All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Dreadnode sells a platform that security teams use to build, test, and run AI agents for offensive work such as web-application testing and network operations. Its public record is mostly research: its sitemap lists 42 pages, and 31 of those URLs contain the word research. One introduces DreadIndex, a benchmark that scores other companies' language models on offensive-security tasks. What the record does not carry is a named buyer. No customers page appears in the sitemap, and the trust center lists controls with no completed audit report. Eighteen months after the February 2025 Series A of $14 million, the proof on offer is research standing rather than paid deployment.
| Description | Dreadnode builds an infrastructure platform that security teams use to build, evaluate, and deploy security agents for offensive work such as AI red teaming, and for defense. | [f1] |
|---|---|---|
| Founded | 2023 | [f2] |
| Funding | $14M total | [f3] |
| Latest funding | Series A (2025) | [f4] |
| Product | What it does |
|---|---|
| Dreadnode Platform | Infrastructure platform to build, evaluate, and deploy security agents, with a CLI, TUI, hosted evaluations, managed sandboxes, and a capability registry of offensive skills and tools. |
| Strikes | Builds and executes cyber evaluations that test AI capabilities and generate training data for models and agents. |
| Spyglass | An AI red team toolkit that probes AI systems for vulnerabilities to support data-driven decisions on model deployments. |
| Crucible | An AI hacking sandbox where security practitioners test, learn, and build their AI red-teaming skills against hosted challenges. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
The Dreadnode Platform probes foundation models, agentic systems, and AI applications for security, safety, and trust risks, and is mapped to the AI Defense Matrix. [f5]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Dreadnode names its buyer and the build, evaluate and deploy pain precisely, and its documentation ties that pain to concrete offensive work. The one independent account of the problem reaches the record through a Dreadnode researcher's own quotes, so the pain stays company-asserted with no outside quantification. [s1, s6, s10] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | Documentation covers the agent life cycle in detail, from a command-line tool and managed sandboxes to hosted evaluations, model training, synthetic environment generation and Kubernetes self-hosting, with reporting mapped to OWASP, MITRE ATLAS, NIST AI RMF and Google SAIF. Beyond the vendor's own pages, the code implementing its offense-versus-defense evaluation is published as DreadGOAD and Ares, and a Dark Reading article examines that work and quotes the researcher behind it. [s2, s6, s9, s18, s10] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | The enabler the company names is that models now perform at or above human capability on offensive tasks, an argument it pressed when version 2.0 became generally available in March 2026, and its own benchmark work measures that shift. What the reviewed sources do not show is buyer-side demand: no analyst category, regulatory driver or budget signal appears, and conference programming and investor participation are community and capital signals rather than purchasing ones. [s3, s8, s11] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | Press corroborates both founders' in-domain pedigree, from leading NVIDIA's AI red team to running research at NetSPI, and the company sustains a public research record: the AIRTBench benchmark paper, a separate Crucible attack-data analysis, the DreadIndex model index, open-source offense-and-defense tooling, and an accepted Black Hat USA briefing that a Dark Reading article describes. That record is publication and community standing rather than evidence of customers. [s11, s12, s7, s10, s14, s15] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 2/5 | No named customer, partnership or marketplace listing appears in any reviewed source, and the site's sitemap lists no customers page. What the record does carry is a generally available platform, a Series A syndicate that includes In-Q-Tel, and the company's own account of unnamed government, enterprise and AI-lab partners, which is one-sided evidence of adoption rather than a named reference. [s17, s11, s5, s3, s21] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | A $14 million Series A is proportional to an early-stage motion, and the release feed records seven consecutive weekly entries alongside two open-source releases and a published model index. No revenue, margin or customer-growth figure appears in any reviewed source, so output per dollar stays unconfirmed. [s11, s2, s9, s8] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 | Independent press places Dreadnode in offensive AI security, while the company's own positioning has moved to infrastructure for any security agent, a slot it explains each time it uses it. The two descriptions do not converge in the reviewed sources, which leaves placement dependent on the vendor's own framing. [s11, s10, s1, s3] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Agent build-and-deploy tooling sits within reach of the agent frameworks developers already use and of security platforms adding AI features, and the pricing page states that customer data stays in the customer's environment, so no cross-customer data asset appears in the record. The capability registry, the private evaluation tasks and the team's reputation raise the cost of replication without forming a moat that bundling could not eventually reach. [s3, s5, s8, s2] |
Dreadnode sells the infrastructure for security agents rather than a finished agent. Its homepage argues that security is going through the transformation software engineering already went through, and that the machine-learning operations layer underneath it is missing. The about page states the same position, that the company builds the platform layer so teams can build and operationalize security agents on their own terms.
The buyer it addresses is the security team that wants to apply AI to offensive work. Documentation covers web-application testing, network operations and vulnerability research, and the quickstart walks a user from installing the command-line tool to running an authorized web penetration test that ends in a report.
Independent reporting frames the same problem from the research side. According to a Dark Reading article on the company's open-source release, its AI research scientist says models from frontier labs are better at offense than at defense and that generating high-quality training data for defensive tasks is difficult. That account comes from a Dreadnode researcher, so it records the company's own framing rather than an outside measure of buyer demand. [s1, s4, s6, s19, s10]
The platform covers the whole life cycle of a security agent. Public documentation describes a command-line tool and terminal interface, hosted evaluations, managed sandboxes, model training and prompt optimization, synthetic network-environment generation, a capability registry, tracing of every tool and model call, and self-hosting on the customer's own Kubernetes cluster.
AI red teaming is the deepest documented capability. The reference covers attack strategies, transforms and scorers spanning generative jailbreaks, adversarial machine learning, multimodal probing and multi-agent attacks, and it maps findings to OWASP, MITRE ATLAS, NIST AI RMF and Google SAIF for export as reports.
Release notes record a weekly cadence. Seven consecutive weekly entries, dated July 2 to August 13 on the feed, cover a Claude Code engine, end-to-end multimodal red teaming, an agent memory and session-monitoring overhaul, a traditional-machine-learning red-teaming suite, and a versioned registry for structured agent output.
Some of the engineering is open to inspection. Dreadnode publishes a lightweight framework for interacting with language models, and example agents, on GitHub, and released DreadGOAD, a reproducible Active Directory training environment, and Ares, a system that runs red and blue agents against the same live environment. [s2, s6, s9, s18, s3, s1]
Dreadnode names the two rivals it positions itself between. Its 2.0 announcement contrasts its approach with closed vendors that deliver a single-purpose agent and with generic agent frameworks that were not built for security's requirements, and claims the middle as security-specific infrastructure.
That middle is a wider arena than the one the company started in. A pitch to be infrastructure for any security agent puts the product beside the agent tooling developers already use and beside security platforms that could add agent building to what they sell.
The claim Dreadnode leads with is breadth. Its own pages describe build, evaluate, train and deploy in one platform, and the reviewed sources establish that the platform covers those stages without establishing that a buyer chose it for that reason. [s3, s2]
Dreadnode runs a self-serve motion with an enterprise tier above it. The Pro plan starts free with $25 of complimentary credits, bills pay-as-you-go against credits worth a cent each, and charges nothing for seats. The Enterprise plan adds a one-time annual fee, on-premises deployment, dedicated engineer support and custom capability work.
No source reviewed for this catalog names a customer. The site's sitemap lists 42 pages and includes no customers page, and the company's own Series A announcement describes government, enterprise and AI-lab partners it does not name. The visible backing is instead the $14 million Series A from Decibel, Next Frontier Capital, In-Q-Tel, Sands Capital and Indie VC, with Aviso Ventures named among the investors as well.
What the company puts in front of practitioners is research and events. It jointly organized the 2025 Offensive AI Con with RemoteThreat and DevSec, and its July 2026 announcement lists an accepted Black Hat USA briefing, a workshop at a Las Vegas AI security forum and talks across DEF CON villages. That program puts the company in front of practitioners who could buy the self-serve plan themselves, and no reviewed source records one who did. [s5, s17, s21, s11, s4, s7, s20]
Dreadnode's about page lists Brad Palm as chief executive, with Will Pearce as co-founder and Nick Landers as co-founder and chief technology officer. The March 2026 launch release quoted Pearce as CEO and co-founder, so the chief-executive title moved after that announcement.
Press corroborates the founders' pedigree. SecurityWeek describes Pearce as the former lead of NVIDIA's AI red team and Landers as a former VP of Research at NetSPI.
The wider bench publishes under its own name. Company researchers wrote the AIRTBench benchmark paper and the Crucible attack-data analysis, introduced the DreadIndex model index, had an accepted Black Hat USA briefing on the August 6 program, which a Dark Reading article describes, and announced an AI Village presentation of an agent-failure-modes paper co-authored with a Google DeepMind researcher. Dreadnode states the team draws on operators from NVIDIA, Microsoft, NetSPI, Meta, Cohere and Run Sybil. [s4, s3, s11, s12, s7, s10, s14, s15, s8]
Dreadnode's clearest readiness signal is deployment choice. The Enterprise plan offers on-premises deployment, the documentation covers self-hosting on the customer's own Kubernetes cluster, and the pricing page states that customer data is never used for training and that evaluation, training, Worlds and AI red teaming data stays inside the customer's environment.
The company publishes a trust center on a Vanta-hosted subdomain. It lists controls across infrastructure, organizational, product, internal-procedure and data-privacy categories, names Amazon Web Services, Cloudflare, Google Workspace and Vanta as subprocessors, lists one resource, an engagement letter, and carries a request-access control.
No completed attestation appears in the reviewed sources. The rendered trust center lists no SOC 2 or ISO 27001 report, the probed homepage, about and pricing pages carry no attestation wording, and the published sitemap lists no compliance page. For an enterprise motion that includes on-premises deployment, a buyer would still ask for an audit report before purchase. [s5, s2, s16, s17]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Gray Swan AI | competes with | Competes for the same buyer looking to test foundation models and agents for adversarial weaknesses. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Mindgard | competes with | Competes for the same automated AI red-teaming work on models and agents. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| TrojAI | competes with | Competes for build-time AI red-teaming budget at the same buyer. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| HiddenLayer | adjacent | Adjacent because a buyer evaluates it for defending deployed models rather than for building and running offensive agents. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
Add analyzed competitors to compare them side by side with Dreadnode.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
Two things are hard for a rival to match, and neither keeps a customer from leaving. Building agents that autonomously attack AI systems takes offensive-security and machine-learning depth, visible in Dreadnode's published benchmarks and its accepted Black Hat briefing. Its DreadIndex evaluation set also includes private tasks the company wrote and has not published, which a rival would have to author for itself. What a departing customer loses is the setup its own team built, which the cited record does not size. The platform self-hosts on standard Kubernetes, and the pay-as-you-go plan carries no commitment. Its trust center lists controls and no completed audit, which a rival could match with ordinary enterprise preparation.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Dreadnode delivers software the customer's team installs, configures and operates, billed by the credits its compute and inference consume. Enterprise support and custom capability work help a team adopt the product without taking ownership of the outcome, which is the software-product level of delivery. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | A team that authors capabilities, tunes agents and builds process around the platform's traces accumulates real friction, so leaving costs more than an uninstall. The cited record does not size that exit: the platform self-hosts on standard Kubernetes, the documentation describes exporting assessment data as Parquet, and no network effect or data-residency obligation appears. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | The trust center lists controls, subprocessors and one gated engagement letter, and no completed SOC 2 or ISO 27001 report appears on it or on the other reviewed surfaces. A funded competitor could assemble the same package through ordinary enterprise preparation. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | The platform combines model fine-tuning on a team's own operational data, prompt optimization, synthetic Active Directory environment generation, sandboxed agent execution and a large adversarial-attack library, and the company's published benchmarks measure autonomous exploitation of AI systems. That is machine-learning and offensive-security depth rather than routine application work. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | The enterprise plan addresses organizations that need on-premises deployment and control of their own data, while the free self-serve tier reaches builders and practitioners who adopt it without a sales conversation. No regulated-enterprise or government customer of the platform appears in the reviewed record, and an investor's identity is not a buyer. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Teams build and run their own agents on the platform, and it ships a software development kit and a shared capability registry, which places it above a single end-user application. No reviewed source shows other production systems depending on it, so it reads as a platform with application features. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 2/3 | The evidenced asset is curated non-public content. DreadIndex includes private evaluation tasks the company authored and states it has not published, and the Crucible environment produced the cross-user attack corpus its own papers analyze. The pricing page states customer data stays in the customer's environment, so the asset is the company's own content rather than tenant telemetry, and a rival with offensive-security staff could author comparable tasks with time and effort. |
Dreadnode addresses two buyer tiers from one price list. The Pro plan is aimed at builders, practitioners and teams and starts free with complimentary credits, while the Enterprise plan is aimed at organizations that need scaled agent workloads, on-premises deployment and custom capabilities.
The personas follow the agent life cycle. The user is the offensive engineer or red teamer running capabilities against authorized targets, the champion is the security engineer or model developer standing AI up for security work, and the enterprise buyer owns the deployment and data-control requirements the higher tier answers.
Two signals suggest government and regulated buyers without confirming one. In-Q-Tel joined the Series A, the enterprise tier sells on-premises deployment and customer-held data, and the company's research program runs on Active Directory environments typical of large organizations. No reviewed source names a public-sector or regulated customer, so segment priorities read from the product and the price list rather than a disclosed roster.
The platform covers a security agent's whole life cycle. Documentation and the 2.0 announcement describe a command-line tool and terminal interface, hosted evaluations, managed sandboxes, model fine-tuning and prompt optimization, synthetic network-environment generation, a resource hub of roughly 1,600 security tasks with packaged capabilities, and tracing that records each tool and model call.
The deepest documented capability is AI red teaming. The reference covers attack strategies, transforms and scorers spanning generative jailbreaks, adversarial machine learning, multimodal probing and multi-agent attacks, with findings mapped to OWASP, MITRE ATLAS, NIST AI RMF and Google SAIF for export as reports.
The advantage the company presses is offensive expertise turned into measurement. Its published benchmark work measures how language models autonomously discover and exploit weaknesses in AI systems, drawing on 70 capture-the-flag challenges from the Crucible environment and an analysis of 214,271 attack attempts by 1,674 users, and its DreadIndex index scores models across 76 offensive-security tasks.
The design choice is horizontal infrastructure rather than a finished agent. The customer brings the domain expertise while the platform supplies the build, evaluate and deploy machinery, which the quickstart makes concrete: install the command-line tool, add the web-security capability, point it at an authorized target and let the agent produce a report.
Dreadnode runs a product-led motion with an enterprise tier above it. The Pro plan starts free with $25 of credits and bills pay-as-you-go with no commitment, so a practitioner can adopt before any sales contact, and the Enterprise plan moves to a quoted annual arrangement with on-premises deployment and dedicated engineer support.
No reviewed source names a customer. The site's sitemap lists 42 pages and includes no customers page, and the company's own Series A announcement describes government, enterprise and AI-lab partners it does not name. The visible backing is instead the $14 million Series A from Decibel, Next Frontier Capital, In-Q-Tel, Sands Capital and Indie VC, with Aviso Ventures named among the investors as well.
Dreadnode generates demand through research and events. The company jointly organized the 2025 Offensive AI Con with RemoteThreat and DevSec, its July 2026 announcement lists an accepted Black Hat USA briefing, a workshop at a Las Vegas AI security forum and talks across DEF CON villages, and it publishes benchmarks and open-source tools that put its work in practitioners' hands directly. Those practitioners are the people the free self-serve plan is priced for, and no reviewed source records one of them buying it.
Dreadnode prices by consumption rather than by seat. The Pro plan bills credits worth a cent each against inference and compute, charges no monthly fee, and puts no separate price on seats, so a team can add users without adding cost.
The enterprise arrangement adds a fixed component to the same meter. A one-time annual fee varies with deployment requirements, service levels and custom work, and usage-based credits continue on top. Dreadnode publishes both structures openly, which fits a self-serve-first stance.
Dreadnode ships the platform both as managed software and as software the customer runs. The Pro plan is fully managed, the Enterprise plan supports on-premises deployment with the customer controlling its own data, and the documentation covers installing the platform on the customer's own Kubernetes cluster.
Dreadnode concentrates operational control in the managed sandbox. Segmented, scalable compute runs agents with guardrails built in, hosted evaluations absorb the rate limits, timeouts and monitoring that agent testing otherwise imposes, and tracing records every tool and model call so a team can reconstruct what an agent did.
The release feed shows an operating cadence. Seven consecutive weekly entries, dated July 2 to August 13 on the feed, cover a Claude Code engine, end-to-end multimodal red teaming, an agent memory and session-monitoring overhaul, a traditional-machine-learning red-teaming suite, and a versioned registry for structured agent output.
Dreadnode's readiness shows most in how it handles the customer's data. The Enterprise plan offers on-premises deployment, the documentation covers self-hosting on the customer's own Kubernetes cluster, and the pricing page states that customer data is never used for training and that evaluation, training, Worlds and AI red teaming data stays inside the customer's environment.
The company publishes a trust center on a Vanta-hosted subdomain. It lists controls across infrastructure, organizational, product, internal-procedure and data-privacy categories, names Amazon Web Services, Cloudflare, Google Workspace and Vanta as subprocessors, lists one resource, an engagement letter, and carries a request-access control.
No completed attestation appears in the reviewed sources. The rendered trust center lists no SOC 2 or ISO 27001 report, the probed homepage, about and pricing pages carry no attestation wording, and the published sitemap lists no compliance page. For an enterprise motion that includes on-premises deployment, a buyer would still ask for an audit report before purchase.
Dreadnode frames the product as infrastructure other security work runs on. The 2.0 release positions it as a platform for security agents rather than a point tool, with a resource hub where teams publish and version capabilities privately or share them with a community.
Part of the ecosystem is deliberately open. The company publishes a lightweight framework for interacting with language models, and example agents, on GitHub and released DreadGOAD and Ares, an Active Directory environment and a red-versus-blue agent system that other teams can run against their own agents.
The platform frame also widens the field of rivals. Sitting between closed single-purpose agents and general agent tooling means the tooling a developer already uses competes for the same build-and-deploy work, and no reviewed source shows a community large enough to hold the platform in place.
Dreadnode's about page lists Brad Palm as chief executive, with Will Pearce as co-founder and Nick Landers as co-founder and chief technology officer. The March 2026 launch release quoted Pearce as CEO and co-founder, so the chief-executive title moved after that announcement.
The founders' backgrounds are corroborated by press. SecurityWeek describes Pearce as the former lead of NVIDIA's AI red team and Landers as a former VP of Research at NetSPI.
The wider bench publishes under its own name. Company researchers wrote the AIRTBench benchmark paper and the Crucible attack-data analysis, introduced the DreadIndex model index, had an accepted Black Hat USA briefing on the August 6 program, which a Dark Reading article describes, and announced an AI Village presentation of an agent-failure-modes paper co-authored with a Google DeepMind researcher. Dreadnode states the team draws on operators from NVIDIA, Microsoft, NetSPI, Meta, Cohere and Run Sybil.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Dreadnode: Dreadnode Launches 2.0 announcement, March 24, 2026 | official | 2026-08-23 |
| f2 | Dreadnode: Series A announcement, February 25, 2025 | official | 2026-08-23 |
| f3 | SecurityWeek: Offensive AI Startup Dreadnode Secures $14M to Stress-Test AI Systems | press | 2026-08-23 |
| f4 | FinTech Global: Dreadnode captures $14m to fortify offensive AI security capabilities | press | 2026-08-23 |
| f5 | Dreadnode Documentation: AI Red Teaming overview | official | 2026-08-23 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Dreadnode: homepage and platform overview “Build, evaluate, and deploy security agents with confidence.” | official | 2026-08-23 |
| s2 | Dreadnode Documentation: documentation index and release-note feed “Terminal-native platform for building, evaluating, and deploying offensive security agents.” | official | 2026-08-23 |
| s3 | Dreadnode: Dreadnode Launches 2.0 announcement, March 24, 2026 “Dreadnode, the infrastructure platform for the security stack, today announced general availability of Dreadnode 2.0.” | official | 2026-08-23 |
| s4 | Dreadnode: About page “Will Pearce Co-Founder Nick Landers Co-Founder & CTO Brad Palm CEO Brian Greunke Head of Engineering” | official | 2026-08-23 |
| s5 | Dreadnode: Pricing page with plan terms and credit definition “Pro Pay-as-you-go For builders, practitioners, and teams.” | official | 2026-08-23 |
| s6 | Dreadnode Documentation: AI Red Teaming overview “AI Red Teaming helps you systematically probe for security, safety, and trust risks in foundation models, agentic systems, AI applications, and traditional ML models - wherever they are deployed.” | official | 2026-08-23 |
| s7 | Dreadnode: Black Hat, DEF CON and AI Security Forum plans, July 9, 2026 “A benchmark of 4,897 tool calls, labeled call-by-call by professional penetration testers, testing whether an inexpensive, trusted judge can stop an autonomous agent before it acts out of scope.” | official | 2026-08-23 |
| s8 | Dreadnode: Introducing DreadIndex, July 16, 2026 “We're releasing DreadIndex, an offensive cybersecurity evaluation index for language models. It's a composite of public and private evaluation tasks” | official | 2026-08-23 |
| s9 | Dreadnode: Mine the Gap, open-source offense-defense measurement tools “Today we're releasing two open-source projects:” | official | 2026-08-23 |
| s10 | Dark Reading: Red Agents vs. Blue Agents, How to Make AI Better at Defense “Earlier this year, Dreadnode, an AI offensive security startup, released two open source tools designed to help users evaluate the security agents deployed in their networks.” | press | 2026-08-23 |
| s11 | SecurityWeek: Offensive AI Startup Dreadnode Secures $14M to Stress-Test AI Systems “Dreadnode, an early stage startup specializing in offensive AI security, has raised $14 million in a funding round from an investment group that includes Decibel, Next Frontier Capital, In-Q-Tel (IQT), Sands Capital, and Indie VC.” | press | 2026-08-23 |
| s12 | FinTech Global: Dreadnode captures $14m to fortify offensive AI security capabilities “The company, co-founded by former NVIDIA AI red-team lead Will Pearce and ex-NetSPI VP of Research Nick Landers, positions itself at the forefront of offensive machine learning.” | press | 2026-08-23 |
| s13 | CyberMaterial: Dreadnode Secures $14M to Tackle AI Security “Dreadnode, an early-stage startup specializing in offensive AI security, recently secured $14 million in Series A funding.” | press | 2026-08-23 |
| s14 | arXiv: AIRTBench, Measuring Autonomous AI Red Teaming Capabilities in Language Models “The benchmark consists of 70 realistic black-box capture-the-flag (CTF) challenges from the Crucible challenge environment on the Dreadnode platform, requiring models to write python code to interact with and compromise AI systems.” | research | 2026-08-23 |
| s15 | arXiv: The Automation Advantage in AI Red Teaming “This paper analyzes Large Language Model (LLM) security vulnerabilities based on data from Crucible, encompassing 214,271 attack attempts by 1,674 users across 30 LLM challenges.” | research | 2026-08-23 |
| s16 | Dreadnode: Vanta-hosted trust centre “Dreadnode builds AI-powered platforms for offensive security operations.” | official | 2026-08-23 |
| s17 | Dreadnode probe, 2026-08-23: DNS subdomains with a random control, six site paths, and the 42-URL published sitemap “DNS trust.dreadnode.io: trust.dreadnode.io is an alias for 693bda3eb8e956cfe79b04ad.cname.vantatrust.com.” | official | 2026-08-23 |
| s18 | Dreadnode: GitHub organisation page “rigging Public Lightweight LLM Interaction Framework Python 418 32” | official | 2026-08-23 |
| s20 | Dreadnode: Offensive AI Con announcement, March 19, 2025 “Event March 19, 2025 Offensive AI Con Announced: First Conference Dedicated to the Use of AI in Offensive Security” | official | 2026-08-23 |
| s21 | Dreadnode: Series A announcement, February 25, 2025 “Dreadnode was founded in 2023 by Will Pearce, who built the AI red teams at Microsoft and NVIDIA, and Nick Landers, an accomplished offensive security engineer, VP of Research, and author of the Dark Side Ops penetration testing and adversary simulation trainings.” | official | 2026-08-23 |
| s19 | Dreadnode Documentation: Quickstart “Install the CLI, install the web-security capability, point it at a target you're authorized to test, and let the agent work until it produces a report. About fifteen minutes end-to-end.” | official | 2026-08-23 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Dreadnode: homepage and platform overview “Build, evaluate, and deploy security agents with confidence.” | official | 2026-08-23 |
| s2 | Dreadnode Documentation: documentation index and release-note feed “Terminal-native platform for building, evaluating, and deploying offensive security agents.” | official | 2026-08-23 |
| s3 | Dreadnode: Dreadnode Launches 2.0 announcement, March 24, 2026 “Dreadnode, the infrastructure platform for the security stack, today announced general availability of Dreadnode 2.0.” | official | 2026-08-23 |
| s4 | Dreadnode: About page “Will Pearce Co-Founder Nick Landers Co-Founder & CTO Brad Palm CEO Brian Greunke Head of Engineering” | official | 2026-08-23 |
| s5 | Dreadnode: Pricing page with plan terms and credit definition “Pro Pay-as-you-go For builders, practitioners, and teams.” | official | 2026-08-23 |
| s6 | Dreadnode Documentation: AI Red Teaming overview “AI Red Teaming helps you systematically probe for security, safety, and trust risks in foundation models, agentic systems, AI applications, and traditional ML models - wherever they are deployed.” | official | 2026-08-23 |
| s7 | Dreadnode: Black Hat, DEF CON and AI Security Forum plans, July 9, 2026 “A benchmark of 4,897 tool calls, labeled call-by-call by professional penetration testers, testing whether an inexpensive, trusted judge can stop an autonomous agent before it acts out of scope.” | official | 2026-08-23 |
| s8 | Dreadnode: Introducing DreadIndex, July 16, 2026 “We're releasing DreadIndex, an offensive cybersecurity evaluation index for language models. It's a composite of public and private evaluation tasks” | official | 2026-08-23 |
| s9 | Dreadnode: Mine the Gap, open-source offense-defense measurement tools “Today we're releasing two open-source projects:” | official | 2026-08-23 |
| s10 | Dark Reading: Red Agents vs. Blue Agents, How to Make AI Better at Defense “Earlier this year, Dreadnode, an AI offensive security startup, released two open source tools designed to help users evaluate the security agents deployed in their networks.” | press | 2026-08-23 |
| s11 | SecurityWeek: Offensive AI Startup Dreadnode Secures $14M to Stress-Test AI Systems “Dreadnode, an early stage startup specializing in offensive AI security, has raised $14 million in a funding round from an investment group that includes Decibel, Next Frontier Capital, In-Q-Tel (IQT), Sands Capital, and Indie VC.” | press | 2026-08-23 |
| s12 | FinTech Global: Dreadnode captures $14m to fortify offensive AI security capabilities “The company, co-founded by former NVIDIA AI red-team lead Will Pearce and ex-NetSPI VP of Research Nick Landers, positions itself at the forefront of offensive machine learning.” | press | 2026-08-23 |
| s13 | CyberMaterial: Dreadnode Secures $14M to Tackle AI Security “Dreadnode, an early-stage startup specializing in offensive AI security, recently secured $14 million in Series A funding.” | press | 2026-08-23 |
| s14 | arXiv: AIRTBench, Measuring Autonomous AI Red Teaming Capabilities in Language Models “The benchmark consists of 70 realistic black-box capture-the-flag (CTF) challenges from the Crucible challenge environment on the Dreadnode platform, requiring models to write python code to interact with and compromise AI systems.” | research | 2026-08-23 |
| s15 | arXiv: The Automation Advantage in AI Red Teaming “This paper analyzes Large Language Model (LLM) security vulnerabilities based on data from Crucible, encompassing 214,271 attack attempts by 1,674 users across 30 LLM challenges.” | research | 2026-08-23 |
| s16 | Dreadnode: Vanta-hosted trust centre “Dreadnode builds AI-powered platforms for offensive security operations.” | official | 2026-08-23 |
| s17 | Dreadnode probe, 2026-08-23: DNS subdomains with a random control, six site paths, and the 42-URL published sitemap “DNS trust.dreadnode.io: trust.dreadnode.io is an alias for 693bda3eb8e956cfe79b04ad.cname.vantatrust.com.” | official | 2026-08-23 |
| s18 | Dreadnode: GitHub organisation page “rigging Public Lightweight LLM Interaction Framework Python 418 32” | official | 2026-08-23 |
| s20 | Dreadnode: Offensive AI Con announcement, March 19, 2025 “Event March 19, 2025 Offensive AI Con Announced: First Conference Dedicated to the Use of AI in Offensive Security” | official | 2026-08-23 |
| s21 | Dreadnode: Series A announcement, February 25, 2025 “Dreadnode was founded in 2023 by Will Pearce, who built the AI red teams at Microsoft and NVIDIA, and Nick Landers, an accomplished offensive security engineer, VP of Research, and author of the Dark Side Ops penetration testing and adversary simulation trainings.” | official | 2026-08-23 |
| s19 | Dreadnode Documentation: Quickstart “Install the CLI, install the web-security capability, point it at a target you're authorized to test, and let the agent work until it produces a report. About fifteen minutes end-to-end.” | official | 2026-08-23 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.