All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
A10 Networks acquired TrojAI in June 2026 for an undisclosed sum. The demanding engineering is the automated red teaming across an extensive built-in test library and the inline firewall that decides on production traffic in real time. The cited sources document that engineering but name no corpus, measure no exclusivity mechanism, and demonstrate no replacement barrier. It sells software rather than a managed service, describes its SOC 2 Type 2 audit as in process, and claims proprietary test data it neither names nor sizes. By covering both build-time testing and runtime defense from one vendor, TrojAI raised the bar for a single bundled replacement, a breadth A10 says it will pair with its hardware AI firewall and sell into its 7,000-customer base.
| Description | TrojAI gives enterprises deploying AI agents visibility into agent behavior and enforcement over agent actions, beyond the prompt layer. | [f1] |
|---|---|---|
| Acquisition | A10 Networks, announced 2026-06-15 | [f2] |
| Founded | 2019 | [f3] |
| HQ | Saint John, New Brunswick, Canada | [f3] |
| Latest funding | Additional seed, USD 5.75M (April 2024), led by Flying Fish | [f4] |
| Deployment | Self-hosted | [f5] |
| Product | What it does |
|---|---|
| TrojAI | TrojAI: Tools that red team AI models at build time and apply a runtime firewall against prompt injection, data leakage, and rogue MCP servers. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
TrojAI red teams AI models at build time and applies a runtime firewall against prompt injection, data leakage, and rogue MCP servers. It is mapped to the AI Defense Matrix. [f6]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | TrojAI names the AI models, applications, and agents it defends and the enterprise security team that buys, and SecurityWeek corroborates the OWASP and privacy pain qualitatively, but no fetched source quantifies the buyer population or loss exposure, so the problem is clear and credible yet unquantified. [s1, s6, s3] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | Detect and Defend are documented with standards mapping, dashboards, and the Defend for MCP extension that Help Net Security covered, but that coverage reports the product rather than benchmarking it and no third-party evaluation of detection quality appears, so depth is vendor-documented without an external validation point. [s2, s3, s8] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | Enterprise adoption of generative and agentic AI, accelerated by MCP through 2025, opened the attack surface TrojAI addresses, and across 2025 and 2026 platform vendors acquired runtime AI security companies one after another, including Check Point buying Lakera, while Gartner now names an AI Security Testing market, multiple corroborated demand signals short of independently accelerating buyer demand. [s8, s16, s9] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | CEO Lee Weiner joined after 11 years as a senior Rapid7 executive leading the company through the revenue growth that BetaKit corroborates, and CTO and co-founder James Stewart holds a PhD and presented TrojAI's adversarial-AI research at a University of New Brunswick seminar, a verifiable in-domain operating and technical record corroborated beyond the company's own pages. [s4, s7, s10] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 | TrojAI shows verifiable partnership motion across a Microsoft Pegasus placement, a generally available OpenAI integration, and a JFrog integration, but no fetched press names a paying customer and the lone independent customer signal is five Gartner Peer Insights reviews, so traction is partnership-landing rather than a named reference roster, level with same-asset peers Lakera and CalypsoAI. [s14, s13, s9] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | The $5.75 million additional seed is proportional to an early-stage motion and TrojAI shipped two products and a Boston office on it, but revenue is undisclosed and the A10 acquisition terms are not public, so output per dollar stays unconfirmed. [s7, s6, s12] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 | Build-time AI red teaming and a runtime AI firewall are recognizable slots, and Gartner Peer Insights places TrojAI in its AI Security Testing market, but the category is still forming through the 2025 consolidation and that single independent placement does not yet show buyers and analysts ranking it, so it sits at the recognizable default alongside Lakera and CalypsoAI. [s9, s2, s3] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Red teaming and an AI firewall are both absorbable by model providers and security platforms, and the 2025 and 2026 acquisitions of runtime AI security rivals show the pressure is real, so covering both jobs raises the bar for a bundled replacement without forming a structural moat. [s3, s9, s16] |
TrojAI treats the AI models, applications, and agents an enterprise builds as the assets under attack, and sells security before and after they ship. The homepage frames the problem as agent actions that adversaries can turn toward prompt injection, tool misuse, and unsafe behavior. The buyer is the enterprise security team putting AI into a production workflow.
Independent reporting corroborates the pain beyond vendor marketing. SecurityWeek describes the platform as helping organizations comply with benchmarks such as the OWASP AI framework and privacy regulations by testing models before deployment and protecting applications from sensitive data loss once deployed. That account treats the build-time and runtime risks as recognized problems rather than vendor speculation.
The pain stays qualitatively described rather than quantified. No fetched source sizes the buyer population or the loss exposure, so TrojAI names a clear and credible problem without an independent measure of its scale. [s1, s6, s3]
TrojAI ships two products that split across the AI lifecycle. TrojAI Detect runs automated red teaming at build time, drawing on more than 150 built-in security and safety tests plus custom tests to surface weaknesses such as jailbreaks, bias, and PII leakage, then maps findings to OWASP, MITRE, and NIST. TrojAI Defend is a runtime firewall that monitors, alerts, blocks, redacts, and logs the inputs and outputs of AI applications in production.
The runtime line has extended toward agentic workflows. Help Net Security covered TrojAI Defend for MCP, built to monitor traffic to and from Model Context Protocol servers and enforce policy across agents and MCP gateways. Browser extensions let employees use third-party generative AI tools while the firewall filters inputs and outputs for PII and intellectual property.
The capability detail is vendor-documented without an external product validation point. The product pages show dashboards, standards mapping, and downloadable data sheets, but no third-party benchmark or independent evaluation of detection quality appears in fetched sources, so depth rests on TrojAI's own documentation. [s2, s3, s8]
TrojAI competes against AI security specialists and the platforms consolidating the category. Adversa AI and Mindgard sell automated AI red teaming, Lakera shipped runtime guardrails before Check Point acquired it, and HiddenLayer runs red teaming inside a broader AI security platform. Gartner Peer Insights places TrojAI in its AI Security Testing market, a sign buyers can locate the slot.
TrojAI's structural distinction is selling both the build-time and runtime jobs from one company. Most independent rivals lead with one side, while TrojAI pairs Detect and Defend so a buyer gets the stack it would otherwise assemble from two vendors. That breadth raises the bar for a single bundled replacement without forming a structural moat.
The question of who owns the buyer relationship drove the outcome, and the acquisition answered it. The model providers and security platforms TrojAI integrates with can test and protect the AI built on their own infrastructure, and the same vendors that bought AI security rivals, Check Point with Lakera among them, can bundle both jobs into deals an enterprise already signs. A10 Networks resolved TrojAI's independence question by acquiring it in June 2026, pairing it with a hardware AI firewall and an installed base to sell into. [s2, s3, s9, s11, s16]
TrojAI's clearest go-to-market signal is the roster of platform partners it routes through. The company joined the Microsoft for Startups Pegasus Program, which gives Microsoft channels and customers access to its platform, and announced a generally available integration with OpenAI's ChatGPT Enterprise Compliance API for compliance visibility and runtime protection. A JFrog integration lets TrojAI Detect red team the models an enterprise registers in JFrog Artifactory.
Named paying-customer proof is thinner than the partner motion. No fetched press names a paying customer, and the independent customer signal that stands out is Gartner Peer Insights, where five reviewers rate TrojAI 4.2 out of 5 in the AI Security Testing market. The traction is real but reads as partnership-landing and early reviews rather than disclosed revenue or a named reference roster.
The motion was enterprise-direct and partner-assisted, and A10 now owns it. TrojAI hired a Rapid7 veteran to lead go-to-market and used the Microsoft, OpenAI, and JFrog integrations to reach buyers inside platforms they already use. After the June 2026 acquisition, A10's stated plan is to sell the combined offering into its base of more than 7,000 customers. [s14, s13, s15, s9, s11]
TrojAI's leadership pairs an enterprise-security operator with technical founders. CEO Lee Weiner joined in 2024 after 11 years as a senior executive at Rapid7, where the about page says he led product, engineering, and innovation as the company scaled from $40 million to over $750 million in revenue, and BetaKit confirms the Rapid7 tenure independently.
The founders carry the technical record. Co-founder and CTO James Stewart holds a PhD and presented TrojAI's adversarial-AI approach at a University of New Brunswick research seminar, a talk titled Redefining Enterprise Cybersecurity in the Age of Adversarial AI, and Stephen Goddard is the other co-founder. That independent university seminar corroborates Stewart's technical background and adversarial-AI subject matter beyond the company's own pages.
The credibility basis is operator pedigree and a shipping product line rather than a research-disclosure stream. TrojAI earns its public standing through two delivered products and named integrations, so a buyer verifies the team through what it built and a verifiable senior security-operator record rather than a benchmark or vulnerability-research history. [s4, s7, s10]
TrojAI leans its trust posture on a self-hosted deployment model. The company describes a platform that runs inside the customer environment so data stays local, which answers the exposure question a security buyer raises early when a product inspects proprietary AI systems and traffic.
TrojAI publishes certification evidence on its footer-linked security page. The page displays a SOC 2 Type II badge and a Controlled Goods Program badge, and the body text describes the SOC 2 Type 2 audit as in process, confirmed by an independent CPA report, with certification expected in early 2024. That date has passed and the page does not say a report is downloadable, so a procurement team would still request the current SOC 2 report directly.
The acquisition adds a data-sovereignty argument. A10 positions the combined offering for customers who want to keep sensitive AI assets in environments they control, extending the self-hosted posture rather than changing it. The readiness gap is a verifiable current report rather than an absent program. [s5, s3, s11]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Adversa AI | competes with | Independent AI red-teaming specialist contesting the same build-time adversarial-testing buyer, without a paired runtime firewall. | |
| Mindgard | competes with | Automated AI red-teaming specialist competing on the build-time testing side of TrojAI's platform. | |
| HiddenLayer | competes with | Independent AI security platform whose attack-simulation module overlaps Detect inside a broader lifecycle suite. | |
| Lakera | competes with | Shipped runtime AI guardrails overlapping Defend before Check Point acquired it, moving the runtime job into a platform. | |
| Prompt Security | competes with | Runtime AI security vendor contesting the production-firewall job that TrojAI Defend covers. | |
| OpenAI | adjacent | Integration partner and model provider that could ship native red teaming and runtime filtering for AI built on its platform. | N/AWe scored these companies at different scopes, so the totals measure different things. |
Add analyzed competitors to compare them side by side with TrojAI.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
pivot urgently
TrojAI's demanding work is building adversarial-AI testing and an inline firewall. The cited sources document that engineering across an extensive built-in test library and a firewall that screens production traffic in real time, and they carry no competitor benchmark, reconstruction evidence, or time-to-copy measure, so neither a replacement barrier nor its absence is demonstrated. TrojAI sells software rather than a service that accepts accountability, describes its SOC 2 Type 2 audit as in process, and claims proprietary test data it neither names nor sizes. By selling both the build-time and runtime jobs from one vendor, TrojAI widened what a single acquisition must replace, a breadth A10 says it will pair with its hardware AI firewall, not a structural moat.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Customers buy software, the Detect red-teaming scanner and the Defend runtime firewall they configure, and the fetched pages describe no managed judgment-and-accountability service layer, the software-product level. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Placing Defend inline in the production request flow and wiring Detect, MCP policy enforcement, and the employee-coverage line into a security team's workflow builds real friction once in place, but the record shows no system-of-record install base or residency lock that would block a replacement. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | TrojAI's security page describes a SOC 2 Type 2 audit as in process rather than a finished report, in-progress table-stakes assurance, and no regime in the cited record mandates buying this product. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Generating automated adversarial tests across an extensive built-in case library against models, applications, and agents, then running an inline firewall that monitors, blocks, and redacts production traffic in real time, is hard applied-security engineering across the model, application, and agent surface. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | The buyer is the large enterprise standing up AI, but the line's own named proof is platform integrations plus five Gartner Peer Insights reviews rather than disclosed paying logos, and A10's base does not lift the line. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Defend is an inline runtime control and Detect is a build-time testing tool with an employee-coverage line, application-layer security features a customer's AI keeps functioning without. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The vendor describes proprietary fine-tuned adversarial models and custom datasets that accelerate testing but names and sizes none of them, so the record shows engineering IP and an accumulating test library rather than a named or sized non-public corpus, and no crowdsourced attack flywheel is quoted. |
TrojAI sells to the enterprise security team standing up AI in a core workflow. The company frames the buyer as an organization deploying AI models, applications, and agents into production, and pitches security for both the build phase and runtime. The homepage leads with securing agent actions against prompt injection, tool misuse, and unsafe behavior, naming the buyer that already runs agents and feels the exposure.
The two products widen the segment without a managed-service tier. A team red teams its models before launch with Detect and filters production traffic with Defend, and the Defend page says its browser extensions let employees use third-party GenAI and co-pilot applications safely, extending runtime coverage to that traffic. The A10 announcement describes protection across on-premises, cloud, and hybrid environments with customers keeping control of sensitive assets, a pitch aimed at the security-conscious enterprise, while TrojAI's own security page describes its production applications as hosted in a secure cloud environment.
The named demand is thin and indirect. No fetched press names a paying customer, and the clearest independent customer signal is five Gartner Peer Insights reviews in the AI Security Testing market alongside platform integrations rather than disclosed logos. A10 now points the line at its own customer base, so the open segment question is which buyers convert soonest under a parent that sells into networks and service providers.
TrojAI splits its capability across the AI lifecycle. TrojAI Detect runs automated red teaming at build time with an extensive built-in library of security and safety tests plus custom tests, attacking models to surface weaknesses and mapping findings to recognized AI security standards such as OWASP. TrojAI Defend is a runtime firewall that monitors, alerts, blocks, redacts, and logs the inputs and outputs of AI applications in production.
The runtime line has extended toward agentic workflows. Help Net Security covered TrojAI Defend for MCP, which monitors traffic to and from Model Context Protocol servers and enforces policy across agents and MCP gateways. Pairing build-time testing with runtime filtering in one vendor is the capability claim that separates TrojAI from single-product rivals.
The durable engineering is real but the data advantage is undemonstrated. Building adversarial test generation and an inline firewall that decides in real time is genuine applied-security work, and the Detect page says testing can be accelerated using TrojAI's proprietary fine-tuned adversarial models and custom datasets. Yet those models and datasets carry no name, size, or exclusivity mechanism in fetched sources, the cited record does not show whether or how quickly the accumulating test library could be reproduced, and no third-party accuracy benchmark appears. The advantage is craft and coverage breadth rather than a demonstrated proprietary data asset.
TrojAI's go-to-market rested on platform reach more than a customer roster. The company landed an OpenAI ChatGPT Enterprise Compliance API integration, which connected it to ChatGPT Enterprise compliance data, and a Microsoft for Startups Pegasus placement, which exposed it through Microsoft channels and customers, and it hired a long-tenured enterprise-security operator to lead the motion. The OpenAI integration paired compliance visibility with runtime protection across enterprise AI interactions.
Verifiable paying-customer proof stayed thinner than the partner motion. No fetched press names a paying customer, though BetaKit quotes an investor describing a production implementation at a major financial-services company, unnamed, and the clearest independent customer signal is five Gartner Peer Insights reviews rating TrojAI 4.2 out of 5. The customer evidence amounts to who TrojAI integrates with, that unnamed deployment, and a handful of reviewers rather than a disclosed reference roster, in an enterprise-direct, partner-assisted motion routing prospects to a contact-sales flow.
The acquisition resolved the standalone question and reset the motion. A10 says it bought TrojAI to sell the combined offering into its base of more than 7,000 customers, a post-acquisition distribution opportunity distinct from TrojAI's own demonstrated traction, so the test shifts from whether partner reach converts to whether A10's channel does. The integration breadth A10 inherited still lacks the named reference roster a buyer requiring customer proof would ask for.
TrojAI does not publish pricing in fetched sources, so the charged unit and list price stay private. A vendor that hides prices usually targets large negotiated enterprise deals, which fits the complex-enterprise buyer the company describes and the contact-sales flow it routes prospects through. The absence withholds the budget-anchoring signal some peers publish openly.
The two products imply two value meters that the public materials do not separate. Build-time red teaming reads as a testing subscription priced by models or scans, while the runtime firewall reads as production coverage priced by traffic or applications, and the firewall dashboard the site shows counts over 500,000 events. What TrojAI charges by, models, applications, events, or seats, is not stated publicly.
The inferable belief is that buyers pay for AI risk coverage rather than per-feature tooling. Confirming the unit and whether consumption is metered would require a sales conversation, which the hidden-price posture signals is the intended path, and A10's ownership may fold the line into its own enterprise contracting.
TrojAI delivers software with deployment flexibility rather than a documented single hosting model. The A10 announcement describes protecting AI across on-premises, cloud, and hybrid environments with customers keeping control of sensitive assets, while TrojAI's own security page describes its production applications as hosted in a secure cloud environment, so the operating split between vendor and customer is not fully documented. Detect runs the build-time scans and Defend runs the inline production firewall.
The runtime path carries the operational weight. Defend monitors, alerts, blocks, redacts, and logs inputs and outputs in production, the Defend for MCP line enforces policy on agent tool connections, and the Defend page describes browser extensions that cover employee use of third-party GenAI and co-pilot applications. The firewall sits in the live request flow, so its availability and latency become the customer's production concern.
The delivery model is software, not a managed outcome. The fetched pages describe no analyst service that accepts hands-on responsibility for results, so the offering reads as a platform the buyer operates against its own accountability. Published uptime or support service levels do not surface in fetched pages, and A10 frames the value as preserving the latency and availability its hardware customers already rely on.
TrojAI leans its trust posture on customer control of sensitive assets and a documented security program. The security page documents AES 256-bit encryption at rest and describes a SOC 2 Type 2 audit as in process, and the A10 announcement emphasizes protecting AI wherever it runs with customers keeping control of sensitive assets. That gives an enterprise buyer baseline procurement information for a product that inspects privileged AI models and traffic.
The attestation posture is in-progress rather than a moat. The in-process SOC 2 audit does not itself demonstrate an exclusive compliance advantage, the page frames the Type 2 audit as in process rather than a finished report, and fetched pages do not show a downloadable current report. A procurement team would verify whether the SOC 2 Type 2 audit completed and request the current report.
The acquisition adds a sovereignty argument to the trust story. A10 positions the combined offering for customers with strict data-sovereignty requirements who want to keep sensitive AI assets in environments they control, extending the customer-control posture rather than changing it. The trust gap remains a verifiable current report rather than an absent program.
TrojAI positions itself as lifecycle coverage for enterprise AI rather than a point tool. It pairs build-time red teaming with a runtime firewall and agent-tool policy enforcement, so TrojAI grounds the platform claim in owning both the pre-launch testing and the production defense for a customer's models, applications, and agents. Gartner Peer Insights places it in the AI Security Testing market, and integrations reach into tools enterprises already use to build and ship AI.
That breadth raises the bar for a bundled replacement. Combining build-time testing and runtime defense in one vendor can reduce the need to assemble the stack from two tools, though the cited record carries no competitor-by-competitor comparison, so the sources demonstrate bundled breadth without establishing a structural replacement barrier.
The exposure is that the platforms TrojAI integrates with own the buyer relationship and the model itself. Model providers can test and protect the AI built on their own infrastructure, and security platforms that bought AI security rivals can fold both jobs into deals an enterprise already signs. A10 resolved the independence question by acquiring the line, pairing a neutral third-party pitch with a parent that has hardware and an installed base.
TrojAI pairs technical founders with an enterprise-security operator at the top. Co-founder and CTO James Stewart holds a PhD and built with his co-founder the platform that secures models at build time and runtime. CEO Lee Weiner brings more than 25 years of B2B software experience and, the about page says, 11 years as a senior Rapid7 executive leading the company through revenue growth.
The team's standing is independently corroborated rather than self-asserted. BetaKit confirms Weiner's Rapid7 tenure, and Stewart was listed as a featured speaker for a University of New Brunswick research seminar on TrojAI's adversarial-AI approach, so a buyer can verify the team through what it built and an outside academic platform rather than a stream of vendor disclosures.
The acquisition is itself a team signal. Weiner is quoted in the A10 announcement, and the engineering that built Detect and Defend is what changed hands. Whether the founders and engineers stay under A10 is a standard post-acquisition question the fetched record does not address.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | TrojAI: The Security Platform for Agentic AI | official | 2026-07-09 |
| f2 | citybiz on A10 Networks acquiring TrojAI for AI and sovereign AI security | press | 2026-06-16 |
| f3 | SecurityWeek on TrojAI, founded 2019 | press | 2026-06-13 |
| f4 | TrojAI USD 5.75M additional seed round, April 2024 | press | 2026-06-13 |
| f5 | AI Defense Matrix Catalog entry | other | 2026-06-10 |
| f6 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | TrojAI homepage: Deploy AI Agents with Confidence “Secure agent actions to prevent prompt injection, tool misuse, and unsafe behavior.” | official | 2026-06-29 |
| s2 | TrojAI Detect build-time red teaming product page “TrojAI delivers more than 150 built-in security and safety tests and lets you create custom tests to find defects in your AI models.” | official | 2026-06-29 |
| s3 | TrojAI Defend runtime firewall product page “Monitor. Alert. Block. Redact. Log. Stop active threats to AI models, applications, and agents in production with real-time monitoring.” | official | 2026-06-29 |
| s4 | TrojAI about page (leadership and mission) “Prior to joining TrojAI, Lee was a senior executive at Rapid7 for 11 years, leading product, engineering, and innovation as the company scaled from $40 million to over $750 million in revenue.” | official | 2026-06-29 |
| s5 | TrojAI security page (SOC 2 Type II and Controlled Goods Program badges, in-process SOC 2 Type 2 audit) “TrojAI is in the process of completing a Type 2 Service Organization Control 2 (SOC 2 Type 2) audit, as confirmed by an independent CPA report and certification.” | official | 2026-06-29 |
| s6 | SecurityWeek on TrojAI seed funding, OWASP and privacy testing “The company says its platform helps organizations comply with benchmarks such as the OWASP AI framework as well as privacy regulations by testing models prior to deployment and protecting applications from things such as sensitive data loss once deployed.” | press | 2026-06-29 |
| s7 | BetaKit on TrojAI funding, new CEO, and Maritimes-to-Boston expansion “Enterprise artificial intelligence (AI) security startup TrojAI has appointed a new CEO and secured $7.76 million CAD ($5.75 million USD) in funding as it expands its footprint out of the Maritimes.” | press | 2026-06-29 |
| s8 | Help Net Security on TrojAI Defend for MCP “TrojAI Defend for MCP was built to monitor traffic to and from MCP servers, providing unified visibility, policy analysis, and runtime enforcement across agents and MCP gateways.” | press | 2026-06-29 |
| s9 | Gartner Peer Insights: TrojAI in the AI Security Testing market “TrojAI is present in 1 market with 1 product. TrojAI has 5 reviews with an overall average rating of 4.2.” | research | 2026-06-29 |
| s10 | University of New Brunswick RIDSAI research seminar featuring TrojAI CTO James Stewart “Name of Speaker: James Stewart (CTO TrojAI) Title: Redefining Enterprise Cybersecurity in the Age of Adversarial AI” | research | 2026-06-29 |
| s11 | A10 Networks acquires TrojAI (Trivedi hardware-plus-software pairing) “Pairing our hardware-based AI firewall with TrojAI's software-based red teaming and runtime protection helps customers adopt AI quickly and confidently, protecting their models, data, and agents without sacrificing the latency or availability they rely on us for” | press | 2026-06-29 |
| s12 | citybiz on A10 acquiring TrojAI (terms undisclosed) “A10 Networks has acquired AI security company TrojAI, advancing its strategy to build a comprehensive security platform for organizations deploying artificial intelligence applications, autonomous agents, and large language models across enterprise environments.” | press | 2026-06-29 |
| s13 | TrojAI integration with OpenAI ChatGPT Enterprise Compliance API “today announced an integration with OpenAI's ChatGPT Enterprise Compliance API to deliver enhanced compliance visibility and runtime protection for organizations.” | press | 2026-06-29 |
| s14 | TrojAI joins Microsoft for Startups Pegasus Program “The Pegasus Program gives Microsoft channels and customers access to TrojAI's innovative platform, which empowers enterprises to safeguard AI applications and models both at build time and run time.” | press | 2026-06-29 |
| s15 | JFrog integration page for TrojAI Detect and JFrog Artifactory “TrojAI uncovers AI vulnerabilities by redteaming JFrog Artifactory models for weaknesses like prompt injections, data leakages, and toxic content.” | official | 2026-06-29 |
| s16 | CyberScoop on Check Point acquiring AI security firm Lakera “Check Point Software Technologies announced Monday it will acquire Lakera, a specialized artificial intelligence security platform, as entrenched cybersecurity companies continue to expand their offerings to match the generative AI boom.” | press | 2026-06-29 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | TrojAI homepage: Deploy AI Agents with Confidence “Secure agent actions to prevent prompt injection, tool misuse, and unsafe behavior.” | official | 2026-06-29 |
| s2 | TrojAI Detect build-time red teaming product page “Leverage thousands of out-of-the-box attacks, manipulations, and adversarial testing scenarios. Manually configure tests or accelerate testing using TrojAI's proprietary fine-tuned adversarial models and custom datasets.” | official | 2026-07-14 |
| s3 | TrojAI Defend runtime firewall product page “Monitor. Alert. Block. Redact. Log. Stop active threats to AI models, applications, and agents in production with real-time monitoring.” | official | 2026-06-29 |
| s4 | TrojAI about page (leadership and mission) “Prior to joining TrojAI, Lee was a senior executive at Rapid7 for 11 years, leading product, engineering, and innovation as the company scaled from $40 million to over $750 million in revenue.” | official | 2026-06-29 |
| s5 | TrojAI security page (in-process SOC 2 Type 2 audit) “TrojAI is in the process of completing a Type 2 Service Organization Control 2 (SOC 2 Type 2) audit, as confirmed by an independent CPA report and certification.” | official | 2026-07-10 |
| s6 | A10 Networks acquires TrojAI (Trivedi hardware-plus-software pairing, data sovereignty) “Pairing our hardware-based AI firewall with TrojAI's software-based red teaming and runtime protection helps customers adopt AI quickly and confidently, protecting their models, data, and agents without sacrificing the latency or availability they rely on us for” | press | 2026-06-29 |
| s7 | citybiz on A10 acquiring TrojAI (terms undisclosed) “A10 Networks has acquired AI security company TrojAI, advancing its strategy to build a comprehensive security platform for organizations deploying artificial intelligence applications, autonomous agents, and large language models across enterprise environments.” | press | 2026-06-29 |
| s8 | Help Net Security on TrojAI Defend for MCP “TrojAI Defend for MCP was built to monitor traffic to and from MCP servers, providing unified visibility, policy analysis, and runtime enforcement across agents and MCP gateways.” | press | 2026-06-29 |
| s9 | SecurityWeek on TrojAI platform, OWASP and privacy testing “The company says its platform helps organizations comply with benchmarks such as the OWASP AI framework as well as privacy regulations by testing models prior to deployment and protecting applications from things such as sensitive data loss once deployed.” | press | 2026-06-29 |
| s10 | Gartner Peer Insights: TrojAI in the AI Security Testing market “TrojAI is present in 1 market with 1 product. TrojAI has 5 reviews with an overall average rating of 4.2.” | research | 2026-06-29 |
| s11 | University of New Brunswick RIDSAI research seminar featuring TrojAI CTO James Stewart “Name of Speaker: James Stewart (CTO TrojAI) Title: Redefining Enterprise Cybersecurity in the Age of Adversarial AI” | research | 2026-06-29 |
| s12 | BetaKit on TrojAI funding, new CEO, and Maritimes-to-Boston expansion “Enterprise artificial intelligence (AI) security startup TrojAI has appointed a new CEO and secured $7.76 million CAD ($5.75 million USD) in funding as it expands its footprint out of the Maritimes.” | press | 2026-06-29 |
| s13 | TrojAI integration with OpenAI ChatGPT Enterprise Compliance API “today announced an integration with OpenAI's ChatGPT Enterprise Compliance API to deliver enhanced compliance visibility and runtime protection for organizations.” | press | 2026-06-29 |
| s14 | JFrog integration page for TrojAI Detect and JFrog Artifactory “TrojAI uncovers AI vulnerabilities by redteaming JFrog Artifactory models for weaknesses like prompt injections, data leakages, and toxic content.” | official | 2026-06-29 |
| s15 | TrojAI joins Microsoft for Startups Pegasus Program “The Pegasus Program gives Microsoft channels and customers access to TrojAI's innovative platform, which empowers enterprises to safeguard AI applications and models both at build time and run time.” | press | 2026-06-29 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.