AI Security Security Tools
Compare the best AI Security tools and vendors. Expert reviews, pricing, and feature comparisons on Latio.
Acquired by Google. Wiz is the leader in having an all-in-one cloud security platform by expanding into CTEM, ASPM, and Runtime capabilities all within a single dashboard. Their posture and vulnerability capabilities remain the strongest, while there are better standalone code and runtime vendors out there.
Oligo Security offers application layer insights as part of a CADR platform. They baseline application library activities at a function level, and can detect either malicious deviation, or the execution of known vulnerable functions. This extends into AI, allowing them to see, detect, and respond to AI applications.
Aikido provides everything the average startup to mid-market company needs for security in a box - every code and cloud security scanner under the sun without much feature compromise, alongside a surprisingly robust runtime application solution for things like bot prevention. A no-nonsense replacement for a lot of more "specialized" solutions that tend to slow developers down.
Upwind has built CNAPP from the ground-up around runtime insights provided from a network focused endpoint agent. They provide unique features like API security, alongside vulnerability prioritization and scanning, and the more generic CNAPP feature sets.
Lasso offers a combination of solutions to offer governance over AI solutions - from plugins to endpoint agents for monitoring and blocking.
AI-powered endpoint security platform that gives teams control over everything running on their endpoints so they can adopt AI safely.
The core of Sweet Security is powerful incident detection and response capabilities for cloud environments. They have since created a larger CNAPP platform expanding more into vulnerability management, posture, and identity capabilities
Bloom discovers and governs AI agents, extensions, IDE plugins, and MCP servers on endpoints with contextual risk assessments.
Backslash offers a unique approach to reachability across SCA and SAST, as well as a suite of vibe-coding security features such as MCP risk assessments and cursor rules.
Raven has built a comprehensive runtime oriented ADR solution that can detect function executions from packages being exploited. This empowers them to detect application layer attacks, create prioritization based on what functions are being used, as well as virtual patching to prevent vulnerability exploitation.
Kodem offers runtime first code security solutions - from runtime function execution SCA to runtime detection for prioritizing SAST findings. They're also one of the few to offer ADR solutions.
Pluto is a leading AI security solution that specializes in securing endpoints and agentic building solutions like Lovable and Base44
Noma's AI Security solution focuses on a broad range of implementations and use cases across posture and runtime protection. They're especially strong for companies looking to secure the work of machine learning or AI engineering teams more broadly.
Pillar provides complete coverage as a developer first AI security solution. They integrate with your SCM, detect & diagram your AI agents, test them for vulnerabilities, and provide real-time protection and guardrails.
Acquired by Cato Networks. Aim has built a flexible offering in the LLM space. They offer a browser plugin, copilot wrappers, can connect to third party network logs, create privacy policies, their own chat, anonymizers, and an API for proxying application level calls.
Zenity has a holistic security offering for AI security, especially for common workforce use cases like Claude, Microsoft 365, and ChatGPT. They are especially strong at tracking permissioning across a workforce.
Orca offers the standard suite of CNAPP features with a focus on agentless scanning. They're a good all around CNAPP offering mostly focused on the posture side.
Operant has focused their application defense solution on securing AI workloads, providing features like runtime detection and redaction for production applications. They excel at securing Kubernetes workloads, and are especially strong at network detections.
Snyk was the first to really do DevSecOps - fast, actionable, developer focused CI/CD security scanning. They also were early to consolidate scanners into a single place - IaC, Code, SCA, and Container. There are many platforms with small improvements over them - better reachability, workflows, etc. - but they remain a strong player in the space for having scaled so meaningfully across enterprises.
Akto has created an open source flavored approach to next generation DAST and API security with features like looking at log data for API discovery, sensitive data flows, and customized scanning. A uniquely helpful feature is the ability to easily edit and tweak tests from the UI.
Miggo is maximizing the value of your existing application performance monitoring, or offers an instrumentation of their own, that excels at building maps of distributed systems and real time attack detection and prevention. Miggo has no-code as well integration based implementations.
Acquired by Palo Alto Networks. Koi offers full inventories and workflows for managing packages, extensions, AI tools, containers and other components that users and developers pull from public marketplaces and registries that MDM and EDR tools rarely see. Koi scores risk per and enforces policy with an agentless approach so even exempt developer machines stay governed.
Acquired by Checkpoint. Lakera offers a simple way to protect LLM's by importing their SDK into your code. Their approach is simple and elegant, and their Gandalf tool allows you to better understand how LLM prompt injections work.
Datadog offers a complete suite a security offerings that are a great fit for developer focused teams not looking for the most mature details in each area. They offer most scanning types, runtime detections, and a full SIEM, and you're probably already sending them your logs. It's a great runtime choice to meet developers where they work, but the UX is built primarily for developers.
Corridor provides a holistic approach to securing AI generated code by helping secure developer endpoints, bringing organizational security context to coding agents, and doing in pipeline security code review.
Harmonic currently has the standard suite of LLM protection visibility via browsers, but has a long term focus on detecting the flow of sensitive data - a vision that aligns well with the team's history in detecting sensitive data across the internet.
Pangea provides an API and SDK to easily implement security features into your application - such as checking a user's password against a breach database, or checking a user's email against a spam database. They've expanded the capabilities of the SDK to focus on runtime AI protection.
Intent-aware workspace security platform that uses on-device AI reasoning to read human, AI, and app activity and intervene before risky actions complete.
Governance capabilities for MCP servers, skills, and AI agents with threat detection, fine-grained permissions, and full observability.
Nullify is also starting with SAST use cases, but has expanded their AI agent functionality to be more holistic with their slack app and creating rudimentary threat models of code changes. Their vision is more holistic - focusing on creating an AI based product security engineer.
Acquired by Tenable, Apex offers visibility, configuration protection, and runtime detection and response for LLMs, both for corporate and application use cases. Everything from DLP to Injection detection, to LLM quarantining.
Acquired by SentinelOne. Prompt Security offers comprehensive solutions for LLM security. They have both corporate IT visibility with their browser plugin, alongside application visibility with API, SDK, and reverse proxy options. You can also trace user sessions and detect/redact/block numerous types of data and attacks.
TrojAI deploys on premise and provides end to end LLM security - providing DAST type testing for LLMs and realtime protection via either a reverse proxy or SDK.
Pixee creates pull request ready fixes for SAST findings for enterprises. They've especially focused on developer workflows and using a mix of LLMs with static rules to create fixes.
Splx focuses on attack testing for LLMs, but provides a helpful open source tester: https://github.com/splx-ai/agentic-radar
Mindgard has taken a cool approach to LLM security by building an in depth testing library for your existing models. Given the rapidly changing nature of the field, it's a great way to learn about existing attacks and how to protect against them.
Unbound offers a browser plugin for DLP and AI usage discovery, and a proxy based approach for data sanitization and visibility.
Provides IaC and SAST auto-fixing via an IDE plugin
Marqus focuses on runtime security for LLMs.
Copperhelm provides automated cloud security remediation