Use cases
AI agent security use cases, from firewall to compliance.
One runtime control plane, 70 ways teams deploy it. Pick the stack, industry, or risk you are securing and see exactly how the firewall, permissions, monitoring, and audit trail apply.
Snowflake Cortex agent security
Snowflake built a real guardrail layer for Cortex Agents and turned it on with one account setting. The gap that matters is narrow and specific: an agent inherits the privileges of the person who called it, and no role grant can express whether the action it just proposed should happen.
Learn moreGemini Enterprise security
Gemini Enterprise ships more platform security than most teams switch on. The gap is narrower than the internet suggests, and it sits in one place: deciding whether an agent should be allowed to take the action it just proposed.
Learn moreBedrock AgentCore security
AgentCore gives you microVM isolation, agent identity and Cedar policy on the gateway. What it does not do, in AWS own words, is inspect what a prompt means or constrain how an agent behaves once it is inside.
Learn moreAzure AI Foundry security
Microsoft Foundry, still searched for as Azure AI Foundry, ships more platform security than most teams use. The gap is not the platform. It is the row in Microsoft own responsibility matrix that never moves off your side of the table.
Learn moreOpenRouter security
OpenRouter routes model calls for a very large number of teams, and its security posture is genuinely good. The gap is not in the gateway. It is in what your agent does after the model answers.
Learn moreAI gateway
An AI gateway is the single point every agent request passes through. Make it the place you enforce security: inspect inputs, gate tools, watch actions, and log everything.
Learn moreLLM security
LLM security is not a model setting. It is a runtime control plane that inspects inputs, constrains actions, and records what happened, in front of every LLM app you ship.
Learn moreRAG security
Your RAG pipeline retrieves untrusted documents and feeds them to the model. That is an injection vector. Secure it by inspecting retrieved content before the agent acts on it.
Learn moreMCP server security
MCP lets agents call external tools, and a poisoned tool output can hijack the agent. AgentShield inspects MCP traffic and enforces which servers and tools each agent may use.
Learn moreCoding agents
A coding agent runs commands, edits files, and calls tools with real credentials. Scope what it can touch, gate the dangerous actions, and log every move.
Learn moreCustomer service agents
Support agents read messages from strangers and can issue refunds and touch accounts. Inspect every message, protect customer data, and gate the actions that move money.
Learn moreAI agent governance
Governance is not a document, it is enforcement. AgentShield turns your agent policy into runtime controls and an audit trail that proves the rules were followed.
Learn moreAI compliance
Compliance for agents comes down to one question: can you prove what your agents did and that policy was enforced? AgentShield gives you that evidence by default.
Learn moreGovernment and public sector
A public-sector agent touches citizen data, case records, and systems that sit under NIST, FedRAMP, and OMB oversight. Constrain what it can reach, hold high-impact actions for a person, and record every action for the reviewer.
Learn moreFinancial services
A banking or fintech agent touches accounts, moves money, and sees regulated data. Constrain what it can reach, hold the transactions for a human, and record every action for the examiner.
Learn moreEnterprise agents
Enterprise procurement now asks how your agents are governed and audited. AgentShield is the control plane that lets you answer with evidence and ship.
Learn moreAI firewall
A network firewall filters packets. An AI firewall filters the untrusted text your model reads and the actions it takes. Put one in the request path and prompt injection stops before it becomes an action.
Learn moreAgentic AI security
Agentic AI is software that decides its own next step and takes it. That autonomy is the value and the risk. Autonomous AI security means constraining what the agent can do, not just what it can say.
Learn moreAI agent monitoring
You cannot secure or debug an agent you cannot see. AI agent monitoring gives you a live view of every action your agents take, plus a permanent record of what they did and why.
Learn moreAI security posture management
AI-SPM tells you what could go wrong across your models, data, and agents. It does not stop an agent mid-action. AgentShield is the runtime half: the control plane that enforces policy while the agent is actually working.
Learn moreAI agent hardening
Hardening a server means closing the ports you do not need. Hardening an agent means closing the actions it does not need. Same idea, different attack surface, and the surface is much larger than most teams assume.
Learn moreAI agent security tools
The AI agent security market is five different product categories wearing one label. Most buying mistakes come from comparing tools that do not actually do the same job. Here is the honest map, including where we are not the answer.
Learn moreAI agent access control
An agent should be able to do its job and nothing else. AgentShield gives each agent a scoped identity and least-privilege permissions, then enforces them on every tool call at runtime.
Learn moreAI agent identity
An agent that shares a service account is an identity you cannot govern. AgentShield gives each agent its own identity, ties every action to it, and enforces what that identity is allowed to do at runtime.
Learn moreAI data leak prevention
An agent that can read your data can leak it. AgentShield inspects every tool call and outbound action at the egress boundary, blocks sensitive data from leaving, and records every attempt.
Learn moreHuman in the loop for AI agents
Some agent actions should never happen without a person signing off. AgentShield puts an approval gate on the ones you choose, so a human reviews the action, with full context, before it runs.
Learn moreAI agent sandboxing
A sandbox isolates where an agent runs. It does not decide which tools the agent may call or what data it may send. AgentShield is the action-boundary layer that governs what the agent actually does.
Learn moreAI penetration testing
A point-in-time AI penetration test finds the holes. Runtime enforcement keeps them closed after you change a prompt, swap a model, or add a tool. You need both.
Learn moreAI agent guardrails
Output filtering catches a bad answer. It does nothing when an agent calls the wrong tool or leaks a record through an approved channel. Real agent guardrails cover the action layer too.
Learn moreHealthcare
A healthcare agent touches patient records, scheduling, and billing. Constrain what PHI it can reach, hold clinical and financial actions for a human, and record every access for HIPAA.
Learn moreLegal
A legal agent touches privileged client files and matter data. Wall each agent to the matter it works on, hold high-stakes actions for a lawyer, and record every access.
Learn moreInsurance AI agents
Insurance regulators already expect a written program governing every AI system that touches a regulated decision. Agents that read claims, quote policies, and message insureds fall squarely inside it.
Learn moreMulti-agent system security
Securing each agent separately does not secure the system they form. The risk lives in the handoff: one agent delegating to another, passing context, and inheriting privilege it was never meant to hold.
Learn moreZero trust for AI agents
Zero trust says never trust, always verify. An AI agent breaks that model in a specific way: it holds a legitimate credential and issues requests written by a model that attacker-controlled text may have influenced.
Learn moreAI agent threat modeling
A web-app threat model asks who can reach what. An AI agent threat model has to ask a second question web apps never faced: what happens when the thing making the requests can be talked into making the wrong ones by text it reads mid-task.
Learn moreAI runtime security
Scanning a model before you ship tells you what it might do. Runtime security tells you what it just tried to do, on real data, with real credentials, half a second ago, and whether the answer was no.
Learn moreMCP gateway
Connecting an agent to a third-party MCP server is a trust decision, and most teams make it once, in a config file, and never again. A gateway turns that into a policy you can change, inspect, and prove.
Learn moreLangChain security
LangChain gives an agent reach. Almost nothing in the framework decides whether a particular reach was allowed. That decision has to live somewhere, and by default it lives nowhere.
Learn moreClaude agent security
Anthropic ships more built-in security than any other agent runtime. It is also explicit that the permission system is a gate, not a sandbox, and that it protects one developer on one machine. The same holds for the Claude Agent SDK, which many teams still search for as the Anthropic Agent SDK: its hooks and permission callbacks are the extension points where security guidance applies, and they run inside your process.
Learn moreOpenAI agent security
OpenAI ships real guardrail primitives in the Agents SDK. It also documents, in its own reference, that input guardrails run only for the first agent in a chain. Most teams read past that line.
Learn moreOpenClaw security
OpenClaw runs on your machine with your permissions and, in its own documentation, describes itself as not secure by default. Censys found more than 21,000 instances exposed to the open internet in a single week.
Learn moreHugging Face security
In July 2026 an autonomous AI agent escaped a testing sandbox and broke into Hugging Face production infrastructure. Hugging Face recovered roughly 17,600 attacker actions from its logs.
Learn moreCursor AI security
Two Cursor vulnerabilities scored CVSS 9.8 and needed no click at all. Both started as prompt injection and ended as code running outside the sandbox, with your developer's privileges.
Learn moreN8n security
One n8n remote code execution flaw is on CISA's Known Exploited Vulnerabilities catalog. Another scored a straight 10.0. Both were reachable through the workflow engine itself.
Learn moreCopilot Studio security
Copilot Studio ships real governance controls, and a maker can weaken most of them in three clicks. The gap that matters is between what the platform configures and what an agent actually does at runtime.
Learn moreLiteLLM security
For about 40 minutes on March 24, 2026, the most widely deployed open source LLM proxy shipped an information stealer to PyPI. Roughly 2,500 organizations installed it.
Learn moreGemini CLI security
A CVSS 10.0 flaw let an attacker run commands on a CI host before the Gemini CLI sandbox even started. Then Google cut off every consumer tier and moved everyone to a different CLI.
Learn moreGitHub Copilot security
GitHub ships real Copilot security controls and documents, in its own words, exactly where each one stops. Every documented gap lands on the same three surfaces: agent mode, the coding agent and Copilot CLI.
Learn moreMicrosoft 365 Copilot security
Microsoft publishes strong data commitments for Copilot and, in the same documentation, states the limits of each one. The gap between those two halves is where almost every real Microsoft 365 Copilot security problem lives.
Learn moreKiro security
Kiro is unusually direct about the limits of its own safety features, including one sentence most buyers never reach. Read that sentence before you decide whether Kiro needs anything around it.
Learn moreCodex security
OpenAI ships a real sandbox and a real approval model with Codex. It also published two CVEs in which that sandbox was the thing that broke. Both facts belong in the same evaluation.
Learn moreMicrosoft Agent 365 security
Agent 365 is the most complete agent control plane any platform vendor ships, and most Microsoft-stack teams should buy it. The gap worth understanding before you sign is narrow: coverage depends on which runtime an agent was built in, and the blocking rules are threat-shaped rather than policy-shaped.
Learn moreOpenAI Agent Builder security
Agent Builder goes away on November 30, 2026, and the Agents SDK is a good destination. The part worth planning before December is smaller than a rewrite: controls you configured once on a canvas become code in every service, and nothing in the migration path produces the evidence an auditor asks for.
Learn moreMicrosoft Agent Framework security
Agent Framework 1.0 shipped on April 3, 2026 and put Semantic Kernel and AutoGen into maintenance mode. The safety documentation is unusually honest about what the framework will not do for you, and the tool registration model changed in a way that quietly widens what your model can call.
Learn moreGoogle ADK security
ADK 2.0 went GA for Python on May 19, 2026 and replaced the agent executor with a graph engine. Google documents that custom overrides of the old run methods are now silently ignored, and the human approval feature does not work on the two session services most production teams use.
Learn moreFlowise security
The Flowise repository was archived on August 13, 2026 and version 3.1.4, published on July 29, is the last release that will ever exist. Advisories published after the code freeze name 3.1.4 as affected and list no patched version, because there is nobody left upstream to publish one. If a Flowise migration is already planned, this page covers how to keep the instance safe until it lands.
Learn moreNeMo Agent Toolkit security
NVIDIA NeMo Agent Toolkit 1.9.0, published on September 10, 2026, carries exactly three breaking changes, and all three move the agent control plane: the local code sandbox is gone, memory tools no longer accept a user ID chosen by the model, and identity resolution got stricter. If you run the toolkit in production, the upgrade is also a security review.
Learn moreZendesk AI agents security
Zendesk removes AI agents Essential and legacy functionality on December 10, 2026, and the migration is not automatic. The upgraded experience is more capable: generative procedures, API integrations and custom actions that change data outside Zendesk. That capability is the reason to put a per-action control in front of the systems it can now reach.
Learn moreChatGPT workspace agents security
ChatGPT workspace agents are shared, scheduled and triggerable from Slack or an API, and they act through whichever connection the builder chose. OpenAI ships real controls for this. They stop at the edge of what OpenAI can see, and the custom MCP tools your agents call into your own systems sit on the other side of that edge.
Learn moreAmazon Quick Suite security
Amazon Quick Suite, now branded Amazon Quick, turns chat agents, flows and always-on agents loose on your CRM, ticketing and internal APIs. AWS ships real controls for it, and AWS is also unusually candid about where they stop: unattended workflows run on service credentials, human review is not required by default, and third-party MCP servers are yours to vet.
Learn moreOracle AI Agent Studio security
Oracle AI Agent Studio for Fusion Applications has one of the better security models in enterprise agents: every Fusion call carries the running user's token and Fusion stays the authorization authority. That model covers Fusion. It does not follow an agent out through an MCP tool, an External REST node, a scheduled service account or an inbound email trigger, and Oracle says so in its own guidance.
Learn morePydantic AI security
Pydantic AI gives Python teams typed tools, validated arguments and a clean way to pause a run for approval. Validation is not authorization, though, and Pydantic says so in its own docs. With V2 stable since June 23, 2026 and V1 security fixes promised for only six months after that, most production teams are porting agents right now, which is the moment to decide what enforces the rules around every tool call.
Learn moreMastra AI security
Mastra is the TypeScript agent framework many product teams picked in 2025 and 2026, and it ships real controls: tool approval, processors for prompt injection and PII, and a classifier policy gate. Most of them are opt-in, several default to failing open, and the June 17, 2026 npm compromise showed that the machines building Mastra agents hold exactly the keys an attacker wants. This page maps what Mastra enforces, what it leaves to you, and where a runtime policy layer earns its cost.
Learn moreDify AI security
Dify is the open-source platform thousands of US teams use to ship chatbots, RAG apps and workflows, and since July 2026 it also runs shell-based agents in a Linux sandbox. The platform has patched a lot this year. The gaps that remain sit in defaults, in keys created before an upgrade, and in what happens after an agent decides to act.
Learn moreNotion Custom Agents security
Notion Custom Agents run on schedules, Slack messages, database changes and finished meeting notes, with their own permissions rather than yours. Since Notion 3.7 on September 15, 2026 they can also take action in GitHub and other tools through custom MCP connections and hand work to sub-agents. Notion built real safeguards. The gaps sit in three tool settings and in what the Business plan does not log.
Learn moreZapier MCP security
Zapier MCP lets Claude, ChatGPT, Cursor and your own agents run actions across thousands of apps, and Zapier turns it on by default for every account. Zapier Agents are being migrated into AI by Zapier steps, where the tool approval switch starts off. Since ZapConnect on September 23, 2026, agents can also build, deploy and repair Zaps. Zapier governs which apps an agent can reach. Whether a given write should happen is still yours to decide.
Learn moreGemini Enterprise Agent Platform security
Gemini Enterprise Agent Platform is what Vertex AI became on April 22, 2026, and Agent Engine is now Agent Runtime. Since then Google has shipped a real governance stack: IAM access policies for Agent Gateway went GA on August 31, VPC Service Controls arrived on September 8 for newly created gateways only, and Semantic Governance has been in Preview since June 29. This page maps what that stack decides for you and what it still leaves to you.
Learn moreOpenAI Agents API security
OpenAI released the Agents API in public beta on September 10, 2026, and added computer use on September 29. It puts the Codex harness behind one API: OpenAI runs the session, the orchestration and the sandbox, and your application supplies tools. That changes where security decisions can happen, and three lines in OpenAI's own documentation decide whether your design holds up.
Learn moreClaude Managed Agents security
Claude Managed Agents is Anthropic's hosted agent harness, in beta since April 2026 and enabled by default for every API account. Since September 10 it has a third permission policy, auto, where Anthropic's server decides whether each tool call runs. On October 7 Anthropic tightened web_fetch to cut a data exfiltration path. Both changes tell you where the real security decisions sit, and which ones are still yours.
Learn moreCopilot Cowork security
Microsoft 365 Copilot Cowork has been generally available since June 16, 2026. It sends email, posts in Teams, edits Office files, drives a browser and calls plugin connectors on a user's behalf, on a schedule or when a matching email arrives. At general availability the control that decides who can use it moved, and the approval model stayed personal: the person whose agent wants to act is the person who approves it.
Learn more