Competitive Intelligence · September 2026

HiddenLayer:
The Agentic Security Bet

A market analysis, product and technology audit, PM critique, and mock product strategy for HiddenLayer — the AI security platform that just raised $100M to prove it can out-run three of its acquired rivals into the agentic era.

HEADQUARTERSAustin / Leander, TX
FOUNDED2022
TOTAL FUNDING~$156M
STATUSSeries B · ARR up 10x YoY
COVERAGEhiddenlayer.com
$156M
Total Funding
10x
ARR Growth, YoY
39
Patents Granted
$100M
Series B, Sep 2026
$2.83B
2026 AI Security Spend
50+
New Customers Signed

Who Is HiddenLayer?

HiddenLayer is an Austin-area (Leander, TX) cybersecurity startup, founded in 2022, that sells a single proposition to the enterprise: the models and agents you're putting into production are unaudited software with a novel attack surface, and nothing in your existing security stack — EDR, WAF, DLP, SIEM — was built to see it. Its AI Security Platform (AISec) spans the AI lifecycle: discovering shadow AI, scanning models before deployment, defending them at runtime, and red-teaming them continuously. In September 2026 it closed a $100M Series B, and its own numbers are the story: ARR up more than 10x in a year, 50+ new platform customers, and a customer list that reportedly includes a frontier model provider with 700M+ weekly users — almost certainly OpenAI or a peer at that scale, though HiddenLayer has not named the account.

Core Thesis HiddenLayer is one of the last sizable independent, full-lifecycle AI security platforms left standing. In the eighteen months before this report, three of its closest direct competitors — Protect AI, Robust Intelligence, and Lakera — were each acquired by a hyperscale security platform (Palo Alto Networks, Cisco, and Check Point respectively). That is either the best news HiddenLayer has had (less independent competition, "last neutral platform" positioning) or a warning about its own likely endgame — and probably both. The rest of this report is written with that tension as the central lens.

Leadership

👤

Chris "Tito" Sestito — CEO & Co-Founder

Formerly led threat research at Cylance (the endpoint-security pioneer acquired by BlackBerry), giving HiddenLayer's research-first identity a direct lineage. The company's public voice on agentic AI risk via podcasts and press.

👤

Mike Gesnaldo — Chief Revenue Officer

Runs go-to-market as the company pivots from a research-led, land-in-finance-and-government motion toward the broader enterprise and EMEA expansion the Series B is explicitly funding.

Public reporting is thin on the full founding team beyond Sestito; HiddenLayer's own materials emphasize the Cylance/adversarial-research pedigree over individual bios — a deliberate research-brand-over-founder-brand choice.

Evolution Timeline

2022
Founded in Texas
Launched to secure machine learning models — the pitch predates the ChatGPT-driven generative AI boom by several months, an early-mover advantage in framing.
2023
$50M Series A
Led by M12, Microsoft's venture fund — an early strategic signal that Microsoft saw model security as a category, not a feature.
2024
ShadowLogic research published; Automated Red Teaming launched
Disclosed a technique for planting codeless backdoors inside "safe" model formats (safetensors, ONNX, TensorFlow) by manipulating the computational graph itself — undermining the industry's format-safety assumption and directly justifying HiddenLayer's runtime and scanning products.
2025
Consolidation wave removes three peers
Palo Alto Networks acquires Protect AI, Cisco acquires Robust Intelligence, Check Point acquires Lakera. HiddenLayer becomes one of very few remaining independent, full-lifecycle AI security platforms of scale.
Early 2026
2026 AI Threat Landscape Report; AISec Platform 2.0
Publishes annual research report spotlighting the rise of agentic AI risk; ships a platform update adding context, visibility, and observability for enterprise AI security.
Sep 2026
$100M Series B
Led by Delta-v Capital with Ten Eleven Ventures, Morgan Stanley, M12, and Booz Allen Ventures. ARR up 10x YoY. Capital earmarked for sales/distribution, engineering, and EMEA expansion — and for two new products: Agentic Runtime Security and Agent Harness Security (for securing autonomous coding agents at runtime).

Industry Landscape & Competitive Positioning

Market Context

Gartner puts 2026 global spend on AI security tools at $2.83B — an 83% jump from 2025 — climbing to $4.78B in 2027 and roughly $7.7B by 2028. That is a real, fast-growing budget line, but it is still a rounding error next to the broader cybersecurity market, and Gartner's own analysts frame the driver bluntly: traditional tools "treat AI applications like any other software" and can't see AI-specific threats like prompt injection, model supply-chain compromise, or agentic misuse. The uncomfortable question for every vendor in this space, HiddenLayer included, is how much of that budget is genuinely new spend versus a reallocation that dries up once boards feel "covered" rather than actually protected.

Market Size

$2.83B (2026) → $4.78B (2027, +69%) → ~$7.7B (2028) per Gartner. AI Application Security is the largest sub-segment ($851M by 2027); AI Usage Control is the fastest-growing (+73%).

Consolidation Wave

Three of HiddenLayer's closest peers were acquired by platform vendors within roughly 18 months: Protect AI → Palo Alto Networks, Robust Intelligence → Cisco, Lakera → Check Point. Prompt Security was separately acquired by SentinelOne.

Fresh Capital Chasing the Same Wedge

Agent-native entrants Noma Security and Zenity have each raised $100M+, meaning HiddenLayer's "agentic security" pivot is a contested land grab, not a walk-in.

Competitive Map

CompanyModelMoatHiddenLayer OverlapThreat
Protect AI (Palo Alto Networks)Broad AI/ML security platformOpen-source tooling (ModelScan, LLM Guard, NB Defense), huntr.com bug bounty, now Palo Alto's distribution and bundling powerFull-platform: discovery, scanning, runtimeHIGH
Robust Intelligence (Cisco)Model validation + AI firewallFolded into Cisco AI Defense; rides Cisco's network-security install baseRuntime defense, red-teamingHIGH
Lakera (Check Point)LLM guardrails, prompt-injection detectionViral developer mindshare via the "Gandalf" prompt-injection game; now Check Point's channelRuntime guardrails — historically HiddenLayer's thinner spotHIGH
CalypsoAIModel validation & red-teaming, still independentDeep government/defense relationshipsAttack simulation, model risk scoringMEDIUM
Noma SecurityAgentic AI & data-pipeline security, built agent-native$100M+ raised in 2025–26; no legacy model-scanning baggage to maintainDirect collision on Agentic Runtime SecurityHIGH
ZenityAI agent governance (Copilot Studio, low-code agent builders)Deep ties into the Microsoft Copilot ecosystem; $100M+ raisedAgent Harness SecurityMEDIUM-HIGH
Hyperscaler-native guardrails (Azure AI Content Safety, Bedrock Guardrails, Google Model Armor)Bundled cloud featuresZero switching cost, billed alongside compute buyers already pay forBaseline runtime guardrails — the "good enough" substituteMEDIUM

Industry Trends Shaping HiddenLayer's Fate

🏦

Platform Vendors Are Buying, Not Building

Palo Alto, Cisco, Check Point, and SentinelOne each concluded it was faster to acquire AI-security depth than build it. That validates the category and removes independent alternatives — but it also means the buyer conversation increasingly starts with "what does our existing platform vendor already bundle for free," which is a harder pitch for a standalone vendor.

🤖

Agentic AI Is Moving Faster Than Its Own Security

HiddenLayer's own 2026 AI Threat Landscape Report found 1 in 8 reported AI breaches already linked to agentic systems, even though most enterprises describe agentic deployment as early-stage. Autonomous coding agents (Claude Code, Cursor, Copilot-style tools) are a new, largely unmonitored execution surface.

📋

Disclosure and Compliance Pressure Is Building

85% of organizations in HiddenLayer's survey support mandatory AI-breach disclosure, yet 53% admit withholding reports out of fear of backlash and 31% don't even know if they've been breached. The EU AI Act and NIST AI RMF are pushing toward auditable inventories (AIBOMs) as a baseline requirement, not a nice-to-have.

💸

Budget Growth Is Outrunning Budget Depth

91% of organizations added AI security budget for 2025, but 40%+ still allocate less than 10% of their total security spend to it. That's a market where the checkbox gets funded before the actual risk does — good for initial land deals, uncertain for expansion revenue.

Key Success Factors in This Domain

Lifecycle Breadth Without Model Access

Winning platforms cover discovery → supply chain → runtime → red-teaming without requiring model weights, retraining, or invasive integration — lowering the barrier for security teams who don't own the model.

Research Credibility That Feeds the Product

CVE disclosures, novel attack research (like ShadowLogic), and MITRE ATLAS alignment aren't marketing exercises when they directly become new detection signatures — they're the actual moat in a market where detection logic ages fast.

Beachheads in Regulated, High-Consequence Verticals

Finance, government/defense, and frontier AI labs need more than hyperscaler-bundled guardrails to satisfy model-risk-management and audit requirements — creating a durable wedge above the "good enough" tier.

Distribution — The Thing Most Startups Here Lack

Every acquired competitor in this space had strong technology and thin distribution. GTM scale, not detection accuracy, is what has actually decided outcomes in this category so far.

What HiddenLayer Actually Sells

The AISec Platform is organized around the AI lifecycle rather than around a single tool. HiddenLayer's own framing groups it into four pillars — Discovery, Supply Chain Security, Attack Simulation, and Runtime Security — with two newer modules (Agentic Runtime Security and Agent Harness Security) extending that coverage to autonomous agents specifically.

AI Discovery
Shadow AI inventory

Identifies AI applications, models, and assets across cloud and on-prem environments that security teams don't already know about — the prerequisite for everything downstream, and the module that most directly surfaces the "76% call shadow AI a definite/probable problem" finding from HiddenLayer's own research.

Supply Chain Security
Model Scanner

Static analysis across 35+ model formats (PyTorch, TensorFlow, ONNX, Keras, GGUF, pickle, safetensors) for malicious code injection, pickle deserialization exploits, and architecture-level backdoors, before a model reaches production. Ships as a GitHub Action and integrates into Azure AI Foundry, AWS SageMaker, Databricks Unity Catalog, and Hugging Face workflows.

Attack Simulation
Automated Red Teaming

Continuously simulates adversarial attacks against production models and agents, mapped to MITRE ATLAS tactics — effectively automating what used to be a manual, expensive, point-in-time pentest engagement.

Runtime Security
AI Detection & Response (AIDR)

Agentless, model-agnostic monitoring of production inference for adversarial inputs, prompt injection, and extraction attempts, without requiring access to model weights or modifying the model itself.

New in 2026
Agentic Runtime Security + Agent Harness Security

Extends runtime monitoring to autonomous agents and, specifically, to the "harness" — the tool-calling and execution environment — that AI coding agents run inside. Funded directly out of the Series B and positioned as the next growth leg.

Target Customer Segments

SegmentProblem SolvedHiddenLayer SolutionNote
Financial services (banking, insurance, trading)Fraud-detection and trading models are high-value, high-scrutiny attack targets; regulators expect model risk managementModel Scanner + Runtime Security + AIBOM for audit trailsNamed as a primary vertical in the Series B announcement
Frontier AI / big techPublic-facing LLMs are among the most-attacked surfaces on the internetRuntime Security + Attack Simulation at hyperscaleReportedly includes a model provider with 700M+ weekly users — an exceptional reference logo, and a concentration risk if it churns
US federal government, defense, intelligenceNational-security AI systems need adversarial-hardened deployment beyond what hyperscaler tooling alone providesFull AISec platformLong sales cycles, high contract value, sticky multi-year relationships
Healthcare, pharma, insurance, airlines, accountingSafety- or compliance-critical AI use cases with third-party/open-source model exposureDiscovery + Model ScannerNamed in Series B materials as newer verticals; smaller logo count than finance/gov so far
Platform & application developer teams (horizontal)Shipping AI features via CI/CD without a security review gateGitHub Action, Azure/AWS Marketplace listingsDeveloper-adjacent distribution, but still an enterprise, sales-led pricing motion — not self-serve

Key Metrics & Recent Performance

📈

ARR up >10x, Year Over Year

The headline growth number behind the Series B — but HiddenLayer describes absolute ARR only as "tens of millions," meaning the multiple is impressive off a genuinely small base, against a market Gartner sizes at $2.83B in 2026.

🆕

50+ New Platform Customers, >90% of ARR Growth

New-logo-driven growth is a strong land signal, but with over 90% of ARR growth coming from new customers, the company discloses little about expansion revenue or net retention within its existing base — an open question, not a confirmed weakness.

🔬

39 Patents Granted, 65 Pending

Alongside 48–50+ disclosed CVEs across ML frameworks (figures vary slightly across company communications from 2024–2026). A genuine, hard-to-fake research output that converts into detection signatures.

💰

$100M Series B, September 2026

Led by Delta-v Capital with Ten Eleven Ventures, Morgan Stanley, M12 (Microsoft), and Booz Allen Ventures — a strategic-investor bench that doubles as a potential channel into finance, defense, and Microsoft's ecosystem.

Core Technology Stack, AI Strategy & AI Readiness

HiddenLayer's technical differentiation rests on one architectural choice: it operates as an agentless, model-agnostic layer, meaning it does not require access to model weights, training data, or prompts, and does not require retraining or modifying the model it protects. That lowers integration friction relative to approaches that need deep model access — but it also means detection is inherently probabilistic and signature/behavior-driven rather than based on inspecting the model's internals directly.

Detection Method
Static + behavioral analysis, not internals inspection

Model Scanner performs static analysis across serialized model files looking for known-malicious code patterns, unsafe deserialization calls (the classic pickle exploit class), and structurally anomalous computation graphs. Runtime/AIDR performs behavioral analysis on inference traffic — inputs and outputs — to flag adversarial or extraction-style patterns without touching the model itself.

ShadowLogic Research
The technical justification for the whole product line

HiddenLayer's own research team demonstrated that backdoors can be implanted in models saved in formats widely assumed to be "safe" — including safetensors and ONNX — not by injecting executable code, but by manipulating the model's computational graph itself. This is the single most important technical claim in HiddenLayer's marketing: it argues that format-level safety (the industry's default mitigation for the older pickle-deserialization problem) is not sufficient, which is precisely the gap Model Scanner and Runtime Security are built to close.

AIBOM
Machine-readable AI bill of materials

Auto-generates inventories of model components, datasets, and dependencies for compliance auditing — positioned squarely ahead of EU AI Act and NIST AI RMF documentation requirements that are still being finalized in most jurisdictions.

Ecosystem
Middleware, not a standalone console

Native integrations with AWS SageMaker, Azure AI Foundry, Databricks Unity Catalog, Hugging Face, MLflow, CrowdStrike, and SIEM/SOAR platforms, plus AWS and Azure Marketplace listings and a GitHub Action for CI/CD. The strategy is to sit inside the MLOps and security-ops tools teams already use rather than asking them to adopt a new console.

AI Strategy & AI Readiness HiddenLayer's AI strategy is reflexive in an interesting way: its Automated Red Teaming product is itself an AI system used to attack other AI systems, and its detection engines are trained on adversarial data. That means the company must secure its own models against the same attack classes it sells protection from — a dependency it doesn't discuss publicly. On external AI readiness, the signal is strong on the enterprise side (deep MLOps/cloud integrations, AIBOM for compliance) but comparatively weak on the developer/bottom-up side: unlike Protect AI's open-source ModelScan or Lakera's viral "Gandalf" prompt-injection game, HiddenLayer has no public, self-serve way for an individual developer to try the technology — a real gap in a market where security tools increasingly spread bottom-up before procurement ever gets involved.

Product Strategy Assessment: What's Real, What's Risk, What's Missing

HiddenLayer has built a genuinely credible, research-backed platform and just proved it can raise growth capital in a hot but still-small market. The PM-level critique is less about whether the technology works and more about whether the go-to-market, pricing, and category positioning are built for the market HiddenLayer will actually have to compete in over the next two years — one where its nearest peers now carry Palo Alto's, Cisco's, and Check Point's sales forces.

⚠ Structural Risk
The Consolidation Wave Cuts Both Ways
Protect AI, Robust Intelligence, and Lakera being acquired removed HiddenLayer's closest independent competitors — but it also means those capabilities now ship bundled inside Prisma AIRS, Cisco AI Defense, and Check Point's platform, often at near-zero incremental cost for customers already paying those vendors for firewalls, endpoint, or network security. HiddenLayer's hardest future sales conversation isn't against another startup — it's against "our existing platform vendor already includes something like this." The Series B's explicit allocation to "sales and distribution expansion" reads as a direct acknowledgment that GTM, not technology, is the constraint.
◈ Strategic Gap
No Open-Source or Bottom-Up On-Ramp
Protect AI built ModelScan, NB Defense, and LLM Guard as open-source tools and ran a public bug-bounty program (huntr.com) before it was acquired — both created developer-level adoption and a crowdsourced threat-intel flywheel independent of the enterprise sales cycle. HiddenLayer has neither. In a category where shadow AI and bottom-up tool adoption are explicitly named as growing problems (76% per its own research), relying entirely on an enterprise, custom-priced, sales-led motion is a mismatch with how the risk actually enters organizations.
◈ Strategic Gap
Guardrails Have Historically Been the Thinner Half of the Platform
Independent comparisons consistently place HiddenLayer ahead on model-level and supply-chain detection but behind specialists like Lakera on LLM guardrails and prompt-injection defense specifically. Agentic Runtime Security is a direct attempt to close that gap, but it is shipping into a market where Lakera's technology now has Check Point's distribution behind it, and Noma and Zenity were built agent-native from day one rather than extending a model-scanning product line.
✦ Opportunity
The Agent Harness Security Bet Is Well-Timed
1 in 8 reported AI breaches already trace to agentic systems, and autonomous coding agents (Claude Code, Cursor, Copilot-style tools) are proliferating inside engineering orgs faster than any security review process. HiddenLayer entering this specific wedge — the execution harness an agent runs inside, not just the model — is a legitimate, differentiated angle. The risk is timing: Noma and Zenity are already funded and agent-native, and this window will not stay open long.
✦ Opportunity
Research Credibility Is a Real, Compounding Moat
ShadowLogic wasn't a marketing stunt — it directly undermined a widely held industry assumption (that safetensors/ONNX formats are inherently safe) and fed straight into product detection logic. Combined with 39 granted patents and roughly 50 disclosed CVEs, this is the kind of technical credibility that is genuinely difficult and slow for an acquirer's internal team to replicate, and it's arguably HiddenLayer's best answer to "why not just use what's bundled in our platform vendor."
⚠ Concentration Risk
One Very Large Logo Is Doing a Lot of Reputational Work
A frontier model provider with 700M+ weekly users is an extraordinary reference customer — and also a single point of both revenue and narrative risk if that account churns, insources the capability, or simply declines to be publicly associated with HiddenLayer going forward. Combined with the disclosure that over 90% of ARR growth came from new logos rather than expansion within the existing base, the growth story currently looks more "wide" than "deep."

Strengths, Weaknesses, Opportunities, Threats

Strengths
  • Genuine, hard-to-replicate research moat (ShadowLogic, 39 patents, ~50 CVEs) feeding directly into detection logic
  • One of the last independent, full-lifecycle AI security platforms after three peer acquisitions
  • Blue-chip regulated customer base: financial services, DoD/intelligence, a 700M-WAU frontier-model logo
  • Fresh $100M Series B with strategic investors (Morgan Stanley, M12/Microsoft, Ten Eleven, Booz Allen) who double as potential channel partners
  • Early, credible mover into agentic/agent-harness security ahead of the broader market
  • Agentless, model-agnostic architecture lowers integration friction
Weaknesses
  • No open-source presence or public bug bounty, unlike Protect AI's pre-acquisition playbook
  • Historically thinner LLM guardrail / prompt-injection capability than specialists like Lakera
  • Enterprise-only, custom/sales-led pricing mismatched to bottom-up shadow-AI adoption patterns
  • >90% of ARR growth from new logos; expansion/retention economics undisclosed
  • ARR still "tens of millions" against a market Gartner sizes at $2.83B in 2026 — high multiple, low absolute share
  • Single flagship AI-lab customer represents meaningful concentration risk
Opportunities
  • Position as "the last neutral, best-of-breed platform" for buyers wary of vendor lock-in
  • Agent Harness Security targets the fastest-growing, least-secured surface at the right moment
  • Package AIBOM/compliance tooling ahead of EU AI Act and NIST AI RMF enforcement
  • Series B capital earmarked for EMEA — regulated European verticals remain underpenetrated
  • Deepen M12/Microsoft and Databricks relationships into native marketplace bundling
Threats
  • Hyperscaler-native guardrails (Azure, Bedrock, Google Model Armor) as free, "good enough" substitutes
  • Noma and Zenity, both well-funded and agent-native from day one, targeting the same pivot
  • Further consolidation — HiddenLayer itself is a plausible next acquisition target
  • Budget reactivity: 91% added AI security budget, but 40%+ allocate under 10% of total spend to it
  • Platform-bundled competitors (Palo Alto, Cisco, Check Point) selling at near-zero incremental cost

Product Strategy 2027–2029: From Model Security Platform to the Agentic Security Standard

Document Type This is a mock product strategy document written from the perspective of a Senior PM/CPO at HiddenLayer. It is directionally grounded in real company data but represents analytical recommendations, not HiddenLayer's actual internal roadmap.
01

Strategic Vision & North Star

Vision: HiddenLayer becomes the default, neutral security layer that any enterprise plugs in the moment it puts a model or an agent into production — regardless of cloud, model vendor, or agent framework — the way CrowdStrike became the default answer for endpoints, not because it was bundled, but because buyers trusted it to be independent.

North Star Metric: Protected Surface Coverage — the percentage of an enterprise's total inventoried AI assets (models and agents surfaced by AI Discovery) that are under continuous runtime monitoring, not just scanned once. A platform that discovers shadow AI but leaves most of it unmonitored after the initial scan hasn't actually reduced risk. Target: 80%+ of discovered assets under continuous monitoring within 12 months of a Discovery deployment, treated as the leading indicator for both retention and expansion revenue.

The Strategic Pivot: From "we scan and monitor your models" to "we are the security layer every agent and model runs inside of" — winning the agentic wedge decisively before Noma or Zenity establish default status, while converting research credibility into a genuine top-of-funnel instead of a pure enterprise-sales asset.

02

Three Strategic Bets (2027–2029)

Bet 1: Win Agent Harness Security With Depth, Not Breadth

Rather than a generic "agent monitoring" pitch, ship deep, best-in-class integrations with the specific agent frameworks enterprises are actually deploying — Claude Code, Cursor, GitHub Copilot Workspace, and internal LangGraph/AutoGen-style agents — before Noma or Zenity establish default status in each.

Why This First The agentic wedge is the one growth vector where HiddenLayer, Noma, and Zenity are all starting close to zero at the same time. It is the only category in this market where being first and deepest still matters more than distribution size.

Bet 2: Build a Self-Serve, Open-Source On-Ramp

Open-source a lightweight scanner (mirroring Protect AI's pre-acquisition ModelScan playbook) and launch a public vulnerability disclosure program, converting HiddenLayer's genuine research credibility into bottom-up developer adoption rather than leaving it as purely a sales-enablement asset.

Phase 1 (Q1 2027)

Free, hosted "scan this model" tool plus an open-sourced detection-only scanner (no fleet dashboard, no compliance reporting — the classic open-core split).

Phase 2 (Q2–Q3 2027)

Public disclosure program modeled on huntr.com; developer community building around real CVE credit.

Moat Mechanism

Every free-tier scan and community disclosure feeds the same detection-signature pipeline that already differentiates the paid platform — turning the funnel itself into R&D.

Bet 3: Turn Compliance Into an EMEA Wedge

Package AIBOM generation and audit-ready reporting as a distinct, faster-close SKU aimed at EU AI Act and NIST AI RMF requirements, using the Series B's EMEA expansion capital to land in regulated European financial services and insurance before expanding those accounts into full runtime and red-teaming coverage.

Why Compliance, Not Just Security A compliance-driven purchase has an externally imposed deadline and a named budget owner — both of which shorten sales cycles relative to a discretionary security purchase, and both of which are structurally harder for a hyperscaler's bundled guardrails to satisfy neutrally.
03

Prioritized Initiative Roadmap

INITIATIVE
PRIORITY / TIMELINE
SUCCESS METRIC
Agent Harness Security — deep framework integrations
Native support for Claude Code, Copilot, LangGraph-style agents.
P0 · Q1 2027
3+ named framework integrations live; 25 agent-security design partners
Open-source scanner + public disclosure program
Free hosted scan tool, OSS detection-only scanner, huntr-style bounty.
P0 · Q1 2027
10K+ free-tier scans and 5K+ GitHub stars within 6 months
Continuous coverage push
Convert AI Discovery findings into actively monitored assets in top accounts.
P1 · Q2 2027
80% of discovered assets under runtime monitoring across the top 20 accounts
EU AI Act compliance SKU
AIBOM + audit-ready reporting packaged as a standalone, faster-close product.
P1 · Q2 2027
15 new EMEA logos within two quarters of launch
Transparent self-serve starter tier
Published entry pricing alongside the existing enterprise/custom motion.
P2 · Q3 2027
500+ self-serve signups; 10% convert to paid within 90 days
Usage-based expansion pricing
Price tied to number of protected assets, not flat platform fee.
P2 · Q3 2027
Net revenue retention above 120%
Frontier-lab reference program
Public case studies and co-marketing with AI-native flagship customers, where permitted.
P3 · Q4 2027
3 public reference customers in the AI-native/frontier-lab segment
04

OKRs — 12-Month Targets (2027)

O1: Establish Agent Harness Security as the default for coding-agent protection
  • KR1: Integrations with 3 major coding-agent platforms shipped by Q1 2027
  • KR2: 100 paying Agent Harness Security customers by Q4 2027
  • KR3: Cited in 2+ analyst reports specifically for agent security by end of 2027
O2: Build a bottom-up adoption funnel to reduce reliance on enterprise sales alone
  • KR1: Open-source scanner reaches 10K+ GitHub stars by Q3 2027
  • KR2: 5,000+ free-tier scans per month sustained by Q4 2027
  • KR3: 15% of new paid logos originate from the self-serve/open-source funnel, up from effectively zero today
O3: Convert compliance pressure into EMEA growth
  • KR1: 25 net-new EMEA logos by Q4 2027, funded by Series B expansion capital
  • KR2: Compliance/AIBOM SKU reaches $5M+ ARR by Q4 2027
  • KR3: Named in EU AI Act vendor guidance or analyst shortlists by mid-2027
O4: Improve growth quality, not just growth rate
  • KR1: Net revenue retention above 120% by Q4 2027, up from a new-logo-dominated 2026
  • KR2: Reduce single-customer revenue concentration below 15% of ARR
  • KR3: Sustain 100%+ ARR growth off the larger 2026 base while improving retention
05

Key Risks & Mitigations

RiskSeverityLikelihoodMitigation
Noma or Zenity out-execute the agentic pivotHIGHMEDIUMShip narrow, best-in-class framework integrations fast rather than broad-but-shallow coverage; lean on research credibility to win technical evaluations head-to-head.
Hyperscaler guardrails commoditize the low endMEDIUMHIGHMove up-market on depth — red-teaming, AIBOM, compliance — where a cloud vendor auditing its own AI stack neutrally is a structural conflict of interest.
HiddenLayer itself becomes the next acquisition target before reaching self-sustaining scaleMEDIUMMEDIUMPreserve platform neutrality as the core value proposition in any strategic conversation; treat independence itself as a sellable asset, not just an interim state.
Compliance SKU sells but doesn't expand into full platformMEDIUMMEDIUMDesign AIBOM/compliance reporting with an explicit technical path into runtime monitoring, not as a standalone report generator.
Open-sourcing the scanner cannibalizes the paid tierLOWMEDIUMScope the OSS tool to detection-only — no fleet-wide dashboard, no compliance reporting, no remediation workflow.
06

Strategic Don'ts

Don't chase feature parity with every acquired competitor

Palo Alto, Cisco, and Check Point will always out-resource a pure feature race. Win on independence and depth in fewer, sharper wedges — agent security and compliance — rather than trying to match a broader bundled platform line for line.

Don't let "Total AI Security" messaging outrun the guardrails gap

Until Agentic Runtime Security is demonstrably strong on prompt injection specifically, keep marketing evidence-based and specific rather than comprehensive-platform claims that invite unfavorable specialist comparisons.

Don't expand horizontally into general cybersecurity yet

The CEO has floated eventually moving into cybersecurity domains that depend on AI. The AI security wedge itself is still barely funded relative to its total addressable market — a horizontal expansion now would repeat the classic mistake of a vision outrunning the product underneath it.

Don't scale sales headcount faster than retention is proven

With over 90% of ARR growth coming from new logos and net revenue retention undisclosed, further GTM scale-up should wait on clearer evidence that the existing customer base expands, not just renews.

The Verdict

HiddenLayer earned its Series B. A genuine research pedigree, a platform that covers the full AI lifecycle without requiring model access, and a customer roster spanning finance, government, and at least one frontier AI lab are not easy things to build, and the 10x ARR growth is real evidence that enterprises are willing to pay for this specifically rather than settle for what's bundled elsewhere — at least for now.

But the same eighteen months that validated the category also stripped out three of HiddenLayer's closest independent peers, each folded into a platform vendor with an existing sales force and an existing customer relationship to sell into. HiddenLayer's remaining independence is simultaneously its best differentiator — "the neutral platform, not a bundled afterthought" — and the exact thing that makes it a plausible acquisition target the moment growth slows or a strategic buyer decides the agentic security wedge is worth paying up for. The Agent Harness Security bet is the right next move, aimed at the fastest-growing, least-defended surface in the market, but it lands in a field where Noma and Zenity started agent-native and are already funded to compete for the same design partners.

The next 18–24 months will likely decide which of two stories this becomes: a company that used its research credibility and fresh capital to build genuine distribution and win the agentic wedge outright — or a well-regarded, well-funded acquisition target whose independence was always a phase rather than a destination. Both are plausible outcomes for the investors who just wrote the check. Only one of them is the outcome a product organization should actually be building toward.

Bottom Line HiddenLayer's technology and research credibility are not in question. What's unresolved is distribution — whether it can out-execute two freshly funded agent-native rivals and outlast the temptation to sell into a platform vendor before it proves it can win independently. The compliance and open-source wedges recommended here are less about new revenue and more about buying the company the bottom-up adoption and faster sales cycles it currently lacks.

Sources: HiddenLayer.com, HiddenLayer press releases and Innovation Hub research (ShadowLogic, 2026 AI Threat Landscape Report, Forrester Opportunity Snapshot), TechCrunch, PR Newswire, Gartner newsroom (Aug 2026 AI security forecast), CB Insights, Tracxn, Microsoft Tech Community, appsecsanta.com, guptadeepak.com, Respan market map. Analysis as of September 2026. Funding, ARR-growth, and customer figures are company-stated; market-size figures are Gartner estimates and may be revised.