Building the Agent Control Layer contains 27 companies across
4 categories.
The OpenAI and Hugging Face incident showed that autonomous agents cannot be trusted to report or police their own behavior. As agents gain more authority, companies will need an independent control and evidence layer around them. This landscape focuses on new pure play companies building that layer rather than established security platforms expanding into agent security.
Tool & MCP Security
Agents increasingly rely on external tools to act. These products provide an independent control layer that decides which MCP servers or tools an agent is allowed to use.
AIR
Website: air.security
AIR builds a security platform that sits between AI agents and the outside world to inspect and control the skills, MCP servers, plugins, and other add ons they use.
Category: Tool & MCP Security.
Funding stage: Seed.
Founded: 2026.
Country: Israel.
Employees: 11-50 employees.
Landscape fit: It fits Tool & MCP Security because the product is designed to scan, govern, and block the external tools, plugins, skills, and MCPs that agents rely on before they can be used.
Funding rounds
-
Seed
announced 2026-09-01
: 10000000 USD
; investors: Sequoia Capital
; source: TechCrunch
; https://techcrunch.com/2026/09/01/air-raises-50m-to-help-companies-vet-the-skills-and-add-ons-ai-agents-use/
-
Seed
announced 2026-09-01
: 40000000 USD
; investors: Greenoaks Capital
; source: TechCrunch
; https://techcrunch.com/2026/09/01/air-raises-50m-to-help-companies-vet-the-skills-and-add-ons-ai-agents-use/
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. AIR looks like an early stage team with a small public headcount and no clear public hiring program visible. The strongest live signals are a recent stealth launch and a senior executive addition, not active job openings.
Source: LinkedIn company page.
https://www.linkedin.com/company/airsecurity/
-
2026-09-03:
Product snapshot
(product)
. AIR is a security layer for AI agents that inspects and controls external add ons before agents use them.
Source: AIR homepage.
https://www.air.security
-
2026-09-01:
AIR passes 20 customers
(gtm)
. AIR said it had more than 20 customers, with roughly a quarter being large enterprises. The company said demand was strongest in regulated industries such as financial services and pharmaceuticals.
Source: TechCrunch.
https://techcrunch.com/2026/09/01/air-raises-50m-to-help-companies-vet-the-skills-and-add-ons-ai-agents-use/
-
2026-09-01:
Seed I
(funding)
. Amount: USD 10M. Led by Sequoia Capital. AIR disclosed this first seed round together with a second USD 40M round led by Greenoaks.
Source: TechCrunch.
https://techcrunch.com/2026/09/01/air-raises-50m-to-help-companies-vet-the-skills-and-add-ons-ai-agents-use/
-
2026-09-01:
AIR comes out of stealth
(gtm)
. AIR announced its public launch and positioned itself as a firewall for AI agent context and the add ons agents use.
Source: AIR blog.
https://www.air.security/blog-posts/out-of-stealth
-
2026-09-01:
AIR comes out of stealth
(product)
. AIR announced its public launch and described the product as a firewall for AI agent context.
Source: AIR Comes Out of Stealth.
https://www.air.security/blog-posts/out-of-stealth
Runlayer
Website: runlayer.com
Runlayer builds a control plane for enterprise AI agents, with an MCP gateway, runtime security, policy controls, and audit visibility for the tools agents use.
Category: Tool & MCP Security.
Funding stage: Series A.
Founded: 2025.
Country: United States.
Employees: 11-50.
Landscape fit: It fits this category because its core product inspects external tools and MCP requests, enforces policy, and blocks risky agent activity before company systems are reached.
Funding rounds
-
Series A
announced 2026-06-24
: 30000000 USD
; investors: Felicis, Khosla Ventures
; source: Runlayer blog
; https://www.runlayer.com/blog/series-A-30m-fundraise-felicis-khosla
-
seed
announced 2025-11-17
: 11000000 USD
; investors: Khosla Ventures, Felicis
; source: TechCrunch
; https://techcrunch.com/2025/11/17/mcp-ai-agent-security-startup-runlayer-launches-with-8-unicorns-11m-from-khoslas-keith-rabois-and-felicis
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. Runlayer is a small enterprise software team with public hiring activity and a roughly 25 person headcount signal from a May 2026 job post.
Source: Runlayer jobs board.
https://jobs.ashbyhq.com/runlayer/6d8ce307-13ea-4394-b28f-3da9b3e7467f
-
2026-09-03:
Product snapshot
(product)
. Runlayer provides an enterprise AI control plane with an MCP gateway, runtime security, policy controls, audit visibility, shadow AI discovery, and a governed catalog for approved connectors, skills, and plugins.
Source: Runlayer website.
https://www.runlayer.com
-
2026-08-28:
Runlayer publishes Slack launch partnership
(product)
. Runlayer announced it is a launch partner for Add to Slack and said governed agents can now run inside Slack.
Source: Runlayer blog.
https://www.runlayer.com/blog/runlayer-agents-now-in-slack
-
2026-08-28:
Runlayer adds Slack distribution
(gtm)
. Runlayer became a launch partner for Add to Slack and brought governed agents into Slack.
Source: Runlayer blog.
https://www.runlayer.com/blog/runlayer-agents-now-in-slack
-
2026-06-24:
Series A
(funding)
. Amount: USD 30M. Investors: Felicis, Khosla Ventures. Runlayer said the round brought total funding to USD 42M.
Source: Runlayer blog.
https://www.runlayer.com/blog/series-A-30m-fundraise-felicis-khosla
-
2026-06-01:
Runlayer publishes customer results for Jane and Homebase
(gtm)
. Runlayer highlighted Jane App and Homebase as examples of production use of its governed AI workflows.
Source: Runlayer customer page.
https://www.runlayer.com/customers
Anomity
Website: anomity.ai
Anomity is an enterprise security platform that gives teams visibility and policy control over AI agents, MCP servers, and related tools running on managed endpoints.
Category: Tool & MCP Security.
Funding stage: Pre Seed.
Founded: 2026.
Country: Israel.
Employees: 1-10.
Landscape fit: It fits Tool and MCP Security because it specifically discovers, inventories, and governs AI agents and MCP servers, including allowing, denying, or logging tool calls and tracking changes over time.
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. Anomity appears to be a very small founder led team with one visible sales opening and no clear evidence of broad hiring.
Source: F4 Startup Intelligence profile.
https://f4.fund/startups/anomity
-
2026-09-03:
Product snapshot
(product)
. Anomity is an enterprise security platform that inventories AI artifacts on managed endpoints and enforces policy around their use. It provides endpoint, browser, and cloud discovery, policy controls before tool calls run, and an audit trail for security teams.
Source: Anomity home page.
https://anomity.ai
-
2026-08-01:
Head of Sales posted
(hr)
. Anomity posted a Head of Sales role for its founding team and said the role would build the sales organization.
Source: Head of Sales job posting.
https://il.linkedin.com/jobs/view/head-of-sales-founding-team-agentic-ai-security-at-anomity-4454200337
-
2026-08-01:
Sales hiring opens
(gtm)
. Anomity posted a Head of Sales role to build its sales organization for enterprise security buyers.
Source: Head of Sales job posting.
https://il.linkedin.com/jobs/view/head-of-sales-founding-team-agentic-ai-security-at-anomity-4454200337
Lasso Security
Website: lasso.security
Lasso Security builds an AI security platform that discovers, scores, monitors, and controls AI agents and their MCP tool connections so enterprises can use them more safely.
Category: Tool & MCP Security.
Funding stage: Seed.
Founded: 2023.
Country: Israel.
Employees: unknown.
Landscape fit: It fits this category because its product focuses on inspecting external tools and MCP connections used by agents, then enforcing policy, blocking risky access, and generating audit trails for those agent interactions.
Funding rounds
-
Funding round
announced 2026-09-02
: 30000000 USD
; investors: ClearSky, Entrée Capital, iAngels, Singtel Innov8, Mindset, Swish Data
; source: GlobeNewswire
; https://www.globenewswire.com/news-release/2026/09/02/3354871/0/en/lasso-security-announces-future-of-ai-security-with-cpu-based-guardrails.html
-
SAFE
announced 2025-06-01
: 10000000 USD
; investors: Mindset Ventures, CyberArk Ventures, Singtel Innov8
; source: Startup Nation Central
; https://finder.startupnationcentral.org/company_page/lasso
-
SAFE
announced 2024-02-01
: 5000000 USD
; investors: ClearSky Security, iAngels
; source: Startup Nation Central
; https://finder.startupnationcentral.org/company_page/lasso
-
seed
announced 2023-11-20
: 6000000 USD
; investors: Entrée Capital, Samsung Next
; source: official company press release
; https://www.lasso.security/resources/lasso-security-funding-announcement-2023
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. Lasso is publicly hiring across a few roles and looks like a small specialist team rather than a large workforce.
Source: careers page.
https://www.lasso.security/careers
-
2026-09-03:
Product snapshot
(product)
. Lasso’s platform discovers and inventories AI agents and applications, maps their tools and MCP connections, scores risk, applies policy and usage controls, runs automated red teaming, and detects and responds to runtime threats.
Source: lasso.security.
https://www.lasso.security
-
2026-09-02:
Lasso reports more than 500% revenue growth
(gtm)
. Lasso said revenue grew by more than 500% over the prior 12 months. It also said the platform protects tens of thousands of agents and processes billions of requests and actions per month, with customers including the U.S. Department of Homeland Security, eToro and Fiverr.
Source: GlobeNewswire.
https://www.globenewswire.com/news-release/2026/09/02/3354871/0/en/lasso-security-announces-future-of-ai-security-with-cpu-based-guardrails.html
-
2026-09-02:
Lasso launches LEAP
(product)
. Lasso launched LEAP, a CPU based runtime guardrail designed to inspect agent requests and actions with low latency without requiring GPUs.
Source: GlobeNewswire.
https://www.globenewswire.com/news-release/2026/09/02/3354871/0/en/lasso-security-announces-future-of-ai-security-with-cpu-based-guardrails.html
-
2026-09-02:
Funding round
(funding)
. Amount: USD 30M. Led by ClearSky, with participation from Entrée Capital, iAngels, Singtel Innov8, Mindset and Swish Data.
Source: GlobeNewswire.
https://www.globenewswire.com/news-release/2026/09/02/3354871/0/en/lasso-security-announces-future-of-ai-security-with-cpu-based-guardrails.html
-
2026-06-28:
TrueFoundry integration added
(product)
. Lasso integrated with TrueFoundry AI Gateway to apply its security layer at the gateway control plane.
Source: official company blog.
https://www.lasso.security/blog/lasso-security-now-integrates-with-truefoundry-ai-gateway
Operant AI
Website: operant.ai
Operant AI builds a runtime security platform that protects AI applications, agents, APIs, and MCP use in real time.
Category: Tool & MCP Security.
Funding stage: Series A.
Founded: 2021.
Country: United States.
Employees: unknown.
Landscape fit: It fits Tool & MCP Security because its platform includes an MCP Gateway and Agent Protector, and its product is built to inspect and control agent use of external tools and connected services in real time.
Funding rounds
-
Series A
announced 2024-09-12
: 10000000 USD
; investors: SineWave Ventures, Felicis, Alumni Ventures, Massive, Calm Ventures, Gaingels, industry-expert angels
; source: GlobeNewswire
; https://www.globenewswire.com/news-release/2024/09/12/2945058/0/en/operant-ai-secures-10m-series-a-to-protect-the-modern-cloud-across-apis-applications-and-ai.html
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. Operant AI is hiring across sales, partnerships, customer success, and APAC engineering while keeping a small enterprise focused team.
Source: Operant AI Careers.
https://www.operant.ai/company/careers
-
2026-09-03:
Product snapshot
(product)
. Operant AI provides runtime security for AI applications, agents, APIs, services, and MCP use across cloud and endpoint environments.
Source: Operant AI product page.
https://www.operant.ai/platform/ai-gatekeeper
-
2026-09-01:
Operant AI opens multiple roles
(hr)
. Operant AI is actively hiring for sales, partnerships, customer success, and APAC engineering roles.
Source: Operant AI Careers.
https://www.operant.ai/company/careers
-
2026-08-27:
Operant launches Semantic Firewall
(product)
. Operant AI launched Semantic Firewall for inline intent based enforcement around agent actions. The release also added Browser AI Protection, Token Meter and expanded Claude coverage.
Source: GlobeNewswire.
https://www.globenewswire.com/news-release/2026/08/27/3351884/0/en/operant-ai-launches-semantic-firewall-to-enforce-ai-agent-intent-in-real-time.html
-
2026-05-04:
Endpoint Protector launches
(product)
. Operant AI launched Endpoint Protector to inspect and block AI tools, coding agents, and MCP connected workflows at the endpoint.
Source: GlobeNewswire.
https://www.globenewswire.com/news-release/2026/05/04/3286769/0/en/operant-ai-launches-endpoint-protector-securing-shadow-ai-coding-agents-and-mcp-across-the-enterprise.html
-
2025-10-23:
AWS Marketplace availability
(gtm)
. Operant AI announced that its products were available on AWS Marketplace for AWS customers.
Source: Operant AI news.
https://www.operant.ai/company/news
Pillar Security
Website: pillar.security
Pillar Security builds an AI security platform that helps enterprises discover, test, and control the risks around AI agents and tools in production.
Category: Tool & MCP Security.
Funding stage: Seed.
Founded: 2023.
Country: Israel.
Employees: unknown.
Landscape fit: It fits this category because its product focuses on inspecting and controlling the tools, MCP servers, and runtime behavior that AI agents depend on, including runtime guardrails and MCP and tool security.
Funding rounds
-
seed
announced 2025-04-16
: 9000000 USD
; investors: Shield Capital, Golden Ventures, Ground Up Ventures, strategic angels
; source: Pillar Security blog
; https://www.pillar.security/blog/pillar-security-raises-9m-to-help-companies-build-and-run-secure-ai-software
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. Pillar Security is actively hiring across sales, solutions, and engineering roles. The public careers page shows openings in Tel Aviv, the U.S. remote market, and Australia.
Source: Pillar Security careers page.
https://www.pillar.security/careers
-
2026-09-03:
Product snapshot
(product)
. Unified AI security platform for enterprises to discover, test, and control AI systems across the AI lifecycle.
Source: Pillar Security about page.
https://www.pillar.security/about
-
2026-08-06:
Pillar launches Red Graph Suite
(product)
. Pillar launched Red Graph Suite as a full AI red teaming suite for mapping attack surfaces, testing live applications, proving execution, and tracking posture over time.
Source: Pillar Security blog.
https://www.pillar.security/blog/pillar-launches-red-graph-suite-version-controlled-contextual-and-continuous-ai-red-teaming
-
2026-05-03:
Pillar extends into agentic CI/CD
(product)
. Pillar introduced discovery and posture management for agentic CI/CD and extended its runtime agent into CI/CD workflows.
Source: Pillar Security blog.
https://www.pillar.security/blog/introducing-pillar-for-agentic-ci-cd
-
2026-03-23:
Pillar partners with Wiz
(gtm)
. Pillar announced a partnership with Wiz that connects Wiz AI discovery with Pillar’s RedGraph testing engine so joint customers can map AI attack surfaces and validate runtime risk.
Source: Pillar Security blog.
https://www.pillar.security/blog/from-ai-discovery-to-attack-surface-mapping-announcing-the-wiz-pillar-partnership
-
2025-04-16:
Seed
(funding)
. Amount: USD 9M. Investors: Shield Capital, Golden Ventures, Ground Up Ventures, strategic angels
Source: Pillar Security blog.
https://www.pillar.security/blog/pillar-security-raises-9m-to-help-companies-build-and-run-secure-ai-software
NeuralTrust
Website: neuraltrust.ai
NeuralTrust builds a security platform that controls and monitors AI agents, their tool calls, and MCP connections so enterprises can govern what agents are allowed to access and do.
Category: Tool & MCP Security.
Funding stage: Seed.
Founded: 2022.
Country: Spain.
Employees: 51-200.
Landscape fit: It fits this category because it inspects the external tools and MCP servers agents rely on, enforces tool use permissions, and acts as a control layer between agents and the systems they access.
Funding rounds
-
Seed
announced 2026-06-17
: 20000000 USD
; investors: Alstin Capital, VentureFriends, Seaya, Kibo Ventures, Banc Sabadell, EA Ventures Plug and Play Fund, Finaves
; source: NeuralTrust
; https://neuraltrust.ai/news/neuraltrust-raises-20m
-
Grant
announced 2025-10-01
: 2360423.54 EUR
; investors: European Innovation Council
; source: CORDIS
; https://cordis.europa.eu/project/id/101247606
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. NeuralTrust appears to have a team in the 51 to 200 employee range and shows one public engineering opening. The company is based in Barcelona and also lists offices in New York and London.
Source: NeuralTrust LinkedIn company page.
https://www.linkedin.com/company/neuraltrust
-
2026-09-03:
Product snapshot
(product)
. NeuralTrust provides enterprise AI security software for securing AI agents, LLM traffic, tools, MCP servers, and agent to agent traffic. The platform includes an agent gateway, runtime security controls, posture management, red teaming, model routing, tool access controls, audit logging, and policy enforcement.
Source: NeuralTrust homepage.
https://neuraltrust.ai
-
2026-09-01:
Frontend Engineer opening
(hr)
. NeuralTrust posted an opening for a Frontend Engineer in Barcelona.
Source: NeuralTrust LinkedIn company page.
https://www.linkedin.com/company/neuraltrust
-
2026-08-05:
Runtime Security Mesh launch
(product)
. NeuralTrust launched Runtime Security Mesh to extend security across every AI agent in an enterprise stack without a bespoke integration per platform.
Source: Runtime Security Mesh launch.
https://neuraltrust.ai/news/neuraltrust-launches-runtime-security-mesh-ai-agents
-
2026-06-17:
Seed
(funding)
. Amount: USD 20M. Led by Alstin Capital, with participation from VentureFriends, Seaya, Kibo Ventures, Banc Sabadell, EA Ventures Plug and Play Fund and Finaves.
Source: NeuralTrust.
https://neuraltrust.ai/news/neuraltrust-raises-20m
-
2026-03-31:
Q1 ARR doubles full year 2025 ARR
(gtm)
. NeuralTrust said its ARR in Q1 2026 was twice its full year 2025 ARR. It also named customers including AirEuropa, Abanca, Iberia and Banc Sabadell.
Source: NeuralTrust.
https://neuraltrust.ai/news/neuraltrust-raises-20m
Agent Runtime & Execution Security
Approved tools can still be used in unsafe ways. These products provide an independent control layer around execution and stop actions that break policy before they affect external systems.
HiddenLayer
Website: hiddenlayer.com
HiddenLayer is an AI security company that protects enterprise AI models and agentic applications from malicious actions and model attacks. ([hiddenlayer.com](https://www.hiddenlayer.com/about-us?utm_source=openai))
Category: Agent Runtime & Execution Security.
Funding stage: Series B.
Founded: 2022.
Country: United States.
Employees: unknown.
Landscape fit: It fits agent runtime and execution security because HiddenLayer’s current platform includes Agentic Runtime Security to secure AI coding agents at runtime and stop unsafe actions before they affect external systems. ([hiddenlayer.com](https://www.hiddenlayer.com/newsroom?utm_source=openai))
Funding rounds
-
series b
announced 2026-09-02
: 100000000 USD
; investors: Delta-v Capital, Ten Eleven Ventures, Morgan Stanley, M12, Microsoft's Venture Fund, Booz Allen Ventures
; source: PR Newswire
; https://www.prnewswire.com/news-releases/hiddenlayer-raises-100m-series-b-to-advance-trustworthy-ai-302867783.html
-
series a
announced 2023-09-19
: 50000000 USD
; investors: M12, Moore Strategic Ventures, Booz Allen Ventures, IBM Ventures, Capital One Ventures, Ten Eleven Ventures
; source: PR Newswire
; https://www.prnewswire.com/news-releases/hiddenlayer-raises-50m-in-series-a-funding-to-safeguard-ai-301931260.html
-
seed
announced 2022-07-19
: 6000000 USD
; investors: Ten Eleven Ventures
; source: PR Newswire
; https://www.prnewswire.com/news-releases/hiddenlayer-launches-the-first-security-solution-to-protect-ai-powered-products-301587864.html
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. HiddenLayer is actively hiring across engineering, research, sales, product, and finance. The company presents itself as growing rapidly, but no exact employee count is visible in the supplied evidence.
Source: HiddenLayer Greenhouse.
https://job-boards.greenhouse.io/hiddenlayer?error=true
-
2026-09-03:
Product snapshot
(product)
. HiddenLayer provides an enterprise AI security platform with AI Discovery, AI Supply Chain Security, AI Attack Simulation, and AI Runtime Security. The company also offers model scanning, red teaming, and newer protections for agentic AI and AI coding agents.
Source: HiddenLayer.
https://www.hiddenlayer.com
-
2026-09-02:
HiddenLayer reports 10x ARR growth
(gtm)
. HiddenLayer said annual recurring revenue grew more than 10x over the prior year and that it added more than 50 new platform customers. The company also said its technology supports a frontier model provider serving more than 700 million weekly users.
Source: HiddenLayer.
https://www.hiddenlayer.com/news/hiddenlayer-100m-series-b-ai-security
-
2026-09-02:
HiddenLayer adds Agent Harness Security
(product)
. HiddenLayer said its Series B funding would support Agent Harness Security, a new solution that extends runtime security to AI coding agents.
Source: PR Newswire.
https://www.prnewswire.com/news-releases/hiddenlayer-raises-100m-series-b-to-advance-trustworthy-ai-302867783.html
-
2026-09-02:
Series B
(funding)
. Amount: USD 100M. Investors: Delta-v Capital, Ten Eleven Ventures, Morgan Stanley, M12, Microsoft's Venture Fund, Booz Allen Ventures
Source: PR Newswire.
https://www.prnewswire.com/news-releases/hiddenlayer-raises-100m-series-b-to-advance-trustworthy-ai-302867783.html
-
2026-09-01:
HiddenLayer expands marketplace distribution
(gtm)
. HiddenLayer said customers can buy its platform through AWS Marketplace and CPPO, extending cloud channel reach.
Source: HiddenLayer.
https://www.hiddenlayer.com/partners/aws
CodeIntegrity
Website: codeintegrity.ai
CodeIntegrity builds secure runtime controls for AI agents, letting enterprises inspect, constrain, approve, and audit tool calls before they reach production systems.
Category: Agent Runtime & Execution Security.
Funding stage: Seed.
Founded: 2024.
Country: United States.
Employees: small.
Landscape fit: It fits Agent Runtime & Execution Security because it focuses on controlling agent actions at execution time and stopping unsafe tool use before external systems are affected.
Funding rounds
-
seed
announced 2026-05-27
: 5000000 USD
; investors: SYN Ventures, Antler, Boost VC
; source: CodeIntegrity Raises $5M in Seed Funding
; https://www.codeintegrity.ai/blog/codeintegrity-seed-round
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. CodeIntegrity appears to have a small team and is hiring across engineering, security research, and customer facing roles. Public postings suggest an early stage company with active recruiting.
Source: CodeIntegrity careers page.
https://www.codeintegrity.ai/careers
-
2026-09-03:
Product snapshot
(product)
. CodeIntegrity provides secure runtime controls for AI agents and MCP clients. The platform enforces policy before tool calls, limits what agents can access or send, and records execution evidence for security review.
Source: CodeIntegrity homepage.
https://www.codeintegrity.ai
-
2026-07-23:
Black Hat presence
(gtm)
. CodeIntegrity said it would meet prospects at Black Hat USA 2026 and discuss secure production use of AI agents.
Source: Meet CodeIntegrity at Black Hat USA 2026 | CodeIntegrity.
https://www.codeintegrity.ai/blog/black-hat-usa-2026
-
2026-07-01:
Healthcare summit presence
(gtm)
. CodeIntegrity spoke with healthcare security leaders at the Cybersecurity Healthcare Education Summit in Park City.
Source: CodeIntegrity at the Cybersecurity Healthcare Education Summit 2026 | CodeIntegrity.
https://www.codeintegrity.ai/blog/healthcare-education-summit-2026
-
2026-05-27:
Seed
(funding)
. Amount: USD 5M. Investors: SYN Ventures, Antler, Boost VC
Source: CodeIntegrity Raises $5M in Seed Funding.
https://www.codeintegrity.ai/blog/codeintegrity-seed-round
-
2026-05-23:
Hiring for forward deployed engineering
(hr)
. CodeIntegrity posted a Forward Deployed Engineer, AI Security role to help customers deploy the product in enterprise environments.
Source: Forward Deployed Engineer, AI Security - Careers | CodeIntegrity.
https://www.codeintegrity.ai/careers/position/5c870d6e-b5ce-4147-90ae-cb7ee402111f
Manifold
Website: manifold.security
Manifold provides runtime security and detection and response for AI agents on endpoints, showing what agents do at runtime and stopping risky actions before they affect external systems.
Category: Agent Runtime & Execution Security.
Funding stage: Seed.
Founded: 2025.
Country: United States.
Employees: 11-50.
Landscape fit: It fits this category because it sits around agent execution and watches or blocks agent actions at runtime rather than only inspecting prompts or outputs.
Funding rounds
-
seed
announced 2026-03-18
: 8000000 USD
; investors: Costanoa Ventures, Cherry Ventures, Rain Capital, Modern Technical Fund, Joe Sullivan, Vijay Bolina
; source: Official funding announcement
; https://www.manifold.security/blog/manifold-raises-8m-seed-funding
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. Manifold appears to be a small team that is hiring selectively but actively. The careers page says there are no immediate vacancies, while Greenhouse shows three open roles and recent LinkedIn posts show new research and sales hires.
Source: Official about page.
https://www.manifold.security/about
-
2026-09-03:
Product snapshot
(product)
. Manifold provides agent runtime security on endpoints and a companion supply chain intelligence product called Manifest. The platform shows what agents do, surfaces risk, and supports response actions, while Manifest lets users search, inspect, and scan AI skills, MCP servers, plugins, and related assets.
Source: Official homepage.
https://www.manifold.security
-
2026-06-01:
Head of research joins
(hr)
. Ax Sharma said he joined Manifold Security as Head of Research.
Source: LinkedIn employee announcement.
https://www.linkedin.com/posts/axsharma_runtime-security-for-ai-agents-on-endpoints-activity-7442563937205923841-M9VX
-
2026-06-01:
Founding account executive joins
(hr)
. Michael Barr said he joined Manifold Security as Founding Account Executive.
Source: LinkedIn employee announcement.
https://www.linkedin.com/posts/michaelbarr13_excited-to-share-that-ive-joined-manifold-activity-7457429178846621696-YqNa
-
2026-04-14:
Manifest launches
(product)
. Manifold launched Manifest as a public supply chain intelligence product for AI agent ecosystem assets.
Source: Official product launch blog.
https://www.manifold.security/blog/manifest-ai-supply-chain-intelligence
-
2026-04-01:
Manifold launches publicly
(gtm)
. Neal Swaelens announced that Manifold Security had launched and described the company as an AI Detection and Response platform for agents on endpoints.
Source: Founder social post.
https://www.linkedin.com/posts/nealswaelens_super-proud-of-this-one-today-we-launch-activity-7440037268918071297-qzpG
Capsule Security
Website: capsulesecurity.io
Capsule Security is a runtime security platform for AI agents that monitors behavior in real time and blocks unsafe actions before they are executed.
Category: Agent Runtime & Execution Security.
Funding stage: Seed.
Founded: 2025.
Country: Israel.
Employees: 11-50.
Landscape fit: It fits this category because it acts as an independent control layer around agent execution, watching actions in real time and stopping unsafe behavior before it reaches external systems.
Funding rounds
-
seed
announced 2026-04-15
: 7000000 USD
; investors: Lama Partners, ForgePoint Capital International
; source: Business Wire on Capsule Security launch
; https://www.businesswire.com/news/home/20260415670902/en/Capsule-Security-Exits-Stealth-With-7M-to-Stop-AI-Agents-From-Going-Rogue-at-Runtime
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. Capsule Security appears to be a small founder led team with headcount in the early startup range. Public evidence shows no clear hiring surge.
Source: Capsule Security About Us.
https://www.capsulesecurity.io/about-us
-
2026-09-03:
Product snapshot
(product)
. Capsule Security is an API first runtime security platform for AI agents. It automatically discovers agents, monitors behavior in real time, assesses security posture, and blocks unsafe actions before they execute.
Source: Capsule Security home.
https://www.capsulesecurity.io
-
2026-09-02:
NVIDIA Nemotron detector is announced
(product)
. Capsule Security said it collaborated with NVIDIA on specialized models for rogue agent detection with low latency runtime interception.
Source: Keeping AI Agents on Track: How Capsule Powers State-of-the-Art Rogue Agent Detection with NVIDIA Nemotron.
https://www.capsulesecurity.io/blog-post/keeping-ai-agents-on-track-how-capsule-powers-state-of-the-art-rogue-agent-detection-with-nvidia-nemotron
-
2026-07-22:
Claude Platform integration launches
(product)
. Capsule Security launched a security integration for Claude Platform using Claude's Compliance API.
Source: Capsule Launches Security Integration for Claude Platform.
https://www.capsulesecurity.io/blog-post/capsule-launches-security-integration-for-claude-platform
-
2026-06-23:
Security research on agent skills
(product)
. Capsule published research analyzing 206,435 AI agent skills and highlighted credential exposure and silent data exfiltration risks.
Source: Capsule research on AI agent skills.
https://www.capsulesecurity.io/blog-post/we-analyzed-206-435-ai-agent-skills-heres-what-we-found
-
2026-05-27:
Agent control standard work is announced
(product)
. Capsule Security said it joined the Agent Control Standard effort and launched hooks.security as a catalog of agent hooks.
Source: Every agent needs a "stop". We're standardizing it..
https://www.capsulesecurity.io/blog-post/every-agent-needs-a-stop-were-standardizing-it
Noma Security
Website: noma.security
Noma Security is an enterprise AI security platform that helps companies discover, govern, test, and protect AI applications and agents at runtime.
Category: Agent Runtime & Execution Security.
Funding stage: Series B.
Founded: 2023.
Country: Israel.
Employees: unknown.
Landscape fit: It fits Agent Runtime & Execution Security because it adds an independent control layer for AI agents and runtime behavior, with controls meant to detect and stop unsafe actions before they reach external systems.
Funding rounds
-
Series B
announced 2025-07-31
: 100000000 USD
; investors: Evolution Equity Partners, Ballistic Ventures, Glilot Capital
; source: Noma Security blog
; https://www.noma.security/blog/noma-security-raises-100m-to-drive-adoption-of-ai-agent-security
-
Strategic investment
announced 2025-06-12
; investors: Silicon Valley CISO Investments
; source: GlobeNewswire
; https://www.globenewswire.com/search/organization/noma%20security%20inc%C2%A7
-
strategic investment
announced 2025-06-05
; investors: Databricks Ventures
; source: Noma Security blog
; https://www.noma.security/blog/databricks-and-noma-security-announce-partnership-to-accelerate-enterprise-ai-security
-
Series A
announced 2024-10-31
: 25000000 USD
; investors: Ballistic Ventures, Glilot Capital Partners, strategic investors
; source: Noma Security blog
; https://www.noma.security/blog/news/ai-security-platform-noma-raises-25-million-series-a
-
Seed
announced 2024-01-01
: 7000000 USD
; investors: Glilot Capital Partners, Cyber Club London
; source: Startup Nation Central
; https://finder.startupnationcentral.org/company_page/noma-security?section=financials
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. Noma is publicly recruiting across multiple senior functions, especially engineering, customer success, sales, product, and research. The company looks like it is still scaling its enterprise team, but the exact headcount is not clear from the supplied sources.
Source: Noma Security | LinkedIn.
https://www.linkedin.com/company/noma-security
-
2026-09-03:
Product snapshot
(product)
. Noma Security provides an enterprise AI security and governance platform for discovering AI assets, governing access, testing systems, and protecting AI and agents at runtime.
Source: Noma Security home page.
https://www.noma.security
-
2026-09-01:
Broad hiring on careers page
(hr)
. Noma's careers page showed open roles across customer success, engineering, product management, marketing, sales, research, finance, and operations.
Source: Noma Security careers page.
https://www.noma.security/careers
-
2026-09-01:
Security strategy hire
(hr)
. Chris Hughes said he joined Noma Security as VP of Security Strategy.
Source: Noma Security blog.
https://www.noma.security/blog/why-i-joined-noma
-
2026-08-26:
Kiro workflow integration
(product)
. Noma launched Noma Power for Amazon Kiro so developers can ask their coding agent for security context without leaving the workflow.
Source: Noma Security blog.
https://www.noma.security/blog/noma-kiro-power
-
2026-08-17:
TrueFoundry guardrail integration
(product)
. Noma became a native guardrail across the TrueFoundry AI Gateway and Agent Harness.
Source: Noma Security blog.
https://www.noma.security/blog/noma-security-is-now-a-native-guardrail-across-the-truefoundry-stack
Straiker
Website: straiker.ai
Straiker builds security software that discovers, tests, and controls AI agents at runtime so unsafe actions can be blocked before they affect external systems.
Category: Agent Runtime & Execution Security.
Funding stage: Series A.
Founded: 2024.
Country: United States.
Employees: unknown.
Landscape fit: It fits this category because the product is an independent control layer around AI agent execution that detects and blocks unsafe actions before they reach connected systems.
Funding rounds
-
series_a
announced 2026-06-29
: 64000000 USD
; investors: Marathon Management Partners, Citi Ventures, Illuminate Financial, Workday Ventures, Bain Capital Ventures, Lightspeed, GTM Capital, Rain Capital, Neva SGR, Firebolt Ventures, Sixty Degree Ventures
; source: Straiker official company blog
; https://www.straiker.ai/blog/straiker-raises-64m-series-a-to-secure-the-agentic-workforce
-
seed
announced 2025-03-27
: 21000000 USD
; investors: Lightspeed Ventures, Bain Capital Ventures
; source: Straiker official company blog
; https://www.straiker.ai/blog/straiker-launches-with-21-million-to-safeguard-ai
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. Straiker appears to be a research heavy startup with ongoing hiring interest for engineers, researchers, and builders. The public careers page invites applicants, but the captured snapshot shows no open positions.
Source: Straiker official careers page.
https://www.straiker.ai/careers
-
2026-09-03:
Product snapshot
(product)
. Straiker builds AI agent security software for enterprises. It maps agentic activity, tests how agents can be manipulated, and protects agent actions at runtime before unsafe behavior reaches enterprise systems.
Source: Straiker official company about page.
https://www.straiker.ai/about
-
2026-09-02:
Straiker publishes Heimdall
(product)
. Straiker introduced Heimdall as a cyber hardened environment for high risk agent evaluation and training.
Source: Straiker blog.
https://www.straiker.ai/blog/agentic-security-partner-ecosystem
-
2026-08-11:
Straiker names OpenAI partner status
(product)
. Straiker said it was named an OpenAI Select Partner within the OpenAI Partner Network.
Source: Straiker official company blog.
https://www.straiker.ai/blog/straiker-named-an-openai-select-partner
-
2026-08-04:
Straiker adds Agentic Kill Switch
(product)
. Straiker introduced a kill switch that lets security teams take compromised or misbehaving AI agents offline in seconds.
Source: Straiker official company blog.
https://www.straiker.ai/blog/agentic-kill-switch-ai-agent-security-for-enterprise-and-coding-agents
-
2026-07-21:
Straiker secures Claude surfaces
(product)
. Straiker said it joined Wave 3 of the Claude Compliance API and added runtime detection, traceability, and blocking for Claude Chat, Cowork, and Code.
Source: Straiker official company blog.
https://www.straiker.ai/blog/how-straiker-secures-claude
WitnessAI
Website: witness.ai
WitnessAI is an enterprise AI security platform that gives companies visibility, policy control, and runtime protection for AI usage, including agents and tools.
Category: Agent Runtime & Execution Security.
Funding stage: Series B.
Founded: 2023.
Country: United States.
Employees: unknown.
Landscape fit: It fits Agent Runtime & Execution Security because its platform monitors AI agent activity, controls tool use, and can block unsafe actions before they reach external systems.
Funding rounds
-
Strategic financing
announced 2026-01-13
: 58000000 USD
; investors: Sound Ventures, Fin Capital, Qualcomm Ventures, Samsung Ventures, Forgepoint Capital Partners
; source: official funding announcement
; https://witness.ai/resources/witnessai-raises-58-million-for-global-expansion-and-announces-new-ways-to-secure-ai-agents
-
Series A
announced 2024-05-21
: 27500000 USD
; investors: GV, Ballistic Ventures
; source: official funding announcement
; https://witness.ai/blog/witnessai-raises-27-5-million-to-enable-safe-use-of-ai
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. WitnessAI is a remote first enterprise security company with visible hiring language and leadership depth, but no reliable public headcount figure in the supplied evidence.
Source: official funding announcement.
https://witness.ai/resources/witnessai-raises-58-million-for-global-expansion-and-announces-new-ways-to-secure-ai-agents
-
2026-09-03:
Product snapshot
(product)
. WitnessAI provides an enterprise AI security and governance platform that gives visibility, policy control, runtime protection, and automated red teaming for AI use across employees, models, applications, agents, and MCP servers.
Source: official homepage.
https://witness.ai
-
2026-06-17:
WitnessAI Agentic Control launch
(product)
. WitnessAI launched Agentic Control, a control plane for agents, tools, and MCP servers.
Source: WitnessAI.
https://witness.ai/blog/introducing-witnessai-agentic-control-one-control-plane-for-every-agent-tool-and-mcp-server/
-
2026-04-01:
Top 10 US wealth manager selection
(gtm)
. A customer testimonial says a top 10 US wealth management firm selected WitnessAI for enterprise AI governance after evaluating multiple vendors.
Source: customer proof PDF.
https://witness.ai/wp-content/uploads/2026/04/CS4-Top-10-US-Wealth-Manager.pdf
-
2026-04-01:
Fortune 500 retailer production use
(gtm)
. A WitnessAI case study says a Fortune 500 omnichannel retailer uses the platform in production for employee and chatbot activity.
Source: customer proof PDF.
https://witness.ai/wp-content/uploads/2026/04/CS5-Fortune-500-Omnichannel-Retailer.pdf
-
2026-04-01:
Japan reseller partnership
(gtm)
. WitnessAI said NTT DATA Japan will resell its platform to Japanese enterprises and has already implemented the product internally.
Source: official partnership announcement.
https://witness.ai/resources/witnessai-and-ntt-data-japan-partner-to-accelerate-secure-ai-adoption-for-japanese-enterprises
Evoke Security
Website: evokesecurity.com
Evoke Security builds a security platform that gives enterprises visibility, policy control, and real time protection for AI agents.
Category: Agent Runtime & Execution Security.
Funding stage: Pre Seed.
Founded: 2025.
Country: United States.
Employees: 2 to 10 employees.
Landscape fit: It fits this category because it sits as an independent control layer around AI agent execution and blocks risky actions before they affect external systems.
Funding rounds
-
pre-seed
announced 2026-02-24
: 4000000 USD
; investors: Crosspoint Capital Partners, Red Cell Partners
; source: Evoke Security raises $4M pre seed funding
; https://www.evokesecurity.com/blogs/evoke-security-raises-4m-pre-seed-round-to-secure-the-agentic-workforce
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. Evoke Security is a very small security company with founder led leadership and active but limited hiring.
Source: Evoke Security LinkedIn company page.
https://www.linkedin.com/company/evoke-security
-
2026-09-03:
Product snapshot
(product)
. Evoke Security provides an AI agent security platform for enterprises. It covers continuous discovery and governance of agents, AI security posture management and threat modeling, and real time detection and response for prompts, tool calls, responses, and agent actions.
Source: Evoke Security home page.
https://www.evokesecurity.com
-
2026-07-23:
Claude compliance integration
(product)
. Evoke added Claude Enterprise coverage through the Claude Compliance API.
Source: Claude Compliance API integration.
https://www.evokesecurity.com/blogs/evoke-claude-compliance-api
-
2026-04-02:
Selected as finalist
(gtm)
. Evoke Security was named one of the finalists for the 2026 CrowdStrike, AWS, and NVIDIA cybersecurity startup accelerator.
Source: Evoke Security Selected as Finalist in the CrowdStrike, AWS, and NVIDIA Startup Accelerator.
https://www.evokesecurity.com/blogs/evoke-security-a-finalist-in-the-crowdstrike-aws-and-nvidia-startup-accelerator
-
2026-02-24:
Pre-seed
(funding)
. Amount: USD 4M. Investors: Crosspoint Capital Partners, Red Cell Partners
Source: Evoke Security raises $4M pre seed funding.
https://www.evokesecurity.com/blogs/evoke-security-raises-4m-pre-seed-round-to-secure-the-agentic-workforce
-
2026-01-05:
Selected for accelerator
(gtm)
. Evoke Security was selected for the 2026 CrowdStrike, AWS, and NVIDIA cybersecurity startup accelerator.
Source: Evoke Security selected for cybersecurity startup accelerator.
https://www.evokesecurity.com/blogs/evoke-security-selected-for-the-2026-crowdstrike-aws-nvidia-cybersecurity-startup-accelerator
Quint Security
Website: quintai.dev
Quint Security builds runtime behavioral security for AI agents. It watches what an agent actually does on the host and network, then blocks or flags actions that violate policy before they reach external systems.
Category: Agent Runtime & Execution Security.
Country: United States.
Employees: 1-10.
Landscape fit: It fits this category because it provides an independent control layer around agent execution and enforces policy at runtime, rather than only monitoring or filtering prompts.
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. Quint appears to be a small founder led team with no clear public hiring push in the supplied sources.
Source: Privacy policy.
https://quintai.dev/privacy
-
2026-09-03:
Product snapshot
(product)
. Quint Security provides runtime behavioral security for AI agents. It intercepts agent activity at the OS and network layers, scores actions in real time, and can block, flag, or allow them while maintaining a cryptographic audit trail.
Source: Quint: Behavioral Security for AI Agents.
https://quintai.dev
-
2026-08-03:
Quint opens demo sales motion
(gtm)
. Quint directs prospects to contact sales and book a live demo for securing an AI agent fleet.
Source: Book a demo.
https://quintai.dev/demo
-
2026-06-01:
Quint adds security graph playbook
(product)
. Quint published a playbook that visualizes agent sessions, cloud resources, and API endpoints.
Source: Security graph playbook.
https://quintsecurity.mintlify.app/playbook/security-graph
-
2026-05-24:
Quint publishes category framing
(gtm)
. Quint published an educational post that defines AI agent runtime security as its category.
Source: What Is AI Agent Runtime Security? The Complete Definition.
https://quintai.dev/blog/what-is-ai-agent-runtime-security
-
2026-05-01:
Quint documents network extension telemetry
(product)
. Quint documented a macOS network extension and transparent proxy flow for telemetry and system approval.
Source: Network extension documentation.
https://quintsecurity.mintlify.app/edge/network-extension
NOFire
Website: nofire.ai
NOFire builds a runtime control layer for AI agents in production, using a live production model to gate actions and prevent unsafe changes before they reach external systems.
Category: Agent Runtime & Execution Security.
Funding stage: Seed.
Founded: 2024.
Country: Greece.
Employees: 11 to 50.
Landscape fit: It fits Agent Runtime & Execution Security because it checks each human or agent action at runtime and blocks policy violations before they affect production systems.
Funding rounds
-
seed
announced 2026-05-01
: 2500000 USD
; investors: Marathon Venture Capital, a16z venture scout fund
; source: NOFire AI newsroom
; https://www.nofire.ai/newsroom/context-control-model-launch
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. NOFire appears to be a small early team with multiple recent technical hires and a couple of current openings. The company is remote and is now hiring both go to market and operations support.
Source: NOFire AI LinkedIn company page.
https://www.linkedin.com/company/nofire-ai
-
2026-09-03:
Product snapshot
(product)
. NOFire provides a production AI control layer that maps live service relationships, tracks changes over time, and gates agent actions at runtime. It also supports read only access to production and observability data sources, VPC deployment, and incident analysis for engineering teams.
Source: NOFire official homepage.
https://www.nofire.ai
-
2026-09-01:
Orchestration lead joins
(hr)
. NOFire announced Alex Touloupis as the lead for its Orchestration and Context team.
Source: Welcoming Alex Touloupis.
https://www.nofire.ai/blog/welcoming-alex-touloupis
-
2026-08-01:
Benchmark result is published
(product)
. NOFire reported that it diagnosed 17 of 20 faults on SREGym lite under observe only conditions.
Source: AI SRE Benchmark: observe-only diagnosis on SREGym.
https://www.nofire.ai/blog/sregym-benchmark-nofire-results
-
2026-08-01:
Core infrastructure hire joins
(hr)
. NOFire announced Sergios Aftsidis as a founding member of technical staff on core infrastructure.
Source: Welcoming Sergios Aftsidis.
https://www.nofire.ai/blog/welcoming-sergios-aftsidis
-
2026-08-01:
Runtime controls hire joins
(hr)
. NOFire announced Maria Gkoutha as a member of technical staff on the Runtime and Controls team.
Source: Welcoming Maria Gkoutha.
https://www.nofire.ai/blog/welcoming-maria-gkoutha
AI Score
Website: aiscore.ai
AI Score builds an AI governance platform that monitors AI use across an organization and turns it into live controls, risk insight, and prioritized action.
Category: Agent Runtime & Execution Security.
Funding stage: Pre Seed.
Founded: 2025.
Country: United Kingdom.
Employees: 2-10.
Landscape fit: It fits the agent control layer category because it sits between AI activity and external systems, using policy, monitoring, and guardrails to stop unsafe or non compliant actions before they spread.
Funding rounds
-
Seed
announced 2026-09-04
: 4600000 EUR
; investors: Fuel Ventures, GALLOS Technologies, Robert Mann, Mo El Husseiny, Alan Morgan
; source: www.eu-startups.com
; https://www.eu-startups.com/2026/09/londons-ai-score-raises-e4-6-million-to-help-businesses-keep-ai-agents-under-control/
-
seed
announced 2026-09-03
: 5400000 USD
; investors: Fuel Ventures, GALLOS Technologies, Alan Morgan, Mo El Husseiny, Robert Mann
; source: Yahoo Finance / Sky News
; https://uk.finance.yahoo.com/news/former-ncsc-executive-raises-millions-070500745.html
-
pre-seed
announced 2025-11-01
: 750000 GBP
; investors: GALLOS Technologies
; source: Soapbox VC
; https://www.soapbox.vc/feed/ai-score-750k-pre-seed
Company timeline
-
2026-09-04:
AI Score expands platform outputs
(product)
. The platform page says AI Score continuously turns enterprise AI activity into compliance mapping, live asset inventory, security and risk views, usage insights, and adoption insights.
Source: Platform - AI Score.
https://aiscore.ai/platform
-
2026-09-04:
AI Score reports team size
(hr)
. AI Score’s LinkedIn page listed the company as having 2 to 10 employees.
Source: AI Score | LinkedIn.
https://www.linkedin.com/company/ai-score-ai
-
2026-09-04:
HR snapshot
(hr)
. AI Score appears to be a small London based team with founders active in the company and a current public sales hiring signal. The clearest opening is for a Founding SDR role.
Source: AI Score | LinkedIn.
https://www.linkedin.com/company/ai-score-ai
-
2026-09-04:
Product snapshot
(product)
. AI Score provides a private cloud SaaS and API driven AI governance platform for enterprises. It connects AI tools into a continuously updated governance view and surfaces monitoring, compliance, inventory, risk, usage, and adoption intelligence.
Source: Home - AI Score.
https://aiscore.ai
-
2026-09-04:
AI Score raises €4.6 million seed round
(funding)
. AI Score raised €4.6 million in seed funding to accelerate product development and expand its platform for managing generative and agentic AI.
Source: www.eu-startups.com.
https://www.eu-startups.com/2026/09/londons-ai-score-raises-e4-6-million-to-help-businesses-keep-ai-agents-under-control/
-
2026-09-03:
Seed
(funding)
. Amount: USD 5.4M. Investors: Fuel Ventures, GALLOS Technologies, Alan Morgan, Mo El Husseiny, Robert Mann
Source: Yahoo Finance / Sky News.
https://uk.finance.yahoo.com/news/former-ncsc-executive-raises-millions-070500745.html
Agent Testing & Assurance
Some agent failures only appear when the system is pushed into difficult situations. These products test agents independently to expose dangerous behavior before it reaches production.
Gray Swan
Website: grayswan.ai
Gray Swan is an AI security company that tests AI models and agents for unsafe behavior before and during deployment.
Category: Agent Testing & Assurance.
Funding stage: Series A.
Founded: 2023.
Country: United States.
Employees: unknown.
Landscape fit: It fits Agent Testing & Assurance because its Shade and Arena products are built to stress test AI systems and surface dangerous behavior before production.
Funding rounds
-
Series A
announced 2026-05-01
: 40000000 USD
; investors: Wing Venture Capital, Madrona, Obvious Ventures, Snowflake Ventures, Hudson River Trading, Samsung Next, Magarac Venture Partners
; source: Gray Swan
; https://www.grayswan.ai/news/gray-swan-announces-series-a
-
seed
announced 2024-08-01
: 5500000 USD
; investors: friends and family, nontraditional investor, organizations focused on AI safety and security
; source: Pittsburgh Post-Gazette
; https://www.post-gazette.com/business/tech-news/2024/08/11/companies-ai-pittsburgh-startup-graw-swan/stories/202408110042
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. Gray Swan appears to be a small research led team with named founders and a few executives. The public careers page suggests hiring interest, but the supplied evidence does not show a clear active multi role hiring cluster.
Source: Gray Swan.
https://www.grayswan.ai/about
-
2026-09-03:
Product snapshot
(product)
. Gray Swan provides automated adversarial testing, continuous red teaming, and runtime AI security for enterprises and frontier labs. Its core products are Shade for adversarial red teaming, Cygnal for runtime protection and monitoring, and Arena for large scale adversarial red teaming.
Source: Gray Swan.
https://www.grayswan.ai/about
-
2026-07-01:
Gray Swan integrates with TrueFoundry
(product)
. Gray Swan added Cygnal into TrueFoundry’s AI gateway so enterprises can apply runtime policy checks and indirect prompt injection detection in the gateway path.
Source: Gray Swan.
https://www.grayswan.ai/news/gray-swan-integrates-with-truefoundry
-
2026-05-28:
Gray Swan partners with Snowflake
(gtm)
. Gray Swan announced a partnership with Snowflake that natively integrates its runtime AI protection into Snowflake's AI ecosystem.
Source: Gray Swan.
https://www.grayswan.ai/news/gray-swan-announces-series-a
-
2026-05-01:
Series A
(funding)
. Amount: USD 40M. Investors: Wing Venture Capital, Madrona, Obvious Ventures, Snowflake Ventures, Hudson River Trading, Samsung Next, Magarac Venture Partners
Source: Gray Swan.
https://www.grayswan.ai/news/gray-swan-announces-series-a
-
2026-05-01:
Gray Swan gains frontier lab customer traction
(gtm)
. Forbes reported that Gray Swan was used by OpenAI, Anthropic, Google DeepMind, Meta, xAI, and ByteDance, and that frontier labs made up most of its revenue.
Source: Forbes.
https://www.forbes.com/sites/rashishrivastava/2026/05/28/this-ai-startups-army-of-15000-hackers-pressure-test-claude-gpt-5-and-gemini
Giskard
Website: giskard.ai
Giskard builds software that tests and red teams AI agents and LLM applications before production, with a focus on finding security, reliability, and quality failures.
Category: Agent Testing & Assurance.
Funding stage: Seed.
Founded: 2021.
Country: France.
Employees: 11-50.
Landscape fit: It fits Agent Testing & Assurance because its core product is an evaluation and red teaming platform designed to expose agent failures, vulnerabilities, and quality issues before deployment.
Funding rounds
-
grant
announced 2024-07-16
: 3000000 EUR
; investors: Bpifrance / France 2030
; source: Giskard
; https://www.giskard.ai/knowledge/giskard-leads-genai-evaluation-in-france-2030s-argimi-consortium
-
grant
announced 2023-08-22
: 2500000.99 EUR
; investors: European Commission / EIC Accelerator
; source: CORDIS
; https://cordis.europa.eu/project/id/190198093
-
grant
announced 2023-07-27
: 500000 EUR
; investors: Bpifrance / France 2030
; source: Giskard
; https://www.giskard.ai/knowledge/1-000-github-stars-3meu-and-new-llm-scan-feature
-
seed
announced 2022-12-01
: 1500000 EUR
; investors: Elaia, Bessemer Venture Partners, Julien Chaumond, Oscar Salazar, Christine Balagué, Nathalie Gaveau, Charles Gorintin, Nick Hernandez, Vincent Huguet, Shéhérazade Semsar de Boisséson, Chris Schagen, Victor Coisne
; source: Giskard closes its first financing round
; https://www.giskard.ai/knowledge/news-fundraising-2022
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. Giskard is publicly hiring and shows a team that spans research, engineering, product, and sales functions. The clearest active opening is for an AI safety and security researcher.
Source: Giskard history and investors.
https://www.giskard.ai/about
-
2026-09-03:
Product snapshot
(product)
. Giskard provides an enterprise platform for AI agent testing and continuous red teaming, plus an open source Python library for LLM testing and evaluation. The scope also includes benchmark work, guardrails, and scenario based vulnerability scans for security and quality failures.
Source: Giskard documentation hub.
https://docs.giskard.ai
-
2026-09-01:
Hub 3.0 launches
(product)
. Giskard released Hub 3.0 with support for any AI agent API, structured scenarios, more built in checks, and a customizable LLM judge.
Source: Release Notes.
https://docs.giskard.ai/hub/ui/release-notes
-
2026-08-01:
AI safety researcher role opens
(hr)
. Giskard posted an AI Safety and Security Researcher role in Paris and said it was hiring people in the EU or willing to relocate.
Source: Giskard hiring AI safety and security researcher.
https://www.linkedin.com/jobs/view/ai-safety-security-researcher-at-giskard-4441992518
-
2026-07-13:
BPCE case study published
(gtm)
. Giskard said BPCE used its red teaming before launch on a customer facing banking assistant and now runs three AI assistants through continuous testing.
Source: BPCE secured its customer facing chatbot with Giskard.
https://www.giskard.ai/knowledge/how-bpce-secured-its-customer-facing-banking-chatbot
-
2026-07-06:
Phare benchmark expands
(product)
. Giskard updated the Phare benchmark with 13 new models and a larger leaderboard.
Source: Phare LLM Benchmark site.
https://phare.giskard.ai
Verno Labs
Website: vernolabs.ai
Verno Labs builds offensive security tools that test AI agents for vulnerabilities before they reach production.
Category: Agent Testing & Assurance.
Funding stage: Pre Seed.
Founded: 2025.
Country: United Kingdom.
Employees: 2 to 10 employees.
Landscape fit: It fits this category because it focuses on testing agents with offensive simulations to find dangerous behavior and weaknesses before production use.
Funding rounds
-
pre-seed
announced 2026-01-28
: 1600000 USD
; investors: Marathon Venture Capital
; source: Marathon Venture Capital
; https://marathon.vc/blog/pallma-ai-raises-usd1-6m-pre-seed-to-build-the-security-layer-for-ai-agents
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. Verno Labs is a very small team with public evidence of one recent cybersecurity hire and a compact leadership bench. The company appears to be building core technical capability around offensive AI security.
Source: Verno Labs LinkedIn company page.
https://www.linkedin.com/company/verno-labs
-
2026-09-03:
Product snapshot
(product)
. Verno Labs provides offensive security tooling for AI agents. Its public site says the platform deploys custom offensive LLMs across text, voice, and multimodal interactions, and it offers Verno Red, Verno Guard, and Verno Fix as the core surfaces.
Source: Verno Labs — Offensive Security for AI Agents.
https://vernolabs.ai
-
2026-08-01:
Cybersecurity engineer joins Verno Labs
(hr)
. Pavlos Mitsoulis announced that Tasos Lepipas joined Verno Labs as Member of Technical Staff in cybersecurity and would work on Verno Red.
Source: Verno Labs hire announcement.
https://www.linkedin.com/posts/pavlosmitsoulis_welcome-to-verno-labs-formerly-pallma-ai-activity-7495049803853258752-i7_7
-
2026-08-01:
Interactive demo is published
(gtm)
. Verno Labs exposed an interactive product tour on its demo domain to show how offensive security for AI agents works from campaigns to findings.
Source: Interactive product tour | Verno Labs.
https://demo.vernolabs.ai/demo/cms392esh099izq0kn48js2ba
-
2026-08-01:
Campaigns workflow appears
(product)
. A Verno Labs product post described Campaigns as the workflow for adversarial testing of AI agents and said the first version focused on one campaign against one agent.
Source: Interactive product tour for Verno Labs.
https://www.linkedin.com/posts/iampanagiotis_interactive-product-tour-verno-labs-activity-7488514657922695169-UFVB
-
2026-08-01:
Black Hat booth announcement
(gtm)
. Verno Labs said it would attend Black Hat USA at Booth 6103 and would demonstrate live attacks against production agents.
Source: Verno Labs at Black Hat USA.
https://www.linkedin.com/posts/verno-labs_verno-labs-is-coming-to-black-hat-usa-find-activity-7480180392323452928-ntX1
Trent AI
Website: trent.ai
Trent AI builds an agentic security platform that scans code, cloud systems, and AI agents to find risk, propose fixes, and verify that those fixes landed before production.
Category: Agent Testing & Assurance.
Funding stage: Seed.
Founded: 2025.
Country: United Kingdom.
Employees: 2-10 employees.
Landscape fit: It fits Agent Testing & Assurance because it evaluates AI agents for risky behavior and security gaps before they reach production, rather than only monitoring them after deployment.
Funding rounds
-
seed
announced 2026-04-07
: 13000000 USD
; investors: LocalGlobe, Cambridge Innovation Capital, Joaquin Quiñonero Candela, Avinash Bhat, Ippokratis Pandis, Tony Jebara, Yaniv Altshuler, Praveen Mandal, Alexander Sainty
; source: Trent AI
; https://trent.ai/blog/trent-ai-raises-13m-to-secure-the-agentic-age
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. Trent AI is a small seed stage team with a named founding group and a visible hiring push in engineering and security roles.
Source: Trent AI LinkedIn company page.
https://www.linkedin.com/company/trentai
-
2026-09-03:
Product snapshot
(product)
. Agentic AI security platform for enterprise teams. Trent scans code, cloud and agentic systems, builds architecture and inventory views, traces attack paths, proposes fixes, and verifies remediation, with shared workspaces and role based access for teams.
Source: About Trent AI.
https://trent.ai/about-us
-
2026-08-01:
Trent AI adds organization workspaces
(product)
. Trent AI released organization workspaces with role based access control, shared analyses, and GitHub connections for enterprise teams.
Source: Trent AI.
https://trent.ai/blog/organization-workspaces-role-based-access-control
-
2026-08-01:
Trent AI ships a new workspace experience
(product)
. Trent AI updated its security engineer experience to use one project flow with Understand, Plan, and Secure sections, plus inline review and regrading.
Source: Trent AI.
https://trent.ai/blog/ai-security-engineer-new-experience
-
2026-07-01:
Trent AI launches agentic workload support
(product)
. Trent AI said its security engineer now secures agentic workloads and showed how it traces attack chains in agent frameworks.
Source: Trent AI.
https://trent.ai/blog/ai-security-engineer-agentic-workloads
-
2026-07-01:
Trent AI introduces its AI Security Engineer
(product)
. Trent AI introduced its core product as an AI Security Engineer that maps systems, inventories agents and tools, and produces prioritized findings with remediation guidance.
Source: Trent AI.
https://trent.ai/blog/ai-security-engineer
Agent Observability & Evidence
Control is not enough if the evidence comes from the agent itself. These products create an independent record of execution so teams can verify what the agent actually did.
Paper Compute
Website: papercompute.com
Paper Compute builds agent telemetry and evidence tools that capture what AI agents actually did, so teams can search, replay, audit, and reuse real sessions.
Category: Agent Observability & Evidence.
Funding stage: .
Founded: 2025.
Country: United States.
Employees: 1-10.
Landscape fit: It fits Agent Observability & Evidence because its core product records agent sessions, tool calls, retries, and execution paths into a durable record that teams can inspect independently of the agent itself.
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. Paper Compute appears to be a very small founder led team with a founding engineer on board. Public sources do not show broad hiring beyond core engineering.
Source: About Paper Compute.
https://papercompute.com/about
-
2026-09-03:
Product snapshot
(product)
. Paper Compute provides an agent telemetry and evidence stack for recording what AI agents actually did, then searching, replaying, auditing, and reusing those sessions. The public surface includes a hosted console, a local CLI and daemon, an open source trace layer, and a skills workflow built from captured sessions.
Source: Official homepage.
https://papercompute.com
-
2026-08-17:
Paper Compute adds open core cassettes
(product)
. Paper Compute released cassettes as a way to extend tapes through a shared API namespace and OpenAPI contract.
Source: Tapes: Free and Open AI Data.
https://papercompute.com/blog/tapes-open-core
-
2026-08-10:
Paper Compute publishes codex subagents support
(product)
. Paper Compute added support for Codex subagents rendering inside their parent session.
Source: Changelog - Paper Compute.
https://papercompute.com/changelog
-
2026-08-10:
Paper Compute adds ChatGPT app capture
(product)
. Paper Compute shipped persistent capture for the ChatGPT desktop app, the IDE extension, and Codex launches through paperd.
Source: Capture the ChatGPT app - Paper Compute Docs.
https://papercompute.com/docs/paper/cli/codex-app
-
2026-08-01:
Paper Compute adds Confluent export
(product)
. Paper Compute introduced a Confluent cassette that streams derived telemetry from tapes into Confluent Cloud.
Source: Paper Compute + Confluent - Agent Telemetry in the Confluent You Already Run.
https://papercompute.com/confluent
Fact0
Website: fact0.io
Fact0 provides a tamper evident audit layer for AI agents that records tool use and execution history so teams can prove what an agent actually did.
Category: Agent Observability & Evidence.
Founded: 2026.
Country: India.
Employees: 1-10.
Landscape fit: It fits agent observability and evidence because it creates an independent, cryptographically verifiable record of agent execution instead of relying on the agent or app logs alone.
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. Fact0 appears to be a very small founder led team. The supplied evidence does not show active public hiring or a broader recruitment push.
Source: Fact0 privacy policy.
https://fact0.io/legal/privacy
-
2026-09-03:
Product snapshot
(product)
. Fact0 provides a managed platform for AI agent accountability. It logs tool calls, execution traces, and audit events, then lets users verify hash chains, replay runs, and export evidence packs.
Source: Fact0 - Security reviews for AI agents.
https://fact0.io
-
2026-07-01:
Fact0 launches its core audit platform
(product)
. Fact0 said the product was live and described it as a tamper evident audit layer for AI agents.
Source: Yash Chauhan post about Fact0 launch.
https://www.linkedin.com/posts/iyashjayesh_golang-aiagents-compliance-activity-7470372449805660160-MLkd
-
2026-06-23:
Fact0 improves dashboard help and tours
(product)
. Fact0 updated several dashboard pages with contextual help and page local tours.
Source: Changelog - Fact0.
https://docs.fact0.io/changelog
-
2026-06-13:
Fact0 adds LLM traces in the dashboard
(product)
. Fact0 added an LLM Traces page that shows model spans, token counts, latency, prompt previews, and model metadata.
Source: Changelog - Fact0.
https://docs.fact0.io/changelog
-
Claude Code integration available
(product)
. Fact0 provides a Claude Code plugin that turns coding sessions into a tamper evident audit log and can block dangerous actions before they run.
Source: Fact0 Claude Code integration.
https://fact0.io/claude-code
Vaara
Website: vaara.io
Vaara builds software that sits in front of AI agents, gates each tool call, and writes a tamper evident execution record so teams can verify what the agent actually did. ([vaara.io](https://vaara.io/?utm_source=openai))
Category: Agent Observability & Evidence.
Funding stage: Bootstrapped.
Founded: 2026.
Country: Finland.
Employees: unknown.
Landscape fit: It fits Agent Observability & Evidence because it creates an independent, tamper evident record of agent actions and decisions instead of relying on the agent's own logs. ([vaara.io](https://vaara.io/?utm_source=openai))
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. Henri Sirkkavaara is the visible founder and builder of Vaara. The supplied evidence does not show a reliable current headcount or a public hiring push.
Source: Henri Sirkkavaara profile.
https://www.linkedin.com/in/sirkkavaara
-
2026-09-03:
Product snapshot
(product)
. Open source AI agent governance software that intercepts tool calls, applies policy decisions, and writes tamper evident execution records for offline verification and compliance evidence.
Source: Vaara — Accountable Autonomy.
https://vaara.io
-
2026-08-29:
Conformance register published
(product)
. Vaara published a public conformance register and independent reproduction rows for its receipt and verification system.
Source: Conformance results.
https://vaara.io/conformance.html
-
2026-08-01:
Expanded runtime surface
(product)
. Vaara v1.58.0 added a macOS menu bar app, an authenticated HTTP server, and human approvals tied to exact argument shape.
Source: Vaara v1.58.0.
https://www.linkedin.com/posts/sirkkavaara_vaara-v1580-activity-7489968986621804544-JfcA
-
2026-08-01:
Commercial licensing offered
(gtm)
. Henri Sirkkavaara said Vaara offers commercial licences for teams that need the product customized for their usage.
Source: Vaara v1.58.0.
https://www.linkedin.com/posts/sirkkavaara_vaara-v1580-activity-7489968986621804544-JfcA
-
2026-07-01:
Sovereign inference harness
(product)
. Henri Sirkkavaara said Vaara opened a sovereign inference harness that places the proof layer in front of a local model and can bind responses to TPM attestation.
Source: Sovereign inference harness launch.
https://www.linkedin.com/posts/sirkkavaara_sovereignai-aigovernance-confidentialcomputing-activity-7472778690700042240-1wFl
Agnys
Website: agnys.net
Agnys is an evidence and observability layer for AI agents that records model calls, tool use, file edits, approvals, and other side effects into a tamper evident session history for review and compliance.
Category: Agent Observability & Evidence.
Employees: unknown.
Landscape fit: It fits Agent Observability & Evidence because the product is built to create an independent, reviewable record of what agents actually did, rather than relying only on the agent’s own logs.
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. Agnys looks like a solo founded company with no clear public hiring signal in the supplied evidence.
Source: LinkedIn post.
https://www.linkedin.com/posts/ashish-reddy0_ai-agent-audit-trails-compliance-agnys-activity-7483401997409251329-c1K5
-
2026-09-03:
Product snapshot
(product)
. Agnys provides AI agent audit trails and observability software. It captures model calls, tool use, file edits, commands, approvals, side effects, and costs into a tamper evident session history with replay, search, alerts, baselines, anomaly detection, and compliance export.
Source: AI Agent Audit Trails & Compliance.
https://agnys.net
-
2026-08-01:
Agnys starts a public benchmark
(product)
. Agnys said it was developing a public benchmark for agent evidence systems and invited practitioners to review the benchmark language.
Source: Agent Evidence Benchmark v0.1 | Agnys.
https://agnys.net/agent-evidence-benchmark
-
2026-08-01:
Agnys launches in beta
(product)
. Ashish Vardhan Reddy Avuluri publicly launched Agnys as an early beta on Product Hunt. He said he built the initial product solo and positioned it as a flight recorder for AI agents with tamper evident audit trails.
Source: LinkedIn post.
https://www.linkedin.com/posts/ashish-reddy0_ai-agent-audit-trails-compliance-agnys-activity-7483401997409251329-c1K5
-
Public pricing available
(gtm)
. Agnys offers a free Developer plan, a $49 per month Team plan, and custom Enterprise pricing for regulated organizations.
Source: Agnys.
https://agnys.net
Tenet AI
Website: tenetai.dev
Tenet AI builds an auditability platform for AI agents that records decisions, reasoning, and execution evidence for regulated teams.
Category: Agent Observability & Evidence.
Funding stage: .
Founded: 2026.
Country: United States.
Employees: 11-50.
Landscape fit: It fits this category because it creates an independent record of agent decisions and execution, which helps teams verify what an agent actually did instead of relying only on the agent’s own logs.
Company timeline
-
2026-09-03:
HR snapshot
(hr)
. Tenet AI is a very small founder led company. Its LinkedIn page lists 2 to 10 employees, and there is no clear public hiring push.
Source: Tenet AI LinkedIn.
https://www.linkedin.com/company/go-tenet-ai
-
2026-09-03:
Product snapshot
(product)
. Tenet AI provides an auditability layer for AI agents. It records reasoning and execution evidence, replays decisions, and supports compliance workflows for regulated enterprises.
Source: Tenet AI home page.
https://tenetai.dev
-
2026-05-01:
Tenet launches publicly
(product)
. Tenet introduced its decision auditability product to the public.
Source: Product Hunt launch overview for Tenet AI.
https://hunted.space/product/tenet-ai-prove-every-ai-decision
-
Public pricing available
(gtm)
. Tenet AI offers a free Developer tier alongside paid Team, Business, and Enterprise plans for its decision auditability platform.
Source: Tenet AI.
https://tenetai.dev