The malware was still malware. That was the awkward part. In an attack described by HiddenLayer, researchers appended strings from benign files to malicious ones. Cylance’s machine-learning detector, built to distinguish dangerous software from harmless software, could then classify the altered files as benign. The attacker had found something more useful than a broken lock: a guard who could be persuaded to wave them through.
- HiddenLayer protects AI models and applications from attacks on their files, inputs and behavior.
- Its platform combines discovery, supply-chain inspection, attack simulation and runtime security.
- Microsoft Azure AI uses its scanner before admitting open models to a curated catalog.
The detector becomes the target
For Christopher “Tito” Sestito, Jim Ballard and Tanner Burns, this was a professional problem before it became a business proposition. The three worked at Cylance. Their investor, Ten Eleven Ventures, describes them developing important intellectual property there, then having to defend the algorithms themselves. They founded HiddenLayer in 2022. Sestito is CEO, Ballard COO and Burns chief scientist.
The change of perspective was small enough to fit in a sentence. An AI system built to detect attacks could itself be attacked. A model did not have to be stolen, deleted or disconnected to become dangerous. Someone could manipulate the evidence it received and make its ordinary decision process produce an extraordinary mistake.
HiddenLayer’s original detection-and-response proposition followed that insight: watch the inputs and outputs of machine-learning algorithms for adversarial activity. Its research roots remain visible in public work on malware, reverse engineering and insecure model serialization. The company publishes tools, too. HiddenPickle, its Python Pickle disassembler and patcher, has a name that almost makes a potentially executable model file sound hospitable.
Four jobs for an untrustworthy guest
The current platform divides the work into four connected jobs. AI Discovery finds models, agents and workflows and maps ownership. AI Supply Chain Security inspects the models an organization builds, buys or borrows. AI Attack Simulation probes applications for weaknesses. AI Runtime Security watches interactions and execution after deployment. Each answers a different question; buying one answer does not settle the other three.
There is a useful distinction inside the packaging. HiddenLayer has promoted noninvasive detection and response that does not require access to a customer’s proprietary model or training data. Supply-chain inspection is a different operation: its product page describes examining architectures, layers, weights and artifacts. The access requirement follows the job. A security buyer should ask which module needs which information, rather than treating “noninvasive” as a universal technical specification.
This combination places HiddenLayer between AI engineering and the security operations team. Engineers need usable models and working deployment pipelines. Security staff need an inventory, evidence, alerts and enforceable policies. A shared view can make the discussion more productive than asking either group to become fluent in the other’s entire profession.
A model card becomes a security checkpoint
Microsoft supplied a concrete example in May 2024. Azure AI announced that it uses HiddenLayer Model Scanner on third-party and open models before onboarding them to its curated catalog. The checks cover malware, vulnerabilities, backdoors and model integrity. The resulting verification appears within a model card, where developers are already deciding what to deploy.
The placement matters. Open models offer flexibility, but a downloaded model is also a package of files and functions. A familiar-looking name can conceal an unfamiliar author. Loading the package may expose an organization to malicious code or unexpected network activity. Inspecting it before adoption moves a security decision closer to the moment that creates the risk.

The wider audience includes enterprise security and AI teams, particularly organizations handling sensitive systems and data. HiddenLayer’s distribution reflects that audience: direct enterprise sales, channel partners, cloud marketplaces and self-hosted options. Its business is security software and associated expertise. The useful purchasing question is which models, applications and environments a proposed deployment will actually cover.
The agent has left the chat window
A chatbot can give an embarrassing answer. An agent with tools can take an embarrassing action. HiddenLayer’s March 2026 runtime update added agent visibility, investigation and threat hunting, and detection and enforcement. By June, it had announced a collaboration with Cohere around North and joined the Databricks Unity AI Gateway ecosystem. The security perimeter was following AI into business workflows.
Money followed it, too. HiddenLayer announced a $100 million Series B in September 2026, led by Delta-v Capital. Alongside its $6 million seed and $50 million Series A, that brings documented financing to $156 million. This is capital raised, not a measure of customer savings or product effectiveness.
There was an earlier commercial turning point. HiddenLayer won RSA Conference’s 2023 Innovation Sandbox. In a later RSAC retrospective, Sestito described the win as making AI security a subject CISOs could prioritize. Recognition helped make an unfamiliar purchasing category discussable. A technical discovery had acquired a place on somebody’s agenda.
“gave CISOs permission to care about AI Security”Christopher “Tito” Sestito, recalling the 2023 RSAC win
That category now has serious alternatives, including Palo Alto Networks’ Prisma AIRS and Check Point’s Lakera Guard. HiddenLayer’s case rests on its research lineage and the combination of model inspection, testing and production defense. Buyers still need to compare deployment fit, coverage and operational burden. A pedigree is a reason to investigate, rather than a substitute for investigation.
Borrow the sequence, keep the responsibility
The copyable lesson is practical: inventory your AI, inspect incoming artifacts, attack-test the actual application, then monitor its production behavior. HiddenLayer’s public GitHub examples show scanning and runtime evaluation in code. Its model-scanning Action can fail a build on detection. Even the plumbing matters: its documentation warns that large models can exceed a hosted runner’s available storage.
The sequence depends on access, integration and someone owning the response. A clean scan cannot guarantee every future interaction. An alert cannot revoke an agent’s permissions by wishful thinking. Identity controls and infrastructure security still matter. HiddenLayer began with a guard being fooled; its most useful proposition is giving that guard colleagues, evidence and a way to intervene.
Website · LinkedIn · X · GitHub
Company news · Research & blog · Watch: Model Scanner demo · Watch: RSAC founder interview · YouTube