Lasso Security
Also known as: Lasso, Lasso Security, LLM Guardian, Lasso Intent Deputy, Lasso Federal
GenAI-first, end-to-end AI security platform covering models, agents, and applications through a five-pillar framework: Discover (shadow AI and agent inventory), Assess (posture on what agents can reach and do), Test (automated red teaming with a 3,000+ attack library and multi-turn agentic attacks), Enforce (inline policies at the proxy, API, or AI gateway layer), and Protect (runtime detection and response). Its Intent Security framework, anchored by the Intent Deputy launched in 2026, sets behavioral baselines for agentic AI and covers MCP security. Sub-50ms classifications with a published 98.6% accuracy rate.
Lasso Security is a GenAI-first, end-to-end AI security platform that protects models, agents, and applications across the enterprise. The platform runs a five-pillar lifecycle. Discover autonomously inventories every AI model, agent, and application in the organization, including shadow AI tools employees adopt without IT approval, with platform integrations and CI connections that automatically surface homegrown applications. Assess analyzes security posture by mapping what each agent is exposed to, what actions it can perform, and what sensitive data it can reach. Test runs automated red teaming through offensive AI agents drawing on a library of more than 3,000 attack types and techniques across the OWASP Top 10, including multi-turn agentic attacks tailored to the customer's use case, with purple teaming that auto-updates policies from findings. Enforce applies policies inline at the proxy, API, or AI gateway layer. Protect detects and terminates threats at runtime mapped to MITRE and OWASP, delivering full context on every attack: what happened, which agent was targeted, the impact, and how to resolve it. In 2026 Lasso introduced the Intent Deputy, pioneering what it calls Intent Security for agentic AI: behavioral baselines that monitor not just what agents do but what they intend to do, extending coverage to MCP servers and prompt injection in agent workflows. The platform deploys via Gateway, API, or SDK with one-line integration, feeds SIEM, SOAR, ticketing, and messaging systems, integrates with Cloudflare for network-level protection, and is available in Azure Marketplace. Lasso serves financial services, healthcare, and regulated industries with HIPAA and GDPR compliance support, and formed Lasso Federal LLC for the US public sector. Alongside Noma and Zenity it is one of the remaining independent platforms in an AI security cluster that has consolidated rapidly into incumbents, differentiated by its guardrails-layer speed claims (sub-50ms classifications, a published 570x cost-efficiency claim versus cloud-native guardrails) and its intent-based approach to agent security.
Vendor details
Canonical URL
https://www.lasso.security
Category
Security / SOC agent
Funding status
Independent Tel Aviv company founded 2023 by Elad Schulman (CEO), Ophir Dror (CPO), Lior Ziv (CTO), and Yuval Abadi (COO); reported ~$28M raised from Entree Capital, CyberArk Ventures, Singtel Innov8, and Samsung Next; ~74 employees; Gartner Cool Vendor for AI Security 2024 and representative vendor in the Gartner Market Guide for AI Gateways; Axonius co-founder Dean Sysman joined the board Feb 2026
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Deploys as a Gateway, API, or SDK in front of LLM traffic; integrates with LiteLLM as a guardrail provider, Cloudflare for network-level monitoring and protection, and existing security stacks including SIEM, SOAR, ticketing, and messaging platforms. CI integration auto-discovers homegrown applications; covers employee use of third-party chatbots (ChatGPT, Gemini, Claude) as well as in-house apps and agents, with MCP security coverage through the Intent Security framework.
Sources & related URLs
Capability coverage
8.5 / 14 capabilities · 61%
| Integrations & Tool CallingDeploys as Gateway, API, or SDK with one-line integration; integrates with LiteLLM, Cloudflare, and existing SIEM, SOAR, ticketing, and messaging stacks; CI integration auto-discovers homegrown apps; Azure Marketplace listing, Lasso site and LiteLLM docs 2026-07-22 | Full |
|---|---|
| Workflow OrchestrationOrchestrates a five-pillar security lifecycle (Discover, Assess, Test, Enforce, Protect) where offensive AI agents run 3,000+ attack types with purple teaming that auto-updates enforcement policies from findings, Lasso AI Security Platform page 2026-07-22 | Full |
| Knowledge Grounding & RAGGrounds detections on behavioral baselines (Intent Security framework), an organization-wide AI inventory map, and a 3,000+ attack knowledge library; not a general knowledge or RAG platform, Lasso materials 2026-07-22 | Partial |
| Human Oversight & GuardrailsPolicy-driven governance with tailored per-application policies under security-team control; threats surfaced with full context (what happened, which agent, impact, resolution) for human remediation, Lasso platform pages 2026-07-22 | Partial |
| Security, Identity & GovernanceSecurity is the product: context-based access controls, policy-driven governance, HIPAA and GDPR compliance support for regulated industries, and Lasso Federal LLC for the US public sector, Lasso site and Business Wire 2026-07-22 | Full |
| Observability & AuditabilityAutonomously discovers and monitors all GenAI interactions including shadow AI, builds a unified audit trail, and delivers full per-attack context (what happened, which agent was targeted, impact, remediation), Lasso platform materials 2026-07-22 | Full |
| Memory & State PersistenceMaintains behavioral baselines over time for intent detection, a unified audit trail of all GenAI interactions, and sortable conversation identifiers for session tracking, Lasso materials and LiteLLM docs 2026-07-22 | Partial |
| Deployment & Data ResidencyGateway, API, or SDK deployment options with cloud and on-premise deployments reported by third-party directories and an Azure Marketplace listing; first-party documentation not retrieved, Lasso site and Security Stack directory 2026-07-22 | Partial |
| Prebuilt Agents, Templates & PacksFive productized platform pillars, a prebuilt 3,000+ attack library across the OWASP Top 10, and tailored policy templates per LLM application, Lasso platform pages 2026-07-22 | Partial |
| Triggers & Channel CoverageContinuous autonomous discovery and real-time runtime monitoring across employee chatbot usage, homegrown applications, agents, and MCP interactions, from buildtime (CI, red teaming) through runtime enforcement, Lasso platform materials 2026-07-22 | Full |
| Model Flexibility & RoutingNo customer-facing model choice or routing; Lasso secures traffic to third-party and in-house models and its internal LLM-as-a-judge classifier is not user-configurable, Lasso materials 2026-07-22 | Unable to verify |
| APIs, SDKs & MCP ExtensibilityAPI and SDK deployment paths, LiteLLM guardrail integration, and MCP security coverage through the Intent Security framework, Lasso site and LiteLLM docs 2026-07-22 | Partial |
| Testing, Debugging & OptimizationAutomated red teaming is a first-class pillar: high-agency adversarial testing with 3,000+ attack types, multi-turn agentic attacks tailored to the use case, and purple teaming that auto-updates policies, Lasso AI Security Platform page 2026-07-22 | Partial |
| Browser & Computer UseNo browser or computer-use capability documented; Lasso operates at the traffic, gateway, and policy layer, Lasso materials 2026-07-22 | Unable to verify |
Pricing
Contact sales
scope of models, agents, and applications secured across discovery, testing, and runtime protection
What is public
The five platform pillars (Discover, Assess, Test, Enforce, Protect) and performance claims (sub-50ms classification, 98.6% accuracy, 3,000+ attack library, 570x cost-efficiency vs cloud-native guardrails) are public; no plans, tiers, or dollar amounts are disclosed.
Variable cost rationale
Cost scales with the footprint of AI usage being secured: number of applications and agents behind the gateway, employee GenAI usage monitored, and red-teaming scope, all of which grow as an organization's AI adoption expands.
Sales call required
Yes — required for paid access
Free / trial
Not published
Related vendors
- 7AI — Swarming agentic SOC from the Cybereason founders: sixty plus domain…
- AirMDR — AI-native MDR built around a Virtual Analyst that triages 95% of…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Bionic SOC: a human-AI collaboration platform that automates triage,…
- Assail — Autonomous red teaming platform (Ares) whose AI agents discover,…
- Astelia — AI native exposure management platform from Israeli National Red…