Adversa AI
Founded 2021 Β· 18 employees on LinkedIn Β· 2 known investors
Adversa AI provides AI red teaming and security testing for enterprise AI agents and applications. It publishes AIRQ, an independent security rating covering enterprise AI agents along with an open source methodology for use in procurement and security posture tracking.
Also known as Adversa Β· Adversa.ai
Founders & leadership
Adversa AI was founded in 2021 by Sergey.
Investors Β· 2
Company profile
researched Aug 2026Adversa AI is an AI security company whose current product is a Coding Agent Security Platform, offered in early access, that acts as a runtime control layer over coding agents an enterprise has already approved, including Claude Code, GitHub Copilot, Cursor and Codex. The platform observes each agent action, interprets sequences of actions as connected chains rather than isolated events, blocks actions it judges dangerous, and records every action for audit purposes. It ships with more than 100 attack-anchored policies derived from the company's own offensive research. Alongside the platform, the company sells AI red teaming as a scoped service engagement covering models, AI agents and MCP servers, delivering findings ranked by business impact and audit packs mapped to frameworks used by auditors.
The company describes coverage of the full AI stack: model-level testing (jailbreaks, adversarial prompts, poisoning, safety bypasses), agentic issues (tool hijacking, goal manipulation, inter-agent and tool-chain abuse) and application/API issues (context contamination, authentication bypass, data exfiltration, session abuse). Core components include Self-Evolving Threat Intelligence (SETI), a vendor-side system that ingests AI security research, exploits and attack patterns and converts findings into structured attack playbooks, and an autonomous attack-planning capability that designs and chains multi-step campaigns against a customer's specific models, agents, tools and data flows rather than replaying a static prompt library. Outputs include business-aware risk prioritization, remediation playbooks with code and configuration changes, and evidence packs mapped to OWASP, MITRE and the EU AI Act.
Adversa AI also maintains public research and open-source work: a knowledge base of roughly 4,000 papers on adversarial AI and LLM security, an MCP Security TOP 25 framework, and SecureClaw, an open-source security framework and plugin for AI agents in the OpenClaw ecosystem, aligned with OWASP and MITRE frameworks and published on GitHub.
Business model
Enterprise software and services: a subscription-style security platform deployed in customer environments (public cloud through fully air-gapped, without calls to third-party public AI APIs), complemented by scoped AI red teaming engagements delivered by the same research lab.
Revenue comes from the enterprise Coding Agent Security Platform (sold via demo-led sales and currently in early access) and from AI red teaming delivered as a paid, scoped service engagement.
Traction
Reported metrics include 300+ attack techniques, a team credited with discovering 300+ zero-day vulnerabilities across AI systems, breaking frontier models in under four hours (GPT-3 through GPT-5 within hours of release), a 4,000-paper adversarial AI knowledge base, SETI enrichment from 3,000+ research and incident sources monthly, 20+ industry awards, SOC 2 Type I and II audits and ISO 27001 certification. Third-party data shows about 8,600 monthly website visits and 19 press mentions, and the SecureClaw open-source repository had 349 GitHub stars. Public research has drawn coverage of vulnerabilities found in Grok, ChatGPT, Claude and DeepSeek.
Latest developments
The company is offering its Coding Agent Security Platform in early access and continues to publish vulnerability research in 2026, including a Cursor deeplink flaw enabling remote code execution via an attacker-controlled MCP server, a zero-click Grok data-theft technique it calls Cryptographic Context Injection, analyses of zero-click attacks on AI agents, and explainers on OWASP agent-security top-ten lists. It also released SecureClaw, an open-source OWASP-aligned security framework for agents in the OpenClaw ecosystem.
βΈFull profile β market position, technology, go-to-market, geography, history
Market position
Positions itself against AI firewalls and evaluation tools by combining offensive research with runtime enforcement; cited as a Representative Vendor in Gartner research on GenAI security risks, listed among OWASP GenAI security tools and in the Cloud Security Alliance's AI security tools registry, and claims 20+ industry awards.
Differentiators claimed include chain-level rather than single-event detection of agent actions, red-team research compiled directly into default runtime policies (100+ attack-anchored policies), business-context risk prioritization tied to each AI use case, no dependency on public AI APIs with air-gap deployment, audit-ready evidence mapped to OWASP, MITRE and EU AI Act, a patented AI protection method, and team leadership roles in AI security standards bodies.
Technology
The platform combines a runtime interception and policy layer for coding agent actions with chain-level analysis of action sequences, Self-Evolving Threat Intelligence that ingests research and incident sources monthly and converts them into attack playbooks, and on-premises AI that autonomously plans and adapts multi-step attacks including system-specific generated zero-days. The company holds US patent 11,275,841 B2, described on its site as the first AI protection patent, and supports on-prem and air-gapped deployment with secrets never stored.
Go-to-market
Demo-led enterprise sales supported by published adversarial research, conference talks (DEF CON AI Village, Black Hat, RSA, HITB SecConf, Hacktivity, ML Conference, CogX), open-source releases such as SecureClaw, analyst recognition, and participation in standards bodies including OWASP, CoSAI, NIST, CSA, IEEE and ISACA.
Enterprises running mission-critical AI in production, particularly security leaders and CISOs in regulated sectors such as financial services and healthcare, including organizations with air-gapped environments; a customer example cited is an international fintech institution testing an internal generative AI assistant.
Geography
Described in company material as an Israeli AI startup; investors, angels and advisors are predominantly US-based with one Singapore-based advisor, and research has been presented at conferences in the USA, Europe, the Middle East and Asia.
History
Company communications describe roughly a decade of adversarial AI research. In 2021 the company publicized a technique for fooling facial recognition systems by adding noise to photos. In December 2022 co-founder and CTO Eugene Neelou was named Researcher of the Year in the SANS Difference Makers Awards. In October 2023 the company's LLM security solution was cited as a Representative Vendor in Gartner GenAI security research, and in September 2025 it published the MCP Security TOP 25 framework. Its product focus has since moved from research and red teaming services toward a runtime Coding Agent Security Platform released in early access.
Compiled by commissioned research from 8 cited public sources β announcements, filings, and press listed under research sources below.
Key figures
latest reportedCompany-reported or press-reported figures, each dated to when it was claimed β not independently audited.
Timeline Β· 7
launches, deals, and filingsResearch described an attack shipping instructions as ciphertext the model decrypts in its own sandbox, leaking full Grok chat histories without user interaction.
Company research described a crafted cursor:// link that installs an attacker-controlled MCP server running unsandboxed commands under the user's account.
Runtime control layer for approved coding agents (Claude Code, Copilot, Cursor, Codex) offered in early access, shipping with 100+ attack-anchored policies.
Open-source security plugin and framework for AI agents in the OpenClaw ecosystem, aligned with OWASP and MITRE frameworks, published on GitHub.
Adversa AI published the MCP Security TOP 25 Framework, a resource cataloguing MCP vulnerabilities, threats and defenses.
Adversa AI's LLM security solution was cited as a Representative Vendor in Gartner's report "Emerging Tech: Top 4 Security Risks of GenAI."
Eugene Neelou, co-founder and CTO of Adversa AI, was named Researcher of the Year by the SANS Difference Makers Awards.
Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.
βΈResearch sources Β· 8
primary sources listed
- Adversa AIadversa.ai Β· web
8 public sources were cited for this profile; the first-party ones are listed here.
Frequently asked questions
- What does Adversa AI do?
- Israeli AI security company offering a runtime control layer for coding agents plus AI red teaming services.
- Who founded Adversa AI?
- Adversa AI was founded by Sergey in 2021.
- Who are Adversa AI's investors?
- Adversa AI's investors include Foundry, Moxxie Ventures.

