DeepKeep
Also known as: DeepKeep Ltd, DeepKeep AI Firewall, AI Agent Scanner, Vibe AI Red Teaming, Reddy, AI Lens
AI security platform spanning automated red teaming, runtime firewall guardrails, agent attack surface scanning and employee AI usage control.
DeepKeep is an AI security platform that covers the full AI lifecycle in one product, from pre deployment testing through continuous runtime enforcement. Five capabilities sit on a shared context layer. AI Red Teaming tests foundation models, applications and autonomous agents across single turn, multi turn and multi session interactions, covering prompt injection, jailbreaking, data leakage, bias exploitation, agent misuse, hallucinations and toxicity. An AI Firewall carrying more than 60 contextual guardrails evaluates every prompt and response in real time and can block, redact or alert according to policy. An AI Agent Scanner maps the attack surface of an agent end to end, inspecting every LLM, tool and integration involved in execution and covering the low and no code agent layer including n8n, CrewAI, Make and Dify. Model Scanning runs static and dynamic pre deployment assessment. AI Lens governs employee AI usage and which models are permitted. The integration is the argument the company makes: vulnerabilities found during red teaming translate into guardrails enforced by the firewall, and risks mapped by the scanner determine where those guardrails are placed. Vibe AI Red Teaming is the agentic surface, driven by Reddy, a named red teaming agent that executes and adapts in real time while pausing at key decision points for the security team to review, redirect or push deeper. Deployment spans SaaS, private cloud, on premises and fully air gapped environments, inline or out of band, and the platform sells as a unified product or as individual modules.
Vendor details
Canonical URL
https://www.deepkeep.ai
Category
Security / SOC agent
Funding status
Private and venture backed. Founded 2021 in Tel Aviv by Rony Ohayon. Raised venture funding from OurCrowd in January 2026. Team size reported 50 to 99 employees.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Deploys as a transparent proxy or via API where AI orchestrators send prompts for scanning and policy enforcement. Published Make.com connector with check input, create conversation and custom authorized API request modules. CI/CD integration for automated red teaming. Agent Scanner covers n8n, CrewAI, Make and Dify. Documentation section carries API and integration guides. Partner portal for channel partners.
In practice
A security team maps every LLM, tool and integration inside an agent built in n8n or CrewAI, then receives a prioritized remediation playbook before that agent ever reaches production.
A CISO runs continuous automated red teaming in staging, with re scans firing whenever a model or dependency changes, and converts the findings directly into runtime guardrails.
An enterprise deploys the firewall inline in an air gapped environment to redact personal data from prompts and block prompt injection before it reaches an internal fine tuned model.
Sources & related URLs
Related / legacy domains
Research sources
Agentic Index coverage score
11.5 / 14 capabilities · 82%
| Integrations & Tool CallingDeploys as transparent proxy or via API where orchestrators send prompts for scanning, per independent Intellyx brief. Published Make.com connector with check input, create conversation and custom API request modules. Agent Scanner covers n8n, CrewAI, Make and Dify. Integrates into existing stacks with no architectural changes. Intellyx Brain Candy Mar 2026 and Make app directory | Full |
|---|---|
| Workflow OrchestrationClosed loop across lifecycle stages: red teaming findings translate into firewall guardrails and Agent Scanner risk maps determine guardrail placement, with the same policy language from build to production. Reddy runs multi step campaigns across single turn, multi turn and multi session interactions. DeepKeep homepage and CyberStars capabilities submission 2026 | Full |
| Knowledge Grounding & RAGGuardrails evaluate against conversational history, industry specific language and regional regulatory requirements, and the platform maps to OWASP, NIST, GDPR and OWASP Top 10 for Agentic Applications, with detection grounded in original published security research. No retrieval architecture or customer knowledge base ingestion documented. DeepKeep capabilities and research pages 2026 | Partial |
| Human Oversight & GuardrailsStrongest axis. More than 60 contextual guardrails with customer selected enforcement per violation: block outright, alert for review, or redact. Vibe mode pauses execution at key decision points for the team to review, redirect or push deeper, and allows custom scenarios injected mid execution. In flight human steering of a running agent, independently confirmed. SiliconANGLE and PRNewswire Apr 2026 | Full |
| Security, Identity & GovernanceVERIFICATION FLAG: graded on product capability only, own corporate attestation UNCONFIRMED. Three searches for SOC 2, ISO 27001 and a trust centre returned nothing; privacy policy last updated March 2025. Product capability is deep: centralized control over which models are permitted, policy enforcement, PII detection and redaction supporting GDPR, CCPA, LGPD and PIPA, full audit logging, air gapped deployment. Same treatment as palo alto networks and sentinelone. DeepKeep employees use case page 2026 | Full |
| Observability & AuditabilityFindings, guardrail events, agent inventories and red team results roll up into a single risk posture mapped to auditor frameworks. Every finding carries full traces, adversarial prompts, responses and decision logic plus root cause analysis. Detection events and policy decisions visible in one dashboard with adjustable thresholds. Everything logged and auditable. DeepKeep homepage and firewall page 2026 | Full |
| Memory & State PersistenceMulti session red teaming implies state carried across sessions, conversational history informs guardrail decisions, and agent inventories plus findings with full traces persist into a single risk posture. No memory architecture, retention control or store is documented anywhere retrieved. DeepKeep CyberStars capabilities submission 2026 | Partial |
| Deployment & Data ResidencyTop of the deployment ladder and independently corroborated. Runs as SaaS, in customer private clouds, on premises data centres, or fully air gapped. Firewall deploys inline or out of band, as a proxy or via API, with no architectural changes required. Regional regulatory requirements handled in guardrail context. Intellyx Brain Candy Mar 2026 | Full |
| Prebuilt Agents, Templates & PacksMore than 60 pre built guardrails ship in the AI Firewall, independently confirmed at that count by trade press. Red teaming covers dozens of prebuilt attack topics, Agent Scanner emits a prioritized remediation playbook keyed to OWASP Top 10 for Agentic Applications, and modules are sold individually. SecurityBrief Dec 2025 and DeepKeep firewall page | Full |
| Triggers & Channel CoverageGenuinely event driven rather than clock driven. Event driven re scans fire when models or dependencies change, plus CI/CD integration, and the firewall evaluates every prompt and response inline at runtime so each interaction is itself the trigger. Passes the cron critique. DeepKeep CyberStars capabilities submission 2026 | Full |
| Model Flexibility & RoutingModel agnostic about what it PROTECTS, covering external LLMs such as ChatGPT, Gemini and Copilot, internal fine tuned models, plus vision and tabular, and letting the customer set which models are permitted. But its own detection engine is proprietary and deliberately not swappable, using cognition based analysis and language classifiers and arguing explicitly against LLM as a judge. Governance of models rather than routing. Preqin profile and DeepKeep LLM page 2026 | Partial |
| APIs, SDKs & MCP ExtensibilityDocumentation section carries API and integration guides, API deployment mode confirmed independently, and the Make connector exposes a custom authorized API request module giving access to any available endpoint. NO MCP CREDIT: DeepKeep SECURES MCP servers as an attack surface but no evidence retrieved that it SHIPS one. Docs not directly readable due to robots restriction. Make app directory and Intellyx Mar 2026 | Full |
| Testing, Debugging & OptimizationCore product. Automated red teaming runs continuously across development and staging with adversarial prompts generated dynamically by topic and context rather than static playbooks, plus static and dynamic model scanning pre deployment. Publishes its own accuracy numbers, including native versus translation detection at 0.834 against 0.614 on Japanese and 0.827 against 0.733 on German, and publishes model evaluations naming failure modes. DeepKeep red teaming pages 2026 | Full |
| Browser & Computer UseNo browser or computer use capability of any kind retrieved. TRAP FLAGGED FOR FUTURE READERS: DeepKeep covers computer VISION model security, meaning protection of image models against visual injection and mislabeling. That is image model security, NOT browser or computer use, and must not be read as a Comp credit. DeepKeep vision and multimodal pages 2026 | Unable to verify |
The Agentic Index coverage score grades every vendor Full, Partial or Unable to verify against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
Contact for pricing
Not published. No seat, token, interaction or scan unit disclosed anywhere retrieved.
Included quota
Not published
What is public
Nothing numeric. The site publishes capability detail and deployment options but no plans, tiers or rates.
Billing mechanics
Not disclosed. Unified platform or individual modules, quoted through sales.
Cost watchouts
Modular selling means the quoted number depends entirely on which of the five capabilities are in scope: AI Firewall, AI Red Teaming, AI Agent Scanner, Model Scanning, AI Lens. Air gapped and on premises deployment typically carries different commercial terms than SaaS in this lane but no terms were retrieved. Establish which modules are included before comparing any quote.
Variable cost rationale
Scoping dominates. The platform sells as a unified product OR as individual modules for buyers who need only part of the stack, so the module mix alone moves the number materially. The firewall inspects every prompt and response inline, which scales with AI interaction volume, and red teaming runs continuously across development and staging. No unit, quota or overage rate is published for any of it, so a buyer cannot model cost before a sales conversation.
Additional watchouts
Contact only pricing in a lane that is overwhelmingly contact only, so this is the lane norm rather than an outlier.
Overage / add-ons
Not published
Sales call required
Yes, required for paid access
Free / trial
No free tier or trial published. A Scan your Agent form offers an agent attack surface scan but it routes to a submission form rather than self serve access.
Lowest paid plan
None published
Commercial notes
Enterprise sales motion with a partner programme and partner portal, so channel pricing may differ from direct. Deployed across enterprise environments in North America, Europe and APAC per vendor statement.
Key ambiguities
Whether pricing is per protected application, per interaction volume, per seat, or per module is entirely undisclosed. No third party source carried a credible number either, and the vendor name collides with DeepSeek, Keeper and UpKeep in pricing searches, so any figure attributed to DeepKeep should be checked against the domain character by character before it is trusted.
Missing data
Entry price, billing unit, quota baseline, overage rule, free tier status and contract terms are all unretrieved. entryPriceUsd left null deliberately rather than guessed.
Related vendors
- 7AI — Swarming agentic SOC from the Cybereason founders: sixty plus domain…
- Abnormal AI — Behavioural AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR built around a Virtual Analyst that triages 95% of…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Bionic SOC: a human-AI collaboration platform that automates triage,…
- Anvilogic — Agentic security operations platform that decouples detection from…