All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This analysis is scoped to Kong AI Gateway (Kong Inc.'s AI-security product line).
Kong is a profitable infrastructure company with more than 700 enterprise customers, so a buyer reads the AI Gateway as backed by a fortress. Scored on its own, the governance product is about as exposed as a venture-stage rival, because the Kong API gateway underneath is what a rival cannot copy, not the AI plugins on top. Removing the prompt guards and PII sanitization leaves the API gateway running, and a cloud or model platform that already carries AI traffic can build the same allow lists and redaction. What the line keeps is a low-cost path to enterprises that already run Kong, where adding AI governance is a plugin install rather than a new vendor decision. The moat is the installed gateway, and the AI capability rides it.
| Description | Kong AI Gateway is a gateway that governs how developers, apps, and agents consume LLMs, MCP servers, and other agents, controlling access, data leakage, and token usage. | [f1] |
|---|---|---|
| Funding | $345M total | [f2] |
| Latest funding | Series E, $175M at a $2B valuation (Nov 2024) | [f2] |
| Deployment | Hybrid, SaaS, Self-hosted | [f3] |
| Product | What it does |
|---|---|
| Kong | AI gateway that proxies traffic to many LLM providers and governs it with prompt guards, PII sanitization, and content-safety policies that screen requests and responses. |
| Konnect Metering and Billing | Usage-based metering and billing for APIs, AI tokens, and data streams in Kong Konnect, built on the acquired OpenMeter platform. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Kong is an AI gateway that proxies traffic to many LLM providers and governs it with prompt guards, PII sanitization, and content-safety policies that screen requests and responses. It is mapped to the AI Defense Matrix. [f4]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Kong names the buyer (enterprises moving AI into production) and concrete pain (token spend, audit gaps, traffic visibility), but the pain is qualitative and the corroboration is a single launch-coverage press source, short of quantified pain across multiple independent sources. [s1, s5] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | The AI Gateway carries a developer documentation portal and named controls (semantic prompt guard, PII sanitization across 20 categories, Agent Gateway), but the line's evidence is vendor docs plus launch announcements with no independent benchmark or third-party evaluation, so the depth is concrete without external validation. [s2, s4, s5] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | The Kong AI Gateway is the timing bet, shipping security guardrails in the 2025 3.10 release and agent-to-agent governance in the 2026 3.14 release, but the cited signals are Kong's own launches and the press covering them, vendor shipping rather than independent buyer-side demand. [s5, s4, s1] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | Co-founders Augusto Marietti and Marco Palladino built Kong itself, the current company in the adjacent API-connectivity market, which is verifiable execution but not a prior separate in-domain exit or publication record, so it fits 3 rather than 4. [s6, s3] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 | The AI line surfaces little customer-specific traction in the cited record and the 700-plus enterprises (GSK, PayPal, NYSE) are whole-company figures, so the score depends on a small indirect-signal bump for that installed-base distribution rather than line traction, which holds it at 3 not 4. [s3, s1] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | No line-level capital, revenue, or margin appears for the AI Gateway, and Kong's whole-company profitability cannot confirm the line's own output per dollar, so with visible shipping but unconfirmed line efficiency the honest read is 3. [s6, s3, s9, s10] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 | Kong and its rivals frame the product as an AI gateway governing LLM, MCP, and agent traffic, but that category is still forming and the placement rests on vendor framing plus launch press without independent buyer or analyst language, which fits 3. [s1, s5] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 2/5 | The AI line's controls are absorbable by cloud and model platforms that already sit in front of AI traffic, a plausible bundled feature, and Kong's installed API-gateway base is distribution reach in a different category rather than a moat in AI security, which places the line at 2. [s1, s5] |
Kong sells the AI Gateway to enterprises that are moving AI from pilots into production and need to control the traffic. The company frames the buyer as engineering and platform teams who lack full visibility into AI usage and resource consumption, struggle to control token spend, and cannot maintain audit trails across agent workflows. The product sits between applications and model providers so that access, data leakage, and token usage become governed in one place.
Press coverage corroborates that the pain exists at enterprise scale. Reporting on the Agent Gateway launch described businesses moving AI systems from pilot projects into production and facing growing pressure to monitor usage, control costs, and maintain audit trails across increasingly complex workflows. That framing comes from trade press rather than Kong's marketing, which is stronger evidence that buyers are searching for the capability.
The asset under management is the AI request and the agent interaction. Kong governs how developers, apps, and agents consume LLMs, and the more recent Agent Gateway extends that to traffic between agents, so the boundary the product addresses is the point where prompts, responses, and agent actions meet privileged model access. [s1, s5]
The Kong AI Gateway is a governance layer built on top of Kong's existing API gateway, with named controls rather than marketing generalities. The documentation describes a semantic prompt guard that builds allow and deny lists of topics across every LLM, and a PII sanitization plugin that detects and redacts sensitive data across 20 categories and several languages and most major AI providers. A public documentation portal lets a buyer inspect how each control works.
Kong has extended the product from model traffic to agent traffic over successive releases. The April 2025 release focused on LLM-level governance, including the PII sanitization plugin and automated retrieval pipelines aimed at reducing hallucinations, and the April 2026 Agent Gateway release added governance of agent-to-agent communication alongside LLM and Model Context Protocol traffic. That progression tracks the market's shift from single model requests toward multi-step agent interactions.
What the public record does not yet include is independent validation of how well these controls perform. The capability is documented and specific, but the evidence is Kong's own documentation and launch announcements rather than a third-party benchmark or a customer technical writeup, which is the checkpoint that would lift the depth further. [s2, s4, s5]
Kong competes for the AI-governance buyer against specialist AI-gateway startups and the platforms that already carry AI traffic. Pure-play vendors such as Portkey, BerriAI, and NeuralTrust pair a gateway with guardrails and multi-LLM routing, overlapping Kong's runtime governance. On the other side, cloud and model platforms that sit in front of AI traffic can bundle the same screening and routing into their own offerings.
Kong's differentiator is the installed base its rivals lack, since the AI Gateway layers onto the API gateway that more than 700 enterprises already run. For a company already operating Kong, adding AI governance is a plugin on infrastructure it already maintains rather than a new vendor decision, which is a distribution advantage a standalone tool cannot easily copy. That same advantage is what the company is betting its repositioning on.
The structural question is whether buyers treat AI governance as part of their connectivity layer or as a separate purchase. If they keep the same control point for API, LLM, and agent traffic, Kong extends a durable position, and if they split the purchase, the AI line faces specialist rivals and platform bundling without the installed-base protection. [s1, s5, s3]
Kong's strongest go-to-market signal for the AI line is distribution rather than a named AI customer. The AI Gateway ships into an installed base of more than 700 enterprises that Kong reports for the whole company, including GSK, PayPal, and NYSE, and into a paid sales motion that already passed 100 million dollars in recurring revenue. A new product reaching that base starts from a different place than a startup hunting for its first deployment.
The whole-company figures are real and third-party reported but do not measure the AI Gateway by itself. The Stack reported the revenue, profitability, and customer count around Kong's November 2024 financing, and none of that coverage separates AI Gateway adoption from API gateway adoption. The 700 customers and the recurring revenue describe Kong, not the AI line, so they support distribution potential rather than proven AI-line traction.
The gap the public record leaves is AI-line depth: the cited record carries little customer-specific traction for the AI Gateway and no AI-line revenue figure. Until Kong reports how many of its enterprises run the AI Gateway and what the line earns, the traction case depends on the installed base and the credibility of the company carrying it, which is why the indirect signal lifts but does not max the go-to-market score. [s3, s1]
Kong's founders have already built one large company in the market adjacent to AI connectivity. Augusto Marietti, the CEO, and Marco Palladino, the CTO, founded Kong and grew it from an open-source API gateway into a business that passed 100 million dollars in recurring revenue, reached profitability, and raised at a 2 billion dollar valuation. That is a verifiable prior build at scale, not a plausible background.
The proven execution is in API connectivity rather than AI security specifically. The team's record demonstrates that it can ship infrastructure software and sell it to large enterprises, which is the harder part of the AI Gateway motion, and the AI-security capability is the newer addition layered on that base. Recording the founders' track record as a structural factor for the AI line keeps the credit honest about what it does and does not prove.
The investor base reinforces the operating credibility. Kong's Series E drew Tiger Global and Balderton alongside continued support from earlier backers, and the round was an up-round at a higher valuation, which is external validation of the company carrying the AI line even though it does not speak to the AI product directly. [s6, s3]
Kong positions the AI Gateway as a governance and control product, so assurance is the value proposition rather than an afterthought. The product controls access, data leakage, and token usage for how developers, apps, and agents consume LLMs, and the PII sanitization plugin lets platform owners enforce data protection at the platform level instead of relying on each developer to code it. That posture targets the compliance and audit needs enterprises raise when moving AI into production.
The company behind the product carries enterprise-grade procurement weight. Kong is profitable, names large regulated enterprises such as GSK and a major financial exchange among its customers, and runs a mature sales and support organization, which resolves the vendor-viability questions a one-product startup would raise. A buyer evaluating the AI Gateway inherits that posture.
What a careful buyer still needs is evidence specific to the AI line. The trust story for the company is strong, but published security attestations, independent guardrail evaluations, or named AI Gateway references would close the distance between trusting Kong and trusting the AI governance product in particular. [s1, s3]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Portkey | competes with | Open-source AI gateway with guardrails and multi-LLM routing, now a Palo Alto Networks product line, overlapping Kong's gateway-plus-governance positioning for enterprise AI traffic. | N/AWe scored these companies at different scopes, so the totals measure different things. |
| BerriAI | competes with | Maker of the LiteLLM open-source AI gateway routing across many model providers with guardrails, contesting the same multi-LLM governance buyer Kong's AI Gateway targets. | N/AWe scored these companies at different scopes, so the totals measure different things. |
| NeuralTrust | competes with | AI gateway paired with guardrails and red teaming, overlapping Kong's runtime governance of LLM and agent traffic. | N/AWe scored these companies at different scopes, so the totals measure different things. |
| Prompt Security | competes with | Runtime LLM and agent guardrails vendor acquired by SentinelOne, competing on the prompt-screening and data-protection controls Kong's AI Gateway provides. | N/AWe scored these companies at different scopes, so the totals measure different things. |
Add analyzed competitors to compare them side by side with Kong Inc..
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
pivot urgently
Kong's durability for the AI Gateway comes from where it sits and who it reaches, not from anything the governance plugins hold. The line runs as an inline proxy on infrastructure regulated enterprises already operate, which gives it a hard engineering core and a serious buyer, and the self-hosted option answers data-residency concerns directly. It stays exposed on the assets a focused rival can match. The controls are configured allow lists and redaction patterns rather than a proprietary detection asset, no regulation forces the buyer to keep it, and the depended-on infrastructure is the API gateway underneath rather than the AI line. The moat is the parent gateway and the installed base it carries, with the AI capability replicable on its own.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Kong sells configured governance software, allow and deny lists, prompt guards, and PII redaction that the buyer turns on and trusts, rather than judgment or accountability delivered as a service. The buyer pays for features. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Replacing the AI Gateway means re-pointing LLM and agent traffic and re-tuning the configured policies, which is meaningful friction from learned configuration and integrations. Removing it leaves the underlying API gateway running, so the friction is the policy layer rather than a whole platform. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | No regulation or certification regime in the cited record forces a buyer to keep an AI-gateway product, and the fetched pricing evidence ties no security attestation to the AI Gateway line itself. Nothing in the record raises a compliance barrier to switching away. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Inspecting natural-language prompts inline at production latency while proxying across many model providers, with token-based rate limiting and semantic caching, is real-time-systems engineering that takes specialized expertise to build well. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | The cited record names no AI Gateway line customer, and the fetched pricing page offers Start for Free and Buy with AWS self-service paths alongside enterprise plans, so the line's evidenced buyer motion is mixed rather than procurement-gated. Parent-level enterprise rosters do not transfer to the line. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | The AI Gateway is the governance layer of plugins on top of Kong's gateway, a platform with application features rather than the infrastructure other applications depend on, because removing the AI plugins leaves the API gateway working. The infrastructure credit belongs to the parent gateway. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The detection runs on configured allow and deny lists and PII redaction patterns, and the public record shows no proprietary attack corpus or model that Kong alone holds. A rival could reproduce the capability by writing similar plugins. |
Kong aims the AI Gateway at enterprises moving AI from pilots into production that need one control point for model and agent traffic. The product page frames the buyer as engineering and platform teams who must govern how developers, apps, and agents consume LLMs, controlling access, data leakage, and token usage in one place. That is the same platform-owner buyer who already runs an API gateway, not a new audience Kong has to find.
The named customers describe regulated, high-stakes enterprises. The Stack reports more than 700 enterprise customers including GSK, PayPal, and NYSE, a pharmaceutical company and a financial exchange. The coverage names them at the company level rather than as AI Gateway users, so these figures describe the segment Kong can reach rather than the segment that has bought the AI line.
Kong's clearest segmentation opening is to sell the AI Gateway into its existing footprint, though the cited sources do not document an actual installed-base-first sequencing choice. For a company already operating Kong, AI governance is an extension of infrastructure the platform team maintains, which narrows the target to organizations that have already standardized on Kong and want to keep one control plane as they add model traffic.
The Kong AI Gateway is a set of governance plugins on Kong's data plane, with named controls rather than marketing generalities. The documentation describes built-in PII sanitization that detects and redacts sensitive data across 20 categories and 9 languages, running privately and self-hosted, and the plan listing names prompt guardrails and LLM access control that screen requests across model providers. A buyer inspects each control through a public documentation portal.
Kong has extended the product from model traffic to agent traffic across releases. Press coverage of the Agent Gateway launch describes it giving engineering teams a single place to govern AI traffic across LLM, Model Context Protocol, and agent-to-agent communication. That progression tracks the market shift from single model requests toward multi-step agent interactions, and it widens the surface the product governs.
The capability rests on configuration rather than a proprietary detection asset. The documentation describes governance through allow and deny lists, redaction patterns, and routing policies that the buyer configures and trusts, and the public record shows no proprietary attack corpus or model that Kong alone holds. The depth is real and inspectable, and a well-funded competitor could reproduce it by writing similar plugins, which is the structural ceiling on this advantage.
Kong's go-to-market for the AI line runs through the installed API-gateway base rather than a separate AI sales motion. The AI Gateway ships into customers that already run Kong, and the pricing page bundles AI Gateway features into the Konnect plans a buyer is already on, so reaching the AI buyer does not require a new vendor relationship. That installed base is a parent distribution channel the AI line rides, not proof the AI line itself has won buyers, and it is the reach a standalone tool cannot copy by writing software.
The public traction evidence measures the company, not the AI Gateway. The Stack reported the recurring revenue, profitability, and 700-customer count, and none of that coverage separates AI Gateway adoption from API gateway adoption. The 700 customers and the recurring revenue describe Kong as a whole, so they support distribution potential for the AI line rather than proven AI-line demand.
The gap the record leaves is a named AI Gateway customer and an AI-line revenue figure. Until Kong reports how many of its enterprises run the AI Gateway and what the line earns, the go-to-market case depends on the installed base and the credibility of the company carrying it, not on dated proof that buyers are choosing the AI Gateway specifically.
Kong publishes pricing for the platform that carries the AI Gateway, and it folds the AI line into existing plan tiers rather than charging for it separately. The pricing page lists AI Gateway features inside the Konnect Plus tier, which is charged per gateway per month, including a universal LLM API across up to 5 models, MCP server proxies, PII sanitization, prompt guardrails, and token-based rate limiting with semantic caching.
The charging unit reveals what Kong believes the buyer pays for. Konnect Plus bills by the gateway, the runtime control point, which signals that the buyer pays for a governed traffic plane rather than per seat or per AI feature. The AI-specific cost controls inside the plan, token-based rate limiting and token-level tracking, align the product with how buyers measure AI spend.
The published price covers the lower tier, and the enterprise motion stays negotiated. The Plus plan is self-serve with a public rate, while larger deployments route to sales, which fits a product sold into regulated enterprises that buy through procurement. The AI Gateway inherits this two-track model from the platform rather than carrying its own price.
The Kong AI Gateway runs wherever the Kong data plane runs, which lets the buyer keep AI traffic inside its own boundary. The documentation states that AI plugins are supported in all deployment modes, including Konnect, self-hosted traditional, hybrid, and DB-less, and on Kubernetes via the Kong Ingress Controller. A buyer can run the gateway privately and self-hosted, which the data governance documentation ties to full control and compliance.
The operational model is the same one Kong customers already run for API traffic. The AI Gateway is plugins on the existing gateway, so a team that operates Kong adds AI governance without standing up a new system, and the same declarative configuration and deployment topologies carry over. That reuse lowers the operational cost of adopting the AI line for an existing Kong operator.
The self-hosted and hybrid options matter particularly for the regulated buyers Kong targets. An enterprise that cannot send prompts and responses to a third-party SaaS can run the governance plane in its own environment, which removes a common blocker for AI adoption in pharmaceutical, financial, and government settings.
Kong positions the AI Gateway as a governance and control product, so assurance is the value proposition rather than an afterthought. The product controls access, data leakage, and token usage for how developers, apps, and agents consume LLMs, and the PII sanitization documented across 20 categories and 9 languages lets platform owners enforce data protection centrally instead of relying on each developer to code it.
The private deployment option is the strongest trust signal specific to the AI line. Because the gateway can run privately and self-hosted, an enterprise keeps prompts and responses inside its own environment, which the data governance documentation frames as full control and compliance. That answers the data-residency concern that blocks many AI deployments more directly than any attestation would.
What a careful buyer still needs is evidence specific to the AI line rather than the company. The public record carries no independent guardrail evaluation, no AI-Gateway-specific security attestation, and no named AI Gateway reference customer, so the trust case for the product itself rests on documented controls and the procurement weight of a profitable vendor rather than on third-party validation.
The AI Gateway's ecosystem advantage is that it is part of Kong's existing plugin platform, so AI routes inherit the gateway's toolset. The plan listing places the AI Gateway features inside the same plan that carries REST, gRPC, GraphQL, Kafka, and WebSocket support, so the auth, rate limiting, and routing that serve API traffic also serve LLM and agent routes on one control plane.
Kong reaches buyers through channels beyond its own sales team. The pricing page offers the Plus plan as a self-serve Start for Free option and through Buy with AWS, so a buyer can adopt the AI Gateway through infrastructure and procurement paths it already uses. That marketplace and multi-protocol reach is a distribution surface a single-purpose AI tool would have to build from scratch.
The ecosystem also covers the agent surface the market is moving toward. The product governs MCP servers and agent-to-agent traffic, extending the gateway from model calls to multi-agent workflows, which keeps the AI Gateway positioned at the connectivity layer as the unit of AI traffic shifts from a single request to a chain of agent interactions.
Kong's founders have already built one large company in the market next to AI connectivity. They grew Kong from an open-source API gateway into a business that passed 100 million dollars in recurring revenue and reached profitability, a verifiable prior build at scale rather than a plausible background. That record shows the team can ship infrastructure software and sell it to large enterprises.
The proven execution is in API connectivity rather than AI security specifically. The team's record demonstrates the harder part of the AI Gateway motion, shipping and selling enterprise infrastructure, while the AI-security capability is the newer addition layered on that base. Recording the founders' track record as a structural factor for the AI line keeps the credit honest about what it does and does not prove.
The company carries the organizational weight that the AI line inherits. Kong runs a mature sales and support organization and a documented platform, which resolves the vendor-viability questions a one-product startup would raise, so a buyer evaluating the AI Gateway inherits an established operator rather than betting on a new entrant.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Kong: Secure, Scalable AI Gateway for AI Connectivity | official | 2026-07-09 |
| f2 | Kong Secures $175 Million New Financing at $2B Valuation to Power the API World | press | 2026-06-21 |
| f3 | AI Defense Matrix Catalog entry | other | 2026-06-09 |
| f4 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Kong AI Gateway product page “Govern how developers, apps, and agents consume LLMs. Control everything from access, to data leakage, to token usage.” | official | 2026-06-14 |
| s2 | Kong AI Gateway documentation “Semantically and intelligently create allow and deny lists of topics that can be requested across every LLM. AI Gateway provides built-in PII sanitization, automatically detecting and redacting sensitive data across 20 categories and 9 languages.” | official | 2026-06-18 |
| s3 | The Stack on Kong's 175 million dollar Series E (November 2024) “passed $100 million in ARR – and also achieved profitability. It now names over 700 enterprise customers globally, including GSK, PayPal and NYSE.” | press | 2026-06-14 |
| s4 | Kong AI Gateway 3.10 next-gen capabilities, via PR Newswire (April 2, 2025) “a Personally Identifiable Information (PII) sanitization plugin which allows for the sanitization and protection of personal data, passwords, codes, and more than 20 categories of PII across 12 different languages.” | press | 2026-06-14 |
| s5 | IT Brief on Kong Agent Gateway in AI Gateway 3.14 (April 23, 2026) “Agent Gateway is intended to give engineering teams a single place to govern AI traffic across LLM, MCP and agent-to-agent communication.” | press | 2026-06-14 |
| s6 | Kong Series E financing announcement (November 19, 2024) “it has closed a $175 million in up-round Series E financing, with a mix of primary and secondary transactions at a $2 billion valuation. This brings Kong's total capital raised to $345 million.” | official | 2026-06-14 |
| s7 | Kong homepage, positioning as the AI Connectivity Company “Kong, The AI Connectivity Company” | official | 2026-06-14 |
| s8 | NVD CVE-2026-6338, HTTP request smuggling in Kong Gateway Enterprise (published June 11, 2026) “A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13, and 3.14 series.” | regulatory | 2026-06-30 |
| s9 | CB Insights company profile for Kong (Mashape Inc.) “$175M | 2 yrs ago” | research | 2026-06-30 |
| s10 | SEC EDGAR submissions record for Kong Inc. (CIK 1528548, formerly Mashape Inc.), listing Form D financing filings through August 2024 “"name":"Kong Inc."” | regulatory | 2026-06-30 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Kong AI Gateway product page “Govern how developers, apps, and agents consume LLMs. Control everything from access, to data leakage, to token usage.” | official | 2026-06-18 |
| s2 | Kong AI Gateway documentation “Yes, AI plugins are supported in all deployment modes, including Konnect, self-hosted traditional, hybrid, and DB-less, and on Kubernetes via the Kong Ingress Controller.” | official | 2026-06-18 |
| s3 | The Stack: API specialist Kong lands 175 million Series E “It now names over 700 enterprise customers globally, including GSK, PayPal and NYSE, among other blue chips.” | press | 2026-06-18 |
| s4 | Kong Konnect Plus pricing tier and AI Gateway features “Plus. Charged per Gateway per month. AI Gateway: Universal LLM API with up to 5 unique LLM models. Unlimited MCP server proxies. PII sanitization and prompt guardrails. LLM access control and auth. Cost Control: Token-based rate limiting and semantic caching. AI Observability: Token-level tracking.” | official | 2026-06-14 |
| s8 | Kong Konnect Plus protocol support and purchase channels “Start for Free. Buy with AWS. API, protocol, and service support: REST APIs, HTTP APIs, LLMs, Kafka, WebSockets, gRPC, GraphQL.” | official | 2026-06-14 |
| s5 | IT Brief: Kong launches Agent Gateway for multi-agent AI traffic “Agent Gateway is intended to give engineering teams a single place to govern AI traffic across LLM, MCP and agent-to-agent communication.” | press | 2026-06-14 |
| s6 | Kong AI Gateway data governance documentation “AI Gateway enforces governance on outgoing AI prompts through allow/deny lists. It also provides built-in PII sanitization, automatically detecting and redacting sensitive data across 20 categories and 9 languages. Running privately and self-hosted for full control and compliance.” | official | 2026-06-18 |
| s7 | The Stack: Kong passed 100 million ARR and reached profitability “the company, which last year passed $100 million in ARR, and also achieved profitability.” | press | 2026-06-18 |
| s9 | Kong corporate Trust Center “Kong's corporate Trust Center lists SOC 2 Type II, ISO 27001, and PCI DSS at the company level, not specific to the AI Gateway line.” | official | 2026-06-24 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.