AI security vendors in the DACH region 2026: who does what

In short
- In the DACH region, the term AI security bundles four different product categories: AI platforms, AI governance software, model and framework providers, and security products that inspect AI usage.
- Only the last category answers what employees actually type into AI tools. From the DACH region that is Lakera (now Check Point) and Patronus Protect, plus several US vendors.
- This overview lists headquarters, category and coverage for each vendor, with source and date. We leave ratings out. What a vendor does not describe on its pages, we do not claim either.
All statements as of September 7, 2026, from the vendors' public pages. Later changes are not reflected.
Four categories, one search term
Searching for "AI security vendor Germany" returns companies that have little in common. It helps to first settle the question you want answered:
| Question | Category | Typical vendors |
|---|---|---|
| Where should our employees use AI? | AI platform | Langdock, nele.ai |
| How do we document AI systems for the AI Act? | AI governance | trail, Modulos |
| Which models can we run in Europe? | model and framework providers | Aleph Alpha, deepset |
| What do employees actually type into AI tools, and what leaves the device? | AI security product | Lakera, Patronus Protect, US vendors |
Vendors based in the DACH region
Lakera (Zurich and San Francisco). Platform for AI agent security, AI red teaming and "Workforce AI Security", which according to the vendor covers browser extensions, desktop applications, SaaS copilots, developer tools and MCP. Acquired by Check Point in September 2025; the website now shows a San Francisco address and the Check Point copyright. Offered as API and SaaS. We found no open models; the data comes from the Gandalf game and the b3 benchmark. Lakera is the vendor closest to Patronus in scope, with a cloud architecture.
Langdock (Berlin). Platform for AI adoption: chat, agents, workflows and API with models from several providers, hosted in the EU, ISO 27001 and SOC 2 Type II according to the security page. Governance features for agents inside the platform. No component on the endpoint, no description of DLP or of visibility into AI usage outside the platform. Covered in detail in Langdock vs. Patronus Protect.
nele.ai (Hungen, Hesse). GDPR-oriented AI platform by GAL Digital GmbH: servers in Germany, ISO 27001, SAML SSO, an optional filter that pseudonymizes personal data, desktop apps for Mac and Windows, and on request a dedicated Llama 3 model in the customer's infrastructure. A chat platform, not a firewall.
deepset (Berlin). Maker of the open-source framework Haystack. Publishes the prompt injection classifier deberta-v3-base-injection (MIT license, English and German) on Hugging Face. Not a security product for endpoints, but a relevant building block for teams securing their own pipelines.
trail (Munich). AI governance software for the EU AI Act and ISO 42001: documentation, risk management, evidence. No endpoint scope.
Modulos (Zurich). ISO 42001-certified AI governance platform. Also documentation and compliance management, no endpoint scope.
Aleph Alpha (Heidelberg). Provider of sovereign language models for Europe, with offices in Berlin, Bayreuth and Munich. In April 2026 the merger with Cohere was announced. A model provider, not a security product.
Patronus Protect (Regensburg). AI firewall on the endpoint: detects every AI interaction on the device by behavior, redacts or blocks sensitive data before it is sent, inspects agent tool calls and MCP invocations, logs decisions locally as evidence for the AI Act. Own detection models under Apache 2.0 on Hugging Face, more than 25,000 downloads. Monitor is free, Protect is the full version.
To our knowledge, Patronus is the only vendor in the DACH region combining enforcement on the device, own open detection models and local AI Act logging in one product. If you know another one, write to us and we will add it.
US vendors that appear in DACH tenders
| Vendor | Based in | Approach | Note |
|---|---|---|---|
| Cyberhaven | Austin, Mountain View, office in Lausanne | endpoint agent plus browser extension, shadow AI discovery, prompt DLP | data lineage and data flow as the core concept |
| Prompt Security | Tel Aviv, part of SentinelOne | shadow AI, prompt injection, DLP; open tools ps-fuzz and ClawSec | Israel, not the US; listed here for market presence |
| Harmonic Security | San Francisco, office in London | browser extension, endpoint agent, MCP gateway, shadow AI discovery | mentions the EU AI Act on its home page |
| Nightfall AI | San Francisco | endpoint agents, browser plugins, prompt injection detection, MCP security | DLP heritage |
These vendors cover the category of endpoint-based AI security and are to be taken seriously. For companies in the DACH region the usual questions apply: where is content processed for analysis, where is support located, which law governs the contract.
How to tell the category apart
Three questions to any vendor settle within minutes which category it plays in:
- Does the product see ChatGPT in the browser when I do not open it through the product? Platforms: no. Governance tools: no. Security products: yes, through an extension, a proxy or an endpoint agent.
- Does it see a local model such as Ollama? Only products with a component on the device. Browser extensions do not see it, proxies do not either.
- Where is the prompt processed for inspection? In the vendor's cloud, or on the device. For GDPR this is the decisive difference, because the prompt itself can contain personal data.
Where Patronus fits in this landscape
Patronus replaces neither an AI platform nor governance software. Anyone rolling out Langdock or nele.ai still needs an answer to whether the workforce takes the approved path. Anyone using trail or Modulos for AI Act documentation still needs the raw data from operations: which AI systems run, which decisions were taken. Both come from the component on the device.
The details are on the AI firewall page. The models behind it are on the models page.
Sources
- Check Point on the Lakera acquisition: https://www.checkpoint.com/press-releases/check-point-acquires-lakera-to-deliver-end-to-end-ai-security-for-enterprises/
- Lakera Workforce AI Security: https://www.lakera.ai/workforce-ai-security
- Langdock security: https://langdock.com/security
- nele.ai: https://www.nele.ai/de/de
- deepset injection model: https://huggingface.co/deepset/deberta-v3-base-injection
- trail: https://www.trail-ml.com/
- Modulos: https://www.modulos.ai/
- Aleph Alpha and Cohere: https://cohere.com/blog/cohere-alephalpha-join-forces
- Cyberhaven: https://www.cyberhaven.com/
- Prompt Security: https://www.prompt.security/
- Harmonic Security: https://www.harmonic.security/
- Nightfall AI: https://www.nightfall.ai/
- As of September 7, 2026. Corrections to team@patronus.studio.
FAQ
Frequently asked questions
Which AI security vendors are based in the DACH region?
Headquartered in Germany, Austria or Switzerland: Lakera (Zurich and San Francisco, part of Check Point since 2025), Langdock (Berlin, AI platform), nele.ai (Hungen, AI platform), deepset (Berlin, framework and an open injection model), trail (Munich, AI governance), Modulos (Zurich, AI governance) and Patronus Protect (Regensburg, AI firewall on the endpoint).
What is the difference between an AI platform and an AI firewall?
An AI platform provides models, chat and agents in a controlled environment, usually hosted in the EU. An AI firewall sits on the device and inspects every AI interaction, whatever tool it goes through. The platform gives employees a safe place, the firewall sees whether they use it and protects every other path.
Is there a DACH vendor with open detection models?
Two. deepset publishes a prompt injection classifier (deberta-v3-base-injection, MIT license, English and German). Patronus Protect publishes seven model families under Apache 2.0, among them Wolf Defender for prompt injection, Orca Sonar for document types and the Husky models for agent tool calls.
Why do Cyberhaven, Nightfall or Harmonic show up in DACH tenders?
Because they occupy the category of endpoint-based AI security with a browser extension or agent, and they appear in tenders of international groups. They are based in the US (Cyberhaven with an office in Lausanne). If you need data processing and support in the EU, read the contracts carefully.