Maxim AI

Security for AI also known as H3 Labs Inc.

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2023
Last updated 2026-09-23

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

This analysis is scoped to Bifrost.

Maxim AI sells Bifrost, an open-source AI gateway that routes requests to more than 20 model providers through one interface. Platform teams adopt it, and Maxim AI markets it to financial institutions and government agencies. Applications can sign in with an access key, and Bifrost applies that key’s permissions, budgets and rate limits. A paid enterprise edition adds single sign-on, audit logs and guardrails that screen prompts and responses. Founded in 2023, Maxim AI raised a $3 million round led by Elevation Capital. It says more than 1,000 teams use Bifrost. Buyers will weigh three high or critical Bifrost security advisories published in 2026 through coordinated disclosure. A departing customer would rebuild its keys, budgets and guardrails in another gateway.

Sourced Details

Description Maxim AI makes Bifrost, an open-source AI gateway that routes and governs a company's model traffic, alongside an evaluation and observability platform for AI agents. [f1]
Founded 2023 [f2]
HQ Mountain View, California, United States [f3]
Latest funding Seed, $3M led by Elevation Capital (June 2024) [f2]

Products

Product What it does
Bifrost Open-source AI gateway that routes model and MCP tool traffic behind one API, with virtual-key budgets and rate limits and enterprise guardrails on prompts and responses.
Maxim Evaluation and observability platform for AI agents, covering prompt experimentation, simulated test scenarios, automated and human evaluations, and production tracing.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Coding and Orchestration Tools AI coding tools and agentic orchestration tools on user devices, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Traffic Paths to external and self-hosted AI services, MCP tool channels, agent-to-agent calls, model-registry downloads, and egress to unapproved AI services. AI gateways, LLM routers, and MCP gateways steer traffic along those paths. The steering decisions and their inputs belong here too: routing policies, MCP server registries, and agent naming and discovery services.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, an AI bill of materials (AIBOM), and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Bifrost routes applications' model traffic through virtual keys that set access permissions, budgets, rate limits and routing for each consumer, and its enterprise guardrails check prompts and responses in real time. These capabilities are mapped to the AI Defense Matrix. [f4]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 26 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Maxim AI names the buyer, platform teams calling many model providers, and the pain of scattered provider keys, cost overruns and missing audit trails. It pitches the gateway to financial institutions and government agencies by name. The druce.ai vendor wiki frames the gateway the same way, as the exit door for model traffic, but no reviewed source quantifies the pain. [s34, s35, s3, s12]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 4/5 Bifrost's documentation details virtual keys, guardrail rules, audit logs and on-premises deployment, and anyone can inspect its Apache-2.0 code in a repository with 8.3k stars and 1.3k forks. Two outside reviews bear on the product. A rival gateway developer's June 2026 benchmark measured its latency and throughput, and the druce.ai wiki reviewed its feature split, although Maxim AI reserves the guardrails for the enterprise edition. [s21, s8, s23, s22, s4, s16, s12]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 The enabler is the spread of model providers and agent tool calls since the repository's creation in March 2025. Bifrost's guardrails now also check MCP tool arguments and results. Buyer-side demand in the record is indirect. An independent practitioner wiki files Bifrost in an AI gateway category, and no reviewed source shows an RFP, budget-line or regulatory signal for the product. [s12, s8]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 Robotics 24/7 reported that co-founders Vaibhavi Gangwar and Akshay Deo bring over a decade of experience from Google and Postman, which is verifiable experience with developer tools. The reviewed sources name no earlier product either founder led. They also record no exit or independent recognition. [s17, s5]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 No source names a Bifrost customer, and Maxim AI's claim that more than 1,000 teams use it is its own, which the druce.ai wiki calls unverified. Google Cloud's Partner Finder lists Maxim AI with a Bifrost entry, a partner-directory presence tied to the line, though the same listing shows no marketplace sales. The public repository's 1.3k forks and 8.3k stars show developer interest. A line-specific partnership listing with that interest meets rung 3, short of named references. [s1, s12, s28, s4]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 The capital record belongs to Maxim AI rather than to Bifrost. Maxim AI's reported funding is a $3 million seed led by Elevation Capital in June 2024, and the druce.ai wiki found no later round as of August 2026. The line ships visibly, with 7,368 commits and a 2.0.0 HTTP transport release, but no revenue or margin figure confirms its economics. [s17, s12, s4, s14]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 4/5 Outside parties place Bifrost in the AI gateway category. The druce.ai wiki files it under AI gateways beside LiteLLM, Portkey, Kong and Cloudflare. The June 2026 GoModel benchmark lists it among four AI gateways people compare, and TrueFoundry, a rival, publishes a Bifrost-versus-LiteLLM comparison. [s12, s16, s29]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 A customer replacing Bifrost would need to migrate its gateway settings. Its virtual keys, team budgets, routing rules and guardrail rules live in the gateway, and applications call their models through it. No structural moat appears, and the druce.ai wiki lists Gravitee, Kong, F5 and Cloudflare as gateway and networking incumbents already extending into AI. [s21, s8, s12]
Business Risks Bifrost's guardrails, single sign-on and configuration audit logs are enterprise-only, so a team running the free build gets no content inspection…
  • Bifrost's guardrails, single sign-on and configuration audit logs are enterprise-only, so a team running the free build gets no content inspection.
  • Three high or critical advisories published in 2026, including unauthenticated remote code execution on dynamically linked builds, put the gateway's own security under buyer scrutiny.
  • Maxim AI's reported capital is a $3 million seed from June 2024. The druce.ai wiki calls that the material risk for infrastructure buyers put on the critical path of every model call.
  • No reviewed source names a Bifrost customer or publishes a certification report, and the druce.ai wiki calls the absence of published certification reports a procurement blocker for the managed tier.
  • Gateway and networking incumbents such as Kong, Cloudflare and F5 are extending into AI. The druce.ai wiki notes they sell to whoever already owns the API estate, which gives them a path to Bifrost's buyers.
  • Bifrost Edge, which extends the gateway to employee devices, is in early access, so the endpoint coverage Maxim AI markets is not yet generally available.
Problem & Market Maxim AI built Bifrost for the sprawl that follows when a company calls models from several providers…

Maxim AI built Bifrost for the sprawl that follows when a company calls models from several providers. Maxim AI's financial-services page says separate provider keys create cost overruns, inconsistent audit trails and no central visibility. The druce.ai vendor wiki describes Bifrost as a proxy with one OpenAI-compatible endpoint, so application code stops holding per-provider keys. The documentation puts more than 20 providers behind that API.

The security case is control over outbound model traffic. The wiki places Bifrost in the model-prompt layer as the single outbound exit door for model traffic. Maxim AI markets the gateway to regulated buyers through industry pages for financial institutions and for government agencies deploying inside an authorized GovCloud environment.

The wiki dates the repository to March 2025, and the guardrails documentation applies the same checks to MCP tool arguments and results as to model prompts and responses. [s34, s12, s3, s35, s8]

Product Capabilities Bifrost is a gateway written in Go that applications adopt by changing one line of code…

Bifrost is a gateway written in Go that applications adopt by changing one line of code. The open-source build, under the Apache 2.0 licence, fails over between providers automatically, caches responses by semantic similarity and exports Prometheus metrics. Virtual keys are its primary governance object: applications authenticate with one and receive that key's permissions, budgets and rate limits, a check the documentation makes optional by default.

Maxim AI puts the content controls in the enterprise edition. The guardrails documentation describes rules in the Common Expression Language that decide which model requests or MCP tool calls to check. Bifrost's own checks include LLM-as-judge enforcement of plain-language policies and Gitleaks-backed secrets detection. The documentation also lists integrations with outside services such as AWS Bedrock Guardrails, Google Model Armor and CrowdStrike AIDR.

Maxim AI adds administrative controls in the enterprise edition. Maxim AI's enterprise page lists SAML single sign-on, role-based access control, peer-to-peer cluster mode and secret storage in HashiCorp Vault and cloud key managers. The audit log records who changed what in the gateway's configuration, and its entries can be signed with an HMAC key.

Maxim AI's performance figures are its own. The documentation claims 11 µs of added overhead at 5,000 requests per second, and the druce.ai wiki says every benchmark is vendor-run and the numbers do not reconcile. A June 2026 benchmark by Jakub A. Wąsek, who builds the rival GoModel gateway, ran against an instant mock backend. It measured Bifrost at 18.3 ms p99 latency and 3,100 requests per second, ahead of Portkey and LiteLLM and behind GoModel. [s12, s1, s4, s3, s21, s8, s7, s23, s16]

Competitive Positioning LiteLLM is Bifrost's direct rival…

LiteLLM is Bifrost's direct rival. The druce.ai vendor wiki lists LiteLLM as the direct target and says buyers shop for Bifrost against LiteLLM rather than against Maxim AI's evaluation suite. TrueFoundry publishes a Bifrost-versus-LiteLLM comparison that also presents its own broader AI platform, and the June 2026 GoModel benchmark tested Bifrost beside LiteLLM and Portkey as gateways people actually compare.

The wiki sets Bifrost apart from gateway and networking incumbents. It names Gravitee, Kong, F5 and Cloudflare as incumbents extending into AI, sold to whoever already owns the API estate. It describes Bifrost as the opposite buy, a component a platform team adopts on its own authority.

The split between free and paid features shapes the security comparison. The wiki notes that an open-source deployment includes no content inspection because guardrails are an enterprise feature. The GoModel benchmark's author makes the same point more broadly: Bifrost's Enterprise edition adds closed or managed features to an Apache-2.0 core. [s12, s29, s16]

Go-to-Market & Traction The public repository showed 1.3k forks, 8.3k stars and 7,368 commits in September 2026…

The public repository showed 1.3k forks, 8.3k stars and 7,368 commits in September 2026. The druce.ai vendor wiki, counting 7.3k stars in August, called the traction real but young.

No reviewed source names a Bifrost customer, so the scale of paid use is not established. Maxim AI's homepage says more than 1,000 teams use Bifrost, and the wiki calls that figure an unverified vendor claim with no named references. The wiki also found no case studies or named financial-services customers.

Maxim AI sells an enterprise licence on top of the free gateway. It offers a 14-day enterprise trial and demos, and the on-premises guide directs enterprise deployers to the Bifrost team for registry credentials. Google Cloud's partner directory includes a Maxim AI profile describing both Bifrost and the evaluation platform. [s4, s12, s1, s22, s28]

Team & Credibility Vaibhavi Gangwar and Akshay Deo founded Maxim AI in 2023…

Vaibhavi Gangwar and Akshay Deo founded Maxim AI in 2023. Robotics 24/7 reported at the June 2024 seed round that the co-founders bring over a decade of experience from Google and the API development platform Postman. Maxim AI's about page says its team has built and scaled products at Google, Postman, Slack and Microsoft Research.

The seed round drew angel investors from other technology companies. Robotics 24/7 reported participation from founders of Postman, Chargebee, Groww, Razorpay and Media.net alongside lead investor Elevation Capital. The reviewed sources name the founders' former employers but no earlier product either founder led, and they record no exit.

The druce.ai vendor wiki describes Bifrost as a single-vendor project. Maxim AI dominates contributions, and the wiki records no foundation or second commercial backer. [s17, s5, s12]

Trust Readiness Maxim AI's financial-services page describes Bifrost's on-premises and in-VPC deployment as SOC 2 Type II, HIPAA and ISO 27001 compliant, and its evaluation-platform page says Maxim is also GDPR compliant…

Maxim AI's financial-services page describes Bifrost's on-premises and in-VPC deployment as SOC 2 Type II, HIPAA and ISO 27001 compliant, and its evaluation-platform page says Maxim is also GDPR compliant. No audit report appears in the reviewed sources, and the druce.ai vendor wiki found no SOC 2, ISO 27001 or similar certification published for Bifrost or Maxim AI.

Bifrost's 2026 vulnerability record is public. NVD lists CVE-2026-55245, a flaw that let an attacker who controls a multimodal request URL make the gateway fetch internal services. Version 1.5.17 fixed it, and OSV rates it 8.7. JFrog's security research team published CVE-2026-86242, an unauthenticated remote code execution flaw through a custom plugin path on dynamically linked builds, fixed in the 2.0.0 HTTP transport.

The project runs coordinated disclosure. On September 23, 2026, its GitHub security page published the plugin advisory alongside a critical advisory for MCP stdio remote code execution. The policy commits to acknowledging reports within 48 hours. The documentation describes Snyk and CodeQL scanning, Dependabot updates and a FIPS base image for the production container.

For regulated deployments the main control is where the software runs. Bifrost Enterprise supports on-premises and air-gapped deployment, and Maxim AI's government page pitches deployment inside an agency's authorized GovCloud environment. [s34, s32, s9, s12, s25, s13, s14, s24, s10, s22, s35]

Competitors LiteLLM, Portkey, TrueFoundry, Kong, Cloudflare…
Company Relationship Note Compare
LiteLLM competes with The druce.ai vendor wiki names LiteLLM as Bifrost's direct target, and platform teams compare the two gateways for the same job. N/AWe scored these companies at different scopes, so the totals measure different things.
Portkey competes with The druce.ai vendor wiki lists Portkey among Bifrost's AI gateway alternatives, and a June 2026 gateway benchmark tested the two side by side. N/AWe scored these companies at different scopes, so the totals measure different things.
TrueFoundry competes with TrueFoundry publishes a Bifrost-versus-LiteLLM comparison that sets its own broader AI platform beside both. N/AWe scored these companies at different scopes, so the totals measure different things.
Kong competes with The druce.ai vendor wiki lists Kong among gateway incumbents extending into AI, competing for the same control point over model traffic. N/AWe scored these companies at different scopes, so the totals measure different things.
Cloudflare competes with The druce.ai vendor wiki lists Cloudflare among gateway and networking incumbents extending into AI. N/AWe scored these companies at different scopes, so the totals measure different things.

Add analyzed competitors to compare them side by side with Maxim AI.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 14 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

Applications that route their model calls through Bifrost depend on it for every call to a provider. They connect through an OpenAI-compatible endpoint after a one-line change, so a customer leaving Bifrost would repoint them and rebuild its virtual keys, team budgets, routing rules and guardrail profiles. The gateway code is public under the Apache 2.0 licence. What Maxim AI charges for is the enterprise layer on that open core: guardrails, single sign-on, audit logs and clustering.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Maxim AI sells gateway software that the customer's platform team installs, configures and operates, free under Apache 2.0 or under an enterprise licence. The customer owns the routing and guardrail outcomes, so the software is the product.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Leaving means pointing applications at another gateway and rebuilding virtual keys, team budgets, routing rules and guardrail profiles, which is meaningful friction. Applications connect to Bifrost through an OpenAI-compatible endpoint after a one-line change, and leaving reverses that change. The cited record documents the switching mechanism but does not size the migration.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 Maxim AI claims SOC 2 Type II, ISO 27001, HIPAA and GDPR compliance, which a funded rival can achieve through ordinary preparation, and the druce.ai wiki found no published certification. The cited record ties no regulation or authorization to Bifrost that would block a replacement.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Bifrost routes live traffic across more than 20 providers with automatic failover, adaptive load balancing and a peer-to-peer cluster mode. It also applies guardrail checks inline on prompts, responses and MCP tool calls. That is real-time distributed-systems work, and a benchmark by the developer of the rival GoModel gateway, run against an instant mock backend, measured it at 3,100 requests per second.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 Buyer profile scores the buyer class the line is built and sold for. Maxim AI builds and sells Bifrost's enterprise edition for regulated financial institutions and government agencies, with air-gapped deployment inside GovCloud or Azure Government and on-premises installation. The druce.ai wiki finds no certifications or named financial-services customers, so this is positioning rather than proven traction, which the positioning reading credits. That meets rung 3.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 3/3 Applications send model requests through Bifrost after changing their base URL, and the gateway routes each one to a provider before it proceeds. Where a deployment enforces virtual keys, which the documentation makes optional by default, the gateway also authenticates each request and applies that key's budgets and rate limits. That puts the open-source gateway between those applications and their model providers for every request routed through it.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 No cited source names a retained dataset, content licence or granted patent, and the gateway code is public under Apache 2.0. What the record evidences is software a customer can run on its own infrastructure and its own traffic.
Strategic Market Segmentation Bifrost is built for the platform and engineering teams that run model access as shared infrastructure…

Bifrost is built for the platform and engineering teams that run model access as shared infrastructure. The druce.ai vendor wiki describes it as a component a platform team adopts on its own authority. Maxim AI's enterprise page sells it as a single control panel for AI infrastructure.

Maxim AI aims the enterprise tier at regulated buyers. Maxim AI publishes industry pages promising air-gapped security and audit trails to regulated financial institutions, and deployment inside authorized GovCloud environments to government agencies. The wiki describes adoption as self-hosted infrastructure chosen on engineering judgement rather than procured on a compliance dossier.

Maxim AI's other product, an evaluation and observability platform for AI agents, is aimed at developers building AI applications. The wiki notes that buyers shop for Bifrost against LiteLLM rather than against that evaluation suite.

Product Capabilities & AI Advantages Bifrost's core is traffic control…

Bifrost's core is traffic control. Applications connect to it through an OpenAI-compatible endpoint, and the gateway fails over between providers. Where a deployment enforces virtual keys, it also applies each key's budgets and rate limits.

Bifrost uses AI in its guardrails. Prompt Guardrails use an LLM as a judge of plain-language policies, regex rules run in-process, and secrets detection is built in on Gitleaks. Bifrost also calls outside services such as AWS Bedrock Guardrails and Google Model Armor. The druce.ai vendor wiki notes that none of this runs in the free build.

Maxim AI's newest extension covers employee devices. Bifrost Edge, offered in early access, installs through Jamf, Intune or Kandji. It sends AI requests from desktop apps, browser AI and coding tools through the customer's Bifrost gateway for governance and guardrails.

Sales Engagement & Go-to-Market Maxim AI sells Bifrost through an open-source funnel…

Maxim AI sells Bifrost through an open-source funnel. Maxim AI distributes the free gateway as a Go binary that starts with npx or Docker, and it offers the enterprise edition through a 14-day trial and demos.

No reviewed source names a paying customer or a sales partner for Bifrost. The homepage claims more than 1,000 teams, which the druce.ai vendor wiki calls unverified. Google Cloud's partner directory lists Maxim AI as a company rather than naming Bifrost deployments.

Interest in the free code is measurable. The repository showed 8.3k stars and 1.3k forks in September 2026, and the wiki had recorded 7.3k stars in August.

Pricing Model The core gateway is free under the Apache 2.0 licence…

The core gateway is free under the Apache 2.0 licence. Maxim AI prices the enterprise edition privately. The druce.ai vendor wiki found no published list pricing and describes a sales conversation for clustering, guardrails, single sign-on, role-based access control and audit logs.

That split puts content guardrails, single sign-on and configuration audit logs in the paid edition. Teams on the free build get routing, budgets and the request log.

Product Delivery & Operations Bifrost runs in the customer's environment…

Bifrost runs in the customer's environment. The open-source gateway runs as a binary or in Docker, and Bifrost Enterprise supports on-premises and air-gapped deployment with images pulled using credentials the Bifrost team issues.

Maxim AI develops the project quickly and in public. The repository showed 7,368 commits by September 2026, and the 2.0.0 HTTP transport release included the fix for the plugin-path flaw JFrog reported.

Build security is documented. Maxim AI describes Snyk and CodeQL scanning, Dependabot dependency updates and a FIPS base image with a non-root user for the production container.

Earning Customers' Trust Maxim AI's financial-services page describes Bifrost's on-premises and in-VPC deployment as SOC 2 Type II, HIPAA and ISO 27001 compliant, and its evaluation-platform page says Maxim is also GDPR compliant…

Maxim AI's financial-services page describes Bifrost's on-premises and in-VPC deployment as SOC 2 Type II, HIPAA and ISO 27001 compliant, and its evaluation-platform page says Maxim is also GDPR compliant. No audit report appears in the reviewed sources, and the druce.ai vendor wiki found no SOC 2, ISO 27001 or similar certification published for Bifrost or Maxim AI.

Bifrost's 2026 vulnerability record is public. NVD lists CVE-2026-55245, a flaw that let an attacker who controls a multimodal request URL make the gateway fetch internal services. Version 1.5.17 fixed it. JFrog's security research team published CVE-2026-86242, unauthenticated remote code execution through a custom plugin path on dynamically linked builds. The GitHub security page added a critical advisory for MCP stdio remote code execution on September 23, 2026.

The audit log covers configuration changes rather than model traffic. Bifrost Enterprise records who changed what in the gateway, and its entries can be signed with an HMAC key.

Platform Strategy & Ecosystem Positioning Bifrost's breadth comes from compatibility…

Bifrost's breadth comes from compatibility. It fronts more than 20 providers, including OpenAI, Anthropic, AWS Bedrock, Google Vertex and Azure. Applications built on the OpenAI, Anthropic, Vercel AI and LangChain SDKs switch to it with a one-line change.

The guardrail layer is an integration hub. Beside Bifrost's own checks, the documentation lists Presidio, Azure AI Language PII, AWS Bedrock Guardrails, Azure Content Safety and Google Model Armor. It also names CrowdStrike AIDR, Gray Swan Cygnal, Patronus AI, Check Point's AI Agent Security, Repello Argus and Singulr AI.

Enterprise integrations connect to identity and secrets systems. The enterprise page lists SAML single sign-on and secret storage in HashiCorp Vault, AWS Secrets Manager, Google Secret Manager and Azure Key Vault.

Team & Execution Capability Vaibhavi Gangwar and Akshay Deo founded Maxim AI in 2023…

Vaibhavi Gangwar and Akshay Deo founded Maxim AI in 2023. Robotics 24/7 reported that the co-founders bring over a decade of experience from Google and the API development platform Postman. The about page lists Google, Postman, Slack and Microsoft Research among the team's former employers.

The druce.ai vendor wiki describes Bifrost as a single-vendor project. Maxim AI dominates contributions, and the wiki records no foundation or second commercial backer.

Sources

Company Detail Sources (4)
Id Source Tier Accessed
f1 Maxim AI: about us official 2026-09-23
f2 Robotics 24/7: Maxim AI announces general availability, $3 million funding round press 2026-09-23
f3 Maxim AI: privacy policy official 2026-09-23
f4 AI Defense Matrix Catalog mapping other 2026-09-23
Profile Analysis Sources (24)
Id Source Tier Accessed
s1 Maxim AI: Bifrost homepage official 2026-09-23
s3 Bifrost documentation: overview official 2026-09-23
s4 GitHub: maximhq/bifrost repository official 2026-09-23
s5 Maxim AI: about us official 2026-09-23
s7 Maxim AI: Bifrost Enterprise page official 2026-09-23
s8 Bifrost documentation: guardrails official 2026-09-23
s9 Maxim AI trust-center probe (2026-09-23): trust.getmaxim.ai served a CloudFront 403 block page to a rendered browser fetch, agent-browser render official 2026-09-23
s10 Bifrost documentation: security practices official 2026-09-23
s12 druce.ai AI Governance and Security Vendor Wiki: Bifrost vendor page research 2026-09-23
s13 OSV: GHSA-w98g-5w9p-p3rc advisory for Bifrost core research 2026-09-23
s14 JFrog Security Research: JFSA-2026-001684572 advisory for Bifrost (CVE-2026-86242) research 2026-09-23
s16 enterpilot blog: Benchmarking AI Gateways, GoModel vs LiteLLM vs Portkey vs Bifrost research 2026-09-23
s17 Robotics 24/7: Maxim AI announces general availability, $3 million funding round press 2026-09-23
s20 Maxim AI: Bifrost Edge page official 2026-09-23
s21 Bifrost documentation: virtual keys official 2026-09-23
s22 Bifrost documentation: on-premise enterprise deployment official 2026-09-23
s23 Bifrost documentation: audit logs official 2026-09-23
s24 GitHub: maximhq/bifrost security policy and advisories official 2026-09-23
s25 NVD record for CVE-2026-55245 in Bifrost regulatory 2026-09-23
s28 Google Cloud Partner Finder: Maxim AI profile other 2026-09-23
s29 TrueFoundry blog: Bifrost vs LiteLLM, choosing the right AI gateway other 2026-09-23
s32 Maxim AI: evaluation and observability platform page official 2026-09-23
s34 Maxim AI: Bifrost financial services and banking page official 2026-09-23
s35 Maxim AI: Bifrost government and public sector page official 2026-09-23
Deep-Dive Sources (24)
Id Source Tier Accessed
s1 Maxim AI: Bifrost homepage official 2026-09-23
s3 Bifrost documentation: overview official 2026-09-23
s4 GitHub: maximhq/bifrost repository official 2026-09-23
s5 Maxim AI: about us official 2026-09-23
s7 Maxim AI: Bifrost Enterprise page official 2026-09-23
s8 Bifrost documentation: guardrails official 2026-09-23
s9 Maxim AI trust-center probe (2026-09-23): trust.getmaxim.ai served a CloudFront 403 block page to a rendered browser fetch, agent-browser render official 2026-09-23
s10 Bifrost documentation: security practices official 2026-09-23
s12 druce.ai AI Governance and Security Vendor Wiki: Bifrost vendor page research 2026-09-23
s13 OSV: GHSA-w98g-5w9p-p3rc advisory for Bifrost core research 2026-09-23
s14 JFrog Security Research: JFSA-2026-001684572 advisory for Bifrost (CVE-2026-86242) research 2026-09-23
s16 enterpilot blog: Benchmarking AI Gateways, GoModel vs LiteLLM vs Portkey vs Bifrost research 2026-09-23
s17 Robotics 24/7: Maxim AI announces general availability, $3 million funding round press 2026-09-23
s20 Maxim AI: Bifrost Edge page official 2026-09-23
s21 Bifrost documentation: virtual keys official 2026-09-23
s22 Bifrost documentation: on-premise enterprise deployment official 2026-09-23
s23 Bifrost documentation: audit logs official 2026-09-23
s24 GitHub: maximhq/bifrost security policy and advisories official 2026-09-23
s25 NVD record for CVE-2026-55245 in Bifrost regulatory 2026-09-23
s28 Google Cloud Partner Finder: Maxim AI profile other 2026-09-23
s29 TrueFoundry blog: Bifrost vs LiteLLM, choosing the right AI gateway other 2026-09-23
s32 Maxim AI: evaluation and observability platform page official 2026-09-23
s34 Maxim AI: Bifrost financial services and banking page official 2026-09-23
s35 Maxim AI: Bifrost government and public sector page official 2026-09-23

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.