Discover why Axari chose HiddenLayer's AI Security Platform to protect its own AI workforce platform.
September 16, 2026

Company Overview
Founded in 2025 and headquartered in San Jose, California, Axari builds Twin, an AI workforce for security teams. Twin tracks commitments, prepares executive briefs, triages alerts, and follows up on findings, the recurring work that otherwise falls to a person to chase down by hand. As of August 2026, Axari counted more than 60 organizations running on the platform.
Twin’s agents run on large language models and connect to the systems customers authorize them to use. As an agent proves itself over time, the scope of that access may expand. A weakness in the underlying agent could therefore extend beyond a single deployment, creating a shared product-level risk across customer environments.
Axari decided to address that risk early. Rather than waiting for an agent to act on an external instruction, the company began adding safeguards while its deployment footprint was still relatively small.
The Challenge
Identifying Risk at a Technical Level
Twin's agents ingest untrusted text all day: alert bodies, ticket comments, policy documents, pen test findings. Any of it can carry an instruction that never came from Axari's own team. The company understood the risk conceptually. What it lacked was a repeatable way to test how Twin would respond to a real attempt at manipulation.
Visibility was the first gap. Axari could see what an agent did but had no way to trace whether the instruction behind that action came from its own team or from a string sitting in a customer's ticket queue.
Testing presented a second gap. A researcher could examine one version of Twin at a point in time, but Axari had no regression coverage to confirm that later model or prompt changes had not reintroduced a previously resolved weakness.
A third gap sat underneath both: no systematic way to inventory or scan the third-party model artifacts and dependencies in Axari's own supply chain, including the hosted models it lists as sub-processors to its customers.
Protecting the Integrity of Security Decisions
For Axari, this problem carries a higher consequence because of who Twin is built for. CISOs and information security teams use Twin to understand risk, prepare for executive conversations, investigate issues, and decide what needs attention. The information behind those decisions has to be right.
That means preventing hallucinations is only part of the problem. Twin also needs to preserve the integrity of the information it uses: where a fact came from, whether the source can be trusted, and whether the information has been altered or manipulated somewhere along the way. A security leader should be able to trace an important statement back to the underlying alert, ticket, finding, policy, or other authoritative source—not simply trust that the AI produced a plausible answer.
For Axari, protecting AI therefore means protecting the integrity and provenance of the information Twin uses to do its job. Security teams need answers they can verify, sources they can trace, and clear attribution for the conclusions Twin puts in front of them.
The Solution
Axari addressed its most immediate visibility needs first, putting one HiddenLayer module into production: AI Runtime Security, which monitors model interactions in live agent flows as they occur. Three of its capabilities line up with how Twin actually operates.
- Knowledge Base Protection detects prompt injection in the content Twin's agents ingest. For Axari, the greatest concern was never a direct user prompt. It was an instruction hidden inside an alert, a ticket comment, or a policy document, the material an agent reads as a normal part of its job.
- Agent Acitivity Monitoring watches behavior during execution itself, catching the failure mode that worries Axari most: an agent reaching for a tool it has no business touching while doing something that looks routine on the surface.
- Sensitive Data Protection extends that coverage to what Twin's agents produce, not just what they consume. After reading from a customer's environment, an agent writes summaries and updates into Slack and ticketing systems, and those messages can carry sensitive data out as easily as an alert can carry a bad instruction in. HiddenLayer inspects that outgoing content before it posts, the same way it inspects what the agent reads.
Axari evaluated several approaches before choosing HiddenLayer. Most competing tools stop at inspecting model inputs and outputs. That coverage was necessary, but insufficient. Axari needed to be able to evaluate the tool calls an agent actually makes during execution, which is where its real exposure lives. That combination narrowed the list of vendors considerably. HiddenLayer also maps its detections to MITRE ATLAS, a catalog of known attack techniques against AI systems, and the OWASP LLM Top 10, giving Axari named standards to point to the next time a customer's security team asks what its controls answer to.
Axari prioritized runtime coverage first because live customer data was already moving through Twin's production workflows. The next phase extends coverage earlier in the lifecycle, through supply chain scanning and automated attack simulation.
AI Supply Chain Security will scan model artifacts and dependencies before they enter Axari's build and continue scanning afterward. AI Attack Simulation will run automated adversarial testing against Twin's agent flows, including prompt injection via ingested customer data, jailbreak attempts, tool-call misuse, and attempts to push an agent beyond its scoped permissions. Both arrive after the current release.
Results
Axari now has production visibility into potential prompt-injection attempts originating from customer-provided content. The team can distinguish suspicious instructions embedded in external data from the system instructions Axari intentionally provides to Twin.
That visibility also gives Axari concrete evidence to share during enterprise security reviews. Instead of relying solely on architecture diagrams and descriptions of intended controls, the team can point to an active runtime security deployment and its findings.
Key Takeaways
- AI vendors enabling agents with credentials to access systems autonomously must recognize how doing so expands the attack surface and secure their systems accordingly.
- Axari's real injection exposure was not the user prompt. It was the alert body, the ticket comment, and the policy document an agent reads as a normal part of its job.
- Securing Twin required visibility into its tool calls in execution, not just its outputs, since the failure mode Axari worried about most was an agent reaching for a tool it shouldn't touch while looking legitimate on the surface.
- A single test of Twin told Axari whether it was safe that day, not whether it stayed safe after the next model or prompt change, which is why turning red-team findings into a continuous evaluation suite matters more than any one finding on its own.
- Once AI Runtime Security was in production, Axari could answer security reviews with a deployed control and its detection output instead of an architecture diagram, which eased the slowest part of its sales cycle.
Looking Ahead
Axari will move on two fronts next. First, it will merge HiddenLayer's AI Supply Chain Security into its own build pipeline, scanning model artifacts and dependencies before they enter a build and continuously thereafter. Second, it will wire AI Attack Simulation into continuous integration, so every model or prompt change is automatically red-teamed for prompt injection, jailbreak attempts, tool-call misuse, and attempts to push an agent past its scoped permissions, before that change ever reaches production.
Each attack simulation finding will become a named test case, and those cases will accumulate into a standing suite that reruns on every future model or prompt change. Twin adds new workflows, tool permissions, and prompts constantly, and that suite is how Axari finds out whether last month's fix still holds, instead of waiting to find out the hard way.
Axari's own pilot program is also expanding the number of agent workflows running in live customer environments this quarter, and the company is extending security coverage as that footprint grows rather than waiting until afterward. Longer term, Axari and HiddenLayer plan continued joint research into identity and permission boundaries for non-human actors.
Experience the HiddenLayer AI Security Platform in Action
Whether you’re securing agentic, generative, or predictive AI applications, see how HiddenLayer protects your AI applications, models, and workflows in real time. Our demos are tailored to your environment.
