All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
HiddenLayer stayed independent after Palo Alto Networks bought Protect AI and Check Point announced its purchase of Lakera in 2025. Both rivals carried a crowdsourced data asset absent from HiddenLayer's public record: Lakera the Gandalf adversarial-pattern corpus, Protect AI the huntr researcher community. HiddenLayer's own research is public disclosure, now listed in the National Vulnerability Database, which lists critical and high CVSS scores for the ChromaDB and MLflow flaws its team found. The federal footing is what a rival would need its own awards to match, and spending records verify it through Air Force machine-learning-security contracts and a classified-environment airgapped edition. Commercial customers stay unnamed, and the record shows no funding round after 2023.
| Description | HiddenLayer defends the AI applications an enterprise runs, whether agentic, generative, or predictive, from development through production, with controls that protect intellectual property and support compliance. | [f1] |
|---|---|---|
| Founded | 2022 | [f2] |
| HQ | Austin, Texas, US | [f2] |
| Funding | $56M total | [f3] |
| Latest funding | Series A, $50M, September 2023 | [f3] |
| Deployment | SaaS, Self-hosted | [f4] |
| Product | What it does |
|---|---|
| HiddenLayer | AI security platform with four modules: model supply-chain scanning, real-time runtime monitoring of prompts and responses, automated red teaming, and AI asset discovery. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
HiddenLayer scans the model supply chain, monitors prompts and responses at runtime, automates red teaming, and discovers AI assets. It is mapped to the AI Defense Matrix. [f5]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score |
|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs, demos, and third-party validation. | 4/5 |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 2/5 |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
| Dimension | Score |
|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | HiddenLayer: Total AI Security | official | 2026-07-09 |
| f2 | The SaaS News on the HiddenLayer seed round (TechCrunch states 2019 in conflict; 2022 corroborated across trackers and RSAC startup coverage) | press | 2026-06-12 |
| f3 | TechCrunch on the HiddenLayer Series A | press | 2026-06-12 |
| f4 | AI Defense Matrix Catalog entry | other | 2026-06-07 |
| f5 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | HiddenLayer homepage | official | 2026-06-12 |
| s2 | HiddenLayer About Us and leadership team “Christopher "Tito" Sestito Chairman of the Board, CEO & Co-Founder ... Jim Ballard Co-founder & CIO ... Jacob Rideout Chief Technology Officer ... Malcolm Harkins Chief Security & Trust Officer ... Mike Bruchanski Chief Product Officer” | official | 2026-06-29 |
| s3 | HiddenLayer AI Security Platform documentation portal “AI Attack Simulation provides automated security testing for your AI systems through two complementary approaches: System Prompt Evaluation and Red Team Evaluation.” | official | 2026-06-12 |
| s4 | HiddenLayer platform overview | official | 2026-06-12 |
| s5 | AI Supply Chain Security module page “Model scanning and model signing work together as complementary security measures, both essential for comprehensive AI model protection.” | official | 2026-06-18 |
| s6 | AI Runtime Security module page | official | 2026-06-12 |
| s7 | AI Attack Simulation module page | official | 2026-06-12 |
| s8 | AI Discovery module page | official | 2026-06-12 |
| s9 | HiddenLayer SAI security advisory hub “Any authenticated user with a valid collection UUID can read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.” | official | 2026-06-18 |
| s10 | HiddenLayer case study (unnamed payments customer) “With over 50 million users and facilitating more than 5 billion transactions annually, our customer grappled with the ongoing challenge of minimizing customer experience issues while simultaneously combating fraud.” | official | 2026-06-12 |
| s11 | HiddenLayer newsroom “HiddenLayer Appoints Chelsea Strong as Chief Revenue Officer to Accelerate Global Growth and Customer Expansion ... AUSTIN, TX, July 16, 2025” | official | 2026-06-29 |
| s12 | HiddenLayer AWS partner page “HiddenLayer's AWS integrations extend the HiddenLayer AI Security Platform to secure Bedrock models, Bedrock Agents, SageMaker models, and model-serving endpoints, as well as agents deployed on Amazon Bedrock Agentcore using the AWS Strands framework.” | official | 2026-06-18 |
| s13 | HiddenLayer Databricks partner page “HiddenLayer brings automated model scanning directly into Databricks Unity Catalog. New model versions are scanned in the background, with results available in Unity Catalog and the HiddenLayer console.” | official | 2026-06-18 |
| s14 | HiddenLayer announcement of the MDA SHIELD IDIQ award “The SHIELD IDIQ has a ceiling value of $151 billion and serves as a core acquisition vehicle supporting the Department of Defense's Golden Dome initiative to rapidly deliver innovative capabilities to the warfighter.” | official | 2026-06-12 |
| s15 | HiddenLayer 2026 AI Threat Landscape Report announcement | official | 2026-06-12 |
| s16 | HiddenLayer post on its AWS Intelligence Community Marketplace listing | official | 2026-06-12 |
| s17 | TechCrunch on the HiddenLayer Series A “it raised $50 million in a funding round co-led by M12 and Moore Strategic Ventures ... HiddenLayer claims to have Fortune 100 customers in the financial, government and defense, including the U.S. Air Force and Space Force, and cybersecurity industries.” | press | 2026-06-18 |
| s18 | RSAC press release on the HiddenLayer Innovation Sandbox win “today announced that HiddenLayer is the winner of the annual RSAC Innovation Sandbox contest” | press | 2026-06-12 |
| s19 | Army Technology on the HiddenLayer SHIELD award “AI security company HiddenLayer has been awarded a place on the US Missile Defense Agency's (MDA) Scalable Homeland Innovative Enterprise Layered Defense (SHIELD) contract.” | press | 2026-06-12 |
| s20 | Ten Eleven Ventures investment note on HiddenLayer “The founders were employees of another (former) portfolio company of ours, AI-based security company Cylance (since acquired by Blackberry).” | other | 2026-06-12 |
| s21 | The SaaS News on the HiddenLayer seed round “HiddenLayer, an Austin, TX-based developer of a security platform ... raised $6 million in Seed funding.” | press | 2026-06-12 |
| s22 | HiddenLayer security and trust page “HiddenLayer, Inc. and our Machine Learning Detection & Response System has met SOC 2 Type II standards regarding the suitability of the design and operation effectiveness of its controls relevant to security, availability and confidentiality.” | official | 2026-06-12 |
| s23 | Palo Alto Networks release on completing the Protect AI acquisition “today announced it has completed its acquisition of Protect AI” | press | 2026-06-12 |
| s24 | CyberScoop on the Check Point acquisition of Lakera “Check Point Software Technologies announced Monday it will acquire Lakera, a specialized artificial intelligence security platform, as entrenched cybersecurity companies continue to expand their offerings to match the generative AI boom.” | press | 2026-06-12 |
| s25 | USAspending.gov: $1,799,680 Air Force award to HiddenLayer Inc (FA864924P0543) “MACHINE LEARNING SECURITY ATTACK WORKBENCH FOR RED TEAMING OF AUTONOMOUS ASSETS” | regulatory | 2026-06-29 |
| s26 | National Vulnerability Database (NVD) entry for CVE-2026-45829 (ChromaDB pre-auth RCE, CVSS 10.0), referencing the HiddenLayer advisory “A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true.” | regulatory | 2026-06-29 |
| s27 | National Vulnerability Database (NVD) entry for CVE-2024-37054 (MLflow deserialization RCE, CVSS 8.8), referencing the HiddenLayer advisory “Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc model to run arbitrary code on an end user's system when interacted with.” | regulatory | 2026-06-29 |
| s28 | SecurityWeek on HiddenLayer's Policy Puppetry prompt-injection research “The cybersecurity firm tested the Policy Puppetry technique against popular gen-AI models from Anthropic, DeepSeek, Google, Meta, Microsoft, Mistral, OpenAI, and Qwen, and successfully demonstrated its effectiveness against all, albeit with some minor adjustments in some cases.” | press | 2026-06-29 |
| s29 | CSO Online on the HiddenLayer-disclosed ChromaDB remote-code-execution flaw “The issue, tracked as CVE-2026-45829, is located in ChromaDB's API server and was published by researchers at HiddenLayer after reportedly failing to get in contact with the developers of ChromaDB, one of the most popular vector databases used for AI applications.” | press | 2026-06-29 |
| s30 | GovCon Wire on the second tranche of MDA SHIELD awards “The latest awards follow the initial group of 1,014 contractors announced earlier this month, the Department of War said Thursday, bringing the total number of SHIELD awardees to more than 2,100.” | press | 2026-06-29 |
| s31 | Military Embedded Systems on HiddenLayer's SHIELD selection “HiddenLayer was selected, say company officials, on the strength of its airgapped AI security platform, a solution designed to protect AI models and development processes in fully classified, disconnected environments.” | press | 2026-06-29 |
| s32 | SiliconANGLE on the HiddenLayer Series A and headcount growth “To advance its revenue growth plans, the company has nearly quadrupled its headcount over the 12 months.” | press | 2026-06-29 |
| s33 | USAspending.gov: $1,249,913 Air Force award to HiddenLayer Inc (FA864923P1251) “HIDDENLAYER MACHINE LEARNING DETECTION & RESPONSE - DEFENSE AGAINST ADVERSARIAL MACHINE LEARNING ATTACKS” | regulatory | 2026-06-29 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | HiddenLayer homepage (Total AI Security) “The HiddenLayer AI Security Platform secures agentic, generative, and predictive AI applications across the entire lifecycle, protecting IP, ensuring compliance, and enabling safe adoption at enterprise scale.” | official | 2026-06-18 |
| s2 | HiddenLayer documentation (One Platform, Four Modules) “AI Supply Chain Security analyzes Machine Learning Models to identify hidden cybersecurity risks and threats such as malware, vulnerabilities, and integrity issues ... inspecting each layer and component to detect possible signs of malicious activity, including malware, tampering, and backdoors.” | official | 2026-06-18 |
| s3 | HiddenLayer documentation portal (platform overview and AI Attack Simulation) “AI Attack Simulation provides automated security testing for your AI systems through two complementary approaches: System Prompt Evaluation and Red Team Evaluation. Together, these evaluation types help you build robust, secure AI applications.” | official | 2026-06-18 |
| s4 | HiddenLayer security and trust page (SOC 2 Type II) “HiddenLayer, Inc. and our Machine Learning Detection & Response System has met SOC 2 Type II standards regarding the suitability of the design and operation effectiveness of its controls relevant to security, availability and confidentiality.” | official | 2026-06-15 |
| s5 | HiddenLayer About Us and leadership team “Christopher "Tito" Sestito Chairman of the Board, CEO & Co-Founder ... Jim Ballard Co-founder & CIO ... Jacob Rideout Chief Technology Officer ... Malcolm Harkins Chief Security & Trust Officer ... Mike Bruchanski Chief Product Officer” | official | 2026-06-29 |
| s6 | Army Technology on the HiddenLayer Missile Defense Agency SHIELD award “HiddenLayer has been awarded a place on the US Missile Defense Agency's (MDA) SHIELD contract ... a ceiling value of $151bn ... HiddenLayer's Airgapped AI Security Platform serves as the core of its solution for classified DoW and USIC deployments.” | press | 2026-06-15 |
| s7 | TechCrunch on the HiddenLayer Series A funding and customer claims “raised $50 million in a funding round co-led by M12 and Moore Strategic Ventures with participation from Booz Allen Hamilton, IBM, Capital One and TenEleven. Bringing the company's total raised to $56 million” | press | 2026-06-15 |
| s8 | RSAC names HiddenLayer Most Innovative Startup at the 2023 Innovation Sandbox “HiddenLayer is the winner of the annual RSAC Innovation Sandbox contest. Named Most Innovative Startup, HiddenLayer was selected by a panel of esteemed judges for helping enterprises safeguard the machine learning models behind their critical products with a comprehensive security platform.” | press | 2026-06-15 |
| s9 | Ten Eleven Ventures investment note on HiddenLayer and Cylance pedigree “founders Tito, Jim, and Tanner developed the critical IP behind the company's competitive advantage and success, but then were forced to defend that most crucial IP from malicious actors who attacked Cylance's ML algorithms.” | other | 2026-06-15 |
| s10 | Palo Alto Networks completes acquisition of Protect AI “today announced it has completed its acquisition of Protect AI” | press | 2026-06-12 |
| s11 | CyberScoop on Check Point acquiring Lakera “Check Point Software Technologies announced Monday it will acquire Lakera, a specialized artificial intelligence security platform, as entrenched cybersecurity companies continue to expand their offerings to match the generative AI boom.” | press | 2026-06-12 |
| s12 | Check Point press release on the Lakera acquisition and Gandalf adversarial-pattern corpus “Powered by Gandalf's 80 million-plus adversarial patterns and guided by a dedicated AI research team, Lakera's platform adapts constantly to emerging AI threats.” | press | 2026-06-15 |
| s13 | DEVOPSdigest on Protect AI acquiring huntr and its researcher community “With a vast network of over ten-thousand security researchers specializing in open-source software (OSS), huntr has been at the forefront of OSS security research and development.” | press | 2026-06-15 |
| s14 | HiddenLayer SAI research on the ShadowLogic computational-graph backdoor “we discovered a novel method for implanting no-code logic backdoors in machine learning models. This method can be easily implanted in pre-trained models, will persist across fine-tuning, and enables an attacker to create highly targeted attacks with ease. We call this technique ShadowLogic.” | research | 2026-06-18 |
| s15 | USAspending.gov: $1,799,680 Air Force award to HiddenLayer Inc (FA864924P0543) “MACHINE LEARNING SECURITY ATTACK WORKBENCH FOR RED TEAMING OF AUTONOMOUS ASSETS” | regulatory | 2026-06-29 |
| s16 | National Vulnerability Database (NVD) entry for CVE-2026-45829 (ChromaDB pre-auth RCE, CVSS 10.0), referencing the HiddenLayer advisory “A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true.” | regulatory | 2026-06-29 |
| s17 | National Vulnerability Database (NVD) entry for CVE-2024-37054 (MLflow deserialization RCE, CVSS 8.8), referencing the HiddenLayer advisory “Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc model to run arbitrary code on an end user's system when interacted with.” | regulatory | 2026-06-29 |
| s18 | SecurityWeek on HiddenLayer's Policy Puppetry prompt-injection research “The cybersecurity firm tested the Policy Puppetry technique against popular gen-AI models from Anthropic, DeepSeek, Google, Meta, Microsoft, Mistral, OpenAI, and Qwen, and successfully demonstrated its effectiveness against all, albeit with some minor adjustments in some cases.” | press | 2026-06-29 |
| s19 | GovCon Wire on the second tranche of MDA SHIELD awards “The latest awards follow the initial group of 1,014 contractors announced earlier this month, the Department of War said Thursday, bringing the total number of SHIELD awardees to more than 2,100.” | press | 2026-06-29 |
| s20 | SiliconANGLE on the HiddenLayer Series A and headcount growth “To advance its revenue growth plans, the company has nearly quadrupled its headcount over the 12 months.” | press | 2026-06-29 |
| s21 | USAspending.gov: $1,249,913 Air Force award to HiddenLayer Inc (FA864923P1251) “HIDDENLAYER MACHINE LEARNING DETECTION & RESPONSE - DEFENSE AGAINST ADVERSARIAL MACHINE LEARNING ATTACKS” | regulatory | 2026-06-29 |
| s22 | HiddenLayer newsroom (Chelsea Strong CRO appointment) “HiddenLayer Appoints Chelsea Strong as Chief Revenue Officer to Accelerate Global Growth and Customer Expansion ... AUSTIN, TX, July 16, 2025” | official | 2026-06-29 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Do not republish its content or share access without the operator's permission.