Back to vendors
F

F5 AI Guardrails

Also known as: CalypsoAI, Calypso AI, F5 AI Red Team

Visit site
Entry priceContact salesFull pricing detail

F5's AI security platform, formerly CalypsoAI, that runs inline guardrails on prompts, responses and agent tool calls across any model and, as F5 AI Red Team, red teams the customer's models and agents with scheduled attack campaigns, as SaaS or self-hosted.

F5 AI Guardrails, formerly CalypsoAI, is an AI security platform owned by F5, which acquired CalypsoAI in a deal announced in September 2025. calypsoai.com now redirects to F5, which sells the platform as two products, F5 AI Guardrails and F5 AI Red Team, documented together as F5 AI Security. The app and the Python SDK still carry the CalypsoAI name.

AI Guardrails sits in front of the customer's models, apps and agents, scanning prompts and responses inline with prebuilt and custom scanners grouped into guardrail packages, in block or audit mode, and F5 says it also audits and blocks unauthorized agent tool calls. Applications can call its scan endpoint or send model traffic through it to OpenAI, Anthropic, Google or custom providers the customer connects with its own keys, chosen per project.

AI Red Team runs campaigns of standard, operational, agentic and custom attacks against the customer's models and agents, drawing on monthly attack packs, on demand or on a schedule, and reports the results. Prompt history, agent sessions, an audit log and SIEM export cover observability, and granular custom roles, MFA and retention controls cover access.

It fits security teams that need one policy layer across many models and clouds and want to test those systems before and after launch. It deploys as SaaS or inside the customer's own AWS, Azure, Google Cloud, Oracle Cloud or Kubernetes environment, including air-gapped on premises, with self-hosting on the customer's own GPUs. It is a security layer, not an agent builder: it does not orchestrate workflows, ground agents in knowledge, give them memory or connect them to business systems. Pricing is not published.

Vendor details

Canonical URL

https://www.f5.com/products/ai-guardrails

Category

Agent infrastructure

Subcategory

AI security and red teaming

Funding status

Acquired by F5 (NASDAQ: FFIV) for $180M in a deal F5 announced in September 2025. The platform is now sold as F5 AI Guardrails and F5 AI Red Team.

Company status

first party product

Use cases & customers

Primary use cases

AI red teamingprompt injection defenseAI runtime guardrailsAI observabilityAI compliance

Target customers

enterprisesecurity teamsregulated industries

Deployment options

SaaSon-premhybrid

Integrations

Model traffic can pass through the platform to OpenAI, Anthropic, Google or custom providers the customer connects with its own keys, and the docs cover proxy setups for the OpenAI and Anthropic SDKs, Claude Code, OpenAI Codex and Google Gemini. Slack, Microsoft Teams and SIEM integrations are documented. A REST API and the calypsoai Python SDK cover almost everything the platform does.

In practice

Your security team needs to know whether your production LLM can be jailbroken before attackers do. AI Red Team runs campaigns of evolving attacks against it, on demand or on a schedule, and reports what got through.

You are rolling out agents across several model providers and cannot bolt a different security tool onto each one. You route their traffic through AI Guardrails so one set of guardrails covers every model and cloud.

Compliance is asking how you monitor and audit AI use across the company. Prompt history, agent sessions and the audit log show what went through and why it was blocked or allowed, and events can flow to your SIEM.

Agentic Index coverage score

9.0 / 14 capabilities · 64%

Integrations & Tool Calling Partial

The docs index lists proxy integrations that route the OpenAI and Anthropic SDKs, Claude Code, OpenAI Codex and Google Gemini through the platform, along with Slack and Microsoft Teams integrations and a SIEM connection. These route model traffic and send events; no connector lets an agent take authenticated action in an outside system. F5's page says it audits and blocks agents' tool calls, which governs actions that other systems take.

SourceF5 AI Security, docs.aisecurity.f5.com (docs index and integration guides) and /reference/roles-permissions.htmlread 2026-09-25

Workflow Orchestration Not documented

The platform sits in front of the customer's models and agents and does not run their workflows. Guardrails scan each call inline, and red team campaigns are ordered attack runs against a target, not agent work in several steps that the customer builds. No workflow model is documented.

SourceF5 AI Security, docs.aisecurity.f5.com/api-docs/about-api.html and /red-team/managing-campaigns.htmlread 2026-09-25

Knowledge Grounding & RAG Not documented

Prompts and responses are scanned and the customer's models attacked, but none of the documented API resources, which cover admin, roles, campaigns, license, projects, prompts, scanners, scans, tokens and users, indexes or retrieves the customer's documents for an agent to ground its answers on.

SourceF5 AI Security, docs.aisecurity.f5.com/api-docs/about-api.htmlread 2026-09-25

Human Oversight & Guardrails Full

AI Guardrails runs structured guardrails inline on prompts and responses. Admins build guardrail packages from prebuilt and custom scanners, switch each one on or off and choose block or audit mode; they can also customize the response a blocked user sees and enforce guardrail use across projects. F5's product page adds that it explains and traces why each interaction was blocked or allowed, and audits and blocks unauthorized tool calls and agent actions. These guardrails stop an output outright; no human approval step is documented.

SourceF5 AI Security, docs.aisecurity.f5.com/reference/roles-permissions.html and f5.com/products/ai-guardrailsread 2026-09-25

Security, Identity & Governance Full

The AI Security platform, formerly CalypsoAI and now sold by F5 (calypsoai.com redirects to f5.com), documents a deep access surface. Admins create custom roles from granular permissions over the organization, guardrails, model connections and secrets, projects, users, red team campaigns, reports and attack types, down to API access, which is off by default for basic users. MFA and user blocking are there too. Admins can switch data retention and prompt history logging on or off, and an audit endpoint records activity. No SSO or SAML integration is named.

No attestation scoped to these products appears. The F5 Trust Center describes a product certification program (FIPS, NIST, ISO) without naming the AI Security products, and no certificate scoped to AI Guardrails or AI Red Team is shown; F5 owns the product, so a scoped F5 certificate would apply.

SourceF5 AI Security, docs.aisecurity.f5.com/reference/roles-permissions.html and f5.com/company/trust-centerread 2026-09-25

Observability & Auditability Full

The platform records the agent's own traffic. Prompt history logs, which admins can switch on or off, can be read in the product and through the API. Agent sessions show agent and tool counts and first and last prompt times, along with errors and the peak outcome, and a dashboard shows token use by project and guardrail. A separate audit log records user and configuration activity, and admins can send events to a SIEM.

SourceF5 AI Security, docs.aisecurity.f5.com/operations/get_agent_sessions.html, /guardrails/guardrails-dashboard.html and /reference/roles-permissions.htmlread 2026-09-25

Memory & State Persistence Not documented

The platform keeps records about the customer's agents, not memory for them. Prompt history, agent sessions and the audit log are read by people and by the scanners' enforcement, and the agent never reads them as context to decide. No memory layer or state the agent carries between runs is documented.

SourceF5 AI Security, docs.aisecurity.f5.com/operations/get_agent_sessions.html and /api-docs/about-api.htmlread 2026-09-25

Deployment & Data Residency Full

The platform runs as SaaS, usually at us1.calypsoai.app, or inside the customer's own environment. The CAI-Deploy installer provisions or installs all AI Security products into AWS, Azure or Google Cloud accounts, into Oracle Cloud, or into an existing Kubernetes cluster, with separate guides for Helm, GCP and OpenShift. F5's product page adds private cloud and fully air gapped on premises deployment with full functionality. Hosting it yourself needs your own GPUs, at least 24 GB for Guardrails and 48 GB for Red Team.

SourceF5 AI Security, docs.aisecurity.f5.com/get-started/ai-security-install.html and f5.com/products/ai-guardrailsread 2026-09-25

Prebuilt Agents, Templates & Packs Partial

Security content ships rather than agents or workflows. Monthly attack packs feed red team campaigns, prebuilt scanners go into guardrail packages the customer assembles, and country PII guardrail sets cover core, France, Japan, Korea and Spain, alongside prompt templates. These are libraries the customer assembles into its own guardrails and campaigns, not packaged assets a buyer adopts as working units.

SourceF5 AI Security, docs.aisecurity.f5.com/red-team/managing-campaigns.html, /reference/roles-permissions.html and the docs index (PII guardrail references)read 2026-09-25

Triggers & Channel Coverage Full

AI Red Team campaigns run on a schedule. The campaign schedules API sets the start and end time, frequency and interval, along with the number of occurrences and the target providers, and it can run remediation automatically. So a schedule starts the platform's own adversarial testing with no person present. Guardrails work inline, starting when the customer's application sends a scan or a proxied prompt, so they add no trigger of their own, and blocks and alerts are outputs, not triggers.

SourceF5 AI Security, docs.aisecurity.f5.com/operations/post_campaign_schedules.html and /api-docs/about-api.htmlread 2026-09-25

Model Flexibility & Routing Full

Admins add model connections with their own stored secrets, set a default provider for each project and switch providers on or off per project. The API sends a prompt to a chosen provider through endpoints compatible with OpenAI, Anthropic and Google, and custom providers can be created too. So admins and users choose the model with their own keys inside the product, and the proxy endpoints do route model traffic.

SourceF5 AI Security, docs.aisecurity.f5.com/api-docs/about-api.html and /reference/roles-permissions.htmlread 2026-09-25

APIs, SDKs & MCP Extensibility Full

The AI Security API covers almost everything the platform does, including admin backup and import, roles and permissions, red team campaigns, license, projects, prompts and prompt templates, scanners (which can be created and versioned, exported and imported), scans, tokens and users. It is a REST API with bearer tokens and a full endpoint reference. A Python SDK, the calypsoai package, wraps it, and every sample in the docs uses it. No MCP server is documented.

SourceF5 AI Security, docs.aisecurity.f5.com/api-docs/about-api.html and /api-reference/read 2026-09-25

Testing, Debugging & Optimization Full

AI Red Team tests the customer's own models, applications and agents. Campaigns bundle attacks of several types, from standard and operational to agentic and custom, each defined by technique, vector and severity, with converters, and drawn from monthly attack packs. They run against the customer's providers, with reports and results the customer reads and compares across runs, and datasets and dataset runs are documented in the API too. Evaluating models is what this module sells, and the model under test is the customer's.

SourceF5 AI Security, docs.aisecurity.f5.com/red-team/managing-campaigns.html and /api-docs/about-api.htmlread 2026-09-25

Browser & Computer Use Not documented

The platform secures and tests AI models, apps and agents and does not operate a browser or computer itself; no capability of that kind appears on the product page or in the docs index.

SourceF5 AI Security, f5.com/products/ai-guardrails and docs.aisecurity.f5.comread 2026-09-25

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Recent platform changes

2026-09-30·Human approval / guardrailsVerified

Arabic language guardrail packages for Saudi Arabia and the United Arab Emirates are now available in F5 AI Guardrails, covering local identifiers such as national IDs, residency and visa numbers, addresses and bank accounts. On premises customers need to redeploy to get them.

Bears on: Security / enterprise

View source
2026-08-26·Security / enterpriseVerified

F5 AI Security released SaaS version 10.98.4, introducing improved project administrator support and a new September attack pack for the AI Red Team. The update grants project admins access to dedicated dashboards and prompt histories, while the new attack pack tests models against stylistic reformulation attacks that disguise harmful requests as poetry or folktales.

Bears on: Security / enterprise

View source
View all 2 changes for F5 AI Guardrails →Tracked since Aug 2026 · Verified from public vendor sources

Pricing

Contact sales

not published

Included quota

Not publicly disclosed. Allowances are set per contract based on inference volume and data processed.

What is public

The two product names, the deployment options and the license requirement are public; no price is.

Billing mechanics

Sold through F5; the product page publishes no price or billing unit. The self-hosted platform runs under a license from AI Security, managed in the product.

Cost watchouts

Self-hosted deployments run on the customer's own GPUs (at least 24 GB for Guardrails and 48 GB for Red Team) plus Kubernetes and storage, and the docs' token-usage dashboard exists to plan that capacity.

Variable cost rationale

No billing unit is published. Self-hosted deployments run on the customer's own GPUs, and the docs' token-usage dashboard exists to plan that capacity, so infrastructure cost grows with guarded traffic.

Additional watchouts

calypsoai.com now redirects to F5's AI Guardrails page, so quotes, contracts and support run through F5.

Overage / add-ons

Not publicly disclosed; usage tiers and overage are negotiated in the subscription.

Sales call required

Yes, required for paid access

Free / trial

No free tier or trial is published for AI Guardrails or AI Red Team; F5 routes buyers to a demo and sales

Lowest paid plan

None published; pricing is by quote

Commercial notes

Aimed at large enterprises and regulated industries with dedicated security operations. Sold with vendor support and SLAs. Now an F5 company, with the capability moving into F5 AI Guardrails and the broader F5 Application Delivery and Security Platform.

Key ambiguities

Whether AI Guardrails and AI Red Team are licensed separately or together, and what unit a license counts.

Cancellation / refund

Enterprise contract terms; not publicly disclosed.

Support SLA / resale

Vendor support and SLAs are part of the commercial offering; specifics are negotiated per contract.

Missing data

Any price, billing unit, tier or overage rate, and how the two products are packaged together.

Agentic Index verified 2026-09-25

Alternatives to F5 AI Guardrails

The closest documented capability profiles to F5 AI Guardrails among agent infrastructure platforms tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Galileo9.0 / 14Matches F5 AI Guardrails across all 14 documented capabilities
  • Opik9.0 / 14Matches F5 AI Guardrails across all 14 documented capabilities
  • W&B Weave9.0 / 14Matches F5 AI Guardrails across all 14 documented capabilities
  • Confident AI8.5 / 14A lighter documented profile than F5 AI Guardrails
  • Fiddler AI8.5 / 14A lighter documented profile than F5 AI Guardrails
  • HoneyHive8.5 / 14A lighter documented profile than F5 AI Guardrails

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.