BUYER'S GUIDE | AI RUNTIME SECURITY
Buyer's Guide13 min read

AI Guardrail Vendors After the Acquisition Wave: What Happens to Lakera (Check Point), Prompt Security (SentinelOne), Aim Security (Cato), and CalypsoAI (F5)

$300M
estimated price reported for Check Point's acquisition of Lakera; Check Point has not published an official deal value
$250M
disclosed value of SentinelOne's acquisition of Prompt Security, combining roughly $133.6 million cash, 1.55 million Class A shares, and assumed options
$180M
disclosed price F5 paid for CalypsoAI, with a final closing cash payment of $145.2 million
4
independent AI guardrail and runtime-security vendors acquired by larger platform companies within roughly six weeks in August and September 2025

SponsoredHorizon3.ai

Proactive Security for the AI Era

NodeZero continuously and autonomously pentests infrastructure, identity, cloud, and now web applications, chaining weaknesses across every domain the way real attackers do. Every finding ships with replayable proof showing exploitable business impact, not theoretical risk.

See NodeZero WebApp in action

Between August and September 2025, four of the more visible independent vendors building AI guardrails, meaning runtime protection against prompt injection, jailbreaks, and data leakage, plus pre-deployment red teaming, were each acquired by a much larger security or networking company. Check Point acquired Lakera. SentinelOne acquired Prompt Security. Cato Networks acquired Aim Security, its first acquisition ever. F5 acquired CalypsoAI. All four deals were announced or closed within roughly six weeks of each other, which is a fast enough clip that it reads less like four unrelated corporate decisions and more like a single market signal: platform vendors decided that AI runtime security needed to be bought rather than built, and needed to be bought now.

For a security buyer who was mid-evaluation on any of these four products, or who deployed one of them and is now watching it get absorbed into someone else's roadmap, the practical question changed overnight. It is no longer "which standalone AI guardrail vendor is best," a question our AI red teaming tools comparison of HiddenLayer, Lakera, and Prisma AIRS and our runtime prompt injection firewall comparison of Lakera, WitnessAI, Pillar, and Noma both addressed while Lakera was still an independent company. The question now is whether each acquired product is still a sound choice as a feature inside its new parent platform, and whether committing to that platform for its AI guardrail capability is worth the rest of what comes bundled with it. This guide works through what actually changed for each of the four, what the acquirers have and have not said publicly about roadmap and pricing, and how to evaluate what remains of the independent AI guardrail market.

At a glance

Lakera → Check PointPrompt Security → SentinelOneAim Security → Cato NetworksCalypsoAI → F5
Acquirer platformCheck Point InfinitySentinelOne Singularity PlatformCato SASE Cloud PlatformF5 Application Delivery and Security Platform (ADSP)
Deal announced / closedReported 2025; expected close Q4 2025 (exact date not published by Check Point)Announced Aug 5, 2025; closed Sept 5, 2025Announced early Sept 2025 (Cato's first acquisition)Announced Aug 2025; closed Sept 26, 2025
Disclosed deal valueNot officially disclosed; reported at approximately $300MApproximately $250M (cash, stock, and assumed options per SEC filing)Not disclosed$180M ($145.2M final cash payment)
Core standalone product before acquisitionRuntime protection for agentic AI apps plus continuous automated red teaming (Gandalf)GenAI/agentic AI visibility, data-leakage and prompt-injection enforcementSecuring employee use of public AI apps, protecting internal AI systems, AI dev-lifecycle securityAgentic red-teaming at scale plus runtime guardrails against prompt injection and jailbreaks
Stated integration timelineIntegration into Infinity underway; no fully published dateIntegrated into Singularity Platform following Sept 2025 closeFull SASE Cloud availability stated for early 2026, with a migration path for existing Aim customersRebranded as F5 AI Guardrails and F5 AI Red Team following Sept 2025 close
Standalone product still purchasableNot as an independent SKUNot as an independent SKUNot as an independent SKU; existing customers migrating to Cato SASENot as an independent SKU
Published pricingNot publishedNot publishedNot publishedNot published

Every cell in the bottom two rows reads the same way for a reason: none of these four acquirers has published a standalone rate card or a fully dated, feature-complete integration timeline for the acquired AI guardrail capability. Treat the rest of this comparison as a guide to what to ask your account team, not a substitute for asking it.

What each product actually did before the acquisition

Lakera built an AI-native security platform aimed specifically at agentic AI applications, combining real-time runtime protection against prompt injection and unsafe agent behavior with continuous automated red teaming. Lakera's Gandalf red-teaming game, which crowdsourced adversarial prompt attempts against its own models, was one of the more widely known pieces of public AI security research to come out of a commercial vendor. Check Point's stated rationale was combining Lakera's runtime protection with its own Infinity architecture to secure what it calls the full lifecycle of AI: models, agents, and data.

Prompt Security focused on generative and agentic AI security for the enterprise: real-time visibility into which AI tools employees and systems were actually accessing, what data was being shared with them, and automated enforcement to stop prompt injection and data leakage before it left the organization. SentinelOne's stated goal is extending its existing Singularity Platform, built around AI-native threat detection for endpoints and cloud workloads, to cover this same generative and agentic AI surface.

Aim Security, founded in 2022 and backed by YL Ventures and Canaan Partners, addressed three related but distinct problems: securing employee use of public AI applications (the shadow-AI problem), protecting AI systems an organization builds and runs itself, and managing security across the AI development lifecycle rather than only at runtime. Cato's stated rationale was extending its SASE platform, which already sits inline on enterprise network traffic, to cover AI-specific risk using that same vantage point.

CalypsoAI, founded in 2018 with offices in Ireland and New York and backed by Paladin Capital Group, Lockheed Martin Ventures, and Hakluyt Capital, built two connected capabilities: agentic red-teaming at scale, meaning automated adversarial testing against models, applications, and agents before deployment, and runtime guardrails that detect prompt injection and jailbreak attempts in production, an approach CalypsoAI described as creating an "inference perimeter" around a deployed model. F5's stated goal is folding both pieces into its existing Application Delivery and Security Platform, the same platform that already handles application and API traffic for many of F5's large enterprise customers.

Free daily briefing

Briefings like this, every morning before 9am.

Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.

Deployment: what each acquirer says is actually shipping

Of the four, Cato Networks has been the most specific in public statements about timing, and what it said should set expectations for the other three as well. Cato stated that Aim Security's capabilities would be offered as part of its SASE Cloud platform beginning in early 2026, and that existing Aim customers would get a migration path from the standalone product to the integrated platform capability. Read plainly, that is an admission that the standalone Aim product does not simply continue running unchanged forever: customers are being moved, on a timeline the acquirer controls, into the parent platform.

SentinelOne closed its Prompt Security acquisition on September 5, 2025 and has described the integration as extending the Singularity Platform's existing AI-native architecture to cover generative and agentic AI use. Check Point has described integrating Lakera's runtime protection into its Infinity architecture, and reporting from industry roundups (not Check Point's own press materials) describes Lakera's product and its Gandalf red-teaming community being folded into offerings branded Check Point AI Red Teaming and AI Agent Security. F5 completed its CalypsoAI acquisition on September 26, 2025 and introduced two explicitly branded products, F5 AI Guardrails and F5 AI Red Team, folding CalypsoAI's runtime detection and red-teaming capability into F5's Application Delivery and Security Platform.

What none of the four acquirers has published is a fully dated, line-item feature parity list comparing the standalone product as it existed before the acquisition to what actually ships inside the parent platform today. For a buyer evaluating any of these right now, the deployment question is less "how do I install this" and more "exactly which of the standalone product's features are live inside the parent platform as of today, versus still on a roadmap." Get that answer in writing, with dates, rather than accepting a general statement that integration is "underway."

Integrations and operational effort: buying the platform, not just the guardrail

The most significant operational change across all four deals is that the AI guardrail capability is no longer something you can adopt in isolation. Adopting Check Point's AI security capability now means being a Check Point Infinity customer, or becoming one. Adopting Prompt Security's capability means being on SentinelOne's Singularity Platform. Adopting Aim Security's capability means being on Cato's SASE Cloud. Adopting CalypsoAI's capability means being an F5 Application Delivery and Security Platform customer. For a security team already standardized on one of these four vendors for endpoint detection, SASE, or application delivery, this is a genuine operational win: one console, one contract, one vendor relationship covering both the existing platform and the AI guardrail layer, instead of a fifth or sixth standalone security tool to integrate and staff for.

For a team that is not already a customer of the relevant acquirer, the calculation is very different. Buying CalypsoAI's former capability today effectively means evaluating and buying into F5's ADSP, not just an AI guardrail. Buying Aim Security's former capability means evaluating and adopting Cato's SASE architecture. That is a materially bigger and more expensive decision than the one a buyer was making when Lakera, Prompt Security, Aim Security, and CalypsoAI were pitched as narrowly scoped, fast-to-deploy point products, which was a meaningful part of their original appeal to security teams trying to get ahead of AI risk without a platform migration project attached. Operationally, budget more evaluation time for the parent platform itself, not just a demo of the AI-specific feature, since that platform is now a mandatory part of the purchase.

Pricing and availability: what is public, and what plainly is not

None of the four acquisitions comes with published, comparable pricing, and that was already true of the standalone products before the acquisitions. SentinelOne's own disclosure gives the clearest number of the group: the Prompt Security deal was valued at roughly $250 million, made up of approximately $133.6 million in cash, 1,555,099 shares of Class A common stock, and 415,109 assumed options, as reported in SentinelOne's SEC filings. F5 has disclosed a $180 million price for CalypsoAI, with a final closing cash payment of $145.2 million. Check Point has not published an official deal value for Lakera; press estimates put the figure at roughly $300 million, and that number should be treated as a reported estimate, not a confirmed figure from Check Point itself. Cato Networks has not disclosed financial terms for the Aim Security acquisition at all.

Those are the acquisition prices, not what a customer pays for the resulting product, and none of the four companies has published customer-facing pricing for the integrated AI guardrail capability either. All four now sit inside a broader platform's enterprise sales motion: Check Point Infinity, SentinelOne Singularity, Cato SASE Cloud, and F5's Application Delivery and Security Platform. Expect a custom quote scoped to your existing or prospective contract with that vendor, and expect the AI guardrail capability to be positioned as an add-on module, a bundled feature at a higher license tier, or a distinct SKU, depending on the vendor and your negotiating leverage. Ask directly which of those three it is before assuming a number.

Strengths, limits, and when to choose neither

Each of the four acquisitions has a plausible strength case and an equally real limit, and the honest answer for all four is that it is too early to fully validate either from the outside.

Check Point's strength case is combining Lakera's runtime protection and red-teaming pedigree, including a team with backgrounds at Google and Meta, with an established enterprise security distribution channel and Check Point's existing Infinity architecture. The limit is that Check Point has not published a specific, dated feature-parity commitment, and the reported $300 million price tag is unconfirmed by Check Point itself.

SentinelOne's strength case is folding Prompt Security's real-time AI-tool visibility and enforcement into an already AI-native detection platform with a large existing endpoint and cloud customer base, giving the combined product a single-pane-of-glass advantage for existing SentinelOne shops. The limit is the same as the others: no published, itemized list of what shipped immediately at close versus what is still being engineered in.

Cato's strength case is the most concretely dated of the four: Aim Security's three-pronged coverage (public AI app use, internal AI systems, AI dev lifecycle) folded into a SASE platform that already inspects enterprise network traffic inline, with a stated early-2026 general availability date. The limit is that same date; a buyer evaluating this today, in September 2026, needs to confirm the integration actually reached that milestone and is generally available now, not still rolling out.

F5's strength case is pairing CalypsoAI's agentic red-teaming and inference-perimeter runtime detection with a platform that already handles application and API delivery for many large enterprises, under clearly branded new products (F5 AI Guardrails, F5 AI Red Team) rather than a vague integration promise. The limit is that CalypsoAI was a comparatively young, VC-backed company (founded 2018, having raised roughly $23 million as of 2023) being absorbed into a much larger public company's roadmap, and prioritization decisions inside F5's broader product portfolio are now out of the acquired team's direct control.

None of these four is the right choice for a team that specifically wants a narrowly scoped, fast-deploying, single-purpose AI guardrail product with no dependency on a much larger platform contract, because that product category, as these four vendors originally defined it, effectively no longer exists among these particular names. A team in that position should look at whichever independent AI guardrail vendors have not been acquired as of this writing (HiddenLayer, WitnessAI, Pillar, and Noma among the names we have covered in prior comparisons) rather than assume one of these four will still behave like a standalone point product a year from now.

Best fit by existing platform and team situation

The right way to evaluate these four today is almost entirely a function of what platform you are already committed to, or willing to commit to, rather than a feature-by-feature comparison of the original standalone products.

A team already running Check Point Infinity

Evaluating the integrated Lakera capability inside your existing Check Point relationship is the lowest-friction path; push your account team for a specific, dated feature list showing what has shipped from Lakera's original product versus what remains on a roadmap.

A team already running SentinelOne Singularity for endpoint or cloud detection

The Prompt Security integration extends a platform you already operate, which is a genuine consolidation win if the AI-specific enforcement (prompt injection, data leakage) meets your requirements; validate it against your own AI usage patterns rather than the original Prompt Security marketing.

A team already on Cato's SASE Cloud, or evaluating a SASE migration for other reasons

Aim Security's three-pronged coverage folded into SASE Cloud is the most concretely dated of the four integrations (early 2026 general availability); confirm that date has actually been met before treating it as a current capability, and ask what the migration path looked like for existing standalone Aim customers.

A team already standardized on F5's Application Delivery and Security Platform

F5 AI Guardrails and F5 AI Red Team are the most clearly branded of the four post-acquisition products, which makes it easier to ask F5 directly for a feature-parity comparison against CalypsoAI's original standalone offering.

A team with no existing relationship to any of the four acquirers

Adopting any of these four AI guardrail capabilities now means adopting the entire parent platform (Check Point Infinity, SentinelOne Singularity, Cato SASE Cloud, or F5's ADSP), which is a materially larger and more expensive decision than evaluating a standalone point product; weigh that full platform cost against your actual AI risk exposure before starting the evaluation.

A team that specifically wants a narrow, standalone AI guardrail with no platform lock-in

None of these four fits that requirement anymore; look instead at independent AI guardrail and prompt-injection firewall vendors that have not been acquired as of this writing, understanding that this list can and likely will keep shrinking as the consolidation trend continues.

Proof-of-concept checklist before evaluating any of the four

Because the acquisition changes what you are actually buying, the standard AI guardrail proof-of-concept checklist needs three additional items specific to a post-acquisition product.

Get a dated, itemized feature-parity list, not a general integration statement

Ask the acquirer's sales team to name specifically which capabilities from the original standalone product (Lakera, Prompt Security, Aim Security, or CalypsoAI) are live in the parent platform today, with a date, versus which remain on a roadmap.

Confirm the licensing structure before assuming inclusion

Determine whether the AI guardrail capability ships at your current or intended license tier of the parent platform, requires a separate add-on SKU, or is not yet generally available to your account type at all.

Ask what happened to existing standalone customers during migration

Cato has publicly described a migration path for existing Aim Security customers moving to SASE Cloud; ask each of the four acquirers for the same detail, including what functionality, if any, was temporarily degraded or unavailable during the transition.

Test detection quality against your own prompts and agent workflows

Run the integrated product against your actual prompt-injection and jailbreak test cases rather than relying on the original standalone vendor's published detection claims, which may no longer describe the current, integrated version of the product.

Price the full platform, not just the AI guardrail module

Since none of the four is purchasable independently, get a total cost figure for the parent platform contract (Check Point Infinity, SentinelOne Singularity, Cato SASE Cloud, or F5's ADSP) that would actually be required to access the AI guardrail capability, not an isolated quote for that feature alone.

Check for continuity of the original team and research output

Ask whether the original founding or research team (for example, the researchers behind Lakera's Gandalf red-teaming work) is still actively developing the integrated capability, since AI guardrail effectiveness depends heavily on continuous research into new attack patterns, not a one-time integration.

The bottom line

There is no universal winner among what remains of Lakera, Prompt Security, Aim Security, and CalypsoAI, and the reason is structural rather than a matter of feature quality: none of the four is purchasable as a standalone AI guardrail anymore. Each is now a feature of a much larger platform (Check Point Infinity, SentinelOne Singularity, Cato SASE Cloud, or F5's Application Delivery and Security Platform), and the buying decision for each has shifted from comparing point products to evaluating whether that entire platform, and its specific integration timeline and licensing structure for the AI-specific capability, fits your team.

A team already committed to one of these four platforms gets the most direct path forward by pushing that vendor for a dated, itemized feature-parity list and a concrete licensing answer, not a general statement that integration is underway. A team with no existing relationship to any of the four should weigh the full cost of adopting an entire new platform against the narrower alternative of an independent AI guardrail vendor that has not yet been acquired, understanding that the list of such vendors is shrinking as this consolidation trend continues. None of the reported deal values, Check Point's estimated $300 million for Lakera, SentinelOne's disclosed roughly $250 million for Prompt Security, the undisclosed terms for Aim Security, or F5's disclosed $180 million for CalypsoAI, tells you anything about how well the integrated product will actually perform inside its new home. Only a proof of concept against your own prompts, agents, and workflows does that.

Frequently asked questions

Are Lakera, Prompt Security, Aim Security, and CalypsoAI still available as standalone products?

No, not in the way they were sold before their respective acquisitions. All four have been or are being folded into their acquirer's platform: Lakera into Check Point's Infinity architecture (reportedly rebranded around Check Point AI Red Teaming and AI Agent Security), Prompt Security into SentinelOne's Singularity Platform, Aim Security into Cato's SASE Cloud Platform (with Cato stating a migration path for existing Aim customers beginning in early 2026), and CalypsoAI into F5's Application Delivery and Security Platform under the F5 AI Guardrails and F5 AI Red Team branding. A buyer evaluating any of these today is evaluating a feature of the parent platform, not an independently sold product.

When did these four acquisitions happen and are they all confirmed?

All four are confirmed, publicly announced acquisitions that closed in 2025. SentinelOne announced its deal for Prompt Security on August 5, 2025 and closed it on September 5, 2025. Cato Networks announced its acquisition of Aim Security, its first acquisition ever, in early September 2025. F5 announced its deal for CalypsoAI in August 2025 and completed the acquisition on September 26, 2025. Check Point's acquisition of Lakera was reported around the same period with an expected close in Q4 2025; Check Point has not published an exact closing date or an official deal value, so treat the $300 million figure as a press estimate rather than a confirmed number.

Does buying the parent platform (Check Point, SentinelOne, Cato, or F5) automatically get you the acquired AI guardrail capability?

Not necessarily, and none of the four companies has published a clear, standardized answer to this for every tier of their platform. Each acquirer has stated the acquired technology is being integrated into an existing platform (Check Point Infinity, SentinelOne Singularity, Cato SASE Cloud, F5's Application Delivery and Security Platform), but integration timelines differ: Cato has explicitly said full SASE Cloud availability begins in early 2026 with a migration path for existing Aim customers, implying the standalone Aim product does not simply continue unchanged in the interim. Before assuming a feature is included, ask the vendor directly whether it ships at every license tier, requires an add-on SKU, or is still being engineered into the platform.

Is there any public information about pricing for these products after the acquisitions?

No vendor in this group has published a standalone rate card, per-seat price, or usage-based pricing figure for its AI guardrail capability, either before or after the acquisition. Pricing for all four is now folded into the broader platform's enterprise sales process (Check Point Infinity, SentinelOne Singularity, Cato SASE Cloud, F5's Application Delivery and Security Platform), which typically means a custom quote scoped to your existing or prospective contract with that vendor. Any specific dollar figure you see quoted for one of these AI guardrail features outside of your own vendor conversation should be treated as unverified.

Should a security buyer avoid all four of these products now that they are part of larger platforms?

Not necessarily; being acquired does not automatically make a product worse, and in some cases a parent platform's distribution and engineering resources genuinely improve a feature over time. The practical shift is in how you should evaluate the purchase. Rather than comparing Lakera, Prompt Security, Aim Security, or CalypsoAI against each other and against independent survivors like HiddenLayer, WitnessAI, Pillar, and Noma as peer standalone products, a buyer now has to evaluate the acquired capability against the full cost, contract structure, and lock-in of adopting that acquirer's entire platform, since none of the four is purchasable on its own anymore.

What is the biggest practical risk of choosing one of these acquired products for a new deployment?

The biggest risk is committing to a platform based on marketing language about integration before the integration is actually complete and generally available. Cato has been explicit that Aim's capabilities reach general availability in its SASE Cloud Platform starting in early 2026, which means a buyer signing today needs a concrete answer on what is shipping now versus what is still on a roadmap. The same caution applies to Check Point, SentinelOne, and F5: ask for a specific, dated feature list and a demo of the integrated capability inside the actual parent platform console, not a screenshot of the standalone product as it existed before the acquisition.

Sources & references

  1. Check Point Software - Check Point Acquires Lakera to Deliver End-to-End AI Security for Enterprises
  2. CSO Online - Check Point acquires Lakera to build a unified AI security stack
  3. SentinelOne - SentinelOne to Acquire Prompt Security to Advance GenAI Security and Agent Security Strategy
  4. SentinelOne - A New Chapter for AI and Cybersecurity: SentinelOne Acquires Prompt Security
  5. Cato Networks - Cato Networks Acquires Aim Security to Extend SASE Leadership and Secure Enterprise AI Transformation
  6. Help Net Security - Cato Networks acquires Aim Security to bring AI protection into SASE Cloud
  7. F5 - F5 to acquire CalypsoAI to bring advanced AI guardrails to large enterprises
  8. F5 - F5 completes acquisition of CalypsoAI, introduces F5 AI Guardrails and F5 AI Red Team
  9. GeekWire - F5 paying $180M to acquire CalypsoAI to boost AI enterprise security offerings
  10. CyberScoop - Cato Networks acquires AI security startup Aim Security

Free resources

25
Free download

Critical CVE Reference Card 2025–2026

25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.

No spam. Unsubscribe anytime.

Free download

Ransomware Incident Response Playbook

Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.

No spam. Unsubscribe anytime.

Free newsletter

Get threat intel before your inbox does.

50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.

Unsubscribe anytime. We never sell your data.

Eric Bang
Author

Founder & Cybersecurity Evangelist, Decryption Digest

Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.

Giveaway: InfoSec World 2026 All Access Pass ($3,895 value)

Details →
Daily Briefing

Subscribe to enter the giveaway

Every subscriber is automatically entered. You also get daily threat intel every morning: zero-days, ransomware, and nation-state campaigns. Free. No spam.

Already subscribed? You're already entered.

Giveaway

Win a $3,895 InfoSec World 2026 pass.