Gray Swan
Pittsburgh, USA
Frontier-lab red teaming (Shade) and runtime defense (Cygnal) trained on unpublished attacks.
Raised $40M Series A co-led by Wing and Madrona, May 2026
Startups securing models, agents, and LLM applications: red teaming, runtime guards, and agent identity.
12 companies. Catalog last reviewed 2026-08-23. Page copy reviewed 2026-08-23. Next review by 2026-09-23. Ordered by name. No paid placement.
AI security is the newest category here and the easiest to confuse with a booth label. This index maps companies whose primary product secures models, agents, and LLM applications: red teaming, runtime guards, and agent identity. A general-purpose SAST tool that added an LLM checkbox does not belong. Every entry carries a 2024 to 2026 proof-of-life signal recorded with a source link, and membership is taxonomy from the research pass.
What they build. The products here include model and agent red-teaming platforms, runtime prompt and tool-call guards, agent identity and authorization, and LLM-application firewalls. Some target builders shipping agents; others target enterprises that need an inventory of model use. Generic code scanners and GRC questionnaires about AI policy live in other directories.
Who this is for. Security engineers responsible for LLM and agent rollouts, founders comparing runtime guards versus red-team platforms, and investors who want companies whose main product is AI security rather than an add-on SKU.
How order works. Listings are the full live catalog slice for this primary category, sorted alphabetically by name. This is not a scored quality ranking and there is no paid placement. Aevral is a disclosed house listing under the same rules (coming soon, no pin). See /transparency.
Pittsburgh, USA
Frontier-lab red teaming (Shade) and runtime defense (Cygnal) trained on unpublished attacks.
Raised $40M Series A co-led by Wing and Madrona, May 2026
Austin, USA
Model scanner, attack simulation, and runtime firewall for agentic, generative, and predictive AI.
Selected to support the US DOE Prometheus initiative under the Genesis Mission, August 2026
Tel Aviv, Israel
Need-to-know access control so Copilots, coding agents, and MCP tools stop oversharing.
Raised $11M to ship need-to-know controls for enterprise AI, March 2025
Tel Aviv, Israel
Discovery, posture, automated red team, and gateway runtime for models and agents.
Published Securing Agentic AI: The Intent Security Framework, March 2026
London, United Kingdom
Attacker-style recon and automated red team for models, agents, IDEs, and the systems around them.
Raised $30M Series A led by Album VC, August 2026
New York, USA
AI-SPM, agent access control, red team, and AI-DR in one control plane for homegrown and SaaS agents.
Raised $100M Series B led by Evolution Equity Partners, July 2025
Miami, USA
Inventory, agentic red team, and self-improving runtime guardrails for the agent lifecycle.
Named a 2026 Gartner Cool Vendor in AI Software Security
New York, USA
MCP gateway plus identity, observability, and threat detection for enterprise agents.
Emerged from stealth with $11M seed from Khosla (Keith Rabois) and Felicis, November 2025
Mountain View, USA
Discover, adversarially test, and kill-switch AI agents and MCP connections in production.
Raised $64M Series A, taking total funding to $85M, June 2026
Menlo Park, USA
Continuous trust tests so enterprise agents stay reliable after they leave the lab.
Raised $17M Series A led by BrightMind Partners, November 2025
Mountain View, USA
Observe, control, and protect employees, models, apps, and agents from one AI security plane.
Raised $58M led by Sound Ventures, January 2026
New York, USA
Agent security that watches the decision, not just the prompt, across SaaS, cloud, and endpoint.
Raised $125M Series C led by Norwest, August 2026