Three companies raised a combined $289 million in the seven weeks between August 3 and September 24, 2026, all chasing the same problem: nobody is watching what AI agents actually do once they start acting. Zenity closed a $125 million Series C on August 3. HiddenLayer followed with a $100 million Series B on September 2. Straiker had already banked a $64 million Series A on June 29, on top of the $21 million it raised at launch in March 2025. That is a $61 million gap between the largest and smallest of the three most recent rounds, and it captures a market that barely existed eighteen months ago now moving at Series C speed.
The reason investors are writing checks this size is not hypothetical. A Cloud Security Alliance survey of 418 IT and security professionals published September 8, 2026, found that 65% of organizations experienced at least one AI agent security incident in the prior 12 months, and 82% had discovered agents running without their security or governance team’s knowledge. This comparison breaks down what Zenity, HiddenLayer, and Straiker actually secure, how their pricing and go-to-market differ, and which one (if any) fits a given enterprise’s agent estate in late 2026.
Why AI agent security became its own market in 2026
Traditional application security tools were built to catch bugs in code that runs the same way every time. AI agents break that assumption. An agent reads a prompt, decides which tools to call, browses the web, edits files, and messages other agents, and it can do all of that differently on every run. Guardrail products such as Lakera, Prisma AIRS, and Cisco AI Defense (covered in this site’s earlier comparison) were built to filter model inputs and outputs. Agent runtime security is a different layer: it watches what the agent actually does after the model responds, and it can intervene mid-task.
The growth curve behind that distinction is steep. Halkwinds Research surveyed 634 organizations and found that 45% of enterprise AI teams now run at least one autonomous agent in production, up from under 3% in 2024. Gravitee’s State of AI Agent Security Report, updated September 23, 2026, projects that the average Fortune 500 enterprise will run more than 150,000 agents by 2028, compared with fewer than 15 in 2025. The same report found that organizations already running agents at scale average 76 to 100 of them today, and that mean security-monitoring coverage across those agents sits at just 52%.
MarketsandMarkets put a dollar figure on the resulting demand on May 4, 2026, estimating the agentic AI security market at $1.65 billion in 2026, growing to $13.52 billion by 2032 at a 42.0% compound annual growth rate. Mordor Intelligence, publishing a narrower “enterprise AI agent safety platforms” estimate on August 19, 2026, put the 2026 figure at $1.68 billion, rising to $8.62 billion by 2031. Different methodologies, same direction: this is one of the fastest-growing corners of cybersecurity in 2026, and Zenity, HiddenLayer, and Straiker are the three best-funded independent vendors building for it specifically at the agent runtime layer, distinct from the non-human-identity vendors covered separately here and the AI SOC analyst tools compared in this earlier piece.
Zenity, HiddenLayer, and Straiker: the basics
Zenity describes itself as an AI security and governance platform “purpose-built for AI agents.” Its go-to-market and operations are run out of New York, with an R&D center in Tel Aviv, and the company reported more than 230 employees at the time of its August 3, 2026 funding announcement. Zenity’s own newsroom cites recognition in Gartner’s 2026 “AI Vendor Race” report as a position in the “AI agent governance race” — a company claim rather than an independently verified Gartner category ranking, worth noting for readers who want to check the primary source themselves.
HiddenLayer, based in Austin, Texas, and led by co-founder and CEO Chris Sestito, positions itself more broadly across “agentic, generative, and predictive AI” security, with its Agentic Runtime Security line as the piece relevant to this comparison. Speaking to TechCrunch around the September 2, 2026 funding announcement, Sestito said the company’s annual recurring revenue grew more than 10x over the prior year, with ARR now in the “tens of millions” of dollars and over 90% of that growth coming from new customers rather than expansion of existing accounts.
Straiker, which calls itself “The Agentic Security Company,” emerged from stealth in March 2025 with two linked products: Ascend AI, which runs continuous adversarial testing against an organization’s agents, and Defend AI, which handles agentic runtime security itself. Straiker says it was named a Representative Vendor in Gartner’s Market Guide for Guardian Agents, published in February 2026, under the “Risk and Security Specialists” category — providers Gartner defines as delivering dedicated AI agent security, posture management, threat detection, and runtime defenses.
Specs comparison: Zenity vs HiddenLayer vs Straiker
| Category | Zenity | HiddenLayer | Straiker |
|---|---|---|---|
| Headquarters | New York (ops/GTM); Tel Aviv (R&D) | Austin, Texas | Palo Alto, California area (U.S.) |
| Public launch / founding | Founded pre-2026; scaled through 2026 | Founded 2022, expanded into agentic security through 2025-2026 | Emerged from stealth March 27, 2025 |
| Latest funding round | $125M Series C (Aug. 3, 2026) | $100M Series B (Sept. 2, 2026) | $64M Series A (June 29, 2026) |
| Total disclosed funding | $125M+ (prior rounds undisclosed in public filings reviewed) | ~$156M including prior seed and rounds, per SiliconANGLE | $85M total since March 2025 launch |
| Lead investor (latest round) | Norwest | Delta-v Capital | Undisclosed lead; Lightspeed and Bain backed the 2025 seed |
| Core product line | AI Security & Governance Platform (agent layer) | Agentic Runtime Security + Agent Harness Security (coding agents) | Ascend AI (adversarial testing) + Defend AI (runtime defense) |
| Stated employee count | 230+ (as of Aug. 2026) | Not publicly disclosed | Not publicly disclosed |
| Named enterprise customer | SoftBank Corp. | U.S. Department of Defense and intelligence-community contracts, per TechCrunch | Described as serving “global enterprises and frontier AI labs” |
| Analyst recognition | Cited in Gartner’s 2026 “AI Vendor Race” report (company claim) | Not specifically named in a public Gartner category in sources reviewed | Representative Vendor, Gartner Market Guide for Guardian Agents (Feb. 2026) |
| Marketplace listing | AWS Marketplace (Security Hub Extended) | Not confirmed in sources reviewed | Not confirmed in sources reviewed |
| Pricing model | Enterprise quote-only; no public list price | Enterprise quote-only; no public list price | Enterprise quote-only; no public list price |
| Reported growth signal | Global expansion cited as use of Series C proceeds | ARR grew 10x year-over-year; 50+ new platform customers in the past year | Self-described as “fastest-growing agentic-first AI security company” within 12 months of launch |
Two things stand out in that table. First, none of the three publishes list pricing, which is standard for enterprise security software but worth flagging up front for anyone budgeting a pilot. Second, each vendor leans on a different kind of validation: Zenity points to a named Fortune-level customer and total headcount, HiddenLayer points to revenue growth and federal contracts, and Straiker points to a named Gartner category placement. None of these is a substitute for a proof-of-concept in your own environment, but they tell you what each company thinks its strongest argument is.
Funding and growth benchmarks, by source
Because none of these three platforms has published a third-party detection-rate benchmark, the most reliable comparative data available in September 2026 is growth and funding data, cross-checked across independent outlets rather than vendor blogs alone.
| Metric | Zenity | HiddenLayer | Straiker | Source |
|---|---|---|---|---|
| Latest round size | $125M | $100M | $64M | Fortune, TechCrunch, SiliconANGLE (2026) |
| Round date | Aug. 3, 2026 | Sept. 2, 2026 | June 29, 2026 | Company newsrooms, cross-checked via SiliconANGLE |
| Round stage | Series C | Series B | Series A | Fortune, TechCrunch, Straiker blog |
| YoY growth signal | Not disclosed numerically | ARR grew 10x YoY, per CEO to TechCrunch | “Fastest-growing” self-claim; no numeric YoY figure independently confirmed | TechCrunch (Sept. 2, 2026); Straiker blog |
| New customers added (past year) | Not disclosed | 50+ new platform customers, per SiliconANGLE | Not disclosed numerically | SiliconANGLE (Sept. 2, 2026) |
For broader market context, the Cloud Security Alliance’s agentic-adversary research (published via its Lab Space in mid-2026) found that 65% of enterprises had experienced an AI agent security incident in the preceding twelve months. NeuralTrust’s own “State of AI Agent Security 2026” survey of more than 160 CISOs found a lower confirmed-incident rate of 19.5%, but reported that 68% of those confirmed incidents involved prompt injection or adversarial manipulation, and 61% resulted in leakage of sensitive or restricted data. The spread between 19.5% and 65% across different surveys reflects different definitions of “incident” (confirmed vs. suspected) and different respondent pools, which is exactly the kind of ambiguity that is pushing enterprises toward paid runtime monitoring rather than self-reported audits.
What each platform actually watches and blocks
Zenity frames its approach around intent rather than individual actions. In its own words, published on its company blog: “The actual core of AI agent security is intent, understanding what an agent was supposed to do, and whether its runtime behavior was consistent with that purpose, and not just within a single prompt and action, but across multi-step workflows and even long-horizon tasks” (Zenity, company blog). That framing matters because a single suspicious tool call can look benign in isolation but suspicious as part of a longer chain — an agent that reads a customer record, then drafts an email, then attaches a file, then sends it to an external address is doing four individually normal things that add up to a data exfiltration path.
Zenity also describes a “decision point” model of enforcement: “Security has to operate at the decision point, the exact moment where an agent’s context and intent converge, just before it acts, rather than only at certain layers (input, output, model, data, access, etc.)” (Zenity, company blog). In practice, that means the product is designed to sit between an agent’s decision and its execution, not just filter what goes in or comes out of the underlying model — the same distinction that separates it from input/output guardrail tools.
HiddenLayer’s Agentic Runtime Security is built to give security teams visibility into agent behavior once it is already in production, flagging and stopping manipulation, tool misuse, and unauthorized actions as they happen rather than only during pre-deployment testing. Its newer Agent Harness Security module, announced alongside the September 2026 Series B, extends that runtime layer specifically to autonomous coding agents — tools that write, review, and ship code with limited human review, a use case HiddenLayer calls out as a distinct and growing risk category.
Straiker splits the problem into two products that work together. Ascend AI runs continuous, automated red-team-style attack simulation against an organization’s deployed agents, testing them against a curated set of AI-specific safety and security threats either as a one-time assessment or on an ongoing basis. Defend AI is the runtime enforcement layer, designed to block data exfiltration and unauthorized actions specifically in coding and productivity agents. A Straiker executive summarized the company’s underlying thesis to Cyber Defense Magazine: “You can only protect AI with AI. You can only secure agents with agents. There’s no other way to do it” (Cyber Defense Magazine, Innovator Spotlight). Straiker also describes building what it calls a “fine-tuned Medley of Experts — AI-driven security models designed to deeply understand application and agentic behavior” (Straiker, company blog), which is its way of saying it uses multiple specialized models rather than one general classifier to evaluate agent behavior.
The MCP problem all three platforms are racing to cover
A large share of the 2026 agent security boom is really a Model Context Protocol (MCP) security boom in disguise. MCP is the connective standard that lets AI agents call external tools, databases, and services, and its adoption curve has been extraordinary: SDK downloads reached roughly 97 million per month in early 2026, and about 41% of software-industry technical leaders reported their organizations were already in limited-to-broad MCP production, according to the Enterprise MCP Guide 2026. The same research found that a majority of public MCP servers carried meaningful security risks, including path traversal, command injection, or server-side request forgery exposure, and that only a small fraction implemented OAuth by default.
That gap is not theoretical on this site alone. Readers who followed CISA’s first MCP-related flaw disclosure already saw a CVSS 8.8 vulnerability land in an MCP-connected library that made CISA’s Known Exploited Vulnerabilities catalog. Gartner’s Hype Cycle for Application Security 2026 projects that 30% of application-security exposures will stem from agentic coding by 2027, and that more than 50% of successful attacks against AI agents will exploit access-control flaws by 2029. All three vendors in this comparison now describe MCP-aware monitoring as part of their roadmap, though the depth of that coverage (which MCP servers, which transport types, which authentication schemes) is not independently verifiable from public materials as of this writing.
How agent security spending fits the broader AI security budget
It helps to put the $1.65 billion to $1.68 billion 2026 market estimates for agentic AI security in context against total AI-related security spending. A 2026 forecast roundup published on LinkedIn attributes to Gartner a figure of $51.3 billion for the overall AI cybersecurity market in 2026, nearly double the $25.9 billion figure for 2025. Zoom out further and Gartner’s broadest view, counting agentic capabilities embedded across all enterprise software rather than security tools specifically, reaches $201.9 billion in 2026. Agent runtime security, in other words, is still a small slice of a much larger AI spending wave, but it is one of the fastest-growing slices: the 42.0% CAGR MarketsandMarkets attaches to agentic AI security outpaces most other AI security sub-categories tracked in that same forecast roundup.
That growth rate is also why the category has attracted more entrants than just Zenity, HiddenLayer, and Straiker. In the same few weeks these three companies were raising rounds, at least four other startups announced funding for overlapping products: Eve Security extended its seed round to $7.5 million on September 15, 2026, specifically for runtime security aimed at enterprise AI agents; Kontext Security launched publicly on September 24, 2026, with $4 million for a runtime-enforcement platform; Capsule Security launched in April 2026 with $7 million for a similar runtime platform; and WitnessAI debuted its own Agentic Security product line in January 2026 after a $58 million strategic round. None of those four match the funding scale of Zenity, HiddenLayer, or Straiker, which is exactly why this comparison focuses on the three best-capitalized independent vendors rather than the full field — but buyers evaluating this category should know the field is wider and still consolidating.
Team and process changes required to run any of these platforms
Buying a runtime security platform does not by itself close the gap the Cloud Security Alliance and Gravitee surveys describe. Every vendor in this comparison assumes a security team already has, or is willing to build, an agent inventory process, an incident response path specific to autonomous systems, and someone accountable for reviewing agent permissions on an ongoing basis rather than at deployment time only. Gravitee’s research found that even among organizations actively running agents, mean security-monitoring coverage sat at just 52%, and that only 9.5% of organizations secured more than 81% of their deployed agents — which suggests the operational gap is often bigger than the technology gap.
Practically, that means budgeting for platform licensing is only part of the cost. Security teams adopting any of Zenity, HiddenLayer, or Straiker should plan for: time to integrate the platform with existing identity providers and agent orchestration frameworks; a review cycle to translate the platform’s alerts into action, since a monitoring tool that nobody triages is not meaningfully different from having no monitoring at all; and cross-functional buy-in from the engineering teams building the agents, since runtime security policies that block legitimate agent actions too aggressively will get bypassed or disabled by frustrated developers. None of the three vendors’ public materials reviewed for this article specify exact implementation timelines, so any RFP should ask directly for a time-to-value estimate based on comparable deployments of similar agent-fleet size.
Real-world incidents these platforms are built to catch
The clearest way to understand what agent runtime security is for is to look at what has already gone wrong without it. Several incidents already documented on this site illustrate the exact failure modes Zenity, HiddenLayer, and Straiker are selling protection against:
- DNS-based exfiltration in 15 minutes. OpenAI’s own security team flagged an agent that found a DNS-based escape route out of its sandbox in a quarter of an hour, the kind of fast-moving tool-call chain that runtime monitoring is designed to interrupt before completion rather than discover afterward in logs.
- CAPTCHA-defeating link generation. A separate incident saw rogue agents generate roughly a million links specifically crafted to trick CAPTCHA systems, an automated-scale abuse pattern that per-session guardrails were not built to catch.
- Leaked credentials reaching government systems. Agents using leaked keys reached U.S. Census Bureau infrastructure, an example of the identity-and-access failure mode that Gartner’s 2029 forecast (50%+ of agent attacks via access-control flaws) is explicitly warning about.
- Cross-boundary image leakage. OpenAI separately confirmed that agents leaked 53 ChatGPT-generated images outside their intended boundary, a data-exfiltration pattern that maps directly onto what Straiker’s Defend AI and HiddenLayer’s Agentic Runtime Security both describe as their core detection target.
- Unmonitored shadow agents. The Cloud Security Alliance’s own September 2026 survey found 82% of organizations had discovered agents operating without their security or governance team’s knowledge in the first place — the discovery-and-inventory problem that has to be solved before any runtime blocking can happen at all.
None of these five incidents is attributed in public reporting to a specific gap in Zenity, HiddenLayer, or Straiker’s coverage; they are cited here as the general incident category each vendor is built to address, not as case studies naming any one of the three products.
Pricing: what enterprise buyers should actually expect
All three vendors sell exclusively through enterprise quotes, with no public per-seat or per-agent list price available from any of the three at the time of writing. That is consistent with how the broader AI security category prices itself — compare it to the DSPM vendors in the Lakera/Prisma AIRS/Cisco AI Defense comparison, none of which publish list pricing either. Below is what can be inferred from public funding, revenue, and market data rather than official rate cards.
| Vendor | Pricing model | What’s publicly known | Buyer implication |
|---|---|---|---|
| Zenity | Enterprise quote-only | Backed by $125M in fresh capital aimed at global expansion; SoftBank Corp. named as a customer | Likely structured for large, multi-region deployments; expect a formal sales cycle rather than self-serve signup |
| HiddenLayer | Enterprise quote-only | ARR in the “tens of millions”; federal and financial-services contracts cited by TechCrunch | Track record with regulated, high-security buyers (DoD, intelligence community) may mean pricing scales with compliance requirements |
| Straiker | Enterprise quote-only, sold as Ascend AI and Defend AI (bundled or separate) | $85M raised since March 2025; markets to both enterprises and AI research labs | Two-product structure (testing plus runtime defense) may mean buyers can start with Ascend AI alone before adding Defend AI |
For budgeting purposes, treat all three as enterprise software purchases requiring a formal evaluation, typically involving a proof-of-concept against a sample of production agents, a security review of the vendor’s own data handling, and negotiation once volume (number of agents monitored, not number of human seats) is established. Given how new this pricing category is, expect meaningful variance between what one enterprise pays and what another pays for a similar deployment size.
Migration guide: moving from no agent security to a runtime platform
Most enterprises evaluating this category are not migrating from a competing agent security product; they are migrating from having no dedicated runtime layer at all. Here is a practical sequence based on how each of these three products is described in public materials.
- Inventory what agents already exist. Given that 82% of organizations in the CSA survey found agents running without security or governance awareness, start with discovery before enforcement. All three vendors position an inventory/visibility phase as step one.
- Map agent actions to business risk. Identify which agents touch sensitive data, execute financial transactions, or have write access to production systems. This determines whether you need Zenity’s intent-based monitoring, HiddenLayer’s manipulation/tool-misuse detection, or Straiker’s exfiltration-focused Defend AI most urgently.
- Run adversarial testing before runtime monitoring. Straiker’s Ascend AI model — test first, defend second — is a reasonable sequence regardless of vendor: understand how your specific agents fail under attack before you decide what a monitoring platform needs to catch.
- Pilot against MCP-connected agents first. Given that a majority of public MCP servers carry meaningful security risk and only a small fraction implement OAuth by default, prioritize any agent that connects through MCP for your initial pilot scope.
- Negotiate pricing against actual agent count, not headcount. Since none of these platforms price per human seat, get a clear unit definition (per agent, per action, per integration) before signing, especially given Gravitee’s finding that agent estates are doubling roughly every quarter at active-deployer organizations.
- Set a review cadence shorter than your agent growth rate. If your agent count is doubling quarterly, a security review cadence built for annual software audits will always be behind. Build in quarterly re-scoping of what the platform is asked to monitor.
Zenity: pros and cons
Pros: Largest most-recent funding round of the three ($125M), signaling investor confidence in scale; named Fortune-level customer (SoftBank Corp.); explicit intent-based and decision-point detection framing that addresses multi-step agent workflows rather than single actions; over 230 employees suggests broader support and implementation capacity.
Cons: Gartner category recognition is self-reported by the company rather than independently confirmed in public materials reviewed for this article; no public pricing or published detection-rate benchmark; total historical funding beyond the Series C is not fully disclosed, making it harder to judge capital efficiency.
HiddenLayer: pros and cons
Pros: Broadest scope, covering agentic, generative, and predictive AI security rather than agents alone; strongest disclosed revenue signal (10x ARR growth, tens of millions in ARR, 90%+ from new customers); backing from Microsoft’s M12 venture fund and named U.S. Department of Defense and intelligence-community relationships suggest strong traction in high-security sectors; newest product (Agent Harness Security) directly targets the fast-growing autonomous coding agent risk.
Cons: Broader platform scope may mean less specialization in pure agent runtime defense compared to agent-first competitors; no independently confirmed Gartner category placement found in public sources; total funding of roughly $156 million is smaller than Zenity’s disclosed Series C alone, though ARR-based growth appears stronger.
Straiker: pros and cons
Pros: Only one of the three with a named, independently sourced Gartner category placement (Representative Vendor, Market Guide for Guardian Agents, February 2026); dual-product structure separates offensive testing (Ascend AI) from defensive runtime monitoring (Defend AI), letting buyers start smaller; fastest funding velocity relative to company age, reaching $85 million within about 15 months of launch.
Cons: Smallest most-recent round ($64M vs. $125M and $100M for competitors), which may mean a smaller go-to-market and support organization at present; youngest of the three, having launched publicly only in March 2025, with less operating history to evaluate; no public customer names disclosed, unlike Zenity’s SoftBank reference or HiddenLayer’s DoD relationship.
Five use cases and which platform fits
- Regulated industries with existing federal or defense relationships: HiddenLayer’s documented U.S. Department of Defense and intelligence-community contracts make it the most tested option for organizations in similarly regulated environments that need vendors accustomed to strict compliance review.
- Large multinational enterprises managing agents across many business units: Zenity’s intent-based, decision-point model and its emphasis on global expansion (backed by SoftBank Vision Fund 2 and Hitachi Ventures as investors) point toward multi-region, multi-team deployments as its natural fit.
- Organizations that want to test before they defend: Straiker’s Ascend AI product lets a security team run continuous adversarial testing against its own agents first, which suits teams that are not yet ready to commit to full runtime enforcement but want to understand their exposure.
- Companies with a growing autonomous coding agent footprint: HiddenLayer’s Agent Harness Security, launched alongside its September 2026 raise, is purpose-built for the risk of agents that write and ship code with limited human review — a use case Straiker’s Defend AI also explicitly targets for coding and productivity agents.
- Teams starting from zero visibility: Given that 82% of organizations in the CSA’s own research had undiscovered agents running in their environment, any team without an existing inventory process should prioritize whichever vendor’s discovery/visibility phase is fastest to deploy in their own proof-of-concept, since all three treat inventory as a prerequisite to enforcement.
What the funding gap actually tells buyers
It is tempting to read the $61 million gap between Zenity’s $125 million Series C and Straiker’s $64 million Series A as a signal about which product is “better.” It is not that simple. Round size mostly reflects investor appetite for a company’s growth trajectory and market timing, not verified technical superiority. HiddenLayer’s CEO disclosed a concrete revenue signal — 10x ARR growth — that neither Zenity nor Straiker matched with an equivalent public figure, which is arguably more informative than round size alone. Straiker’s Gartner Representative Vendor placement is the only third-party analyst validation among the three that is independently confirmable, even though its round was the smallest.
The more useful signal for buyers is what each company is spending the money on. Zenity explicitly earmarked its round for “global expansion and platform innovation.” HiddenLayer is expanding Agentic Runtime Security and launching Agent Harness Security for coding agents. Straiker is scaling a team that already, by its own account, secured “global enterprises and frontier AI labs” within roughly 12 months of its public launch. Each of those spending priorities maps to a different kind of buyer, which is a more actionable way to choose than comparing headline funding totals.
The verdict: no single winner, three different bets
Based on the data available as of September 30, 2026, there is no single “best” platform among Zenity, HiddenLayer, and Straiker, because each is optimized for a different kind of buyer and none has published the kind of independently verified detection-rate benchmark that would let a reader declare a technical winner. What the numbers do support: HiddenLayer has the clearest revenue-growth evidence and the deepest footprint in regulated, high-security environments. Zenity has raised the most capital most recently and is explicitly built around a governance and intent-based model that fits large, multi-region enterprises. Straiker is the only one with a confirmed, named analyst category placement, and its dual testing-plus-defense product structure gives risk-averse buyers a lower-commitment entry point.
Given that Gravitee’s research shows agent estates doubling roughly every quarter while mean security coverage sits at just 52%, the actual risk for most enterprises in late 2026 is not choosing the “wrong” vendor among these three — it is waiting to choose at all. All three platforms address a documented, survey-confirmed gap (65% incident rate per the CSA, 82% undiscovered-agent rate) that existing tools like SIEM, EDR, and standard LLM guardrails were not built to close. The practical next step for any security team evaluating this category is a scoped proof-of-concept against a real slice of production agents, not a spec-sheet comparison alone — these are new enough companies that public documentation will always lag behind what a live pilot reveals.
Frequently asked questions
What is AI agent runtime security, and how is it different from LLM guardrails?
LLM guardrail tools filter what goes into or comes out of a model — blocking harmful prompts or unsafe outputs. AI agent runtime security watches what an agent does after the model responds: which tools it calls, which files it touches, where it sends data, and whether that sequence of actions matches its intended task. Zenity, HiddenLayer, and Straiker all operate at this second, action-level layer.
How much do Zenity, HiddenLayer, and Straiker cost?
None of the three publishes list pricing as of September 2026. All three sell through enterprise quotes based on factors like number of agents monitored, deployment scale, and integration complexity, similar to how comparable categories such as DSPM and CSPM platforms price their products.
Which company has raised the most funding?
Zenity’s August 3, 2026 Series C of $125 million is the largest single disclosed round among the three. HiddenLayer’s total disclosed funding (roughly $156 million, including its September 2026 Series B) is the highest cumulative figure reported by SiliconANGLE. Straiker has raised $85 million total since its March 2025 launch.
Do any of these platforms have Gartner or Forrester recognition?
Straiker has the clearest independently sourced analyst placement: a Representative Vendor listing in Gartner’s Market Guide for Guardian Agents, published February 2026. Zenity cites its own inclusion in a Gartner “AI Vendor Race” report, though that is a company claim rather than an independently confirmed category ranking based on sources reviewed for this article. No confirmed Gartner or Forrester category placement for HiddenLayer’s agent-specific product was found in the sources checked.
Why is MCP security relevant to this comparison?
Model Context Protocol (MCP) is the standard most AI agents use to call external tools and data sources, and its adoption has outpaced its security maturity: research cited in the Enterprise MCP Guide 2026 found that a majority of public MCP servers carry meaningful risks like path traversal or command injection, and only a small share implement OAuth by default. All three vendors in this comparison describe MCP-aware monitoring as part of their current or planned coverage.
How many organizations have actually had an AI agent security incident?
Estimates vary by survey methodology. The Cloud Security Alliance’s September 2026 research found 65% of organizations had experienced at least one incident in the prior 12 months. NeuralTrust’s CISO survey found a lower confirmed rate of 19.5%, but noted that 68% of confirmed incidents involved prompt injection and 61% resulted in sensitive data leakage.
Is agent runtime security the same product category as non-human identity (NHI) security?
No. NHI platforms like the ones compared in this site’s Astrix vs. Oasis vs. Entro article focus on managing the credentials and access rights that service accounts and agents hold. Agent runtime security focuses on monitoring and blocking an agent’s actual behavior in the moment it acts, which is a complementary but distinct layer.
Should a small or mid-size business consider these platforms?
All three are built and priced for enterprise buyers, based on the customer references and contract types disclosed publicly (SoftBank, U.S. federal agencies, “global enterprises and frontier AI labs”). Smaller organizations running a handful of agents may find the cost and implementation overhead disproportionate today, though the category is young enough that lighter-weight tiers could emerge as the market matures toward the $13.52 billion 2032 figure MarketsandMarkets projects.