HiddenLayer
HiddenLayer is an Austin, Texas-based AI security company founded in March 2022 by Chris Sestito (CEO), Tanner Burns (Chief Scientist), and Jim Ballard (CIO) — former Cylance researchers who encountered a real-world attack on production ML models. HiddenLayer builds an AI Security Platform that protects machine learning and generative AI systems across their entire lifecycle, comprising four integrated modules: AI Discovery (catalogs AI assets and eliminates shadow AI), AI Supply Chain Security (Model Scanner inspects models, weights, and pickle/RDS files for malicious payloads and backdoors), AI Attack Simulation (continuous adversarial red-teaming for agentic and generative systems), and AI Runtime Security / AIDR (a real-time detection-and-response firewall using deterministic classifiers that sit outside the model inference path to detect prompt injection, jailbreaks, indirect attacks, data leakage, and malicious tool calls in agentic and MCP systems). The platform exposes native connectors for CI/CD, MLOps, SIEM/SOAR, API gateways, and major data and cloud platforms, plus guardrail integrations for OpenAI Agents, LangChain, AWS Strands, Microsoft Agent Framework, Azure APIM, and a GitHub Action for Model Scanner. HiddenLayer publishes Python, TypeScript, and Java/Kotlin SDKs and research-grade tooling such as HiddenPickle (Python pickle disassembler/patcher) and HiddenPromise (R .rdx/.rdb/.rds disassembler). The company has raised $56M total ($50M Series A in September 2023 led by M12 / Microsoft's Venture Fund and Moore Strategic Ventures, with Booz Allen Ventures, IBM Ventures, Capital One Ventures, and Ten Eleven Ventures participating) and serves Fortune 500 enterprises, financial services, and US Federal agencies. The HiddenLayer SaaS console and REST API are gated behind enterprise sales and not publicly self-serve, placing this profile in Tier-3 (enterprise-gated) coverage.
Index entry only — little beyond a description and a link, and nothing machine-readable enough for an agent to act on without a human reading the site first.
API Evangelist profiles HiddenLayer the way a machine reads it — 1 machine-readable artifact, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.
Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — HiddenLayer scores 7.9/100 (minimal), with a separate agent-readiness read of 0/100 (human only). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.
Kin Score
This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance.
How we profile HiddenLayer
Each block below is one kind of artifact we hold for HiddenLayer. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.
Security Posture 1
Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Resources
Every other property we hold for HiddenLayer — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.
Get Started 2
Portal, sign-up, and the first successful call
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Build 5
SDKs, sample code, and the tooling you integrate with
Access & Security 1
Authentication, authorization, and security posture
Learn 1
Tutorials, courses, talks, and written guidance
Operate 1
Status, limits, changes, and where to get help
Company 7
The organization behind the API
Scroll within the panel for all 7 ·
Other 16
Properties that don't map to a standard resource type
Scroll within the panel for all 16 ·
← All providers · Data indexed from github.com/api-evangelist/hidden-layer · machine-readable index on apis.io