Gray Swan
Gray Swan is an AI security company that provides adversarial evaluation and runtime protection for AI models and agents, serving frontier AI labs and global enterprises through automated red-teaming, runtime monitoring, and a 15,000+ researcher community.
- Company typePrivate
- Founded2023
- HeadquartersPittsburgh, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Gray Swan does
Gray Swan is a Pittsburgh-based AI security company founded in 2023 as a Carnegie Mellon University spinout by professors Matt Fredrikson and Zico Kolter. The company builds a platform for adversarial evaluation and runtime protection of AI models and agents, serving two primary customer segments: frontier AI labs (Anthropic, OpenAI, Meta, Google DeepMind, xAI, ByteDance) that require independent pre-release safety evaluations, and global enterprises (Snowflake, Amazon, Deloitte, ElevenLabs, Intercom, among 20+ customers) deploying AI agents in production.
The technical platform consists of three interconnected products: Shade, an automated adversarial testing solution powered by LLM-based adversarial agents that runs attacks against AI models and agents in pre-deployment and CI/CD pipelines; Cygnal, a runtime protection and monitoring service that classifies and blocks adversarial inputs and unsafe outputs in production; and Arena, a community-driven red-teaming network of 15,000+ researchers generating more than one million real-world attack trajectories that continuously inform product capabilities. The portfolio also includes the ARTEMIS automated penetration testing framework, proprietary benchmarks (ART, IPI, AgentHarm, WMDP), the RepE Chat research demo, and the open-source nanoGCG toolkit.
Gray Swan monetizes through enterprise subscriptions for Cygnal and Shade, usage-based per-token API services, multi-year private red-teaming engagements staffed by hand-selected Arena experts, and an embedded distribution partnership with Snowflake's AI ecosystem. Go-to-market combines enterprise field sales to CISOs and security decision-makers, an API-first self-serve developer channel, and community-led growth via Arena competitions. The company raised a $40M Series A in May 2026 at a $200M post-money valuation, co-led by Wing Venture Capital and Madrona with participation from Snowflake Ventures, Obvious Ventures, Hudson River Trading, Samsung Next, and Magarac Venture Partners.
Gray Swan firmographics
Firmographics- Name
- Gray Swan
- Legal name
- Gray Swan Security Inc.
- Website
- https://grayswan.ai
- Company type
- Private
- Founded year
- 2023
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Gray Swan is an AI security company that provides adversarial evaluation and runtime protection for AI models and agents, serving frontier AI labs and global enterprises through automated red-teaming, runtime monitoring, and a 15,000+ researcher community.
- Ownership category
- akta.pro rank
Gray Swan industry classification
Industry- Product category
- AI Security Platform
- NAICS
- Security Systems Services (except Locksmiths) (561621)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Model Security Testing & Red Teaming (adversarial ML, jailbreaks) (HDAAAKAC)
- akta.pro secondary industries
- Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII) (HDAEANAG), Safety & Alignment Evaluation (red-teaming, harmful capability testing) (HDAAAMAL), AI Observability, Monitoring & Evaluation Platforms (Drift, Quality, Safety) (HDAEANAF)
Keywords
Where Gray Swan is headquartered
LocationHeadquarters
- HQ city
- Pittsburgh
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Gray Swan business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Cygnal Platform: Real-time AI monitoring and protection with custom policies enforced 24/7. Subscription or usage-based pricing for runtime security services.
- Shade Platform: Automated adversarial testing as part of pre-deployment testing and CI/CD pipeline integration.
- API Services: Programmatic access to AI security services with per-token pricing model. Customers pay based on API usage volume.
- Private Red-Teaming Services: Dedicated adversarial assessment scoped to specific customer deployments, with hand-selected expert red teamers from Arena network.
- Snowflake Integration: Native integration with Snowflake's AI ecosystem enabling enterprises to embed Gray Swan's AI security capabilities directly into the platform where enterprises build and scale AI applications.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Usage-based | Pay-as-you-go | API Services with per-token pricing |
| Subscription | Annual | Enterprise Platform Subscription |
| Other | Multi-year contract | Private Red-Teaming Engagement |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels4 records
Gray Swan product offering
Product offeringCore offering
Gray Swan is an AI security platform that provides adversarial testing and runtime protection for AI systems. Its core offerings include Shade for automated pre-deployment adversarial testing, Cygnal for real-time production monitoring and blocking of adversarial inputs, and Arena, a global red-teaming network with over 15,000 researchers generating continuous threat intelligence. The platform is complemented by private AI red-teaming services and adversarial evaluation benchmarks used by frontier AI labs before model release.
Product overview
Gray Swan is an AI security platform providing a unified portfolio of products and services for adversarial testing and runtime protection of AI systems. The core platform consists of three interconnected products: Shade (automated adversarial testing for pre-deployment), Cygnal (runtime monitoring and protection in production), and Arena (global red-teaming network with 15,000+ researchers generating threat intelligence). These are powered by research benchmarks including ART, IPI, AgentHarm, and WMDP. The platform is complemented by private AI red-teaming services, adversarial evaluation for frontier labs, and open-source tools like nanoGCG. The company emerged from CMU research and serves leading frontier AI labs including Anthropic, OpenAI, and Meta.
Differentiator
Problem solved
Functional benefit
Brands
- Arena: The world's largest adversarial AI red-teaming network with over 15,000 researchers.
- Shade
- Cygnal
- Cygnet
- RepE Chat
- Proving Ground
Products and services
- Shade Automated adversarial testing and red-teaming solution that runs AI red team agents against models and agents as part of pre-deployment testing and CI/CD pipelines. Powers automated attack strategies discovered through the Arena network.
- Cygnal Runtime protection and monitoring solution that classifies and blocks adversarial inputs and unsafe outputs in production. Trained on attacks discovered by the security research team and global red-teaming network with continuous agentic monitoring and vulnerability testing.
- Arena World's largest adversarial AI red-teaming network with over 15,000 researchers and security professionals. Generates threat intelligence powering Shade and Cygnal, producing over one million high-quality real-world attack trajectories.
- Adversarial Evaluation Pre-release model safety testing using automated adversarial testing, crowdsourced intelligence, priority benchmarking, and private AI red-teaming. Includes ART (Agent Red-Teaming) and IPI (Indirect Prompt Injection) benchmarks used by frontier AI labs before model release.
- AI Red-Teaming Service Private red-teaming engagements with hand-selected adversarial experts drawn from top Arena performers. Scoped to specific AI deployments with threat modeling, executive summaries, reproducible transcripts, and prioritized remediation roadmaps.
Quantifiable outcome
- Attack success rate range from 0.5% (Claude Opus 4.5) to 8.5% (Gemini 2.5 Pro) across 13 frontier models tested in IPI Arena
- +3 more outcomes
Companies that use Gray Swan
Customer profileNamed customers7 records
Segments3 records
Ideal customer profiles3 records
Gray Swan technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration1 record
AI capability8 records
Feature6 records
Gray Swan partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered minor and core.
- OperativeminorPartnership to integrate AI-based data visualization and observability into Operative's revenue platforms for media companies. Collaboration enables real-time insights, performance monitoring, and revenue optimization across linear, streaming, and digital media.
- US AI Safety InstitutecoreJoined UK AISI Agent Red-Teaming Challenge as co-judge alongside UK AISI. Helped evaluate submissions focused on AI agent failures, instruction bypass, misuse risk, and over-refusals.
- UK AI Security InstitutecoreMain sponsor and judging partner for UK AISI Agent Red-Teaming Challenge. Provided funding and crucial expertise, helping calibrate automated judging and handling manual break appeal reviews. Challenge was the largest public evaluation of agentic LLM safety to date.
- OpenAIcoreCo-sponsor of UK AISI Agent Red-Teaming Challenge with $171,800 prize pool. Customer for Arena red-teaming platform. Zico Kolter sits on OpenAI Foundation's board as chair of the safety committee.
- AnthropiccoreCo-sponsor of UK AISI Agent Red-Teaming Challenge. Customer for safety evaluations on Claude models. Arena challenge sponsor.
- Google DeepMindcoreCo-sponsor of UK AISI Agent Red-Teaming Challenge. Arena challenge sponsor. Research collaboration on adversarial attacks (co-authored GCG algorithm).
Scale indicators9 records
Recent moves7 records
Expansion highlights6 records
Gray Swan competitors and assessment
Company assessmentDirect peers
- Protect AI: AI/ML security platform offering model scanning, supply chain security, and adversarial robustness testing. Similar positioning around securing the AI lifecycle for enterprises.
- HiddenLayer: AI security platform providing adversarial threat protection, model scanning, and red-teaming for ML systems and LLM applications. Closely comparable product suite targeting enterprise CISOs and AI developers.
- Lakera: AI security company focused on prompt injection defense, LLM guardrails, and red-teaming for production AI applications. Competes directly in the runtime protection and pre-deployment testing categories.
- CalypsoAI: AI security and governance platform providing adversarial testing, observability, and policy enforcement for generative AI applications. Overlaps with Gray Swan's Cygnal runtime monitoring and Shade testing offerings.
Broad incumbents
- Cisco AI Defense: Cisco's AI security portfolio (built on the acquired Robust Intelligence platform) offering model scanning, runtime protection, and adversarial testing for enterprise AI deployments. Broad incumbent that bundles AI safety into enterprise security stacks.
- Microsoft Azure AI Content Safety: Microsoft's native AI safety service providing content filtering, jailbreak detection, and prompt injection guardrails for Azure OpenAI and enterprise AI deployments. Competes on runtime protection as a bundled platform capability.
- AWS Bedrock Guardrails: Amazon's built-in safety controls for Bedrock-hosted foundation models, including content filters and policy enforcement for generative AI applications. Bundled alternative to standalone AI security platforms.
- Google Cloud Vertex AI Safety: Google's AI safety features integrated into Vertex AI, including model evaluation, content safety filters, and responsible AI tooling. Competes with Gray Swan on enterprise AI safety infrastructure.
- Databricks AI Security (Mosaic AI): Databricks' AI governance and safety features including model evaluation, AI guardrails, and lakehouse-integrated monitoring. Competes at the enterprise data/AI platform layer similar to Gray Swan's Snowflake partnership motion.
Emerging players
- PromptArmor: Early-stage startup focused on prompt injection detection and AI agent security monitoring. Smaller niche overlap with Gray Swan's Cygnal runtime protection capabilities.
Market position
Strengths1 record
Weaknesses1 record
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Gray Swan social profiles
Digital presenceGray Swan compliance and trust
Trust signalCompliance2 records
Gray Swan financial estimates
Financial estimateRevenue estimate
Valuation estimate
Gray Swan leadership team
Management profileNumber of profiles
Profiles5 records
Gray Swan funding detail
Funding detailFunding overview
Funding rounds1 record
Investors7 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Gray Swan M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Gray Swan
What does Gray Swan do?
Gray Swan is an AI security platform that provides adversarial testing and runtime protection for AI systems. Its core offerings include Shade for automated pre-deployment adversarial testing, Cygnal for real-time production monitoring and blocking of adversarial inputs, and Arena, a global red-teaming network with over 15,000 researchers generating continuous threat intelligence. The platform is complemented by private AI red-teaming services and adversarial evaluation benchmarks used by frontier AI labs before model release.
Is Gray Swan a public or private company?
Gray Swan is a private company. It is classified as venture growth investor backed and is currently operating.
When was Gray Swan founded?
Gray Swan was founded in 2023. It employs 11 to 50 people.
Where is Gray Swan based?
Gray Swan is headquartered in Pittsburgh, United States, in the North America region.
How does Gray Swan make money?
Five revenue lines are on record. Cygnal Platform is the primary driver. The others are shade Platform, API Services, private Red-Teaming Services and snowflake Integration.
Who are Gray Swan's main competitors?
Direct peers on record are Protect AI, HiddenLayer, Lakera and CalypsoAI. Broad incumbents are Cisco AI Defense, Microsoft Azure AI Content Safety, AWS Bedrock Guardrails, Google Cloud Vertex AI Safety and Databricks AI Security (Mosaic AI). PromptArmor is listed as an emerging player.
Does Gray Swan have an API?
Yes. Gray Swan offers API Services that permit programmatic use of the AI Services. The API Services are described at https://grayswan.ai/cygnet, which includes pricing information. Customers choosing to use the API Services pay fees as described on that page. Access begins once payment is received. Developer documentation is at docs.grayswan.ai.
What industry is Gray Swan in?
Gray Swan's product category is AI Security Platform. Its primary akta.pro industry code is HDAAAKAC, Model Security Testing & Red Teaming (adversarial ML, jailbreaks), with a secondary code of HDAEANAG, Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII). Its NAICS code is 561621 and its SIC code is 7373.