All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
HiddenLayer stayed independent after Palo Alto Networks bought Protect AI and Check Point announced its purchase of Lakera in 2025. Both rivals carried a crowdsourced asset absent from HiddenLayer's record: Lakera the Gandalf adversarial-pattern corpus, Protect AI the huntr researcher community. HiddenLayer's own research is public disclosure, and the National Vulnerability Database lists critical and high CVSS scores for the ChromaDB and MLflow flaws its team found. The federal footing is what a rival would need its own awards to match. Spending records verify Air Force contracts, and the company says it offers an airgapped edition for classified use. No commercial customer describes a paid deployment in the reviewed pages, and the record shows no funding round after 2023.
| Description | HiddenLayer defends the AI applications an enterprise runs, whether agentic, generative, or predictive, from development through production, with controls that protect intellectual property and support compliance. | [f1] |
|---|---|---|
| Founded | 2022 | [f2] |
| HQ | Austin, Texas, US | [f2] |
| Funding | $56M total | [f3] |
| Latest funding | Series A, $50M, September 2023 | [f3] |
| Deployment | SaaS, Self-hosted | [f4] |
| Product | What it does |
|---|---|
| HiddenLayer | AI security platform with four modules: model supply-chain scanning, real-time runtime monitoring of prompts and responses, automated red teaming, and AI asset discovery. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
HiddenLayer scans the model supply chain, monitors prompts and responses at runtime, automates red teaming, and discovers AI assets. It is mapped to the AI Defense Matrix. [f5]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | The buyers, enterprise CISOs and defense programs, and the assets are named, and independent records now document the problem class the platform addresses, including National Vulnerability Database entries for the remote-code-execution flaws HiddenLayer found in AI tooling such as ChromaDB and MLflow. Buyer-side pain stays qualitative with no independent quantification or regulatory mandate, which holds it at the present-but-unproven bar. [s18, s26, s27, s14] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | A public docs portal details all four modules and an airgapped edition, and HiddenLayer's vulnerability research is now externally cataloged: the National Vulnerability Database lists the ChromaDB and MLflow remote-code-execution flaws its team disclosed, rated critical and high, and references HiddenLayer's advisories, while SecurityWeek reported its Policy Puppetry prompt-injection testing across eight model providers. No independent benchmark of the product's own detection efficacy is published. [s3, s26, s27, s28, s9] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | Recent buyer-side signals include the SHIELD selection with independent defense-trade coverage reported in early 2026, alongside current AWS and Databricks platform integrations. The enabler is enterprise and government adoption of generative and agentic AI since 2022 to 2023, which created the asset class the platform defends and the federal procurement vehicles now buying it, evidenced by Air Force machine-learning-security contracts obligated from 2023. Consolidation is the window pressure, as platform vendors bought the two closest rivals in 2025. [s19, s14, s12, s13, s25, s23, s24] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | Press-verified Cylance pedigree for the three founders pairs with a research record now independently validated, as the National Vulnerability Database credits HiddenLayer's advisories for CVE-2026-45829 and CVE-2024-37054 and SecurityWeek covered its cross-model prompt-injection work. The founders still run the company, Sestito as CEO, Ballard as CIO, and Burns as Chief Scientist, alongside a hired bench that includes a chief product officer, a chief revenue officer, and a chief security and trust officer. [s17, s20, s26, s28, s2, s11] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | Federal spending records independently confirm obligated Air Force machine-learning-security contracts, including a 1.8 million dollar red-teaming award and a separate machine-learning detection and response award, and the AWS and Databricks partnership motions are separately sourced. The headline SHIELD vehicle is a crowded pool of more than 2,100 awardees that obligated no base funding, and no commercial customer is named publicly, which caps the score. [s25, s33, s30, s17, s32, s13, s14] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 2/5 | The 50 million dollar Series A of September 2023, on a 6 million dollar seed, outruns the verifiable commercial results: a set of Air Force contracts of roughly 3 million dollars combined and unnamed commercial customers, with no disclosed revenue or margin nearly three years on. An outsized raise with no disclosed revenue scores at the thin bar even while the company ships four modules and an airgapped edition. [s17, s25, s33, s32] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Independent outlets place HiddenLayer in security for AI without coaching, called an AI security firm by SecurityWeek and an AI security provider in defense-trade coverage of the SHIELD award. Platform-vendor acquisitions of Protect AI and Lakera confirm a budget destination incumbents now pay to enter. The category is broadly recognized but not HiddenLayer-defined. [s28, s31, s23, s24] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Palo Alto Networks and Check Point now own the two closest rivals and Microsoft is both an M12 investor and a plausible absorber, so absorption pressure is demonstrated rather than hypothetical. The airgapped platform and the now-verified federal past performance raise replication cost, but the SHIELD pool holds more than 2,100 awardees, federal revenue is modest, and no data flywheel appears in the record, so the moat evidence stays partial. [s23, s24, s25, s30] |
HiddenLayer treats AI models, prompts, and agents as assets that attackers target directly, and sells a platform to defend them. The founders frame the problem from lived experience. Ten Eleven Ventures, an early investor, writes that they built the machine-learning IP behind Cylance's endpoint product and then defended it against adversaries who attacked Cylance's ML algorithms.
Non-vendor parties corroborate the problem at scale. A judging panel named HiddenLayer the winner of the RSA Conference 2023 Innovation Sandbox contest for safeguarding the machine-learning models behind critical products. Independent records now document the attack class the platform addresses: the National Vulnerability Database lists the ChromaDB pre-authentication remote-code-execution flaw the company disclosed and displays a maximum 10.0 CVSS score, with the MLflow deserialization flaw at 8.8, both in the AI tooling the supply-chain module scans.
The buyer spans two motions. HiddenLayer pitches CISOs and AI leaders at large enterprises commercially, with solution pages for financial services and application developers. The federal motion addresses Department of Defense and intelligence-community programs that run models in classified, disconnected environments, served by an airgapped edition of the platform. [s20, s18, s26, s27, s14]
The HiddenLayer AI Security Platform ships four documented modules under one console. AI Supply Chain Security scans model files for malware, tampering, and backdoors and produces an AI bill of materials, and the same module documents model signing as a complementary integrity layer. AI Runtime Security enforces guardrails and blocks malicious prompts against deployed AI applications. AI Attack Simulation runs automated testing through two evaluation types, System Prompt Evaluation and Red Team Evaluation. AI Discovery inventories models, agents, and AI workflows across cloud providers and surfaces shadow AI.
Public documentation backs the capability claims. The docs portal describes each module, the console, integration guides, an airgapped deployment option, and release notes without requiring a customer login. The vendor states that the airgapped platform deploys locally in classified, disconnected environments, and company officials said HiddenLayer was selected for the Missile Defense Agency vehicle on the strength of that platform.
The research program is now independently validated rather than only self-published. SAI advisories document vulnerabilities in AI development tooling, and the National Vulnerability Database lists the ChromaDB and MLflow remote-code-execution flaws the team disclosed, displays critical and high severity ratings, and references HiddenLayer's advisories. SecurityWeek separately reported that HiddenLayer tested its Policy Puppetry prompt-injection technique against models from eight major providers, evidence of adversarial-AI craft in the same artifacts the product defends. [s3, s5, s6, s7, s8, s26, s27, s28, s31]
HiddenLayer now competes mostly against platform giants rather than independent peers. Palo Alto Networks completed its acquisition of Protect AI, the closest module-for-module rival, in July 2025, and Check Point announced its acquisition of Lakera that September. CyberScoop framed the Lakera deal as entrenched cybersecurity companies expanding to match the generative AI boom.
Against the bundles, HiddenLayer's visible differentiators are breadth and classified-environment deployment. Four modules span the model lifecycle from supply chain to runtime, and the airgapped edition reaches networks that cloud-delivered platform offerings do not serve. An AWS marketplace listing for the intelligence community is a channel a commercial bundle cannot enter quickly. The SHIELD position is real but not exclusive, as GovCon Wire reports the pool now exceeds 2,100 awardees.
Independent specialists still contest each module, among them Noma Security and Mindgard. Microsoft is both a potential absorber and an investor through M12, which cuts in two directions for HiddenLayer's commercial segment. [s23, s24, s30, s16, s14]
Federal traction is the clearest public proof, and it is now independently verified rather than vendor-claimed. USAspending records obligated Air Force contracts to HiddenLayer Inc, including a 1.8 million dollar award for a machine-learning-security red-teaming workbench and a 1.25 million dollar award for machine-learning detection and response against adversarial attacks. The Missile Defense Agency also placed HiddenLayer on the SHIELD vehicle, reported by defense trade press in early 2026, though GovCon Wire reports SHIELD obligated no funding at the base level and now holds more than 2,100 awardees, so task-order wins, not the vehicle position, will determine federal revenue.
Commercial proof is thinner and mostly anonymous. TechCrunch relayed in 2023 the company's claim of Fortune 100 customers in finance and cybersecurity, and SiliconANGLE separately reported that HiddenLayer had nearly quadrupled its headcount over the prior year. The published case study describes a red-teaming engagement for an unnamed payments customer with over 50 million users. No named commercial customer case study appears in reviewed pages.
Ecosystem motion runs through cloud and data-platform partners. HiddenLayer ships expanded AWS integrations covering Amazon Bedrock, Bedrock AgentCore, and SageMaker, and a Databricks integration that scans new model versions in Unity Catalog, alongside advisory, resale, and technology-alliance programs. [s25, s33, s30, s14, s17, s32, s12, s13, s10]
The founding team's domain pedigree is press-verified. Chris Sestito led threat research at Cylance before co-founding HiddenLayer with Jim Ballard and Tanner Burns, and Ten Eleven Ventures writes that the three developed the critical IP behind Cylance's competitive advantage. The founders still run the company: Sestito chairs the board and serves as CEO, Ballard is CIO, and Burns is Chief Scientist.
The company has built out a senior bench around the founders. The about page lists Jacob Rideout as Chief Technology Officer, Malcolm Harkins as Chief Security and Trust Officer, and Mike Bruchanski as Chief Product Officer, and the newsroom records the July 2025 appointment of Chelsea Strong as Chief Revenue Officer. This is a scaling executive team rather than a founder-only operation.
The research organization gives the team a sustained, independently validated record. The National Vulnerability Database credits HiddenLayer's advisories for the ChromaDB and MLflow remote-code-execution flaws, and SecurityWeek covered its cross-model prompt-injection research, a multi-year publication pattern in the company's own product domain rather than a single covered event. [s2, s20, s26, s28, s11]
HiddenLayer publishes the trust artifacts a security buyer checks first. The security page states that HiddenLayer, Inc. and its Machine Learning Detection and Response system met SOC 2 Type II standards for security, availability, and confidentiality, and details encryption at rest and TLS 1.2 or higher in transit. A vulnerability disclosure policy and a disclosure contact address appear on the same page.
Classified-environment posture is the differentiated trust claim, and it is now backed by a federal record. The vendor states that the airgapped platform deploys locally so customer data stays in user-controlled environments, and USAspending confirms the Air Force contracts that establish the past performance HiddenLayer cites for its Missile Defense Agency selection. FedRAMP authorization does not appear in reviewed pages, which leaves the civilian-agency procurement path undocumented. [s22, s25, s14]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Protect AI | competes with | Closest module-for-module rival across model scanning and runtime defense, acquired by Palo Alto Networks in July 2025. | |
| Lakera | competes with | Runtime guardrails and adversarial-testing rival, acquired by Check Point in September 2025. | |
| Noma Security | competes with | Independent platform covering AI discovery, governance, and protection for the same enterprise buyer. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Mindgard | competes with | Automated AI red-teaming specialist contesting the attack-simulation module. | |
| Microsoft | adjacent | Platform vendor and M12 investor whose native Azure AI security features could absorb the commercial segment. | N/AMicrosoft is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product. |
| Palo Alto Networks | adjacent | Prisma AIRS bundles the acquired Protect AI capabilities into a platform sold to the same CISO. | N/AWe scored these companies at different scopes, so the totals measure different things. |
Add analyzed competitors to compare them side by side with HiddenLayer.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
HiddenLayer is hardest to displace where its engineering is deepest and its buyers most regulated. Model scanning for backdoors, runtime detection, and automated testing require specialized adversarial-AI engineering, as its ShadowLogic research and NVD listings show. Spending records verify obligated Air Force machine-learning-security contracts, while the Missile Defense Agency SHIELD placement for classified deployments obligated no base funding. Customers buy a software platform they configure and run, not a managed outcome. Check Point credits Gandalf's adversarial patterns in Lakera's platform, Protect AI ran the huntr researcher community, and HiddenLayer's record names no non-public corpus. The federal and airgapped posture is hardest to take away, though modest in dollars.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | HiddenLayer delivers a four-module software platform the customer configures and runs across its own pipelines and environments, priced as enterprise software, the software-product level. Automated scanning, runtime detection, and red-team testing are software output, not a managed-service layer that accepts accountability. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Wiring supply-chain scanning into CI/CD, the runtime monitor into the production request flow, and the airgapped edition into customer-managed classified infrastructure creates meaningful friction to replace. No data-residency lock or buyer-side network effect earns the 3. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | SOC 2 Type II is table-stakes assurance a rival can earn, the airgapped edition's federal-requirements fit is vendor-stated, the verified Air Force awards are research contracts rather than compliance gates, and no FedRAMP authorization or product-class mandate appears in the record. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Scanning model layers and components for backdoors of the kind its ShadowLogic research demonstrated, inline real-time detection of malicious prompts, and automated red teaming require specialized adversarial-AI engineering, and the team's research is independently corroborated as the National Vulnerability Database lists the remote-code-execution flaws HiddenLayer disclosed, rated critical and high, and references its advisories. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | Federal spending records verify the Department of the Air Force as a paying buyer through obligated machine-learning-security contracts, the demanding regulated-government segment. The SHIELD placement targets classified deployments but has obligated no base funding, and a 2023 Fortune 100 claim adds an enterprise buyer the public record does not yet name. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | The supply-chain and discovery modules are pipeline and inventory tools the customer runs and the runtime monitor is an inline control, a platform with application features a customer application keeps functioning without. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | HiddenLayer's public research is a record of CVE advisories now listed in the National Vulnerability Database, a craft and demand-generation signal rather than a named non-public dataset, and the record shows no crowdsourced attack corpus behind its detectors. |
HiddenLayer treats the AI models, prompts, and agents an organization runs as assets attackers target directly, and sells a platform to defend them across the lifecycle. The homepage frames the buyer as the enterprise securing agentic, generative, and predictive AI at scale, and the founding story grounds the pitch: Ten Eleven Ventures, an early investor, writes that the founders built the machine-learning IP behind Cylance and then had to defend it from adversaries who attacked Cylance's ML algorithms.
The buyer splits into two motions, and the federal one is where the named evidence concentrates. Commercially, HiddenLayer pitches CISOs and AI leaders at large enterprises, with role and industry pages for application developers and financial services. The federal motion serves Department of Defense and intelligence-community programs that run models in classified, disconnected environments, addressed by a dedicated airgapped edition of the platform.
Non-vendor sources confirm category recognition and access to federal procurement. An RSA Conference 2023 judging panel named HiddenLayer Most Innovative Startup for safeguarding machine-learning models, and the Missile Defense Agency later placed the company on the SHIELD missile-defense vehicle, while the obligated Air Force awards, not the unfunded SHIELD base, show defense money reaching machine-learning security.
The HiddenLayer AI Security Platform ships four documented modules under one console. AI Supply Chain Security scans machine-learning models for malware, tampering, and backdoors and produces an AI bill of materials with model genealogy and integrity checks. AI Runtime Security is a real-time input and output monitor for hosted or custom LLMs that detects malicious prompts and undesired output and can block content. AI Attack Simulation runs automated testing through System Prompt Evaluation and Red Team Evaluation. AI Discovery inventories models, applications, and datasets across cloud providers and surfaces shadow AI.
The depth is documented rather than asserted, and the research behind it is now independently corroborated. A public docs portal describes each module, the console, integration guides, and an airgapped deployment option without a customer login. The documentation describes the supply-chain module as scanning models for malware, tampering, backdoors, and vulnerabilities. Separately, HiddenLayer's own research demonstrated ShadowLogic, a no-code computational-graph backdoor, which evidences in-domain craft rather than a documented module capability. The National Vulnerability Database lists remote-code-execution flaws the team disclosed in ChromaDB and MLflow and references HiddenLayer's advisories, which is research output rather than documented module scope.
What the platform does not have is the differentiating data asset its acquisition-target rivals carried. HiddenLayer's public research is a record of CVE advisories in AI tooling, evidence of in-domain craft but a stream of public disclosures rather than a proprietary corpus that trains its detectors. The capability advantage is the span of the four modules working together, not an accumulated dataset a copycat cannot assemble.
Federal procurement is HiddenLayer's clearest and most current public traction, and it is now independently verified rather than vendor-claimed. USAspending records obligated Air Force contracts to HiddenLayer Inc, including a 1.8 million dollar award for a machine-learning-security red-teaming workbench and a 1.25 million dollar award for machine-learning detection and response against adversarial attacks. The Missile Defense Agency placed the company on the SHIELD indefinite-delivery vehicle, reported by defense trade press in early 2026, though GovCon Wire reports SHIELD obligated no funding at the base level and now holds more than 2,100 awardees, so task-order wins will determine federal revenue.
Commercial proof is thinner and mostly anonymous. TechCrunch relayed in 2023 the company's claim of Fortune 100 customers across finance, government, defense, and cybersecurity, and SiliconANGLE separately reported that HiddenLayer had nearly quadrupled its headcount over the prior year. No commercial customer speaks in its own voice describing a paid deployment in the reviewed pages.
The selling motion is funded for the federal and enterprise push but light on disclosed revenue. The 50 million dollar Series A in September 2023, co-led by M12 and Moore Strategic Ventures with Booz Allen, IBM, Capital One, and Ten Eleven, brought the total raised to 56 million dollars, and the reviewed record shows no follow-on round since, even as the company added federal contract positions.
No platform price appears on the reviewed public pages, which signals a negotiated enterprise and federal motion rather than self-serve buyers. The site routes prospective buyers to a demo request, consistent with a vendor selling four-module platform deals into large enterprises and government programs through direct conversations.
The reviewed pages do not state the metering unit, so the basis of the bill is not publicly answerable from the fetched record. Because the platform spans build-time model scanning, runtime inspection, red-team simulation, and discovery, cost would plausibly track the size of the AI estate under protection, but that is inference rather than a published unit.
The absence of a published price on those pages fits the named buyer and raises a barrier for smaller teams. HiddenLayer likely negotiates enterprise and government contracts case by case, while a developer evaluating the platform has no transparent entry point.
HiddenLayer delivers as software the customer integrates and operates, with a runtime path that sits inline. AI Runtime Security monitors model input and output in real time and can block content before it reaches the LLM or the user, and HiddenLayer documents the supply-chain scanning CLI as carrying runtime options that make it suitable for integrating with common CI/CD workflows, so model verification can become a standard part of deployment. The documented integration work sits with the customer, which runs the supply-chain scanner from its own command line or orchestration system and wires the runtime controls into its request flow.
The differentiated delivery option is the airgapped edition. The platform installs within customer-managed infrastructure in classified, disconnected environments, which the vendor states meets federal security requirements while offering detection, scanning, and response without sending data to a vendor cloud. Army Technology reports that edition is the core of HiddenLayer's classified Department of War and intelligence-community solution, and USAspending records separately confirm the obligated Air Force contracts.
The heavier operational question the reviewed pages leave open is the inline runtime path. Because AI Runtime Security inspects production model traffic and can block it, a careful buyer would examine its latency, failure modes, and where inspection occurs, evidence the product pages describe at a capability level rather than with a published operational benchmark.
HiddenLayer publishes the trust artifacts an enterprise security buyer checks first. The security page states that HiddenLayer, Inc. and its Machine Learning Detection and Response system met SOC 2 Type II standards for security, availability, and confidentiality, documents encryption of data at rest and in transit, and carries a vulnerability disclosure policy and contact. SOC 2 Type II is completed third-party assurance rather than an in-process claim.
Classified-environment posture is the differentiated trust claim, and the SHIELD placement plus verified Air Force awards sit alongside the vendor's own deployment statements. The airgapped platform installs inside customer-managed infrastructure so data stays in user-controlled environments, Army Technology reports it meets federal security requirements as the core of HiddenLayer's classified solution, and USAspending separately verifies the obligated Air Force contracts.
The gap is published efficacy and a downloadable trust portal. No independent benchmark of detection quality and no FedRAMP authorization appear in the reviewed pages, so a civilian-agency procurement path is undocumented and the protection claims rest on vendor description rather than third-party evaluation.
HiddenLayer is built as a single platform spanning the AI lifecycle rather than a point tool. The documentation frames four modules, supply chain, runtime, attack simulation, and discovery, under one console, and the homepage positions the platform as covering the model lifecycle from build-time ingest through production runtime, so the modules share a common spine rather than standing alone.
Outward reach runs through cloud and data-platform integrations rather than an external builder ecosystem. AI Discovery inventories models, applications, and datasets across cloud providers, and the documentation carries integration guides for wiring the platform into those environments, but no third-party developer marketplace or partner-built integration catalog with a network effect appeared in the reviewed pages, so the platform claim sits on internal module consolidation and integration breadth.
Inward, the breadth is the strategy, since each module reinforces the others, but it is also the exposure. The same module breadth that lets a buyer consolidate is what a well-funded platform vendor can assemble. Two adjacent vendors have been taken up by larger platform owners, Protect AI absorbed by Palo Alto Networks and Lakera the subject of Check Point's announced purchase, which increases competition from that direction.
The founding team's domain pedigree is documented by investor Ten Eleven Ventures, which writes that founders Tito Sestito, Jim Ballard, and Tanner Burns developed the critical IP behind Cylance's competitive advantage and then defended it from adversaries who attacked Cylance's ML algorithms, the exact problem HiddenLayer now productizes. The founders still run the company, with Sestito as chairman and CEO, Ballard as CIO, and Burns as Chief Scientist.
The company has built a senior bench around the founders rather than staying founder-only. The about page lists Jacob Rideout as Chief Technology Officer, Malcolm Harkins as Chief Security and Trust Officer, and Mike Bruchanski as Chief Product Officer, and the newsroom announced in July 2025 that HiddenLayer had appointed Chelsea Strong as Chief Revenue Officer, a dated release read in the June 29, 2026 capture of that page rather than a statement about the current roster.
The research organization gives the team a sustained, independently validated record. The National Vulnerability Database credits HiddenLayer's advisories for the ChromaDB and MLflow remote-code-execution flaws, and SecurityWeek covered its cross-model prompt-injection research, a multi-year pattern in the company's own product domain rather than a single covered event.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | HiddenLayer: Total AI Security | official | 2026-07-09 |
| f2 | The SaaS News on the HiddenLayer seed round (TechCrunch states 2019 in conflict; 2022 corroborated across trackers and RSAC startup coverage) | press | 2026-06-12 |
| f3 | TechCrunch on the HiddenLayer Series A | press | 2026-06-12 |
| f4 | AI Defense Matrix Catalog entry | other | 2026-06-07 |
| f5 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | HiddenLayer homepage | official | 2026-06-12 |
| s2 | HiddenLayer About Us and leadership team “Christopher "Tito" Sestito Chairman of the Board, CEO & Co-Founder ... Jim Ballard Co-founder & CIO ... Jacob Rideout Chief Technology Officer ... Malcolm Harkins Chief Security & Trust Officer ... Mike Bruchanski Chief Product Officer” | official | 2026-06-29 |
| s3 | HiddenLayer AI Security Platform documentation portal “AI Attack Simulation provides automated security testing for your AI systems through two complementary approaches: System Prompt Evaluation and Red Team Evaluation.” | official | 2026-06-12 |
| s4 | HiddenLayer platform overview | official | 2026-06-12 |
| s5 | AI Supply Chain Security module page “Model scanning and model signing work together as complementary security measures, both essential for comprehensive AI model protection.” | official | 2026-06-18 |
| s6 | AI Runtime Security module page | official | 2026-06-12 |
| s7 | AI Attack Simulation module page | official | 2026-06-12 |
| s8 | AI Discovery module page | official | 2026-06-12 |
| s9 | HiddenLayer SAI security advisory hub “Any authenticated user with a valid collection UUID can read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.” | official | 2026-06-18 |
| s10 | HiddenLayer case study (unnamed payments customer) “With over 50 million users and facilitating more than 5 billion transactions annually, our customer grappled with the ongoing challenge of minimizing customer experience issues while simultaneously combating fraud.” | official | 2026-06-12 |
| s11 | HiddenLayer newsroom “HiddenLayer Appoints Chelsea Strong as Chief Revenue Officer to Accelerate Global Growth and Customer Expansion ... AUSTIN, TX, July 16, 2025” | official | 2026-06-29 |
| s12 | HiddenLayer AWS partner page “HiddenLayer's AWS integrations extend the HiddenLayer AI Security Platform to secure Bedrock models, Bedrock Agents, SageMaker models, and model-serving endpoints, as well as agents deployed on Amazon Bedrock Agentcore using the AWS Strands framework.” | official | 2026-06-18 |
| s13 | HiddenLayer Databricks partner page “HiddenLayer brings automated model scanning directly into Databricks Unity Catalog. New model versions are scanned in the background, with results available in Unity Catalog and the HiddenLayer console.” | official | 2026-06-18 |
| s14 | HiddenLayer announcement of the MDA SHIELD IDIQ award “The SHIELD IDIQ has a ceiling value of $151 billion and serves as a core acquisition vehicle supporting the Department of Defense's Golden Dome initiative to rapidly deliver innovative capabilities to the warfighter.” | official | 2026-06-12 |
| s15 | HiddenLayer 2026 AI Threat Landscape Report announcement | official | 2026-06-12 |
| s16 | HiddenLayer post on its AWS Intelligence Community Marketplace listing | official | 2026-06-12 |
| s17 | TechCrunch on the HiddenLayer Series A “it raised $50 million in a funding round co-led by M12 and Moore Strategic Ventures ... HiddenLayer claims to have Fortune 100 customers in the financial, government and defense, including the U.S. Air Force and Space Force, and cybersecurity industries.” | press | 2026-06-18 |
| s18 | RSAC press release on the HiddenLayer Innovation Sandbox win “today announced that HiddenLayer is the winner of the annual RSAC Innovation Sandbox contest” | press | 2026-06-12 |
| s19 | Army Technology on the HiddenLayer SHIELD award “AI security company HiddenLayer has been awarded a place on the US Missile Defense Agency's (MDA) Scalable Homeland Innovative Enterprise Layered Defense (SHIELD) contract.” | press | 2026-06-12 |
| s20 | Ten Eleven Ventures investment note on HiddenLayer “The founders were employees of another (former) portfolio company of ours, AI-based security company Cylance (since acquired by Blackberry).” | other | 2026-06-12 |
| s21 | The SaaS News on the HiddenLayer seed round “HiddenLayer, an Austin, TX-based developer of a security platform ... raised $6 million in Seed funding.” | press | 2026-06-12 |
| s22 | HiddenLayer security and trust page “HiddenLayer, Inc. and our Machine Learning Detection & Response System has met SOC 2 Type II standards regarding the suitability of the design and operation effectiveness of its controls relevant to security, availability and confidentiality.” | official | 2026-06-12 |
| s23 | Palo Alto Networks release on completing the Protect AI acquisition “today announced it has completed its acquisition of Protect AI” | press | 2026-06-12 |
| s24 | CyberScoop on the Check Point acquisition of Lakera “Check Point Software Technologies announced Monday it will acquire Lakera, a specialized artificial intelligence security platform, as entrenched cybersecurity companies continue to expand their offerings to match the generative AI boom.” | press | 2026-06-12 |
| s25 | USAspending.gov: $1,799,680 Air Force award to HiddenLayer Inc (FA864924P0543) “MACHINE LEARNING SECURITY ATTACK WORKBENCH FOR RED TEAMING OF AUTONOMOUS ASSETS” | regulatory | 2026-06-29 |
| s26 | National Vulnerability Database (NVD) entry for CVE-2026-45829 (ChromaDB pre-auth RCE, CVSS 10.0), referencing the HiddenLayer advisory “A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true.” | regulatory | 2026-06-29 |
| s27 | National Vulnerability Database (NVD) entry for CVE-2024-37054 (MLflow deserialization RCE, CVSS 8.8), referencing the HiddenLayer advisory “Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc model to run arbitrary code on an end user's system when interacted with.” | regulatory | 2026-06-29 |
| s28 | SecurityWeek on HiddenLayer's Policy Puppetry prompt-injection research “The cybersecurity firm tested the Policy Puppetry technique against popular gen-AI models from Anthropic, DeepSeek, Google, Meta, Microsoft, Mistral, OpenAI, and Qwen, and successfully demonstrated its effectiveness against all, albeit with some minor adjustments in some cases.” | press | 2026-06-29 |
| s29 | CSO Online on the HiddenLayer-disclosed ChromaDB remote-code-execution flaw “The issue, tracked as CVE-2026-45829, is located in ChromaDB's API server and was published by researchers at HiddenLayer after reportedly failing to get in contact with the developers of ChromaDB, one of the most popular vector databases used for AI applications.” | press | 2026-06-29 |
| s30 | GovCon Wire on the second tranche of MDA SHIELD awards “The latest awards follow the initial group of 1,014 contractors announced earlier this month, the Department of War said Thursday, bringing the total number of SHIELD awardees to more than 2,100.” | press | 2026-06-29 |
| s31 | Military Embedded Systems on HiddenLayer's SHIELD selection “HiddenLayer was selected, say company officials, on the strength of its airgapped AI security platform, a solution designed to protect AI models and development processes in fully classified, disconnected environments.” | press | 2026-06-29 |
| s32 | SiliconANGLE on the HiddenLayer Series A and headcount growth “To advance its revenue growth plans, the company has nearly quadrupled its headcount over the 12 months.” | press | 2026-06-29 |
| s33 | USAspending.gov: $1,249,913 Air Force award to HiddenLayer Inc (FA864923P1251) “HIDDENLAYER MACHINE LEARNING DETECTION & RESPONSE - DEFENSE AGAINST ADVERSARIAL MACHINE LEARNING ATTACKS” | regulatory | 2026-06-29 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | HiddenLayer homepage (Total AI Security) “The HiddenLayer AI Security Platform secures agentic, generative, and predictive AI applications across the entire lifecycle, protecting IP, ensuring compliance, and enabling safe adoption at enterprise scale.” | official | 2026-06-18 |
| s2 | HiddenLayer documentation (One Platform, Four Modules) “AI Supply Chain Security analyzes Machine Learning Models to identify hidden cybersecurity risks and threats such as malware, vulnerabilities, and integrity issues ... inspecting each layer and component to detect possible signs of malicious activity, including malware, tampering, and backdoors.” | official | 2026-06-18 |
| s3 | HiddenLayer documentation portal (platform overview and AI Attack Simulation) “AI Attack Simulation provides automated security testing for your AI systems through two complementary approaches: System Prompt Evaluation and Red Team Evaluation. Together, these evaluation types help you build robust, secure AI applications.” | official | 2026-06-18 |
| s4 | HiddenLayer security and trust page (SOC 2 Type II) “HiddenLayer, Inc. and our Machine Learning Detection & Response System has met SOC 2 Type II standards regarding the suitability of the design and operation effectiveness of its controls relevant to security, availability and confidentiality.” | official | 2026-06-15 |
| s5 | HiddenLayer About Us and leadership team “Christopher "Tito" Sestito Chairman of the Board, CEO & Co-Founder ... Jim Ballard Co-founder & CIO ... Jacob Rideout Chief Technology Officer ... Malcolm Harkins Chief Security & Trust Officer ... Mike Bruchanski Chief Product Officer” | official | 2026-06-29 |
| s6 | Army Technology on the HiddenLayer Missile Defense Agency SHIELD award “HiddenLayer has been awarded a place on the US Missile Defense Agency's (MDA) SHIELD contract ... a ceiling value of $151bn ... HiddenLayer's Airgapped AI Security Platform serves as the core of its solution for classified DoW and USIC deployments.” | press | 2026-06-15 |
| s7 | TechCrunch on the HiddenLayer Series A funding and customer claims “raised $50 million in a funding round co-led by M12 and Moore Strategic Ventures with participation from Booz Allen Hamilton, IBM, Capital One and TenEleven. Bringing the company's total raised to $56 million” | press | 2026-06-15 |
| s8 | RSAC names HiddenLayer Most Innovative Startup at the 2023 Innovation Sandbox “HiddenLayer is the winner of the annual RSAC Innovation Sandbox contest. Named Most Innovative Startup, HiddenLayer was selected by a panel of esteemed judges for helping enterprises safeguard the machine learning models behind their critical products with a comprehensive security platform.” | press | 2026-06-15 |
| s9 | Ten Eleven Ventures investment note on HiddenLayer and Cylance pedigree “founders Tito, Jim, and Tanner developed the critical IP behind the company's competitive advantage and success, but then were forced to defend that most crucial IP from malicious actors who attacked Cylance's ML algorithms.” | other | 2026-06-15 |
| s10 | Palo Alto Networks completes acquisition of Protect AI “today announced it has completed its acquisition of Protect AI” | press | 2026-06-12 |
| s11 | CyberScoop on Check Point acquiring Lakera “Check Point Software Technologies announced Monday it will acquire Lakera, a specialized artificial intelligence security platform, as entrenched cybersecurity companies continue to expand their offerings to match the generative AI boom.” | press | 2026-06-12 |
| s12 | Check Point press release on the Lakera acquisition and Gandalf adversarial-pattern corpus “Powered by Gandalf's 80 million-plus adversarial patterns and guided by a dedicated AI research team, Lakera's platform adapts constantly to emerging AI threats.” | press | 2026-06-15 |
| s13 | DEVOPSdigest on Protect AI acquiring huntr and its researcher community “With a vast network of over ten-thousand security researchers specializing in open-source software (OSS), huntr has been at the forefront of OSS security research and development.” | press | 2026-06-15 |
| s14 | HiddenLayer SAI research on the ShadowLogic computational-graph backdoor “we discovered a novel method for implanting no-code logic backdoors in machine learning models. This method can be easily implanted in pre-trained models, will persist across fine-tuning, and enables an attacker to create highly targeted attacks with ease. We call this technique ShadowLogic.” | research | 2026-06-18 |
| s15 | USAspending.gov: $1,799,680 Air Force award to HiddenLayer Inc (FA864924P0543) “MACHINE LEARNING SECURITY ATTACK WORKBENCH FOR RED TEAMING OF AUTONOMOUS ASSETS” | regulatory | 2026-06-29 |
| s16 | National Vulnerability Database (NVD) entry for CVE-2026-45829 (ChromaDB pre-auth RCE, CVSS 10.0), referencing the HiddenLayer advisory “A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true.” | regulatory | 2026-06-29 |
| s17 | National Vulnerability Database (NVD) entry for CVE-2024-37054 (MLflow deserialization RCE, CVSS 8.8), referencing the HiddenLayer advisory “Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc model to run arbitrary code on an end user's system when interacted with.” | regulatory | 2026-06-29 |
| s18 | SecurityWeek on HiddenLayer's Policy Puppetry prompt-injection research “The cybersecurity firm tested the Policy Puppetry technique against popular gen-AI models from Anthropic, DeepSeek, Google, Meta, Microsoft, Mistral, OpenAI, and Qwen, and successfully demonstrated its effectiveness against all, albeit with some minor adjustments in some cases.” | press | 2026-06-29 |
| s19 | GovCon Wire on the second tranche of MDA SHIELD awards “The latest awards follow the initial group of 1,014 contractors announced earlier this month, the Department of War said Thursday, bringing the total number of SHIELD awardees to more than 2,100.” | press | 2026-06-29 |
| s20 | SiliconANGLE on the HiddenLayer Series A and headcount growth “To advance its revenue growth plans, the company has nearly quadrupled its headcount over the 12 months.” | press | 2026-06-29 |
| s21 | USAspending.gov: $1,249,913 Air Force award to HiddenLayer Inc (FA864923P1251) “HIDDENLAYER MACHINE LEARNING DETECTION & RESPONSE - DEFENSE AGAINST ADVERSARIAL MACHINE LEARNING ATTACKS” | regulatory | 2026-06-29 |
| s22 | HiddenLayer newsroom (Chelsea Strong CRO appointment) “HiddenLayer Appoints Chelsea Strong as Chief Revenue Officer to Accelerate Global Growth and Customer Expansion ... AUSTIN, TX, July 16, 2025” | official | 2026-06-29 |
| s23 | HiddenLayer documentation: AI Supply Chain Security CLI deployment and CI/CD fit “Users can run it directly from the command line, or can integrate it into their own queueing and orchestration systems. Supply Chain CLI includes runtime options that make it suitable for integrating with common CI/CD workflows.” | official | 2026-08-05 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.