Comparison · agent governance · Lasso Security

Lasso Security, measured.

Lasso Security inspects every prompt, response and tool call crossing your AI gateway and blocks the dangerous ones inline. This page scores that architecture across 16 capabilities against the same capabilities in Agen.co — with the sources, the scoring ladder, and the three rows Lasso wins all on the page.

The short answer

  • The enforcement is real and it is inline. Policy is evaluated in the request path at the proxy, API or AI gateway layer, with a published figure of under 50ms per classification, and a violation is blocked before it reaches the model. Masking, MCP tool governance and data-loss protection all publish level with us at the top of the scale.
  • The verdict is about the content of a request, not about who sent it. Prompts, responses and tool calls are classified for injection, exfiltration and sensitive data. Nothing in the published material gives an agent an identity object or records a human answerable for one, which is the widest row in the table.
  • Access is decided when a connection is made, not when an action is taken. Role-based permissions control which users and teams can reach which MCP servers; after that, every action inside the session is judged on its content. We judge the action itself against what that person is entitled to, every time.
  • The enforcement point is the path. Kong, Portkey, LiteLLM and Envoy are supported without reconfiguring them, which is genuine depth — and it means an agent acting on a device, in a browser, or straight against a SaaS application has nothing standing in front of it.
  • Three rows go to them. The MCP gateway is published open source under MIT and can be read and self-hosted, the network layer is their architecture and not one we work at, and an automated adversarial testing suite runs 3,000+ payloads in CI/CD — a capability we do not offer, scored a 1 in our own column.
  • Pricing is not published anywhere in the public material, so the unit a buyer is billed per cannot be established before a sales conversation.
The long read

What the verdict is about.

Most comparisons on this site turn on whether a product can stop an agent mid-action. This one does not, because Lasso Security can, and the table prints four level rows saying so. The distinction is narrower and it sits in what the decision is made about: the content of a request that crossed the gateway, or the principal who sent it and what that principal is entitled to right now.


The enforcement is inline, and that is the starting point

It is worth being unambiguous before anything else on this page: this is not a posture product wearing a runtime label. Policy is enforced in the request path at the proxy, API or AI gateway layer. The decision figure is published rather than implied — under 50ms per classification, using an intent model rather than a keyword list. A request that violates policy is blocked before it reaches the model provider, and the calling agent carries on.

Four published rows come out level at the top of the scale as a result: masking and redaction at action time, per-call MCP tool governance, data-loss protection on agent actions, and a complete audit record of what happened. A page that scored those any lower would be wrong on the first row a technical reader checked, and the argument here has to survive all four.

Where Lasso Security is strongest

Three of the sixteen rows go to them outright, plus the four level ones above. They are worth reading as a set, because they follow from the same two decisions: publish the gateway, and meet the traffic where it already flows.

  • A gateway you can readthe MCP gateway is published open source under the MIT licence, installed with a single package manager command and configured through the same file an MCP client already uses. Its plugins cover credential masking across the major cloud providers, Presidio-based detection of personal data, prompt-injection policy and a scanner that refuses low-reputation MCP servers before they load. For a buyer who wants to read the enforcement path rather than take a vendor's word for it, that is a genuine and checkable advantage, and this row goes to them without qualification. We make the opposite bet — a commercial platform with no open core — and both bets are legible to a procurement team.
  • The network layerthis is not a bolt-on for them, it is the architecture. The product attaches to gateway infrastructure already in place — Kong, Portkey, LiteLLM, Envoy — without requiring that gateway to be reconfigured or redeployed, and evaluates traffic as it crosses. We do not enforce at that layer and do not claim to; we govern the action and run alongside whatever holds the network, which is what lets one policy also reach the agents whose traffic never crosses a gateway at all.
  • Adversarial testing before productionan automated red-teaming suite runs a library of over three thousand attack payloads, with new variants added weekly, covering prompt injection, multi-turn adversarial sequences, agent-logic corruption and tool-chain exploitation. It runs in CI/CD on every application update with nothing to deploy, and its findings turn into guardrail and system-prompt recommendations. Agen governs agents in production and does not ship an equivalent; that row scores a 1 in our column and it is printed rather than left out.

The request arrives with no human attached

The widest row in the table is the one about whether an agent holds a first-class identity object, and it turns on where the product sits. A decision point in the traffic path sees a request: a prompt, a response, a tool call, a destination. It can classify that request extremely well — that is what the intent model, the detector library and the execution graph are all for. What it does not receive is a principal. Across the platform, gateway and detection documentation, no source describes an identity an agent holds, and none names a person answerable for one.

The nearest thing published is a behavioural baseline per agent and per user, built by observing traffic, and a role-based list of which users and teams may connect to which MCP servers. Both are real and both are useful. A baseline describes what an agent usually does; it is not an attribution of who authorised this particular action. A connect-time permission establishes reach at the start of a session, after which every action inside that session is judged on its content rather than against the entitlement of the person behind it.

That is one architectural fact, so this table charges it once. The identity object row publishes and separates by four; the rows for a unified fabric, a named accountable owner, on-behalf-of delegation and identity-provider compatibility all stayed in the worksheet rather than scoring the same fact five times over. Agen runs humans, machines and agents as primitives on one fabric, on a customer identity foundation seven years in production, which is why entitlement at the moment of the action is a lookup rather than an inference from past behaviour.

Where the enforcement reaches

The decision points are named precisely, which makes this easy to score in both directions: the proxy, the API and the AI gateway. Anything routed through one of those is covered well, and the integration story is unusually low-friction — an existing gateway does not have to be reconfigured or redeployed to gain the controls.

The endpoint and browser rows score on what sits outside that path. There is no device-side control and no browser extension in the published material, so an agent acting locally on a laptop, or a person pasting into a chat interface in a tab, is not somewhere a decision can be made. Discovery reaches considerably further than enforcement does — the inventory connects to CI/CD pipelines, the major cloud AI platforms and third-party agent builders, cataloguing each agent's models, prompts, tools and guardrails — and it scores well. Knowing an agent exists and being able to stop it are different rows, and on this architecture they separate.

This is the ordinary shape of a product built at the network layer, and it is not a criticism of the depth there. It is a boundary a buyer can check against their own agent inventory in an afternoon: count the agents whose traffic does not cross a gateway you control, and that count is the gap.

What is not published

The pricing row publishes on an absence rather than a number. There is no pricing or packaging page in the published URL set, the site navigation carries no pricing entry, and no billing unit, tier or rate appears in the public material. That is a normal enterprise motion and not a criticism, but it means the cost of governing a hundred agents cannot be modelled before a sales conversation, and the row says exactly that. The total-cost row was dropped rather than scored a second time off the same absence.

Two other rows were held. Their new-integration commitment is not published, and scoring an unpublished figure against our own three-day one would measure documentation habits rather than capability. Our own audit-first rollout row stays held pending internal confirmation, which is the sixth comparison in a row it has sat out.

The scored comparison

Sixteen capabilities, scored side by side.

Runtime enforcement, identity and accountability, coverage, and what it costs to operate — each scored 0–5 on capability depth against vendor documentation, including the four rows that come out level and the three Lasso Security wins.

Capability depthNoneCompleteLasso SecurityAgen.co
01 · Runtime enforcement
Verdict rendered at the moment of actionLasso SecurityInline at the gateway, in pathStrong4/5Agen.coPer-action verdicts, <30msComplete5/5
Decision latency, published and measuredLasso Security<50ms per classificationStrong4/5Agen.co<30ms, published, no samplingComplete5/5
Masking or redaction at action timeLasso SecurityPII and secret masking inlineComplete5/5Agen.coMasking at action timeComplete5/5
Adversarial testing that feeds the runtime policyLasso Security3,000+ payloads, runs in CI/CDComplete5/5Agen.coNot a capability we offerBasic1/5
02 · Identity & accountability
Agent has a first-class identity objectLasso SecurityNo agent identity objectBasic1/5Agen.coFirst-class agent identityComplete5/5
Each individual action attributed to that humanLasso SecurityBaselines per agent and userPartial2/5Agen.coAttributed per actionComplete5/5
Access evaluated at action time, not only at grant timeLasso SecurityServer access set at connectPartial2/5Agen.coJudged in context, per actionComplete5/5
Audit record per actionLasso SecurityFull execution-graph traceComplete5/5Agen.coA record per actionComplete5/5
03 · Coverage
Endpoint enforcementLasso SecurityNo endpoint enforcement pointBasic1/5Agen.coAgenShield on the deviceComplete5/5
Browser enforcementLasso SecurityNo browser enforcement pointBasic1/5Agen.coBrowserShield, early accessCapable3/5
Network-layer enforcementLasso SecurityInline at proxy and gatewayComplete5/5Agen.coNot our layer — works alongsidePartial2/5
MCP tool governanceLasso SecurityPer-call MCP inspectionComplete5/5Agen.coMCP tools governed per callComplete5/5
Data-loss protection on agent actionsLasso SecurityMasks and blocks exfiltrationComplete5/5Agen.coLeak blocking at action timeComplete5/5
04 · Operate & buy
Pricing unit — what you are billed perLasso SecurityNo published pricing modelBasic1/5Agen.coPer governed agentComplete5/5
Enforcement gateway published as open sourceLasso SecurityMCP gateway, MIT licensedComplete5/5Agen.coCommercial platform, no open coreBasic1/5
First-party depth inside the productivity suiteLasso SecurityNot a suite-native productBasic1/5Agen.coGoverns the suite, doesn't live in itPartial2/5
9 rows Agen.co leads4 tied3 rows Lasso Security leads
Levels reflect capability depth and supporting evidence. Capability descriptions based on vendor public documentation, September 2026.
What the table says

Both products stop the action. One of them knows whose action it was.

Read the four groups in order and the shape is consistent. Runtime enforcement is level on masking and separates by one on the verdict and the latency figure, both scored 4 for a named caveat rather than a missing capability. Identity is level on the audit record and separates on everything about the principal. Coverage is level on MCP and data loss, goes to them on the network layer, and separates on the device and in the browser. Operate and buy splits three ways.

That is not a gap in feature scope, and this page has not argued that it is. Classifying a request for injection and exfiltration answers whether this content is dangerous. Answering whether this action is permitted means knowing which agent took it, which human it answers to, and what that human is entitled to at that moment — and reaching the action at all means being present where the agent acts, not only where its traffic was routed.

The findings

Four groups, four boundaries.

One per group in the table above, each traceable to the rows beneath it.

01

Inline, in the path, and fast

Policy is enforced at the proxy, API or gateway layer at a published figure of under 50ms per classification, blocking a violation before it reaches the model while the agent carries on. Masking and data-loss protection publish level with us. The caveat on the verdict row is not depth — it is that the decision exists only where traffic is routed through something they sit inside.

decision pointproxy · API · gateway
published latency<50ms per classification
02

A request, classified — not a principal, authorized

The published material describes no identity object an agent holds and no human recorded as answerable for one. What exists is a behavioural baseline per agent and user, built by observation, and a connect-time list of which teams may reach which MCP servers. The audit record is a level row; who the record is about is the widest gap in the table.

agent identity objectnone published
access decidedat connect, not per action
03

Deep in the path, absent beside it

Attaches to Kong, Portkey, LiteLLM and Envoy without reconfiguring them, and governs MCP tool calls per call — both strong rows, one of them level. There is no device-side control and no browser extension, so an agent running locally or a person working in a tab sits outside every decision point. Discovery reaches much further than enforcement does.

enforcement pointsproxy · API · gateway
endpoint and browserno control published
04

Open at the gateway, unpriced at the edge

The MCP gateway is published open source under MIT, readable and self-hostable, which is a real advantage and a row they win outright. What cannot be planned is the bill: no pricing or packaging page exists in the published URL set and no billing unit appears anywhere in the public material.

gateway licenceMIT, open source
published pricing unitnone
Watch it happen

Every action resolved to the human who answers for it.

Not a behavioural baseline inferred from traffic, and not a permission granted when the connection opened — the human and the agent as primitives on one fabric, with every individual action judged against that person's entitlement in the moment it happens, including the agents that run with nobody watching.

agent ownership · live product scene
What closes the gap

Keep the gateway. Add the layer that knows whose request it was.

Nothing about inspecting a request at the gateway conflicts with governing it from a layer that holds identity. Agen adds what content classification cannot carry on its own: a first-class identity for every agent with a named human behind it, every action judged against that person's entitlement as it happens, and enforcement that reaches the device and the browser as well as the path — internal agents and the ones facing your customers, on the same plane.

Select a capability

Continuous discovery across your IdP, gateway, devices, cloud, and registries. Nothing has to self-register: agents are found, risk-scored, and resolved to a named human before they act.

  • Agentless and API-based across five surfaces
  • First-party, custom, and third-party agents alike
  • Every agent mapped to an owner, approver, and escalation
Agen Discover AI agent discovery flow: any identity provider, productivity suites and assistants, cloud, gateway, endpoints, and MCP server registries all feed one agent registry where every AI agent is inventoried, risk-scored on arrival, given a named human owner, and shadow AI is surfaced.
Discovery pulls from five surfaces into a single agent registry — no SDK self-registration required.
ClosesWhich agents are running that nobody registered?
no SDK required5 surfacesowner-mapped
Discover in depth →

Methodology

How these scores were reached.

Sixteen capabilities publish from a worksheet of forty-one scored rows, on one 0–5 ladder applied to both columns. Four rows were dropped rather than guessed: our own audit-first rollout row, held pending internal confirmation; the new-integration commitment and the total platform cost, unpublished on their side, where scoring an absence twice would double-count one gap; and identity-provider compatibility, which would have charged the same architectural fact as the agent identity row a second time. Ties and the three rows Lasso Security wins are printed rather than filtered.

Sources8 primary
Evidence ledger
  1. Lasso Security — AI security platformTier APolicies are enforced inline at the proxy, API or AI gateway layer at under 50ms per classification, using an LLM-as-judge intent model, with a cited 98.6% threat detection accuracy rate. Discovery connects to CI/CD pipelines, cloud platforms including Vertex AI, Bedrock and Salesforce, and third-party agent builder tools, inventorying each agent's models, system prompts, tools and guardrails with continuous updates as the environment changes.
  2. Lasso Security — platform overviewTier AFive pillars are published: discovery and AI-BOM, AI security posture management, automated AI red teaming, runtime enforcement, and AI detection and response. Runtime enforcement blocks violations inline at the proxy, API or gateway layer; detection and response detects and terminates threats with full attack context. Cited figures are sub-50ms intent analysis and 98.6% detection accuracy.
  3. Lasso Security — AI gateway securityTier AConnects to existing AI gateway infrastructure — including Kong, Portkey, LiteLLM and Envoy — without requiring changes to how that gateway is configured or deployed. Enforcement works by analysing the content of prompts, responses and all tool calling, and can mask sensitive data, block a request or trigger an alert without manual intervention.
  4. Lasso Security — MCP securityTier APerforms request and response filtering on all tool calls with real-time threat detection for prompt injection and data exfiltration, and masks sensitive contents before they reach external servers. Responses are configurable as block, alert or sanitize, and untrusted servers are blocked automatically. Role-based permissions control which users and teams can connect to which MCP servers.
  5. Lasso Security — MCP Gateway (open source)Tier AAn MIT-licensed open-source MCP gateway installed with pip and configured through mcp.json or an MCP client's own config file. Plugins cover token and secret masking for Azure, GitHub, GCP, AWS, JWT and Slack credentials, Presidio-based PII detection for cards, emails, phone numbers, national identifiers and IP addresses, Lasso's own prompt-injection and harmful-content policies, xetrack tracing, and a scanner that evaluates server reputation and blocks risky MCP servers before they load.
  6. Lasso Security — automated AI red teamingTier AA library of 3,000+ attack payloads with 500+ new variants added weekly and 50+ evasion techniques, covering prompt injection, multi-turn adversarial sequences, agent-logic corruption, tool-chain exploitation and reconnaissance, mapped to the OWASP LLM and Agentic Top 10. Runs automatically in CI/CD on every application update with zero deployment and no source-code access, and surfaces guardrail recommendations, system prompt fixes and tool permission changes automatically.
  7. Lasso Security — AI detection and responseTier AMonitors every interaction between applications, LLMs, tools and agents — including tool calls, memory reads, RAG retrievals and sub-agent communications — and maps them into an execution graph giving the full sequence of events. Response actions are block or quarantine before execution, alert with full trace context, and terminate across the kill chain. Behavioural baselines are built for every AI agent and user in the environment, and findings stream into the customer's SIEM.
  8. Lasso Security — published URL setTier BNo pricing or packaging page exists in the published URL set: the site navigation carries no pricing entry, and /pricing and /plans both return HTTP 404. No billing unit, tier or rate appears anywhere in the public material. This is the basis for scoring the pricing unit row on an absence rather than a figure.

Vendor capabilities change. If a row is out of date or wrong, tell us and we will re-score it — corrections are published with the date they were made.

FAQ

Questions, answered.

What is Lasso Security?
Lasso Security is a GenAI security platform built around five published pillars: discovery and an AI bill of materials that inventories every agent's models, system prompts, tools and guardrails; AI security posture management for misconfiguration and supply-chain risk; automated red teaming with a library of over three thousand attack payloads; runtime enforcement that applies policy inline at the proxy, API or AI gateway layer; and AI detection and response, which maps interactions between applications, models, tools and sub-agents into an execution graph and can block, alert or terminate. It also publishes an open-source MCP gateway under the MIT licence.
Does Lasso Security enforce policy at runtime, or only observe?
It enforces, and this page scores it that way. Policy is applied inline in the request path at the proxy, API or AI gateway layer, the published decision figure is under 50ms per classification using an intent model rather than pattern matching, and a violating request is blocked before it reaches the model provider while the calling agent keeps running. Responses are configurable as block, alert or sanitize, and sensitive content can be masked before it leaves for an external server. Four published rows on this page — masking, MCP tool governance, data-loss protection and the audit record — come out level with Agen at the top of the scale.
Where does Lasso Security score better than Agen.co?
Three rows of sixteen, and four more are level. The MCP gateway is published open source under the MIT licence and can be read, self-hosted and extended with plugins, which we do not offer. Network-layer enforcement is their architecture rather than a feature — they attach to Kong, Portkey, LiteLLM and Envoy without those gateways being reconfigured — and it is not a layer we work at. And their automated red-teaming suite runs over three thousand adversarial payloads in CI/CD on every application update, a capability Agen does not ship at all; that row scores a 1 in our column and is printed rather than dropped.
How does Lasso Security handle agent identity, and how is that different from Agen.co?
The published material does not describe an identity object that an agent holds. Enforcement decisions are made about the content of a request — a prompt, a response, a tool call — rather than about an authenticated principal that sent it. The closest published equivalents are behavioural baselines built for every AI agent and user by observing traffic, and role-based permissions controlling which users and teams may connect to which MCP servers, established at connect time. Agen takes the other route: humans, machines and agents are primitives on one fabric, on a customer identity foundation in production for seven years, so every action resolves to a named accountable human and is judged against that person's entitlement in the moment.
What surfaces does Lasso Security enforce on?
The named decision points are the proxy, the API and the AI gateway, plus the MCP layer through its own gateway. Anything routed through one of those is covered well, and existing gateway infrastructure does not have to be reconfigured or redeployed to gain the controls. The boundary is what sits outside that path: no device-side control and no browser extension appear in the published material, so an agent acting locally on a laptop, or a person working directly in a browser tab, has no enforcement point in front of it. Discovery reaches further than enforcement — it connects to CI/CD pipelines, the major cloud AI platforms and third-party agent builders — which is why the discovery rows score above the endpoint and browser rows.
Is the Lasso MCP gateway really open source?
Yes, and that row goes to them. The MCP gateway is published under the MIT licence, installed with a single package manager command and configured through the same file an MCP client already uses. Its plugin set covers token and secret masking for Azure, GitHub, GCP, AWS, JWT and Slack credentials, Presidio-based detection of personal data, Lasso's own prompt-injection and harmful-content policies, execution tracing, and a scanner that evaluates server reputation and blocks risky MCP servers before they load. Agen ships no open-source component, which is why that row scores a 1 in our column.
How is Lasso Security priced?
It is not published. There is no pricing or packaging page in the published URL set, the site navigation carries no pricing entry, and no billing unit, tier or rate appears anywhere in the public material. This is a normal enterprise motion, and it is why the pricing unit row on this page scores on an absence rather than a number — a buyer cannot tell from public material what they would be billed per. The total platform cost row was dropped rather than scored a second time off the same absence. Agen is priced per governed agent with no prerequisite tier.
Can Agen.co run alongside Lasso Security?
Yes, and on this pairing that is a straightforward answer. The two products meet at different layers: they inspect the content of traffic crossing a gateway, and we govern the action against the identity that took it. If a team has already put Lasso in front of its MCP servers and AI gateway for prompt-injection and data-exfiltration scanning, Agen adds the half that layer cannot see — a first-class identity for every agent with a named human behind it, every action judged against that person's entitlement in under 30ms, and enforcement on the device, in the browser and against cloud and SaaS applications directly, for internal and customer-facing agents alike. Nothing you already run has to be removed.

See the row that decides it.

Bring the agent you are least comfortable with. We will show you the named human behind every action it takes, judged against what that person is actually entitled to, in a working environment, in under a day.