CalypsoAI Review (2026)
Inference-layer AI security acquired by F5 in September 2025. Announced at $180M, it actually closed at $145.2M according to F5's own SEC filing - a detail worth knowing about how these deals get reported.
Rating
Starting Price
Not published
Free Plan
No
SDKs & Frameworks
3
Deployment
3
Best For
Enterprises already buying F5 for application delivery and security, who want AI guardrails integrated into that platform rather than as a separate vendor relationship.
Last Updated:
10 Things You Should Know About CalypsoAI
- 1 F5 announced its intention to acquire CalypsoAI on 11 September 2025 for $180 million
- 2 The acquisition closed on 26 September 2025 for $145.2 million in cash, per F5's FY2026 Form 10-Q
- 3 CalypsoAI became a wholly-owned subsidiary of F5 on closing
- 4 Founded in 2018 in Dublin, Ireland, having raised over $40 million
- 5 Investors included Paladin Capital Group, Lockheed Martin Ventures and Hakluyt Capital
- 6 Placed second at the RSAC Conference Innovation Sandbox in 2025
- 7 It was F5's fourth acquisition of 2025, following Fletch, MantisNet and LeakSignal
Pros & Cons
Pros
- ✓ Genuinely differentiated position at the inference layer rather than as an application-side library
- ✓ Combines offensive testing (red teaming at scale) with runtime defence, which few competitors do in one product
- ✓ Recognised independently, placing second at the RSAC Conference Innovation Sandbox in 2025
- ✓ F5 ownership brings serious enterprise distribution, support and procurement standing
- ✓ Agentic AI coverage rather than text-completion-only filtering
Cons
- ✕ No standalone product or pricing - it is now a capability inside F5's platform, so you are buying F5
- ✕ Nothing published on cost, and the buying process is enterprise sales through F5
- ✕ Proprietary, not open source, and not self-hostable independently of F5's platform
- ✕ Independent evaluation is now very difficult, since it is no longer sold or documented as a standalone product
- ✕ Roadmap is set by F5's platform strategy rather than by AI security customers directly
Features
The number in the filing is not the number in the headline
F5 announced its intention to acquire CalypsoAI on 11 September 2025 for $180 million.
F5’s own FY2026 Form 10-Q records that the acquisition closed on 26 September 2025 for $145.2 million in cash, with CalypsoAI immediately becoming a wholly-owned subsidiary.
That is a roughly 19% gap, and it is worth flagging beyond this one deal.
Almost all coverage of AI security M&A quotes announcement figures. Those figures routinely fold in retention packages, earnouts or equity components that never appear in the closing cash consideration. If you are trying to understand what this segment is actually worth - which matters if you are assessing whether your vendor is likely to be acquired next - SEC filings are a materially better source than press releases.
What F5 bought
CalypsoAI delivered real-time threat defence, red teaming at scale, and data security for enterprises deploying generative and agentic AI, describing itself as a full-lifecycle platform securing AI models and applications at the inference layer.
Two things there are genuinely differentiated.
Inference-layer positioning. Sitting where the model is called, rather than inside application code, means coverage does not depend on which team remembered to import your library. Every call is visible regardless of the client’s language or owner. For a large enterprise with many teams shipping AI features at different speeds, that is a substantial architectural advantage - and the same argument that makes gateways attractive.
Offensive plus defensive in one product. Most guardrails only filter. CalypsoAI combined runtime protection with systematic red teaming at scale, so you find weaknesses before an attacker does rather than trusting your filter to catch everything. Giskard does something comparable in open source, and Lakera has Lakera Red, but the pairing is uncommon and is the more interesting half of the acquisition.
It placed second at the RSAC Conference Innovation Sandbox in 2025, which is meaningful independent recognition in security.
Founded 2018 in Dublin, it had raised over $40 million from investors including Paladin Capital Group, Lockheed Martin Ventures and Hakluyt Capital.
You are buying F5 now
There is no standalone product. CalypsoAI is being integrated into the F5 Application Delivery and Security Platform, with no independent pricing and no standalone documentation of the kind you would need to evaluate it separately.
This was F5’s fourth acquisition of 2025, after Fletch (agentic SOC intelligence), MantisNet (network observability) and LeakSignal (AI data protection) - a deliberate portfolio build, not an opportunistic purchase.
So the evaluation changes shape:
- Already an F5 customer? This is straightforwardly good. A capability you might buy separately arrives inside a platform you run, with procurement solved.
- Not an F5 customer? You now have to adopt a large application delivery vendor to get an AI guardrail. That is a far bigger commitment than an API subscription.
The roadmap concern is ordinary but real: priorities are now set by F5’s platform strategy rather than by AI security buyers.
The structural story this is part of
CalypsoAI is not an isolated case, and the pattern is the most important thing on this page.
| Acquirer | Target |
|---|---|
| F5 | CalypsoAI |
| Check Point | Lakera |
| SentinelOne | Prompt Security |
| CrowdStrike | Pangea |
| Cisco | Robust Intelligence |
Reporting indicates that Cato Networks, Check Point, CrowdStrike, F5 and SentinelOne agreed in September alone to spend a combined $1.31 billion on AI security, across roughly a dozen deals.
The independent guardrails vendor is close to extinct. Guardrails are being absorbed into network and endpoint security platforms, which means the realistic choice for buyers is narrowing to two options: an incumbent security vendor’s bundle, or an open-source library you run yourself.
If you want a specialist independent API, the window on that is closing, and it is worth factoring into a multi-year decision.
Should you use it?
Use it if you are an F5 customer and want AI guardrails inside the platform you already run.
Don’t use it if you are not - adopting F5 to get a guardrail is a large commitment, and Lakera (managed) or NeMo Guardrails and Guardrails AI (free, open source) are more proportionate.
Bottom line: genuinely good technology, particularly the inference-layer positioning and the red teaming, now only available as part of something much larger. Rated on availability as a standalone choice rather than on capability - if you are an F5 shop, mentally add a point.
Acquisition dates and values verified against F5’s press release and its FY2026 Form 10-Q filing on 3 August 2026; the announced and closing figures differ and both are reported here. No standalone pricing is published. This is a researched directory entry - we have not instrumented this platform with our reference application.
Pricing Plans
Enterprise
Not published
- Now sold as part of the F5 Application Delivery and Security Platform
- No standalone public pricing
- Contact F5 sales
SDKs & Frameworks
Deployment
Eval Methods
Corporate Status
Our Verdict
CalypsoAI is no longer a product you buy, it is a capability inside F5's platform, and that reframes the evaluation entirely. F5 announced the acquisition on 11 September 2025 at $180 million and closed it on 26 September for $145.2 million in cash - a discrepancy visible in F5's own FY2026 10-Q and a useful reminder that announced deal values and closing values are different numbers. What F5 bought was real - real-time threat defence, red teaming at scale, and data security for generative and agentic AI, positioned at the inference layer rather than as an application-side library, and second place at RSAC's Innovation Sandbox in 2025. It was F5's fourth acquisition of the year, after Fletch, MantisNet and LeakSignal, so this is a deliberate portfolio build rather than an opportunistic buy. The practical consequence is that you cannot evaluate CalypsoAI on its own merits any more. You are evaluating F5, and the question is whether you want your AI guardrails from your application delivery vendor.
Similar Tools
Prompt Security
Existing SentinelOne customers who want GenAI runtime protection inside their endpoint security platform, and any team where agents calling MCP servers is a live security concern.
LLM Guard
Nobody adopting fresh. Existing users should plan a migration. The code remains a reasonable reference implementation or fork base for teams that will own it.
Arthur
Teams that want open-source guardrails running inside their own stack with the option of an inexpensive managed tier, and who value published pricing and unlimited seats.
Fiddler AI
Regulated enterprises that need guardrails running inside their own environment, particularly those already running predictive ML alongside LLM systems, and who can work with enterprise procurement.
Frequently Asked Questions
Why do the two deal values differ?
Because announced and closing values are genuinely different numbers, and this is a clean example. F5 announced its intention to acquire CalypsoAI on 11 September 2025 for $180 million. F5's own FY2026 Form 10-Q records that the acquisition closed on 26 September 2025 for $145.2 million in cash. We are highlighting it because most coverage of AI security M&A quotes announcement figures, and those figures routinely include retention packages, earnouts or equity components that do not appear in the closing cash consideration. If you are trying to understand what this segment is actually worth, SEC filings are a better source than press releases - the difference here is roughly 19%.
Can I still buy CalypsoAI on its own?
Not meaningfully. It became a wholly-owned F5 subsidiary on closing, and the technology is being integrated into the F5 Application Delivery and Security Platform. There is no standalone public pricing and no independent product documentation of the kind you would need to evaluate it separately. Practically, buying this capability means buying F5, and the relevant question is whether you want AI guardrails from your application delivery vendor rather than from a specialist.
What is inference-layer security and why does it matter?
It means sitting where the model is actually called rather than inside your application code. CalypsoAI described itself as a full-lifecycle platform securing AI models and applications at the inference layer. The practical advantage is coverage - an application-side library only protects the applications that import it, whereas something at the inference layer sees every call regardless of which team wrote the client or what language it is in. For a large enterprise with many teams shipping AI features at different speeds, that difference is significant, and it is the same architectural argument that makes gateways attractive.
What did the red teaming capability do?
Offensive testing at scale against deployed models and agents, which is a genuinely useful pairing with runtime defence. Most guardrails products only filter - they sit in the path and block things. Combining that with systematic adversarial testing means you find weaknesses before an attacker does, rather than relying on your filter catching everything in production. Giskard offers something comparable in the open-source world and Lakera has Lakera Red. Having both offensive and defensive capability in one product is uncommon and is the more interesting half of what F5 bought.
Should the F5 acquisition worry me?
It depends what you are optimising for. If you are already an F5 customer, this is straightforwardly good - a capability you might otherwise buy separately arrives inside a platform you already run, with procurement already solved. If you are not, you now have to adopt a large application delivery vendor to get an AI guardrail, which is a much bigger commitment than an API subscription. The roadmap concern is real but ordinary - it is now set by F5's platform strategy rather than by AI security buyers, so features that serve F5's broader portfolio will likely be prioritised over ones that serve you specifically.
What does this tell me about the guardrails market?
That the independent vendor is close to extinct in this segment. F5 bought CalypsoAI, Check Point bought Lakera, SentinelOne bought Prompt Security, CrowdStrike bought Pangea and Cisco bought Robust Intelligence. Reporting indicates Cato Networks, Check Point, CrowdStrike, F5 and SentinelOne agreed in September alone to spend a combined $1.31 billion on AI security across roughly a dozen deals. The consequence for buyers is structural - guardrails are being absorbed into network and endpoint security platforms, which means the realistic choice is increasingly between an incumbent security vendor's bundle and an open-source library you run yourself. The independent specialist API is disappearing as a category.