HiddenLayer Review (2026)
One of the last independent AI security vendors, and the only one here with a serious security research record - 48+ CVEs disclosed in ML frameworks. Still Series A while every direct competitor was bought by a security giant.
Rating
Starting Price
Not published
Free Plan
No
SDKs & Frameworks
3
Deployment
4
Best For
Enterprises and government buyers who need model supply chain security, AI asset discovery and airgapped operation, rather than application-layer output filtering.
Last Updated:
10 Things You Should Know About HiddenLayer
- 1 Founded in 2022 and based in Austin, Texas
- 2 Has raised roughly $56M across two rounds from seven investors and remains independent
- 3 The $50M Series A in September 2023 was led by M12, Microsoft's venture fund, and Moore Strategic Ventures
- 4 Other investors include Booz Allen Ventures, IBM Ventures, Capital One Ventures and Ten Eleven Ventures
- 5 Listed at 172 employees as of June 2026
- 6 The MLSec Platform branding was superseded by AISec, with AISec Platform 2.0 unveiled in April 2025
- 7 Has disclosed 48+ CVEs in ML frameworks and holds 25+ granted patents
- 8 Joined the Databricks Unity AI Gateway ecosystem and partnered with Cohere in June 2026
- 9 Selected as an awardee on the Missile Defense Agency's SHIELD IDIQ
Pros & Cons
Pros
- ✓ Genuine security research output - 48+ CVEs disclosed in ML frameworks and 25+ granted patents, which is substance rather than positioning
- ✓ One of very few independent AI security vendors remaining, so its roadmap is not set by a network security platform's strategy
- ✓ Model supply chain security addresses a real and under-covered risk, since a tampered model artefact bypasses every runtime guardrail you have
- ✓ Airgapped deployment and serious defence credentials, including selection on the Missile Defense Agency SHIELD IDIQ
- ✓ Agentless and model-agnostic, so deployment does not require instrumenting each application
- ✓ Strong strategic investor base including M12, IBM Ventures, Capital One Ventures and Booz Allen Ventures
Cons
- ✕ No published pricing of any kind, so it cannot be cost-compared without a sales process
- ✕ Still Series A at roughly $56M raised while direct competitors are now funded by Palo Alto, Cisco, Check Point and F5
- ✕ That capitalisation gap makes it an obvious acquisition target, and this segment's spotlight has already moved to the remaining independents
- ✕ Focused on model and infrastructure security rather than LLM output validation, so it does not replace an application-layer guardrail
- ✕ Aggregator sources carry a probable re-syndication of its 2023 round as fresh 2026 funding, so third-party financial data needs care
Features
A different problem from the rest of this category
Most guardrails here operate at the application layer. Lakera inspects prompts for injection. Guardrails AI validates outputs. Both assume the model itself is trustworthy and guard the traffic around it.
HiddenLayer secures the model and the pipeline that produced it. The AISec Platform covers:
- AI discovery - finding models deployed across your estate that nobody registered
- Supply chain security - checking artefacts for tampering
- Runtime defence - adversarial attack protection
- Attack simulation - offensive testing against deployed models
Model-agnostic and agentless, so deployment does not require instrumenting each application.
These are complementary concerns, not competing ones. And the supply chain piece addresses something the rest of this category structurally cannot: a tampered model artefact passes every output validator you have, because the output looks fine and the compromise happened upstream of everything you are checking.
Why the supply chain gap is real
Model artefacts are executable content that most organisations treat as data.
Teams pull weights from public hubs, fine-tune them, deploy the result - frequently with less scrutiny than they would apply to a third-party npm package. A tampered artefact can carry a payload that executes on load, or behaviour that triggers only under specific conditions.
No runtime guardrail catches this. By the time the model is answering, the compromise already happened.
This is the same class of problem as dependency confusion in software supply chains, and it is considerably less well defended in AI because the tooling is newer and the norms have not formed. Prompt Security’s MCP Gateway addresses the adjacent version of this for tool calls; HiddenLayer addresses it for the models themselves.
The credibility signal that counts
48+ CVEs disclosed in ML frameworks. 25+ granted patents.
This is the most useful thing on the page for anyone evaluating a security vendor.
Publishing CVEs means finding genuine vulnerabilities in widely used software and going through coordinated disclosure - slow, unglamorous work that cannot be manufactured with marketing spend. Very little in this category can point to comparable output.
When you are assessing a security product and cannot independently test its detection quality - which is the normal situation, since the vendors do not publish reproducible benchmarks and you cannot easily construct your own adversarial corpus - published vulnerability research is one of the few credible proxies for whether the team can do the work.
Independent, and undercapitalised
HiddenLayer was founded in 2022 in Austin, has raised roughly $56M across two rounds, and remains independent. The $50M Series A in September 2023 was led by M12 (Microsoft’s venture fund) and Moore Strategic Ventures, with Booz Allen Ventures, IBM Ventures, Capital One Ventures and Ten Eleven Ventures participating. Around 172 employees as of June 2026.
That investor list is strategically interesting - Microsoft, IBM, Capital One and Booz Allen are all potential acquirers or channel partners as much as financial backers.
Now the tension, stated plainly:
| Company | Status |
|---|---|
| Protect AI | → Palo Alto Networks |
| Robust Intelligence | → Cisco |
| Lakera | → Check Point |
| CalypsoAI | → F5 |
| Prompt Security | → SentinelOne |
| HiddenLayer | Independent, Series A, ~$56M |
Independence is a genuine virtue here, and we have criticised the acquired alternatives for exactly the reason it matters - their roadmaps now serve a network security platform’s strategy rather than AI security buyers.
But competing against those balance sheets and distribution channels on $56M is hard, and reporting indicates the M&A spotlight has already moved to the remaining independents. Assume acquisition is a plausible outcome within your contract term and ask what happens to your agreement if it occurs.
Recent traction
Genuine momentum in 2026, weighted toward defence and government:
- Databricks Unity AI Gateway ecosystem and a Cohere partnership for securing enterprise agentic AI, both June 2026
- Awardable status in the DoD Tradewinds Marketplace, June 2026
- Selected as an awardee on the Missile Defense Agency’s SHIELD IDIQ, supporting the Golden Dome initiative with airgapped AI security
Airgapped operation is rare in this category and is a real differentiator for defence, intelligence and heavily regulated buyers.
A caution on third-party data
We found a specific error worth flagging. One aggregator dated March 2026 describes a fresh $50 million round, but the details closely mirror the September 2023 Series A, and other 2026 profiles still list $56M total across two rounds.
That reads as re-syndicated old news rather than new funding. We have reported the $56M figure.
If funding status matters to your assessment - and in this segment it reasonably does, since it bears directly on acquisition likelihood - verify against the company’s own newsroom rather than an aggregator.
Should you use it?
Use HiddenLayer if model supply chain security, AI asset discovery or airgapped operation are your requirements, particularly in defence, government or regulated enterprise.
Don’t use it if you need application-layer output validation - that is Guardrails AI or NeMo - or you need published pricing to shortlist.
Bottom line: the most technically credible independent in AI security, working on a problem the application-layer guardrails cannot touch, with a research record that substantiates the claim. Pair it with an output validator rather than choosing between them, and go in assuming it may be acquired.
Funding, employee count, platform scope and 2026 partnerships verified against the company’s newsroom and third-party company databases on 3 August 2026. A conflicting aggregator report of fresh March 2026 funding appears to be a re-syndication of the 2023 round and has not been reported as new. Pricing is not published and has not been estimated. This is a researched directory entry - we have not instrumented this platform with our reference application.
Pricing Plans
AISec Platform
Not published
- Enterprise sales, no public rate card
- Model-agnostic and agentless
- Airgapped deployment available
- Contact sales
SDKs & Frameworks
Deployment
Eval Methods
Corporate Status
Our Verdict
HiddenLayer is the most technically credible independent left in AI security, and it solves a different problem from most of this category. Where Guardrails AI validates output and Lakera detects prompt injection, HiddenLayer secures models and the pipeline around them - AI discovery, supply chain security, runtime defence and attack simulation, all model-agnostic and agentless. Supply chain in particular is genuinely under-covered, because a tampered model artefact bypasses every runtime guardrail you have deployed. The credibility signal that matters is research output rather than marketing - 48+ CVEs disclosed in ML frameworks and 25+ granted patents is substance, and very little in this segment can point to comparable work. The tension is capital. It remains Series A at roughly $56M while Protect AI went to Palo Alto, Robust Intelligence to Cisco, Lakera to Check Point and CalypsoAI to F5. Independence is a real virtue in a consolidated market, but competing against acquirers' balance sheets on that base is hard, and it makes HiddenLayer a conspicuous target.
Similar Tools
Lakera
Teams that want managed, low-latency prompt injection defence with enterprise support and are comfortable with a proprietary API and an enterprise sales process.
NVIDIA NeMo Guardrails
Teams building conversational products where the risk emerges across a dialogue rather than in one message, and who want programmable, self-hosted, permissively licensed guardrails.
Aporia
Existing Coralogix customers, and teams that want AI observability and guardrails correlated with full-stack logs, metrics and traces rather than as a standalone layer.
CalypsoAI
Enterprises already buying F5 for application delivery and security, who want AI guardrails integrated into that platform rather than as a separate vendor relationship.
Frequently Asked Questions
How is this different from a guardrail like Lakera or Guardrails AI?
It secures the model and its supply chain rather than filtering what the model says. Lakera detects prompt injection in inputs, Guardrails AI validates outputs, and both operate at the application layer around a model you trust. HiddenLayer's AISec Platform covers AI discovery, supply chain security, runtime defence and attack simulation - finding models deployed across your estate that nobody registered, checking artefacts for tampering, and testing deployed models adversarially. These are complementary rather than competing concerns. A tampered model artefact will happily pass every output validator you have, because the output looks fine and the compromise is upstream of everything you are checking.
Why does model supply chain security matter?
Because model artefacts are executable content that most organisations treat as data. Teams pull weights from public hubs, fine-tune them, and deploy the result, frequently with less scrutiny than they would apply to a third-party npm package. A tampered artefact can carry a payload that executes on load, or behaviour that only triggers under specific conditions - and no runtime guardrail catches it, because by the time the model is answering, the compromise already happened. This is the same class of problem as dependency confusion in software supply chains, and it is considerably less well defended in AI because the tooling is newer.
What does the CVE record tell me?
That the research is real. HiddenLayer has disclosed 48+ CVEs in ML frameworks and holds 25+ granted patents. Publishing CVEs means finding genuine vulnerabilities in widely used software and going through coordinated disclosure, which is slow, unglamorous work that cannot be faked with marketing. Very little in this category can point to comparable output. When you are evaluating a security vendor and cannot independently test their detection quality - which is the normal situation - published vulnerability research is one of the few credible proxies for whether the team can actually do the work.
Should the Series A status worry me?
It is the central tension and worth being clear-eyed about. HiddenLayer has raised roughly $56M and remains independent, while Protect AI went to Palo Alto, Robust Intelligence to Cisco, Lakera to Check Point, CalypsoAI to F5 and Prompt Security to SentinelOne. Independence has genuine value here - the roadmap is set by AI security customers rather than by a network security platform's strategy, which is exactly the criticism we have levelled at the acquired alternatives. But competing against acquirers' balance sheets and distribution on a $56M base is hard, and reporting indicates the M&A spotlight has already moved to the remaining independents. Assume acquisition is a plausible outcome and ask what your contract says about it.
What does it cost?
Not published. HiddenLayer sells enterprise, with no public rate card, so assessing cost requires a sales process. We are recording this as not published rather than estimating. That is standard for this segment - Lakera, CalypsoAI, Prompt Security and Fiddler all withhold pricing too - but it means the entire commercial guardrails and AI security market is effectively opaque to a buyer doing self-directed comparison, and the only tools you can price yourself are the open-source ones.
Why the warning about third-party financial data?
Because we found a specific error worth avoiding. One aggregator dated March 2026 describes a fresh $50 million round, but the details closely mirror the September 2023 Series A announcement, and other 2026 profiles still list $56M raised in total across two rounds. That reads as a re-syndication of old news rather than new funding. We have reported the $56M total figure. If funding status matters to your assessment - and in this segment it reasonably might, since it bears on acquisition likelihood - verify against the company's own newsroom rather than an aggregator.