Evoke Security
Detection and response for AI agents that records every prompt, tool call and action of the customer's agents across endpoint, web and cloud, inventories agents, MCP servers and Skills, and blocks or redirects risky actions in real time.
Evoke Security secures what it calls the agentic workforce: the AI agents employees and engineering teams run with access to email, customer data, source code and production systems. It has three modules. Agent Detection and Response monitors every prompt, tool call and action across endpoint, web and cloud, blocks agent misuse and nudges rogue actions to safer paths. Agent Inventory and Governance tracks the agents, MCP servers, Agent Skills and tools in use across the enterprise, with their permissions.
Agent Security Posture Management finds over permissioned agents, toxic tool combinations and malicious Skills and MCP servers. Evoke collects through an endpoint sensor for local agents on Mac and Windows, an SDK and proxy API for production agents in the cloud, and API integrations and a browser extension for SaaS agents, covering Claude, Cursor, OpenAI, Google Antigravity, Amazon Bedrock and others, and in July 2026 it added coverage through Anthropic's Claude Compliance API.
Evoke was founded in 2025 by CEO Jason Rebholz and Jeffrey Chan and raised a four million dollar pre seed in February 2026 led by Crosspoint Capital Partners with Red Cell Partners. Its trust center renders only in a browser, and its pages do not document an attestation, a hosting region or deployment option for the platform, a published SDK reference, or an approval step that holds an agent's action for a person. It fits security teams that need to see and police what employees' and production AI agents actually do, from coding assistants to SaaS agents; buyers who need documented attestations or a self hosted control plane should ask.
Vendor details
Canonical URL
https://www.evokesecurity.com/
Category
Security / SOC agent
Funding status
$4M pre seed (February 2026), led by Crosspoint Capital Partners with Red Cell Partners. Founded 2025.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
An endpoint sensor for local agents on Mac and Windows, an SDK and proxy API for production agents, and API integrations and a browser extension for SaaS agents, covering Claude, Cursor, OpenAI, Google Antigravity and Amazon Bedrock among others; the Claude Compliance API integration (July 2026) adds read access to Claude activity.
In practice
Engineers run Claude Code and Cursor with access to production. Evoke's endpoint sensor records every prompt, tool call and action, and steers an agent away from a destructive command before it runs.
Someone installs an agent Skill from an unknown repository. Evoke flags the malicious Skill and the over permissioned agent using it, and notifies the security team.
Your security lead needs to know which AI agents exist across laptops, cloud and SaaS. Evoke deploys through your MDM in minutes and builds the inventory of agents, MCP servers, Skills and their permissions.
Sources & related URLs
Agentic Index coverage score
5.0 / 14 capabilities · 36%
| Integrations & Tool Calling | Full |
|---|---|
|
Evoke reaches the customer's agents through an endpoint sensor on Mac and Windows, an SDK and proxy API for production agents, and API integrations and a browser extension for SaaS agents, and it blocks misuse or nudges rogue actions to safer paths inline. Coverage spans local agents such as Claude, Cursor, OpenAI Codex and Google Antigravity, production agents on Amazon Bedrock, GitHub and Google Cloud, and SaaS agents from Anthropic, OpenAI and Gemini, and the Claude Compliance API integration adds read coverage of Claude activity. SourceEvoke Security, evokesecurity.comread 2026-10-06 |
|
| Workflow Orchestration | Not documented |
|
Evoke governs the customer's agents rather than running work of its own, and no agent or buyer built flow is documented. SourceEvoke Security, evokesecurity.comread 2026-10-06 |
|
| Knowledge Grounding & RAG | Partial |
|
Agent Inventory and Governance keeps a live inventory of the customer's agents, MCP servers, Agent Skills and tools with their permissions, and AI-SPM maps toxic tool combinations over it. No retrieval structure an agent queries is documented. SourceEvoke Security, evokesecurity.comread 2026-10-06 |
|
| Human Oversight & Guardrails | Partial |
|
Custom policies block agent misuse, notify the security team and nudge rogue actions to a safer alternative automatically, before anything lands, which are constraints the customer sets on its own agents. No approve or ask step that holds an agent action for a person is documented. SourceEvoke Security, evokesecurity.comread 2026-10-06 |
|
| Security, Identity & Governance | Not documented |
|
For the Evoke console, the site names no attestation, SSO or role model, and Evoke lists a trust center at trust.evokesecurity.com. The product's security features, from blocking to posture management, protect the customer's agents rather than the console itself. SourceEvoke Security, evokesecurity.com; trust.evokesecurity.comread 2026-10-06 |
|
| Observability & Auditability | Full |
|
Agent Detection and Response monitors "every prompt, tool call, and action across endpoint, web, and cloud", capturing prompts, tool calls, actions and sessions for the customer's agents so the buyer can inspect each tool call. A fast prefilter scores every agent action with a confidence score, and deeper, context aware layers judge the actions it flags. SourceEvoke Security, evokesecurity.com and /blogs/a-system-one-prefilter-for-agent-securityread 2026-10-06 |
|
| Memory & State Persistence | Not documented |
|
Beyond the live inventory of agents and their permissions, no memory with a stated scope and lifetime is documented, either for Evoke or for the agents it watches. SourceEvoke Security, evokesecurity.comread 2026-10-06 |
|
| Deployment & Data Residency | Not documented |
|
The endpoint sensor, SDK and proxy and browser extension are how Evoke collects from the customer's agents, and it deploys in minutes through the customer's existing MDM and API integrations, but none of that is where the platform runs. No hosting region or customer environment option is published, and a trust center sits at trust.evokesecurity.com. SourceEvoke Security, evokesecurity.com; trust.evokesecurity.comread 2026-10-06 |
|
| Prebuilt Agents / Templates / Packs | Not documented |
|
Policies are custom, and no prebuilt agents, templates or named policy packs are documented; Evoke sells three modules, Agent Detection and Response, Agent Inventory and Governance, and Agent Security Posture Management. SourceEvoke Security, evokesecurity.comread 2026-10-06 |
|
| Triggers & Channel Coverage | Full |
|
Detection and blocking fire automatically on each prompt, tool call and action of the customer's agents across endpoint, web and cloud, so events start the work without a person, and Evoke promises coverage around the clock. SourceEvoke Security, evokesecurity.comread 2026-10-06 |
|
| Model Flexibility & Routing | Not documented |
|
Evoke governs the models other agents use, and its detection prefilter runs Jev, TypeSafe's System One model, which answers yes or no questions about each action in milliseconds with a confidence score. The models in the deeper detection layers are not named, and no customer choice of model applies. SourceEvoke Security, evokesecurity.com/blogs/a-system-one-prefilter-for-agent-securityread 2026-10-06 |
|
| APIs / SDKs / MCP Extensibility | Partial |
|
An SDK and proxy API for instrumenting production agents are named on the homepage, but no reference, auth scheme or package is published, so outside software has no documented way to call Evoke. SourceEvoke Security, evokesecurity.comread 2026-10-06 |
|
| Testing, Debugging & Optimization | Partial |
|
AI-SPM identifies over permissioned agents, toxic tool combinations and malicious Skills and MCP servers, a configuration assessment of the customer's agents, and no red teaming or scored tests of agent behavior are documented. Evoke's own test of its prefilter on 104,368 real agent tool calls caught 96% of risky calls at a 5.3% combined review load. SourceEvoke Security, evokesecurity.com and /blogs/a-system-one-prefilter-for-agent-securityread 2026-10-06 |
|
| Browser / Computer-use | Not documented |
|
The browser extension monitors SaaS agents, which is where the product runs, not an agent operating a browser, and no computer use by Evoke is documented. SourceEvoke Security, evokesecurity.comread 2026-10-06 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
No public pricing; the site directs buyers to contact Evoke. Pre seed, enterprise sales led with a demo based motion.
not disclosed
Cost watchouts
Inference, not stated by the vendor: broad coverage across local, production and SaaS agents may require deploying the endpoint sensor, the proxy and the browser extension, adding operational overhead.
Variable cost rationale
Inference, not stated by the vendor: coverage likely scales with the number of agents, endpoints and environments monitored; no metered axis is published.
Sales call required
Yes, required for paid access
Free / trial
Demo on request; no public free tier
Lowest paid plan
None public; contact sales
Key ambiguities
Nothing numeric is public; early pre seed stage with bespoke terms.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Evoke Security
The closest documented capability profiles to Evoke Security among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Knostic5.5 / 14Adds documented Workflow Orchestration and Security, Identity & Governance
- Lasso Security7.0 / 14Adds documented Workflow Orchestration and Security, Identity & Governance, among others
- Portal265.5 / 14Adds documented Workflow Orchestration and Security, Identity & Governance
- Clutch Security6.0 / 14Adds documented Workflow Orchestration and Security, Identity & Governance, among others
- Mindgard7.0 / 14Adds documented Workflow Orchestration and Security, Identity & Governance, among others
- Noma Security7.0 / 14Adds documented Workflow Orchestration and Security, Identity & Governance, among others
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded