Straiker
by Straiker
Agentic AI security that discovers, red-teams and protects AI agents at runtime
Straiker is an agentic AI security platform that inventories the AI agents, MCP servers and coding assistants running across an enterprise, attacks them with automated red teaming before release, and blocks prompt injection, data exfiltration and tool misuse at runtime. It is built for CISOs and security teams governing AI agents.
Straiker is a Mountain View, California security company founded in 2024 by CEO Ankur Shah, a veteran cloud-security executive, and CTO Sreenath Kurupati, who led AI and security research at Akamai after it acquired his earlier startup Cyberfend. Its platform has three modules that share threat intelligence. Discover AI, launched in March 2026, inventories agents, MCP servers and tools across coding assistants such as Cursor, Claude Code and GitHub Copilot, productivity agents such as Microsoft Copilot, ChatGPT Enterprise and Salesforce Agentforce, and custom agents built on Amazon Bedrock AgentCore, Azure Foundry and Copilot Studio, flagging excessive permissions, unrestricted execution modes and risky MCP configurations. Ascend AI runs pre-deployment adversarial testing for prompt injection, goal hijacking, tool misuse and inter-agent manipulation. Defend AI enforces runtime guardrails, either in monitoring mode through API integrations or inline through an AI gateway, SDK or eBPF-based sensors, and emits OpenTelemetry-native traces so incidents land in existing SOC, SIEM and ITSM tools. Its STAR Labs research team feeds new attack techniques back into the defensive models. On 29 June 2026 Straiker announced a $64M Series A led by Marathon Management Partners, Citi Ventures, Illuminate Financial and Workday Ventures, taking total funding to $85M after a $21M seed in March 2025, and said run-rate revenue had grown more than 15x in under a year. It names no customers publicly beyond Fortune 500 enterprises and frontier AI labs. Gartner listed it as a Representative Vendor in its February 2026 Market Guide for Guardian Agents. It competes with Zenity, Noma Security and Lakera in agent security.
CISOs and AI security leads at large enterprises rolling out coding assistants, Copilot-style productivity agents and in-house agents, who need one inventory and runtime control point across all of them.
A single view of which AI agents and MCP servers are running, red-team evidence of which attack paths are actually exploitable, and inline blocking of prompt injection and data exfiltration.
At a Glance
- Category
- Governance & Security
- Pricing
- Contact for pricing
- Target Market
- CISOs, CIOs, CTOs, Security Engineers
- Deployment
- Cloud-first, API-based
- Founded
- 2024
- Headquarters
- Mountain View, USA
- Team Size
- 51-200
Key Features
- ✓Discover AI
Automatically inventories AI agents, MCP servers and tools across coding assistants, productivity platforms and agent frameworks, flagging risky permissions and configurations.
- ✓Ascend AI red teaming
Runs automated adversarial attacks against agents before deployment to surface prompt injection, goal hijacking, tool misuse and inter-agent manipulation.
- ✓Defend AI runtime guardrails
Inspects agent inputs, outputs and tool calls in production to block prompt injection, data exfiltration, tool misuse and agent hijacking.
- ✓Flexible insertion points
Deploys in monitoring mode through API integrations or inline through an AI gateway, SDK or eBPF sensors, so teams choose how invasive enforcement is.
- ✓SOC integration via OpenTelemetry
Emits OpenTelemetry-native traces so agent incidents flow into existing SOC, SIEM and ITSM platforms instead of yet another console.
- ✓STAR Labs threat research
An in-house research team whose findings on new agent attack techniques, such as malicious skills files, feed the defensive models.
Capabilities
Use Cases
- •Coding-assistant governance
Security teams discover Cursor, Claude Code and GitHub Copilot usage and connected MCP servers, then flag agents running with unrestricted execution modes.
- •Pre-release agent testing
AppSec teams red-team a customer-facing agent before launch to prove whether prompt injection can actually reach sensitive tools and data.
- •Productivity-agent data protection
Enterprises monitor Microsoft Copilot and ChatGPT Enterprise agent activity and block silent exfiltration of sensitive data through tool calls.
- •Runtime protection for custom agents
Platform teams building on Amazon Bedrock AgentCore or Azure Foundry add inline guardrails through a gateway, SDK or eBPF sensor and route incidents to their SIEM.
Ideal For
Best For
- ✓Inventorying shadow AI agents and MCP servers across coding assistants and productivity suites
- ✓Red-teaming in-house agents for prompt injection, goal hijacking and tool misuse before release
- ✓Runtime blocking of data exfiltration and malicious tool calls by production agents
- ✓Routing agent security incidents into existing SOC, SIEM and ITSM workflows
- ✓Governing third-party agents such as Microsoft Copilot, ChatGPT Enterprise and Salesforce Agentforce
Not Ideal For
- ✗Buyers who need a vendor with a deep reference list in their industry or a large enterprise support organisation: independent reviewers describe Straiker as earlier-stage than peers such as Noma Security, and it names no customers publicly.
- ✗Teams hoping to replace SAST, SCA, DAST, cloud posture or identity controls: Straiker covers the agent layer only and sits alongside those tools.
- ✗Organisations that want self-serve evaluation or published pricing: access starts with a demo request and there is no public API reference or installation guide.
Integrations
Deployment
Market Analysis
Pros
- ✓Full lifecycle coverage (discovery, red teaming and runtime protection) in one platform
- ✓Broad coverage of third-party agents and coding assistants as well as custom agents on major cloud agent platforms
- ✓Well funded at $85M total, with SOC 2 Type II and ISO/IEC 27001 certification
- ✓Listed as a Representative Vendor in Gartner's February 2026 Market Guide for Guardian Agents
Cons
- ✗Earlier-stage than rivals such as Noma Security, with a thin public reference list and no named customers
- ✗No public pricing, API reference, installation guide or versioned release archive
- ✗Inline blocking can itself affect agent reliability, and a passed red-team test set does not prove every prompt-injection path is covered
- ✗Does not replace SAST, SCA, DAST, cloud posture or identity controls, so it adds another tool to the security stack
Pricing
Enterprise
Contact for pricing
- ✓Discover AI, Ascend AI and Defend AI modules
- ✓SaaS with API, SDK, gateway or eBPF sensor integration
- ✓Evaluation by demo request
Straiker publishes no list pricing, free tier, self-serve trial, API reference or installation guide; evaluation starts with a demo request, and independent reviewers (AppSec Santa, SecurityOps Wire) both confirm pricing is not disclosed. Expect a sales-led enterprise contract.
Security & Compliance
Sources
This page was written from 7 sources, 7 on domains other than straiker.ai.
- 1.prnewswire.com — straiker raises 64m series a to secure the agentic workforce
- 2.govinfosecurity.com — straiker raises 64m to safeguard autonomous ai agents a 3209
- 3.helpnetsecurity.com — straiker discover ai
- 4.intellyx.com — straiker controlled attackers and response guards for agenti
- 5.appsecsanta.com — straiker
- 6.securitystack.app — straiker
- 7.securityopswire.com — noma security alternatives
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
WitnessAI
Network-layer AI security and governance for employee AI use, models, apps and agents
Ascerta
Enterprise AI management: measure the ROI, cost and adoption of every AI initiative, agent and coding tool
Reco
AI agent security and SaaS security platform that discovers, governs and secures every agent, app and identity
Arcjet
Runtime security for AI agents: observe, enforce and audit agent tool calls, with prompt-injection, PII and abuse controls in code