Mindgard

Security for AI also known as Mindgard Ltd

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software.
Founded 2022
Last updated 2026-07-09

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Mindgard sells automated AI red teaming that finds prompt-injection and jailbreak flaws before an enterprise deploys AI. Its credibility comes from published research: its team's techniques evaded six protection systems including Microsoft's Azure Prompt Shield, documented in a 2025 LLMSec paper, and Microsoft acknowledged the issue while disputing its severity. The public record names no paying customer, only unnamed Fortune 500 design partners. The Defend module monitors production traffic inline to block attacks, the piece hardest for a buyer to drop, while the red-team testing is easy to adopt and to cancel. Mindgard has proven its research standing. The commercial traction to match it is not yet public.

Sourced Details

Description Mindgard is an AI security platform that operates as an autonomous red teamer, continuously mapping and running attack workflows against enterprise models and agents to find and reduce exploitable AI vulnerabilities. [f1]
Founded 2022 [f2]
HQ Boston, Massachusetts and London, United Kingdom [f3]
Latest funding $8M seed led by .406 Ventures (December 2024) [f4]
Deployment SaaS [f5]

Products

Product What it does
Mindgard Automated AI red-teaming platform that maps the AI attack surface and continuously tests models and agents for prompt injection, jailbreak, and model-manipulation flaws.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Mindgard is an automated AI red-teaming platform that maps the AI attack surface and continuously tests models and agents for prompt injection, jailbreak, and model-manipulation flaws. It is mapped to the AI Defense Matrix. [f6]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 26 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 The buyer and problem are clear, the enterprise security team that needs to catch prompt-injection and jailbreak flaws traditional application security tools miss. The pain is corroborated beyond marketing by an LLMSec 2025 paper and independent press, but the quantification traces to Mindgard's own research rather than independent market-scale measurement, so it sits at present-but-unproven. [s2, s8, s9]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 4/5 The platform automates adversary workflows across reconnaissance, attack, and defense, deploys through CI/CD and Burp Suite, and maps findings to the EU AI Act, NIST AI RMF, OWASP, and MITRE ATLAS. A public documentation portal carries a Quickstart and a named Attack Library, evidence of a shipped product, and the external validation is strong: an LLMSec 2025 paper and an independently covered bypass of Microsoft Azure AI Content Safety filters. [s2, s3, s6, s8]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 4/5 The enabler is the move of enterprise AI into production since 2023 without security assurances, and the EU AI Act plus the OWASP LLM Top 10 and MITRE ATLAS signal that buyers now treat AI red teaming as a recognized need. The 2025 consolidation, Check Point's agreement for Lakera and the completed Palo Alto Networks purchase of Protect AI, is independent demand validation for the category. [s2, s8, s12, s13]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 4/5 Founder Peter Garraghan is a Lancaster University professor and EPSRC Fellow with more than 60 published research articles, and the LLMSec 2025 paper plus the independently covered Azure filter bypass make a sustained in-domain record rather than a single event. CEO James Brear previously led Swimlane, and senior offensive-security hires deepen the bench. [s8, s14, s4, s16]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 2/5 No named paying customer appears in the reviewed sources, only unnamed Fortune 500 design partners plus awards and publicized research disclosures, so the score sits at the unnamed-traction level with a small upward adjustment for the .406 Ventures seed and the research disclosures that draw independent coverage. [s4, s1, s11]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 The 8 million dollar seed is proportional to an early enterprise motion with visible shipping across testing and the Defend runtime module, but no disclosed revenue, customer growth, or efficiency metric confirms output per dollar, the honest default for a funded private startup. [s11, s3, s5]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Automated AI red teaming is externally placed by the OWASP LLM Top 10, MITRE ATLAS, and the 2025 consolidation, but the category is still forming rather than established and buyers still place it across application security, AI governance, and runtime budgets, so placement stays nascent. [s2, s8, s12, s13]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 Automated red teaming is absorbable by model providers and platform vendors, and the 2025 moves on Lakera and Protect AI show the pressure is real. The decade of Lancaster research and the adversarial-machine-learning bench raise replication cost but do not form a structural moat. [s8, s9, s12, s13]
Business Risks Platform vendors that consolidated the category, Check Point through its Lakera agreement and Palo Alto Networks through its completed Protect AI purchase, could fold automated AI red teaming into broader suites and undercut a standalone Mindgard purchase before it names commercial references…
  • Platform vendors that consolidated the category, Check Point through its Lakera agreement and Palo Alto Networks through its completed Protect AI purchase, could fold automated AI red teaming into broader suites and undercut a standalone Mindgard purchase before it names commercial references.
  • Model providers such as Microsoft could ship native red teaming for the systems built on their own platforms, removing the third-party budget line Mindgard depends on.
  • No named paying customer appears in the reviewed sources, so buyers who require current named references could stall enterprise deals.
  • Mindgard's pipeline depends on the guardrail-bypass disclosures it publishes, so vendors patching those guardrails, as Microsoft did with stronger Azure mitigations, could erode the research that drives its inbound interest.
  • The founder moved from chief executive to Chief Science Officer in 2025 and an outside CEO took over, so if the enterprise sales motion does not take hold the research lead could outlast the commercial runway disclosed in the 2024 seed.
  • Switching cost stays low while testing findings are advisory rather than embedded in production controls, so a buyer can drop the subscription until the Defend runtime module matures into a daily dependency.
Problem & Market Mindgard treats the AI models, agents, and applications an enterprise runs as assets attackers target directly, and sells automated adversarial testing to find the flaws before deployment…

Mindgard treats the AI models, agents, and applications an enterprise runs as assets attackers target directly, and sells automated adversarial testing to find the flaws before deployment. The company frames the problem as runtime-specific, the prompt-injection and jailbreak weaknesses that exploit a model's probabilistic behavior and only appear once a system is live, which traditional application security tools were not built to catch.

Independent evidence corroborates the pain beyond vendor marketing. A 2025 paper from Mindgard's team, accepted to the LLMSec workshop, showed that six guardrail systems including Microsoft's Azure Prompt Shield could be evaded with up to 100 percent success, and CSO Online and Hackread covered the related Azure AI Content Safety bypass independently. Microsoft acknowledged the Azure issue and later deployed stronger mitigations, which establishes the problem as real rather than asserted.

The buyer is the enterprise security team, developer, or red teamer standing up AI in production. Mindgard routes them to a platform that integrates into existing automation, so the offering reads as a testing capability that fits established workflows rather than a separate practice a team must staff and learn. [s2, s8, s9]

Product Capabilities The Mindgard platform runs as an autonomous red teamer rather than a fixed checklist…

The Mindgard platform runs as an autonomous red teamer rather than a fixed checklist. The product chains domain-specific attack techniques across one-shot and multi-step interactions to map the models, agents, and tools in a system, plan attacks, and surface the highest-impact flaws. Findings map to the EU AI Act, the NIST AI Risk Management Framework, the OWASP LLM Top 10, and MITRE ATLAS so a security team can translate them into governance and reporting.

The deployment design targets teams without specialist AI expertise. Mindgard runs through CI/CD pipelines, the Burp Suite proxy, or a single click, and a public documentation portal carries a Quickstart and a named Attack Library of LLM and ML techniques, evidence of a shipped product rather than a demo.

The research output demonstrates the same capability the product sells. The LLMSec 2025 paper documented character-injection and adversarial-machine-learning bypasses of Microsoft's Azure Prompt Shield and Content Safety filters, work that CSO Online and Hackread covered, which validates that the team can find the complex flaws the platform automates. [s2, s6, s8]

Competitive Positioning Mindgard competes in automated AI red teaming against both independent specialists, such as Adversa AI and Repello AI, and broader AI-security platforms, such as HiddenLayer, alongside the platform vendors that bought the category around it…

Mindgard competes in automated AI red teaming against both independent specialists, such as Adversa AI and Repello AI, and broader AI-security platforms, such as HiddenLayer, alongside the platform vendors that bought the category around it. The 2025 consolidation puts overlapping adversarial testing inside larger suites.

Mindgard's visible differentiator is the depth and independence of its research. The company came out of more than a decade of academic work at Lancaster University, where founder Peter Garraghan has published more than 60 research articles, and it publishes guardrail-bypass findings that outside outlets cover, which gives it a profile larger than its headcount would predict. That research is the part a bundled competitor would take the longest to reproduce.

The structural risk is who owns the buyer. Check Point agreed to acquire Lakera and Palo Alto Networks completed its purchase of Protect AI in 2025, so platform vendors can bundle red teaming into deals an enterprise already signs, and the model providers whose guardrails Mindgard probes could test the systems built on their own platforms. [s8, s12, s13]

Go-to-Market & Traction Research is Mindgard's clearest go-to-market engine, and it points outward rather than at named accounts…

Research is Mindgard's clearest go-to-market engine, and it points outward rather than at named accounts. The team's guardrail-bypass findings against Microsoft Azure and other targets drew independent coverage from CSO Online and Hackread, which builds inbound awareness and positions the company as a research authority. This is demand generation through public findings rather than evidence of paid deployments.

Verifiable commercial proof is thin. The about page records Fortune 500 design partners in 2026 but names none, and the other signals on offer are awards and the publicized guardrail-bypass disclosures, not named paying references. The 8 million dollar seed that .406 Ventures led in December 2024 funds the build, but the paying buyers themselves are not yet visible.

The motion is early, opening through a booked demo rather than self-serve signup. Mindgard leans on a low-friction first scan through CI/CD and Burp Suite and on its research brand to open enterprise conversations. Named references would be the signal that the inbound attention its disclosures generate has converted into deployments. [s4, s11, s9]

Team & Credibility The founding story pairs academic depth with offensive-security craft…

The founding story pairs academic depth with offensive-security craft. Peter Garraghan founded Mindgard on his Lancaster University research and is a professor and EPSRC Fellow there with more than 60 published research articles, and the company is spun out from over a decade of AI security research at Lancaster. The bench is unusually research-heavy for the stage.

The research record is the team's strongest public signal. Mindgard has published a stream of in-domain adversarial work, including the LLMSec 2025 guardrail-evasion paper and the documented bypass of Microsoft's Azure Prompt Shield and Content Safety filters that independent outlets covered. This is a sustained publication pattern in the company's own product domain rather than a single covered event.

The leadership matured as the company scaled. Garraghan led as chief executive through the 2024 raise and moved to Chief Science Officer in 2025, when Mindgard brought in James Brear as chief executive alongside the senior research and offensive-security hires Aaron Portnoy and Rich Smith, separating the founder's research role from the commercial leadership the next stage demands. [s14, s8, s4]

Trust Readiness Mindgard publishes the trust artifact a security buyer checks first…

Mindgard publishes the trust artifact a security buyer checks first. The site displays an AICPA SOC 2 Type 2 badge in the footer, which gives a procurement team a starting point rather than only a sales conversation. No inspectable trust portal or downloadable report surfaces in the fetched pages beyond that badge.

The deeper trust question is the one any offensive testing vendor faces. Mindgard's product probes a customer's proprietary AI systems and the Defend module sits inline in production, so a security review will ask where the testing runs and what data leaves the environment. The pages reviewed describe integration through CI/CD and proxies but do not lay out the data-handling and isolation detail a regulated buyer would press on, which is the readiness item most likely to surface in a deal. [s15, s5]

Competitors Adversa AI, Lakera, HiddenLayer, Repello AI, Noma Security, Microsoft…
Company Relationship Note Compare
Adversa AI competes with Independent continuous AI red teaming specialist contesting the same adversarial-testing buyer.
Lakera competes with Shipped automated AI red teaming alongside runtime guardrails before Check Point agreed to acquire it, overlapping Mindgard's testing motion.
HiddenLayer competes with Independent AI security platform whose attack-simulation module runs red teaming inside a broader lifecycle suite.
Repello AI competes with Offers automated AI red teaming for generative-AI applications, a direct same-category independent.
Noma Security adjacent Covers AI discovery, governance, and runtime protection for the same enterprise AI buyer, adjacent to Mindgard's testing focus. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Microsoft adjacent Model and platform provider whose Azure AI guardrails Mindgard has probed and that could test the systems built on its own platform. N/AMicrosoft is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product.

Add analyzed competitors to compare them side by side with Mindgard.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Exposed 12 /21 Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software. pivot urgently

Most of what built Mindgard's name is public and replicable. Its guardrail-bypass findings are published, its attack-technique library is advertised, and customers run the testing on their own AI systems, so a funded rival could reproduce most of the offering. The adversarial machine-learning skill behind that research, shown when its researchers evaded six protection systems in a 2025 LLMSec paper, takes years to build and is the real head start, though not yet a durable lead. A self-displayed SOC 2 badge and framework mappings ease procurement any peer can match. No paid reference customer appears in the public record. Where leaving would cost a buyer most is the Defend module, which screens production traffic inline and must be re-integrated to remove.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Customers connect Mindgard to their own AI systems, launch the automated tests, consume the reports, and run the remediation themselves. The delivered artifact is software the buyer operates and configures, the software-product level.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Testing is advisory and low-friction to adopt and to drop through CI/CD and Burp Suite, while the Defend module sits inline in production where leaving means re-integrating enforcement, real friction short of data residency or network effects.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 Mindgard self-displays an AICPA SOC 2 Type 2 badge and maps findings to the EU AI Act, NIST AI RMF, OWASP, and MITRE ATLAS, table-stakes assurance that eases procurement. No regulation mandates an AI red-teaming product.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Chaining domain-specific attack techniques across one-shot and multi-step interactions to find prompt-injection and jailbreak flaws, built on a decade of Lancaster University machine-learning security research and shown in the LLMSec 2025 paper, is applied adversarial ML that takes years of expertise.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 The named buyer is the enterprise security team, with unnamed Fortune 500 design partners cited as the demand signal and no paid reference customer in the public record, a thin regulated footing.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 The platform tests a customer's AI systems and the Defend module screens production traffic, a control layer beside the workload a customer can swap, not infrastructure other software depends on to function.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 Mindgard advertises a named, ever-growing Attack Library of LLM and ML attack techniques on its public documentation portal, and the guardrail-bypass research that built its name is published, so the corpus is replicable rather than a non-public dataset.
Strategic Market Segmentation Mindgard sells to the enterprise security team, developer, or red teamer standing up AI in production…

Mindgard sells to the enterprise security team, developer, or red teamer standing up AI in production. The company frames its buyer as an enterprise that needs to discover, assess, and defend the AI models, agents, and applications it runs, and routes that buyer through a platform rather than a consulting engagement. The pain it names is AI-specific, the prompt-injection and jailbreak weaknesses traditional application security tools were not built to catch.

The segment is the upper enterprise reached through direct sales. The about page records Fortune 500 design partners in 2026 as the demand signal, and the entry point is a booked demo rather than self-serve signup, the shape of a vendor selling negotiated enterprise deals. Incorporated in the UK in 2022 and now headquartered in Boston and London, Mindgard reaches both US and UK enterprise buyers.

The segmentation widens by surface rather than by buyer. Mindgard spans discovery, reconnaissance, automated attack, and runtime defense on one platform, so it can address an enterprise across the AI lifecycle regardless of which models it runs. That breadth puts it against both independent AI red-teaming specialists and the platform vendors that bought adjacent runtime AI security companies in 2025.

Product Capabilities & AI Advantages Mindgard runs as an autonomous red teamer rather than a fixed checklist…

Mindgard runs as an autonomous red teamer rather than a fixed checklist. The product chains domain-specific attack techniques across one-shot and multi-step interactions to evaluate how models reason and behave under pressure, and tests complete AI systems rather than isolated models, capturing how agents, tools, APIs, and data sources interact. Findings map to the EU AI Act, the NIST AI Risk Management Framework, the OWASP LLM Top 10, and MITRE ATLAS for governance and reporting.

The deployment design targets teams without specialist AI expertise. Mindgard deploys through CI/CD, the Burp Suite proxy, or a single click, and surfaces high-impact findings with attacker context and remediation guidance that teams send into existing tooling and ticketing systems.

The verifiable footprint is strong for the category. A public documentation portal carries a Quickstart and a named Attack Library, evidence of a shipped product rather than a demo, and the LLMSec 2025 paper showing up to 100 percent evasion of six guardrail systems including Microsoft's Azure Prompt Shield validates that the team can find the complex flaws the platform automates. The accumulating attack library plus a decade of Lancaster research is the part a rival would take the longest to match, since the frontier models are ones every competitor can license.

Sales Engagement & Go-to-Market Research is Mindgard's clearest go-to-market engine, and it points outward rather than at named accounts…

Research is Mindgard's clearest go-to-market engine, and it points outward rather than at named accounts. The team's guardrail-bypass disclosures, including the Azure AI Content Safety bypass that CSO Online and Hackread covered, build inbound awareness and position the company as a research authority. This is demand generation through public findings rather than evidence of paid deployments.

Commercial proof stays thin. The about page records Fortune 500 design partners in 2026 but names none, and the other signals on offer are awards and the publicized guardrail-bypass disclosures, not named paying references. No paying customer speaks in its own voice in the fetched sources.

The motion is early and demo-led. Mindgard leans on a low-friction first scan through CI/CD and Burp Suite and on its research brand to open enterprise conversations, with a booked demo as the entry point. The 8 million dollar seed that .406 Ventures led in December 2024 funds the build, and named references would be the signal that inbound attention has converted into deployments.

Pricing Model Mindgard publishes no public price, so the charged unit and list price stay private…

Mindgard publishes no public price, so the charged unit and list price stay private. Every conversion path on the site routes to a booked demo rather than a rate card or free tier, the posture of a vendor selling negotiated enterprise deals to the Fortune 500 buyer it names. The absence withholds the budget-anchoring signal some peers publish.

The buying unit is not publicly answerable from the record. Because the platform tests AI systems and the Defend module sits in the production request flow, cost would plausibly track the number of systems tested or the volume of traffic screened, but that is inference rather than a published unit.

The inferable belief is that buyers pay for assurance over a moving AI attack surface rather than for a fixed feature set. Confirming the unit and whether testing volume is capped would require a sales conversation, which the demo-only posture signals is the intended path.

Product Delivery & Operations Mindgard delivers as software the customer connects to its own AI systems and runs, not as a managed engagement…

Mindgard delivers as software the customer connects to its own AI systems and runs, not as a managed engagement. The platform flow is connect, launch automated discovery and assessment, integrate findings into security workflows, and remediate, with the customer operating the tests and consuming the reports. A team can bring its own techniques to test its systems its way.

The operational job follows a moving attack surface rather than a static rule set. Mindgard runs recon, safety, and adversarial evaluations, deploys through CI/CD and Burp Suite, and the Defend module continuously monitors prompts, responses, and agent actions to block malicious behavior in production. Published uptime or support service-level commitments do not surface in the fetched pages.

The runtime module raises the heavier operational question. A control that sits in the production AI request flow becomes a dependency whose latency and availability a careful buyer examines, and the fetched pages describe the blocking behavior but not the data-handling and isolation detail a regulated buyer testing its own proprietary models would press on.

Earning Customers' Trust Mindgard publishes the trust artifact a security buyer checks first…

Mindgard publishes the trust artifact a security buyer checks first. The site displays an AICPA SOC 2 Type 2 badge in the footer, confirmed in the rendered page, which gives a procurement team a starting point rather than only a sales conversation. No inspectable trust portal or downloadable report surfaces in the fetched pages beyond that badge.

The research record adds to that assurance. The LLMSec 2025 paper and the documented bypass of Microsoft's Azure AI Content Safety filters, which CSO Online covered along with Microsoft's response, are public evidence that the team understands the attacks the product runs, an in-domain signal a buyer can weigh alongside the attestation. Findings also map to the EU AI Act, NIST AI RMF, OWASP, and MITRE ATLAS, which helps a buyer translate results into its own compliance reporting.

The deeper trust question is the one any offensive testing vendor faces. Because Mindgard's product probes a customer's proprietary AI models and its Defend layer sits inline in production, a security review will ask where the testing runs and what data leaves the environment, the readiness item most likely to surface in a regulated deal beyond the published badge.

Platform Strategy & Ecosystem Positioning Mindgard positions itself as the security control point across an enterprise's AI estate rather than a point tool…

Mindgard positions itself as the security control point across an enterprise's AI estate rather than a point tool. It spans discovery of agents and shadow AI, reconnaissance, automated attack, and runtime defense on one platform, and tests complete AI systems including agents, tools, APIs, and data sources rather than isolated models. The platform claim rests on covering the full attack surface an enterprise exposes when it adopts AI.

Outward, the company reaches buyers as model-agnostic coverage that works regardless of which AI tools an enterprise runs. By deploying through CI/CD and Burp Suite and sending findings into existing security tooling and ticketing systems, Mindgard fits established workflows rather than asking a team to adopt a separate practice.

The exposure is who owns the buyer. Palo Alto Networks completed its purchase of Protect AI and Check Point agreed to acquire Lakera in 2025, so platform vendors can bundle equivalent red teaming into deals an enterprise already signs, and the model providers whose guardrails Mindgard probes could test the systems built on their own platforms.

Team & Execution Capability Mindgard's credibility comes from an academic research lineage that is unusual for the stage…

Mindgard's credibility comes from an academic research lineage that is unusual for the stage. Founder Peter Garraghan is a Lancaster University professor and EPSRC Fellow with more than 60 published research articles, now Chief Science Officer, and the company is spun out from over a decade of AI security research at Lancaster. The Azure AI Content Safety bypass the team disclosed, and the LLMSec 2025 guardrail-evasion paper, show the craft is in-domain rather than a single unrelated finding.

The leadership matured as the company scaled. The about page records a 2025 milestone of expanded leadership with key hires, an outside chief executive in James Brear, alongside the senior research and offensive-security hires Aaron Portnoy and Rich Smith, separating the founder's research role from the commercial leadership the enterprise stage demands. Brear previously led Swimlane, a security automation company, before joining Mindgard.

The verifiable strength is the research record and the named senior leaders, with the open item the depth of the commercial organization. The 8 million dollar seed that .406 Ventures led in December 2024 funds the build, and whether the new leadership converts the research brand into a paying book of business is what the team has yet to prove publicly.

Sources

Company Detail Sources (6)
Id Source Tier Accessed
f1 Mindgard: AI Security Platform official 2026-07-09
f2 Companies House: MINDGARD LTD (company number 14120558) regulatory 2026-06-29
f3 About Mindgard official 2026-06-13
f4 Tech.eu on the Mindgard 8M raise press 2026-06-13
f5 AI Defense Matrix Catalog entry other 2026-06-09
f6 AI Defense Matrix Catalog mapping other 2026-06-23
Profile Analysis Sources (16)
Id Source Tier Accessed
s1 Mindgard homepage
“Deploy through CI/CD, Burp Suite, or a single click. Mindgard gives teams actionable AI security insights without requiring specialist AI security expertise in-house.”
official 2026-06-29
s2 Mindgard automated AI red teaming page
“Identified risks are mapped to global and industry frameworks, including the EU AI Act, NIST AI Risk Management Framework, OWASP LLM Top 10, and MITRE ATLAS, allowing organizations to translate technical findings into defensible governance, compliance, and reporting outcomes.”
official 2026-06-29
s3 Mindgard AI Security Platform page
“Spun out from over a decade of AI security research at Lancaster University and headquartered in Boston and London, Mindgard combines AI red teaming with offensive security expertise and AI research to identify exploitable vulnerabilities in AI models, agents, and applications before attackers do.”
official 2026-06-29
s4 About Mindgard (leadership, key milestones)
“Expanded leadership with key hires: CEO James Brear, Head of Research Aaron Portnoy, and Offensive Security Lead Rich Smith. Secured Fortune 500 design partners, validating enterprise demand for attacker-aligned AI security.”
official 2026-06-29
s5 Mindgard Defend runtime detection and response page
“Mindgard Defend continuously monitors prompts, responses, and agent actions to identify malicious behavior. Runtime detection and response uses intelligence gathered during reconnaissance and red teaming to stop attacks in production.”
official 2026-06-29
s6 Mindgard product documentation portal
“Jump right in: 5 minute Quickstart. Attack Library: An ever growing list of LLM/ML attack techniques.”
official 2026-06-29
s7 Companies House: MINDGARD LTD (company number 14120558)
“Company status Active. Company type Private limited Company. Incorporated on 20 May 2022.”
regulatory 2026-06-29
s8 Bypassing LLM Guardrails, evading Microsoft Azure Prompt Shield (Hackett, Garraghan et al.), arXiv 2504.11168, LLMSec 2025
“Through testing against six prominent protection systems, including Microsoft's Azure Prompt Shield and Meta's Prompt Guard, we show that both methods can be used to evade detection while maintaining adversarial utility achieving in some instances up to 100% evasion success.”
research 2026-06-29
s9 CSO Online: Security researchers circumvent Microsoft Azure AI Content Safety
“In response to queries from CSO, Microsoft acknowledged an issue but downplayed the seriousness of the problem by arguing that the techniques uncovered by Mindgard are limited to the user's individual session and do not pose a security risk to other users.”
press 2026-06-29
s10 Hackread: Azure AI Vulnerabilities Allowed Attacks to Bypass Moderation Safeguards
“A UK-based cybersecurity-for-AI startup, Mindgard, discovered two critical security vulnerabilities in Microsoft's Azure AI Content Safety Service in February 2024. The vulnerabilities were responsibly disclosed to Microsoft in March 2024.”
press 2026-06-29
s11 Tech.eu (Cate Lawrence): Mindgard secures $8M to tackle emerging AI security risks
“Mindgard secures $8M to tackle emerging AI security risks. According to Greg Dracon, Partner at .406 Ventures, the rapid adoption of AI has introduced new and complex security risks that traditional tools cannot address.”
press 2026-06-29
s12 Check Point: Acquires Lakera to Deliver End-to-End AI Security (16 Sep 2025)
“Check Point Software Technologies Ltd. today announced it has entered into an agreement to acquire Lakera, one of the world's leading AI-native security platforms for Agentic AI applications.”
press 2026-06-29
s13 Palo Alto Networks: Completes Acquisition of Protect AI (22 Jul 2025)
“Palo Alto Networks today announced it has completed its acquisition of Protect AI, an innovative leader in securing Artificial Intelligence (AI) applications and models.”
press 2026-06-29
s14 Lancaster University: Professor Peter Garraghan faculty profile
“Peter has published over 60 research articles, led software teams to create bleeding-edge technology, has industrial experience building large-scale production distributed systems, and has worked and collaborated internationally with the likes of Microsoft, Nvidia, BT, BBC, Alibaba Group.”
press 2026-06-29
s15 Mindgard AI Security Platform footer trust badge (SOC 2 Type 2)
“AICPA SOC SOC 2 Type 2 Compliant (footer trust badge image, COMPLIANCE LOGO-300.webp, displayed on the Mindgard AI Security Platform page).”
official 2026-06-29
s16 Mindgard: Appoints James Brear as CEO (October 2025)
“James Brear, a seasoned growth-stage CEO with over 15 years in cybersecurity, brings a proven track record of scaling public and private technology companies. Most recently, he served as CEO of Swimlane, where he grew the company into the industry’s largest standalone security automation provider.”
official 2026-06-29
Deep-Dive Sources (16)
Id Source Tier Accessed
s1 Mindgard homepage
“Deploy through CI/CD, Burp Suite, or a single click. Mindgard gives teams actionable AI security insights without requiring specialist AI security expertise in-house.”
official 2026-06-29
s2 Mindgard automated AI red teaming page
“Identified risks are mapped to global and industry frameworks, including the EU AI Act, NIST AI Risk Management Framework, OWASP LLM Top 10, and MITRE ATLAS, allowing organizations to translate technical findings into defensible governance, compliance, and reporting outcomes.”
official 2026-06-29
s3 Mindgard AI Security Platform page
“Spun out from over a decade of AI security research at Lancaster University and headquartered in Boston and London, Mindgard combines AI red teaming with offensive security expertise and AI research to identify exploitable vulnerabilities in AI models, agents, and applications before attackers do.”
official 2026-06-29
s4 About Mindgard (leadership, key milestones)
“Expanded leadership with key hires: CEO James Brear, Head of Research Aaron Portnoy, and Offensive Security Lead Rich Smith. Secured Fortune 500 design partners, validating enterprise demand for attacker-aligned AI security.”
official 2026-06-29
s5 Mindgard Defend runtime detection and response page
“Mindgard Defend continuously monitors prompts, responses, and agent actions to identify malicious behavior. Runtime detection and response uses intelligence gathered during reconnaissance and red teaming to stop attacks in production.”
official 2026-06-29
s6 Mindgard product documentation portal
“Jump right in: 5 minute Quickstart. Attack Library: An ever growing list of LLM/ML attack techniques.”
official 2026-06-29
s7 Companies House: MINDGARD LTD (company number 14120558)
“Company status Active. Company type Private limited Company. Incorporated on 20 May 2022.”
regulatory 2026-06-29
s8 Bypassing LLM Guardrails, evading Microsoft Azure Prompt Shield (Hackett, Garraghan et al.), arXiv 2504.11168, LLMSec 2025
“Through testing against six prominent protection systems, including Microsoft's Azure Prompt Shield and Meta's Prompt Guard, we show that both methods can be used to evade detection while maintaining adversarial utility achieving in some instances up to 100% evasion success.”
research 2026-06-29
s9 CSO Online: Security researchers circumvent Microsoft Azure AI Content Safety
“In response to queries from CSO, Microsoft acknowledged an issue but downplayed the seriousness of the problem by arguing that the techniques uncovered by Mindgard are limited to the user's individual session and do not pose a security risk to other users.”
press 2026-06-29
s10 Hackread: Azure AI Vulnerabilities Allowed Attacks to Bypass Moderation Safeguards
“A UK-based cybersecurity-for-AI startup, Mindgard, discovered two critical security vulnerabilities in Microsoft's Azure AI Content Safety Service in February 2024. The vulnerabilities were responsibly disclosed to Microsoft in March 2024.”
press 2026-06-29
s11 Tech.eu (Cate Lawrence): Mindgard secures $8M to tackle emerging AI security risks
“Mindgard secures $8M to tackle emerging AI security risks. According to Greg Dracon, Partner at .406 Ventures, the rapid adoption of AI has introduced new and complex security risks that traditional tools cannot address.”
press 2026-06-29
s12 Check Point: Acquires Lakera to Deliver End-to-End AI Security (16 Sep 2025)
“Check Point Software Technologies Ltd. today announced it has entered into an agreement to acquire Lakera, one of the world's leading AI-native security platforms for Agentic AI applications.”
press 2026-06-29
s13 Palo Alto Networks: Completes Acquisition of Protect AI (22 Jul 2025)
“Palo Alto Networks today announced it has completed its acquisition of Protect AI, an innovative leader in securing Artificial Intelligence (AI) applications and models.”
press 2026-06-29
s14 Lancaster University: Professor Peter Garraghan faculty profile
“Peter has published over 60 research articles, led software teams to create bleeding-edge technology, has industrial experience building large-scale production distributed systems, and has worked and collaborated internationally with the likes of Microsoft, Nvidia, BT, BBC, Alibaba Group.”
press 2026-06-29
s15 Mindgard AI Security Platform footer trust badge (SOC 2 Type 2)
“AICPA SOC SOC 2 Type 2 Compliant (footer trust badge image, COMPLIANCE LOGO-300.webp, displayed on the Mindgard AI Security Platform page).”
official 2026-06-29
s16 Mindgard: Appoints James Brear as CEO (October 2025)
“James Brear, a seasoned growth-stage CEO with over 15 years in cybersecurity, brings a proven track record of scaling public and private technology companies. Most recently, he served as CEO of Swimlane, where he grew the company into the industry’s largest standalone security automation provider.”
official 2026-06-29

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.