Skip to content

TrojAI

AI/LLM security platform that scans models for vulnerabilities before deployment and inspects prompts and outputs at runtime to block prompt injection, jailbreaks, and data leakage.

Visit Website ↗ + Add to Compare
63/100Incremental Innovator

Overview

TrojAI sells two connected products: TrojAI Detect, which scans machine learning models during the build/validation phase for vulnerabilities such as embedded trojans, backdoors, and adversarial weaknesses before they reach production; and TrojAI Defend, a runtime guardrail layer that inspects prompts and model outputs in real time to catch prompt injection, jailbreak attempts, sensitive-data leakage, and exposure of personally identifiable information in generative AI applications. The pairing addresses both ends of the AI security lifecycle, pre-deployment model assurance and in-production application protection, rather than only one.

Founded in 2019 in Saint John, New Brunswick, Canada, by James Stewart and Stephen Goddard, TrojAI has raised a total of roughly $11.4M across a pre-seed round backed by Techstars and two seed rounds, most recently a $5.75M raise in April 2024 led by Flying Fish with new participation from Flybridge Capital and Alteryx Ventures; that round also funded a new Boston office as the company expanded into the U.S. market. TrojAI states it landed a Fortune 100 customer prior to the post-ChatGPT surge in generative AI security spending, which if accurate would predate most of its current AI-security competitors.

TrojAI’s products are built to map to existing frameworks (OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF) rather than a proprietary taxonomy, which should ease integration into security teams’ existing AI governance processes. As a small, seed-stage company competing in a fast-filling AI security field against both dedicated LLM-security startups and the AI-safety features being added by major cloud and model providers, its long-term differentiation will depend on maintaining detection accuracy as attack techniques evolve.

Innovation Matrix Assessment

Innovation Velocity 7/10

Shipped a paired build-time (Detect) and runtime (Defend) product line and expanded operations into a new U.S. office within its first five years, a reasonably fast pace for a seed-stage company.

Operational Value 5/10

Small seed-stage team (roughly 11-50 employees) with dual Canada/Boston offices; real product but limited scale compared to more established AI security vendors.

Market Momentum 7/10

Raised a $5.75M seed extension in April 2024 following an earlier $3M seed round, with new investor participation (Flybridge, Alteryx Ventures) alongside existing backers, indicating continued investor confidence in a fast-growing category.

Category Disruption 6/10

Addresses a genuinely emerging attack surface (LLM prompt injection, jailbreaks, model trojans) that legacy AppSec/DLP tools were not built for, though it now competes with a rapidly growing field of similarly positioned AI security startups.

Real-World Efficacy 4/10

No independent red-team, MITRE ATLAS evaluation, or benchmark results were found; the marquee 'Fortune 100 customer' claim is vendor-stated and unnamed, so effectiveness evidence is currently limited to vendor messaging.

Enduring Relevance 9/10

AI/LLM security has become one of the fastest-growing CISO priorities as generative AI adoption accelerates, and TrojAI's framework alignment (OWASP, MITRE ATLAS, NIST AI RMF) keeps it squarely positioned against current enterprise AI governance requirements.

Why CISOs Should Care

Provides both pre-deployment model scanning and runtime prompt/output inspection for generative AI applications, addressing prompt injection, jailbreaks, and sensitive-data leakage that traditional AppSec and DLP tools are not built to catch.

What Makes It Different

Covers both the model-build phase (TrojAI Detect) and production runtime (TrojAI Defend) rather than only one stage of the AI security lifecycle, and maps controls explicitly to OWASP LLM Top 10, MITRE ATLAS, and NIST AI RMF.

The Matrix Verdict

63/100 — INCREMENTAL INNOVATOR

A well-positioned, framework-aligned AI security vendor with real, if early, enterprise traction and credible seed-stage funding momentum; still small enough that its long-term detection efficacy against fast-evolving LLM attack techniques remains to be proven at scale.

Editorial Note: Claims vs. Verified Findings

The claim of landing a 'Fortune 100' customer before generative AI security was a mainstream category is a vendor-sourced, unnamed-customer claim and could not be independently verified. Funding amounts, founding details, and the Boston office expansion are corroborated by independent reporting (SecurityWeek, BetaKit, PR Newswire).

Sources