Model / data poisoning detection companies, products & suppliers
Finding poisoned training data or backdoored models. Jobs: training-set scans; backdoor tests; supply-chain of weights.
What is Model / data poisoning detection?
Finding poisoned training data or backdoored models. Jobs: training-set scans; backdoor tests; supply-chain of weights.
What problems does it solve?
Training sets and fine-tunes can carry backdoors nobody tests for.
Typical business use cases
- Training-set scans
- Backdoor tests
- Supply-chain of weights
Important capabilities
- Dataset scans
- Trigger tests
- Weight attestations
What buyers should evaluate
- Coverage of your supply chain
- False positives
- What you do when it fires
Risks and governance considerations
A scan that requires uploading the entire training corpus.
Procurement checklist
- Data handling
- Trigger library
- Response playbook
Relevant AI Trustmark assurance
AI Trustmark independent findings appear only when an assessment or certificate exists. Category membership does not imply verification.
Companies and providers
Claimed suppliers appear first so buyers can start with listings the company has taken ownership of. Payment does not buy this order.
Achieve AI security and safety with a platform that detects threats, removes vulnerabilities, and monitors performance for continuous insights. Enkrypt AI publishes Enkrypt AI Data
Secure your AI with HiddenLayer’s end-to-end platform that detects threats, protects models, and ensures safe, compliant AI adoption at scale. HiddenLayer, Inc. trades as HiddenLay
International Business Machines Corporation sells hybrid-cloud software, Granite models and enterprise AI tooling. Public pages distinguish IBM software and models from IBM Consult
JFrog publishes JFrog ML and JFrog Xray as named AI products. JFrog is used for Model / data poisoning detection and Feature stores work. JFrog is recorded in Israel. JFrog publish
Implement Zero Trust, Secure your Network, Cloud workloads, Hybrid Workforce, Leverage Threat Intelligence & Security Consulting. Cybersecurity Services & Education for CISO’
The AI Security Platform that catches vulnerabilities in development. Trusted by 156 of the Fortune 500 and 300,000+ developers worldwide. Promptfoo publishes ModelAudit as named A
Deploy Bravely with the world’s most comprehensive AI security platform securing your AI agents, apps, models and data at every step. Protect AI publishes ModelScan, LLM Guar
ReversingLabs unifies malware analysis, threat hunting, and software supply chain security with deep binary intelligence built for enterprise scale. ReversingLabs publishes Reversi
Trail of Bits secures the software, blockchains, and AI systems the world relies on. Browse our security reviews, research, open-source tools, and talks. Trail of Bits publishes Fi
Products
Claimed products appear first. Ranking packs and payment do not change this list.
- Adversarial Robustness Toolbox· IBM
- Enkrypt AI Data Risk Audit· Enkrypt AI
- Fickling· Trail of Bits
- HiddenLayer Automated Red Team· HiddenLayer
- HiddenLayer Model Scanner· HiddenLayer
- JFrog Xray· JFrog
- ModelAudit· Promptfoo
- ModelScan· Protect AI
- Prisma AIRS AI Model Security· Palo Alto Networks
- ReversingLabs Spectra Assure· ReversingLabs
Also used in this category
These products have a different primary category so they do not compete for the same ranking queries. They are listed here because buyers still encounter them in this job.
- Protect AI Platform· Protect AI
Related categories
Relevant procurement and assurance guides
Frequently asked questions
What is Model / data poisoning detection?
Finding poisoned training data or backdoored models. Jobs: training-set scans; backdoor tests; supply-chain of weights.
What should not be listed as Model / data poisoning detection?
Products whose buyer job is runtime guardrails, red teaming of apps, or content moderation. Those belong on their own category page so search queries are not split.
Has AI Trustmark independently assessed every Model / data poisoning detection supplier?
No. A category listing is descriptive. Independent assessment is shown only on company or product pages that carry Trustmark evidence.
What security testing evidence should buyers request for an AI product?
Ask what was tested, against which version, whether prompt-injection, data-exfiltration and tenant isolation were in scope, and where failed prompts were stored. A generic ISO certificate or a vendor scanner screenshot is not by itself an AI TrustMark assessment.
How should prompt injection and tool-output attacks be controlled?
Agents that read untrusted content or tool output can be instructed to exfiltrate data or take writes. Buyers should ask what is treated as untrusted, whether tool output can change the plan, and what tests were run. Scanner marketing is not the same as independent testing.
What model or provider changes should a buyer insist on being told about?
Material change usually includes a new model family, new region, new subprocessor, new write-capable tool, or a change that affects logging, privacy or human oversight. Those changes should trigger evidence refresh rather than a silent release.
How should buyers verify where AI customer data is processed?
Ask for the named processing locations, cloud regions and any subprocessors that see prompts, files or outputs. A directory listing is not evidence of residency. Independent assessment records the locations that were in scope on the assessment date.
Does a TrustMark on one product cover the rest of the company?
No. Independent assessment is scoped to the named organisation and, where relevant, the named product. Category pages list suppliers as a topic label. They do not imply that every listed company has been assessed.