How Secure Are the Forbes AI 50? We Scanned All 50 Companies (2026)

The 50 most promising private AI companies have encryption down cold. The next layer of domain security, the controls that stop email interception, rogue certificates and DNS tampering, is still mostly switched off.

49/50
support TLS 1.3, the newest encryption standard
22/50
tell mail servers to reject email that spoofs their domain
5/50
have working DNSSEC, which protects DNS answers from tampering
1/50
publish MTA-STS to require encrypted delivery of inbound email

Key findings

  1. The basics are solved. 49 of 50 sites support TLS 1.3, none still accept the retired TLS 1.0 or 1.1, and all 50 publish a DMARC email policy.
  2. Only 22 of 50 block spoofed email outright. 24 send it to spam instead, and 4 (Applied Intuition, EliseAI, Rogo and Clay) don't act on it at all.
  3. One company out of 50 uses MTA-STS, and it's in testing mode, so no company on the list requires that its inbound email arrive encrypted.
  4. 10 companies turned on DNSSEC; 5 finished the job. The other 5 signed their DNS but never published the registrar record that makes the signatures count.
  5. Only 4 send all five recommended security headers. 32 have a Content-Security-Policy, but only Sierra's avoids settings that weaken it.
  6. The AI 50 run on the same few vendors. 46 of 50 use Google Workspace for email and 28 use Cloudflare for DNS.
  7. One company on the list appears in Have I Been Pwned: Suno (55,282,226 accounts).
How many of the 50 have each control switched on
Number of Forbes AI 50 companies, 28 September 2026
Table stakes
DMARC policy published
50 / 50
TLS 1.3 supported
49 / 50
HSTS enabled
43 / 50
The next layer
DMARC set to reject
22 / 50
security.txt published
22 / 50
SPF hard fail (-all)
18 / 50
HSTS preload
12 / 50
CAA records
7 / 50
Working DNSSEC
5 / 50
MTA-STS
1 / 50

The scorecard: all 50 companies

Each grade summarizes the checks LynxRadar weights: TLS, HSTS, email authentication, security headers, certificate hygiene, DNS configuration, known breaches and exposed software vulnerabilities. The average is 83.7 and the median 85. OpenAI leads with 98. Click any company for its full, live report.

Report
OpenAIChatGPT and the GPT models Foundation models A+98 Rejected On 4/5 Yes View →
DatabricksData and AI platform Infrastructure & dev tools A-92 Rejected On 4/5 Yes View →
PerplexityAI answer engine Search & productivity A-92 Rejected On 5/5 Yes View →
ReflectionAutonomous coding models Foundation models A-92 Rejected On 3/5 — View →
SierraCustomer service agents Vertical agents A-92 Rejected On 3/5 Yes View →
World Labs3D world models Robotics & world models A-92 Rejected On 3/5 — View →
Black Forest LabsImage models (FLUX) Generative media B+88 Rejected On 2/5 Yes View →
CognitionDevin and Windsurf Coding B+88 Rejected On 2/5 — View →
FalGenerative media inference Infrastructure & dev tools B+88 Rejected On 1/5 — View →
GensparkAI agent workspace Search & productivity B+88 Rejected Short 4/5 — View →
GleanEnterprise search and agents Search & productivity B+88 Rejected On 2/5 — View →
HarveyLegal AI Vertical agents B+88 Rejected On 1/5 Yes View →
HeyGenAI video avatars Generative media B+88 Rejected On 0/5 Yes View →
LegoraLegal AI Vertical agents B+88 Rejected On 1/5 Yes View →
Physical IntelligenceRobot foundation models Robotics & world models B+88 Spam folder not checked not checked — View →
ReplitAI app builder and IDE Coding B+88 Rejected On 2/5 — View →
Safe SuperintelligenceSuperintelligence research lab Foundation models B+88 Rejected On 0/5 — View →
Skild AIRobot foundation models Robotics & world models B+88 Rejected On 0/5 — View →
SynthesiaAI video avatars Generative media B+88 Rejected On 1/5 — View →
AbridgeClinical documentation Healthcare B85 Spam folder On 4/5 — View →
Applied IntuitionAutonomous vehicle software Robotics & world models B85 Not blocked On 4/5 — View →
CrusoeAI cloud and data centers Infrastructure & dev tools B85 Spam folder On 4/5 Yes View →
Listen LabsAI customer research Vertical agents B85 Spam folder On 3/5 — View →
LovableAI app builder Coding B85 Spam folder On 5/5 Yes View →
MercorExpert talent for AI training Data & talent B85 Spam folder On 4/5 Yes View →
Mistral AIOpen-weight and commercial LLMs Foundation models B85 Spam folder On 5/5 Yes View →
RunwayVideo generation Generative media B85 Spam folder On 4/5 — View →
SunoMusic generation Generative media B85 Rejected On 3/5 — View →
AnthropicClaude models Foundation models B-82 Rejected Short 1/5 Yes View →
RogoFinance research AI Vertical agents B-82 Not blocked On 1/5 — View →
BasetenModel inference platform Infrastructure & dev tools B-80 Spam folder On 2/5 — View →
Chai DiscoveryAI drug discovery Healthcare B-80 Spam folder On 1/5 — View →
CohereEnterprise LLMs and search Foundation models B-80 Spam folder On 2/5 — View →
CursorAI code editor Coding B-80 Spam folder On 1/5 Yes View →
DecagonCustomer support agents Vertical agents B-80 Spam folder On 2/5 Yes View →
EliseAIProperty and healthcare agents Vertical agents B-80 Not blocked On 0/5 — View →
Fireworks AIInference platform Infrastructure & dev tools B-80 Spam folder On 2/5 — View →
GammaAI presentations Search & productivity B-80 Spam folder Off 4/5 — View →
Krea AICreative generation tools Generative media B-80 Spam folder On 1/5 — View →
NotionWorkspace with AI Search & productivity B-80 Spam folder On 2/5 Yes View →
OpenEvidenceMedical search for clinicians Healthcare B-80 Spam folder On 0/5 Yes View →
SambaNova SystemsAI chips and inference Infrastructure & dev tools B-80 Spam folder On 2/5 — View →
SpeakAI language tutor Search & productivity B-80 Spam folder On 2/5 Yes View →
CyeraAI-native data security Infrastructure & dev tools C+78 Rejected On 2/5 — View →
Thinking Machines LabAI research and products Foundation models C+78 Rejected Off 2/5 Yes View →
ElevenLabsVoice AI Generative media C75 Spam folder Short 1/5 Yes View →
MidjourneyImage generation Generative media C75 Spam folder Off 5/5 — View →
ClaySales data and GTM agents Vertical agents C-70 Not blocked Off 2/5 Yes View →
Surge AIData labeling Data & talent C-70 Spam folder Off 2/5 — View →
Together AIInference and training cloud Infrastructure & dev tools C-70 Spam folder Off 1/5 Yes View →

Snapshot from 28 September 2026. "Spoofed email" is the domain's DMARC policy. "Short" HSTS means a max-age under 180 days. "Not checked" means the site rate-limited our scanner, so that check was left out of the score.

The basics are solved

Start with the good news. Every connection to these companies' websites is encrypted with a modern protocol. 49 of 50 support TLS 1.3, and Cyera still negotiates the older but still-secure TLS 1.2. Not one accepts TLS 1.0 or 1.1, which browsers retired in 2020. Certificates come from mainstream authorities: Google Trust Services, Let's Encrypt and Amazon.

Email authentication has also crossed a threshold. All 50 domains publish a DMARC record, the policy that tells receiving mail servers what to do with messages that fail sender checks. Google and Yahoo have required DMARC from bulk senders since February 2024, so for a company that sends product email at scale it's no longer optional.

Email: everyone publishes DMARC, fewer than half enforce it fully

Publishing DMARC and enforcing it are different things. A DMARC policy has three settings: p=none only monitors, p=quarantine sends failing mail to spam, and p=reject blocks it before it reaches anyone's inbox.

What happens to email that spoofs the company's domain
DMARC policy of the 50 companies
Rejected (p=reject) Sent to spam (p=quarantine) Delivered (p=none)

22 companies, including OpenAI, Anthropic, Databricks and Perplexity, reject spoofed mail. 24 stop at quarantine, which still lands a convincing fake in a spam folder where people do go looking. Applied Intuition, EliseAI, Rogo and Clay are at p=none, so a message forged to look like it came from their domain gets delivered normally.

For buyers this matters more than it sounds. One of the most common frauds against a vendor's customers is a fake invoice or "updated bank details" email sent from the vendor's own domain. DMARC at reject is the control that makes that exact forgery fail.

On the sending side, 18 of 50 use a hard-fail SPF record (-all) and most of the rest use soft fail (~all). With DMARC enforcing, the difference is small, but it shows how many teams have tightened every setting rather than just the headline one.

MTA-STS: one company out of 50

Email between mail servers is encrypted only if both sides agree to it, and the agreement happens in the clear. An attacker positioned on the network can strip the offer to encrypt, and the message falls back to plain text without anyone noticing. MTA-STS closes that gap: it's a published policy that tells other mail servers "only deliver to me over verified TLS."

Sierra is the only company on the list with an MTA-STS policy, and it's set to testing, which reports failures without blocking anything. Sierra also publishes a TLS-RPT record, so it gets daily reports on delivery failures. Every other company leaves its inbound email to opportunistic encryption.

This is the clearest gap in the whole study because the fix is small. With 46 of the 50 companies on Google Workspace, the setup is the same for almost all of them: host a short policy file, add two DNS records, and move from testing to enforce once the reports come back clean. Read the MTA-STS guide →

DNSSEC and CAA: switched on, not always finished

DNSSEC signs a domain's DNS records so that resolvers can detect forged answers, such as a redirect of the company's login page or mail servers to an attacker. It takes two steps: sign the zone at the DNS provider, then publish a DS record at the registrar so the rest of the internet knows to check the signatures.

10 of the 50 companies took the first step. Only 5 (Databricks, Abridge, Glean, Rogo and ElevenLabs) took the second. SambaNova Systems, Fal, Physical Intelligence, Genspark and Speak have signed zones with no DS record at the registrar, which means resolvers never validate the signatures. It's a one-record fix, and it's also the most common way DNSSEC rollouts stall.

CAA records are simpler still: a DNS entry naming which certificate authorities may issue certificates for the domain. 7 of 50 publish one (OpenAI, Mistral AI, Databricks, Together AI, Fal, Listen Labs and HeyGen). Without one, any publicly trusted certificate authority can issue a certificate for the domain, so a single CA with weak validation is enough for an attacker to get one.

Browser protections: HSTS and security headers

HSTS tells browsers to only ever connect to a site over HTTPS, closing the window where a first visit over plain HTTP can be intercepted. 43 of 50 send the header. Thinking Machines Lab, Together AI, Gamma, Clay, Midjourney and Surge AI don't send it on their homepage.

A few send HSTS with a lifetime too short to help: ElevenLabs' expires after 30 minutes, Anthropic's expires after one hour, and Genspark's expires after 30 days. The protection only covers visitors who've been to the site within that window, so a one-hour policy covers almost no one. The common recommendation is at least six months, and a year with preload (12 companies do this) bakes the rule into browsers themselves.

Security header adoption
Companies sending each header on their homepage, of 49 checked
Content-Security-Policy
32 / 49
X-Content-Type-Options
27 / 49
X-Frame-Options
27 / 49
Referrer-Policy
19 / 49
Permissions-Policy
7 / 49

Security headers are instructions the site sends to the browser: don't let other sites frame this page, don't guess file types, don't leak full URLs to third parties. Only Mistral AI, Lovable, Perplexity and Midjourney send all five. Safe Superintelligence, OpenEvidence, Skild AI, EliseAI and HeyGen send none on their homepage.

Content-Security-Policy is the most powerful and the hardest to get right. 32 companies send one, but Sierra's is the only one free of settings like 'unsafe-inline' or 'unsafe-eval', which re-open the script-injection attacks CSP exists to stop. A CSP with those settings is common on marketing sites built on modern frameworks. It's better than nothing, but it's not the protection it looks like.

A caveat on headersWe check each company's homepage, which is usually a marketing site on Vercel, Webflow or similar. The product (the app you log in to) often lives on a separate subdomain with its own, usually stricter, configuration. A weak homepage header set is a signal worth asking about, not proof the product is exposed.

Who do you call? security.txt and bug bounties

A security.txt file (RFC 9116) tells researchers where to report a vulnerability. It's a small file, and its absence often means a report goes to a support inbox or nowhere. 22 of 50 companies publish one. OpenAI, Anthropic, Together AI and Sierra route reports to a public bug bounty or disclosure program on Bugcrowd or HackerOne.

For AI companies this matters more than usual. Prompt-injection, data-exfiltration and model-abuse reports are a new and fast-growing category, and researchers need a clear place to send them.

Known breaches

Suno is the only company on the list that appears in Have I Been Pwned, the public breach database. According to its HIBP entry, 55,282,226 accounts were exposed in a breach in November 2025 that was added to the database on 20 July 2026. The exposed data included email addresses, names, phone numbers, physical addresses, partial payment card details (card type, expiry and last four digits) and purchase history.

Configuration scores and breaches measure different things. Suno's domain configuration scores 85, around the list average. Most breaches start with stolen credentials, a compromised vendor or a vulnerable application, none of which a DNS or header check can see. Breach history is weighted in the LynxRadar score, but a good score is never evidence that a breach couldn't happen.

The AI 50 run on the same three vendors

46 of the 50 companies handle email through Google Workspace. 28 use Cloudflare for DNS, and 32 serve their website through Cloudflare; 21 host on Vercel. Those are sensible defaults, and each vendor is better at running its piece than a startup would be. The trade-off is correlated risk: an outage or misconfiguration at one of them lands on most of the list at once, and a phishing kit that imitates the Google Workspace login works against nearly all of them.

How the categories compare

Score range by category
Line spans lowest to highest score; dot marks the average. Scale 60–100.
Robotics & world models (4)
88.2
Foundation models (7)
86.1
Coding (4)
85.2
Search & productivity (6)
84.7
Vertical agents (8)
83.1
Generative media (8)
83.0
Healthcare (3)
81.7
Infrastructure & dev tools (8)
81.6
Data & talent (2)
77.5
60708090100

Robotics & world models companies average highest (88.2) and Data & talent lowest (77.5), but with two to eight companies per group the differences between categories are smaller than the spread inside them. What kind of AI a company builds says little about how it runs its domain.

What the score does and doesn't tell you

An external scan sees what anyone on the internet can see: DNS, certificates, email policy and the headers a homepage sends. It's a fast, objective read on how carefully a company manages its public attack surface, and it's the same view an attacker starts with.

It can't see access controls, employee security training, how customer data is stored, or whether the company has SOC 2 or ISO 27001. A small lab with a one-page website (Safe Superintelligence scores 88) can outscore a company running a large product platform, simply because there's less to configure. Treat the grade as a first filter and a list of good questions, not a verdict.

Vetting an AI vendor? Six checks that take a minute

Everything in this study can be checked for any vendor before you sign. Here's what to look for, in order of how much it tells you:

  1. DMARC at p=reject. If it's at none, anyone can send email as that vendor, including invoices to you.
  2. A security.txt or published disclosure policy. It shows someone owns security reports, and tells you where to send one.
  3. HSTS with a max-age of at least six months. Short or missing HSTS means nobody has reviewed the site's transport settings.
  4. No appearances in breach databases, or a clear public account of what happened and what changed.
  5. DNSSEC fully deployed and CAA records present. Rare, so treat them as a sign of a mature team rather than a requirement.
  6. MTA-STS in enforce mode. The strongest signal on this list: almost nobody has it, so the teams that do are paying close attention.

Check any vendor the same way

Enter a domain to see its grade and every check in this study. It's free, needs no login, and the scan is passive.

Frequently asked questions

Which Forbes AI 50 company has the best security score?

OpenAI scored highest at 98/100 (A+) in LynxRadar's scan on 2026-09-28. Reflection, Databricks, World Labs, Perplexity followed at 92. The list averaged 83.7.

How secure are the Forbes AI 50 companies overall?

Their basics are strong: 49 of 50 support TLS 1.3 and every company publishes a DMARC email policy. The next layer is mostly missing: 22 of 50 reject spoofed email, 5 have working DNSSEC, 7 publish CAA records and 1 use MTA-STS.

How many Forbes AI 50 companies block email spoofing?

22 of 50 set DMARC to p=reject, which blocks forged email outright. 24 use p=quarantine (sent to spam) and 4 use p=none, which lets spoofed email through.

What is MTA-STS and why do so few companies use it?

MTA-STS is a policy that tells other mail servers to deliver email to your domain only over verified, encrypted connections, which stops attackers from downgrading mail to plain text. Only 1 of the 50 companies publish one, likely because email works without it and nothing visibly breaks. Setup is a small policy file plus two DNS records.

Has any Forbes AI 50 company had a data breach?

Suno appears in the Have I Been Pwned breach database, with 55,282,226 accounts listed. It was the only company on the list with a breach recorded there at the time of our scan.

Is this a security audit?

No. It's a passive external scan of what anyone on the internet can see: DNS records, TLS, email policy and homepage headers. It can't assess internal controls, data handling or certifications like SOC 2, so treat the grade as a first filter, not a verdict.

How can I check an AI vendor's security myself?

Enter the vendor's domain at lynxradar.com. The free report covers the same 16 checks as this study, including DMARC, HSTS, security headers and breach history, and needs no login.

Methodology

We scanned the primary website domain of each company on the Forbes 2026 AI 50 list on 28 September 2026, using the same scanner that powers every LynxRadar report. Each domain was scanned 3 times and we publish the median run; 7 of 50 scores moved between runs. LynxRadar is not affiliated with Forbes, and neither Forbes nor the companies reviewed this study.

  • Passive only. We read public DNS records, complete a normal TLS handshake and load the homepage like a browser would. No port scanning, no login attempts, no vulnerability probing.
  • 16 checks per domain, including TLS versions, certificate hygiene, DMARC/SPF/DKIM, MTA-STS, DNSSEC, CAA, HSTS, five HTTP security headers, cookies, security.txt, breach databases and software fingerprinting against known CVEs.
  • The score (0–100) weights TLS (20), DMARC (15), breaches (15), CVE exposure (15), HSTS (10), security headers (10), certificates (10) and DNS (5). MTA-STS, CAA and security.txt are reported but not scored. A check that couldn't run, for example because the site rate-limited us, is left out rather than counted as a failure.
  • Point in time. Headers can vary between requests and companies change settings. Each company's linked report shows its current result and history.
  • Corrections. If you work at one of these companies and something looks wrong, tell us or rescan your domain from its report page. We'll update this study when you do.

The full dataset is available as a CSV download under CC BY 4.0. Please cite "LynxRadar, Forbes AI 50 Security Study (2026)" with a link to this page.

Related guides