Aurascape

Security for AI Data SecurityGovernance Risk ComplianceApplication Security also known as Aurascape, Inc., Aurascape AI

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2023
Funding $50M
Last updated 2026-08-30

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Aurascape sells enterprises software that monitors employee AI use and controls the AI agents their teams build, inspecting prompts, responses, and agent tool calls as they happen. The asset underneath is a catalog of more than twenty thousand AI applications, each with a decoder and a risk score. Its team extends that catalog daily and targets forty-eight hours to cover most AI applications, which is permanent engineering rather than a shipped feature. The company has raised 50 million dollars, and its customer record of four case studies and eighteen named organizations is published entirely by Aurascape. The funding is independently reported, and the deployments are not.

Sourced Details

Description Aurascape secures how enterprises use and build AI, inspecting prompts and responses inline to discover AI apps and agents, enforce policy, and protect sensitive data across employee AI use and agentic workflows. [f1]
Founded 2023 [f2]
HQ Santa Clara, California, United States [f3]
Funding $50M total [f2]
Latest funding Series A (April 2025), co-led by Menlo Ventures and Mayfield Fund, amount not separately disclosed [f4]

Products

Product What it does
Aurascape AI Security Platform Inline platform that discovers and risk-scores AI apps, copilots, and agents, inspects prompts and responses, and enforces data-protection and threat-prevention policy across AI activity.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

The Aurascape AI Security Platform inspects prompts and responses inline to protect runtime AI data and detect risky activity, and discovers AI apps and agents while guarding tool use through an MCP gateway. These capabilities are mapped to the AI Defense Matrix. [f1]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Emerging 23 /40 Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Aurascape names the security and compliance buyer and the shadow-AI exposure, SecurityWeek frames the same problem in its own voice, and SiliconANGLE attributes quantified findings to McKinsey and Deloitte on how far employee AI use runs ahead of what leaders expect. Those same two figures appear in Aurascape's own launch release, so the quantification does not rest on several non-vendor sources reaching it independently. [s5, s4, s15, s1]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 Menlo Ventures describes a concrete architecture, an inline proxy paired with an endpoint client decoding more than 1,500 applications, and Aurascape's own engineering post details a 20,000-application catalog with daily decoder additions, which is capability detail rather than slogans. Menlo is an investor rather than an evaluator, and the one third-party technical write-up in the record, an NSFOCUS analysis, works from Aurascape's own pages and concludes that real-world validation is still needed. [s7, s1, s12, s13]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 Enterprise adoption of generative AI since the company's founding, which SiliconANGLE and an NSFOCUS analysis date to 2023 while BankInfoSecurity says 2024, and the Model Context Protocol becoming a standard way for agents to connect to tools as Aurascape's March 2026 expansion describes, are credible enablers, and the April 2025 round drew capital from security operators. Evidence that buyers are actively searching stays indirect, because the analyst listing and every customer deployment reach the record through Aurascape's own pages rather than an independently documented signal. [s4, s13, s6, s9, s18]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 BankInfoSecurity independently documents Khan's three years leading Zscaler's SSE and data protection business, after four and a half years in product management at Palo Alto Networks and 18 months at Netskope, which is verifiable senior in-domain experience. The record documents no product build attributable to a named founder, no exit, and no independently evidenced publication standing, and the wider group's track record rests on Mayfield's own characterization. [s6, s2, s13, s15]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 Aurascape publishes a company-attributed testimonial from WinWire Technologies, a named case study at The Police Credit Union, three Fortune 500 deployments described without names, and image alt text naming eighteen customer organizations, which is well past design partners and carries the small indirect-signal bump its Mayfield and Menlo backing earns. Every one of those data points is the company speaking, so none of it is corroborated by a second voice. [s3, s10, s16, s19, s20, s15, s14]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 2/5 The $50 million in cumulative launch funding, which includes the $12.8 million seed and a Series A whose amount is not separately disclosed, is large against the commercial record beside it, and that record is early and published entirely by Aurascape: four case studies on its own pages. The August 2026 chief revenue officer hire is a spend rather than a commercial result. No revenue or margin is disclosed, and the recurring-revenue figure is only a target the chief executive stated. The capital outruns verifiable commercial results, and self-published deployments do not close that gap. [s4, s6, s15, s10, s16, s19, s20, s14]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Aurascape's analyst-coverage page reports a Gartner listing as a sample vendor in AI usage control, and SecurityWeek and SiliconANGLE both place the company in shadow-AI security, so a buyer can find a slot for it. The category is still forming, and Aurascape's own market page sorts the 2026 AI-security market into four vendor groups and places the product across all of them, so a buyer still needs the vendor's explanation to file it. [s9, s5, s4, s17]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 The 20,000-application catalog, the inline position, and the MCP gateway raise the cost of replication above a policy toggle, which is real friction to absorption. Aurascape's own market page positions the product as additive to an existing secure-web platform and records that Zscaler announced an MCP gateway in early 2026, so the reviewed sources show no structural moat that bundling could not reach. [s12, s1, s17, s5]
Business Risks A secure-web or data-loss platform could add inline AI discovery and prompt inspection to controls security teams already buy, absorbing the employee-use half as a bundled feature…
  • A secure-web or data-loss platform could add inline AI discovery and prompt inspection to controls security teams already buy, absorbing the employee-use half as a bundled feature.
  • Every customer figure in the public record is Aurascape's own, so disclosed adoption could prove smaller or shallower than the case studies imply.
  • The reviewed sources record no SOC 2 or ISO 27001 report for Aurascape, and regulated buyers can require one before signing.
  • The gateway half of the agent controls enforces policy on tool calls routed through it, so enterprises moving away from the Model Context Protocol would blunt that half.
  • The application catalog needs daily engineering to stay current, so a slowdown in that work would erode the coverage the product is sold on.
  • Splitting effort across employee AI use and the agent build side could leave each half matched by a more focused competitor.
Problem & Market Aurascape targets the gap between how fast enterprises adopt AI and how little their security teams can see of it…

Aurascape targets the gap between how fast enterprises adopt AI and how little their security teams can see of it. Employees paste sensitive material into chatbots and copilots nobody sanctioned, and developers wire agents into internal systems through tools and APIs that older controls were never built to read. The company sells to the security and compliance leaders who carry that exposure.

SecurityWeek echoes the problem framing in its own voice, describing unsanctioned third-party AI applications that slip past traditional security controls and a sizable enterprise market for tools that mitigate them. SiliconANGLE adds quantification, attributing to McKinsey a finding that employees use generative AI three times more than leaders expect and to Deloitte a finding that one in three employees pay for an AI application themselves. Both figures also sit in Aurascape's own launch release.

Aurascape scopes the problem in two halves on one platform. One half is employee AI use across apps, browsers, and copilots. The other is the agents and applications a company's own teams build and run, which its March 2026 platform expansion moved to the center of the pitch. Covering both is the company's positioning bet, and it asks a governance owner and an engineering owner to buy the same product. [s5, s4, s15, s1]

Product Capabilities The platform inspects AI activity while it happens rather than after the fact…

The platform inspects AI activity while it happens rather than after the fact. Menlo Ventures describes a cloud-native inline proxy paired with an endpoint agent that decodes more than 1,500 applications and captures activity across text, audio, image, and code, and Khan told BankInfoSecurity the endpoint client redirects only AI-related traffic to the cloud platform. Sitting in that path is what lets the product classify sensitive data inside prompts and responses and stop risky activity in real time.

Aurascape's own engineering post puts the current coverage at more than 20,000 catalogued AI applications as of June 2026, each carrying a decoder implementation and a risk characterization, with new applications added daily and a 48-hour target the company scopes to the vast majority of AI applications. The catalog is the working asset behind the discovery and policy claims, and keeping it current is continuous engineering rather than a shipped feature.

The build side extends the same position to agents. The product maps MCP servers, tool connections, and data flows, stress-tests agents against simulated prompt injection and jailbreak attempts before release, and enforces policy on the model conversation and on gateway-routed tool calls.

Depth otherwise rests on the company's own account. The one third-party technical write-up in the record, an NSFOCUS analysis of the vendor's pages, concludes that real-world validation is still needed. A buyer would have to confirm the decode and enforcement claims hands-on. [s7, s1, s12, s23, s13]

Competitive Positioning Aurascape competes on covering both AI use and AI building on one platform…

Aurascape competes on covering both AI use and AI building on one platform. Its product pages document discovery and policy across employee AI activity, and a separate agent side that maps MCP servers, tests agents before release, and governs tool calls at runtime. The one survey of competing coverage in the reviewed sources is Aurascape's own market page, which sorts the market into four vendor groups and places Aurascape across all of them, so the breadth claim rests on the vendor's account of its rivals rather than on evidence about them.

The sharper pressure comes from the platforms whose budget line Aurascape shares. By its own market page, Zscaler delivers AI security through its cloud proxy, discovers AI applications using its existing shadow-IT framework, applies inline threat detection and data-loss controls, and announced an MCP gateway in early 2026. The same page positions Aurascape as additive to an existing secure-web deployment rather than a replacement, which lowers the bar to adoption and leaves the network position with the vendors already in that path.

Aurascape's counterweight is the application catalog and the agent controls, which take more work to reproduce than a policy toggle. Whether that depth embeds the product in customer workflows deeply enough to resist bundling is not answerable from the reviewed record, which carries no independent account of how any customer runs it. [s1, s17, s12, s5]

Go-to-Market & Traction Aurascape's disclosed traction grew substantially over the past year, and the company published all of it…

Aurascape's disclosed traction grew substantially over the past year, and the company published all of it. The homepage carries four testimonials whose speakers are identified by title alone, plus one quote attributed to Vineet Arora, CTO of WinWire Technologies. The homepage publishes image alt text naming eighteen organizations, among them two credit unions, a transit agency, and a university, and one of those names is Auradine, the portfolio company Mayfield describes Aurascape as spinning out of, so at least one published customer name is the company Aurascape came out of.

Aurascape publishes four case studies. One names The Police Credit Union and records a two-phase deployment aligned to NCUA guidance and the NIST AI Risk Management Framework, with a projected 27 percent productivity gain and a projected 83 percent reduction in AI-based risk. Three describe unnamed Fortune 500 enterprises, at more than 30,000 users at an insurer, more than 15,000 developers at a financial services firm, and more than 60,000 users at a healthcare technology company. Aurascape publishes every one of those figures, and the credit-union percentages are that customer's own projections.

The independent record covers the money and stops. SecurityWeek, SiliconANGLE, and BankInfoSecurity all reported the April 2025 launch and the 50 million dollars behind it, RSA Conference's finalist announcement records a 5 million dollar investment awarded to each of the ten 2025 finalists, and BankInfoSecurity recorded a near-term goal of 25 enterprise customers in finance, healthcare, and retail plus a recurring-revenue target of 10 to 15 million dollars within two years. No reviewed source outside Aurascape reports a customer, a deployment, or a revenue figure since. In August 2026 the company named Jim Walsh chief revenue officer, an appointment it frames as following a year of growth. [s3, s10, s16, s19, s20, s22, s6, s14]

Team & Credibility Aurascape names its founders publicly…

Aurascape names its founders publicly. The company page lists Moinul Khan as CEO, Patrick Xu as CTO, Viswesh in product management, and Liang Li in engineering under leadership, adds a marketing lead and a sales lead beside them, and separately lists Rajiv Khemani as a co-founder and board member. Aurascape announced Jim Walsh as chief revenue officer on August 3, 2026.

The senior experience the independent record documents belongs to the chief executive. BankInfoSecurity reports that Khan spent nearly six years at Zscaler, ending with three years leading its SSE and data protection business, after four and a half years in product management at Palo Alto Networks and 18 months at Netskope. It names no product he built. Mayfield credits the six people it names as the team it partnered with, saying they built products that generated over 10 billion dollars in revenue, and it names none of those products.

The backers are the louder credibility signal, and they are backers rather than builders here. Former Palo Alto Networks CEO Mark McLaughlin sits as a board observer, and the launch release names him alongside former Symantec CEO Greg Clark and former Zscaler strategy chief Manoj Apte among the investors. The company page also lists CISOs at AT&T and Mastercard and a Databricks CIO as advisors, which is advisory standing rather than customer proof. [s2, s6, s22, s14, s15]

Trust Readiness Aurascape publishes no attestation a security buyer can read…

Aurascape publishes no attestation a security buyer can read. A probe of its public surfaces found the trust and security subdomains failing DNS against a nonsense control subdomain that failed the same way, the /trust and /pricing paths returning 404, the /security path serving an image file, and no compliance badge filename in the homepage markup. The reviewed sources record no SOC 2 or ISO 27001 report for the company.

That gap carries weight for this particular product. The platform reads every prompt and response an employee sends, and the buyers its case studies name are examined by the National Credit Union Administration or bound by state insurance data security laws. Those case studies are built around assembling examiner-ready evidence with the product, while the reviewed record documents nothing about Aurascape's own controls.

The company's visible security credibility is its research instead. Its AuraLabs team published a coordinated disclosure of a zero-click prompt-injection takeover in Meta's Manus agent, reported to that vendor in September 2025 and published in February 2026. That shows engineering depth and does not speak to how Aurascape handles customer traffic. [s11, s10, s16, s21]

Competitors WitnessAI, Harmonic Security, Prompt Security, Straiker, Zscaler, Netskope…
Company Relationship Note Compare
WitnessAI competes with Competes for the same security buyer governing employee AI activity with inline visibility and policy enforcement. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Harmonic Security competes with Competes for the budget that protects sensitive data in employee AI use, a segment Aurascape's own market page groups it into. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Prompt Security competes with Competes across both employee AI use and the agents teams build. Aurascape's own market page lists it as now part of SentinelOne. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Straiker competes with Adjacent on securing the AI agents and applications a company builds. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Zscaler adjacent Holds the network position Aurascape's own market page says the product runs alongside rather than replacing. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Netskope adjacent Sits in the same secure-web and data-loss budget line Aurascape's own market page says the product is additive to. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.

Add analyzed competitors to compare them side by side with Aurascape.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 14 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

Aurascape keeps a catalog of more than twenty thousand AI applications, each carrying a decoder and a risk score, and its team states a 48-hour target for covering the vast majority of AI applications. The platform decodes AI traffic with that catalog, and Aurascape argues that firewalls and secure-web tools cannot read the same traffic. Matching the catalog would cost a rival the same daily engineering. By Aurascape's own market page, Zscaler discovers AI applications through its existing shadow-IT framework and announced an MCP gateway in early 2026. The same page positions Aurascape as running alongside Zscaler rather than replacing it. A probe of the public surfaces found no SOC 2 or ISO 27001 attestation.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Aurascape delivers software the customer's own team operates, a cloud proxy and an endpoint client with policies the organization configures, sold as a multi-year subscription. The reviewed sources describe no managed service and no expertise layer blended into the delivery.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Routing AI traffic through the inline proxy, rolling the endpoint client across a fleet, and tuning per-organization classifiers make leaving a re-integration and re-tuning project, which is real friction short of a lock. The cited record does not size the migration, and Aurascape's own market page describes the product as additive with no rip-and-replace.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 A probe of the public surfaces on 2026-08-29 found no SOC 2 or ISO 27001 attestation for Aurascape, and the obligations its case studies cite, NCUA guidance and the Gramm-Leach-Bliley Act, bind the customer rather than binding that customer to this vendor. A funded competitor could reach the same posture through ordinary enterprise-market preparation.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Decoding prompt and response traffic inline across more than 20,000 AI applications and several media formats, holding streaming protocols open without buffering developers' sessions, and governing live agent tool calls is real-time traffic engineering under adversarial pressure. The AuraLabs agent-vulnerability disclosures show the team working at that edge.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 The evidenced buyers are procurement-gated organizations: The Police Credit Union is documented preparing for National Credit Union Administration examination, three case studies describe Fortune 500 enterprises in insurance, financial services, and healthcare technology, and the stated target verticals are finance, healthcare, and retail. That evidence is Aurascape's own publication rather than independent reporting.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 The proxy and the MCP gateway form a control layer that AI traffic and agent tool calls route through, which is more than an application for one use case. The reviewed sources show no other software depending on Aurascape to function, and its own market page describes the product as an additive overlay a buyer runs beside an existing stack.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 2/3 Aurascape's engineering post names a retained asset, a database of more than 20,000 catalogued AI applications each carrying a decoder implementation and a risk characterization, built by the company's own discovery bots from web crawling and API feeds and extended daily. It accrues to the vendor rather than sitting in per-tenant custody, the reviewed sources do not show it published or duplicated by a public catalog, and a funded rival could rebuild it with the same daily engineering, which is a matter of time rather than the catalog being public.
Strategic Market Segmentation Aurascape sells to enterprise security and compliance leaders carrying two exposures at once, employees sending sensitive material into AI apps nobody sanctioned and internal teams wiring AI agents into business systems…

Aurascape sells to enterprise security and compliance leaders carrying two exposures at once, employees sending sensitive material into AI apps nobody sanctioned and internal teams wiring AI agents into business systems. At launch the company told BankInfoSecurity its near-term goal was 25 enterprise customers across finance, healthcare, and retail, on multi-year subscriptions. The buyers it has since published match that aim.

Those buyers are regulated and data-sensitive. A case study documents The Police Credit Union governing AI use against NCUA guidance and the NIST AI Risk Management Framework, and three more describe Fortune 500 enterprises in insurance, financial services, and healthcare technology. The homepage publishes image alt text naming eighteen organizations, among them two credit unions, a transit agency, and a university.

The segmentation bet is scope. Aurascape addresses both the employees who use AI and the teams who build it, which widens the addressable budget and asks a governance owner and an engineering owner to buy one platform.

Product Capabilities & AI Advantages The core capability is decoding AI traffic while it moves…

The core capability is decoding AI traffic while it moves. Menlo Ventures describes a cloud-native inline proxy paired with an endpoint agent that decodes more than 1,500 applications and captures activity across text, audio, image, and code, and Khan told BankInfoSecurity that the endpoint client redirects only AI-related traffic to the cloud platform for real-time inspection and enforcement.

Aurascape's own engineering post puts current coverage at more than 20,000 catalogued AI applications as of June 2026, each carrying a decoder implementation and a risk characterization, extended daily by automated discovery bots that crawl the web and pull API feeds from app catalog sites, under a stated 48-hour target that the company scopes to the vast majority of AI applications and not to all of them. That catalog is the working asset behind every discovery and policy claim, and keeping it current is a permanent engineering cost rather than a shipped feature.

The agent side extends the same position to what agents do. The platform maps MCP servers, tool connections, and data flows, stress-tests agents with simulated prompt injection and jailbreak attempts before release, and enforces policy on the model conversation and on gateway-routed tool calls. The company also runs its own offensive research, with its AuraLabs team disclosing a zero-click prompt-injection takeover in Meta's Manus agent through a coordinated window that closed in February 2026.

Two limits sit on the agent claim. Aurascape names the control point the Zero-Bypass MCP Gateway, while its own March 2026 announcement describes that gateway combined with its AI proxy as identifying risky MCP activity visible to the platform and reducing bypass risk across agent interactions, which is a narrower promise than the name carries. Depth otherwise rests on the company's own account, since the one third-party technical write-up in the record, an NSFOCUS analysis of the vendor's pages, concludes that real-world validation is still needed.

Sales Engagement & Go-to-Market The motion is direct enterprise sales funded ahead of any disclosed revenue…

The motion is direct enterprise sales funded ahead of any disclosed revenue. No free tier or self-serve sign-up appears on the reviewed pages, and Khan told BankInfoSecurity the near-term plan was 25 enterprise customers in finance, healthcare, and retail on multi-year subscriptions, and a recurring-revenue target of 10 to 15 million dollars within two years.

The published customer record is now substantial and it is entirely Aurascape's. Four case studies describe deployments, one naming The Police Credit Union and three describing unnamed Fortune 500 enterprises at more than 30,000 users, more than 15,000 developers, and more than 60,000 users. The homepage publishes image alt text naming eighteen organizations, one of which is Auradine, the portfolio company Mayfield describes Aurascape as spinning out of, so one published customer name is the company Aurascape came out of. The homepage testimonials pair speakers with titles rather than employers apart from the WinWire Technologies quote.

Awareness leans on backing and recognition rather than reported adoption. RSA Conference named Aurascape one of ten Innovation Sandbox finalists in April 2025, its analyst-coverage page reports a Gartner listing as a sample vendor in AI usage control, and the launch drew coverage in SecurityWeek, SiliconANGLE, and BankInfoSecurity. None of those sources reports a customer or a deployment, and the chief revenue officer appointed in August 2026 is the company's own account of a year of growth.

Pricing Model Aurascape publishes no pricing…

Aurascape publishes no pricing. The /pricing path returns 404, and the reviewed sources do not state the unit the company charges by, whether per user, per traffic volume, or per agent.

The one pricing signal in the record is structural. Launch coverage records that the company set retention targets for multi-year subscriptions, so revenue is recurring. Nothing public indicates how Aurascape prices agent-side usage, where consumption varies with agent activity rather than headcount.

Product Delivery & Operations Delivery is a cloud service with an endpoint component…

Delivery is a cloud service with an endpoint component. Aurascape pairs a cloud-native inline proxy with an endpoint client that redirects only AI-related traffic to its cloud platform, so a deployment touches both network routing and device fleets. A financial services case study records the product deployed alongside the firm's existing secure-service-edge stack, carrying AI traffic only.

The heavier operating load sits with the vendor. Decoding more than 20,000 AI applications works only while the decoders track those applications as they change, which Aurascape handles with automated discovery bots and a daily addition of new applications with their decoders and risk characterizations. For the customer, the visible work is routing AI traffic through the proxy, rolling out the endpoint client, and tuning policy to roles and data.

Earning Customers' Trust Aurascape's public trust collateral lags what it sells…

Aurascape's public trust collateral lags what it sells. A probe of its public surfaces found the trust and security subdomains failing DNS against a nonsense control subdomain that failed the same way, the /trust and /pricing paths returning 404, the /security path serving an image file, and no compliance badge filename in the homepage markup. The reviewed sources record no SOC 2 or ISO 27001 report for the company.

The company's visible security credibility is its research instead. Its AuraLabs team published a coordinated disclosure of a zero-click agent takeover in Meta's Manus agent, reported to that vendor in September 2025 and published in February 2026, which shows engineering depth and does not speak to how Aurascape handles customer traffic.

On the buyer-facing side, trust is part of the pitch. The Police Credit Union case study is built around examiner-ready evidence and controls mapped to NCUA guidance and the NIST AI Risk Management Framework, so the product sells compliance readiness to its customers while the reviewed record documents none of the company's own certifications.

Platform Strategy & Ecosystem Positioning Aurascape positions itself beside the incumbents rather than against them…

Aurascape positions itself beside the incumbents rather than against them. Its own market page states the product runs alongside an existing secure-service-edge platform such as Zscaler rather than replacing it, and describes itself as additive to existing secure-web, cloud-access, and data-loss tools with no rip-and-replace. That lowers adoption friction and leaves the network position with vendors already in the path.

The platform hooks it is building are agent-era control points. The Zero-Bypass MCP Gateway sits on the tool-call channel and an AI proxy on the model channel, and if agent traffic settles on the Model Context Protocol, holding a policy-enforcing checkpoint there is a real position. The same market page records the threat to it, noting that Zscaler discovers AI applications through its existing shadow-IT framework and announced an MCP gateway in early 2026.

Team & Execution Capability The founding team is public and senior…

The founding team is public and senior. The company page names Moinul Khan as CEO, Patrick Xu as CTO, Viswesh in product management, and Liang Li in engineering under leadership, lists Rajiv Khemani separately as a co-founder and board member, and Mayfield's seed announcement names six people it partnered with, including Rajiv Khemani, and describes Aurascape as a spin-out from its portfolio company Auradine.

The senior experience the independent record documents belongs to the chief executive. BankInfoSecurity reports that Khan spent nearly six years at Zscaler, ending with three years leading its SSE and data protection business, after four and a half years in product management at Palo Alto Networks and 18 months at Netskope. It names no product he built. Mayfield credits the six people it names as the team it partnered with, saying they built products that generated over 10 billion dollars in revenue, and it names none of those products.

The company page lists a marketing lead and a sales lead beside the founders, and Aurascape announced Jim Walsh as chief revenue officer on August 3, 2026. Former Palo Alto Networks CEO Mark McLaughlin sits as a board observer, and the company page lists CISOs at AT&T and Mastercard and a Databricks CIO as advisors, which is advisory standing rather than operating leadership or customer proof.

Sources

Company Detail Sources (4)
Id Source Tier Accessed
f1 Aurascape: A Security Platform Purpose-Built for the AI Era official 2026-08-29
f2 SiliconANGLE: Aurascape launches with $50M in funding to bring security and observability to AI apps press 2026-08-29
f3 Aurascape Launches from Stealth with $50M in Funding official 2026-08-29
f4 Menlo Ventures: Investing in Aurascape, Building the Security Stack for the AI Era press 2026-08-29
Profile Analysis Sources (23)
Id Source Tier Accessed
s1 Aurascape: Product, A Security Platform Purpose-Built for the AI Era
“Aurascape gives enterprises real-time visibility, classification, and control over every AI interaction—so they can adopt AI with confidence and without risk.”
official 2026-08-29
s2 Aurascape: Built for the Age of AI (company page)
“Rajiv Khemani Co-Founder & Board Member of Aurascape”
official 2026-08-29
s3 Aurascape: The AI Security Company (homepage)
“Book a Demo”
official 2026-08-29
s4 SiliconANGLE: Aurascape launches with $50M in funding to bring security and observability to AI apps
“A report from market analyst McKinsey & Company revealed that employees are three times more likely to use generative AI in their work than industry leaders expect.”
press 2026-08-29
s5 SecurityWeek: Aurascape Banks Hefty $50 Million to Mitigate 'Shadow AI' Risks
“Silicon Valley startup Aurascape has emerged from a year-long stealth phase with $50 million in funding from Menlo Ventures and Mayfield Fund and ambitious plans to solve the “shadow AI” security problem.”
press 2026-08-29
s6 BankInfoSecurity: Aurascape Takes On AI Data Protection With $50M in Funding
“Existing firewall and proxies cannot do content inspection on WebSocket protocol," said CEO Moinul Khan.”
press 2026-08-29
s7 Menlo Ventures: Investing in Aurascape, Building the Security Stack for the AI Era
“Aurascape’s approach is prevention-first: a cloud-native, inline proxy paired with an endpoint agent that can decode 1,500+ applications and detect risky AI behavior in real-time, with minimal false positives.”
press 2026-08-29
s8 RSA Conference: Finalists Announced for 20th Annual RSAC Innovation Sandbox Contest 2025
“The Top 10 Finalists will present a three-minute pitch and participate in a question-and-answer round as they battle on stage for the title of “Most Innovative Startup.””
press 2026-08-29
s9 Aurascape analyst-coverage page: Gartner Hype Cycle for AI Governance Technologies, 2026
“Aurascape is listed as a Sample Vendor in the AI Usage Control category of the Gartner® Hype Cycle® for AI Governance Technologies, 2026.”
official 2026-08-29
s10 Aurascape case study: The Police Credit Union AI compliance deployment
“Staff use approved AI tools to work faster, and the credit union keeps examiner-ready evidence that AI is being used responsibly.”
official 2026-08-29
s11 Aurascape trust probe 2026-08-29 (curl, DNS, markup grep): trust. and security. DNS-fail vs a control, /trust /pricing 404, /security is a PNG official 2026-08-29
s12 Aurascape blog: AI Application Discovery, coverage and deployment velocity
“Discovery Bot Identify new AI applications across the web • Web crawling • API feed integration from app catalog sites”
official 2026-08-29
s13 NSFOCUS: RSAC 2025 Innovation Sandbox analysis of Aurascape
“Its solutions are forward-looking in design philosophy, but further observation is needed in terms of cross-industry adaptation, real-world validation, and model interpretability.”
press 2026-08-29
s14 Aurascape news: Jim Walsh named Chief Revenue Officer
“SANTA CLARA, Calif., August 3, 2026 – Aurascape, the enterprise AI security company, today announced the appointment of Jim Walsh as Chief Revenue Officer.”
official 2026-08-29
s15 Aurascape news: Launch from stealth with $50M in funding
“Yet executives underestimate by up to 300% the actual extent of employees’ use of third-party, and often unsanctioned, AI apps, creating hidden risks known as “shadow AI.” Additionally, one in three employees report paying out-of-pocket for at least one AI app.”
official 2026-08-29
s16 Aurascape case study: a Fortune 500 insurer securing data and agents
“Prove it all: keep audit-ready records of every AI interaction, showing what data was involved, what policy applied, and what happened next.”
official 2026-08-29
s17 Aurascape market page: The AI Security Landscape in 2026, vendors and categories
“Aurascape spans all four groups on one platform, covering both waves of AI adoption: the AI employees use, and the AI teams build.”
official 2026-08-29
s18 Aurascape news: Zero-Bypass MCP Gateway and platform expansion for enterprise agents
“Aurascape combines its MCP Gateway with its AI Proxy to help organizations govern trusted tool use, identify risky MCP-related activity visible to the platform, and reduce bypass risk across agent interactions.”
official 2026-08-29
s19 Aurascape case study: AI coding assistants at a Fortune 500 financial services firm
“Alongside existing SASE, AI traffic only”
official 2026-08-29
s20 Aurascape case study: unsanctioned AI at a Fortune 500 healthcare technology enterprise
“Unsanctioned AI access fell to near zero while governed AI use grew to 60,000+ users worldwide.”
official 2026-08-29
s21 Aurascape AuraLabs research: SilentBridge, zero-click agent takeover in Meta Manus
“2025‑09‑18 – Initial report sent to Manus security team.”
official 2026-08-29
s22 Mayfield: Partnering with Aurascape.ai to Transform Cybersecurity for Generative AI
“I’m delighted to announce Mayfield is leading an oversubscribed $12.8M seed investment in Aurascape AI (a spin-out from our portfolio company Auradine).”
press 2026-08-29
s23 Aurascape: Secure Agentic AI solution page
“Aurascape governs agent activity through the Zero-Bypass Agent Gateway, enforcing policy across the model conversation and gateway-routed tool execution before tool actions reach external systems.”
official 2026-08-29
Deep-Dive Sources (22)
Id Source Tier Accessed
s1 Aurascape: Product, A Security Platform Purpose-Built for the AI Era
“Aurascape gives enterprises real-time visibility, classification, and control over every AI interaction—so they can adopt AI with confidence and without risk.”
official 2026-08-29
s2 Aurascape: The AI Security Company (homepage)
“Book a Demo”
official 2026-08-29
s3 Aurascape: Built for the Age of AI (company page)
“Rajiv Khemani Co-Founder & Board Member of Aurascape”
official 2026-08-29
s4 SiliconANGLE: Aurascape launches with $50M in funding to bring security and observability to AI apps
“A report from market analyst McKinsey & Company revealed that employees are three times more likely to use generative AI in their work than industry leaders expect.”
press 2026-08-29
s5 SecurityWeek: Aurascape Banks Hefty $50 Million to Mitigate 'Shadow AI' Risks
“Silicon Valley startup Aurascape has emerged from a year-long stealth phase with $50 million in funding from Menlo Ventures and Mayfield Fund and ambitious plans to solve the “shadow AI” security problem.”
press 2026-08-29
s6 Menlo Ventures: Investing in Aurascape, Building the Security Stack for the AI Era
“Aurascape’s approach is prevention-first: a cloud-native, inline proxy paired with an endpoint agent that can decode 1,500+ applications and detect risky AI behavior in real-time, with minimal false positives.”
press 2026-08-29
s7 Mayfield: Partnering with Aurascape.ai to Transform Cybersecurity for Generative AI
“I’m delighted to announce Mayfield is leading an oversubscribed $12.8M seed investment in Aurascape AI (a spin-out from our portfolio company Auradine).”
press 2026-08-29
s8 BankInfoSecurity: Aurascape Takes On AI Data Protection With $50M in Funding
“Existing firewall and proxies cannot do content inspection on WebSocket protocol," said CEO Moinul Khan.”
press 2026-08-29
s9 Aurascape case study: The Police Credit Union AI compliance deployment
“Staff use approved AI tools to work faster, and the credit union keeps examiner-ready evidence that AI is being used responsibly.”
official 2026-08-29
s10 Aurascape news: Zero-Bypass MCP Gateway and platform expansion for enterprise agents
“Aurascape combines its MCP Gateway with its AI Proxy to help organizations govern trusted tool use, identify risky MCP-related activity visible to the platform, and reduce bypass risk across agent interactions.”
official 2026-08-29
s11 Aurascape analyst-coverage page: Gartner Hype Cycle for AI Governance Technologies, 2026
“Aurascape is listed as a Sample Vendor in the AI Usage Control category of the Gartner® Hype Cycle® for AI Governance Technologies, 2026.”
official 2026-08-29
s12 Aurascape market page: The AI Security Landscape in 2026, vendors and categories
“Aurascape spans all four groups on one platform, covering both waves of AI adoption: the AI employees use, and the AI teams build.”
official 2026-08-29
s13 Aurascape: Secure Agentic AI solution page
“Aurascape governs agent activity through the Zero-Bypass Agent Gateway, enforcing policy across the model conversation and gateway-routed tool execution before tool actions reach external systems.”
official 2026-08-29
s14 Aurascape trust probe 2026-08-29 (curl, DNS, markup grep): trust. and security. DNS-fail vs a control, /trust /pricing 404, /security is a PNG official 2026-08-29
s15 Aurascape AuraLabs research: SilentBridge, zero-click agent takeover in Meta Manus
“2025‑09‑18 – Initial report sent to Manus security team.”
official 2026-08-29
s16 Aurascape blog: AI Application Discovery, coverage and deployment velocity
“Discovery Bot Identify new AI applications across the web • Web crawling • API feed integration from app catalog sites”
official 2026-08-29
s17 Aurascape case study: AI coding assistants at a Fortune 500 financial services firm
“Alongside existing SASE, AI traffic only”
official 2026-08-29
s18 Aurascape case study: unsanctioned AI at a Fortune 500 healthcare technology enterprise
“Unsanctioned AI access fell to near zero while governed AI use grew to 60,000+ users worldwide.”
official 2026-08-29
s19 Aurascape case study: a Fortune 500 insurer securing data and agents
“Prove it all: keep audit-ready records of every AI interaction, showing what data was involved, what policy applied, and what happened next.”
official 2026-08-29
s20 RSA Conference: Finalists Announced for 20th Annual RSAC Innovation Sandbox Contest 2025
“The Top 10 Finalists will present a three-minute pitch and participate in a question-and-answer round as they battle on stage for the title of “Most Innovative Startup.””
press 2026-08-29
s21 Aurascape news: Jim Walsh named Chief Revenue Officer
“SANTA CLARA, Calif., August 3, 2026 – Aurascape, the enterprise AI security company, today announced the appointment of Jim Walsh as Chief Revenue Officer.”
official 2026-08-29
s22 NSFOCUS: RSAC 2025 Innovation Sandbox analysis of Aurascape
“Its solutions are forward-looking in design philosophy, but further observation is needed in terms of cross-industry adaptation, real-world validation, and model interpretability.”
press 2026-08-29

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.