JetStream Security
by JetStream Security Inc.
Security-first AI governance — discover every agent, bind it to an owner, govern it at runtime
JetStream Security is an AI governance platform for enterprises running generative and agentic AI in production. It discovers shadow AI across SaaS, cloud, endpoints and APIs, maps how agents, models, data and identities connect, binds every non-human identity and key to an accountable human owner, and enforces approved behaviour and spend while workflows are running.
JetStream Security is an enterprise AI governance platform that came out of stealth in March 2026 with $34M in oversubscribed seed funding led by Redpoint Ventures, joined by the CrowdStrike Falcon Fund and angels including CrowdStrike CEO George Kurtz, Wiz CEO Assaf Rappaport and Okta vice-chairman Frederic Kerrest. Its founding bench is unusually senior for a seed-stage company: CEO Raj Rajamani was chief product officer at both CrowdStrike and SentinelOne, COO Jared Phipps ran revenue at Dazz and sales engineering at SentinelOne, chief architect Venu Vissamsetty spent over a decade at McAfee and eight years at Attivo Networks before its $616M acquisition by SentinelOne, and CTO Jatheen Anand led engineering at Khoros and Lightning AI. The product, marketed as the Security-First AI Governance (SAIG) Platform, is positioned as a control plane rather than another scanner and rests on five capabilities: AI visibility, continuously inventorying agents, models, tools and workflows across SaaS, endpoints, cloud, APIs and internal systems to surface shadow AI; AI design control, injecting intent and risk context while agentic systems are still being built; agentic identity, binding human, agentic and non-human identities and the keys they use to a responsible owner; runtime governance, comparing live behaviour against approved design blueprints instead of reacting after an incident; and AI FinOps accountability, tracking usage and spend by model, agent, workflow and owner. Underneath sit named components — AI Blueprints, AI Manifest, AI Hub, Identity Broker, Key Broker, Stream Context, an AI Kill Switch and a Verified MCP Catalog. The company says it already works with Fortune 500 organisations but names none, publishes no pricing, and has no general-availability date on record.
The CISO or head of AI security at a large enterprise that already has agents running in production and cannot say how many exist, who owns them, or what they cost.
A live inventory of every AI agent, model and key, each bound to an accountable human owner, with a runtime kill switch when behaviour drifts from the approved design.
At a Glance
- Category
- Governance & Security
- Pricing
- Contact for pricing
- Target Market
- CISOs, CIOs, Heads of AI Platform, Enterprise Security Architects
- Deployment
- Cloud-first
- Headquarters
- Santa Clara, California, United States
- Customers
- Undisclosed; the company states it is working with Fortune 500 organisations but names none
Key Features
- ✓JetStream AI Blueprints
Dynamic, system-generated graphs mapping each agent to the models, data, tools and identities it touches in real time.
- ✓AI visibility and AI Manifest
Continuously discovers and inventories AI agents, models, tools and workflows across SaaS, endpoints, cloud, APIs and internal systems.
- ✓Agentic identity and Key Broker
Binds human, agentic and non-human identities to a responsible owner and issues virtual, scoped credentials in place of raw long-lived keys.
- ✓Runtime governance
Compares live agent behaviour against the approved design blueprint and flags deviation as it happens rather than in post-incident review.
- ✓JetStream AI Kill Switch
Cuts off a misbehaving agent or workflow at runtime, giving security teams an interrupt they otherwise do not have.
- ✓AI FinOps accountability
Tracks AI usage and spend precisely by model, agent, workflow and owner, turning a single provider bill into attributable cost.
- ✓Verified MCP Catalog
A vetted catalogue of Model Context Protocol servers so developers connect approved tools instead of arbitrary third-party endpoints.
Use Cases
- •Shadow AI discovery before an audit
Security produces a defensible inventory of every agent, model and copilot in use before a regulator or the board asks for one.
- •Onboarding an agent to production
A new agentic workflow is registered with declared intent and risk context, then continuously monitored against that blueprint once live.
- •Non-human identity cleanup
Long-lived API keys held by agents are replaced with scoped virtual credentials and attributed to a named human owner.
- •Containing a runaway agent
An agent deviating from its approved behaviour is flagged and killed at runtime before it acts against production systems.
- •Chargeback for AI spend
Finance attributes model spend to the specific agent, workflow and team that generated it instead of one blended monthly invoice.
Ideal For
Best For
- ✓Discovering shadow AI — unsanctioned agents, copilots, models and MCP servers already running across SaaS, endpoints, cloud and internal systems
- ✓Assigning ownership to non-human identities and the API keys they hold, so an agent's actions are attributable to a named person
- ✓Runtime enforcement for agentic workflows, comparing live behaviour against an approved blueprint and cutting it off when it deviates
- ✓AI cost accountability — attributing model spend to a specific agent, workflow and owner instead of one blended provider invoice
- ✓Vetting MCP server usage through a verified catalogue before developers wire arbitrary tools into production agents
Not Ideal For
- ✗Organisations that have not yet put agents into production — a governance control plane has nothing to govern and the business case collapses
- ✗Buyers who require published pricing, named reference customers or third-party review evidence before signing; JetStream publishes none of the three as of August 2026
- ✗Small and mid-market teams — the platform, the founding team's background and the go-to-market are aimed squarely at Fortune 500 security organisations
- ✗Teams wanting to buy through an existing AWS commitment or start with a self-serve trial; the AWS Marketplace seller profile carries no transactable product listing
Deployment
Market & Ratings
Undisclosed; the company states it is working with Fortune 500 organisations but names none
Market Analysis
Pros
- ✓Unusually strong founding bench for a seed-stage company — chief product officer of both CrowdStrike and SentinelOne, plus Attivo's engineering lead — in a category where enterprise trust is the entire sale
- ✓A $34M oversubscribed seed with CrowdStrike's Falcon Fund plus the CEOs of CrowdStrike, Wiz and Okta personally invested is strong signal on distribution and design-partner access
- ✓Scope is genuinely broad: discovery, design-time control, agentic identity, runtime enforcement and cost attribution in one control plane rather than a point tool
- ✓Addresses agentic identity and MCP server vetting, which most AI-security tooling has not caught up to yet
Cons
- ✗Launched out of stealth in March 2026 with no published general-availability date; this is early-access maturity, not a proven large-scale deployment
- ✗No independent user evidence exists — Hacker News returns zero stories mentioning the company, and no G2, Capterra or TrustRadius listing surfaced during research
- ✗No pricing, no named reference customers and no published compliance certifications, so every claim about scale currently traces back to the vendor or its launch PR
- ✗Its AWS Marketplace seller profile carries no transactable product listing, so procurement cannot draw down an existing AWS commitment to buy it
- ✗Very crowded category — Zenity, WitnessAI, Noma Security and Lasso are chasing the same budget while the large platform vendors bundle AI governance into existing suites
Pricing
Enterprise
Contact for pricing
- ✓AI visibility and inventory across SaaS, cloud, endpoints and APIs
- ✓AI Blueprints and design-time control
- ✓Agentic identity binding and scoped key brokering
- ✓Runtime governance and AI Kill Switch
- ✓AI FinOps cost attribution by model, agent and owner
No list pricing is published anywhere — the product pages and the AWS Marketplace seller profile both route to a demo request rather than a transactable listing, so every deal is quoted individually and cost almost certainly scales with the number of AI agents, models and identities under management. Expect a Fortune 500 enterprise sales motion with the security organisation as budget holder, and no self-serve entry point.
Security & Compliance
Sources
This page was written from 7 sources, 4 on domains other than jetstream.security.
- 1.jetstream.security — jetstream.securityvendor
- 2.jetstream.security — aboutvendor
- 3.jetstream.security — platformvendor
- 4.securityweek.com — ai security firm jetstream launches with 34 million in seed
- 5.finance.yahoo.com — cybersecurity heavyweights launch jetstream 34m 140000888
- 6.aws.amazon.com — seller profile
- 7.hn.algolia.com — search
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
Exaforce
Agentic SOC and MDR platform whose Exabot AI agents detect, triage, investigate and respond, now with an AI-agent kill switch
Arcjet
Runtime security for AI agents: observe, enforce and audit agent tool calls, with prompt-injection, PII and abuse controls in code
Vals AI
Independent AI benchmarking on private test sets, plus custom evals built from your own code, for legal, finance, healthcare and coding workloads
Alation AIOS
Governed data, context and AI agents in one intelligence operating system for the enterprise