Invariant Labs
Invariant Labs built a security and observability platform for autonomous AI agents and Model Context Protocol deployments, offering guardrails, trace debugging, and vulnerability scanning. The ETH Zurich spin-off was acquired by Snyk in June 2025.
- Company typePrivate
- Founded2024
- HeadquartersZürich, Switzerland
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Invariant Labs does
Invariant Labs AG is a Zürich-based AI security company founded in 2024 as an official ETH Zurich spin-off, acquired by Snyk in June 2025. The company built a security and observability platform for autonomous AI agents and Model Context Protocol (MCP) deployments, targeting agent builders, enterprise security teams, and AI safety researchers. Its product portfolio included Guardrails (a contextual security layer enforcing deterministic rules on tool calls, MCP interactions, and data flows), Explorer (a trace visualization and debugging tool), MCP-Scan (a scanner for MCP server vulnerabilities including Tool Poisoning Attacks and rug pulls), Gateway (a zero-configuration proxy intercepting LLM traffic), Testing (an open-source unit testing library for agents), and AgentDojo (a NeurIPS 2024 benchmark framework with 97 tasks and 629 security test cases).
The underlying technology combines a research-grade formal security analyzer, an MCP-aware vulnerability scanner, and a transparent proxy architecture that sits between agents and LLM providers (OpenAI, Anthropic, Gemini) to enforce policy without requiring code changes. Distribution was primarily product-led through open-source channels (PyPI, GitHub, uvx), supplemented by an early-access enterprise program for Guardrails and a partnership with Smithery embedding MCP-Scan into the MCP server registry. Revenue mechanics were subscription-recurring for the planned Guardrails platform, but pricing was not publicly disclosed and the platform remained in early-access mode at acquisition. Post-acquisition, the company's tools and research team have been integrated into Snyk Labs to extend Snyk's AI Trust Platform.
Invariant Labs firmographics
Firmographics- Name
- Invariant Labs
- Legal name
- Invariant Labs AG
- Website
- https://invariantlabs.ai
- Company type
- Private
- Founded year
- 2024
- Operating status
- Acquired
- Headcount range
- 1–10 employees
- Short description
- Invariant Labs built a security and observability platform for autonomous AI agents and Model Context Protocol deployments, offering guardrails, trace debugging, and vulnerability scanning. The ETH Zurich spin-off was acquired by Snyk in June 2025.
- Ownership category
- akta.pro rank
Invariant Labs industry classification
Industry- Product category
- AI Agent Security Software
- NAICS
- Security Systems Services (except Locksmiths) (561621), Computer Systems Design and Related Services (5415)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Secure Model Deployment & Runtime Protection (sandboxing, isolation) (HDAAAKAH)
- akta.pro secondary industries
- AI Application Enablement Platforms (Copilot/Agent Frameworks, SDKs) (HDAEANAJ), App Security, Compliance & Review Automation Platforms (BPAMADAJ)
Keywords
Where Invariant Labs is headquartered
LocationHeadquarters
- HQ city
- Zürich
- HQ country
- Switzerland
- HQ region
- Europe
Offices1 record
Markets served
Invariant Labs business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure
Revenue model
- SaaS Platform Subscription: Early access platform for Guardrails security layer. Likely subscription-based model for enterprise security platform with per-seat or usage-based pricing.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Monthly | Early Access |
Go-to-market motion2 records
Distribution channels5 records
Marketing channels6 records
Invariant Labs product offering
Product offeringCore offering
Invariant Labs builds a software platform for securing, testing, observing, and debugging AI agent systems. Its core products include Invariant Guardrails (a contextual security layer for AI agents), Invariant Explorer (an observability tool for agent traces), Invariant Gateway (a transparent LLM proxy), and MCP-Scan (a security scanner for Model Context Protocol servers). The platform targets agent builders, enterprise security teams, and AI safety researchers with both open-source developer tools and an enterprise Guardrails product.
Product overview
Invariant Labs is an AI security company focused on making AI agents work. The product portfolio centers on the Invariant platform — a comprehensive stack for securing, testing, observing, and debugging AI agents. The flagship product is Invariant Guardrails, a contextual security layer that enforces deterministic rules on agent actions, MCP interactions, and data flows. Guardrails is deployed transparently via Invariant Gateway, which proxies all LLM traffic between agents and providers (OpenAI, Anthropic, Gemini). The platform also includes Invariant Explorer for observability and trace visualization, MCP-Scan for scanning MCP server vulnerabilities, Invariant Testing for unit testing AI agents, and AgentDojo for benchmarking agent security and utility. Following acquisition by Snyk in June 2025, these products are being integrated into Snyk's AI Trust Platform. All major components (Explorer, Testing, Gateway, MCP-Scan) are open source and available on GitHub.
Differentiator
Problem solved
Functional benefit
Brands
- Explorer: Observability tool for visualizing and analyzing AI agent traces.
- Guardrails
- MCP Scan
- Testing
- Gateway
- AgentDojo
Products and services
- Invariant Guardrails A state-of-the-art contextual security layer for AI agents that enforces expressive deterministic security rules on tool calls, MCP interactions, data flows, and content. Deployed as a transparent security layer via Gateway proxy, enabling agent builders to augment existing models without code changes.
- Invariant Explorer An observability tool for visualizing, inspecting, and analyzing AI agent traces in an intuitive visual interface. Enables step-by-step trace visualization, annotation, filtering, and collaborative debugging. Supports integration with GitHub for sharing traces in issues and PRs.
- MCP-Scan A security scanner for the Model Context Protocol (MCP) that identifies tool poisoning attacks, rug pulls, cross-origin escalation attacks, and prompt injection vulnerabilities in MCP server tool descriptions. Includes built-in tool pinning to detect unauthorized changes to tool descriptions.
- Invariant Gateway A lightweight, zero-configuration proxy service that acts as an intermediary between AI agents and LLM providers (OpenAI, Anthropic, Gemini). Automatically traces agent interactions and stores them in Explorer, enabling monitoring, debugging, and security enforcement without code changes.
- Invariant Testing An open-source library for debuggable unit testing of AI agents. Enables test-driven agent development by creating controlled environments for edge cases, stress scenarios, and performance benchmarks. Available via the invariant-ai PyPI package.
- AgentDojo A framework for jointly benchmarking the utility and security resilience of AI agents under prompt injection attacks. Contains 97 realistic tasks and 629 security test cases across office work, Slack, banking, and travel environments. Co-developed with ETH Zurich, presented at NeurIPS 2024.
Quantifiable outcome
- Achieved 16% improvement on WebArena benchmark by analyzing and fixing common agent failure modes
- +2 more outcomes
Companies that use Invariant Labs
Customer profileNamed customers1 record
Segments3 records
Ideal customer profiles3 records
Invariant Labs technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration16 records
AI capability10 records
Feature6 records
Invariant Labs partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered flagship and core.
- SnykflagshipSnyk acquired Invariant Labs to enhance its AI Trust Platform and establish Snyk Labs. Acquisition includes Invariant Labs' research team and security tools focused on agentic AI vulnerabilities, including tool poisoning and MCP vulnerabilities.
- SmitherycoreSmithery integrated Invariant's MCP-Scan tool to protect their MCP server registry users from security vulnerabilities. All MCP servers on Smithery are now scanned for vulnerabilities, with results displayed on each server's registry page.
Scale indicators5 records
Recent moves7 records
Expansion highlights5 records
Invariant Labs competitors and assessment
Company assessmentDirect peers
- Lakera: Lakera builds enterprise-grade guardrails for LLM applications, including prompt injection defense (Gandalf) and agent security tooling. It competes most directly with Invariant Guardrails for the agent/AI security budget.
- Protect AI: Protect AI offers a platform for AI/ML model and application security, including scanning, guardrails, and observability. It targets similar enterprise buyers concerned with AI-specific threats.
- HiddenLayer: HiddenLayer provides AI security solutions covering model theft, adversarial input detection, and AI threat defense — overlapping with Invariant's anomaly detection and runtime protection capabilities.
Emerging players
- CalypsoAI: CalypsoAI focuses on AI security posture management and guardrails for generative AI and agent systems. It is an emerging competitor with similar enterprise security buyers and use cases.
- Arize AI: Arize AI provides LLM/agent observability, tracing, and evaluation — closely adjacent to Invariant Explorer and Gateway, though focused on performance/quality rather than security.
- WhyLabs: WhyLabs offers LLM and ML observability with security-adjacent anomaly detection. It targets similar engineering and platform teams building LLM applications in production.
- NeuralTrust: NeuralTrust provides AI security and trust tooling for LLM applications, including prompt injection defense and agent observability. It is a smaller European emerging player competing for the same agent security buyers.
Broad incumbents
- Robust Intelligence: Robust Intelligence (acquired by Cisco) builds AI application security including model firewalls and adversarial robustness — a now-incumbent comparable to Invariant's Guardrails and MCP-Scan offerings.
- Snyk: Snyk acquired Invariant Labs and now operates it as Snyk Labs within its AI Trust Platform. As the parent, Snyk sets distribution, pricing, and roadmap context for all Invariant products.
- Palo Alto Networks (Prisma Cloud / AI Security): Palo Alto Networks is rapidly embedding AI/agent security capabilities into Prisma Cloud and Cortex. It is a broad incumbent that can absorb Invariant-style capabilities into a much larger security suite.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
Invariant Labs social profiles
Digital presenceInvariant Labs compliance and trust
Trust signalCompliance1 record
Invariant Labs financial estimates
Financial estimateRevenue estimate
Valuation estimate
Invariant Labs leadership team
Management profileNumber of profiles
Profiles7 records
Invariant Labs funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Invariant Labs M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Invariant Labs
What does Invariant Labs do?
Invariant Labs builds a software platform for securing, testing, observing, and debugging AI agent systems. Its core products include Invariant Guardrails (a contextual security layer for AI agents), Invariant Explorer (an observability tool for agent traces), Invariant Gateway (a transparent LLM proxy), and MCP-Scan (a security scanner for Model Context Protocol servers). The platform targets agent builders, enterprise security teams, and AI safety researchers with both open-source developer tools and an enterprise Guardrails product.
Is Invariant Labs a public or private company?
Invariant Labs is a private company. It is classified as corporate owned and is currently acquired.
When was Invariant Labs founded?
Invariant Labs was founded in 2024. It employs 1 to 10 people.
Where is Invariant Labs based?
Invariant Labs is headquartered in Zürich, Switzerland, in the Europe region.
How does Invariant Labs make money?
One revenue line is on record: saaS Platform Subscription.
Who are Invariant Labs's main competitors?
Direct peers on record are Lakera, Protect AI and HiddenLayer. Emerging players are CalypsoAI, Arize AI, WhyLabs and NeuralTrust. Broad incumbents are Robust Intelligence, Snyk and Palo Alto Networks (Prisma Cloud / AI Security).
Does Invariant Labs have an API?
Yes. Invariant Labs provides API access through its Explorer platform, which supports programmatic trace uploads via a REST API. MCP-Scan uses the Invariant Guardrails API to analyze tool descriptions for malicious instructions. Gateway acts as a transparent proxy API that intercepts LLM-level interactions and routes them through Invariant's security stack. Users can authenticate using Bearer tokens via the 'Invariant-Authorization' header and route requests through Gateway endpoints. Explorer API enables pushing traces programmatically to the platform. Developer documentation is at github.com/invariantlabs-ai/invariant.
What industry is Invariant Labs in?
Invariant Labs's product category is AI Agent Security Software. Its primary akta.pro industry code is HDAAAKAH, Secure Model Deployment & Runtime Protection (sandboxing, isolation), with a secondary code of HDAEANAJ, AI Application Enablement Platforms (Copilot/Agent Frameworks, SDKs). Its NAICS code is 561621 and its SIC code is 7372.