SurePath AI
Denver startup that discovers shadow AI and agentic activity at the network layer; acquired by F5 in 2026 to anchor F5's new AI Security Platform.
Visit Website ↗ + Add to CompareOverview
SurePath AI builds network-based discovery for shadow AI: rather than relying on a browser extension or an endpoint agent that employees can route around, it monitors network traffic out-of-band to identify which AI tools, chat interfaces, coding assistants, and autonomous agents are actually in use across an organization, including ones IT and security never approved. The platform classifies the intent behind each interaction and traces agent tool calls and MCP server connections, giving security teams a policy-enforcement layer over AI usage that doesn’t depend on user cooperation.
Founded in Denver in 2023 by CEO Casey Bleeker, SurePath grew to roughly 19 employees and raised about $6 million in venture funding while targeting industries, financial services, healthcare, education, and professional services, where a leaked prompt or an ungoverned agent is a genuine incident, not just an IT nuisance.
In June 2026, F5 acquired SurePath AI to serve as the foundation of its new F5 AI Security Platform, giving F5 an out-of-band way to see and govern AI and agentic traffic across enterprise networks. Financial terms were not disclosed. SurePath’s technology now continues inside F5’s broader security portfolio rather than as an independent company.
Innovation Matrix Assessment
SurePath went from founding in 2023 to a strategic acquisition by a major public security vendor within three years, including keeping pace with a fast-moving target (agentic AI and MCP server traffic), a fast iteration cycle for a company this size.
An out-of-band, network-layer discovery approach avoids the deployment friction and evadability of browser-extension or endpoint-agent based AI-usage monitoring, a technically sound design choice for visibility into unsanctioned tools.
Acquisition by F5 in June 2026, to anchor F5's newly launched AI Security Platform, is a concrete, independently reported strategic validation of the company's technology and market timing.
Tracing agent tool calls and MCP server connections at the network level addresses a genuinely new blind spot, agentic AI workflows, rather than repackaging existing DLP or CASB techniques for an AI use case.
No independent, third-party test of SurePath's detection accuracy or coverage was found; available evidence is vendor and acquirer (F5) press describing the capability rather than named customer outcomes or benchmark results.
Shadow AI usage and ungoverned agentic workflows are near the top of CISO concerns in 2026, and network-layer visibility that doesn't require user opt-in directly addresses the enforcement gap most AI-governance tools have.
Why CISOs Should Care
Gives security teams visibility into which AI tools, agents, and MCP servers employees are actually using, including unsanctioned shadow AI, without requiring an endpoint agent or user cooperation.
What Makes It Different
Detects and classifies AI and agentic activity out-of-band at the network layer, rather than through browser extensions or endpoint agents that shadow AI usage can simply avoid.
The Matrix Verdict
67/100 — INCREMENTAL INNOVATOR
A young, technically differentiated shadow-AI visibility company whose approach was validated by a strategic acquisition within three years of founding; real disruption potential, now continuing inside a much larger platform rather than as an independent vendor.
Editorial Note: Claims vs. Verified Findings
Employee count (~19) and funding total (~$6M) are reported by GeekWire, not SurePath itself. The network-layer discovery mechanism is corroborated by both independent trade press and F5's acquisition announcement, but detection-accuracy and coverage claims are vendor-sourced and not independently tested.
Sources
Alternatives to SurePath AI
Adaptive Security
AI-driven platform that simulates deepfake, voice, and multichannel social-engineering attacks to train and test organizations against next-generation phishing.
Quilr
Early-stage agentic AI security startup building a 'Service-as-Software' platform to guard against human-related breaches and secure AI agent…
Zenity
Governance and security platform for AI agents and low-code/no-code development, securing agent identity, permissions and behavior across the…
Tenzai
An agentic AI penetration testing startup building autonomous 'AI hackers' to find and validate exploitable vulnerabilities at a…
Reco
Reco secures the "agentic ecosystem" — mapping what AI agents can access across SaaS and enterprise apps, detecting…
Charm Security
Agentic AI workforce that investigates and intervenes on scams and fraud in real time, reading manipulation and intent…