All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
HydroX AI works alongside the companies that build AI models, but the public record names no customer paying for its products. The San Jose startup announced Anthropic bug-bounty participation for universal-jailbreak testing, and AI Business reported collaboration with Meta and IBM on safety benchmarks. Google chose it for the 2025 Cloud AI Accelerator, and HydroX announced Marketplace availability for its Firewall in July 2025. Disclosed funding remains the $4 million angel round of June 2024. The company sells in several directions: an enterprise AI firewall, a child-safety platform for schools and families, a private meeting assistant, and an anti-scraping red-team service. Watch whether HydroX names its first enterprise reference customer.
| Description | HydroX AI sells an AI security and safety platform spanning a runtime firewall that blocks jailbreaks and prompt injection, model safety evaluation and red teaming, a child safety product, and a local-first AI meeting assistant. | [f1] |
|---|---|---|
| Founded | 2023 | [f2] |
| HQ | San Jose, California, USA | [f3] |
| Latest funding | $4M angel round (June 2024) | [f2] |
| Product | What it does |
|---|---|
| HydroX Firewall | Model-agnostic runtime firewall for LLMs, agents, and AI applications that blocks jailbreaks, prompt injection, and data leaks in real time, listed on Google Cloud Marketplace. |
| EPASS | Evaluation platform for AI safety and security that stress-tests models against adversarial attacks and publishes a public leaderboard comparing model security, privacy, and integrity. |
| Stay Aware AI | Child safety platform for families and schools that uses AI to turn children's conversations and online activity into emotional and behavioral insights and real-time guidance. |
| CaptainNote | Offline-first AI meeting assistant that records, transcribes, and summarizes meetings locally using open-source models, keeping data on the user's device. |
| AI-Driven Scraper | Red-teaming service for defining and validating anti-scraping defenses with AI-agent-driven scraping over 60+ residential IP addresses and LLM-based results processing. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
HydroX Firewall intercepts AI inputs and outputs to block jailbreaks and prompt injection and to redact sensitive data from responses, and EPASS red-teams and stress-tests models to uncover vulnerabilities. These capabilities are mapped to the AI Defense Matrix. [f4]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score |
|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs, demos, and third-party validation. | 3/5 |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 2/5 |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
pivot urgently
| Dimension | Score |
|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | HydroX AI product page | official | 2026-07-03 |
| f2 | PR Newswire: HydroX AI Announces Closing of $4 Million Angel Funding Round and Launches EPASS | press | 2026-07-03 |
| f3 | HydroX AI homepage footer | official | 2026-07-03 |
| f4 | HydroX AI (AI Defense Matrix Catalog), mapping aligned to the catalog | other | 2026-07-03 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | HydroX AI homepage “HydroX AI is an AI security platform that protects children and organizations by enforcing safety, governance, and compliance across large language models.” | official | 2026-07-03 |
| s2 | HydroX AI about page (current team roster) “Zhuo Li Founder & CEO Kan Liu Cheif Architect Rick C. Yang VP, Sales and Marketing Peikang Hu Head of Engineering Jin Qin Head of Seattle Office” | official | 2026-07-03 |
| s3 | HydroX AI product page (firewall, evaluation, Stay Aware AI, CaptainNote, AI-Driven Scraper) “Stay Aware AI is an AI-powered child safety platform that helps families and schools detect digital risks early, understand emotional wellbeing, and guide children with education instead of fear.” | official | 2026-07-03 |
| s4 | HydroX AI public model-safety leaderboard “Leaderboard | Compare Model Security, Privacy & Integrity” | official | 2026-07-03 |
| s5 | HydroX AI blog index, newest post dated October 8, 2025 (accessed July 3, 2026) “When AI Leaks Dangerous Information: Why AI Models Are a Public Safety Risk” | official | 2026-07-03 |
| s6 | HydroX AI blog: Now on Google Cloud Marketplace: HydroX Firewall for Generative AI Security (July 1, 2025) “our HydroX Firewall is now available on Google Cloud Marketplace, giving enterprises an easy, secure, and scalable way to deploy and protect GenAI systems.” | official | 2026-07-03 |
| s7 | PR Newswire: HydroX AI $4M angel round and EPASS launch, June 25, 2024 (founder Zhuo Li: ByteDance privacy office head, earlier Meta and LinkedIn) “today announced closing a $4 million angel round from Vitalbridge Capital, Atom Capital and noted AI expert, Qi Lu, EVP of Microsoft, former COO of Baidu.” | press | 2026-07-03 |
| s8 | Pulse 2.0 (Amit Chowdhry): HydroX AI Trust, Risk, And Security Management Company Raises $4 Million (July 9, 2024) “announced the closing of a $4 million angel round from Vitalbridge Capital, Atom Capital, and AI expert Qi Lu.” | press | 2026-07-03 |
| s9 | The SaaS News (Ben Murray): HydroX AI Closes $4 Million in Funding “Company: Hydrox AI LLC. Raised: $4.0M Round: Angel Round Funding Month: June 2024” | press | 2026-07-03 |
| s10 | AI Business (Ben Wodecki): Meta, IBM Working With Startup to Test AI Model Safety (July 12, 2024) “HydroX AI is working with big-name tech firms and the AI Alliance to evaluate generative AI models in industries such as health care and finance” | press | 2026-07-03 |
| s11 | Google Cloud blog: 15 new startups join Google AI Accelerator (March 27, 2025) “HydroX AI (San Jose, CA): Automates generative AI risk and compliance.” | press | 2026-07-03 |
| s12 | AI Alliance: The State of Open Source AI Trust and Safety, End of 2024 Edition (December 11, 2024) “Zhuo Li (HydroX AI), Florencio Cano (Red Hat), Victor Bian (HydroX AI)” | research | 2026-07-03 |
| s13 | ROOST homepage: Built in partnership with logo wall including Hydrox AI “Built in partnership with: (logo wall; the served HTML carries the image /images/logos/hydrox-ai.webp with alt text "Hydrox AI")” | other | 2026-07-03 |
| s14 | HydroX AI blog: HydroX AI Partners with Anthropic to Strengthen LLM Red Teaming (October 20, 2024) “As part of Anthropic's bug bounty program, HydroX AI will play a pivotal role in stress testing their LLMs, with a focus on identifying and mitigating universal jailbreak attacks.” | official | 2026-07-03 |
| s15 | HydroX AI blog: HydroX AI Graduates from the Google Cloud AI Accelerator (June 11, 2025) “Chosen as one of just 15 leading AI startups across the U.S. and Canada” | official | 2026-07-03 |
| s16 | HydroX AI blog: Proudly Present with ROOST in Advancing AI Trust & Safety (March 13, 2025) “HydroX AI is proudly sponsoring and collaborating with ROOST (Robust Open Online Safety Tools)” | official | 2026-07-03 |
| s17 | HydroX AI blog: HydroX AI at RSAC 2025, Human vs. Machine (April 28, 2025) “Led by Victor Bian (COO, HydroX AI) and Theodora Skeadas (Chief of Staff, Humane Intelligence), the session delivered a high-impact red-teaming experience.” | official | 2026-07-03 |
| s18 | GitHub API: HydroXai organization profile (26 public repos, includes the pii-masker open-source tool) “An AI native community for AI Safety & Security. We plan to open source as much as possible.” | other | 2026-07-03 |
| s19 | Trust-surface probe (trust./security. subdomains, /trust /security /compliance paths, footer badges): no SOC 2, ISO 27001, or other attestation, July 3, 2026 | other | 2026-07-03 |
| s20 | HydroX AI (AI Defense Matrix Catalog) “Model-agnostic runtime firewall for LLMs and agents that blocks jailbreaks, prompt injection, and data leaks, redacts PII from responses, and red-teams models for vulnerabilities.” | other | 2026-07-03 |
| s21 | Documentation probe: the product-page Documentation button carries no link target, docs.hydrox.ai does not resolve, /docs returns 404, July 3, 2026 | other | 2026-07-03 |
| s22 | GitHub API: HydroXai repository list (includes pii-masker, an open-source PII tool, and implementations of published jailbreak methods) “PII Masker is an open-source tool for protecting sensitive data” | other | 2026-07-03 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | HydroX AI homepage “HydroX AI is an AI security platform that protects children and organizations by enforcing safety, governance, and compliance across large language models.” | official | 2026-07-03 |
| s2 | HydroX AI about page (current team roster) “Zhuo Li Founder & CEO Kan Liu Cheif Architect Rick C. Yang VP, Sales and Marketing Peikang Hu Head of Engineering Jin Qin Head of Seattle Office” | official | 2026-07-03 |
| s3 | HydroX AI product page (firewall, evaluation, Stay Aware AI, CaptainNote, AI-Driven Scraper) “Stay Aware AI is an AI-powered child safety platform that helps families and schools detect digital risks early, understand emotional wellbeing, and guide children with education instead of fear.” | official | 2026-07-03 |
| s4 | HydroX AI public model-safety leaderboard “Leaderboard | Compare Model Security, Privacy & Integrity” | official | 2026-07-03 |
| s5 | HydroX AI blog index, newest post dated October 8, 2025 (accessed July 3, 2026) “When AI Leaks Dangerous Information: Why AI Models Are a Public Safety Risk” | official | 2026-07-03 |
| s6 | HydroX AI blog: Now on Google Cloud Marketplace: HydroX Firewall for Generative AI Security (July 1, 2025) “Catch threats in real time: Stop jailbreaks, hallucinations, data leaks, and adversarial prompts in under 100ms.” | official | 2026-07-03 |
| s7 | PR Newswire: HydroX AI $4M angel round and EPASS launch, June 25, 2024 (founder Zhuo Li: ByteDance privacy office head, earlier Meta and LinkedIn) “today announced closing a $4 million angel round from Vitalbridge Capital, Atom Capital and noted AI expert, Qi Lu, EVP of Microsoft, former COO of Baidu.” | press | 2026-07-03 |
| s8 | Pulse 2.0 (Amit Chowdhry): HydroX AI Trust, Risk, And Security Management Company Raises $4 Million (July 9, 2024) “HydroX AI was created to address these LLM risks by offering a comprehensive platform for the evaluation, mitigation, protection, and monitoring of Large Language Model (LLM) safety and security” | press | 2026-07-03 |
| s9 | The SaaS News (Ben Murray): HydroX AI Closes $4 Million in Funding “Company: Hydrox AI LLC. Raised: $4.0M Round: Angel Round Funding Month: June 2024” | press | 2026-07-03 |
| s10 | AI Business (Ben Wodecki): Meta, IBM Working With Startup to Test AI Model Safety (July 12, 2024) “HydroX AI is working with big-name tech firms and the AI Alliance to evaluate generative AI models in industries such as health care and finance” | press | 2026-07-03 |
| s11 | Google Cloud blog: 15 new startups join Google AI Accelerator (March 27, 2025) “HydroX AI (San Jose, CA): Automates generative AI risk and compliance.” | press | 2026-07-03 |
| s12 | AI Alliance: The State of Open Source AI Trust and Safety, End of 2024 Edition (December 11, 2024) “Zhuo Li (HydroX AI), Florencio Cano (Red Hat), Victor Bian (HydroX AI)” | research | 2026-07-03 |
| s13 | ROOST homepage: Built in partnership with logo wall including Hydrox AI “Built in partnership with: (logo wall; the served HTML carries the image /images/logos/hydrox-ai.webp with alt text "Hydrox AI")” | other | 2026-07-03 |
| s14 | HydroX AI blog: HydroX AI Partners with Anthropic to Strengthen LLM Red Teaming (October 20, 2024) “As part of Anthropic's bug bounty program, HydroX AI will play a pivotal role in stress testing their LLMs, with a focus on identifying and mitigating universal jailbreak attacks.” | official | 2026-07-03 |
| s15 | HydroX AI blog: HydroX AI Graduates from the Google Cloud AI Accelerator (June 11, 2025) “Chosen as one of just 15 leading AI startups across the U.S. and Canada” | official | 2026-07-03 |
| s16 | HydroX AI blog: Proudly Present with ROOST in Advancing AI Trust & Safety (March 13, 2025) “HydroX AI is proudly sponsoring and collaborating with ROOST (Robust Open Online Safety Tools), a groundbreaking initiative incubated with the support of major funders like Discord, OpenAI, Google, and more.” | official | 2026-07-03 |
| s17 | HydroX AI blog: HydroX AI at RSAC 2025, Human vs. Machine (April 28, 2025) “Led by Victor Bian (COO, HydroX AI) and Theodora Skeadas (Chief of Staff, Humane Intelligence), the session delivered a high-impact red-teaming experience.” | official | 2026-07-03 |
| s18 | GitHub API: HydroXai organization profile (26 public repos, includes the pii-masker open-source tool) “An AI native community for AI Safety & Security. We plan to open source as much as possible.” | other | 2026-07-03 |
| s19 | Trust-surface probe (trust./security. subdomains, /trust /security /compliance paths, footer badges): no SOC 2, ISO 27001, or other attestation, July 3, 2026 | other | 2026-07-03 |
| s20 | HydroX AI (AI Defense Matrix Catalog) “Model-agnostic runtime firewall for LLMs and agents that blocks jailbreaks, prompt injection, and data leaks, redacts PII from responses, and red-teams models for vulnerabilities.” | other | 2026-07-03 |
| s21 | Documentation probe: the product-page Documentation button carries no link target, docs.hydrox.ai does not resolve, /docs returns 404, July 3, 2026 | other | 2026-07-03 |
| s22 | GitHub API: HydroXai repository list (includes pii-masker, an open-source PII tool, and implementations of published jailbreak methods) “PII Masker is an open-source tool for protecting sensitive data” | other | 2026-07-03 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Do not republish its content or share access without the operator's permission.