Manifold Security
by Manifold Security
Runtime detection and response for AI agents — watch what agents do, not what they say
Manifold is an agentic AI Detection and Response platform that gives security teams runtime visibility into what AI agents actually do on enterprise endpoints — the tools they call, the systems they touch and the actions they take. It targets the blind spot left by AI security tooling that only inspects prompts and model outputs at the inference layer.
Manifold Security builds an agentic AI Detection and Response (AIDR) platform for autonomous AI agents running on enterprise endpoints. Its founding argument is that the first generation of AI security tooling was built to inspect text — prompts in, model outputs out, at the inference layer — which leaves the part that actually causes damage invisible: the tools an agent invokes, the files and credentials it reads, the commands it executes and the external services it reaches. Manifold instead captures agent behaviour at runtime on the endpoint, establishes a behavioural baseline per agent, and flags anomalies the moment activity drifts, producing a live map of every agent in the environment along with its connections to MCP servers, databases and external systems. The company positions this squarely at coding agents — the scenario where a developer's laptop runs an agent with access to source code, credentials and CI/CD pipelines — and stresses agentless deployment in days without new gateways or proxy layers. It was founded by Neal Swaelens, Oleksandr Yaremchuk and Michael McKenna, the team behind Laiyer AI and its open-source LLM Guard project, which Protect AI acquired in January 2024. Manifold announced an $8 million seed round on 18 March 2026 led by Costanoa Ventures, with Cherry Ventures, Rain Capital and Modern Technical Fund participating alongside former Uber CSO Joe Sullivan and former Google DeepMind CISO Vijay Bolina. In April 2026 it launched Manifest, a free supply-chain intelligence platform that graphs how agent skills, plugins and MCP servers behave, indexing more than 100,000 assets.
A CISO or security engineering lead at a company where developers already run coding agents with production and CI/CD access, and EDR shows nothing useful about them
A real-time inventory of every agent on your endpoints and what it actually touched, with anomalies flagged before an action becomes an incident
At a Glance
- Category
- Governance & Security
- Pricing
- Freemium, Contact for pricing
- Target Market
- CISOs, Security Engineers, Detection and Response Teams, Platform Security Leads, CTOs
- Deployment
- Cloud-first
Key Features
- ✓Agent discovery
Enumerates every agent running in the environment along with the MCP servers, tools, resources and skills each one invokes at runtime.
- ✓Behavioural baselining
Captures API calls, file access, command execution and external service interactions, then establishes a normal profile per agent to detect drift.
- ✓Risk and exposure analysis
Surfaces risky agent behaviour such as unauthorised system access or improper data exposure, mapped against the systems each agent reaches.
- ✓Detection and response
Real-time monitoring with anomaly flagging and intervention, so a misbehaving agent can be stopped rather than reviewed after the fact.
- ✓Agentless deployment
Installs in days on existing endpoint infrastructure without new gateways or proxy layers, avoiding the latency cost of inline inspection.
- ✓Manifest supply-chain graphs
Free platform building execution graphs of what a skill calls and environment graphs tracking authorship, similarity and cross-registry relationships across 100,000+ indexed assets.
Use Cases
- •Shadow AI agent inventory
Security teams find out which agents developers are already running, what those agents connect to, and where the unmanaged risk sits.
- •Coding agent containment
Monitor agents that hold repository, credential and pipeline access so an over-broad action is caught before it reaches production.
- •MCP server supply-chain review
Use Manifest's execution and environment graphs to check a third-party skill or MCP server before approving it for internal use.
- •Incident investigation for agent activity
Reconstruct precisely which tools an agent called and which systems it touched, evidence that prompt and output logs cannot supply.
- •Detecting malicious agent plugins
Manifold's own published research has identified squatted plugin scopes and skills recruiting agents into crypto activity across public registries.
Ideal For
Best For
- ✓Discovering shadow AI agents and MCP server connections already running on developer endpoints
- ✓Monitoring coding agents that hold access to source code, secrets and CI/CD pipelines
- ✓Investigating what an agent actually did during an incident, rather than reconstructing it from prompt logs
- ✓Vetting third-party agent skills, plugins and MCP servers before allowing them into the estate, via the free Manifest index
- ✓Security teams that need agent coverage without deploying another proxy or inline gateway
Not Ideal For
- ✗Teams whose agents run entirely server-side in cloud or Kubernetes estates rather than on employee endpoints — Manifold's scope is endpoint runtime, and broader AI security posture platforms cover that ground
- ✗Buyers who require published pricing, reference customers or analyst coverage before purchase: this is a seed-stage vendor with no disclosed customer count and no public case studies
- ✗Organisations looking to consolidate model-layer guardrails, prompt filtering and red-teaming into one purchase, which is a different product category
Deployment
Market Analysis
Pros
- ✓Addresses a real and specific gap: agent tool calls, file access and command execution are invisible to both traditional EDR and prompt-layer AI security tools
- ✓Agentless deployment in days with no inline proxy means no added latency in the agent's execution path and a low-friction pilot
- ✓The free Manifest platform lets a security team evaluate agent supply-chain risk before any commercial commitment
- ✓Founding team has a prior exit in exactly this domain, having built Laiyer AI and the widely used open-source LLM Guard
- ✓Publishes original research on live agent supply-chain attacks, including scope-squatting in public plugin registries
Cons
- ✗Seed-stage at $8M with no disclosed customers, no named references and no public case studies — SiliconANGLE's coverage noted enterprise-scale scalability and integration complexity were not addressed
- ✗No published pricing at all for the enterprise platform, so total cost cannot be estimated before a sales conversation
- ✗Scope is endpoint runtime, so agents running server-side in cloud or Kubernetes estates need complementary tooling from a broader AI security posture vendor
- ✗No presence on G2, Capterra, TrustRadius or PeerSpot, and effectively no Hacker News or Reddit discussion, so detection quality and false-positive rates are unverified by any independent user
- ✗Competing against far better-funded incumbents — Zenity was named a leader in AI agent governance by Gartner in April 2026, and CrowdStrike now ships AIDR inside Falcon
- ✗No public trust page confirming SOC 2, ISO 27001 or data residency, which will slow procurement at regulated buyers
Pricing
Manifest (free)
$0
- ✓Open-access supply-chain intelligence platform
- ✓Indexed database of 100,000+ agent skills and components
- ✓Search, analysis and review capabilities
- ✓Execution and environment graphs
Manifold Enterprise
Contact for pricing
- ✓Runtime agent discovery, risk and detection on endpoints
- ✓Coverage extended to browser extensions and MCP servers
- ✓Behavioural baselining and anomaly response
- ✓Agentless deployment
Manifold publishes no list pricing for the enterprise platform — evaluation runs through sales, and none of the launch coverage disclosed pricing models, per-endpoint rates or minimums. What is genuinely free is Manifest, the supply-chain intelligence platform launched in April 2026 as open access with an indexed database of more than 100,000 agent components, search and review. That gives a security team a real way to get value before any commercial conversation, which is unusual at this stage. Enterprise features extend coverage to additional components such as browser extensions and MCP servers and fold the intelligence into the runtime platform. As a March 2026 seed-stage company with $8 million raised, expect design-partner-style commercial terms rather than a published rate card.
Security & Compliance
Sources
This page was written from 5 sources, 3 on domains other than manifold.security.
- 1.manifold.security — manifold.securityvendor
- 2.manifold.security — manifold raises 8m seed fundingvendor
- 3.siliconangle.com — manifold raises 8m secure autonomous ai agents enterprise en
- 4.siliconangle.com — manifest platform manifold targets ai agent supply chain sec
- 5.fintech.global — manifold raises 8m seed round to secure ai agents at runtime
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
AvePoint AgentPulse
Multicloud AI agent governance — discover, own, secure and cost-control every agent from one console
Act Security
Action-centric cloud security that removes standing access from humans, workloads and AI agents
Ambient.ai
Agentic physical security: vision-language models that watch every camera continuously
Obsidian Security
Governs what AI agents and non-human identities can access and do inside your SaaS apps