Seminal AI
§6

AI red teaming and pre-deployment security testing

AI red teaming is the offensive counterpart to runtime guardrails: before an LLM application ships, someone deliberately attempts prompt injection, jailbreaks, tool abuse, authorisation bypass and data exfiltration against the real system, and writes down what worked. The tooling splits into three shapes — open-source frameworks you script and run in CI, commercial SaaS platforms that maintain an attack library and produce management reporting, and human-led penetration tests that produce a signed, scoped report.

Data checked 2026-09-06

What has changed is who asks for it: enterprise procurement questionnaires, EU AI Act Article 15 robustness evidence, NIST AI RMF MEASURE controls and ISO/IEC 42001 audits increasingly want an artefact, not an assurance. The category also consolidated hard through 2025-2026 — Robust Intelligence into Cisco, Protect AI into Palo Alto, Lakera into Check Point, CalypsoAI into F5, SPLX into Zscaler and Virtue AI into Fortinet — so several names on a 2024 shortlist are now modules of a network-security platform rather than products you can buy alone.

A How to choose

Four axes actually separate these tools. First, what gets attacked: garak and CyberSecEval probe a bare model endpoint, while promptfoo, Giskard, DeepTeam and the commercial platforms attack your assembled application — system prompt, retrieval corpus, tool scopes and authorisation logic — which is where almost all real exploitable findings live, so a model-level scan that comes back clean proves very little about your product. Second, who runs it: a framework like PyRIT is a construction kit that assumes a security engineer who will write Python and own the reporting, whereas Mindgard, Repello or F5 hand you a maintained attack library and a report, and Bugcrowd hands you humans.

Third, what evidence you need out the other end: if the requirement is an auditor-facing artefact, a JSONL hit-rate table from garak will not do, and Giskard's own docs explicitly state its scan results are "not a safety or compliance guarantee" — check the OWASP LLM Top 10 / NIST AI RMF / EU AI Act mapping before you buy, and expect that a CREST-accredited human pentest is what a regulated customer actually asks for. Fourth, whether you want testing alone or a platform that also sells the runtime firewall, because that choice buys you either best-of-breed independence or one throat to choke — and, right now, meaningful acquisition risk. On when not to use the default: promptfoo is the correct starting point for most teams and costs nothing, but it is the wrong choice if nobody will maintain the config and grader models, if your token budget cannot absorb runs the docs themselves warn can cost "hundreds of dollars," or if your blocker is a procurement questionnaire demanding a named, accountable tester.

Conversely, do not buy a six-figure platform SKU to solve a problem an afternoon with garak plus promptfoo in CI would surface — run the free tools first, and buy a platform only once you need continuous coverage, attack research you are not going to do yourself, or on-prem/air-gapped execution. Whatever you pick, point it at the real deployed application with real tool scopes and a low-privilege test tenant, not a mock, and re-run it on every prompt or tool-permission change, because a red team report against last quarter's system prompt is decoration. Two watch-outs on the candidate lists circulating: Patronus AI has pivoted to simulation and RL environments and no longer lists red teaming, so it should come off 2024-era shortlists, and Haize Labs' GitHub org is still active into 2026 while its product site blocks automated access — verify it directly before shortlisting.

Straiker (Ascend AI) and Pillar Security are credible agent-focused adjacents worth adding if multi-turn agent and MCP testing is your specific problem.

B At a glance

Name DeploymentAttack libraryAgentic / tool-abuse testingFramework mappingRuntime guardrails from same vendor Pricing
promptfoo Self-hosted CLI/Docker; Enterprise SaaS or on-prem157 plugins plus multi-turn/encoding strategiesYes — BOLA, BFLA, RBAC and tool-abuse pluginsOWASP LLM Top 10, NIST AI RMF, EU AI ActNo — testing only Community tier free forever, capped at 10,000 red team probes per month. Enterprise and On-Premise are listed as "Custom" with no dollar figures published; the vendor states pricing is based on team size and needs.
NVIDIA garak Self-hosted CLI (pip or Docker)19+ probe modules, hundreds of payloadsLimited — model-endpoint focusedNone built in (probe-level taxonomy only)No (NeMo Guardrails is a separate NVIDIA project) Free. Apache 2.0 licensed, no commercial tier.
Microsoft PyRIT Self-hosted Python library; optional GUI and CoPyRIT on AzureComposable attacks plus ~30 prompt convertersYes, via custom targets — but you build the harnessNone built inNo (Azure AI Content Safety is separate) Free. MIT licensed. CoPyRIT deployment consumes your own Azure Container Apps capacity.
DeepTeam Self-hosted Python library; optional Confident AI SaaS20+ attack methods across 50+ vulnerability categoriesYes — goal theft, excessive agency, tool abuse, RBACOWASP Top 10 LLM, NIST AI RMF, MITRE ATLAS, EU AI ActYes — DeepTeam ships production guardrails DeepTeam library is free (Apache 2.0). Confident AI platform: Free $0/month, Starter $200/month, Team $2,000/month, Enterprise custom — the hosted AI red teaming module is listed only as an "Enterprise ++" add-on beyond the base Enterprise plan.
Giskard Self-hosted Python library; Hub as managed or on-prem50+ adversarial probes plus generated app-specific suitesPartial — multi-turn agent testing is the v3 targetOWASP LLM Top 10; EU AI Act positioningNo — testing and evaluation only Open-source library $0 USD, described as a solo tier. Giskard Hub (Enterprise) is quote-only — no dollar or euro figures are published on the pricing page.
Meta Purple Llama (CyberSecEval) Self-hosted benchmark harness (Python)8 benchmark suites; static datasets, not generated attacksPartial — code-interpreter abuse and autonomous cyber ops onlyNone built inYes — Llama Guard, Prompt Guard, Code Shield Free. Evaluations MIT-licensed; safeguard models under Llama Community licence.
Mindgard SaaS platform with CLI and Python SDKVendor-maintained LLM/ML attack library; size undisclosedYes — agent profiling and guardrail-busting testsunknown — not stated on public pagesNo — discovery, assessment and defence guidance unknown — no pricing tiers or figures are published; the pricing page routes to "Book a Demo".
SPLX (Zscaler) SaaS platform; Agentic Radar runs locallyVendor-maintained; size undisclosedYes — plus static agent-workflow scanningOWASP and governance/compliance automation moduleYes — input/output guardrails and log inspection unknown — the site references a pricing section but publishes no rates; access is via "Book a Demo". Agentic Radar is free and open source.
Repello AI (ARTEMIS) SaaS platform; endpoint agent for Workstation LensClaimed 15M+ attack patterns (unaudited)Yes — agents, tools and multimodal inputsOWASP, NIST, MITREYes — ARGUS unknown — no pricing published; a free Recon scan and a 7-day pilot are offered, with pricing by quote.
HiddenLayer SaaS platform with discovery and runtime componentsVendor-maintained adversarial simulations; size undisclosedYes — agentic, MCP and agent-harness security modulesunknown — not stated on public pagesYes — AI Runtime Security and AI Guardrails unknown — no pricing published on the site.
Lakera (Check Point) SaaS platform; expert-led service engagementsGandalf-derived injection corpus plus vendor researchYes — AI Agent Security line covers agent runtime and testingunknown — not stated on public pagesYes — runtime AI Agent Security unknown — no pricing published; sales-led under Check Point.
Virtue AI (Fortinet) SaaS platform with sandboxed agent environmentsClaimed 100+ algorithms, 600+ attack vectors (unaudited)Yes — 50+ sandboxed environments across 14 domainsunknown — not stated on public pagesYes — VirtueGuard and AgentSuite-Blue unknown — no pricing published on the site.
Gray Swan AI SaaS (Shade) plus managed human red team engagementsAutomated attacks plus a live human researcher networkYes — explicitly targets agents with tool and API accessunknown — not stated on public pagesYes — Cygnal unknown — no pricing published on the site.
F5 AI Red Team SaaS on AWS/Azure/GCP, or on-prem Red Hat OpenShift operatorClaimed 10,000+ new attack patterns added monthlyYes — dynamic agent workflows with attack-path tracingunknown — not stated on the product pageYes — F5 AI Guardrails, sold separately unknown — no pricing published; contact sales or request a trial.
Cisco AI Defense SaaS with network-inline enforcement pointsAlgorithmic red teaming; library size undisclosedunknown — not detailed on public pagesunknown — not stated on the product pageYes — guardrails are the paired half of the product unknown — no pricing listed; an Explorer Edition is available for evaluation.
Palo Alto Prisma AIRS SaaS platform with gateway and runtime enforcementVendor-maintained; size undisclosedYes — dedicated Agent Security module plus agent red teamingunknown — not stated on public pagesYes — AI Runtime Security and AI Gateway unknown — quote-only; no published rates for the platform or individual modules.
Adversa AI Services engagements plus a runtime platform for coding agentsSETI threat intelligence ingested from public research monthlyYes — agentic and MCP red teaming are named offeringsunknown — not stated on public pagesYes — Coding Agent Security Platform unknown — not disclosed publicly; requires a demo conversation.
Bugcrowd AI Pen Test Managed human penetration test engagementResearcher expertise plus platform vulnerability corpusYes — excessive agency and tool misuse are named in scopeOWASP Top 10 for LLMs; ISO 27001, SOC 2, HIPAA, GDPR, PCI DSS reportingNo — services only unknown — quote-only, priced per engagement by scope.

C Entries

promptfoo

Reads a config describing your application, generates application-specific adversarial test cases, executes them against your live endpoint and produces a vulnerability report with a web dashboard. 157 plugins span brand risk, compliance and legal, research datasets, security and access control, trust and safety, and custom policy tests; separate strategies transform single-turn seeds into multi-turn or encoded sequences. Unlike garak, which fires a fixed battery at a model endpoint, promptfoo derives attacks from your system's stated purpose and can therefore probe your system prompt, RAG corpus and tool permissions.

DeploymentSelf-hosted CLI/Docker; Enterprise SaaS or on-prem
Attack library157 plugins plus multi-turn/encoding strategies
Agentic / tool-abuse testingYes — BOLA, BFLA, RBAC and tool-abuse plugins
Framework mappingOWASP LLM Top 10, NIST AI RMF, EU AI Act
Runtime guardrails from same vendorNo — testing only

Watch out: The docs warn that a single red team run "can range anywhere from a few cents to hundreds of dollars" in token spend, and cost scales with plugin and strategy count — teams routinely get surprised. Finding quality depends entirely on the grader model you configure, so a weak judge produces both false positives and quiet misses. Team features (RBAC, shared reporting, unlimited probes) sit behind an unpriced Enterprise contract, and the free tier's 10k probes/month is consumed quickly by a serious run.

Community tier free forever, capped at 10,000 red team probes per month. Enterprise and On-Premise are listed as "Custom" with no dollar figures published; the vendor states pricing is based on team size and needs. · open source

NVIDIA garak

A probe-and-detector scanner: each probe module emits a family of attack payloads, detectors score the responses, and you get a hit rate per probe. Nineteen-plus probe modules cover encoding-based injection, DAN-style jailbreaks, toxicity, malware generation, prompt injection and XSS, against targets including Hugging Face Hub, OpenAI, AWS Bedrock, Replicate, Cohere, Groq, LiteLLM, generic REST endpoints, GGUF via llama.cpp and NVIDIA NIM. Version 0.16.0 shipped 4 August 2026 and added technique and intent annotation plus an initial IntentProbe.

DeploymentSelf-hosted CLI (pip or Docker)
Attack library19+ probe modules, hundreds of payloads
Agentic / tool-abuse testingLimited — model-endpoint focused
Framework mappingNone built in (probe-level taxonomy only)
Runtime guardrails from same vendorNo (NeMo Guardrails is a separate NVIDIA project)

Watch out: It tests the model, not the application — garak has no concept of your system prompt, retrieval corpus, tool scopes or per-user authorisation, so it will never find BOLA/BFLA-class agent flaws. Output is a JSONL log and a hit-rate table with no compliance mapping or management reporting, so it does not produce an auditor-facing artefact on its own. v0.16.0 introduced breaking changes to the unified spec syntax and config file formats, so pinned CI jobs will need rework.

Free. Apache 2.0 licensed, no commercial tier. · open source

Microsoft PyRIT

A construction kit rather than a scanner: you compose targets, attack strategies, prompt converters and scorers in Python to automate whatever attack your red team designs. Version 1.1.0 (4 September 2026) added best-of-N jailbreaks, split-payload and multilingual attacks, audio analysis, and ten new converters including bijection, CharNoise, CodeAttack, SATA, Vigenère, acrostic and IPA, plus a GUI scenario catalog with HTML export. Note the repository moved: Azure/PyRIT was archived read-only on 27 March 2026 and development continues at microsoft/PyRIT.

DeploymentSelf-hosted Python library; optional GUI and CoPyRIT on Azure
Attack libraryComposable attacks plus ~30 prompt converters
Agentic / tool-abuse testingYes, via custom targets — but you build the harness
Framework mappingNone built in
Runtime guardrails from same vendorNo (Azure AI Content Safety is separate)

Watch out: It is deliberately unopinionated — there is no turnkey "scan my app" command, and you own scoping, orchestration and reporting, which is real headcount rather than a licence cost. v1.1.0 shipped breaking changes to score handling (you must check score.is_undetermined before reading a value) and to CoPyRIT deployment. Anyone still pinned to Azure/PyRIT is consuming an archived, read-only repository and will silently miss updates.

Free. MIT licensed. CoPyRIT deployment consumes your own Azure Container Apps capacity. · open source

DeepTeam

Declarative Python red teaming from the team behind DeepEval, so the config idiom is familiar to anyone already writing DeepEval metrics. Vulnerability coverage spans PII and prompt leakage, bias, toxicity, SQL/shell injection, SSRF, and agentic-specific risks such as goal theft, excessive agency and tool abuse; attacks include roleplay, leetspeak/ROT13/base64 encoding and multi-turn linear, tree and crescendo jailbreaking. Results map to OWASP Top 10 for LLMs, NIST AI RMF, MITRE ATLAS and the EU AI Act, and can be pushed to the Confident AI platform for tracking.

DeploymentSelf-hosted Python library; optional Confident AI SaaS
Attack library20+ attack methods across 50+ vulnerability categories
Agentic / tool-abuse testingYes — goal theft, excessive agency, tool abuse, RBAC
Framework mappingOWASP Top 10 LLM, NIST AI RMF, MITRE ATLAS, EU AI Act
Runtime guardrails from same vendorYes — DeepTeam ships production guardrails

Watch out: The hosted reporting is where the value concentrates, and the AI red teaming module is gated behind an Enterprise++ add-on — neither the $200/month Starter nor the $2,000/month Team tier includes it, so the genuinely free path is self-hosting and building your own dashboards. Both attack generation and judging burn tokens on a model you supply, so cost is yours to model. Coverage breadth (120+ claimed vulnerability variants) outruns depth on any single class, and the multi-turn attackers are LLM-driven, so results vary run to run.

DeepTeam library is free (Apache 2.0). Confident AI platform: Free $0/month, Starter $200/month, Team $2,000/month, Enterprise custom — the hosted AI red teaming module is listed only as an "Enterprise ++" add-on beyond the base Enterprise plan. · open source

Giskard

The Apache-2.0 library (~5.8k stars) exposes vulnerability_scan and quality_scan plus pytest-style behavioural tests, generating adversarial suites automatically from a plain-language description of the agent and shipping a built-in corpus of injection payloads. Coverage includes prompt injection, harmful content, stereotypes and bias, misinformation and the OWASP LLM Top-10 categories, with dedicated RAG knowledge-base quality checks that most red team tools omit. The paid Giskard Hub layers on continuous red teaming, RBAC, dataset management, custom failure categories, SSO and audit logs; a v3 rewrite is underway focused on dynamic multi-turn agent testing.

DeploymentSelf-hosted Python library; Hub as managed or on-prem
Attack library50+ adversarial probes plus generated app-specific suites
Agentic / tool-abuse testingPartial — multi-turn agent testing is the v3 target
Framework mappingOWASP LLM Top 10; EU AI Act positioning
Runtime guardrails from same vendorNo — testing and evaluation only

Watch out: Giskard's own documentation states that scan "results are not a safety or compliance guarantee" — do not present the report to an auditor as a pass. The v2 tabular and classic-ML scanning functionality still ships but is no longer actively maintained, so do not build on it. The open-source tier is explicitly positioned for solo experiments: continuous red teaming and anything team-shaped requires the unpriced Hub contract, and the v3 rewrite means near-term API churn.

Open-source library $0 USD, described as a solo tier. Giskard Hub (Enterprise) is quote-only — no dollar or euro figures are published on the pricing page. · open source

Meta Purple Llama (CyberSecEval)

CyberSecEval is a benchmark suite, not a scanner: it measures insecure code suggestions, malicious code generation, code-interpreter abuse, offensive cyber capability, prompt-injection and visual prompt-injection susceptibility, spear-phishing capability, and autonomous offensive operations. It ships inside Purple Llama alongside the Llama Guard input/output moderation models, Prompt Guard for injection and jailbreak detection, and Code Shield for filtering insecure generated code. Evaluations are MIT-licensed; the safeguard model weights carry Llama Community licences permitting research and commercial use.

DeploymentSelf-hosted benchmark harness (Python)
Attack library8 benchmark suites; static datasets, not generated attacks
Agentic / tool-abuse testingPartial — code-interpreter abuse and autonomous cyber ops only
Framework mappingNone built in
Runtime guardrails from same vendorYes — Llama Guard, Prompt Guard, Code Shield

Watch out: This is model-selection evidence, not an application penetration test: it scores a model in isolation and says nothing about your system prompt, retrieval corpus, tool scopes or authorisation logic, so a good CyberSecEval score is not a defensible pre-deployment sign-off. Repository activity is bursty (478 commits total) and tied to Llama release cycles rather than any support commitment, and there is no reporting layer, ticketing integration or compliance mapping. As a public benchmark it is also a training-contamination target, so scores drift upward for reasons unrelated to safety.

Free. Evaluations MIT-licensed; safeguard models under Llama Community licence. · open source

Mindgard

A Lancaster University spin-out (Boston and London) that runs a maintained attack library against your deployed application via CLI, Python SDK or the platform UI, pairing each finding with entries from a remediation library. Beyond straight red teaming it does AI attack-surface enumeration and shadow-AI discovery, plus agent-specific tests it calls psychometric agent profiling and guardrail busting. The team publishes disclosed vulnerabilities — 150+ including findings in Google's Antigravity IDE, OpenAI Sora, Zed and Grok — which is a usable proxy for whether the underlying attack research is real rather than repackaged public payloads.

DeploymentSaaS platform with CLI and Python SDK
Attack libraryVendor-maintained LLM/ML attack library; size undisclosed
Agentic / tool-abuse testingYes — agent profiling and guardrail-busting tests
Framework mappingunknown — not stated on public pages
Runtime guardrails from same vendorNo — discovery, assessment and defence guidance

Watch out: No published pricing at any tier, so every evaluation begins with a sales conversation and there is no way to budget before contact. Public documentation is thin on the exact size of the attack library and on CI/CD wiring specifics, which makes scoping a pilot harder than it should be. As an independent of modest size it lacks the procurement gravity of the Cisco, Palo Alto or F5 platform plays, and buyers in regulated sectors should ask directly about data residency and whether prompts leave their tenancy.

unknown — no pricing tiers or figures are published; the pricing page routes to "Book a Demo".

SPLX (Zscaler)

SPLX's platform combines AI asset discovery and vulnerability mapping, automated red teaming, runtime input/output guardrails, governance automation and — unusually — dynamic remediation that proposes hardened system prompts derived from the findings. Agentic Radar is a separately usable open-source scanner that statically maps an agent framework's workflow graph and flags tool and prompt risks, which is useful even if you never buy the commercial product. The company publishes model-level stress tests (GPT-5, Claude Opus 4.1, Grok 4) as marketing but also as a demonstration of the attack methodology.

DeploymentSaaS platform; Agentic Radar runs locally
Attack libraryVendor-maintained; size undisclosed
Agentic / tool-abuse testingYes — plus static agent-workflow scanning
Framework mappingOWASP and governance/compliance automation module
Runtime guardrails from same vendorYes — input/output guardrails and log inspection

Watch out: Acquisition risk is live rather than theoretical: standalone SPLX contracting, roadmap and pricing are being absorbed into Zscaler's AI lifecycle bundles, so non-Zscaler buyers must confirm in writing that standalone purchase survives and at what price. No pricing is published at any level. The remediation feature that auto-hardens system prompts is genuinely useful but also creates a dependency — regenerated prompts need their own review before they reach production.

unknown — the site references a pricing section but publishes no rates; access is via "Book a Demo". Agentic Radar is free and open source.

Repello AI (ARTEMIS)

ARTEMIS runs continuous autonomous red teaming against AI agents and applications and reports validated, exploitable attack paths rather than a raw list of suspicious responses, which materially cuts triage time. Repello claims 15M+ evolving attack patterns and maps findings to OWASP, NIST and MITRE. The surrounding portfolio is broader than most: ARGUS for runtime enforcement, an AI asset Inventory, and Workstation Lens, which monitors coding agents such as Claude Code, Cursor and Copilot on employee endpoints for file access, command execution and exfiltration. SOC 2 and ISO 27001 certified, with a free Recon scan and a 7-day pilot.

DeploymentSaaS platform; endpoint agent for Workstation Lens
Attack libraryClaimed 15M+ attack patterns (unaudited)
Agentic / tool-abuse testingYes — agents, tools and multimodal inputs
Framework mappingOWASP, NIST, MITRE
Runtime guardrails from same vendorYes — ARGUS

Watch out: No published pricing and a young company, so contract terms and long-term viability carry more weight in the decision than they would with an incumbent. Named reference customers (Groww, PhysicsWallah, Lyzr, Lorikeet) are concentrated in India-based fintech and edtech — ask for references in your own regulatory geography and data-residency regime. The "15M+ attack patterns" figure is a vendor count with no published methodology, and should not be compared numerically against other vendors' claims.

unknown — no pricing published; a free Recon scan and a 7-day pilot are offered, with pricing by quote.

HiddenLayer

The platform is organised as AI Discovery, AI Supply Chain Security, AI Attack Simulation and AI Runtime Security. Attack Simulation runs continuous adversarial testing against deployed AI; the supply-chain module detects malicious models, backdoored weights and vulnerable dependencies before deployment, a lane most pure red team tools do not cover at all. Additional modules address agentic and MCP security and agent-harness security. The company raised a $100M Series B, which is meaningful for enterprise buyers weighing vendor longevity.

DeploymentSaaS platform with discovery and runtime components
Attack libraryVendor-maintained adversarial simulations; size undisclosed
Agentic / tool-abuse testingYes — agentic, MCP and agent-harness security modules
Framework mappingunknown — not stated on public pages
Runtime guardrails from same vendorYes — AI Runtime Security and AI Guardrails

Watch out: Red teaming is one module of a platform sale, so buying it standalone is awkward and pricing is entirely undisclosed. If all your models are hosted APIs you never download, the model-file scanning that justifies a large share of the price is dead weight — in that case a specialist testing tool is better value. The four-module structure also means real deployment effort (discovery agents, runtime interception) before you get to the red teaming you actually came for.

unknown — no pricing published on the site.

Lakera (Check Point)

Lakera sells AI Red Teaming as risk-based automated vulnerability testing of GenAI applications, and a separate expert-led AI Red Teaming Service for engagements that need humans. These sit alongside runtime AI Agent Security and Workforce AI Security for shadow-AI discovery and data protection. Attack data is informed by Gandalf, its long-running public prompt-injection game, which has produced one of the larger real-world corpora of human-authored injection attempts. The Lakera brand is retained under Check Point ownership; the site now carries Check Point's copyright.

DeploymentSaaS platform; expert-led service engagements
Attack libraryGandalf-derived injection corpus plus vendor research
Agentic / tool-abuse testingYes — AI Agent Security line covers agent runtime and testing
Framework mappingunknown — not stated on public pages
Runtime guardrails from same vendorYes — runtime AI Agent Security

Watch out: Post-acquisition naming has shifted — the familiar "Lakera Red" and "Lakera Guard" split is no longer how the site presents the portfolio, so verify exactly which SKU you are buying. Roadmap priorities now serve Check Point's platform strategy, which is a genuine risk if you want a best-of-breed testing tool that stays independent of a network-security suite. No public pricing, and the strongest published evidence (Gandalf) is about prompt injection specifically rather than the full agent tool-abuse surface.

unknown — no pricing published; sales-led under Check Point.

Virtue AI (Fortinet)

VirtueRed performs continuous automated red teaming with a claimed 100+ proprietary red-teaming algorithms and 600+ attack vectors across 1,000+ risk categories. The genuine differentiator is AgentSuite-Red: 50+ sandboxed environments across 14 high-stakes domains modelled on real tools (Databricks, Gmail, PayPal analogues), so an agent can be attacked while actually holding tools and taking consequential actions rather than answering in a chat box. VirtueGuard and AgentSuite-Blue cover the runtime side, including MCP Guard for tool scanning and CodeGuard for AI-generated code. Fortinet announced the acquisition in 2026.

DeploymentSaaS platform with sandboxed agent environments
Attack libraryClaimed 100+ algorithms, 600+ attack vectors (unaudited)
Agentic / tool-abuse testingYes — 50+ sandboxed environments across 14 domains
Framework mappingunknown — not stated on public pages
Runtime guardrails from same vendorYes — VirtueGuard and AgentSuite-Blue

Watch out: Fortinet's 2026 acquisition puts standalone contracting, pricing continuity and roadmap independence in question — get commitments in the contract, not the demo. The headline algorithm, attack-vector and risk-category counts are unaudited vendor numbers with no published methodology and should not be compared against rivals' equivalents. Sandboxed environments are approximations of your stack, not your stack, so passing AgentSuite-Red does not substitute for testing against your real integrations with real permission scopes.

unknown — no pricing published on the site.

Gray Swan AI

Three distinct offerings: Shade for automated adversarial red teaming, Cygnal for runtime blocking of adversarial inputs and unsafe outputs, and Arena, a competitive network of human red teamers that Gray Swan describes as the largest adversarial AI red teaming network. It also runs pre-release adversarial evaluations for frontier model builders. The human-crowd model finds classes of attack that automated generators do not, at the cost of scheduling an event rather than running a command.

DeploymentSaaS (Shade) plus managed human red team engagements
Attack libraryAutomated attacks plus a live human researcher network
Agentic / tool-abuse testingYes — explicitly targets agents with tool and API access
Framework mappingunknown — not stated on public pages
Runtime guardrails from same vendorYes — Cygnal

Watch out: The centre of gravity is frontier-model evaluation and crowd events, not routine CI testing of a mid-size company's RAG chatbot — expect a services-shaped engagement with lead times, not a self-serve tool. No public pricing at any tier. The named labs (OpenAI, Google DeepMind, Anthropic, Amazon, Meta) are research partnerships rather than customer endorsements, so do not read them as commercial references for enterprise deployment work.

unknown — no pricing published on the site.

F5 AI Red Team

Sold as a product distinct from F5 AI Guardrails: autonomous swarm agents run attack campaigns against models, applications and agents covering prompt injection, jailbreaks and static and multi-turn attacks, and return "agentic fingerprints" that trace how each successful exploit propagated. F5 states 10,000+ new attack patterns are added to the library monthly. It runs on AWS, Azure and Google Cloud or on-premises as a certified Red Hat OpenShift operator — one of the few red teaming platforms with a credible air-gapped and sovereign deployment story. This is the former CalypsoAI Inference Red-Team; calypsoai.com now redirects to F5.

DeploymentSaaS on AWS/Azure/GCP, or on-prem Red Hat OpenShift operator
Attack libraryClaimed 10,000+ new attack patterns added monthly
Agentic / tool-abuse testingYes — dynamic agent workflows with attack-path tracing
Framework mappingunknown — not stated on the product page
Runtime guardrails from same vendorYes — F5 AI Guardrails, sold separately

Watch out: Branding and packaging have changed twice in short order (CalypsoAI to F5, then split into AI Guardrails and AI Red Team), so existing CalypsoAI customers must confirm exactly what their contract converts to and which engineering team owns the roadmap. Pricing is entirely undisclosed. The "10,000 attack patterns added every month" figure has no published methodology, and an on-prem OpenShift deployment is a substantially heavier lift than a pip install if you do not already run OpenShift.

unknown — no pricing published; contact sales or request a trial.

Cisco AI Defense

The AI Model and Application Validation component applies algorithmic red teaming to surface safety and security vulnerabilities across models at scale, then feeds the findings directly into guardrails deployed in front of the application — the validate-then-protect loop is the product's core argument. The technology descends from Cisco's Robust Intelligence acquisition, one of the earliest serious AI validation vendors. An Explorer Edition is available for evaluation without a full commitment.

DeploymentSaaS with network-inline enforcement points
Attack libraryAlgorithmic red teaming; library size undisclosed
Agentic / tool-abuse testingunknown — not detailed on public pages
Framework mappingunknown — not stated on the product page
Runtime guardrails from same vendorYes — guardrails are the paired half of the product

Watch out: This is a Cisco security-platform purchase, and it makes far less sense as a standalone testing tool for a single application team than as part of an existing Cisco relationship. Public documentation of application-level agent testing depth — tool abuse, multi-step authorisation bypass, MCP surfaces — is thinner than at the specialists, so probe that in a POC rather than assuming parity. Pricing is undisclosed, and the marketing emphasis on assessing risk "in mere seconds" should be validated against your own application rather than taken at face value.

unknown — no pricing listed; an Explorer Edition is available for evaluation.

Palo Alto Prisma AIRS

Prisma AIRS bundles AI Red Teaming — simulating real-world attacks to find loopholes across AI agents and applications — with AI Model Security, which scans third-party models for tampering, malicious scripts and deserialization attacks before you adopt them. Around these sit an AI Gateway control plane, Agent Security for identity verification and enforcement, AI Runtime Security and AI Posture Management. The model-supply-chain lineage runs through the Protect AI acquisition, which brought ModelScan and related tooling.

DeploymentSaaS platform with gateway and runtime enforcement
Attack libraryVendor-maintained; size undisclosed
Agentic / tool-abuse testingYes — dedicated Agent Security module plus agent red teaming
Framework mappingunknown — not stated on public pages
Runtime guardrails from same vendorYes — AI Runtime Security and AI Gateway

Watch out: Red teaming is one line item in a large platform SKU — you will not buy it standalone, and pricing is quote-only, so this is a heavier procurement than the problem warrants if all you need is a pre-deployment report. The platform assumes you are also adopting the AI Gateway and runtime layers, which is architectural commitment as well as spend. Product naming in this portfolio has churned repeatedly since the Protect AI acquisition, so confirm which module names are current at contract time.

unknown — quote-only; no published rates for the platform or individual modules.

Adversa AI

Adversa delivers agentic AI, LLM, generative AI and MCP red teaming, underpinned by what it calls Self-Evolving Threat Intelligence, which continuously ingests published AI security research, exploits and attack patterns from thousands of sources each month. Its newer Coding Agent Security Platform is a runtime control layer that blocks dangerous actions from Claude Code, Copilot, Cursor and Codex. The team has a long track record in adversarial ML research and public vulnerability disclosure, and is cited as a Gartner Representative Vendor and IDC Innovator.

DeploymentServices engagements plus a runtime platform for coding agents
Attack librarySETI threat intelligence ingested from public research monthly
Agentic / tool-abuse testingYes — agentic and MCP red teaming are named offerings
Framework mappingunknown — not stated on public pages
Runtime guardrails from same vendorYes — Coding Agent Security Platform

Watch out: Small team with a services centre of gravity, so throughput and turnaround depend on their availability — this is not a scanner you drop into CI and forget. Product focus has visibly shifted toward the coding-agent runtime control layer, so confirm that pre-deployment red teaming is still a first-class engagement rather than an add-on to a platform sale. No published pricing, and being research-led means the depth is in the people, so ask who specifically is assigned to your engagement.

unknown — not disclosed publicly; requires a demo conversation.

Bugcrowd AI Pen Test

A scoped human penetration test rather than a scanner. Bugcrowd matches researchers with demonstrated LLM security experience via its CrowdMatch system, tests for prompt injection, excessive agency, training-data poisoning and the rest of the OWASP Top 10 for LLMs, and delivers customisable reports that support ISO 27001, SOC 2, HIPAA, GDPR and PCI DSS evidence requirements. It holds CREST accreditation for penetration testing, which matters when a customer's security questionnaire asks who performed the test and under what standard.

DeploymentManaged human penetration test engagement
Attack libraryResearcher expertise plus platform vulnerability corpus
Agentic / tool-abuse testingYes — excessive agency and tool misuse are named in scope
Framework mappingOWASP Top 10 for LLMs; ISO 27001, SOC 2, HIPAA, GDPR, PCI DSS reporting
Runtime guardrails from same vendorNo — services only

Watch out: Point-in-time and slow: one scoped engagement produces one report and zero continuous coverage, so it complements rather than replaces automated testing in CI — your system prompt will change the week after delivery. Pricing is quote-only per engagement and typically an order of magnitude above tooling. Output quality varies with which researchers get matched to your scope, and HackerOne offers a near-identical AI pentest product, so run both quotes before committing.

unknown — quote-only, priced per engagement by scope.