SplxAI

Cybersecurity Acquired asset Dual-Use Technology Founded 2023

Last updated: Jul 31, 2026

SplxAI, now branded SPLX and part of Zscaler, provides an end-to-end AI security platform spanning AI asset discovery, automated red teaming, runtime threat protection, governance, and remediation for LLM applications and agentic workflows. It is best analyzed as an acquired AI-security technology asset rather than an independent strategically relevant startup.

Visit Website

Company Overview

SplxAI built a lifecycle security platform for enterprise AI systems. Its product set has expanded from Probe-style automated testing into AI asset management, automated red teaming, runtime protection, threat inspection, governance and compliance mapping, and dynamic remediation. The technical thesis is that LLM applications and agents cannot be secured only by protecting the underlying model or by applying a conventional web application firewall: organizations need to discover models, workflows, retrieval systems, tools, and MCP servers; simulate attacks against them; inspect live inputs and outputs; enforce policies; and feed findings back into prompts and deployment controls. The platform's public materials describe input and output guardrails, prompt-injection and jailbreak detection, data-leakage prevention, policy enforcement, and CI/CD integration. These are useful capabilities, but public evidence does not establish that every advertised control provides a complete security guarantee or that the company has independently validated all claimed mitigation rates.

The primary customer is an enterprise security, engineering, risk, or compliance team responsible for deploying internal copilots, customer-facing assistants, RAG applications, and autonomous or multi-agent workflows. The market problem is credible: AI systems change frequently, their behavior is probabilistic, and agent tools can create privilege-escalation, data-exfiltration, and unsafe-action paths that are difficult to test manually. SPLX's public funding announcement named KPMG, Infobip, Brand Engagement Network, and Glean as customers and reported 127% quarter-over-quarter growth after the platform launched in August 2024; those are company-reported signals rather than independently audited revenue or retention evidence. The company also announced AWS Marketplace availability, later marketplace distribution through Azure, and open-source Agentic Radar for mapping agentic workflow dependencies. These channels can reduce adoption friction, but diligence should distinguish marketplace availability and named customers from durable recurring revenue, deployment scale, and renewal performance.

Competition is fragmented across AI red teaming, AI runtime security, model security, application security, and governance. Relevant alternatives include Lakera, Protect AI, HiddenLayer, Robust Intelligence, CalypsoAI, Adversa AI, Prompt Security, and internal security engineering teams using open-source attack libraries and custom evaluations. SPLX's strongest differentiator was the attempt to join pre-deployment adversarial testing with continuous runtime controls and governance for multi-step systems. That breadth can be strategically valuable because findings from a red-team run can be translated into prompt hardening or policy changes, but it also creates a large product surface and exposes the company to competition from better-capitalized cloud, model, and security-platform vendors. Its acquisition by Zscaler materially changes the commercial thesis: Zscaler can supply enterprise distribution, data-protection context, and a broader control plane, while SPLX's independent brand, roadmap, and customer relationships may be absorbed or repositioned.

The dual-use case is substantive but should remain bounded. The same discovery, adversarial testing, runtime inspection, and policy-enforcement mechanisms can help secure government, intelligence, defense, and critical-infrastructure AI systems, including sensitive-data assistants and tool-using workflows. However, the public record reviewed here does not prove defense contracts, classified deployments, military customers, or certification for high-assurance environments. The strategic relevance therefore comes from enabling secure adoption of AI in sensitive organizations, not from demonstrated battlefield use. Zscaler's acquisition announcement specifically positions SPLX technology for enterprise AI lifecycle security and identifies AI asset discovery, automated red teaming, and governance as integration areas. The acquisition is a strong validation of strategic relevance and provides a credible route to scale, while also ending the case for treating SplxAI as an independent seed-stage strategic-screening signal.

Dual-Use Assessment

Military & Commercial Applications

SPLX's core capabilities have credible commercial and security-sector applicability: adversarial testing, runtime threat inspection, prompt and output controls, asset discovery, and governance can reduce risks in government or defense AI workflows as well as enterprise deployments. The connection is enabling infrastructure rather than a defense-specific product. Public sources reviewed confirm Zscaler's acquisition and AI-security integration plans, but do not confirm military, intelligence, classified, or government contracts; the dual-use score reflects that evidence boundary.

Strategic Fit Assessment

SplxAI was a credible seed-stage AI-security company, with a reported $7M seed round, a named customer set, product expansion, and a technically relevant lifecycle-security thesis. That historical evidence supports diligence on the technology and acquisition outcome, but Zscaler acquired SPLXAI Inc. in 2025, so the record is no longer an independent strategic-screening signal. The appropriate current question is whether Zscaler can integrate SPLX's red teaming, discovery, runtime protection, and governance into a differentiated platform, retain the technical team, and convert the product into durable enterprise expansion. Public sources do not provide enough information to assess post-acquisition revenue, standalone margins, retention, or roadmap ownership.

Strategic Value to U.S.-Israel Alliance

SPLX has strategic value as an acquired capability inside Zscaler's Zero Trust Exchange rather than as a standalone company. It adds shift-left AI asset discovery, automated red teaming, governance, threat inspection, and remediation to a security platform that already has enterprise distribution and visibility into data flows. This combination could help organizations secure AI from development through deployment and could lower barriers to adoption in regulated or security-sensitive environments. For national-security readers, the relevant value is AI assurance and control-plane capability; there is no public evidence here of accredited defense deployment, classified data handling, or government contracting.

Key Technologies

  • Automated adversarial red teaming with domain-specific attack probes
  • AI asset discovery and AI bill of materials across models, workflows, repositories, RAG systems, and MCP servers
  • Runtime input and output threat inspection for prompt injection, jailbreaks, and sensitive-data leakage
  • Policy-based guardrails and authorization controls for tool-using and multi-agent workflows
  • System-prompt hardening and dynamic remediation driven by red-team findings
  • AI governance, compliance mapping, and lifecycle risk assessment
  • Static workflow analysis through the open-source Agentic Radar tool

Use Cases & Applications

  • Continuous pre-deployment security testing of enterprise copilots and LLM applications
  • Runtime blocking of prompt injection, jailbreak attempts, unsafe outputs, and sensitive-data leakage
  • Security review of RAG pipelines, model integrations, tools, and MCP-enabled agent workflows
  • Policy enforcement and least-privilege controls for agents that can call business systems
  • AI asset inventory and risk mapping for security and compliance teams
  • Red-team evaluation and hardening of customer-facing assistants in regulated industries
  • Security assurance for government, defense, intelligence, and critical-infrastructure AI pilots, subject to required accreditation
  • Translating recurring attack findings into prompt, policy, and deployment remediation

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.

This record lists 6 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

  • splx.ai Public source used for profile verification.
  • splx.ai Public source used for profile verification.
  • splx.ai Public source used for profile verification.
  • zscaler.com Public source used for profile verification.
  • ir.zscaler.com Public source used for profile verification.
  • LinkedIn company page Public source used for profile verification.
  • Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.

Investor Lens

What this entry is

Acquired asset

Why it may matter

SplxAI may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.

How an independent investor should read this

Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.

Evidence to verify

  • Verify current status
  • Verify technical claims
  • Verify regulatory/export-control issues

Main investor questions

  • Is this entry a benchmark, buyer, ecosystem node, acquired asset, or strategic reference rather than a live startup opportunity?
  • What does this reference clarify about buyers, sector structure, public-market context, or strategic demand?
  • Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
  • What evidence would change the thesis or show that the profile is stale?

What not to infer

  • Inclusion does not imply endorsement.
  • Inclusion does not imply allocation availability or current fundraising.
  • Scores do not indicate investment suitability or expected returns.
  • Strategic importance does not automatically imply venture return potential.

Diligence questions

  • What evidence verifies SplxAI's current customer traction, deployment status, and revenue concentration?
  • Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
  • Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
  • How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
  • Is the company a live venture opportunity, a mature strategic reference, an acquired asset, or primarily a market-mapping entry?

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.

Need a diligence readout?

Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.