Trent AI
AI security engineer whose four specialist agents scan code, cloud and AI agents, prioritize exploitable risk, open fix pull requests and verify them, reaching developers inside their coding tools through a hosted MCP server and plugin.
Trent AI is a London based security company founded in 2025. Chief executive Eno Thereska was a distinguished engineer at Alcion, which Veeam acquired, and earlier at AWS and Confluent; chief scientist Neil Lawrence is the DeepMind Professor of Machine Learning at the University of Cambridge and a former director of machine learning at Amazon; and chief technology officer Zhenwen Dai came from machine learning roles at AWS and Spotify. In April 2026 the company emerged from stealth with a thirteen million dollar seed led by LocalGlobe and Cambridge Innovation Capital.
Trent sells an AI security engineer that scans a customer's code, cloud and AI agents, finds exploitable risk, ships fixes and verifies them. Four specialist agents divide the work: a Threat Scanning Agent observes agents, code, infrastructure and dependencies; an Analysis Agent separates signal from noise and prioritizes by business impact; a Remediation Agent patches vulnerabilities, opens pull requests and adjusts configurations; and a Security Posture Agent tracks trends and benchmarks against standards such as SOC 2 and NIST.
Since August 2026 the work is organized as Understand, Plan and Secure, with every finding linked to its evidence and severities that users can challenge and regrade in place. Trent reaches developers inside Claude Code, Codex, Cursor, GitHub Copilot and other coding tools through its hosted MCP server, now delivered as a plugin with US and EU endpoints, and in September 2026 it added read only Security Connectors that pull findings from Semgrep, SARIF tools, Notion and Linear into one judgment.
Trent states it can run in public cloud, the customer's VPC or on premises, with frontier, open source or private models. Organization workspaces carry Admin and Member roles, and a trust center exists but renders only in a browser. Pull requests go through GitHub's own merge gate rather than an approval step inside Trent, and the MCP server's tool list is not published.
Pricing is tailored by segment, from solo builders to regulated enterprises, through a proposal. It fits an engineering or security team that wants security review embedded in its coding tools and repositories across code, cloud and its own agents; a buyer needing a published tool catalog, a named attestation or a long operating record should treat it as early stage.
Vendor details
Canonical URL
https://trent.ai
Category
Security / SOC agent
Subcategory
Security for AI agents
Funding status
Independent, headquartered in London, founded in 2025 by Eno Thereska (CEO, formerly a distinguished engineer at Alcion, AWS, and Confluent), Neil Lawrence (chief scientist, DeepMind Professor of Machine Learning at Cambridge and former Amazon ML director), and Zhenwen Dai (CTO, formerly of AWS and Spotify). Trent emerged from stealth in April 2026 with a thirteen million dollar seed led by LocalGlobe and Cambridge Innovation Capital, with angels including OpenAI's Joaquin Quinonero Candela, AWS director Avinash Bhat, Databricks engineer Ippokratis Pandis, and former Spotify AI leader Tony Jebara. Early design partners include Canopy, Commscentre, ML@Cam, Qbeast, and Weblogic.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Trent connects to repositories through a GitHub App, where its Remediation Agent opens pull requests, takes code uploads and live application URLs, and reaches developers in Claude Code, OpenAI Codex, Cursor, GitHub Copilot, Gemini CLI, Windsurf, Lovable and Claude Desktop through its hosted MCP server, delivered as a plugin, and runs as a skill in OpenClaw. Security Connectors, launched in September 2026, read findings from Semgrep, SARIF compatible scanners, Snyk and Semgrep JSON, Notion and Linear and write nothing back.
In practice
A team ships an AI agent with access to real systems and no security review built for it. Trent's Threat Scanning Agent maps where risk lives across the code, infrastructure and agents, and its Analysis Agent prioritizes what is exploitable.
A repository carries a vulnerability that could let an agent be steered into exfiltrating data. Trent's Remediation Agent opens a fix pull request or hands a ready to run prompt to the developer's coding assistant, then verifies the fix landed.
Security wants to keep pace with builders without slowing them down. Trent runs inside Claude Code, Cursor and other coding tools through its MCP plugin, and its Security Connectors bring existing scanner findings into one prioritized view.
Sources & related URLs
Research sources
Agentic Index coverage score
8.0 / 14 capabilities · 57%
| Integrations & Tool Calling | Partial |
|---|---|
|
The Remediation Agent opens pull requests and adjusts configurations through a GitHub App connection, and fixes can be handed to the customer's coding assistant as a ready to run prompt, but GitHub is the only write connector named; the Security Connectors launched 25 Sep 2026 (Semgrep, Notion, Linear, SARIF tools) are read only, "Trent reads your sources and writes nothing back". Sourcetrent.ai/productread 2026-09-28 |
|
| Workflow Orchestration | Full |
|
Four specialist agents divide the work: a Threat Scanning Agent, an Analysis Agent that classifies signal from noise and prioritizes by business impact, a Remediation Agent and a Security Posture Agent. Sourcetrent.ai/productread 2026-09-28 |
|
| Knowledge Grounding & RAG | Full |
|
Trent builds a context layer over the customer's application code, infrastructure code, configurations, agents and automations, and its Inventory and Architecture Review maps software, services, agents and data flows that later rescans update, a maintained structure the agents reason over; how it is stored is not documented. Sourcetrent.airead 2026-09-28 |
|
| Human Oversight & Guardrails | Partial |
|
Users can challenge and regrade a severity in place, edit draft requirements and make task decisions, in a product pitched as "Built to Be Corrected, Not Blindly Trusted"; fixes arrive as pull requests or prompts for the developer, so the decision stays with the team. The merge gate belongs to GitHub, and no approval step inside Trent that holds an agent action is documented. Sourcetrent.ai/productread 2026-09-28 |
|
| Security, Identity & Governance | Partial |
|
Organization workspaces carry role based access control: Admins manage members and roles, create GitHub App connections and view and revoke any member's API keys, Members run analyses and plan remediation. No attestation is named outside the trust center at trust.trent.ai, which renders only in a browser. Sourcetrent.ai/blog/organization-workspaces-role-based-access-controlread 2026-09-28 |
|
| Observability & Auditability | Partial |
|
Every finding links back to its evidence with an explanation of how Trent graded it, a Report changelog shows what moved after each rescan, and fixes are confirmed with an audit trail, which explains the agents' verdicts; no run trace of the agents' own steps is documented. Posture tracking reports on the customer's estate, not on the agents. Sourcetrent.ai/productread 2026-09-28 |
|
| Memory & State Persistence | Not documented |
|
The scanning agent is described as "learning where to look and reducing noise over time", a learning claim, and the context layer is a knowledge structure rather than memory; no agent memory with a stated scope and lifetime is documented. Sourcetrent.ai/productread 2026-09-28 |
|
| Deployment & Data Residency | Full |
|
"Run Trent wherever your security and compliance posture demands: public cloud, your VPC, or on-prem", named customer environment options, and the hosted MCP service publishes separate US and EU endpoints (mcp.trent.ai and mcp.eu.trent.ai). Sourcetrent.airead 2026-09-28 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
Trent ships four named prebuilt agents with stated jobs, Threat Scanning, Analysis, Remediation and Security Posture, and a plugin for Claude Code and Codex CLI that packages review, threat modeling and remediation tracking skills. Sourcetrent.ai/productread 2026-09-28 |
|
| Triggers & Channel Coverage | Partial |
|
Continuous scanning of code, cloud and agents is claimed and rescans are described, but no event, webhook or schedule that wakes the agents is named, and the plugin and MCP tools run when the developer's assistant calls them. Sourcetrent.ai/productread 2026-09-28 |
|
| Model Flexibility & Routing | Full |
|
The deployment line lets the customer run Trent "with frontier, open-source, or private models", a customer choice that includes the customer's own models; no provider list is published. Sourcetrent.airead 2026-09-28 |
|
| APIs, SDKs & MCP Extensibility | Partial |
|
A hosted MCP server of Trent's own has published endpoints (https://mcp.trent.ai/mcp and https://mcp.eu.trent.ai/mcp) and a published auth scheme (browser sign in, or one API key for remote connection), delivered through an MIT licensed plugin for Claude Code and Codex CLI. Its tools are not listed on any public page, and no REST API or SDK is documented. Sourcegithub.com/trnt-ai/trent-agent-pluginread 2026-09-28 |
|
| Testing, Debugging & Optimization | Not documented |
|
The Remediation Agent validates that fixes work and the Posture Agent benchmarks against standards, which test the customer's code and estate, not Trent's agents; no harness, scored test cases or quality gate for the agents is documented. Sourcetrent.ai/productread 2026-09-28 |
|
| Browser & Computer Use | Not documented |
|
Trent reads repositories, uploaded code and live applications by URL and works through MCP and GitHub; assessing a site by URL is not an agent operating a browser, and no browser or desktop operation is documented. Sourcetrent.ai/integrationsread 2026-09-28 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Version 0.3.0 of Trent's plugin for Claude Code and Codex adds a trent-loop skill. After a scan, the coding agent fixes up to 10 open findings on a new branch, checks each fix with the repo's tests and Trent's security advisor, and opens one pull request. The same release drops the step where a user signed off on the remediation plan before fixes started.
Bears on: Human approval / guardrails
View sourceTrent AI introduced a new interactive experience for its AI Security Engineer, enabling users to review the agent's work incrementally instead of waiting for a complete scan. The update organizes workflows into a three-part structure: Understand, Plan, and Secure. It also allows users to trace findings back to their evidence, follow attack paths, and regrade severities in place.
Bears on: Human approval / guardrails
View sourcePricing
Not public; tailored proposal on request
tailored proposal; basis not disclosed
What is public
A pricing page with no prices. It says pricing is tailored to the team and stack, names three segments (Solo Builders and Startups, Engineering Teams, Enterprise and Regulated Industries) and offers Request Pricing.
Billing mechanics
Proposal based; the pricing page names three segments but no tiers, units or billing period.
Cost watchouts
Inference, not stated by the vendor: scope may grow with the repositories, applications and agents covered.
Variable cost rationale
Inference, not stated by the vendor: with tailored pricing and no published unit, cost likely scales with the code, cloud and agents in scope.
Additional watchouts
Ask how the segments differ and what unit the proposal prices on (repositories, developers or agents), and confirm terms given the company's early stage.
Sales call required
Yes, required for paid access
Free / trial
No free tier or trial published; request pricing
Key ambiguities
No public rate, entry point or scope unit; the three segments on the pricing page carry no prices.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Trent AI
The closest documented capability profiles to Trent AI among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Crogl9.0 / 14Fuller documented coverage on Integrations & Tool Calling and Observability & Auditability
- ThreatModeler10.0 / 14Adds documented Testing, Debugging & Optimization
- Seemplicity8.5 / 14Fuller documented coverage on Integrations & Tool Calling and Triggers & Channel Coverage
- UnderDefense8.5 / 14Fuller documented coverage on Integrations & Tool Calling and Observability & Auditability
- Ghost Security10.0 / 14Fuller documented coverage on Integrations & Tool Calling and Human Oversight & Guardrails
- StrikeReady7.0 / 14Fuller documented coverage on Integrations & Tool Calling and Triggers & Channel Coverage
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded