Skip to content

A firm selling protection against attacks that did not yet exist raised 100 million: the market arrived three years later

1 min read
Share
A firm selling protection against attacks that did not yet exist raised 100 million: the market arrived three years later

Three years ago, when the American startup HiddenLayer raised 50 million dollars in its first serious funding round, the industry was openly asking whether the market the firm was selling into even existed. It offered protection for artificial intelligence models against attacks - and at that moment it was hard to point to even one real, documented large-scale attack on AI. The company was selling a cure for a disease nobody had seen yet.

This week HiddenLayer raised another 100 million dollars in a second round led by Delta-v Capital, with participation from Ten Eleven Ventures, Morgan Stanley, Microsoft's M12 fund and Booz Allen Hamilton. So the market showed up.

The most telling figure does not come from the startup but from the analyst house Gartner: companies will spend 2.83 billion dollars this year on tools to secure their artificial intelligence - 83 percent more than last year, with the estimate for next year at almost 4.78 billion. That is classic tech boom dynamics: the same industry building the systems also sells you protection from them, so both sides of the transaction grow together.

Co-founder and chief executive Chris Sestito says the firm's annual recurring revenue grew more than tenfold in twelve months. He refuses to give an exact figure - only that it is "in the tens of millions" of dollars, and that over 90 percent of the growth came from entirely new clients. The biggest buyers are financial institutions and large technology firms, and the contracts include ones with the US Department of Defense and the intelligence community.

One client is described only as a "leading provider of frontier models" with "more than 700 million weekly users" - a description that narrows the list to two or three names and names none of them. That is the essence of the business: the firms that insist loudest their models are safe quietly buy protection from third parties.

Sestito insists the firm did not pivot, only widened its scope. "Locking down is still locking down. Whether it is a classic machine learning model, generative AI or an agentic workflow - a large part of our technology still applies," he says. Among the new products he singles out scanning of open-weight models: "We review and scan around 50 different formats. We look for models presenting themselves as one thing while being another - hidden models inside models."

That is the part that looks least like marketing. Open models are downloaded millions of times, embedded straight into products, and nobody along the way checks what is actually in the file. Anyone who has ever installed a library without looking at its code knows how that story ends - except this time the file weighs several gigabytes and nobody can read it.

With the new money the firm plans to enter Europe. And harder work waits there: the big players in cybersecurity - Cisco, Palo Alto Networks, Check Point - have historically preferred to buy such technology rather than build it, while competitors Noma and Zenity have each already raised over 100 million for overlapping areas. Sestito himself admits that part of what he sells may one day end up built into the platforms of Microsoft, OpenAI and AWS.

In other words: the firm raised 100 million to run ahead of an industry that is running after it. If it succeeds, it will be bought expensively. If it fails, the function will become a free add-on inside somebody else's product. A third scenario is not on offer for now.