Hirundo

Security for AI also known as Hirundo AI

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software.
Founded 2023
Funding $8M
Last updated 2026-07-15

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Hirundo edits the weights of an already-trained AI model so it forgets specific things it learned, jailbreak weaknesses, memorized personal data, hallucination triggers, and bias, instead of retraining it. A Google DeepMind-hosted case study reports Hirundo's own result: hardening a Gemma model cut successful attacks by about three-quarters while keeping its benchmark scores. That result also names the threat, because the model providers Hirundo hardens could fold unlearning into their own training. Founders from the Technion give the team real academic standing, and Hirundo is an early entrant in a young discipline. It has no named paying customer and no proprietary dataset in the public record, so today the lead is being first, not being hard to copy.

Sourced Details

Description Hirundo builds a machine unlearning platform that removes memorized PII, jailbreak vulnerabilities, biases, and hallucination-causing data from already-trained AI models without full retraining. [f1]
Founded 2023 [f2]
HQ Tel Aviv, Israel [f2]
Funding $8M total [f3]
Latest funding Seed ($8M, June 2025, led by Maverick Ventures Israel) [f2]

Products

Product What it does
Hirundo Machine Unlearning Platform Detects weaknesses in trained models, then surgically removes the parameters behind unwanted behavior such as jailbreaks, hallucinations, bias, and memorized data, without full retraining.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

The Hirundo Machine Unlearning Platform removes the parameters behind jailbreaks, bias, hallucinations, and memorized data in trained models, and screens training data for the issues that cause them. These capabilities are mapped to the AI Defense Matrix. [f4]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Emerging 24 /40 Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 The pain (memorized PII, jailbreak weakness, hallucination triggers, and bias at the weight level) is corroborated by the DeepMind case study and DeepSeek and Llama press metrics, but the buyer persona is unsettled across ML, security, and application teams, so the problem is grounded yet not pinned to a specific quantified buyer. [s1, s5, s6]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 4/5 The platform detects model weaknesses and removes the parameters behind them without full retraining, and a Google DeepMind case study supplies an external validation point, a 74.47% cut in successful attacks on a Gemma model while preserving utility benchmarks. Deep public technical documentation is thin, holding this at 4 rather than 5. [s3, s5, s1]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 The enabler is real (tightening data-deletion regulation and rising jailbreak and leakage incidents since 2023) and labs like DeepSeek, Llama, and Gemma are public targets, but buyer-side budget signals are still forming, so demand is indirect rather than the multiple corroborated signals a higher score needs. [s5, s8, s7]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 The founders are elite in pedigree (a Technion Dean of Computer Science as chief scientist, a Rhodes Scholar repeat founder as CEO), but the prior build (Worqly) sits in fintech rather than the domain and no sustained in-domain publication record appears under Hirundo, so the team holds at credible rather than corroborated. [s2, s6]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 2/5 Hirundo names customers only by sector, finance, government, healthcare, and defense, and shows an NVIDIA, NEC, and Intel logo wall it does not tie to paying deployments. No named reference customer appears in the public record, so traction sits at the design-partner level even after a modest indirect-signal allowance for reputable VC backing. [s7, s1, s6]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 An $8M seed led by Maverick Ventures Israel is sized to a roughly 19-person research-led team, and visible output, the DeepMind collaboration and a shipping platform, matches the raise. The round is recent enough that capital-efficient growth is plausible but not yet proven at scale. [s9, s6, s5]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Machine unlearning is a vendor-coined label that maps cleanly to AI model security, but buyers have no established budget line for it and may file it under model risk, MLOps, or compliance. The concept is legible to technical buyers yet not an analyst category they place without coaching. [s1, s8, s7]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 The unlearning technique rests on applied research that a model provider or platform vendor could fold into its own training pipeline, the same absorbable-technique exposure the AI-model-security pure-plays carry. The research lead and academic team supply some friction. [s5, s8, s2]
Business Risks Model providers such as OpenAI, Anthropic, and Google could build unlearning into their own training pipelines, absorbing Hirundo's core technique as a feature of the model lifecycle…
  • Model providers such as OpenAI, Anthropic, and Google could build unlearning into their own training pipelines, absorbing Hirundo's core technique as a feature of the model lifecycle.
  • Hirundo discloses no named paying customer, so its commercial traction could prove far thinner than its technical validation suggests.
  • Machine unlearning has no established enterprise budget line, and buyers could keep routing the spend to retraining, guardrails, or governance tools instead.
  • Closed-weight API models are handled by Hirundo's inference-time Prism mechanism rather than weight editing, so the deepest remediation applies only to open-weight models a customer can modify.
  • As a roughly 19-person seed-stage company, Hirundo could struggle to fund an enterprise go-to-market against larger AI-security rivals before its $8M seed runs down.
Problem & Market Hirundo targets a failure that retraining and guardrails handle badly, a model that has already learned something it should not know…

Hirundo targets a failure that retraining and guardrails handle badly, a model that has already learned something it should not know. Memorized personal data, jailbreak susceptibility, hallucination triggers, and bias all live in the model's weights, and the company argues that filtering outputs or adding guardrails masks these without removing the root cause. The buyer is the team that owns model risk and cannot afford to retrain from scratch every time a problem surfaces.

The problem is corroborated beyond Hirundo's own marketing. A Google DeepMind case study documents weight-level adversarial weaknesses in a production-class model, and press coverage cites measured reductions in bias on DeepSeek-R1 and in successful prompt injections on Llama. These are external reference points a buyer can check, which lifts the problem above a vendor-asserted pain.

Who carries this budget is the open question. AI security spans ML platform teams, security organizations, and application teams, and none has a settled mandate for model-level remediation. Hirundo describes regulated sectors, finance, government, healthcare, and defense, as the buyers feeling the pain first, where a regulator or a breach can force data out of a deployed model. [s1, s5, s7]

Product Capabilities Hirundo's platform finds the parameters responsible for an unwanted behavior and modifies them, removing what the model learned without retraining it…

Hirundo's platform finds the parameters responsible for an unwanted behavior and modifies them, removing what the model learned without retraining it. The company contrasts this with guardrails and output filtering that leave the underlying model untouched, and CEO Ben Luria describes the approach as a form of model neurosurgery that excises the source of a behavior. The platform covers generative and non-generative systems, extending to computer vision and other model types.

A third-party result is the strongest evidence for the capability. A Google DeepMind case study reports that Hirundo's weight-level hardening of a Gemma model cut successful attacks by about three-quarters while preserving the model's utility-benchmark scores, addressing the usual fear that aggressive hardening degrades general performance. Few seed-stage AI security companies carry validation from a frontier lab.

The mechanism differs by model type. Hirundo edits the weights directly for open-weight models such as Llama and Mistral, and for closed-weight API models like Gemini and ChatGPT it changes behavior at inference time through a separate mechanism it calls Prism. Public technical documentation is thin, so a buyer evaluates the depth through the DeepMind result and press metrics rather than through detailed architecture pages. [s5, s8, s1]

Competitive Positioning Hirundo positions machine unlearning as a new discipline it helped define, and presents its product as an early entrant in that category…

Hirundo positions machine unlearning as a new discipline it helped define, and presents its product as an early entrant in that category. The framing is ambitious and legible to technical buyers, but it asks the market to adopt a category analysts have not yet codified, competing for attention with adjacent labels like AI red teaming, model security, and AI governance.

The competitive frame is the AI-model-security cluster plus the model providers themselves. Pure-play peers such as TrojAI, HiddenLayer, and Mindgard attack overlapping model-risk problems from red teaming and runtime angles, while the platform vendors that host models can bundle remediation into their stacks. Hirundo's distinction is the weight-level removal step rather than detection or runtime filtering.

The structural risk sits under the differentiation. The same model providers Hirundo hardens, including the labs it demonstrated results on, are the parties best placed to build unlearning into their own training pipelines. Hirundo's positioning bet is that unlearning becomes a named requirement buyers ask for directly, before a provider folds it into the model lifecycle. [s1, s8, s5]

Go-to-Market & Traction Hirundo's traction evidence is heavier on validation than on disclosed customers…

Hirundo's traction evidence is heavier on validation than on disclosed customers. The Google DeepMind collaboration is the clearest external signal, a supply-side proof that the method works on a real model rather than a record of who pays for it. Press materials add measured outcomes on DeepSeek and Llama and a homepage logo wall featuring NVIDIA, NEC, and Intel.

Named paying customers do not appear in the public record. The company describes deployments only by sector, finance, government, healthcare, and defense, and presents testimonials from individuals at Intel Ignite and Taranis rather than disclosed enterprise references. The logo wall reads as trusted-by recognition without a stated paying relationship, so a buyer requiring customer proof finds sector descriptions rather than references.

The funding signal partly offsets the thin named traction. A $8M seed led by Maverick Ventures Israel with several AI-focused investors is a credible indirect endorsement, and the DeepMind work suggests pilots with serious counterparties. The traction is early-stage and substantially undisclosed, which the gtm_proof score reflects. [s5, s7, s9]

Team & Credibility Hirundo pairs senior academic founders with a repeat entrepreneur at the helm…

Hirundo pairs senior academic founders with a repeat entrepreneur at the helm. Chief Scientist Oded Shmueli is an Emeritus Professor who was Dean of Computer Science and Executive VP at the Technion, with prior research experience at IBM, HP, and AT&T. The academic depth is unusual for a seed-stage company and directly relevant to the model-internals problem Hirundo works on.

The operating leadership carries its own record. CEO Ben Luria is a Rhodes Scholar and former Visiting Fellow at Oxford who previously founded and led the fintech startup Worqly and the nonprofit ScholarsIL. CTO Michael Leybovich is a Technion computer-science researcher and a former award-winning R&D officer, supplying the engineering lead for the platform.

The credibility basis is verifiable pedigree rather than a sustained publication record under the Hirundo name. The founders' Technion standing and the DeepMind result are the public signals a buyer can check, which place the team above a typical early roster without yet a multi-year stream of company-branded research. [s2, s6, s5]

Trust Readiness Hirundo's trust argument leans on a deployment model that keeps customer data and models inside the customer's environment…

Hirundo's trust argument leans on a deployment model that keeps customer data and models inside the customer's environment. The company states that its solution runs as an API or platform with deployment via SaaS, VPC, or air-gapped on-premises, which answers the data-exposure question a buyer raises first when a product operates on proprietary model weights. For a tool with this level of access, local deployment is the central trust point.

The company asserts SOC 2 on its own site but offers no inspectable evidence. The Data QA page calls the product a SOC 2 certified solution, yet no trust center is published. Probes of the trust and security subdomains and the /trust and /security paths returned nothing inspectable, and no badge or downloadable report appears in the footer. The attestation is self-displayed rather than verifiable.

The readiness gap is verifiable evidence, not an absent program. A procurement team would request the SOC 2 report and a current bridge letter directly, and would look for an ISO 27001 or ISO 42001 attestation that the public record does not show. SOC 2 alone is table stakes a serious rival can also earn, so it gives baseline assurance rather than a procurement advantage. [s4, s11, s1]

Competitors TrojAI, HiddenLayer, Mindgard, Protect AI…
Company Relationship Note Compare
TrojAI competes with Secures AI models and agents through build-time red teaming and a runtime firewall, overlapping on model-level risk discovery.
HiddenLayer competes with Detects and defends against attacks on machine learning models, competing on the model-security problem from a detection angle.
Mindgard competes with Runs automated AI red teaming to surface model vulnerabilities, an adjacent approach to the weaknesses Hirundo removes.
Protect AI adjacent Secures the ML supply chain and model lifecycle, overlapping on training-data and model integrity rather than weight-level unlearning.

Add analyzed competitors to compare them side by side with Hirundo.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Exposed 12 /21 Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software. pivot urgently

The model providers whose systems Hirundo hardens are also positioned to fold unlearning into their own training. Removing the specific weights behind a behavior without degrading the model is hard applied research, reported in a DeepMind-hosted case study. That depth is the part a rival cannot copy quickly. Hirundo holds little else a competitor cannot match. The documented offer is software with no managed-accountability service in the fetched record, and it names no proprietary dataset a rival could not build. It calls its product SOC 2 certified but publishes no inspectable report, and the cited record identifies no regulation or certification mandating it. The durable edge today is being early and academically credible, not owning something others cannot obtain.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 The documented offer is an API and platform that produce a cleaned model, with no managed judgment-and-accountability outcome in the fetched record, the software artifact a 1 reflects.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Unlearning is a remediation step a team runs against a model rather than an embedded daily workflow, so it builds some friction once wired into an MLOps process but reabsorbs little when dropped.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 Hirundo asserts SOC 2 on its site with no inspectable trust center or report, and the cited record identifies no regime mandating the product, below a federal-procurement or certification-mandated posture.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Identifying the specific weights that encode a behavior and excising them without degrading utility is hard applied-ML research, with a DeepMind-hosted case study reporting Hirundo's strongest public result on a Gemma model.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 The buyer is the enterprise running model risk in regulated sectors, a credible identity, but the line's own named proof is sector descriptions and a logo wall rather than disclosed paying references.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 Weight-level unlearning is an offline remediation that produces a cleaned model, and the inference-time Prism path sits in the serving flow, but neither is documented as infrastructure other systems depend on to run, an application-layer function that scores at 2.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 The advantage is a publicly described engineering approach with no named non-public corpus or cross-customer flywheel in fetched sources, an asset a funded rival or model provider could rebuild.
Strategic Market Segmentation Hirundo sells to the team that owns risk in a deployed AI model and cannot retrain it cheaply…

Hirundo sells to the team that owns risk in a deployed AI model and cannot retrain it cheaply. The company frames the buyer across AI and product teams, security and privacy teams, and frontier AI labs, three audiences that share the problem of a model carrying data or behavior it should not. The common thread is a model already in production where retraining is too slow or expensive to be the fix.

The segment spans regulated industries where the pain bites first. Press materials name finance, government, healthcare, and defense as the sectors using the product, and the platform covers both generative and non-generative systems, which extends the reach to computer vision and other model types beyond large language models. That breadth widens the addressable base but blurs which buyer is the beachhead.

The buyer identity is credible but the named demand is thin. Hirundo describes deployments by sector rather than by company, so the segment is defined by where the problem is acute rather than by a disclosed roster. Whether the ML platform owner, the security organization, or the privacy team holds the budget is unsettled, which is a live risk for a young company picking its first buyer to win.

Product Capabilities & AI Advantages Hirundo's capability is weight-level removal rather than detection or filtering…

Hirundo's capability is weight-level removal rather than detection or filtering. The platform identifies the parameters responsible for a behavior and modifies them, removing what the model learned without full retraining, which the company contrasts with guardrails and output filters that leave the model untouched. It removes memorized personal data, hallucination triggers, bias, and jailbreak susceptibility at the model level.

Google DeepMind hosts a case study on its Gemmaverse pages reporting Hirundo's own measurements: weight-level hardening of a Gemma model cut successful attacks by about three-quarters while preserving its utility-benchmark scores, and press materials add measured outcomes on DeepSeek-R1 and Llama. A frontier lab hosting the work is a notable signal for a seed-stage company, though the measurements are Hirundo's, and the result addresses the fear that hardening degrades general performance.

The advantage is genuine engineering, not a data asset that compounds. For open-weight models such as Llama and Mistral, Hirundo edits the weights directly, and for closed-weight API models like Gemini and ChatGPT it changes behavior at inference time through a separate mechanism it calls Prism. No proprietary corpus or accumulating dataset appears in fetched sources, so the edge is applied research and craft that a funded rival or a model provider could rebuild over time.

Sales Engagement & Go-to-Market Hirundo's go-to-market leads with proof of method over a customer roster…

Hirundo's go-to-market leads with proof of method over a customer roster. The company routes prospects to a book-a-demo and early-access flow, and its most visible external signal is the DeepMind-hosted Gemmaverse case study, a platform feature rather than a paying reference. A homepage logo wall featuring NVIDIA and TCS sits alongside testimonials from individuals at Intel Ignite and Taranis.

Named paying customers stay undisclosed. Hirundo describes deployments only by sector, finance, government, healthcare, and defense, so the public evidence is who has validated the technology rather than who pays for it. For a buyer that requires named references, the materials offer sector descriptions and individual testimonials, including one from Intel Ignite's CTO, rather than a disclosed enterprise deployment.

The motion is early and research-led, backed by a recent seed round led by Maverick Ventures Israel. That raise funds the build-out, and the founders' academic standing plus the DeepMind-hosted case study are the credibility the sales motion leans on. The open question is whether Hirundo can convert technical credibility into named, repeatable enterprise deals before the seed capital runs down.

Pricing Model Hirundo does not publish pricing in fetched sources, so the charged unit and list price stay private…

Hirundo does not publish pricing in fetched sources, so the charged unit and list price stay private. The company routes buyers to a demo and early-access flow, the posture of a vendor selling negotiated deals rather than self-serve, which fits the regulated-enterprise buyer it describes. The absence withholds the budget-anchoring signal some peers publish openly.

The value meter the product implies is the model or the remediation, not the seat. Unlearning is a per-model, per-issue operation run against specific models, so a natural unit is models processed or remediation runs rather than user seats, though the public materials do not state which. For a security team that is small while model counts grow, a per-model meter would align price with value better than per-seat.

The belief under the hidden price is that buyers pay for model risk removed rather than for tooling. Confirming the unit and whether the work is metered would require a sales conversation, which the early-access posture signals is the intended path. A compliance-driven buyer may also pay for audit-ready evidence that data was removed, a value Hirundo's regulatory framing implies but the public pricing does not name.

Product Delivery & Operations Hirundo delivers as software the customer operates, available across deployment modes that keep models in place…

Hirundo delivers as software the customer operates, available across deployment modes that keep models in place. The company states that the solution runs as an API or platform with deployment via SaaS, VPC, or air-gapped on-premises, which lets a security-conscious buyer run the remediation without sending proprietary model weights to a vendor cloud. The air-gapped option targets the defense and regulated buyers it names.

For open-weight models the delivery is a remediation step rather than an always-on control. Editing the weights produces a cleaned version, so the operational footprint is a processing job and an evaluation of the result rather than an inline component that inspects every live request. The Prism path for closed-weight API models works at inference time instead, so that route carries the operational profile of an inline component while the weight-editing path stays a processing job.

The documented offer is a platform and an API across those deployment modes, and the fetched pages describe no managed-service tier, analyst layer, or accountability commitment, so on the reviewed record the customer owns the workflow and the verification. Published uptime and support SLAs do not surface in fetched pages either.

Earning Customers' Trust Hirundo's trust argument depends on keeping models and data inside the customer's environment…

Hirundo's trust argument depends on keeping models and data inside the customer's environment. The SaaS, VPC, and air-gapped deployment options answer the data-exposure question a buyer raises first when a product operates directly on proprietary model weights, and for a tool with this level of access, local deployment is the central assurance the company offers.

The compliance posture is asserted but not inspectable. The Data QA page calls the product a SOC 2 certified solution, yet no trust center is published. Probes of the trust and security subdomains and the /trust and /security paths returned nothing inspectable, and no badge or downloadable report appears in the footer. The attestation is self-displayed rather than backed by an inspectable report.

The gap is verifiable evidence, not an absent program. A procurement team would request the SOC 2 report and a current bridge letter directly, and would look for an ISO 27001 or ISO 42001 attestation the public record does not show. SOC 2 alone is assurance a serious rival can also earn, so it is a credibility floor rather than a barrier that wins the deal.

Platform Strategy & Ecosystem Positioning Hirundo operates on the models other platforms produce rather than owning a platform of its own…

Hirundo operates on the models other platforms produce rather than owning a platform of its own. It works across open-weight models such as Llama and Mistral and demonstrated results on Gemma and DeepSeek, positioning itself as a remediation layer that sits below the application and above the base model. The Google DeepMind-hosted Gemmaverse case study is the clearest ecosystem tie, a platform feature by a model provider rather than a distribution channel.

The ecosystem dependence cuts two ways. Hirundo edits open-weight models directly and addresses closed-weight API models like Gemini and ChatGPT through its inference-time Prism mechanism, so its reach grows as more models of either kind are deployed. The direct weight-editing path still depends on access to model weights, which open-weight ecosystems grant and closed providers withhold.

The deeper exposure is that the model providers are also the natural competitors. The labs whose models Hirundo cleans are the parties best placed to build unlearning into their own training and release pipelines, turning an ecosystem partner into a competitor. Hirundo's position holds only while removal stays a separate step buyers want from an independent vendor.

Team & Execution Capability Hirundo pairs senior academic founders with a repeat entrepreneur…

Hirundo pairs senior academic founders with a repeat entrepreneur. Chief Scientist Oded Shmueli is an Emeritus Professor who was Dean of Computer Science and Executive VP at the Technion, with earlier research experience at IBM, HP, and AT&T, a depth directly relevant to the model-internals problem the company works on. The academic standing is unusual for a company at this stage.

The operating leadership carries its own record. CEO Ben Luria is a Rhodes Scholar and former Visiting Fellow at Oxford who previously founded and led the fintech startup Worqly and the nonprofit ScholarsIL, and CTO Michael Leybovich is a Technion computer-science researcher and former award-winning R&D officer. The pairing puts a commercial operator and an engineering lead alongside the research founder.

The credibility basis is verifiable pedigree and a frontier-lab result rather than a sustained company-branded publication record. A buyer can check the founders' Technion standing and the DeepMind work today, which places the team above a typical early roster, while a multi-year stream of Hirundo research that would deepen the moat is not yet in evidence.

Sources

Company Detail Sources (4)
Id Source Tier Accessed
f1 https://www.hirundo.io/ official 2026-06-25
f2 PR Newswire: Hirundo Raises $8M Seed to Make AI Forget Hallucinations, Biases and Vulnerabilities press 2026-06-25
f3 SecurityWeek: Hirundo Raises $8 Million to Eliminate AI's Bad Behavior press 2026-06-25
f4 AI Defense Matrix Catalog: Hirundo official 2026-06-25
Profile Analysis Sources (11)
Id Source Tier Accessed
s1 Hirundo homepage: Machine Unlearning Platform
“Machine Unlearning surgically removes risky knowledge and behavior from trained LLMs at the model level, without retraining.”
official 2026-06-25
s2 Hirundo about page (founders and roles)
“Ben Luria CEO and Co-Founder Rhodes Scholar. Michael Leybovich CTO and Co-Founder Previously a graduate CS researcher at the Technion. Prof. (Emeritus) Oded Shmueli Chief Scientist and Co-Founder Previously the Dean of Computer Science and Executive VP at the Technion.”
official 2026-06-25
s3 Hirundo for AI teams: Detect and fix risks in your AI models (model coverage FAQ)
“Open-weight models (both OSS base models and fine-tuned variants), where we directly edit the model's weights. Closed-weight/API models (like Gemini or ChatGPT), where we use a separate mechanism called Prism relying on log probs to change model behavior at inference time.”
official 2026-06-25
s4 Hirundo Data QA page (SOC 2 self-claim, SaaS / VPC / air-gapped deployment)
“Our SOC-2 certified solution runs as an API or platform, with deployment available via SaaS, VPC, or air-gapped on-premises.”
official 2026-06-25
s5 Google DeepMind Gemmaverse case study on Hirundo (weight-level hardening of Gemma 4 E4B, attack-success-rate results)
“Hirundo's weight-optimization process achieved a 74.47% reduction in successful attacks relative to the base model, resulting in a final Attack Success Rate (ASR) of 4.78%.”
research 2026-06-25
s6 PR Newswire: Hirundo Raises $8M Seed (founders, round, sector applications)
“Hirundo - specialists in machine unlearning, has raised an $8M seed funding round, led by Maverick Ventures Israel, with participation from SuperSeed, Alpha Intelligence Capital, Tachles VC, AI.FUND and Plug and Play Tech Center.”
press 2026-06-25
s7 SecurityWeek: Hirundo Raises $8 Million to Eliminate AI's Bad Behavior
“The product supports both generative and non-generative systems and is used by organizations across the finance, government, healthcare, and other sectors.”
press 2026-06-25
s8 SiliconANGLE: Hirundo raises $8M to make AI forget bad data (model coverage, gated-model roadmap)
“it can do this for both open-source models such as Llama and Mistral, and soon it will also be able to do the same for gated models such as OpenAI's GPT and Anthropic PBC's Claude.”
press 2026-06-25
s9 Calcalist: Hirundo raises $8M in Seed funding to help AI forget its mistakes
“The round was led by Maverick Ventures Israel, with participation from SuperSeed, Alpha Intelligence Capital, Tachles VC, AI.FUND, and Plug and Play Tech Center.”
press 2026-06-25
s10 AI Defense Matrix Catalog: Hirundo (AI Model primary, Training Data secondary)
“Machine unlearning that removes memorized PII, jailbreak vulnerabilities, and biased behaviors from trained models without retraining.”
official 2026-06-25
s11 Hirundo Data QA page, SOC 2 self-claimed, no inspectable trust center (/trust and /security return 404, trust. and security. subdomains do not resolve)
“Our SOC-2 certified solution runs as an API or platform, with deployment available via SaaS, VPC, or air-gapped on-premises.”
official 2026-06-25
Deep-Dive Sources (11)
Id Source Tier Accessed
s1 Hirundo homepage: Machine Unlearning Platform
“Machine Unlearning surgically removes risky knowledge and behavior from trained LLMs at the model level, without retraining.”
official 2026-06-25
s2 Hirundo about page (founders and roles)
“Ben Luria CEO and Co-Founder Rhodes Scholar. Michael Leybovich CTO and Co-Founder Previously a graduate CS researcher at the Technion. Prof. (Emeritus) Oded Shmueli Chief Scientist and Co-Founder Previously the Dean of Computer Science and Executive VP at the Technion.”
official 2026-06-25
s3 Hirundo for AI teams: Detect and fix risks in your AI models (model coverage FAQ)
“Open-weight models (both OSS base models and fine-tuned variants), where we directly edit the model's weights. Closed-weight/API models (like Gemini or ChatGPT), where we use a separate mechanism called Prism relying on log probs to change model behavior at inference time.”
official 2026-06-25
s4 Hirundo Data QA page (SOC 2 self-claim, SaaS / VPC / air-gapped deployment)
“Our SOC-2 certified solution runs as an API or platform, with deployment available via SaaS, VPC, or air-gapped on-premises.”
official 2026-06-25
s5 Google DeepMind Gemmaverse case study on Hirundo (weight-level hardening of Gemma 4 E4B, attack-success-rate results)
“Hirundo's weight-optimization process achieved a 74.47% reduction in successful attacks relative to the base model, resulting in a final Attack Success Rate (ASR) of 4.78%. Crucially, this hardening strictly preserved the model's high performance across standard utility benchmarks.”
research 2026-06-25
s6 PR Newswire: Hirundo Raises $8M Seed (founders, round, metrics, sector applications)
“When deployed, Hirundo's solution has led to the removal of up to 70% of biases - as demonstrated in their work on DeepSeek-R1, as well as up to 55% reduction of hallucinations and 85% decrease in successful prompt injections, showcased with the company's work on Llama.”
press 2026-06-25
s7 SecurityWeek: Hirundo Raises $8 Million to Eliminate AI's Bad Behavior
“The product supports both generative and non-generative systems and is used by organizations across the finance, government, healthcare, and other sectors.”
press 2026-06-25
s8 SiliconANGLE: Hirundo raises $8M to make AI forget bad data (model coverage, gated-model roadmap)
“it can do this for both open-source models such as Llama and Mistral, and soon it will also be able to do the same for gated models such as OpenAI's GPT and Anthropic PBC's Claude.”
press 2026-06-25
s9 Calcalist: Hirundo raises $8M in Seed funding (round, investors, founded 2023)
“The round was led by Maverick Ventures Israel, with participation from SuperSeed, Alpha Intelligence Capital, Tachles VC, AI.FUND, and Plug and Play Tech Center. Founded in 2023, Hirundo is pioneering a discipline known as machine unlearning.”
press 2026-06-25
s10 AI Defense Matrix Catalog: Hirundo (AI Model primary, Training Data secondary)
“Machine unlearning that removes memorized PII, jailbreak vulnerabilities, and biased behaviors from trained models without retraining.”
official 2026-06-25
s11 Hirundo Data QA page, SOC 2 self-claimed, no inspectable trust center (/trust and /security return 404, trust. and security. subdomains do not resolve)
“Our SOC-2 certified solution runs as an API or platform, with deployment available via SaaS, VPC, or air-gapped on-premises.”
official 2026-06-25

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.