Qualifire

Security for AI

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2023
Funding $4.6M
Last updated 2026-09-02

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Qualifire sells engineering teams a checking layer for applications built on large language models: small models, each trained for one test such as prompt injection or personal data, inspect every request, and a failing check blocks the response before the user sees it. The company a buyer would contract with is harder to pin down. The AWS listing that qualifire.ai links to for cloud deployment is sold by Rogue Security and describes a broader agent-security platform, the Hugging Face account holding those models carries the same name, and qualifire.ai still sells that product while nothing in the reviewed record explains the relationship. The four customer references on its homepage are logos linking to company sites, with no outside source confirming any of them.

Sourced Details

Description Qualifire sells guardrails and evaluation for applications built on large language models. Small purpose-built judge models evaluate prompts, model outputs, and agent actions in real time, and a failing check can block the response before the user sees it. [f1]
Founded 2023 [f2]
HQ Tel Aviv, Israel [f3]
Funding $4.6M total [f2]

Products

Product What it does
Qualifire Guardrails Guardrails applied through an LLM proxy or SDK, covering prompt injection, PII, content safety, grounding, and custom policy assertions.
Rogue Pre-production testing and red teaming for AI agents, driving multi-turn adversarial conversations over the A2A protocol and reporting findings.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Qualifire Guardrails runs on the input and the output of model calls, blocking a response that fails a configured check and covering prompt injection, personal data, content safety, grounding, and custom policy. These capabilities are mapped to the AI Defense Matrix. [f4]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 25 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Qualifire names a buyer and a failure mode without hedging: teams putting chatbots, retrieval applications, and agents into production, whose models answer off-policy. CTech carried the founders framing the same pain with a concrete precedent, an Air Canada chatbot that promised a free ticket against company policy, after which the customer sued and won. No reviewed source counts how often that failure occurs or what it costs, so the problem is credible and unmeasured. [s1, s10, s6]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 4/5 The documentation names each check as an API parameter and each judge model by task, with a per-model table of accuracy, latency, and cost. The detection is also open to inspection: the Sentinel model card and the benchmark are published on Hugging Face. An arXiv preprint describing a classifier called CourtGuard ran its own methods against that benchmark, and LiteLLM's documentation shows the request a failing check rejects. Neither runs Sentinel itself. [s4, s23, s5, s13, s15, s21]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 The enabler is credible and the buyer-side evidence is thin. Google selected the company for an AI-for-cybersecurity cohort in February 2025, and two gateway projects added it as a guardrail provider, but both are supply-side signals rather than records of buyers searching. No analyst category note, procurement language, or regulatory driver appears in the reviewed sources, so one kind of indirect signal carries the score. [s12, s10, s15, s16]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 Three co-founders are named with relevant in-domain history. Gilad Ivry told CTech he had worked at Vianai on first-generation language-model products before starting the company with his brother Dror, and Dror Ivry co-authored the Sentinel preprint. The about page credits the chief executive with two exits but names neither, and no reviewed source outside the company confirms them, so a verifiable prior build sits below the corroborated tier. [s6, s10, s14, s11]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 4/5 Traction shows up in three forms a buyer can check. Each homepage testimonial's logo links to a company site, naming DoiT, Empire Media, Anodot, and Novacy as references. LiteLLM and Portkey each document the integration in their own documentation. The homepage also links to cloud marketplace listings, though the AWS one is sold under the name Rogue Security. Every reference is presented by the company, and no reviewed outside source confirms a deployment or a scale. [s1, s22, s15, s16]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 The raise matches the motion it funds. CTech's September 2025 conference profile recorded $4.6 million and nine employees, against which the company ships published documentation, a priced self-serve tier, seven task-specific judge models, and a publicly published red-teaming tool. No revenue, margin, or growth figure appears in the reviewed record, so output per dollar stays unconfirmed. [s11, s7, s4, s9]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 A buyer can place the product without coaching, because the slot already exists: LiteLLM's guardrail-provider directory lists it beside dozens of others, which is a stack position a purchaser can point at. That directory is also crowded, listing dozens of entries for the same job, and no analyst placement or third-party category note appears in the reviewed sources. [s15, s16, s2]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 2/5 The same directory that carries Qualifire offers dozens of alternative guardrail providers a customer can select instead, among them entries from Amazon, Microsoft, Google, Palo Alto Networks, and CrowdStrike, so platforms already adjacent to the buyer sell into this slot. What keeps the product off the replicable floor is the judge family itself, seven named task-specific models the documentation publishes accuracy and latency figures for, which took training work a bundling decision alone does not reproduce. [s15, s4, s23, s17, s20]
Business Risks Every customer reference in the record is presented by the company through a logo link on its own homepage, and no reviewed outside source mentions DoiT, Empire Media, Anodot, or Novacy in connection with it, so a buyer has nothing independent to check a reference against…
  • Every customer reference in the record is presented by the company through a logo link on its own homepage, and no reviewed outside source mentions DoiT, Empire Media, Anodot, or Novacy in connection with it, so a buyer has nothing independent to check a reference against.
  • The same LiteLLM directory that distributes Qualifire lists dozens of alternative guardrail providers, among them entries from Amazon, Microsoft, Google, Palo Alto Networks, and CrowdStrike, so a customer already buying from one of those vendors has a guardrail option that adds no supplier.
  • The company publishes its prompt-injection model card and its benchmark dataset on Hugging Face under a licence the page labels other, so a competitor can inspect and evaluate the detection it sells rather than infer it, subject to whatever those terms allow.
  • The AWS listing the homepage points at for cloud deployment names Rogue Security as its seller and the Hugging Face account holding the judge models carries that name too, while nothing in the reviewed record explains the brand or legal-entity relationship between the two names.
  • No compliance attestation was found on the probed surfaces, which will stall deals with buyers whose procurement asks for one before a pilot.
  • The ISO 42001 page states that prompts or completions are stored by default with an opt-out, so a customer with regulated or confidential traffic has a configuration change to make before any production traffic reaches it.
Problem & Market The argument is that offline testing cannot tell you how a model will behave in front of a user. Gilad Ivry told CTech that companies invest in development and offline testing to tune behaviour and still have no way of knowing how the model is performing while it is in use, and that Qualifire moves testing to runtime and decides in the milliseconds before the user sees an answer whether it meets the required standards. The buyer is the team that owns a shipped AI feature. The documentation is addressed to developers wiring a proxy or an SDK into an existing application, and the pricing page sells a free tier and a paid plan listed at $550 per month alongside an enterprise arrangement, which describes a product a developer can adopt without a procurement cycle. What the reviewed record does not carry is a measure of the pain. The concrete case the founders reach for is an Air Canada chatbot that promised a free ticket against policy, after which the customer sued and won, a single incident rather than a body of evidence, and no research, survey, or incident study in these sources counts how often production models answer off-policy or what it costs when they do…

The argument is that offline testing cannot tell you how a model will behave in front of a user. Gilad Ivry told CTech that companies invest in development and offline testing to tune behaviour and still have no way of knowing how the model is performing while it is in use, and that Qualifire moves testing to runtime and decides in the milliseconds before the user sees an answer whether it meets the required standards.

The buyer is the team that owns a shipped AI feature. The documentation is addressed to developers wiring a proxy or an SDK into an existing application, and the pricing page sells a free tier and a paid plan listed at $550 per month alongside an enterprise arrangement, which describes a product a developer can adopt without a procurement cycle.

What the reviewed record does not carry is a measure of the pain. The concrete case the founders reach for is an Air Canada chatbot that promised a free ticket against policy, after which the customer sued and won, a single incident rather than a body of evidence, and no research, survey, or incident study in these sources counts how often production models answer off-policy or what it costs when they do. [s10, s2, s7, s6]

Product Capabilities The product can make a decision on each call rather than only reporting afterwards. The guardrails documentation states plainly that guardrails which fail will block the response from reaching users, and the LiteLLM integration page records block as the default action, raising an HTTP 400 when a violation is detected, while a monitor setting logs the violation and lets the request proceed. Checks run before the model call on the input, after it on input and output, or in parallel with it. Traffic reaches the checks through a proxy endpoint that stands in for the model provider's own API, or through an SDK call. The checks themselves are small models rather than a large one grading output. The documentation names seven, each fitted to one task: prompt injection and jailbreak detection, content safety, grounding against supplied context, tool selection quality, natural-language policy assertions, hallucination detection, and personal-data scanning. Ariel Dan told CTech these are small language models or classic machine learning algorithms rather than a language model used as a judge, and that the one-model approach rivals take is slow and expensive. Speed, balanced, and quality modes trade latency for reasoning depth on each check. Rogue is the pre-production half. It drives multi-turn adversarial conversations against an agent over the agent-to-agent protocol, generates test scenarios from a described business context, and reports what the agent did, and the page names regression testing and continuous-integration automation among its purposes. The company publishes it in a public repository the homepage links to…

The product can make a decision on each call rather than only reporting afterwards. The guardrails documentation states plainly that guardrails which fail will block the response from reaching users, and the LiteLLM integration page records block as the default action, raising an HTTP 400 when a violation is detected, while a monitor setting logs the violation and lets the request proceed. Checks run before the model call on the input, after it on input and output, or in parallel with it. Traffic reaches the checks through a proxy endpoint that stands in for the model provider's own API, or through an SDK call.

The checks themselves are small models rather than a large one grading output. The documentation names seven, each fitted to one task: prompt injection and jailbreak detection, content safety, grounding against supplied context, tool selection quality, natural-language policy assertions, hallucination detection, and personal-data scanning. Ariel Dan told CTech these are small language models or classic machine learning algorithms rather than a language model used as a judge, and that the one-model approach rivals take is slow and expensive. Speed, balanced, and quality modes trade latency for reasoning depth on each check.

Rogue is the pre-production half. It drives multi-turn adversarial conversations against an agent over the agent-to-agent protocol, generates test scenarios from a described business context, and reports what the agent did, and the page names regression testing and continuous-integration automation among its purposes. The company publishes it in a public repository the homepage links to. [s3, s21, s4, s10, s9]

Competitive Positioning The company competes on cost and latency rather than on a capability rivals lack. Its own pages argue that small purpose-built judges are faster and cheaper than using a large model to grade output, and its judge documentation publishes a prompt-injection comparison table placing Sentinel v2 at 0.957 average F1 above entries for Qwen3Guard, OpenAI's GPT OSS Safeguard, and Meta's Llama Guard 3. That table is the vendor's own, and no reviewed independent source reproduces it. Outside researchers have picked the benchmark up, which is a weaker thing than an outside measurement and still worth noting. An arXiv preprint describing a classifier called CourtGuard evaluated its own approach on the benchmark Qualifire published, and reported alongside it the 97.6% Sentinel figure and a 65.2% figure for ProtectAI's open alternative, both credited to Qualifire's own paper rather than re-measured. Nobody in the reviewed record has run Sentinel independently. The structural problem is where the product is sold. LiteLLM's guardrail-provider directory lists Qualifire beside dozens of other entries, among them ones from Amazon, Microsoft, Google, Palo Alto Networks, and CrowdStrike. Being in that directory is real distribution and it is also a public inventory of what a buyer could select instead…

The company competes on cost and latency rather than on a capability rivals lack. Its own pages argue that small purpose-built judges are faster and cheaper than using a large model to grade output, and its judge documentation publishes a prompt-injection comparison table placing Sentinel v2 at 0.957 average F1 above entries for Qwen3Guard, OpenAI's GPT OSS Safeguard, and Meta's Llama Guard 3. That table is the vendor's own, and no reviewed independent source reproduces it.

Outside researchers have picked the benchmark up, which is a weaker thing than an outside measurement and still worth noting. An arXiv preprint describing a classifier called CourtGuard evaluated its own approach on the benchmark Qualifire published, and reported alongside it the 97.6% Sentinel figure and a 65.2% figure for ProtectAI's open alternative, both credited to Qualifire's own paper rather than re-measured. Nobody in the reviewed record has run Sentinel independently.

The structural problem is where the product is sold. LiteLLM's guardrail-provider directory lists Qualifire beside dozens of other entries, among them ones from Amazon, Microsoft, Google, Palo Alto Networks, and CrowdStrike. Being in that directory is real distribution and it is also a public inventory of what a buyer could select instead. [s4, s13, s15, s1]

Go-to-Market & Traction The customer references are on the homepage and they take reading the markup to find. Four testimonials each carry a person's name and a job title with no employer in the visible text, but each testimonial's logo links to a company site: DoiT, Empire Media, Anodot, and Novacy. Every one of these references is presented by the company, and no reviewed source outside it mentions any of the four. Marketplace and gateway placement is the second signal. LiteLLM and Portkey each carry a Qualifire page in their own documentation showing how to turn the checks on, which a prospective buyer can verify without asking the vendor. The homepage also points at cloud marketplace listings, and the AWS one it links to is sold under the name Rogue Security rather than Qualifire. Google selected the company for its 2025 AI-for-cybersecurity cohort of sixteen startups, and CTech reported the same selection and noted that no other Israeli company was in it. The public repository is the third channel. Rogue lives in a public repository the homepage links to, and the free pricing tier lists Rogue reports inside the commercial product, which is the ordinary shape of a free tool feeding a paid one. What the reviewed record still lacks is any figure: no revenue, no customer count, no deployment scale…

The customer references are on the homepage and they take reading the markup to find. Four testimonials each carry a person's name and a job title with no employer in the visible text, but each testimonial's logo links to a company site: DoiT, Empire Media, Anodot, and Novacy. Every one of these references is presented by the company, and no reviewed source outside it mentions any of the four.

Marketplace and gateway placement is the second signal. LiteLLM and Portkey each carry a Qualifire page in their own documentation showing how to turn the checks on, which a prospective buyer can verify without asking the vendor. The homepage also points at cloud marketplace listings, and the AWS one it links to is sold under the name Rogue Security rather than Qualifire. Google selected the company for its 2025 AI-for-cybersecurity cohort of sixteen startups, and CTech reported the same selection and noted that no other Israeli company was in it.

The public repository is the third channel. Rogue lives in a public repository the homepage links to, and the free pricing tier lists Rogue reports inside the commercial product, which is the ordinary shape of a free tool feeding a paid one. What the reviewed record still lacks is any figure: no revenue, no customer count, no deployment scale. [s1, s15, s16, s12, s10, s9, s7]

Team & Credibility The founding team is three people and the site names all of them…

The founding team is three people and the site names all of them. Ariel Dan is listed as co-founder and chief executive, described as an entrepreneur of more than twenty years who has led two companies to acquisitions; Dror Ivry as co-founder and chief technology officer; and Gilad Ivry as co-founder and chief product officer with a decade of applying machine learning to business problems.

The parts an outsider can check are narrower. Gilad Ivry told CTech he had worked at Vianai building products for an early generation of large language models before he and his brother started the company, and Dror Ivry co-authored the preprint describing the prompt-injection model, which is one publication rather than a record. Neither of the chief executive's two acquisitions is named on the about page, and no reviewed source outside the company identifies them.

CTech's conference profile put the company at nine employees in September 2025. Nothing later in the reviewed record restates that figure or describes anyone beyond the three founders. [s6, s10, s14, s11]

Trust Readiness The company sells compliance help rather than holding a certificate…

The company sells compliance help rather than holding a certificate. Its ISO 42001 page explains what the standard asks of an AI management system and offers the product as the layer that monitors and enforces those requirements in production, and it offers visitors a free certificate for signing up. That is a marketing surface addressed to the customer's obligations, not evidence about the vendor's own audit position.

No attestation was found by probe on 2026-09-01. The trust and security paths return errors, the matching subdomains do not resolve, and a control probe of a nonsense subdomain does not resolve either, so the absence is genuine rather than an artifact of wildcard DNS.

What the record does offer a cautious buyer is control over the data path. The ISO 42001 page states that prompts or completions are stored by default with an opt-out, that logs and evaluation results are encrypted in transit and at rest, and that on-premises deployment is available, and the pricing page lists a bring-your-own-cloud or on-premises option on the enterprise tier. A default that stores prompts is the detail a buyer with sensitive traffic will want to change first. [s8, s18, s7]

Competitors Guardrails AI, Lakera, Guardion, Patronus AI, Prediction Guard…
Company Relationship Note Compare
Guardrails AI competes with Competes for the same developer choosing a guardrail layer for a shipped language-model application. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Lakera competes with Competes for the same buyer looking for runtime prompt-injection defence. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Guardion competes with Competes for the same buyer with a comparable inline guardrail sold through gateway integrations. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Patronus AI adjacent Adjacent because its centre of gravity is evaluating model output rather than enforcing a decision on it. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Prediction Guard adjacent Adjacent because it sells a self-hosted control plane rather than a checker other gateways call.

Add analyzed competitors to compare them side by side with Qualifire.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 13 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

The seven judge models are the asset worth naming: each is fitted to one check, and the company reports pass-or-fail latencies in the tens of milliseconds where a large model used as a grader takes seconds. The record shows a private slice of training data behind them, though it neither names nor sizes it, and the prompt-injection model is published on a public account under a licence its page labels other. What a buyer would check next comes up thin on three counts. No compliance attestation appears on the probed surfaces, the product is reached through gateways a customer can point at another checker, and the pricing tiers describe software the customer configures and runs rather than an outcome the company underwrites.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Customers buy software they configure and run. The tiers are metered by token volume and the checks are switches the customer turns on. The enterprise tier attaches people to that software, listing ten consulting hours, a dedicated customer success manager, and forward-deployed engineering support, but those are an implementation and support wrap on a product the customer operates, and the reviewed record shows no accountability for the outcome moving to the vendor.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Leaving means real work and the cited record does not size it. A customer accumulates configured guardrails, natural-language policy assertions, and up to ninety days of logs, which is data history and learned workflow rather than a rebuild. Against that, the product is reached through a proxy that stands in for the model provider's own interface, or through a gateway directory entry, so redirecting traffic to another checker is a configuration change.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 No attestation belonging to the company appears on the probed surfaces. The ISO 42001 page sells help with the customer's own compliance rather than recording a certificate the company holds, and a funded competitor could obtain the ordinary enterprise credentials through routine preparation. Nothing in the reviewed record blocks a replacement on compliance grounds.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 The work is machine learning under a real-time budget. The company trains and serves a family of task-specific judge models and publishes accuracy, latency, and cost for each, with the documentation recording pass-or-fail latencies around twenty milliseconds where the alternative approach uses a large model and takes seconds. Holding accuracy at that latency and cost is specialised engineering rather than assembly.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 The evidenced buyer is a developer or an engineering team, not a regulated enterprise. Entry is a free self-serve tier with a start button, and the next published step is a plan at $550 per month, which is a self-service path rather than a procurement one. An enterprise tier with on-premises deployment and seven-year retention addresses a governed buyer, and no reviewed source shows one buying.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 The product runs beside the model traffic rather than underneath the application. It offers its own proxy and an SDK, which is platform shape, and its documented distribution is as one entry in the guardrail directory of a gateway the customer already operates. The applications it protects call models directly without it.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 2/3 The record evidences an accumulated asset without naming or sizing it. The Sentinel preprint, written by the company's chief technology officer, states the model was fine-tuned on a mix of open-source and private collections, with the private datasets targeting error correction and real-world misclassifications, and the documentation names seven task-specific judges, of which the public model listings carry a subset covering Sentinel, Ranger, and Paladin. The published models are fetchable from that account, so the retained part is the training material rather than the artefact.
Strategic Market Segmentation The segment is the engineering team that already has an AI feature in front of users. The documentation is addressed to a developer wiring a proxy endpoint or an SDK into an existing application, the homepage names agents, retrieval applications, and chatbots as the shapes it serves, and the entry price is zero, which describes a product adopted by the person who writes the code rather than bought by the person who signs contracts. Two segments sit inside that. The self-serve tiers cap token volume, protection rules, and log retention, which fits a team validating one application. The enterprise tier lifts those caps and adds a customer-hosted or on-premises install, single sign-on, a model fitted to the customer, long log retention, and support commitments, which is the shape of a regulated buyer's requirements list. The named references are four company sites the homepage testimonials link to: DoiT, Empire Media, Anodot, and Novacy. Nothing in the reviewed record says which tier any of them bought, describes a deployment at any of them, or places any of them in a regulated industry. No cited page identifies an industry served or a customer in the governed segment the top tier is built for…

The segment is the engineering team that already has an AI feature in front of users. The documentation is addressed to a developer wiring a proxy endpoint or an SDK into an existing application, the homepage names agents, retrieval applications, and chatbots as the shapes it serves, and the entry price is zero, which describes a product adopted by the person who writes the code rather than bought by the person who signs contracts.

Two segments sit inside that. The self-serve tiers cap token volume, protection rules, and log retention, which fits a team validating one application. The enterprise tier lifts those caps and adds a customer-hosted or on-premises install, single sign-on, a model fitted to the customer, long log retention, and support commitments, which is the shape of a regulated buyer's requirements list.

The named references are four company sites the homepage testimonials link to: DoiT, Empire Media, Anodot, and Novacy. Nothing in the reviewed record says which tier any of them bought, describes a deployment at any of them, or places any of them in a regulated industry. No cited page identifies an industry served or a customer in the governed segment the top tier is built for.

Product Capabilities & AI Advantages The technical argument is that the checker should be small…

The technical argument is that the checker should be small. Ariel Dan told CTech the company uses small language models or classic machine learning algorithms rather than a large model grading output, and that the one-model approach rivals take is slow and expensive. The documentation follows through: seven judges, each fitted to one task, with speed, balanced, and quality modes trading latency against reasoning depth on every check.

Enforcement is a decision rather than a report. The guardrails page states that guardrails which fail will block the response from reaching users; the API exposes each check as a named parameter over input, output, or both; and the LiteLLM integration records the default action as block, raising an HTTP 400 when a violation is detected, with the check running before the model call, after it, or in parallel with it.

Outside attention exists and is narrower than it looks. An arXiv preprint describing a classifier called CourtGuard evaluated its own approach on the benchmark Qualifire published, and reported alongside it the 97.6% Sentinel figure and a 65.2% figure for ProtectAI's open alternative, both credited to Qualifire's own paper rather than re-measured. So a third party treats the benchmark as worth running against, nobody in the reviewed record has run Sentinel independently, and the comparison table placing Sentinel v2 above Qwen3Guard, GPT OSS Safeguard, and Llama Guard 3 is the company's own.

Sales Engagement & Go-to-Market Distribution runs through other people's gateways and marketplaces…

Distribution runs through other people's gateways and marketplaces. LiteLLM and Portkey each carry a Qualifire page in their own documentation showing how to turn the checks on, and Portkey's page describes the product as offering more than twenty guardrail checks across content safety, quality, and compliance. That is placement a prospective buyer can verify without asking the vendor. The homepage also points at cloud marketplace listings, and the AWS one it links to is sold under the name Rogue Security.

References are self-presented and take reading the markup to find. Each homepage testimonial's logo links to a company site, naming DoiT, Empire Media, Anodot, and Novacy, and no reviewed source outside the company mentions any of them.

The public repository and institutional selection round it out. Rogue lives in a public repository the homepage links to, and the free pricing tier lists Rogue reports inside the commercial product. Google named the company in its 2025 AI-for-cybersecurity cohort of sixteen startups, and CTech reported the same selection, adding that no other Israeli company was in it. The reviewed record still carries no revenue figure and no deployment count.

Pricing Model Pricing is published rather than quoted, which tells a buyer what the product costs before any conversation. A free tier carries three hundred thousand monthly tokens, up to three protection rules, seven days of log retention, and one environment. A paid plan listed at $550 per month adds API access, custom policies, content analysis, personal-data masking, unlimited protection rules, and ninety days of retention. An enterprise arrangement is quoted rather than listed and adds customer-hosted or on-premises deployment and seven-year retention. The meter on the pricing page is tokens: the free plan bundles a monthly allowance and the paid plan a much larger one, with the quoted tier described as unlimited. That aligns cost with the traffic the customer already pays a model provider for, and it makes the guardrail a visible percentage of that bill rather than a fixed line item. Two things the tiers reveal are worth a buyer's attention. Personal-data masking sits on the paid plan while detection sits on the free one, so the remediation half of the privacy story is a paid upgrade. And the ceiling that matters at scale is retention rather than capability: the published window runs to ninety days on the paid plan, so a team with a longer audit obligation is pushed to the quoted tier by the log window rather than by the checks…

Pricing is published rather than quoted, which tells a buyer what the product costs before any conversation. A free tier carries three hundred thousand monthly tokens, up to three protection rules, seven days of log retention, and one environment. A paid plan listed at $550 per month adds API access, custom policies, content analysis, personal-data masking, unlimited protection rules, and ninety days of retention. An enterprise arrangement is quoted rather than listed and adds customer-hosted or on-premises deployment and seven-year retention.

The meter on the pricing page is tokens: the free plan bundles a monthly allowance and the paid plan a much larger one, with the quoted tier described as unlimited. That aligns cost with the traffic the customer already pays a model provider for, and it makes the guardrail a visible percentage of that bill rather than a fixed line item.

Two things the tiers reveal are worth a buyer's attention. Personal-data masking sits on the paid plan while detection sits on the free one, so the remediation half of the privacy story is a paid upgrade. And the ceiling that matters at scale is retention rather than capability: the published window runs to ninety days on the paid plan, so a team with a longer audit obligation is pushed to the quoted tier by the log window rather than by the checks.

Product Delivery & Operations The product is delivered as a hosted service the customer points traffic at. Requests reach the checks through a proxy endpoint that stands in for the model provider's own API, so adopting it is a base-URL change and a header, or through an SDK call the application makes itself. The homepage offers the customer's own cloud, an on-premises install, and the hosted service as deployment choices. The operational cost of an inline check is latency, and the company is specific about it. The documentation records a speed mode at roughly twenty milliseconds giving a simple pass or fail, a balanced mode near one hundred that returns reasoning, and a quality mode near five hundred using larger models. Those figures are the vendor's own and no reviewed source reproduces them. The data handling is stated plainly and the default is the part to notice. The ISO 42001 page says prompts or completions are stored by default with a customer opt-out, that logs and evaluation results are encrypted in transit and at rest, and that on-premises deployment is available. A team whose prompts carry regulated or confidential material has a configuration change to make before it sends production traffic…

The product is delivered as a hosted service the customer points traffic at. Requests reach the checks through a proxy endpoint that stands in for the model provider's own API, so adopting it is a base-URL change and a header, or through an SDK call the application makes itself. The homepage offers the customer's own cloud, an on-premises install, and the hosted service as deployment choices.

The operational cost of an inline check is latency, and the company is specific about it. The documentation records a speed mode at roughly twenty milliseconds giving a simple pass or fail, a balanced mode near one hundred that returns reasoning, and a quality mode near five hundred using larger models. Those figures are the vendor's own and no reviewed source reproduces them.

The data handling is stated plainly and the default is the part to notice. The ISO 42001 page says prompts or completions are stored by default with a customer opt-out, that logs and evaluation results are encrypted in transit and at rest, and that on-premises deployment is available. A team whose prompts carry regulated or confidential material has a configuration change to make before it sends production traffic.

Earning Customers' Trust The company markets compliance help rather than holding a certificate…

The company markets compliance help rather than holding a certificate. Its ISO 42001 page explains what the standard asks of an AI management system, positions the product as the layer that monitors and enforces those requirements in production, and offers visitors a free certificate for signing up. That is a surface addressed to the customer's obligations, and it says nothing about the vendor's own audit position.

No attestation was found by probe on 2026-09-01. The trust and security paths on the company's domain return errors, the matching subdomains do not resolve, and a control probe of a nonsense subdomain does not resolve either, so the absence is genuine rather than an artifact of wildcard DNS.

What a cautious buyer can lean on instead is deployment control and published artefacts. The enterprise tier offers a customer-hosted or on-premises install, which keeps the traffic inside the customer's own boundary, and the prompt-injection model and its benchmark are published openly enough that a security team can test the detection itself rather than take a number on trust.

Platform Strategy & Ecosystem Positioning The ecosystem position is a component inside someone else's control point…

The ecosystem position is a component inside someone else's control point. The product speaks the interfaces developers already use, offering a proxy that stands in for a provider's own endpoint, and it appears in the guardrail directories of two gateway projects. That is cheap to adopt, and the same property makes it cheap to swap: a customer that wants a different checker changes a configuration entry in the gateway it already runs.

Those directories are also a competitive inventory. LiteLLM's list carries Qualifire beside dozens of entries, among them guardrails from Amazon, Microsoft, Google, Palo Alto Networks, and CrowdStrike. Portkey's list is shorter and carries several of the same names.

The agent-testing engine is the part of the position that is genuinely the company's own. Rogue drives adversarial conversations against an agent over the agent-to-agent protocol and reports what the agent did, the page names regression testing and continuous-integration automation among its purposes, and the homepage links developers straight to the repository.

Team & Execution Capability Three co-founders run the company and the site names them all…

Three co-founders run the company and the site names them all. Ariel Dan is co-founder and chief executive, described as an entrepreneur of more than twenty years who has led two companies to acquisitions. Dror Ivry is co-founder and chief technology officer. Gilad Ivry is co-founder and chief product officer, credited with a decade of applying machine learning to business problems.

The checkable parts are narrower than the claims. Gilad Ivry told CTech he had worked at Vianai building products for an early generation of large language models before he and his brother started the company, and Dror Ivry co-authored the preprint describing the prompt-injection model, which is one publication rather than a record. Neither of the chief executive's two acquisitions is named on the about page, and no reviewed source outside the company identifies them.

The company was small when it was last counted. CTech's September 2025 conference profile recorded nine employees against $4.6 million raised, and nothing later in the reviewed record restates either figure or describes anyone beyond the three founders.

Sources

Company Detail Sources (4)
Id Source Tier Accessed
f1 Qualifire: homepage official 2026-09-01
f2 CTech: Qualifire, an AI governance platform ensuring businesses receive accurate responses from chatbots press 2026-09-01
f3 Google: 16 startups using AI to make our world safer press 2026-09-01
f4 Qualifire docs: Guardrails official 2026-09-01
Profile Analysis Sources (23)
Id Source Tier Accessed
s1 Qualifire: homepage
“Continuous evaluation, real time guardrails and pre production agentic testing. Made for agents, RAG and chatbots.”
official 2026-09-01
s2 Qualifire docs: introduction
“Contextual, real-time guardrails that protect your application from safety, security, and policy violations while taking context into account.”
official 2026-09-01
s3 Qualifire docs: Guardrails
“Guardrails that fail will block the response from reaching your users. Make sure to test your guardrail configuration thoroughly before deploying to production.”
official 2026-09-01
s4 Qualifire docs: Evaluations and the judge models
“Detects prompt injection and jailbreak attempts that try to manipulate your AI into ignoring its instructions or behaving maliciously.”
official 2026-09-01
s5 Qualifire docs: Evaluate endpoint API reference
“Evaluates given input, output, or messages using Qualifire's detectors.”
official 2026-09-01
s6 Qualifire: about page
“Qualifire provides real-time guardrails for LLM applications by preventing hallucinations, moderating content, and enforcing policy guidelines.”
official 2026-09-01
s7 Qualifire: pricing page
“Pro $550 / month”
official 2026-09-01
s8 Qualifire: ISO 42001 page
“Qualifire monitors and enforces AI compliance in production – in line with ISO/IEC 42001:2024.”
official 2026-09-01
s9 Qualifire: Rogue product page
“End to End Testing Framework for Agentic Systems”
official 2026-09-01
s10 CTech: The Israeli startup tackling AI unpredictable behavior
“The moment the model delivers an answer, milliseconds before the user sees it, we analyze it and decide if the response meets the required standards. If we detect a violation, it is blocked, preventing the customer from experiencing it”
press 2026-09-01
s11 CTech: Qualifire, an AI governance platform ensuring businesses receive accurate responses from chatbots
“Founded: 2023”
press 2026-09-01
s12 Google: 16 startups using AI to make our world safer
“Qualifire (Tel Aviv, Israel): Qualifire evaluates LLM-based applications in real time, ensuring safety, reliability and compliance.”
press 2026-09-01
s13 arXiv preprint: CourtGuard, a local multiagent prompt injection classifier
“Qualifire’s Sentinel model, which was self proclaimed as state-of-the-art in its release in June, 2025, scores 97.6% on the Qualifire Prompt Injection Benchmark—much higher than all instances of the Direct Detector or CourtGuard”
research 2026-09-01
s14 arXiv preprint: Sentinel, a model to protect against prompt injections
“By leveraging ModernBERT's advanced features and fine-tuning on an extensive and diverse dataset comprising a few open-source and private collections, Sentinel achieves state-of-the-art performance.”
research 2026-09-01
s15 LiteLLM docs: Qualifire guardrail provider page
“"error" : "Violated guardrail policy" ,”
research 2026-09-01
s16 Portkey docs: Qualifire guardrails page on a partner gateway
“Qualifire provides comprehensive AI reliability and quality checks including content moderation, hallucination detection, and policy compliance.”
official 2026-09-01
s17 Hugging Face: the Qualifire organization page
“qualifire (Rogue Security)”
official 2026-09-01
s18 Qualifire: trust probe 2026-09-01, /trust and /security return 404, trust. and security. subdomains unresolved, random-subdomain control also unresolved
“Page Not Found The page you are looking for doesn't exist or has been moved”
official 2026-09-01
s19 Rogue Security: homepage
“Real-time protection and policy enforcement for every agent, everywhere.”
official 2026-09-01
s20 Hugging Face: the Sentinel prompt-injection model card
“This model is a fine-tuned version of a ModernBERT-large architecture specifically trained to detect prompt injection attacks in LLM inputs.”
official 2026-09-01
s21 Qualifire docs: LiteLLM guardrails integration
“`on_flagged: "block"` raises an HTTP 400 exception when violations are detected”
official 2026-09-01
s22 AWS Marketplace: Rogue Security runtime security listing
“Sold by: Rogue Security”
official 2026-09-01
s23 Qualifire docs: SLM judges and the vendor benchmark comparison
“**Benchmark comparison (Prompt Injection):**”
official 2026-09-01
Deep-Dive Sources (23)
Id Source Tier Accessed
s1 Qualifire: homepage
“Continuous evaluation, real time guardrails and pre production agentic testing. Made for agents, RAG and chatbots.”
official 2026-09-01
s2 Qualifire docs: introduction
“Contextual, real-time guardrails that protect your application from safety, security, and policy violations while taking context into account.”
official 2026-09-01
s3 Qualifire docs: Guardrails
“Guardrails that fail will block the response from reaching your users. Make sure to test your guardrail configuration thoroughly before deploying to production.”
official 2026-09-01
s4 Qualifire docs: Evaluations and the judge models
“Detects prompt injection and jailbreak attempts that try to manipulate your AI into ignoring its instructions or behaving maliciously.”
official 2026-09-01
s5 Qualifire docs: Evaluate endpoint API reference
“Evaluates given input, output, or messages using Qualifire's detectors.”
official 2026-09-01
s6 Qualifire: about page
“Qualifire provides real-time guardrails for LLM applications by preventing hallucinations, moderating content, and enforcing policy guidelines.”
official 2026-09-01
s7 Qualifire: pricing page
“Pro $550 / month”
official 2026-09-01
s8 Qualifire: ISO 42001 page
“Qualifire monitors and enforces AI compliance in production – in line with ISO/IEC 42001:2024.”
official 2026-09-01
s9 Qualifire: Rogue product page
“End to End Testing Framework for Agentic Systems”
official 2026-09-01
s10 CTech: The Israeli startup tackling AI unpredictable behavior
“The moment the model delivers an answer, milliseconds before the user sees it, we analyze it and decide if the response meets the required standards. If we detect a violation, it is blocked, preventing the customer from experiencing it”
press 2026-09-01
s11 CTech: Qualifire, an AI governance platform ensuring businesses receive accurate responses from chatbots
“Founded: 2023”
press 2026-09-01
s12 Google: 16 startups using AI to make our world safer
“Qualifire (Tel Aviv, Israel): Qualifire evaluates LLM-based applications in real time, ensuring safety, reliability and compliance.”
press 2026-09-01
s13 arXiv preprint: CourtGuard, a local multiagent prompt injection classifier
“Qualifire’s Sentinel model, which was self proclaimed as state-of-the-art in its release in June, 2025, scores 97.6% on the Qualifire Prompt Injection Benchmark—much higher than all instances of the Direct Detector or CourtGuard”
research 2026-09-01
s14 arXiv preprint: Sentinel, a model to protect against prompt injections
“By leveraging ModernBERT's advanced features and fine-tuning on an extensive and diverse dataset comprising a few open-source and private collections, Sentinel achieves state-of-the-art performance.”
research 2026-09-01
s15 LiteLLM docs: Qualifire guardrail provider page
“"error" : "Violated guardrail policy" ,”
research 2026-09-01
s16 Portkey docs: Qualifire guardrails page on a partner gateway
“Qualifire provides comprehensive AI reliability and quality checks including content moderation, hallucination detection, and policy compliance.”
official 2026-09-01
s17 Hugging Face: the Qualifire organization page
“qualifire (Rogue Security)”
official 2026-09-01
s18 Qualifire: trust probe 2026-09-01, /trust and /security return 404, trust. and security. subdomains unresolved, random-subdomain control also unresolved
“Page Not Found The page you are looking for doesn't exist or has been moved”
official 2026-09-01
s19 Rogue Security: homepage
“Real-time protection and policy enforcement for every agent, everywhere.”
official 2026-09-01
s20 Hugging Face: the Sentinel prompt-injection model card
“This model is a fine-tuned version of a ModernBERT-large architecture specifically trained to detect prompt injection attacks in LLM inputs.”
official 2026-09-01
s21 Qualifire docs: LiteLLM guardrails integration
“`on_flagged: "block"` raises an HTTP 400 exception when violations are detected”
official 2026-09-01
s22 AWS Marketplace: Rogue Security runtime security listing
“Sold by: Rogue Security”
official 2026-09-01
s23 Qualifire docs: SLM judges and the vendor benchmark comparison
“**Benchmark comparison (Prompt Injection):**”
official 2026-09-01

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.