Zscaler acquired AI-security company SPLX to strengthen its enterprise AI-security platform—not to add a consumer chatbot or a general-purpose AI assistant. The deal adds technology for discovering AI assets, managing AI-security posture, continuously red-teaming AI applications and governing AI systems across development and production.
Zscaler announced the transaction on November 3, 2025; its SEC filings say it legally closed on October 31, 2025. The disclosed consideration was $40.6 million in cash plus restricted-stock awards with a $16.6 million grant-date fair value, subject to employee-service conditions.
What Zscaler bought
SPLX, formerly known as SplxAI, focused on security for AI applications and the broader AI lifecycle. Before the acquisition, it marketed automated AI red teaming, AI-asset management, real-time threat detection and response, prompt security, governance and compliance, and vulnerability discovery for generative-AI applications. SPLX describes the transaction at splx.ai.
Zscaler says the acquired technology now contributes to capabilities including:
Recommended Free Tools
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
- AI asset discovery and management
- AI security posture management (AI-SPM)
- Automated and continuous AI red teaming
- AI threat inspection and prompt hardening
- Governance, policy enforcement and remediation
- Discovery of large language models, AI workflows and Model Context Protocol (MCP) servers
These functions address security risks in enterprise-built models, copilots, agents, developer pipelines and tool connections. They are different from adding AI features for ordinary Zscaler users.
Zscaler’s acquisition announcement and its AI Security overview describe the combined positioning.
Why Zscaler wanted SPLX
Enterprises are deploying public and private large language models, AI applications, agents and MCP-connected workflows while employees also use unapproved “shadow AI.” Those systems create risks that conventional network controls may not see: prompt injection, jailbreaks, unsafe tool permissions, data leakage, supply-chain weaknesses and behavior that changes after deployment.
Zscaler already controlled users’ access to cloud services through its Zero Trust Exchange, identity-aware policies, inline inspection and data-security controls. SPLX extended the story toward the AI systems themselves, especially during development and testing. Zscaler’s stated strategy is to connect discovery and pre-deployment testing with access control and runtime enforcement.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteHow the combined AI-security lifecycle works
- Discover: Inventory AI applications, models, agents, workflows, pipelines and MCP servers, including assets that may not be centrally approved.
- Assess: Examine configuration, access, data connections, supply-chain and behavioral risks.
- Test: Run automated red-team attacks against AI applications and repeat them as systems change.
- Govern: Apply policy to users, applications, models, prompts, responses and connected tools.
- Protect at runtime: Inspect live AI traffic and block attacks, data leakage and policy violations.
- Remediate: Feed findings into development and operational workflows so weaknesses can be fixed.
This division matters. SPLX primarily strengthened the discover-and-test portions of Zscaler’s AI-security proposition, while Zscaler supplied much of the inline access, identity, data-loss-prevention and runtime-enforcement context.
Rank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
What the new capabilities do
AI asset discovery and posture management
Zscaler says its platform can map AI applications, models, workflows, pipelines and MCP servers. AI-SPM is intended to identify risky configurations and relationships across those assets. Discovery can expose shadow AI, but completeness and classification depend on deployment architecture, telemetry and integrations; an inventory is not automatically perfect.
Automated AI red teaming
Zscaler has reported more than 5,000 purpose-built and domain-specific attack simulations. The company cites testing for prompt injection, jailbreaks, hallucination, bias, behavior drift, prompt extraction and other unsafe behavior. The figure is a vendor-reported attack-library count, not an independent benchmark of detection or remediation quality. Red teaming finds weaknesses; it does not guarantee that attacks will be prevented.
Zscaler later said its AI Red Teaming platform was formerly SPLX in an announcement with OpenAI: Zscaler–OpenAI announcement.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRuntime and access controls
Zscaler separately markets inline controls for AI prompts and responses, including data-loss prevention, content moderation and blocking of AI-specific attacks. Its AI Guard materials describe protections for prompt injection, jailbreaks, malicious URLs, invisible text, sensitive-data leakage and inappropriate responses: Zscaler AI Guard.
These controls address several different layers:
| Layer | Primary question |
|---|---|
| AI access security | Can employees use public AI services safely and according to policy? |
| AI application security | Are enterprise-built applications, prompts and tool calls resilient to attack? |
| AI model security | Are models, data pipelines and supply chains trustworthy? |
| AI runtime security | What are live prompts, responses, tools and data flows doing? |
| AI governance | Are assets inventoried, accountable, compliant and subject to enforceable policy? |
Transaction value and dates
| Item | Disclosed detail |
|---|---|
| Legal closing | October 31, 2025 |
| Public announcement | November 3, 2025 |
| Cash consideration | $40.6 million |
| Restricted stock awards | $16.6 million grant-date fair value, subject to future employee service |
The closing and consideration figures come from Zscaler’s SEC filing and its business-combination disclosure.
Rank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
Zscaler also disclosed $692.0 million of aggregate purchase-price consideration for SPLX and Red Canary together during the first quarter of fiscal 2026. That amount is not the price of SPLX alone: Zscaler’s quarterly filing.
What happened to SPLX as a standalone product?
SPLX’s homepage now says the company is part of Zscaler: splx.ai. Zscaler presents the technology within its AI Security and AI Protect portfolio rather than as an independent vendor product. Its later filings list AI Asset Management, AI Access Security and AI Red Teaming among the portfolio’s capabilities: Zscaler AI Protect.
As of August 18, 2026, public materials establish integration and product positioning, but not a complete feature-by-feature migration matrix. Buyers should not assume that every former SPLX feature has the same name, interface, SKU or service level inside AI Protect.
Zscaler’s Q1 fiscal 2026 earnings-call materials said SPLX was being used to extend AI-SPM, continuously test AI applications at scale and integrate testing with customers’ CI/CD pipelines: earnings-call transcript.
What enterprise buyers should evaluate
- Coverage: public AI services, private endpoints, custom applications, models, agents and MCP servers.
- Deployment: inline proxy, API gateway, CI/CD integration, endpoint agent, SaaS console or self-hosted option.
- Testing depth: whether tests understand tools, data sources, permissions and business context rather than only static jailbreaks.
- Remediation: actionable policy, code or configuration changes instead of findings alone.
- Data handling: where prompts, responses, telemetry and model artifacts are processed and retained.
- Integration: connections to CI/CD, SIEM, SOAR, ticketing, GRC and identity systems.
- Identity: attribution to a human user, agent, application or service account.
- Performance: latency added by inline inspection and the effect on AI workloads.
- Evidence: reproducible attack records and audit-ready retention.
- Licensing: which AI Protect modules are included in an existing Zscaler agreement.
Trade-offs and limitations
Platform consolidation versus specialist depth
A single Zscaler platform could combine discovery, DLP, access policy, red teaming and runtime controls. The trade-off is that a broad platform may offer less specialist depth in one area than a dedicated AI-security or evaluation vendor.
Rank #4
- Runs UniFi Network for full-stack network management
- Manages 30+ UniFi Network devices and 300+ clients
- 1 Gbps routing with IDS/IPS
- Multi-WAN load balancing
- 0.96" LCM status display
Inline protection does not replace pre-production testing
Runtime controls can block or contain attacks, but they cannot substitute for testing before release. Models, prompts, tools, users and data change, so organizations generally need both development-stage testing and live controls.
Free tools Windows power users keep installed
One-click scans. No signup required.
More tests can mean more noise and cost
A large attack library may improve coverage while producing false positives or additional testing consumption. Ask how findings are prioritized, how business context is incorporated and how frequently tests run.
Availability and pricing remain sales-led
Zscaler’s pricing and plans page does not publish a simple standalone price for AI Protect or AI red teaming. Final pricing can depend on existing Zscaler commitments, users, AI traffic volume, deployment model and selected modules.
Alternatives
Palo Alto Networks Prisma AIRS
Palo Alto positions Prisma AIRS across AI runtime security, model security, AI red teaming, application and agent protection, posture management and API controls. Relevant materials include AI Model Security, Runtime Security, AI Red Teaming and documentation. It may fit organizations already standardized on Palo Alto Networks; its public pages direct prospects to a sales process rather than list a price.
Promptfoo
Promptfoo is a more developer-oriented evaluation and red-teaming option. Its pricing page lists a free Community plan with up to 10,000 red-team probes per month, local or self-hosted execution and custom-priced enterprise and on-premise options. It can suit teams wanting CI/CD workflows and open-source flexibility, but it is not a replacement for a unified network, identity, DLP and runtime-enforcement platform. The same page says Promptfoo is now part of OpenAI; that corporate status can change and should be confirmed when purchasing.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Bottom line for buyers
SPLX gives Zscaler a stronger AI-lifecycle-security story, especially for asset discovery, AI-SPM and automated red teaming. The strategic value is the connection between finding AI systems, testing them, governing them and applying runtime controls through the Zero Trust Exchange. The acquisition announcement and vendor-reported attack counts do not independently prove superior effectiveness, complete feature integration or universal discovery. Enterprises should validate coverage, data handling, deployment, evidence, remediation and licensing in a proof of concept.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




