CalypsoAI

-

CalypsoAI is an enterprise-grade AI inference security platform that provides adversarial attack defense, red team testing, data leakage prevention and compliance governance capabilities. It was acquired by F5 in September 2025 for approximately $180 million, and its core capabilities evolved into two product lines: F5 AI Guardrails and F5 AI Red Team.

CalypsoAI Product Interface

CalypsoAI

Core parameters and statistics

CalypsoAI was an independent AI inference security platform before being acquired by F5. After the acquisition, its core capabilities were integrated into F5 AI Guardrails. The following parameters reflect its key specifications as a standalone product and when integrated into the F5 platform:

Projects Public Information
Product positioning Full life cycle AI inference security platform
Core Defense Layer Inference Layer
Threat library size 10,000+ new attack patterns added every month
Deployment Models SaaS, On-premises, Private Cloud, Hybrid Cloud
Model compatibility Model-agnostic, supports public and private models
Agent support Compatible with AI Agents in OpenAI / Anthropic and similar formats
Compliance Coverage GDPR, EU AI Act, PCI, PHI
Customer cases Palantir, SGK (official public disclosure)
Acquisition price Approximately $180 million (F5, September 2025)
Home Dublin, Ireland

Post-acquisition architecture: CalypsoAI's capabilities are split into two product lines - F5 AI Guardrails (runtime security guardrails) and F5 AI Red Team (automated red team testing), which run together as the AI security module of the F5 Application Delivery and Security Platform (ADSP).

User and market recognition

CalypsoAI's market recognition is reflected in three dimensions: technical authority endorsement, core customer adoption, and industry awards:

Authority Approval:

  • RSAC 2025 Innovation Sandbox Finals: Being among the top two finalists in the world's top cybersecurity innovation competition RSAC Innovation Sandbox marks the security industry's recognition of its technical route.
  • Fast Company 2025 Most Innovative AI Company: Selected into Fast Company's annual list, reflecting the media and industry's recognition of its business value.
  • Gartner AI TRiSM Market Guide: F5 said Gartner's AI Trust, Risk and Security Management (TRiSM) market analysis is an important reference in its acquisition decisions.

Enterprise Customers: CalypsoAI’s officially disclosed customers include Palantir (big data analytics platform) and SGK (global brand services company), indicating that its products have passed a more stringent enterprise security review process.

Industry Benchmarking: Compared with similar AI security solutions, the core difference of CalypsoAI lies in the full life cycle coverage of the inference layer - from red team testing before going online to real-time interception at runtime, supporting closed management of policies. The 2025 SecureIQLab test report states that the base model’s built-in guardrails can only block about 13% of sophisticated attacks, highlighting the value of a dedicated AI security platform.

Cost advantage

  • C-side/Individual: Usually a free version is provided to experience the core functions, and high-frequency use requires a paid package subscription.
  • API/Developer: Billed by call volume, suitable for development teams that can be flexibly integrated into their own systems.
  • Enterprise/Privatized: Contact the business owner for customized quotation and deployment plan. The specific price is subject to the official real-time pricing page.

Main functions

CalypsoAI's capabilities are designed around inference layer security, covering the complete link from threat discovery, real-time defense to compliance auditing:

  • Adversarial Attack Defense: Real-time detection and interception of prompt injection (Prompt Injection), jailbreak attack (Jailbreak), data leakage and model escape. The threat library is continuously updated by the F5 Labs security research team, with 10,000+ new attack patterns added every month.
  • Automated Red Team Testing (AI Red Team): Deploy autonomous Agent clusters to simulate thousands of attack modes, automatically scan AI system vulnerabilities and generate risk scores. The attack technology library covers both common vulnerabilities and extreme exploitation scenarios, and the detection results can be directly transformed into runtime guardrail strategies.
  • Data Leakage Prevention: Detect and prevent the leakage of sensitive data (PII, PCI, PHI, etc.) at runtime, support custom sensitive categories, and ensure that model input and output do not carry illegal data.
  • Content Audit and Compliance Governance: Built-in bias/toxic/harmful content filters, supports customized policies through natural language, and quickly creates compliance guardrails by industry, region and use case. GDPR, EU AI Act, PCI and PHI compliance templates available out of the box.
  • Agent Security Governance: Audit and intercept AI Agent's tool calls and action executions to prevent privilege escalation (Privilege Escalation) and unauthorized operations (Excessive Agency), ensuring that the behavior of multi-Agent systems is controllable.
  • Audit Observability: Record the complete decision-making link of each interception or release, including Agentic Fingerprints and Outcome Analysis, providing interpretable context for compliance audits and security event traceability.

Model and version evolution

Continuous iterative updates, the latest version introduces performance optimization and new features. Historical version information can be viewed on the official release page. There is no complete public version evolution timeline yet. It is recommended to pay attention to the official announcement to understand the rhythm of feature updates.

Technical advantages

The core of CalypsoAI's technology is to embed security capabilities into the AI reasoning link rather than as a plug-in detection layer.

Inference layer native protection: Unlike traditional input/output filtering, CalypsoAI implements real-time policy execution in the inference layer. This means that every model call—whether prompting input or generating output—goes through context-aware analysis by the security engine, rather than simple keyword matching. This architecture can effectively detect semantic-based adversarial attacks while maintaining a low false positive rate.

Agentic Warfare™ Methodology: CalypsoAI's patented threat protection framework, the core idea is to use Agents to fight against Agents - deploy autonomous Agent clusters to simulate the attacker's intrusion path, extract detection rules from them and automatically deploy them to the inference layer guardrail. This approach transforms threat intelligence from "passive updating" to "active hunting."

Model-agnostic architecture: CalypsoAI’s security policy is independent of the underlying model, and the same policy can be applied to GPT, Claude, Gemini, open source models, and fine-tuned variants. This allows enterprises to maintain security consistency across mixed model architectures without being locked into a single model vendor.

Explainable Security Auditing: While traditional security interceptions can only tell "what was blocked," CalypsoAI provides complete decision context—including triggering rules, contextual analysis, risk scores, and similar historical patterns—enabling security teams to quickly locate false positives or adjust policy granularity.

How to use

CalypsoAI no longer offers a separate registration portal since its acquisition by F5, and its capabilities are delivered through the F5 AI Guardrails product line. The usage path is divided into two stages:

How to use Applicable stages Entry/method Description
F5 AI Guardrails Post-acquisition (current) Request a demo or purchase on the F5 official website Integrated into the F5 ADSP platform to unify management of application delivery and AI security
CalypsoAI independent platform Before acquisition (history) Original calypsoai.com (now jump to F5) Independent sales have been stopped, and existing customers have been migrated to the F5 platform

Typical deployment process:

  1. Access Model: Deploy F5 AI Guardrails between AI models and users/applications, supporting SaaS, on-premises deployment, private cloud and air-gapped environments.
  2. Configuration Policy: Use built-in policy templates (prompt injection defense PII protection, content moderation, etc.) or create custom guardrail rules through natural language.
  3. Red Team Test: Start the AI ​​Red Team to perform automated penetration testing on the AI ​​system to verify the effectiveness of existing protection strategies.
  4. Continuous Monitoring: Monitor interception events, performance indicators and usage trends through a unified dashboard, and export audit logs to the SIEM system.
  5. Strategy Iteration: Adjust guardrail strategies based on red team test results and runtime data to achieve continuous evolution of security capabilities.

Product Pricing

The pricing model is subject to the official real-time page. Usually a freemium or subscription system is used, and basic functions can be used for free. Advanced functions or high-frequency use require paid subscriptions, and users are advised to evaluate the optimal solution based on actual usage.

Application scenarios

Typical deployment scenarios of CalypsoAI / F5 AI Guardrails cover the following four categories:

  • AI Compliance Security for Financial Services: When banks and insurance companies use large models to process customer inquiries and credit assessments, they need to ensure that the output does not contain unauthorized PII, is GDPR and PCI compliant, and cannot be manipulated by malicious prompts to lead to inappropriate decisions. Key points of verification: coverage and false positive rate of the compliance template.
  • PHI data protection in the medical industry: Medical AI applications involve the transmission of protected health information (PHI), and the inference layer guardrails need to detect and intercept PHI leaks in input and output in real time while ensuring low latency. Verification focus: recognition accuracy of medical terminology and impact on diagnostic accuracy.
  • AI Agent Permission Management: In a multi-Agent system, a single Agent may obtain tool calling permissions beyond its scope of responsibility. CalypsoAI's Agent security capabilities audit and limit the operational boundaries of each Agent to prevent abuse of cascading permissions. Verification focus: The integrity of the Agent behavior audit log.
  • Large model red team testing and pre-launch assessment: Before putting the model into production, enterprises use AI Red Team to perform automated security assessments, covering risk dimensions such as prompt injection, jailbreaking, and harmful content generation, and output risk scores and repair suggestions. Verification focus: The coverage of the attack pattern library and the controllability of false positives.

Applicable people

  • Enterprise Security Team (SOC/CISO): A production-level solution is needed to manage the security risks of AI models. The full life cycle protection provided by CalypsoAI covers pre-launch testing, runtime defense and post-event auditing. Prerequisites: The security team needs to have a basic understanding of AI inference architecture, otherwise it is recommended to complete a proof of concept first.
  • AI/ML Platform Team: The engineering team responsible for the internal AI infrastructure of the enterprise needs a unified model-agnostic security layer to prevent the management burden of fragmented security tools. Unsuitable scenario: If an enterprise only has a single model supplier and its own guardrails already meet compliance requirements, the marginal benefits of introducing an independent security platform are limited.
  • Compliance and Risk Management Team: Industries facing regulatory pressures such as the EU AI Act, HIPAA, PCI, and more can leverage built-in compliance templates to simplify audit preparation. Not suitable for use cases: Non-regulated industries or small teams that only use closed testing environments may not need enterprise-level compliance capabilities.
  • AI Agent Development Team: A development team that builds a multi-Agent system and needs to monitor and limit the tool calling behavior of Agents to prevent privilege escalation. Prerequisite: The Agent framework output format must be compatible with OpenAI/Anthropic, otherwise additional adaptation development is required.

Summary and Outlook

CalypsoAI’s independent development trajectory came to an end in September 2025, but its technical value has gained greater ground through F5’s platform. The core insight is that the security of the AI ​​inference layer cannot rely on the basic protection provided by the model, but requires an independent, dedicated, and continuously updated security engine to deal with rapidly evolving attack technologies. CalypsoAI’s Agentic Warfare™ methodology—Agent against Agent—is the first in the industry to transform red team testing from manual penetration into an automated, quantifiable, continuous process.

The split of the product line after the acquisition (AI Guardrails for runtime defense and AI Red Team for proactive detection) is in line with the security industry's best practice of "separation of detection and response." F5 integrates a series of AI security assets such as CalypsoAI, LeakSignal, and Fletch on the ADSP platform, and is building a complete AI security stack covering data, model agents, and APIs.

Current Limitations and Uncertainties:

  • CalypsoAI no longer exists as a standalone product, and historical version information is limited to enable independent assessment of the actual performance metrics of its pre-acquisition product.
  • The pricing of F5 AI Guardrails has not been disclosed. Enterprises need to obtain a formal quotation through F5 Sales before purchasing. It is recommended to evaluate the actual effect with a proof-of-concept (POC) before making a budget.
  • There are many competing products on the market (such as Guardrails AI, Rebuff, Lakera Guard, etc.). Customers migrating to the F5 platform need to evaluate the lock-in cost and migration price.
  • For non-F5 existing customers, introducing AI Guardrails may require additional procurement of F5 ADSP or related components. It is recommended to comprehensively evaluate infrastructure dependence and total cost of ownership.

Related tools: originality-ai, gptzero

CalypsoAI version and evolution history

CalypsoAI's version history has gone through three key stages: "independent product → acquisition by F5 → product line split":

Independent product stage (2018-September 2025)

CalypsoAI was founded in 2018. After 7 years of R&D accumulation, it has built a complete AI inference security platform. A total of $40M+ has been raised by 2025, with investors including Paladin Capital Group, Lockheed Martin Ventures and Hakluyt Capital. The product form at this stage is an independent SaaS/local deployment platform, which already has core adversarial attack defense, red team testing, data leakage prevention and policy management capabilities.

Acquisition integration phase (September 2025)

  • 2025-09-11: F5 announced the acquisition of CalypsoAI for approximately $180 million. The transaction is mainly cash and is expected to be completed in the fourth quarter of F5's fiscal year 2025 (as of 2025-09-30).
  • 2025-09-29: F5 announced the completion of the acquisition and officially released two product lines: F5 AI Guardrails (runtime AI safety guardrail) and F5 AI Red Team (automated red team testing).

F5 platform stage (September 2025 to present)

Following the acquisition, CalypsoAI no longer exists as a standalone product and its capabilities continue to evolve as the AI security module of F5 ADSP. F5 also acquired LeakSignal (AI data protection), Fletch (Agentic AI threat detection) and MantisNet (cloud native observability) in 2025, forming an AI security capability matrix with CalypsoAI.

Version Info

  • F5 AI Guardrails (formerly CalypsoAI platform) :After completing the acquisition of CalypsoAI, F5 officially released F5 AI Guardrails and F5 AI Red Team, integrating CalypsoAI's reasoning layer security, red team testing, policy execution and compliance governance capabilities.
  • CalypsoAI independent platform :The independent product version of CalypsoAI before F5 announced the acquisition already had core capabilities such as inference layer protection, red team testing, data leakage prevention and policy management. There is no official precise date yet.

User Reviews

  • Loading reviews...