WitnessAI
by WitnessAI
Network-layer AI security and governance for employee AI use, models, apps and agents
WitnessAI is an enterprise AI security and governance platform that sits in the network path between users, agents and AI models. Security and compliance teams at large regulated companies use it to find shadow AI and MCP servers, apply intent-based policies, redact sensitive data and block prompt injection at runtime.
WitnessAI is a Mountain View company founded in 2023 by Rick Caccia (CEO) and Gil Spencer. Its platform is organised into three modules. Observe discovers AI applications, agents and MCP servers in use across the company and classifies each interaction by type and intent. Control applies department, role and intent-based policies, routes prompts to approved models based on risk, cost and data sensitivity, enforces which MCP servers may be used, and redacts sensitive data in real time with an audit trail. Protect handles runtime defence: prompt injection and jailbreak blocking, output filtering and automated red teaming before deployment. The product inspects traffic at the network layer between users and models, without modifying the models, so it sees the most when a company already routes traffic through central egress such as a SASE overlay or always-on VPN. In January 2026 the company added agentic security, which detects agent activity in Claude Desktop, VS Code AI extensions, ChatGPT plugins and local LangChain, LlamaIndex and CrewAI agents, fingerprints MCP servers, and ties each agent action back to the human who started the workflow. The same month it raised a $58 million round led by Sound Ventures, with Fin Capital, Qualcomm Ventures, Samsung Ventures and Forgepoint taking part, after a $27.5 million Series A from GV and Ballistic Ventures in 2024. WitnessAI reports more than 500% ARR growth, a figure it disclosed itself and that no outside party has audited. It holds SOC 2 Type 1 and Type 2, offers single-tenant deployment for regulated buyers, and competes with Lakera, Prompt Security, CalypsoAI and SSE vendors that have added AI controls.
A CISO or AI governance lead at a large regulated enterprise with centralised network egress who has to account for every employee and agent interaction with AI models.
One policy and audit layer for employee AI use, model traffic and agent tool calls, with sensitive data redacted before it reaches a model.
At a Glance
- Category
- Governance & Security
- Pricing
- Contact for pricing
- Target Market
- CISOs, CIOs, AI Governance Leads, Compliance Teams
- Deployment
- Hybrid, Cloud-first
- Founded
- 2023
- Headquarters
- Mountain View, United States
- Team Size
- 51-200
Key Features
- ✓Shadow AI and MCP discovery
Catalogues the AI applications, agents and MCP servers employees actually use, so security teams can see exposure before writing policy.
- ✓Intent-based policy engine
Classifies what a prompt is trying to do and applies role, department and intent rules, which cuts false positives from plain pattern matching.
- ✓Real-time data redaction
Tokenises PII and credentials in prompts before they leave the network and logs each interaction for compliance audits.
- ✓Runtime prompt injection defence
Blocks prompt injection, jailbreaks and role-playing attacks before execution and filters model responses afterwards.
- ✓Agent identity attribution
Links agent-to-agent and agent-to-tool activity back to the human who started the workflow under one audit log.
- ✓Intelligent model routing
Sends each prompt to an approved model based on risk, cost and data sensitivity, which also supports FinOps controls on AI spend.
- ✓Automated red teaming
Tests internal AI applications for vulnerabilities before they are deployed to employees or customers.
Capabilities
Use Cases
- •Governing employee use of public chatbots
Let staff use ChatGPT, Claude or Gemini while redacting customer data and logging every prompt for auditors.
- •Securing coding agents and MCP servers
Find which developers run Claude Desktop or VS Code agents, fingerprint the MCP servers they connect to, and block unapproved ones.
- •Protecting customer-facing chatbots
Put runtime injection and jailbreak filtering in front of an external chatbot so attackers cannot extract data or hijack its instructions.
- •Regulatory evidence for AI use
Produce per-user and per-agent audit trails that compliance teams can hand to regulators in financial services or telecoms.
Ideal For
Best For
- ✓Discovering shadow AI apps, agents and MCP servers in use across a large workforce
- ✓Enforcing role and department-based AI usage policies with an audit trail for regulators
- ✓Redacting PII and credentials from prompts before they reach third-party models
- ✓Attributing agent and MCP tool activity to the human who initiated it
- ✓Banks, utilities, telecoms and automotive firms that need single-tenant data sovereignty
Not Ideal For
- ✗Remote-first companies with no SASE overlay or always-on VPN, since a network-inline product only partly sees traffic that leaves home connections directly
- ✗Teams that want to stop a malicious MCP tool call on the developer's own machine, because WitnessAI does not hook the IDE toolchain or run a native browser extension
- ✗Small companies that need published self-serve pricing; every deal is quote-based
Deployment
Market Analysis
Pros
- ✓Covers employee AI use, model traffic, applications and agents in one platform
- ✓Intent-based detection catches multi-turn jailbreaks that pattern matching misses
- ✓SOC 2 Type 1 and Type 2 with single-tenant deployment for regulated buyers
- ✓Early support for MCP server discovery and agent-to-human attribution
Cons
- ✗Strongest only where traffic already flows through a central proxy; distributed teams without SASE get partial coverage
- ✗No native browser extension or IDE hook, so it cannot stop a malicious MCP call on a developer laptop
- ✗Almost no public user reviews to check vendor claims against, and Hacker News has no practitioner discussion of it
- ✗Quote-only pricing, and intent-classifier accuracy and ISO 42001 mapping are unpublished
Pricing
Enterprise
Contact for pricing
- ✓Observe, Control and Protect modules
- ✓Single-tenant deployment option
- ✓Agentic security and MCP discovery
- ✓Demo booked through sales
WitnessAI publishes no list prices. Every deployment is quote-based through sales, and independent reviewers on AppSecSanta and AI Security Platform both flag the lack of a public rate card, so budget for a procurement cycle.
Security & Compliance
Sources
This page was written from 6 sources, 4 on domains other than witness.ai.
- 1.witness.ai — witness.aivendor
- 2.witness.ai — introducing witnessai agentic security extending the confidevendor
- 3.bankinfosecurity.com — witnessai secures 58m to grow global ai security reach a 305
- 4.theaiinsider.tech — witnessai raises 58m to expand enterprise ai security and ag
- 5.appsecsanta.com — witnessai
- 6.aisecurityplatform.com — witness ai
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
Reco
AI agent security and SaaS security platform that discovers, governs and secures every agent, app and identity
Ascerta
Enterprise AI management: measure the ROI, cost and adoption of every AI initiative, agent and coding tool
Arcjet
Runtime security for AI agents: observe, enforce and audit agent tool calls, with prompt-injection, PII and abuse controls in code
Exaforce
Agentic SOC and MDR platform whose Exabot AI agents detect, triage, investigate and respond, now with an AI-agent kill switch