All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Gray Swan's closest counterparties are also its likeliest competitors. Forbes reports partnerships and contracts with OpenAI, Anthropic, and the UK AI Safety Institute, and the frontier labs among them could ship a runtime guardrail of their own, the enterprise business Gray Swan now sells. The engine behind the products is a crowdsourced network of more than 15,000 red teamers generating over a million real-world attack trajectories that train both the guardrail and the attack tool. The catch is demand the buyer can verify. The company reports over 20 customers and a data-platform integration, but the reviewed record shows no named end-customer deployment, so the visible proof is research standing rather than named deployments.
| Description | Gray Swan's Cygnal is a runtime guardrail that sits inline between users, models, agents, and their tools, classifying adversarial inputs and unsafe outputs in real time for enterprise AI applications in production. | [f1] |
|---|---|---|
| Founded | 2023 | [f2] |
| HQ | Pittsburgh, Pennsylvania, USA | [f2] |
| Latest funding | Series A, USD 40M (May 2026), co-led by Wing Venture Capital and Madrona | [f2] |
| Deployment | Hybrid, SaaS, Self-hosted | [f3] |
| Compliance | Cyber Essentials, SOC 2 Type 2 | [f3] |
| Product | What it does |
|---|---|
| Gray Swan Cygnal | Gray Swan Cygnal: Inline runtime guardrail that screens prompts, model responses, and agent tool calls, blocking prompt injection, jailbreaks, and unsafe outputs against custom policies. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Gray Swan Cygnal is an inline runtime guardrail that screens prompts, model responses, and agent tool calls, blocking prompt injection, jailbreaks, and unsafe outputs against custom policies. It is mapped to the AI Defense Matrix. [f4]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score |
|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 4/5 |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs, demos, and third-party validation. | 4/5 |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 5/5 |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 4/5 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
| Dimension | Score |
|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 2/3 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Gray Swan: Cygnal - Runtime Monitoring and Protection | official | 2026-07-09 |
| f2 | Technical.ly on Gray Swan, founded 2023 | press | 2026-06-13 |
| f3 | AI Defense Matrix Catalog entry | other | 2026-06-13 |
| f4 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Gray Swan AI homepage | official | 2026-06-13 |
| s2 | Gray Swan Cygnal product page “Cygnal sits inline: between users and your model, between your agent and the tools it calls, between your retrieval pipeline and the content it returns. It classifies adversarial inputs and unsafe outputs in real time” | official | 2026-06-13 |
| s3 | Gray Swan AI about page with leadership and Arena scale “Our Arena, the world's largest adversarial AI red teaming network, powers everything we do with threat intelligence from over 15,000 red teamers discovering novel vulnerabilties daily.” | official | 2026-06-18 |
| s4 | Gray Swan Cygnal API documentation “If Cygnal detected any violations, it will cut the model's responses and return a refusal message such as `Sorry, I can't help with that.` and mark the `finish_reason` as `violation`” | official | 2026-06-13 |
| s5 | Gray Swan Shade adversarial red-teaming page “Shade is different. LLM-powered adversarial agent, powered by attack data from the largest network of AI red teamers breaking frontier models around the clock, running attack campaigns against your model, your guardrails, and your actual deployment context.” | official | 2026-06-13 |
| s6 | Gray Swan Series A announcement “Gray Swan already works with over 20 customers across frontier labs and global enterprises, and has established partnerships with technology platforms, including Snowflake.” | official | 2026-06-13 |
| s7 | Forbes on Gray Swan AI red teaming for frontier labs “More than 600 hackers convened last month to compete in a "jailbreaking arena" ... It's gotten early traction, securing notable partnerships and contracts with OpenAI, Anthropic and the United Kingdom's AI Safety Institute.” | press | 2026-06-18 |
| s8 | Technical.ly on Gray Swan $40M Series A, Pittsburgh, founded 2023 “Gray Swan, a Pittsburgh-based AI security startup, announced today the close of a $40 million Series A. ... Founded in 2023, Gray Swan's platform has three components. ... It previously raised $5 million of early-stage capital in 2024 and another $5 million in 2025.” | press | 2026-06-13 |
| s9 | FinTech Global on Gray Swan system-card citations and attack trajectories “having been cited in 11 recent frontier model system cards, including those published by Anthropic, OpenAI, and Meta ... The platform generates more than one million real-world attack trajectories, which are used to train the models underpinning both Cygnal and Shade.” | press | 2026-06-18 |
| s10 | Gray Swan research page on its 2023 automated jailbreaking method “In July 2023, we published the first-ever automated jailbreaking method on large language models (LLMs) and exposed their susceptibility to adversarial attacks.” | official | 2026-06-13 |
| s11 | Gray Swan AI Trust Center (SOC 2 Type 2, Cyber Essentials) “Compliance: Cyber Essentials, SOC 2 Type 2” | official | 2026-06-16 |
| s12 | arXiv: Improving Alignment and Robustness with Circuit Breakers, co-authored by Gray Swan co-founders Matt Fredrikson, Zico Kolter, and Andy Zou “AI systems can take harmful actions and are highly vulnerable to adversarial attacks. We present an approach, inspired by recent advances in representation engineering, that interrupts the models as they respond with harmful outputs with "circuit breakers."” | research | 2026-06-30 |
| s13 | SEC Form D for Gray Swan Security Inc., a Delaware corporation based in Pittsburgh, 2024 filing (CIK 0002015570) “Gray Swan Security Inc.” | regulatory | 2026-06-30 |
| s14 | CB Insights company profile for Gray Swan Security “Gray Swan Security is a technology company that operates in stealth mode. The company was founded in 2023 and is based in Pittsburgh, Pennsylvania.” | other | 2026-06-30 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Gray Swan Cygnal runtime protection page “Cygnal sits inline: between users and your model, between your agent and the tools it calls, between your retrieval pipeline and the content it returns. It classifies adversarial inputs and unsafe outputs in real time” | official | 2026-06-15 |
| s2 | Gray Swan Shade adversarial red-teaming page “Shade is different. LLM-powered adversarial agent, powered by attack data from the largest network of AI red teamers breaking frontier models around the clock, running attack campaigns against your model, your guardrails, and your actual deployment context.” | official | 2026-06-15 |
| s3 | Gray Swan about page with Arena scale and research record “Our Arena, the world's largest adversarial AI red teaming network, powers everything we do with threat intelligence from over 15,000 red teamers discovering novel vulnerabilties daily.” | official | 2026-06-18 |
| s4 | Gray Swan Cygnal API documentation “If Cygnal detected any violations, it will cut the model's responses and return a refusal message such as `Sorry, I can't help with that.` and mark the `finish_reason` as `violation`” | official | 2026-06-15 |
| s5 | Gray Swan Series A announcement “Gray Swan already works with over 20 customers across frontier labs and global enterprises, and has established partnerships with technology platforms, including Snowflake.” | official | 2026-06-18 |
| s6 | FinTech Global on Gray Swan attack trajectories and three components “The platform generates more than one million real-world attack trajectories, which are used to train the models underpinning both Cygnal and Shade.” | press | 2026-06-15 |
| s7 | Technical.ly on Gray Swan USD 40M Series A and Pittsburgh roots “Gray Swan, a Pittsburgh-based AI security startup, announced today the close of a $40 million Series A.” | press | 2026-06-15 |
| s8 | Forbes: This Hacker Team Is Bulletproofing AI Models For Companies Like OpenAI And Anthropic “It's gotten early traction, securing notable partnerships and contracts with OpenAI, Anthropic and the United Kingdom's AI Safety Institute.” | press | 2026-06-18 |
| s9 | Gray Swan research on its 2023 automated jailbreaking method “In July 2023, we published the first-ever automated jailbreaking method on large language models (LLMs) and exposed their susceptibility to adversarial attacks.” | official | 2026-06-15 |
| s10 | Gray Swan AI Trust Center (SOC 2 Type 2, Cyber Essentials) “Compliance: Cyber Essentials, SOC 2 Type 2” | official | 2026-06-18 |
| s11 | Gray Swan Cygnal API documentation (free tier limits) “The free tier has 200,000 tokens/minute and 10,000,000 tokens/day limits; if you reach quota, Cygnal will still proxy your request to the provider, just without filtering.” | official | 2026-07-14 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Do not republish its content or share access without the operator's permission.