What Noma Security actually governs.
Noma is a discovery-first product that grew a real enforcement layer, and both halves are strong. The line this page draws is not about whether it enforces — it does — but about what its enforcement is anchored to, and where it can reach.
Four modules over one inventory
The platform is presented as four modules sharing a single picture of the environment, and each is worth scoring separately.
- Posture managementthe front door and the heritage. It scans the environment and builds an inventory of models, agents, MCP servers and data sources, then maps how they connect. Nothing has to enroll and no code changes are required.
- Red teamingautomated adversarial testing of AI systems before they reach production. It is a named module and a separately billed dimension, and it is a capability we do not offer.
- Runtime protectionthe enforcement layer. Responses range from alerting and audit logging, through masking sensitive data, to blocking the request outright, configurable by application, agent profile, risk level or policy type.
- Agentic access controlpolicy-based approval and continuous monitoring applied to what agents are permitted to do, including permissions exercised through MCP.
The conformance claim, and what it proves
Noma is listed at Extended conformance against Autonomous Action Runtime Management, the open runtime-security specification governed by a Cloud Security Alliance working group. Extended is the full set: all nine requirements, including the three optional ones.
That is worth taking seriously, and this page does. It means pre-execution interception, five distinct authorization outcomes, tamper-evident receipts, intent-drift tracking and telemetry export have been reviewed against a published standard rather than asserted in marketing copy. A comparison that treated this product as a monitoring tool would be wrong on the first row and the reader would know it.
So Group 01 in the table below is close. Noma scores a 4 on rendering a verdict at the moment of action, and the single caveat behind that 4 is the same one the architecture implies: interception happens where the action passes through their gateway or an instrumented framework.
Where the identity binding stops
This is the boundary the table is really measuring, and the specification states it plainly. The requirement is that every action receipt is cryptographically bound to an agent identity. Not to a person — to the agent.
For forensics that is a genuine advance, and it is why the audit-record row comes out level at 5. You can prove which agent took an action and that the record has not been altered. What you cannot do from that receipt alone is answer the question a regulator, an incident review or a board actually asks, which is who authorised this.
Agen starts from the other end. An agent is an identity object in the same fabric as the humans and machines around it, carrying a named accountable owner, and each individual action is attributed to that person and judged against their authority in context — not against a role granted at connect time. That is the difference between reconstructing what happened and knowing, at the moment it happens, whether it is allowed.
Where enforcement can reach
Discovery and enforcement have different footprints here, and conflating them is the most common mistake made about this product.
Discovery is agentless and broad: sanctioned workflows and agents an employee stood up alone, MCP deployments included. It is one of the three rows on this page that scores level with us, and it earns that.
Enforcement is narrower. It reaches the action through the gateway or through an SDK in a supported framework. There is no device-level control point and no in-browser enforcement point in the platform documentation, which is where the endpoint and browser rows land. An agent that is discovered but sits on neither path is visible without being governable — and the inventory is what tells you that gap exists.
Internal agents, and the ones facing your customers
The product is built for the AI stack an enterprise runs internally: its models, its pipelines, its employees' assistants. That is the larger market today and it is a reasonable place to build.
Agents that act on behalf of customers sit outside that frame. They need the same per-action verdicts and the same accountable owner, but they resolve to an external identity rather than an employee — which is a customer identity problem before it is an agent problem. Running both on one policy plane is a direct consequence of the seven-year customer-identity foundation underneath Agen, and it is why the external-agent row separates the two products by three points.
What it costs to run
The platform is listed on a twelve-month contract, with usage billed by assets scanned, by millions of tokens scanned, and by red-teaming test. The unit is the volume of the estate being inspected.
That model tracks how much AI you have rather than how many agents you govern, so the bill moves with traffic and inventory growth that governance work has not caused. Agen is licensed per governed agent with no prerequisite tier — which is cleaner on the unit, and is also net-new spend for a buyer who has already bought a platform contract elsewhere. That is why we score a 4 on total platform cost rather than a 5.
Where Noma is strongest
Two of the sixteen rows below go to Noma and three are level — the highest a vendor has scored against us on any comparison we publish. None of them are close calls.
- Protocol-gateway enforcementa control point on the wire that we deliberately do not operate. We govern the action rather than the path to it, and run alongside whatever already sits in that path rather than replacing it.
- Ecosystem and marketplace reacha cloud-marketplace listing and a native integration with the hyperscaler's own security console give them a wider distribution footprint than ours today.
- Adversarial testing before deploymentautomated red teaming of AI systems is a module in their platform and is not something we do at all. If pre-production testing is part of what you are buying, that is a reason to buy it from them.
- Three capabilities scored levelmasking at action time, the tamper-evident per-action audit record, and agentless discovery with no SDK. Complete on both sides, and printed that way.