Zenity
by Zenity
Runtime AI agent security that blocks a harmful agent action before it executes
Zenity is an AI agent security and governance platform for enterprises running Copilot, ChatGPT Enterprise, Gemini, Claude, Cursor and home-grown agents. It discovers every agent in the estate, reads the intent behind an agent's execution path, and allows, modifies or blocks the action before it runs — closing the gap between agent adoption and the security controls that were built for humans.
Zenity, founded in 2021 by CEO Ben Kliger and CTO Michael Bargury, sells a security and governance layer purpose-built for AI agents, and raised a $125 million Series C led by Norwest in August 2026 that brings total funding to roughly $180-185 million. The platform is organised in three planes: Surface discovers the agents running across the estate along with their blast radius and exploitable elements; Enforce turns policy into runtime action control; and Protect handles threat detection, investigation and response, with policies mapped to the OWASP LLM Top 10 and MITRE ATLAS. Its differentiating mechanism is intent-based detection — rather than scanning prompts or outputs in isolation, it inspects the execution path (tool calls, memory access, data touched) to distinguish legitimate work from behaviour that has been manipulated, compromised or drifted outside its intended purpose, then deterministically allows, modifies or blocks the action before it executes. Coverage spans commercial assistants including Microsoft Copilot, ChatGPT Enterprise, Gemini, Claude, Cursor and AWS Bedrock and Google Vertex AI-built agents, plus custom agentic platforms and endpoint agents. The company reports 230-plus employees with R&D in Tel Aviv and go-to-market in New York, revenue tripling in each of the past two years against a base of tens of millions in annual revenue, and a customer base weighted to Fortune 500 and Global 2000 organisations in financial services, healthcare, pharmaceuticals, manufacturing and technology. Gartner named it a Cool Vendor in Agentic AI TRiSM (2025) and, per the vendor, 'the company to beat' in AI agent governance. Zenity Labs, its research arm, publishes vulnerability findings against commercial agent platforms.
The CISO or head of security engineering at a large enterprise where Copilot and ChatGPT Enterprise are already deployed at scale and business units are building their own agents faster than security can review them.
A single inventory and enforcement point across every agent platform in the estate, with the ability to stop a manipulated agent action at runtime rather than discover it in an audit.
At a Glance
- Category
- Governance & Security
- Pricing
- Contact for pricing
- Target Market
- CISOs, CIOs, Security Architects, GRC Leaders, Enterprise Developers
- Deployment
- Cloud-only
- Founded
- 2021
- Headquarters
- Tel Aviv, Israel
- Team Size
- 201-500
Key Features
- ✓Agent discovery (Surface)
Continuously inventories agents across SaaS, cloud and endpoint, including business-built ones security never approved
- ✓Intent-based detection
Analyses the execution path — tool calls, memory reads, data usage — to judge whether an action matches the agent's legitimate purpose
- ✓Runtime action enforcement
Deterministically allows, modifies or blocks an agent action before execution rather than alerting after the fact
- ✓Cross-platform coverage
One policy layer over Copilot, ChatGPT Enterprise, Gemini, Claude, Cursor, AWS Bedrock, Vertex AI and custom agent frameworks
- ✓OWASP and MITRE ATLAS mapping
Detections and policies align to recognised AI threat taxonomies, which shortens audit and board reporting work
- ✓Zenity Labs research feed
In-house research team publishes agent-platform vulnerabilities, feeding new detections back into the product
Use Cases
- •Copilot sprawl control
Inventory every Copilot Studio agent a business unit has published and enforce data-access policy on each one centrally
- •Prompt-injection containment
Detect an agent acting on injected instructions from a poisoned document and block the resulting tool call before data leaves
- •Agent data-exfiltration prevention
Stop an agent from moving sensitive records into an unapproved destination even when the user request looks routine
- •Agent incident investigation
Reconstruct what an agent did, which tools it invoked and what data it touched when responding to a security incident
- •Pre-deployment agent review
Assess a new internally-built agent's blast radius and exploitable surface before it is released to employees
Ideal For
Best For
- ✓Discovering shadow AI agents built by business units across Copilot Studio, ChatGPT Enterprise and custom platforms
- ✓Blocking prompt-injection and tool-poisoning attacks at runtime before the agent acts on them
- ✓Enforcing consistent agent policy across multiple vendors' agent frameworks from one control point
- ✓Investigating agent incidents with execution-path evidence mapped to OWASP LLM Top 10 and MITRE ATLAS
- ✓Governing Microsoft Copilot at enterprise scale, where Zenity has its longest track record
Not Ideal For
- ✗Air-gapped or zero-egress environments — delivery is cloud-oriented and independent reviews specifically flag that it is not built for fully isolated operation
- ✗Teams whose risk is at the GPU, model-serving or inference-node layer; Zenity's surface is SaaS assistants and enterprise agents, not infrastructure protection
- ✗Small and mid-market buyers — pricing is unpublished, sales-led and pitched at Fortune 1000 estates, so the platform is oversized for a handful of agents
- ✗Organisations wanting a single tool for both agent security and model evaluation or quality testing, which is a separate category Zenity does not cover
Deployment
Market Analysis
Pros
- ✓Genuine runtime enforcement — the platform can stop an action pre-execution, which most competitors in this category cannot do outside a narrow prompt filter
- ✓Broadest platform coverage seen in the category: Copilot, ChatGPT Enterprise, Gemini, Claude, Cursor, Bedrock, Vertex AI and custom agents under one policy layer
- ✓Strong commercial signal — revenue tripled in each of the last two years, 230+ staff, and a $125M Series C in August 2026 with SoftBank, Hitachi, LG and Intel Capital on the cap table
- ✓Analyst validation from Gartner (Cool Vendor, Agentic AI TRiSM 2025) reduces the internal justification burden for a security buyer
Cons
- ✗Cloud-delivered and, per independent reviews, not designed for air-gapped or zero-egress deployment — a hard blocker for defence, intelligence and some critical-infrastructure buyers
- ✗Coverage leans toward discovery, posture and detection across the SaaS surface; agent-side inline enforcement is less complete than the marketing implies, and reviewers call this out
- ✗No protection at the GPU, model-serving or inference layer, so it is one part of an AI security stack rather than the whole of it
- ✗No public pricing, no free tier and no trial — evaluation requires a sales cycle, and the metering unit is not disclosed
- ✗Protection is only as good as its platform connectors, so an agent framework Zenity has not integrated is simply invisible to it
- ✗Extremely crowded category — three AI-agent security companies raised roughly $270M in a single week in August 2026, so differentiation and pricing power may compress quickly
Pricing
Enterprise
Contact for pricing
- ✓Agent discovery across SaaS, cloud and endpoint
- ✓Intent-based runtime enforcement
- ✓Threat detection and response
- ✓OWASP LLM Top 10 and MITRE ATLAS policy mapping
No list pricing is published anywhere on the vendor site — every engagement is sales-led and quoted, which is standard for enterprise security but means there is no way to size a deal without a call. The company reports tens of millions in annual revenue across a customer base weighted to Fortune 500 and Global 2000 accounts, so the entry point is an enterprise-scale commitment rather than a per-seat or per-agent self-serve tier. Neither a free tier nor a public trial is offered, and the pages fetched did not state the metering unit (agents, users or tenants).
Security & Compliance
Sources
This page was written from 4 sources, 2 on domains other than zenity.io.
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
Saviynt Zuma
Identity control plane for AI agents and non-human identities, with runtime authorization
Bigeye AI Trust Platform
Governance, observability and runtime enforcement for the data your AI agents are allowed to touch
Legit Security VibeGuard
Endpoint guardrails that discover every coding agent on a developer's machine and police what it is allowed to do
Filigran XTM One
An AI agent layer that runs threat exposure management across OpenCTI and OpenAEV as one loop