Agent security & threat detection

Noma Security Platform

Platform that inventories agents, MCP servers, skills and models across endpoints, SaaS agent builders and homegrown AI stacks, maps each agent's permissions and data access, red teams them before production, and evaluates runtime actions to alert, block, mask data or route to a human. Claims rest on vendor pages.

commercial · generally available · Research snapshot 2026-09-06

Visit the official product source ↗

Where it fits

Agent security & threat detection · Agent discovery & inventory · Evaluation & testing · Runtime authorization & controls

Useful conversation with: CISO, AI security lead, Head of platform security.

Ask for a demonstration

Show me Noma discovering an unapproved MCP server on a developer laptop, mapping its blast radius, and then routing a risky agent action to a human for approval.

Capabilities and evidence

Support labels reflect the supplied research. Documentation and vendor claims are not independent product tests. “Not established” means the researcher did not find support; it does not prove a capability is absent.

Vendor claim

Noma states it discovers every agent, MCP server, skill and model across endpoint, SaaS and homegrown environments and correlates each agent's connections, permissions and data access to surface toxic combinations.

Limit: Discovery mechanisms and platform coverage limits are not documented in reference material.

Source s1 · Source s2

Vendor claim

Runtime protection is described as evaluating each action in context and, based on policy, alerting, blocking, masking data or routing to a human, catching prompt injection, data exfiltration and scope violations.

Limit: Human-approval routing is asserted on a solution page without workflow documentation.

Source s2

Vendor claim

The platform is described as including adversarial testing and red teaming that compound techniques into multi-turn campaigns before agents reach production.

Limit: Testing methodology, coverage and reporting formats are not documented.

Source s1 · Source s2

Limitations to discuss

Sources

  1. Govern and Secure AI Agents Everywhere They Run · Noma Security · official product
    Access date reported by researcher: 2026-09-06
  2. AI Application Security for Bedrock, Azure & Databricks · Noma Security · official product
    Access date reported by researcher: 2026-09-06

Listing does not imply partnership, supplier status, a working DutyGraph integration, or a compliance certification.

Suggest a correction