Onyx Security
by Onyx Security Ltd.
The secure AI control plane — inspect, govern and block what your agents do
Onyx Security is a control plane that sits between an enterprise's AI agents and the systems they act on, inspecting prompts, tool calls and responses in real time and blocking risky actions before they execute. It combines shadow-AI discovery, inline threat protection, natural-language policy enforcement, an LLM gateway and adoption dashboards, and is aimed at security, governance and platform teams overseeing agent rollouts.
Onyx Security sells what it calls a secure AI control plane: a layer that sits between an enterprise's AI agents and the systems they act on, inspecting each step of an agent's reasoning and tool use before the action executes. The platform is organised into five modules. AI Observability discovers sanctioned and shadow AI across SaaS, cloud, endpoints, browsers, coding assistants, desktop agents and MCP servers, with session replay, audit trails and anomaly detection. AI Security applies inline inspection of prompts, tool calls and model responses to catch prompt injection, jailbreaks, data exfiltration, over-permissioned agents and credential mishandling, and runs continuous autonomous agentic red teaming across reconnaissance, jailbreaking and weaponisation phases. AI Governance lets policies be authored in natural language and maps them to OWASP LLM Top 10, NIST AI RMF, MITRE ATLAS, ISO 42001 and the EU AI Act. AI Orchestration provides a centralised AI gateway with LLM routing, automated failover, cost optimisation and MCP traffic proxying with inline guardrails. AI ROI supplies executive dashboards on adoption, productivity and cost avoidance. Enforcement offers five actions — alert, block, mask, steer, or ask a human — and requires no SDK changes. Onyx reports more than 1.1 million agents secured, 1.8 million employees covered and 66.2 million sessions analysed, with 100+ prebuilt integrations spanning AWS, Azure, GCP, OpenAI, Okta, Microsoft Entra, Splunk and CrowdStrike; Anthropic announced an integration in June 2026 pulling Claude Enterprise conversations, files and activity logs in through the Compliance API. Founded in Israel in 2024 by Maxim Bar Kogan and Gil Elbaz, it raised a $113 million Series B on 29 July 2026 led by Bessemer at roughly a $640 million valuation, taking total funding to $153 million.
A CISO or head of security engineering at a large enterprise where business units have already deployed AI agents faster than security can inventory them, and who needs enforcement rather than another dashboard.
A working inventory of every agent and AI surface in the estate within about 24 hours, with runtime policy that can actually block an agent action before it executes.
At a Glance
- Category
- Governance & Security
- Pricing
- Contact for pricing, Subscription
- Target Market
- CISOs, CIOs, Security Engineering Leads, AI Governance Teams, Platform Engineering Leaders
- Deployment
- Cloud-first, Hybrid, Self-hosted, Multi-cloud
- Founded
- 2024
- Headquarters
- Tel Aviv, Israel
- Team Size
- 51-200
- Customers
- Fortune 500 customers in banking, energy, healthcare and insurance; 1.1M+ agents secured across 1.8M+ employees
Key Features
- ✓Runtime action inspection
Inspects prompts, tool calls and model responses inline and can alert, block, mask, steer or ask a human before the action executes.
- ✓Shadow AI discovery
Finds unsanctioned agents and AI usage across SaaS, cloud, endpoints, browsers and code, typically producing a working inventory within 24 hours.
- ✓Autonomous agentic red teaming
Continuously attacks deployed agents across reconnaissance, jailbreaking and weaponisation phases rather than relying on a point-in-time pentest.
- ✓Natural-language policy authoring
Policies are written in plain language and mapped to OWASP LLM Top 10, NIST AI RMF, MITRE ATLAS, ISO 42001 and the EU AI Act.
- ✓AI gateway and MCP proxying
Centralised LLM routing with automated failover, cost optimisation and MCP traffic proxying with inline guardrails applied at the gateway.
- ✓AI ROI dashboards
Executive reporting on AI adoption, productivity gains and cost avoidance by department, aimed at justifying the programme to the board.
- ✓Agentless deployment
Integrates with the existing stack — Okta, Entra, Intune, Jamf, Tanium, Splunk, CrowdStrike — with no SDK changes required in applications.
Capabilities
Use Cases
- •Inventorying an ungoverned agent estate
Security discovers which agents and AI tools business units have already deployed across the environment before setting any policy at all.
- •Blocking data exfiltration by an over-permissioned agent
An agent attempting an unauthorised API call or data access is stopped inline rather than surfaced in a log review days later.
- •Securing a Claude Enterprise rollout
The Anthropic integration pulls conversation content, uploaded files, project data and activity logs into Onyx through the Compliance API.
- •Producing EU AI Act audit evidence
Policies mapped to regulatory frameworks generate unified audit trails that satisfy SOC 2 and ISO checklists for AI systems.
- •Controlling multi-provider LLM spend
The AI gateway routes traffic across OpenAI, Anthropic, Bedrock and others with failover and cost optimisation applied centrally.
Ideal For
Best For
- ✓Discovering shadow AI and unsanctioned agents already running across SaaS, browsers, endpoints and code
- ✓Enforcing runtime guardrails on autonomous agents acting inside financial, healthcare or energy systems
- ✓Mapping AI controls to EU AI Act, NIST AI RMF, ISO 42001, MITRE ATLAS and OWASP LLM Top 10 for audit evidence
- ✓Centralising multi-provider LLM traffic behind one gateway with routing, failover and cost controls
- ✓Securing Claude Enterprise, OpenAI and Bedrock deployments without instrumenting each application separately
Not Ideal For
- ✗Smaller organisations with a handful of AI applications — the five-module scope and enterprise-direct sales motion are sized for estates with thousands of agents, not dozens
- ✗Buyers who need published pricing or a self-serve trial to evaluate; there is no rate card and no free tier anywhere
- ✗Teams that have already bought overlapping CASB, DSPM, SIEM and AI-gateway products, where a large share of Onyx's surface is duplicate spend
- ✗Anyone requiring a long production track record — the company is roughly two years old and only came out of stealth in early 2026
Deployment
Market & Ratings
Fortune 500 customers in banking, energy, healthcare and insurance; 1.1M+ agents secured across 1.8M+ employees
Market Analysis
Pros
- ✓Enforcement, not just visibility — the five inline actions (alert, block, mask, steer, ask) put it ahead of tools that only observe, and agentless deployment means no application rewrites
- ✓The strongest third-party validation in this category: Anthropic shipped a first-party Claude Enterprise integration in June 2026, and Bessemer led a $113M round at roughly $640M four months out of stealth
- ✓Genuinely published compliance posture — a SafeBase trust centre listing ISO/IEC 27001:2022, SOC 2 Type 2 and GDPR, with SOC 2 and pentest reports available on request and subprocessors disclosed
- ✓Scale claims are specific and checkable in shape (1.1M+ agents, 1.8M+ employees, 66.2M+ sessions) rather than vague, and deployment supports cloud, hybrid and self-hosted
Cons
- ✗Extremely crowded category — Zenity ($125M Series C), Act Security ($60M), Neo ($100M) and the Cyera/Oasis Security combination all sell overlapping AI control planes, and durable differentiation is unproven
- ✗Roughly two years old and only about four months out of stealth at the Series B; 'quadrupled revenue' is growth off an undisclosed and almost certainly small base, with no absolute ARR published
- ✗No independent review presence whatsoever — nothing on G2, Capterra, TrustRadius or PeerSpot, and no Hacker News or Reddit discussion — so all product and scale claims are vendor-reported
- ✗Only one enterprise customer (Revolut) is named in press coverage; the site's testimonials are from smaller companies, so the 'Fortune 500' base is unverifiable from outside
- ✗The five-module scope overlaps heavily with incumbent CASB, DSPM and SIEM tooling and with native controls the model vendors ship themselves, creating a real risk of paying twice
- ✗No pricing published at all, no free tier and no self-serve trial, so evaluation requires a sales cycle before any technical assessment
- ✗OpenAI is a disclosed subprocessor, which is worth understanding for buyers whose reason for adopting a control plane is precisely to constrain where AI-adjacent data flows
Pricing
Enterprise
Contact for pricing
- ✓AI Observability, Security, Governance, Orchestration and ROI modules
- ✓100+ prebuilt integrations
- ✓Cloud, hybrid or self-hosted deployment
- ✓SOC 2 Type II and ISO 27001 certified
No pricing is published in any form — no rate card, no tiers, no free tier and no self-serve trial. Onyx sells enterprise-direct, and the natural metering units given the product's own metrics (agents secured, employees covered, sessions analysed) are likely some combination of seats and inspected volume, but the vendor does not say. Expect a scoped commercial negotiation, and note the overlap with existing CASB, DSPM, SIEM and AI-gateway spend when comparing quotes — a meaningful part of the five-module surface may already be covered elsewhere.
Security & Compliance
Sources
This page was written from 6 sources, 4 on domains other than onyx.security.
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
Norm Ai
Regulatory AI agents that turn written rules into executable compliance checks
Torq SOC Brain
A self-learning layer that trains your SOC's own AI on your analysts' past verdicts
Okta for AI Agents
Identity, least-privilege access and a kill switch for every AI agent in the enterprise
ServiceNow AI Control Tower
Enterprise command center to discover, govern, secure and measure every AI agent and model