Natoma

Security for AI

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2024
Funding $7M
Last updated 2026-07-09

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Snowflake signed a definitive agreement to buy Natoma about two years after the company started in 2024, when the public record named one detailed customer, HPE. In that window a team of 27 people, per press reports, built a gateway that checks every AI agent tool call against Cedar access policies, discovers unsanctioned AI across an organization, and logs each action for audit. Its founder, Pratyus Patnaik, sold his prior startup, atSpoke, to Okta in 2021 for 79.3 million dollars. Press coverage reads the deal as a bet that enterprises will require centralized governance, identity controls, and auditability as AI agents reach internal applications. The main public evidence of demand is the buyer itself. A data-platform vendor agreed to acquire the gateway rather than compete with it.

Sourced Details

Description Natoma is a governed MCP gateway that connects AI clients and agents to enterprise tools and centralizes identity-aware authorization over which tools each agent can use. [f1]
Founded 2024 [f2]
HQ San Francisco, California, United States [f2]
Funding $7M total [f2]
Latest funding Seed (May 2025), led by Index Ventures and Greylock [f2]
Deployment SaaS, Self-hosted [f3]

Products

Product What it does
Natoma Governed MCP gateway that treats AI agents as non-human identities, enforcing identity-aware authorization and per-tool policy over agent access to tools, with shadow-AI discovery and audit.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Natoma is a governed MCP gateway that treats AI agents as non-human identities, enforcing identity-aware authorization and per-tool policy over agent access to tools, with shadow-AI discovery and audit. It is mapped to the AI Defense Matrix. [f4]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 27 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs, demos, and third-party validation. 3/5
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 4/5
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 4/5
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 4/5
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5

Unlock the Full Analysis

The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.

One-time purchase: $20 per profile.

Unlock

Reading several? Unlock the entire catalog.

Business Risks
Problem & Market
Product Capabilities
Competitive Positioning
Go-to-Market & Traction
Team & Credibility
Trust Readiness
Competitors

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 13 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

Dimension Score
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 3/3
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3

Unlock the Full Analysis

The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.

One-time purchase: $20 per profile.

Unlock

Reading several? Unlock the entire catalog.

Strategic Market Segmentation
Product Capabilities & AI Advantages
Sales Engagement & Go-to-Market
Pricing Model
Product Delivery & Operations
Earning Customers' Trust
Platform Strategy & Ecosystem Positioning
Team & Execution Capability

Sources

Company Detail Sources (4)
Id Source Tier Accessed
f1 Natoma: MCP Gateway Platform official 2026-07-09
f2 DataBreachToday on Natoma founding year and team press 2026-06-13
f3 AI Defense Matrix Catalog entry other 2026-06-09
f4 AI Defense Matrix Catalog mapping other 2026-06-23
Profile Analysis Sources (17)
Id Source Tier Accessed
s1 Natoma homepage official 2026-06-13
s2 Natoma platform features
“Natoma centralizes authorization for AI tool usage. Define who can access which tools (and under what conditions) using granular, attribute-based policies.”
official 2026-06-13
s3 Natoma authorization use case official 2026-06-13
s4 Natoma enterprise MCP platform launch announcement
“managing these non-human actors, especially when their activities blur the lines between user and automated client”
official 2026-06-13
s5 Snowflake press release on intent to acquire Natoma
“today announced it has signed a definitive agreement to acquire Natoma, an enterprise Model Context Protocol (MCP) platform for AI agents”
official 2026-06-13
s6 DataBreachToday on Snowflake acquiring Natoma with founder and funding detail
“Natoma, founded in 2024, employs 27 people ... The company has been led since its inception by Pratyus Patnaik, who sold workplace operations platform atSpoke to Okta in August 2021 for $79.3 million and spent more than two years as a senior director at Okta before leaving to establish Natoma.”
press 2026-07-02
s7 CIO on Snowflake acquiring Natoma with analyst commentary
“MCP is becoming the connective tissue for enterprise agents, but without identity, policy, privileged access controls, and auditability, it can quickly become a shadow AI risk”
press 2026-06-13
s8 InfoWorld on Snowflake acquiring Natoma to boost agent governance
“betting that enterprises will increasingly require centralized governance, identity controls, and auditability as AI agents begin interacting more deeply with internal applications”
press 2026-06-13
s9 The Register on Snowflake buying Natoma for the agentic control plane
“It is the database titan's sixth acquisition announcement since June 2025”
press 2026-06-13
s10 Signalbase on Natoma 7M seed round framed as non-human identity
“This milestone investment, supported by leading venture capital firms including Greylock, Index, and other prominent industry leaders, marks a pivotal moment for the company, which was founded by a team of identity experts from Okta, Microsoft, Google, and Salesforce.”
press 2026-07-02
s11 Index Ventures portfolio page listing Natoma founders
“Pratyus Patnaik Paresh Bhaya Will Potter Zachary Hart”
other 2026-06-13
s12 Natoma Trust Center (Vanta portal, SOC 2 Type II)
“Compliance SOC 2 GDPR aligned CCPA COMPLIANT ... Compliance Reports Natoma SOC 2 Type II 2025 ... Penetration testing performed”
official 2026-06-16
s13 Natoma customer story: how HPE governs AI agents at enterprise scale
“Natoma provided that framework that helps us have an inventory of all the different agents, qualify the agents through the lifecycle, secure the agents, and manage it end to end. ... 500 ChatGPT users connected to Salesforce and Gong through Natoma.”
official 2026-06-16
s14 Natoma homepage with HPE customer story and joining-forces banner
“Customer Story ... Venky Rangachari CIO, HPE Networking ... Natoma is joining forces with Snowflake”
official 2026-06-16
s15 Natoma platform deployment metrics
“Granular authorization via Cedar ... 1000s of MCP servers ... 225+ Shadow AIs detected per org ... 1.8m Tool calls per day”
official 2026-06-16
s16 CB Insights profile of Natoma (non-human identity management, Los Altos, one filed patent, ConductorOne among competitors)
“Natoma offers non-human identity management within the cybersecurity sector. It offers a platform for discovering, monitoring, and managing non-human identities, including service accounts, access tokens ... It was founded in 2024 and is based in Los Altos, California.”
other 2026-06-30
s17 USPTO record for application 18/410,083, Natoma Labs, Inc. patent US 12,615,260 B1, filed 2024-01-11, granted 2026-04-28, inventor Pratyus Patnaik
“System for managing non-human identities”
regulatory 2026-06-30
Deep-Dive Sources (13)
Id Source Tier Accessed
s1 Natoma homepage with HPE customer story and joining-forces banner
“Works with Claude Code, ChatGPT, Cortex, Snowflake Intelligence, custom AI, and more. Lives wherever you use AI. ... Natoma is joining forces with Snowflake ... Authorize every AI tool call. Define policy once with Cedar. Enforce it across every tool, every client, every call”
official 2026-06-18
s2 Natoma platform: governed MCP gateway, Cedar authorization, deployment metrics
“Works with SIEM, IAM, EDR, and MDM. Run in VPCs, leverage your MCP artifactory. Supports desktop MCP servers. Audit export. Support for on-prem environments. Granular authorization via Cedar. ... 1000s of MCP servers. 225+ Shadow AIs detected per org. 1.8m Tool calls per day”
official 2026-06-18
s3 Natoma platform FAQ: gateway definition and Shadow AI discovery
“Natoma serves as that platform, providing a governed MCP gateway so AI agents can operate securely across your organization. ... On average, Natoma detects 225 unmanaged Shadow AI instances per enterprise”
official 2026-06-18
s4 Natoma pricing: Free, Pro, Enterprise plans metered by servers, users, tool calls
“Natoma's pricing is based on the number of MCP servers, users, and tool calls, not on the number of agents. This means you can deploy any number of AI clients and agents within your plan limits without incurring per-agent fees. ... OAuth 2.1-based authentication. Tool call authorization.”
official 2026-06-18
s5 Natoma Enterprise plan and uptime SLA tiers
“Pro ... SSO / SAML / SCIM. Access policies. ... 99.99% uptime SLA. Enterprise ... Unlimited tool calls. 24/7 dedicated support. On-prem deployment. BYO Vault. DLP filters. SIEM and OTel integration. Custom data retention. 99.999% uptime SLA ... SOC2 certified. GDPR compliant. CCPA. US Data Privacy”
official 2026-06-18
s6 Natoma customer story: how HPE governs AI agents at enterprise scale
“Natoma provided that framework that helps us have an inventory of all the different agents, qualify the agents through the lifecycle, secure the agents, and manage it end to end. ... From 500 ChatGPT users to a full organization, across chat, coding, and autonomous agents.”
official 2026-06-17
s7 Snowflake announces intent to acquire Natoma (definitive agreement, pending close)
“Natoma's platform is already deployed at some of the world's largest enterprises ... Its team brings deep expertise in MCPs, gateway infrastructure, identity governance and privileged access management ... Closing of the acquisition is subject to customary closing conditions.”
official 2026-06-18
s8 DataBreachToday on Snowflake acquiring Natoma (founder, funding, headcount)
“Natoma, founded in 2024, employs 27 people ... The company has been led since its inception by Pratyus Patnaik, who sold workplace operations platform atSpoke to Okta in August 2021 for $79.3 million and spent more than two years as a senior director at Okta before leaving to establish Natoma.”
press 2026-07-02
s9 Natoma Trust Center (Vanta portal, SOC 2 Type II 2025)
“Compliance SOC 2 GDPR aligned CCPA COMPLIANT ... Compliance Reports Natoma SOC 2 Type II 2025 ... Penetration testing performed”
official 2026-06-17
s10 CIO on Snowflake acquiring Natoma (analyst view of the governance demand)
“The cloud data platform provider is betting that enterprises will increasingly require centralized governance, identity controls, and auditability as AI agents begin interacting more deeply with internal applications, APIs, and business workflows through the emerging MCP standard.”
press 2026-06-17
s11 The Register: Snowflake buys Natoma to help freeze out rogue agents
“Snowflake plans to buy Natoma, a startup that has made a gateway for managing AI agent permissions across enterprise applications. If it passes customary regulatory and closing conditions, the deal would bring 20 employees to Snowflake.”
press 2026-07-02
s12 arXiv preprint: Simplified and Secure MCP Gateways for Enterprise AI Integration
“This paper introduces the MCP Gateway to simplify self-hosted MCP server integration. The proposed architecture integrates security principles, authentication, intrusion detection, and secure tunneling, enabling secure self-hosting without exposing infrastructure.”
research 2026-06-30
s13 Google Patents: US 12,615,260 B1, System for managing non-human identities, assignee Natoma Labs Inc
“A system for managing NHIs ingests data from an existing system and determines the NHIs.”
regulatory 2026-06-30

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Do not republish its content or share access without the operator's permission.