How Secure Are the Forbes AI 50? We Scanned All 50 Companies (2026)
The 50 most promising private AI companies have encryption down cold. The next layer of domain security, the controls that stop email interception, rogue certificates and DNS tampering, is still mostly switched off.
Key findings
- The basics are solved. 49 of 50 sites support TLS 1.3, none still accept the retired TLS 1.0 or 1.1, and all 50 publish a DMARC email policy.
- Only 22 of 50 block spoofed email outright. 24 send it to spam instead, and 4 (Applied Intuition, EliseAI, Rogo and Clay) don't act on it at all.
- One company out of 50 uses MTA-STS, and it's in testing mode, so no company on the list requires that its inbound email arrive encrypted.
- 10 companies turned on DNSSEC; 5 finished the job. The other 5 signed their DNS but never published the registrar record that makes the signatures count.
- Only 4 send all five recommended security headers. 32 have a Content-Security-Policy, but only Sierra's avoids settings that weaken it.
- The AI 50 run on the same few vendors. 46 of 50 use Google Workspace for email and 28 use Cloudflare for DNS.
- One company on the list appears in Have I Been Pwned: Suno (55,282,226 accounts).
The scorecard: all 50 companies
Each grade summarizes the checks LynxRadar weights: TLS, HSTS, email authentication, security headers, certificate hygiene, DNS configuration, known breaches and exposed software vulnerabilities. The average is 83.7 and the median 85. OpenAI leads with 98. Click any company for its full, live report.
| Report | |||||||
|---|---|---|---|---|---|---|---|
| OpenAIChatGPT and the GPT models | Foundation models | A+98 | Rejected | On | 4/5 | Yes | View → |
| DatabricksData and AI platform | Infrastructure & dev tools | A-92 | Rejected | On | 4/5 | Yes | View → |
| PerplexityAI answer engine | Search & productivity | A-92 | Rejected | On | 5/5 | Yes | View → |
| ReflectionAutonomous coding models | Foundation models | A-92 | Rejected | On | 3/5 | — | View → |
| SierraCustomer service agents | Vertical agents | A-92 | Rejected | On | 3/5 | Yes | View → |
| World Labs3D world models | Robotics & world models | A-92 | Rejected | On | 3/5 | — | View → |
| Black Forest LabsImage models (FLUX) | Generative media | B+88 | Rejected | On | 2/5 | Yes | View → |
| CognitionDevin and Windsurf | Coding | B+88 | Rejected | On | 2/5 | — | View → |
| FalGenerative media inference | Infrastructure & dev tools | B+88 | Rejected | On | 1/5 | — | View → |
| GensparkAI agent workspace | Search & productivity | B+88 | Rejected | Short | 4/5 | — | View → |
| GleanEnterprise search and agents | Search & productivity | B+88 | Rejected | On | 2/5 | — | View → |
| HarveyLegal AI | Vertical agents | B+88 | Rejected | On | 1/5 | Yes | View → |
| HeyGenAI video avatars | Generative media | B+88 | Rejected | On | 0/5 | Yes | View → |
| LegoraLegal AI | Vertical agents | B+88 | Rejected | On | 1/5 | Yes | View → |
| Physical IntelligenceRobot foundation models | Robotics & world models | B+88 | Spam folder | not checked | not checked | — | View → |
| ReplitAI app builder and IDE | Coding | B+88 | Rejected | On | 2/5 | — | View → |
| Safe SuperintelligenceSuperintelligence research lab | Foundation models | B+88 | Rejected | On | 0/5 | — | View → |
| Skild AIRobot foundation models | Robotics & world models | B+88 | Rejected | On | 0/5 | — | View → |
| SynthesiaAI video avatars | Generative media | B+88 | Rejected | On | 1/5 | — | View → |
| AbridgeClinical documentation | Healthcare | B85 | Spam folder | On | 4/5 | — | View → |
| Applied IntuitionAutonomous vehicle software | Robotics & world models | B85 | Not blocked | On | 4/5 | — | View → |
| CrusoeAI cloud and data centers | Infrastructure & dev tools | B85 | Spam folder | On | 4/5 | Yes | View → |
| Listen LabsAI customer research | Vertical agents | B85 | Spam folder | On | 3/5 | — | View → |
| LovableAI app builder | Coding | B85 | Spam folder | On | 5/5 | Yes | View → |
| MercorExpert talent for AI training | Data & talent | B85 | Spam folder | On | 4/5 | Yes | View → |
| Mistral AIOpen-weight and commercial LLMs | Foundation models | B85 | Spam folder | On | 5/5 | Yes | View → |
| RunwayVideo generation | Generative media | B85 | Spam folder | On | 4/5 | — | View → |
| SunoMusic generation | Generative media | B85 | Rejected | On | 3/5 | — | View → |
| AnthropicClaude models | Foundation models | B-82 | Rejected | Short | 1/5 | Yes | View → |
| RogoFinance research AI | Vertical agents | B-82 | Not blocked | On | 1/5 | — | View → |
| BasetenModel inference platform | Infrastructure & dev tools | B-80 | Spam folder | On | 2/5 | — | View → |
| Chai DiscoveryAI drug discovery | Healthcare | B-80 | Spam folder | On | 1/5 | — | View → |
| CohereEnterprise LLMs and search | Foundation models | B-80 | Spam folder | On | 2/5 | — | View → |
| CursorAI code editor | Coding | B-80 | Spam folder | On | 1/5 | Yes | View → |
| DecagonCustomer support agents | Vertical agents | B-80 | Spam folder | On | 2/5 | Yes | View → |
| EliseAIProperty and healthcare agents | Vertical agents | B-80 | Not blocked | On | 0/5 | — | View → |
| Fireworks AIInference platform | Infrastructure & dev tools | B-80 | Spam folder | On | 2/5 | — | View → |
| GammaAI presentations | Search & productivity | B-80 | Spam folder | Off | 4/5 | — | View → |
| Krea AICreative generation tools | Generative media | B-80 | Spam folder | On | 1/5 | — | View → |
| NotionWorkspace with AI | Search & productivity | B-80 | Spam folder | On | 2/5 | Yes | View → |
| OpenEvidenceMedical search for clinicians | Healthcare | B-80 | Spam folder | On | 0/5 | Yes | View → |
| SambaNova SystemsAI chips and inference | Infrastructure & dev tools | B-80 | Spam folder | On | 2/5 | — | View → |
| SpeakAI language tutor | Search & productivity | B-80 | Spam folder | On | 2/5 | Yes | View → |
| CyeraAI-native data security | Infrastructure & dev tools | C+78 | Rejected | On | 2/5 | — | View → |
| Thinking Machines LabAI research and products | Foundation models | C+78 | Rejected | Off | 2/5 | Yes | View → |
| ElevenLabsVoice AI | Generative media | C75 | Spam folder | Short | 1/5 | Yes | View → |
| MidjourneyImage generation | Generative media | C75 | Spam folder | Off | 5/5 | — | View → |
| ClaySales data and GTM agents | Vertical agents | C-70 | Not blocked | Off | 2/5 | Yes | View → |
| Surge AIData labeling | Data & talent | C-70 | Spam folder | Off | 2/5 | — | View → |
| Together AIInference and training cloud | Infrastructure & dev tools | C-70 | Spam folder | Off | 1/5 | Yes | View → |
Snapshot from 28 September 2026. "Spoofed email" is the domain's DMARC policy. "Short" HSTS means a max-age under 180 days. "Not checked" means the site rate-limited our scanner, so that check was left out of the score.
The basics are solved
Start with the good news. Every connection to these companies' websites is encrypted with a modern protocol. 49 of 50 support TLS 1.3, and Cyera still negotiates the older but still-secure TLS 1.2. Not one accepts TLS 1.0 or 1.1, which browsers retired in 2020. Certificates come from mainstream authorities: Google Trust Services, Let's Encrypt and Amazon.
Email authentication has also crossed a threshold. All 50 domains publish a DMARC record, the policy that tells receiving mail servers what to do with messages that fail sender checks. Google and Yahoo have required DMARC from bulk senders since February 2024, so for a company that sends product email at scale it's no longer optional.
Email: everyone publishes DMARC, fewer than half enforce it fully
Publishing DMARC and enforcing it are different things. A DMARC policy has three settings: p=none only monitors, p=quarantine sends failing mail to spam, and p=reject blocks it before it reaches anyone's inbox.
22 companies, including OpenAI, Anthropic, Databricks and Perplexity, reject spoofed mail. 24 stop at quarantine, which still lands a convincing fake in a spam folder where people do go looking. Applied Intuition, EliseAI, Rogo and Clay are at p=none, so a message forged to look like it came from their domain gets delivered normally.
For buyers this matters more than it sounds. One of the most common frauds against a vendor's customers is a fake invoice or "updated bank details" email sent from the vendor's own domain. DMARC at reject is the control that makes that exact forgery fail.
On the sending side, 18 of 50 use a hard-fail SPF record (-all) and most of the rest use soft fail (~all). With DMARC enforcing, the difference is small, but it shows how many teams have tightened every setting rather than just the headline one.
MTA-STS: one company out of 50
Email between mail servers is encrypted only if both sides agree to it, and the agreement happens in the clear. An attacker positioned on the network can strip the offer to encrypt, and the message falls back to plain text without anyone noticing. MTA-STS closes that gap: it's a published policy that tells other mail servers "only deliver to me over verified TLS."
Sierra is the only company on the list with an MTA-STS policy, and it's set to testing, which reports failures without blocking anything. Sierra also publishes a TLS-RPT record, so it gets daily reports on delivery failures. Every other company leaves its inbound email to opportunistic encryption.
This is the clearest gap in the whole study because the fix is small. With 46 of the 50 companies on Google Workspace, the setup is the same for almost all of them: host a short policy file, add two DNS records, and move from testing to enforce once the reports come back clean. Read the MTA-STS guide →
DNSSEC and CAA: switched on, not always finished
DNSSEC signs a domain's DNS records so that resolvers can detect forged answers, such as a redirect of the company's login page or mail servers to an attacker. It takes two steps: sign the zone at the DNS provider, then publish a DS record at the registrar so the rest of the internet knows to check the signatures.
10 of the 50 companies took the first step. Only 5 (Databricks, Abridge, Glean, Rogo and ElevenLabs) took the second. SambaNova Systems, Fal, Physical Intelligence, Genspark and Speak have signed zones with no DS record at the registrar, which means resolvers never validate the signatures. It's a one-record fix, and it's also the most common way DNSSEC rollouts stall.
CAA records are simpler still: a DNS entry naming which certificate authorities may issue certificates for the domain. 7 of 50 publish one (OpenAI, Mistral AI, Databricks, Together AI, Fal, Listen Labs and HeyGen). Without one, any publicly trusted certificate authority can issue a certificate for the domain, so a single CA with weak validation is enough for an attacker to get one.
Browser protections: HSTS and security headers
HSTS tells browsers to only ever connect to a site over HTTPS, closing the window where a first visit over plain HTTP can be intercepted. 43 of 50 send the header. Thinking Machines Lab, Together AI, Gamma, Clay, Midjourney and Surge AI don't send it on their homepage.
A few send HSTS with a lifetime too short to help: ElevenLabs' expires after 30 minutes, Anthropic's expires after one hour, and Genspark's expires after 30 days. The protection only covers visitors who've been to the site within that window, so a one-hour policy covers almost no one. The common recommendation is at least six months, and a year with preload (12 companies do this) bakes the rule into browsers themselves.
Security headers are instructions the site sends to the browser: don't let other sites frame this page, don't guess file types, don't leak full URLs to third parties. Only Mistral AI, Lovable, Perplexity and Midjourney send all five. Safe Superintelligence, OpenEvidence, Skild AI, EliseAI and HeyGen send none on their homepage.
Content-Security-Policy is the most powerful and the hardest to get right. 32 companies send one, but Sierra's is the only one free of settings like 'unsafe-inline' or 'unsafe-eval', which re-open the script-injection attacks CSP exists to stop. A CSP with those settings is common on marketing sites built on modern frameworks. It's better than nothing, but it's not the protection it looks like.
Who do you call? security.txt and bug bounties
A security.txt file (RFC 9116) tells researchers where to report a vulnerability. It's a small file, and its absence often means a report goes to a support inbox or nowhere. 22 of 50 companies publish one. OpenAI, Anthropic, Together AI and Sierra route reports to a public bug bounty or disclosure program on Bugcrowd or HackerOne.
For AI companies this matters more than usual. Prompt-injection, data-exfiltration and model-abuse reports are a new and fast-growing category, and researchers need a clear place to send them.
Known breaches
Suno is the only company on the list that appears in Have I Been Pwned, the public breach database. According to its HIBP entry, 55,282,226 accounts were exposed in a breach in November 2025 that was added to the database on 20 July 2026. The exposed data included email addresses, names, phone numbers, physical addresses, partial payment card details (card type, expiry and last four digits) and purchase history.
Configuration scores and breaches measure different things. Suno's domain configuration scores 85, around the list average. Most breaches start with stolen credentials, a compromised vendor or a vulnerable application, none of which a DNS or header check can see. Breach history is weighted in the LynxRadar score, but a good score is never evidence that a breach couldn't happen.
The AI 50 run on the same three vendors
46 of the 50 companies handle email through Google Workspace. 28 use Cloudflare for DNS, and 32 serve their website through Cloudflare; 21 host on Vercel. Those are sensible defaults, and each vendor is better at running its piece than a startup would be. The trade-off is correlated risk: an outage or misconfiguration at one of them lands on most of the list at once, and a phishing kit that imitates the Google Workspace login works against nearly all of them.
How the categories compare
Robotics & world models companies average highest (88.2) and Data & talent lowest (77.5), but with two to eight companies per group the differences between categories are smaller than the spread inside them. What kind of AI a company builds says little about how it runs its domain.
What the score does and doesn't tell you
An external scan sees what anyone on the internet can see: DNS, certificates, email policy and the headers a homepage sends. It's a fast, objective read on how carefully a company manages its public attack surface, and it's the same view an attacker starts with.
It can't see access controls, employee security training, how customer data is stored, or whether the company has SOC 2 or ISO 27001. A small lab with a one-page website (Safe Superintelligence scores 88) can outscore a company running a large product platform, simply because there's less to configure. Treat the grade as a first filter and a list of good questions, not a verdict.
Vetting an AI vendor? Six checks that take a minute
Everything in this study can be checked for any vendor before you sign. Here's what to look for, in order of how much it tells you:
- DMARC at
p=reject. If it's atnone, anyone can send email as that vendor, including invoices to you. - A security.txt or published disclosure policy. It shows someone owns security reports, and tells you where to send one.
- HSTS with a max-age of at least six months. Short or missing HSTS means nobody has reviewed the site's transport settings.
- No appearances in breach databases, or a clear public account of what happened and what changed.
- DNSSEC fully deployed and CAA records present. Rare, so treat them as a sign of a mature team rather than a requirement.
- MTA-STS in enforce mode. The strongest signal on this list: almost nobody has it, so the teams that do are paying close attention.
Check any vendor the same way
Enter a domain to see its grade and every check in this study. It's free, needs no login, and the scan is passive.
Frequently asked questions
Which Forbes AI 50 company has the best security score?
OpenAI scored highest at 98/100 (A+) in LynxRadar's scan on 2026-09-28. Reflection, Databricks, World Labs, Perplexity followed at 92. The list averaged 83.7.
How secure are the Forbes AI 50 companies overall?
Their basics are strong: 49 of 50 support TLS 1.3 and every company publishes a DMARC email policy. The next layer is mostly missing: 22 of 50 reject spoofed email, 5 have working DNSSEC, 7 publish CAA records and 1 use MTA-STS.
How many Forbes AI 50 companies block email spoofing?
22 of 50 set DMARC to p=reject, which blocks forged email outright. 24 use p=quarantine (sent to spam) and 4 use p=none, which lets spoofed email through.
What is MTA-STS and why do so few companies use it?
MTA-STS is a policy that tells other mail servers to deliver email to your domain only over verified, encrypted connections, which stops attackers from downgrading mail to plain text. Only 1 of the 50 companies publish one, likely because email works without it and nothing visibly breaks. Setup is a small policy file plus two DNS records.
Has any Forbes AI 50 company had a data breach?
Suno appears in the Have I Been Pwned breach database, with 55,282,226 accounts listed. It was the only company on the list with a breach recorded there at the time of our scan.
Is this a security audit?
No. It's a passive external scan of what anyone on the internet can see: DNS records, TLS, email policy and homepage headers. It can't assess internal controls, data handling or certifications like SOC 2, so treat the grade as a first filter, not a verdict.
How can I check an AI vendor's security myself?
Enter the vendor's domain at lynxradar.com. The free report covers the same 16 checks as this study, including DMARC, HSTS, security headers and breach history, and needs no login.
Methodology
We scanned the primary website domain of each company on the Forbes 2026 AI 50 list on 28 September 2026, using the same scanner that powers every LynxRadar report. Each domain was scanned 3 times and we publish the median run; 7 of 50 scores moved between runs. LynxRadar is not affiliated with Forbes, and neither Forbes nor the companies reviewed this study.
- Passive only. We read public DNS records, complete a normal TLS handshake and load the homepage like a browser would. No port scanning, no login attempts, no vulnerability probing.
- 16 checks per domain, including TLS versions, certificate hygiene, DMARC/SPF/DKIM, MTA-STS, DNSSEC, CAA, HSTS, five HTTP security headers, cookies, security.txt, breach databases and software fingerprinting against known CVEs.
- The score (0–100) weights TLS (20), DMARC (15), breaches (15), CVE exposure (15), HSTS (10), security headers (10), certificates (10) and DNS (5). MTA-STS, CAA and security.txt are reported but not scored. A check that couldn't run, for example because the site rate-limited us, is left out rather than counted as a failure.
- Point in time. Headers can vary between requests and companies change settings. Each company's linked report shows its current result and history.
- Corrections. If you work at one of these companies and something looks wrong, tell us or rescan your domain from its report page. We'll update this study when you do.
The full dataset is available as a CSV download under CC BY 4.0. Please cite "LynxRadar, Forbes AI 50 Security Study (2026)" with a link to this page.