+ Incentive compensation + Bonus + Restricted stock units
F5 offers multi-cloud application services and security to keep apps secure and available across different hosting environments. Its products include web application and API protection (WAF and API security), bot defense, fraud prevention, and application delivery features like load balancing and access management. The solutions protect and accelerate applications wherever they run, combining security with delivery in a single toolkit, sold as licenses, subscriptions, and support contracts, plus professional services. The goal is to help customers securely deliver fast, reliable applications across any cloud or data center while reducing abuse and ensuring smooth user access.
Company Size
5,001-10,000
Company Stage
IPO
Headquarters
Seattle, Washington
Founded
1996
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Comprehensive medical, dental, & vision coverage
Paid employee life & disability insurance
Employee Assistance Program (EAP)
Competitive pay
Employee Stock Purchase Plan
401(k) with company match
Health and daycare saving accounts (HSA and FSAs)
Tuition assistance
Adoption assistance
20 days of vacation and 25 days of vacation after year 5
10 days of sick leave
8 Weeks Paid FMLA & Family Leave
11 paid holidays
Headspace (Meditation App)
F5 positioned as market shaper in the Gartner Emerging Market Quadrant for AI Application Security. F5 | Published 22 Sept 2026 COMPANY NEWS: To us, the recognition underscores F5's ability to secure AI across cloud, on-premises, and air-gapped environments at enterprise scale F5 - 22 September - (NASDAQ: FFIV), the global leader in delivering and securing every app and API, today announced it has been positioned by Gartner(R) in the Market Shapers quadrant of the September 2026 Emerging Market Quadrant for AI Application Security - one of only two vendors to be recognised in that position.1 According to Gartner, vendors evaluated in the Emerging Market Quadrant for AI Application Security are assessed across two axes: potential for market disruption and potential to execute. "Enterprises are not running AI in a lab. They are running it inside regulated networks, behind APIs, and across agents that authenticate and act on their own," said John Maddison, Chief Marketing Officer at F5. "Enterprises cannot assemble a security posture from dozens of disparate point products. More than 40 vendors are competing to secure enterprise AI, and most are solving one slice of the problem. In our view, F5's positioning in the Market Shapers quadrant offers confirmation of a straightforward conviction: security leaders cannot govern what they cannot see, and AI cannot be secured from the outside in. F5 secures AI where enterprises actually run it." Securing AI where enterprises run it Enterprise AI has inverted the traditional security model. Today's AI systems operate with greater access, autonomy, and speed than human users are capable of, and the pace of adoption is outrunning the controls meant to govern it. F5's 2026 State of Application Strategy Report found that 88 per cent of organisations have already encountered at least one AI-related operational or security challenge, and 98 per cent are preparing for agentic AI. Meeting these challenges takes more than a collection of point products. AI application security spans the models and applications themselves, the agents that act on their behalf, the MCP servers and APIs that connect them, and the data they can reach. Securing that expansive surface calls for four essential components: * A comprehensive platform with centralised management across every AI workflow * Proven application security capabilities extended into agent-based controls, where intent-aware access control and continuous runtime monitoring govern what an autonomous agent is permitted to do * Adversarial testing wired directly into automated runtime defences, so what red teaming uncovers becomes what production enforces * Secure, air-gapped deployment for regulated sectors where sovereignty is not optional By bringing these capabilities together, F5 is shaping the AI security market and delivering substantive protections to security leaders. F5's approach is grounded in the premise that has shaped the company since its founding: security has to live where traffic flows. Every model call, agent action, and MCP connection traverses the network and application layers, where F5 already delivers and secures applications and APIs for the world's largest banks, carriers, governments, and consumer brands. That vantage point is what allows F5 to unify governance, discovery, testing, runtime protection, and observability - across generative and agentic AI - into a continuous loop rather than a collection of disparate tools, and to deliver those capabilities across hybrid multicloud, on-premises, air-gapped, private cloud, hybrid, and public cloud environments, including those where data residency and sovereignty are non-negotiable. It also shows up in measured performance. F5 AI Guardrails demonstrated up to 98.4 per cent security efficacy in independent testing, enforcing protections inline at the point of interaction rather than inspecting after the fact. F5 AI Red Team stress-tests AI systems against more than 140,000 attack patterns drawn from the industry's deepest AI threat database and converts what it finds directly into enforceable runtime defences. And because F5 discovers AI activity at the network layer, security teams gain visibility into every model, agent, and MCP call - including shadow AI - without a single application integration or code change. "The AI application security market is going to consolidate around vendors who can operate at enterprise scale, in regulated environments, with real traffic and real consequences," Maddison added. "F5's 30 years of experience in these demanding environments gives our customers the foundation to confidently and securely build for the future with AI." Customer demand for F5's AI security solutions is growing as the gap between AI adoption and AI control widens. In its third quarter fiscal year 2026 earnings results, F5 reported that the number of customers purchasing F5 solutions for AI security doubled quarter-over-quarter. Additional information on F5's AI security portfolio is available at f5.com/ai. Supporting resources
F5 and Salesforce announced an integration on 2 September, embedding F5 AI Guardrails into MuleSoft's Agent Fabric Omni Gateway. The partnership aims to address security risks in agentic AI deployments, including prompt injection and data leakage. F5 reported Q3 FY26 revenue of $865 million, up 11% year-over-year, with non-GAAP operating margin at 35.0%. Salesforce posted Q2 FY27 revenue of $11.3 billion, also up 11%, with non-GAAP operating margin of 34.1%. Salesforce raised full-year FY27 revenue guidance to $46.1 billion–$46.4 billion. Both companies operate at similar profitability levels. Salesforce leads in scale with $33.5 billion in cRPO backlog, whilst F5 benefits from specialised AI security positioning. Agentforce ARR grew 210% year-over-year, nearing $3.9 billion.
F5 announced the upcoming availability of F5 Workforce AI Security, an agentless offering within its AI Security Platform that provides visibility and policy control over workforce AI activity. The product addresses how employees delegate work to AI agents that can access enterprise systems and manipulate data using user permissions. According to F5's 2026 State of Application Strategy Report, 66% of organisations already permit AI to automatically adjust policies and configurations. The new offering will enable organisations to govern workforce AI use, understand identity and intent, control agent actions before execution, and enforce policy across browsers, coding agents, and other tools. F5 Workforce AI Security extends capabilities F5 introduced to its AI Security Platform in June and August 2026. The product will be generally available beginning October 2026.
F5 and MuleSoft, a Salesforce company, collaborate to deliver inline security and governance for Agent Fabric and agentic AI applications. F5 announced a technology integration with MuleSoft, bringing F5 AI Guardrails - part of the F5 AI Security Platform - directly into Agent Fabric. As enterprises rapidly scale AI agents and large language model (LLM) applications, this native integration provides security and platform engineering teams with centralized policy enforcement, real-time protection against malicious prompts, and enhanced auditability without re-architecting or replacing the systems already in use. As organizations scale agentic AI capabilities, security teams face a growing governance gap and frequently lack visibility into agentic traffic. They risk exposure from prompt injection, harmful outputs, and sensitive data leakage. The joint integration federates F5's runtime AI security into Agent Fabric's Omni Gateway, enabling enterprises to enforce unified guardrail policies across all prompts and outputs moving through their agentic workflows. Eliminating the governance gap for agentic AI. Until now, organizations deploying Agent Fabric and seeking to leverage F5 AI Guardrails have faced a trade-off: either route LLM traffic through a separate F5 inspection layer, creating additional operational complexity and fragmented telemetry, or rely solely on native gateway controls without extending F5 AI Guardrails policies directly into their MuleSoft-managed workflows. By federating F5 AI Guardrails into Agent Fabric, enterprises gain: * Unified governance and zero double-proxy overhead: Policy management for AI traffic lives in a single control plane. Agent Fabric's Omni Gateway routes LLM calls directly to the F5 AI Guardrails Scan API, inspecting inbound prompts and outbound completions inline before models are invoked or responses returned. * Support for Agentforce ecosystems: Organizations can apply consistent runtime security controls across Agentforce-powered agents, Agent Fabric workflows, and custom AI applications. * Proactive threat mitigation: The solution is designed to block prompt injection, jailbreaks, toxicity, and unauthorized topics while reducing personally identifiable information (PII) and protected data exposure at runtime. * Data residency and sovereign control: Flexible dual-deployment topology allows self-hosted Kubernetes deployments including private VPCs, allowing sensitive prompt and completion data to remain within customer boundaries. * Low-touch policy tuning: Security teams author and version scanners, blocklists, and sensitivity thresholds within the F5 console, which Omni Gateway picks up dynamically without requiring policy or code changes. * SOC back-correlation and compliance auditability: Decisions carry detailed telemetry and shared scan IDs for seamless correlation in the F5 console, simplifying compliance with regulations such as the EU AI Act, GDPR, and HIPAA. "AI agents are moving from experiments into the critical path of the enterprise," said Kunal Anand, Chief Product Officer at F5. "The biggest risk in agentic AI is that agents will move faster than enterprise security and governance models can keep up. By integrating the F5 AI Security Platform directly into Agent Fabric, we are putting protection in the path of every prompt and response, where it can operate in real time. That lets organizations move faster with AI while preserving the control, visibility, and accountability their most important business processes demand." "We built Agent Fabric as the neutral solution to support enterprises running agents across a mix of models and platforms," said Andrew Comstock, SVP & GM at MuleSoft. "By extending Agent Fabric's existing LLM API and AI services to support F5 AI Guardrails as a first-class provider, we're making it even easier for customers to scale their agentic enterprise on the security tooling they know and trust." David Marshall is the founder of VMblog.com, one of the industry's longest-running independent publications covering modern data center technologies. What began as a focus on virtualization and cloud computing has expanded to cover the full spectrum of enterprise IT, including AI, security, and DevOps, making VMblog a trusted destination for vendor news, technology analysis, and industry commentary.Beyond publishing, David has spent his career at the intersection of technology and business, inventing, marketing, and launching a number of successful software companies and products, and building a reputation as a skilled marketing executive in the enterprise IT space.David is also a published author, having written two well-regarded books on virtualization and served as technical editor for two "For Dummies" titles covering virtualization and cloud computing. He co-founded CloudCow.com, a publication focused on cloud computing, and has been named a VMware vExpert every year since 2009, one of the longest continuous honoree streaks in the program's history.Connect with David on LinkedIn: https://www.linkedin.com/in/davidmarshall/
F5 and MuleSoft have integrated F5 AI Guardrails into Agent Fabric to provide inline security for AI agent applications. The integration addresses growing security challenges as enterprises scale AI deployments, including risks from prompt injection, harmful outputs, and data leakage. The solution enables unified governance without requiring additional infrastructure. Agent Fabric's Omni Gateway routes calls directly to F5's Scan API, inspecting prompts and responses before model invocation. Security teams can manage policies centrally whilst maintaining data residency control through flexible deployment options. The integration supports Agentforce ecosystems and provides threat mitigation against jailbreaks and unauthorized data exposure. It includes compliance features for regulations including the EU AI Act, GDPR, and HIPAA. F5 AI Guardrails for Agent Fabric is now generally available. The companies will demonstrate the integration at Dreamforce in San Francisco from 15-17 September 2026.