THE LATEST
Mindgard closes $30M Series A · August 2026Research-led security for AI agents150+ public disclosures · company-reported

Company / AI security / Mindgard

Mindgard finds the trouble your AI talks itself into

An AI assistant can refuse a dangerous request and still leak a secret through its tools. Mindgard turns that awkward distinction into a business: finding the paths from helpful behavior to harmful action.

The reward was a $40 Amazon merchandise gift certificate. Mindgard had found a way for an AI coding assistant to send a local secret to an outside endpoint. There is something exquisitely odd about paying for a glimpse of tomorrow’s security problem with yesterday’s shopping voucher.

The 30-second read
  • Mindgard tests AI models, agents and the tools around them.
  • Its approach starts with reconnaissance, then follows exploitable paths.
  • Enterprise buyers get testing, remediation evidence and runtime protection.

A gift certificate for a data leak

In its September 2026 Kiro disclosure, Mindgard described malicious repository content influencing an agent to read sensitive information, alter a workspace setting and trigger an outbound request. Each capability belonged in a developer’s toolkit. Their combination let project content acquire the authority of an instruction.

The demonstration had boundaries: Kiro IDE 0.7.45 on Windows, a crafted workspace opened through a workspace file, then a message to the agent. Mindgard says Amazon validated the report and fixed it in version 0.8.140. An earlier finding had been classified as a duplicate; the team returned and found a distinct route. The first disappointment changed the investigation’s direction.

That is a useful introduction to Mindgard. The interesting failure occurs between a model’s interpretation and an application’s permissions. A file can become persuasive. A persuasive file can become an action. The security problem lives in the journey.

The professor’s inconvenient question

Peter Garraghan’s question began at Lancaster University: could existing security tools adequately test deep-learning systems? Years of work suggested that AI introduced properties those tools were poorly equipped to examine. Mindgard emerged as a spinout in 2022, with research co-founder Neeraj Suri and commercial co-founder Steve Street among its original founders.

“All software has security risks, and AI is no exception,” Garraghan said in the company’s funding announcement. His point is refreshingly unromantic. AI runs on infrastructure, handles data and inherits ordinary software problems. Its behavior adds another layer of exposure. Connecting a language model to useful tools makes that layer consequential.

Peter Garraghan, Mindgard founder and Chief Science Officer
The professor brought homework for the chatbot. Peter Garraghan, now Mindgard’s Chief Science Officer. Photograph: Mindgard.

The university connection matters because this work requires expertise that companies cannot conjure by adding “AI” to a security team’s job titles. An early Innovate UK account framed specialist labor as the bottleneck. Mindgard’s commercial proposition was to make that knowledge repeatable through software.

First, learn its habits

Today the platform’s sequence is discover, recon, attack, defend. Discovery inventories AI assets, including shadow AI. Reconnaissance examines instructions, behavior, connected tools and data sources. Adversarial testing probes the routes that information suggests. Runtime protection applies responses informed by those findings.

Think of the difference between rattling every door in a building and learning which door opens onto the records room. Mindgard emphasizes understanding the system before selecting attacks. Its stated differentiation is reconnaissance coupled with research-derived intelligence, rather than simply sending a large collection of hostile prompts.

Mindgard reconnaissance dashboard displaying an AI attack surface profile
A personality test with an ulterior motive. Mindgard’s reconnaissance dashboard maps the behavior that helps guide adversarial testing. Product image: Mindgard.

This places it within a busy AI security market. Alternatives include HiddenLayer and Palo Alto Networks’ Prisma AIRS; open-source projects such as PyRIT and Garak give practitioners other routes into testing. Mindgard’s proposition combines research, workflow integration and enterprise delivery. Buyers should compare coverage against their own systems, rather than treating any vendor’s comparison table as a verdict.

The buyer wants a repeatable answer

A security team needs more than a spectacular jailbreak. It needs to reproduce the failure, assign a fix and determine whether the fix holds. Mindgard supplies risk reporting and remediation workflows alongside testing. Its documentation and public repositories include a command-line interface, Python SDK, Burp Suite extension and GitHub Actions example.

Those integrations are a revealing detail. They put AI testing into places engineers already work. A team can assess an application through existing security tooling, feed findings into development and repeat checks as prompts, models or connected tools change. The useful output is evidence that a particular defense survived a particular test.

Its published customer stories describe a healthcare AI company improving a system prompt, a technology-services provider comparing defenses, and insurance and semiconductor organizations examining risk. The stories are anonymous. They reveal the jobs being done: validate sensitive applications, distinguish exploitable problems from noisy findings, and establish a baseline that can be revisited.

Mindgard sells enterprise software through tailored contracts, with professional services and training alongside it. Deployment options include SaaS and private or customer-managed environments. Customer cost requires a quote; the size of a funding round tells you nothing about the price of testing your application.

“We don't just automate attacks. We operationalize expertise.”

James Brear · CEO, Mindgard

Thirty million dollars for the next test

The financing follows the move from laboratory to enterprise sales: £3 million in 2023, an $8 million round announced in December 2024, then a $30 million Series A in August 2026. Album VC led the latest round, with Karma Ventures and returning investors participating. The stated spending plan covers product, engineering, sales and marketing.

150+

Publicly disclosed AI vulnerabilities, according to Mindgard’s August 2026 announcement. Research findings feed its attack intelligence.

In October 2025, James Brear became CEO and Garraghan moved to Chief Science Officer. September 2026 brought ecosystem relationships across Anthropic, NVIDIA, Microsoft, Google Cloud and AWS. These include verification and startup programs. The rationale is practical: enterprise AI spans providers, and security research must follow those connections.

Mindgard also won the UK’s Most Innovative Cyber SME award at Infosecurity Europe in June 2024. Awards supply recognition; the more useful signal is what a team does between ceremonies. Its public GitHub repositories and Hugging Face datasets let practitioners inspect some of the work. The company’s stated culture emphasizes collaboration, professional growth and flexibility. Public research offers a more concrete window into that culture: findings become demonstrations, datasets and methods other people can examine.

Copy the sequence

The transferable lesson is procedural. Inventory the system. Map what it can reach. Define an unacceptable outcome. Test the path, repair the weakness and rerun the experiment. That sequence helps even before a software purchase.

It depends on access to the relevant application and on someone acting on the findings. A passing test covers the behavior examined; new tools, permissions or model updates can alter the result. Mindgard’s appeal is the discipline of returning to the question. What could this helpful assistant be persuaded to do next?