Last updated: 2026-08-19
HiddenLayer is an enterprise AI security platform certified to SOC 2 Type II and ISO 27001 that scans machine learning model files for backdoors before they reach production, then monitors live model behavior and, since March 2026, autonomous AI agent sessions for adversarial attacks and prompt injection at runtime.
About HiddenLayer
HiddenLayer is an enterprise AI security platform founded in Austin, Texas in March 2022 by Chris Sestito, Jim Ballard, and Tanner Burns. The company has raised $56M across two rounds, including a $50M Series A led by Microsoft's venture fund M12 in September 2023, with participation from IBM Ventures, Capital One Ventures, Booz Allen Ventures, and Moore Strategic Ventures. It protects organizations that run machine learning models in production from four categories of risk: model supply chain attacks, adversarial inputs, runtime exploitation, and unauthorized model access.
The platform is built around four integrated modules covering the full model lifecycle: AI Discovery for asset inventory, AI Supply Chain Security (ModelScanner) for pre-deployment file scanning, AI Attack Simulation for adversarial red teaming, and AI Runtime Security (MLDR) for live production defense. Each module operates independently, so a security team can adopt file scanning first and add runtime monitoring later without re-architecting its stack.
In March 2026, HiddenLayer extended that runtime layer to autonomous agents, adding the ability to reconstruct full agent sessions and flag malicious tool calls or data exfiltration mid-workflow. The move followed the company's own 2026 AI Threat Landscape Report, which found that one in eight AI breaches now involves an agentic system.
HiddenLayer deploys as SaaS, on-prem, air-gapped, or hybrid, with SDKs for Python, TypeScript, and Java (the Python SDK ships on PyPI as hiddenlayer-sdk). Native integrations cover AWS Bedrock, Amazon SageMaker, Amazon AgentCore, Google Cloud, Azure, MLflow, Hugging Face Hub, and Databricks Unity Catalog.
Pricing
Enterprise pricing only, quote-based. No public tiers or self-serve plan. Third-party estimates suggest contracts may start around $500/month.
Deployment options include SaaS, on-prem, and air-gapped. com for a custom proposal.
Key Features
- ModelScanner: Scans 35+ ML model file formats (PyTorch, TensorFlow, ONNX, Keras, Pickle, and others) for backdoors, trojans, and serialization exploits before models reach production.
- AI Runtime Security (MLDR): Monitors live model inputs and outputs in real time to detect adversarial attacks, prompt injection, and model evasion without requiring access to model weights or training data.
- AI Discovery: Automatically inventories all AI and ML assets across cloud environments, producing a full map of the organization's AI footprint to eliminate shadow AI risk.
- Agentic Runtime Security: Launched March 2026, reconstructs every autonomous agent session to detect malicious tool calls, data exfiltration attempts, and multi-step prompt injection in real time.
- AI Attack Simulation: Continuously runs adversarial red teaming against deployed models and AI applications to identify exploitable weaknesses before attackers do.
Pros
- Covers the full AI security lifecycle from model discovery and supply chain scanning through runtime defense, unlike most point solutions that address only one layer.
- ModelScanner supports more model formats than any confirmed competitor, and integrates directly into CI/CD pipelines via GitHub Actions and MLflow.
- Remains an independent company while its largest rivals have all been acquired by larger security vendors, so its roadmap is not subject to a parent company's shifting priorities.
Cons
- Enterprise-only pricing with no published tiers; teams cannot evaluate cost without a sales call, slowing procurement for mid-size organizations.
- Deployment requires a team of ML and infrastructure engineers; Gartner Peer Insights reviewers report a steep initial setup curve and a need for dedicated MLOps staff.
- No confirmed HIPAA attestation published on the website, limiting use in healthcare organizations that need AI security with a BAA.
Data Handling
- Training-data policy
- Does not require access to customer model weights or training data; the MLDR module analyzes model inputs and outputs only.
- Compliance
- SOC 2 Type II · ISO 27001
Frequently Asked Questions
What are HiddenLayer's pricing plans in 2026?
HiddenLayer publishes no self-serve pricing; every plan is quote-based after a sales call. Third-party estimates put entry-level enterprise contracts at roughly $500 a month, though HiddenLayer has not confirmed that figure. The final cost depends on how many models you monitor and whether you deploy as SaaS, on-prem, or air-gapped.
Can you use HiddenLayer without paying?
Not on a self-serve basis. There is no trial you can sign up for, and access starts with a sales conversation, though HiddenLayer may stand up a proof-of-concept environment for qualified prospects. Teams that want a no-cost entry point into model security can start with ModelScan, the open-source scanner HiddenLayer contributed to, before paying for the full platform.
What are HiddenLayer's closest competitors?
Most of HiddenLayer's direct rivals have already been absorbed: Protect AI was acquired by Palo Alto Networks in 2025, Lakera by Check Point in November 2025, and a third AI security startup was folded into Cisco in August 2024. On hokai, Cyera covers AI data security posture management rather than model file scanning, and Clawvisor focuses on agent credential and authorization control with a free tier HiddenLayer does not offer. For dedicated model and runtime scanning without an acquirer's roadmap attached, HiddenLayer remains the standalone choice.
HiddenLayer or Cyera: which should you pick?
Both companies sell AI security, yet they guard different layers. HiddenLayer scans and defends the model itself, covering file scanning plus runtime and agent monitoring, while Cyera classifies and governs the data those models train on, at 95%+ classification precision across cloud and on-prem stores. Model supply chains and agent behavior point to HiddenLayer; data discovery and loss prevention across a whole estate point to Cyera.
What does it take to start using HiddenLayer?
Everything begins with a demo request at hiddenlayer.com, since signup is sales-gated. After the discovery call, most customers land on the SaaS deployment because it stands up fastest, with on-prem and air-gapped builds available for stricter environments. Gartner Peer Insights reviewers report that a first deployment usually occupies a dedicated ML and infrastructure engineer for several weeks.
Top Alternatives
- Cyera: HiddenLayer guards the model file and its runtime agents; Cyera handles AI data security posture across cloud and on-prem stores.
- Clawvisor: Clawvisor gates AI agent credentials for free and in the open; HiddenLayer brings enterprise model scanning and runtime defense with SOC 2 and ISO 27001 behind it.
HokAI guides covering HiddenLayer
- What You Actually Get When You Buy Cyera: Cyera launched Agent Guardian in August 2026, its sixth acquisition-fueled move this year. What the AI security platform ships today, and what it still doesn't.
- Clawvisor vs. Cyera: Why These Two AI Security Tools Aren't Really Competing: Clawvisor is free and built by one person. Cyera just raised $600M at a $12B valuation. Here is why picking between them is the wrong question for most teams.