Back to vendors
N

Noma Security

Also known as: Noma, Noma Security, noma.security, Noma ARM, Noma Agent Access Control, Noma AIDR

Visit site
Security / SOC agentindependentVerified 2026-07-22

Market-leading independent enterprise AI and agent security platform: discovery and posture (AI-SPM), Agent Access Control (tool-level governance of agents and MCP servers), runtime AI Detection and Response across prompts, tool calls, MCP, and agent-to-agent traffic, plus continuous AI Red Teaming. Covers homegrown, SaaS, and developer-machine agents. The leading independent counterpart to Zenity.

Noma is an enterprise AI and agent security platform that secures the full AI lifecycle from models to autonomous agents. It spans four context-sharing products: discovery and posture management (AI-SPM) that scans the environment to inventory every model, agent, MCP server, and data source and build a relationship map; Agent Access Control that governs what each agent and MCP server can access, letting security teams approve, unapprove, or flag individual tools (not just whole systems) and scope policies by tool, agent type, user, team, or environment, checking every MCP connection against a registry the moment it is established; runtime AI Detection and Response (AI-DR) whose proprietary AI security models monitor every prompt, response, tool call, MCP interaction, and agent-to-agent communication in real time and detect, mask, or block threats before they execute; and continuous AI Red Teaming that adversarially tests defenses against prompt injection, jailbreaks, and data leakage. Its Agent Risk Management (ARM) offering combines discovery, posture management, and runtime protection to visualize and control an agent's blast radius, intercepting dangerous tool and permission combinations before deployment. Because each product shares context, discovery and posture inform what an agent connects to, access control defines what it is permitted to do, and that context flows into runtime detection to sharpen every alert. Covering homegrown, SaaS, and developer-machine agents and purpose-built for regulated enterprises, Noma is the leading independent counterpart to Zenity in the AI-agent-security cluster, distinguished by first-class MCP tool-level governance and adversarial red teaming as a native product.

Vendor details

Canonical URL

https://noma.security

Category

Security / SOC agent

Funding status

Independent, well-funded Israeli-founded company (reported to have raised a $100M round); positions itself as the market-leading enterprise AI and agent security platform; CEO and co-founder Niv Braun; award-winning, with traction in regulated industries

Company status

independent

Use cases & customers

Primary use cases

AI agent and MCP server discovery and inventoryagentic access control and tool-level governanceruntime AI detection and response (prompt injection, data leakage)AI security posture management for models and agentscontinuous AI red teaming and adversarial testing

Target customers

enterprise security, data, and MLOps teamsregulated industries adopting AI agentsorganizations running homegrown and SaaS agents at scaleteams governing MCP servers and developer-machine agents

Deployment options

cloud-delivered enterprise platform spanning AWS, Azure, and Databrickscoverage across SaaS agent platforms and developer-machine agents

Integrations

Discovers and secures agents across homegrown applications on AWS Bedrock, Azure AI Foundry, and Databricks; SaaS agent platforms including Microsoft Copilot Studio and Salesforce Agentforce; and prebuilt developer-machine agents like Claude Code, Cursor, and GitHub Copilot. Governs Model Context Protocol (MCP) servers at the individual-tool level and monitors agent-to-agent (A2A) communication, building a dynamic Enterprise Agentic Registry of every agent, MCP server, and tool.

Capability coverage

8.5 / 14 capabilities · 61%

Integrations & Tool CallingDiscovers and secures agents across AWS Bedrock, Azure AI Foundry, Databricks, Copilot Studio, Agentforce, Claude Code, Cursor, and GitHub Copilot, and governs MCP servers at the individual-tool level, Noma PR Newswire and agentic-access-control materials 2026-07-22 Full
Workflow OrchestrationOrchestrates a full-lifecycle AI security workflow across four context-sharing products (discovery/posture, access control, runtime detection and response, red teaming) where each stage informs the next, Noma PR Newswire and platform materials 2026-07-22 Full
Knowledge Grounding & RAGBuilds a dynamic Enterprise Agentic Registry and relationship map cataloging each agent's owner, permissions, connected tools, knowledge sources, and risk context to ground cascading-risk analysis, short of a customer-facing knowledge or retrieval product, Noma agentic-access-control and Help Net Security materials 2026-07-22 Partial
Human Oversight & GuardrailsSecurity teams can approve, unapprove, or flag any agent, MCP, or tool for validation and choose graduated responses (alert, audit, mask, or block) to policy violations, a human-approval-and-guardrail model short of documented step-level runtime approval, Noma agentic-access-control and runtime materials 2026-07-22 Partial
Security, Identity & GovernanceNoma is itself an AI security, identity, and access-governance product: identity and access controls for every agent, action/privacy/compliance policies enforced at runtime, and posture management, purpose-built for regulated enterprises, Noma site and platform materials 2026-07-22 Full
Observability & AuditabilityProvides complete real-time visibility into all AI communications from a single pane of glass with audit logging, plus continuous discovery and inventory, giving first-class observability and auditability, Noma runtime-protection materials 2026-07-22 Full
Memory & State PersistenceMaintains a persistent, continuously current agent and MCP inventory and relationship map from day one, with context flowing between products, a persistent state layer short of a documented agent memory product, Noma PR Newswire materials 2026-07-22 Partial
Deployment & Data ResidencyCloud-delivered with deployment scope spanning AWS, Azure, and Databricks and coverage extending to developer-machine agents, implying multi-environment deployment breadth short of a documented customer self-host or residency guarantee, Noma review and platform materials 2026-07-22 Partial
Prebuilt Agents, Templates & PacksShips four productized capabilities with proprietary AI security models and pre-built security, privacy, and compliance policy types out of the box, a productized starting set short of a customer template library, Noma runtime and platform materials 2026-07-22 Partial
Triggers & Channel CoverageMonitors every AI interaction in real time (prompts, responses, tool calls, MCP server interactions, and agent-to-agent communications) and checks every MCP connection the moment it is established, a broad continuous trigger surface, Noma runtime-protection materials 2026-07-22 Full
Model Flexibility & RoutingNo customer facing model choice or routing; Noma's proprietary AI security models are internal to the product and it secures rather than serves models, Noma materials 2026-07-22 Unable to verify
APIs, SDKs & MCP ExtensibilityCloud-delivered and API-based with native MCP awareness (a registry of MCP servers and tool-level connection checks), an integration and MCP surface short of a documented public SDK for building on Noma, Noma platform materials 2026-07-22 Partial
Testing, Debugging & OptimizationShips continuous AI Red Teaming as a native product, running automated adversarial assessments against prompt injection, jailbreaks, and data leakage to validate defenses, a first-class testing capability short of a build-time agent evaluation and optimization suite, Noma site and review materials 2026-07-22 Partial
Browser & Computer UseNo browser or computer use capability; Noma monitors and governs other agents rather than driving a browser or GUI itself, Noma materials 2026-07-22 Unable to verify

Pricing

Contact sales

number of agents secured, MCP servers, integrations, deployment scope

Contact onlyMedium variable cost

What is public

The billing axes are public (number of agents secured, MCP servers covered, integrations enabled, deployment scope) and the platform is sold as a single product rather than per module; no dollar amounts are published.

Variable cost rationale

Cost scales with the number of agents secured, MCP servers covered, integrations, and deployment scope, so it grows as an organization's agent footprint expands.

Sales call required

Yes — required for paid access

Free / trial

Not published

Verified 2026-07-22

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.