AI Application Security — Discovery, Testing, and Runtime Defense for Enterprise AI
Custom-built AI applications and agents carry risks that traditional AppSec never had to cover — prompt injection, sensitive data leakage, and agents that quietly drift from the job they were given. This directory tracks the startups building purpose-made defenses for that gap.
Whatever the vendor, three capabilities keep showing up — discovery is what makes the other two possible, since a team can't test or defend an AI application it doesn't know exists.
01 · Discover
Inventory AI applications and agents
Find sanctioned and shadow AI alike — via traffic inspection, code repository scans, and cloud AI service integrations — and catalog what each one is, who owns it, and how critical it is.
02 · Test
Attack it before someone else does
Automated adversarial prompting and model repository scanning to surface vulnerabilities, feeding red-team programs and, increasingly, live runtime policy.
03 · Defend
Block it in production
Runtime guardrails and anomaly detection watch every input and output, catching data leakage, jailbreaks, and prompt injection — and, for agents, drift away from their original instructions.
Market Shapers
Full-spectrum agentic security
The two vendors furthest ahead on funding, partnerships, and breadth — both analyze an agent's full behavioral picture (instructions, memory, tool use, data access) rather than just inspecting individual prompts.
Agent-native security that tracks an agent's stated intent against its real behavior across memory, tool use, and data access to catch drift and misuse as it happens. An early Databricks investment underpins its data-platform integrations.
Governs enterprise copilots and low-code AI agents across build, deploy, and runtime, comparing what an agent was authorized to do against what it actually does. Backed early by Microsoft's M12 venture arm.
Copilot governanceLifecycle security
Visit site
Pace Setters
Advanced runtime defense & adversarial testing
One vendor here, distinguished by adaptive, reasoning-driven red-teaming that escalates its own attack strategy in response to how the target application reacts.
A publicly traded, nine-year-old cybersecurity vendor with deep APAC roots, applying adaptive red-teaming that escalates attack strategy in real time and enforcing system-level instructions against live user prompts.
Adversarial testingAPAC-focused
Visit site
Pioneers
Architecturally advanced, still scaling
Nine vendors with strong technical depth across the AI application lifecycle — discovery, testing, and runtime defense in one architecture — who are still building out the partnerships and go-to-market reach of the tiers above.
API security discovery and testing extended to the APIs that expose AI models and agents, folding AI-specific checks into an existing API attack-surface management workflow.
Network-level visibility into how employees and agents actually use AI applications and services, applying policy at the traffic layer rather than inside any single app.
Focuses on the model itself — scanning for tampering and adversarial manipulation, and detecting attacks that target a model's weights and architecture rather than just its prompts.
Pairs AI governance and regulatory compliance workflows with technical security testing, aimed at teams that need audit-ready evidence alongside runtime protection.
A runtime firewall that sits in front of LLM applications, inspecting every prompt and response to block jailbreaks, injection attempts, and data leakage inline.
Follows an AI application from its code and model repositories through to production, running red-team exercises and enforcing the guardrails those exercises inform.
Continuous adversarial testing feeds directly into runtime protection, closing the loop between what red-teaming finds and what the production guardrails actually block.
Combines automated red-teaming with runtime guardrails purpose-built for production AI agents, aiming to cover both pre-deployment testing and live defense in one platform.
Agent securityRed teaming
Visit site
Specialists
Niche capabilities, targeted differentiation
Eleven earlier-stage vendors, each strongest in a specific corner of the problem — good shortlist candidates for a targeted pilot rather than a single do-everything platform.
An agent orchestration platform with policy controls built into the workflow itself, so governance is enforced as agents are assembled rather than bolted on afterward.
Tests models and agents for robustness, bias, and adversarial vulnerability across text, vision, and voice — one of the few vendors here built for multimodal AI from the start.
Runtime guardrails and automated red-teaming for AI applications and agents, detecting prompt injection, jailbreaking, and data leakage in real time. Acquired by Anaconda in August 2026.
Discovers GenAI usage across the enterprise — sanctioned copilots and the shadow AI tools employees adopt on their own — and applies security policy to both.
A secure AI control plane that continuously discovers agents, sets usage policy, and deploys a guardian agent to intervene — blocking an action, cutting permissions, or asking for human approval — in real time.
Gives security teams an inventory of every AI model, agent, and tool in use across the organization, as a foundation for exposure management before deeper controls go on.
A runtime governance layer for AI agents that enforces cost, safety, and compliance policy while agents are actually executing, not just at design time.
Tests, defends, and continuously evaluates AI agents across their lifecycle, aimed at shortening how long it takes an agent to earn enough trust to reach production.
Red-teaming and runtime protection for AI applications, evaluating models and agents for safety and security gaps before and after deployment. Agreed to be acquired by Fortinet, completed August 2026.
A visibility and policy layer over how employees, applications, and agents use AI — flagging data leakage and compliance violations while tracking AI usage and spend.