AI agent security platforms: Compare capabilities

Compare Zenity, Agent 365, Prisma AIRS, Noma, gateways, and Arcjet by where each enforces and what it can stop.

13 min read
In short: Compare Zenity, Microsoft Agent 365, Check Point (Lakera), Prisma AIRS, SentinelOne Prompt Security, Noma Security, AI gateways, and Arcjet by the controls and integrations you need. Verify discovery, permissions, runtime enforcement, and evidence on your own workflows.

Which AI agent security platforms can you evaluate?

AI agent security platforms are products that discover, govern, or control what AI agents do. They fall into five groups: enterprise governance and posture products, identity controls, gateways and MCP proxies, content guardrails, and runtime enforcement in the path of the action. The options to evaluate include Zenity, Microsoft Agent 365, Check Point AI Agent Security (Lakera), Palo Alto Networks Prisma AIRS, SentinelOne Prompt Security, Noma Security, and Arcjet. Choose a governance or posture product such as Zenity, Microsoft Agent 365, or Noma Security if you first need an inventory of agents across SaaS and cloud platforms. Choose a gateway if your agent traffic already routes through one proxy. Choose Arcjet if you need a decision before a tool call runs: Arcjet enforces in your code for agents you build, and in the hooks of Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code, with no proxy. Products often span groups, so compare integrations and observable outcomes rather than assigning each vendor one category.

Arcjet publishes this comparison. Competitor details come from each vendor's public documentation, reviewed on September 25, 2026. The comparison isn't an independent effectiveness benchmark or a ranking by market share. The source links in the table support the stated product scope, and the evaluation questions are checks to perform in your own environment.

Platform and sourceDocumented focusWhat to verify
Zenity

Agent inventory and posture, enforcement, and response across SaaS, low-code, custom, and

coding agents

, using native hooks and an MCP gateway on developer machines

Coverage of your agent platforms and whether the actions you need to stop are blocked or only detected. Arcjet vs Zenity

Microsoft Agent 365

Agent registry, governance, and security through Entra, Purview, and Defender;

generally available since May 1, 2026, at $15 per user per month

. Defender for Endpoint adds

AI agent runtime protection

(preview, Windows) that screens Claude Code, Codex CLI, and GitHub Copilot CLI and app hooks for prompt injection, and discovers local agents and MCP configurations

Prerequisite licenses, agent registration, and controls for each non-Microsoft platform.

Arcjet vs Microsoft Agent 365

Check Point AI Agent Security

Lakera's Guard API for prompt, data leakage, and tool screening, plus agent discovery and risk ratings documented as early access

Connector availability and how your workflow acts on a flagged result. Arcjet vs Lakera

Palo Alto Networks Prisma AIRS

AI gateway, runtime security at the network or code layer, agent identity, supply chain scanning, red teaming, and inventory, with

Agentic Endpoint Security

for coding tools

Which deployment inspects each tool, model, or network path. Arcjet vs Prisma AIRS

SentinelOne Prompt Security

Employee AI use, homegrown AI applications, and agent controls, from SentinelOne's

acquisition of Prompt Security

, completed September 5, 2025

The specific product, integration, and enforcement mode for your use case.

Arcjet vs Prompt Security

Noma Security

Agent discovery, posture management, red teaming, and runtime protection

Which runtime paths are enforced and which are observed. Arcjet vs Noma Security

Arcjet

Policy on agent actions in code through SDKs, and on Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code tool calls through their hooks, with prompt injection, sensitive information, and destination threat detectors, and SIEM export on the Enterprise plan

Whether every sensitive action reaches a check and which data each detector sends remotely

For discovery and configuration evaluation specifically, see AI security posture management versus runtime security. For implementation details, use the agent framework comparison.

Which vendor comparisons are available?

Arcjet publishes 16 detailed comparisons: 15 compare one vendor with Arcjet, and one compares AI gateways in general. Each page includes when to choose the other product, and the following list groups the pages into four categories.

The grouping follows each vendor's own description, and most products reach into more than one group. Onyx Security, which launched in March 2026 with $40 million in funding, describes a control plane that discovers agents, monitors each reasoning step, and approves or corrects agent actions. Noma Security, which announced a $100 million Series B on July 31, 2025, combines agent discovery, posture management, red teaming, and runtime protection. Pillar Security lists discovery and posture, red teaming, runtime guardrails, and governance.

What do agent identity controls cover?

Agent identity controls establish which user, agent, or workload is acting and what authority it holds. Microsoft Agent 365 uses Entra for risk-based access controls on users and the agents acting for them. For more information about Agent 365, see Arcjet vs Microsoft Agent 365.

An identity control doesn't authorize a specific resource on its own. Scope credentials to the required service and operation, and have the downstream application authorize the particular resource and action using current state. A valid token doesn't establish that the requested invoice belongs to the caller.

When you evaluate an identity control, ask whether delegation preserves both the user and agent identity, how revocation affects active runs, and whether a model-supplied field can influence authorization. For a concrete permission matrix, follow the least-privilege tool-call guide.

What do AI gateways and MCP control planes cover?

An AI gateway or Model Context Protocol (MCP) control plane is a proxy that governs the traffic routed through it. Depending on the implementation, that traffic can include model calls, MCP requests, destination restrictions, and identity-aware policies.

LLM gateways apply guardrails to model traffic, as Portkey, LiteLLM, and Kong's AI Prompt Guard plugin document. MCP control planes such as Runlayer and Lasso Security's MCP gateway proxy tool calls between agents and MCP servers. For more information about each product, see Arcjet vs Portkey, LiteLLM, Kong AI Gateway, Runlayer, and Lasso Security.

A gateway's coverage depends on routing, so identify the direct API calls, local tools, shell commands, and background jobs that bypass it. A coding agent's built-in shell and file tools never cross an MCP proxy, so they need a check in the agent's hook or on the device. A catalog of approved MCP servers doesn't by itself prove that all tool executions are authorized. For more information, see AI gateways versus Arcjet and MCP server security platforms.

What do guardrails and content inspection products do?

Content guardrails assess prompts, retrieved documents, tool results, and model outputs for risks such as prompt injection or sensitive-data exposure. A guardrail can block an interaction only when the application waits for the result and enforces it before proceeding. Lakera, Prompt Security, Pillar Security, and Datadog AI Guard all document content screening.

For more information about each product, see Arcjet vs Lakera, Prompt Security, Pillar Security, and Datadog AI Guard. When you evaluate a guardrail, measure accuracy on representative benign and malicious content, data processing location, retained telemetry, and failure behavior. Don't infer an entire vendor's scope from one detector, because a vendor can combine inspection with action policies, posture, or identity features.

What does observability add to agent security?

Agent observability records the traces and decisions that reconstruct which inputs, tools, and policies affected a run. Observability products differ in timing: some combine these records with inline enforcement, and others only collect or analyze completed activity.

When you evaluate an observability product, ask when the verdict arrives and what consumes it. If an evaluator can stop the action, test that path. A record of a completed call is useful evidence but can't prevent that call, so preserve the distinction between a proposed action, a policy decision, and an observed downstream effect.

How does enforcement in application code work?

In-code enforcement is a check inside a tool handler or worker that uses application context before the operation runs. Arcjet Guards provide this integration point, and your code supplies the relevant context and handles the decision. Rein Security also runs next to the application, as a sidecar, rather than as a network proxy. For more information about Rein, see Arcjet vs Rein Security.

An SDK call can still use a remote evaluation service, so in-code integration doesn't imply that all inspection stays local. In-code coverage also depends on where your team installs checks. Test built-in tools, dynamically mounted tools, retries, and alternate paths to the same service, and use AI agent security testing to prove that a denial prevents the actual effect.

How do you compare AI agent security platforms?

Compare AI agent security platforms by running each candidate against the same small, representative workflow with synthetic data. Include a successful authorized action, an unauthorized resource, a disallowed destination, and a policy-service timeout. For each candidate, record the following:

  • Which calls were observed and which were eligible for enforcement.
  • Whether a denied operation reached the downstream service.
  • Whether benign tasks still completed, and the latency added to those tasks.
  • Where raw content and telemetry were processed and retained.
  • How the policy was deployed, changed, and rolled back.
  • What happened to queued work and active credentials after access was revoked.

Record the product version, deployment mode, and configuration. Don't substitute a vendor's generic detection percentage for a result on your own tool paths.

Which control do you need first?

Choose the control that your program is missing. If you can't identify your agents and their owners, begin with discovery and posture. If credentials are too broad, reduce privileges. If a known application can make an unauthorized payment, or a coding agent can run a destructive command, put a check at that boundary.

One platform or several integrations can provide these controls. Use an agent threat model to decide which consequence to prevent first, then assign each control an owner and an observable acceptance test. Buying overlapping products doesn't close execution paths that none of them reaches.

Where does Arcjet fit?

Arcjet is an AI agent runtime security platform that enforces policy in the path of the action, so the decision returns before the tool runs. For agents you build, the JavaScript, TypeScript, Python, and Go SDKs add a check to tool calls, MCP handlers, and queue workers through Guards, and to HTTP routes with bot detection, rate limiting, and Shield WAF.

For coding agents, the hooks of Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code call Arcjet with no SDK and no code change, and one policy applies across all five. Arcjet evaluates hook requests at the edge in over 300 data centers, and each hook adds one request of latency, typically a few tens of milliseconds. Enforcement depends on the vendor, the event, and the installed policy, as set out in how to secure AI coding agents.

An Arcjet policy can score the hosts an agent is about to contact with Arcjet threat intelligence and deny destinations, including MCP servers, that Arcjet rates high risk. The Arcjet Console records every decision and session, and on the Enterprise plan decisions export to Datadog, Splunk, SentinelOne, Panther, and Amazon S3 for detection and alerting.

Evaluate Arcjet's data handling per control. SDK-local sensitive information detection can inspect content in process. Prompt injection detection uses the Arcjet Cloud API, and coding-agent hooks have a server-side sensitive information path. Don't interpret local inspection of personally identifiable information (PII) as a claim that all Arcjet traffic stays in your environment.

Arcjet doesn't supply your business authorization or cover tools that bypass its checks, and it doesn't scan cloud assets for posture or enforce inside closed SaaS agents such as Microsoft Copilot Studio. Keep resource ownership, atomic business limits, cancellation, and downstream permissions in the systems that own them. Start with the production agent security guide, then test the specific failure you need to prevent.

Frequently asked questions

Which AI agent security platforms can I evaluate?

Candidates include Zenity, Microsoft Agent 365, Check Point AI Agent Security (Lakera), Prisma AIRS, SentinelOne Prompt Security, Noma Security, AI gateways such as Portkey and LiteLLM, and Arcjet. Choose according to your agent platforms, required controls, and integration model, then verify the result in a proof of concept.

Which AI agent security platform covers coding agents?

Arcjet, Zenity, Microsoft Defender for Endpoint, and Prisma AIRS each document coding-agent coverage, through different mechanisms. Arcjet enforces one policy on Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code tool calls through the hooks each agent fires, installed through managed settings. Zenity documents native hooks and an MCP gateway, Defender for Endpoint documents hook-based prompt injection protection in preview on Windows, and Prisma AIRS documents an endpoint component.

How do I choose a tool for securing agentic AI workflows?

Choose according to the missing control: discovery, scoped identity, content inspection, action authorization, or response. A single product can span several of these categories. Run each candidate against the same workflow, and test whether the product blocks your specific unauthorized action while legitimate tasks still succeed.

Is an MCP gateway enough to secure AI agents?

No. An MCP gateway enforces only on the traffic routed through it. Local tools, direct API calls, background jobs, and a coding agent's built-in shell and file tools don't cross an MCP gateway and need coverage too. Verify additional integrations and retain resource-level authorization in downstream services.

Does in-code security mean all data stays local?

No. An SDK integration can call remote services, so evaluate data handling separately for each detector and telemetry path. Arcjet supports SDK-local sensitive-information inspection, which keeps the raw body in your process, while prompt-injection detection uses the Arcjet Cloud API and coding-agent hooks use a server-side sensitive information detector.

AI runtime security in your code

Protect your AI agent workflows with Arcjet

Arcjet runs inside your application, where it can use runtime context to enforce agent actions and budgets, detect prompt injection, and protect sensitive information before a workflow acts.