Comparison · agent governance · Virtue AI

Virtue AI, measured.

Virtue AI red-teams agents before they ship and blocks unsafe tool calls once they run. What its documentation never names is the person who owns the agent making the call. This page scores that architecture across 15 capabilities against the same capabilities in Agen.co — with the sources, the scoring ladder, and the three rows Virtue AI wins all on the page.

The short answer

  • Virtue AI guards the agent's tool calls. ActionGuard judges each call in the context of the steps before it and blocks an out-of-policy one before it fires, leaving the agent running.
  • The verdict asks whether a call is unsafe or out of policy. No owner object is documented for an agent, so nothing documented resolves the call to a named, accountable human. Agen resolves each action to one.
  • Shadow AI discovers agents through an endpoint collector, alongside the EDR you already run or on its own, and the vendor places active blocking in ActionGuard rather than on the device. Agen discovers agentlessly across five surfaces and enforces on the device.
  • Its guard models publish sub-50ms end-to-end for content checks; the action guardrail is described as low-latency, with no figure. Agen renders a verdict on every action, against any policy you write, in under 30ms.
  • Virtue AI is stronger at adversarial testing before an agent ships, at prompt-injection and content-threat detection, and in ecosystem reach now that it is part of Fortinet. MCP tool governance, the per-action audit record, framework coverage and deployment model score level with ours.
The long read

What Virtue AI actually governs.

Virtue AI comes out of AI security research, and the product shows it: it attacks agents before they ship and guards their tool calls once they run. What it is built to decide is whether an action is unsafe. Who the action belongs to is a different question.


The product, module by module

The platform is sold as a set of named modules. The agent-specific ones sit under AgentSuite, a blue-team side and a red-team side, with general-purpose guardrails and governance beside them.

  • AgentSuite-Bluethe runtime side. ActionGuard applies stateful guardrails to each agent action, judging a tool call in the context of the steps before it so multi-step attacks are caught. MCPGuard scans MCP servers continuously, both their source code and their tool descriptions. A unified agent gateway sits between agents and their MCP tools as one enforcement point.
  • Shadow AIendpoint-level discovery for AI tools and agents. A lightweight collector runs on Linux, macOS and Windows, alongside an existing EDR or on its own, and surfaces commercial assistants, self-hosted models, browser extensions, IDE plugins and informal agent pipelines.
  • AgentSuite-Red and VirtueRedadversarial testing. A red-teaming agent probes your agent across dozens of sandboxed, production-grade environments under direct and indirect prompt-injection threat models, and reports attack success rates as control evidence.
  • VirtueGuard and VirtueGovguard models for text, code, image, audio and video in more than a hundred languages, natural-language policy authoring mapped to over fifty regulatory and industry frameworks, and the compliance reporting around them.

It deploys in the cloud or on-premises, and it supports agents built on the major frameworks plus custom ones through generic wrappers. Virtue AI is now part of Fortinet, which says the acquisition complements its AI gateway and that Virtue AI will enhance its Security Fabric.

Where Virtue AI is strongest

Three of the fifteen rows below go to Virtue AI and four are level. They follow from what the product was built to do: find out how an agent can be broken, and stop the attempt when it happens.

  • Adversarial testing before productiona red-teaming agent working through sandboxed environments that mirror real business systems, before the agent under test ever touches one. We govern agents once they run, which is what lets the same policy reach agents nobody tested first.
  • Prompt-injection and content-threat detectionpurpose-built guard models across five modalities and more than a hundred languages. We judge the action an agent takes rather than the text it was given, and run alongside whatever inspects that text.
  • Ecosystem reachjoining Fortinet's Security Fabric gives the product a wider distribution footprint than ours today.
  • Level on four rowsMCP tool governance, with servers scanned and every call guarded; an audit record per action, from tool-call traces and the endpoint collector's operational record; agents built on any framework; and deployment in the cloud or on-premises.

Where Shadow AI stops and ActionGuard starts

ActionGuard's enforcement is real: a tool call that breaks policy is blocked before it fires, and the agent keeps running. The open question is not whether Virtue AI blocks, but where.

The vendor draws the line itself. Shadow AI is the discovery and monitoring layer, a collector on the endpoint, and active blocking lives in ActionGuard on the tool call. An assistant found on a laptop, or an agent running as a browser extension, is inventoried with its host and user; no page documents stopping its next action on that device or in that browser. That is why the moment-of-action row scores a 3 rather than a 5.

Unsafe is not the same as unaccountable

Every verdict in this product answers one question well: is this call an attack, or out of policy? It is a good question, and the stateful view across steps makes the answer better than a call-by-call filter.

A security review asks a second question: whose agent is this, and who answers for what it just did? The collector records host and user context, but no page documents a standing owner assigned to an agent, or an action attributed to one. A perfectly safe action can still be one nobody should have taken, and the verdict about safety cannot tell you who owns it.

Three questions to put to Virtue AI

Virtue AI answers the security questions thoroughly: can this agent be broken, and is this call an attack? Governing an agent asks three more, and the table is organised around them.

  • Be at runtimeActionGuard decides as the tool call happens. The test is reach: does the assistant Shadow AI found on a laptop, or the agent living in a browser extension, get that same decision before it acts?
  • Know the identityShadow AI records the host and the user context. The test is whether an action resolves to the named person who answers for the agent, rather than to the machine it ran on or whoever was signed in.
  • Cover everythingAgentSuite-Red covers the agents someone chose to test, and VirtueGuard covers what it is plugged into. The test is everything else: agents on devices, in browsers, and facing your customers.

Price usually settles the decision, and Virtue AI, now part of Fortinet, publishes neither a price nor a pricing unit. Cost stays unscored here rather than guessed.

The scored comparison

Fifteen capabilities, scored side by side.

Runtime enforcement, identity and accountability, coverage, and how it deploys — each scored 0–5 on capability depth against vendor documentation, including the three rows Virtue AI wins.

Capability depthNoneCompleteVirtue AIAgen.co
01 · Runtime enforcement
Verdict rendered at the moment of actionVirtue AITool-call path; not device or browserCapable3/5Agen.coPer-action verdicts, <30msComplete5/5
Decision latency, published and measuredVirtue AIContent guards sub-50ms; actions unpublishedPartial2/5Agen.co<30ms, published, no samplingComplete5/5
Adversarial testing of an agent before productionVirtue AIAgent red teaming in sandboxesComplete5/5Agen.coNot offeredBasic1/5
Prompt-injection and content-threat detectionVirtue AIMultimodal guard models, 100+ languagesComplete5/5Agen.coAction-level, not prompt inspectionPartial2/5
02 · Identity & accountability
A named human accountable for each agentVirtue AINo ownership object documentedBasic1/5Agen.coNamed owner, every agentComplete5/5
Each individual action attributed to that humanVirtue AIUser context on the hostPartial2/5Agen.coAttributed per actionComplete5/5
Access evaluated at action time, not only at grant timeVirtue AIPer call, in context; role-based accessStrong4/5Agen.coJudged in context, per actionComplete5/5
Audit record per actionVirtue AITraces, audit log, endpoint recordComplete5/5Agen.coA record per actionComplete5/5
03 · Coverage
Endpoint enforcementVirtue AIEndpoint collector, visibility onlyPartial2/5Agen.coAgenShield on the deviceComplete5/5
Browser enforcementVirtue AIExtensions discovered, not enforcedBasic1/5Agen.coBrowserShield, early accessCapable3/5
Agentless discovery — no SDK, no self-registrationVirtue AIEndpoint collector or existing EDRCapable3/5Agen.coAgentless, 5 surfaces, no SDKComplete5/5
Agents built outside the vendor's own stackVirtue AIAny framework, custom wrappersComplete5/5Agen.coAny agent, any stackComplete5/5
MCP tool governanceVirtue AIServers scanned, every call guardedComplete5/5Agen.coMCP tools governed per callComplete5/5
04 · Operate & buy
Deployment model and data residencyVirtue AICloud or on-premisesComplete5/5Agen.coSaaS, hybrid, or on-premComplete5/5
Ecosystem and marketplace breadthVirtue AIFortinet Security Fabric, integration underwayStrong4/5Agen.coFocused platform, not a marketplacePartial2/5
8 rows Agen.co leads4 tied3 rows Virtue AI leads
Levels reflect capability depth and supporting evidence. Capability descriptions based on vendor public documentation.
Get the walkthrough

Get the scored comparison walkthrough.

Thirty minutes, row by row, including the ones we lose to Virtue AI. You leave with the same table, scored for your environment. Tell us anything we should know in the comments.

length30 minutes
formatrow by row
commitmentnone
What the table shows

Two documented gaps: the owner and the device.

Virtue AI's runtime enforcement is real, and the scores say so: a 3 on the moment of action, three rows won outright and four more level. How ActionGuard detects and blocks an attack is not where the table separates.

It separates in two places Virtue AI's own pages describe. Every verdict asks whether a call is safe, and nothing documented names who owns the agent that made it. And Shadow AI finds agents on laptops and in browsers that no page documents stopping there. The cards below follow those two facts through each group of the table.

Reading the table

What the scores mean under ActionGuard and Shadow AI.

One card per table group: what each set of scores means once an agent guarded or inventoried by Virtue AI is running against your systems.

01

Every call judged; the clock unpublished

ActionGuard blocks an out-of-policy tool call before it fires and leaves the agent running, which is real action-level enforcement. The guard models publish their latency; the action guardrail is called low-latency and given no number, so what a verdict adds to the agent's loop is yours to measure.

action-guard latencyunpublished
02

Safe is answered; whose is not

Every tool call is judged for risk in the context of the steps before it. None of it resolves to a standing, named owner for the agent, so a security review gets a detailed trace and no accountable person at the end of it.

named owner per agentnot documented
03

Discovery sees further than enforcement reaches

The endpoint collector inventories assistants, extensions, IDE plugins and agent pipelines across the fleet. The vendor leaves blocking to ActionGuard, so what the collector finds on a device or in a browser is listed rather than governed there.

device-level blockingnot documented
04

Joining a larger suite

No pricing is published, so cost is not scored here. What is public is the direction: the product is now Fortinet's, which says the acquisition complements Fortinet's AI gateway and will enhance the Security Fabric — a wider distribution footprint than a standalone product has.

published pricingnone
Watch it happen

Every action resolved to the human who answers for it.

Not the host it ran on or whoever was signed in — a named accountable owner carried on every agent, and every individual action attributed back to them, including agents found on a laptop or in a browser.

agent ownership · live product scene
What closes the gap

Keep the red team. Add the accountable layer.

Your red-teaming and guard models keep testing and filtering. Agen governs on top: every agent discovered agentlessly, with no collector to roll out first, every action judged against your policy at the moment it happens, every verdict resolved to the human behind the agent.

Select a capability

Continuous discovery across your IdP, gateway, devices, cloud, and registries. Nothing has to self-register: agents are found, risk-scored, and resolved to a named human before they act.

  • Agentless and API-based across five surfaces
  • First-party, custom, and third-party agents alike
  • Every agent mapped to an owner, approver, and escalation
Agen Discover AI agent discovery flow: any identity provider, productivity suites and assistants, cloud, gateway, endpoints, and MCP server registries all feed one agent registry where every AI agent is inventoried, risk-scored on arrival, given a named human owner, and shadow AI is surfaced.
Discovery pulls from five surfaces into a single agent registry — no SDK self-registration required.
ClosesWhich agents are running that nobody registered?
no SDK required5 surfacesowner-mapped
Discover in depth →

Methodology

How these scores were reached.

Twenty-five capabilities were scored against the ladder in our internal rubric, two of them case-by-case rows for adversarial testing and content-threat detection; fifteen are published here. Nineteen standard capabilities were dropped and are not published on any page — most because the only finding was an absence in public documentation, which is weaker evidence than a documented limit, both pricing rows because no pricing is published, and connector breadth because the two products count the underlying thing differently enough that the row would not have been a fair like-for-like. Each score reflects capability depth in the vendor's best available configuration.

Sources7 primary
Evidence ledger
  1. Virtue AI — AgentSuite and platform overviewTier AActionGuard judges every tool call in full context and prevents unsafe, malicious or out-of-policy actions before they execute; Shadow AI detection through the EDR already in place; agent red teaming across 50+ sandboxed environments in 14 domains; natural-language policy with 50+ compliance frameworks; guard models that plug into an application, agent, gateway or RAG pipeline; cloud and on-premises deployment; SOC 2. The same page is served at virtueai.com/platform.
  2. Virtue AI — AgentSuite-BlueTier AStateful, real-time guardrails for every agent action with tunable thresholds; continuous security analysis of MCP servers; a unified agent gateway as a single enforcement point between agents and MCPs; endpoint-level discovery across laptops, SaaS, developer workflows and browser extensions; observability and access control with visibility into conversations, actions, tool calls and token traces; described as optimized for low latency, with no figure. No agent identity object, owner or delegation model is described.
  3. Virtue AI — Shadow AITier AA lightweight endpoint collector on Linux, macOS and Windows, running alongside an existing EDR or independently; covers commercial AI tools, self-hosted models, browser extensions, IDE plugins and informal agent pipelines; keeps a continuous operational record of host, user context, tool calls and sequence; handles the discovery layer, with active blocking of malicious tool calls living in ActionGuard.
  4. Virtue AI — VirtueGuardTier AGuard models for text, image, audio, video and code in 100+ languages; sub-50ms end-to-end latency with core inference under 10ms; PII exposure, jailbreaks and 12+ harm categories covered; custom policy; plugs into a chatbot, application, gateway, RAG system or pipeline.
  5. Virtue AI — AgentSuite-RedTier AAn adversarial red-teaming agent across 50+ production-grade environments in 14 domains, under direct and indirect prompt-injection threat models; supports the OpenAI Agents SDK, Claude SDK, Google ADK, LangChain, PocketFlow and generic wrappers for custom agents.
  6. Virtue AI — AgentSuite announcementTier ARed teaming of agent behavior with 100+ agent-specific attack strategies; MCPGuard scanning CWEs in MCP code and prompt injection in tool descriptions; ActionGuard as a real-time guardrail over agent action trajectories; a unified agent gateway as a single enforcement point between agents and all tools; role-based access control and centralized audit logging.
  7. Fortinet — acquisition announcementTier AFortinet acquired Virtue AI; the acquisition complements FortiAIGate and will enhance the Fortinet AI-Native Security Fabric.

Vendor capabilities change. If a row is out of date or wrong, tell us and we will re-score it — corrections are published with the date they were made.

FAQ

Questions, answered.

What is Virtue AI?
Virtue AI builds security and compliance products for AI models and agents. AgentSuite-Blue guards agents at runtime with ActionGuard, MCPGuard and a unified agent gateway; Shadow AI discovers AI tools and agents on endpoints; AgentSuite-Red and VirtueRed red-team agents and models in sandboxed environments; VirtueGuard provides multimodal guard models; and VirtueGov covers governance and compliance reporting. The company is now part of Fortinet.
Does Virtue AI block agent actions at runtime?
Yes. ActionGuard evaluates each tool call in the context of the agent's previous steps and blocks an unsafe or out-of-policy call before it executes, with tunable thresholds and real-time alerts, and a unified agent gateway gives agents and their MCP tools a single enforcement point. Shadow AI is the discovery and monitoring layer: the vendor places active blocking in ActionGuard, and no public page documents blocking an agent on the device or in the browser where Shadow AI finds it.
How does Virtue AI identify the human behind an agent?
Shadow AI records host and user context for the AI tools and agents it finds, and AgentSuite-Blue traces conversations, actions and tool calls. No public documentation describes a standing owner assigned to an agent or an action attributed to a named, accountable human, which is what Agen records for every agent and every action.
Can Agen.co run alongside Virtue AI?
Yes. Red-teaming an agent before it ships and inspecting prompts and content for injection are two of the rows on this page where Virtue AI leads, and both sit upstream of the action. Agen governs the action and its owner: every agent discovered agentlessly across five surfaces, every action judged against your policy in under 30ms, and every verdict resolved to a named accountable human.
How is Virtue AI priced?
Virtue AI does not publish pricing or a pricing unit, so this comparison leaves cost unscored rather than estimate it. Agen is priced per governed agent with no prerequisite tier.
Where does Virtue AI score better than Agen.co?
Three of the fifteen rows go to Virtue AI outright: adversarial testing of an agent before production, prompt-injection and content-threat detection, and ecosystem reach through Fortinet. Four more are level: MCP tool governance, an audit record per action, coverage of agents built on any framework, and deployment model.
What changed with the Fortinet acquisition?
Fortinet acquired Virtue AI and has said the acquisition complements FortiAIGate, its AI gateway, and that Virtue AI will enhance the Fortinet Security Fabric. This page scores the product as Virtue AI documents it today; where the integration changes a capability, the affected rows are re-scored against the new documentation.
How current is this comparison?
It is scored against vendor public documentation and re-scored on a schedule we hold ourselves to. Every published row is backed by at least one primary vendor source, all of which are listed on this page — so any row can be checked against the vendor's own docs rather than taken on trust.

Bring your own comparison.

Send us the rows you would score differently. We will show you the evidence behind ours, and where we are wrong we will change the page.