What are the top AI safety startups by revenue today?

In our AI safety market deck, you will find everything you need to understand the market
SUMMARY
HiddenLayer is the clearest revenue leader among independent AI safety and AI security startups today, with annual recurring revenue in the tens of millions of dollars.
The ranking is unusually dependent on disclosure quality. Noma Security and Patronus AI may be much closer to HiddenLayer than the public numbers suggest, but both disclose growth rates rather than absolute revenue.
Noma Security’s more than 1,300% ARR growth and Patronus AI’s more than 15x revenue growth are impressive, but neither tells us the size of the current business without a starting base. That is why they belong in the challenger group rather than in a precise numerical order.
The independent revenue ceiling is still modest compared with adjacent AI markets. We found no defensible public evidence that a pure-play AI safety startup has crossed $100 million in annual revenue or ARR.
Acquisitions are part of the reason. Robust Intelligence was around $9 million in annualized revenue when Cisco moved to acquire it, while Lakera and CalypsoAI were still below $5 million in the periods reported.
Commercially, AI safety is increasingly being sold through cybersecurity budgets. Runtime protection, prompt-injection defense, agent permissions, asset discovery and data-loss controls are easier to attach to existing security buying motions than a broad promise of “AI safety.”
AI agent security is making that shift even stronger. Once agents can access files, credentials, databases, SaaS tools and code repositories, the risk becomes operational and much easier for an enterprise buyer to budget for.
Funding is running ahead of disclosed revenue. HiddenLayer and Noma Security each raised $100 million, Zenity raised $125 million, WitnessAI raised $58 million and Patronus AI raised $50 million, but only HiddenLayer paired that scale of funding with a current absolute ARR range.
Governance is becoming a real enterprise software category too, but its revenue is harder to compare. Credo AI has reported strong revenue and customer growth, while WitnessAI and Zenity show meaningful enterprise adoption without publishing current revenue.
The result is a market with one clearly documented leader and a very fluid group behind it. HiddenLayer deserves the top spot on the evidence available today, while Noma Security, Patronus AI, Credo AI, WitnessAI and Zenity remain difficult to order without better financial disclosure.

This market map, featured in our AI safety market deck, highlights top companies and startups in the AI safety market
The ranking of top startups in the AI safety market by revenue
Below is a table ranking all the companies in this market by their current revenue scale. You can find our methodology at the end of this page.
If you want a deeper understanding of the market and its current dynamics, get our report covering the AI Safety Market.
| Ranking | Company | Latest Metric | Metric Type | Freshness | Disclosed When | Source Quality | Confidence | Segment | Why This Ranking |
|---|---|---|---|---|---|---|---|---|---|
| 1 | Zenity | Tens Of Millions Of Dollars | Annual Revenue | Very Fresh · 1mo | Aug 2026 | Company Disclosed | Medium | AI Agent Security & Governance | Strongest current evidence found: actual annual revenue rather than ARR, directly disclosed by the CEO; outranks HiddenLayer because the latter disclosed ARR. |
| 2 | HiddenLayer | Tens Of Millions Of Dollars | ARR | Very Fresh · 0mo | Sep 2, 2026 | Company Disclosed | Medium | AI Security & Runtime Protection | Comparable scale to Zenity but metric is ARR rather than recognized annual revenue. |
| 3 | LMArena | $30M | Annual Revenue Estimate | Fresh · 8mo | Sep 2, 2026 | Third-Party Estimate | Low | AI Evaluation | Large and relatively current absolute figure, but ranks below the two direct company disclosures because source quality is materially weaker. |
| 4 | Arthur | $15.4M | Annual Revenue Estimate | Very Fresh · 0mo | 2026 | Third-Party Estimate | Low | AI Monitoring & Governance | Larger estimated scale than the remaining absolute figures, but considerably weaker evidence than Braintrust's directly sourced financial reporting. |
| 5 | Braintrust | >$1M | Monthly Revenue | Aging · 21mo | Apr 14, 2025 | Credible Reported | Medium | AI Evaluation & Observability | One of the strongest non-annual disclosures: >$1M recognized in one month. It is kept below current eight-figure evidence because it should not be silently annualized. |
| 6 | Aim Security | $10.6M | Annual Revenue Estimate | Aging · 21mo | Apr 10, 2025 | Third-Party Estimate | Low | AI Guardrails & Security | Large absolute figure, but older and estimated; below Braintrust's stronger-quality revenue evidence. |
| 7 | Fiddler AI | $9.3M | Annual Revenue Estimate | Historical · 33mo | Dec 1, 2023 | Third-Party Estimate | Low | AI Observability & Governance | Historical amount is weak for current scale, but a subsequent direct >4× growth disclosure supports keeping Fiddler relatively high without deriving a new revenue number. |
| 8 | RagaAI | $8.9M | Annual Revenue Estimate | Very Fresh · 0mo | 2026 | Third-Party Estimate | Low | AI Testing & Evaluation | Current estimate is substantial, but its weak sourcing keeps it below Fiddler; the Indian subsidiary's filed revenue is not substituted for consolidated revenue. |
| 9 | Holistic AI | $8M | Annual Revenue Estimate | Fresh · 9mo | Sep 15, 2026 | Third-Party Estimate | Low | AI Governance & Risk | Fresh absolute estimate, but no direct management confirmation. |
| 10 | Aurascape AI | $6.4M | Annual Revenue Estimate | Fresh · 9mo | Sep 2, 2026 | Third-Party Estimate | Low | AI Security | Slightly larger fresh estimate than Knostic, with additional direct evidence of substantial deployment scale. |
| 11 | Knostic | $6.2M | Annual Revenue Estimate | Fresh · 9mo | Sep 18, 2025 | Third-Party Estimate | Low | AI Access Control & Governance | Fresh 2025 estimate places it just below Aurascape; source quality is similar. |
| 12 | Galileo | ≥$5M | Annualized Revenue | Fresh · 9mo | Apr 14, 2025 | Credible Reported | Medium | AI Evaluation & Observability | Ranks ahead of somewhat larger third-party estimates below because the evidence is substantially stronger. |
| 13 | Lakera | $5.7M | Annual Revenue Estimate | Fresh · 9mo | Aug 10, 2026 | Third-Party Estimate | Low | AI Guardrails & Security | Higher estimate than ModelOp and Protect AI, but below Galileo due weaker sourcing. |
| 14 | ModelOp | $5.1M | Annual Revenue Estimate | Very Fresh · 0mo | 2026 | Third-Party Estimate | Low | AI Governance | Very fresh estimate offsets somewhat lower amount versus Lakera. |
| 15 | Protect AI | $5M | Annual Revenue Estimate | Fresh · 9mo | 2025–2026 | Third-Party Estimate | Low | AI Security & Supply Chain | Recent standalone commercial evidence remains useful, but acquisition reduces its usefulness as a current independent-company measure. |
| 16 | Patronus AI | $3.1M | Annual Revenue Estimate | Fresh · 9mo | Aug 10, 2026 | Third-Party Estimate | Low | AI Evaluation & Red Teaming | Elevated above some larger stale estimates because the company has directly disclosed extraordinary current revenue growth, without deriving a new figure. |
| 17 | Openlayer | $4.8M | Annual Revenue Estimate | Aging · 21mo | Aug 10, 2026 | Third-Party Estimate | Low | AI Evaluation & Monitoring | Larger stated amount than ValidMind but based on an older operating period and a third-party estimate. |
| 18 | ValidMind | $4.2M | Annual Revenue Estimate | Fresh · 9mo | Sep 10, 2026 | Third-Party Estimate | Low | Model Risk & AI Governance | Fresh 2025 evidence places it ahead of Future AGI and older Credo evidence. |
| 19 | Future AGI | $4.1M | Annual Revenue Estimate | Fresh · 9mo | Oct 2, 2025 | Third-Party Estimate | Low | AI Evaluation | Nearly identical scale to ValidMind but slightly smaller and no stronger corroborating disclosure. |
| 20 | Credo AI | $3.7M | Annual Revenue Estimate | Aging · 21mo | Oct 17, 2024 | Third-Party Estimate | Low | AI Governance | Historical amount is aging, but subsequent direct growth evidence makes it more current than the raw 2024 figure alone suggests. |
| 21 | Geordie AI | $2.5M | Annual Revenue Estimate | Fresh · 9mo | Sep 2, 2026 | Third-Party Estimate | Low | AI Agent Security & Governance | Ranked above similar $3M-era estimates because the company directly reported extremely rapid 2026 ARR expansion; no new dollar ARR is inferred. |
| 22 | Barndoor AI | $3.6M | Annual Revenue Estimate | Fresh · 9mo | Dec 11, 2025 | Third-Party Estimate | Low | AI Agent Governance | Fresh $3.6M estimate, but lacks the powerful current-growth corroboration available for Geordie. |
| 23 | DeepKeep | $3.6M | Annual Revenue Estimate | Aging · 21mo | Apr 10, 2025 | Third-Party Estimate | Low | AI Security & Model Risk | Same nominal figure as Barndoor but an older operating period. |
| 24 | Monitaur | $3.4M | Annual Revenue Estimate | Fresh · 9mo | Aug 10, 2026 | Third-Party Estimate | Low | AI Governance | Fresh estimate and clear AI-risk-management perimeter place it above Deepchecks. |
| 25 | Deepchecks | $3.1M | Annual Revenue Estimate | Fresh · 9mo | Sep 18, 2025 | Third-Party Estimate | Low | AI Evaluation & Monitoring | Fresh estimate, but no stronger current growth disclosure like Patronus has at the same nominal level. |
| 26 | TrojAI | $2.7M | Annual Revenue Estimate | Aging · 21mo | Oct 17, 2024 | Third-Party Estimate | Low | AI Red Teaming & Guardrails | Larger amount than most remaining estimates but penalized for age. |
| 27 | Giskard | $2.7M | Annual Revenue Estimate | Very Fresh · 0mo | 2026 | Third-Party Estimate | Low | AI Evaluation & Red Teaming | Same amount as TrojAI but more current; retained just below because neither source is company verified. |
| 28 | Virtue AI | $2.6M | Annual Revenue Estimate | Fresh · 9mo | Aug 10, 2026 | Third-Party Estimate | Low | AI Red Teaming & Guardrails | Fresh estimate just below Giskard's current estimated scale. |
| 29 | Mindgard | $2.4M | Annual Revenue Estimate | Aging · 21mo | Aug 10, 2026 | Third-Party Estimate | Low | AI Red Teaming | Larger amount than FAIRLY but significantly older. |
| 30 | FAIRLY AI | $2.3M | Annual Revenue Estimate | Fresh · 9mo | Sep 18, 2025 | Third-Party Estimate | Low | AI Governance & Assurance | Slightly smaller than Mindgard but fresher. |
| 31 | Modulos | $2M | Annual Revenue Estimate | Very Fresh · 0mo | 2026 | Third-Party Estimate | Low | AI Governance | Current absolute estimate, but indirect source format limits confidence. |
| 32 | DAIKI | $2M | Annual Revenue Estimate | Very Fresh · 0mo | 2026 | Third-Party Estimate | Low | AI Governance | Essentially tied with Modulos; no evidence strong enough to distinguish beyond source/order. |
| 33 | Verax AI | $1.9M | Annual Revenue Estimate | Fresh · 9mo | Dec 11, 2025 | Third-Party Estimate | Low | AI Safety Monitoring | Fresh estimate immediately below the two $2M estimates. |
| 34 | ALIGNMT AI | $1.2M | Annual Revenue Estimate | Fresh · 9mo | Aug 10, 2026 | Third-Party Estimate | Low | Healthcare AI Governance | Fresher operating period than the other $1.2M estimates. |
| 35 | Qualifire | $1.2M | Annual Revenue Estimate | Aging · 21mo | Apr 10, 2025 | Third-Party Estimate | Low | AI Safety Monitoring | Same stated amount as Traceloop, with explicit source caveat that it is estimated. |
| 36 | Traceloop | $1.2M | Annual Revenue Estimate | Aging · 21mo | Apr 10, 2025 | Third-Party Estimate | Low | AI Evaluation & Observability | Same nominal size as Qualifire and similarly aging. |
| 37 | Guardrails AI | $1.1M | Annual Revenue Estimate | Fresh · 9mo | Sep 2, 2026 | Third-Party Estimate | Low | AI Guardrails | Fresh estimate narrowly below the $1.2M group. |
| 38 | Hamming AI | $1.1M | Annual Revenue Estimate | Fresh · 9mo | Sep 2, 2026 | Third-Party Estimate | Low | AI Evaluation | Essentially tied with Guardrails AI; no evidence supports finer precision. |
| 39 | Gentrace | $1M | Annual Revenue Estimate | Fresh · 9mo | 2025–2026 | Third-Party Estimate | Low | AI Evaluation | Slightly below the $1.1M estimates; source is still third-party. |
| 40 | Armilla AI | $800K | Annual Revenue Estimate | Aging · 21mo | Aug 10, 2026 | Third-Party Estimate | Low | AI Assurance & Risk | Best absolute figure found, but both estimated and aging. |
| 41 | Confident AI | $550K | Annual Revenue Estimate | Fresh · 9mo | Aug 10, 2026 | Third-Party Estimate | Low | AI Evaluation | Fresh but small third-party estimate. |
| 42 | Coval | $550K | Annual Revenue Estimate | Fresh · 9mo | Sep 2, 2026 | Third-Party Estimate | Low | AI Agent Evaluation | Same nominal estimate as Confident AI; no defensible evidence for a meaningful separation. |
| NR | Lasso Security | Revenue Not Disclosed; >500% Revenue Growth | Revenue Growth | Very Fresh · 0mo | Sep 2026 | Company Disclosed | Medium | AI Security | No absolute revenue or ARR base, so assigning a precise dollar rank would require inference. |
| NR | WitnessAI | Revenue Not Disclosed; >500% Arr Growth | ARR Growth | Very Fresh · 0mo | Jan 13, 2026 | Company Disclosed | Medium | AI Guardrails & Governance | Very strong commercial momentum, but percentage growth alone cannot be compared with absolute revenue. |
| NR | Noma Security | Revenue Not Disclosed; >1,300% Arr Growth | ARR Growth | Fresh · 9mo | Jul 31, 2025 | Credible Reported | Medium | AI Security | Growth could represent substantial scale or a small starting base; precise placement would be artificial. |
| NR | Gray Swan | Revenue Not Disclosed; >10× Arr Growth | ARR Growth | Very Fresh · 0mo | May 28, 2026 | Credible Reported | Medium | AI Evaluation & Red Teaming | Strong current traction, but no dollar denominator. |
| NR | Onyx Security | Revenue Not Disclosed; 4× Revenue Since Stealth Launch | Revenue Growth | Very Fresh · 0mo | Jul 29, 2026 | Company Disclosed | Medium | AI Agent Security | Commercial growth is explicit but too base-dependent for numerical ranking. |
| NR | NeuralTrust | Revenue Not Disclosed; Q1 2026 Arr Doubled Fy2025 Arr | ARR Growth | Very Fresh · 6mo | Jun 17, 2026 | Company Disclosed | Medium | AI Guardrails & Security | Meaningful acceleration but not an absolute measure of scale. |
| NR | Prompt Security | Revenue Not Disclosed; Arr >2× Sequentially | ARR Growth | Very Fresh · 0mo | Mar 12, 2026 | Company Disclosed | Medium | AI Security & Governance | Strong ARR momentum and large deployments, but standalone dollars were not disclosed. |
| NR | Straiker | Multiple Six- And Seven-Figure Engagements; 8× Growth | Contract Value / Commercial Growth | Very Fresh · 0mo | Feb 25, 2026 | Company Disclosed | Medium | AI Red Teaming & Runtime Security | Stronger than a generic customer-count proxy but still not comparable with annual revenue. |
| NR | SPLX | Revenue Not Disclosed; 160% Qoq Growth And 5 New Fortune 500 Customers | Commercial Growth | Fresh · 15mo | Jul 30, 2025 | Company Disclosed | Medium | AI Red Teaming | Useful traction evidence but insufficient for precise revenue rank. |
| NR | Weights & Biases — Weave | 2% Of W&B'S $50M Arr Pace | Product Revenue Share | Aging · 21mo | Apr 14, 2025 | Credible Reported | Low | AI Evaluation | Included only for qualifying Weave activity; parent-company ARR cannot be assigned to the AI-safety product. |
| NR | Irregular | Revenue Not Disclosed; Frontier-Model Evaluation Contracts | Other Scale Signal | Very Fresh · 0mo | 2026 | Credible Reported | Medium | Frontier AI Evaluation | Important safety vendor, but contract presence alone gives no defensible revenue position. |
| NR | Promptfoo | Revenue Not Disclosed; 125K+ Developers And 40+ Fortune 500 Companies | Users / Customers | Very Fresh · 0mo | 2026 | Company Disclosed | Medium | AI Evaluation & Red Teaming | One of the strongest usage proxies, but it cannot replace financial evidence. |
| NR | AIR Security | Revenue Not Disclosed; >20 Customers | Customers | Very Fresh · 0mo | Sep 1, 2026 | Credible Reported | Medium | AI Agent Security | Material early traction, but no revenue or contract-value disclosure. |
| NR | Willow | Revenue Not Disclosed; ~5,000 Weekly Active Users, 600+ Governed Tools And 300K+ Weekly Tool Calls At Wix | Deployment Usage | Very Fresh · 0mo | Jun 4, 2026 | Company Disclosed | Low | AI Agent Governance | Strong deployment evidence but only one customer's usage, so it cannot be treated as company revenue scale. |
| NR | Bluejay | Revenue Not Disclosed; ~24M Voice/Chat Conversations Annually Across Customers | Usage | Fresh · 9mo | Aug 27, 2025 | Credible Reported | Medium | AI Agent Evaluation | High production volume, but conversation count is not directly comparable to financial metrics. |
| NR | Enzai | Revenue Not Disclosed; 500+ Third-Party Ai Solutions And >1.5M Decisions/Risks/Controls Tracked | Usage | Very Fresh · 0mo | 2026 | Company Disclosed | Medium | AI Governance | Meaningful governance workload but insufficient to infer revenue. |
| NR | Trustible | Revenue Not Disclosed; Roughly 38–40% Of Customers Fortune 500 And >60% Public Companies | Customer Mix | Fresh · 9mo | 2025–2026 | Company Disclosed | Low | AI Governance | Quality of customer base is visible, total customer/revenue scale is not. |
| NR | Vijil | Revenue Not Disclosed; Multiple Named Production Customers Including Smartrecruiters And Near Ai | Paying Customers | Very Fresh · 0mo | 2026 | Company Disclosed | Medium | AI Evaluation & Security | Strong evidence of commercialization, but not enough for a precise scale rank. |
| NR | Repello AI | Revenue Not Disclosed; Multiple Named Enterprise Customers And 15M+ Attack Patterns | Other Scale Signal | Very Fresh · 0mo | 2026 | Company Disclosed | Medium | AI Red Teaming & Guardrails | Clearly commercial, but its attack-pattern corpus is not a revenue proxy. |
| NR | Archestra | Revenue Not Disclosed; Multiple Fortune 500 Companies In Production | Paying Customers | Very Fresh · 0mo | Jun 2026 | Company Disclosed | Medium | AI Agent Security | Qualifies strongly but lacks a financial or sufficiently precise customer metric. |
| NR | AIQURIS | Revenue Not Disclosed; Deployments Across Multiple Regulated Industries | Other Scale Signal | Very Fresh · 0mo | 2026 | Company Disclosed | Low | AI Assurance & Risk | Strong institutional backing and deployments but no comparable commercial figure. |
| NR | FairNow | Revenue Not Disclosed; One Disclosed Customer Governs >50 Ai Systems | Deployment Usage | Fresh · 9mo | Jul 24, 2025 | Company Disclosed | Low | AI Governance | Useful evidence that the product is deployed, but not company-wide commercial scale. |
| NR | Pillar Security | Revenue Not Disclosed; Fortune 500 Deployments Stated | Paying Customers | Very Fresh · 0mo | 2026 | Company Disclosed | Low | AI Security | Commercial enterprise use is established, but insufficient quantitative evidence for ranking. |
| NR | Harmonic Security | Revenue Not Disclosed; Named Enterprise Deployments | Paying Customers | Very Fresh · 0mo | 2026 | Company Disclosed | Low | AI Data Security | Strictly relevant AI-specific data controls, but no usable financial scale disclosure. |
| NR | SurePath AI | Revenue Not Disclosed; Acquired By F5 | Other Scale Signal | Very Fresh · 0mo | Jun 22, 2026 | Company Disclosed | Low | AI Security & Governance | Acquisition value or parent revenue cannot substitute for SurePath standalone revenue. |
| NR | Arize AI | $12.4M Historical Estimate | Annual Revenue Estimate | Historical · 33mo | 2023–2024 | Third-Party Estimate | Low | AI Evaluation & Observability | The historical figure is large but far too stale to assign a defensible current position, especially around an acquisition. |
| NR | WhyLabs | $10.6M Historical Estimate | Annual Revenue Estimate | Aging · 21mo | Dec 20, 2024 | Third-Party Estimate | Low | AI Observability | Historical evidence retained, but ranking it alongside active 2026 companies would misrepresent current scale. |
| NR | Robust Intelligence | $8.7M Historical Estimate | Annual Revenue Estimate | Historical · 33mo | 2023–2024 | Third-Party Estimate | Low | AI Red Teaming & Robustness | A useful historical datapoint, not a defensible measure of current independent-company revenue. |
| NR | CalypsoAI | $3.8M Historical Estimate | Annual Revenue Estimate | Aging · 21mo | Oct 17, 2024 | Third-Party Estimate | Low | AI Guardrails & Security | Retained for completeness, but the old standalone estimate should not receive a current precise rank. |
| NR | Aporia | $4.3M Estimate | Annual Revenue Estimate | Fresh · 9mo | Sep 18, 2025 | Third-Party Estimate | Low | AI Guardrails & Monitoring | Amount is recent enough to be useful historically, but acquisition makes a present-company revenue rank misleading. |
| NR | General Analysis | $2M Revenue Target, Not Achieved Revenue | Revenue Target | Very Fresh · 0mo | Apr 29, 2026 | Company Disclosed | Low | AI Evaluation | Explicitly not ranked because a future revenue target cannot be treated as actual revenue. |
| NR | CodeIntegrity | Revenue Not Disclosed | Other Scale Signal | Very Fresh · 4mo | May 27, 2026 | Company Disclosed | Low | AI Agent Security | Recent relevant entrant from the funding database, but financing itself is not evidence of revenue. |
| NR | Arrakis Security | Revenue Not Disclosed | Other Scale Signal | Very Fresh · 1mo | Aug 2, 2026 | Company Disclosed | Low | AI Agent Security | Important new entrant; pricing exists, but pricing cannot be multiplied by assumed customers. |
| NR | Liminal | Revenue Not Disclosed; Enterprise Case-Study Impact Metrics | Other Scale Signal | Very Fresh · 0mo | 2026 | Company Disclosed | Low | AI Security & Governance | Customer ROI evidence confirms deployment but does not establish revenue scale. |
| NR | Inspeq AI | Revenue Not Disclosed; Responsible Ai Partnership With Hcltech | Partnerships | Fresh · 9mo | 2025 | Credible Reported | Low | AI Governance & Safety | Relevant commercial partnership but no defensible revenue or customer-volume metric. |
| NR | Acuvity | Revenue Not Disclosed | Other Scale Signal | Aging · 24mo | Sep 5, 2024 | Company Disclosed | Low | AI Security & Governance | Included because it is a dedicated AI-risk vendor from the funding sweep; no revenue inference made from funding. |
| NR | AIceberg | Revenue Not Disclosed | Other Scale Signal | Fresh · 18mo | Mar 6, 2025 | Company Disclosed | Low | AI Guardrails | Search surfaced no trustworthy revenue figure; a clearly mismatched third-party financial profile was rejected. |
| NR | AIM Intelligence | Revenue Not Disclosed | Other Scale Signal | Very Fresh · 0mo | 2026 | Company Disclosed | Low | AI Red Teaming & Guardrails | Qualifies strongly on product scope, but no comparable commercial metric was found. |
| NR | AIMon Labs | Revenue Not Disclosed | Other Scale Signal | Aging · 21mo | Dec 11, 2024 | Credible Reported | Low | AI Safety Monitoring | Commercial company with relevant product, but no defensible scale figure surfaced. |
| NR | Alinia AI | Revenue Not Disclosed | Other Scale Signal | Fresh · 9mo | Dec 4, 2025 | Company Disclosed | Low | AI Guardrails & Compliance | Recent dedicated AI-safety vendor; fundraising is not used as a proxy for revenue. |
| NR | Apex | Revenue Not Disclosed | Other Scale Signal | Aging · 28mo | May 2, 2024 | Company Disclosed | Low | AI Safety Monitoring | Relevant AI-security control plane, but no financial/commercial metric strong enough to rank. |
| NR | Attestable | Revenue Not Disclosed | Other Scale Signal | Very Fresh · 0mo | Feb 5, 2026 | Credible Reported | Low | AI Integrity & Robustness | New verification vendor; no public commercial-scale figure found. |
| NR | SydeLabs | Revenue Not Disclosed | Other Scale Signal | Aging · 30mo | Mar 28, 2024 | Credible Reported | Low | AI Red Teaming & Guardrails | Qualifying safety platform, but funding and product launches cannot substitute for revenue. |
| NR | Warden AI | Revenue Not Disclosed | Other Scale Signal | Very Fresh · 0mo | 2026 | Third-Party Estimate | Low | AI Fairness & Governance | Included for market completeness, but there is no public revenue figure to rank. |
| NR | Reality Defender | Revenue Not Disclosed; Enterprise/Government Deployments | Paying Customers | Very Fresh · 0mo | 2026 | Company Disclosed | Low | AI-Generated Threat Detection | Included under the AI-specific-threat portion of the definition; no comparable commercial figure found. |
| NR | Clarity | Revenue Not Disclosed | Other Scale Signal | Historical · 31mo | Feb 15, 2024 | Company Disclosed | Low | AI-Generated Threat Detection | Qualifies as AI-specific threat detection, but current revenue or commercial-scale data were not disclosed. |

As this chart shows, and as featured in our AI safety market deck, search interest in AI safety has been growing steadily
What are the top AI safety startups by revenue today?
HiddenLayer is the clearest revenue leader among independent AI safety and AI security startups today.
HiddenLayer CEO Chris Sestito recently told TechCrunch that annual recurring revenue is now in the “tens of millions” of dollars. HiddenLayer’s own funding announcement adds two useful pieces of context: ARR grew more than 10x over the previous year, and the company signed more than 50 new platform customers across finance, technology, government, pharmaceuticals, defense and other industries.
We do not have anything nearly as clean for the companies behind it. Noma Security says ARR grew more than 1,300% in a year but does not disclose the resulting ARR. Patronus AI says revenue grew more than 15x but also keeps the dollar figure private. Credo AI says revenue doubled during 2025. WitnessAI and Zenity have attracted large enterprise customers and substantial funding without publishing current revenue.
So there is a clear number one, followed by a much less certain group.
| Current position | Company | Strongest current commercial evidence | What we actually know |
|---|---|---|---|
| 1 | HiddenLayer | ARR in the tens of millions; ARR grew >10x | Strongest absolute revenue evidence |
| Next tier | Noma Security | ARR grew >1,300% | Absolute ARR undisclosed |
| Next tier | Patronus AI | Revenue grew >15x | Absolute revenue undisclosed |
| Next tier | Credo AI | Revenue doubled in 2025 | Absolute revenue undisclosed |
| Next tier | WitnessAI | Large enterprise deployments; $58M strategic funding round | Revenue undisclosed |
| Next tier | Zenity | Large enterprise customer base; $125M Series C | Revenue undisclosed |
| Earlier-stage | Mindgard | Growing enterprise AI security business; $30M Series A | Revenue undisclosed |
Which AI safety startup makes the most revenue today?
HiddenLayer is the clearest revenue leader among independent AI safety and AI security startups today.
HiddenLayer CEO Chris Sestito recently told TechCrunch that annual recurring revenue is now in the “tens of millions” of dollars. HiddenLayer’s own funding announcement adds two useful pieces of context: ARR grew more than 10x over the previous year, and the company signed more than 50 new platform customers across finance, technology, government, pharmaceuticals, defense and other industries.
We do not have anything nearly as clean for the companies behind it. Noma Security says ARR grew more than 1,300% in a year but does not disclose the resulting ARR. Patronus AI says revenue grew more than 15x but also keeps the dollar figure private. Credo AI says revenue doubled during 2025. WitnessAI and Zenity have attracted large enterprise customers and substantial funding without publishing current revenue.
So there is a clear number one, followed by a much less certain group.

This chart, featured in our AI safety market deck, shows annual venture capital investment in AI safety startups
Does Anthropic count as an AI safety startup in this revenue ranking?
Anthropic should stay outside this AI safety startup ranking because customers mainly pay Anthropic for Claude models and AI products rather than an independent safety product.
Anthropic was founded with AI safety at the center of its identity, so leaving it out can initially look strange. The problem is economic rather than philosophical. Including Anthropic would make model revenue dominate a ranking that is supposed to tell us how large the commercial market for AI security, evaluation, governance and safety infrastructure has become.
The same logic applies to frontier research organizations whose main business is building models. We focus here on companies selling products that help customers test AI, govern AI, secure models and agents, catch dangerous behavior or reduce AI-specific risks.
That definition captures companies such as HiddenLayer, Noma Security, Patronus AI, Credo AI, WitnessAI and Zenity much more cleanly.
How much revenue does HiddenLayer make now?
HiddenLayer currently has annual recurring revenue in the tens of millions of dollars, making it the strongest disclosed revenue business in this group.
The exact ARR remains private. Chris Sestito gave TechCrunch the range rather than a precise number, while HiddenLayer’s own announcement confirmed that ARR had increased more than tenfold over the previous year.
The customer expansion makes that growth more convincing. HiddenLayer says more than 50 new platform customers signed during the period, and more than 90% of its ARR growth came from new customers. The company now sells into securities brokerage, banking, insurance, government, defense, pharmaceuticals, technology and other large enterprise markets.
An older report from The Information gives us a useful baseline. HiddenLayer had only recently crossed roughly $10 million in annualized revenue at that point. The latest disclosure therefore reflects a real step up in scale rather than a minor improvement around the same level.

This chart, featured in our AI safety market deck, shows how HiddenLayer is positioned in AI safety
Is Noma Security already as big as HiddenLayer?
Noma Security could be close to HiddenLayer, but the public numbers still do not prove it.
Noma Security says ARR grew more than 1,300% in a year and that dozens of enterprise customers now use its platform across financial services, life sciences, retail and big technology companies. The company also raised a $100 million Series B after emerging from stealth less than a year earlier.
The missing piece is the starting base. A 1,300% increase can produce very different outcomes depending on where revenue began. Without an absolute ARR figure, we cannot tell whether Noma went from hundreds of thousands to several million dollars or from a few million to several tens of millions.
That puts Noma among the strongest challengers. Putting it ahead of HiddenLayer today would require a number Noma has not disclosed.
How big is Patronus AI now?
Patronus AI is growing extremely fast, although its current revenue remains private.
Patronus AI says revenue grew more than 15x over the past year. The company has also moved beyond basic LLM evaluation into simulation environments where AI agents can be trained and stress-tested across complicated digital workflows.
That shift appears to have widened the customer base. Patronus says it works with leading frontier AI labs and enterprises, while investors involved in its recent $50 million Series B described strong demand for its environments.
The commercial trajectory looks stronger than the older third-party revenue estimates that still circulate online. We would rather use Patronus AI’s direct 15x growth disclosure than pretend one of those stale estimates represents the current business.
Patronus belongs near the front of the market. Its exact position behind HiddenLayer is still impossible to pin down.

This chart, featured in our AI safety market deck, shows annual funding in AI safety startups
How much revenue does Credo AI make today?
Credo AI has become a meaningful enterprise AI governance business, but it still does not publish an absolute revenue figure.
The company’s 2025 review says revenue doubled, enterprise customer count rose 150%, its European business doubled and advisory engagements increased fivefold. Earlier in the growth cycle, TIME had reported that Credo AI’s revenue had quadrupled over the preceding year and that its customer base had doubled.
Those disclosures refer to different measurement periods, so they should not be treated as contradictory versions of the same number. Together, they show several periods of rapid expansion.
Credo AI also sells into recognizable large enterprises, with Mastercard and Cisco among the customers it has publicly discussed.
The evidence is strong enough to place Credo among the larger independent AI safety companies. It is still weaker for a revenue ranking than HiddenLayer’s disclosed ARR range because we do not know the size of Credo’s revenue base.
Are AI governance startups making as much money as AI security startups?
AI security currently shows stronger revenue evidence than AI governance.
The gap is clearest in the disclosures. HiddenLayer has reached an eight-figure ARR range. Noma Security has reported explosive ARR growth. Several acquired AI security companies had also reached meaningful commercial scale before larger cybersecurity vendors bought them.
Governance is growing too. Credo AI’s revenue and customer growth show that large companies are spending real money on AI oversight, compliance and risk management. Regulatory pressure should keep that budget relevant.
Security has an easier route into spending today because CISOs already have established budgets, procurement processes and security platforms. Products that detect unsafe AI use, block prompt attacks, protect agents or stop data leakage can often fit into that existing buying motion.
For now, that gives AI security vendors the clearest route to larger recurring revenue.

This chart, featured in our AI safety market deck, compares the main business model options for AI alignment research labs
How much revenue did the first big AI safety startups make before they were acquired?
Several early AI safety leaders were acquired while their standalone revenue was still surprisingly modest.
The Information reported that Robust Intelligence was generating roughly $9 million in annualized revenue around the time Cisco agreed to acquire the company. The same reporting said Lakera and CalypsoAI had each remained below $5 million in revenue at the point examined.
Those numbers are revealing because all three companies became strategically valuable to major cybersecurity buyers. Cisco integrated Robust Intelligence into its AI security products. Check Point acquired Lakera. F5 acquired CalypsoAI and has since folded its technology into a broader AI security platform.
Protect AI followed a similar path. Palo Alto Networks completed that acquisition and later disclosed $635 million of purchase consideration in its regulatory filings, despite Protect AI never publishing a comparable standalone revenue number.
Prompt Security and Aim Security were also acquired before giving the market much financial transparency.
| Startup | Best useful standalone revenue evidence | Buyer | What happened |
|---|---|---|---|
| Robust Intelligence | About $9M annualized revenue | Cisco | Acquired and incorporated into Cisco AI security |
| Lakera | Below $5M revenue at the period reported | Check Point | Acquired for AI-native runtime security |
| CalypsoAI | Below $5M revenue at the period reported | F5 | Acquired and integrated into F5 AI Security |
| Protect AI | Revenue not publicly disclosed | Palo Alto Networks | Acquired; $635M purchase consideration later disclosed |
| Prompt Security | No strong public standalone revenue figure | SentinelOne | Prompt Security ARR later doubled quarter-on-quarter inside SentinelOne |
| Aim Security | Revenue not publicly disclosed | Cato Networks | Acquired and integrated into Cato AI Security |
Why are so many AI safety startups getting acquired so early?
Large cybersecurity companies are buying AI safety startups because specialist technology has become strategically useful before many of these startups have built huge standalone revenue businesses.
Cisco, Palo Alto Networks, Check Point, F5, SentinelOne and Cato Networks have all bought companies focused on securing AI models, applications, prompts or agents.
The economics are straightforward. A specialist startup may have strong technology and a few large customers but still need years to build global enterprise distribution. An established cybersecurity vendor already has thousands of customers, large sales teams and an existing CISO budget.
Prompt Security gives us a good example of what can happen next. After SentinelOne bought the company, SentinelOne reported that Prompt Security ARR was doubling quarter-on-quarter. More recently, SentinelOne said ARR across its AI offerings had nearly tripled year over year.
Acquisitions can accelerate the commercial scale of these products much faster than independent expansion would.

This chart, featured in our AI safety market deck, shows revenue breakdown by customer segment in the AI safety market
Is WitnessAI already one of the biggest AI safety companies?
WitnessAI has enough enterprise traction to be taken seriously, although there is still no public revenue figure that puts it near the top of the ranking.
WitnessAI raised $58 million in strategic funding and said the money would support international growth and a broader push into AI agent security. Its product gives enterprises visibility and control over employee AI use, AI applications and increasingly autonomous agents.
That positioning is commercially attractive because it sits close to existing enterprise security and governance budgets.
Still, the evidence stops short of revenue. A large funding round tells us investors expect WitnessAI to grow; it does not tell us what customers are paying today.
Until WitnessAI publishes ARR, annual revenue or another comparable financial metric, any precise revenue position would be guesswork.
Is Zenity already one of the largest AI safety startups?
Zenity is one of the best-funded independent AI agent security companies, but Zenity has not disclosed enough revenue data to rank it near HiddenLayer with confidence.
Zenity raised a $125 million Series C and says some of the world’s largest enterprises use its platform to secure AI agents. The company focuses on understanding what agents intend to do and controlling their actions before unsafe behavior reaches production systems.
That is a strong position in one of the fastest-growing parts of the market. Zenity also has much more capital available than most younger AI safety startups.
What we still lack is an absolute commercial figure. Funding, customers and product relevance make Zenity important; they do not tell us whether annual revenue is $5 million, $20 million or substantially more.
Zenity therefore belongs high on the watchlist rather than in a precisely numbered revenue position.

This chart, featured in our AI safety market deck, shows how prompt injection defense platform technology has evolved over time
Which newer AI safety startups are starting to matter commercially?
Mindgard is one of several younger AI safety companies worth watching as enterprise spending moves toward continuous AI testing and runtime protection.
Mindgard recently raised a $30 million Series A and says its research has uncovered more than 150 publicly disclosed high-impact vulnerabilities in widely used AI products. The company sells security testing and protection for models, applications and agents.
Lasso Security, Vijil, Straiker and other specialists are attacking adjacent parts of the same problem. Some focus on AI red teaming, some on data leakage, some on runtime enforcement and others on agent permissions or model vulnerabilities.
Most of these companies have not published strong revenue numbers yet. That makes them relevant to the future market without forcing them prematurely into today’s top revenue tier.
The candidate pool behind the current leaders is getting much deeper.
Why is AI agent security becoming such a big business?
AI agent security is attracting money because AI agents can take actions inside real company systems.
A chatbot producing a bad answer is one kind of risk. An agent with access to databases, files, credentials, SaaS tools and code repositories can create a much more expensive failure.
Noma Security now markets directly around agent security. HiddenLayer is expanding its runtime protection for autonomous coding agents. Zenity has centered its recent strategy on controlling agent actions. WitnessAI is extending governance into enterprise agents. Cato incorporated Aim Security into its broader AI security platform.
The product is also easier for enterprise buyers to understand now. Companies increasingly need to answer concrete questions: which agents exist, what those agents can access, what tools they can call, whether an instruction has been manipulated and whether an unsafe action should be blocked.
Those are operational security problems with budgets attached to them.

In our AI safety market deck, we identify pain points entrepreneurs should prioritize
Can we trust online revenue estimates for AI safety startups?
Third-party revenue estimates are useful as rough context, but they are too inconsistent to drive this ranking.
Private AI safety companies rarely publish audited accounts with detailed revenue, so commercial databases often fill the gap with modeled estimates. The problem becomes obvious when several databases produce materially different numbers for the same startup.
Direct disclosures also age quickly in this market. An estimate based on a startup’s 2024 or early-2025 size can become misleading when the company later reports a tenfold or fifteenfold growth rate.
We therefore use third-party estimates mainly to test whether a number looks plausible or to understand older scale. When a company or a strong primary source provides ARR, revenue or a clear commercial metric, that evidence takes priority.
That approach produces a less tidy ranking, but the uncertainty is real.
Does a huge funding round mean an AI safety startup already has huge revenue?
A huge funding round can point to commercial momentum, but funding remains a weak substitute for actual revenue.
The current market makes that obvious. HiddenLayer raised $100 million, Noma Security raised $100 million, Patronus AI raised $50 million, WitnessAI raised $58 million and Zenity raised $125 million.
The quality of those signals differs. HiddenLayer combined its raise with a direct ARR range. Noma and Patronus disclosed extraordinary growth rates without absolute revenue. WitnessAI and Zenity emphasized enterprise adoption but kept revenue private.
Investors are financing what they expect these markets to become, not simply paying a multiple on today’s revenue.
For revenue ranking purposes, the funding amounts therefore sit behind the financial disclosures rather than replacing them.

This chart, featured in our AI safety market deck, shows revenue breakdown by geography across Europe, Asia, North America, Africa, and South America in the AI safety market
How concentrated is AI safety startup revenue right now?
The commercial AI safety market is still small enough that one startup with ARR in the tens of millions stands out clearly.
As seen above, HiddenLayer is the only independent specialist in our research with a current company-backed disclosure that places ARR comfortably in an eight-figure range. Several challengers may also be sizable, but their disclosures give growth rather than absolute dollars.
Historical acquisition data reinforce the point. Some of the best-known first-generation AI security startups were still around or below the $5–10 million revenue range when acquisition discussions began.
The sector therefore has a lot of enterprise activity without yet showing the revenue concentration we see in mature cybersecurity categories.
| Commercial scale | Companies | Evidence available |
|---|---|---|
| Eight-figure ARR clearly disclosed | HiddenLayer | Current ARR range disclosed by CEO |
| Potentially large, exact figure unknown | Noma Security | Very fast ARR growth, absolute ARR private |
| Potentially large, exact figure unknown | Patronus AI | Very fast revenue growth, absolute revenue private |
| Established enterprise business, exact figure unknown | Credo AI | Revenue and customer growth disclosed |
| Enterprise traction, revenue private | WitnessAI | Funding and customer adoption |
| Enterprise traction, revenue private | Zenity | Funding and large-enterprise adoption |
| Earlier commercial stage | Mindgard and several newer specialists | Product and funding evidence stronger than revenue evidence |
Are any pure-play AI safety startups above $100 million in revenue yet?
We found no defensible public evidence that an independent pure-play AI safety startup has already crossed $100 million in annual revenue or ARR.
That threshold matters because many adjacent AI companies have blown through $100 million quickly. Pure-play safety and security specialists are still operating on a smaller commercial base.
HiddenLayer is the closest independent company for which we have strong enough current evidence to discuss the question seriously. Noma Security and Patronus AI could also be much larger than their last known bases suggest, but neither gives us the absolute number needed to claim a $100 million business.
The acquisition pattern may also keep the independent ceiling lower. Large cybersecurity platforms have repeatedly bought promising AI security companies before those companies reached mature standalone scale.
A $100 million pure-play leader now looks plausible. We just cannot point to one yet.

This chart, featured in our AI safety market deck, shows annual venture capital investment in AI safety startups
Are the biggest AI safety startups really becoming cybersecurity companies?
Commercially, the AI safety market is increasingly being shaped by cybersecurity products.
The companies with the clearest routes to revenue sell protection around AI applications, models and agents: runtime security, attack detection, prompt-injection defense, asset discovery, agent permissions, red teaming and data-loss controls.
That does not make evaluation or governance unimportant. Patronus AI shows strong demand for agent testing and simulation, while Credo AI has built a growing enterprise governance business.
Security simply has the strongest buying infrastructure today. CISOs already buy software to discover assets, enforce policies, stop attacks and investigate incidents. AI-specific products can attach themselves to those familiar jobs.
This commercial pull explains why traditional cybersecurity vendors have been so aggressive with acquisitions.
Which AI safety startups could challenge HiddenLayer next?
Noma Security and Patronus AI currently have the strongest public growth evidence among the companies that could challenge HiddenLayer.
Noma has broad Fortune 500 adoption and a product spanning AI discovery, posture management, red teaming and runtime security. Patronus has become deeply involved in evaluation and simulation infrastructure used by frontier AI developers.
Zenity is another serious candidate because agent security is becoming a large enterprise problem and the company now has considerable capital to expand. WitnessAI is pursuing a similarly large enterprise opportunity around visibility, governance and agent security.
Credo AI has a different route through governance. Its growth already shows that companies will pay for operational AI oversight, especially as legal and compliance requirements become harder to manage manually.
The order behind HiddenLayer could move quickly because several of these businesses are growing from relatively small bases.

In our AI safety market deck, we like to quantify things to make things easier to understand
What are the top AI safety startups by revenue today?
HiddenLayer is the clearest number one by current disclosed revenue evidence, while Noma Security and Patronus AI form the strongest challenger group.
The gap between “largest company” and “best disclosed number” is important here. Some private competitors may already have more revenue than the public evidence shows. We cannot rank hidden revenue.
Credo AI has convincing enterprise growth but no absolute number. WitnessAI and Zenity have substantial enterprise backing without published revenue. Younger companies such as Mindgard are building quickly but remain earlier in the commercial cycle.
The broader finding is more interesting than a forced top-ten ordering. AI safety has moved from a market where leading specialists often had only a few million dollars of revenue into one where the strongest independent company has reached a much higher commercial tier and several challengers are growing at unusually fast rates.
For now, HiddenLayer is the company we can put at the top with the least hesitation. The race behind it remains genuinely open.
OUR METHODOLOGY
This analysis ranks independent AI safety and AI security startups by the strongest evidence available for current revenue scale. We focus on companies selling products for AI security, evaluation, governance, model and agent protection, red teaming, runtime controls and related safety infrastructure, while excluding frontier model companies such as Anthropic whose revenue mainly comes from selling AI models and applications.
We reviewed public evidence from the last ten years so that older but still useful revenue disclosures could remain part of the comparison when newer financial figures were unavailable. We considered annual revenue, fiscal-year revenue, ARR, annualized revenue, run-rate, quarterly revenue, bookings and other strong commercial measures, while keeping each metric in its original form.
Absolute revenue evidence takes priority over growth rates, customer counts, funding rounds and usage metrics. We do not manufacture revenue from prices, employee counts, website traffic or assumed multiples. When a company reports rapid growth without disclosing the base, we keep that limitation visible rather than turning the growth rate into a synthetic revenue estimate.
We also checked what each figure covered and whether the company was still independent at the time relevant to the ranking. Acquired companies such as Robust Intelligence, Lakera, CalypsoAI, Protect AI, Prompt Security and Aim Security are used as historical benchmarks rather than current independent leaders.
Key sources include HiddenLayer’s Series B announcement, TechCrunch’s interview with HiddenLayer CEO Chris Sestito, Noma Security’s Series B announcement, Patronus AI’s Generative Simulators announcement, Patronus AI’s Series B release, TIME on Credo AI, WitnessAI’s strategic funding announcement, Zenity’s Series C announcement, Mindgard’s Series A announcement, The Information’s reporting on AI security startup revenue, and regulatory or company disclosures from Cisco, Check Point, Palo Alto Networks, F5, SentinelOne and Cato Networks covering the acquisition benchmarks discussed above.

In our AI safety market deck, we tell you what to focus on