Noma Security
Also known as: Noma, Noma Security, noma.security, Noma ARM, Noma Agent Access Control, Noma AIDR
Market-leading independent enterprise AI and agent security platform: discovery and posture (AI-SPM), Agent Access Control (tool-level governance of agents and MCP servers), runtime AI Detection and Response across prompts, tool calls, MCP, and agent-to-agent traffic, plus continuous AI Red Teaming. Covers homegrown, SaaS, and developer-machine agents. The leading independent counterpart to Zenity.
Noma is an enterprise AI and agent security platform that secures the full AI lifecycle from models to autonomous agents. It spans four context-sharing products: discovery and posture management (AI-SPM) that scans the environment to inventory every model, agent, MCP server, and data source and build a relationship map; Agent Access Control that governs what each agent and MCP server can access, letting security teams approve, unapprove, or flag individual tools (not just whole systems) and scope policies by tool, agent type, user, team, or environment, checking every MCP connection against a registry the moment it is established; runtime AI Detection and Response (AI-DR) whose proprietary AI security models monitor every prompt, response, tool call, MCP interaction, and agent-to-agent communication in real time and detect, mask, or block threats before they execute; and continuous AI Red Teaming that adversarially tests defenses against prompt injection, jailbreaks, and data leakage. Its Agent Risk Management (ARM) offering combines discovery, posture management, and runtime protection to visualize and control an agent's blast radius, intercepting dangerous tool and permission combinations before deployment. Because each product shares context, discovery and posture inform what an agent connects to, access control defines what it is permitted to do, and that context flows into runtime detection to sharpen every alert. Covering homegrown, SaaS, and developer-machine agents and purpose-built for regulated enterprises, Noma is the leading independent counterpart to Zenity in the AI-agent-security cluster, distinguished by first-class MCP tool-level governance and adversarial red teaming as a native product.
Vendor details
Canonical URL
https://noma.security
Category
Security / SOC agent
Funding status
Independent, well-funded Israeli-founded company (reported to have raised a $100M round); positions itself as the market-leading enterprise AI and agent security platform; CEO and co-founder Niv Braun; award-winning, with traction in regulated industries
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Discovers and secures agents across homegrown applications on AWS Bedrock, Azure AI Foundry, and Databricks; SaaS agent platforms including Microsoft Copilot Studio and Salesforce Agentforce; and prebuilt developer-machine agents like Claude Code, Cursor, and GitHub Copilot. Governs Model Context Protocol (MCP) servers at the individual-tool level and monitors agent-to-agent (A2A) communication, building a dynamic Enterprise Agentic Registry of every agent, MCP server, and tool.
Sources & related URLs
Research sources
Capability coverage
8.5 / 14 capabilities · 61%
| Integrations & Tool CallingDiscovers and secures agents across AWS Bedrock, Azure AI Foundry, Databricks, Copilot Studio, Agentforce, Claude Code, Cursor, and GitHub Copilot, and governs MCP servers at the individual-tool level, Noma PR Newswire and agentic-access-control materials 2026-07-22 | Full |
|---|---|
| Workflow OrchestrationOrchestrates a full-lifecycle AI security workflow across four context-sharing products (discovery/posture, access control, runtime detection and response, red teaming) where each stage informs the next, Noma PR Newswire and platform materials 2026-07-22 | Full |
| Knowledge Grounding & RAGBuilds a dynamic Enterprise Agentic Registry and relationship map cataloging each agent's owner, permissions, connected tools, knowledge sources, and risk context to ground cascading-risk analysis, short of a customer-facing knowledge or retrieval product, Noma agentic-access-control and Help Net Security materials 2026-07-22 | Partial |
| Human Oversight & GuardrailsSecurity teams can approve, unapprove, or flag any agent, MCP, or tool for validation and choose graduated responses (alert, audit, mask, or block) to policy violations, a human-approval-and-guardrail model short of documented step-level runtime approval, Noma agentic-access-control and runtime materials 2026-07-22 | Partial |
| Security, Identity & GovernanceNoma is itself an AI security, identity, and access-governance product: identity and access controls for every agent, action/privacy/compliance policies enforced at runtime, and posture management, purpose-built for regulated enterprises, Noma site and platform materials 2026-07-22 | Full |
| Observability & AuditabilityProvides complete real-time visibility into all AI communications from a single pane of glass with audit logging, plus continuous discovery and inventory, giving first-class observability and auditability, Noma runtime-protection materials 2026-07-22 | Full |
| Memory & State PersistenceMaintains a persistent, continuously current agent and MCP inventory and relationship map from day one, with context flowing between products, a persistent state layer short of a documented agent memory product, Noma PR Newswire materials 2026-07-22 | Partial |
| Deployment & Data ResidencyCloud-delivered with deployment scope spanning AWS, Azure, and Databricks and coverage extending to developer-machine agents, implying multi-environment deployment breadth short of a documented customer self-host or residency guarantee, Noma review and platform materials 2026-07-22 | Partial |
| Prebuilt Agents, Templates & PacksShips four productized capabilities with proprietary AI security models and pre-built security, privacy, and compliance policy types out of the box, a productized starting set short of a customer template library, Noma runtime and platform materials 2026-07-22 | Partial |
| Triggers & Channel CoverageMonitors every AI interaction in real time (prompts, responses, tool calls, MCP server interactions, and agent-to-agent communications) and checks every MCP connection the moment it is established, a broad continuous trigger surface, Noma runtime-protection materials 2026-07-22 | Full |
| Model Flexibility & RoutingNo customer facing model choice or routing; Noma's proprietary AI security models are internal to the product and it secures rather than serves models, Noma materials 2026-07-22 | Unable to verify |
| APIs, SDKs & MCP ExtensibilityCloud-delivered and API-based with native MCP awareness (a registry of MCP servers and tool-level connection checks), an integration and MCP surface short of a documented public SDK for building on Noma, Noma platform materials 2026-07-22 | Partial |
| Testing, Debugging & OptimizationShips continuous AI Red Teaming as a native product, running automated adversarial assessments against prompt injection, jailbreaks, and data leakage to validate defenses, a first-class testing capability short of a build-time agent evaluation and optimization suite, Noma site and review materials 2026-07-22 | Partial |
| Browser & Computer UseNo browser or computer use capability; Noma monitors and governs other agents rather than driving a browser or GUI itself, Noma materials 2026-07-22 | Unable to verify |
Pricing
Contact sales
number of agents secured, MCP servers, integrations, deployment scope
What is public
The billing axes are public (number of agents secured, MCP servers covered, integrations enabled, deployment scope) and the platform is sold as a single product rather than per module; no dollar amounts are published.
Variable cost rationale
Cost scales with the number of agents secured, MCP servers covered, integrations, and deployment scope, so it grows as an organization's agent footprint expands.
Sales call required
Yes — required for paid access
Free / trial
Not published
Related vendors
- 7AI — Swarming agentic SOC from the Cybereason founders: sixty plus domain…
- AirMDR — AI-native MDR built around a Virtual Analyst that triages 95% of…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Bionic SOC: a human-AI collaboration platform that automates triage,…
- Assail — Autonomous red teaming platform (Ares) whose AI agents discover,…
- Astelia — AI native exposure management platform from Israeli National Red…