Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Zscaler acquired AI-security startup SPLX in a deal announced November 3, 2025, after the transaction closed October 31. The purchase adds AI asset discovery, automated red teaming, prompt hardening, runtime guardrails and governance capabilities to Zscaler’s Zero Trust Exchange. Zscaler’s broader aim is to protect AI systems before deployment as well as the users, data and traffic they handle at runtime.
What Zscaler bought
The buyer was Zscaler, Inc.; the acquired legal entity was SPLXAI Inc. Zscaler initially announced no financial terms. Its fiscal Q1 2026 Form 10-Q later reported $40.6 million in cash consideration and $16.6 million in grant-date fair value for restricted stock awards issued to certain continuing SPLX employees. The filing says the acquisition closed October 31, 2025.
The same filing reported aggregate consideration of $692 million for the SPLX and Red Canary acquisitions together. That figure is not the price of SPLX alone. Zscaler characterized SPLX as an early-stage U.S. technology company and said it planned to integrate its technology with existing AI Security offerings. Zscaler’s Form 10-Q provides the clearest accounting detail.
Later Zscaler material refers to its AI Red Teaming platform as “formerly SPLX,” indicating that the technology became part of Zscaler’s portfolio rather than remaining a separately marketed independent vendor. The available announcements do not establish a complete renaming timeline, customer-retention statistics or a universal SPLX product price.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11#1 Best Overall
What SPLX adds to Zscaler
| Capability | Practical purpose |
|---|---|
| AI asset discovery | Find models, applications, workflows, repositories, RAG systems and MCP servers across public and private deployments, according to Zscaler. |
| AI posture and risk assessment | Identify risky configurations, permissions, data paths and connected components. |
| Automated red teaming | Continuously probe AI systems for security, safety and reliability weaknesses, including through CI/CD pipelines. |
| Prompt hardening and runtime guardrails | Apply controls to prompts, model interactions, outputs and AI traffic. |
| Governance support | Provide ownership, policy, testing and audit evidence for internal governance programs. |
Zscaler says SPLX’s red-teaming technology includes more than 5,000 purpose-built and domain-specific attack simulations. That is a vendor claim, not an independently verified measure of comprehensive coverage.
In its Q1 FY2026 earnings-call commentary, Zscaler said the technology extended AI Security Posture Management to discovery of large language models, workflows and Model Context Protocol servers. It also described CI/CD testing for hallucination, bias and behavior drift, in addition to conventional security weaknesses. Read the earnings-call transcript.
Why AI discovery is different from application discovery
Knowing that an employee used ChatGPT does not reveal the AI system operating inside an enterprise. A modern deployment may include a foundation model, a fine-tuned model, prompt libraries, an agent workflow, identities, tool connectors, a retrieval-augmented-generation pipeline, vector databases and an MCP server.
Zscaler says SPLX can discover those components, including code repositories and private deployments. In practice, coverage depends on telemetry, integrations, permissions and whether activity passes through observable infrastructure. “AI asset discovery” should therefore be tested as a specific product capability, not treated as a guarantee that every ephemeral or unsanctioned asset will be found.
How the acquisition changes the Zero Trust Exchange strategy
- Discover: Identify sanctioned and unsanctioned AI applications and infrastructure.
- Assess: Map risk in models, workflows, permissions, configurations and data flows.
- Test before release: Run adversarial evaluations in development and CI/CD pipelines.
- Protect at runtime: Enforce access, data-protection rules, prompt controls and guardrails.
- Govern: Record ownership, approvals, testing results and policy evidence.
This is a shift from protecting AI use mainly at runtime to addressing the full lifecycle from development through deployment. It also gives Zscaler a platform-consolidation story: one security provider could connect discovery, testing, data protection, access and runtime enforcement instead of leaving customers to assemble separate tools.
What automated AI red teaming can and cannot do
Automated red teaming is continuous adversarial testing, not a one-time penetration test. Useful test areas include:
Rank #3
- Prompt injection and jailbreaks
- Sensitive-data extraction and output exfiltration
- Unsafe or excessive tool use by agents
- Overbroad identities and permissions
- Unsafe retrieval from poisoned or untrusted RAG sources
- Hallucination, factuality, toxicity and bias
- Behavior drift after a model, prompt or policy change
- Malicious interactions with MCP tools
Testing can improve coverage and expose regressions, but it cannot prove that an AI system is safe. Unknown attacks, flawed business logic, bad training data and harmful human decisions can remain outside a test library, including one described by Zscaler as containing more than 5,000 simulations.
Governance is not the same as compliance
Security seeks to prevent compromise, abuse, injection, data loss and unauthorized actions. Governance establishes ownership, permitted use, risk classification, approval processes, auditability and testing obligations. Safety and quality address reliability, bias, hallucinations and behavioral drift.
Zscaler positioned SPLX as helping customers move toward proactive protection and governance. Neither the announcement nor the cited filings identifies a regulatory certification or guarantees compliance with a particular law. Requirements also vary by country, industry and use case, so platform evidence still has to be matched to an organization’s legal and control framework.
Rank #4
What enterprise buyers should verify
- Whether discovery covers private models, shadow AI, agents, RAG components, vector stores, repositories and MCP servers—not only traffic visible to Zscaler.
- How direct API calls, developer laptops, private-cloud workloads and service-to-service traffic are observed.
- Whether red-team tests run in CI/CD without creating unusable pipeline delays or untriageable noise.
- How findings are prioritized, assigned and remediated, and whether developers can reproduce them.
- Where prompts, outputs, code, model metadata and test results are processed and retained.
- Which capabilities are available in the buyer’s geography, subscription edition and deployment model.
- How the product integrates with existing AI-SPM, application-security, SIEM and SOAR tools.
- Whether licensing is based on users, assets, workloads, models, transactions or traffic volume.
Trade-offs and unresolved questions
Consolidation may reduce the number of disconnected tools and give security teams a common policy layer. It can also increase dependence on one vendor, create migration and integration work, and make customers responsible for a larger volume of findings. Zscaler itself warned in its transaction materials about integrating the technology and retaining employees.
The acquisition does not establish that Zscaler finds every AI asset, replaces specialized model-security products, or protects every novel attack. A model may be well defended while its connected tool has dangerous permissions; prompt filters do not validate a poisoned RAG corpus; and governance controls do not automatically make an organization compliant.
Zscaler’s public materials also do not establish a standalone SPLX price or a universal feature matrix. Pricing and availability should be confirmed directly for the relevant edition, region, integrations and traffic or workload scope.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteBest Value
Competitive context
Zscaler is pursuing an integrated-platform approach. Buyers may compare it with broader security portfolios such as Microsoft security controls, Palo Alto Networks Prisma AIRS and Cisco AI Defense, or with specialists such as Protect AI and HiddenLayer. These are comparison candidates, not proof that one approach is universally superior or directly equivalent.
Bottom line for customers and investors
The SPLX acquisition is strategically significant because it adds the shift-left layer Zscaler needed to connect AI discovery and testing with its existing zero-trust, data-protection and runtime controls. The company is trying to make AI security a lifecycle discipline covering models, agents, tools, data and traffic—not merely a filter for chatbot prompts.
Whether that strategy delivers value will depend on real discovery coverage, CI/CD adoption, remediation quality, data-handling terms and the availability of the acquired capabilities in each customer’s subscription. The deal is a meaningful platform bet, but its announcement is not evidence that end-to-end AI security or regulatory compliance has already been achieved.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools




