Back to vendors
E

Evoke Security

Visit site
Entry priceNo public pricing; the site directs buyers to contact Evoke. Pre seed, enterprise sales led with a demo based motion.Full pricing detail

Detection and response for AI agents that records every prompt, tool call and action of the customer's agents across endpoint, web and cloud, inventories agents, MCP servers and Skills, and blocks or redirects risky actions in real time.

Evoke Security secures what it calls the agentic workforce: the AI agents employees and engineering teams run with access to email, customer data, source code and production systems. It has three modules. Agent Detection and Response monitors every prompt, tool call and action across endpoint, web and cloud, blocks agent misuse and nudges rogue actions to safer paths. Agent Inventory and Governance tracks the agents, MCP servers, Agent Skills and tools in use across the enterprise, with their permissions.

Agent Security Posture Management finds over permissioned agents, toxic tool combinations and malicious Skills and MCP servers. Evoke collects through an endpoint sensor for local agents on Mac and Windows, an SDK and proxy API for production agents in the cloud, and API integrations and a browser extension for SaaS agents, covering Claude, Cursor, OpenAI, Google Antigravity, Amazon Bedrock and others, and in July 2026 it added coverage through Anthropic's Claude Compliance API.

Evoke was founded in 2025 by CEO Jason Rebholz and Jeffrey Chan and raised a four million dollar pre seed in February 2026 led by Crosspoint Capital Partners with Red Cell Partners. Its trust center renders only in a browser, and its pages do not document an attestation, a hosting region or deployment option for the platform, a published SDK reference, or an approval step that holds an agent's action for a person. It fits security teams that need to see and police what employees' and production AI agents actually do, from coding assistants to SaaS agents; buyers who need documented attestations or a self hosted control plane should ask.

Vendor details

Canonical URL

https://www.evokesecurity.com/

Category

Security / SOC agent

Funding status

$4M pre seed (February 2026), led by Crosspoint Capital Partners with Red Cell Partners. Founded 2025.

Company status

independent

Use cases & customers

Primary use cases

AI agent discovery and shadow AI eliminationAI security posture management and threat modelingReal time detection and blocking of rogue agent actionsOver permissioned agent remediation

Target customers

Enterprise security teams and CISOsOrganizations deploying AI agents at scaleRegulated enterprises

Deployment options

Endpoint sensorSDK and proxyBrowser extension

Integrations

An endpoint sensor for local agents on Mac and Windows, an SDK and proxy API for production agents, and API integrations and a browser extension for SaaS agents, covering Claude, Cursor, OpenAI, Google Antigravity and Amazon Bedrock among others; the Claude Compliance API integration (July 2026) adds read access to Claude activity.

In practice

Engineers run Claude Code and Cursor with access to production. Evoke's endpoint sensor records every prompt, tool call and action, and steers an agent away from a destructive command before it runs.

Someone installs an agent Skill from an unknown repository. Evoke flags the malicious Skill and the over permissioned agent using it, and notifies the security team.

Your security lead needs to know which AI agents exist across laptops, cloud and SaaS. Evoke deploys through your MDM in minutes and builds the inventory of agents, MCP servers, Skills and their permissions.

Agentic Index coverage score

5.0 / 14 capabilities · 36%

Integrations & Tool Calling Full

Evoke reaches the customer's agents through an endpoint sensor on Mac and Windows, an SDK and proxy API for production agents, and API integrations and a browser extension for SaaS agents, and it blocks misuse or nudges rogue actions to safer paths inline. Coverage spans local agents such as Claude, Cursor, OpenAI Codex and Google Antigravity, production agents on Amazon Bedrock, GitHub and Google Cloud, and SaaS agents from Anthropic, OpenAI and Gemini, and the Claude Compliance API integration adds read coverage of Claude activity.

SourceEvoke Security, evokesecurity.comread 2026-10-06

Workflow Orchestration Not documented

Evoke governs the customer's agents rather than running work of its own, and no agent or buyer built flow is documented.

SourceEvoke Security, evokesecurity.comread 2026-10-06

Knowledge Grounding & RAG Partial

Agent Inventory and Governance keeps a live inventory of the customer's agents, MCP servers, Agent Skills and tools with their permissions, and AI-SPM maps toxic tool combinations over it. No retrieval structure an agent queries is documented.

SourceEvoke Security, evokesecurity.comread 2026-10-06

Human Oversight & Guardrails Partial

Custom policies block agent misuse, notify the security team and nudge rogue actions to a safer alternative automatically, before anything lands, which are constraints the customer sets on its own agents. No approve or ask step that holds an agent action for a person is documented.

SourceEvoke Security, evokesecurity.comread 2026-10-06

Security, Identity & Governance Not documented

For the Evoke console, the site names no attestation, SSO or role model, and Evoke lists a trust center at trust.evokesecurity.com. The product's security features, from blocking to posture management, protect the customer's agents rather than the console itself.

SourceEvoke Security, evokesecurity.com; trust.evokesecurity.comread 2026-10-06

Observability & Auditability Full

Agent Detection and Response monitors "every prompt, tool call, and action across endpoint, web, and cloud", capturing prompts, tool calls, actions and sessions for the customer's agents so the buyer can inspect each tool call. A fast prefilter scores every agent action with a confidence score, and deeper, context aware layers judge the actions it flags.

SourceEvoke Security, evokesecurity.com and /blogs/a-system-one-prefilter-for-agent-securityread 2026-10-06

Memory & State Persistence Not documented

Beyond the live inventory of agents and their permissions, no memory with a stated scope and lifetime is documented, either for Evoke or for the agents it watches.

SourceEvoke Security, evokesecurity.comread 2026-10-06

Deployment & Data Residency Not documented

The endpoint sensor, SDK and proxy and browser extension are how Evoke collects from the customer's agents, and it deploys in minutes through the customer's existing MDM and API integrations, but none of that is where the platform runs. No hosting region or customer environment option is published, and a trust center sits at trust.evokesecurity.com.

SourceEvoke Security, evokesecurity.com; trust.evokesecurity.comread 2026-10-06

Prebuilt Agents / Templates / Packs Not documented

Policies are custom, and no prebuilt agents, templates or named policy packs are documented; Evoke sells three modules, Agent Detection and Response, Agent Inventory and Governance, and Agent Security Posture Management.

SourceEvoke Security, evokesecurity.comread 2026-10-06

Triggers & Channel Coverage Full

Detection and blocking fire automatically on each prompt, tool call and action of the customer's agents across endpoint, web and cloud, so events start the work without a person, and Evoke promises coverage around the clock.

SourceEvoke Security, evokesecurity.comread 2026-10-06

Model Flexibility & Routing Not documented

Evoke governs the models other agents use, and its detection prefilter runs Jev, TypeSafe's System One model, which answers yes or no questions about each action in milliseconds with a confidence score. The models in the deeper detection layers are not named, and no customer choice of model applies.

SourceEvoke Security, evokesecurity.com/blogs/a-system-one-prefilter-for-agent-securityread 2026-10-06

APIs / SDKs / MCP Extensibility Partial

An SDK and proxy API for instrumenting production agents are named on the homepage, but no reference, auth scheme or package is published, so outside software has no documented way to call Evoke.

SourceEvoke Security, evokesecurity.comread 2026-10-06

Testing, Debugging & Optimization Partial

AI-SPM identifies over permissioned agents, toxic tool combinations and malicious Skills and MCP servers, a configuration assessment of the customer's agents, and no red teaming or scored tests of agent behavior are documented. Evoke's own test of its prefilter on 104,368 real agent tool calls caught 96% of risky calls at a 5.3% combined review load.

SourceEvoke Security, evokesecurity.com and /blogs/a-system-one-prefilter-for-agent-securityread 2026-10-06

Browser / Computer-use Not documented

The browser extension monitors SaaS agents, which is where the product runs, not an agent operating a browser, and no computer use by Evoke is documented.

SourceEvoke Security, evokesecurity.comread 2026-10-06

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Pricing

No public pricing; the site directs buyers to contact Evoke. Pre seed, enterprise sales led with a demo based motion.

not disclosed

Cost watchouts

Inference, not stated by the vendor: broad coverage across local, production and SaaS agents may require deploying the endpoint sensor, the proxy and the browser extension, adding operational overhead.

Variable cost rationale

Inference, not stated by the vendor: coverage likely scales with the number of agents, endpoints and environments monitored; no metered axis is published.

Sales call required

Yes, required for paid access

Free / trial

Demo on request; no public free tier

Lowest paid plan

None public; contact sales

Key ambiguities

Nothing numeric is public; early pre seed stage with bespoke terms.

Agentic Index verified 2026-09-28

Alternatives to Evoke Security

The closest documented capability profiles to Evoke Security among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Knostic5.5 / 14Adds documented Workflow Orchestration and Security, Identity & Governance
  • Lasso Security7.0 / 14Adds documented Workflow Orchestration and Security, Identity & Governance, among others
  • Portal265.5 / 14Adds documented Workflow Orchestration and Security, Identity & Governance
  • Clutch Security6.0 / 14Adds documented Workflow Orchestration and Security, Identity & Governance, among others
  • Mindgard7.0 / 14Adds documented Workflow Orchestration and Security, Identity & Governance, among others
  • Noma Security7.0 / 14Adds documented Workflow Orchestration and Security, Identity & Governance, among others

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.