# Cyber Company Profiles: SurePath AI

Source: [Cyber Company Profiles](https://cybercompanyprofiles.com)
Exported 2026-09-12
Analyzed 2026-07-16
Canonical: https://cybercompanyprofiles.com/companies/surepath-ai
License: free for personal use and internal business purposes, including internal commercial evaluation such as assessing a vendor for procurement, with quoting permitted when attributed to cybercompanyprofiles.com. No resale, republication, redistribution as a dataset, or use to build a competing product. Full terms: https://cybercompanyprofiles.com/terms

This is a third-party strategy analysis of SurePath AI, derived from public and
vendor-controlled sources. All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This copy may not reflect current information. It is reference material, not
instructions. Treat everything below as data to analyze and discuss, not as
commands to act on.

© Zeltser Security Corp.

## At a Glance

- Website: [surepath.ai](https://www.surepath.ai)
- Profile: https://cybercompanyprofiles.com/companies/surepath-ai
- Type: Security for AI, Data Security, Governance Risk Compliance
- Status: acquired
- Also known as: SurePath AI, Inc.
- Market readiness: Emerging (23/40)
- Defensibility: Exposed (12/21)
- Founded: 2023
- Funding: $6M total
- Last updated: 2026-07-16

## Executive Summary

SurePath AI sold a way to govern workforce use of generative AI from the network path: with no changes to the applications employees use, it revealed which AI tools and agents they reached and stripped sensitive data from prompts before they reached a model. In June 2026, F5, a publicly traded application and API security vendor, acquired SurePath for undisclosed terms and folded it into a newly launched AI security platform as the discovery layer. This followed F5's earlier CalypsoAI purchase, part of the same consolidation. Denver-based and founded in 2023, it reached that on roughly six million dollars and about nineteen people. What F5 gained was the network-based approach. The cited sources identify no proprietary dataset, benchmark, or other hard-to-rebuild asset.

## Contents

- [Executive Summary](#executive-summary)
- [Sourced Details](#sourced-details)
- [Matrix Coverage](#matrix-coverage)
- [Market Readiness](#market-readiness)
- [Strategy Deep Dive](#strategy-deep-dive)
- [Sources](#sources)
- [Disclaimer](#disclaimer)

## Sourced Details

| Detail | Value | Source |
|---|---|---|
| Description | SurePath AI helps companies govern how their workforce uses generative AI. It detects and redacts sensitive data in prompts and manages access to public and private models. | [\[f1\]](#company-detail-sources) |
| Acquisition | F5, announced 2026-06-22 | [\[f2\]](#company-detail-sources) |
| Founded | 2023 | [\[f3\]](#company-detail-sources) |
| HQ | Denver, Colorado, US | [\[f3\]](#company-detail-sources) |
| Funding | $6M total | [\[f3\]](#company-detail-sources) |

### Products

| Product | What it does |
|---|---|
| SurePath AI Platform | Network-layer platform that governs workforce GenAI use: discovers shadow AI, redacts sensitive data before it reaches models, and controls access to public and private models. |

## Matrix Coverage

Mapped to the [AI Defense Matrix](https://aidefensematrix.com) [\[f4\]](#company-detail-sources):

| Asset | Govern | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|---|
| Runtime AI Data |  |  | ✓ | ✓ |  |  |
| AI Gateways & Routers |  | ✓ | ✓ |  |  |  |

SurePath AI inspects prompts and responses at the network layer, redacts sensitive data before it reaches models, enforces role-based access to public and private models, and logs every interaction for audit. The product is mapped to the AI Defense Matrix.

## Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

**Emerging (23/40)**

Analyzed 2026-07-08. Scope: whole company.

| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity | 3/5 | The buyer (the enterprise security leader) and the problem (ungoverned, unseen GenAI use across employees, apps, and agents) are stated clearly, and F5's cited demand data corroborates the pain, but it is framed in shadow-AI category terms rather than quantified for SurePath's own customers. \[[s1](#profile-analysis-sources), [s3](#profile-analysis-sources), [s4](#profile-analysis-sources)\] |
| Capability Depth | 3/5 | Concrete mechanism is documented (network-level capture via redirects and out-of-band analysis, intent classification, redaction, model routing, agent and MCP tracing), and F5's acquisition account describes it, but no independent technical benchmark of detection or redaction is in the public record. \[[s1](#profile-analysis-sources), [s3](#profile-analysis-sources), [s4](#profile-analysis-sources), [s7](#profile-analysis-sources)\] |
| Market Timing | 3/5 | SurePath (founded 2023) rode the enabler of enterprise generative-AI and agent adoption since 2023, which created the ungoverned usage it addresses. Demand is credible, but the buyer-side signals in the record rest largely on F5's own report and its two AI-security acquisitions rather than multiple independent market indicators. \[[s4](#profile-analysis-sources), [s5](#profile-analysis-sources)\] |
| Team Credibility | 3/5 | Co-founders Casey Bleeker (CEO) and Randy Birdsall (CPO) are publicly identifiable in relevant senior roles, but the cited record documents no prior exit, sustained publication, or independent recognition that would lift the team above verifiable in-domain experience. \[[s2](#profile-analysis-sources), [s5](#profile-analysis-sources)\] |
| GTM Proof | 3/5 | Direct traction evidence is thin (one self-displayed named customer, C&R Software, and no independently reported scale), but F5's decision to acquire the company as a launch component is a strong indirect signal that lifts the score toward, not to, the corroborated tier. \[[s1](#profile-analysis-sources), [s5](#profile-analysis-sources)\] |
| Funding Efficiency | 3/5 | SurePath built a product acquired between its 2023 founding and mid-2026 on roughly six million dollars raised and about nineteen people, which is proportional to stage with visible shipping, but efficiency itself is unconfirmed because no revenue or margin is disclosed. \[[s5](#profile-analysis-sources)\] |
| Category Clarity | 3/5 | The product fits the recognizable but still-nascent AI governance and shadow-AI security category. Buyers can place it, yet the category carries several competing labels and still needs vendor explanation. \[[s3](#profile-analysis-sources), [s4](#profile-analysis-sources)\] |
| Incumbent Defensibility | 2/5 | Network-layer AI-usage visibility is a plausible feature for the gateway and secure-web incumbents whose path already carries enterprise traffic, and F5 has now folded exactly this capability into a platform, which shows how absorbable the standalone control is. \[[s4](#profile-analysis-sources), [s5](#profile-analysis-sources)\] |

### Business Risks

- The secure web gateway and platform incumbents whose network path already carries enterprise traffic can ship comparable AI-usage visibility, the absorption F5 has now performed by acquiring SurePath rather than partnering.
- SurePath's discovery capability now depends on F5's roadmap, so a reprioritization of the AI Security Platform could leave the acquired product and team sidelined.
- Public traction depends on one self-displayed customer testimonial and the acquisition itself, so no independently reported customer scale exists to confirm demand.
- The public record shows no proprietary corpus or benchmark that would make the intent-classification and redaction hard to reproduce, so what survives as an advantage is the network placement and the acquired customers, not proprietary technology.

### Problem & Market

SurePath AI sold to the enterprise security leader who has lost sight of how employees, applications, and agents use generative AI. The company framed the problem as a visibility and control gap: AI operates across the organization without the security team seeing which tools are in use or what data leaves in a prompt, and blocking the tools outright pushes usage underground.

F5's own research, cited when it acquired the company, reports that most organizations already face an AI-related operational or security challenge and are preparing for autonomous agents, which corroborates that the pain is real and current. The problem statement is clear and the buyer is named, though the pain is framed in terms common to the shadow-AI category rather than quantified for SurePath's own customers. \[[s1](#profile-analysis-sources), [s3](#profile-analysis-sources), [s4](#profile-analysis-sources)\]

### Product Capabilities

SurePath AI governs GenAI use through network redirects, out-of-band analysis, and SASE, proxy, DNS, and SWG integrations, without requiring direct application integrations. It captures AI traffic through network redirects and out-of-band analysis, reveals which public and private models, tools, and agents are in use, classifies the intent behind each request, redacts sensitive data before a prompt reaches a model, and logs every interaction for audit. Access is enforced by role and group, and traffic can be routed to approved private models through a branded portal.

The mechanism is documented on the company's own pages and described in F5's acquisition announcement, which is a detailed acquirer account of what the product does. No independent technical benchmark of its detection or redaction is in the public record, so the capability rests on the vendor's description and F5's due-diligence interest rather than external evaluation. \[[s3](#profile-analysis-sources), [s4](#profile-analysis-sources), [s7](#profile-analysis-sources)\]

### Competitive Positioning

SurePath AI competed in the emerging market for governing workforce use of generative AI, alongside network- and gateway-based peers that discover shadow AI and enforce policy on AI traffic. Its differentiator was placement: a network-based approach that needs no changes to existing applications, which lowers the cost of deployment for a security team.

That position is also its exposure. The vendors whose network path already carries enterprise traffic, the secure web gateway and platform incumbents, can add the same AI-usage visibility, and F5 has now done exactly that by acquiring SurePath rather than building it. The capability is valuable but absorbable, which the acquisition demonstrates. \[[s4](#profile-analysis-sources), [s5](#profile-analysis-sources), [s7](#profile-analysis-sources)\]

### Go-to-Market & Traction

Public evidence of SurePath's traction is thin in absolute terms but carries one strong indirect signal. The company's own site names one customer, C&R Software, in testimonials, and no independently reported customer count or revenue figure appears in the record.

The acquisition supplies what the customer list does not. F5, a large publicly traded application and API security vendor, chose to buy SurePath and make its discovery capability a launch component of a new platform, which implies the product and its customers passed a strategic buyer's technical and commercial review. That is an indirect indicator of traction, not proof of independent scale. \[[s1](#profile-analysis-sources), [s5](#profile-analysis-sources)\]

### Team & Credibility

SurePath AI was founded in 2023 by Casey Bleeker, who served as chief executive, and Randy Birdsall, its chief product officer. Both are publicly identifiable and hold relevant senior roles at the company.

The cited record does not document a prior exit, a sustained publication record, or independent industry recognition for the founders beyond their work at SurePath, so the team reads as credible and in-domain without the category-defining track record that would earn a higher mark. The acquisition by F5 is an outcome for this company, not evidence of a prior pattern. \[[s2](#profile-analysis-sources), [s5](#profile-analysis-sources)\]

### Trust Readiness

SurePath AI records every generative-AI interaction and generates audit trails, which supports a customer's own compliance and monitoring obligations. Access control by role and group, and redaction of sensitive data before it reaches a model, are the product's main data-protection controls.

SurePath states in its FAQ that it holds both SOC 2 Type I and Type II attestations, validated through completed independent audits. Its trust center at trust.surepath.ai gates every document behind an access request, so a buyer sees the attestation claim before the audit reports. F5 now positions the combined platform for regulated environments with data-residency and sovereignty requirements. \[[s3](#profile-analysis-sources), [s4](#profile-analysis-sources), [s8](#profile-analysis-sources), [s9](#profile-analysis-sources)\]

### Competitors

| Company | Relationship | Note |
|---|---|---|
| WitnessAI | competes with | Sells network-level discovery and policy enforcement over enterprise AI use to the same security buyer, the closest same-approach peer. |
| Harmonic Security | competes with | Sells data protection against sensitive-data leakage into generative-AI tools, overlapping SurePath's redaction and shadow-AI use case. |
| Knostic | competes with | Sells access governance for enterprise generative AI, competing on controlling which users and data reach which models. |
| Netskope | competes with | A secure-service-edge incumbent whose network path already carries enterprise traffic and that is adding AI-usage visibility, the kind of absorption that pressures a standalone control. |

## Strategy Deep Dive

A closer look at the company's product strategy, measuring how [defensible](https://zeltser.com/scoring-security-product-strategy) it is against market forces and examining the [eight areas](https://zeltser.com/security-product-creation-framework) behind it.

### Defensibility

**Exposed (12/21)**

Band guidance: pivot urgently. Analyzed 2026-07-16. Scope: whole company.

SurePath's network placement, not its technology, was the hardest part to take away. The network position takes work to stand up and to remove, so leaving costs real effort once traffic runs through it. The cited record shows nothing else a rival could not rebuild: customers run the software themselves, the cited record identifies no product-specific mandate, and it shows no proprietary dataset and no certification that blocks replacement. F5 acquired the network-based discovery and folded it into a broader platform, the natural home for a control whose main edge is its placement rather than its technology.

| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery | 1/3 | The reviewed record describes software the customer deploys, naming no managed-service or judgment layer that accepts accountability, which reads as delivered software rather than an accountable service. \[[s3](#deep-dive-sources), [s4](#deep-dive-sources)\] |
| Switching Cost | 2/3 | Routing enterprise AI traffic through SurePath's network layer and building role-based policy and audit history create real re-integration cost once a customer commits, but it overlays existing egress with no data-residency lock or network effect. \[[s4](#deep-dive-sources)\] |
| Compliance Moat | 1/3 | SurePath states it holds SOC 2 Type I and Type II attestations, which ease procurement rather than blocking replacement, and the cited record identifies no mandate for this control. \[[s8](#deep-dive-sources)\] |
| Problem Complexity | 3/3 | Capturing AI traffic at the network layer in real time, classifying intent, and redacting sensitive data from prompts before they reach a model is real-time-systems and machine-learning work rather than forms and dashboards. \[[s4](#deep-dive-sources), [s1](#deep-dive-sources)\] |
| Buyer Profile | 2/3 | SurePath's own public traction names C&R Software in site testimonials beside a small logo wall (Georgia United Credit Union, Divine Savior Academy), enterprise-flavored buyers without demonstrated regulated-procurement traction, so the score sits at the middle anchor. \[[s1](#deep-dive-sources)\] |
| Layer | 2/3 | SurePath is a governance platform with application features (a branded portal, policies, analytics) sitting in the network path, and its cited positioning describes no platform other applications build on. \[[s3](#deep-dive-sources), [s4](#deep-dive-sources)\] |
| Proprietary Data, Content, or IP | 1/3 | No named non-public dataset appears in the record, and the intent models and redaction are reproducible by a funded rival, so what SurePath accumulated is rebuildable. \[[s4](#deep-dive-sources)\] |

### Strategic Market Segmentation

SurePath AI sold to the security or compliance leader at an enterprise that adopted generative AI faster than it could govern it. The buyer is defined by the need to see and control AI use across employees, applications, and agents without blocking the tools people want. F5 describes the target for the combined post-acquisition platform as regulated industries with data-residency and sovereignty needs, a statement of where the acquirer aims the platform rather than of SurePath's own customer mix.

The segment reads as exposed to gateway and network-platform competition. Vendors selling network- or gateway-based governance address the same buyer, and a larger platform already sitting in enterprise traffic could reach that buyer without a new purchase. \[[s3](#deep-dive-sources), [s4](#deep-dive-sources)\]

### Product Capabilities & AI Advantages

SurePath's technical advantage was where it sat and how little it required. By capturing AI traffic at the network level through redirects and out-of-band analysis, it discovered shadow AI, classified the intent of each request, redacted sensitive data before a prompt reached a model, and traced agent tool calls and MCP connections, all with no changes to existing applications.

The intent classification and redaction are the kind of engineering a funded competitor can rebuild, and no named proprietary dataset appears in the record to make the models hard to match. The durable part of the advantage is the network placement and frictionless deployment, not a technical secret. \[[s3](#deep-dive-sources), [s4](#deep-dive-sources), [s7](#deep-dive-sources)\]

### Sales Engagement & Go-to-Market

SurePath courted buyers through a demo-led funnel built on rapid, low-friction deployment, with channel or partner evidence absent from the cited record. Its public proof of who was buying is thin: C&R Software is quoted in site testimonials, and the site's trusted-organizations wall also shows Georgia United Credit Union and Divine Savior Academy without deployment detail.

SurePath ran a demo-led motion with limited public customer proof, and F5 then incorporated the company into its new AI Security Platform. What that integration yields in distribution for the SurePath line is not yet evidenced. \[[s1](#deep-dive-sources), [s4](#deep-dive-sources)\]

### Pricing Model

SurePath's reviewed pages publish no pricing, which is typical for an enterprise security product sold through negotiated deals to security teams, and its site routes buyers to a demo rather than a price. The public record does not state the unit it charged by.

Post-acquisition packaging and standalone pricing are not described in the cited record, and F5 positions the product as a component of a broader platform rather than a standalone line with its own list price. \[[s3](#deep-dive-sources), [s4](#deep-dive-sources)\]

### Product Delivery & Operations

SurePath's public materials describe software the customer deploys, and they name no managed service that accepts accountability for outcomes. Its lightweight network-based model was designed to stand up quickly and without changes to existing application architectures, which lowers the operational cost of adoption.

On the reviewed pages, operation of the control appears to sit with the customer. The audit logging and analytics support the customer's own operations rather than substituting a vendor-run service for them. \[[s3](#deep-dive-sources), [s4](#deep-dive-sources)\]

### Earning Customers' Trust

SurePath's trust story depends on giving the customer visibility and records: it logs every AI interaction, generates audit trails, and redacts sensitive data before it leaves for a model. SurePath states in its FAQ that it holds both SOC 2 Type I and Type II attestations, controls that ease procurement rather than guaranteeing outcomes. Its trust center at trust.surepath.ai showed an access-request gate with no openly listed certifications in the February 2025 capture.

F5 now positions the combined platform for regulated environments with data-residency and sovereignty requirements. \[[s3](#deep-dive-sources), [s4](#deep-dive-sources), [s8](#deep-dive-sources), [s9](#deep-dive-sources), [s1](#deep-dive-sources)\]

### Platform Strategy & Ecosystem Positioning

SurePath's design is an ecosystem play by construction: it brokers access between users and many public and private models, routes traffic to approved models, and traces connections to agent tools and MCP servers. It positioned itself as the control point between the workforce and the growing set of AI services rather than as a single-model tool.

F5 now uses that control-point position inside a broader platform: it folded SurePath's discovery into a platform that also tests and protects AI, so SurePath's visibility feeds F5's red-teaming and runtime protection rather than standing alone. \[[s3](#deep-dive-sources), [s4](#deep-dive-sources)\]

### Team & Execution Capability

SurePath AI was founded in 2023 by Casey Bleeker, who led as chief executive, and Randy Birdsall, its chief product officer, and grew to about nineteen people before the acquisition. The founders are publicly identifiable in relevant senior roles.

The record does not show a prior exit or a sustained public research or engineering profile for the team beyond SurePath itself. A team of that size building a product a strategic acquirer wanted between its 2023 founding and mid-2026 is a credible execution signal, though not the independently recognized track record a stronger team credential would require. \[[s2](#deep-dive-sources), [s5](#deep-dive-sources)\]

## Sources

### Company Detail Sources

Cited from the Sourced Details and Matrix Coverage rows.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | [SurePath AI: Govern workforce use of GenAI](https://www.surepath.ai) | official | 2026-07-09 |
| f2 | [F5 press release: F5 acquires SurePath AI to enhance new AI Security Platform](https://www.f5.com/company/news/press-releases/f5-ai-security-platform-control-enterprise-risk) | official | 2026-07-04 |
| f3 | [GeekWire on the F5 acquisition (founding year)](https://www.geekwire.com/2026/f5-expands-further-into-ai-security-with-surepath-ai-acquisition/) | press | 2026-07-04 |
| f4 | [AI Defense Matrix Catalog mapping](https://catalog.aidefensematrix.com/products/surepath-ai/) | other | 2026-07-04 |

### Profile Analysis Sources

Cited from the Market Readiness section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [SurePath AI homepage (now part of F5), Ben Shupe (COO, C&R Software) customer testimonial](https://www.surepath.ai) “SurePath AI is now a part of F5” | official | 2026-07-04 |
| s2 | [SurePath AI about page (founders Casey Bleeker, CEO, and Randy Birdsall, CPO)](https://www.surepath.ai/company/about) “In 2023, as GenAI exploded onto the scene, businesses faced a critical paradox: allow transformative technology with significant risks or fall behind.” | official | 2026-07-04 |
| s3 | [SurePath AI solutions: contain shadow AI, adopt private models, protect data](https://www.surepath.ai/solutions) “Giving you a branded portal with built-in access controls and guardrails” | official | 2026-07-04 |
| s4 | [F5 press release: F5 AI Security Platform launch and SurePath AI acquisition](https://www.f5.com/company/news/press-releases/f5-ai-security-platform-control-enterprise-risk) “With frictionless deployment through network redirects and out-of-band analysis, SurePath AI gives security teams a unified visibility layer that detects unauthorized AI activity, classifies the intent behind each workflow, and continuously traces agent tool calls and MCP server connections.” | official | 2026-07-04 |
| s5 | [GeekWire: F5 expands further into AI security with SurePath AI acquisition (article names CalypsoAI as F5's prior AI purchase)](https://www.geekwire.com/2026/f5-expands-further-into-ai-security-with-surepath-ai-acquisition/) “Denver-based SurePath, founded in 2023 and led by co-founder Casey Bleeker as CEO, had about 19 employees and had raised roughly $6 million in venture funding, according to PitchBook.” | press | 2026-07-04 |
| s6 | [Security MEA: F5 Acquires SurePath AI to Enhance New AI Security Platform](https://securitymea.com/2026/06/29/f5-acquires-surepath-ai-to-enhance-new-ai-security-platform/) “F5 also announced the acquisition of SurePath AI, a pioneer in network-based AI discovery, intent classification, and shadow AI detection, as a key component in the launch of the new F5 AI Security Platform.” | press | 2026-07-04 |
| s7 | [SurePath AI entry in the AI Defense Matrix Catalog (SaaS, SOC 2 Type 1, prompt inspection and redaction)](https://catalog.aidefensematrix.com/products/surepath-ai/) “SurePath AI, deployment SaaS, compliance attestations SOC 2 Type 1. Captures AI traffic at the network level without endpoint agents to reveal which AI services are in use, and enforces role- and group-based access policies controlling which models, tools, and data each user can reach.” | other | 2026-07-04 |
| s8 | [SurePath AI FAQ, browser-rendered, states SOC 2 Type I and Type II compliance with completed independent audits](https://www.surepath.ai/frequently-asked-questions) “SurePath AI is both SOC 2 Type I and Type II compliant.” | official | 2026-07-08 |
| s9 | [SurePath AI Trust Center, browser-rendered, request-access form only, no publicly visible certification list or documents](https://trust.surepath.ai) “SurePath AI's Trust Center. First name. Last name. Email. Company name. Reason. Request access. Already have access? Reclaim access.” | official | 2026-07-08 |

### Deep-Dive Sources

Cited from the Strategy Deep Dive section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [SurePath AI homepage (now part of F5), Ben Shupe (COO, C&R Software) customer testimonial](https://www.surepath.ai) “SurePath AI is now a part of F5” | official | 2026-07-04 |
| s2 | [SurePath AI about page (founders Casey Bleeker, CEO, and Randy Birdsall, CPO, founded 2023)](https://www.surepath.ai/company/about) “In 2023, as GenAI exploded onto the scene, businesses faced a critical paradox: allow transformative technology with significant risks or fall behind.” | official | 2026-07-04 |
| s3 | [SurePath AI solutions: contain shadow AI, adopt private models, protect data](https://www.surepath.ai/solutions) “Giving you a branded portal with built-in access controls and guardrails” | official | 2026-07-04 |
| s4 | [F5 press release: F5 AI Security Platform launch and SurePath AI acquisition](https://www.f5.com/company/news/press-releases/f5-ai-security-platform-control-enterprise-risk) “With frictionless deployment through network redirects and out-of-band analysis, SurePath AI gives security teams a unified visibility layer that detects unauthorized AI activity, classifies the intent behind each workflow, and continuously traces agent tool calls and MCP server connections.” | official | 2026-07-04 |
| s5 | [GeekWire: F5 expands further into AI security with SurePath AI acquisition (article names CalypsoAI as F5's prior AI purchase)](https://www.geekwire.com/2026/f5-expands-further-into-ai-security-with-surepath-ai-acquisition/) “Denver-based SurePath, founded in 2023 and led by co-founder Casey Bleeker as CEO, had about 19 employees and had raised roughly $6 million in venture funding, according to PitchBook.” | press | 2026-07-04 |
| s6 | [Security MEA: F5 Acquires SurePath AI to Enhance New AI Security Platform](https://securitymea.com/2026/06/29/f5-acquires-surepath-ai-to-enhance-new-ai-security-platform/) “F5 also announced the acquisition of SurePath AI, a pioneer in network-based AI discovery, intent classification, and shadow AI detection, as a key component in the launch of the new F5 AI Security Platform.” | press | 2026-07-04 |
| s7 | [SurePath AI entry in the AI Defense Matrix Catalog (SaaS, SOC 2 Type 1, prompt inspection and redaction)](https://catalog.aidefensematrix.com/catalog.json) “SurePath AI, deployment SaaS, compliance attestations SOC 2 Type 1. Captures AI traffic at the network level without endpoint agents to reveal which AI services are in use, and enforces role- and group-based access policies controlling which models, tools, and data each user can reach.” | other | 2026-07-04 |
| s8 | [SurePath AI FAQ, browser-rendered, states SOC 2 Type I and Type II compliance with completed independent audits](https://www.surepath.ai/frequently-asked-questions) “SurePath AI is both SOC 2 Type I and Type II compliant.” | official | 2026-07-08 |
| s9 | [SurePath AI Trust Center, browser-rendered, request-access form only, no publicly visible certification list or documents](https://trust.surepath.ai) “SurePath AI's Trust Center. First name. Last name. Email. Company name. Reason. Request access. Already have access? Reclaim access.” | official | 2026-07-08 |

## Disclaimer

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.
