Skip to content

Security AI apps

AI security tooling — guardrails, red-teaming, and protection for models, agents, and AI-powered SOCs.

32 apps · researched & kept current by Claude Code

Filter & search these 32 apps
  • View LLM Guard details
    SecurityFREEOSS

    LLM Guard

    Protect AI (Palo Alto Networks)

    Security toolkit that sanitizes and screens LLM prompts and responses.

    LLM Guard is a security toolkit for large language model applications. It runs prompts and model responses through configurable scanners — prompt-injection and jailbreak detection, PII redaction, toxicity and bias checks, and secrets scanning — to sanitize input and validate output before it reaches users. It ships as a Python library you wrap around your own LLM calls, with the scanners running locally.

    Prompt-injection & jailbreak detection
    Python library — you build the integration
    • llm-security
    • prompt-injection
    • guardrails
    • pii-redaction
  • View Reco details
    SecurityPAID

    Reco

    Reco

    Security posture and threat detection for SaaS and AI agents.

    Reco is a SaaS security platform that discovers and secures the apps, identities, and AI agents running across an organization. It maps human and non-human identities, surfaces shadow AI and misconfigurations, and detects threats across 200+ integrated applications. Its AI Agent Security adds visibility and control over autonomous agents like Copilot and Agentforce.

    200+ SaaS app integrations
    Enterprise-only, no public pricing
    • saas-security
    • sspm
    • agent-security
    • identity
  • View Strix details
    SecurityFREEMIUMOpen core

    Strix

    Strix

    Open-source AI agents that pentest your app and prove findings.

    Strix runs autonomous AI agents that behave like real attackers: they execute your code dynamically, explore the app through an HTTP proxy and headless browser, and surface vulnerabilities — then validate each with a working proof-of-concept instead of a static-analysis guess. It runs locally via Docker from the CLI, against a local codebase, a GitHub repo, or a black-box web target, with a hosted cloud version and GitHub Actions integration for CI.

    Open-source (Apache-2.0)
    Requires your own LLM API key
    • pentest
    • security-testing
    • ai-agents
    • vulnerability
    • +2
  • View Tinfoil details
    InferenceFREEMIUMOpen core

    Tinfoil

    Tinfoil

    Verifiably private AI inference inside secure hardware enclaves.

    Tinfoil runs open-weight LLMs inside confidential-computing GPU enclaves so that neither Tinfoil nor the cloud provider can see your prompts or data — and the setup is remotely attestable rather than a policy promise. It offers a private chat, an OpenAI-compatible inference API, and Tinfoil Containers for arbitrary Docker workloads, serving models like GPT-OSS, Llama 3.3, and Kimi K2. The software stack is open source and verifiable.

    Hardware-enforced, verifiable privacy
    Open-weight models only, no GPT-4/Claude
    • confidential-computing
    • privacy
    • inference
    • secure-enclave
    • +1
  • View Credal details
    SecurityPAID

    Credal

    Credal

    The control plane for enterprise AI agents.

    Credal is a platform for building, governing, and deploying enterprise AI agents and MCP servers powered by company data. It syncs and inherits permissions from 50+ source systems, redacts sensitive data, and logs every run for audit, so security and governance are woven into each agent. Teams ship no-code agents to surfaces like Slack, ChatGPT, and Claude while keeping centralized access controls and compliance.

    Inherits permissions from source systems
    Enterprise focus, custom pricing
    • ai-governance
    • enterprise-agents
    • permissions
    • audit
    • +1
  • View Pentera details
    SecurityPAID

    Pentera

    Pentera

    Automated security validation that emulates real attacks to prove exploitable exposures.

    Pentera is an automated security validation platform that safely emulates real-world attacks across internal networks, external attack surfaces, and cloud to show which vulnerabilities are genuinely exploitable. It maps complete attack paths, prioritizes remediation by proven risk, and re-validates after fixes. Its 2026 'Pentera 8' release added Pentera Peer, an agentic AI interface that lets teams direct testing and investigate findings in natural language.

    Proves real exploitability, not just CVE lists
    Enterprise pricing, quote-only
    • security-validation
    • pentesting
    • exposure-management
    • adversarial-testing
  • View Horizon3.ai details
    SecurityPAID

    Horizon3.ai

    Horizon3.ai

    Autonomous pentesting that safely runs real attacks in production to find exploitable risk.

    Horizon3.ai's NodeZero platform runs autonomous, production-safe penetration tests that chain real attacker techniques — credential abuse, misconfigurations, and exploitable CVEs — across internal, external, cloud, and hybrid environments without deploying agents. It shows exactly how an attacker could move and what they would reach, prioritizes fixes by impact, and re-tests to verify remediation. It is sold to enterprises and government as continuous attack-surface validation rather than a once-a-year manual engagement.

    No agents to deploy in your environment
    Enterprise pricing, quote-only
    • pentesting
    • offensive-security
    • attack-surface
    • autonomous-agents
  • View Aikido Security details
    SecurityFREEMIUM

    Aikido Security

    Aikido

    All-in-one AppSec that finds and fixes vulnerabilities across code, cloud, and runtime.

    Aikido Security consolidates the application-security toolchain — SAST, dependency/SCA scanning, secret detection, IaC and container scanning, CSPM, DAST, and API security — into one developer-facing platform. It deduplicates and prioritizes findings by real exploitability to cut alert noise, and its AI AutoFix proposes code changes to remediate issues. It is built for engineering teams that want broad coverage without stitching together separate point tools.

    Consolidates ~10 scanners in one platform
    Larger teams and features need paid plans
    • appsec
    • sast
    • sca
    • cspm
    • +1
  • View Prophet Security details
    SecurityPAID

    Prophet Security

    Prophet Security

    Agentic AI SOC platform that autonomously investigates and responds to alerts.

    Prophet Security's agentic AI SOC platform triages, investigates, and responds to security alerts across endpoint, email, identity, cloud, and DLP sources, mimicking how an expert analyst reasons through an alert. Alongside its AI SOC Analyst it ships a threat hunter that surfaces suspicious patterns and a detection advisor that improves coverage and reduces noise. It connects to existing security tooling through bi-directional integrations spanning the investigation lifecycle.

    Autonomous Tier 1-3 alert investigation
    Demo-led sales, no public pricing
    • soc
    • agentic-ai
    • alert-triage
    • threat-hunting
    • +1
  • View Exaforce details
    SecurityPAID

    Exaforce

    Exaforce

    Agentic SOC platform that detects, triages, investigates, and responds to threats.

    Exaforce runs an agentic security operations center built around AI agents it calls 'Exabots' that detect threats, cut alert noise, investigate incidents, and execute response actions with analyst oversight. It combines large language models with semantic, statistical, and behavioral models, and integrates with 100+ sources spanning SIEMs, cloud, identity, and SaaS. Available as a self-managed platform or a managed detection and response (MDR) service.

    Covers detection through response, not just triage
    Enterprise sales, no public pricing or self-serve
    • soc
    • agentic-ai
    • threat-detection
    • mdr
    • +1
  • View Cranium details
    SecurityPAID

    Cranium

    Cranium

    Enterprise platform for AI security, governance, and trust.

    Cranium helps enterprises see, secure, and govern the AI across their organization by discovering models, datasets, and pipelines and assembling them into an AI Bill of Materials (AI-BOM). It runs automated evaluations and red-teaming to surface unsafe behavior, configuration gaps, and compliance risk, and monitors AI systems in production. The platform targets security, risk, and compliance teams standing up responsible-AI programs.

    Model, dataset, and pipeline discovery
    Enterprise-only; no public pricing
    • ai-security
    • ai-governance
    • ai-bom
    • compliance
    • +1
  • View SPLX details
    SecurityPAID

    SPLX

    Zscaler

    Automated AI red teaming, runtime protection, and governance.

    SPLX is an AI security platform that runs automated red teaming against LLM apps and AI agents, simulating thousands of adversarial attacks — prompt injection, jailbreaks, data leakage — to surface vulnerabilities. It adds AI asset discovery, system-prompt hardening, runtime protection, and governance across the AI lifecycle, plus Agentic Radar, an open-source scanner for agentic workflows. It targets security teams shipping AI to production.

    Automated, continuous red teaming
    Sales-led, no public pricing
    • ai-security
    • red-teaming
    • prompt-injection
    • llm-security
    • +1
  • View Hive details
    VisionPAID

    Hive

    Hive

    Cloud AI APIs for content moderation, search, and generation.

    Hive offers pre-trained deep-learning models delivered as cloud APIs for understanding, moderating, and generating visual, text, and audio content. Its core business is automated content moderation — flagging unsafe imagery, video, text, and audio at platform scale — alongside logo and object detection, AI-generated-content and deepfake detection, and reverse image search. The San Francisco company powers trust-and-safety pipelines for platforms including Reddit, Bluesky, and Midjourney. Models integrate with a few lines of code and run as managed or on-premise deployments.

    Broad pre-trained moderation models
    Enterprise sales, no public pricing
    • content-moderation
    • computer-vision
    • deepfake-detection
    • moderation-api
  • View WitnessAI details
    SecurityPAID

    WitnessAI

    WitnessAI, Inc.

    Security and governance gateway for enterprise AI use.

    WitnessAI is a unified security and governance platform for how an organization uses AI. It sits as a gateway over employee and AI-agent interactions, giving security teams three things: observability into all AI activity (including shadow AI), policy enforcement and governance, and protection against prompt injection, data leakage, and other model-layer threats. Each customer runs in an isolated, single-tenant environment encrypted with their own keys.

    Model-agnostic guardrails across all AI use
    Enterprise sales motion, no public pricing
    • ai-security
    • governance
    • guardrails
    • observability
    • +1
  • View Pillar Security details
    SecurityPAID

    Pillar Security

    Pillar Security

    Discover, govern, and secure the AI agents across your organization.

    Pillar Security is an end-to-end platform for securing enterprise AI — from discovering every AI agent, model, and integration in use to red-teaming them and enforcing runtime guardrails. It maps the AI supply chain across code, SaaS, and endpoints, then layers on governance, data-privacy controls, and compliance mapping. It targets AI-specific risks such as prompt injection, jailbreaks, and data poisoning.

    End-to-end AI lifecycle coverage
    Enterprise sales; no public pricing
    • ai-security
    • guardrails
    • red-teaming
    • ai-governance
    • +1
  • View Mindgard details
    SecurityPAID

    Mindgard

    Mindgard

    Automated AI red teaming and security testing for models and agents.

    Mindgard is an automated AI red-teaming and security-testing platform that runs attacker-aligned tests — prompt injection, jailbreaks, model extraction, agent misuse — against LLM applications, agents, and multimodal models. It discovers AI assets, tests continuously through CI/CD and Burp Suite integrations, and adds runtime guardrails informed by findings. The Lancaster University spinout is SOC 2 Type 2 certified and operates from London and Boston.

    Research-grade attack library
    No public pricing
    • security
    • red-teaming
    • llm-security
    • pentesting
  • View Resemble AI details
    VoiceFREEMIUM

    Resemble AI

    Resemble AI

    Voice cloning, audio watermarking, and deepfake detection in one platform.

    Resemble AI spans both sides of synthetic voice: generating it and policing it. The platform offers voice cloning and text-to-speech built on its Chatterbox models, real-time audio watermarking, and Detect, a multimodal deepfake detector covering audio, image, and video. It deploys in the cloud or fully on-premises for regulated environments.

    Generation + detection in one
    Limited free tier
    • voice-cloning
    • deepfake-detection
    • watermarking
    • tts
    • +1
  • View Dropzone AI details
    SecurityPAID

    Dropzone AI

    Dropzone AI

    AI SOC analysts that autonomously investigate and triage security alerts 24/7.

    Dropzone AI puts autonomous AI analysts inside the security operations center: agents that investigate alerts end-to-end across phishing, endpoint, network, cloud, identity, and insider-threat domains without a human in the critical path. It connects to existing tools like Splunk, CrowdStrike, Microsoft Defender, and AWS Security Hub via API, deploying in about an hour, and reports 300+ deployments including UiPath and Zapier.

    Covers phishing, endpoint, cloud, identity
    Enterprise pricing (from ~$36k/year)
    • soc
    • alert-triage
    • security-operations
    • agentic
  • View Noma Security details
    SecurityPAID

    Noma Security

    Noma Security

    Enterprise platform to discover, govern, and protect AI agents and applications.

    An enterprise AI security platform that inventories every model, agent, MCP server, and data dependency across your stack, scans for misconfigurations and supply-chain risks, red-teams AI applications, and enforces runtime guardrails against prompt injection and rogue agent behavior. Founded in Tel Aviv in 2023, it counts UiPath, Best Buy, and Nielsen among its customers. Enterprise pricing via demo.

    End-to-end posture to runtime
    Demo-gated enterprise pricing
    • ai-security
    • agent-security
    • red-teaming
    • governance
    • +1
  • View Zenity details
    SecurityPAID

    Zenity

    Zenity

    Security and governance for AI agents and copilots.

    Zenity is a security platform for AI agents, copilots, and low-code/no-code apps built across enterprise platforms. It discovers agents in use, applies governance and security guardrails, and continuously monitors for risks and threats — giving security teams observability and runtime protection over autonomous and business-built applications.

    Agent/copilot-specific security posture
    Enterprise-only, no public pricing
    • agent-security
    • governance
    • copilots
    • low-code
  • View XBOW details
    SecurityPAID

    XBOW

    XBOW

    Autonomous AI pentesting that finds and exploit-validates vulnerabilities continuously.

    XBOW is an autonomous offensive security platform that runs AI-driven penetration tests against web applications, validating every finding through real exploitation rather than flagging unconfirmed scanner noise. Founded by Semmle founder and GitHub Copilot creator Oege de Moor, it runs continuously instead of as a point-in-time engagement. Customers include Moderna, Samsung SDS, and Tyler Technologies; it raised a $120M Series C at a $1B+ valuation in 2025.

    Findings validated by real exploitation
    Enterprise sales only, no public pricing
    • pentesting
    • offensive-security
    • appsec
    • autonomous-agents
  • View Pangea details
    SecurityFREEMIUM

    Pangea

    Pangea

    API-based security guardrails for AI apps: prompt injection, PII redaction, and access control.

    Pangea provides composable, API-first security services for AI applications. AI Guard and Prompt Guard defend against prompt injection, sensitive-data disclosure, and malicious content, alongside AI access control and visibility products. Pay-as-you-go with a free monthly balance, integrable via LiteLLM and Portkey.

    Composable, API-first security services
    You wire the guardrails in yourself
    • ai-guardrails
    • prompt-injection
    • pii-redaction
    • api-security
  • View Lakera details
    SecurityFREEMIUM

    Lakera

    Lakera (Check Point)

    Real-time guardrails against prompt injection and jailbreaks for AI apps.

    Lakera Guard sits between users and LLMs as a low-latency security layer, detecting and blocking direct and indirect prompt injection, jailbreaks, and system-prompt extraction across 100+ languages. Its models are trained on adversarial data from Gandalf, Lakera's prompt-injection game. Acquired by Check Point in 2025.

    Detection sharpened by the Gandalf game
    Behavioral detection risks false positives
    • prompt-injection
    • guardrails
    • llm-security
    • jailbreak
  • View Lasso Security details
    SecurityPAID

    Lasso Security

    Lasso Security

    End-to-end GenAI security with red-teaming and runtime guardrails.

    Lasso Security protects every LLM interaction across cloud and on-prem deployments, combining shadow-AI discovery, real-time threat detection, policy enforcement, and red-teaming with thousands of attack types. It deploys via gateway, API, or SDK to secure both internal LLM apps and employee use of third-party chatbots.

    Shadow-AI discovery for third-party use
    Paid, enterprise-oriented
    • llm-security
    • shadow-ai
    • guardrails
    • red-teaming
  • View Snyk details
    SecurityFREEMIUM

    Snyk

    Snyk

    Developer security platform with DeepCode AI for SAST, SCA, and AI-generated fixes.

    Snyk finds and fixes vulnerabilities in code, open-source dependencies, containers, and IaC. Its Snyk Code SAST engine, DeepCode AI, combines symbolic and machine-learning analysis with inter-file data-flow tracing to detect issues and auto-generate fixes. Integrates into IDEs, the CLI, and CI.

    Covers code, deps, containers, IaC
    Per-developer pricing adds up
    • appsec
    • sast
    • deepcode-ai
    • vulnerability-scanning
  • View Prompt Security details
    SecurityPAID

    Prompt Security

    Prompt Security (SentinelOne)

    Runtime security for enterprise GenAI: shadow-AI visibility, data-leak and prompt-injection defense.

    Prompt Security secures both employee use of GenAI tools and homegrown LLM applications, giving organizations visibility into shadow AI, blocking sensitive-data leakage, and preventing prompt injection in real time. Acquired by SentinelOne in 2025 and integrated into its Singularity platform.

    Real-time data-leak prevention
    Enterprise, paid-only pricing
    • genai-security
    • shadow-ai
    • data-leak-prevention
    • prompt-injection
  • View HiddenLayer details
    SecurityPAID

    HiddenLayer

    HiddenLayer

    AI security platform: model scanning, runtime defense, and automated red-teaming.

    HiddenLayer's AISec Platform unifies AI supply-chain security, runtime detection and response, posture management, and automated red-teaming for generative, agentic, and predictive AI. Its Model Scanner inspects model files for malware and integrity issues, while AI Detection & Response monitors prompts and responses with deterministic classifiers.

    Model-file malware/integrity scanning
    Opaque, quote-based enterprise pricing
    • ai-detection-response
    • model-scanning
    • adversarial-ml
    • red-teaming
  • View Protect AI details
    SecurityPAID

    Protect AI

    Protect AI (Palo Alto Networks)

    End-to-end security for ML models, AI apps, and the AI supply chain.

    Protect AI secures the AI/ML lifecycle from model selection through deployment and runtime: model scanning for serialization attacks, AI red teaming, posture management, and runtime protection. It also stewards open-source tools like ModelScan. Acquired by Palo Alto Networks in 2025 and integrated into the Prisma AIRS platform.

    Covers full AI/ML lifecycle
    Enterprise, paid-only
    • mlsecops
    • model-scanning
    • ai-supply-chain
    • red-teaming
  • View Galileo details
    ObservabilityFREEMIUM

    Galileo

    Galileo

    Evaluation and observability for GenAI apps and agents, with inline guardrails.

    A platform for testing, monitoring, and guardrailing LLM and agent applications. It ships 20+ out-of-the-box evals for RAG, agents, and safety, lets teams author custom evaluators, and turns those offline evals into real-time production guardrails powered by its own Luna eval models.

    20+ out-of-the-box evals for RAG and agents
    Pricing tiers gate the production guardrails
    • evaluation
    • observability
    • guardrails
    • agents
  • View Giskard details
    EvalFREEMIUMOpen core

    Giskard

    Giskard

    Open-source evaluation and red-teaming for LLM agents and RAG apps.

    Giskard is an open-source (Apache-2.0) Python library for testing LLMs, RAG pipelines, and ML models — its Scan automatically surfaces hallucinations, prompt injection, bias, and other vulnerabilities, while red-teaming agents run multi-turn adversarial attacks across dozens of probes. The paid Giskard Hub adds team collaboration, continuous testing, and scheduled scans. The team also publishes the open Phare LLM safety benchmark.

    Automatic vulnerability scan
    Python-library learning curve
    • llm-eval
    • red-teaming
    • testing
    • rag
    • +1
  • View Fiddler AI details
    ObservabilityPAID

    Fiddler AI

    Fiddler AI

    AI observability and security platform for LLM apps, agents, and ML models.

    An enterprise platform to monitor, analyze, and safeguard generative AI and ML in production. The Fiddler Trust Service scores prompts and responses for hallucination, toxicity, PII leakage, and prompt-injection, with low-latency guardrails plus real-time alerting and root-cause analysis. Originally an explainable-AI and model-monitoring pioneer, now spanning LLM and agent observability.

    Covers classic ML and LLM monitoring
    Enterprise, sales-quoted pricing
    • llm-observability
    • monitoring
    • guardrails
    • ml-monitoring
  • View Tines details
    AutomationFREEMIUM

    Tines

    Tines

    No-code workflow automation and AI agents for security teams.

    Tines is a no-code platform for building automated workflows that connect security and IT tools. Its Workbench chat and AI agents layer LLM reasoning onto deterministic 'stories,' so teams can automate incident response without writing code. A free Community Edition runs in the cloud; Business and Enterprise plans add self-hosting and governance controls.

    Built for SOC/security incident response
    Niche focus narrows general use
    • workflow-automation
    • security
    • no-code
    • secops