Securing the Future of AI: A Look at RSAC 2025 Innovation Sandbox Finalists
I recently had the privilege of keynoting RSAC 2025 on "Zero Trust AI: Securing Multi-Agent Systems for Private Data Reasoning" addressing critical areas such as threat modeling with the MAESTRO framework, agentic AI red teaming, and Zero Trust strategies for MAS. The energy at the conference was palpable, fueled by forward-thinking discussions on securing agentic AI. In addition, I spoke at the Aegis of Tomorrow Summit, delivering the opening keynote on the rise of AI agents and their security implications. I also participated in the media interviews with ISMG and Protect AI/MLSecOps, discussing key trends in AI and cybersecurity. As part of the OWASP GenAI Project, I contributed to a panel on red teaming guidance for generative AI and spoke on a session on threat modeling for agentic AI systems. Throughout the event, I closely followed the RSAC Innovation Sandbox finalists to stay informed on cutting-edge developments in security innovation.
This Substack series will delve into the groundbreaking work of the RSAC Innovation Sandbox finalists, highlighting how their technologies are shaping the intersection of AI security, agentic architectures, and enterprise risk. We begin with CalypsoAI, a pioneer in securing AI at the most critical moment: runtime.
Why CalypsoAI Matters: Securing the Inference Layer
Organizations are rapidly deploying AI across all facets of their operations. While much focus is given to the security of model building and training, the most immediate risks often arise at the inference layer. This is the point where AI models generate outputs in response to real-world data and user prompts – where business value is realized, but also where vulnerabilities can be exploited in real-time. This is where CalypsoAI's innovative approach truly shines. Their focus on securing the "inference perimeter" provides a vital layer of defense.
CalypsoAI: A Technical Deep Dive into Inference Security
CalypsoAI's core mission is to secure AI systems and agents in real time, specifically at the inference layer, where business value and potential risk converge. Their unified platform, the "Inference Perimeter," offers robust protection for any AI model, regardless of the environment (public cloud, private cloud, on-premises) or vendor (OpenAI, Meta, Anthropic, etc.). The Inference Perimeter operates on the core principles of Red-Team, Defend, and Observe
Three Pillars of Protection: The Inference Perimeter
Red Team: Proactive Vulnerability Assessment
Automated Adversarial Testing: CalypsoAI simulates real-world attacks using a massive, continuously updated attack library. These simulations include prompt injections, incremental attacks, and operational exploits. This allows for proactive identification of weaknesses before they can be exploited.
Agentic Warfare: Going beyond static testing, CalypsoAI employs dynamic, multi-turn adversarial dialogues, revealing vulnerabilities that may only surface during extended interactions. This mirrors the MAESTRO framework's emphasis on dynamic, multi-layer threat modeling and continuous validation of agent behaviors.
Continuous Assessment: Red-teaming is not a one-time event. CalypsoAI enables automated, repeatable adversarial tests to ensure ongoing resilience, adapting to both model and threat evolution. This is crucial for maintaining a strong security posture in a rapidly changing AI landscape.
Defend: Real-Time Threat Interception
Inference-Layer Security: CalypsoAI directly analyzes every input and output at runtime, effectively intercepting threats such as prompt injection, jailbreaking attempts, and data leakage before they impact business operations.
Customizable Controls: Enterprises can define security policies tailored to their specific risk profiles and regulatory requirements. This allows for a balanced approach between robust protection and continued innovation. Granular security policies can be set to automate remediation processes.
Immediate Protection: Security scanning engines are activated instantly upon deployment, providing zero-delay defense for new AI services. This ensures immediate protection from potential threats.
Observe: Unified Monitoring and Governance
Unified Monitoring: Real-time dashboards and detailed audit trails provide security teams with comprehensive visibility into AI usage, model behavior, and compliance status.
Automated Risk Marking: The platform automatically flags non-compliant or risky behavior, aiding organizations in maintaining robust governance and regulatory alignment.
Seamless Integration: CalypsoAI seamlessly connects with existing Security Information and Event Management (SIEM), Security Orchestration, Automation and Response (SOAR), and ticketing systems, ensuring that AI security events are integrated into existing enterprise workflows.
Next-Generation Features
Customizable Security Scanners: CalypsoAI enables organizations to build their own AI-powered scanners, set granular policies, and block or redact content based on proprietary or industry-specific needs. This is particularly valuable in sectors like finance and pharmaceuticals, where sensitive data requires stringent control.
Model-Agnostic Bots for Collaboration Platforms: CalypsoAI integrates with popular workplace chat tools such as Slack and Microsoft Teams, securing AI-powered workflows without disrupting productivity. It supports Retrieval-Augmented Generation (RAG) for secure document handling and auditing.
Real-World Impact
CalypsoAI's platform is currently deployed in production environments, protecting mission-critical AI systems across highly regulated industries. Its approach is gaining recognition as a new industry benchmark, effectively combining observability, automated remediation, and adaptive defense mechanisms to neutralize threats before they escalate into incidents. By enforcing Zero Trust principles at every AI decision point, CalypsoAI is defining a new standard for enterprise resilience in the age of agentic AI.
The 2025 RSAC Sandbox Innovation Finalists:
What’s Next?
Over the coming weeks, I’ll delve into each of these companies, exploring their specific solutions and their contribution to securing the future of AI. Stay tuned for the next installment, where we’ll explore how Aurascape is helping enterprises safely embrace AI.
Referring to my upcoming book: https://www.amazon.com/Agentic-AI-Theories-Practices-Progress/dp/3031900251




CalypsoAI's technology looks to do a great job on the front-end.
I suspect many people still have concerns about how their data is being used on the back-end.
We all know that the AI providers can promise not to mishandle our data, but breaches occur and promises are sometimes broken.
Any true solution has our data encrypted throughout the entire flow, so any leak of data is useless.
TinFoil (tinfoil.sh) claims to do just this by "[putting] large-language-model workloads inside GPU-backed secure enclaves, so every prompt, completion and model weight stays encrypted in transit and in use"
(I am in no way affiliated with TinFoil, I just think that their technology is incredible.)