THE FULL AI SECURITY LANDSCAPE
61 companies, what each one actually does, and whether you would run it alongside Mountain Theory or instead of it. Most of this market is complementary. 41 of these work alongside us, 14 are genuine head-to-heads, and 6 do a different job entirely.
Mountain Theory sits at the execution layer: it checks the action an AI is about to take against your policy and returns ALLOW, HOLD or BLOCK. Almost nothing else in this table does that, which is why so many of these pair with us rather than compete.
Showing 61 of 61 companies
| Company | What they do | With Mountain Theory |
|---|---|---|
| ZenityInline agent runtime security | Controls agent actions inline inside Microsoft Foundry, Copilot Studio, AWS Bedrock and OpenAI AgentKit. Raised a $125MM Series C led by Norwest in August 2026. | Head to headRarely both. If all your agents live in those platforms Zenity covers them; Mountain Theory reaches the custom and on-prem agents that never touch those control planes. |
| Canyon RoadExecution-layer security for AI workloads | Three products on one control plane: agentsh wraps agents in CI, containers and dev environments; Beacon monitors AI desktop apps at the OS level; Watchtower holds central policy, approvals, SIEM export and a fleet kill switch. Outcomes are allow, block, prompt and redirect. | Head to headThe closest company to us on language and the earliest to publish on the term. They govern the environment an AI tool runs in; Mountain Theory evaluates the business action an agent proposes. Different unit, same sentence. |
| AiriaEnterprise AI security and orchestration | Platform for building and running enterprise AI agents, secured with role-based permissions, AI firewalls, runtime policy and audit evidence. Model agnostic. | Head to headRarely both. Airia if you want one platform to build the agents and secure them. Mountain Theory if the agents already exist and the control has to be independent of whoever built them. |
| Capsule SecurityAI agent runtime security | Open-source ClawGuard checkpoint that assesses agent intent before a tool call. | Head to headStart with ClawGuard if you are a developer team. Move to Mountain Theory when policy needs an owner outside engineering and an auditor needs evidence. |
| Eve SecurityAgentic AI intent and policy | Infers intent across multi-step reasoning chains to detect goal drift, with Agent-in-the-Loop review. | Head to headBoth check before the action. Eve reasons probabilistically about intent; Mountain Theory checks the action deterministically so the answer is auditable. |
| Sondera.aiDeterministic policy enforcement | Open-source harness that compiles natural-language rules into formally verified Cedar policy and enforces outside the model. | Head to headClosest philosophy in the market. Sondera for coding agents inside dev frameworks; Mountain Theory for production agents across the business. |
| Obsidian SecurityAgent security inside third-party SaaS | Governs how AI agents act inside third-party business applications, with visibility, access controls and runtime protection against unauthorised agent actions. Raised an $85MM Series D in August 2026 at about $1.1B. | Head to headThe same reach question as Zenity, in a different place. Obsidian covers agents operating inside your SaaS applications. Mountain Theory reaches the custom and on-prem agents that never touch a SaaS control plane, and governs the action itself rather than the application it lands in. Large estates will have both. |
| Geordie AIAI agent security and governance | Maps the agentic footprint across an enterprise and applies automated mitigations at platform level. | Works alongsideGeordie tells you where your agents are. Mountain Theory governs what they do. Discovery feeds enforcement. |
| StraikerAgentic AI security | Runtime protection for AI agents, aimed at enterprises and frontier labs. In August 2026 published its own definition of the 'AI agent execution gap' and in September launched Heimdall, a hardened sandbox for high-risk agent evaluation. | Head to headSimilar problem statement. Evaluate on whether control is model and framework agnostic and whether policy is written by the risk owner. |
| AIR SecurityInline firewall for AI agents | Emerged from stealth on 1 September 2026 with $50MM led by Sequoia and Greenoaks. Protects agents from malicious instructions, untrusted data and compromised tools, and governs which tools, skills, plug-ins and MCP servers an agent may use. | Head to headAIR filters what reaches the agent and which tools it may call. Mountain Theory checks the specific action the agent then proposes against policy, whatever got it there. Different control point, same worry. |
| Trent AIAI agent security | Security for autonomous AI agents. London-based, backed by OpenAI, Spotify and Databricks operators. | Head to headSame category, earlier stage. Worth watching rather than displacing today. |
| MultifactorMulti-agent security controls | Verifiable, fine-grained controls for complex multi-agent systems, built for CISOs. | Head to headOverlapping intent on multi-agent estates. Very early. |
| Operant AIMCP and runtime security | Runtime security for AI applications and MCP deployments. Launched Semantic Firewall in August 2026, which Operant describes as enforcing an agent's intent inline before an action executes. | Head to headOperant now says it stops an action at the MCP boundary. Mountain Theory governs the business action whatever route it arrived by, with the policy written and owned outside engineering. |
| RunlayerMCP security | Security for MCP server deployments. First mover on the protocol. | Works alongsideRun both if MCP is central. They harden the connection, we govern the action it enables. |
| Astrix Security (Cisco)Non-human identity | Discovers and governs API keys, service accounts, OAuth tokens and AI agent identities. Acquired by Cisco. | Works alongsideRun both. Astrix establishes who the agent is and that its credentials are sound. Mountain Theory decides whether the action it is attempting is allowed right now. |
| Permiso SecurityIdentity threat detection for agents | Detects threats across human, non-human and agentic identities in multi-cloud environments, and sandboxes agent skills and prompts. Okta announced the acquisition on 30 July 2026 (just under $200MM per TechCrunch; Okta stated no price) and closed it on 26 August 2026. | Works alongsideRun both. Permiso tells you an agent identity is behaving unlike itself. Mountain Theory decides whether the action that agent is attempting right now is allowed, whether or not anything about it looks unusual. |
| SaviyntAI identity and access management | Extends enterprise IAM to AI agents with an identity control plane. | Works alongsideRun both. Saviynt authorises the identity at session start; Mountain Theory authorises every action after it. |
| Oasis SecurityNon-human identity management | Machine identity lifecycle: discovery, governance and remediation of NHIs. Cyera agreed to acquire Oasis on 28 July 2026 at a reported $1B and announced completion in September 2026. | Works alongsideRun both. Credential hygiene lowers how often a wrong actor acts; execution control decides whether the act goes through. |
| WideField Security (Cisco)Identity lifecycle for the agentic SOC | Identity, credential and session intelligence feeding Splunk investigations. Acquired by Cisco. | Works alongsideSequential. WideField helps the SOC understand an agentic incident; Mountain Theory reduces how many reach the SOC. |
| HiddenLayerAI model and agentic runtime security | Scans model artifacts across 35+ formats and defends at inference without needing weights, training data or prompts. Raised a $100MM Series B on 2 September 2026, led by Delta-v Capital, for agentic runtime security and a product for securing AI coding agents. | Works alongsideRun both. HiddenLayer tells you the model is trustworthy. Mountain Theory governs what a trustworthy model then does. |
| Noma SecurityUnified AI and agent security | AI asset discovery, data context, posture management and an agentic risk map. | Works alongsideRun both in a large estate. Noma shows exposure; Mountain Theory intercepts the transaction. |
| Protect AI (Palo Alto)ML security platform | Model scanning, posture, red teaming and runtime, now the core of Prisma AIRS. | Works alongsideNow part of Palo Alto. See the Prisma AIRS entry. |
| Robust Intelligence (Cisco)AI firewall and red teaming | AI Firewall for real-time model protection, now Cisco AI Defense. | Works alongsideContent and model protection. Mountain Theory covers the action layer neither addresses. |
| Oligo SecurityApplication-level AI integrity | eBPF kernel-level runtime monitoring of AI workloads, catching library-level exploits. Raised $60MM in August 2026 to $140MM total, named by AWS as its AI runtime security partner for Security Hub Extended, and in Palantir FedStart on the way to FedRAMP High. | Works alongsideDifferent depth of the stack. Oligo watches the workload; Mountain Theory gates the action. |
| MindgardAI red teaming | First DAST for AI. Continuous automated red teaming with a large attack library. Raised a $30MM Series A in August 2026, led by Album VC. | Works alongsideTesting, not enforcement. Mindgard finds the weakness; Mountain Theory is what stops it being exploited in production. |
| TrojAI (A10 Networks)AI red teaming and runtime protection | Red teaming that probes models, agents and applications at build time, plus real-time threat protection at runtime. Acquired by A10 Networks, announced 15 June 2026, to support sovereign AI security. | Works alongsideBuild-time assurance plus their own runtime layer, now inside a network infrastructure vendor. Their runtime defends the model and the application. Mountain Theory governs the action a clean model triggers, so the two sit at different points and most estates would run both. |
| Haize LabsAI safety ratings | Red teaming that produces safety ratings, working with frontier labs. | Different jobRatings and benchmarks. Different buyer, different purpose. |
| NoveeAutonomous AI pen testing | Autonomous black-box red teaming with a proprietary AI attacker. | Different jobOffensive testing. Complements any defensive control including ours. |
| SPLX (Zscaler)AI runtime protection and guardrails | Inline prompt and output filtering, natural-language policy, red teaming, now inside Zscaler. | Works alongsideRun both. SPLX stops the model saying something unsafe; Mountain Theory stops the agent doing something unsafe. Different failure. |
| Prompt Security (SentinelOne)GenAI security | Inspects every prompt and response for DLP, injection and jailbreaks. Now in Singularity. | Works alongsideContent safety. Sits before the action layer, not on it. |
| Lakera (Check Point)GenAI security | Real-time protection from prompt injection, data leakage and toxic content. | Works alongsidePrompt-layer defence. Mountain Theory is the backstop for when the prompt filter is beaten. |
| Guardrails AIOpen-source LLM guardrails | Programmable guardrails on LLM outputs, developer-first. | Works alongsideOutput validation. Pairs with, does not substitute for, execution control. |
| Virtue AIAI security and compliance | Multi-modal guardrail suite with continuous model benchmarking, strong academic pedigree. Acquired by Fortinet, announced 17 August 2026, terms not disclosed. | Works alongsideContent and model assurance alongside action control. |
| Galileo AIAI evaluation platform | Evaluation foundation models detecting hallucination, injection, PII and toxicity in real time. Acquired by Cisco, completed 22 May 2026, and now sold as Splunk Agent Observability. | Works alongsideOutput quality and safety. Different question from whether an action should run. |
| Patronus AILLM evaluation and testing | Automated evaluation detecting LLM mistakes at scale. | Different jobEvaluation tooling. Rarely in the same procurement. |
| Arthur AIAI monitoring and governance | Monitoring, evaluation and governance with an LLM firewall, pivoting to agentic governance. | Works alongsideObservability plus governance. Mountain Theory supplies the enforcement they describe. |
| AurascapeAI-native security layer | Real-time visibility and intent-based controls across thousands of AI applications. | Works alongsideBreadth across AI app usage. Complements depth at the execution boundary. |
| Promptfoo (OpenAI)LLM security testing | Open-source CLI for adversarial testing of LLM apps. OpenAI announced its acquisition in March 2026. | Different jobDeveloper testing tool. Not an enforcement product. |
| Lasso SecurityLLM security and MCP gateways | Shadow AI discovery, data-flow monitoring and MCP gateways, distributed via Cloudflare. On 2 September 2026 raised $30MM led by ClearSky and launched LEAP, a CPU-based guardrail, and RAPID, a self-hosted judge model. | Works alongsideRun both. Lasso controls the user-to-model boundary; Mountain Theory governs what an agent already inside your systems does. |
| ThalesAI runtime data security | AI Security Fabric controlling which data agents may access, with an MCP gateway on the 2026 roadmap. | Works alongsideRun both in regulated estates. Thales is the data vault; Mountain Theory is the decision gate. |
| CalypsoAI (F5)Inference security | Red teaming and real-time threat defence at the inference layer. Acquired by F5. | Works alongsideInference-layer defence, complementary to action control. |
| Nightfall AICloud-native DLP for AI | ML data discovery, classification and protection across SaaS, APIs and browsers. | Works alongsideData loss prevention. Different object entirely. |
| LiminalSecure multi-model AI access | Intelligent data masking rather than redaction, single-tenant, for regulated industries. | Works alongsideProtects the data in the prompt. Mountain Theory protects the system from the action. |
| WitnessAIAI governance and security | Visibility, control and compliance for enterprise AI usage. | Works alongsideUsage governance alongside action enforcement. |
| Harmonic SecurityAI data loss prevention | DLP purpose-built for AI workflows rather than retrofitted. | Works alongsideData-layer control, complementary. |
| Pillar SecurityAI lifecycle security | Discovery, testing and adaptive guardrails across the AI lifecycle. | Head to headBreadth versus depth. Pillar covers the lifecycle; Mountain Theory is deeper at the one boundary that stops an action. |
| Credo AIAI governance platform | AI governance, risk and compliance programme management. | Works alongsideRun both. Credo produces the policy and the paperwork; Mountain Theory is what actually enforces it. |
| Palo Alto Networks (Prisma AIRS)Platform AI security | Model scanning, posture, red teaming and runtime across the AI lifecycle, from the Protect AI acquisition. Acquired Console, an AI agent platform, on 1 September 2026, placed in Cortex rather than AIRS. | Head to headOften the default if you already run Palo Alto. Ask what stops a custom agent on your own infrastructure tonight. |
| Cisco (AI Defense)Platform AI and identity security | AI Defense plus Astrix and WideField, building an identity-led trust layer for agentic AI. | Works alongsideStrong on identity and investigation. Mountain Theory supplies inline action enforcement. |
| MicrosoftPlatform AI security | Security Copilot, Agent 365 control plane and an agent governance toolkit. | Works alongsidePlatform-native controls for Microsoft-hosted agents. Mountain Theory reaches everything else. |
| GoogleCloud AI security | AI-SPM and AI protection through Wiz, plus the A2A protocol. | Works alongsideCloud-native posture. Complementary to execution control. |
| SentinelOneEndpoint and AI security | Singularity platform with Prompt AI Agent Security from the Prompt Security acquisition. | Works alongsideEndpoint and content security. Different layer. |
| CrowdStrikeEndpoint and agent security | Falcon and AIDR, expanding into AI identity through SGNL and Pangea. | Works alongsideEndpoint and identity strength. Mountain Theory governs the action. |
| Check PointNetwork and AI security | Infinity AI with Lakera for AI-native detection. | Works alongsideNetwork and prompt layers, complementary. |
| DarktraceAI anomaly detection | Self-learning anomaly detection moving into AI tool security. | Works alongsideDetection and anomaly. Mountain Theory is prevention at the action. |
| UpwindRuntime-first CNAPP | Runtime cloud security with AI posture, inventory and behaviour tracing via eBPF. Raised a $300MM Series C at a $3.8B valuation in September 2026, led by Bessemer and TCV. | Works alongsideRun both. Upwind explains what happened across your cloud; Mountain Theory decides whether it happens. |
| Apex Security (Tenable)AI visibility and policy | AI activity visibility and policy enforcement. Acquired by Tenable. | Works alongsideVisibility layer, complementary. |
| PindropVoice biometric AI security | Deepfake detection and authentication for the voice channel. | Works alongsideRun both if you operate voice AI. They authenticate one channel; we govern action across all of them. |
| ZeroDriftAI communications compliance | Checks every AI-generated message against SEC, FINRA, HIPAA and firm policy before it sends. Launched Guard for Agents on 2 September 2026, checking agent-generated email, SMS and Slack against imported company policy before send. | Works alongsideRun both in financial services. ZeroDrift governs what AI says; Mountain Theory governs what it does. |
| 7AIAgentic SOC automation | Autonomous AI agents automating security operations work. | Different jobAI for security rather than security for AI. Notably, their agents are themselves something you would want governed. |
| ArmadinAutonomous AI SecOps | Agentic security operations, founded by the Mandiant founder. | Different jobSame note: an autonomous SecOps agent is a strong candidate for execution-layer control. |
No company matches that search.