Operant AI
Also known as: Operant, Operant AI, Agent Protector, 3D Runtime Defense, AI Gatekeeper, MCP Gateway, Woodpecker
Runtime AI application defense platform protecting every layer of live cloud and AI applications through discovery, detection, and defense, deployed via single-step Helm inside the customer's own Kubernetes cluster with zero instrumentation. Agent Protector (Feb 2026) adds agentic security: prompt-to-tool-to-memory tracing, intent analysis, continuous runtime re-authorization of tool calls, and memory poisoning protection, integrating with LangGraph, CrewAI, n8n, and the ChatGPT Agents SDK. Also ships AI Gatekeeper, MCP Gateway, and open-source Woodpecker red teaming. The only vendor in six Gartner AI security reports.
Operant AI is a runtime AI application defense platform that protects every layer of live cloud and AI applications, from infrastructure to APIs, through a 3D approach combining discovery, detection, and defense. The platform deploys via a single-step Helm installation inside the customer's Kubernetes environment with zero instrumentation, no eBPF, and no agents, delivering full-stack visibility within minutes. Discovery generates live blueprints of AI workloads, models, and APIs, continuously identifying ghost APIs and shadow data flows across providers including OpenAI, Anthropic, Gemini, Cohere, and Bedrock. Detection targets the OWASP LLM Top 10, including prompt injection, model theft, data poisoning, and sensitive data leakage, monitoring ingress and egress flows for PII, PCI, PHI, and API keys. Defense acts inline: auto-redaction and obfuscation of sensitive data, isolation of suspicious containers and models, and intelligent rate limiting. Agent Protector, launched February 2026, extends the platform to agentic AI with complete tracing from prompts to tools to memory stores, continuous analysis of agent intent and behavior, execution telemetry with activity timelines and tool activity graphs, real-time least-permissioned access controls tailored to each agent and identity with continuous runtime re-authorization of tool calls, and agent memory and context poisoning protection through sandboxing. It integrates with LangGraph, CrewAI, n8n, and the ChatGPT Agents SDK via a low-code framework. The portfolio also includes AI Gatekeeper, MCP Gateway, Endpoint Protector for the AI workforce, and Woodpecker, an open-source red-teaming tool used by teams including Cohere. Operant is the only vendor featured across six Gartner AI security reports and runs an Ecosystem Partnership Program embedding its runtime defense into AI inference platforms. Within the AI-agent-security cluster of independents, Operant is the infrastructure-native entrant: it runs inside the customer's own cluster rather than as a cloud-delivered gateway.
Vendor details
Canonical URL
https://www.operant.ai
Category
Security / SOC agent
Funding status
Independent San Francisco company founded 2020 by Vrajesh Bhavsar (CEO, previously built iPhone security foundations at Apple and founded the ML business unit at ARM), Dr. Priyanka Tembey (CTO), and Ashley Roof; $13.5M total funding including a $10M Series A (Sep 2024) co-led by SineWave Ventures and Felicis, with board members Patricia Muoio (SineWave, former NSA/DoD) and Nancy Wang (Felicis, former AWS Data Protection GM); ~43 employees; the only vendor featured across six Gartner AI security reports including the AI TRiSM Market Guide, API Protection Market Guide, and MCP Gateways Innovation Insight
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Agent Protector integrates with leading agent frameworks including LangGraph, CrewAI, n8n, and the ChatGPT Agents SDK through a low-code security framework with embeddable security primitives. The platform tracks and analyzes all major AI providers and third-party models (OpenAI, Anthropic, Gemini, Cohere, Bedrock) and secures APIs, Kubernetes clusters, and MCP ecosystems, with MCP Gateway and AI Gatekeeper offered as named products and an Ecosystem Partnership Program embedding runtime defense into inference platforms.
Sources & related URLs
Research sources
Capability coverage
9.0 / 14 capabilities · 64%
| Integrations & Tool CallingIntegrates with LangGraph, CrewAI, n8n, and the ChatGPT Agents SDK via a low-code framework; tracks all major AI providers (OpenAI, Anthropic, Gemini, Cohere, Bedrock); secures APIs, Kubernetes, and MCP ecosystems with zero-instrumentation deployment, Operant materials 2026-07-22 | Full |
|---|---|
| Workflow Orchestration3D discovery-detection-defense pipeline runs continuously with automated inline responses (auto-redaction, container isolation, rate limiting), while Agent Protector continuously analyzes agent intent and behavior with runtime re-authorization of every tool call, Operant platform pages and Agent Protector launch 2026-07-22 | Full |
| Knowledge Grounding & RAGGrounds detection on live blueprints of AI workloads, models, and APIs, tool activity graphs showing correlations and dependencies, and discovered agent context and memory usage patterns; not a general knowledge or RAG platform, Operant materials 2026-07-22 | Partial |
| Human Oversight & GuardrailsBuilt-in no-code enforcements and guardrails configured by security teams, with least-permissioned access policies per agent and identity; inline blocking itself runs autonomously, Operant materials 2026-07-22 | Partial |
| Security, Identity & GovernanceSecurity is the product: real-time least-permissioned access controls tailored to each agent and identity with continuous runtime re-authorization, inline DLP for PII, PCI, PHI, and API keys, auto-redaction by default, and identity coverage beyond the firewall, Operant platform and Agent Protector materials 2026-07-22 | Full |
| Observability & AuditabilityComplete tracing from prompts to tools to memory stores, execution telemetry with detailed activity timelines, tool activity graphs, live workload blueprints, and continuous ghost-API and shadow-data-flow discovery, Operant materials 2026-07-22 | Full |
| Memory & State PersistenceTraces agent execution through memory stores, retains execution telemetry with detailed activity timelines, and protects agent memory and context from poisoning via sandboxing, Agent Protector launch materials 2026-07-22 | Partial |
| Deployment & Data ResidencyRuns inside the customer's own environment via single-step Helm deployment into their Kubernetes cluster with zero instrumentation, covering cloud and hybrid environments with private mode operation and inline auto-redaction keeping data private in use, Operant site 2026-07-22 | Full |
| Prebuilt Agents, Templates & PacksProductized modules (3D Runtime Defense, Agent Protector, AI Gatekeeper, MCP Gateway, Endpoint Protector) plus embeddable security primitives and a low-code security framework, Operant materials 2026-07-22 | Partial |
| Triggers & Channel CoverageContinuous real-time discovery and inline runtime enforcement across clusters, clouds, and hybrid environments, with all observability data captured and analyzed in real time for immediate detection and response, Operant platform pages 2026-07-22 | Full |
| Model Flexibility & RoutingNo customer-facing model choice or routing; Operant tracks and secures traffic to third-party models rather than serving or routing them, Operant materials 2026-07-22 | Unable to verify |
| APIs, SDKs & MCP ExtensibilityMCP Gateway as a named product, embeddable security primitives, a low-code framework for agent platforms, partner-program APIs, and the open-source Woodpecker tool, Operant materials 2026-07-22 | Partial |
| Testing, Debugging & OptimizationWoodpecker open-source red-teaming tool enables attack simulation and early vulnerability detection, endorsed by Cohere for testing its North platform; runtime scanning surfaces risks continuously, Operant site testimonials 2026-07-22 | Partial |
| Browser & Computer UseNo browser or computer-use capability documented; Operant operates at the cluster, API, and runtime-traffic layer, Operant materials 2026-07-22 | Unable to verify |
Pricing
Contact sales
scope of clusters, applications, agents, and MCP ecosystems under runtime protection
What is public
The product modules (3D Runtime Defense, Agent Protector, AI Gatekeeper, MCP Gateway, Endpoint Protector), the single-step Helm deployment model, and the open-source Woodpecker red-teaming tool are public; no plans, tiers, or dollar amounts are disclosed.
Variable cost rationale
Cost scales with the footprint under protection: Kubernetes clusters, cloud applications, APIs, agents, and MCP ecosystems secured, growing as an organization's cloud-native and agentic deployments expand.
Sales call required
Yes — required for paid access
Free / trial
Trial available on request; Woodpecker open source
Related vendors
- 7AI — Swarming agentic SOC from the Cybereason founders: sixty plus domain…
- AirMDR — AI-native MDR built around a Virtual Analyst that triages 95% of…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Bionic SOC: a human-AI collaboration platform that automates triage,…
- Assail — Autonomous red teaming platform (Ares) whose AI agents discover,…
- Astelia — AI native exposure management platform from Israeli National Red…