What are the top AI safety startups by revenue today?

Last updated: 21 September 2026
market research pitch 2026 statistics AI safety market

In our AI safety market deck, you will find everything you need to understand the market

SUMMARY

HiddenLayer is the clearest revenue leader among independent AI safety and AI security startups today, with annual recurring revenue in the tens of millions of dollars.

The ranking is unusually dependent on disclosure quality. Noma Security and Patronus AI may be much closer to HiddenLayer than the public numbers suggest, but both disclose growth rates rather than absolute revenue.

Noma Security’s more than 1,300% ARR growth and Patronus AI’s more than 15x revenue growth are impressive, but neither tells us the size of the current business without a starting base. That is why they belong in the challenger group rather than in a precise numerical order.

The independent revenue ceiling is still modest compared with adjacent AI markets. We found no defensible public evidence that a pure-play AI safety startup has crossed $100 million in annual revenue or ARR.

Acquisitions are part of the reason. Robust Intelligence was around $9 million in annualized revenue when Cisco moved to acquire it, while Lakera and CalypsoAI were still below $5 million in the periods reported.

Commercially, AI safety is increasingly being sold through cybersecurity budgets. Runtime protection, prompt-injection defense, agent permissions, asset discovery and data-loss controls are easier to attach to existing security buying motions than a broad promise of “AI safety.”

AI agent security is making that shift even stronger. Once agents can access files, credentials, databases, SaaS tools and code repositories, the risk becomes operational and much easier for an enterprise buyer to budget for.

Funding is running ahead of disclosed revenue. HiddenLayer and Noma Security each raised $100 million, Zenity raised $125 million, WitnessAI raised $58 million and Patronus AI raised $50 million, but only HiddenLayer paired that scale of funding with a current absolute ARR range.

Governance is becoming a real enterprise software category too, but its revenue is harder to compare. Credo AI has reported strong revenue and customer growth, while WitnessAI and Zenity show meaningful enterprise adoption without publishing current revenue.

The result is a market with one clearly documented leader and a very fluid group behind it. HiddenLayer deserves the top spot on the evidence available today, while Noma Security, Patronus AI, Credo AI, WitnessAI and Zenity remain difficult to order without better financial disclosure.

Market map chart showing top companies and startups in the AI safety market

This market map, featured in our AI safety market deck, highlights top companies and startups in the AI safety market

The ranking of top startups in the AI safety market by revenue

Below is a table ranking all the companies in this market by their current revenue scale. You can find our methodology at the end of this page.

If you want a deeper understanding of the market and its current dynamics, get our report covering the AI Safety Market.

Ranking Company Latest Metric Metric Type Freshness Disclosed When Source Quality Confidence Segment Why This Ranking
1 Zenity Tens Of Millions Of Dollars Annual Revenue Very Fresh · 1mo Aug 2026 Company Disclosed Medium AI Agent Security & Governance Strongest current evidence found: actual annual revenue rather than ARR, directly disclosed by the CEO; outranks HiddenLayer because the latter disclosed ARR.
2 HiddenLayer Tens Of Millions Of Dollars ARR Very Fresh · 0mo Sep 2, 2026 Company Disclosed Medium AI Security & Runtime Protection Comparable scale to Zenity but metric is ARR rather than recognized annual revenue.
3 LMArena $30M Annual Revenue Estimate Fresh · 8mo Sep 2, 2026 Third-Party Estimate Low AI Evaluation Large and relatively current absolute figure, but ranks below the two direct company disclosures because source quality is materially weaker.
4 Arthur $15.4M Annual Revenue Estimate Very Fresh · 0mo 2026 Third-Party Estimate Low AI Monitoring & Governance Larger estimated scale than the remaining absolute figures, but considerably weaker evidence than Braintrust's directly sourced financial reporting.
5 Braintrust >$1M Monthly Revenue Aging · 21mo Apr 14, 2025 Credible Reported Medium AI Evaluation & Observability One of the strongest non-annual disclosures: >$1M recognized in one month. It is kept below current eight-figure evidence because it should not be silently annualized.
6 Aim Security $10.6M Annual Revenue Estimate Aging · 21mo Apr 10, 2025 Third-Party Estimate Low AI Guardrails & Security Large absolute figure, but older and estimated; below Braintrust's stronger-quality revenue evidence.
7 Fiddler AI $9.3M Annual Revenue Estimate Historical · 33mo Dec 1, 2023 Third-Party Estimate Low AI Observability & Governance Historical amount is weak for current scale, but a subsequent direct >4× growth disclosure supports keeping Fiddler relatively high without deriving a new revenue number.
8 RagaAI $8.9M Annual Revenue Estimate Very Fresh · 0mo 2026 Third-Party Estimate Low AI Testing & Evaluation Current estimate is substantial, but its weak sourcing keeps it below Fiddler; the Indian subsidiary's filed revenue is not substituted for consolidated revenue.
9 Holistic AI $8M Annual Revenue Estimate Fresh · 9mo Sep 15, 2026 Third-Party Estimate Low AI Governance & Risk Fresh absolute estimate, but no direct management confirmation.
10 Aurascape AI $6.4M Annual Revenue Estimate Fresh · 9mo Sep 2, 2026 Third-Party Estimate Low AI Security Slightly larger fresh estimate than Knostic, with additional direct evidence of substantial deployment scale.
11 Knostic $6.2M Annual Revenue Estimate Fresh · 9mo Sep 18, 2025 Third-Party Estimate Low AI Access Control & Governance Fresh 2025 estimate places it just below Aurascape; source quality is similar.
12 Galileo ≥$5M Annualized Revenue Fresh · 9mo Apr 14, 2025 Credible Reported Medium AI Evaluation & Observability Ranks ahead of somewhat larger third-party estimates below because the evidence is substantially stronger.
13 Lakera $5.7M Annual Revenue Estimate Fresh · 9mo Aug 10, 2026 Third-Party Estimate Low AI Guardrails & Security Higher estimate than ModelOp and Protect AI, but below Galileo due weaker sourcing.
14 ModelOp $5.1M Annual Revenue Estimate Very Fresh · 0mo 2026 Third-Party Estimate Low AI Governance Very fresh estimate offsets somewhat lower amount versus Lakera.
15 Protect AI $5M Annual Revenue Estimate Fresh · 9mo 2025–2026 Third-Party Estimate Low AI Security & Supply Chain Recent standalone commercial evidence remains useful, but acquisition reduces its usefulness as a current independent-company measure.
16 Patronus AI $3.1M Annual Revenue Estimate Fresh · 9mo Aug 10, 2026 Third-Party Estimate Low AI Evaluation & Red Teaming Elevated above some larger stale estimates because the company has directly disclosed extraordinary current revenue growth, without deriving a new figure.
17 Openlayer $4.8M Annual Revenue Estimate Aging · 21mo Aug 10, 2026 Third-Party Estimate Low AI Evaluation & Monitoring Larger stated amount than ValidMind but based on an older operating period and a third-party estimate.
18 ValidMind $4.2M Annual Revenue Estimate Fresh · 9mo Sep 10, 2026 Third-Party Estimate Low Model Risk & AI Governance Fresh 2025 evidence places it ahead of Future AGI and older Credo evidence.
19 Future AGI $4.1M Annual Revenue Estimate Fresh · 9mo Oct 2, 2025 Third-Party Estimate Low AI Evaluation Nearly identical scale to ValidMind but slightly smaller and no stronger corroborating disclosure.
20 Credo AI $3.7M Annual Revenue Estimate Aging · 21mo Oct 17, 2024 Third-Party Estimate Low AI Governance Historical amount is aging, but subsequent direct growth evidence makes it more current than the raw 2024 figure alone suggests.
21 Geordie AI $2.5M Annual Revenue Estimate Fresh · 9mo Sep 2, 2026 Third-Party Estimate Low AI Agent Security & Governance Ranked above similar $3M-era estimates because the company directly reported extremely rapid 2026 ARR expansion; no new dollar ARR is inferred.
22 Barndoor AI $3.6M Annual Revenue Estimate Fresh · 9mo Dec 11, 2025 Third-Party Estimate Low AI Agent Governance Fresh $3.6M estimate, but lacks the powerful current-growth corroboration available for Geordie.
23 DeepKeep $3.6M Annual Revenue Estimate Aging · 21mo Apr 10, 2025 Third-Party Estimate Low AI Security & Model Risk Same nominal figure as Barndoor but an older operating period.
24 Monitaur $3.4M Annual Revenue Estimate Fresh · 9mo Aug 10, 2026 Third-Party Estimate Low AI Governance Fresh estimate and clear AI-risk-management perimeter place it above Deepchecks.
25 Deepchecks $3.1M Annual Revenue Estimate Fresh · 9mo Sep 18, 2025 Third-Party Estimate Low AI Evaluation & Monitoring Fresh estimate, but no stronger current growth disclosure like Patronus has at the same nominal level.
26 TrojAI $2.7M Annual Revenue Estimate Aging · 21mo Oct 17, 2024 Third-Party Estimate Low AI Red Teaming & Guardrails Larger amount than most remaining estimates but penalized for age.
27 Giskard $2.7M Annual Revenue Estimate Very Fresh · 0mo 2026 Third-Party Estimate Low AI Evaluation & Red Teaming Same amount as TrojAI but more current; retained just below because neither source is company verified.
28 Virtue AI $2.6M Annual Revenue Estimate Fresh · 9mo Aug 10, 2026 Third-Party Estimate Low AI Red Teaming & Guardrails Fresh estimate just below Giskard's current estimated scale.
29 Mindgard $2.4M Annual Revenue Estimate Aging · 21mo Aug 10, 2026 Third-Party Estimate Low AI Red Teaming Larger amount than FAIRLY but significantly older.
30 FAIRLY AI $2.3M Annual Revenue Estimate Fresh · 9mo Sep 18, 2025 Third-Party Estimate Low AI Governance & Assurance Slightly smaller than Mindgard but fresher.
31 Modulos $2M Annual Revenue Estimate Very Fresh · 0mo 2026 Third-Party Estimate Low AI Governance Current absolute estimate, but indirect source format limits confidence.
32 DAIKI $2M Annual Revenue Estimate Very Fresh · 0mo 2026 Third-Party Estimate Low AI Governance Essentially tied with Modulos; no evidence strong enough to distinguish beyond source/order.
33 Verax AI $1.9M Annual Revenue Estimate Fresh · 9mo Dec 11, 2025 Third-Party Estimate Low AI Safety Monitoring Fresh estimate immediately below the two $2M estimates.
34 ALIGNMT AI $1.2M Annual Revenue Estimate Fresh · 9mo Aug 10, 2026 Third-Party Estimate Low Healthcare AI Governance Fresher operating period than the other $1.2M estimates.
35 Qualifire $1.2M Annual Revenue Estimate Aging · 21mo Apr 10, 2025 Third-Party Estimate Low AI Safety Monitoring Same stated amount as Traceloop, with explicit source caveat that it is estimated.
36 Traceloop $1.2M Annual Revenue Estimate Aging · 21mo Apr 10, 2025 Third-Party Estimate Low AI Evaluation & Observability Same nominal size as Qualifire and similarly aging.
37 Guardrails AI $1.1M Annual Revenue Estimate Fresh · 9mo Sep 2, 2026 Third-Party Estimate Low AI Guardrails Fresh estimate narrowly below the $1.2M group.
38 Hamming AI $1.1M Annual Revenue Estimate Fresh · 9mo Sep 2, 2026 Third-Party Estimate Low AI Evaluation Essentially tied with Guardrails AI; no evidence supports finer precision.
39 Gentrace $1M Annual Revenue Estimate Fresh · 9mo 2025–2026 Third-Party Estimate Low AI Evaluation Slightly below the $1.1M estimates; source is still third-party.
40 Armilla AI $800K Annual Revenue Estimate Aging · 21mo Aug 10, 2026 Third-Party Estimate Low AI Assurance & Risk Best absolute figure found, but both estimated and aging.
41 Confident AI $550K Annual Revenue Estimate Fresh · 9mo Aug 10, 2026 Third-Party Estimate Low AI Evaluation Fresh but small third-party estimate.
42 Coval $550K Annual Revenue Estimate Fresh · 9mo Sep 2, 2026 Third-Party Estimate Low AI Agent Evaluation Same nominal estimate as Confident AI; no defensible evidence for a meaningful separation.
NR Lasso Security Revenue Not Disclosed; >500% Revenue Growth Revenue Growth Very Fresh · 0mo Sep 2026 Company Disclosed Medium AI Security No absolute revenue or ARR base, so assigning a precise dollar rank would require inference.
NR WitnessAI Revenue Not Disclosed; >500% Arr Growth ARR Growth Very Fresh · 0mo Jan 13, 2026 Company Disclosed Medium AI Guardrails & Governance Very strong commercial momentum, but percentage growth alone cannot be compared with absolute revenue.
NR Noma Security Revenue Not Disclosed; >1,300% Arr Growth ARR Growth Fresh · 9mo Jul 31, 2025 Credible Reported Medium AI Security Growth could represent substantial scale or a small starting base; precise placement would be artificial.
NR Gray Swan Revenue Not Disclosed; >10× Arr Growth ARR Growth Very Fresh · 0mo May 28, 2026 Credible Reported Medium AI Evaluation & Red Teaming Strong current traction, but no dollar denominator.
NR Onyx Security Revenue Not Disclosed; 4× Revenue Since Stealth Launch Revenue Growth Very Fresh · 0mo Jul 29, 2026 Company Disclosed Medium AI Agent Security Commercial growth is explicit but too base-dependent for numerical ranking.
NR NeuralTrust Revenue Not Disclosed; Q1 2026 Arr Doubled Fy2025 Arr ARR Growth Very Fresh · 6mo Jun 17, 2026 Company Disclosed Medium AI Guardrails & Security Meaningful acceleration but not an absolute measure of scale.
NR Prompt Security Revenue Not Disclosed; Arr >2× Sequentially ARR Growth Very Fresh · 0mo Mar 12, 2026 Company Disclosed Medium AI Security & Governance Strong ARR momentum and large deployments, but standalone dollars were not disclosed.
NR Straiker Multiple Six- And Seven-Figure Engagements; 8× Growth Contract Value / Commercial Growth Very Fresh · 0mo Feb 25, 2026 Company Disclosed Medium AI Red Teaming & Runtime Security Stronger than a generic customer-count proxy but still not comparable with annual revenue.
NR SPLX Revenue Not Disclosed; 160% Qoq Growth And 5 New Fortune 500 Customers Commercial Growth Fresh · 15mo Jul 30, 2025 Company Disclosed Medium AI Red Teaming Useful traction evidence but insufficient for precise revenue rank.
NR Weights & Biases — Weave 2% Of W&B'S $50M Arr Pace Product Revenue Share Aging · 21mo Apr 14, 2025 Credible Reported Low AI Evaluation Included only for qualifying Weave activity; parent-company ARR cannot be assigned to the AI-safety product.
NR Irregular Revenue Not Disclosed; Frontier-Model Evaluation Contracts Other Scale Signal Very Fresh · 0mo 2026 Credible Reported Medium Frontier AI Evaluation Important safety vendor, but contract presence alone gives no defensible revenue position.
NR Promptfoo Revenue Not Disclosed; 125K+ Developers And 40+ Fortune 500 Companies Users / Customers Very Fresh · 0mo 2026 Company Disclosed Medium AI Evaluation & Red Teaming One of the strongest usage proxies, but it cannot replace financial evidence.
NR AIR Security Revenue Not Disclosed; >20 Customers Customers Very Fresh · 0mo Sep 1, 2026 Credible Reported Medium AI Agent Security Material early traction, but no revenue or contract-value disclosure.
NR Willow Revenue Not Disclosed; ~5,000 Weekly Active Users, 600+ Governed Tools And 300K+ Weekly Tool Calls At Wix Deployment Usage Very Fresh · 0mo Jun 4, 2026 Company Disclosed Low AI Agent Governance Strong deployment evidence but only one customer's usage, so it cannot be treated as company revenue scale.
NR Bluejay Revenue Not Disclosed; ~24M Voice/Chat Conversations Annually Across Customers Usage Fresh · 9mo Aug 27, 2025 Credible Reported Medium AI Agent Evaluation High production volume, but conversation count is not directly comparable to financial metrics.
NR Enzai Revenue Not Disclosed; 500+ Third-Party Ai Solutions And >1.5M Decisions/Risks/Controls Tracked Usage Very Fresh · 0mo 2026 Company Disclosed Medium AI Governance Meaningful governance workload but insufficient to infer revenue.
NR Trustible Revenue Not Disclosed; Roughly 38–40% Of Customers Fortune 500 And >60% Public Companies Customer Mix Fresh · 9mo 2025–2026 Company Disclosed Low AI Governance Quality of customer base is visible, total customer/revenue scale is not.
NR Vijil Revenue Not Disclosed; Multiple Named Production Customers Including Smartrecruiters And Near Ai Paying Customers Very Fresh · 0mo 2026 Company Disclosed Medium AI Evaluation & Security Strong evidence of commercialization, but not enough for a precise scale rank.
NR Repello AI Revenue Not Disclosed; Multiple Named Enterprise Customers And 15M+ Attack Patterns Other Scale Signal Very Fresh · 0mo 2026 Company Disclosed Medium AI Red Teaming & Guardrails Clearly commercial, but its attack-pattern corpus is not a revenue proxy.
NR Archestra Revenue Not Disclosed; Multiple Fortune 500 Companies In Production Paying Customers Very Fresh · 0mo Jun 2026 Company Disclosed Medium AI Agent Security Qualifies strongly but lacks a financial or sufficiently precise customer metric.
NR AIQURIS Revenue Not Disclosed; Deployments Across Multiple Regulated Industries Other Scale Signal Very Fresh · 0mo 2026 Company Disclosed Low AI Assurance & Risk Strong institutional backing and deployments but no comparable commercial figure.
NR FairNow Revenue Not Disclosed; One Disclosed Customer Governs >50 Ai Systems Deployment Usage Fresh · 9mo Jul 24, 2025 Company Disclosed Low AI Governance Useful evidence that the product is deployed, but not company-wide commercial scale.
NR Pillar Security Revenue Not Disclosed; Fortune 500 Deployments Stated Paying Customers Very Fresh · 0mo 2026 Company Disclosed Low AI Security Commercial enterprise use is established, but insufficient quantitative evidence for ranking.
NR Harmonic Security Revenue Not Disclosed; Named Enterprise Deployments Paying Customers Very Fresh · 0mo 2026 Company Disclosed Low AI Data Security Strictly relevant AI-specific data controls, but no usable financial scale disclosure.
NR SurePath AI Revenue Not Disclosed; Acquired By F5 Other Scale Signal Very Fresh · 0mo Jun 22, 2026 Company Disclosed Low AI Security & Governance Acquisition value or parent revenue cannot substitute for SurePath standalone revenue.
NR Arize AI $12.4M Historical Estimate Annual Revenue Estimate Historical · 33mo 2023–2024 Third-Party Estimate Low AI Evaluation & Observability The historical figure is large but far too stale to assign a defensible current position, especially around an acquisition.
NR WhyLabs $10.6M Historical Estimate Annual Revenue Estimate Aging · 21mo Dec 20, 2024 Third-Party Estimate Low AI Observability Historical evidence retained, but ranking it alongside active 2026 companies would misrepresent current scale.
NR Robust Intelligence $8.7M Historical Estimate Annual Revenue Estimate Historical · 33mo 2023–2024 Third-Party Estimate Low AI Red Teaming & Robustness A useful historical datapoint, not a defensible measure of current independent-company revenue.
NR CalypsoAI $3.8M Historical Estimate Annual Revenue Estimate Aging · 21mo Oct 17, 2024 Third-Party Estimate Low AI Guardrails & Security Retained for completeness, but the old standalone estimate should not receive a current precise rank.
NR Aporia $4.3M Estimate Annual Revenue Estimate Fresh · 9mo Sep 18, 2025 Third-Party Estimate Low AI Guardrails & Monitoring Amount is recent enough to be useful historically, but acquisition makes a present-company revenue rank misleading.
NR General Analysis $2M Revenue Target, Not Achieved Revenue Revenue Target Very Fresh · 0mo Apr 29, 2026 Company Disclosed Low AI Evaluation Explicitly not ranked because a future revenue target cannot be treated as actual revenue.
NR CodeIntegrity Revenue Not Disclosed Other Scale Signal Very Fresh · 4mo May 27, 2026 Company Disclosed Low AI Agent Security Recent relevant entrant from the funding database, but financing itself is not evidence of revenue.
NR Arrakis Security Revenue Not Disclosed Other Scale Signal Very Fresh · 1mo Aug 2, 2026 Company Disclosed Low AI Agent Security Important new entrant; pricing exists, but pricing cannot be multiplied by assumed customers.
NR Liminal Revenue Not Disclosed; Enterprise Case-Study Impact Metrics Other Scale Signal Very Fresh · 0mo 2026 Company Disclosed Low AI Security & Governance Customer ROI evidence confirms deployment but does not establish revenue scale.
NR Inspeq AI Revenue Not Disclosed; Responsible Ai Partnership With Hcltech Partnerships Fresh · 9mo 2025 Credible Reported Low AI Governance & Safety Relevant commercial partnership but no defensible revenue or customer-volume metric.
NR Acuvity Revenue Not Disclosed Other Scale Signal Aging · 24mo Sep 5, 2024 Company Disclosed Low AI Security & Governance Included because it is a dedicated AI-risk vendor from the funding sweep; no revenue inference made from funding.
NR AIceberg Revenue Not Disclosed Other Scale Signal Fresh · 18mo Mar 6, 2025 Company Disclosed Low AI Guardrails Search surfaced no trustworthy revenue figure; a clearly mismatched third-party financial profile was rejected.
NR AIM Intelligence Revenue Not Disclosed Other Scale Signal Very Fresh · 0mo 2026 Company Disclosed Low AI Red Teaming & Guardrails Qualifies strongly on product scope, but no comparable commercial metric was found.
NR AIMon Labs Revenue Not Disclosed Other Scale Signal Aging · 21mo Dec 11, 2024 Credible Reported Low AI Safety Monitoring Commercial company with relevant product, but no defensible scale figure surfaced.
NR Alinia AI Revenue Not Disclosed Other Scale Signal Fresh · 9mo Dec 4, 2025 Company Disclosed Low AI Guardrails & Compliance Recent dedicated AI-safety vendor; fundraising is not used as a proxy for revenue.
NR Apex Revenue Not Disclosed Other Scale Signal Aging · 28mo May 2, 2024 Company Disclosed Low AI Safety Monitoring Relevant AI-security control plane, but no financial/commercial metric strong enough to rank.
NR Attestable Revenue Not Disclosed Other Scale Signal Very Fresh · 0mo Feb 5, 2026 Credible Reported Low AI Integrity & Robustness New verification vendor; no public commercial-scale figure found.
NR SydeLabs Revenue Not Disclosed Other Scale Signal Aging · 30mo Mar 28, 2024 Credible Reported Low AI Red Teaming & Guardrails Qualifying safety platform, but funding and product launches cannot substitute for revenue.
NR Warden AI Revenue Not Disclosed Other Scale Signal Very Fresh · 0mo 2026 Third-Party Estimate Low AI Fairness & Governance Included for market completeness, but there is no public revenue figure to rank.
NR Reality Defender Revenue Not Disclosed; Enterprise/Government Deployments Paying Customers Very Fresh · 0mo 2026 Company Disclosed Low AI-Generated Threat Detection Included under the AI-specific-threat portion of the definition; no comparable commercial figure found.
NR Clarity Revenue Not Disclosed Other Scale Signal Historical · 31mo Feb 15, 2024 Company Disclosed Low AI-Generated Threat Detection Qualifies as AI-specific threat detection, but current revenue or commercial-scale data were not disclosed.
Google Trends chart showing rising interest in AI safety

As this chart shows, and as featured in our AI safety market deck, search interest in AI safety has been growing steadily

What are the top AI safety startups by revenue today?

HiddenLayer is the clearest revenue leader among independent AI safety and AI security startups today.

HiddenLayer CEO Chris Sestito recently told TechCrunch that annual recurring revenue is now in the “tens of millions” of dollars. HiddenLayer’s own funding announcement adds two useful pieces of context: ARR grew more than 10x over the previous year, and the company signed more than 50 new platform customers across finance, technology, government, pharmaceuticals, defense and other industries.

We do not have anything nearly as clean for the companies behind it. Noma Security says ARR grew more than 1,300% in a year but does not disclose the resulting ARR. Patronus AI says revenue grew more than 15x but also keeps the dollar figure private. Credo AI says revenue doubled during 2025. WitnessAI and Zenity have attracted large enterprise customers and substantial funding without publishing current revenue.

So there is a clear number one, followed by a much less certain group.

Current position Company Strongest current commercial evidence What we actually know
1 HiddenLayer ARR in the tens of millions; ARR grew >10x Strongest absolute revenue evidence
Next tier Noma Security ARR grew >1,300% Absolute ARR undisclosed
Next tier Patronus AI Revenue grew >15x Absolute revenue undisclosed
Next tier Credo AI Revenue doubled in 2025 Absolute revenue undisclosed
Next tier WitnessAI Large enterprise deployments; $58M strategic funding round Revenue undisclosed
Next tier Zenity Large enterprise customer base; $125M Series C Revenue undisclosed
Earlier-stage Mindgard Growing enterprise AI security business; $30M Series A Revenue undisclosed

Which AI safety startup makes the most revenue today?

HiddenLayer is the clearest revenue leader among independent AI safety and AI security startups today.

HiddenLayer CEO Chris Sestito recently told TechCrunch that annual recurring revenue is now in the “tens of millions” of dollars. HiddenLayer’s own funding announcement adds two useful pieces of context: ARR grew more than 10x over the previous year, and the company signed more than 50 new platform customers across finance, technology, government, pharmaceuticals, defense and other industries.

We do not have anything nearly as clean for the companies behind it. Noma Security says ARR grew more than 1,300% in a year but does not disclose the resulting ARR. Patronus AI says revenue grew more than 15x but also keeps the dollar figure private. Credo AI says revenue doubled during 2025. WitnessAI and Zenity have attracted large enterprise customers and substantial funding without publishing current revenue.

So there is a clear number one, followed by a much less certain group.

Chart showing annual venture capital investment in AI safety startups

This chart, featured in our AI safety market deck, shows annual venture capital investment in AI safety startups

Does Anthropic count as an AI safety startup in this revenue ranking?

Anthropic should stay outside this AI safety startup ranking because customers mainly pay Anthropic for Claude models and AI products rather than an independent safety product.

Anthropic was founded with AI safety at the center of its identity, so leaving it out can initially look strange. The problem is economic rather than philosophical. Including Anthropic would make model revenue dominate a ranking that is supposed to tell us how large the commercial market for AI security, evaluation, governance and safety infrastructure has become.

The same logic applies to frontier research organizations whose main business is building models. We focus here on companies selling products that help customers test AI, govern AI, secure models and agents, catch dangerous behavior or reduce AI-specific risks.

That definition captures companies such as HiddenLayer, Noma Security, Patronus AI, Credo AI, WitnessAI and Zenity much more cleanly.

How much revenue does HiddenLayer make now?

HiddenLayer currently has annual recurring revenue in the tens of millions of dollars, making it the strongest disclosed revenue business in this group.

The exact ARR remains private. Chris Sestito gave TechCrunch the range rather than a precise number, while HiddenLayer’s own announcement confirmed that ARR had increased more than tenfold over the previous year.

The customer expansion makes that growth more convincing. HiddenLayer says more than 50 new platform customers signed during the period, and more than 90% of its ARR growth came from new customers. The company now sells into securities brokerage, banking, insurance, government, defense, pharmaceuticals, technology and other large enterprise markets.

An older report from The Information gives us a useful baseline. HiddenLayer had only recently crossed roughly $10 million in annualized revenue at that point. The latest disclosure therefore reflects a real step up in scale rather than a minor improvement around the same level.

Chart showing how HiddenLayer is positioned in the AI safety market

This chart, featured in our AI safety market deck, shows how HiddenLayer is positioned in AI safety

Is Noma Security already as big as HiddenLayer?

Noma Security could be close to HiddenLayer, but the public numbers still do not prove it.

Noma Security says ARR grew more than 1,300% in a year and that dozens of enterprise customers now use its platform across financial services, life sciences, retail and big technology companies. The company also raised a $100 million Series B after emerging from stealth less than a year earlier.

The missing piece is the starting base. A 1,300% increase can produce very different outcomes depending on where revenue began. Without an absolute ARR figure, we cannot tell whether Noma went from hundreds of thousands to several million dollars or from a few million to several tens of millions.

That puts Noma among the strongest challengers. Putting it ahead of HiddenLayer today would require a number Noma has not disclosed.

How big is Patronus AI now?

Patronus AI is growing extremely fast, although its current revenue remains private.

Patronus AI says revenue grew more than 15x over the past year. The company has also moved beyond basic LLM evaluation into simulation environments where AI agents can be trained and stress-tested across complicated digital workflows.

That shift appears to have widened the customer base. Patronus says it works with leading frontier AI labs and enterprises, while investors involved in its recent $50 million Series B described strong demand for its environments.

The commercial trajectory looks stronger than the older third-party revenue estimates that still circulate online. We would rather use Patronus AI’s direct 15x growth disclosure than pretend one of those stale estimates represents the current business.

Patronus belongs near the front of the market. Its exact position behind HiddenLayer is still impossible to pin down.

Chart showing the projected CAGR of the AI safety market

This chart, featured in our AI safety market deck, shows annual funding in AI safety startups

How much revenue does Credo AI make today?

Credo AI has become a meaningful enterprise AI governance business, but it still does not publish an absolute revenue figure.

The company’s 2025 review says revenue doubled, enterprise customer count rose 150%, its European business doubled and advisory engagements increased fivefold. Earlier in the growth cycle, TIME had reported that Credo AI’s revenue had quadrupled over the preceding year and that its customer base had doubled.

Those disclosures refer to different measurement periods, so they should not be treated as contradictory versions of the same number. Together, they show several periods of rapid expansion.

Credo AI also sells into recognizable large enterprises, with Mastercard and Cisco among the customers it has publicly discussed.

The evidence is strong enough to place Credo among the larger independent AI safety companies. It is still weaker for a revenue ranking than HiddenLayer’s disclosed ARR range because we do not know the size of Credo’s revenue base.

Are AI governance startups making as much money as AI security startups?

AI security currently shows stronger revenue evidence than AI governance.

The gap is clearest in the disclosures. HiddenLayer has reached an eight-figure ARR range. Noma Security has reported explosive ARR growth. Several acquired AI security companies had also reached meaningful commercial scale before larger cybersecurity vendors bought them.

Governance is growing too. Credo AI’s revenue and customer growth show that large companies are spending real money on AI oversight, compliance and risk management. Regulatory pressure should keep that budget relevant.

Security has an easier route into spending today because CISOs already have established budgets, procurement processes and security platforms. Products that detect unsafe AI use, block prompt attacks, protect agents or stop data leakage can often fit into that existing buying motion.

For now, that gives AI security vendors the clearest route to larger recurring revenue.

Chart comparing business model options for AI alignment research labs

This chart, featured in our AI safety market deck, compares the main business model options for AI alignment research labs

How much revenue did the first big AI safety startups make before they were acquired?

Several early AI safety leaders were acquired while their standalone revenue was still surprisingly modest.

The Information reported that Robust Intelligence was generating roughly $9 million in annualized revenue around the time Cisco agreed to acquire the company. The same reporting said Lakera and CalypsoAI had each remained below $5 million in revenue at the point examined.

Those numbers are revealing because all three companies became strategically valuable to major cybersecurity buyers. Cisco integrated Robust Intelligence into its AI security products. Check Point acquired Lakera. F5 acquired CalypsoAI and has since folded its technology into a broader AI security platform.

Protect AI followed a similar path. Palo Alto Networks completed that acquisition and later disclosed $635 million of purchase consideration in its regulatory filings, despite Protect AI never publishing a comparable standalone revenue number.

Prompt Security and Aim Security were also acquired before giving the market much financial transparency.

Startup Best useful standalone revenue evidence Buyer What happened
Robust Intelligence About $9M annualized revenue Cisco Acquired and incorporated into Cisco AI security
Lakera Below $5M revenue at the period reported Check Point Acquired for AI-native runtime security
CalypsoAI Below $5M revenue at the period reported F5 Acquired and integrated into F5 AI Security
Protect AI Revenue not publicly disclosed Palo Alto Networks Acquired; $635M purchase consideration later disclosed
Prompt Security No strong public standalone revenue figure SentinelOne Prompt Security ARR later doubled quarter-on-quarter inside SentinelOne
Aim Security Revenue not publicly disclosed Cato Networks Acquired and integrated into Cato AI Security

Why are so many AI safety startups getting acquired so early?

Large cybersecurity companies are buying AI safety startups because specialist technology has become strategically useful before many of these startups have built huge standalone revenue businesses.

Cisco, Palo Alto Networks, Check Point, F5, SentinelOne and Cato Networks have all bought companies focused on securing AI models, applications, prompts or agents.

The economics are straightforward. A specialist startup may have strong technology and a few large customers but still need years to build global enterprise distribution. An established cybersecurity vendor already has thousands of customers, large sales teams and an existing CISO budget.

Prompt Security gives us a good example of what can happen next. After SentinelOne bought the company, SentinelOne reported that Prompt Security ARR was doubling quarter-on-quarter. More recently, SentinelOne said ARR across its AI offerings had nearly tripled year over year.

Acquisitions can accelerate the commercial scale of these products much faster than independent expansion would.

Chart showing revenue breakdown by customer segment in the AI safety market

This chart, featured in our AI safety market deck, shows revenue breakdown by customer segment in the AI safety market

Is WitnessAI already one of the biggest AI safety companies?

WitnessAI has enough enterprise traction to be taken seriously, although there is still no public revenue figure that puts it near the top of the ranking.

WitnessAI raised $58 million in strategic funding and said the money would support international growth and a broader push into AI agent security. Its product gives enterprises visibility and control over employee AI use, AI applications and increasingly autonomous agents.

That positioning is commercially attractive because it sits close to existing enterprise security and governance budgets.

Still, the evidence stops short of revenue. A large funding round tells us investors expect WitnessAI to grow; it does not tell us what customers are paying today.

Until WitnessAI publishes ARR, annual revenue or another comparable financial metric, any precise revenue position would be guesswork.

Is Zenity already one of the largest AI safety startups?

Zenity is one of the best-funded independent AI agent security companies, but Zenity has not disclosed enough revenue data to rank it near HiddenLayer with confidence.

Zenity raised a $125 million Series C and says some of the world’s largest enterprises use its platform to secure AI agents. The company focuses on understanding what agents intend to do and controlling their actions before unsafe behavior reaches production systems.

That is a strong position in one of the fastest-growing parts of the market. Zenity also has much more capital available than most younger AI safety startups.

What we still lack is an absolute commercial figure. Funding, customers and product relevance make Zenity important; they do not tell us whether annual revenue is $5 million, $20 million or substantially more.

Zenity therefore belongs high on the watchlist rather than in a precisely numbered revenue position.

Chart showing how prompt injection defense platform technology has evolved over time

This chart, featured in our AI safety market deck, shows how prompt injection defense platform technology has evolved over time

Which newer AI safety startups are starting to matter commercially?

Mindgard is one of several younger AI safety companies worth watching as enterprise spending moves toward continuous AI testing and runtime protection.

Mindgard recently raised a $30 million Series A and says its research has uncovered more than 150 publicly disclosed high-impact vulnerabilities in widely used AI products. The company sells security testing and protection for models, applications and agents.

Lasso Security, Vijil, Straiker and other specialists are attacking adjacent parts of the same problem. Some focus on AI red teaming, some on data leakage, some on runtime enforcement and others on agent permissions or model vulnerabilities.

Most of these companies have not published strong revenue numbers yet. That makes them relevant to the future market without forcing them prematurely into today’s top revenue tier.

The candidate pool behind the current leaders is getting much deeper.

Why is AI agent security becoming such a big business?

AI agent security is attracting money because AI agents can take actions inside real company systems.

A chatbot producing a bad answer is one kind of risk. An agent with access to databases, files, credentials, SaaS tools and code repositories can create a much more expensive failure.

Noma Security now markets directly around agent security. HiddenLayer is expanding its runtime protection for autonomous coding agents. Zenity has centered its recent strategy on controlling agent actions. WitnessAI is extending governance into enterprise agents. Cato incorporated Aim Security into its broader AI security platform.

The product is also easier for enterprise buyers to understand now. Companies increasingly need to answer concrete questions: which agents exist, what those agents can access, what tools they can call, whether an instruction has been manipulated and whether an unsafe action should be blocked.

Those are operational security problems with budgets attached to them.

Table scoring and prioritizing the main pain points faced by companies in the AI safety market

In our AI safety market deck, we identify pain points entrepreneurs should prioritize

Can we trust online revenue estimates for AI safety startups?

Third-party revenue estimates are useful as rough context, but they are too inconsistent to drive this ranking.

Private AI safety companies rarely publish audited accounts with detailed revenue, so commercial databases often fill the gap with modeled estimates. The problem becomes obvious when several databases produce materially different numbers for the same startup.

Direct disclosures also age quickly in this market. An estimate based on a startup’s 2024 or early-2025 size can become misleading when the company later reports a tenfold or fifteenfold growth rate.

We therefore use third-party estimates mainly to test whether a number looks plausible or to understand older scale. When a company or a strong primary source provides ARR, revenue or a clear commercial metric, that evidence takes priority.

That approach produces a less tidy ranking, but the uncertainty is real.

Does a huge funding round mean an AI safety startup already has huge revenue?

A huge funding round can point to commercial momentum, but funding remains a weak substitute for actual revenue.

The current market makes that obvious. HiddenLayer raised $100 million, Noma Security raised $100 million, Patronus AI raised $50 million, WitnessAI raised $58 million and Zenity raised $125 million.

The quality of those signals differs. HiddenLayer combined its raise with a direct ARR range. Noma and Patronus disclosed extraordinary growth rates without absolute revenue. WitnessAI and Zenity emphasized enterprise adoption but kept revenue private.

Investors are financing what they expect these markets to become, not simply paying a multiple on today’s revenue.

For revenue ranking purposes, the funding amounts therefore sit behind the financial disclosures rather than replacing them.

Chart showing revenue breakdown by geography across Europe, Asia, North America, Africa, and South America in the AI safety market

This chart, featured in our AI safety market deck, shows revenue breakdown by geography across Europe, Asia, North America, Africa, and South America in the AI safety market

How concentrated is AI safety startup revenue right now?

The commercial AI safety market is still small enough that one startup with ARR in the tens of millions stands out clearly.

As seen above, HiddenLayer is the only independent specialist in our research with a current company-backed disclosure that places ARR comfortably in an eight-figure range. Several challengers may also be sizable, but their disclosures give growth rather than absolute dollars.

Historical acquisition data reinforce the point. Some of the best-known first-generation AI security startups were still around or below the $5–10 million revenue range when acquisition discussions began.

The sector therefore has a lot of enterprise activity without yet showing the revenue concentration we see in mature cybersecurity categories.

Commercial scale Companies Evidence available
Eight-figure ARR clearly disclosed HiddenLayer Current ARR range disclosed by CEO
Potentially large, exact figure unknown Noma Security Very fast ARR growth, absolute ARR private
Potentially large, exact figure unknown Patronus AI Very fast revenue growth, absolute revenue private
Established enterprise business, exact figure unknown Credo AI Revenue and customer growth disclosed
Enterprise traction, revenue private WitnessAI Funding and customer adoption
Enterprise traction, revenue private Zenity Funding and large-enterprise adoption
Earlier commercial stage Mindgard and several newer specialists Product and funding evidence stronger than revenue evidence

Are any pure-play AI safety startups above $100 million in revenue yet?

We found no defensible public evidence that an independent pure-play AI safety startup has already crossed $100 million in annual revenue or ARR.

That threshold matters because many adjacent AI companies have blown through $100 million quickly. Pure-play safety and security specialists are still operating on a smaller commercial base.

HiddenLayer is the closest independent company for which we have strong enough current evidence to discuss the question seriously. Noma Security and Patronus AI could also be much larger than their last known bases suggest, but neither gives us the absolute number needed to claim a $100 million business.

The acquisition pattern may also keep the independent ceiling lower. Large cybersecurity platforms have repeatedly bought promising AI security companies before those companies reached mature standalone scale.

A $100 million pure-play leader now looks plausible. We just cannot point to one yet.

Chart showing annual venture capital investment in AI safety startups

This chart, featured in our AI safety market deck, shows annual venture capital investment in AI safety startups

Are the biggest AI safety startups really becoming cybersecurity companies?

Commercially, the AI safety market is increasingly being shaped by cybersecurity products.

The companies with the clearest routes to revenue sell protection around AI applications, models and agents: runtime security, attack detection, prompt-injection defense, asset discovery, agent permissions, red teaming and data-loss controls.

That does not make evaluation or governance unimportant. Patronus AI shows strong demand for agent testing and simulation, while Credo AI has built a growing enterprise governance business.

Security simply has the strongest buying infrastructure today. CISOs already buy software to discover assets, enforce policies, stop attacks and investigate incidents. AI-specific products can attach themselves to those familiar jobs.

This commercial pull explains why traditional cybersecurity vendors have been so aggressive with acquisitions.

Which AI safety startups could challenge HiddenLayer next?

Noma Security and Patronus AI currently have the strongest public growth evidence among the companies that could challenge HiddenLayer.

Noma has broad Fortune 500 adoption and a product spanning AI discovery, posture management, red teaming and runtime security. Patronus has become deeply involved in evaluation and simulation infrastructure used by frontier AI developers.

Zenity is another serious candidate because agent security is becoming a large enterprise problem and the company now has considerable capital to expand. WitnessAI is pursuing a similarly large enterprise opportunity around visibility, governance and agent security.

Credo AI has a different route through governance. Its growth already shows that companies will pay for operational AI oversight, especially as legal and compliance requirements become harder to manage manually.

The order behind HiddenLayer could move quickly because several of these businesses are growing from relatively small bases.

Chart assessing the maturity level of the AI safety market

In our AI safety market deck, we like to quantify things to make things easier to understand

What are the top AI safety startups by revenue today?

HiddenLayer is the clearest number one by current disclosed revenue evidence, while Noma Security and Patronus AI form the strongest challenger group.

The gap between “largest company” and “best disclosed number” is important here. Some private competitors may already have more revenue than the public evidence shows. We cannot rank hidden revenue.

Credo AI has convincing enterprise growth but no absolute number. WitnessAI and Zenity have substantial enterprise backing without published revenue. Younger companies such as Mindgard are building quickly but remain earlier in the commercial cycle.

The broader finding is more interesting than a forced top-ten ordering. AI safety has moved from a market where leading specialists often had only a few million dollars of revenue into one where the strongest independent company has reached a much higher commercial tier and several challengers are growing at unusually fast rates.

For now, HiddenLayer is the company we can put at the top with the least hesitation. The race behind it remains genuinely open.

OUR METHODOLOGY

This analysis ranks independent AI safety and AI security startups by the strongest evidence available for current revenue scale. We focus on companies selling products for AI security, evaluation, governance, model and agent protection, red teaming, runtime controls and related safety infrastructure, while excluding frontier model companies such as Anthropic whose revenue mainly comes from selling AI models and applications.

We reviewed public evidence from the last ten years so that older but still useful revenue disclosures could remain part of the comparison when newer financial figures were unavailable. We considered annual revenue, fiscal-year revenue, ARR, annualized revenue, run-rate, quarterly revenue, bookings and other strong commercial measures, while keeping each metric in its original form.

Absolute revenue evidence takes priority over growth rates, customer counts, funding rounds and usage metrics. We do not manufacture revenue from prices, employee counts, website traffic or assumed multiples. When a company reports rapid growth without disclosing the base, we keep that limitation visible rather than turning the growth rate into a synthetic revenue estimate.

We also checked what each figure covered and whether the company was still independent at the time relevant to the ranking. Acquired companies such as Robust Intelligence, Lakera, CalypsoAI, Protect AI, Prompt Security and Aim Security are used as historical benchmarks rather than current independent leaders.

Key sources include HiddenLayer’s Series B announcement, TechCrunch’s interview with HiddenLayer CEO Chris Sestito, Noma Security’s Series B announcement, Patronus AI’s Generative Simulators announcement, Patronus AI’s Series B release, TIME on Credo AI, WitnessAI’s strategic funding announcement, Zenity’s Series C announcement, Mindgard’s Series A announcement, The Information’s reporting on AI security startup revenue, and regulatory or company disclosures from Cisco, Check Point, Palo Alto Networks, F5, SentinelOne and Cato Networks covering the acquisition benchmarks discussed above.

Chart showing the scarcest and most valuable assets in the AI safety market

In our AI safety market deck, we tell you what to focus on