AI model and agent security
Scanning, red-teaming and runtime monitoring of models, AI applications and autonomous agents for attacks and unsafe behaviour.
27 vendors · alphabetical, never ranked
- 42Crunch42Crunch sells an API security platform that tests APIs against their contract before they reach production, protects them at runtime, and extends the same approach to the MCP servers that AI agents call and expose.Ownership not established
- Abnormal AIAbnormal AI sells a behavioral analytics platform that protects email and identity systems and monitors use of AI tools and agents, with separate modules for account takeover detection, identity threat protection and AI agent security.Privately held
- AponoApono sells a cloud-native privileged access management platform that grants just-in-time, scoped access to humans, machine identities and AI agents and revokes it automatically once a task is complete. 1Password announced on June 15, 2026, that it had acquired Apono.Owned by 1Password since 2026
- AppOmniAppOmni sells a SaaS and AI security platform that monitors configuration settings, user permissions and AI agent activity across enterprise SaaS applications, detecting threats, data exposures and compliance gaps for applications including Salesforce, Microsoft 365, ServiceNow, Google Workspace and Workday.Ownership not established
- CraniumCranium sells a platform that gives visibility into AI models, agents and vendors, enforces AI policy against frameworks such as the NIST AI RMF and EU AI Act, stress-tests models for vulnerabilities, and generates compliance evidence.Privately held
- Credo AICredo AI sells software that discovers AI systems, agents, vendors and models across an organization, enforces AI policy, and manages AI risk and compliance evidence.Privately held
- DTEX SystemsDTEX Systems sells an insider risk management platform that combines user activity monitoring, behavioral analytics and adaptive data loss prevention, along with investigative services and AI agent risk tools.Privately held
- Enkrypt AIEnkrypt AI sells software that red-teams AI systems for security, safety and brand risks, applies real-time guardrails against threats, and monitors AI risk and compliance.Privately held · primary category
- HiddenLayerHiddenLayer sells software that secures machine learning models and AI applications, covering model scanning, red teaming, runtime guardrails and protection for autonomous agents and MCP connections.Privately held · primary category
- Impart SecurityImpart Security sells a runtime enforcement platform that blocks attacks against LLMs, AI agents, MCP servers, APIs and web applications, including inline agent behavior controls and MCP policy enforcement.Privately held
- KnosticKnostic sells software that discovers and secures AI agents and coding assistants, along with related supply chain components such as MCP servers and IDE extensions, and is intended to detect shadow AI and block data exfiltration and destructive commands.Privately held · primary category
- KnowBe4KnowBe4 sells security awareness training and simulated phishing software, alongside email and collaboration security products and a set of AI agents branded AIDA for automating human risk management tasks.Owned by Vista Equity Partners since 2023
- LakeraLakera sells software that secures generative AI systems: runtime protection against prompt attacks and data leakage for AI agents and applications, a red teaming service that tests AI systems for vulnerabilities, and discovery of employees' use of outside AI tools.Owned by Check Point Software Technologies since 2025
- Lasso SecurityLasso Security sells a platform that gives enterprises visibility, control and real-time defense across the AI models they use, the agents they build and the applications they ship, combining automated red teaming with runtime enforcement of security policies.Privately held
- Levo.aiLevo.ai sells a runtime application security platform that discovers APIs, AI agents, MCP servers and LLMs, tests them offensively, and enforces inline protection against malicious traffic.Ownership not established
- MindgardMindgard sells software that maps AI systems for exposure, red-teams AI models and agents for vulnerabilities, and applies runtime protection against attacks.Privately held · primary category
- Noma SecurityNoma Security sells software that discovers AI agents, models and tools across an organization's environments, manages AI security posture and policy enforcement, and combines red teaming with runtime protection against attacks such as prompt injection and data exfiltration.Privately held · primary category
- NowSecureNowSecure sells mobile application risk management software that tests mobile apps' code, dependencies, runtime behavior and data flows, and finds AI components hidden inside them, for both apps a company builds and third-party apps its workforce uses.Ownership not established
- Operant AIOperant AI sells a runtime security platform that reads the intent behind AI agent actions and blocks, allows or redacts them inline, with dedicated protection for AI agents, MCP servers and APIs.Privately held
- PangeaPangea sells software that gives security teams visibility into how AI is used across an organization and applies guardrails against threats such as prompt injection and sensitive data leakage in AI applications.Owned by CrowdStrike since 2025 · primary category
- PlerionPlerion sells a cloud and AI security platform that maps cloud assets, identities, permissions and workloads into a single graph across AWS, Azure and GCP, with an AI agent that prioritizes exploitable risks and carries out fixes.Ownership not established
- Prompt SecurityPrompt Security sells software that discovers and governs how employees, developers and AI agents use generative AI, and tests and protects AI applications an organization builds against prompt injection and other runtime threats.Owned by SentinelOne since 2025
- Salt SecuritySalt Security sells an API security platform that discovers and protects APIs using machine learning, and has extended it into agentic AI security covering AI agents, MCP servers and the models and APIs they connect to.Ownership not established
- SkyflowSkyflow sells a data privacy vault that sanitizes and tokenizes sensitive data on ingest, protects it at runtime with zero-trust architecture, and controls how that data is used by applications, data platforms and AI agents.Privately held
- Stream.SecurityStream.Security sells an AI-native cloud detection and response platform that models a customer's cloud environment in real time and autonomously prevents, detects and remediates exposures and threats.Privately held
- WallarmWallarm sells a platform that secures APIs, web applications and AI workloads, with products covering AI workload discovery and governance and inline API protection.Privately held
- ZenityZenity sells a platform that governs and secures AI agents by examining how they are built, what they can access, and what they do, combining agentic red teaming with runtime defense across SaaS, homegrown agent platforms and end-user devices.Privately held · primary category
No vendor pays to be listed or to change what we write. Descriptions are ours, drawn from each company's own site and filings. Corrections: /corrections.