All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Helmet Security's efficiency story is also its competitive exposure. Its product finds the Model Context Protocol (MCP) servers and agents running in an enterprise, the connections AI agents use to reach company systems, vets them in a registry, and enforces policy through a gateway, and co-founder Kaushik Shanadi built that platform in a couple of months using AI tools. A funded rival with the same tooling could match that pace. SYN Ventures and WhiteRabbit Ventures led a 9 million dollar seed round. CEO Fred Kneip previously founded and sold the cyber-risk firm CyberGRX. Its roughly ten reported customers are unnamed. Helmet has scheduled its SOC 2 audit for Summer 2026. The lasting asset, if one forms, is the registry and policy layer customers wire into audits, not the build speed.
| Description | Helmet Security is an agentic AI security platform that discovers the MCP servers, agents, skills, and plugins running in an enterprise, monitors their traffic, and enforces policy through agent hooks and an MCP gateway with an audit trail. | [f1] |
|---|---|---|
| Founded | 2025 | [f2] |
| HQ | Washington, D.C. | [f3] |
| Funding | $9M total | [f2] |
| Latest funding | Seed (announced December 2025), led by SYN Ventures and WhiteRabbit Ventures | [f2] |
| Product | What it does |
|---|---|
| Helmet | Discovers agents and MCP servers through existing security tools, maintains a verified registry with code scanning, and enforces policy via agent hooks and an MCP gateway. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Helmet inventories the agents, MCP servers, skills, and plugins running in an enterprise, enforces policy on them through agent hooks and an MCP gateway, monitors their traffic, and blocks prompt injection and data leakage in real time. These capabilities are mapped to the AI Defense Matrix. [f4]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | The buyer is the enterprise security team and the problem is stated concretely, agents reaching company systems over MCP connections that existing tools do not monitor (s7, s8). The pain is argued by the vendor and restated in press coverage of its launch, with no independent quantification in the reviewed sources. [s7, s8, s9] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | The platform page details concrete architecture, discovery from EDR, IdP, network, and SaaS signals, a verified registry with secret scanning, SAST and DAST, and a gateway deployable hosted, self-hosted, or into AWS Bedrock and Azure APIM (s1, s2). No external validation point exists: no public docs portal or demo, zero public repositories (s10), and access gated behind an early-access form (s1). [s1, s2, s10] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | The enabler is the Model Context Protocol, the Anthropic-created standard whose enterprise spread through 2025 produced agent connections older tools cannot see, and Helmet's December 2025 stealth exit dates its bet on that window (s6, s8). Buyer-side demand in the reviewed record is indirect: customer counts are founder-stated and no analyst or survey source corroborates budget movement (s9). [s6, s8, s9] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | CEO Fred Kneip founded CyberGRX, which raised 100 million dollars and was acquired by Marlin Equity Partners / ProcessUnity, a verifiable prior build and exit in security (s7). CTO Kaushik Shanadi's engineering background is self-described on the vendor's own pages rather than independently corroborated (s4, s5). [s7, s4, s5] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 2/5 | At the December 2025 stealth exit Kneip reported about 10 customers with 30 more onboarding, a mix of commercial firms and government agencies, and declined to name any. Backing from SYN Ventures and WhiteRabbit Ventures is an indirect signal that lifts the read toward, but not to, the named-reference bar (s7). [s9, s7] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | The 9 million dollar seed is proportional to a seed-stage enterprise motion, and shipping is visible, a platform built and launched within the founding year by a three-person team (s7, s9). No revenue or margin is disclosed, so efficiency itself is unconfirmed, the honest default for a funded private startup. [s7, s9] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 | Agentic AI security is a recognizable but nascent category, and Kneip himself says the market is saturated with tools that each cover one aspect, so placement still needs vendor explanation (s9). No analyst category note or independent placement appears in the reviewed sources. [s9, s8] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 2/5 | Helmet's discovery reads signals from security tools other vendors own, and its enforcement pushes policy into AWS Bedrock and Azure APIM, gateways whose operators could ship MCP governance natively (s1, s2). With no named production embedding yet, the capability is a plausible quarterly feature for an adjacent platform vendor. [s1, s2, s9] |
Enterprises are wiring AI agents into their software faster than security teams can see it, and Helmet Security sells the missing visibility and control. The Model Context Protocol, an open standard created by Anthropic, lets AI tools read data and take actions inside company systems. Helmet's pitch is that these connections multiply outside security's view, and its platform finds them, watches them, and polices them (s7, s8).
The pain is vendor-argued rather than independently measured. Kneip frames the problem as a practitioner's fear, not knowing what is running, and press coverage of the launch repeats that framing (s9). No analyst report, survey, or incident study in the reviewed sources quantifies how much unmonitored MCP traffic enterprises actually carry.
The buyer is clear even where the numbers are not. Helmet addresses the security chief who must approve agent deployments, and it courts the developers who build them with a promise of speed kept, an adoption argument Kneip makes explicitly (s9). [s7, s8, s9]
Helmet covers the lifecycle of an enterprise's agent connections in three phases. Discovery is agentless, reading signals from the EDR, identity, network, and SaaS tools a company already runs, with an optional endpoint agent for deeper coverage (s2). A verified registry imports MCP servers from GitHub or OpenAPI specs and scans them, including secret scanning and static and dynamic analysis, to catch drift and swapped behavior before it ships (s2). Enforcement runs through native agent hooks and an MCP gateway offered hosted, self-hosted, or pushed into AWS Bedrock and Azure APIM, with real-time blocking of prompt injection and data leakage and an audit trail mapped to SOC 2, ISO 27001, and the OWASP AI Top 10 (s1).
The depth of these claims rests entirely on the vendor's marketing pages. Helmet publishes no documentation portal, no demo, and no open code, its GitHub organization holds zero public repositories, and the product sits behind an early-access contact form (s1, s10). The company's own origin story is candid about the pace: the platform grew out of a scanner side project, and the CTO assembled it in a couple of months using AI tooling (s5, s9). [s1, s2, s5, s9, s10]
Helmet positions breadth against a field of narrower tools. Kneip acknowledges the AI-security market is saturated and argues most rivals cover one slice, permissions here, guardrails there, while Helmet spans discovery, vetting, and enforcement in one platform (s9, s5). Its investor makes the adoption-cost argument: an immediate, installation-free view into where MCP is operating, because discovery rides tools the customer already owns (s8).
The same design choices mark the absorption risk. Discovery depends on other vendors' security products for its signals, and enforcement can run inside AWS Bedrock and Azure APIM, gateways whose operators could ship MCP governance as a native feature (s1, s2). Helmet is a late-2025 entrant differentiating on claimed lifecycle breadth in a market its own founder describes as saturated (s9). [s9, s5, s8, s1, s2]
Traction is early, real by the founder's account, and entirely unnamed. At the December 2025 stealth exit Kneip reported about 10 customers with 30 more onboarding, a mix of commercial firms and government agencies, and declined to name any (s9). The product is sold through an early-access contact form with no published pricing (s1).
The distribution levers are relationships rather than channels. Helmet's investors, SYN Ventures and WhiteRabbit Ventures, connect the company to prospective customers, and its Agentic AI Foundation membership places it inside the Linux Foundation body that stewards the protocols it secures (s9, s6). The funding round exists partly to build the go-to-market: the raise expands the team from 3 to 10 people, with customer management among the early hires (s9). [s9, s1, s6, s7]
The team's credibility concentrates in one verifiable record. CEO Fred Kneip founded CyberGRX, raised 100 million dollars for it, and sold it to Marlin Equity Partners / ProcessUnity, a prior build and exit in the cyber-risk market Helmet now sells governance into (s7). The vendor's own pages describe him as a former CISO and GRC founder (s4).
CTO Kaushik Shanadi is the product's creator, and his background is self-described rather than independently documented. The founder story presents him as a security engineer with startup and enterprise experience who built Helmet from a side project (s4, s5). The company runs deliberately small, three people expanding to ten, with AI tooling standing in for early hires (s9). [s7, s4, s5, s9]
Helmet holds no completed security attestation. Its security page states a SOC 2 Type II audit is scheduled for Summer 2026 and a Vanta-powered trust center is coming, and a probe on July 3, 2026 found no trust or security subdomain and no attestation badges in the site footer (s3). The page describes standard practices, encryption in transit and at rest, role-based access with SSO and multi-factor authentication, code review and dependency scanning, and a responsible-disclosure contact (s3).
The gap is sharper for this vendor than for most young companies. Helmet sells audit-ready evidence of agent activity mapped to SOC 2 and ISO 27001 while its own audit is months away (s1, s3). Enterprise and government buyers, the mix Kneip says Helmet already serves, typically ask for the vendor's own report early in procurement (s9). [s3, s1, s9]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Runlayer | competes with | MCP security gateway that vets servers and skills, screens each tool call, and ties agent access to enterprise single sign-on, with named enterprise customers. | |
| Natoma | competes with | Governed MCP gateway treating AI agents as non-human identities, with identity-aware authorization and shadow-AI discovery. | |
| MintMCP | competes with | Hosted enterprise MCP gateway adding SSO, role-based access control, and audit trails over agent tool calls. | |
| Archestra | competes with | Open-source enterprise MCP platform running servers behind a governed gateway with deterministic guardrails. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
Add analyzed competitors to compare them side by side with Helmet Security.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
pivot urgently
What Helmet built fast, a rival can build fast. By the company's own account, one engineer assembled the platform in a couple of months with AI tooling. The public record shows no proprietary dataset, completed certification, or install base that would slow a copy. A gateway that enforces policy on agent traffic, with an audit trail wired into compliance reporting, would take real work to remove. Reported customers numbered about ten in December 2025, all unnamed. Security buyers know Fred Kneip from CyberGRX, the cyber-risk firm he founded and sold, and that recognition is an advantage a new team cannot quickly match. Until Helmet names customers and completes the SOC 2 audit scheduled for Summer 2026, it competes on speed and founder recognition, and rivals can contest both.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Helmet delivers software the customer adopts and configures, a discovery, registry, and gateway platform, and buyers pay for those features, the software-product level with no judgment or accountability layer sold on top. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | A deployed gateway with accumulated policies, a vetted registry, and audit feeds into SIEM and compliance reporting is real effort to unwind, but with roughly ten unnamed early customers no multi-year embedding exists, so the friction is effort rather than lock-in. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | Helmet holds no completed attestation, its SOC 2 Type II audit is scheduled for Summer 2026, and no regulation mandates the product, so compliance neither blocks rivals nor yet gives Helmet an edge. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 2/3 | The platform is integration work across security signals, code scanning, and gateway enforcement, and the company's own account says the CTO built it in a couple of months with AI tooling, which places it at non-trivial integration depth rather than the years-of-specialized-expertise level peers evidence with inspectable engineering. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | Helmet reports commercial firms and government agencies among its roughly ten customers, a procurement-gated profile if proven, but every deployment is unnamed, so the evidenced buyer sits at the mid-market-with-governance level rather than the demonstrated regulated-enterprise level. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | The gateway sits in the path of agent traffic when deployed and policy can embed into AWS Bedrock and Azure APIM, but the agentless discovery mode observes from existing tools rather than carrying traffic, and no evidence shows Helmet hosting infrastructure customers depend on. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | No named non-public dataset feeds the product, the registry vets servers the customer brings, and audit logs land in the customer's own systems, so a funded rival starting from scratch could reach parity, as Helmet's own build pace suggests. |
Helmet sells to the enterprise security organization, with the developer as the constituency it must not slow down. Kneip names the security practitioner's fear, not knowing what is running, as the problem, and frames the product as a way to give developers guardrails without taking away speed (s9, s7). The reported customer base is a mix of commercial firms and government agencies, which suggests a segment defined by agent adoption rather than by industry (s9).
The segment is early by construction. Buyers must already run AI agents over MCP connections at enough scale to need discovery and policy, a population that began forming only after the protocol spread through enterprises. Helmet's bet is that this population grows into a standard budget line before incumbents claim it.
Helmet's differentiating claim is lifecycle breadth, not a smarter model. The platform spans discovery of agents and MCP servers through signals from EDR, identity, network, and SaaS tools, a verified registry that imports and scans server code, and runtime enforcement through agent hooks and a gateway (s2, s1). The founder story is explicit that breadth is the thesis: Shanadi began with a scanner and decided to manage the whole lifecycle instead (s5).
The claims lack an external validation point. Helmet publishes no documentation portal or demo, its GitHub organization holds zero public repositories, and no third-party technical evaluation of the product appears in the reviewed sources (s10). The engineering is also, by the company's own account, quick to produce: the platform came together in a couple of months of AI-assisted work (s9). What a buyer can verify today is the vendor's description, not the depth beneath it.
Helmet sells founder-led and relationship-driven. Kneip fronts the company's public selling, the product sits behind an early-access contact form, and the investors, SYN Ventures and WhiteRabbit Ventures, open doors to prospective customers (s9, s1). That motion matches the stage: at the December 2025 raise, about 10 customers with 30 more onboarding, all unnamed, and a hiring plan that adds customer management next (s9).
The proof gap is the missing named reference. A mix of commercial and government customers is a claim a buyer cannot check, and in a category where rivals already name enterprise logos, the anonymous roster is what a shortlist would probe. The Agentic AI Foundation membership adds standards-body visibility rather than customer proof (s6).
Helmet publishes no pricing. Access runs through a contact form for early access, the pattern of negotiated, sales-led deals, and no pricing unit, seat, server, or traffic volume, appears anywhere in the reviewed sources (s1).
The unpriced posture fits a product still finding its packaging. With deployment options spanning a managed cloud, self-hosted proxies, and policy pushed into AWS Bedrock and Azure APIM, the value metric could reasonably attach to servers governed, actions enforced, or seats, and the company has published nothing that commits it to any of them (s2).
Delivery flexes across three models. Buyers can take the gateway as a managed service in Helmet Cloud, run it themselves in their own VPC or as a local endpoint proxy so data never leaves their environment, or push policy into gateways they already operate, AWS Bedrock and Azure APIM among them (s2). Discovery is agentless, riding the customer's existing security stack, with an optional endpoint agent for deeper coverage (s2).
Operations are deliberately thin. Three people run the company, AI tooling substitutes for early hires in engineering and back-office work, and the funding round exists partly to grow the team to ten (s9). That leanness keeps burn low, and it also means enterprise and government customers are being served by a very small operations bench.
Helmet's own trust posture trails what it sells. The product promises audit-ready evidence mapped to SOC 2, ISO 27001, and the OWASP AI Top 10, while the company's security page states its SOC 2 Type II audit is scheduled for Summer 2026 and its Vanta trust center is still being built (s1, s3). A probe on July 3, 2026 found no trust or security subdomain and no attestation badges in the site footer, so no completed attestation was found in the public record as of that date (s3).
The interim posture is described practices plus disclosure. The security page commits to encryption in transit and at rest, role-based access with SSO and multi-factor authentication, code review and dependency scanning, and a responsible-disclosure contact at a security mailbox (s3). For the government-inclusive customer mix Kneip describes, the completed report will matter earlier than for most seed-stage vendors (s9).
Helmet positions itself inside other vendors' surfaces rather than beside them. Discovery consumes signals from EDR, identity, network, and SaaS products the customer already owns, enforcement can live inside AWS Bedrock and Azure APIM, and findings export to the customer's SIEM (s2, s1). The investor pitch makes this the differentiator: an installation-free view of MCP activity (s8).
The company also bought a seat in the standards body. Helmet joined the Agentic AI Foundation, the Linux Foundation home that stewards MCP and related agent protocols, as a Silver Member in March 2026 (s6). The dependency cuts both ways: the platforms Helmet embeds into, and the foundation governing the protocol it polices, could each absorb parts of its role.
The team is two founders with one verifiable track record between them. Fred Kneip founded CyberGRX, raised 100 million dollars, and sold it to Marlin Equity Partners / ProcessUnity, and Helmet's pages describe him as a former CISO and GRC founder (s7, s4). Kaushik Shanadi, the CTO, created the product, and his security-engineering background is self-described rather than independently documented (s4, s5).
Beyond the founders, the bench is aspiration. The company is three people expanding to ten, positions itself as a team of security engineers and GRC experts, and relies on AI tooling in place of early hires (s9, s4).
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Helmet Security homepage: The Agentic AI Security Platform | official | 2026-07-03 |
| f2 | Technical.ly: DC startup Helmet Security raises $9M to secure agentic AI (startup profile) | press | 2026-07-03 |
| f3 | SecurityWeek: Helmet Security Emerges From Stealth Mode With $9 Million in Funding | press | 2026-07-03 |
| f4 | Helmet Security: How Helmet works (platform page) | official | 2026-07-03 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Helmet Security homepage (early-access contact form; blocks prompt injection & data leakage; SOC 2, ISO 27001, OWASP AI Top 10) “Enforce policy in real time, through native agent hooks and the Helmet MCP gateway: hosted by us, self-hosted, or orchestrated into AWS Bedrock, Azure APIM, and more.” | official | 2026-07-03 |
| s2 | Helmet Security: How Helmet works (signals in: EDR, IdP, network, SaaS; verified registry; secret scanning, SAST & DAST; drift and rug pulls; SIEM export) “Agentless discovery through your existing security stack. Our endpoint agent is optional, for deeper coverage.” | official | 2026-07-03 |
| s3 | Helmet Security: Security & Trust (probe 2026-07-03: no trust or security subdomain resolves, no badge images in homepage footer HTML) “Our first SOC 2 Type II audit is scheduled for Summer 2026, and we are building our public Trust Center, powered by Vanta, to give customers transparent access to our security documentation and reports.” | official | 2026-07-03 |
| s4 | Helmet Security: About, The team (Fred Kneip co-founder and CEO; Kaushik Shanadi co-founder and CTO, creator of Helmet) “Former CISO and GRC founder. Brings deep expertise in enterprise risk, governance, and building trust in emerging technologies.” | official | 2026-07-03 |
| s5 | Helmet Security blog: Introducing Helmet Security, How We Started (Kaushik Shanadi, November 10, 2025; began as an MCP server-code scanner) “I didn’t want to build just a scanner. I wanted to architect something that would manage the whole lifecycle.” | official | 2026-07-03 |
| s6 | Helmet Security blog: Helmet Security Joins the Agentic AI Foundation as a Silver Member (March 2, 2026; AAIF under the Linux Foundation, nearly 150 members) “With founding contributions to leading open-source AI projects that include Anthropic’s Model Context Protocol, Block’s goose, and OpenAI’s AGENTS.md, AAIF governs the core standards and protocols that enable agents to operate across platforms.” | official | 2026-07-03 |
| s7 | SecurityWeek: Helmet Security Emerges From Stealth Mode With $9 Million in Funding (SYN Ventures and WhiteRabbit Ventures) “Headquartered in Washington, D.C., Helmet Security was co-founded by Fred Kneip (the founder of CyberGRX, which raised $100 million and was acquired by Marlin Equity Partners / ProcessUnity) and Kaushik Shanadi. Kneip serves as Helmet’s CEO and Shanadi as CTO.” | press | 2026-07-03 |
| s8 | SiliconANGLE: Helmet Security lands $9M to protect enterprises from MCP-based AI security risks (Dec 4, 2025; founded earlier this year; Jay Leek, SYN Ventures) “Helmet gives enterprises an immediate, installation-free view into where and how MCP is operating across their environments, plus the ability to act on rogue connections” | press | 2026-07-03 |
| s9 | Technical.ly: DC startup Helmet Security raises $9M (built the product in a couple of months; team from 3 to 10; market saturated with tools) “The startup currently has about 10 customers and is in the process of onboarding 30 more to join in the next couple of months, he said. Though he declined to name any, he described them as a mix of commercial firms and government agencies.” | press | 2026-07-03 |
| s10 | GitHub: helmet-sh organization (API probe 2026-07-03: zero public repositories) | official | 2026-07-03 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Helmet Security homepage (early-access contact form; blocks prompt injection & data leakage; SOC 2, ISO 27001, OWASP AI Top 10) “Enforce policy in real time, through native agent hooks and the Helmet MCP gateway: hosted by us, self-hosted, or orchestrated into AWS Bedrock, Azure APIM, and more.” | official | 2026-07-03 |
| s2 | Helmet Security: How Helmet works (signals in: EDR, IdP, network, SaaS; verified registry; secret scanning, SAST & DAST; drift and rug pulls; SIEM export) “SAAS Helmet-hosted Fully managed in Helmet Cloud. Nothing to operate. VPC / ENDPOINT Self-hosted Your VPC or a local endpoint proxy. Data never leaves. BEDROCK / APIM Orchestrated Policy pushed into AWS Bedrock, Azure APIM & more.” | official | 2026-07-03 |
| s3 | Helmet Security: Security & Trust (probe 2026-07-03: no trust or security subdomain resolves, no badge images in homepage footer HTML) “Our first SOC 2 Type II audit is scheduled for Summer 2026, and we are building our public Trust Center, powered by Vanta, to give customers transparent access to our security documentation and reports.” | official | 2026-07-03 |
| s4 | Helmet Security: About, The team (Fred Kneip co-founder and CEO; Kaushik Shanadi co-founder and CTO, creator of Helmet) “We are a team of security engineers and GRC experts dedicated to making agentic workflows safe for enterprise.” | official | 2026-07-03 |
| s5 | Helmet Security blog: Introducing Helmet Security, How We Started (Kaushik Shanadi, November 10, 2025; began as an MCP server-code scanner) “I didn’t want to build just a scanner. I wanted to architect something that would manage the whole lifecycle.” | official | 2026-07-03 |
| s6 | Helmet Security blog: Helmet Security Joins the Agentic AI Foundation as a Silver Member (March 2, 2026; AAIF under the Linux Foundation, nearly 150 members) “With founding contributions to leading open-source AI projects that include Anthropic’s Model Context Protocol, Block’s goose, and OpenAI’s AGENTS.md, AAIF governs the core standards and protocols that enable agents to operate across platforms.” | official | 2026-07-03 |
| s7 | SecurityWeek: Helmet Security Emerges From Stealth Mode With $9 Million in Funding (SYN Ventures and WhiteRabbit Ventures) “Headquartered in Washington, D.C., Helmet Security was co-founded by Fred Kneip (the founder of CyberGRX, which raised $100 million and was acquired by Marlin Equity Partners / ProcessUnity) and Kaushik Shanadi. Kneip serves as Helmet’s CEO and Shanadi as CTO.” | press | 2026-07-03 |
| s8 | SiliconANGLE: Helmet Security lands $9M to protect enterprises from MCP-based AI security risks (Dec 4, 2025; founded earlier this year; Jay Leek, SYN Ventures) “Helmet gives enterprises an immediate, installation-free view into where and how MCP is operating across their environments, plus the ability to act on rogue connections” | press | 2026-07-03 |
| s9 | Technical.ly: DC startup Helmet Security raises $9M (built the product in a couple of months; team from 3 to 10; market saturated with tools) “The startup currently has about 10 customers and is in the process of onboarding 30 more to join in the next couple of months, he said. Though he declined to name any, he described them as a mix of commercial firms and government agencies.” | press | 2026-07-03 |
| s10 | GitHub: helmet-sh organization (API probe 2026-07-03: zero public repositories) | official | 2026-07-03 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.