Brixo
Skip to main content
Back to Security Agents
ProtectAI logo

ProtectAI

Prisma AIRS is the world’s most comprehensive AI security platform. It's natively integrated and uses best-in-class security to secure the entire AI attack lifecycle for every AI app, agent, models and dataset your business uses or builds. It empowers organizations to deploy AI bravely knowing that whatever they build is secure.

Visit Website

Founded

2022

Location

Santa Clara, CA

Employees

46

Funding

$35M Series B

Protect AI (Now Part of Palo Alto Networks) — Company Dossier

Overview

**Protect AI** is an AI security company focused on end-to-end model security and governance across the AI lifecycle—from pre-production testing to runtime protection. Its platform unified three core products:

  • **Guardian** for model scanning and governance
  • **Recon** for automated red teaming and safety testing
  • **Layer** for runtime detection and blocking
  • On July 22, 2025, Palo Alto Networks completed its acquisition of Protect AI and integrated its capabilities into Prisma AIRS, an enterprise AI security platform. See the official announcement from [Palo Alto Networks](https://www.paloaltonetworks.com/company/press/2025/palo-alto-networks-completes-acquisition-of-protect-ai).

  • Company site: [Protect AI](https://protectai.com)
  • About/Founding: [About Us](https://protectai.com/about-us)
  • What Protect AI Secures

  • Models and LLM applications (including multi-agent systems)
  • Model supply chain and governance metadata
  • Runtime traffic and agent behaviors
  • GenAI app safeguards (prompt injection, tool misuse, data exfiltration)
  • Core Products

  • [**Guardian**](https://protectai.com/guardian): Model scanning, policy controls, and governance. Helps enforce security policies, track model lineage, flag unsafe code and formats, and manage compliance artifacts.
  • [**Recon**](https://protectai.com/recon): Automated red teaming and safety testing for GenAI apps and agents; includes scenario generation, attack simulation, and reporting. Recon was strengthened via the [SydeLabs acquisition](https://protectai.com/newsroom/protect-ai-acquires-sydelabs).
  • [**Layer**](https://protectai.com/layer): Runtime protection that detects and blocks prompt injection, tool abuse, sensitive data leakage, and abnormal agent behavior.
  • Learn more at the [Protect AI homepage](https://protectai.com).

    Integrations and Alliances

    Protect AI prioritized alignment with major AI platforms and MLOps stacks:

  • [Amazon Bedrock and SageMaker](https://protectai.com/newsroom/protect-ai-announces-integration-with-amazon-bedrock)
  • [Databricks Data Intelligence Platform](https://protectai.com/databricks) (mapped to the Databricks AI Security Framework)
  • [Dataiku](https://protectai.com/blog/strengthening-ai-security-protect-ai-dataiku)
  • Broader ecosystem: [Technology Alliances](https://protectai.com/tech-alliances)
  • Public sector collaboration: [Leidos partnership](https://protectai.com/newsroom/protect-ai-and-leidos-secure-government-systems)
  • Open Source and Research

  • [ModelScan](https://protectai.com/modelscan): Open-source model file scanner to detect malicious or unsafe artifacts.
  • Threat research: [Model serialization risks](https://protectai.com/threat-research/model-files-are-invisible-viruses).
  • Why automated GenAI red teaming matters: [Protect AI blog](https://protectai.com/blog/why-automated-red-teaming-is-essential-for-genai-security).
  • Who It’s For

  • Security, risk, and compliance teams responsible for AI systems
  • ML/platform engineering teams building LLM apps, agents, and traditional ML models
  • Regulated industries with strict model governance requirements (finance, healthcare, critical infrastructure)
  • Public sector, defense, and contractors needing AI assurance
  • Primary Use Cases

  • Pre-production safety/security testing for LLM apps and agents via automated red teaming
  • Model scanning for unsafe code, policy violations, and supply chain risks
  • Governance and audit of model metadata, formats, lineage, and sources
  • Runtime protection against prompt injection, tool misuse, data exfiltration, and anomalous agent behavior
  • Advantages (Observed)

  • Broad end-to-end coverage across model scanning, red teaming, and runtime in a single platform: [Guardian](https://protectai.com/guardian), [Recon](https://protectai.com/recon), [Layer](https://protectai.com/layer)
  • Strong integrations with major AI stacks: [Amazon Bedrock/SageMaker](https://protectai.com/newsroom/protect-ai-announces-integration-with-amazon-bedrock), [Databricks](https://protectai.com/databricks), [Dataiku](https://protectai.com/blog/strengthening-ai-security-protect-ai-dataiku)
  • Deep focus on automated red teaming for GenAI and agents: [Recon](https://protectai.com/recon)
  • Government credibility through the [Leidos collaboration](https://protectai.com/newsroom/protect-ai-and-leidos-secure-government-systems)
  • Active research and open-source posture: [ModelScan](https://protectai.com/modelscan), [threat research](https://protectai.com/threat-research/model-files-are-invisible-viruses)
  • Considerations (Buyer Notes)

  • Limited third-party customer reviews (e.g., G2/Capterra) publicly available at time of review; community discussion tends to be news-focused (e.g., this [Reddit thread](https://www.reddit.com/r/ArtificialInteligence/comments/1kaj8gt/palo_alto_networks_acquiring_protect_ai_to_boost/)).
  • Enterprise deployment may require cross-team coordination (security, ML, IT) for integrations and policy governance: [Guardian](https://protectai.com/guardian), [Alliances](https://protectai.com/tech-alliances).
  • Post-acquisition naming, packaging, and support are evolving within Prisma AIRS; confirm current SKUs, SLAs, and pricing with [Palo Alto Networks](https://www.paloaltonetworks.com/company/press/2025/palo-alto-networks-completes-acquisition-of-protect-ai).
  • Buying and Pricing

  • No public free trial or list pricing found. Expect an enterprise sales motion.
  • Use the [Protect AI site](https://protectai.com) contact flow or engage via Palo Alto Networks and Prisma AIRS for current purchasing paths.
  • Fast Facts

  • Focus: AI model security and governance across the lifecycle
  • Core products: [Guardian](https://protectai.com/guardian), [Recon](https://protectai.com/recon), [Layer](https://protectai.com/layer)
  • Integrations: [Amazon Bedrock/SageMaker](https://protectai.com/newsroom/protect-ai-announces-integration-with-amazon-bedrock), [Databricks](https://protectai.com/databricks), [Dataiku](https://protectai.com/blog/strengthening-ai-security-protect-ai-dataiku)
  • Partnerships: [Leidos](https://protectai.com/newsroom/protect-ai-and-leidos-secure-government-systems)
  • Open source: [ModelScan](https://protectai.com/modelscan)
  • Acquisition: Palo Alto Networks completed acquisition on July 22, 2025
  • Founded: 2022; leadership with backgrounds from Amazon and Oracle
  • Related Reading

  • Company: [Protect AI](https://protectai.com)
  • Products: [Guardian](https://protectai.com/guardian) • [Recon](https://protectai.com/recon) • [Layer](https://protectai.com/layer)
  • Integrations: [Amazon Bedrock/SageMaker](https://protectai.com/newsroom/protect-ai-announces-integration-with-amazon-bedrock) • [Databricks](https://protectai.com/databricks) • [Dataiku](https://protectai.com/blog/strengthening-ai-security-protect-ai-dataiku) • [Alliances](https://protectai.com/tech-alliances)
  • Research/Open Source: [ModelScan](https://protectai.com/modelscan) • [Model file threats](https://protectai.com/threat-research/model-files-are-invisible-viruses)
  • Public sector: [Leidos partnership](https://protectai.com/newsroom/protect-ai-and-leidos-secure-government-systems)
  • Corporate development: [SydeLabs acquisition](https://protectai.com/newsroom/protect-ai-acquires-sydelabs) • [Palo Alto Networks acquisition](https://www.paloaltonetworks.com/company/press/2025/palo-alto-networks-completes-acquisition-of-protect-ai)
  • Related Companies

    CalypsoAI logo

    CalypsoAI

    CalypsoAI is an adaptive AI security platform that empowers enterprises to innovate safely—staying ahead of evolving threats to deliver unmatched protection and performance. As a trusted global leader, CalypsoAI partners with organizations of all sizes to responsibly unlock AI’s full potential. Founded in Silicon Valley in 2018 by the most talented minds in AI, data science and machine learning, CalypsoAI has established key partnerships with some of the world’s largest companies and secured backing from investors including Paladin Capital Group, Lockheed Martin Ventures, Lightspeed Venture Partners, 8VC, Hakluyt Capital and Empros Capital. The company has raised $38.2 million to date.

    Dropzone AI logo

    Dropzone AI

    Dropzone AI is the first AI SOC analyst that autonomously investigates alerts 24/7. It integrates with existing tools, adapts to your environment, and generates decision-ready reports. You can focus on real threats and 10X your team without adding headcount. No playbooks, code, or prompts required.

    HiddenLayer logo

    HiddenLayer

    HiddenLayer, a Gartner-recognized Cool Vendor for AI Security, is the leading provider of Security for AI. Its AISec Platform unifies supply chain security, runtime defense, posture management, and automated red teaming to protect agentic, generative and predictive AI applications. The platform enables organizations across the private and public sectors to reduce risk, ensure compliance, and adopt AI with confidence. Founded by a team of cybersecurity and machine learning veterans, HiddenLayer combines patented technology with industry-leading research to defend against prompt injection, adversarial manipulation, model theft, and supply chain compromise. The company is backed by strategic investors including M12 (Microsoft’s Venture Fund), Moore Strategic Ventures, Booz Allen Ventures, IBM Ventures, and Capital One Ventures.

    Lakera logo

    Lakera

    Lakera is the world’s leading real-time GenAI security company. Customers rely on the Lakera AI Security Platform for security that doesn’t slow down their AI applications. To accelerate secure adoption of AI, the company created Gandalf, an educational platform, where more than one million users have learned about AI security. Lakera uses AI to continuously evolve defenses, so customers can stay ahead of emerging threats. Join us to shape the future of intelligent computing: www.lakera.ai/careers

    Mindgard logo

    Mindgard

    Mindgard is the leading provider of AI security solutions. Spun out from over a decade of AI security research at Lancaster University and headquartered in Boston and London, Mindgard helps enterprises secure their AI models, agents, and applications across the AI lifecycle. AI introduces risks that traditional security tools cannot detect, leaving organizations unable to find, measure, or secure their AI. Security teams struggle with a lack of visibility into AI activity and its attack surfaces. Difficulty reproducing agentic AI behavior creates uncertainty and compliance challenges. Ultimately, an inability to enforce AI controls heights the risk of compromise. Mindgard delivers AI detection and response through attack-driven defense, giving enterprises the ability to map their AI attack surface, measure and validate AI risk, and actively defend their AI. - Visibility into AI inventory and activity reveals what attackers can find out about your AI. - Continuous and automated AI red teaming assesses how attackers can exploit your AI. - Enforcement controls and policies at runtime stops attackers from breaching your AI. Mindgard stands out for its: - Flexibility: Test AI models directly or via apps using CI/CD, our web UI, or tools like Burp Suite. - Usability: The only non-open-source AI red teaming platform, fast and easy to set up, test, and report with. - R&D pipeline: Backed by a decade of university research and active PhD-level innovation and publishing. Mindgard works with the AI models and guardrails you build, buy and use. Extensive coverage beyond LLMs, including image, audio, and multi-modal. Whether you are using open source, internally developed, 3rd party purchased, or popular LLMs like OpenAI, Claude, Bard, we’ve got you covered. Trusted by leading organizations in finance, healthcare, and technology, Mindgard is backed by investors including .406 Ventures, IQ Capital, Atlantic Bridge, and Lakestar. For more information, visit mindgard.ai

    Nexusflow logo

    Nexusflow

    Nexusflow Solution enables Generative AI agents that surpass GPT-4 in your workflow and continuously automatically update with security guardrails.