What the verdict is about.
Most comparisons on this site turn on whether a product can stop an agent mid-action. This one does not, because Lasso Security can, and the table prints four level rows saying so. The distinction is narrower and it sits in what the decision is made about: the content of a request that crossed the gateway, or the principal who sent it and what that principal is entitled to right now.
The enforcement is inline, and that is the starting point
It is worth being unambiguous before anything else on this page: this is not a posture product wearing a runtime label. Policy is enforced in the request path at the proxy, API or AI gateway layer. The decision figure is published rather than implied — under 50ms per classification, using an intent model rather than a keyword list. A request that violates policy is blocked before it reaches the model provider, and the calling agent carries on.
Four published rows come out level at the top of the scale as a result: masking and redaction at action time, per-call MCP tool governance, data-loss protection on agent actions, and a complete audit record of what happened. A page that scored those any lower would be wrong on the first row a technical reader checked, and the argument here has to survive all four.
Where Lasso Security is strongest
Three of the sixteen rows go to them outright, plus the four level ones above. They are worth reading as a set, because they follow from the same two decisions: publish the gateway, and meet the traffic where it already flows.
- A gateway you can readthe MCP gateway is published open source under the MIT licence, installed with a single package manager command and configured through the same file an MCP client already uses. Its plugins cover credential masking across the major cloud providers, Presidio-based detection of personal data, prompt-injection policy and a scanner that refuses low-reputation MCP servers before they load. For a buyer who wants to read the enforcement path rather than take a vendor's word for it, that is a genuine and checkable advantage, and this row goes to them without qualification. We make the opposite bet — a commercial platform with no open core — and both bets are legible to a procurement team.
- The network layerthis is not a bolt-on for them, it is the architecture. The product attaches to gateway infrastructure already in place — Kong, Portkey, LiteLLM, Envoy — without requiring that gateway to be reconfigured or redeployed, and evaluates traffic as it crosses. We do not enforce at that layer and do not claim to; we govern the action and run alongside whatever holds the network, which is what lets one policy also reach the agents whose traffic never crosses a gateway at all.
- Adversarial testing before productionan automated red-teaming suite runs a library of over three thousand attack payloads, with new variants added weekly, covering prompt injection, multi-turn adversarial sequences, agent-logic corruption and tool-chain exploitation. It runs in CI/CD on every application update with nothing to deploy, and its findings turn into guardrail and system-prompt recommendations. Agen governs agents in production and does not ship an equivalent; that row scores a 1 in our column and it is printed rather than left out.
The request arrives with no human attached
The widest row in the table is the one about whether an agent holds a first-class identity object, and it turns on where the product sits. A decision point in the traffic path sees a request: a prompt, a response, a tool call, a destination. It can classify that request extremely well — that is what the intent model, the detector library and the execution graph are all for. What it does not receive is a principal. Across the platform, gateway and detection documentation, no source describes an identity an agent holds, and none names a person answerable for one.
The nearest thing published is a behavioural baseline per agent and per user, built by observing traffic, and a role-based list of which users and teams may connect to which MCP servers. Both are real and both are useful. A baseline describes what an agent usually does; it is not an attribution of who authorised this particular action. A connect-time permission establishes reach at the start of a session, after which every action inside that session is judged on its content rather than against the entitlement of the person behind it.
That is one architectural fact, so this table charges it once. The identity object row publishes and separates by four; the rows for a unified fabric, a named accountable owner, on-behalf-of delegation and identity-provider compatibility all stayed in the worksheet rather than scoring the same fact five times over. Agen runs humans, machines and agents as primitives on one fabric, on a customer identity foundation seven years in production, which is why entitlement at the moment of the action is a lookup rather than an inference from past behaviour.
Where the enforcement reaches
The decision points are named precisely, which makes this easy to score in both directions: the proxy, the API and the AI gateway. Anything routed through one of those is covered well, and the integration story is unusually low-friction — an existing gateway does not have to be reconfigured or redeployed to gain the controls.
The endpoint and browser rows score on what sits outside that path. There is no device-side control and no browser extension in the published material, so an agent acting locally on a laptop, or a person pasting into a chat interface in a tab, is not somewhere a decision can be made. Discovery reaches considerably further than enforcement does — the inventory connects to CI/CD pipelines, the major cloud AI platforms and third-party agent builders, cataloguing each agent's models, prompts, tools and guardrails — and it scores well. Knowing an agent exists and being able to stop it are different rows, and on this architecture they separate.
This is the ordinary shape of a product built at the network layer, and it is not a criticism of the depth there. It is a boundary a buyer can check against their own agent inventory in an afternoon: count the agents whose traffic does not cross a gateway you control, and that count is the gap.
What is not published
The pricing row publishes on an absence rather than a number. There is no pricing or packaging page in the published URL set, the site navigation carries no pricing entry, and no billing unit, tier or rate appears in the public material. That is a normal enterprise motion and not a criticism, but it means the cost of governing a hundred agents cannot be modelled before a sales conversation, and the row says exactly that. The total-cost row was dropped rather than scored a second time off the same absence.
Two other rows were held. Their new-integration commitment is not published, and scoring an unpublished figure against our own three-day one would measure documentation habits rather than capability. Our own audit-first rollout row stays held pending internal confirmation, which is the sixth comparison in a row it has sat out.