Mindgard has raised $30 million in Series A funding, bringing its total funding to almost $42 million.
The platform has found more than 150 vulnerabilities in AI products, including a zero-day in Cursor and weaknesses in ChatGPT’s guardrails.
Two major competitors were acquired in the past year, and the AI security market is expected to reach $56.5 billion by 2033.
Researchers found a way to make Cursor’s AI-powered editor run any code without needing phishing links or malware. The same team also leaked Google Antigravity data across trust boundaries and bypassed ChatGPT’s image-generation guardrails.
Mindgard disclosed all three vulnerabilities.
The startup completed a $30 million Series A round led by Album VC, with new investor Karma Ventures and returning investors .406 Ventures, Atlantic Bridge, IQ Capital, and Lakestar. This brings its total funding to nearly $42 million, up from about $11.9 million raised in a 2023 seed round and a December 2024 Series A tranche.
“AI is creating an entirely new attack surface, and organisations need a fundamentally different approach to securing it. We don’t just automate attacks. We operationalize expertise, turning the knowledge of leading AI security researchers and offensive security practitioners into the capabilities every enterprise needs to secure their AI,” said James Brear, chief executive of Mindgard.
From a Lancaster University lab to a commercial red-teaming platform
Founded in 2022, the startup began in what it describes as the world’s largest AI security lab, built on more than ten years of research by Dr. Peter Garraghan at Lancaster University. Garraghan is now Mindgard’s chief science officer.
James Brear, who previously led Swimlane, Veriflow, and Procera, became CEO in October 2025 as the company moved from research to enterprise sales. The company has not shared its current headcount.
The platform runs ongoing, automated red-teaming against models, agents, and applications, simulating real attacker behavior rather than relying on static checklists. It does three main things: finds unmonitored “shadow AI,” tests deployed systems for vulnerabilities, and monitors AI applications in operation. For example, a bank launching a customer chatbot could use the platform to check for prompt injection and data leaks before and after launch.
Mindgard stands out by offering proof of work, with more than 150 disclosed vulnerabilities in real products added to its threat database. The company works with clients in financial services, pharmaceuticals, gaming, digital services, semiconductors, and healthcare.
Rapidly consolidating and well-funded category
The AI security sector has shifted from a crowded market to a consolidating one within a year. HiddenLayer raised $56 million, backed by Microsoft’s M12 and IBM Ventures. Zurich-based Lakera, known for its Gandalf prompt-injection game, raised $30 million before being acquired by Check Point in September 2025. Protect AI secured $60 million at a reported $400 million valuation before its acquisition by Palo Alto Networks the same year.
While other companies focus on guardrails, monitoring, or posture management, Mindgard prioritises offensive research by focusing on finding new exploits. This strategy is harder to copy, but it means Mindgard must stay ahead of attackers who also have access to AI tools. Two of its closest competitors, which focus on endpoint protection and stopping AI-era threats, have also raised large amounts of funding this year, showing how competitive this sector is.
“Organisations are moving AI into critical operations without security infrastructure designed for how these systems operate in practice. Mindgard has translated deep research and elite offensive-security expertise into a continuously evolving capability that enables enterprises to stay ahead of emerging AI threats,” said Ty Boswell, partner at Album VC.
“AI security is an emerging category, and Mindgard stands out as one of the names to watch. Its technology is built on world-class offensive security research, combining automated reconnaissance with smart penetration testing. Crucially, it’s already proven in production — some of the most demanding F2000 enterprises rely on it to safeguard their AI systems,” added Kristjan Laanemaa, founding partner at Karma Ventures.
The future beyond vulnerability discovery
The AI security platforms market was valued at about $15.8 billion this year and is expected to reach $56.5 billion by 2033. The smaller but faster-growing agentic AI security segment could grow more than ten times by the early 2030s, according to some estimates.
The new funding will help grow product development, engineering, sales, and marketing.
Lakera and Protect AI have been bought and are now part of bigger security platforms. Mindgard, HiddenLayer, and a few others are still competing for market share. Now, the main question is who can turn these discoveries into long-term enterprise contracts before a bigger company buys them.