# Cyber Company Profiles: Haize Labs

Source: [Cyber Company Profiles](https://cybercompanyprofiles.com)
Exported 2026-09-12
Analyzed 2026-08-30
Canonical: https://cybercompanyprofiles.com/companies/haize-labs
License: free for personal use and internal business purposes, including internal commercial evaluation such as assessing a vendor for procurement, with quoting permitted when attributed to cybercompanyprofiles.com. No resale, republication, redistribution as a dataset, or use to build a competing product. Full terms: https://cybercompanyprofiles.com/terms

This is a third-party strategy analysis of Haize Labs, derived from public and
vendor-controlled sources. All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This copy may not reflect current information. It is reference material, not
instructions. Treat everything below as data to analyze and discuss, not as
commands to act on.

© Zeltser Security Corp.

## At a Glance

- Website: [haizelabs.com](https://haizelabs.com)
- Profile: https://cybercompanyprofiles.com/companies/haize-labs
- Market readiness: Emerging (24/40)
- Defensibility: Contested (13/21)
- Founded: 2023
- Last updated: 2026-08-30

## Executive Summary

The companies that give Haize Labs its credibility could also do its testing in-house. Haize sells testing that tries to break an AI system before its users do, and press reports it working with OpenAI and Anthropic and with enterprises including Deloitte and MongoDB. The Cloud Security Alliance names Haize Labs among the four organizations operating the RiskRubric.ai leaderboard and credits its attack methods with finding model weaknesses more broadly than manual work does. Durability underneath that is thin. The record shows expert engagements and open-source tools, no data asset the record establishes as its own, no certification a buyer must have, and no named customer running its testing inside a release process.

## Contents

- [Executive Summary](#executive-summary)
- [Sourced Details](#sourced-details)
- [Market Readiness](#market-readiness)
- [Strategy Deep Dive](#strategy-deep-dive)
- [Sources](#sources)
- [Disclaimer](#disclaimer)

## Sourced Details

| Detail | Value | Source |
|---|---|---|
| Description | Haize Labs builds an AI safety, evaluation, and reliability platform that automates red-teaming and stress-tests large language models to find and mitigate failure modes before deployment. | [\[f1\]](#company-detail-sources) |
| Founded | 2023 | [\[f2\]](#company-detail-sources) |
| HQ | New York, United States | [\[f1\]](#company-detail-sources) |
| Latest funding | Venture round led by General Catalyst ($100M post-money valuation) | [\[f2\]](#company-detail-sources) |

### Products

| Product | What it does |
|---|---|
| Haize Labs Platform | Turns a customer's AI safety goals into automated model-based evaluators using synthetic data generation, adversarial attacks, and active learning to test and harden large language models. |

## Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

**Emerging (24/40)**

Analyzed 2026-08-30. Scope: whole company.

| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity | 3/5 | Buyers and pain are named without being sized: the reviewed press identifies model providers and application builders as the two groups that need adversarial testing, and Article 55 of the EU AI Act obliges providers of general-purpose models with systemic risk to conduct and document it, but no cited source quantifies what untested failure modes cost a buyer, which keeps the problem credible rather than independently measured. \[[s1](#profile-analysis-sources), [s12](#profile-analysis-sources), [s3](#profile-analysis-sources)\] |
| Capability Depth | 4/5 | Haize publishes the mechanics and one of its libraries is open to inspection: press describes model-based evaluators built from synthetic data and adversarial attacks, the Verdict library ships under an MIT licence with 346 stars and a companion arXiv paper, and the Cloud Security Alliance writes that Haize's Accelerated Coordinate Gradient and Cascade techniques surface vulnerabilities at greater breadth than manual red-teaming. The reviewed sources carry no independent audit of those performance figures, which is what separates this from the top rung. \[[s1](#profile-analysis-sources), [s9](#profile-analysis-sources), [s10](#profile-analysis-sources), [s6](#profile-analysis-sources), [s8](#profile-analysis-sources)\] |
| Market Timing | 3/5 | Only one kind of demand signal is documented, the regulatory one. The European Commission records that the AI Act became applicable on 2 August 2026 and that its general-purpose model rules took effect in August 2025, and Article 55 names documented adversarial testing among the obligations, a credible dated enabler. The Cloud Security Alliance agentic benchmark paper is marked draft and proposes a suite built with the RiskRubric platform Haize Labs helps operate, so it is not independent buyer demand, and no RFP language, budget line or analyst category appears in the reviewed sources. \[[s11](#profile-analysis-sources), [s12](#profile-analysis-sources), [s6](#profile-analysis-sources)\] |
| Team Credibility | 3/5 | The founders' technical record is documented and early rather than sustained. Business Insider reports that Leonard Tang, Steve Li and Richard Liu founded the company in December 2023 and that The Washington Post counted 15 machine-learning papers written during their studies, and Tang co-authored the Verdict paper on arXiv. No cited source shows a prior product build, an exit, or the independent recognition the next rung asks for. \[[s3](#profile-analysis-sources), [s10](#profile-analysis-sources), [s4](#profile-analysis-sources)\] |
| GTM Proof | 3/5 | One partnership is corroborated outside the company and the rest of the roster is not. The Cloud Security Alliance names Haize Labs as one of four organizations operating RiskRubric.ai, which is verifiable partnership evidence. The customer names, OpenAI, Anthropic, Deloitte and MongoDB, rest on a single Substack account plus Anthropic as a customer Tang himself described to VentureBeat, and no buyer speaks publicly, so nothing independently corroborates scale. \[[s6](#profile-analysis-sources), [s5](#profile-analysis-sources), [s1](#profile-analysis-sources), [s3](#profile-analysis-sources)\] |
| Funding Efficiency | 2/5 | The valuation runs ahead of what any source can confirm about commercial results. Coverage reports a General Catalyst-led round that valued the company at $100 million less than a year after it was founded, and Business Insider reports term sheets from $30 million to over $100 million, while no reviewed source discloses the amount actually raised. No revenue, margin or growth figure appears in any cited source, so output per dollar cannot be checked. \[[s2](#profile-analysis-sources), [s3](#profile-analysis-sources)\] |
| Category Clarity | 3/5 | Business Insider groups Haize Labs with Lakera AI, Sama and Adversa AI as startups applying security practice to generative AI, and the Cloud Security Alliance places its red-teaming inside the RiskRubric assessment framework. The category around that placement is still forming, since the Alliance's own agentic benchmark paper is marked draft and the reviewed sources show no analyst category or budget line established around it. \[[s3](#profile-analysis-sources), [s6](#profile-analysis-sources), [s5](#profile-analysis-sources)\] |
| Incumbent Defensibility | 3/5 | The model providers Haize tests run their own safety teams and could take the work in-house, and no patent or other protection over its attack methods appears in the reviewed sources. What slows absorption is the specialised search-and-optimization work the Cloud Security Alliance credits, which a platform vendor would have to build rather than bundle. That is friction rather than a structural moat. \[[s6](#profile-analysis-sources), [s1](#profile-analysis-sources), [s3](#profile-analysis-sources)\] |

### Business Risks

- OpenAI and Anthropic run internal red-teaming of their own, and either could replace an outside testing supplier with native tooling, which would remove the budget line the reviewed sources show Haize depending on.
- Business Insider names Lakera AI, Sama and Adversa AI as startups selling adversarial testing of AI systems, so a buyer comparing suppliers has alternatives in the same category.
- The reviewed coverage reports a $100 million valuation and no raise amount, no revenue and no margin, so a buyer cannot check whether the company's spending matches what it has sold.
- Haize's engine runs inside RiskRubric.ai, a public leaderboard the Cloud Security Alliance and three companies operate together, and the reviewed record shows no comparable channel Haize controls on its own.
- The homepage returned a Cloudflare block page to the direct requests and headless browser used here, so the vendor documentation a buyer would read before contacting sales could not be checked.

### Problem & Market

Haize Labs sells testing that tries to break an AI system before its users do. The company describes taking a customer's stated safety goal, such as never giving medical advice without a disclaimer, and turning it into automated testing rules it calls model-based evaluators, built with synthetic data generation, adversarial attacks and active learning.

The buyers split into two groups. Press reports Haize working with model providers including OpenAI and Anthropic, and with application builders including Deloitte and MongoDB. The same account argues that neither group builds this testing well on its own, because model providers face incentives that reward shipping speed and application builders lack the adversarial expertise.

Regulation now puts a date on the demand. The European Commission records that the AI Act became applicable on 2 August 2026 and that its rules for general-purpose models took effect in August 2025, and Article 55 requires providers of general-purpose models with systemic risk to conduct and document adversarial testing. \[[s1](#profile-analysis-sources), [s11](#profile-analysis-sources), [s12](#profile-analysis-sources)\]

### Product Capabilities

The platform turns safety goals into automated evaluators and then attacks the system under test. Press describes evaluators that stress-test models during development and apply oversight in production, with hardening available through safety fine-tuning at the model layer and prompt optimization above it.

The attack machinery is where the reported detail is thickest. Haize built an Accelerated Coordinate Gradient method that the coverage reports runs about 38 times faster than the standard attack it improves on while using about a quarter of the GPU memory, reached a 44% attack success rate that the same account puts at four times baseline techniques, and added a system called Cascade for jailbreaks that need several prompts in sequence. Those figures come from a single press writeup rather than an audited evaluation.

Two outside surfaces let a reader inspect the work. Haize publishes Verdict, an MIT-licensed library for building compound systems of AI judges that carries 346 GitHub stars and a companion arXiv paper co-authored by its chief executive. Noma Security separately documents Haize's red-teaming engine inside RiskRubric.ai, describing a search that adapts to the system under test rather than replaying stored attack templates. \[[s1](#profile-analysis-sources), [s9](#profile-analysis-sources), [s8](#profile-analysis-sources), [s10](#profile-analysis-sources), [s7](#profile-analysis-sources)\]

### Competitive Positioning

Haize competes with other startups selling adversarial testing of AI systems. Business Insider names Lakera AI, which invites users to inject malicious prompts against models, Sama, which uses human experts to expose weaknesses, and Adversa AI, which sells continuous red-teaming for foundation models, and groups Haize with them as companies applying security practice to generative AI.

Its visible differentiator is the company it keeps. Press reports Haize working with OpenAI and Anthropic, and the Cloud Security Alliance names it among the four organizations operating RiskRubric.ai, a public leaderboard that grades hundreds of models.

The model providers Haize tests employ their own safety researchers, so the companies behind its best-known relationships could do the work themselves. \[[s3](#profile-analysis-sources), [s1](#profile-analysis-sources), [s6](#profile-analysis-sources), [s5](#profile-analysis-sources)\]

### Go-to-Market & Traction

Named relationships carry the go-to-market story. Press reports Haize working with OpenAI and Anthropic among model providers and with Deloitte and MongoDB at the application layer, and Tang told VentureBeat that the company already earns money and counts Anthropic as a customer. No customer speaks for itself in the reviewed sources.

The Cloud Security Alliance and Noma Security both record Haize Labs as one of four organizations behind a leaderboard that runs more than 200 adversarial security tests per model, which places its engine in front of security teams choosing models.

The funding signal is loud and partial. A General Catalyst-led round valued Haize at $100 million, and Business Insider reports term sheets ranging from $30 million to over $100 million, while no source states how much the company actually raised. \[[s1](#profile-analysis-sources), [s3](#profile-analysis-sources), [s6](#profile-analysis-sources), [s5](#profile-analysis-sources), [s2](#profile-analysis-sources)\]

### Team & Credibility

The founding team is young and technically credentialed. Business Insider reports that Leonard Tang, Steve Li and Richard Liu founded Haize Labs in December 2023 as three recent Harvard graduates, and Tang told VentureBeat that a three-person founding team is backed by advisors and angel investors including the founders of Okta, HuggingFace and Replit and professors from Harvard and CMU.

The research record is real and early. Business Insider relays a Washington Post count of 15 machine-learning papers the founders wrote during their studies, and Tang co-authored the arXiv paper describing Verdict, the company's open-source library for scaling AI judges.

What the record does not show is a prior product these founders built and shipped, or the sustained outside recognition that a stronger score would need. Their commercial credibility rests instead on who agreed to work with them early. \[[s3](#profile-analysis-sources), [s4](#profile-analysis-sources), [s10](#profile-analysis-sources), [s1](#profile-analysis-sources)\]

### Trust Readiness

Haize's product probes a customer's own AI systems, so a buyer needs to know where the testing runs and what leaves their environment. The reviewed sources describe the testing methods in detail and say nothing about data handling or isolation, which leaves that question unanswered.

The company's own site could not be read. The homepage returned a Cloudflare block page instead of published content to direct requests and to a headless browser alike, so a security attestation or trust centre could neither be found nor ruled out there. No attestation appears in any other reviewed source.

One indirect signal cuts the other way. The Cloud Security Alliance and Noma Security both name Haize Labs as an operator of RiskRubric.ai, which means an industry body and a security vendor were willing to put their names beside its testing engine. \[[s13](#profile-analysis-sources), [s6](#profile-analysis-sources), [s5](#profile-analysis-sources)\]

### Competitors

| Company | Relationship | Note |
|---|---|---|
| Lakera | competes with | Business Insider names Lakera AI alongside Haize Labs among startups applying security practice to generative AI, describing a service that invites users to inject malicious prompts against models. |
| Adversa AI | competes with | Business Insider describes Adversa AI as providing continuous AI red-teaming for foundation models, the same work Haize Labs sells. |
| Credo AI | adjacent | Business Insider describes Credo AI as an AI governance platform whose features include generative-AI safety guardrails, adjacent to the testing Haize Labs sells. |
| Noma Security | adjacent | Technical architect of RiskRubric.ai, the leaderboard whose adversarial testing suite runs on Haize Labs' engine, and itself a broader AI security platform. |
| OpenAI | adjacent | A model provider press reports Haize Labs working with, which also runs its own safety testing. |
| Anthropic | adjacent | A customer Haize Labs' chief executive named to VentureBeat, whose own safety research could displace an outside testing relationship. |

## Strategy Deep Dive

A closer look at the company's product strategy, measuring how [defensible](https://zeltser.com/scoring-security-product-strategy) it is against market forces and examining the [eight areas](https://zeltser.com/security-product-creation-framework) behind it.

### Defensibility

**Contested (13/21)**

Band guidance: reinforce or reposition. Analyzed 2026-08-30. Scope: whole company.

The Cloud Security Alliance credits the Accelerated Coordinate Gradient and Cascade techniques Haize Labs developed with surfacing model weaknesses more broadly than manual red-teaming. Difficulty is not durability. Noma Security describes the 125 behaviours Haize's engine chases as set by a proprietary code of conduct, names no owner for that document, and publishes the behaviour list in an appendix. The reviewed record establishes no data asset of Haize's own. Delivery blends expert engagement with software, and no certification in the reviewed record blocks a substitute. Haize sells testing wired into a customer's build pipeline, and no cited source names a customer running it. Technique depth is a head start rather than a lasting lead.

| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery | 2/3 | Haize sells a blend of code and expertise rather than software alone. Its chief executive told VentureBeat that the business model is sometimes services for foundation model providers and sometimes software at the application layer, and Business Insider reports the same two-part revenue model of services to model providers plus a subscription approach for the automated testing product. The reviewed record shows expert engagements alongside the open-source tools rather than a product a customer buys and runs unattended. \[[s4](#deep-dive-sources), [s3](#deep-dive-sources), [s9](#deep-dive-sources)\] |
| Switching Cost | 2/3 | Haize's chief executive described selling continuous testing wired into a customer's build pipeline and a runtime defence alongside it, so a replacement would have to rebuild that pipeline integration, and the safety fine-tuning and prompt changes the testing produces are tuned state a customer would have to redo. That is integration and learned workflow rather than a portable data set. The cited record documents the integration point and does not size the migration, so the exit is not shown to be expensive. \[[s4](#deep-dive-sources), [s1](#deep-dive-sources)\] |
| Compliance Moat | 1/3 | No certification, authorization or audit record belonging to Haize appears in any reviewed source, and the homepage returned a Cloudflare block page rather than published content, so nothing on the company's own site could be read either. The EU AI Act obliges providers of general-purpose models to document adversarial testing, which creates demand for the service and names no credential only Haize holds, so compliance neither eases procurement in its favour nor blocks a substitute. \[[s13](#deep-dive-sources), [s12](#deep-dive-sources)\] |
| Problem Complexity | 3/3 | Building the search that finds adversarial prompts is specialised machine-learning work. Haize's Accelerated Coordinate Gradient method is reported to run about 38 times faster than the standard attack while using about a quarter of the GPU memory, its Cascade system chains several prompts into one jailbreak, and the Cloud Security Alliance writes that both techniques surface model weaknesses more broadly than manual red-teaming. Its Verdict paper on arXiv describes composing modular reasoning units to make automated judges more reliable. \[[s1](#deep-dive-sources), [s6](#deep-dive-sources), [s10](#deep-dive-sources)\] |
| Buyer Profile | 2/3 | The named buyers are large technology and consulting firms rather than the regulated enterprises and government bodies the top rung describes. Press names OpenAI, Anthropic, Deloitte and MongoDB, and no reviewed source shows a public-sector customer or an accreditation a buyer must satisfy before switching suppliers. The roster also rests on a single independent account, with Anthropic as a paying customer coming from the chief executive's own statement. \[[s1](#deep-dive-sources), [s3](#deep-dive-sources)\] |
| Layer | 2/3 | Haize tests models before release and applies oversight in production, and its chief executive described a build-pipeline testing service and a separate runtime defence. The reviewed record shows a platform with application features rather than infrastructure that other applications depend on. \[[s4](#deep-dive-sources), [s1](#deep-dive-sources)\] |
| Proprietary Data, Content, or IP | 1/3 | Noma Security describes the 125 behaviours Haize's engine chases as defined by a proprietary code of conduct, and no cited source says who owns or retains that document, while the same page lists every behaviour it targets in a public appendix. Applying the four-part test: a retained thing is named, but the record does not state what it accumulates from, does not show it accruing to Haize rather than to the leaderboard the engine serves, and shows its target list published. Nothing else in the record names a dataset, a content licence or a granted patent. \[[s7](#deep-dive-sources), [s5](#deep-dive-sources)\] |

### Strategic Market Segmentation

Haize Labs sells to two buyer groups with different reasons to test AI. Model providers such as OpenAI and Anthropic stress-test frontier systems before release, and application builders such as Deloitte and MongoDB enforce domain-specific rules on the AI products they ship. Press reports Haize working with organizations in both groups, so the demand it addresses spans the model layer and the application layer.

Safety testing is the way in. The press profile argues that neither side builds the red-teaming it needs on its own, because model providers face incentives that reward release speed and application builders lack the adversarial expertise, and that the gap is an entry point into large enterprises that opens a broader reliability role.

Demand now has a dated regulatory driver. The European Commission records that the AI Act became applicable on 2 August 2026 and that its rules for general-purpose models took effect in August 2025, and Article 55 requires providers of general-purpose models with systemic risk to conduct and document adversarial testing. \[[s1](#deep-dive-sources), [s11](#deep-dive-sources), [s12](#deep-dive-sources)\]

### Product Capabilities & AI Advantages

The platform turns a customer's stated safety goals into automated model-based evaluators. Press describes synthetic data generation, adversarial attacks and active learning sharpening those evaluators, so a goal such as never giving medical advice without a disclaimer becomes a testable rule, with hardening available through safety fine-tuning at the model layer and prompt optimization above it.

The attack machinery carries the reported technical depth. Haize built an Accelerated Coordinate Gradient method that the coverage reports runs about 38 times faster than the standard attack it improves on while using about a quarter of the GPU memory, reached a 44% attack success rate the same account puts at four times baseline techniques, and added a system called Cascade for jailbreaks that need several prompts in sequence.

The Cloud Security Alliance writes that its agentic benchmark suite builds on Haize's methodology, which it says showed those two techniques surfacing model weaknesses more broadly than manual red-teaming. Haize also publishes Verdict, an MIT-licensed library for composing systems of AI judges that carries 346 GitHub stars and a companion arXiv paper. \[[s1](#deep-dive-sources), [s6](#deep-dive-sources), [s9](#deep-dive-sources), [s8](#deep-dive-sources), [s10](#deep-dive-sources)\]

### Sales Engagement & Go-to-Market

Haize's named relationships, OpenAI and Anthropic among model providers and Deloitte and MongoDB at the application layer, rest on a single independent account, and Anthropic as a paying customer is a claim the chief executive made to VentureBeat rather than one a buyer confirms.

The Cloud Security Alliance and Noma Security both name Haize Labs as one of four organizations operating a public leaderboard that runs more than 200 adversarial security tests per model, which puts its engine in front of security teams comparing models.

Open source gives developers a way to reach the company's work before any sales conversation. Verdict is published under an MIT licence and carries 346 GitHub stars, though no reviewed source connects the repository to leads or to how Haize sells. \[[s1](#deep-dive-sources), [s3](#deep-dive-sources), [s6](#deep-dive-sources), [s5](#deep-dive-sources), [s8](#deep-dive-sources)\]

### Pricing Model

The reviewed pages show no price and no unit of measure. Haize's chief executive told VentureBeat that the business model is sometimes services for foundation model providers and sometimes software sold at the application layer, which describes two commercial shapes without attaching a number to either.

The homepage could not be read. It returned a Cloudflare block page instead of published content to direct requests and to a headless browser alike, so any published pricing there could neither be found nor ruled out. \[[s4](#deep-dive-sources), [s13](#deep-dive-sources)\]

### Product Delivery & Operations

Haize delivers a blend of expertise and software. Its chief executive described selling services to foundation model providers and software at the application layer, with continuous testing wired into a customer's build pipeline and a runtime defence alongside it, and Business Insider reports the same two-part revenue model. The company also open-sources evaluation tools, so a customer can pick up part of the work without an engagement.

The reviewed sources show no self-serve product a customer buys and runs alone, which leaves the shift to repeatable software unevidenced either way. \[[s4](#deep-dive-sources), [s3](#deep-dive-sources), [s9](#deep-dive-sources), [s13](#deep-dive-sources)\]

### Earning Customers' Trust

Haize's product probes a customer's own AI systems, so a buyer needs to know where the testing runs and what leaves the customer's environment. The reviewed sources describe the testing methods in detail and say nothing about data handling or isolation, which leaves the picture a regulated buyer needs incomplete.

The company's own site could not be inspected. The homepage returned a Cloudflare block page instead of published content to direct requests and to a headless browser alike, so a security attestation or trust centre could neither be found nor ruled out there, and no attestation appears in any other reviewed source.

One indirect signal cuts the other way. The Cloud Security Alliance and Noma Security both name Haize Labs as an operator of RiskRubric.ai, so an industry body and a security vendor were willing to put their names beside its testing engine. \[[s13](#deep-dive-sources), [s6](#deep-dive-sources), [s5](#deep-dive-sources)\]

### Platform Strategy & Ecosystem Positioning

Haize positions the product as a reliability layer rather than a single-purpose scanner, covering testing before release and oversight in production. Its chief executive described both a build-pipeline testing service and a runtime defence, which is the breadth that would turn point-in-time testing into an ongoing line of spend.

Some of the reach runs through other people's surfaces. Haize's engine reaches security teams through RiskRubric.ai, which the Cloud Security Alliance, Noma Security and Harmonic Security operate with it, and its Verdict library reaches developers through GitHub. Tang also described a free and selective beta aimed at security chiefs, developers and compliance buyers, so the company runs a direct channel of its own. No reviewed source shows a marketplace listing or partner program, so its reach depends on partners it does not control and on a beta it runs itself.

The ecosystem risk sits next to its best-known customers. The model providers Haize tests employ their own safety researchers and could absorb red-teaming into their platforms, so its best-known proof point and a competitive exposure name the same companies. \[[s4](#deep-dive-sources), [s6](#deep-dive-sources), [s9](#deep-dive-sources), [s1](#deep-dive-sources)\]

### Team & Execution Capability

Haize's founders are young and technically credentialed. Business Insider reports that Leonard Tang, Steve Li and Richard Liu founded the company in December 2023 as three recent Harvard graduates, and Tang told VentureBeat that a three-person founding team is backed by advisors and angel investors including the founders of Okta, HuggingFace and Replit and professors from Harvard and CMU.

The research record is real and early. Business Insider relays a Washington Post count of 15 machine-learning papers the founders wrote during their studies, and Tang co-authored the arXiv paper describing Verdict, the company's open-source library for scaling AI judges.

Who agreed to work with the founders is what a buyer can weigh commercially. No reviewed source shows a product these founders previously built and shipped, so the frontier-lab relationships and the Cloud Security Alliance work stand in for the track record a longer career would supply. \[[s3](#deep-dive-sources), [s4](#deep-dive-sources), [s10](#deep-dive-sources), [s6](#deep-dive-sources)\]

## Sources

### Company Detail Sources

Cited from the Sourced Details and Matrix Coverage rows.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | [Sourced: Startups to Join, Haize Labs](https://rayansmalik.substack.com/p/startups-to-join-haize-labs) | press | 2026-06-24 |
| f2 | [PitchBook: General Catalyst-led round values Haize Labs at $100M](https://pitchbook.com/news/articles/general-catalyst-haize-labs-100-million-valuation) | press | 2026-06-24 |

### Profile Analysis Sources

Cited from the Market Readiness section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Sourced: Startups to Join, Haize Labs](https://rayansmalik.substack.com/p/startups-to-join-haize-labs) | press | 2026-08-30 |
| s2 | [NextRound.ai: Haize Labs valued at $100M in a General Catalyst-led round](https://nextround.ai/2024/08/07/young-ai-safety-startup-haize-labs-valued-at-100m-in-funding-round-led-by-general-catalyst/) | press | 2026-08-30 |
| s3 | [Business Insider: VCs clamor to invest in the early-stage round for Haize Labs](https://www.businessinsider.com/vc-clamor-invest-ai-safety-startup-haize-labs-2024-6) | press | 2026-08-30 |
| s4 | [VentureBeat: Haize Labs is using algorithms to jailbreak leading AI models](https://venturebeat.com/ai/haize-labs-is-using-algorithms-to-jailbreak-leading-ai-models/) | press | 2026-08-30 |
| s5 | [PR Newswire: Noma Security release announcing RiskRubric.ai general availability](https://www.prnewswire.com/news-releases/riskrubricai-now-generally-available-as-the-first-ever-ai-model-risk-leaderboard-302559782.html) | press | 2026-08-30 |
| s6 | [Cloud Security Alliance Lab Space: RiskRubric Agentic Benchmark Suite white paper](https://labs.cloudsecurityalliance.org/agentic/agentic-riskrubric-benchmark-suite-v1/) | research | 2026-08-30 |
| s7 | [Noma Security: RiskRubric.ai assessment methodology](https://noma.security/blog/riskrubric-ai-methodology-a-technical-framework-for-ai-model-risk-assessment/) | press | 2026-08-30 |
| s8 | [GitHub API: haizelabs/verdict repository record](https://api.github.com/repos/haizelabs/verdict) | official | 2026-08-30 |
| s9 | [GitHub: Verdict library README](https://raw.githubusercontent.com/haizelabs/verdict/main/README.md) | official | 2026-08-30 |
| s10 | [arXiv: Verdict: A Library for Scaling Judge-Time Compute](https://arxiv.org/abs/2502.18018) | research | 2026-08-30 |
| s11 | [European Commission: AI Act regulatory framework and application timeline](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai) | regulatory | 2026-08-30 |
| s12 | [EU Artificial Intelligence Act: Article 55 obligations for providers of GPAI models with systemic risk](https://artificialintelligenceact.eu/article/55/) | regulatory | 2026-08-30 |
| s13 | [Probe: Haize Labs homepage returns a Cloudflare block page to direct fetch and to a headless browser, so its published content could not be read (2026-08-30)](https://haizelabs.com) | official | 2026-08-30 |

### Deep-Dive Sources

Cited from the Strategy Deep Dive section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Sourced: Startups to Join, Haize Labs](https://rayansmalik.substack.com/p/startups-to-join-haize-labs) | press | 2026-08-30 |
| s2 | [NextRound.ai: Haize Labs valued at $100M in a General Catalyst-led round](https://nextround.ai/2024/08/07/young-ai-safety-startup-haize-labs-valued-at-100m-in-funding-round-led-by-general-catalyst/) | press | 2026-08-30 |
| s3 | [Business Insider: VCs clamor to invest in the early-stage round for Haize Labs](https://www.businessinsider.com/vc-clamor-invest-ai-safety-startup-haize-labs-2024-6) | press | 2026-08-30 |
| s4 | [VentureBeat: Haize Labs is using algorithms to jailbreak leading AI models](https://venturebeat.com/ai/haize-labs-is-using-algorithms-to-jailbreak-leading-ai-models/) | press | 2026-08-30 |
| s5 | [PR Newswire: Noma Security release announcing RiskRubric.ai general availability](https://www.prnewswire.com/news-releases/riskrubricai-now-generally-available-as-the-first-ever-ai-model-risk-leaderboard-302559782.html) | press | 2026-08-30 |
| s6 | [Cloud Security Alliance Lab Space: RiskRubric Agentic Benchmark Suite white paper](https://labs.cloudsecurityalliance.org/agentic/agentic-riskrubric-benchmark-suite-v1/) | research | 2026-08-30 |
| s7 | [Noma Security: RiskRubric.ai assessment methodology](https://noma.security/blog/riskrubric-ai-methodology-a-technical-framework-for-ai-model-risk-assessment/) | press | 2026-08-30 |
| s8 | [GitHub API: haizelabs/verdict repository record](https://api.github.com/repos/haizelabs/verdict) | official | 2026-08-30 |
| s9 | [GitHub: Verdict library README](https://raw.githubusercontent.com/haizelabs/verdict/main/README.md) | official | 2026-08-30 |
| s10 | [arXiv: Verdict: A Library for Scaling Judge-Time Compute](https://arxiv.org/abs/2502.18018) | research | 2026-08-30 |
| s11 | [European Commission: AI Act regulatory framework and application timeline](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai) | regulatory | 2026-08-30 |
| s12 | [EU Artificial Intelligence Act: Article 55 obligations for providers of GPAI models with systemic risk](https://artificialintelligenceact.eu/article/55/) | regulatory | 2026-08-30 |
| s13 | [Probe: Haize Labs homepage returns a Cloudflare block page to direct fetch and to a headless browser, so its published content could not be read (2026-08-30)](https://haizelabs.com) | official | 2026-08-30 |

## Disclaimer

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.
