News

ATHENE UP26@it-sa finalists: An interview with Blindsight

07/09/2026

Blindsight is one of the five finalists for the ATHENE UP26@it-sa Award

Blindsight provides transparency across the entire AI stack – from prompt injection to shadow AI. It was founded by ethical hacking expert Guilherme Santos, who repeatedly discovered the same vulnerabilities in supposedly secure AI systems. The aim: not to ban the use of AI, but to make it secure.

Your start-up in one sentence?

Blindsight provides transparency across a company’s entire AI stack and protects it end-to-end, from prompt injection through RAG and training data poisoning to shadow AI.

#AISecurity #ShadowAI #TrustworthyAI

How did your business idea come about?

Guilherme has carried out numerous assessments of AI systems and has repeatedly identified the same vulnerabilities. Even systems that were already secured by AI security tools remained vulnerable – thereby creating new risks in supposedly secure environments. That was the starting point: together with his team, he set about closing these gaps.

Through keynote speeches and live hacking demonstrations at conferences worldwide, Guilherme spoke with numerous CISOs and CEOs. Their feedback in early 2026 confirmed just how directly the technology addresses some of the most pressing pain points in the market and that Blindsight is on the right track.

How big is your team, who’s in it, and how did you all meet?

Blindsight comprises a core team of six, as well as four strategic advisers. The team came together through the cybersecurity community. The technical founders have known each other for over seven years and have previously worked together as cybersecurity experts.

Maurits met Guilherme and Mário in the spring of 2025 following their presentation at a cybersecurity conference in Zurich, which he had helped organise. Their shared interest in AI security and their complementary backgrounds marked the beginning of Blindsight.

Guilherme Santos (CEO) is one of the world’s leading ethical hackers and AI security experts. Over the past few years, he has carried out assessments and red teaming exercises for numerous large corporations. Prior to this, as a security architect at Kühne & Nagel, he was responsible for the secure implementation of AI and cloud technology.

Filipe Azevedo (CTO) is a Principal Application Security Engineer and was previously responsible for enterprise projects at Checkmarx. He has discovered several zero-day vulnerabilities and is in charge of development at Blindsight.

Filipa Barros, PhD (Head of Research), obtained her PhD in Computer Science from FCUP/LIACC. At Blindsight, she is responsible for research into the platform’s recognition methods and benchmarking, and leads the company’s scientific research and research collaborations.

Maurits de Knecht (CCO/CFO) is responsible for marketing and financial planning; he previously worked in the technology investment sector at G Squared and Mountain Capital Partners, and, together with cybersecurity entrepreneur Dr Cornelius Boersch, established a venture capital fund specialising in AI, DeepTech and security.

Mário Portocarrero (COO) oversees product design and validation in collaboration with design partners.

As a UX/UI designer, Diogo Ribeiro is responsible for design at Blindsight. His focus is on presenting complex security findings in such a way that security teams can act quickly.

The team’s strength lies in the fact that its expertise in adversarial ML, offensive security, data integrity and rigorous benchmarking has been integrated directly into the runtime and governance layers with the same high standards. Furthermore, the team has been expanded to include consultants who bring additional expertise in the areas of sales and go-to-market (GTM), AI governance and compliance, technical research into AI security, and strategy and governance.

Who benefits from your product or solution, and why?

Teams that develop or use AI and need to manage the risks this poses to their system landscape. This is particularly relevant in regulated sectors. Specifically, we make day-to-day work easier for:

  • CISOs who wish to reduce the risks associated with their AI systems – such as data breaches, prompt injection and misuse – whilst ensuring compliance with AI usage regulations, all on a single platform that generates the relevant reports at the touch of a button.
  • Executives and AI/innovation leads who want to keep pace with the rapid development of AI and enable their teams to utilise AI without having to accept the associated risks. Adversarial attacks using AI as a vector, data breaches and the misuse of AI by employees can be managed with our help, whilst maintaining full transparency over what is actually happening within your own AI stack.
  • Teams that want to use AI productively. Without safeguards in place, companies often react with blanket bans or severe restrictions. We ensure that AI remains authorised, rather than being blocked out of an abundance of caution.

What are your next steps?

Having bootstrapped our way to a high-performing product with our first paying customers in regulated sectors, we will launch a fundraising round this autumn, specifically targeting angel investors and VC funds. At the same time, we are expanding our commercial team (Forward Deployed Engineers, Account Executive, US GTM Lead) and broadening our channel partner network to include transformation and security consultancies as well as MSPs. In the US, we are actively establishing partnerships to secure early market access. In addition, we will be delivering keynote speeches at inter­national security and AI conferences and finalising our research collaboration with the ETH AI Centre on Agentic Security, the results of which we will publish. At the same time, we are having our threat detection capabilities independently validated through external benchmarks.

If everything goes according to plan, in twelve months’ time we will have an Annual Recurring Revenue (ARR) of around 1.75 million euros, eight SME and three enterprise clients in regulated sectors in Europe and the US, twelve active sales partners (channel partners) and two academic publications.

Why are you so convinced that you, of all people, will be successful?

Our strength lies in the combination of our in-depth threat detection and ease of use. Our background in cyber attacks gives us a clear advantage: we understand AI-based security threats from the attacker’s perspective and therefore know exactly how tools like ours can be circumvented.

This is complemented by a strong academic research base, which enables our models to detect a broader and deeper range of issues than the competition. And all this in a product that is easy to deploy and runs locally within our customers’ environments or in their private cloud. The data remains in their control.

Added to this is the commercial foundation: a team with genuine experience in sales, market entry, fundraising and venture capital. As a result, our technical expertise does not remain confined to research, but reaches the customer. Individual competitors may cover some aspects of this, but not the full picture.

What have been the biggest successes and challenges so far?

Initially, we focused on a solution for data poisoning, a potent class of attack that is becoming a serious problem for organisations using AI. We soon realised that we were ahead of market developments. Most organisations still lacked basic visibility into their AI systems, let alone the capacity to deal with poisoned training data.

In hindsight, starting there was not a mistake: it gave us our detection capabilities, and as the market has matured, this has become a genuine point of differentiation. We protect agents from this type of attack and enable the deployment of RAG systems without companies having to worry about vulnerabilities that most competitors still fail to address today. Discussions with CISOs about these advanced attacks have also shown us just how urgent the issue of AI visibility really is. This has shaped our product strategy and enabled us to close precisely the gap they are facing.

Why did you enter the ATHENE Startup Award UP26@it-sa?


The decisive factor was the opportunity to showcase our work at it-sa and meet the right people in the security sector. The award would also help in discussions with investors, at a time when we could really do with that. The Fraunhofer Institute’s call for research proposals, the network of industry partners and the validation of our work by a panel of experts made the decision an easy one.

show all news