SplxAI (now part of Zscaler)

Sources: Homepage · Seed funding announcement (Splx blog) · Zscaler acquisition coverage (The Recursive)

What

Croatian-founded agentic-AI red-teaming and security testing company. Automated security testing of AI agents and customer-facing AI applications via simulated adversarial scenarios. Acquired by Zscaler during the same year for advanced LLM security and AI governance — the first publicly disclosed exit in the agentic-AI-security seed cohort tracked here.

Funding

$7M seed round, March 26, 2025 — led by LAUNCHub Ventures with Rain Capital, Inovo, Runtime Ventures, DNV Ventures, South Central Ventures.

Acquired by Zscaler later in 2025 (exact date not in primary sources reviewed).

Relevance

Maps to the CMM D7 (Observability & Detection) continuous-red-team / CART evidence slot. Closest peers: Mindgard CART, Promptfoo (now part of OpenAI), Garak (NVIDIA), General Analysis (the next-cohort seed).

The Zscaler acquisition is a category signal: the offensive/CART side of agentic AI security is consolidating into existing CNAPP / SSE platforms, not staying independent. Comparable trajectory to Promptfoo → OpenAI (also part of a larger platform now). Implication for the seed-stage cohort: pure-play CART startups may have a shorter independent runway than gateway / runtime / identity startups.

Product

Capabilities advertised at seed:

  • Automated security testing of internal AI agents and customer-facing AI applications
  • Simulates sophisticated adversarial scenarios that mimic the tactics of highly skilled attackers
  • Detects and mitigates prompt injection, off-topic responses, hallucinations
  • Continuous monitoring and dynamic remediation

Founding team included AI red teamers and CTF winners (Wiz Capture-The-Flag, Black Hat) — pedigree-grade research staff.

Notable

The SplxAI exit happened before the next seed wave (Trent AI, General Analysis, Capsule Security in April 2026). This timing is informative for the broader synthesis: investors funded Helmet, Runlayer, Capsule, etc. knowing the CART category had already absorbed, suggesting the seed cohort views the gateway / runtime / identity / lifecycle plays as more durable independent businesses than the testing-only category.

See Also