Skip to content

CyberAGI

Dallas-based, US-owned offensive security company running an on-premises AI system (Excalibur) that discovers, validates and remediates exposures.

Visit Website ↗ + Add to Compare Claim This Company
32/100Emerging / Unranked

Overview

CyberAGI builds Excalibur, a unified security system built around a closed-loop process — discover, model, validate, correlate, assess posture, remediate, govern, predict, learn — pitched as an AI-driven alternative to the typical fragmented stack of separate scanning, pentesting and posture-management tools. The company emphasizes that Excalibur runs entirely on-premises without transmitting customer data to the cloud, and positions itself as “sovereign AI for cybersecurity” built and operated entirely within the United States.

Founded in 2019 in Texas by CEO Shubham Khichi, with Diana Morales as Chief AI Scientist and Sujata Kaushal as CTO and founding engineer, CyberAGI has a Crunchbase profile confirming its existence and leadership but has disclosed no funding round publicly. The company names four production customers on its own site — Loial, General Atomics, Ultramain and the City of Los Lunas — but provides no independent third-party validation, analyst coverage or published effectiveness metrics beyond those self-reported names.

Innovation Matrix Assessment

Innovation Velocity 3/10

Founded in 2019 with no disclosed funding round and minimal independent press coverage in six-plus years, suggesting slow external validation despite an apparently functioning product.

Operational Value 4/10

Consolidating discovery, validation and remediation into one on-prem system addresses real tool-sprawl pain, but claims of automating 80% of manual security work are unverified.

Market Momentum 2/10

No disclosed funding, no analyst recognition found, and only a handful of named customers on the company's own site with no independent confirmation.

Category Disruption 3/10

On-prem, closed-loop exposure management overlaps heavily with established exposure-management and CTEM vendors; the sovereign/on-prem angle is a differentiator but not a new category.

Real-World Efficacy 2/10

No independent testing, analyst validation, or customer testimonials beyond bare customer names were found anywhere.

Enduring Relevance 5/10

On-premises, data-sovereign security tooling remains relevant for government and defense-adjacent buyers (consistent with named customers like General Atomics and a municipal government), a durable but narrow niche.

Why CISOs Should Care

For organizations with strict data-sovereignty or air-gapped requirements (defense contractors, government), an on-prem AI exposure-management system avoids sending sensitive data to third-party clouds.

What Makes It Different

Explicit on-premises, U.S.-only operation model rather than the cloud-native SaaS delivery most exposure-management competitors use.

The Matrix Verdict

32/100 — EMERGING / UNRANKED

Emerging tier: a long-operating, real company with named customers in defense-adjacent sectors, but the near-total absence of independent verification, funding disclosure, or analyst coverage after six years keeps confidence low.

Editorial Note: Claims vs. Verified Findings

Company existence, founding date, leadership and named customers are drawn directly from the company's own site and its Crunchbase profile; no independent press, analyst, or funding confirmation was found, so all performance and adoption claims should be treated as unverified.

Sources