Mindgard, a British artificial intelligence security startup spun out of Lancaster University, announced on August 12, 2026, that it secured $30 million in Series A funding led by Album VC. The round drew participation from new investor Karma Ventures alongside returning backers .406 Ventures, Atlantic Bridge, IQ Capital and Lakestar, though the company declined to name a valuation.
The startup's core business is red teaming for AI systems. Its platform discovers vulnerabilities in large language models and autonomous agents, then tests defenses against attacks that traditional cybersecurity tools miss entirely. According to Mindgard, its researchers have uncovered more than 150 publicly disclosed vulnerabilities across widely used AI applications, including the code editor Cursor, Google's experimental Antigravity project, and OpenAI's ChatGPT.
That disclosure record has become something of a calling card. In what it described as a stalled disclosure process, Mindgard went public with a zero-click remote code execution flaw in Cursor IDE. The company also coordinated vulnerability reports with Zed Industries, which subsequently acknowledged implementing security improvements in its code editor. John Swanson, Zed's head of security, publicly credited Mindgard's research in a statement acknowledging the fixes.
For Album VC partner Ty Boswell, the appeal lies in a basic mismatch between how companies deploy AI and how they protect it. "Organizations are moving AI into critical operations without security infrastructure designed for how these systems operate in practice," Boswell said.
The problem Mindgard addresses is structural. Traditional security tools scan for known attack patterns or malicious payloads. AI systems, though, fail in different ways. A cleverly phrased prompt can coax a chatbot into leaking proprietary data. An agent with access to customer records might misinterpret instructions and act on them anyway. These aren't bugs in the conventional sense; they're exploitable quirks in how models process language and context.
Mindgard's platform starts with automated reconnaissance, mapping an AI system's full attack surface: the models themselves, prompt templates, integrated tools, external APIs. It then runs adversarial tests designed to surface weaknesses an attacker might exploit. In production environments, the platform enforces runtime policies intended to block those attacks before they land.

Several Fortune 500 security teams now use the tool, according to the company. Zed's disclosure episode appears to have helped. Mindgard also launched what it called the industry's first reconnaissance capability tailored to AI systems, a tool that the company says discovered more than 80 publicly reported vulnerabilities in a three-month span. A separate release, GuardBuster, stress-tests whether AI guardrails and safety gateways hold up when subjected to adaptive, adversarial prompting.
"Attackers do not rely on set prompts," Dr. Peter Garraghan, Mindgard's founder and former CEO, said in an earlier statement. "They adapt to other forms of adversarial prompting."
Garraghan, a Lancaster University professor specializing in AI security, founded Mindgard in 2022 and led the company until late last year. The startup then brought in James Brear, a veteran who previously ran Swimlane and Veriflow before VMware's acquisition of the latter, to oversee the business as it expands across the Atlantic. Brear opened a Boston headquarters and the company now operates teams in both Boston and London, though exact headcount figures shift as the business scales.

Aaron Portnoy, Mindgard's chief product officer, oversees offensive research alongside Rich Smith, the startup's head of offensive R&D. The company won UK's Most Innovative Cyber SME award in 2024 from Infosecurity Europe, a credential that matters in an industry where credibility hinges on demonstrated technical chops.
The funding history reflects steady, if not meteoric, growth. Mindgard raised a £3 million seed round in August 2023, according to Lancaster University. In December 2024, .406 Ventures led an $8 million round with participation from Atlantic Bridge, WillowTree Investments, IQ Capital and Lakestar. The new $30 million brings total disclosed funding to approximately $41 million.
Karma Ventures founding partner Kristjan Laanemaa called AI security "an emerging category" and named Mindgard "one of the names to watch," a bit of investor speak that nonetheless captures the uncertainty in the space. The market for AI security tools is still taking shape, with no clear winner and plenty of room for consolidation or surprise entrants.
Mindgard plans to channel the capital into product development, engineering, sales and marketing. "AI is creating an entirely new attack surface," Brear said. "Organizations need a fundamentally different approach to securing it."
Whether that approach crystallizes around Mindgard's platform or a competitor's remains an open question. But the startup's vulnerability disclosures and public research give it an edge in a field where trust is earned through proof, not promises.
