Guardians of Agents

Industry map · last updated September 21, 2026 (fact-checked row by row)

The Agent Security Industry

Who is building the controls for AI agents: 169 startups, incumbents, platforms, labs and open-source projects, sorted by the method they use, how mature and how well funded they are, who bought whom, and who benefits.

169organizations mapped
40acquisitions since Aug 2024
$7Bventure funding tracked
$2.8Bmarket for securing AI, 2026 (Gartner)
46ship open-source or open-core code
12segments in 4 layers

What the market looks like, in eight points

A snapshot of a market that barely existed three years ago. Prices marked "reported" come from press sources, not the companies.

  1. The market consolidated in two years.

    We track 40 acquisitions of agent- and AI-security companies since August 2024. Nearly every major security vendor bought at least one. Disclosed or reported prices for startups range from about $50M (Aporia) to about $1B (Oasis, and Veza as reported), and $1.7B for data-security scale-up Securiti; the platform deals alongside them are far larger (CyberArk ~$25B, Wiz $32B).

  2. Identity produced the biggest startup exits.

    Identity was the hottest acquisition target: Oasis ($1B, confirmed by Cyera), Veza (~$1B reported, ServiceNow), Astrix (~$400M reported, Cisco), and Entro and Permiso (~$200M each reported). Buyers are betting that controlling what an agent is allowed to do matters more than filtering what it says.

  3. Money still flows to independents.

    Large 2026 rounds include Cyera ($600M at a $12B valuation), Modal ($355M at $4.65B), Zenity ($125M), HiddenLayer ($100M), WorkOS ($100M at $2B), Straiker ($64M) and Runlayer ($30M). We tracked $7B raised by independent and acquired companies.

  4. The market is small, fast and opaque.

    Gartner sizes the market for securing AI at about $2.8B in 2026, rising to $7.7B in 2028; other analysts range from $3B to $19B depending on definition. Only one vendor discloses an AI-security revenue line (Palo Alto Networks, over $100M ARR), so real market shares cannot be measured from public data.

  5. Platforms are bundling the basics.

    Microsoft Agent 365 ($15 per user per month), AWS AgentCore Policy, Google Agent Gateway and Okta Agent SSO (included in core SSO) put identity, policy and inventory inside the platforms. Point products must now win on cross-platform coverage or depth.

  6. Methods are converging on deterministic control.

    The core of most 2026 architectures is identity plus a gateway plus policy, with classifiers as an extra layer. That matches the research record: out-of-band controls hold up better under adaptive attack than filters that try to spot bad text.

  7. Open source is foundational but fragile.

    46 of 169 organizations here ship open-source or open-core code. Acquisitions cut both ways: OpenAI says it will keep building Promptfoo's open-source project and Portkey open-sourced its gateway, but LLM Guard was archived after its owner was acquired.

  8. MCP became a sub-market in a year.

    MCP gateways and scanners (Runlayer, Obot, Kong, Docker, ToolHive, Snyk Agent Scan) and big-vendor MCP catalogs appeared within twelve months of the protocol. Enkrypt AI reported vulnerabilities in 73% of 25,000 MCP servers it scanned (a vendor claim).

Market map

Four layers, twelve segments. Within each segment, leaders come first. Click any company for its profile. Colors mark the layer; the style marks ownership.

IndependentAcquired (→ buyer)Major / publicOpen source / nonprofit
Runtime controlstop bad actions as they happen
Guardrails & AI firewalls 13
AI & MCP gateways 9
Agent identity & access 31
Sandboxes & isolation 7
Visibility & governanceknow what agents exist and do
Posture, discovery & governance 30
Observability & tracing 8
Assurancetest before and after deployment
Red teaming & evaluation 15
Model & supply-chain security 9
Research & testing labs 5
Platforms & ecosystemwho bundles it, what is shared
AI platforms (built-in controls) 11
Security incumbents 17
Open source & standards 14

Taxonomy: layers, segments and methods

How the industry divides the problem. The chips on the right are the most common technical methods in each segment, with the number of organizations using them.

Agent security169 organizationsRuntime control60 organizationsGuardrails & AI firewalls13 · inspect prompts, content and outputs inlineclassifier 13gateway 7red team 6SDK 4AI & MCP gateways9 · one checkpoint for model and tool trafficpolicy 9gateway 9tracing 3identity 3Agent identity & access31 · who is acting, with which permissionspolicy 20identity 18graph 13SDK 9Sandboxes & isolation7 · run agent code and browsers in a boxsandbox 7SDK 4tracing 1red team 1Visibility & governance38 organizationsPosture, discovery & governance30 · inventory agents, map risk, set usage policypolicy 19classifier 14graph 13gateway 9Observability & tracing8 · record every step an agent takestracing 8LLM judge 6SDK 5classifier 1Assurance29 organizationsRed teaming & evaluation15 · attack your own agents firstred team 14LLM judge 6classifier 5sandbox 4Model & supply-chain security9 · scan models, skills and AI artifactsscan 9graph 3red team 2classifier 2Research & testing labs5 · frontier testing and evaluationsred team 3formal 2sandbox 2LLM judge 2Platforms & ecosystem42 organizationsAI platforms (built-in controls)11 · agent builders shipping their own controlspolicy 8identity 6classifier 6gateway 5Security incumbents17 · buy, bundle and cross-sellclassifier 14gateway 12red team 7SDK 6Open source & standards14 · shared tools, protocols and threat mapsLLM judge 3SDK 3identity 3sandbox 3

The methods, explained

policy 69

Deterministic rules (Cedar, OPA, allowlists) decide what an agent may do.

classifier 60

A small trained model scores prompts, documents or outputs as malicious or safe.

gateway 54

All model and tool traffic is routed through a checkpoint that can log, rewrite or block.

red team 41

Automated or human attackers probe the system to find failures.

identity 38

Each agent gets its own identity and short-lived, scoped credentials.

SDK 37

A library the developer adds to the agent's code.

graph 36

Permissions, identities and data flows are mapped as a graph to find risky paths.

tracing 31

Every step of an agent run is recorded for debugging, evaluation and forensics.

LLM judge 28

A second language model reviews the first model's inputs, plans or outputs.

scan 27

Files, models, tool descriptions or configs are inspected before use.

sandbox 20

Code and browsers run inside isolated microVMs or containers.

browser 10

An extension watches what users and browser agents do in web apps.

endpoint 8

An agent on the laptop or server watches processes, extensions and local AI tools.

formal 4

Mathematical or program-analysis guarantees about behavior.

hardware 1

Trusted execution environments or hardware isolation.

Consolidation: who bought whom

41 acquisitions in our data. Left: buyers, sized by number of deals. Right: targets, colored by layer, with date and price.

AcquirerTargetSegment · date · pricePalo Alto Networks (4)Protect AIModel & supply chain · 2025-04 · $500M (reported)CyberArk (Idira)Identity & access · 2025-07 · $25BKoiPosture & governance · 2026-02 · $400M (reported)PortkeyAI & MCP gateways · 2026-04 · undisclosedCisco (3)Robust IntelligenceRed teaming & evaluation · 2024-08 · $400M (reported)GalileoObservability & tracing · 2026-04 · undisclosedAstrix SecurityIdentity & access · 2026-05 · $400M (reported)F5 (2)CalypsoAIGuardrails & firewalls · 2025-09 · $180MSurePath AIPosture & governance · 2026-06 · undisclosedCheck Point (2)LakeraGuardrails & firewalls · 2025-09 · undisclosed (reported)CyataPosture & governance · 2026-02 · undisclosedIBM (1)HashiCorp VaultIdentity & access · 2024-04 · $6.4BCoralogix (1)AporiaGuardrails & firewalls · 2024-12 · $50M (reported)CoreWeave (1)W&B WeaveObservability & tracing · 2025-03 · $1.7B (reported)Google (1)WizPosture & governance · 2025-03 · $32BTenable (1)Apex SecurityPosture & governance · 2025-05 · $105M (reported)Snyk (1)Invariant LabsAI & MCP gateways · 2025-06 · undisclosedSentinelOne (1)Prompt SecurityPosture & governance · 2025-08 · $250M (reported)Cato Networks (1)Aim SecurityPosture & governance · 2025-09 · $350M (reported)CrowdStrike (1)PangeaGuardrails & firewalls · 2025-09 · $260M (reported)Veeam (1)SecuritiPosture & governance · 2025-10 · $1.7BTwilio (1)StytchIdentity & access · 2025-10 · undisclosedZscaler (1)SPLXRed teaming & evaluation · 2025-11 · undisclosedServiceNow (1)VezaIdentity & access · 2025-12 · $1B (reported)ClickHouse (1)LangfuseObservability & tracing · 2026-01 · undisclosedProofpoint (1)AcuvityPosture & governance · 2026-02 · undisclosedMintlify (1)HeliconeObservability & tracing · 2026-03 · undisclosedOpenAI (1)PromptfooRed teaming & evaluation · 2026-03 · undisclosedDatabricks (1)AntimatterIdentity & access · 2026-03 · undisclosedSilverfort (1)Fabrix SecurityIdentity & access · 2026-04 · undisclosedAkamai (1)LayerXPosture & governance · 2026-05 · $205MSnowflake (1)NatomaIdentity & access · 2026-05 · $110M (reported)A10 Networks (1)TrojAIRed teaming & evaluation · 2026-06 · undisclosedSailPoint (1)Entro SecurityIdentity & access · 2026-06 · $200M (reported)Keyfactor (1)CofideIdentity & access · 2026-07 · undisclosedCyera (1)Oasis SecurityIdentity & access · 2026-07 · $1BOkta (1)Permiso SecurityIdentity & access · 2026-07 · $200M (reported)Anaconda (1)Enkrypt AIGuardrails & firewalls · 2026-08 · undisclosedFortinet (1)Virtue AIRed teaming & evaluation · 2026-08 · undisclosedKiteworks (1)Bonfy.AIPosture & governance · 2026-09 · undisclosed (reported)Beacon Software (1)Haize LabsRed teaming & evaluation · 2026-09 · undisclosed

Deal timeline

Each dot is a deal, sized by price (log scale). Hollow dots: price not disclosed.

JulOctJan 2025AprJulOctJan 2026AprJulOctWiz → Google, 2025-03-18, $32BCyberArk (Idira) → Palo Alto Networks, 2025-07-30, $25BHashiCorp Vault → IBM, 2024-04-24, $6.4BSecuriti → Veeam, 2025-10-21, $1.7BW&B Weave → CoreWeave, 2025-03-04, $1.7B (reported)Veza → ServiceNow, 2025-12-02, $1B (reported)Oasis Security → Cyera, 2026-07-28, $1BProtect AI → Palo Alto Networks, 2025-04-28, $500M (reported)Robust Intelligence → Cisco, 2024-08-26, $400M (reported)Koi → Palo Alto Networks, 2026-02-17, $400M (reported)Astrix Security → Cisco, 2026-05-04, $400M (reported)Aim Security → Cato Networks, 2025-09-03, $350M (reported)Pangea → CrowdStrike, 2025-09-16, $260M (reported)Prompt Security → SentinelOne, 2025-08-05, $250M (reported)LayerX → Akamai, 2026-05-14, $205MEntro Security → SailPoint, 2026-06-15, $200M (reported)Permiso Security → Okta, 2026-07-30, $200M (reported)CalypsoAI → F5, 2025-09-11, $180MNatoma → Snowflake, 2026-05-27, $110M (reported)Apex Security → Tenable, 2025-05-29, $105M (reported)Aporia → Coralogix, 2024-12-23, $50M (reported)Invariant Labs → Snyk, 2025-06-24, undisclosedLakera → Check Point, 2025-09-16, undisclosed (reported)Stytch → Twilio, 2025-10-30, undisclosedSPLX → Zscaler, 2025-11-04, undisclosedLangfuse → ClickHouse, 2026-01-16, undisclosedAcuvity → Proofpoint, 2026-02-12, undisclosedCyata → Check Point, 2026-02, undisclosedHelicone → Mintlify, 2026-03-03, undisclosedPromptfoo → OpenAI, 2026-03-09, undisclosedAntimatter → Databricks, 2026-03-24, undisclosedGalileo → Cisco, 2026-04-09, undisclosedFabrix Security → Silverfort, 2026-04-28, undisclosedPortkey → Palo Alto Networks, 2026-04-30, undisclosedTrojAI → A10 Networks, 2026-06-15, undisclosedSurePath AI → F5, 2026-06, undisclosedCofide → Keyfactor, 2026-07-27, undisclosedEnkrypt AI → Anaconda, 2026-08-04, undisclosedVirtue AI → Fortinet, 2026-08-17, undisclosedBonfy.AI → Kiteworks, 2026-09-11, undisclosed (reported)Haize Labs → Beacon Software, 2026-09-17, undisclosedHashiCorp Vault $6.4BRobust Intelligence $400MW&B Weave $1.7BWiz $32BProtect AI $500MCyberArk (Idira) $25BSecuriti $1.7BVeza $1BKoi $400MAstrix Security $400MOasis Security $1B

Where the money went

Filled dots: total venture funding of a company. Rings: price paid for an acquired company. Squares: last valuation when funding is not public. Log scale; hover or tap a dot for the figure. Public companies and open-source projects are left out.

$1M$10M$100M$1B$10BGuardrails &firewallsPrediction Guard: raised $4MGuardrails AI: raised $8MPillar Security: raised $9MLasso Security: raised $37MAporia: acquired for $50MArthur: raised $60MStraiker: raised $85MCalypsoAI: acquired for $180MPangea: acquired for $260MCalypsoAIPangeaAI &MCP gatewaysLunar.dev: raised $6MPortkey: raised $18MObot AI: raised $35MRunlayer: raised $42MKong AI Gateway: valued at $2BRunlayerKong AI GatewayIdentity &accessAnon: raised $6MFabrix Security: raised $8MCerbos: raised $11MAntimatter: raised $12MPermit.io: raised $14MP0 Security: raised $20MOso: raised $25MToken Security: raised $27MClutch Security: raised $28MComposio: raised $29MBritive: raised $36MKeycard: raised $38MAembit: raised $45MOak: raised $60MArcade.dev: raised $72MDescope: raised $88MNatoma: acquired for $110MStytch: raised $120MTeleport: raised $169MEntro Security: acquired for $200MPermiso Security: acquired for $200MSilverfort: raised $222MAstrix Security: acquired for $400MOasis Security: acquired for $1BVeza: acquired for $1BWorkOS: valued at $2BVezaWorkOSSandboxes &isolationNorthflank: raised $22MModal: valued at $4.7BNorthflankModalPosture &governanceUnbound: raised $4MSurePath AI: raised $6MCyata: raised $8MAcuvity: raised $9MBonfy.AI: raised $10MSingulr AI: raised $10MKnostic: raised $14MLumia Security: raised $18MHarmonic Security: raised $26MGeordie AI: raised $36MCredo AI: raised $41MAurascape: raised $50MNightfall AI: raised $60MWitnessAI: raised $85MReco: raised $85MApex Security: acquired for $105MNoma Security: raised $132MZenity: raised $185MLayerX: acquired for $205MPrompt Security: acquired for $250MAim Security: acquired for $350MKoi: acquired for $400MSecuriti: acquired for $1.7BOrca Security: valued at $1.8BCyera: raised $2.3BWiz: acquired for $32BCyeraWizObservability &tracingGalileo: raised $68MBraintrust: valued at $800MLangChain: valued at $1.2BW&B Weave: acquired for $1.7BLangChainW&B WeaveRed teaming& evaluationRepello AI: raised $1MSPLX: raised $9MPromptfoo: raised $23MVirtue AI: raised $30MGray Swan AI: raised $50MPatronus AI: raised $70MHaize Labs: valued at $100MRobust Intelligence: acquired for $400MScale AI: valued at $29BRobust IntelligenceScale AIModel &supply chainManifold Security: raised $8MManifest: raised $23MCranium: raised $32MHiddenLayer: raised $156MProtect AI: acquired for $500MChainguard: raised $900MProtect AIChainguardResearch labsFAR.AI: raised $30MMETR: raised $71MIrregular: raised $80MMETRIrregular

Segment scorecard

Size, ownership mix, maturity spread, license mix and money for each segment. Maturity: 1 research, 2 early product, 3 generally available, 4 scaled, 5 category standard.

SegmentOrganizations by statusMaturity 1–5 (count)LicenseMoney trackedGuardrails & AI firewalls13Independent: 77Acquired: 55Open source / nonprofit: 1maturity 2: 2maturity 3: 8maturity 4: 3proprietary: 10open_core: 2open_source: 1$323M raised · $490M in dealsAI & MCP gateways9Independent: 66Acquired: 22Open source / nonprofit: 1maturity 2: 3maturity 3: 4maturity 4: 2proprietary: 2open_core: 5open_source: 2$101M raisedAgent identity & access31Independent: 1818Acquired: 1010Major / public: 33maturity 1: 1maturity 2: 7maturity 3: 14maturity 4: 7maturity 5: 2proprietary: 25open_core: 6$1.6B raised · $2.9B in dealsSandboxes & isolation7Independent: 77maturity 2: 2maturity 3: 3maturity 4: 2proprietary: 4open_core: 3$22M raisedPosture, discovery & governance30Independent: 1818Acquired: 1111Major / public: 1maturity 2: 11maturity 3: 13maturity 4: 5maturity 5: 1proprietary: 30$3.2B raised · $3B in dealsObservability & tracing8Independent: 44Acquired: 44maturity 2: 1maturity 3: 3maturity 4: 4proprietary: 2open_core: 4open_source: 2$68M raised · $1.7B in dealsRed teaming & evaluation15Independent: 77Acquired: 66Major / public: 1Open source / nonprofit: 1maturity 2: 3maturity 3: 8maturity 4: 2maturity 5: 2proprietary: 12open_core: 2open_source: 1$227M raised · $400M in dealsModel & supply-chain security9Independent: 55Acquired: 1Major / public: 22Open source / nonprofit: 1maturity 2: 1maturity 3: 3maturity 4: 4maturity 5: 1proprietary: 8open_source: 1$1.2B raised · $500M in dealsResearch & testing labs5Independent: 44Major / public: 1maturity 1: 1maturity 2: 1maturity 3: 2maturity 4: 1proprietary: 5$181M raisedAI platforms (built-in controls)11Major / public: 1111maturity 2: 1maturity 3: 4maturity 4: 6proprietary: 9open_core: 1open_source: 1n/a (public / OSS)Security incumbents17Independent: 22Major / public: 1515maturity 2: 2maturity 3: 14maturity 4: 1proprietary: 16open_core: 1n/a (public / OSS)Open source & standards14Open source / nonprofit: 1414maturity 2: 1maturity 3: 5maturity 4: 3maturity 5: 5open_source: 14n/a (public / OSS)12345
IndependentAcquiredMajor / publicOpen sourceProprietaryOpen coreOpen-source license

How big is the market?

Analyst estimates disagree by a factor of five because they define the market differently. Dots: current estimate; line: forecast. Only one vendor reports revenue for this line of business: Palo Alto Networks' Prisma AIRS passed $100M in annual recurring revenue with about 800 customers.

$1B$3B$10B$30BGrand View ResearchAI trust, risk and security management market$14.1B by 2033 (23%/yr)$2.8B (2025)GartnerMarket for securing AI (AI app security, AI usage co…$7.7B by 2028$2.8B (2026)Precedence ResearchAI TRiSM market$21.1B by 2035 (22%/yr)$3B (2025)MarketsandMarketsAI TRiSM market$11.6B by 2031 (30%/yr)$3.1B (2026)Gartner'Securing AI' segment of information security spendi…$37.6B by 2030 (18%/yr)$15.6B (2025)SNS InsiderAI agent security market$507.6B by 2035 (39%/yr) →$18.7B (2025)

Sources: Gartner · Gartner · MarketsandMarkets · Grand View Research · Precedence Research · SNS Insider

The twelve segments

What each segment does, how it works, how mature and effective it is, and who benefits.

Runtime control stop bad actions as they happen

Guardrails & AI firewalls

13 organizations: 7 independent · 5 acquired · 1 open source / nonprofit

Products that sit in the request path and inspect what goes into and comes out of a model: user prompts, retrieved documents, tool results and responses. They block prompt injection, jailbreaks, toxic output and leaks of sensitive data.

How it works
Mostly small fine-tuned classifiers, sometimes backed by an LLM judge, regex and data-loss rules. Delivered as an API call, an SDK or an inline proxy; several now run at the network edge (Cloudflare runs Llama Guard on its GPUs) or on CPUs only (Lasso claims under 5 ms, its own measurement).
Maturity
Generally available and widely bought, and the fastest-consolidating segment: Lakera, Prompt Security, CalypsoAI, Pangea, Aporia and Enkrypt AI have all been acquired.
How well it works
Cheap, fast and effective against known and low-effort attacks. The research record says classifiers are bypassed by adaptive attackers far more often than their static scores suggest, so treat them as one layer, not a security boundary.
Who benefits
Application teams shipping chat assistants and agents; regulated firms that need data-loss controls on AI traffic.
Open source
NVIDIA NeMo Guardrails, Meta LlamaFirewall / Prompt Guard, Guardrails AI. Protect AI's LLM Guard was archived in July 2026 after the Palo Alto Networks acquisition.
Strengths
  • Drop-in; no change to the agent's design
  • Low latency and vendor-neutral
  • Doubles as data-loss prevention
Limits
  • Probabilistic: misses novel attacks, blocks some benign requests
  • Sees one message at a time, not multi-step intent
  • Adaptive attackers tune against it

Leaders:

AI & MCP gateways

9 organizations: 6 independent · 2 acquired · 1 open source / nonprofit

A proxy between agents and the models and tools they call. AI gateways centralize keys, routing, cost and logging for model calls; MCP gateways keep a registry of approved tool servers, check tool descriptions and enforce per-tool permissions.

How it works
Reverse proxy plus policy engine, OAuth 2.1 for MCP servers, allowlists, tool-description scanning and full request logging.
Maturity
Young but scaling. AI gateways are mature (Kong; Portkey reported over one trillion tokens a day before Palo Alto Networks agreed to buy it). MCP gateways appeared within a year of MCP's launch: Runlayer, Obot, Docker, Stacklok ToolHive, Lunar.dev. Open-core is the norm.
How well it works
Strong for inventory, audit and least-privilege tool access, because enforcement is deterministic. It only sees traffic that is routed through it, and judging whether a tool call is harmful still needs semantics.
Who benefits
Platform and infrastructure teams rolling out MCP and agents across a company.
Open source
Portkey gateway (open-sourced March 2026), Obot, Stacklok ToolHive, Docker MCP Gateway, Snyk Agent Scan (ex-Invariant mcp-scan), Trail of Bits mcp-context-protector.
Strengths
  • Single choke point across vendors
  • Deterministic allow/deny for tools
  • Natural place for a kill switch
Limits
  • Blind to traffic that bypasses it
  • Adds a hop of latency
  • Tool descriptions and servers change constantly

Leaders:

Agent identity & access

31 organizations: 18 independent · 10 acquired · 3 major / public

Give every agent its own identity, issue short-lived and narrowly scoped credentials, let it act on a user's behalf without sharing the user's password, and find and rotate the secrets agents leave behind (non-human identities, NHI).

How it works
OAuth token exchange and delegation, workload identity (SPIFFE), secrets discovery, permission graphs and policy engines such as Cedar and OPA. Standards are arriving: MCP authorization, and Okta's Cross App Access adopted as MCP's Enterprise-Managed Authorization.
Maturity
The most mature control, because it extends identity and access management that enterprises already run. It is also where the largest startup exits happened: Oasis ($1B, Cyera), Veza (~$1B reported, ServiceNow), Astrix (~$400M reported, Cisco), Entro and Permiso, plus Palo Alto Networks' ~$25B CyberArk deal.
How well it works
Limits the blast radius of any compromise, including prompt injection, and is fully auditable. It cannot stop an agent from misusing permissions it legitimately holds.
Who benefits
Identity teams, CISOs, and SaaS builders that expose APIs to agents.
Open source
SPIFFE/SPIRE; open-core authorization engines (Cerbos, Oso, Permit.io).
Strengths
  • Deterministic and auditable
  • Works whatever the model does
  • Fits existing IAM budgets and teams
Limits
  • Misuse of granted rights still possible
  • Delegation semantics for agents are immature
  • Identity sprawl as agents multiply

Leaders:

Sandboxes & isolation

7 organizations: 7 independent

Run the code an agent writes, and the browsers it drives, inside disposable isolated environments so a mistake or an attack cannot reach the host or other tenants.

How it works
Firecracker microVMs, gVisor, hardened containers, ephemeral per-task environments and network egress controls.
Maturity
Scaled infrastructure. Modal reports more than a billion sandboxes launched and over $300M annualized revenue; Docker and Cloudflare shipped agent sandboxes in April 2026. Fine-grained egress and data controls are less mature than the isolation itself.
How well it works
Strong, deterministic containment of code execution. It does nothing about what the agent does through legitimate APIs, or data it sends out over allowed channels.
Who benefits
Builders of coding agents and computer-use agents, AI labs, platforms that run untrusted code.
Open source
Firecracker, gVisor, Anthropic sandbox-runtime, open-core E2B and Daytona.
Strengths
  • Hard isolation boundary
  • Open-source foundations
  • Scales to millions of runs
Limits
  • Does not govern API actions
  • Exfiltration over allowed egress
  • Performance and cost trade-offs

Leaders:

Visibility & governance know what agents exist and do

Posture, discovery & governance

30 organizations: 18 independent · 11 acquired · 1 major / public

Find every AI app and agent in use, including 'shadow AI', map what data and permissions each can reach, score the risk, and enforce usage policy and compliance (for example the EU AI Act).

How it works
API-based discovery across agent platforms, browser extensions, inline proxies, data classification, permission graphs and policy engines.
Maturity
The most crowded segment (30 organizations here) and heavily acquired (11). Many startups are at early-product stage; Zenity, Noma, Cyera and Wiz lead.
How well it works
Gives security teams the visibility they lack today, which is a prerequisite for everything else. Much of it detects and reports after the fact; agentless inventory misses local and custom-built agents.
Who benefits
CISOs, governance/risk/compliance teams, Microsoft 365 Copilot and SaaS administrators.
Open source
Few; this segment is almost entirely proprietary.
Strengths
  • Visibility first; easy for a CISO to buy
  • Supports compliance evidence
  • Covers SaaS copilots and low-code agents
Limits
  • Crowded and overlapping offerings
  • Largely detective, not preventive
  • Coverage gaps for home-grown agents

Leaders:

Observability & tracing

8 organizations: 4 independent · 4 acquired

Record every prompt, tool call and result an agent produces, score runs with evaluations, and keep a forensic trail.

How it works
SDK instrumentation, OpenTelemetry GenAI conventions (still marked 'Development'), LLM-judge scoring and dashboards.
Maturity
Developer tools are mature, and the segment is being absorbed: Langfuse (ClickHouse), Galileo (Cisco/Splunk), Weights & Biases (CoreWeave), Helicone (Mintlify).
How well it works
Essential for incident response, debugging and deciding when to pull a kill switch; it does not prevent anything by itself.
Who benefits
AI engineering teams, SOC and incident responders.
Open source
Langfuse, Arize Phoenix, OpenTelemetry GenAI conventions.
Strengths
  • Forensic record of agent behavior
  • Feeds evaluation and red-team loops
  • Strong open-source options
Limits
  • Not preventive
  • Logs contain sensitive data
  • Standards still settling

Leaders:

Assurance test before and after deployment

Red teaming & evaluation

15 organizations: 7 independent · 6 acquired · 1 major / public · 1 open source / nonprofit

Attack agents before and after deployment to find failures: prompt injection, jailbreaks, data leakage, unsafe tool use.

How it works
Automated attack generation with attacker LLMs and reinforcement learning, probe libraries, benchmark suites and human expert red teams.
Maturity
Generally available and consolidating: Promptfoo (OpenAI), SPLX (Zscaler), Virtue AI (Fortinet), TrojAI (A10), Haize Labs (Beacon), Robust Intelligence (Cisco). Promptfoo reports use at more than a quarter of the Fortune 500.
How well it works
Finds real bugs and produces compliance evidence. Results are point-in-time and not comparable across tools, and automated attackers are weaker than a determined adaptive human.
Who benefits
AppSec and AI red teams, model builders, auditors.
Open source
Promptfoo (MIT; OpenAI says the open-source project continues), NVIDIA garak, Microsoft PyRIT, UK AISI Inspect.
Strengths
  • Finds real failures before attackers do
  • Evidence for audits and customers
  • Mature open-source tools
Limits
  • Coverage is never complete
  • Scores not comparable across tools
  • Point-in-time unless continuous

Leaders:

Model & supply-chain security

9 organizations: 5 independent · 1 acquired · 2 major / public · 1 open source / nonprofit

Check model files, datasets, agent skills and tool servers for malware and tampering, and keep an AI bill of materials (AI-BOM).

How it works
Static scanning of model formats (for example unsafe pickle files), signature and provenance checks, registry monitoring and AI-BOM generation.
Maturity
Mature for model files: Protect AI's scanner had checked 4.47M Hugging Face model versions by April 2025, and JFrog became a second Hugging Face scanning partner. New artifact types such as agent skills and MCP servers are the frontier (Manifold says it has indexed over 238,000 skills).
How well it works
Reliable for known malicious patterns; weak against novel backdoors hidden in model weights.
Who benefits
ML platform teams, AppSec, companies that pull open models and skills.
Open source
ModelScan; Hugging Face Hub scanning is free to users.
Strengths
  • Deterministic for known threats
  • Fits existing software supply-chain tooling
  • Registry-scale coverage
Limits
  • Weight-level backdoors are hard to detect
  • New artifact types appear monthly
  • False sense of safety if treated as complete

Leaders:

Research & testing labs

5 organizations: 4 independent · 1 major / public

Independent labs that test frontier models and agents for dangerous capabilities, scheming and security weaknesses, often for AI companies and governments.

How it works
Custom evaluation harnesses, adversarial testing, sandboxed capability trials and program analysis.
Maturity
Small and influential. Irregular raised $80M in September 2025 and is reported to be profitable; METR and Apollo Research publish evaluations used in frontier model launches.
How well it works
High-quality findings for a handful of frontier systems; not a product most enterprises can buy.
Who benefits
Frontier AI labs, governments and AI safety institutes.
Open source
Some tools and evals released openly (for example UK AISI Inspect is used widely).
Strengths
  • Deep expertise
  • Independent of the vendors they test
  • Sets the evaluation agenda
Limits
  • Low capacity
  • Mostly serves frontier labs
  • Results often under NDA

Leaders:

Platforms & ecosystem who bundles it, what is shared

AI platforms (built-in controls)

11 organizations: 11 major / public

The companies that build and host agents, shipping security controls inside their platforms.

How it works
Native agent registries and identities (Microsoft Entra Agent ID, Google Agent Identity), policy at the gateway (AWS AgentCore Policy in Cedar, Google Agent Gateway), model-level defenses (Anthropic's Constitutional Classifiers++, about 1% extra compute) and bundled posture tools.
Maturity
Rapid bundling: Microsoft Agent 365 went GA on May 1, 2026 at $15 per user per month; AWS AgentCore Policy went GA in March 2026; Okta includes Agent SSO in core SSO at no extra cost.
How well it works
The default for customers inside one ecosystem, and cheap because bundled. Coverage stops at the platform's edge, and a platform grading its own agents has an obvious conflict of interest.
Who benefits
Customers standardized on one cloud or productivity suite.
Open source
NVIDIA NeMo Guardrails and garak; Meta PurpleLlama; open protocols (MCP, A2A).
Strengths
  • Native and bundled
  • Default choice inside an ecosystem
  • Deep model-level defenses
Limits
  • Single-ecosystem
  • Multi-cloud and cross-vendor gaps
  • Conflict of interest

Leaders:

Security incumbents

17 organizations: 2 independent · 15 major / public

Established security vendors that bought agent-security startups and fold them into firewalls, SASE, endpoint, identity and data-security suites.

How it works
Acquired runtime guardrails, red teaming, posture and identity, delivered through existing gateways and consoles.
Maturity
Every large vendor now has an offer, most built on 2025–2026 acquisitions. Palo Alto Networks is the only one to disclose a number: Prisma AIRS passed $100M annual recurring revenue with about 800 customers.
How well it works
Easy to buy and integrate with the security operations center; products acquired recently are still being integrated.
Who benefits
Large enterprises that already buy from these vendors.
Open source
Rare; OpenAI says Promptfoo's open-source project will continue.
Strengths
  • Procurement and integration ease
  • Global scale and support
  • Ties into SOC workflows
Limits
  • Integration lag after acquisitions
  • Slower innovation
  • Bundles can hide weak components

Leaders:

Open source & standards

14 organizations: 14 open source / nonprofit

Free tools, protocols and shared threat models that the whole industry builds on.

How it works
Threat taxonomies (OWASP Top 10 for LLM and Agentic Applications, MITRE ATLAS), protocols with security built in (MCP authorization, A2A, SPIFFE), telemetry standards (OpenTelemetry GenAI), and open tools for guardrails, red teaming and isolation.
Maturity
The taxonomies are de-facto standards; the protocols are still moving (MCP's July 2026 spec added issuer verification). Tools are well used but fragile when their sponsor is acquired.
How well it works
Creates a common language and a free baseline; quality and maintenance vary.
Who benefits
Everyone; especially small teams, researchers and educators.
Open source
All entries in this segment.
Strengths
  • Free and inspectable
  • Common vocabulary for buyers and vendors
  • Foundation for products
Limits
  • Maintenance risk after acquisitions
  • No support or SLA
  • Standards lag practice

Leaders:

Company table

All 169 organizations. Filter, sort by any column, and click a row for the full profile with sources. Download: CSV · Excel.

CompanySegmentApproachOwnershipFounded Funding / priceMaturityPositionLicenseNamed clients

Method and caveats

  • Data as of September 21, 2026. Every row was re-checked by an independent pass against primary sources (company and acquirer press releases, filings, GitHub) and reputable press; 50 of 169 rows were corrected and each profile shows its fact-check note. Data gathered from company announcements, filings and trade press (TechCrunch, SecurityWeek, SiliconANGLE, Calcalist and others). Every row lists its sources.
  • Deal dates are announcement dates. Acquisition prices are marked disclosed (stated by a party), reported (press citing sources) or undisclosed. Reported figures can conflict; Lakera's is shown as reported with both figures in the notes.
  • Funding totals are the latest public figures we could verify; blanks mean not found, not zero.
  • Maturity (1 research to 5 category standard) and position (leader, challenger, niche, emerging) are our editorial judgments from public evidence, not analyst rankings.
  • Market share is not published for this market. We show proxies instead: counts, money raised, deal values and the one disclosed revenue line.
  • Large vendors appear once, with their agent-security products and acquisitions listed together. Companies are placed in their primary segment; secondary segments appear as tags.
  • Inclusion is not endorsement. Corrections are welcome by email.

Related: the Research atlas maps the academic side of the same problem, and Issue 13 in the curriculum tells the story of the players.