 1/3 The cited page markets custom policy creation through a natural language interface as rapid, and enforcement logs export to a third-party SIEM, so the documented posture favors portability rather than lock-in. No source documents non-portable accumulated history, deployed customer integrations, learned workflows, or migration cost, and the technology-alliance material describes vendor partnerships rather than customer coupling, so the record does not establish meaningful exit friction.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 The GDPR, HIPAA, and EU AI Act presets on the AI Guardrails page are alignment features that help a buyer meet its own obligations, not a certification or liability gate that blocks an easy replacement. The line earns no compliance lock.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Adversarial red teaming at scale that draws on a vulnerability database F5 says grows by more than 10,000 attack patterns a month is a genuinely hard problem requiring specialized expertise.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 The evidenced buyers are large global enterprises, with Palantir and SGK named in the press release, and the product sells with automated auditing templates for GDPR, HIPAA, and the EU AI Act plus on-premises and air-gapped deployment options, the operating context of regulated enterprise procurement. The cited pages do not directly document procurement or legal gates, so the rung rests on the evidenced buyer class rather than a documented procurement process.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 The line runs at the inference layer, in the path of the traffic flowing between users and AI applications, but F5 presents it as a guardrails and red-team product with platform features rather than infrastructure other applications independently depend on. The rung reflects the line itself rather than F5's platform reach.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 The cited record describes the regularly updated attack-pattern database as a vendor-maintained research library and identifies no non-public cross-customer pooled corpus behind it. On that record the asset reads as accumulating but reproducible rather than a proprietary data moat, and weaker as a lock than a non-public cross-customer dataset would be.
Strategic Market Segmentation The line targets the enterprise putting generative and agentic AI into production, the buyer with both the budget and the regulatory exposure to defend the inference layer…

The line targets the enterprise putting generative and agentic AI into production, the buyer with both the budget and the regulatory exposure to defend the inference layer. F5 describes the work as real-time protection for AI models, agents, and connected data, and names data governance, threat management, and risk auditing as the jobs the buyer is paying for.

The disclosed target is the large, compliance-sensitive enterprise. F5's press release names Palantir and SGK as enterprises that trusted CalypsoAI before the deal, and GeekWire describes the customer as organizations deploying AI-related workloads. The compliance presets for GDPR, HIPAA, and the EU AI Act on the AI Guardrails page point to the enterprise with a procurement reviewer and a regulatory checklist, though the public materials do not define the segment's boundaries or rule out less-regulated buyers.

The segment's edges stay fuzzy in the public record. F5 does not disclose how many enterprises pay for the line or what they pay, and called the acquisition immaterial to its revenue, so the size of the paying population as opposed to the evaluating one is not visible.

Product Capabilities & AI Advantages The line splits into a defensive half and an offensive half that feed each other…

The line splits into a defensive half and an offensive half that feed each other. AI Guardrails inspects how AI interacts with users and data in real time, enforces data-flow policy, and ships audit-ready observability with compliance presets. AI Red Team is the offensive half, and F5 describes it as unleashing swarms of autonomous agents that simulate thousands of attack patterns and hunt vulnerabilities in AI systems.

The advantage that is hard to copy sits in the offensive half. F5 says the simulated attacks draw on a vulnerability database it updates with more than 10,000 new attack patterns each month, and that findings translate into active guardrail policy with a few clicks. The defensive half is valuable but reproducible, because real-time inspection and policy enforcement are a capability a competing AI gateway could add. The research engine that generates the attack library would be harder for a well-funded copycat to reproduce quickly than the runtime enforcement.

Public technical depth stops at product and blog pages. F5 frames the underlying CalypsoAI system as a full-lifecycle inference-layer platform, and CEO Donnchadh Casey described it to GeekWire as pressure testing AI systems at scale and setting inference-layer guardrails that adapt as models change. Independent benchmarks of detection efficacy are not yet visible.

Sales Engagement & Go-to-Market The strongest disclosed go-to-market signals predate the acquisition…

The strongest disclosed go-to-market signals predate the acquisition. F5's press release states CalypsoAI is trusted by global enterprises including Palantir and SGK, a vendor-stated named-customer claim rather than an independently confirmed reference, and the company held a Top-Two Finalist slot in the 2025 RSAC Innovation Sandbox. GeekWire describes the customer as organizations deploying AI-related workloads.

The motion now becomes F5's rather than CalypsoAI's. F5 says it will fold the line into the F5 Application Delivery and Security Platform, an integration that may give the line access to F5's enterprise go-to-market instead of the standalone sales effort that carried CalypsoAI to the deal. Whether that platform reach converts into adoption of this line is not yet public.

The conversion is the open question. F5 sized the purchase as immaterial to its own revenue, which means CalypsoAI's standalone enterprise pull was not large enough to move F5's numbers and was not separately disclosed. Whether F5's reach turns the settled market moment into named, public adoption is the signal worth watching.

Pricing Model The line publishes no price…

The line publishes no price. The AI Guardrails product page sells the capability and routes the reader to a demo, and that cited page states no unit of charge and no list price.

Hidden pricing fits the buyer and the motion. A line sold into regulated enterprises through a platform sales team, against deals an enterprise negotiates, typically prices through quotes rather than a published rate. The absence of a public number is consistent with that motion rather than a gap in the analysis.

What the public record does not settle is the unit of value. There is no fetched evidence of whether F5 charges by traffic inspected, by models protected, or as a platform add-on, so the question of what F5 believes the buyer is paying for stays open at the pricing level.

Product Delivery & Operations The line is delivered as inference-layer software that sits in the path between users and AI…

The line is delivered as inference-layer software that sits in the path between users and AI. F5 describes real-time protection for AI models, agents, and connected data, and Casey described setting inference-layer guardrails that adapt as models change, which places the runtime work in the live request flow rather than in an after-the-fact scan.

The two halves operate as a loop. AI Red Team runs simulated attacks from the vulnerability database, and F5 says teams translate those findings into active AI Guardrails policy with a few clicks, so the offensive testing and the runtime enforcement share one operational cycle rather than running as separate tools.

The deployment specifics for the rebranded line are not yet public. The captured pages did not document the line's own deployment architecture or data residency model, the operational detail a security review would ask for next; the live product page has since drifted and now advertises on-premises and air-gapped deployment.

Earning Customers' Trust The trust story now runs through F5 rather than a venture-stage independent…

The trust story now runs through F5 rather than a venture-stage independent. F5's public-company status and enterprise security history improve the vendor-viability story in a way a startup at CalypsoAI's stage could not, while product-level attestations remain the line's own question, which matters to a security buyer weighing whether the vendor will still exist at renewal.

On the product side, AI Guardrails markets audit-ready observability, scanning, and logging with ready-made compliance presets for GDPR, HIPAA, and the EU AI Act. That feature set speaks directly to a procurement reviewer's regulatory checklist, and the earlier outside recognition, a 2025 RSAC Innovation Sandbox Top-Two Finalist slot, gives the pre-acquisition product a third-party signal.

What is not yet public for the rebranded line is the specific attestation set at the product level, as opposed to F5's corporate posture. Independent product-level certifications are the artifacts a buyer would ask to see, and the fetched pages do not show them. The current product page lists public-cloud, private-cloud, on-premises, and air-gapped deployment options, but detailed architecture, data-residency, and data-handling documentation for a regulated environment is not yet public.

Platform Strategy & Ecosystem Positioning The line is now a component of a larger platform rather than a standalone product…

The line is now a component of a larger platform rather than a standalone product. F5 folds AI Guardrails and AI Red Team into the F5 Application Delivery and Security Platform, so the line competes platform against platform, though the cited pages do not establish how enterprise buyers are choosing between bundled and standalone runtime AI security.

The platform move cuts both ways for the line. F5 may extend the line's reach by distributing it into its enterprise base, and that is the upside. The downside is that F5 itself becomes the kind of incumbent that can bundle a guardrails feature into a deal an enterprise already signs, the same pressure other platform vendors that absorbed runtime AI-security companies through 2025 apply from their own stacks.

The durable separation, if one holds, is the adversarial-research engine behind AI Red Team, which a bundled competitor cannot reproduce quickly. Whether that engine keeps its edge inside F5's roadmap is the platform-level question.

Team & Execution Capability The team's clearest public assets are outside recognition and shipped product depth…

The team's clearest public assets are outside recognition and shipped product depth. CalypsoAI was founded in 2018 and was named a Top-Two Finalist in the 2025 RSAC Innovation Sandbox, and the current product demonstrates adversarial-testing depth, signals that the group could ship a hard product.

The public record does not establish prior security-company exits by the founders, so the credibility read rests on the recognition and the product rather than on a named founder track record. CEO Donnchadh Casey led the company into the F5 deal, and described the customer-facing work as pressure testing AI systems at scale.

The acquisition reshapes the team question going forward. The group that built the adversarial-research engine now folds into F5's larger organization, so the line's future depth depends on F5's retention and roadmap rather than on the independent team that earned the honors. The 10,000-patterns-a-month cadence the depth claim rests on is the thing that retention has to sustain.

Sources

Company Detail Sources (5)
Id Source Tier Accessed
f1 F5: F5 AI Guardrails official 2026-07-09
f2 F5 to acquire CalypsoAI (announcement) official 2026-06-07
f3 F5 press release: About CalypsoAI funding official 2026-06-14
f4 AI Defense Matrix Catalog entry other 2026-06-07
f5 AI Defense Matrix Catalog mapping other 2026-06-23
Profile Analysis Sources (12)
Id Source Tier Accessed
s1 F5 AI Guardrails product page
“F5 AI Guardrails meets the evolving needs of AI security by providing scalable data governance, augmented threat management, and risk auditing for present and future challenges.”
official 2026-06-14
s2 F5 completes acquisition of CalypsoAI, introduces F5 AI Guardrails and F5 AI Red Team
“unleashing swarms of autonomous agents to simulate thousands of attack patterns and hunt vulnerabilities in AI systems.”
official 2026-06-14
s3 F5 to acquire CalypsoAI (press release, September 11, 2025)
“F5 will acquire all issued and outstanding shares of CalypsoAI, a private company with major operations in Dublin, Ireland for $180 million in purchase consideration financed primarily with cash.”
official 2026-06-14
s4 GeekWire on F5's $180M CalypsoAI acquisition
“Founded in 2018 with offices in Ireland and New York City, Calypso provides real-time threat defense and other data security products to customers deploying AI-related workloads.”
press 2026-06-14
s5 CTech: M&A spotlight shifts to Lasso, Aim, and Pillar after SentinelOne's $250M Prompt deal
“In April, Palo Alto fired the opening shot in a consolidation wave with its $700 million acquisition of Protect AI.”
press 2026-06-18
s6 F5 press release: About CalypsoAI block
“CalypsoAI was founded in 2018 and has secured over $40 million in venture funding from investors including Paladin Capital Group, Lockheed Martin Ventures and Hakluyt Capital.”
official 2026-06-14
s7 Check Point: Check Point Acquires Lakera to Deliver End-to-End AI Security for Enterprises
“Check Point Software Technologies Ltd. (NASDAQ: CHKP) ... today announced it has entered into an agreement to acquire Lakera, one of the world's leading AI-native security platforms for Agentic AI applications.”
official 2026-06-18
s8 Cato Networks: Cato Networks Acquires Aim Security to Extend SASE Leadership and Secure Enterprise AI Transformation
“Cato Networks, the SASE leader, announced today that it acquired Aim Security, a visionary leader of AI security.”
official 2026-06-18
s9 F5 Form 10-Q Note 4 Business Combinations: CalypsoAI acquisition, quarter ended December 31, 2025
“On September 26, 2025, the Company closed on a transaction for the acquisition of CalypsoAI Corp. ("CalypsoAI"), a provider in enterprise AI security for $145.2 million in cash, with CalypsoAI immediately becoming a wholly-owned subsidiary of F5 upon the closing of the transaction.”
regulatory 2026-06-30
s10 CB Insights: CalypsoAI analyst profile and Expert Collections
“Expert Collections are analyst-curated lists that highlight the companies you need to know in the most important technology spaces. CalypsoAI is included in 6 Expert Collections, including Artificial Intelligence (AI).”
research 2026-06-30
s11 OWASP GenAI Security Project: CalypsoAI Inference Platform in the AI Security Solutions Landscape
“CalypsoAI secures GenAI across applications and agents. The CalypsoAI Inference Platform tests, defends, and monitors AI in development and production.”
research 2026-06-30
s12 F5 AI Guardrails: Private AI deployment methods
“Maintain consistent privacy with full functionality in on-prem and fully air-gapped deployments.”
official 2026-06-30
Deep-Dive Sources (7)
Id Source Tier Accessed
s1 F5 AI Guardrails product page
“Ensure enterprise-wide policy alignment with automated auditing templates for GDPR, HIPAA, EUAIA, and more.”
official 2026-08-01
s2 F5 completes acquisition of CalypsoAI, introduces F5 AI Guardrails and F5 AI Red Team
“unleashing swarms of autonomous agents to simulate thousands of attack patterns and hunt vulnerabilities in AI systems. simulated attack techniques are rooted in our preeminent AI vulnerability database, a vast library updated regularly with over 10,000 new attack patterns each month.”
official 2026-06-18
s3 F5 press release: transaction details (September 11, 2025)
“F5 will acquire all issued and outstanding shares of CalypsoAI, a private company with major operations in Dublin, Ireland for $180 million in purchase consideration financed primarily with cash. The transaction is expected to be immaterial to F5's revenue and operating results.”
official 2026-08-01
s4 GeekWire on F5's $180M CalypsoAI acquisition
“Founded in 2018 with offices in Ireland and New York City, Calypso provides real-time threat defense and other data security products to customers deploying AI-related workloads.”
press 2026-06-18
s5 CTech on the AI-security M&A wave (post-Prompt Security deal)
“In April, Palo Alto fired the opening shot in a consolidation wave with its $700 million acquisition of Protect AI.”
press 2026-08-05
s6 F5 press release: About CalypsoAI block
“Trusted by global enterprises including Palantir and SGK. CalypsoAI was founded in 2018 and has secured over $40 million in venture funding from investors including Paladin Capital Group, Lockheed Martin Ventures and Hakluyt Capital.”
official 2026-08-01
s7 GeekWire on CalypsoAI funding history and product framing
“Our customers rely on us to pressure test AI systems at scale, set inference layer guardrails that adapt as models change, and to gain visibility and auditability across their AI estate, CalypsoAI CEO Donnchadh Casey said in a statement.”
press 2026-08-01

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.