Category 4 of 12 · Controls: What agents exist
Agent discovery and AI posture
Tools that find agents, copilots, MCP servers, and the credentials behind them across SaaS, cloud, and endpoints, and flag risky configuration. Often sold as AI security posture management.
Mitigates: ASI04 Agentic Supply Chain Vulnerabilities, ASI10 Rogue Agents, LLM03 Supply Chain
Vendors, by signal score
- #1Geordie AI41
Agent security and governance platform that discovers agents across cloud, code, and endpoints, maps each agent's tools and permissions, keeps an auditable record of every tool invocation, and steers agent behavior through its Beam remediation engine.
- #2Noma Security29
AI security platform that discovers agents, models, MCP servers, and skills across cloud, SaaS, and endpoints, keeps an approved-agent registry with per-tool access policies, and monitors agent sessions at runtime.
- #3Apex SecurityAcquired by Tenable10
Discovery and governance of how employees and agents use enterprise AI platforms. Acquired by Tenable in 2025; the product now ships as Tenable One AI Exposure.
Ranked within this category only. How the score works.
Also covers this category
- Aim SecurityAcquired by Cato Networks17
AI security for employee AI use, coding agents, and MCP: discovers agents, inspects prompts and tool calls, and blocks unsafe actions at runtime. Acquired by Cato Networks in 2025; now part of Cato's SASE platform.
- AIR31
Context firewall for AI agents: vets skills, plugins, MCP servers, and sub-agents before they are installed, keeps a marketplace of approved add-ons, discovers sanctioned and shadow agents, and blocks malicious agent actions at runtime.
- Astrix SecurityAcquired by Cisco30
Non-human identity and AI agent security: inventories agents, MCP servers, and secrets, assigns human owners, and issues short-lived, just-in-time access. Acquired by Cisco in 2026.
- Check PointPlatform suite55
The Check Point AI Defense Plane combines Workforce AI Security, AI Application and Agent Security, and AI Red Teaming (in limited release), built on the Lakera acquisition (Lakera Guard and Lakera Red) and the Cyata agent discovery acquisition.
- Cyera55
Data security platform whose AI Guardian discovers AI models and agents, maps them to the identities and data they can reach, evaluates tool invocations and data access against policy at runtime, and can quarantine an agent.
- Entro SecurityAcquired by SailPoint16
Non-human identity and secrets security: discovers AI agents, MCP servers, and secrets, maps each to a human owner, and detects anomalous use. Acquired by SailPoint in 2026.
- Lasso Security39
GenAI and agent security platform with intent-based runtime guardrails, a CPU-only guardrail model (LEAP), agent discovery, and policy over which tools and resources an agent may use.
- Operant AI37
Runtime defense for AI applications and agents, including an MCP Gateway that catalogs MCP servers and tools, enforces trust zones and least-privilege tool permissions, and blocks untrusted servers and data flows inline.
- Palo Alto NetworksPlatform suite65
Prisma AIRS: AI runtime security, agent security, AI red teaming, model scanning, posture management, and an AI gateway, built partly from acquisitions of Protect AI, Koi (agentic endpoint security), and Portkey (now Prisma AIRS AI Gateway), with CyberArk as its identity security platform.
- Pillar Security10
AI agent security platform: RedGraph runs multi-turn adversarial attacks against agents to test tool orchestration and permission escalation, alongside AI discovery and posture, runtime guardrails, and governance.
- SailPointPlatform suite74
SailPoint Agentic Fabric inventories AI agents and machine identities, ties each agent to a human owner through its lifecycle, applies real-time authorization, and disables rogue agents and revokes their credentials. The Entro Security acquisition extends it to non-human identity discovery.
- SentinelOnePlatform suite55
AI security built on the Prompt Security acquisition: runtime protection for employee and homegrown AI, discovery of shadow MCP servers and agents, Prompt AI Agent Security (preview) for agent governance, and Prompt AI Red Teaming.
- SPLXAcquired by Zscaler10
Automated AI red teaming with thousands of attack simulations, plus runtime guardrails, prompt hardening, and discovery of models, workflows, and MCP servers. Acquired by Zscaler in 2025 and now sold as Zscaler AI Red Teaming.
- Straiker36
Agent security platform: Discover AI inventories agents and MCP servers, Ascend AI red-teams them, and Defend AI blocks prompt injection, data exfiltration, and destructive actions at runtime, with a kill switch to cut off or shut down a rogue agent.
- Token Security29
Identity security for AI agents and non-human identities: discovers agents and MCP servers, assigns human owners, right-sizes permissions by intended purpose, and retires unused agents.
- VezaAcquired by ServiceNow50
Identity security platform built on a permissions graph; its AI Agent Security product discovers agents and MCP servers, assigns human owners, and shows what data each agent can reach. Acquired by ServiceNow in 2026.
- WitnessAI36
AI security and governance for employees and agents: catalogs AI apps, agents, and MCP servers, applies intent-based policy by department and role, enforces control at the tool-call and MCP-server level, and blocks prompt injection and jailbreaks.
- Zenity49
Agent security and governance platform: catalogs agents across SaaS, custom frameworks, and endpoints, correlates each agent's identities with its tools, data, and behavior, and detects and blocks prompt injection, data leakage, and unauthorized tool calls at runtime.
Questions to ask a vendor
- Does discovery cover SaaS copilots and coding agents, not only cloud AI services?
- Does it map each agent to the credential and data it can reach?
- Does it assign a human owner to every discovered agent?
Go deeper
FAQ
- What is AI security posture management?
- Continuous discovery and configuration assessment for AI assets: models, agents, data connections, and their permissions, similar to what cloud posture management does for cloud resources.
- What is a shadow agent?
- An agent built or connected without security review, often by a business team on a SaaS platform. It usually runs on a person's credentials and outlives that person's interest in it.