DeepKeep

Filing note. DeepKeep is a five-module suite, not a single product, so no one category holds it cleanly. It is filed primary in ai-runtime-security because the AI Firewall is the lead SKU and the thing a buyer would actually swap in, with cross-listings in ai-red-teaming, ai-spm and agent-runtime-security. Its Model Scanning module does MLBOM and CVE detection on model artifacts, which is ML supply chain — but not software-supply-chain as this wiki defines it (SAST/SCA/pipeline security for code you ship). DeepKeep does no code scanning, so it is deliberately not cross-listed there. Same shape as hiddenlayer, which is filed the same way.

One-liner — An Israeli AI-security suite that puts runtime guardrails, red teaming, AI discovery, agent attack-surface mapping and model scanning behind one console — and is the rare vendor here that covers computer vision as well as LLMs.

What it does — Five modules, sold as a lifecycle platform:

  • AI Firewall — real-time detection and guardrails; the site claims 60+ runtime guardrails for apps and agents. The inline enforcement point.
  • AI Red Teaming — automated adversarial evaluation and robustness tests, plus Vibe AI Red Teaming (launched 2026-04-20), a human-steered mode where an agent runs the campaign but staff intervene at decision points, adapt the plan on intermediate findings, and inject scenarios mid-run.
  • AI Lens — discovery, visibility and access control over who is using what AI across teams; the shadow-AI / usage-control angle.
  • AI Agent Scanner — launched 2026-03-03. Maps an agent’s connected tools, data sources and reachable actions into a visual attack-surface graph, scores it against the OWASP Top 10 for Agentic Applications, and — for select frameworks only — places firewalls and guardrails based on observed behaviour.
  • Model Scanning — static and dynamic checks on model artifacts, producing an MLBOM and CVE detection.

The suite is sold in two lines, DeepKeep for LLM and DeepKeep for Vision. The vision half is genuinely differentiating: nearly every peer in ai-runtime-security is a text/prompt inspector only.

Naming / provenance — Founded 2021 by Rony Ohayon (CEO); CTO is Yossi Altevet. Tel Aviv. Launched publicly with the seed round in May 2024, pitched as an “AI-native TRiSM” platform (Gartner’s Trust, Risk and Security Management framing). No renames or spinouts found. Do not confuse with “Deepkeep Systems” as it appears in some funding aggregators — same company, aggregator naming.

Ownership & viability — Independent and VC-backed. The only round with a primary source is the $10M seed announced 2024-05-01, led by Awz Ventures. Funding aggregators claim ~$19M total across four rounds including a January 2026 round involving OurCrowd, but DeepKeep has published nothing about it and no primary source corroborates it, so this page does not assert it. At a confirmed $10M seed and no confirmed Series A more than two years later, this is a small vendor in a consolidating categoryprompt-security, aim-security, robust-intelligence and Protect AI have all been absorbed by platform vendors. Acquisition or stall are both live outcomes; underwrite accordingly.

Positioning & differentiators

  • Multimodal, not just text. DeepKeep for Vision covers computer-vision pipelines. If you have vision models — document/ID processing, surveillance, industrial inspection — almost nobody else on the ai-runtime-security shortlist will cover them. For a hedge fund running text and tabular models only, this differentiator is worth nothing.
  • Breadth from one console. Firewall + red team + discovery + agent mapping + model scanning in one contract is a real convenience versus assembling lakera + splxai + a posture tool. The tradeoff is the usual one: none of the five modules is the category’s best.
  • Free agent scanner as the funnel. The AI Agent Scanner is offered free at agentscanner.deepkeep.ai. That makes it cheap to trial and a genuinely useful way to see your agent attack surface before committing to anything.
  • Agent-framework coverage is broad and includes the low-code tier — Agentforce, OpenAI Agents, CrewAI, Amazon Bedrock AgentCore, n8n and Make. Covering n8n and Make matters: that is where ungoverned business-built agents actually live, and it is the same ground zenity works.

Who should choose them / anti-fit — Best fit: an enterprise with a mixed LLM-and-vision AI estate that wants one vendor and one console across the lifecycle, and is comfortable buying from a small Israeli startup. Anti-fit: a firm that already owns a platform with an AI-security module (prisma-airs, cisco-ai-defense, wiz) — DeepKeep has to beat something you already pay for. Also an anti-fit if you need best-of-breed depth in exactly one slot: buy lakera for prompt-injection detection or a red-teaming specialist for red teaming. And an anti-fit for procurement teams that need a SOC 2 report in hand before signing, since DeepKeep publishes badges but no retrievable report — you will be waiting on the vendor to produce one (see below).

Known weaknesses / gotchas

  • Certifications are claimed on the website, not evidenced. The footer carries four badge images — ISO 27001, ISO 9001, SOC 2 and GDPR — and nothing sits behind them: none of the badges is a hyperlink, there is no trust centre, compliance page or downloadable report, and no certificate number, auditor, audit period or scope statement appears anywhere. The SOC 2 badge carries no Type marking, which is the detail that matters — Type I is a point-in-time opinion on control design, Type II tests operating effectiveness over a period, and only the latter is worth much to a regulated buyer. For a product that sits inline on prompts and responses, ask for the report, the audit period, the auditor and the SOC 2 Type before treating any of these badges as evidence.
  • No public pricing at all, and no published tier structure. Full sales cycle.
  • “For select frameworks” is doing work. The Agent Scanner discovers and maps across the listed frameworks, but runtime enforcement on agents is limited to a subset the release does not name. Get the enumerated list in writing before assuming agent coverage.
  • Marketing claims outrun independent evidence. “First-of-its-kind” Vibe red teaming has no third-party validation; the trade coverage restates the press release verbatim. The “60+ guardrails” count is a vendor number with no public benchmark behind it. Treat detection efficacy as untested until you test it.
  • Gartner mention is an inclusion, not a ranking. DeepKeep is a Representative Provider in the 2026 Gartner Competitive Landscape: AI Operations Management (report May 2026, announced 2026-06-04). That is a listing, not a Magic Quadrant position, and it is in an AI operations landscape rather than an AI-security one.
  • No MCP story found. Nothing on the site or in releases mentions Model Context Protocol, in a category where peers are racing to cover MCP tool calls.

Deployment & data handling — One SaaS console, with the platform deployable in SaaS, on-prem, your own VPC, or air-gapped. The air-gapped and in-tenant options are the reason to look at DeepKeep if prompt content cannot leave your boundary. In default SaaS mode the firewall is inline on prompts and responses, so data_leaves_tenancy: partial — inspected content transits DeepKeep unless you self-deploy. Retention, training-use and latency numbers are not published; all three are must-asks. The free hosted Agent Scanner at agentscanner.deepkeep.ai is separate from your tenancy — do not point it at production agents before you understand what it retains.

Agent-security relevance — The Agent Scanner is explicitly built for the case where an agent’s own permissions become the attack surface: it enumerates the tools and reachable actions an agent has, which is exactly the mapping you need before you can reason about whether untrusted input, sensitive data and an egress path have collapsed into a single agent context (see overview and agent-runtime-security). Mapping is the strong half; enforcement is framework-limited.

Integrations & partnerships — Agent frameworks: Microsoft-based frameworks, Agentforce, OpenAI Agents, CrewAI, Amazon Bedrock AgentCore, n8n, Make. No published SIEM, IdP, gateway or observability integrations were found — notable for a security product that should be feeding siem-soc. No marketplace listings found. No FS channel partners found.

Compliance & FS traction — Four compliance badges (ISO 27001, ISO 9001, SOC 2, GDPR) are displayed in the site footer as static images with no report, trust centre or Type marking behind them; treat them as vendor-stated until you hold the documents. Logos shown on the site are NTT Data, ST Engineering and EY — systems integrators and a Big Four firm, i.e. a partner/services motion, not named end-user references. No financial-services customer is named anywhere, and nothing indicates hedge-fund-scale deployment. For this wiki’s reader, DeepKeep is currently an unproven-in-FS vendor.

Commercial — No public pricing, no published packaging, no free tier for the platform (the Agent Scanner alone is free). Assume enterprise annual contract and a full sales cycle.

Open questions

  • Funding since the 2024 seed. Aggregators say ~$19M / 4 rounds and an OurCrowd round in January 2026; DeepKeep has announced nothing. Is there a Series A? Unresolved — aggregator-only, not asserted on this page.
  • What backs the four badges? ISO 27001, ISO 9001, SOC 2 and GDPR are displayed, so audits are being asserted — but no report, certificate number, auditor, audit period or scope is published, and the SOC 2 badge shows no Type. Is the SOC 2 a Type I or a Type II? What is the ISO 27001 scope and which body issued it? A targeted search on 2026-08-22 retrieved nothing; “not retrievable” is not “does not exist” — these are the questions for the first call, not a conclusion.
  • Which frameworks get runtime enforcement, as opposed to discovery/mapping only? The release says “select frameworks” without enumerating.
  • MCP support — none found, but absence of evidence only. Unverified.
  • Latency and retention for the inline AI Firewall — unpublished.
  • Headcount and FS references — unverified.
  • Is DeepKeep for Vision a real, separately-supported line or marketing packaging around the same scanners? Unverified.

Sources

History

  • [2026-08-22] Page created and researched in one pass via wiki-create + wiki-research. Category call (ai-runtime-security primary, three cross-lists, no software-supply-chain) recorded in log.md.
  • [2026-08-22] Correction. The page asserted in three places that DeepKeep publishes no certifications; certifications: [] and an open question rested on the same claim. Wrong: the site footer carries ISO 27001, ISO 9001, SOC 2 and GDPR badges. Re-fetched https://www.deepkeep.ai/about and confirmed the badges exist, none is a hyperlink, the SOC 2 badge carries no Type marking, and no trust centre or report sits behind them. Reframed from “no certification is published” to “claimed on the website, not evidenced” (the idiom already used on signoz), certifications: set with the (vendor-stated) convention used on hadrius, and the procurement advice changed to ask for the report, period, auditor and SOC 2 Type. Source cached.