Noma Security

Independent platform for agent discovery, MCP and tool access control, runtime detection and red teaming.

ToolAI Agent SecurityCloud

Pricing: Not published. noma.security/pricing returns 404; a Microsoft Marketplace listing exists but could not be fetched (403).

Reviewed by the Cyber Vendor Guide editorial team against the public sources cited below · Last reviewed September 2026 · How we review listings

What is Noma Security?

Noma Security is an AI agent security platform made up of four modules: AI-SPM, which discovers agents, MCP servers, skills and models across endpoint, SaaS and homegrown agents and maps each agent's permissions and data access; Agent Access Control, which enforces policies on which MCP servers, skills and tools agents can use, linked to identity provider groups; AI-DR, which detects prompt injection, data exfiltration, scope violations and rogue agents at runtime and can alert, block, mask data or escalate to a human; and AI Red Teaming, which runs multi-turn campaigns whose findings feed AI-DR policies. It covers endpoint agents such as Claude Code and Cursor, homegrown systems on Bedrock, Azure AI Foundry, LangChain and CrewAI, and SaaS platforms including Copilot Studio, Agentforce and ServiceNow, and is available as a runtime guardrail plugin for Kong AI Gateway and LiteLLM through api.noma.security. The company was founded in 2023 by Niv Braun and Alon Tron, states that its headquarters is New York City with product, R&D and research teams in Tel Aviv, and has raised a USD 32 million Series A (announced October 2024) and a USD 100 million Series B led by Evolution Equity Partners (July 2025). It remains independent. Pricing is not published; the trust centre lists SOC 2 Type II, ISO 27001, ISO/IEC 42001 and HIPAA.

Best for: Enterprises that want one independent platform spanning agent posture, MCP and tool permissions, runtime detection and red teaming across SaaS, homegrown and endpoint agents.
Pros
  • Trust centre lists SOC 2 Type II (audited by EY), ISO 27001, ISO/IEC 42001 and HIPAA
  • Independent coverage from SecurityWeek and TechCrunch, plus a PR Newswire funding release
  • Documented third-party gateway integrations at Kong and LiteLLM
Things to check
  • No published pricing, and Kong's docs say API credentials come from a Noma Technical Account Manager, which points to sales-led onboarding
  • Young company (founded 2023) with no public product documentation reachable and no open-source components found

Reported in public reviews and vendor documentation. See sources below.

Key Features

AI-SPM: discovery of agents, MCP servers, skills and models across endpoint, SaaS and homegrown agents
Agent Access Control: policies on which MCP servers, skills and tools agents may use, linked to identity provider groups
AI-DR: runtime detection of prompt injection, data exfiltration, scope violations and rogue agents, with alert, block, mask or escalate actions
AI Red Teaming with multi-turn campaigns, prebuilt scan profiles and compliance presets
Coverage for Copilot Studio, Agentforce, ServiceNow, Bedrock, Azure AI Foundry, LangChain and CrewAI
Runtime guardrail plugins for Kong AI Gateway and LiteLLM using api.noma.security
Monitor and blocking modes in gateway integrations

Do you work at Noma Security? to confirm the details or send us a correction.

Quick Info
PricingNot published. noma.security/pricing returns 404; a Microsoft Marketplace listing exists but could not be fetched (403).
ModelContact sales
Founded2023
CloudYes
Self-HostedNo

Last updated: Sep 8, 2026

Certifications
SOC 2 Type IIISO 27001ISO/IEC 42001HIPAA