All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Irregular runs offensive-cyber simulations on new AI models before they ship, and its assessments already appear in the published safety documentation for OpenAI's o3 and o4-mini and for Claude 3.7 Sonnet. The cited pages describe an actively deployed proprietary platform integrated with the labs' systems and delivering assessments, so a rival must reproduce both the platform and scarce offensive-AI talent to compete. The catch is customer concentration: the engagements are with frontier labs, and lab insourcing is a labeled risk rather than a documented plan. Press puts revenue in the millions, with the paying accounts unnamed. Sequoia and Redpoint led an $80 million round at a reported $450 million valuation. Its credibility and its concentration risk share one source: the frontier labs.
| Description | Irregular is a frontier AI security research lab that runs controlled simulations on advanced AI models to measure their offensive cyber capabilities before deployment, delivering findings as a service to AI labs. Its public surface is research, news, and careers, with no purchasable product. | [f1] |
|---|---|---|
| Founded | 2023 | [f2] |
| Funding | $80M total | [f3] |
| Latest funding | $80M round (2025) | [f2] |
| Product | What it does |
|---|---|
| AI Evaluation Platform | A proprietary platform and evaluation library Irregular operates in-house to test AI systems' offensive cyber capabilities and deliver findings to frontier labs. It is not sold or self-deployed. |
| SOLVE | A published framework for scoring how difficult a vulnerability-discovery and exploit-development challenge is, used to benchmark AI models. A research artifact, not a sold product. |
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Irregular names the buyer, frontier AI labs, and a real pain of measuring offensive cyber capability before a model ships, but the pain stays qualitative with no quantified cost, and press corroboration of a qualitative problem holds it at present but unproven. [s2, s4, s5] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | A detailed technical writeup describes the evaluation platform's challenge types across vulnerability detection, evasion, and network attack simulation, and TechCrunch reports the SOLVE scoring framework is widely used in the industry. The work cited in published model system cards is an external validation point beyond marketing. [s2, s4, s6] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | Frontier labs already commission AI model evaluation, and by 2025 OpenAI's o3 and o4-mini and the Claude 3.7 Sonnet system cards cited Irregular's work, a third-party-published demand signal. The enabler is that models have grown capable enough to perform real offensive cyber tasks, the shift that makes pre-release evaluation necessary. The demand concentrates in a handful of labs citing the research rather than a broad buyer-side market, so 4 rather than the independently confirmed 5. [s4, s5] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | Lahav and Nevo speak publicly with technical specificity and built an evaluation practice that frontier labs adopted, but that is the current company's traction, not a prior in-domain exit or a sustained publication record, so the founders sit at competent rather than the earned 4. [s4, s6] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 | Irregular names OpenAI and Anthropic as labs it works with and its research is cited in their published system cards, but those are citations of research, not product reference customers, and the site sells no purchasable product, so there is no product-GTM motion to credit. The single vague press line about millions in revenue and the reputable Sequoia and Redpoint backing are indirect signals that hold the score at 3 rather than below. A 4 would need named product reference customers. [s4, s5] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | The $80 million round is sized to a frontier-lab research-and-services motion, but the visible output is research publications and an in-house evaluation engagement rather than a shipped product, so output per dollar cannot be confirmed against the raise. That places it at adequate rather than the visible-shipping 4. [s3, s4] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 | AI model evaluation is a clearly emerging category, but Irregular occupies it as a research-and-services lab whose self-coined "frontier security lab" label and absence of a purchasable product give buyers no budget line or stack slot to place it in without coaching. That is adequate category presence, short of the clean buyer-placeable fit a 4 names. [s4, s5] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | The evaluations woven into frontier labs' release processes and the accumulating evaluation library create workflow friction, but the rationale concedes those same labs can rebuild the work themselves, so the position has friction without a structural moat bundling could not replicate. [s2, s4] |
Irregular measures whether a new AI model can carry out offensive cyber operations before the model ships. The buyer is a frontier AI lab that wants to show its own safety teams, and likely regulators, that it tested a model's potential for misuse and its resilience under attack.
The problem is corroborated beyond the vendor's framing. Press describes Irregular running controlled simulations on frontier models to test both misuse potential and resilience, and reports that leading labs already pay for this work rather than build it alone today. [s2, s5]
Irregular's AI Evaluation Platform tests models against challenge sets that span vulnerability detection and exploitation, evasion of detection systems such as EDR, and network attack simulation. A technical writeup describes the platform and a large evaluation library applied across difficulty levels, evidence beyond a marketing page. The platform is proprietary and run in house, not sold or deployed by buyers, so Irregular delivers the findings rather than the software.
The company also publishes SOLVE, a framework for scoring a model's vulnerability-detection ability that TechCrunch reports is widely used in the industry. Co-founder Omer Nevo describes complex network simulations in which AI plays both attacker and defender, so the team can see where a new model's defenses hold and where they fail. [s2, s4, s6]
Irregular competes with a cluster of AI evaluation and red-team companies, including Dreadnode, Gray Swan AI, and Adversa AI, that test AI models for security weaknesses. Most of that cluster sells to security teams or enterprise AI deployers rather than to the model builders themselves.
What separates Irregular is the buyer it reaches and the proof it carries. Its evaluations appear in the published safety documentation of OpenAI's o3 and o4-mini and Claude 3.7 Sonnet, a release-process position the cluster has not shown. That same concentration on a handful of frontier labs is the vulnerability, because those labs hold the talent to rebuild the work. [s3, s4]
Irregular names OpenAI and Anthropic as labs it works alongside, and its research is cited in those labs' published model evaluations. Those are citations of the research and a services relationship rather than product reference customers, since Irregular sells no purchasable product.
Press reports the company has reached millions in annual revenue, though that figure is a single vague line rather than a corroborated number. The revenue rests on a small set of frontier-lab accounts, so the named labs are evidence of fit and a concentration risk at the same time. [s4, s5]
Co-founders Dan Lahav and Omer Nevo lead the company and speak publicly with technical specificity about the simulation work. Nevo describes how the platform pits AI against AI to find where a model's defenses fail, the kind of detail that signals real engineering depth.
Adoption is the clearest credibility signal. Frontier labs put Irregular's evaluations into their own safety documentation, which is third-party validation of the team's work that few peers can claim. [s4, s6]
Irregular's trust signal is the company it keeps rather than a published compliance posture. Its evaluations are referenced in the safety documentation of the AI labs it serves, and Sequoia Capital and Redpoint Ventures led its funding, with Wiz CEO Assaf Rappaport among the angels.
No public trust collateral, such as a SOC 2 or ISO 27001 attestation or a trust center, was found on the company's site as of June 2026. For a vendor handling pre-release model evaluations for frontier labs, formal attestations would be the next readiness step a larger enterprise buyer expects. [s1, s3]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Dreadnode | competes with | Both build offensive-AI evaluation platforms that stress-test models' security capabilities, though Dreadnode targets security teams while Irregular sells to frontier labs. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Gray Swan AI | competes with | Both evaluate frontier AI models for security weaknesses on behalf of the labs that build them. | N/AThese companies operate in different domains, so the scores reflect readiness in different markets. |
| Adversa AI | competes with | Both perform AI red-teaming and model security assessment, with Adversa focused more on enterprise AI deployments. | N/AThese companies operate in different domains, so the scores reflect readiness in different markets. |
Add analyzed competitors to compare them side by side with Irregular.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
press the advantage
Irregular is hard to displace because of the difficulty of its work, not because of any hold over its customers. Running offensive-cyber simulations on frontier models takes scarce adversarial-AI expertise and a proprietary platform, and Irregular's platform delivers assessments through direct integrations, so a rival must reproduce both. Its evaluations are cited by name in the frontier labs' published safety documentation. The trouble is concentration: those same labs are the buyers, and insourcing by a lab is a risk the record does not document rather than an observed pattern. The SOLVE scoring method it is known for is public, so its reputation travels while the method locks no one in. No attestation or regulatory mandate raises a rival's cost to enter.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 2/3 | The cited record shows Irregular deploying its own evaluation platform and delivering expert findings that frontier labs use to analyze their models, a blend of proprietary tooling and specialist judgment rather than a product the buyer configures, which sits above a self-run software tool. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | A lab that wires Irregular's evaluations into its model release process and reporting builds real dependence, so replacing the work means standing up the simulations and expertise itself. The friction is bounded, because the engagement is a periodic service a lab can end and no data residency or integration binds it in place. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | A probe of the trust and security subdomains, the /security, /trust, and /compliance paths, and the homepage found no SOC 2 or ISO 27001 report or trust portal as of July 2026. The cited record identifies no mandate requiring the evaluation, so compliance is not yet a barrier a competitor must clear. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Building high-fidelity simulations that pit AI against AI to measure a model's offensive-cyber capability, and quantifying challenge difficulty through the published SOLVE method, demands scarce adversarial-AI and systems expertise well beyond routine software. Adoption of the work in frontier labs' safety documentation confirms the depth. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | The evidenced engagements are with frontier AI labs, with OpenAI and Anthropic publicly citing Irregular's evaluations in safety documentation and press describing it working alongside them, while the paying accounts behind its millions in annual revenue stay unnamed. That is a demanding, high-value buyer population with an exacting technical and procurement bar, though the base is concentrated. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Irregular's evaluation attaches to a lab's model release process as an assessment step rather than sitting inline in production or serving as infrastructure other systems depend on. It is an evaluation layer beside the model that a buyer could insource or replace without breaking a running system. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 2/3 | The SOLVE scoring method is published and guards nothing, but the cited pages name a proprietary evaluation library whose challenges are mostly developed in-house to avoid training contamination, a guarded non-public content asset a funded rival cannot trivially assemble, which earns the 2 the corpus gives protected evaluation sets. |
Irregular targets a narrow, high-value segment: the frontier AI labs that build the most capable models. Press names OpenAI and Anthropic as labs it works alongside, and its evaluations appear in those labs' published model documentation. The buyer is the lab's safety or security function that must measure a model's offensive-cyber capability before release.
The segment is deliberately small. Rather than pursue a broad enterprise market, Irregular concentrates on the handful of organizations training frontier models, where the need to show pre-release testing is most acute and best funded. That focus wins credibility but leaves the company without a disclosed foothold among the enterprise AI deployers that its peers pursue.
The evaluating persona is a lab's model-safety researcher or security lead, the same technical function that champions the work. No engagement outside the frontier-lab segment speaks publicly.
Irregular's core capability is a proprietary evaluation platform that runs controlled offensive-cyber simulations against AI models. Documented challenge types span vulnerability detection and exploitation and evasion of monitoring systems such as endpoint detection and response, applied across a range of difficulty levels.
The advantage is adversarial-AI depth. Co-founder Omer Nevo describes complex network simulations in which AI plays both attacker and defender, so the team can see where a new model's defenses hold and where they fail. The published SOLVE scoring method, which quantifies how difficult a vulnerability-discovery and exploitation challenge is, reflects the same expertise and is used across the industry.
AI is both the subject and the method. The platform measures models' offensive capability, and Irregular applies its own simulation engine and specialist judgment to produce the assessment. The assessments are the deliverable the cited pages describe.
Irregular's visible acquisition motion is research-led. Its evaluations appear in the published safety documentation of OpenAI's o3 and o4-mini and Anthropic's Claude 3.7 Sonnet, which puts its work directly in front of the labs that would buy it, and press describes it working side by side with those labs.
The company sells no self-serve product. The motion is a direct research-and-services engagement with frontier labs. Press reports it has reached millions in annual revenue, a single unquantified figure rather than a disclosed customer roster.
Investor backing adds a second signal beside the published lab references. Sequoia Capital and Redpoint Ventures led the $80 million round, with Wiz CEO Assaf Rappaport among the angels, a syndicate that signals conviction where published customer case studies are absent.
Irregular publishes no pricing. The work is a direct relationship with frontier labs, and no terms, units, or list prices appear in the cited record.
The unit the company charges by is not disclosed. Press places revenue in the millions and discloses no account count, contract size, or billing basis, so bespoke negotiated pricing is an inference from the engagement model rather than a disclosure. Hidden, bespoke pricing fits a business delivering expert assessments to a small number of sophisticated buyers, though it also means the company has no published, repeatable price a broader market could adopt.
Irregular's platform is actively deployed and integrates with the labs' AI-system components, delivering assessments; the cited pages leave the contracting boundary and what customers themselves run undescribed. The company describes high-fidelity research platforms that simulate and monitor real-world AI security scenarios.
The findings from the platform are used at scale by frontier AI labs to analyze their systems. The cited pages show the platform connecting directly to AI-system components and supplying assessments, with the operational boundary between vendor and customer left undescribed.
The operational model is a continuous evaluation relationship. Nevo's account of running new models through attacker-and-defender simulations as they are released points to repeated engagements tied to each model generation rather than a one-time deliverable.
Irregular's trust rests on the company it keeps rather than a published compliance posture. Its evaluations are referenced in the safety documentation of the labs it serves, and Sequoia Capital and Redpoint Ventures led its funding, with Wiz CEO Assaf Rappaport among the angels.
No public security attestation appears against the company. A probe of the trust and security subdomains, the /security, /trust, and /compliance paths, and the homepage as of July 2026 found no SOC 2 or ISO 27001 report and no trust portal. For a vendor handling pre-release evaluation of frontier models, inspectable compliance collateral would be the next readiness step a larger enterprise buyer expects.
Irregular is positioned as a research lab and evaluation provider, not a platform others build on. Its evaluation platform is proprietary infrastructure integrated with the labs' systems to produce findings, and the ecosystem it participates in is the frontier-lab safety community rather than a partner or integration marketplace.
Its one broadly adopted contribution is the SOLVE scoring method, published and used across the industry. That spreads Irregular's methods and name, but as an open method it invites others to apply the same yardstick rather than binding the ecosystem to Irregular's platform.
The competitive field includes AI evaluation and red-team companies that test models for security weaknesses. The cited pages do not survey that cluster's delivery models; what they document for Irregular is expert assessment delivered to the model builders themselves.
The founding team sits at the center of the offensive-AI-evaluation niche. Co-founder Omer Nevo speaks publicly with technical specificity, describing complex network simulations in which AI plays both attacker and defender so the team can see where a new model's defenses hold and where they fail.
Adoption is the clearest credibility signal. The frontier labs put Irregular's evaluations into their own safety documentation, third-party validation of the team's work, and Sequoia Capital and Redpoint Ventures backed the company with an $80 million round.
The company's origin adds context. Formerly Pattern Labs, Irregular has reached millions in annual revenue while working alongside frontier labs, a trajectory that reflects a team whose evaluation practice the most demanding buyers adopted.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | https://www.irregular.com/about | official | 2026-07-20 |
| f2 | citybiz: Irregular Raises $80 Million | press | 2026-06-24 |
| f3 | TechCrunch: Irregular raises $80M to secure frontier AI models | press | 2026-06-24 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Irregular: About “Irregular is the first frontier security lab with the mission of protecting the world in the time of increasingly capable and sophisticated AI systems. We build next-generation defenses through high-fidelity research platforms that simulate and monitor real-world AI security scenarios.” | official | 2026-06-24 |
| s2 | Irregular: AI Evaluation Platform, Cyber Use-Case “Vulnerability Detection and Exploitation challenges require the AI system to identify and exploit security weaknesses. Evasion challenges require the AI system to perform tasks while avoiding detection by monitoring systems, such as endpoint detection and response (EDR) systems.” | official | 2026-06-24 |
| s3 | TechCrunch: Irregular raises $80M to secure frontier AI models “On Wednesday, AI security firm Irregular announced $80 million in new funding in a round led by Sequoia Capital and Redpoint Ventures, with participation from Wiz CEO Assaf Rappaport. A source close to the deal said the round valued Irregular at $450 million.” | press | 2026-06-24 |
| s4 | TechCrunch: Irregular, formerly Pattern Labs, on SOLVE and model evaluations “The company's work is cited in security evaluations for Claude 3.7 Sonnet, as well as OpenAI's o3 and o4-mini models. More generally, the company's framework for scoring a model's vulnerability-detection ability (dubbed SOLVE) is widely used within the industry.” | press | 2026-06-24 |
| s5 | citybiz: Irregular Raises $80 Million “Formerly known as Pattern Labs, Irregular has reached millions in annual revenue. It works side by side with the world's leading AI labs like OpenAI and Anthropic to evaluate how next generation AI models may themselves carry out real world threats.” | press | 2026-06-24 |
| s6 | TechCrunch: Irregular co-founder Omer Nevo on simulated environments “We have complex network simulations where we have AI both taking the role of attacker and defender, says co-founder Omer Nevo. So when a new model comes out, we can see where the defenses hold up and where they don't.” | press | 2026-06-24 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Irregular: About “Irregular is the first frontier security lab with the mission of protecting the world in the time of increasingly capable and sophisticated AI systems. We build next-generation defenses through high-fidelity research platforms that simulate and monitor real-world AI security scenarios.” | official | 2026-07-08 |
| s2 | Irregular: AI Evaluation Platform, Cyber Use-Case (delivery) “The findings from Irregular's Evaluation Platform are already being used, at scale, by leading frontier AI labs to analyze their AI systems, and subsequently progress the field of AI Security significantly.” | official | 2026-07-08 |
| s3 | Irregular: AI Evaluation Platform, Cyber Use-Case (challenge types) “Vulnerability Detection and Exploitation challenges require the AI system to identify and exploit security weaknesses. Evasion challenges require the AI system to perform tasks while avoiding detection by monitoring systems, such as endpoint detection and response (EDR) systems.” | official | 2026-07-08 |
| s4 | Irregular: Introducing SOLVE “At Irregular, we evaluate dangerous cyber capabilities of AI, and as part of our evaluations, we take into account the difficulty of vulnerability and exploitation tasks in order to quantify the skill level demonstrated by an AI when given cyber challenges.” | official | 2026-07-08 |
| s5 | TechCrunch: Irregular raises $80M to secure frontier AI models “On Wednesday, AI security firm Irregular announced $80 million in new funding in a round led by Sequoia Capital and Redpoint Ventures, with participation from Wiz CEO Assaf Rappaport. A source close to the deal said the round valued Irregular at $450 million.” | press | 2026-07-08 |
| s6 | TechCrunch: Irregular work cited in model security evaluations “The company's work is cited in security evaluations for Claude 3.7 Sonnet, as well as OpenAI's o3 and o4-mini models. More generally, the company's framework for scoring a model's vulnerability-detection ability (dubbed SOLVE) is widely used within the industry.” | press | 2026-07-08 |
| s7 | TechCrunch: Irregular co-founder Omer Nevo on simulated environments “We have complex network simulations where we have AI both taking the role of attacker and defender, says co-founder Omer Nevo. So when a new model comes out, we can see where the defenses hold up and where they don't.” | press | 2026-07-08 |
| s8 | citybiz: Irregular Raises $80 Million (syndicated company announcement) “Formerly known as Pattern Labs, Irregular has reached millions in annual revenue. It works side by side with the world's leading AI labs like OpenAI and Anthropic to evaluate how next generation AI models may themselves carry out real world threats.” | press | 2026-07-08 |
| s9 | Irregular attestation probe 2026-07-08 (trust and security subdomains, /security /trust /compliance, homepage): no SOC 2, ISO 27001, or trust portal “Frontier AI Security” | official | 2026-07-08 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.