All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Repello AI's case for standing apart is a data claim a buyer cannot check. The company sells ARTEMIS, software that attacks a customer's AI applications the way a human attacker would, and ARGUS, guardrails that use what the testing engine learns to block similar attacks in production. It says the engine draws on a repository of more than 15 million attack patterns, a self-asserted figure that could take time to reproduce, with no outside audit or benchmark in the cited sources. Repello is a 2024 startup on a 1.2 million dollar seed, with users named in press coverage, two attributed testimonials, one lacking its organization, and certification badges without inspectable reports. Hands-on proof exists in a public playground and open-source tools, but audited proof does not.
| Description | Repello AI is an enterprise AI security and red-teaming platform for AI applications, agentic workflows, and MCP. It discovers AI assets, simulates attacks such as prompt injection and jailbreaks, and blocks malicious inputs at runtime. | [f1] |
|---|---|---|
| Founded | 2024 | [f2] |
| HQ | San Francisco, California, USA (with operations in Bengaluru, India) | [f2] |
| Latest funding | $1.2M seed (2025) | [f2] |
| Deployment | SaaS | [f3] |
| Product | What it does |
|---|---|
| Repello AI | Enterprise AI security and red-teaming platform that discovers AI assets, runs adversarial attack simulations against models and apps, and adds runtime protection and MCP visibility. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Repello AI discovers AI assets, runs adversarial attack simulations against models and apps, and adds runtime protection and MCP visibility. It is mapped to the AI Defense Matrix. [f4]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score |
|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs, demos, and third-party validation. | 4/5 |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 2/5 |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
| Dimension | Score |
|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 2/3 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Repello AI: Enterprise AI Security & Red Teaming Platform | official | 2026-07-09 |
| f2 | Entrepreneur India on Repello AI, founded 2024 (corroborated by repello.ai WHOIS creation 2024-02-12) | press | 2026-06-13 |
| f3 | AI Defense Matrix Catalog entry | other | 2026-06-09 |
| f4 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Repello AI homepage “Repello ARTEMIS helped us identify AI vulnerabilities we never knew existed, it's essential for any enterprise deploying GenAI. Pradeep Bhat, Head of Security, no organization in page text. Sandeep Varma, PhysicsWallah AI. Logo wall images include Groww (/img/customers/groww.png).” | official | 2026-07-02 |
| s2 | Repello ARTEMIS autonomous red teaming product page “Autonomous red teaming that profiles, plans, and attacks like a human red-teamer. Builds threat models, executes multi-stage attacks, and visualizes attack paths showing exactly how your AI is breached.” | official | 2026-06-13 |
| s3 | Repello ARGUS runtime security product page “ARGUS is informed by battle-tested adversarial insights from the world's most advanced AI red teaming engine. The same system used to discover critical vulnerabilities in enterprise AI now powers real-time protection.” | official | 2026-06-13 |
| s4 | Repello AI Asset Inventory product page “One click scans your codebases, cloud environments, infrastructure, and third-party apps, automatically uncovering every AI agent, model, dataset, and tool in use.” | official | 2026-06-13 |
| s5 | Repello Workstation Lens coding-agent security page “See every Claude, Cursor, Codex CLI, and Copilot agent your developers run. Catch the skills and MCP servers reading credentials they didn't declare.” | official | 2026-06-13 |
| s6 | Entrepreneur India on Repello AI seed round, founders, and named users “Founded in 2024 by IIT Roorkee alumni Aryaman Behera and Naman Mishra... Currently used by companies like Groww and PhysicsWallah... raised USD 1.2 million in seed funding... participation from Venture Highway (acquired by General Catalyst), pi Ventures, Entrepreneur First, and angel investors” | press | 2026-07-02 |
| s7 | Repello-AI Agent-Wiz open-source threat-modeling tool on GitHub “A CLI tool for threat modeling and visualizing AI agents built using popular frameworks like LangGraph, AutoGen, CrewAI, and more.” | other | 2026-06-13 |
| s8 | Repello AI blog announcing inclusion in a Gartner AI TRiSM report “Repello AI has been featured in Gartner's latest research report, "Emerging Tech: Top-Funded Startups in AI TRiSM: Agentic AI and Beyond".” | official | 2026-06-13 |
| s9 | Repello-AI Whistleblower open-source prompt-leak testing tool on GitHub “Whistleblower is a offensive security tool for testing against system prompt leakage and capability discovery of an AI application exposed through API.” | other | 2026-06-13 |
| s10 | GitHub API record for Repello-AI Agent-Wiz showing its stargazers count “"stargazers_count": 378” | research | 2026-06-13 |
| s11 | Repello AI homepage footer showing AICPA SOC and ISO 27001 attestation seals “img alt "AICPA SOC" loading /img/1j1e17JPyOhdZgjoM7q7oX9gIU.png (HTTP 200, image/png) and img alt "ISO 27001" loading /img/PZNwWPWiXTLhMZRu185R2x4Pg.png (HTTP 200, image/png), both in the footer next to contact@repello.ai. trust.repello.ai returns NXDOMAIN.” | official | 2026-06-16 |
| s12 | Repello AI blog: Validating Enterprise AI Security, Repello's Red Teaming Assessment of Lyzr AI Agents “In July 2025, Lyzr conducted a comprehensive AI red teaming engagement with Repello AI, an enterprise grade AI security platform, to test, validate, and strengthen the security of our agents.” | official | 2026-07-02 |
| s13 | Repello AI homepage: enterprise-scale claim, organizations across industries “Trusted by leading organizations across industries. Repello secures AI systems serving millions of users and processing billions of interactions” | official | 2026-07-02 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Repello AI homepage: AI red teaming repository and named users “Leverage our threat intelligence repository of 15M+ evolving attack patterns with 15x more coverage than manual testing. ARTEMIS provides automated red teaming with multi-lingual testing across text, image, and audio interactions.” | official | 2026-06-19 |
| s2 | Repello ARTEMIS product page: autonomous red teaming and attack-vector count “Autonomous red teaming that profiles, plans, and attacks like a human red-teamer. Builds threat models, executes multi-stage attacks, and visualizes attack paths showing exactly how your AI is breached. 15M+ curated attack vectors. less than 1 min time to first vulnerability.” | official | 2026-06-17 |
| s3 | Repello ARGUS runtime security page: offense-informed guardrails and live playground “ARGUS is informed by battle-tested adversarial insights from the world's most advanced AI red teaming engine. Head to our interactive playground and put them to the test. Try the Playground at guard.repello.ai: test prompt injection scenarios, detect system prompt leaks, inspect policy hits.” | official | 2026-06-19 |
| s4 | Repello homepage testimonials and customer logo wall “Repello ARTEMIS helped us identify AI vulnerabilities we never knew existed. Pradeep Bhat, Head of Security, no organization in the page text. ARTEMIS transformed our AI security from reactive patching to proactive defense. Sandeep Varma, PhysicsWallah AI. Logo wall images include groww.png.” | official | 2026-07-02 |
| s5 | Repello homepage: proprietary 3-phase AI security framework “Repello follows a proprietary 3 phase framework to provide end to end security for AI systems: Discovery feeds continuous testing, testing results calibrate runtime defenses, and runtime insights improve future testing, creating an integrated security ecosystem.” | official | 2026-06-17 |
| s6 | Entrepreneur India on Repello AI $1.2 million seed round, founders, and backers “Founded in 2024 by IIT Roorkee alumni Aryaman Behera and Naman Mishra. The seed round saw participation from Venture Highway (acquired by General Catalyst), pi Ventures, Entrepreneur First, and angel investors including Charles Songhurst (Board Member, Meta).” | press | 2026-06-17 |
| s7 | Repello-AI Agent-Wiz open-source threat-modeling tool on GitHub “A CLI tool for threat modeling and visualizing AI agents built using popular frameworks like LangGraph, AutoGen, CrewAI, and more. stargazers_count 382, forks_count 57 per the GitHub API.” | other | 2026-07-02 |
| s8 | Repello homepage footer: self-displayed AICPA SOC and ISO 27001 badge seals “Footer badge seals alt AICPA SOC (img 1j1e17JPyOhdZgjoM7q7oX9gIU.png) and alt ISO 27001 (img PZNwWPWiXTLhMZRu185R2x4Pg.png), beside 8 The Green, Ste A Dover, DE 19901 and Repello Inc. All rights reserved.” | official | 2026-06-19 |
| s9 | Repello-AI Whistleblower open-source system-prompt-leakage tool on GitHub “Whistleblower is a offensive security tool for testing against system prompt leakage and capability discovery of an AI application exposed through API. stargazers_count 157, forks_count 26 per the GitHub API.” | other | 2026-07-02 |
| s10 | Probe of Repello trust surfaces (trust./security. NXDOMAIN, /trust /security /compliance /soc2 404, footer badges in served bytes, python urllib, 2026-07-16) “trust.repello.ai and security.repello.ai return NXDOMAIN, /trust, /security, /compliance, and /soc2 return 404, and the served homepage (sha256 8213b157) carries AICPA SOC and ISO 27001 badge images in footer markup with no linked report.” | official | 2026-07-16 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Do not republish its content or share access without the operator's permission.