All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Snowflake signed a definitive agreement to buy Natoma about two years after the company started in 2024, when the public record named one detailed customer, HPE. In that window a team of 27 people, per press reports, built a gateway that checks every AI agent tool call against Cedar access policies, discovers unsanctioned AI across an organization, and logs each action for audit. Its founder, Pratyus Patnaik, sold his prior startup, atSpoke, to Okta in 2021 for 79.3 million dollars. Press coverage reads the deal as a bet that enterprises will require centralized governance, identity controls, and auditability as AI agents reach internal applications. The main public evidence of demand is the buyer itself. A data-platform vendor agreed to acquire the gateway rather than compete with it.
| Description | Natoma is a governed MCP gateway that connects AI clients and agents to enterprise tools and centralizes identity-aware authorization over which tools each agent can use. | [f1] |
|---|---|---|
| Founded | 2024 | [f2] |
| HQ | San Francisco, California, United States | [f2] |
| Funding | $7M total | [f2] |
| Latest funding | Seed (May 2025), led by Index Ventures and Greylock | [f2] |
| Deployment | SaaS, Self-hosted | [f3] |
| Product | What it does |
|---|---|
| Natoma | Governed MCP gateway that treats AI agents as non-human identities, enforcing identity-aware authorization and per-tool policy over agent access to tools, with shadow-AI discovery and audit. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Natoma is a governed MCP gateway that treats AI agents as non-human identities, enforcing identity-aware authorization and per-tool policy over agent access to tools, with shadow-AI discovery and audit. It is mapped to the AI Defense Matrix. [f4]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Natoma names the enterprise security buyer and the agent-and-MCP visibility gap, and CIO and InfoWorld analysts corroborate the governance pain, but it stays qualitative with no independent quantification. [s2, s7, s8] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | The platform page details Cedar-based authorization, credential governance, audit, and SIEM integration, but the evidence offers no demo, open code, benchmark, or third-party technical evaluation, and the Snowflake acquisition validates market value rather than product depth. [s2, s15, s6] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | Enterprise adoption of MCP and the shadow-AI surge through 2025 created the tool-access risk Natoma governs, and CIO and InfoWorld quote analysts saying enterprises now need governed MCP to move agents into production. The enabler is the 2024 to 2025 spread of MCP as an agent-to-tool standard, and the window pressure is platform vendors absorbing this layer into suites buyers already hold. [s7, s8, s5] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | Co-founder and CEO Pratyus Patnaik sold a prior startup, atSpoke, to Okta in 2021 for 79.3 million dollars and was a senior director there, and the founding team came from Okta, Microsoft, Google, and Salesforce. That verifiable prior in-domain exit is a documented founder track record. [s6, s10, s11] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 | One named enterprise, HPE Networking, is on record with a CIO-quoted deployment, and Snowflake says the platform runs at some very large enterprises, but no revenue metric or broad customer roster is disclosed. A single named reference plus a pending acquisition beats investor signal alone yet falls short of the multi-customer traction a 4 needs, so the score holds at 3. See the calibration note: the new HPE customer story is a candidate for a future move to 4 once a second named reference appears. [s13, s14, s5] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 4/5 | A 7 million dollar seed produced a full governed-MCP platform, a 27-person team, and an acquisition agreement inside about a year, which is visible output per dollar at the early stage. The raise is sized to the motion and the shipping pace. [s6, s10, s2] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 | CIO, InfoWorld, and The Register place the governed-MCP gateway without coaching, but the agentic MCP-governance category itself is still forming through 2025 and 2026, which keeps it short of an established stack slot. [s7, s9, s5] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | MCP tool gating is the densest vendor cell in the agent-security landscape, and a data-platform vendor absorbed the capability outright, which is the bundling exposure a standalone offering carries. The identity-aware authorization depth and non-human-identity inventory raise replication cost but do not form a structural moat. [s9, s5, s2] |
Natoma sells to the enterprise security team that wants to deploy AI agents but cannot see or control what those agents reach for. The platform frames the problem as AI agents and MCP connections spreading across a company faster than security can track, including shadow AI that nobody approved, where an agent can touch production systems and expose data it was never meant to see.
Independent reporting corroborates the gap beyond vendor marketing. CIO and InfoWorld quote analysts who describe MCP as the connective tissue for enterprise agents that turns into shadow-AI risk without identity, policy, and auditability, and Snowflake built its acquisition rationale on the same need to govern what agents can do. The buyer pain is described by outside voices, not asserted by the vendor alone.
Natoma states the consequence in concrete terms. The vendor says agents should act with exactly the permissions of the person behind them, which is the control its authorization and discovery are meant to enforce before an agent runs loose inside core systems. [s7, s8, s1]
The Natoma platform centers on a governed gateway for the connections AI agents use to reach company tools. The product page describes identity-aware authorization, attribute-based policy that defines who can use which tools and under what conditions, managed or bring-your-own credentials, data filters, and context-aware enforcement keyed to user, group, device, and AI client.
The platform pairs that control layer with discovery and audit. Natoma describes finding and inventorying MCP connections across the organization, including unsanctioned shadow AI, plus a complete audit trail of tool access and integration with SIEM, EDR, and MDM systems. The platform page cites a verified library of thousands of MCP servers and granular authorization via Cedar, with support for custom servers across cloud, desktop, and self-hosted environments.
The acquisition itself is strategic validation by Snowflake, the pending acquirer, rather than an independent technical evaluation. Snowflake describes the MCP Gateway as unlocking centralized governance and says Natoma's platform is already deployed at some very large enterprises, an acquirer's endorsement of market value. Natoma also holds a granted patent in the category. The US Patent and Trademark Office granted Natoma Labs patent US 12,615,260 B1, titled System for managing non-human identities, in April 2026 on a January 2024 filing that names co-founder Pratyus Patnaik as inventor, and the analyst tracker CB Insights describes the platform as discovering, monitoring, and managing non-human identities such as service accounts, access tokens, and API keys. [s2, s15, s5, s16, s17]
Natoma competes for the governed-MCP layer against both startups and the platforms moving to own it. Other MCP-gateway companies cover the same tool-gating and governance stack for the enterprise buyer, while SaaS vendors and hyperscalers race to make themselves the orchestration and governance layer for enterprise agents, per analysts quoted by CIO. The analyst tracker CB Insights places Natoma in the non-human identity space and lists access-governance vendor ConductorOne among its competitors, which fits the identity-governance heritage the founding team brought from Okta.
Natoma's visible edge was a credible identity team and an early, clean entry into the category. Founders from Okta and other identity and cloud companies gave it standing, and a library of prebuilt MCP servers gave buyers a fast path to value. That head start is what a data-platform acquirer paid for.
The structural risk is who owns the buyer, and the pending Snowflake deal points against independence. A platform that already holds the enterprise's data is the natural owner of the agent's permissions too, and Snowflake acted on exactly that logic by signing a definitive agreement to buy Natoma rather than competing with it. [s7, s5, s9, s16]
Natoma's go-to-market leans on the agentic-AI wave and inbound interest, routing prospects to a demo request and building awareness through MCP content. The published proof now includes one named enterprise: HPE Networking CIO Venky Rangachari describes Natoma as the framework his team uses to inventory, qualify, secure, and manage agents end to end, starting with 500 ChatGPT users connected to Salesforce and Gong.
The buyer-side proof is decisive. Snowflake signed a definitive agreement to acquire the company about fourteen months after launch, and its own announcement says Natoma's platform is already deployed at some very large enterprises, so enterprise validation is arriving both as a reference customer and as an acquisition.
Investor conviction reinforces the picture. Index Ventures and Greylock led the 7 million dollar seed, and the founders' Okta exit gave the round senior pedigree. One named customer story is still thin proof of broad reach, but it moves the record past investor signal alone. [s13, s14, s5]
The founders pair identity-product experience with a prior exit in the same domain. Co-founder and CEO Pratyus Patnaik sold his earlier startup, atSpoke, to Okta in 2021 for 79.3 million dollars and then spent more than two years as a senior director at Okta before starting Natoma. Co-founders Paresh Bhaya, Will Potter, and Zachary Hart came from Okta, Microsoft, Google, and Salesforce.
That background sits directly under the product Natoma built. Authorization, credential governance, and non-human identity are the problems this team worked on at established identity and cloud companies, so the move into agent tool access is continuous with their prior work rather than a reach.
Greylock's Saam Motamedi and Index's Shardul Shah backed the company on that basis, framing non-human identities as a core part of the enterprise identity perimeter. The pedigree is verifiable through a named acquisition and named investors, not just titles. [s6, s10, s11]
Natoma publishes a trust center at natoma.ai/trust, hosted on Vanta, that lists SOC 2 compliance with a downloadable SOC 2 Type II 2025 report behind an access request, GDPR alignment, and CCPA compliance, and it states that penetration testing is performed. No ISO 27001 attestation appears. That collateral matters because the product sits in the path of agent access to sensitive systems, and the platform pairs it with the audit trails, identity-aware policy, credential governance, and SIEM integration a security buyer evaluates.
The pending acquisition reframes the readiness question. Snowflake plans to integrate the gateway into its governed data platform, so the trust story shifts from Natoma's standalone certifications to how Snowflake governs the capability at enterprise scale, a point CIO's analysts flagged as the real test. [s12, s2, s7, s1]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Aembit | competes with | Brokers non-human and agent credentials across clouds, SaaS, and on-prem, overlapping Natoma's identity-aware agent authorization. | |
| Astrix Security | competes with | Secures non-human identities and agent access, the category Natoma launched from before repositioning to the MCP gateway. | |
| Zenity | competes with | Governs AI agents and their tool access for the enterprise, contesting Natoma's authorization and discovery layers. | |
| MintMCP | competes with | Enterprise MCP gateway with SSO, RBAC, guardrails, and audit, directly overlapping Natoma's governed-gateway motion. | |
| ConductorOne | competes with | Identity and access governance vendor that CB Insights lists among Natoma's competitors, overlapping the access-governance side of non-human and agent identity. | |
| Microsoft | adjacent | Hyperscaler consolidating agent development and governance toolkits that could bundle MCP tool gating natively. | N/AMicrosoft is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product. |
| Snowflake | adjacent | Pending acquirer planning to integrate Natoma's gateway into its data platform to build a governed agentic control plane. |
Add analyzed competitors to compare them side by side with Natoma.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
Natoma's case for durability is its position in the agent access path. Every agent tool call Natoma mediates runs through its gateway and proxy under Cedar policy, so a customer that replaces the product must re-plumb how every agent reaches every tool. That inline role is what Snowflake agreed to buy, since owning the path lets it govern AI actions the way it already governs stored data. The accumulating assets are thin. Natoma sells software the customer configures rather than an accountable service, holds no proprietary dataset, and carries no compliance attestation a substitute could not match. A customer that embeds policies, credentials, and integrations in the gateway raises its own cost of leaving, which makes embedded-policy depth the number to watch.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Natoma is a platform the customer consumes and configures, through a no-cost Free plan and sales-quoted Pro and Enterprise tiers, offered in managed cloud, customer VPC, and on-prem deployment modes with no analyst-led accountability layer for outcomes, so delivery sits at the software level. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Once the gateway sits in the agent access path with accumulated Cedar policies, managed credentials, an MCP registry, and SIEM and IAM integrations, replacing it means re-plumbing how every agent reaches every tool, but no network effect or residency lock appears in fetched sources. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | Natoma displays a completed SOC 2 Type II 2025 report with GDPR and CCPA alignment, table-stakes assurance that eases procurement without blocking a substitute, and no regime mandates a governed MCP gateway. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Building an inline gateway and proxy that authorizes and routes every agent tool call across cloud, VPC, on-prem, and desktop environments with Cedar policy and OAuth 2.1, plus discovery of shadow MCP connections, is security-critical distributed-systems engineering where a failure would disrupt production agent access. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | The named buyer is the large enterprise, with HPE Networking on record through its CIO and Snowflake stating deployment at large global enterprises, where procurement and legal slow replacement, but the free tier and sales-quoted higher plans blend the profile. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 3/3 | Natoma is the access path agents authenticate and route through to reach tools, a gateway and proxy enforcing policy in-line via Cedar and OAuth 2.1 rather than observing from the side, so agents reach tools through it rather than around it. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The MCP registry, Cedar policies, and per-customer audit trails are tenant-specific configuration and engineering rather than a named non-public corpus, so a funded rival could rebuild the gateway from the same MCP standard. |
Natoma targets the enterprise security and platform team standing up AI agents at scale. The buyer is the organization where agents already connect to on-prem, cloud, and hybrid systems and where security cannot see or control what those agents reach for. HPE Networking is the named instance, with a CIO-led team that needed a single platform to inventory, qualify, secure, and manage agents across chat, coding, and autonomous use.
The product is built for that buyer rather than the small team experimenting with one agent. The platform page lists VPC deployment, on-prem support, SIEM and IAM and EDR and MDM integration, and audit export, which are the controls an enterprise security review demands before agents touch production. Snowflake describes the platform as already deployed at large global enterprises, which corroborates the enterprise focus beyond Natoma's own pages.
The free tier widens the top of the funnel without changing the target. A team can start with 5 MCP servers and 5,000 tool calls a month at no cost, then grow into Pro and Enterprise as governance needs appear. The motion is land in a developer or platform team and expand into a security-governed deployment, which fits a buyer who adopts agents before the controls catch up.
Natoma's claimed advantage is sitting in the tool-call path rather than watching from the side. The platform is a governed MCP gateway and proxy through which AI clients and agents reach enterprise tools, with identity-aware, attribute-based authorization enforced through Cedar policy and OAuth 2.1 authentication. Every Natoma-mediated tool call routes through the gateway, so policy is applied at the moment of access rather than reconstructed afterward from logs.
Discovery and audit pair with the enforcement layer. Natoma finds and inventories MCP connections across the organization, including unsanctioned shadow AI, and the platform page reports detecting on average 225 unmanaged shadow-AI instances per enterprise. The product produces a complete audit trail of tool access and integrates that activity into SIEM, EDR, and MDM systems, which is the visibility a security team needs to bring shadow connections under one policy.
The verifiable footprint is strong for an emerging category, with deployment metrics and an enterprise reference that corroborate real usage. What holds up, though, is the gateway position and the Cedar-based policy engine rather than a model advantage, since the connectors and authorization logic are engineering a funded rival could rebuild from the same MCP standard. No proprietary model or named non-public dataset appears in fetched sources.
Natoma runs an inbound, demo-led motion riding the surge of enterprise MCP adoption. The homepage routes prospects to a demo request and frames the product around letting AI safely reach everything a company knows, and the free tier gives a developer or platform team a no-cost entry before a security-governed expansion. The founder's Okta pedigree and Index and Greylock backing gave the early round senior credibility.
Named demand is thin but real. HPE Networking is on record through its CIO describing a deployment that began with 500 ChatGPT users connected to Salesforce and Gong and grew into governing chat, coding, and autonomous agents. Snowflake's announcement states the platform is already deployed at large global enterprises, though it names no additional logos, so the public roster rests on one detailed customer story plus the acquirer's unquantified claim.
The decisive go-to-market signal is the acquisition itself. Snowflake signed a definitive agreement to buy the company within about two years of its 2024 founding, which validates enterprise demand for the layer more strongly than investor conviction alone. What it does not settle is whether Natoma would have converted that demand into a broad independent customer base, since a platform vendor moved to absorb the layer before that proof accumulated.
Natoma publishes pricing, which is rare for an enterprise security product and gives buyers a budget anchor. The Free plan covers 5 MCP servers, 5 users, and 5,000 tool calls a month at no cost, Pro raises those limits and adds SSO, access policies, and a 99.99% uptime commitment, and Enterprise adds unlimited tool calls, on-prem deployment, bring-your-own vault, DLP filters, and a 99.999% uptime commitment. Pro and Enterprise prices are quoted through sales rather than listed.
The metering reveals what Natoma believes buyers pay for. The company charges by the number of MCP servers, users, and tool calls, and states plainly that it does not charge per agent, so a customer can deploy any number of agents within plan limits without per-agent fees. That choice prices the product like infrastructure billed on throughput rather than a tool billed on seats, and it positions the meter on connection volume, the unit that grows as agents proliferate.
The published unit also signals the durability case. By tying cost to tool calls on the metered Free and Pro plans, Natoma earns more as a customer pushes more agent activity through the path it controls, which aligns revenue with the inline position. Enterprise breaks that link by including unlimited tool calls, so high-volume deployments are priced on a custom basis rather than by throughput. The tradeoff is that throughput-based pricing exposes the customer to cost as usage grows, which the activity monitoring and budget alerts in higher tiers are meant to manage.
Natoma is a platform offered in managed cloud, customer VPC, and on-prem deployment modes. The platform supports hosted and desktop MCP servers, runs in a customer VPC, and offers on-prem deployment in the Enterprise tier, so a buyer can place the gateway where its security posture requires. The product is software rather than a managed-expertise service, and the platform page says a customer can run Natoma's MCP gateway infrastructure inside its own environment, so the buyer consumes the platform and sets the policy without an analyst-staffed accountability layer.
Operational commitments are unusually concrete for the category. The Pro plan guarantees 99.99% uptime and the Enterprise plan 99.999%, the platform produces audit logs and audit export, and it integrates with SIEM, IAM, EDR, MDM, and OpenTelemetry tooling. Those published SLAs and the integration surface are the operational signals an enterprise change-management review looks for before an access-path component goes into production.
The inline role raises the operational stakes. Because every Natoma-mediated agent tool call routes through the gateway, Natoma becomes a dependency in the agent's access path, so its availability and latency directly affect whether agents can act. The five-nines Enterprise SLA is the company's answer to that exposure, and the bring-your-own-vault and DLP options let a customer keep sensitive credential and data handling under its own controls.
Natoma runs a Vanta-hosted trust center that lists a completed SOC 2 Type II 2025 report, GDPR alignment, and CCPA compliance, and states that penetration testing is performed. The pricing page repeats the SOC 2, GDPR, CCPA, and US Data Privacy claims as procurement assurance. The SOC 2 Type II report is available through an access request rather than open download, which is the standard posture for an enterprise security vendor.
That collateral matters because the product sits directly in the path of agent access to sensitive systems. A gateway that authorizes and proxies tool calls handles credentials, policy, and a record of every action, so a security buyer evaluates the attestations alongside the audit trail, identity-aware policy, credential governance, and SIEM integration the platform provides. The published SLAs and the bring-your-own-vault option add to the formal-review surface.
The attestations are enterprise-grade but table-stakes rather than a moat. SOC 2 Type II and the privacy alignments ease procurement without blocking a substitute, and no compliance regime mandates a governed MCP gateway as a product class. The pending Snowflake acquisition shifts the longer-term trust question from Natoma's standalone certifications to how a data-platform owner governs the same capability at its scale.
Natoma positions itself as the connectivity and governance layer between AI clients and enterprise tools rather than a point control. It standardizes how agents connect to tools through a single governed gateway, maintains an enterprise MCP registry and artifactory, supports custom and self-hosted MCP servers, and works across Claude Code, ChatGPT, Cortex, and custom AI clients. The platform claim rests on owning the access path that agents traverse to reach company systems.
That position is what Snowflake signed a definitive agreement to acquire, a deal still subject to customary closing conditions. Snowflake's stated rationale is to extend its governance perimeter from data assets to AI actions and interactions, connecting Snowflake Intelligence and Cortex Code to enterprise systems through Natoma's verified MCP library and centralizing governance through the gateway. The acquirer wanted the path, not a side monitor, because the path is where data access and AI action meet.
The exposure is that platform owners are the natural owners of this layer. A vendor that already holds the enterprise's data and identity is positioned to fold MCP tool gating into a suite the buyer already licenses, which is the logic Snowflake acted on by agreeing to buy Natoma rather than compete with it. The same logic leaves an independent gateway exposed to hyperscalers such as Microsoft, AWS, and Google, which are consolidating their agentic development toolkits with similar tools and functions as vendors race to own the governance layer.
Natoma's credibility comes from a founder with a prior startup exit and years inside an identity vendor. Founder Pratyus Patnaik previously built and sold his earlier startup, atSpoke, to Okta in 2021 for $79.3 million, then spent more than two years as a senior director at Okta before leaving to establish Natoma. That sale is a verifiable prior exit rather than an unverified background claim, though atSpoke was a workplace operations platform, so the identity-domain grounding comes from his Okta years rather than from what he built before.
Natoma built its governed-gateway platform with a small team, with DataBreachToday reporting 27 total employees and The Register reporting that the pending deal would bring 20 employees to Snowflake. Patnaik has a prior enterprise software exit to Okta, and Snowflake credits Natoma's team with expertise in MCPs, gateway infrastructure, identity governance, and privileged access management, so the move into agent tool access builds on that base.
The backer and acquirer signals reinforce the team read. Index Partners and Greylock led the seed, and Snowflake's own announcement credits the team with deep expertise in MCPs, gateway infrastructure, identity governance, and privileged access management. The verifiable strength is the founder's domain track record and the confidence it drew, with depth below the principal the open question fetched sources do not resolve.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Natoma: MCP Gateway Platform | official | 2026-07-09 |
| f2 | DataBreachToday on Natoma founding year and team | press | 2026-06-13 |
| f3 | AI Defense Matrix Catalog entry | other | 2026-06-09 |
| f4 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Natoma homepage | official | 2026-06-13 |
| s2 | Natoma platform features “Natoma centralizes authorization for AI tool usage. Define who can access which tools (and under what conditions) using granular, attribute-based policies.” | official | 2026-06-13 |
| s3 | Natoma authorization use case | official | 2026-06-13 |
| s4 | Natoma enterprise MCP platform launch announcement “managing these non-human actors, especially when their activities blur the lines between user and automated client” | official | 2026-06-13 |
| s5 | Snowflake press release on intent to acquire Natoma “today announced it has signed a definitive agreement to acquire Natoma, an enterprise Model Context Protocol (MCP) platform for AI agents” | official | 2026-06-13 |
| s6 | DataBreachToday on Snowflake acquiring Natoma with founder and funding detail “Natoma, founded in 2024, employs 27 people ... The company has been led since its inception by Pratyus Patnaik, who sold workplace operations platform atSpoke to Okta in August 2021 for $79.3 million and spent more than two years as a senior director at Okta before leaving to establish Natoma.” | press | 2026-07-02 |
| s7 | CIO on Snowflake acquiring Natoma with analyst commentary “MCP is becoming the connective tissue for enterprise agents, but without identity, policy, privileged access controls, and auditability, it can quickly become a shadow AI risk” | press | 2026-06-13 |
| s8 | InfoWorld on Snowflake acquiring Natoma to boost agent governance “betting that enterprises will increasingly require centralized governance, identity controls, and auditability as AI agents begin interacting more deeply with internal applications” | press | 2026-06-13 |
| s9 | The Register on Snowflake buying Natoma for the agentic control plane “It is the database titan's sixth acquisition announcement since June 2025” | press | 2026-06-13 |
| s10 | Signalbase on Natoma 7M seed round framed as non-human identity “This milestone investment, supported by leading venture capital firms including Greylock, Index, and other prominent industry leaders, marks a pivotal moment for the company, which was founded by a team of identity experts from Okta, Microsoft, Google, and Salesforce.” | press | 2026-07-02 |
| s11 | Index Ventures portfolio page listing Natoma founders “Pratyus Patnaik Paresh Bhaya Will Potter Zachary Hart” | other | 2026-06-13 |
| s12 | Natoma Trust Center (Vanta portal, SOC 2 Type II) “Compliance SOC 2 GDPR aligned CCPA COMPLIANT ... Compliance Reports Natoma SOC 2 Type II 2025 ... Penetration testing performed” | official | 2026-06-16 |
| s13 | Natoma customer story: how HPE governs AI agents at enterprise scale “Natoma provided that framework that helps us have an inventory of all the different agents, qualify the agents through the lifecycle, secure the agents, and manage it end to end. ... 500 ChatGPT users connected to Salesforce and Gong through Natoma.” | official | 2026-06-16 |
| s14 | Natoma homepage with HPE customer story and joining-forces banner “Customer Story ... Venky Rangachari CIO, HPE Networking ... Natoma is joining forces with Snowflake” | official | 2026-06-16 |
| s15 | Natoma platform deployment metrics “Granular authorization via Cedar ... 1000s of MCP servers ... 225+ Shadow AIs detected per org ... 1.8m Tool calls per day” | official | 2026-06-16 |
| s16 | CB Insights profile of Natoma (non-human identity management, Los Altos, one filed patent, ConductorOne among competitors) “Natoma offers non-human identity management within the cybersecurity sector. It offers a platform for discovering, monitoring, and managing non-human identities, including service accounts, access tokens ... It was founded in 2024 and is based in Los Altos, California.” | other | 2026-06-30 |
| s17 | USPTO record for application 18/410,083, Natoma Labs, Inc. patent US 12,615,260 B1, filed 2024-01-11, granted 2026-04-28, inventor Pratyus Patnaik “System for managing non-human identities” | regulatory | 2026-06-30 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Natoma homepage with HPE customer story and joining-forces banner “Works with Claude Code, ChatGPT, Cortex, Snowflake Intelligence, custom AI, and more. Lives wherever you use AI. ... Natoma is joining forces with Snowflake ... Authorize every AI tool call. Define policy once with Cedar. Enforce it across every tool, every client, every call” | official | 2026-06-18 |
| s2 | Natoma platform: governed MCP gateway, Cedar authorization, deployment metrics “Works with SIEM, IAM, EDR, and MDM. Run in VPCs, leverage your MCP artifactory. Supports desktop MCP servers. Audit export. Support for on-prem environments. Granular authorization via Cedar. ... 1000s of MCP servers. 225+ Shadow AIs detected per org. 1.8m Tool calls per day” | official | 2026-06-18 |
| s3 | Natoma platform FAQ: gateway definition and Shadow AI discovery “Natoma serves as that platform, providing a governed MCP gateway so AI agents can operate securely across your organization. ... On average, Natoma detects 225 unmanaged Shadow AI instances per enterprise” | official | 2026-06-18 |
| s4 | Natoma pricing: Free, Pro, Enterprise plans metered by servers, users, tool calls “Natoma's pricing is based on the number of MCP servers, users, and tool calls, not on the number of agents. This means you can deploy any number of AI clients and agents within your plan limits without incurring per-agent fees. ... OAuth 2.1-based authentication. Tool call authorization.” | official | 2026-06-18 |
| s5 | Natoma Enterprise plan and uptime SLA tiers “Pro ... SSO / SAML / SCIM. Access policies. ... 99.99% uptime SLA. Enterprise ... Unlimited tool calls. 24/7 dedicated support. On-prem deployment. BYO Vault. DLP filters. SIEM and OTel integration. Custom data retention. 99.999% uptime SLA ... SOC2 certified. GDPR compliant. CCPA. US Data Privacy” | official | 2026-06-18 |
| s6 | Natoma customer story: how HPE governs AI agents at enterprise scale “Natoma provided that framework that helps us have an inventory of all the different agents, qualify the agents through the lifecycle, secure the agents, and manage it end to end. ... From 500 ChatGPT users to a full organization, across chat, coding, and autonomous agents.” | official | 2026-06-17 |
| s7 | Snowflake announces intent to acquire Natoma (definitive agreement, pending close) “Natoma's platform is already deployed at some of the world's largest enterprises ... Its team brings deep expertise in MCPs, gateway infrastructure, identity governance and privileged access management ... Closing of the acquisition is subject to customary closing conditions.” | official | 2026-06-18 |
| s8 | DataBreachToday on Snowflake acquiring Natoma (founder, funding, headcount) “Natoma, founded in 2024, employs 27 people ... The company has been led since its inception by Pratyus Patnaik, who sold workplace operations platform atSpoke to Okta in August 2021 for $79.3 million and spent more than two years as a senior director at Okta before leaving to establish Natoma.” | press | 2026-07-02 |
| s9 | Natoma Trust Center (Vanta portal, SOC 2 Type II 2025) “Compliance SOC 2 GDPR aligned CCPA COMPLIANT ... Compliance Reports Natoma SOC 2 Type II 2025 ... Penetration testing performed” | official | 2026-06-17 |
| s10 | CIO on Snowflake acquiring Natoma (analyst view of the governance demand) “The cloud data platform provider is betting that enterprises will increasingly require centralized governance, identity controls, and auditability as AI agents begin interacting more deeply with internal applications, APIs, and business workflows through the emerging MCP standard.” | press | 2026-06-17 |
| s11 | The Register: Snowflake buys Natoma to help freeze out rogue agents “Snowflake plans to buy Natoma, a startup that has made a gateway for managing AI agent permissions across enterprise applications. If it passes customary regulatory and closing conditions, the deal would bring 20 employees to Snowflake.” | press | 2026-07-02 |
| s12 | arXiv preprint: Simplified and Secure MCP Gateways for Enterprise AI Integration “This paper introduces the MCP Gateway to simplify self-hosted MCP server integration. The proposed architecture integrates security principles, authentication, intrusion detection, and secure tunneling, enabling secure self-hosting without exposing infrastructure.” | research | 2026-06-30 |
| s13 | Google Patents: US 12,615,260 B1, System for managing non-human identities, assignee Natoma Labs Inc “A system for managing NHIs ingests data from an existing system and determines the NHIs.” | regulatory | 2026-06-30 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.