Protect AI
Protect AI is a Seattle-based AI security company (founded 2022, acquired by Palo Alto Networks in July 2025) that provides Guardian, Recon, and Layer—an end-to-end platform for scanning, red-teaming, and runtime protection of AI/ML models—targeting enterprises in financial services, biotech, telecom, and government.
- Company typePrivate
- Founded2022
- HeadquartersSeattle, United States
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What Protect AI does
Protect AI is a Seattle-based cybersecurity company founded in 2022 that built an end-to-end AI security platform covering the entire machine learning application lifecycle—from model selection and testing through deployment and runtime monitoring. The core product suite consists of three products on a unified platform: Guardian (pre-deployment AI model security, scanning first- and third-party models for vulnerabilities), Recon (scalable automated red teaming for LLM and generative AI applications, identifying vulnerabilities through adversarial testing), and Layer (runtime security providing real-time threat detection and response for production AI systems). Two open-source tools—ModelScan and LLM Guard (acquired via Laiyer AI in January 2024)—extended the platform into developer workflows, while community assets (huntr bug bounty platform and the MLSecOps community with 17,000+ security researchers and 8,000+ practitioners respectively) provided a continuous vulnerability research and threat intelligence flywheel.
The company sold primarily to enterprise customers in financial services, biotechnology/life sciences, telecommunications, and government/defense—verticals with high AI adoption and elevated security/compliance stakes. Go-to-market combined direct enterprise field sales with a Channel Partner Program launched in February 2025 targeting security and AI-focused resellers, plus deep technology integrations with major platforms including Hugging Face (Guardian scans the entire Hugging Face hub covering 1M+ foundational models), AWS (Bedrock and SageMaker), Databricks (Mosaic AI Model Serving), Microsoft (Pegasus Program), and Leidos (U.S. government). Protect AI operated on subscription-based enterprise licensing with quote-based annual contracts supplemented by professional services for implementation; pricing was customized to deployment scale and number of AI models secured.
Protect AI raised approximately $108.5M in total equity funding across a $13.5M seed (December 2022), a $35M Series A (July 2023), and a $60M Series B (August 2024), reaching a $650-700M post-money valuation at Series B. The company executed three strategic acquisitions—huntr (August 2023, bug bounty platform), Laiyer AI (January 2024, LLM Guard), and SydeLabs (July 2024, automated red teaming)—to assemble its platform. In April 2025 Palo Alto Networks announced an agreement to acquire Protect AI for approximately $500-700M to integrate its capabilities into the Prisma AIRS platform; the acquisition closed in July 2025, making Protect AI a wholly-owned subsidiary of Palo Alto Networks (NYSE: PANW).
Protect AI firmographics
Firmographics- Name
- Protect AI
- Legal name
- Protect AI
- Website
- https://protectai.com
- Company type
- Private
- Founded year
- 2022
- Operating status
- Acquired
- Headcount range
- 51–100 employees
- Short description
- Protect AI is a Seattle-based AI security company (founded 2022, acquired by Palo Alto Networks in July 2025) that provides Guardian, Recon, and Layer—an end-to-end platform for scanning, red-teaming, and runtime protection of AI/ML models—targeting enterprises in financial services, biotech, telecom, and government.
- Ownership category
- akta.pro rank
Protect AI industry classification
Industry- Product category
- AI Security Software
- NAICS
- Software Publishers (5132)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII) (HDAEANAG)
- akta.pro secondary industries
- Prompt Security & Injection Defense (HDAAAKAE), Model Security Testing & Red Teaming (adversarial ML, jailbreaks) (HDAAAKAC), Secure Model Deployment & Runtime Protection (sandboxing, isolation) (HDAAAKAH), Responsible AI, AI Governance & Compliance Services (BPAEAHAJ), Third-Party Model/Vendor Risk & Supply-Chain Assurance (HDAAAMAK)
Keywords
Where Protect AI is headquartered
LocationHeadquarters
- HQ city
- Seattle
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Protect AI business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Platform Software Licenses: Subscription-based licensing of the Protect AI security platform including Guardian, Recon, and Layer products. Enterprise contracts with pricing based on usage and deployment scale.
- Professional Services: Implementation and consulting services for enterprise customers deploying the platform. Includes training, integration support, and security assessments.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise subscription with customizable tiers based on organizational needs |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels7 records
Protect AI product offering
Product offeringCore offering
Protect AI provides an end-to-end AI security platform with three core products — Guardian for AI model scanning, Recon for automated red teaming of LLM applications, and Layer for runtime AI threat protection — supported by open-source tools (ModelScan, LLM Guard) and community platforms (huntr bug bounty, MLSecOps Community). The offering is sold to enterprises deploying AI/ML systems in financial services, biotech, telecom, and government sectors via annual subscriptions.
Product overview
Protect AI is a comprehensive AI security platform offering three core products—Guardian, Recon, and Layer—operating on a unified platform that secures AI applications from model selection and testing through runtime and beyond. Guardian provides AI model security with zero compromises, scanning models for vulnerabilities before use. Recon enables scalable red teaming for AI systems, automating security assessments and vulnerability discovery. Layer delivers runtime security for AI with deep visibility and instant threat response. The platform also includes open-source tools (ModelScan, LLM Guard) and community platforms (huntr bug bounty, MLSecOps Community) that leverage 17,000+ security researchers. Protect AI was acquired by Palo Alto Networks in July 2025 and its capabilities are now integrated into Palo Alto's Prisma AIRS platform.
Differentiator
Problem solved
Functional benefit
Brands
- Guardian: AI Model Security with Zero Compromises - comprehensive security for AI models
- Recon
- Layer
- MLSecOps
- huntr
- ModelScan
- LLM Guard
Products and services
- Guardian AI Model Security platform that scans first- and third-party AI/ML models for threats and blocks unsafe models from usage by ML teams; used as the scanner for the entire Hugging Face hub covering more than 1 million foundational models. Targeted at enterprise security and ML teams.
- Recon Scalable automated red-teaming platform for AI that rigorously tests and evaluates AI applications and LLMs for vulnerabilities; integrates with Databricks Mosaic AI Model Serving endpoints and Dataiku Agents. Targeted at enterprise AI/ML and security teams.
- Layer Runtime Security platform for AI that stops AI threats instantly at runtime with deep visibility and control for AI applications in production. Targeted at enterprise security operations teams deploying AI applications.
- ModelScan Open-source tool for scanning AI/ML model files for malicious code, backdoors, and other security risks prior to deployment. Available to developers and ML practitioners.
- LLM Guard Open-source framework providing real-time protection for Large Language Models against prompt injection, data leakage, and malicious inputs via input/output validation guards. Available to developers and AI application teams.
- huntr World's first bug bounty platform specifically for AI/ML security, hosting 17,000+ security researchers who discover and report AI/ML vulnerabilities and submit CVE records. Targeted at AI/ML vendors and security researchers.
- Sightline AI/ML vulnerability database providing comprehensive tracking of AI-specific vulnerabilities and threats for organizations deploying AI systems. Targeted at enterprise security and AI risk teams.
Quantifiable outcome
- 4,840,000+ model versions scanned
- +2 more outcomes
Companies that use Protect AI
Customer profileNamed customers4 records
Segments4 records
Ideal customer profiles5 records
Protect AI technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration6 records
AI capability7 records
Feature8 records
Protect AI partnerships and signals
Strategic signalPartnerships
Ten partnerships are on record, tiered flagship, core and minor.
- Hugging FaceflagshipProtect AI and Hugging Face partnered to enable safe and trusted delivery of ML models to the global AI community. Protect AI's Guardian is now used as a scanner for the entire Hugging Face hub, providing comprehensive security alerts and deep insights into the safety of more than 1 million foundational models.
- Amazon Web Services (AWS)flagshipUsing Protect AI's Guardian and Recon products, customers can secure generative AI models in Amazon Bedrock and Amazon SageMaker at every stage of the AI workflow. Deep integration with AWS AI services.
- LeidoscoreCollaboration to strengthen security for AI systems used by U.S. government agencies. Combines Leidos' expertise in secure digital transformation with Protect AI's platform to enhance end-to-end protection against AI threats.
- MicrosoftcorePart of the Microsoft Pegasus Program for startups, combining innovative products for securing AI systems with Microsoft's vast infrastructure to enable the mission of safeguarding AI systems from emerging threats.
- DatabricksflagshipIntegration of Protect AI's Recon with Databricks Mosaic AI Model Serving endpoints, enabling enterprises to harness advanced red-teaming capabilities to proactively identify vulnerabilities and ensure compliance with AI governance standards.
- CISA (Cybersecurity and Infrastructure Security Agency)coreParticipated in the federal government's inaugural AI tabletop exercise with government and industry partners, focusing on effective responses to AI security incidents.
- OASIS Coalition for Secure AIminorProtect AI joined as a Premier Sponsor of the Coalition for Secure AI, working with organizations committed to advancing AI security standards and best practices.
- FINOS (FINOS Financial Open Source)minorNew Platinum Member of FINOS, collaborating on the AI Governance Framework for Financial Institutions alongside key financial services and AI industry leaders.
- Laiyer AIcoreAcquired Laiyer AI in January 2024 to strengthen capabilities in LLM content filtering and security. Laiyer AI's LLM Guard technology provides real-time protection against prompt injection, data leakage, and malicious inputs.
- SydeLabscoreAcquired SydeLabs in July 2024, a Bangalore-based AI security company specializing in automated red teaming for generative AI systems. SydeBox product rebranded as Protect AI Recon.
Scale indicators10 records
Recent moves6 records
Expansion highlights6 records
Protect AI competitors and assessment
Company assessmentDirect peers
- HiddenLayer: HiddenLayer provides AI application security, including model scanning, adversarial defense, and AI threat detection for enterprises. Directly comparable to Protect AI's Guardian and Layer products serving similar enterprise security buyers.
- Robust Intelligence: AI security platform providing model validation, adversarial testing, and runtime protection for ML systems. Direct competitor to Protect AI, now part of Cisco, overlapping heavily in financial services and enterprise AI deployment.
- Lakera: Lakera specializes in LLM security, prompt injection defense, and AI red teaming with products like Gandalf. Direct competitor in the LLM and GenAI application security segment overlapping with Protect AI's Recon and LLM Guard capabilities.
- TrojAI: TrojAI provides AI/ML security testing and trojan detection for models, with focus on defense and government applications. Overlaps with Protect AI's Recon red teaming and Guardian model scanning capabilities.
- Calypso AI: Calypso AI offers AI security testing, model risk management, and adversarial robustness for enterprise AI deployments. Directly comparable to Protect AI in providing red teaming and continuous AI security testing.
Emerging players
- Arize AI: Arize AI provides AI observability and evaluation platform for ML/LLM applications, with adjacent security and drift detection capabilities. Emerging player in the broader AI trust and safety space overlapping with Protect AI's runtime monitoring.
- WhyLabs: WhyLabs offers AI observability and monitoring for ML models with security and data quality features. Emerging player with partial overlap to Protect AI's runtime AI security and anomaly detection capabilities.
Broad incumbents
- Palo Alto Networks: Palo Alto Networks is now Protect AI's parent company and offers the Prisma AIRS AI security platform incorporating the acquired Protect AI technology. Broad incumbent in cybersecurity with extensive enterprise distribution and competing in-house AI security capabilities.
- Microsoft: Microsoft provides Azure AI Content Safety, Azure AI Studio security features, and broader cloud security through Defender for Cloud. Broad incumbent with native AI security capabilities competing with Protect AI on Azure enterprise workloads and a former Pegasus Program partner.
- Cisco: Cisco acquired Robust Intelligence to add AI security to its security portfolio and offers broader networking and security solutions. Broad incumbent with overlapping AI security capabilities for enterprise and government customers.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key highlights7 records
Customer concentration
Protect AI social profiles
Digital presenceProtect AI compliance and trust
Trust signalCompliance3 records
Protect AI financial estimates
Financial estimateRevenue estimate
Valuation estimate
Protect AI leadership team
Management profileNumber of profiles
Profiles6 records
Protect AI subsidiaries and ownership
Company hierarchySubsidiaries3 records
Protect AI funding detail
Funding detailFunding overview
Funding rounds3 records
Investors11 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Protect AI M&A and investment
M&A and investmentM&A3 records
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Protect AI
What does Protect AI do?
Protect AI provides an end-to-end AI security platform with three core products — Guardian for AI model scanning, Recon for automated red teaming of LLM applications, and Layer for runtime AI threat protection — supported by open-source tools (ModelScan, LLM Guard) and community platforms (huntr bug bounty, MLSecOps Community). The offering is sold to enterprises deploying AI/ML systems in financial services, biotech, telecom, and government sectors via annual subscriptions.
Is Protect AI a public or private company?
Protect AI is a private company. It is classified as venture growth investor backed and is currently acquired.
When was Protect AI founded?
Protect AI was founded in 2022. It employs 51 to 100 people.
Where is Protect AI based?
Protect AI is headquartered in Seattle, United States, in the North America region.
How does Protect AI make money?
Two revenue lines are on record. Platform Software Licenses are the primary driver. The others are professional Services.
Who are Protect AI's main competitors?
Direct peers on record are HiddenLayer, Robust Intelligence, Lakera, TrojAI and Calypso AI. Emerging players are Arize AI and WhyLabs. Broad incumbents are Palo Alto Networks, Microsoft and Cisco.
Does Protect AI have an API?
No public API is recorded for Protect AI.
What industry is Protect AI in?
Protect AI's product category is AI Security Software. Its primary akta.pro industry code is HDAEANAG, Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII), with a secondary code of HDAAAKAE, Prompt Security & Injection Defense. Its NAICS code is 5132 and its SIC code is 7372.