DeepKeep

Security for AI

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software.
Founded 2021
Funding $19.49M
Last updated 2026-07-30

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

DeepKeep sells standalone runtime AI security in a category that platform vendors moved to consolidate through 2025. Palo Alto completed its acquisition of Protect AI and Check Point completed its acquisition of Lakera, so an enterprise could source an LLM firewall and red teaming from suites it already buys. DeepKeep also defends computer-vision and multimodal models, work backed by adversarial-vision research including a paper founder Rony Ohayon co-authored, and a EUR 2.5 million European Innovation Council grant. That vision coverage is a distinctive part of its pitch. DeepKeep's own pages show a Trusted By logo wall and no attributed customer reference. DeepKeep fits an enterprise securing vision or multimodal AI. Elsewhere it competes with vendors the buyer already pays.

Sourced Details

Description DeepKeep helps organizations secure their AI applications, agents, and models, using an AI firewall, red teaming, and model scanning across language and computer vision systems. [f1]
Founded 2021 [f2]
HQ Tel Aviv, Israel [f2]
Funding $19.49M total [f3]
Latest funding SAFE round (undisclosed amount) from OurCrowd, February 2026 [f4]
Deployment SaaS, Self-hosted [f5]

Products

Product What it does
DeepKeep DeepKeep: AI security platform with a runtime AI firewall, automated red teaming, and model scanning for LLM and computer vision systems.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

DeepKeep is an AI security platform with a runtime AI firewall, automated red teaming, and model scanning for LLM and computer vision systems. It is mapped to the AI Defense Matrix. [f6]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 27 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 DeepKeep names the AI assets it defends and the enterprise buyer, but the pain stays qualitative and the non-vendor grounding is limited to SecurityWeek's funding-announcement description (s6), a single source rather than multiply-sourced quantified pain. [s1, s2, s6]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 DeepKeep documents capability slots on its own pages, but the peer-reviewed papers (s5) count toward team rather than product, and no public docs benchmark, demo, or third-party evaluation supplies an external product validation point. [s2, s5, s8]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 4/5 Enterprise adoption of LLMs and AI agents since 2024 created the attack surface DeepKeep tests and protects, and the founder cites MITRE ATLAS, first released in 2021, as the external signal that adversarial AI threat modeling would grow. Buyer-side regulatory drivers in the EU reinforce the demand. [s8, s2, s9]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 4/5 Founder and CEO Rony Ohayon founded LiveU and ran DriveU as CEO, holds a PhD in communication systems engineering and more than 30 patents, and co-authors the adversarial-vision research the product builds on. That repeat-builder record plus a sustained in-domain publication pattern is strong, without an AI-security exit that would lift it higher. [s15, s5, s4]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 DeepKeep displays a Trusted By logo wall on its homepage naming firms such as EY, NTT Data, and ST Engineering, but publishes no named buyer reference with an attributed quote or case study, and its strongest external endorsements remain an Awz seed and a European Innovation Council grant. That absence of a named buyer reference holds it below vendors that show named integrations. [s1, s9, s7]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 DeepKeep's $10 million seed and EUR 2.5 million grant (s6, s9) are proportional to a seed-stage motion with visible shipping, but no disclosed revenue or growth confirms output per dollar, the default for a funded startup. [s6, s9, s11]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 4/5 An AI firewall, automated red teaming, and model scanning are recognizable slots that buyers and analysts place without vendor coaching, and the press describes DeepKeep in those terms. The category is the same one platform vendors validated by acquiring standalone AI security companies in 2025, with Palo Alto completing its purchase of Protect AI and Check Point its purchase of Lakera. [s6, s11, s2, s16, s17]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 The LLM firewall and red-teaming capabilities are absorbable by model providers and platforms, and the completed 2025 acquisitions of runtime AI security rivals, Protect AI into Prisma AIRS and Lakera into Check Point, show the pressure is real. The computer-vision line and the founder's research raise replication cost in that niche but do not form a structural moat. [s3, s5, s16, s17]
Business Risks Model providers and the platforms that bought runtime AI security rivals in 2025 could bundle an LLM firewall and red teaming into suites an enterprise already buys, undercutting a standalone DeepKeep purchase on its crowded side…
  • Model providers and the platforms that bought runtime AI security rivals in 2025 could bundle an LLM firewall and red teaming into suites an enterprise already buys, undercutting a standalone DeepKeep purchase on its crowded side.
  • DeepKeep names no paying customer publicly, so buyers who require current named references could stall enterprise deals for a small company.
  • The computer-vision differentiation rests heavily on founder Rony Ohayon's research and pedigree, so his reduced involvement could erode the part of the platform rivals find hardest to copy.
  • DeepKeep has disclosed under $25 million in total funding, and a capital-heavy fight for enterprise deployments against better-funded platforms could force a raise on weak terms or a sale.
  • The computer-vision and multimodal security that sets DeepKeep apart serves a narrower buyer set, so the vision line could stay a research-grade specialty while revenue depends on the contested language-model side.
  • Switching costs may stay low where DeepKeep is deployed as an out-of-band or policy overlay rather than inline in production controls, so a customer could cancel the firewall and red-teaming subscription with less friction, though the firewall can also sit inline in the request flow and the actual integration depth at each buyer is unverified.
Problem & Market DeepKeep treats the AI models, applications, and agents an enterprise builds as the assets under attack, and sells security across the lifecycle for both language and vision models…

DeepKeep treats the AI models, applications, and agents an enterprise builds as the assets under attack, and sells security across the lifecycle for both language and vision models. The homepage frames the platform as covering applications, agents, and models, and the LLM page names prompt injection, adversarial manipulation, data leakage, hallucination, and toxic output as the threats it addresses. The buyer is the enterprise security team standing up AI in a core workflow.

Independent reporting corroborates the pain beyond vendor marketing. SecurityWeek describes DeepKeep as a model-agnostic, multi-layer platform that protects AI from research and development through deployment, covering risk assessment, detection, mitigation, and prevention. That account establishes the lifecycle risks as recognized problems rather than vendor speculation.

The company splits its problem statement across two model families. DeepKeep markets a language-model line and a separate computer-vision line, arguing that securing AI requires protecting image and multimodal systems alongside text. That dual framing is what distinguishes its problem statement from rivals that address language models alone. [s1, s2, s6]

Product Capabilities DeepKeep ships a platform of capabilities that span build time and runtime…

DeepKeep ships a platform of capabilities that span build time and runtime. The AI firewall applies real-time detection and guardrails, automated red teaming runs adaptive robustness tests, model scanning performs static and dynamic supply-chain checks, an agent scanner adds runtime protection for agentic systems, and an AI Lens layer governs employee AI usage. The LLM line covers prompt injection, semantic attacks, data leakage, hallucination, and compliance across agentic AI and MCP connections.

The computer-vision line is the capability rivals are least set up to match. DeepKeep protects vision pipelines against adversarial attacks, and its researchers, including the founder, have published peer-reviewed work on physical adversarial attacks against object detectors and on detecting adversarial attacks on deepfake detectors. That research demonstrates the vision-security craft the product line sells.

The deployment model answers a data-exposure question a security buyer raises early. The founder states that DeepKeep offers cloud-agnostic, on-premises, and air-gapped deployment, so customer data can stay inside the customer environment, and the company recently added an upgraded PII guardrail for stricter data protection. The combination of LLM and computer-vision coverage in one vendor is the capability claim that separates it from single-modality rivals. [s2, s5, s3]

Competitive Positioning DeepKeep competes against both AI security specialists and the platforms consolidating the category…

DeepKeep competes against both AI security specialists and the platforms consolidating the category. TrojAI pairs build-time red teaming with a runtime firewall, HiddenLayer runs red teaming and supply-chain security inside a broader platform, Adversa AI sells continuous red teaming, and Lakera shipped runtime guardrails before Check Point acquired it into its platform. The completed 2025 acquisitions of runtime AI security companies, Protect AI folded into Palo Alto's Prisma AIRS and Lakera into Check Point, moved overlapping LLM coverage inside larger suites.

DeepKeep's visible distinction is computer-vision and multimodal security. Where the runtime AI security peers lead with language-model defense, DeepKeep protects vision and multimodal models on top of LLMs, a combination grounded in the founder's adversarial-vision research and a European grant for multimodal protection. That coverage is the asset a bundled LLM-focused competitor cannot quickly reproduce.

The structural risk is who owns the buyer on the crowded side. Model providers can test and protect the LLMs built on their own platforms, and the vendors that bought runtime AI security rivals in 2025 can bundle a firewall and red teaming into deals an enterprise already signs. DeepKeep's vision niche is its neutrality pitch, while its LLM line is its exposure. [s3, s5, s16, s17]

Go-to-Market & Traction DeepKeep's clearest external endorsements come from funders rather than named buyers…

DeepKeep's clearest external endorsements come from funders rather than named buyers. A $10 million seed led by the Canadian-Israeli VC Awz Ventures, placed through the Awz X-Seed Hub joint venture with the Israeli Ministry of Defense R&D directorate, and a EUR 2.5 million European Innovation Council grant for multimodal AI security give it institutional credibility. These are validation signals from investors and a public funder, not evidence of paid deployments.

Verifiable named-customer proof is thin. DeepKeep displays a Trusted By logo wall on its homepage naming firms such as EY, NTT Data, Macnica, and ST Engineering, and SecurityWeek reports it is already used by global enterprises in AI computing, finance, and security, but no buyer speaks publicly with an attributed reference or case study in the cited record. That gap between displayed logos and a named, quotable deployment is the signal a buyer demanding current references would probe first.

The motion is enterprise-direct and research-assisted. DeepKeep routes prospects to a book-demo flow, publishes original adversarial research and a steady blog, and recently launched Vibe AI Red Teaming that pairs human expertise with AI-driven execution. Disclosed customer references would be the signal that this attention has converted to deployments. [s1, s9, s6]

Team & Credibility DeepKeep's credibility comes from a repeat-builder founder with an in-domain research record…

DeepKeep's credibility comes from a repeat-builder founder with an in-domain research record. Founder and CEO Rony Ohayon founded the live-video company LiveU and served as its CTO, ran the autonomous-driving connectivity company DriveU as CEO, and holds a PhD in communication systems engineering along with more than 30 registered patents. That career in video, vision, and autonomous systems is the background the company's computer-vision focus draws on.

The research record reinforces the team's standing. DeepKeep researchers, including the founder, have co-authored peer-reviewed adversarial-ML papers such as a study of physical black-box attacks on object detectors and a method for detecting adversarial attacks on deepfake detectors. This is a sustained in-domain publication pattern rather than a single covered event.

The wider leadership team is publicly identifiable. The about page lists CTO Yossi Altevet, VP of Research and Development Gad Sosa, a VP of Product, a VP of Marketing, and a VP of Sales for the Americas, which shows a built-out function set for a company of its size. [s15, s5, s4]

Trust Readiness DeepKeep's trust posture leans on flexible deployment…

DeepKeep's trust posture leans on flexible deployment. The founder states that the platform runs cloud-agnostic, on-premises, and air-gapped, so an enterprise can keep customer data inside its own environment, which addresses the data-exposure question a security buyer raises first when a product inspects proprietary AI systems. The company also added an upgraded PII guardrail aimed at global compliance requirements.

The homepage now displays SOC 2, ISO 27001, ISO 9001, and GDPR badges, which signals a compliance posture a procurement team expects. Those badges are vendor-displayed claims rather than the downloadable third-party attestation reports a security review requests, so for a company selling into financial-services and regulated buyers, producing the underlying reports on request is the readiness item that would still surface. [s1, s8, s2]

Competitors TrojAI, HiddenLayer, Adversa AI, Mindgard, Lakera, OpenAI…
Company Relationship Note Compare
TrojAI competes with Pairs build-time red teaming with a runtime firewall for the same enterprise AI buyer, on the language-model side DeepKeep also contests.
HiddenLayer competes with Independent AI security platform running red teaming and supply-chain security across the lifecycle, overlapping DeepKeep's runtime capabilities.
Adversa AI competes with Continuous AI red-teaming specialist contesting the build-time adversarial-testing job DeepKeep also covers.
Mindgard competes with Automated AI red-teaming specialist competing on the model and application testing side of DeepKeep's platform.
Lakera competes with Shipped runtime AI guardrails overlapping DeepKeep's firewall before Check Point acquired it, moving the runtime job into a platform.
OpenAI adjacent Model provider that could ship native red teaming and runtime filtering for the LLMs built on its platform, removing the third-party budget line. N/AWe scored these companies at different scopes, so the totals measure different things.

Add analyzed competitors to compare them side by side with DeepKeep.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Exposed 12 /21 Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software. pivot urgently

Once a customer wires DeepKeep's firewall into live AI traffic, the costly exit is removing it and integrating a replacement. The record shows no other structural blocker. The SOC 2, ISO 27001, and GDPR badges are self-displayed attestations any rival can earn. The AI firewall and red teaming are the capabilities Palo Alto bought with Protect AI and Check Point bought with Lakera. DeepKeep's distinctive vision and multimodal defense draws on research the founder published, though the record does not show how much of the production method the papers disclose. No public source names a proprietary dataset or a regulation requiring the product class. Matching that defense takes a rival years of adversarial-ML work, and Rony Ohayon's record is a head start rather than a tested moat.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Customers buy a platform of software modules, an AI firewall, model scanning, red teaming, and an agent scanner, that they configure and run themselves, with no managed service in which DeepKeep analysts accept hands-on accountability for outcomes.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Placing the firewall inline in the request flow and wiring scanning and red teaming into a customer's AI pipelines builds real friction once in place, while no data-residency lock, network effect, or system-of-record install base appears in fetched sources to reach the 3.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 DeepKeep displays SOC 2, ISO 27001, and GDPR badges in its homepage footer, confirmed by the served filenames, but these are table-stakes vendor-displayed attestations that ease procurement with no inspectable third-party portal, and the cited record identifies no regulation mandating the product class.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Defending both LLMs and computer-vision models against adversarial, physical, and supply-chain attacks with detection, scanning, and red teaming is applied adversarial-ML engineering that takes years of specialized work, and the founder's published adversarial-ML research reflects that depth.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 The buyer is the enterprise AI-security team, and the customer evidence is a vendor-displayed Trusted By logo wall naming EY, NTT Data, and ST Engineering plus a SecurityWeek report of use in finance and security, none of it a named referenceable account.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 The firewall is an inline runtime control and the scanning and red-teaming modules are tools the customer runs over its own pipelines, an application layer that a customer's AI keeps functioning without.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 The founder's adversarial-ML work is published research, and no named non-public dataset or cross-customer telemetry flywheel appears in fetched sources, so no demonstrated data asset lifts the score.
Strategic Market Segmentation DeepKeep sells to the enterprise security team standing up AI in a core workflow…

DeepKeep sells to the enterprise security team standing up AI in a core workflow. The company frames its platform as covering the applications, agents, and models an organization builds, and SecurityWeek reports it is already used by global enterprises in the AI computing, finance, and security industries. The buyer owns the AI deployment and answers for its safety, not a small team outsourcing the function.

The segment splits across two model families, and that split is the deliberate distinction. DeepKeep markets a language-model line and a separate computer-vision line, and the founder states that its expertise spans both computer vision and LLMs. Rivals in the cited record emphasize language-model protection, so the vision coverage widens the addressable set toward image and multimodal buyers.

The funding mix points at Europe without settling customer geography. The European Innovation Council grant ties the company to European public funding, and SecurityWeek places early use in the finance and security industries. The open question is whether the vision and multimodal segment is large enough to anchor revenue, or stays a specialty while the contested language-model side carries the load.

Product Capabilities & AI Advantages DeepKeep's claimed advantage is covering the full AI lifecycle across both model families in one platform…

DeepKeep's claimed advantage is covering the full AI lifecycle across both model families in one platform. The capabilities span an AI firewall for real-time detection and guardrails, automated red teaming for robustness tests, model scanning for static and dynamic supply-chain checks, an agent scanner for runtime protection of agentic systems, and an AI Lens layer that governs internal AI usage. The LLM line names prompt injection, adversarial manipulation, and semantic attacks as the threats it stops.

CV and multimodal coverage appears to be DeepKeep's clearest differentiation in this source set. The company protects vision pipelines against adversarial attacks, and its research page lists a founder-co-authored deepfake-detector defense in TMLR 2024 alongside a physical adversarial-attack study on object detectors. That published research demonstrates the vision-security craft the product line sells rather than asserting it from marketing pages.

The durable technical asset is depth in adversarial ML, not a data advantage. The reasoning behind detection and red teaming is engineering and research a funded competitor can reproduce, and no fetched page names a non-public training corpus or a third-party accuracy benchmark. The breadth across LLM and vision is the verifiable differentiator, and the research record is what makes it credible.

Sales Engagement & Go-to-Market DeepKeep's clearest external endorsements come from funders rather than named buyers…

DeepKeep's clearest external endorsements come from funders rather than named buyers. A $10 million seed led by Awz Ventures and a EUR 2.5 million European Innovation Council grant for multimodal AI security give it institutional credibility. These are validation signals from investors and a public funder, not evidence of paid deployments.

Named-customer proof stays thin. The homepage shows a Trusted By logo wall currently naming EY, NTT Data, Macnica, and ST Engineering, with Sumitomo Corporation and Toshiba on the June capture but not the live wall, and SecurityWeek reports use by global enterprises in finance and security, but no buyer speaks publicly with an attributed reference or case study in the fetched pages. That gap between displayed logos and a quotable deployment is what a buyer demanding current references would probe first.

The motion is enterprise-direct and research-assisted. DeepKeep routes prospects to a book-demo flow, publishes original adversarial research and a company blog, and recently launched a Vibe AI Red Teaming offering. Founder-fronted selling and the grant and seed backing fit a company at this stage, and while SecurityWeek reports enterprise use, an attributed customer reference remains the missing public signal.

Pricing Model DeepKeep does not publish pricing in fetched sources, so the charged unit and list price stay private…

DeepKeep does not publish pricing in fetched sources, so the charged unit and list price stay private. Every page routes to a book-demo flow rather than a self-serve plan or a pricing table. A vendor that hides prices this way usually targets large negotiated enterprise deals, which fits the global-enterprise buyer SecurityWeek describes.

The charged unit is not stated, and the platform's breadth makes several plausible. Coverage spans model scanning at build time, an inline firewall at runtime, and red teaming on demand, so DeepKeep could meter by models protected, by request volume through the firewall, or by platform subscription. None of these is confirmed publicly, which withholds the budget-anchoring signal some peers publish.

The inferable belief is that buyers pay for lifecycle AI assurance rather than a single feature. The platform framing around risk assessment, detection, mitigation, and prevention points to a suite sale, and confirming the meter and whether consumption is capped would require the sales conversation the hidden-price posture signals as the intended path.

Product Delivery & Operations DeepKeep delivers as software the customer configures and runs across the AI lifecycle…

DeepKeep delivers as software the customer configures and runs across the AI lifecycle. The AI firewall inspects every interaction as it happens and blocks or redacts violations before they cause harm, model scanning runs static and dynamic supply-chain checks, and automated red teaming runs adaptive robustness tests. The platform spans build time and runtime rather than a single insertion point.

The deployment model answers a data-exposure question a security buyer raises early. DeepKeep states that it supports cloud, on-premises, and air-gapped deployments, so an enterprise inspecting proprietary AI systems can keep its data inside its own perimeter. That flexibility matters for the finance and defense-adjacent buyers the company courts.

The operational profile is a tool the customer operates, not a managed service. Nothing in the fetched pages shows DeepKeep analysts running the platform on a customer's behalf or accepting hands-on responsibility for outcomes, and no published uptime or support SLA surfaces. The firewall can sit inline in the request flow, which raises the operational stakes of a misfire and is the readiness item a buyer would test.

Earning Customers' Trust DeepKeep displays a common enterprise attestation set for a tool that inspects privileged AI traffic…

DeepKeep displays a common enterprise attestation set for a tool that inspects privileged AI traffic. The homepage footer carries SOC 2, ISO 27001, and GDPR badges, confirmed by the served image filenames and the rendered footer. These signal a compliance posture a procurement team expects, but they are self-displayed badges rather than an inspectable third-party portal with downloadable reports.

Deployment flexibility carries part of the trust case. By offering cloud, on-premises, and air-gapped options, DeepKeep lets a buyer keep customer data inside its own environment, which answers the data-residency objection a security review raises when a product reads proprietary models and prompts. The firewall's inline blocking and redaction is framed as the runtime control that enforces the buyer's standards.

The attestations are enterprise-grade but table-stakes rather than a moat. Because the platform handles a customer's prompts, model artifacts, and outputs, a buyer should still resolve data-handling, retention, and the underlying audit reports in a formal review beyond the published badges, and producing those reports on request is the readiness item that would surface for a regulated buyer.

Platform Strategy & Ecosystem Positioning DeepKeep positions itself as a lifecycle platform rather than a point tool…

DeepKeep positions itself as a lifecycle platform rather than a point tool. It ties model scanning at build time, an inline firewall at runtime, red teaming, an agent scanner, and an AI Lens governance layer into one offering, so the platform claim rests on covering the whole AI application ecosystem rather than a single control. The founder argues the real risks emerge within the full application ecosystem, not just the models themselves.

The ecosystem bet extends toward agents and multimodal systems. The founder describes evolving the platform to secure custom AI applications and agents, and the next step in which agents interact with each other across domains, while the vision line already protects image and multimodal pipelines. That forward coverage is a roadmap claim more than a shipped network of integrations in the fetched pages.

The exposure is that platforms are moving to own the buyer on the runtime side. Palo Alto Networks completed its purchase of Protect AI into Prisma AIRS in July 2025, and Check Point completed its acquisition of Lakera in October 2025. With both deals closed, the incumbents can fold an LLM firewall and red teaming into suites an enterprise already buys, so the breadth DeepKeep assembles competes against bundles rather than standalone tools. CV and multimodal coverage is the differentiation DeepKeep itself emphasizes, though the cited pages do not map the rival bundles' vision coverage.

Team & Execution Capability DeepKeep's credibility comes from a repeat-builder founder with an in-domain research record…

DeepKeep's credibility comes from a repeat-builder founder with an in-domain research record. Founder and chief executive Rony Ohayon holds a PhD in communication systems engineering and an MBA, names more than 30 registered patents, founded the live-video company LiveU, and ran the autonomous-vehicle teleoperation company DriveU as chief executive. That career in video, vision, and connectivity is the background the computer-vision focus draws on.

The research record reinforces the team's standing. Ohayon co-authors adversarial-ML work the company publishes, including a deepfake-detector defense in TMLR 2024, and the company frames its expertise as spanning both computer vision and LLMs. This is a sustained in-domain publication pattern rather than a single covered event.

The depth below the founder is the open question in fetched sources. The public record this analysis establishes Ohayon's track record and the company's research output clearly, but individual prior builds for the wider leadership bench do not surface in the press fetched here. The verifiable strength is the founder's pedigree and the institutional backing it has drawn.

Sources

Company Detail Sources (6)
Id Source Tier Accessed
f1 DeepKeep: AI Security Platform for Applications, Agents and Models official 2026-07-09
f2 SecurityWeek on DeepKeep seed funding press 2026-06-13
f3 Exa company research aggregate funding for DeepKeep Ltd. other 2026-06-13
f4 Startup Nation Finder DeepKeep company page other 2026-06-21
f5 AI Defense Matrix Catalog entry other 2026-06-10
f6 AI Defense Matrix Catalog mapping other 2026-06-23
Profile Analysis Sources (17)
Id Source Tier Accessed
s1 DeepKeep homepage
“Trusted By (logo wall, image alt text): EY logo, NTT Data logo, Macnica logo, ST Engineering logo, CTC logo, Consist logo. SOC 2 badge, ISO 27001 badge, ISO 9001 badge, GDPR badge”
official 2026-06-16
s2 DeepKeep for LLM product page
“Protects against LLM attacks, including prompt injection, adversarial manipulation and semantic attacks”
official 2026-06-13
s3 DeepKeep for Vision product page official 2026-06-13
s4 DeepKeep about page with management team
“Rony Ohayon CEO & Founder ... Yossi Altevet Chief Technology Officer ... Gad Sosa VP of Research & Development”
official 2026-06-13
s5 DeepKeep research page with academic publications
“XAI-Based Detection of Adversarial Attacks on Deepfake Detectors ... Ben Pinhasov, Raz Lapid, Rony Ohayon, Moshe Sipper, Yehudit Aperstein ... TMLR 2024 ... Computer Vision”
official 2026-06-13
s6 SecurityWeek on DeepKeep $10M seed funding
“DeepKeep, an Israeli startup providing AI-native security ... raised $10 million in a seed funding round led by VC Awz Ventures. Founded in 2021, the Tel Aviv-based company”
press 2026-06-13
s7 SecurityInfoWatch on DeepKeep seed and Awz X-Seed Hub
“as part of the first cohort of the Awz X-Seed Hub ... established in a joint venture with MAFAT, a leading Israeli Ministry of Defense's Directorate of Defense R&D”
press 2026-06-13
s8 Unite.AI interview with DeepKeep founder Rony Ohayon
“frameworks like MITRE's ATLAS - first released in 2021 - started to appear, which was an important external signal that the field of AI security and adversarial threat modeling was about to grow”
press 2026-06-13
s9 DeepKeep EIC Accelerator award blog
“DeepKeep has been awarded EUR 2.5M in blended finance through the EIC Accelerator's October 2024 cut-off. The co-funded project: Multimodal Models with AI-Native Security and Trustworthiness”
official 2026-06-13
s10 DeepKeep Vibe AI Red Teaming launch blog official 2026-06-13
s11 DeepKeep AI firewall capability page
“AI Firewall & Guardrails, AI Runtime Protection”
official 2026-06-13
s12 DeepKeep stealth-exit launch blog official 2026-06-13
s13 Palo Alto Networks intent to acquire Protect AI (April 2025)
“today announced that it has entered into a definitive agreement to acquire Protect AI, an innovative leader in securing the use of Artificial Intelligence (AI) and Machine Learning (ML) applications and models”
press 2026-06-13
s14 SecurityWeek on Check Point acquiring Lakera (September 2025)
“Check Point Software Technologies today announced plans to acquire Lakera, a Zurich and San Francisco-based company specializing in security for Agentic AI applications”
press 2026-06-13
s15 Pulse 2.0: interview with DeepKeep founder Rony Ohayon
“I have a Ph.D. in Communication Systems Engineering, an MBA, and more than 30 registered patents in my name. Before DeepKeep, I was the CEO and Founder of DriveU ... Additionally, I founded LiveU”
press 2026-06-16
s16 Palo Alto Networks: completes acquisition of Protect AI (July 2025)
“today announced it has completed its acquisition of Protect AI ... The integration of Protect AI's forward-thinking technology and its team of experts will be a cornerstone of Palo Alto Networks' Prisma AIRS”
press 2026-06-16
s17 CSO Online: Check Point acquires Lakera into its Infinity platform
“The acquisition brings runtime protection, continuous red teaming, and multilingual defenses into Check Point's Infinity platform”
press 2026-06-16
Deep-Dive Sources (12)
Id Source Tier Accessed
s1 DeepKeep homepage: AI Security Platform for Applications, Agents and Models
“Trusted By logo wall, rendered image filenames: ey-logo.svg, ntt-data-logo.svg, macnica-logo.svg, sumitomo.svg, toshiba.svg, st-engineering-logo.svg, consist-logo.svg, ctc-logo.svg. Footer compliance badge filenames: ISO 27001.svg, soc2.svg, gdpr-compliance.svg.”
official 2026-06-17
s2 DeepKeep AI Firewall and Guardrails, AI Runtime Protection
“The AI Firewall inspects every interaction as it happens. If something violates your standards, we block or redact it before it causes harm. Otherwise, we alert you.”
official 2026-06-17
s3 DeepKeep for LLM product page
“Protects against LLM attacks, including prompt injection, adversarial manipulation and semantic attacks”
official 2026-06-17
s4 DeepKeep About page with management team
“DeepKeep for LLM. Secure language models end-to-end. DeepKeep for Vision. Protect computer vision pipelines.”
official 2026-06-17
s5 SecurityWeek on DeepKeep seed funding and TRiSM platform
“raised $10 million in a seed funding round led by VC Awz Ventures. Founded in 2021, the Tel Aviv-based company. Already used by global enterprises in the AI computing, finance, and security industries, the TRiSM platform covers risk assessments, detection, mitigation, and prevention.”
press 2026-06-17
s6 Unite.AI interview with DeepKeep founder Rony Ohayon
“We enable model scanning across all model types, but also protect against the most urgent threats such as adversarial attacks, data leakage, system misuse, and trust erosion by red-teaming the models and applying guardrails. The real risks emerge within the full application ecosystem.”
press 2026-06-17
s7 Pulse 2.0 interview with DeepKeep founder Rony Ohayon
“I have a Ph.D. in Communication Systems Engineering, an MBA, and more than 30 registered patents in my name. Before DeepKeep, I was the CEO and Founder of DriveU. Additionally, I founded LiveU. DeepKeep's expertise spans several AI model types, covering both computer vision and LLMs.”
press 2026-06-17
s8 DeepKeep EIC Accelerator award blog
“The European Innovation Council doesn't fund trends. DeepKeep has been awarded EUR 2.5M in blended finance through the EIC Accelerator's October 2024 cut-off. The co-funded project: Multimodal Models with AI-Native Security and Trustworthiness”
official 2026-06-17
s9 Palo Alto Networks completes acquisition of Protect AI (July 2025)
“Palo Alto Networks today announced it has completed its acquisition of Protect AI. The integration of Protect AI's forward-thinking technology and its team of experts will be a cornerstone of Palo Alto Networks' Prisma AIRS”
press 2026-06-18
s10 SecurityWeek on Check Point announcing plans to acquire Lakera (September 2025)
“Check Point Software Technologies today announced plans to acquire Lakera, a Zurich and San Francisco-based company specializing in security for Agentic AI applications.”
press 2026-06-18
s13 CRN India: Check Point Software Technologies completes acquisition of Lakera (October 2025)
“Check Point Software Technologies has officially completed its acquisition of Lakera.”
press 2026-07-15
s11 DeepKeep academic research page
“XAI-Based Detection of Adversarial Attacks on Deepfake Detectors. Ben Pinhasov, Raz Lapid, Rony Ohayon, Moshe Sipper, Yehudit Aperstein. TMLR 2024. Computer Vision. Patch of Invisibility: Naturalistic Physical Black-Box Adversarial Attacks on Object Detectors. MLCS @ ECML-PKDD 2024”
official 2026-06-17

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.