Humanbound

Security for AI also known as AI AND ME IDIOTIKI KEFALAIOUCHIKI ETAIREIA P.C.

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Last updated 2026-09-23

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Humanbound sells continuous security testing for companies building AI agents. Its free, open-source engine sends attacks such as prompt injection to an agent’s API endpoint and scores the agent’s security. A companion firewall, which Humanbound labels a preview release, blocks prompt injection and learns from each agent’s test results. Paid hosted plans start at 29 euros a month, with an Enterprise plan for regulated industries. Humanbound’s named customers are Eurobank, Eurolife FFH, Viva.com, OWASP and Uni.Fund. Startupper.gr reported that, after a funding round, Humanbound works with large banks and defense organizations. A customer replacing Humanbound would re-create each agent’s test scope, reconnect build pipelines and security monitoring tools, and move its findings history.

Sourced Details

Description Humanbound builds open-source software that runs adversarial tests against AI agents over their API endpoints, scores each agent's security posture, and adds a runtime firewall that screens user input before it reaches the agent. [f1]
HQ Ioannina, Greece [f2]

Products

Product What it does
Humanbound Adversarial and behavioral testing engine, CLI and hosted platform for AI agents, with posture scoring, findings tracking, SIEM webhooks and an open-source runtime firewall.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Coding and Orchestration Tools AI coding tools and agentic orchestration tools on user devices, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Traffic Paths to external and self-hosted AI services, MCP tool channels, agent-to-agent calls, model-registry downloads, and egress to unapproved AI services. AI gateways, LLM routers, and MCP gateways steer traffic along those paths. The steering decisions and their inputs belong here too: routing policies, MCP server registries, and agent naming and discovery services.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, an AI bill of materials (AIBOM), and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Humanbound runs OWASP-aligned attack campaigns against a live AI agent and its tools, grades the conversations into a posture score, and ships a firewall that screens user input before the agent sees it. These capabilities are mapped to the AI Defense Matrix. [f3]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Emerging 23 /40 Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Humanbound names its buyers by plan, from developers to regulated industries, and states the problem as untested agents exposed to prompt injection, jailbreaks and tool abuse (s2, s3). Startupper.gr describes risks from autonomous agents, including indirect prompt injection, without quantifying their impact (s16). [s2, s3, s16]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 The documentation details endpoint-driven multi-turn attacks, judge-model grading, the ASCAM drift engine and a four-tier firewall, and Humanbound's own Apache 2.0 code implements them (s3, s5, s4, s19). No independent evaluation, benchmark or customer technical write-up appears in the cited sources. [s3, s4, s5, s19]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 The enabler is AI agents gaining autonomy, which Startupper.gr's September 2026 report ties to indirect prompt injection (s16). Buyer-side demand is indirect, based on SysteCom's May 2026 cooperation announcement (s11). [s11, s12, s14, s16]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 Endeavor Greece and Typos-i.gr independently name Dimitris Gerogiannis as co-founder and co-CEO, and the company blog names Kostas Siabanis as co-founder. Endeavor selected the company for its AI-native cohort from more than 240 applications, and the team ships its own open-source adversarial testing engine with 16 releases. That is verifiable relevant operating experience and outside selection, without a prior build, exit or sustained research record, which is rung 3. [s12, s17, s18, s4]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 Humanbound names Eurobank, Eurolife FFH and Viva.com among the organizations under its homepage "Trusted by" heading, and SysteCom announced a cooperation in May 2026 (s1, s11). The cited Startupper.gr account describes relationships with banks and defense organizations without quantifying their scale (s16). [s1, s11, s16]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 2/5 Humanbound ships open-source releases and sells hosted plans from 29 to 249 euros a month (s4, s2). Startupper.gr reports a recent funding round without an amount, date or investor, so the size of the capital behind that output is unknown (s16). [s2, s4, s16]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Humanbound fits AI agent security testing, and Startupper.gr's event coverage and SysteCom's partner announcement both describe it as AI security (s16, s11). The company explains its placement against penetration testing on its own homepage (s1). [s1, s11, s16]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 Each agent's test failures become firewall rules and train a classifier on that agent's logs, and CI and SIEM hooks tie the product into existing workflows (s4, s5, s3, s23). A rival could reproduce the integrations and train a classifier on the customer's own logs (s3, s5, s23). [s3, s4, s5, s23]
Business Risks The runtime firewall is labelled a preview at version 0.2.x whose interfaces may change before 1.0, while the testing engine is at version 2.9.0, so the runtime half of the offering is the less mature one…
  • The runtime firewall is labelled a preview at version 0.2.x whose interfaces may change before 1.0, while the testing engine is at version 2.9.0, so the runtime half of the offering is the less mature one.
  • The firewall's first detection tier runs pre-trained models from other providers, such as DeBERTa models, Azure Content Safety and Lakera, so part of Humanbound's runtime defense depends on detectors it does not build.
Problem & Market Humanbound addresses the risk that an AI agent exposed to users can be manipulated through prompt injection, jailbreaks, tool abuse or data exfiltration before anyone has tested it…

Humanbound addresses the risk that an AI agent exposed to users can be manipulated through prompt injection, jailbreaks, tool abuse or data exfiltration before anyone has tested it. Its homepage frames the answer as testing before launch, protection at runtime, and monitoring for regressions as models and configurations change.

Humanbound's pricing page names its buyers by plan. The free plan is for developers evaluating agent security. The Team plan serves organisations running continuous security operations, and the Enterprise plan serves regulated industries with custom deployment, compliance and integration requirements.

Press coverage describes the same risk. A September 2026 Startupper.gr report on a regional technology event places the company in AI security, safety and assurance. It cites the growing autonomy of AI agents, with indirect prompt injection as its example. [s1, s2, s3, s16]

Product Capabilities Humanbound tests a running agent over its own API rather than inspecting the model alone…

Humanbound tests a running agent over its own API rather than inspecting the model alone. The documentation describes pointing the engine at an agent's endpoint, defining or auto-extracting its scope, and receiving findings mapped to OWASP LLM and Agentic AI categories. Attacks run in single-turn, multi-turn and agentic modes, a judge model evaluates the conversations, and each agent receives a posture score from 0 to 100 with a letter grade.

A continuous-assurance engine the company calls ASCAM repeats that testing over time. The documentation says it borrows from coverage-guided fuzzing, weighs nine signals each cycle, tracks untested attack surface and flags statistical drift in agent behavior. Every finding, posture change and drift event can be sent as a signed webhook to a SIEM or ticketing system, including an alert when a previously fixed finding reappears.

The Humanbound Firewall is the runtime component. It evaluates each user message in up to four tiers and escalates only when an earlier tier cannot decide. Sanitization and pre-trained attack detectors come first, then a classifier trained on the customer's own test logs, and an LLM judge runs only when the cheaper tiers are uncertain. Its repository labels the firewall a preview release at version 0.2.x whose interfaces may change before 1.0.

The testing engine, SDK and firewall are published under the Apache 2.0 license. The main repository shows 155 stars, 15 forks and 12 contributors, with version 2.9.0 released in August 2026. [s1, s3, s4, s5, s19, s23]

Competitive Positioning Humanbound positions continuous testing against the point-in-time penetration test…

Humanbound positions continuous testing against the point-in-time penetration test. Its homepage says a penetration test yields a report at one moment, while Humanbound keeps a posture score that updates as agents, models and configurations change.

The company pairs testing with its own runtime defense. The repository describes a loop in which failed tests become firewall rules, and the firewall's agent-specific tier is trained on the same test logs. Humanbound maps each finding to the EU AI Act, NIST AI RMF or the OWASP Top 10 lists, and its homepage says customers can export compliance evidence packages.

Outside descriptions place Humanbound in the same frame. SysteCom, an Athens-based provider of cybersecurity and infrastructure solutions, describes Humanbound as an AI security platform focused on testing, governing and protecting enterprise AI deployments. [s1, s4, s5, s11]

Go-to-Market & Traction Humanbound names its customers on its homepage, where a "Trusted by" heading lists Eurobank, Eurolife FFH, Viva.com, OWASP and Uni.Fund…

Humanbound names its customers on its homepage, where a "Trusted by" heading lists Eurobank, Eurolife FFH, Viva.com, OWASP and Uni.Fund. SysteCom announced a cooperation with Humanbound in May 2026, and the two companies offer an executive guide to AI security written for CISOs.

Startupper.gr's September 2026 report on a regional event, where Dimitris Gerogiannis spoke for the company, says Humanbound works with large banks and defense organizations. Startupper.gr does not identify those organizations in the cited article.

The commercial motion runs from free software to paid plans. The engine, CLI and firewall are free and open source. The hosted platform sells Pro at 29 euros a month, Team at 249 euros a month and a custom Enterprise tier. Humanbound says an enterprise-wide first assessment takes about two weeks from kickoff to delivered posture scores. [s1, s2, s11, s16]

Team & Credibility Humanbound's leadership is publicly identified…

Humanbound's leadership is publicly identified. Endeavor Greece lists Dimitris Gerogiannis as co-founder and co-CEO for product and technology, and Typos-i.gr names him co-founder and co-CEO in its report on a discussion about technology in Ioannina. The company blog identifies Kostas Siabanis as a co-founder.

The captured sources confirm the founders' current roles and describe no earlier companies, product builds or exits for either of them. The main GitHub repository lists 12 contributors.

The company was selected for Greece's first national AI accelerator, which Endeavor Greece ran with OpenAI and the Hellenic Government. CNN Greece reports that 21 startups were chosen from 240 applications, and Humanbound is on its list. [s4, s12, s14, s17, s18]

Trust Readiness Humanbound offers three deployment models…

Humanbound offers three deployment models. The SaaS service stores data in the EU North Europe region on SOC 2 compliant infrastructure. An on-premises option installs inside the customer's network, and a private cloud option runs a dedicated instance in the customer's Azure or AWS tenant that the Humanbound team manages.

The local engine can run fully offline against Ollama and other self-hosted models, so a test can run without data leaving the customer's environment.

No attestation for Humanbound itself appears in the captured sources, so the SOC 2 statement covers only its hosting. A probe of humanbound.ai/security returned a not-found page, and neither the trust nor the security subdomain resolved. [s1, s22, s24]

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 13 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

Humanbound offers free open-source testing software and paid hosted plans, and regulated enterprises are the buyers its Enterprise plan is built for. The product is technically demanding, spanning multi-turn attack generation, judge-model grading, drift detection and a firewall whose classifier learns from each agent's own test logs. A customer replacing Humanbound with another product would re-create its per-agent scope files, reconnect build pipelines and security monitoring tools, and move its findings history.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Humanbound offers a free open-source engine and firewall plus paid hosted plans (s2, s4).
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Replacing Humanbound with another product would mean re-creating per-agent scope files and CI and SIEM wiring and moving the findings history (s3, s23). The open-source firewall and its classifier stay usable on their own (s19), so these are integrations and learned workflows, and the cited record does not size the migration.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 No attestation held by Humanbound appears in the captured sources, and the /security probe returned a not-found page (s24). SOC 2 compliant hosting describes the infrastructure provider, and framework mappings are a product feature, so neither blocks a replacement (s22, s1).
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 The product combines multi-turn and agentic attack generation, judge-model grading, a fuzzing-style decision engine with statistical drift detection, and a firewall with a per-agent trained classifier (s3, s5, s19). That is ML and real-time work requiring specialized expertise.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 Humanbound builds its Enterprise tier for regulated industries and names Eurobank, Eurolife FFH and Viva.com under its "Trusted by" heading (s2, s1). SysteCom cites DORA, NIS2 and EU AI Act reporting, so the regulated-enterprise buyer class is credibly addressed alongside a free developer plan (s11).
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 The firewall screens each user message before the agent sees it, but developers call the library from the agent's code and choose how to act on its verdict, and the repository labels it a preview (s1, s5, s19). Testing and monitoring run beside the agent, so Humanbound is a platform with application features.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 The firewall's Tier 2 classifier is trained on each customer's own test logs, and the customer provides the model (s5, s19). No cited source names a dataset, content licence or patent that Humanbound retains across customers, and the engine code is public under Apache 2.0 (s4).
Strategic Market Segmentation Humanbound sells to two segments through one product…

Humanbound sells to two segments through one product. Developers get the open-source engine, CLI and firewall free, with no account needed for local use. Organizations get a hosted platform whose plans run from a free tier through Pro and Team to a custom Enterprise tier described as built for regulated industries.

The regulated segment appears in several places. The homepage names Eurobank, Eurolife FFH and Viva.com among the organizations under its "Trusted by" heading. SysteCom describes compliance reporting aligned with DORA, NIS2, ISO 42001 and the EU AI Act. Startupper.gr's account of the founder's September 2026 presentation says the company works with large banks and defense organizations.

Product Capabilities & AI Advantages Humanbound's core capability is adversarial testing of a live agent…

Humanbound's core capability is adversarial testing of a live agent. The engine runs multi-turn conversations against the agent's real endpoint, probes tool use and scope boundaries, and scores results against the customer's security policy. A judge model grades each conversation, and the ASCAM engine repeats campaigns, weighing nine signals per cycle and flagging behavioral drift.

The firewall reuses what testing produces. Its Tier 2 classifier is trained on the customer's own adversarial and QA test logs. Humanbound says the fast local tiers resolve the majority of requests, and only ambiguous inputs reach the LLM judge. Test findings can also be exported as protection rules in OpenAI or Humanbound Firewall format.

Sales Engagement & Go-to-Market Humanbound runs an open-source, product-led motion with a sales-assisted enterprise path…

Humanbound runs an open-source, product-led motion with a sales-assisted enterprise path. The free engine and a free hosted plan let developers start on their own. For larger buyers, the homepage offers a booked conversation and puts an enterprise-wide first assessment at about two weeks.

SysteCom, an Athens-based provider of cybersecurity and infrastructure solutions, announced its cooperation in May 2026 and offers an executive guide with Humanbound. Humanbound took part in the 2026 cohort of Greece's national AI accelerator run by Endeavor Greece with OpenAI and the Hellenic Government.

Pricing Model Humanbound publishes its prices…

Humanbound publishes its prices. The engine, CLI and firewall are free and open source, and security tests run locally with no account. The hosted platform has a free plan with three seats, Pro at 29 euros a month and Team at 249 euros a month.

Pro is aimed at teams running regular testing cycles with faster monitoring and longer retention, and Team at organisations with continuous security operations across several teams. Enterprise pricing is custom, and the plan comparison lists model fine-tuning, on-premises installation and dedicated support with an SLA.

Product Delivery & Operations Humanbound delivers the product as software in three deployment models…

Humanbound delivers the product as software in three deployment models. The SaaS service stores data in the EU North Europe region on SOC 2 compliant infrastructure. The on-premises option runs inside the customer's network, and the private cloud option runs a dedicated instance in the customer's Azure or AWS tenant under Humanbound's management.

Local use works without a Humanbound account and can run fully offline against self-hosted models through Ollama. Findings flow into CI pipelines through exit codes and a pytest plugin, and into SIEM and ticketing tools through signed webhooks.

Earning Customers' Trust The captured sources show no security attestation held by Humanbound itself…

The captured sources show no security attestation held by Humanbound itself. The documentation says the SaaS deployment runs on SOC 2 compliant infrastructure. That statement concerns the hosting, and no captured source documents an attestation covering Humanbound itself.

A probe of humanbound.ai/security returned a not-found page, and neither the trust nor the security subdomain resolved. The terms of use name the operating entity as AI AND ME IDIOTIKI KEFALAIOUCHIKI ETAIREIA P.C., registered in Ioannina, Greece.

Platform Strategy & Ecosystem Positioning Humanbound builds its ecosystem around open code and existing security tools…

Humanbound builds its ecosystem around open code and existing security tools. The testing engine and firewall are separate Apache 2.0 repositories, and the main repository shows 155 stars, 15 forks and 12 contributors.

Integrations reach into the tools security and engineering teams already run. Findings reach SIEM and ticketing systems as HMAC-signed webhooks, CI pipelines can block insecure deployments, and the firewall's attack-detection tier can combine pluggable detector models.

Team & Execution Capability Humanbound's co-founders are named in independent and company sources…

Humanbound's co-founders are named in independent and company sources. Endeavor Greece lists Dimitris Gerogiannis as co-founder and co-CEO for product and technology, and Typos-i.gr names him co-founder and co-CEO. The company blog names Kostas Siabanis as a co-founder based in Athens.

The captured sources do not describe the founders' earlier careers. Startupper.gr describes Humanbound as a startup from Ioannina whose team works on a fully remote model.

Sources

Company Detail Sources (3)
Id Source Tier Accessed
f1 Humanbound homepage official 2026-09-23
f2 Startupper.gr: Tech Coffee in Zagori, day 2 press 2026-09-23
f3 AI Defense Matrix Catalog mapping other 2026-09-23
Profile Analysis Sources (17)
Id Source Tier Accessed
s1 Humanbound: homepage official 2026-09-23
s2 Humanbound: pricing page official 2026-09-23
s3 Humanbound documentation: home official 2026-09-23
s4 GitHub: humanbound/humanbound repository official 2026-09-23
s5 Humanbound documentation: Firewall official 2026-09-23
s6 Humanbound: terms of use official 2026-09-23
s11 SysteCom: announcement of its cooperation with Humanbound other 2026-09-23
s12 Endeavor Greece: Greek AI Accelerator San Francisco event page research 2026-09-23
s14 CNN Greece: article on the OpenAI Greek startup accelerator press 2026-09-23
s15 Startupper.gr: the startups in the first OpenAI accelerator in Greece press 2026-09-23
s16 Startupper.gr: Tech Coffee in Zagori, day 2 press 2026-09-23
s17 Typos-i.gr: technology and innovation in Ioannina press 2026-09-23
s18 Humanbound blog: AI security means two different things official 2026-09-23
s19 GitHub: humanbound/humanbound-firewall repository official 2026-09-23
s22 Humanbound documentation: deployment options official 2026-09-23
s23 Humanbound documentation: SIEM integration official 2026-09-23
s24 Humanbound security-page probe (2026-09-23): /security is a not-found page, trust. and security. subdomains and a random control do not resolve official 2026-09-23
Deep-Dive Sources (17)
Id Source Tier Accessed
s1 Humanbound: homepage official 2026-09-23
s2 Humanbound: pricing page official 2026-09-23
s3 Humanbound documentation: home official 2026-09-23
s4 GitHub: humanbound/humanbound repository official 2026-09-23
s5 Humanbound documentation: Firewall official 2026-09-23
s6 Humanbound: terms of use official 2026-09-23
s11 SysteCom: announcement of its cooperation with Humanbound other 2026-09-23
s12 Endeavor Greece: Greek AI Accelerator San Francisco event page research 2026-09-23
s14 CNN Greece: article on the OpenAI Greek startup accelerator press 2026-09-23
s15 Startupper.gr: the startups in the first OpenAI accelerator in Greece press 2026-09-23
s16 Startupper.gr: Tech Coffee in Zagori, day 2 press 2026-09-23
s17 Typos-i.gr: technology and innovation in Ioannina press 2026-09-23
s18 Humanbound blog: AI security means two different things official 2026-09-23
s19 GitHub: humanbound/humanbound-firewall repository official 2026-09-23
s22 Humanbound documentation: deployment options official 2026-09-23
s23 Humanbound documentation: SIEM integration official 2026-09-23
s24 Humanbound security-page probe (2026-09-23): /security is a not-found page, trust. and security. subdomains and a random control do not resolve official 2026-09-23

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.