Virtue AI

Security for AI Application SecurityGovernance Risk Compliance acquired also known as Virtue AI Inc

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2024
Funding $30M
Last updated 2026-08-29

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Fortinet acquired Virtue AI, an enterprise AI security company, in August 2026, having already shipped its own product that guards large language models against prompt injection and data leakage. Fortinet says Virtue extends that protection to applications and autonomous agents. Virtue's products red-team agents across more than 50 sandboxed environments, apply real-time guardrails across five media types, and block an agent's tool call before it fires. The customer names in the reviewed record, among them AllianceBernstein, Uber and Glean, come from Virtue and one investor rather than independent reporting. Three of its four founders sit on the DecodingTrust author list, a NeurIPS 2023 Outstanding Paper.

Sourced Details

Description Virtue AI builds an enterprise platform that red-teams, guards, and governs AI models, applications, and agents. [f1]
Acquisition Fortinet, announced 2026-08-17 [f2]
Founded 2024 [f3]
HQ San Francisco, California, United States [f4]
Funding $30M total [f4]
Latest funding Series A [f4]

Products

Product What it does
VirtueRed Continuous automated AI red-teaming using proprietary algorithms across 600+ attack vectors and 1000+ risk categories, generating audit-ready evidence for security and compliance reviews.
VirtueGuard A family of real-time guardrail models covering violence, hate, PII exposure and jailbreaks across text, code, image, video and audio in more than 100 languages, with policies written in plain text.
AgentSuite-Red An enterprise-scale testing ground that red-teams agentic systems across more than 50 sandboxed environments and 14 high-stakes domains, probing them with an adversarial agent.
AgentSuite-Blue A runtime security, governance and compliance suite for agentic systems that scans MCP tools for injections, blocks malicious tool calls, and surfaces unsanctioned AI through the endpoint agent.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

VirtueGuard filters runtime prompts and responses, AgentSuite-Blue gates agent tool calls in real time, and VirtueRed red-teams models and applications. These capabilities are mapped to the AI Defense Matrix. [f5]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 27 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Virtue names the regulated industries it is built for and the failure classes it sells against, and a Federal Register notice from NIST's AI standards center documents agent hijacking and backdoor attacks as live risks. Neither source puts a figure on what those failures cost a named buyer, so the problem is credible and unquantified. [s2, s10]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 Vendor pages name specific mechanisms rather than slogans: an inference engine Virtue built in-house and calls Prelude, guardrails covering five media types across a hundred-plus languages, and agent testing that runs through more than 50 sandboxed environments. No independently published technical evaluation of Virtue's own products appears in the reviewed sources, and the customer statements Virtue publishes are testimonials rather than test results. [s1, s2, s4]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 4/5 Two demand drivers of different kinds fall within the past year, neither of them Virtue's own. Gartner's 30 July 2026 forecast, cited by report title and analyst in Fortinet's announcement, puts buyer spending on securing AI ecosystems and AI agents at $2.8 billion in 2026 rising to $16.4 billion by 2030, which is the analyst-category kind. NIST's Center for AI Standards and Innovation sought industry practices for measuring and improving AI agent security in a Federal Register notice published on 8 January 2026, comments closing 9 March, which is the regulatory-driver kind. [s4, s10]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 4/5 Three of the four founders, Bo Li, Dawn Song and Sanmi Koyejo, appear on the DecodingTrust author list that arXiv records as a NeurIPS 2023 Outstanding Paper in the Datasets and Benchmarks Track, and SC Media gave Bo Li its 2026 Innovator of the Year award. A plurality of the founding team therefore carries recognition awarded by parties outside the company. [s3, s7, s9]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 4/5 Virtue publishes multiple named enterprise references with a named executive attached, among them AllianceBernstein, Uber and Glean, alongside a financial-services case study, and its investor Walden Catalyst separately names Uber and Glean as early adopters. Those customer names are Virtue's own with an investor relaying two of them, so the references are multiple while the scale behind them stays undisclosed. [s1, s2, s8]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 4/5 Virtue raised $30 million in seed and Series A funding and Fortinet acquired the company within roughly two years, an exit SecurityWeek reported independently, which is confirmed output for the capital deployed. The price was not disclosed and no revenue or margin figure appears in the reviewed sources, so operating efficiency stays unconfirmed. [s5, s6]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Gartner names a Guardian Agents category and lists Virtue in a market guide and a hype cycle, but Virtue's own pages are where those placements are read, and the independent framing in SecurityWeek is the broad label AI security company. The placement that names it precisely comes from the vendor's display. [s1, s5]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 2/5 Fortinet shipped FortiAIGate, which guards large language models against prompt injection and data leakage, earlier in 2026, then acquired Virtue in August, saying the deal complements FortiAIGate and strengthens its own AI runtime security. [s4, s5]
Business Risks Fortinet has not said whether the Virtue brand and its separate product line continue, so a buyer choosing VirtueRed or VirtueGuard today cannot tell from the public record how those products will be packaged and sold…
  • Fortinet has not said whether the Virtue brand and its separate product line continue, so a buyer choosing VirtueRed or VirtueGuard today cannot tell from the public record how those products will be packaged and sold.
  • FortiAIGate already covers the guardrail layer Fortinet bought Virtue to extend, so a customer standardized on one of the two could find overlapping functions consolidated into a single product line.
  • Buyers had the founders' research record to go on, and the reviewed sources do not say which founders continue with the company after the acquisition.
  • The trust center at trust.virtueai.com returns a page-not-found screen, so the reviewed sources carry no inspectable attestation while the transition runs.
Problem & Market Virtue AI sells into the gap between conventional security tooling and the attack surface generative AI creates. The company argues that prompt injection, data leakage, jailbreaks and out-of-policy agent actions expose enterprises. Public policy documents the same problem. NIST's Center for AI Standards and Innovation told the Federal Register in January 2026 that AI agent systems take autonomous actions affecting real-world environments and may be susceptible to hijacking, backdoor attacks and other exploits, and it asked industry for measurement practices by 9 March. Virtue names the environments it is built for: financial services, healthcare, insurance, government and the Fortune 500. Naming regulated industries puts compliance timing alongside attacker pressure in the pitch…

Virtue AI sells into the gap between conventional security tooling and the attack surface generative AI creates. The company argues that prompt injection, data leakage, jailbreaks and out-of-policy agent actions expose enterprises.

Public policy documents the same problem. NIST's Center for AI Standards and Innovation told the Federal Register in January 2026 that AI agent systems take autonomous actions affecting real-world environments and may be susceptible to hijacking, backdoor attacks and other exploits, and it asked industry for measurement practices by 9 March.

Virtue names the environments it is built for: financial services, healthcare, insurance, government and the Fortune 500. Naming regulated industries puts compliance timing alongside attacker pressure in the pitch. [s2, s10]

Product Capabilities Virtue ships a multi-product platform rather than a single control…

Virtue ships a multi-product platform rather than a single control. VirtueRed runs continuous automated red-teaming, which the company sizes at more than 100 proprietary algorithms against 600-plus attack vectors and 1,000-plus risk categories. VirtueGuard applies runtime guardrails across text, code, image, video and audio in more than 100 languages, with policies a customer writes in plain language.

AgentSuite-Red and AgentSuite-Blue extend that work to agents. The testing side runs agents through more than 50 sandboxed environments across 14 domains with an adversarial agent, a figure Fortinet repeats in its own description of what it bought. The runtime side scans MCP tools for hidden injections, blocks malicious tool calls before they fire, and surfaces unsanctioned AI through the endpoint agent a customer already runs.

Virtue states that VirtueGuard runs on Prelude, an inference engine it built in-house to cut end-to-end latency. [s1, s2, s4]

Competitive Positioning Fortinet was already selling into this problem before it bought Virtue…

Fortinet was already selling into this problem before it bought Virtue. Its press release states that it shipped FortiAIGate earlier in 2026 to safeguard large language models against prompt injections, data leakage and model poisoning, and that Virtue AI extends that security to models, applications and agentic systems from development through runtime.

That pairing tells a buyer where the two halves of Virtue's platform sit. The guardrail half covers ground a network-security incumbent had already built for itself. Fortinet's release lists four capabilities the deal brings: agentic red-teaming, agent protection and governance, continuous validation, and real-time guardrails. The scope Fortinet gives FortiAIGate in the same release is the model layer. [s4, s5]

Go-to-Market & Traction Virtue shows early enterprise references for a company founded in 2024…

Virtue shows early enterprise references for a company founded in 2024. It publishes a case study with the asset manager AllianceBernstein, quoting its chief AI officer, plus a testimonial from a lead technical manager at Uber and one from Glean's founder and chief executive. Its investor Walden Catalyst separately names Uber and Glean as early adopters.

Every one of those names comes from Virtue or from a firm that invested in it, and the revenue or seat volume behind them is not disclosed. SecurityWeek reported the $30 million seed and Series A round and the Fortinet acquisition, and neither report carries a customer count.

The commercial outcome the record does document is the exit itself. Fortinet bought the company roughly two years after it was founded, and said the consideration was immaterial to its business, so the deal confirms that the work found a buyer without sizing what it was worth. [s1, s2, s5, s6, s7, s8]

Team & Credibility Bo Li is founder and chief executive, joined by Dawn Song as a founder and board director, Sanmi Koyejo as founder and chief AI officer, and Carlos Guestrin as founder and chief scientist. Bo Li also teaches computer science at the University of Illinois Urbana-Champaign. The research record is more specific than the company's own summary of it. Virtue's site credits the founders with open-sourcing DecodingTrust and winning a NeurIPS best-paper award, while arXiv records the paper as a NeurIPS 2023 Outstanding Paper in the Datasets and Benchmarks Track with 19 authors, three of whom are Virtue founders. Carlos Guestrin is not on that author list. Independent recognition reaches beyond the paper. SC Media named Bo Li its 2026 Innovator of the Year and reported that Fortune had listed Virtue AI among its Cyber 60 companies…

Bo Li is founder and chief executive, joined by Dawn Song as a founder and board director, Sanmi Koyejo as founder and chief AI officer, and Carlos Guestrin as founder and chief scientist. Bo Li also teaches computer science at the University of Illinois Urbana-Champaign.

The research record is more specific than the company's own summary of it. Virtue's site credits the founders with open-sourcing DecodingTrust and winning a NeurIPS best-paper award, while arXiv records the paper as a NeurIPS 2023 Outstanding Paper in the Datasets and Benchmarks Track with 19 authors, three of whom are Virtue founders. Carlos Guestrin is not on that author list.

Independent recognition reaches beyond the paper. SC Media named Bo Li its 2026 Innovator of the Year and reported that Fortune had listed Virtue AI among its Cyber 60 companies. [s3, s7, s9]

Trust Readiness Virtue states on its platform page that it is built to satisfy enterprise reviews with SOC 2 compliance and HIPAA-ready data privacy protocols. That is the company's own statement of its posture, and the reviewed sources do not carry a report, its scope or its date. The page at trust.virtueai.com returned a page-not-found screen to an agent-browser render on 29 August 2026, and a direct fetch of the same URL that day returned a document whose only extracted text was the word Vanta. The practical consequence falls on procurement rather than on the product. A regulated buyer cannot complete the compliance half of its diligence from the public materials reviewed here…

Virtue states on its platform page that it is built to satisfy enterprise reviews with SOC 2 compliance and HIPAA-ready data privacy protocols. That is the company's own statement of its posture, and the reviewed sources do not carry a report, its scope or its date.

The page at trust.virtueai.com returned a page-not-found screen to an agent-browser render on 29 August 2026, and a direct fetch of the same URL that day returned a document whose only extracted text was the word Vanta.

The practical consequence falls on procurement rather than on the product. A regulated buyer cannot complete the compliance half of its diligence from the public materials reviewed here. [s2, s11]

Competitors Lakera, CalypsoAI, Robust Intelligence, Enkrypt AI, Straiker…
Company Relationship Note Compare
Lakera competes with N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
CalypsoAI competes with N/AWe scored these companies at different scopes, so the totals measure different things.
Robust Intelligence competes with N/AWe scored these companies at different scopes, so the totals measure different things.
Enkrypt AI competes with N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Straiker competes with N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.

Add analyzed competitors to compare them side by side with Virtue AI.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 14 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

Virtue ships guardrail models covering five media types and a hundred-plus languages, an inference engine it built in-house, and agent testing across dozens of sandboxed environments. Virtue names AllianceBernstein as a customer and says the product is built for regulated environments. What Virtue owns exclusively is narrower, since it calls more than 100 attack algorithms exclusive to its platform while publishing the DecodingTrust benchmark openly. Its compliance claims are vendor-stated, and a probe of trust.virtueai.com on 29 August 2026 returned a page-not-found screen. Fortinet, already selling a guardrail product of its own, bought the company.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Virtue delivers software the customer deploys and runs: guardrail classifiers plugged into applications and agents, a red-teaming engine that tests on a schedule, and a policy layer the customer authors in plain text. The reviewed sources describe the purchase as that software, with no managed-service or accountability layer beside it.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Guards embed into a customer's applications, agents, gateways and retrieval pipelines, and a customer authors the enforcement policies. The cited record documents that integration but does not size the migration, and it shows no network effect, no state a customer cannot export, and no obligation binding its data to Virtue's footprint.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 Virtue states SOC 2 compliance and HIPAA-ready protocols on its platform page, and a probe of its trust center at trust.virtueai.com on 29 August 2026 returned a page-not-found screen rather than a document list. SOC 2 is preparation a funded competitor completes for the enterprise market, so it does not block a replacement whether or not the report exists.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Virtue says its guardrails run on its own models across five media types and more than 100 languages, and on Prelude, an inference engine it built in-house. It tests agents across more than 50 sandboxed environments in 14 domains with an adversarial agent. That mix spans machine learning and real-time systems.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 Virtue names AllianceBernstein as a customer, and its platform page states the product is purpose-built for regulated environments across financial services, healthcare, insurance, government and the Fortune 500.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 VirtueGuard classifiers and the AgentSuite controls plug into a customer's applications, agents, gateways and retrieval pipelines, which is a platform carrying application features. The reviewed sources show no other application depending on Virtue as infrastructure.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 2/3 Virtue's homepage names more than 100 red-teaming algorithms and reusable attack skills it says are built in-house and exclusive to its platform, drawn from its own research program, held by the vendor rather than in per-tenant custody, and nowhere shown public. That is an accumulated asset a funded rival could rebuild with time and effort, and the benchmark Virtue published openly is a public input rather than the retained output.
Strategic Market Segmentation Virtue AI names industries rather than a job title…

Virtue AI names industries rather than a job title. Its platform page states the product is purpose-built for regulated environments across financial services, healthcare, insurance, government and the Fortune 500, and the named case study is the asset manager AllianceBernstein.

The product line sharpens the segment around autonomous agents. AgentSuite-Blue watches agents as they call tools and blocks a malicious call before it fires, and Shadow AI surfaces unsanctioned agents and apps across a customer's cloud and endpoints. Virtue delivers that discovery through the endpoint detection product a customer already runs.

NIST's Center for AI Standards and Innovation published a Federal Register notice in January 2026 seeking industry practices for measuring and improving the security of AI agent systems, naming hijacking and backdoor attacks among the risks.

Product Capabilities & AI Advantages Virtue ships a multi-product platform rather than a single control…

Virtue ships a multi-product platform rather than a single control. VirtueRed runs continuous automated red-teaming, sized on the vendor's page at more than 100 proprietary algorithms across 600-plus attack vectors and 1,000-plus risk categories. VirtueGuard supplies real-time guardrail models across text, code, image, video and audio in more than 100 languages, with policies a customer writes in plain text or extracts from existing documents.

AgentSuite-Red and AgentSuite-Blue carry the work into agent systems. The testing side runs agents through more than 50 sandboxed environments across 14 domains with an adversarial agent and an injection server that replays real attacks against any MCP-tool-using agent, a figure Fortinet repeats in describing what it bought. The runtime side scans MCP tools and source code for hidden injections and blocks tool calls in flight.

Virtue says VirtueGuard runs on Prelude, an inference engine it built in-house to accelerate prefill and cut end-to-end latency.

Sales Engagement & Go-to-Market The reviewed sources do not document a sales engine…

The reviewed sources do not document a sales engine. Bo Li won a 2026 SC Award as innovator of the year, and the company publishes an AllianceBernstein case study, an Uber testimonial for its guardrails, and a testimonial from Glean's founder and chief executive.

The financial backing is better documented than the sales record. SecurityWeek reported the $30 million seed and Series A round led by Lightspeed Venture Partners and Walden Catalyst Ventures, and Walden Catalyst separately named Uber and Glean as early adopters. Every customer name in the reviewed record comes from Virtue or from a firm that invested in it, so the references are countable while the revenue behind them is not.

The commercial outcome the record does document is the exit. Fortinet bought the company roughly two years after it was founded and said the consideration was immaterial to its business, which confirms that the work found a buyer without sizing what it fetched.

Pricing Model No pricing appears in the reviewed sources, and Virtue's platform page does not name the unit Virtue charges by. Virtue describes each guard as a small, fast classifier a customer plugs into an application, agent, gateway or retrieval pipeline. No list price, tier or per-call rate appears in the reviewed sources…

No pricing appears in the reviewed sources, and Virtue's platform page does not name the unit Virtue charges by.

Virtue describes each guard as a small, fast classifier a customer plugs into an application, agent, gateway or retrieval pipeline. No list price, tier or per-call rate appears in the reviewed sources.

Product Delivery & Operations Virtue delivers controls as software the customer embeds, with cloud and on-premises options so a buyer can keep proprietary data and sensitive AI infrastructure inside its own environment. Guards attach at the application, agent, gateway or retrieval-pipeline boundary, and Shadow AI rides the endpoint agent a security team already runs. A customer authors enforcement policies, or has PolicyGuard extract them from existing documents, and runs agents through sandboxed environments. VirtueRed is the product Virtue credits with generating audit-ready evidence for a compliance review…

Virtue delivers controls as software the customer embeds, with cloud and on-premises options so a buyer can keep proprietary data and sensitive AI infrastructure inside its own environment. Guards attach at the application, agent, gateway or retrieval-pipeline boundary, and Shadow AI rides the endpoint agent a security team already runs.

A customer authors enforcement policies, or has PolicyGuard extract them from existing documents, and runs agents through sandboxed environments. VirtueRed is the product Virtue credits with generating audit-ready evidence for a compliance review.

Earning Customers' Trust Compliance sits at the center of what Virtue sells…

Compliance sits at the center of what Virtue sells. Its products align to the EU AI Act, GDPR, FINRA and NIST's AI risk framework among others, and the governance layer lets a customer stack more than 50 standardized frameworks alongside its own policies in one enforcement layer.

Virtue's own security posture is stated rather than shown. The platform page says the product is built to satisfy rigorous enterprise reviews with SOC 2 compliance and HIPAA-ready privacy protocols, and the reviewed sources carry no report, scope or date behind that statement.

A probe on 29 August 2026 found nothing readable either. The trust center at trust.virtueai.com returned a page-not-found screen to an agent-browser render, and a direct fetch of the same URL that day returned a document whose only extracted text was the word Vanta. A regulated buyer therefore cannot complete the compliance half of its diligence from public materials.

Platform Strategy & Ecosystem Positioning Virtue's platform reaches into a customer's stack rather than standing alone. Guards plug into applications, agents, gateways and retrieval pipelines, the agent controls judge tool calls inside frameworks a customer already uses, and shadow-AI discovery rides the endpoint agent a security team already runs. Virtue published DecodingTrust openly and keeps publishing follow-on agent red-teaming work. Its about page lists a DecodingTrust-Agent Platform among that research rather than among the products it sells. The acquisition redrew the ecosystem boundary. Fortinet had already shipped FortiAIGate to guard large language models against prompt injections and data leakage, and it says the acquisition complements FortiAIGate and further strengthens its AI runtime security capabilities…

Virtue's platform reaches into a customer's stack rather than standing alone. Guards plug into applications, agents, gateways and retrieval pipelines, the agent controls judge tool calls inside frameworks a customer already uses, and shadow-AI discovery rides the endpoint agent a security team already runs.

Virtue published DecodingTrust openly and keeps publishing follow-on agent red-teaming work. Its about page lists a DecodingTrust-Agent Platform among that research rather than among the products it sells.

The acquisition redrew the ecosystem boundary. Fortinet had already shipped FortiAIGate to guard large language models against prompt injections and data leakage, and it says the acquisition complements FortiAIGate and further strengthens its AI runtime security capabilities.

Team & Execution Capability Bo Li is founder and chief executive, joined by Dawn Song as founder and board director, Sanmi Koyejo as founder and chief AI officer, and Carlos Guestrin as founder and chief scientist. SC Media reports that Bo Li launched the company in 2024 with the other three and teaches computer science at the University of Illinois Urbana-Champaign. The primary record is more specific than the company's summary of it. Virtue's site credits the founders with open-sourcing DecodingTrust and winning a NeurIPS best-paper award, while arXiv records the paper as a NeurIPS 2023 Outstanding Paper in the Datasets and Benchmarks Track with 19 authors, three of whom are Virtue founders. Carlos Guestrin is not among them. Recognition also reaches beyond the paper. SC Media named Bo Li its 2026 Innovator of the Year and reported that Fortune had listed Virtue AI among its Cyber 60 companies. The reviewed sources describe the founders' research record in detail and say little about the bench below them…

Bo Li is founder and chief executive, joined by Dawn Song as founder and board director, Sanmi Koyejo as founder and chief AI officer, and Carlos Guestrin as founder and chief scientist. SC Media reports that Bo Li launched the company in 2024 with the other three and teaches computer science at the University of Illinois Urbana-Champaign.

The primary record is more specific than the company's summary of it. Virtue's site credits the founders with open-sourcing DecodingTrust and winning a NeurIPS best-paper award, while arXiv records the paper as a NeurIPS 2023 Outstanding Paper in the Datasets and Benchmarks Track with 19 authors, three of whom are Virtue founders. Carlos Guestrin is not among them.

Recognition also reaches beyond the paper. SC Media named Bo Li its 2026 Innovator of the Year and reported that Fortune had listed Virtue AI among its Cyber 60 companies. The reviewed sources describe the founders' research record in detail and say little about the bench below them.

Sources

Company Detail Sources (5)
Id Source Tier Accessed
f1 SecurityWeek: Fortinet Acquires AI Security Company Virtue AI press 2026-08-29
f2 Fortinet: Fortinet Advances Continuous AI Protection with the Acquisition of Virtue AI official 2026-08-29
f3 SC Media: 2026 SC Award winner Bo Li, Innovator of the Year press 2026-08-29
f4 SecurityWeek: Virtue AI Attracts $30M Investment to Address Critical AI Deployment Risks press 2026-08-29
f5 AI Defense Matrix Catalog mapping other 2026-08-29
Profile Analysis Sources (11)
Id Source Tier Accessed
s1 Virtue AI: Enterprise AI Safety Platform home page official 2026-08-29
s2 Virtue AI: Platform Overview official 2026-08-29
s3 Virtue AI: About page with founder roster and research timeline official 2026-08-29
s4 Fortinet: Fortinet Advances Continuous AI Protection with the Acquisition of Virtue AI official 2026-08-29
s5 SecurityWeek: Fortinet Acquires AI Security Company Virtue AI press 2026-08-29
s6 SecurityWeek: Virtue AI Attracts $30M Investment to Address Critical AI Deployment Risks press 2026-08-29
s7 SC Media: 2026 SC Award winner Bo Li, Innovator of the Year press 2026-08-29
s8 Walden Catalyst: Why We Invested in Virtue AI press 2026-08-29
s9 arXiv: DecodingTrust abstract page with author list and venue note research 2026-08-29
s10 GovInfo: Federal Register notice, Request for Information Regarding Security Considerations for Artificial Intelligence Agents regulatory 2026-08-29
s11 Probe of trust.virtueai.com on 2026-08-29, agent-browser render plus direct fetch official 2026-08-29
Deep-Dive Sources (11)
Id Source Tier Accessed
s1 Virtue AI: Enterprise AI Safety Platform home page official 2026-08-29
s2 Virtue AI: Platform Overview official 2026-08-29
s3 Virtue AI: About page with founder roster and research timeline official 2026-08-29
s4 Fortinet: Fortinet Advances Continuous AI Protection with the Acquisition of Virtue AI official 2026-08-29
s5 SecurityWeek: Fortinet Acquires AI Security Company Virtue AI press 2026-08-29
s6 SecurityWeek: Virtue AI Attracts $30M Investment to Address Critical AI Deployment Risks press 2026-08-29
s7 SC Media: 2026 SC Award winner Bo Li, Innovator of the Year press 2026-08-29
s8 Walden Catalyst: Why We Invested in Virtue AI press 2026-08-29
s9 arXiv: DecodingTrust abstract page with author list and venue note research 2026-08-29
s10 GovInfo: Federal Register notice, Request for Information Regarding Security Considerations for Artificial Intelligence Agents regulatory 2026-08-29
s11 Probe of trust.virtueai.com on 2026-08-29, agent-browser render plus direct fetch official 2026-08-29

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.