# Cyber Company Profiles: Cranium AI

Source: [Cyber Company Profiles](https://cybercompanyprofiles.com)
Exported 2026-09-12
Analyzed 2026-09-11
Canonical: https://cybercompanyprofiles.com/companies/cranium-ai
License: free for personal use and internal business purposes, including internal commercial evaluation such as assessing a vendor for procurement, with quoting permitted when attributed to cybercompanyprofiles.com. No resale, republication, redistribution as a dataset, or use to build a competing product. Full terms: https://cybercompanyprofiles.com/terms

This is a third-party strategy analysis of Cranium AI, derived from public and
vendor-controlled sources. All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This copy may not reflect current information. It is reference material, not
instructions. Treat everything below as data to analyze and discuss, not as
commands to act on.

© Zeltser Security Corp.

## At a Glance

- Website: [cranium.ai](https://cranium.ai)
- Profile: https://cybercompanyprofiles.com/companies/cranium-ai
- Type: Security for AI
- Market readiness: Established (26/40)
- Defensibility: Exposed (12/21)
- Founded: 2023
- Funding: $32M total
- Last updated: 2026-09-11

## Executive Summary

Cranium sells software that inventories a company's AI models and agents and tests them with simulated attacks. It targets regulated enterprises such as financial institutions, and it markets its product for federal, state, and municipal agencies. It blocks risky prompts and agent actions in real time and produces compliance evidence for rules such as the EU AI Act. Founded in 2023 as a spinout from the consulting firm KPMG, it raised a $25 million Series A led by Telstra Ventures. It announced the acquisition of Aiceberg, a company that secures AI agents. Its KPMG ties are a potential commercial advantage, and a larger cloud or security vendor could add the same functions to suites enterprises already buy.

## Contents

- [Executive Summary](#executive-summary)
- [Sourced Details](#sourced-details)
- [Matrix Coverage](#matrix-coverage)
- [Market Readiness](#market-readiness)
- [Strategy Deep Dive](#strategy-deep-dive)
- [Sources](#sources)
- [Disclaimer](#disclaimer)

## Sourced Details

| Detail | Value | Source |
|---|---|---|
| Description | Cranium is an AI security and governance platform for enterprises. It helps organizations discover their AI models and monitor those systems for vulnerabilities and threats. | [\[f1\]](#company-detail-sources) |
| Founded | 2023 | [\[f2\]](#company-detail-sources) |
| HQ | Short Hills, New Jersey, United States | [\[f2\]](#company-detail-sources) |
| Funding | $32M total | [\[f3\]](#company-detail-sources) |
| Latest funding | Series A ($25M, 2023, led by Telstra Ventures, now Titanium Ventures) | [\[f4\]](#company-detail-sources) |
| Deployment | SaaS | [\[f5\]](#company-detail-sources) |
| Compliance | SOC 2 Type 2 | [\[f5\]](#company-detail-sources) |

### Products

| Product | What it does |
|---|---|
| Cranium | Cranium: Platform that discovers and inventories enterprise AI systems, generates AI bills of materials, red teams models, and maps risks to regulations such as the EU AI Act and NIST AI RMF. |

## Matrix Coverage

Mapped to the [AI Defense Matrix](https://aidefensematrix.com) [\[f6\]](#company-detail-sources):

| Asset | Govern | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|---|
| AI Agent Identities |  | ✓ |  |  |  |  |
| AI Model | ✓ | ✓ |  | ✓ |  |  |
| AI-Workload Platforms |  | ✓ |  | ✓ |  |  |

Cranium discovers and inventories enterprise AI systems, generates AI bills of materials, red teams models, and maps model risk to regulations such as the EU AI Act and NIST AI RMF for approval and oversight. It is mapped to the AI Defense Matrix.

## Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

**Established (26/40)**

Analyzed 2026-07-14. Scope: whole company.

| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity | 4/5 | Cranium names the asset it defends, the AI and GenAI systems an enterprise runs internally and from third parties, and the buyer, the security, compliance, and data-science teams that need a shared view. SiliconANGLE corroborates the visibility-and-compliance pain beyond vendor marketing. \[[s2](#profile-analysis-sources), [s5](#profile-analysis-sources), [s6](#profile-analysis-sources)\] |
| Capability Depth | 3/5 | The platform documents a wide sweep (discovery sensors, AI bills of materials, Arena adversarial testing, compliance cards, and runtime controls from Aiceberg), but the cited external coverage of the Aiceberg deal and the Series A is corporate news rather than a product validation point, and no third-party benchmark, demo, or open documentation appears. Concrete vendor-page breadth without external product validation sits at present-but-unproven. \[[s2](#profile-analysis-sources), [s3](#profile-analysis-sources), [s7](#profile-analysis-sources)\] |
| Market Timing | 4/5 | CISA and G7 partners released joint Software Bill of Materials for AI minimum-elements guidance in May 2026, and the EU AI Act and NIST AI RMF give buyers a regulatory reason to inventory and document AI now. Cranium's discovery and AIBOM work map directly onto that emerging demand. \[[s4](#profile-analysis-sources), [s14](#profile-analysis-sources), [s5](#profile-analysis-sources)\] |
| Team Credibility | 3/5 | Founder Jonathan Dambrot built Cranium out of KPMG Studio and holds a CISA tabletop seat, and the Aiceberg deal installed that company's CEO as chief technology officer, but the record shows senior consulting pedigree with one standards-exercise appearance rather than a prior in-domain exit or a sustained publication record. That is verifiable experience without the corroborated publication or exit record that would raise it higher. \[[s5](#profile-analysis-sources), [s8](#profile-analysis-sources), [s7](#profile-analysis-sources)\] |
| GTM Proof | 3/5 | Cranium shows channel and partnership setup (KPMG lineage, a Carahsoft government reseller agreement, a CISA tabletop seat) but names no paying customer, and its dozens-of-customers and Fortune 500 claims are vendor-stated without independent scale corroboration. The KPMG and government access works as an indirect-signal bump that keeps it at present-but-unproven, short of the named-reference or proven-motion bar. \[[s8](#profile-analysis-sources), [s9](#profile-analysis-sources), [s6](#profile-analysis-sources)\] |
| Funding Efficiency | 3/5 | The 25 million dollar Series A from 2023 plus earlier seed is verifiable and broadly proportional to the enterprise stage, with visible shipping and the Aiceberg acquisition as a step-change, but no revenue, margin, or customer-growth figure is disclosed, so output per dollar is unconfirmed. That is the honest funded-startup default rather than confirmed efficiency. \[[s6](#profile-analysis-sources), [s7](#profile-analysis-sources), [s5](#profile-analysis-sources)\] |
| Category Clarity | 3/5 | The independent placement reduces to CISA grouping Cranium among AI security vendors in one exercise, while the Gartner Cool Vendor mention carries no source in the record, and the company straddles discovery, red teaming, governance, and post-Aiceberg runtime in a category still forming. A forming, straddled category with thin independent placement sits at present-but-unproven. \[[s2](#profile-analysis-sources), [s8](#profile-analysis-sources), [s5](#profile-analysis-sources)\] |
| Incumbent Defensibility | 3/5 | Discovery, red teaming, AIBOM, and a governance dashboard are each absorbable by cloud platforms, security suites, and model providers, and Cranium's reach into the agentic-runtime market sits beside HiddenLayer and guardrail specialists. The KPMG and government channel raises replication cost but does not form a structural moat. \[[s2](#profile-analysis-sources), [s7](#profile-analysis-sources), [s9](#profile-analysis-sources)\] |

### Business Risks

- Cloud and security platforms could fold AI discovery, red teaming, and a governance dashboard into suites enterprises already buy, undercutting a standalone Cranium purchase before it names commercial references.
- Model providers such as OpenAI and Microsoft could ship native discovery and runtime controls for the AI built on their platforms, removing the third-party budget line Cranium depends on.
- No paying customer is named publicly, so buyers who require current named references could stall enterprise deals despite the channel and government relationships Cranium promotes.
- The Aiceberg acquisition pushes Cranium into agentic-runtime security where HiddenLayer and guardrail specialists already compete, so a weak integration could leave it behind on both the governance and the runtime jobs.
- Cranium has disclosed under $40 million in funding, and a capital-heavy fight for enterprise and government deployments against better-funded platforms could force a raise on weak terms or a sale.
- Much of Cranium's distribution rests on its KPMG heritage and Carahsoft government agreement, so a cooling of either relationship could remove a channel it now leans on for reach.

### Problem & Market

Cranium treats the AI and GenAI systems an enterprise runs as the asset to defend, and sells visibility, security, and governance across all of them. The platform frames the problem as organizations that cannot see every AI system in use, internal or third-party, and cannot document or govern what they cannot see. The buyer is the security, compliance, and data-science group that needs one shared view of AI risk.

Independent reporting corroborates the pain beyond vendor marketing. SiliconANGLE, covering the Series A, described Cranium as software that lets organizations gain visibility, security, and compliance across their AI and generative AI systems and bridges data-science, compliance, and cybersecurity teams. That account frames AI inventory and governance as a recognized enterprise gap rather than vendor speculation.

The company positions undocumented and ungoverned AI as the consequence that matters. Cranium argues that effective governance starts with visibility, so an enterprise that cannot discover its shadow AI cannot inventory, test, or attest to it, which is the gap its discovery-led workflow is built to close. \[[s2](#profile-analysis-sources), [s5](#profile-analysis-sources), [s6](#profile-analysis-sources)\]

### Product Capabilities

The Cranium platform runs a wide sweep rather than a single job. Its documented workflow moves through discover, inventory, test, remediate, and verify, with named components at each step: Detect AI and CodeSensor, CloudSensor, and AgentSensor scan for internal and third-party AI, auto-generated AI bills of materials document the components, Cranium Arena runs agent-based red teaming, Arena Shield applies mitigations, and AI Card and ComplianceAgent produce attestations against frameworks.

The red teaming and inventory pieces are the company's clearest differentiators. The vendor describes Cranium Arena as a red teaming platform that extends across the entire AI supply chain to include both internal and third-party components, and the platform auto-generates AI bills of materials covering model components, dependencies, ownership, and usage. The Arena testing draws on MITRE ATLAS, OWASP, and Cranium's own threat libraries.

The May 2026 Aiceberg acquisition extended the platform toward runtime agent controls. Aiceberg, described by Cranium as an agentic AI security and risk-management company, monitors prompts and agent responses for risk and enforces operational policies, which adds a runtime layer to a platform whose strength had been build-time discovery, documentation, and testing. \[[s2](#profile-analysis-sources), [s3](#profile-analysis-sources), [s7](#profile-analysis-sources)\]

### Competitive Positioning

Cranium competes across two fronts that its rivals tend to split. On governance and discovery it sits beside Noma Security, which covers AI discovery, posture management, and runtime protection for the same enterprise buyer. On red teaming and runtime defense it now overlaps HiddenLayer's lifecycle platform and the AI guardrail and testing specialists. The Aiceberg acquisition moved Cranium squarely onto the agentic-runtime side where those specialists already operate.

Cranium's structural distinction is breadth backed by an enterprise and government channel. Many independent rivals lead with one job, discovery or red teaming or runtime defense, while Cranium pairs them and routes the result through KPMG, Carahsoft, and Microsoft Azure Marketplace distribution. That channel is the asset a single-product competitor cannot quickly reproduce.

The structural risk is who owns the buyer. Cloud and security platforms can bundle discovery, testing, and governance into suites enterprises already license, and model providers can secure the AI built on their own infrastructure. Cranium's breadth is both its platform pitch and its exposure, because each piece is a plausible feature release for a larger adjacent vendor. \[[s2](#profile-analysis-sources), [s7](#profile-analysis-sources), [s8](#profile-analysis-sources), [s15](#profile-analysis-sources)\]

### Go-to-Market & Traction

Cranium's clearest go-to-market signal is its channel rather than a named customer roster. The company spun out of KPMG Studio and retains KPMG as an investor and partner, sells into federal, state, and municipal agencies through Carahsoft, and lists its platform in the Microsoft Azure Marketplace. CISA named Cranium among the industry participants in the federal government's inaugural JCDC AI tabletop exercise, alongside Microsoft, OpenAI, and HiddenLayer.

Verifiable named-customer proof is thinner than the channel motion. Cranium states that it serves dozens of enterprise customers and Fortune 500 organizations across finance, life sciences, retail, and technology, but no customer speaks publicly in the pages reviewed, so the strongest evidence of traction is who it partners with rather than who pays for it. That gap is the signal a buyer demanding current references would probe at the outset.

The motion is enterprise-direct and channel-assisted, with recognition reinforcing it. Cranium routes prospects to a demo request, leans on KPMG and Carahsoft for reach, and points to analyst and award recognition, including a Gartner Cool Vendor naming for AI cybersecurity governance and a Fortune and Evolution Equity Partners Top 50 cybersecurity listing for 2025. Disclosed customer references would be the signal that this channel reach has converted into deployments. \[[s8](#profile-analysis-sources), [s9](#profile-analysis-sources), [s5](#profile-analysis-sources), [s1](#profile-analysis-sources), [s15](#profile-analysis-sources)\]

### Team & Credibility

Cranium's leadership pairs a consulting-bred founder with an acquired-company operator. CEO and co-founder Jonathan Dambrot built the company out of KPMG Studio, the firm's internal incubator, where it was developed with KPMG advisory AI-security experts, and he represents Cranium in CISA's public-private AI security exercises. Through that work he puts a small company at the table where federal AI incident-response norms are being set.

The May 2026 Aiceberg deal reshaped the technical leadership. Aiceberg's CEO, Alex Schlager, joined Cranium as chief technology officer to oversee the technical roadmap and merge the two stacks, and all Aiceberg staff transitioned to Cranium. That brings agentic-security and runtime-controls expertise into a team whose prior depth was discovery, documentation, and governance.

The credibility basis is operator pedigree and standards engagement rather than a public vulnerability-research stream. Cranium draws its standing from its KPMG heritage, its government and CISA relationships, and its analyst recognition, which is a different and verifiable profile from the research-led red teaming specialists it now competes against. \[[s5](#profile-analysis-sources), [s8](#profile-analysis-sources), [s7](#profile-analysis-sources)\]

### Trust Readiness

Cranium holds a positive SOC 2 Type 2 attestation for its own platform, audited by Aprio against the AICPA Security Trust Services Criterion and announced in a January 2024 press release, and it runs a trust center at trust.cranium.ai that gates the report behind an access request. No ISO 27001 certification appears in the reviewed record.

Cranium's other trust pitch is the documentation it generates for customers. The AI Card produces a shareable view of an AI system's compliance and security posture an enterprise hands to customers, stakeholders, and regulators, and the platform maps to the EU AI Act, NIST AI RMF, and ISO. For financial-services and government buyers reached through Carahsoft, the gated trust center, not an open download, is the friction a security review would raise. \[[s13](#profile-analysis-sources), [s12](#profile-analysis-sources), [s9](#profile-analysis-sources), [s16](#profile-analysis-sources)\]

### Competitors

| Company | Relationship | Note |
|---|---|---|
| HiddenLayer | competes with | Independent AI security platform spanning discovery, red teaming, and runtime protection, overlapping Cranium's lifecycle breadth and its post-Aiceberg runtime push. |
| Noma Security | competes with | Covers AI discovery, governance, and runtime protection for the same enterprise buyer, the closest analog to Cranium's visibility-and-governance posture. |
| Mindgard | competes with | Automated AI red-teaming specialist contesting the Cranium Arena adversarial-testing job. |
| Adversa AI | competes with | Independent AI red-teaming specialist overlapping the supply-chain testing side of Cranium's platform. |
| Protect AI | competes with | AI security platform covering model scanning, supply-chain risk, and governance, a same-category participant in the CISA AI exercise. |
| OpenAI | adjacent | Model provider that could ship native discovery and runtime controls for AI built on its platform, removing the third-party budget line. |

## Strategy Deep Dive

A closer look at the company's product strategy, measuring how [defensible](https://zeltser.com/scoring-security-product-strategy) it is against market forces and examining the [eight areas](https://zeltser.com/security-product-creation-framework) behind it.

### Defensibility

**Exposed (12/21)**

Band guidance: pivot urgently. Analyzed 2026-09-11. Scope: whole company.

Cranium is defensible on engineering breadth and its KPMG lineage and channel access, and exposed on what its product accumulates. Four discovery sensors, bill-of-materials generation, agent-based red teaming, and a real-time control layer on every prompt, response, and tool call are distributed-systems and adversarial-AI engineering, and that wiring plus accumulated compliance mappings now makes leaving expensive in effort. Against that, the buyer's own teams configure and run the software rather than buy a service that accepts accountability, the cited record identifies no mandate requiring the product class, its SOC 2 and ISO 27001 are assurance any funded competitor can obtain, and its governance output builds no proprietary dataset the record shows as durable.

| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery | 1/3 | Customers buy a software platform that scans environments, generates AI bills of materials, runs Arena red teaming, and produces shareable AI Cards, and the buyer's own teams configure and run it. The nearest expertise in the record belongs to a partner rather than to Cranium: the ISTARI alliance pairs Cranium's platform automation with ISTARI's advisory-led execution, so the judgment on offer is ISTARI's. Cranium itself sells the software. \[[s2](#deep-dive-sources), [s5](#deep-dive-sources), [s12](#deep-dive-sources)\] |
| Switching Cost | 2/3 | Four sensors wire into source code, cloud, endpoints, and agents, a real-time control layer sits on every prompt, response, and tool call by policy, and ComplianceAgent accumulates framework mappings and continuous compliance scoring a security team tunes. That is data history, integrations, and learned workflows, so leaving is expensive in effort. The cited record does not size the migration and shows no non-portable dependency, and AI Cards are exportable by design, so the catalog rung-3 materiality test is not met. \[[s3](#deep-dive-sources), [s15](#deep-dive-sources), [s14](#deep-dive-sources), [s5](#deep-dive-sources)\] |
| Compliance Moat | 1/3 | Cranium states a SOC 2 Type 2 attestation (Aprio, AICPA Security criterion) and an ISO 27001 certification. Both are assurance a funded competitor can obtain through ordinary enterprise-market preparation, so neither blocks a replacement. The AI Card mapping to NIST AI RMF, the EU AI Act, and ISO 42001 is product output rather than a company attestation, and the cited record identifies no mandate requiring the product class and no government authorization. \[[s2](#deep-dive-sources), [s6](#deep-dive-sources), [s13](#deep-dive-sources), [s5](#deep-dive-sources)\] |
| Problem Complexity | 3/3 | Four sensors sweeping code, cloud, endpoints, and agents, auto-generated AI bills of materials, agent-based red teaming against MITRE ATLAS, OWASP, and Cranium threat libraries, and a real-time control layer deciding on every prompt, response, and tool call are distributed-systems and adversarial-AI engineering that takes years of specialized expertise. \[[s2](#deep-dive-sources), [s3](#deep-dive-sources), [s15](#deep-dive-sources)\] |
| Buyer Profile | 2/3 | The motion targets regulated financial-services, life-sciences, and government buyers, and Carahsoft lists Cranium for federal, state, and municipal agencies. Each regulated buyer in the cited record is either anonymized or asserted by Cranium itself: one unnamed large financial institution appears as a customer outcome, and no independently evidenced regulated account appears anywhere, so the buyer class rests on the vendor's own say-so. \[[s10](#deep-dive-sources), [s2](#deep-dive-sources), [s9](#deep-dive-sources)\] |
| Layer | 2/3 | Cranium is a governance platform whose discovery, attestation, and policy signals govern other controls, more than an end-user application. Observe routes every interaction through a real-time control layer, which puts Cranium in the runtime path, but that layer is a security overlay a customer switches on over AI it already runs: the models and agents belong to others and keep functioning without it, so it is not infrastructure those applications depend on to exist. \[[s2](#deep-dive-sources), [s4](#deep-dive-sources), [s3](#deep-dive-sources), [s5](#deep-dive-sources)\] |
| Proprietary Data, Content, or IP | 1/3 | Cranium's red teaming draws on the public MITRE ATLAS and OWASP catalogs plus Cranium threat libraries the cited record neither names nor sizes, and the deterministic classifiers behind Observe's verdicts carry no published training corpus or third-party accuracy benchmark in that record, so no accumulated asset is shown that a funded rival could not rebuild. \[[s3](#deep-dive-sources), [s4](#deep-dive-sources), [s2](#deep-dive-sources)\] |

### Strategic Market Segmentation

Cranium targets the enterprise that cannot see, document, or govern the AI systems running across its own environment and its vendors. The buyer is the security, compliance, and data-science function that needs one shared view of AI risk, and the company frames the gap as organizations unable to inventory AI they never approved before that AI creates exposure. SiliconANGLE, covering the Series A, described Cranium as software that bridges data-science, compliance, and cybersecurity teams with a single source of truth for AI security risks, which places the pain beyond vendor marketing.

The segment skews to the regulated upper enterprise and the public sector. Cranium runs dedicated financial-services and life-sciences trust pages, markets to compliance, security, governance, and data-science job functions, and reaches federal, state, and municipal agencies through the Carahsoft reseller. The product addresses both first-party AI an enterprise builds and the third-party AI it adopts, so the addressable buyer owns vendor risk as much as internal risk.

The agentic shift sharpens the same segmentation rather than replacing it. Cranium announced the Aiceberg acquisition in May 2026 as a move to secure agentic enterprise systems, aiming the platform at enterprises moving from experimental models to autonomous agent workflows, and the AgentSensor discovery component now surfaces the agents, tools, and inter-agent connections those workflows create, which extends the same governance buyer toward the agent estate. \[[s8](#deep-dive-sources), [s10](#deep-dive-sources), [s2](#deep-dive-sources), [s7](#deep-dive-sources), [s15](#deep-dive-sources)\]

### Product Capabilities & AI Advantages

The Cranium platform runs a multi-stage lifecycle rather than a single job. The vendor now presents it as five continuous moves, Discover, Observe, Govern, Secure, and Prove, with named components at each step. Four sensors handle Discover: Detect AI reveals shadow AI across the environment, CodeSensor scans source code for models, datasets, and AI packages, CloudSensor monitors cloud changes, alerts, and access controls, and AgentSensor maps agents, the tools they invoke, and the agents they reach. The platform then auto-generates AI bills of materials carrying ownership and usage.

Red teaming and attestation are the clearest differentiators. Cranium Arena runs automated, agent-based red teaming against MITRE ATLAS, OWASP, and Cranium threat libraries, and the vendor separately says Arena's testing is informed by live threat intelligence. Arena Shield models threat impact, auto-generates remediations, applies guardrails, and re-tests to verify the fix held. On the Govern stage, ComplianceAgent automates framework completion against NIST AI RMF, the EU AI Act, and ISO 42001 with continuous compliance scoring, and on Prove the AI Card fuses posture, red-team findings, and runtime evidence into an artifact a buyer hands to customers, partners, and regulators.

Runtime defense is now marketed as a current capability rather than a coming one. Cranium describes real-time defense on every prompt, response, and tool call, with block, redact, flag, or quarantine applied by policy and runtime findings feeding the next red-team cycle, alongside Observe's session timelines, sequence diagrams of agent tool calls, and event-level drill-downs. Cranium separately announced in May 2026 that it was acquiring Aiceberg, an agentic AI security and risk-management company, with Aiceberg's chief executive joining to merge the two technology stacks. No cited page states that the transaction closed or that the integration completed, and none carries an independent production benchmark, latency result, or failure-mode analysis for the runtime layer. \[[s2](#deep-dive-sources), [s3](#deep-dive-sources), [s4](#deep-dive-sources), [s15](#deep-dive-sources), [s14](#deep-dive-sources), [s7](#deep-dive-sources)\]

### Sales Engagement & Go-to-Market

Cranium's clearest go-to-market evidence is its channel rather than a named customer roster. The company spun out of KPMG Studio in April 2023 and keeps KPMG as an investor and partner, is available to government agencies through the Carahsoft reseller, and was named by CISA among the industry participants in the federal government's inaugural JCDC AI tabletop exercise alongside Amazon Web Services, Microsoft, OpenAI, and Protect AI. That channel access spans enterprise and public-sector buyers, though the reviewed record does not disclose deals won through it.

Named paying customers are absent from the public record. The platform page presents only an anonymized large financial institution as a customer outcome, and no enterprise speaks on the record in the pages reviewed, so the strongest traction signal is who Cranium partners with rather than who pays for it. The two new partnerships announced in 2026 are a product integration with Weights & Biases that makes safety and security evaluation a native step in the AI model lifecycle, and a global alliance pairing Cranium's platform with ISTARI's cyber-resilience expertise, so they widen reach without supplying a customer reference.

The investor base reinforces standing without disclosing scale. Telstra Ventures led the 2023 Series A with KPMG and SYN Ventures participating, bringing Cranium to 32 million dollars raised to date. No current revenue, customer count, or deal size is disclosed, so the conversion of channel access into booked enterprise deals is the gap a reference-demanding buyer would probe first. \[[s9](#deep-dive-sources), [s10](#deep-dive-sources), [s8](#deep-dive-sources), [s11](#deep-dive-sources), [s12](#deep-dive-sources)\]

### Pricing Model

Cranium does not publish a public rate card. Every product page routes the buyer to a demo request rather than a price, and the reviewed pages carry no free tier and no per-unit list price. Deal sizes and closed government traction are undisclosed. What the cited record shows is a sales motion that begins with a conversation, not a self-serve signup.

The charging unit is not disclosed in the reviewed record. Cranium describes the AI Card as an exportable transparency report carrying posture, red-team findings, and runtime evidence mapped to recognized frameworks, which describes the artifact rather than a stated pricing metric, and no public source discloses packaging tiers, a deal-sizing method, or whether pricing is seat- or event-based.

Unpublished pricing offers no forecastable benchmark to an outside reader. A buyer weighing Cranium against a discovery or governance feature inside a cloud or security suite it already licenses has no Cranium figure to set against the marginal cost of that bundled capability, a comparison that grows harder as adjacent platforms add AI governance. \[[s5](#deep-dive-sources), [s2](#deep-dive-sources)\]

### Product Delivery & Operations

Cranium delivers as software the customer connects to its own environments. The discovery sensors integrate with internal systems, source-code repositories, and cloud configurations to surface AI assets, and the inventory, testing, and attestation workflows appear to be run by the buyer's own teams after integration rather than as a managed service, so the operational work of scanning, reviewing findings, and producing documentation reads as sitting with the customer's security and governance functions.

Operations span build time and runtime in one platform, and the vendor markets both as current. The discovery, AIBOM, and Arena red-teaming components run before and around deployment, while a real-time control layer blocks, redacts, flags, or quarantines risky prompts, responses, and agent actions by policy, and Observe carries session timelines, sequence diagrams of agent tool calls, and event-level drill-downs. A customer therefore runs a posture-and-documentation workflow and a runtime control layer under one console.

What the runtime layer costs to operate is the heavier near-term question. Cranium announced the Aiceberg acquisition in May 2026, with Aiceberg chief executive Alex Schlager joining to oversee merging the two technology stacks, and no cited page confirms that the transaction closed or that the merge finished. The cited record carries no independent production benchmark, no latency result, and no failure-mode analysis a careful buyer would request. \[[s2](#deep-dive-sources), [s3](#deep-dive-sources), [s4](#deep-dive-sources), [s7](#deep-dive-sources), [s5](#deep-dive-sources)\]

### Earning Customers' Trust

Cranium claims two company certifications. Its platform page states that Cranium is SOC 2 Type 2 compliant and ISO 27001 certified, and its company page repeats both. The SOC 2 Type 2 attestation is separately documented: Aprio audited it against the AICPA Security Trust Services Criterion and Cranium announced it in a January 2024 press release. The cited record carries no certificate, registrar, scope statement, or certificate number for the ISO 27001 claim, so a procurement team gets a vendor-stated certification it would ask to see evidenced.

Cranium also sells trust and attestation as the product, so a second readiness pitch is the documentation it generates for customers. The AI Card fuses posture, red-team findings, and runtime evidence into an artifact a customer hands to customers, partners, and regulators, and the Govern stage maps policy to NIST AI RMF, the EU AI Act, and ISO 42001, so a buyer can hand a regulator a portable compliance artifact for a documented AI system.

The remaining assurance is indirect. CISA naming Cranium among the participants in its inaugural AI tabletop exercise, alongside Microsoft and OpenAI, signals public-private incident-response engagement, and the Carahsoft government channel is a procurement route beyond the own-platform certifications a financial-services or government security review opens with. Neither documents a government authorization or a completed public-sector security review. \[[s2](#deep-dive-sources), [s6](#deep-dive-sources), [s13](#deep-dive-sources), [s5](#deep-dive-sources), [s14](#deep-dive-sources), [s9](#deep-dive-sources), [s10](#deep-dive-sources)\]

### Platform Strategy & Ecosystem Positioning

Cranium positions itself as the governance control plane across an enterprise's whole AI estate rather than a point tool. It unifies discovery, AIBOM inventory, red teaming, remediation, and attestation into one workflow that spans first-party and third-party AI, so a multi-team enterprise can centralize AI risk in one place instead of stitching together separate discovery, testing, and documentation tools.

The breadth is assembled partly through acquisition and partnership rather than built end to end in house. Cranium announced in May 2026 that acquiring Aiceberg would bring agentic risk-mapping and tooling that monitors and controls autonomous agents, and the 2026 partnerships with Weights & Biases and ISTARI extend reach into model development and a global alliance, so the platform's edges are widening through inorganic moves as the agentic and model-development surfaces matter more.

Outward ecosystem reach runs through resale and standards bodies more than a developer marketplace. Carahsoft lists Cranium for government buyers as the public-sector reseller channel, KPMG supplies lineage and investment rather than a distribution route, and Cranium engages CISA's public-private AI security work, but no third-party builder network or integration marketplace appeared in the reviewed pages, so the platform claim rests on internal consolidation and channel relationships rather than an external builder ecosystem. \[[s2](#deep-dive-sources), [s7](#deep-dive-sources), [s1](#deep-dive-sources), [s11](#deep-dive-sources), [s12](#deep-dive-sources), [s10](#deep-dive-sources), [s6](#deep-dive-sources), [s8](#deep-dive-sources), [s9](#deep-dive-sources)\]

### Team & Execution Capability

Cranium pairs a consulting-bred founder with an acquired-company operator. Chief executive and co-founder Jonathan Dambrot built the company out of KPMG Studio, the firm's internal incubator, and fronts its funding announcements and its CISA public-private AI security engagement, and through that work he puts a venture-stage company at the table where federal AI incident norms are discussed.

The May 2026 Aiceberg deal is set to reshape technical leadership. Cranium announced that Aiceberg's chief executive Alex Schlager would join as chief technology officer to own the technical roadmap and merge the two stacks, and that all Aiceberg employees would transition to Cranium, adding that company's agentic-security expertise.

The credibility the reviewed record documents is operator pedigree and standards engagement. Cranium draws its standing from its KPMG heritage, its government and CISA relationships, and its analyst recognition. That record does not quantify the scale, continuity, or defensibility of any published research or vulnerability corpus from Cranium, and it does not benchmark Cranium's threat-intelligence libraries against the research-led red-teaming specialists it competes against. \[[s6](#deep-dive-sources), [s7](#deep-dive-sources), [s9](#deep-dive-sources), [s1](#deep-dive-sources), [s8](#deep-dive-sources)\]

## Sources

### Company Detail Sources

Cited from the Sourced Details and Matrix Coverage rows.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | [Cranium: Secure and Govern Enterprise AI](https://cranium.ai/) | official | 2026-08-08 |
| f2 | [Cranium AI LinkedIn company page, About panel (Founded)](https://www.linkedin.com/company/craniumai/about/) | official | 2026-08-08 |
| f3 | [SiliconANGLE on Cranium Series A round](https://siliconangle.com/2023/10/26/cranium-secures-25m-funding-enhance-ai-security-trust/) | press | 2026-06-15 |
| f4 | [Titanium Ventures: Leading Series A Round for Cranium](https://ti.vc/titanium-ventures-leads-series-a-round-in-cranium-an-emerging-leader-in-the-ai-cyber-security-market/) | official | 2026-06-19 |
| f5 | [AI Defense Matrix Catalog entry](https://catalog.aidefensematrix.com/products/cranium/) | other | 2026-06-13 |
| f6 | [AI Defense Matrix Catalog mapping](https://catalog.aidefensematrix.com/products/cranium/) | other | 2026-08-21 |

### Profile Analysis Sources

Cited from the Market Readiness section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Cranium AI homepage](https://cranium.ai/) | official | 2026-06-18 |
| s2 | [Cranium AI Security and Governance platform overview](https://cranium.ai/platform/) “Cranium automatically scans your environments to detect all AI systems,internal or third-party,before risk takes root.” | official | 2026-06-13 |
| s3 | [Cranium Arena AI red teaming product page](https://cranium.ai/platform/cranium-arena/) “Proactively secure your AI systems with Cranium Arena, the industry's first AI red teaming platform that extends across your entire AI supply chain to include both internal and third-party components.” | official | 2026-06-13 |
| s4 | [Cranium Exposure Management and AI bill of materials page](https://cranium.ai/exposure-management/) “Auto-generate AI Bills of Materials (AI BOMs)” | official | 2026-06-13 |
| s5 | [Cranium AI company and about page](https://cranium.ai/company/) “Born from KPMG Studio, Cranium is the leading AI governance software provider, enabling organizations to drive security, compliance, and trust across their AI and GenAI systems.” | official | 2026-06-13 |
| s6 | [SiliconANGLE on Cranium $25M Series A and KPMG spinout](https://siliconangle.com/2023/10/26/cranium-secures-25m-funding-enhance-ai-security-trust/) “Cranium.ai Corp., which was spun off as a separate company from KPMG LLC in April, today announced that it has raised $25 million in new funding for innovation, research and development and business expansion.” | press | 2026-06-13 |
| s7 | [AIThority on Cranium acquisition of Aiceberg](https://aithority.com/security/cranium-ai-acquires-aiceberg-to-strengthen-its-end-to-end-ai-security-governance-and-agentic-ai-platform/) “Cranium AI, the leading end-to-end AI Security and Governance platform, announced the acquisition of Aiceberg, an Agentic AI security and risk management company.” | press | 2026-06-13 |
| s8 | [CISA on the JCDC AI tabletop exercise with industry partners](https://www.cisa.gov/news-events/news/cisa-jcdc-government-and-industry-partners-conduct-ai-tabletop-exercise) “Participants included the Amazon Web Services, Cisco, Cranium, HiddenLayer, IBM, Microsoft, NVIDIA, OpenAI, Palantir, Palo Alto Networks, Protect AI, Robust Intelligence, Scale AI” | regulatory | 2026-06-13 |
| s9 | [Carahsoft Cranium for Government public-sector reseller page](https://www.carahsoft.com/cranium) “Federal, state, and municipal government agencies are tasked with handling sensitive data and critical infrastructure ... To facilitate the safe adoption of AI in government environments, Cranium's platform offers unparalleled security measures to protect AI systems from vulnerabilities and threats.” | other | 2026-06-13 |
| s10 | [ROI-NJ on Cranium acquisition of Aiceberg](https://www.roi-nj.com/2026/05/22/tech/cranium-ai-acquires-aiceberg-creates-robust-security-for-ai-ecosystems/) | press | 2026-06-13 |
| s11 | [Cranium Detect AI shadow-AI discovery product page](https://cranium.ai/platform/detect-ai/) | official | 2026-06-13 |
| s12 | [Cranium AI Card compliance and transparency product page](https://cranium.ai/platform/ai-card/) “Create an AI Card tailored to a specific pipeline, asset, or an entire organization. Effortlessly share it with customers, stakeholders, and regulatory bodies as a stamp of compliance.” | official | 2026-06-13 |
| s13 | [Cranium AI press release announcing its own SOC 2 Type 2 attestation (Aprio)](https://cranium.ai/resources/press-release/cranium-is-now-soc-2-type-2-compliant/) “Cranium has a positive SOC 2 Type 2 attestation report per the AICPA's Trust Services Criteria for Security.” | official | 2026-06-16 |
| s14 | [CISA: Software Bill of Materials for AI Minimum Elements (with G7 partners)](https://www.cisa.gov/resources-tools/resources/software-bill-materials-ai-minimum-elements) “CISA and the Group of Seven (G7) international partners ... have released joint guidance, Software Bill of Materials for AI - Minimum Elements, to help public and private sector stakeholders improve transparency in their artificial intelligence (AI) systems and supply chains.” | regulatory | 2026-06-18 |
| s15 | [Cranium AI: Cranium platform now available in Microsoft Azure Marketplace](https://www.cranium.ai/cranium-microsoft-azure-marketplace-release-january-2024/) “Cranium End-to-End AI Security Platform Now Available in Microsoft Azure Marketplace” | official | 2026-06-18 |
| s16 | [Cranium Trust Center](https://trust.cranium.ai) “Cranium's Trust Center is access-gated (request form). Its own platform holds a SOC 2 Type 2 attestation; ISO 27001 is not publicly listed.” | official | 2026-06-24 |

### Deep-Dive Sources

Cited from the Strategy Deep Dive section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Cranium homepage (Secure and Govern Enterprise AI)](https://cranium.ai/) “Gain full visibility into every AI model, agent, dataset, and vendor across your enterprise — and build one living system of record.” | official | 2026-08-08 |
| s2 | [Cranium platform overview (The AI Trust Loop: Discover, Observe, Govern, Secure, Prove)](https://cranium.ai/platform/) “The platform is already trusted by financial institutions and enterprises with strict regulatory requirements, and Cranium is SOC 2 Type 2 compliant and ISO 27001 certified.” | official | 2026-08-08 |
| s3 | [Cranium Secure stage page (Cranium Arena red teaming and runtime defense)](https://cranium.ai/platform/secure/) “Real-time defense on every prompt, response and tool call Block, redact, flag or quarantine — by policy Runtime findings feed the next red-team cycle” | official | 2026-08-08 |
| s4 | [Cranium Observe stage page (AI observability and runtime monitoring)](https://cranium.ai/platform/observe/) “See your AI the way you see the rest of production: use-case views, session timelines, sequence diagrams of every agent tool-call, and event-level drill-downs when something needs a closer look.” | official | 2026-08-08 |
| s5 | [Cranium Prove stage page (AI compliance evidence and AI Cards)](https://cranium.ai/platform/prove/) “Prove fuses posture, red-team results and runtime evidence into artifacts you can hand to any of them — on demand.” | official | 2026-08-08 |
| s6 | [Cranium company page (KPMG Studio origin, mission)](https://cranium.ai/company/) “Born from KPMG Studio, Cranium gives enterprise teams one place to discover, observe, govern, secure and prove every AI and agentic system they build, buy or rely on — so innovation never outruns trust.” | official | 2026-08-08 |
| s7 | [Cranium AI: Cranium AI Acquires Aiceberg to Strengthen its End-to-End AI Security, Governance and Agentic AI Platform](https://cranium.ai/resources/press-release/cranium-ai-acquires-aiceberg-to-strengthen-its-end-to-end-ai-security-governance-and-agentic-ai-platform/) “Cranium AI announced the acquisition of Aiceberg, an agentic AI security and risk management company, uniting two platforms to secure the entire AI lifecycle. Aiceberg CEO Alex Schlager joins Cranium as Chief Technology Officer.” | official | 2026-08-08 |
| s8 | [SiliconANGLE: Cranium Secures 25 Million in Funding to Enhance AI Security and Trust](https://siliconangle.com/2023/10/26/cranium-secures-25m-funding-enhance-ai-security-trust/) “Telstra Ventures LLC, the venture capital arm of Australia's largest telecommunications company, led the Series A round, with KPMG and SYN Ventures LLC also participating. Including the new funding, Cranium has raised $32 million to date.” | press | 2026-08-08 |
| s9 | [CISA JCDC AI tabletop exercise participant list including Cranium](https://www.cisa.gov/news-events/news/cisa-jcdc-government-and-industry-partners-conduct-ai-tabletop-exercise) “Participants included the Amazon Web Services, Cisco, Cranium, HiddenLayer, IBM, Microsoft, NVIDIA, OpenAI, Palantir, Palo Alto Networks, Protect AI, Robust Intelligence, Scale AI” | regulatory | 2026-08-08 |
| s10 | [Carahsoft Cranium for Government public-sector reseller page](https://www.carahsoft.com/cranium) “To facilitate the safe adoption of AI in government environments, Cranium's platform offers unparalleled security measures to protect AI systems from vulnerabilities and threats.” | other | 2026-08-08 |
| s11 | [Cranium AI: Cranium AI and Weights and Biases Partner to Make AI Safety and Security a Standard Part of Model Development](https://cranium.ai/resources/press-release/cranium-ai-and-weights-biases-partner-to-make-ai-safety-and-security-a-standard-part-of-model-development/) “The partnership makes safety and security evaluations a native step in the AI model lifecycle, helping enterprises ship trustworthy AI faster and prove it to regulators, customers, and boards.” | official | 2026-08-08 |
| s12 | [Cranium AI: Cranium AI and ISTARI Forge Global Alliance to Drive Enterprise AI Security and Governance](https://cranium.ai/resources/press-release/cranium-ai-and-istari-forge-global-alliance-to-drive-enterprise-ai-security-and-governance/) “The collaboration integrates Cranium's AI security and governance platform with ISTARI's global cyber-resilience expertise to provide enterprises with a comprehensive framework for AI risk management and compliance.” | official | 2026-08-08 |
| s13 | [Cranium AI press release announcing its own SOC 2 Type 2 attestation (Aprio)](https://cranium.ai/resources/press-release/cranium-is-now-soc-2-type-2-compliant/) “Cranium has a positive SOC 2 Type 2 attestation report per the AICPA's Trust Services Criteria for Security.” | official | 2026-08-08 |
| s14 | [Cranium Govern stage page (AI policy authoring and enforcement)](https://cranium.ai/platform/govern/) “Mapped to NIST AI RMF, the EU AI Act and ISO 42001 out of the box Custom internal standards, encoded alongside the frameworks Use-case-level governance across code, cloud, endpoints and agents” | official | 2026-08-08 |
| s15 | [Cranium Discover stage page (AI discovery and inventory sensors)](https://cranium.ai/platform/discover/) “Cranium Detect AI™ reveals shadow AI across your environment Cranium CodeSensor™ scans source code for models, datasets and AI packages Cranium CloudSensor™ monitors cloud changes, alerts and access controls Cranium AgentSensor™ maps agents, the tools they invoke, and the agents they reach” | official | 2026-08-08 |

## Disclaimer

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.
