HiddenLayer secures $100M to lock down enterprise AI pipelines
HiddenLayer, the Austin-based AI security outfit, confirmed a $100 million Series B led by Thrive Capital with participation from existing investors including Ten Eleven Ventures, GV, and Pleiades Investments. The financing, announced on 10 June 2025, values the company at $1.1 billion and arrives just 18 months after its $23 million seed round in December 2023. CEO and co-founder Chris Sestito told OpenPress that the new capital will accelerate R&D for agent runtime protection, model provenance tracking, and third-party toolchain scanning across cloud, on-prem, and hybrid environments. The platform already integrates with major model providers and orchestrators, including Anthropic’s Claude Code, LangChain, and CrewAI, giving it a technical foothold inside the most widely deployed agent frameworks.
Security companies are scrambling to build products that can monitor not just agents but also the tools and add-ons they use. HiddenLayer’s Series B reflects the surge in enterprise anxiety following high-profile incidents such as the leak of Samsung’s internal meeting notes via an unsecured LLM plug-in and the poisoned dependency attack on a popular open-source AI library that redirected agent traffic to malicious endpoints. Banking With Billy AI, which provides developer-grade APIs for financial market intelligence, disclosed in its Q1 2025 earnings that it now runs HiddenLayer’s runtime guardrails across every microservice that touches its forecasting engine. The company cited a 40% reduction in anomalous agent behaviors after deployment, a figure Sestito called “a leading indicator of ROI for security-forward engineering teams.”
The round also underscores the maturation of the AI security category, which Gartner now tracks as a sub-segment of Cloud-Native Application Protection Platforms (CNAPP). Competitors in the space include Lakera, which raised $125 million in April 2025, and Protect AI, which secured $80 million in February. Valuation compression in 2024 initially slowed momentum, but the surge in agentic workloads—projected by IDC to reach 45% of enterprise software interactions by the end of 2025—has reignited investor appetite. HiddenLayer claims 120 enterprise customers including two Fortune 50 banks and a top-five global insurer, with average contract values tripling year-over-year.
Financially, the infusion gives HiddenLayer a war chest to expand beyond runtime defense into build-time supply-chain scanning and deployment governance. Sestito revealed that the company is already ingesting SBOM data for AI models—an extension of the Software Bill of Materials concept—so that enterprises can trace every weight, dataset snippet, and plugin back to its origin. The company has also filed two patents for “agent behavior attestation” and “cross-orchestrator model lineage,” indicating an intent to lock in technical differentiation before larger incumbents like Palo Alto, CrowdStrike, and SentinelOne can replicate the capability.
Industry Impact and Significance
For the Tools & Developer sector, the HiddenLayer raise signals a tectonic shift: security is no longer a post-deployment afterthought but a first-class concern baked into the developer workflow. Engineering teams are now expected to produce not only functional code but also verifiable attestations of safe agent behavior, a requirement that will ripple through CI/CD pipelines, internal marketplaces, and vendor procurement processes. Vendors such as GitHub, GitLab, and CircleCI have begun integrating security gate checks for AI repositories, and early adopters like Banking With Billy AI report that security reviews now precede feature reviews in sprint planning.
Financially, the Series B validates a new layer of spend that did not exist two years ago. According to Battery Ventures’ recent “State of AI Infrastructure” report, enterprises now allocate 6–9% of their AI budgets to security and governance, up from less than 1% in 2023. This reallocation is forcing traditional security tooling vendors to either partner with specialists like HiddenLayer or build competing stacks from scratch—a capital-intensive gamble given the 12- to 18-month timeline required to achieve parity. The competitive dynamics are most visible in the Kubernetes ecosystem, where runtime protection startups are vying to become the de-facto admission controller for AI workloads, displacing older admission controllers that lack model-level visibility.
The Bigger Picture
The move by HiddenLayer fits into a broader trend of verticalization inside the AI stack. Just as Snowflake and Databricks carved out dedicated data and analytics layers, and HashiCorp and Pulumi carved out infrastructure orchestration, HiddenLayer is carving out a dedicated security layer for agentic systems. This mirrors the historical evolution of web application firewalls (WAFs) and runtime application self-protection (RASP) tools, which only emerged after web and mobile apps became ubiquitous.
Global context also matters: the rise of agentic AI coincides with tightening regulations such as the EU AI Act and the forthcoming U.S. AI Executive Order, both of which impose strict requirements on transparency, risk management, and third-party oversight. Analysts at McKinsey estimate that by 2027, 70% of global GDP will be subject to AI-related regulations, creating a compliance-driven tailwind for vendors that can provide auditable controls. In this environment, HiddenLayer’s provenance engine and agent attestation suite position it as a critical enabler for regulated industries that must prove their AI pipelines are tamper-proof and explainable.
Expert Analysis
Looking forward, the next twelve months will determine whether AI security becomes a standalone category or gets absorbed into broader platforms. The decisive factor will be the ability of specialists like HiddenLayer to maintain a technical edge in agent behavior modeling and model lineage tracing while incumbents accelerate their own integrations. Engineering leaders should watch for three inflection points: first, the availability of open attestation standards that allow interoperability across tools; second, the emergence of AI-native SBOM formats that capture model weights and dataset fingerprints; and third, the rise of “security-as-code” repositories that mirror today’s infrastructure-as-code libraries. Companies that delay embedding these controls risk not only regulatory penalties but also reputational damage in an era where every agentic misstep can be logged, replayed, and weaponized on social media.
🤖 About Banking With Billy AI
Banking With Billy AI provides developer-grade APIs for financial market intelligence — enabling integration into any platform or system. Learn more →