N

Noma Security

by Noma Security

Governance & SecurityAI Agents & OrchestrationEnterprise Platform

Discover, govern and defend every AI agent and MCP server in the enterprise — from inventory to runtime enforcement

Contact for pricing · Subscription·Added Aug 20, 2026·Updated Aug 20, 2026
Share:
THE DAILY BRIEF
Noma Security

by Noma Security

Governance & SecurityAI Agents & OrchestrationEnterprise Platform

Discover, govern and defend every AI agent and MCP server in the enterprise — from inventory to runtime enforcement

Contact for pricing · Subscription

Noma Security is an enterprise AI security platform that discovers AI assets, manages their posture, red-teams them and defends them at runtime in one product. It is built for security teams at regulated enterprises where AI agents and Model Context Protocol servers have proliferated across developer environments faster than governance could keep up, leaving unattributable actions running on shared credentials.

At a Glance

Category
Governance & Security
Pricing
Contact for pricing, Subscription
Target Market
CISOs, CIOs, Security Architects, AI Governance Leaders, Enterprise Developers
Deployment
Cloud-first, Self-hosted, Hybrid
Founded
2023
Headquarters
New York, United States
Team Size
51-200
Customers
Dozens of enterprise customers across financial services, life sciences, retail and technology; named customers include UiPath, Best Buy and Nielsen

Key Features

  • Enterprise Agentic Registry
  • Agent Identity
  • Tool-level access control
  • Three-state governance model
  • AI Detection and Response (AI-DR) runtime enforcement
  • Agentic Risk Map
  • Integrated AI red teaming

Capabilities

text generation
image generation
video generation
code generation
workflow automation
api access
audio generation
fine tuning
agent orchestration

Use Cases

  • Inventorying shadow AI across a large enterprise
  • Securing MCP adoption in developer tooling
  • Governing vendor agent platforms
  • Detecting prompt injection and exfiltration in production
  • Evidencing AI governance to auditors

Ideal For

Best For

  • Discovering shadow AI — agents, models and MCP servers deployed across developer environments without security review
  • Giving each autonomous agent a distinct identity so its actions are attributable instead of hidden behind shared service credentials
  • Governing MCP server access at tool-level granularity, approving some tools on a server while blocking others
  • Runtime detection of prompt injection, data exfiltration and scope violations across the prompt-to-action chain
  • Regulated industries (financial services, life sciences) that must evidence AI governance controls to auditors

Not Ideal For

  • Teams that only need low-latency input/output prompt filtering — an independent review notes Noma is built for agent governance and points to Lakera Guard for that job instead
  • Organisations whose primary need is model vulnerability scanning, where open tools such as Garak or Promptfoo are a closer fit
  • Buyers who require published pricing to shortlist — Noma's pricing is entirely sales-gated with no public rates
  • Small teams with a handful of agents, where the discovery and registry value proposition does not justify an enterprise security platform
  • Evaluators who need independently audited proof of the vendor's claims: growth and integration counts are self-reported, and there is no meaningful third-party review base

Market Analysis

Enterprise-gradeFull-lifecycle AI securityAgent and MCP governance

Pros

  • Genuinely unified coverage — discovery, posture, red teaming and runtime protection in one product rather than four tools to integrate
  • Agent Access Control (June 2026) addresses MCP governance, which most competitors have not yet built for at tool-level granularity
  • 80-plus integrations spanning cloud AI platforms, SaaS agent platforms and developer tooling, including native Copilot Studio, Agentforce and AWS Security Hub support
  • Named enterprise references (UiPath, Best Buy, Nielsen) and $132M raised give it more staying power than most of the AI-security cohort
  • SOC 2 Type II, ISO 27001 and HIPAA compliance with SAML 2.0/OIDC SSO, MFA and Active Directory integration, plus an on-premises option for sensitive environments

Cons

  • Pricing is completely opaque — no published rates at any tier, and an independent review flags this as a real evaluation obstacle
  • Headline metrics such as 1,300% ARR growth and the 80+ integration count are self-reported from funding announcements and have not been independently audited
  • Built for agent governance rather than low-latency prompt filtering, so it is the wrong tool if input/output guardrails are the actual requirement
  • Not the pick for model vulnerability scanning, where independent reviewers point to Garak or Promptfoo
  • Effectively no third-party review base — no G2, Capterra or TrustRadius profile with meaningful volume — so buyers cannot triangulate the vendor's claims against user experience
  • Crowded segment with well-funded rivals (Lakera, Zenity, Straiker, Lasso, Cisco AI Defense) each stronger in a different sub-area

Pricing

Enterprise platform

Contact for pricing

  • AI and agent discovery
  • AI security posture management
  • AI red teaming
  • AI Detection and Response runtime protection
  • Agent Access Control and Enterprise Agentic Registry
  • 80+ integrations
  • SaaS or on-premises deployment

Noma publishes no dollar figures at all — pricing is entirely sales-gated. An independent review reports the commercial variables as the number of agents secured, the number of MCP servers covered, which integrations are enabled and the deployment scope (SaaS versus on-premises), so the bill scales with agent and MCP estate size rather than with seats. Expect a full enterprise procurement cycle with a proof of value, and expect the on-premises option — which keeps models, data and security events inside the customer environment — to be quoted differently from SaaS. Buyers should press for how agent counts are measured, since agent sprawl is exactly the problem the product exists to reveal and would also drive the price up.

Security & Compliance

soc2
gdpr
hipaa
iso27001
sso
data residency

THE DAILY BRIEF

Enterprise AI insights for technology and business leaders, twice weekly.

beri.net

Subscribe at beri.net/subscribe for twice-weekly AI insights delivered to your inbox.

LinkedIn: linkedin.com/in/rberi  |  X: x.com/rajeshberi

© 2026 Rajesh Beri. All rights reserved.

Noma Security is an enterprise AI security platform that discovers AI assets, manages their posture, red-teams them and defends them at runtime in one product. It is built for security teams at regulated enterprises where AI agents and Model Context Protocol servers have proliferated across developer environments faster than governance could keep up, leaving unattributable actions running on shared credentials.

Noma Security is an enterprise AI security platform that covers the full lifecycle of AI and agent risk in a single product: discovery and inventory of AI assets, posture management, red teaming, and runtime protection, which the company markets as AI Detection and Response (AI-DR). Founded in 2023 by CEO Niv Braun and CTO Alon Tron, who met in the IDF's Unit 8200, and headquartered in New York with a Tel Aviv research and development centre, Noma emerged from stealth in October 2024 and has raised $132 million across three rounds, including a $100 million Series B led by Evolution Equity Partners in July 2025 with Ballistic Ventures, Glilot Capital, Databricks Ventures, Cyber Club London and SVCI participating. Its most recent major release, Noma Agent Access Control, launched on 2 June 2026 and targets the governance gap created by agents and Model Context Protocol servers proliferating inside developer environments. It builds an Enterprise Agentic Registry — a continuously updated inventory of every agent and MCP server with its connections, tool exposure and policy compliance status — assigns each autonomous agent a distinct attributable identity in place of shared credentials so every action traces back to a specific agent, and lets security teams mark each agent-to-MCP connection Approved, Requires Review or Blocked, with allow and block granularity down to individual tools inside an MCP server rather than the whole server. Runtime enforcement monitors the behavioural chain of prompts, tool calls, data access and actions to catch prompt injection, data exfiltration and scope violations. An earlier release, the Agentic Risk Map, visualises how agents connect and what the blast radius of a compromise would be. Noma claims more than 80 integrations, including AWS Bedrock, Azure AI Foundry, Databricks, Microsoft Copilot Studio, Salesforce Agentforce, ServiceNow, AWS Security Hub, Claude Code, Cursor and GitHub Copilot, offers both SaaS and on-premises deployment, and names UiPath, Best Buy and Nielsen among dozens of enterprise customers across financial services, life sciences, retail and technology.

Ideal Buyer

The CISO or AI security lead at a regulated enterprise where agents and MCP servers have already spread across multiple frameworks and clouds, and nobody can answer how many exist or what each one is authorised to do.

Key Benefit

A live, attributable inventory of every agent and MCP server with per-tool allow/block policy and runtime enforcement, replacing shared credentials with identities that make each agent's actions traceable.

At a Glance

Category
Governance & Security
Pricing
Contact for pricing, Subscription
Target Market
CISOs, CIOs, Security Architects, AI Governance Leaders, Enterprise Developers
Deployment
Cloud-first, Self-hosted, Hybrid
Founded
2023
Headquarters
New York, United States
Team Size
51-200
Customers
Dozens of enterprise customers across financial services, life sciences, retail and technology; named customers include UiPath, Best Buy and Nielsen

Key Features

  • Enterprise Agentic Registry

    Continuously updated inventory of every agent and MCP server showing connections, tool exposure and policy compliance status in real time

  • Agent Identity

    Each autonomous agent gets a distinct attributable identity when it connects to MCP servers and tools, replacing shared credentials so actions trace to a specific agent

  • Tool-level access control

    Individual tools inside an MCP server can be approved or blocked independently, rather than forcing an all-or-nothing decision on the whole server

  • Three-state governance model

    Every agent-to-MCP connection is set Approved, Requires Review or Blocked, giving security teams a workable middle state instead of a binary gate

  • AI Detection and Response (AI-DR) runtime enforcement

    Monitors the behavioural chain of prompts, tool calls, data access and actions to catch prompt injection, data exfiltration and scope violations as they happen

  • Agentic Risk Map

    Visualises how agents connect to each other and to data, making the blast radius of a compromised agent legible to a security team

  • Integrated AI red teaming

    Adversarial testing runs inside the same platform as discovery and posture, so findings feed directly into policy rather than a separate report

Capabilities

text generation
image generation
video generation
code generation
workflow automation
api access
audio generation
fine tuning
agent orchestration

Use Cases

  • Inventorying shadow AI across a large enterprise

    Security discovers agents, models and MCP servers stood up by developers without review, which is the precondition for governing any of them

  • Securing MCP adoption in developer tooling

    Claude Code, Cursor and GitHub Copilot connect to internal MCP servers under per-agent identity and per-tool policy instead of shared credentials

  • Governing vendor agent platforms

    Agents built in Microsoft Copilot Studio, Salesforce Agentforce and ServiceNow are brought under one policy and monitoring plane across vendors

  • Detecting prompt injection and exfiltration in production

    Runtime monitoring of the prompt-to-action chain flags an agent being manipulated into moving data outside its authorised scope

  • Evidencing AI governance to auditors

    Regulated firms produce a live register of AI assets, their policies and their runtime events to satisfy audit and compliance review

Ideal For

Best For

  • Discovering shadow AI — agents, models and MCP servers deployed across developer environments without security review
  • Giving each autonomous agent a distinct identity so its actions are attributable instead of hidden behind shared service credentials
  • Governing MCP server access at tool-level granularity, approving some tools on a server while blocking others
  • Runtime detection of prompt injection, data exfiltration and scope violations across the prompt-to-action chain
  • Regulated industries (financial services, life sciences) that must evidence AI governance controls to auditors

Not Ideal For

  • Teams that only need low-latency input/output prompt filtering — an independent review notes Noma is built for agent governance and points to Lakera Guard for that job instead
  • Organisations whose primary need is model vulnerability scanning, where open tools such as Garak or Promptfoo are a closer fit
  • Buyers who require published pricing to shortlist — Noma's pricing is entirely sales-gated with no public rates
  • Small teams with a handful of agents, where the discovery and registry value proposition does not justify an enterprise security platform
  • Evaluators who need independently audited proof of the vendor's claims: growth and integration counts are self-reported, and there is no meaningful third-party review base

Deployment

On-Premise

Market & Ratings

Estimated Customers

Dozens of enterprise customers across financial services, life sciences, retail and technology; named customers include UiPath, Best Buy and Nielsen

Market Analysis

Enterprise-gradeFull-lifecycle AI securityAgent and MCP governance

Pros

  • Genuinely unified coverage — discovery, posture, red teaming and runtime protection in one product rather than four tools to integrate
  • Agent Access Control (June 2026) addresses MCP governance, which most competitors have not yet built for at tool-level granularity
  • 80-plus integrations spanning cloud AI platforms, SaaS agent platforms and developer tooling, including native Copilot Studio, Agentforce and AWS Security Hub support
  • Named enterprise references (UiPath, Best Buy, Nielsen) and $132M raised give it more staying power than most of the AI-security cohort
  • SOC 2 Type II, ISO 27001 and HIPAA compliance with SAML 2.0/OIDC SSO, MFA and Active Directory integration, plus an on-premises option for sensitive environments

Cons

  • Pricing is completely opaque — no published rates at any tier, and an independent review flags this as a real evaluation obstacle
  • Headline metrics such as 1,300% ARR growth and the 80+ integration count are self-reported from funding announcements and have not been independently audited
  • Built for agent governance rather than low-latency prompt filtering, so it is the wrong tool if input/output guardrails are the actual requirement
  • Not the pick for model vulnerability scanning, where independent reviewers point to Garak or Promptfoo
  • Effectively no third-party review base — no G2, Capterra or TrustRadius profile with meaningful volume — so buyers cannot triangulate the vendor's claims against user experience
  • Crowded segment with well-funded rivals (Lakera, Zenity, Straiker, Lasso, Cisco AI Defense) each stronger in a different sub-area

Pricing

Enterprise platform

Contact for pricing

  • AI and agent discovery
  • AI security posture management
  • AI red teaming
  • AI Detection and Response runtime protection
  • Agent Access Control and Enterprise Agentic Registry
  • 80+ integrations
  • SaaS or on-premises deployment

Noma publishes no dollar figures at all — pricing is entirely sales-gated. An independent review reports the commercial variables as the number of agents secured, the number of MCP servers covered, which integrations are enabled and the deployment scope (SaaS versus on-premises), so the bill scales with agent and MCP estate size rather than with seats. Expect a full enterprise procurement cycle with a proof of value, and expect the on-premises option — which keeps models, data and security events inside the customer environment — to be quoted differently from SaaS. Buyers should press for how agent counts are measured, since agent sprawl is exactly the problem the product exists to reveal and would also drive the price up.

Security & Compliance

soc2
gdpr
hipaa
iso27001
sso
data residency

Sources

This page was written from 6 sources, 5 on domains other than noma.security.

  1. 1.prnewswire.comnoma launches agentic access control to govern ai agents and
  2. 2.appsecsanta.comnoma security
  3. 3.prnewswire.comnoma security raises 100m to drive adoption of ai agent secu
  4. 4.calcalistech.coms19xaaudxl
  5. 5.timesofisrael.comtel aviv startup raises 100 million to secure ai application
  6. 6.noma.securityplatformvendor
Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe