Landscape
The AI-Agent Governance Vendor Map
Who sells what in agent identity, permissions, MCP security, and spend governance. Maintained weekly; every change ships with an evidence link in the briefing's Landscape Watch section.
PREVIEW — seeded categories; per-vendor details land after evidence verification.
No vendors match — try a shorter term, or suggest one we're missing.
Agent identity & NHI 6
Identity, authentication, and lifecycle for AI agents and non-human identities.
- Oasis Security
- Saviynt
- Cyera
- SailPoint†
- Okta†
- Microsoft Entra†
MCP security & gateways 7
Gateways, allowlisting, and security tooling for Model Context Protocol deployments.
- Runlayer
- Helmet Security
- Operant AI
- Manufact
- Kong
- MintMCP
- Composio
AI security platforms 5
Broader platforms securing AI applications, models, and agents.
- Noma Security
- WitnessAI
- Lasso Security
- Lakera (Check Point)
- Protect AI (Palo Alto)
Agentic SOC 4
AI agents doing security operations work.
- Torq
- 7AI
- Dropzone AI
- Qevlar AI
Offensive & testing 2
Automated pentesting and adversarial testing of AI systems.
- XBOW
- RunSybil
Exposure management 3
Discovering and managing AI-related attack surface.
- Astelia
- Eclypsium
- Surf AI
LLM gateways & spend 5
Model routing, observability, and cost governance.
- TrueFoundry
- Maxim AI
- Concentrate AI
- LiteLLM†
- Portkey†
Agent observability 6
Tracing, logging, and evaluation — the audit trail for what agents actually did.
- Langfuse†
- LangSmith (LangChain)†
- Arize†
- Braintrust†
- Helicone†
- W&B Weave†
Data flow & AI-DLP 6
Controlling what data reaches agents, and what agents can leak back out.
- Nightfall†
- Harmonic Security†
- Metomic†
- BigID†
- Varonis†
- Cyera
Shadow-AI discovery 5
Finding and governing the AI tools employees adopted without asking.
- Nudge Security†
- Reco†
- Grip Security†
- Island†
- SquareX†
AI governance & compliance 6
Policy, risk, and regulatory compliance for AI programs (EU AI Act, NIST RMF).
- Credo AI†
- Holistic AI†
- OneTrust†
- IBM†
- Vanta†
- Drata†
Agent sandboxing (watchlist) 2
Runtime isolation for agent code execution. Early — mostly developer infrastructure today.
- E2B†
- Daytona†
Agent payments (watchlist) 3
Wallets, virtual cards, and transaction limits for agents that spend money. Embryonic.
- Stripe†
- Skyfire†
- Payman†
Platform giants 6
Hyperscalers and incumbents shipping agent-governance features.
- Microsoft
- Okta
- AWS
- ServiceNow
- Palo Alto Networks
† seeded pending verification. Vendor-neutral: inclusion is editorial, never paid. Corrections: [email protected]