
AI security company Mindgard has raised $30 million (£22.2 million) in a Series A funding round as the Lancaster University spinout prepares to expand its product and commercial operations, particularly in the United States.
The round was led by Album VC, with participation from Karma Ventures and existing investors .406 Ventures, Atlantic Bridge, IQ Capital and Lakestar. Mindgard said the funding will be used across product, engineering, sales and marketing as it responds to growing demand from organisations deploying AI systems.
Founded in 2022 from research at Lancaster University, Mindgard develops security technology for AI models, agents and applications. The company says its platform combines automated reconnaissance, AI red teaming and runtime protection to identify and address vulnerabilities that can emerge when AI is integrated into wider software systems.
From University Research to a $30m Series A
Mindgard’s origins are closely tied to Lancaster University’s security research. The company was founded by researchers including Professor Peter Garraghan, whose work focused on the security of AI systems before the current wave of generative AI applications and autonomous agents.
Lancaster University announced Mindgard’s first major funding in 2023, when it raised £3 million in seed financing from IQ Capital and Lakestar. The university said the company was commercialising technology developed through its research into the security of AI systems.
Mindgard subsequently raised an $8 million round led by .406 Ventures in December 2024. Atlantic Bridge, WillowTree Investments, IQ Capital and Lakestar also participated. The company said that financing would accelerate research and development and support expansion into the US market.
The latest round represents another substantial increase in the company’s fundraising as it moves from research-led development towards larger-scale enterprise deployment.
Mindgard is Targeting a Different Layer of AI Security
Mindgard’s approach is built around attacking AI systems to identify weaknesses before they can be exploited. Its platform includes AI discovery and reconnaissance, continuous red teaming, security assessment, model scanning and runtime protection.
The company argues that testing an AI model in isolation is not enough because security problems can emerge from the way a model interacts with applications, data, users, authentication systems and external tools.
That position has become increasingly relevant as businesses deploy AI agents and coding assistants that can interact with files, APIs and other software. Mindgard’s research has increasingly focused on these broader systems rather than treating the underlying model as the only security boundary.
More than 150 Vulnerability Disclosures
Mindgard says its security research has resulted in the public disclosure of more than 150 high-impact vulnerabilities involving AI applications and related software.
Its public disclosure archive currently lists findings involving products from companies including OpenAI, Google, Microsoft, NVIDIA, Cursor and Anthropic, among others. Recent disclosures include an issue in Cursor IDE, vulnerabilities affecting OpenAI’s Codex CLI and a content-safety issue involving ChatGPT’s image generation.
Because the 150-plus figure is a company-reported figure, it is more accurate to attribute the number to Mindgard rather than present it as an independently audited total.
AI Coding Tools Have Become a Major Research Target
One of Mindgard’s recent research areas has been AI-assisted development environments, where AI systems are given access to code, files and development tools.
In November 2025, Mindgard reported a vulnerability in Google’s Antigravity IDE involving malicious trusted workspaces. According to the company’s disclosure, a compromised workspace could establish a persistent backdoor capable of executing code when the application was subsequently launched. Mindgard said it reported the vulnerability to Google on November 19, 2025, and published its research on November 25.
Mindgard also disclosed a vulnerability in Cursor in July 2026. The company said it had originally reported the issue in December 2025 and later released technical details after an extended disclosure process. These claims describe Mindgard’s account of the vulnerability and disclosure timeline.
The research points to a broader security challenge: AI coding systems increasingly sit inside environments where untrusted input can potentially influence software with access to sensitive files or high-privilege actions.
Leadership has Shifted as the Company Scales
Mindgard has also changed its leadership structure as it moves into a larger commercial phase. James Brear is now chief executive, while founder Peter Garraghan serves as chief science officer.
Brear joined from Swimlane, where he was CEO, and previously held leadership roles at Veriflow and Procera. Mindgard said his appointment was intended to support the company’s transition from research and product development towards broader enterprise deployment. The company also established Boston as its US headquarters and North American hub.
Garraghan continues to lead the company’s scientific direction while remaining a professor of computer science at Lancaster University.
The US is Becoming Central to Mindgard’s Growth Strategy
Mindgard now operates from London and Boston, with the US playing an increasingly important role in its expansion plans.
The company says its platform is being deployed among Fortune 2000 organisations and AI-focused companies across financial services, pharmaceuticals, gaming, digital services, semiconductors and healthcare. It has also said that it secured Fortune 500 design partners in 2026. Those customer and design-partner figures come from Mindgard and have not been independently verified in the sources reviewed.
The new capital will allow Mindgard to increase investment in the teams responsible for building and commercialising the platform while extending its international reach.
A Growing Market for Offensive AI Security
Mindgard’s funding arrives as security companies increasingly focus on attacks against AI applications rather than only conventional software or standalone machine-learning models.
The company’s own research argues that prompt injection and jailbreaks are only part of the problem. Security teams also need to assess how AI interacts with application permissions, data flows, authentication and connected tools.
That is the market Mindgard is attempting to occupy: an offensive-security layer for AI systems that can continuously test how those systems behave under attack and identify vulnerabilities before they become operational incidents.
For Lancaster University, the deal is also another example of academic cybersecurity research being converted into a venture-backed technology company. Mindgard has now progressed from its £3 million seed round in 2023, through its $8 million financing in 2024, to a $30 million Series A in 2026.
The immediate test will be whether Mindgard can turn its research advantage and growing vulnerability-disclosure record into sustained enterprise adoption as the market for AI security becomes increasingly competitive.
References for Further Reading
- Lancaster University — Mindgard £3m seed funding
- Lancaster University — Mindgard $8m funding round
- Mindgard — About the company
- Mindgard — AI vulnerability disclosures
- UKTN — Mindgard Series A
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.

