Comparison · agent governance · Noma Security

Noma Security, measured.

Noma discovers the AI stack and defends it at runtime, with conformance to an open runtime-security standard to back it. This page scores that architecture across 16 capabilities against the same capabilities in Agen.co — with the sources, the scoring ladder, and the rows Noma wins all on the page.

The short answer

  • Noma intercepts agent actions before they execute and can allow, deny, modify, step up or defer them. That is verified against an open standard, not only claimed — and it means this is not a comparison about whether they enforce.
  • Interception happens at their gateway or through an instrumented framework. An agent action that reaches neither has no decision point. Agen governs the action itself, wherever the agent runs.
  • Every action receipt is cryptographically bound to an agent identity. The standard they conform to stops there. Agen resolves each individual action to the named human accountable for it.
  • Discovery is genuinely excellent — sanctioned and employee-deployed agents and MCP servers alike, with no code changes. This row comes out level, and it is one of three that do.
  • Coverage is built for the internal AI stack. There is no device-level or in-browser enforcement point, and customer-facing agents are outside the frame. Agen runs one policy plane across both.
  • Billing is per asset and per million tokens scanned on top of a platform contract. Agen is licensed per governed agent. Noma is ahead of us on marketplace reach and at the protocol-gateway layer.
The long read

What Noma Security actually governs.

Noma is a discovery-first product that grew a real enforcement layer, and both halves are strong. The line this page draws is not about whether it enforces — it does — but about what its enforcement is anchored to, and where it can reach.


Four modules over one inventory

The platform is presented as four modules sharing a single picture of the environment, and each is worth scoring separately.

  • Posture managementthe front door and the heritage. It scans the environment and builds an inventory of models, agents, MCP servers and data sources, then maps how they connect. Nothing has to enroll and no code changes are required.
  • Red teamingautomated adversarial testing of AI systems before they reach production. It is a named module and a separately billed dimension, and it is a capability we do not offer.
  • Runtime protectionthe enforcement layer. Responses range from alerting and audit logging, through masking sensitive data, to blocking the request outright, configurable by application, agent profile, risk level or policy type.
  • Agentic access controlpolicy-based approval and continuous monitoring applied to what agents are permitted to do, including permissions exercised through MCP.

The conformance claim, and what it proves

Noma is listed at Extended conformance against Autonomous Action Runtime Management, the open runtime-security specification governed by a Cloud Security Alliance working group. Extended is the full set: all nine requirements, including the three optional ones.

That is worth taking seriously, and this page does. It means pre-execution interception, five distinct authorization outcomes, tamper-evident receipts, intent-drift tracking and telemetry export have been reviewed against a published standard rather than asserted in marketing copy. A comparison that treated this product as a monitoring tool would be wrong on the first row and the reader would know it.

So Group 01 in the table below is close. Noma scores a 4 on rendering a verdict at the moment of action, and the single caveat behind that 4 is the same one the architecture implies: interception happens where the action passes through their gateway or an instrumented framework.

Where the identity binding stops

This is the boundary the table is really measuring, and the specification states it plainly. The requirement is that every action receipt is cryptographically bound to an agent identity. Not to a person — to the agent.

For forensics that is a genuine advance, and it is why the audit-record row comes out level at 5. You can prove which agent took an action and that the record has not been altered. What you cannot do from that receipt alone is answer the question a regulator, an incident review or a board actually asks, which is who authorised this.

Agen starts from the other end. An agent is an identity object in the same fabric as the humans and machines around it, carrying a named accountable owner, and each individual action is attributed to that person and judged against their authority in context — not against a role granted at connect time. That is the difference between reconstructing what happened and knowing, at the moment it happens, whether it is allowed.

Where enforcement can reach

Discovery and enforcement have different footprints here, and conflating them is the most common mistake made about this product.

Discovery is agentless and broad: sanctioned workflows and agents an employee stood up alone, MCP deployments included. It is one of the three rows on this page that scores level with us, and it earns that.

Enforcement is narrower. It reaches the action through the gateway or through an SDK in a supported framework. There is no device-level control point and no in-browser enforcement point in the platform documentation, which is where the endpoint and browser rows land. An agent that is discovered but sits on neither path is visible without being governable — and the inventory is what tells you that gap exists.

Internal agents, and the ones facing your customers

The product is built for the AI stack an enterprise runs internally: its models, its pipelines, its employees' assistants. That is the larger market today and it is a reasonable place to build.

Agents that act on behalf of customers sit outside that frame. They need the same per-action verdicts and the same accountable owner, but they resolve to an external identity rather than an employee — which is a customer identity problem before it is an agent problem. Running both on one policy plane is a direct consequence of the seven-year customer-identity foundation underneath Agen, and it is why the external-agent row separates the two products by three points.

What it costs to run

The platform is listed on a twelve-month contract, with usage billed by assets scanned, by millions of tokens scanned, and by red-teaming test. The unit is the volume of the estate being inspected.

That model tracks how much AI you have rather than how many agents you govern, so the bill moves with traffic and inventory growth that governance work has not caused. Agen is licensed per governed agent with no prerequisite tier — which is cleaner on the unit, and is also net-new spend for a buyer who has already bought a platform contract elsewhere. That is why we score a 4 on total platform cost rather than a 5.

Where Noma is strongest

Two of the sixteen rows below go to Noma and three are level — the highest a vendor has scored against us on any comparison we publish. None of them are close calls.

  • Protocol-gateway enforcementa control point on the wire that we deliberately do not operate. We govern the action rather than the path to it, and run alongside whatever already sits in that path rather than replacing it.
  • Ecosystem and marketplace reacha cloud-marketplace listing and a native integration with the hyperscaler's own security console give them a wider distribution footprint than ours today.
  • Adversarial testing before deploymentautomated red teaming of AI systems is a module in their platform and is not something we do at all. If pre-production testing is part of what you are buying, that is a reason to buy it from them.
  • Three capabilities scored levelmasking at action time, the tamper-evident per-action audit record, and agentless discovery with no SDK. Complete on both sides, and printed that way.
The scored comparison

Sixteen capabilities, scored side by side.

Runtime enforcement, identity and accountability, coverage, and what it costs to operate — each scored 0–5 on capability depth against vendor documentation, including the rows Noma wins and the rows that come out level.

Capability depthNoneCompleteNoma SecurityAgen.co
01 · Runtime enforcement
Verdict rendered at the moment of actionNoma SecurityPre-execution, gateway or SDKStrong4/5Agen.coPer-action verdicts, <30msComplete5/5
Decision latency, published and measuredNoma SecurityNot publishedPartial2/5Agen.co<30ms, published, no samplingComplete5/5
Masking or redaction at action timeNoma SecuritySensitive data masked inlineComplete5/5Agen.coMasking at action timeComplete5/5
02 · Identity & accountability
Agent has a first-class identity objectNoma SecurityDiscovered and inventoriedCapable3/5Agen.coFirst-class agent identityComplete5/5
Agent identity unified with human and machine identityNoma SecurityAgent identity onlyPartial2/5Agen.coOne fabric: humans, machines, agentsComplete5/5
Each individual action attributed to that humanNoma SecurityReceipts bound to the agentPartial2/5Agen.coAttributed per actionComplete5/5
Authority chain preserved across agent-to-agent callsNoma SecuritySession context, not a chainPartial2/5Agen.coFull chain, agent to agentComplete5/5
Audit record per actionNoma SecurityTamper-evident action receiptsComplete5/5Agen.coA record per actionComplete5/5
03 · Coverage
Endpoint enforcementNoma SecurityIDE integrations, no device clientPartial2/5Agen.coAgenShield on the deviceComplete5/5
Browser enforcementNoma SecurityNo browser enforcement pointBasic1/5Agen.coBrowserShield, early accessCapable3/5
Network-layer enforcementNoma SecurityProtocol gateway on the pathCapable3/5Agen.coNot our layer — works alongsidePartial2/5
Agentless discovery — no SDK, no self-registrationNoma SecurityScans the environment, no code changesComplete5/5Agen.coAgentless, 5 surfaces, no SDKComplete5/5
External customer-facing agentsNoma SecurityInternal AI stack focusPartial2/5Agen.coCustomer-facing agents, same planeComplete5/5
04 · Operate & buy
Pricing unitNoma SecurityPer asset and tokens scannedPartial2/5Agen.coPer governed agentComplete5/5
Platform cost to govern every agentNoma SecurityFlat platform contract, plus usageCapable3/5Agen.coScales with agents, not headcountStrong4/5
Ecosystem and marketplace breadthNoma SecurityAWS Marketplace and Security HubStrong4/5Agen.coFocused platform, not a marketplacePartial2/5
11 rows Agen.co leads3 tied2 rows Noma leads
Levels reflect capability depth and supporting evidence. Capability descriptions based on vendor public documentation, August 2026.
What the scores mean

One boundary, and it is not enforcement.

Most comparisons in this category turn on whether the other product can stop an action. This one does not. Noma intercepts before execution and can allow, deny, modify, step up or defer — reviewed against an open standard, and scored here accordingly.

The boundary is what the decision is anchored to. A receipt bound to an agent proves which agent acted. A verdict resolved to a named human decides whether it should have — before it does, in under 30ms, on every surface the agent can reach rather than the ones it happens to route through.

Findings

Four consequences, one per group.

Each card is the practical version of a group in the table above — what the scores mean once an agent is actually running against your systems.

01

Real enforcement, on the paths it can see

Interception happens before execution and the full set of authorization outcomes is there, verified against an open standard. The condition is that the action reaches the gateway or an instrumented framework, and no decision latency is published — so the enforcement footprint is a deployment question rather than a capability one.

published latencynone
02

The receipt names the agent, not the person

Tamper-evident receipts bound to an agent identity are genuinely complete for forensics, and the audit row is scored level because of it. They answer which agent acted. They do not carry the named human who answers for it, so accountability has to be reconstructed after the fact rather than enforced at the moment of action.

accountable human per actionno
03

Discovery is wider than enforcement

Agentless discovery reaches sanctioned and employee-deployed agents alike and scores level with ours. Enforcement reaches the gateway and instrumented frameworks — there is no device-level or in-browser control point — so the inventory will surface agents the platform cannot then govern.

device-level enforcementnone
04

Billed for what you scan, not what you govern

A platform contract with usage billed by assets and by millions of tokens scanned means the bill tracks the size of the AI estate. Governing ten agents well and a thousand agents well are priced by inspection volume rather than by the thing being governed.

billed perasset scanned
Watch it happen

Every action resolved to the human who answers for it.

Not the agent that took it — a named accountable owner carried on every agent, and every individual action attributed back to them, judged in context before it runs.

agent ownership · live product scene
What closes the gap

Keep the inventory. Anchor it to a person.

Your posture tooling keeps finding what is out there and your gateway keeps inspecting what crosses it. Agen governs on top: every agent carrying a named accountable owner, every action judged against your policy at the moment it happens in under 30ms, on the endpoint and in the browser as well as at the gateway.

Select a capability

Continuous discovery across your IdP, gateway, devices, cloud, and registries. Nothing has to self-register: agents are found, risk-scored, and resolved to a named human before they act.

  • Agentless and API-based across five surfaces
  • First-party, custom, and third-party agents alike
  • Every agent mapped to an owner, approver, and escalation
Agen Discover AI agent discovery flow: any identity provider, productivity suites and assistants, cloud, gateway, endpoints, and MCP server registries all feed one agent registry where every AI agent is inventoried, risk-scored on arrival, given a named human owner, and shadow AI is surfaced.
Discovery pulls from five surfaces into a single agent registry — no SDK self-registration required.
ClosesWhich agents are running that nobody registered?
no SDK required5 surfacesowner-mapped
Discover in depth →

Methodology

How these scores were reached.

Forty-two capabilities were scored against the ladder in our internal rubric; sixteen are published here. Seven were dropped and are not published on any page — five because the only finding was an absence in public documentation, which is weaker evidence than a documented limit, and two because our own column could not be verified against the rubric baseline. Two further capabilities where Noma leads, intent-drift detection and automated adversarial testing, are held back for the same reason rather than scored from inference. Each score reflects capability depth in the vendor's best available configuration — where a capability requires a separate module, it is scored at its real depth and the licensing cost is carried in the Operate & buy group instead of penalised twice.

Sources8 primary
Evidence ledger
  1. Cloud Security Alliance — AARM builder registryTier ANoma Security is listed at Extended conformance (R1–R9). Interception architecture is given as protocol gateway and SDK instrumentation; the authorization decisions supported are ALLOW, DENY, MODIFY, STEP_UP and DEFER; intent-drift detection is embedding-based; telemetry is exported over OpenTelemetry.
  2. Noma Security — Runtime ProtectionTier AResponses range from real-time alerts and audit logging, to sensitive data masking, to full request blocking, configurable by application, agent profile, risk level or policy type. Enforcement happens at the point of execution. No decision latency is published.
  3. Noma Security — PlatformTier AFour modules: AI security posture management, red teaming, runtime protection, and agentic access control. More than eighty integrations. Enforcement is available through a REST API, native Python and JavaScript SDKs for frameworks such as LangChain and CrewAI, or a centralized gateway. On-premise and SaaS deployment are both offered.
  4. Noma Security — AI Agent SecurityTier AAgentic identity and access control provides policy-based approval, runtime enforcement and continuous monitoring. The platform automatically discovers every agent within the environment.
  5. Noma Security — MCP Server SecurityTier ADiscovers all MCP deployments and agent connections, whether deployed as part of sanctioned workflows or directly by employees. Guardrails restrict both connections and the permissions an agent exercises through MCP.
  6. AWS Marketplace — Noma Security PlatformTier BThe platform is listed on a twelve-month contract. The companion Security Hub listing bills by millions of tokens scanned, by number of assets scanned, and by number of red-teaming tests.
  7. Noma SecurityTier APositions the platform as discover, secure and protect across AI, agents and MCP. Catches threats including prompt injection and jailbreaks; privacy policies block sensitive data from leaving the environment.
  8. Cloud Security Alliance — AARM specificationTier ARequirement R6 states that every action receipt must be cryptographically bound to an agent identity. The specification's identity-binding requirement terminates at the agent rather than at an accountable person.

Vendor capabilities change. If a row is out of date or wrong, tell us and we will re-score it — corrections are published with the date they were made.

FAQ

Questions, answered.

What is Noma Security?
It is a platform for discovering and defending the AI systems an enterprise runs, built around four modules over a shared inventory. Posture management scans the environment for models, agents, MCP servers and data sources and maps how they connect. Red teaming runs automated adversarial tests before deployment. Runtime protection enforces at the point of execution, with responses ranging from alerting through masking to blocking the request. Agentic access control applies policy-based approval and continuous monitoring to what agents are permitted to do.
Does Noma Security block agent actions at runtime?
Yes, and this is not in dispute. Noma is listed at Extended conformance against Autonomous Action Runtime Management, the open runtime-security specification governed by a Cloud Security Alliance working group, which covers pre-execution interception and all five authorization outcomes — allow, deny, modify, step up and defer. Interception happens at their gateway or through an SDK in a supported framework, so the practical question is which of your agent actions reach one of those paths rather than whether enforcement exists. No decision latency figure is published.
How does Noma Security identify the human behind an agent?
It binds the record to the agent rather than to a person. The specification it conforms to requires that every action receipt is cryptographically bound to an agent identity, and that is what the product delivers — which is why the per-action audit row scores level with ours at 5. It proves which agent acted and that the record has not been altered. It does not carry a named accountable human, so answering who authorised an action means reconstructing it from session context afterwards rather than resolving it at the moment the action is judged.
Can Agen.co run alongside Noma Security?
Yes, and for a lot of buyers that is the right answer. Protocol-gateway enforcement is a layer we deliberately do not operate and is one of the two rows on this page where Noma scores above us, and their automated red teaming is a capability we do not offer at all. Agen adds the layer above: every agent carrying a named accountable owner, every action judged against your policy in under 30ms, and enforcement on the endpoint and in the browser as well as at the gateway. Nothing in your existing stack has to be removed.
How is Noma Security priced?
The platform is listed publicly on a twelve-month contract, with usage billed by number of assets scanned, by millions of tokens scanned, and by red-teaming test. The unit is the volume of the AI estate being inspected, so the bill tracks how much AI you have rather than how many agents you are governing. Agen is priced per governed agent with no prerequisite tier — cleaner on the unit, and net-new spend if you already hold a platform contract elsewhere, which is why we score a 4 rather than a 5 on total platform cost.
Where does Noma Security score better than Agen.co?
Two rows of sixteen outright, and three more are level — the strongest a vendor has scored against us on any comparison we publish. Protocol-gateway enforcement, because that is a layer we do not operate. Ecosystem and marketplace reach, through a cloud-marketplace listing and a native integration with the hyperscaler's own security console. Level with us on masking at action time, on the tamper-evident per-action audit record, and on agentless discovery with no SDK. Separately, their automated red teaming has no counterpart in our platform and is not scored on this page for that reason.
Does this cover agents that never reach a gateway?
That is one of the two differences the table measures. Agen discovers agents agentlessly across five surfaces — identity provider, gateway, devices, cloud and registries — and enforces on the endpoint, in the browser, at the gateway and in the cloud, so an agent does not have to be routed anywhere or carry an SDK to be governed. Internal and customer-facing agents run on the same policy plane.
How current is this comparison?
It is scored against vendor public documentation and re-scored on a schedule we hold ourselves to. Every published row is backed by at least one primary vendor source, all of which are listed on this page — so any row can be checked against the vendor's own docs rather than taken on trust.

Bring your own comparison.

Send us the rows you would score differently. We will show you the evidence behind ours, and where we are wrong we will change the page.