AI security companies, products & suppliers
AI security products protect AI systems from abuse: prompt injection, data exfiltration through models, poisoned retrieval, and unsafe tool use. They are not generic antivirus. Procurement should ask which layer they cover — model, application, or gateway.
What is AI security?
AI security products protect AI systems from abuse: prompt injection, data exfiltration through models, poisoned retrieval, and unsafe tool use. They are not generic antivirus. Procurement should ask which layer they cover — model, application, or gateway.
What problems does it solve?
LLM applications fail traditional AppSec tests and still ship with tool access.
Typical business use cases
- Runtime filters
- Red team
- Gateway policies
- Secure SDLC for AI
Important capabilities
- Attack libraries
- Policy
- Findings
- Runtime
What buyers should evaluate
- Stack coverage
- Where prompts are sent
- Evidence quality
Risks and governance considerations
The scanner becoming a prompt store.
Procurement checklist
- Prompt handling
- Retention
- Integration
- Retest
Relevant AI Trustmark assurance
Vendor scan output is not a Trustmark technical test.
Companies and providers
Claimed suppliers appear first so buyers can start with listings the company has taken ownership of. Payment does not buy this order.
Corgea finds, triages, and fixes vulnerabilities across code, packages, infrastructure, and containers. Corgea is used for AI security work. Corgea is recorded in United States. Co
CybSafe is a London cyber-security company selling behaviour-based security awareness software. Public marketing covers measuring and changing employee security behaviour rather th
Darktrace is a Cambridge-headquartered cyber-security company that sells AI-based threat detection and autonomous response products for enterprise networks, cloud and email. Darktr
Google is a US technology company that sells consumer and cloud AI products, including Gemini, Search, and related developer APIs on Google Cloud. Google publishes Imagen, Gemini f
Govern AI wherever your workforce runs it. Detect shadow AI, prevent data leaks, and coach employees inline — across web, desktop, and agentic workflows. Harmonic Security publishe
Secure your AI with HiddenLayer’s end-to-end platform that detects threats, protects models, and ensures safe, compliant AI adoption at scale. HiddenLayer, Inc. trades as HiddenLay
Discover, assess and red team AI models, agents and applications with Mindgard’s attacker-aligned AI security platform. Mindgard publishes Mindgard DAST-AI and Mindgard AI Security
NCC Group is a UK cyber-security company. Public pages describe assurance, testing, incident response and related security services, including assessment of AI-enabled systems. NCC
Protect your AI Agents and Applications from attacks, hallucinations and data leakages with our AI native entreprise-grade cybersecurity solutions. NeuralTrust publishes TrustTest,
From models to agents, get secure, safe, and trustworthy AI with an award-winning AI security platform designed to stay ahead of AI risk. Noma Security publishes Noma AI Security P
Implement Zero Trust, Secure your Network, Cloud workloads, Hybrid Workforce, Leverage Threat Intelligence & Security Consulting. Cybersecurity Services & Education for CISO’
One platform to discover, govern, and secure every AI agent or workflow across your organization. Pillar Security Technologies Ltd..security, AI security. Pillar Security publishes
Open-source tools, research, analysis, and guidance to understand and respond to AI threats. Prompt Security publishes Prompt Security Automated AI Red Teaming and Prompt Security
Deploy Bravely with the world’s most comprehensive AI security platform securing your AI agents, apps, models and data at every step. Protect AI publishes ModelScan, LLM Guar
Wiz connects code, cloud, and runtime into one agentic cybersecurity platform. Prevent risk, detect threats, and start secure – across every cloud and AI layer. Wiz, Inc. trades as
Decide exactly what your AI agents can and can’t do. Zenity evaluates every agent action in real time and steers it. Zenity publishes Zenity AI Security and Governance Platform as
Products
Claimed products appear first. Ranking packs and payment do not change this list.
- AI Runtime Security· Palo Alto Networks
- Corgea· Corgea
- Harmonic Protect· Harmonic Security
- Model Armor· Google
- Noma AI Security Platform· Noma Security
- Pillar Secure AI· Pillar Security
- Prisma AIRS· Palo Alto Networks
- Protect AI Platform· Protect AI
- TrustLens· NeuralTrust
- Zenity AI Security and Governance Platform· Zenity
Also used in this category
These products have a different primary category so they do not compete for the same ranking queries. They are listed here because buyers still encounter them in this job.
- CybSafe· CybSafe
- Darktrace· Darktrace
- HiddenLayer Automated Red Team· HiddenLayer
- Mindgard AI Security Labs· Mindgard
- NCC Group· NCC Group
- Prompt Security Platform· Prompt Security
- Wiz AI-SPM· Wiz
Related categories
Relevant procurement and assurance guides
Frequently asked questions
How is this different from LLM security?
LLM security is narrower, focused on language-model applications. AI security also covers ML pipelines and model supply chain.
What is AI security?
AI security products protect AI systems from abuse: prompt injection, data exfiltration through models, poisoned retrieval, and unsafe tool use. They are not generic antivirus. Procurement should ask which layer they cover — model, application, or gateway.
What security testing evidence should buyers request for an AI product?
Ask what was tested, against which version, whether prompt-injection, data-exfiltration and tenant isolation were in scope, and where failed prompts were stored. A generic ISO certificate or a vendor scanner screenshot is not by itself an AI TrustMark assessment.
How should prompt injection and tool-output attacks be controlled?
Agents that read untrusted content or tool output can be instructed to exfiltrate data or take writes. Buyers should ask what is treated as untrusted, whether tool output can change the plan, and what tests were run. Scanner marketing is not the same as independent testing.
What model or provider changes should a buyer insist on being told about?
Material change usually includes a new model family, new region, new subprocessor, new write-capable tool, or a change that affects logging, privacy or human oversight. Those changes should trigger evidence refresh rather than a silent release.
How should buyers verify where AI customer data is processed?
Ask for the named processing locations, cloud regions and any subprocessors that see prompts, files or outputs. A directory listing is not evidence of residency. Independent assessment records the locations that were in scope on the assessment date.
Does a TrustMark on one product cover the rest of the company?
No. Independent assessment is scoped to the named organisation and, where relevant, the named product. Category pages list suppliers as a topic label. They do not imply that every listed company has been assessed.
What incident-handling evidence is useful for AI suppliers?
Buyers should see how AI-specific failures are detected, contained and notified — including unsafe outputs, data leakage and unauthorised agent actions. An incident policy that never mentions models, prompts or tools is incomplete for this class of product.