Wallarm

Wallarm is an AI security and API security company focused on protecting production workloads rather than stopping at posture visibility. Its platform is built around a closed-loop model that discovers AI workloads and APIs, observes runtime behavior, enforces policy inline, and generates continuous evidence for governance and compliance. The current positioning centers on enterprises running AI on AWS, especially teams that need to understand what models, agents, MCP servers, APIs, and cloud assets are actually active in production.

Beyond AI governance, Wallarm also addresses the broader application and API attack surface with cloud-native protection, automated testing, and inventory-driven risk reduction. It supports modern API protocols and deployment patterns across cloud, Kubernetes, and hybrid environments, giving security teams a way to connect discovery, protection, response, and audit readiness in one operating model.

Offerings, Capabilities, and Integrations

Wallarm combines agentless discovery, inline enforcement, runtime observability, and automated security testing. Depending on the workload and operating model, customers can deploy through in-cluster, self-hosted, managed edge, connector-based, or out-of-band approaches. The platform supports AWS, Google Cloud, Microsoft Azure, Kubernetes, private data centers, and common traffic layers such as NGINX, Envoy, Kong, and MuleSoft.

Wallarm is designed to fit into existing security and operations workflows. Its integrations span incident response and ticketing tools such as PagerDuty, Opsgenie, Jira, and ServiceNow; collaboration channels such as Slack and Microsoft Teams; and analytics and SIEM environments such as Splunk, Sumo Logic, Microsoft Sentinel, IBM QRadar, and Datadog. It also supports webhooks, APIs, Fluentd, and Logstash for custom event delivery and downstream automation.

Products and Services

  • AI Hypervisor: Runtime governance for AI workloads on Amazon EKS that uses kernel-level eBPF instrumentation to observe AI agent behavior, enforce policy at the connection level, and generate continuous compliance evidence without code changes or sidecars.
  • Infrastructure Discovery: Continuous AWS inventory, change detection, and AI workload mapping that scans connected accounts with read-only access to surface cloud assets, APIs, IAM resources, and shadow AI across regions.
  • API Security: Real-time inline API protection that discovers and inventories APIs, blocks OWASP API Top 10 and abuse-driven threats, tracks sensitive data, and supports REST, GraphQL, gRPC, SOAP, and WebSocket.
  • API Security Testing: Automated testing for APIs and web assets that combines schema-based testing, threat replay, vulnerability scanning, passive detection, and CI/CD-oriented workflows, including Postman-based testing paths.
  • Wallarm WAF: Wallarm’s next-generation web application firewall capabilities for protecting web applications from common attack classes, applying virtual patches, and using WAF rules for fine-grained traffic controls.
  • Wallarm WAAP: Cloud-native web application and API protection that unifies web threat defense, API protection, bot and account takeover mitigation, and L7 DDoS controls in a single inline engine.
  • API Attack Surface Management: Agentless external discovery and assessment that scans domains, IP addresses, and network ranges to identify exposed APIs, missing WAF or WAAP coverage, and related security issues.
  • API Leak Management: Continuous detection and response for leaked API keys and secrets, including discovery of exposed credentials in public sources and controls to block their use across the API estate.
  • Security Edge: Managed edge deployment option that routes traffic through Wallarm-operated infrastructure for API and application protection, reducing customer hosting and operational overhead.

Target Customers

Wallarm targets enterprises and digital businesses that rely on APIs, microservices, and AI-enabled applications in production. Its strongest fit is organizations running AI on AWS and Amazon EKS that need continuous visibility into AI workloads, shadow AI, API dependencies, and runtime behavior without forcing code changes or slowing engineering delivery.

The main buying centers are application security, cloud security, platform engineering, DevSecOps, SOC, and compliance teams. Wallarm also aligns well with regulated and API-intensive sectors such as financial services, healthcare, ecommerce, and technology companies that need to secure public, partner, and internal APIs while keeping modern and legacy applications under a common protection and governance model.

Cloud Integrations and Marketplace

  • AWS Marketplace: Wallarm maintains AWS Marketplace presence for multiple offerings, including AI Hypervisor, Infrastructure Discovery, and API Security listings for inline traffic analysis and broader platform adoption on AWS.
  • Microsoft Azure Marketplace: Wallarm API Security Platform is listed in Microsoft Azure Marketplace for organizations protecting APIs, web applications, microservices, and serverless workloads in Azure environments.
  • Google Cloud Marketplace: Wallarm supports deployment in Google Cloud through a marketplace machine image for its node, giving GCP users a marketplace-based path to deploy protection in Google Cloud environments.

Key People

  • Shayne Higdon: Chief Executive Officer
  • Bill Berryman: Chief Revenue Officer
  • David Cramer: Chief Operating Officer
  • Ivan Demshin: SVP of Engineering
  • Tim Ebbers: Field Chief Technology Officer
  • Michelle Gerson: VP of Marketing
  • Stephen Ivey: VP of Customer Success
  • Ivan Novikov: Co-Founder
  • Stepan Ilyin: Co-Founder

Key Facts

  • Headquarters: Austin, Texas, United States
  • Employees: 176
  • Annual Revenue: $20M-$33M
  • Parent Company: None
  • Subsidiaries: None
  • Publicly Listed: Not publicly listed
wallarm

Enter a search