All outcomes
    Outcome

    Secure AI agents & LLM apps

    Govern AI usage, protect LLMs and agents at runtime, and automate SOC investigations with AI.

    "We're shipping AI features and need to lock them down."

    Categories that solve this

    Pick the angle you care most about, or scroll for the full vendor list.

    All 906 tools for this outcome

    Air Security logo
    Air Security
    AI Runtime & Agent Security

    AIR secures every AI add-on before it becomes part of your enterprise. From discovery and continuous vetting to governance and runtime protection, AIR enables organizations to adopt AI safely. Air provides four solutions as a complete agentic security platform: - Air Control - Governance and control of agents across the enterprise, shadow ai discovery, posture management of agents configuration and connectivity - Air Defend - Runtime protection of agents behavior in real time. Visibility of every agent prompt and action, detection and response to dangerous and malicious behavior, runtime guardrails for agent behavior in realtime - Air Filter - Governing all agent add-ons which exist in the enterprise, continuously vetting of them, and detect and response to supply chain incidents. - Air Marketplace - Secured-by-default marketplace of pre-vetted add-ons, both external from open source and internally built, as a single source of truth for all enterprise usage

    Real-time prompt injection and jailbreak detection for LLM requests before they reach models used in agentic applications.
    Archestra.AI logo
    Archestra.AI
    AI Runtime & Agent Security

    Archestra.AI is an open source security and governance layer positioned between large language models, AI agents, and enterprise data systems. The platform enforces a deterministic control layer so that access rules for agents stay fixed and predictable, independent of model judgment or prompt wording. It includes a private registry for Model Context Protocol (MCP) servers that governs which tools agents can reach, a retrieval augmented generation stack that runs inside the customer's own infrastructure, and a Kubernetes native orchestrator for multi-team deployments. The product is self-hostable and targets organizations connecting AI agents to systems such as HR platforms, email, and internal communication tools. Archestra.AI is a London based, early stage, seed funded company.

    Private MCP server registry+5
    Artemis logo
    Artemis
    AI Security Posture (AI-SPM)

    Artemis is a specialized AI Security Posture Management (AI-SPM) platform focused on discovering, inventorying, and securing AI models, datasets, and notebooks across cloud environments. It provides continuous visibility into AI misconfigurations, exposure risks, and training-data classification, while mapping findings to OWASP LLM/ML Top 10. Artemis detects leaked AI credentials and assesses AI-BOM and supply-chain risks in ML pipelines. The vendor targets mid-to-large enterprises actively scaling AI adoption and needing operational governance without added headcount. Artemis also offers adjacent runtime security products, but its AI-SPM suite remains distinct for posture-focused buyers.

    AI inventory and bill of materialsAI misconfiguration and exposure scanning+4
    Burgus Security logo
    Burgus Security
    Application Security (DAST/SAST)

    I could not verify that a distinct vendor named Burgus Security has a documented Application Security product from the provided results. The only application-security-related result tied to the name is a directory-style entry that appears to refer to general application security services rather than a clearly described vendor platform. Based on the evidence available, Burgus Security cannot be reliably profiled as an AppSec product vendor, so the safest characterization is that its AppSec positioning is unconfirmed. If the intent was a different vendor name, the profile should be rebuilt from source documentation for that vendor.

    Inspects LLM API traffic in production to enforce security checkpoints on prompts, responses, and agent-to-model exchanges for agentic applications.
    CalypsoAI (F5) logo
    CalypsoAI (F5)
    AI Runtime & Agent Security

    CalypsoAI, acquired by F5 in 2025 and rebranded as F5 AI Guardrails (formerly Inference Defend), delivers runtime security for AI models, agents, and applications. It combines agentic red-teaming with swarms generating 10,000+ new attack prompts monthly and real-time inference-layer protection against prompt injection, jailbreaks, data exfiltration, and denial-of-service. The platform includes the CalypsoAI Security Index and Agentic Warfare Resilience leaderboards for model benchmarking, plus policy enforcement for GDPR, HIPAA, and EU AI Act compliance. Best for enterprises deploying production AI copilots, RAG apps, and autonomous agents needing continuous vulnerability testing and defense integrated with F5 ADSP.

    Runtime prompt injection blocking+8
    C
    Caver
    Agentic SOC & Investigations

    Caver is an AI-native security operations and investigation platform designed to automate and accelerate SOC workflows. It acts as an agentic layer on top of security telemetry, helping teams triage alerts, investigate incidents, and correlate signals across tools without manual context switching. Instead of static dashboards or rule-based alerting, it uses AI agents to reason over security data, surface likely threats, and guide or execute investigative steps. The platform reduces analyst workload by handling repetitive investigation tasks, enriching alerts with contextual intelligence, and streamlining escalation paths. It’s built to improve detection-to-response speed while maintaining human oversight for critical decisions.

    Multi-agent workflows across security lifecycleAutonomous entity-centric triage and investigation+4
    Conifers logo
    Conifers
    Agentic SOC & Investigations

    Conifers is a startup vendor focused on **agentic SOC and investigations** through its CognitiveSOC platform. Its core value in this category is autonomous, multi-stage security operations that connect threat intelligence, hunting, detection engineering, investigation, and remediation in one workflow, with actions governed by customer-defined guardrails and evidence trails. It is best suited for enterprises and MSSPs that want to layer AI-driven investigation and triage on top of existing security tools rather than replace their stack. The company also sells adjacent agentic SOC functions beyond investigations, but its investigation capability is central to the offer.

    Uses an agentic fabric to correlate threat intelligence, hunting, detection engineering, investigation, and remediation in a single workflow so findings move across SOC stages without manual handoffs.
    Contrast Security logo
    Contrast Security
    Application Security (DAST/SAST)

    Contrast Security provides an IAST platform that embeds agents into running applications, instrumenting code with sensors for real-time vulnerability detection and attack telemetry. Unlike external DAST scans or static SAST analysis, it analyzes data flows, application logic, and runtime behavior across development, CI/CD pipelines, and production. This reduces false positives by validating vulnerabilities in context, supports DevSecOps integration, and offers continuous monitoring for web apps, APIs, and microservices. Best for organizations prioritizing accurate, low-noise AppSec in agile environments over traditional black-box or white-box tools.

    Agent-based runtime vulnerability detectionContinuous monitoring with reduced false positives+8
    General Analysis logo
    General Analysis
    AI Runtime & Agent Security

    General Analysis is a security platform for organizations that run AI agents and large language model systems in production. It discovers and inventories AI assets, including models, vector stores, MCP servers and agent workflows, by connecting to code repositories, LLM providers and cloud infrastructure, and scores each asset by risk. The platform runs automated red team simulations covering prompt injection, tool misuse, sensitive data retrieval and multi step exploit chains to find exploitable gaps before an incident occurs. It also deploys runtime guardrails that block threats and monitor for policy violations and performance drift. Buyers include enterprise security teams securing employee copilots, customer support agents and AI workflows in healthcare, legal and financial services.

    AI asset discovery & inventory+5
    Groovy Security logo
    Groovy Security
    AI Security Posture (AI-SPM)

    Groovy Security helps enterprises adopt AI without losing control of their data, an AI Security Posture Management (AI-SPM) and GenAI data-protection platform built for complete visibility and inline control. We build two products. Whiteout AI is an AI interaction interception platform that inspects and enforces policy on every AI interaction in real time, across desktop, browser, IDE, MCP agents, and cloud. Its full-LLM detection engine reads context to make decisions on compliant user AI usage. Whiteout AI surfaces shadow AI, stopping sensitive data exfiltration, enforcing security guardrails, and mapping AI-specific compliance across heterogeneous AI environments. Deployed via Groovy Security or hosted by the client organization to maximize data security. Maestro: our AI-driven penetration testing platform, automates security testing across your APIs, cloud, and AI/ML pipelines. Purpose-built for a world where AI is both the innovator and the risk.

    Whiteout AI: Shadow AI discovery+8
    Heeler logo
    Heeler
    Static Application Security Testing (SAST)

    Heeler is an application security vendor focused on SAST-centric code analysis and remediation workflows, with product messaging that also spans adjacent AppSec functions such as secrets and open-source risk. In its SAST offering, Heeler emphasizes context-aware findings, runtime-aware prioritization, and validated fixes for developer teams that need to reduce alert noise and connect code issues to production behavior. It appears best suited for CISOs, AppSec, Product Security, and DevSecOps groups in cloud-native environments that want security findings tied to actual application context rather than static code-only results. The company also offers related AppSec posture and remediation capabilities beyond pure SAST/DAST.

    Context-aware SAST scanning+10
    ManageEngine PAM360 logo
    ManageEngine Endpoint DLP Plus
    Data Loss Prevention (DLP)

    ManageEngine Endpoint DLP Plus is an enterprise-grade endpoint data loss prevention solution that scans network endpoints to discover and classify structured and unstructured sensitive data using pre-defined or customizable templates. It monitors data-in-use, data-at-rest, and data-in-motion across endpoints via a centralized web console, enforcing policies to block unauthorized uploads to cloud storage, email transmissions to unpermitted addresses, and peripheral device access like USBs and printers. Designed for large organizations with distributed setups including WAN and mobile users, it supports GDPR compliance through incident management, user behavior analytics, and detailed audit reports. Best suited for enterprises needing comprehensive endpoint DLP in Windows environments.

    Discover and classify sensitive data+11
    NeuralTrust logo
    NeuralTrust
    AI Runtime & Agent Security

    NeuralTrust is an AI security platform that discovers and protects autonomous AI agents, models, and tools across an enterprise. Its runtime layer inspects every request an agent makes to models, tools, MCP servers, and data before execution, blocking prompt injection, data leakage, and unauthorized API calls in real time. The platform combines an agent gateway that enforces unified policies across homegrown apps, SaaS tools, and platforms like ChatGPT, Gemini, and Copilot, an agent discovery and posture module that inventories deployed agents and workflows, and adversarial red teaming to surface model vulnerabilities before deployment. It is built for enterprise security and compliance teams and deploys as SaaS, on premises, or hybrid, keeping the data plane local for data sovereignty.

    Runtime agent protection+5
    Phoenix Security logo
    Phoenix Security
    Application Security Posture Management (ASPM)

    Phoenix Security is an application security platform focused on finding and triaging code-level and runtime vulnerabilities across the software delivery lifecycle. In the DAST/SAST scope, it normalizes findings from source-code analysis, dynamic testing, and related appsec scanners into a single model, then uses runtime context to help prioritize remediation. Public materials also indicate support for air-gapped deployments and broader AppSec workflows, but the core value for buyers in this category is combining static and dynamic findings with remediation guidance. It is best suited for security teams and developers that need one place to correlate application vulnerability signals from multiple testing methods.

    Static application security testing for source code and compiled artifacts to identify issues such as injection flaws, unsafe input handling, and other OWASP Top 10-style defects before deployment.
    R
    Radware AppWall
    API Security

    Radware AppWall is Radware’s web application and API protection offering, positioned around positive security policy enforcement for HTTP-based services. In the API security scope, it protects REST, GraphQL, and SOAP endpoints with auto-generated policies, request validation, and attack blocking for abuse, injection, authentication bypass, and data theft attempts. It is best suited for enterprises that already use Radware application delivery infrastructure or need API protection tied to WAF policy enforcement rather than a standalone API gateway. The product is also used in environments with PCI-driven web application security requirements.

    Applies positive security model enforcement to API traffic, allowing only known-good request patterns and blocking anomalous calls that do not match the learned schema or policy.
    Raven logo
    Raven
    Application Security Posture Management (ASPM)

    Raven.io provides a runtime application security platform that runs inside cloud-deployed applications to detect and block malicious code execution as it happens, independent of whether a CVE exists. The platform includes application detection and response for forensic visibility down to libraries, functions and call paths, a runtime software composition analysis capability that uses reachability data to de-prioritize vulnerabilities, and a module for discovering and controlling AI agents operating inside application environments. It is aimed at enterprises running internet-facing applications on Kubernetes, containers and compute instances across AWS, GCP and Azure, supporting languages including Java, Python, JavaScript, Go, Ruby, PHP, C++ and .NET. Customers include organizations in regulated industries such as insurance and financial services.

    Runtime exploit prevention+5
    Skyhigh Security CASB logo
    Skyhigh Security CASB
    CASB (Cloud Access Security Broker)

    Skyhigh Security CASB is a cloud-based, multi-tenant Cloud Access Security Broker that deploys via forward and reverse proxy modes for real-time control over sanctioned and unsanctioned cloud services. It leverages the Cloud Registry for 50+ attribute risk assessments across 20,000+ services, enabling discovery, classification, and remediation. Key capabilities include DLP policy enforcement synced with endpoint DLP, machine learning-based UEBA for insider threat detection, malware analysis, configuration auditing against benchmarks with automated remediation, and contextual access controls. Best suited for enterprises needing comprehensive visibility and governance across hybrid cloud environments with SharePoint integration.

    Discover unsanctioned cloud servicesApply cloud data loss prevention+10
    Tenet Security logo
    Tenet Security
    AI Runtime & Agent Security

    Tenet Security provides runtime protection for autonomous AI agents inside enterprises. Its platform, built around a technique it calls Agent-side Simulation, models an agent's likely next actions before they execute against live systems and can block actions judged risky before they occur, rather than alerting after the fact. It addresses threats specific to agentic AI, including unauthorized access, data exfiltration, agent manipulation and a technique the company calls Agentjacking, where malicious content hidden in emails, documents, logs or databases covertly alters agent behavior. The company was founded by former Cisco AI Defense researchers Barak Sternberg and Nevo Poran and emerged from stealth in 2026 with a six million dollar seed round.

    Agent-side action simulation+5
    Trent AI logo
    Trent AI
    AI Runtime & Agent Security

    Trent AI builds an AI-native security platform for organizations building or operating autonomous AI agents. The product uses a coordinated set of scanning, judgment, mitigation and evaluation agents to continuously assess code, infrastructure and AI agent runtime behavior, detecting risks such as prompt injection, tool misuse, unintended actions, data exfiltration and privilege escalation. It prioritizes findings by real-world exploitability, generates remediation fixes or prompts for developer tools, verifies that fixes are deployed, and maps controls to compliance frameworks such as SOC 2 and NIST. It targets AI-native startups without dedicated security staff and enterprise security teams seeking automation, and can be deployed in public cloud, a customer VPC, or on-premises using frontier, open-source or private AI models.

    Continuous code and infra scanning+5