All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Noma Security sells enterprises a single platform for the AI agents now running on staff laptops, inside SaaS tools, and in software their own engineers build. The platform finds those agents, governs what they may do, tests them for weaknesses, and watches them at runtime. Three customers speak for Noma by name on its homepage, including the security chief at UiPath. Five customer voices appear there in all, and two of them, Varun Badhwar and Chris Hatter, also sit on Noma’s own advisor roster. Fewer of those names are arm’s-length references than the count implies. AWS curated Noma into the Security Hub Extended partner roster in February 2026, and the platform lists at $200,000 a year on AWS Marketplace.
| Description | Noma Security gives enterprises one platform to discover, govern, test, and protect the AI agents running on staff laptops, inside SaaS tools, and in software their own engineers build. | [f1] |
|---|---|---|
| Founded | 2023 | [f2] |
| HQ | New York, United States | [f3] |
| Funding | $132M total | [f4] |
| Latest funding | $100M Series B led by Evolution Equity Partners (July 2025) | [f2] |
| Deployment | SaaS, Self-hosted | [f5] |
| Compliance | GDPR, HIPAA, ISO 27001, SOC 2 Type 2 | [f5] |
| Product | What it does |
|---|---|
| Noma Security | An enterprise platform that discovers, governs, and protects AI and AI agents across the enterprise, spanning homegrown AI, SaaS agents, and coding assistants. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Noma Security discovers, governs, and protects AI and AI agents across the enterprise, spanning homegrown AI, SaaS agents, and coding assistants. It is mapped to the AI Defense Matrix. [f6]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | The security team that owns ungoverned enterprise AI is a clear buyer, and Noma splits the surface into employee, SaaS and engineering-built agents. The reviewed record carries one quantification of the pain, a 2024 TechCrunch citation of a poll of more than 350 IT leaders. TechCrunch names no pollster, so the pain reads as credible without being independently established. [s5, s2, s1] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | Noma documents discovery, access control, runtime detection and adversarial testing in mechanism-level detail on its own pages. Help Net Security’s industry-news writeup of Noma’s June 2026 launch announcement describes the agent registry and its three-state policy model. The documentation subdomain at docs.noma.security returns a login page, so an outside reader cannot check that depth against Noma’s own documentation. [s2, s13, s20] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | Within the past year the record documents one kind of buyer-side demand. AWS built an AI slot into its Security Hub Extended procurement plan and curated Noma into that roster in February 2026, which AWS announced itself and Security Boulevard reported. The CISO-voted Rising in Cyber 2026 listing is recognition rather than purchasing, and the Gartner Peer Insights page carries no reviews. The enabler is enterprise AI adoption outrunning security teams, which TechCrunch quantified in 2024, with Calcalist relaying UBS Research that 53% of surveyed organizations plan to adopt agentic AI by 2026. [s11, s18, s19, s8, s4, s5] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | Braun and Tron met in the IDF’s 8200 unit, and neither carries a prior company build or exit in the reviewed record. Noma Labs has published seven dated vulnerability disclosures since September 2025. In the reviewed record, independent coverage names Noma as the discloser of one of them, the Salesforce finding, in The Hacker News and Infosecurity Magazine. [s4, s7, s16, s9, s10] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | AWS curated Noma into the Security Hub Extended partner roster in February 2026, documented by AWS itself and reported by Security Boulevard, and the AWS Marketplace listing prices a 12-month contract at $200,000. Three enterprises speak by name on the homepage, and Rising in Cyber 2026 adds a CISO-voted listing, so sources outside Noma document the partnership even though scale figures stay vendor-reported. [s11, s18, s15, s1, s19] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 2/5 | Calcalist reports $132 million raised in under two years, including the $100 million Series B, against a company that discloses no revenue and had 40 employees at the round. Shipping is visible in four products and a June 2026 access-control release, yet the raise still outruns what the record verifies commercially. [s4, s6, s2, s13] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 | Gartner Peer Insights describes Noma as addressing the security risks of enterprise AI adoption, and AWS placed it in a roster whose categories include AI. The labels still multiply across AI security, agent security and governance, and Gartner’s framing of AI applications and agents, which keeps the category at a forming stage. [s8, s11, s3] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Covering employee, SaaS and engineering-built agents in one place is friction a single platform vendor securing its own estate would not remove, and the agent registry and per-agent identity embed in security workflow. The reviewed record evidences no proprietary dataset, and each environment Noma names as covered is run by the vendor that owns it. [s2, s13, s11] |
Noma Security sells into the governance gap that opens when staff, business teams and engineers all start running AI agents at once. The platform page splits that surface three ways: employees running coding agents such as Claude Code, Cursor and Codex on their own machines, business teams building agents on Microsoft Copilot Studio, Salesforce AgentForce and ServiceNow, and engineering teams building on AWS Bedrock, Azure AI Foundry, Databricks, LangChain and CrewAI. One security team owns all three, and that team is the buyer.
Independent measurement of the pain is thin and ageing. TechCrunch’s 2024 launch coverage cited a poll of more than 350 IT leaders in which over half said the complexity of AI applications weakened their security posture. Calcalist relays a UBS Research forecast that 53% of surveyed organizations plan to adopt agentic AI by 2026 and 83% by 2028, which measures adoption rather than the security gap.
Noma’s own framing has moved with the market. SecurityWeek’s Series A coverage quoted Braun describing one platform covering the new data and AI lifecycle, and the About page now calls the company an enterprise Agent Security and Governance Platform. The June 2026 access-control release, which Help Net Security covered, is where that repositioning shows up in shipped product. [s2, s5, s4, s7, s3, s13]
Four products share one set of findings. AI-SPM discovers every agent, MCP server, skill and model and maps each agent’s connections, permissions and data access. Access control decides which MCP servers, skills and tools an agent may use, keyed to identity-provider groups or applied by tool sensitivity. AI-DR detects prompt injection, data exfiltration, scope violations and agents drifting from their intent at runtime. AI red teaming runs multi-turn attack campaigns whose findings feed the runtime policies.
The June 2026 access-control release added enforcement. Help Net Security ran Noma’s launch announcement as industry news. That writeup describes a live registry of agents and MCP servers, a distinct attributable identity for each agent, three states covering approved, requires-review and blocked, and control at the level of an individual tool rather than a whole server.
Noma’s stated design keeps that enforcement out of one chokepoint. The homepage describes Open Enforcement as decoupling policy from infrastructure and enforcing at agent hooks, MCP gateways, AI gateways, agent SDKs and direct APIs, which spreads enforcement across several control points.
The documentation subdomain at docs.noma.security returns a login page, so the reviewed record carries no product documentation an outside reader can check. A reader without an account works from marketing pages, press coverage and Noma Labs writeups instead. [s2, s13, s1, s20]
Noma sells one platform against tools that each cover a slice of the problem. TechCrunch’s launch coverage named HiddenLayer and Protect AI as focused on defending AI systems from adversarial attacks and Cranium as providing visibility at the application level, then quoted Braun claiming Noma does all of that and more.
Noma’s distribution runs through AWS. AWS’s own announcement names Noma among the curated partner solutions in Security Hub Extended, a roster spanning endpoint, identity, email, network, data, browser, cloud, AI and security operations. Security Boulevard reported the same roster in May 2026, quoting an AWS director of security services. The narrower claim that AWS chose Noma specifically for AI security appears on Noma’s blog rather than in AWS’s announcement.
The platforms Noma covers are also the bundling risk. Its coverage list names Microsoft Copilot Studio, Salesforce AgentForce, ServiceNow, AWS Bedrock and Databricks, and each of those vendors owns the environment it runs. A vendor adding native controls for the agents it hosts would cover part of what Noma sells, without matching the span across all three environments. [s5, s11, s18, s12, s2]
Named customer evidence sits on Noma’s own homepage. Under a heading reading “What customers are saying” the page carries five voices: Jari Koister, a technology chief at Kantar, who says Noma helped his team detect issues and make them actionable, Scott Roberts, CISO of UiPath, who describes the platform deployed across the company’s AI stack, Matthew Hurewitz of Best Buy, Varun Badhwar of Endor Labs and Chris Hatter, a former CISO of Nielsen.
Two of those five are Noma’s own advisors. The About page groups Varun Badhwar and Chris Hatter under a strategic advisors heading, so their endorsements are not arm’s-length customer references and the named-reference base is three rather than five.
Scale claims remain the company’s own account. Calcalist reports that Noma discloses no revenue while reporting significant year-over-year growth after adoption by Fortune 500 companies in financial services, life sciences, retail and high tech, and no source in the reviewed record confirms the growth or a customer count.
Records Noma does not control carry the rest of the traction. AWS curated Noma into the Security Hub Extended roster in February 2026, the AWS Marketplace listing prices a 12-month contract at $200,000 with private offers available, and Noma appears on Rising in Cyber 2026, a list of 30 private cybersecurity companies selected by 150 CISOs and operating security executives. [s1, s3, s4, s11, s15, s19]
Niv Braun and Alon Tron founded Noma Security in 2023 after meeting in the IDF’s 8200 intelligence unit, as both Calcalist and SecurityWeek report. Neither founder has a prior company build or exit in the reviewed record.
Noma publishes a named executive team. The About page lists Ralph Pisani as chief revenue officer and Diana Kelley as chief information security officer. Calcalist recorded 40 people at the Series B, and Gartner Peer Insights now lists a band of 51 to 200 employees.
Noma Labs supplies the public research record. Its index lists seven dated vulnerability disclosures between September 2025 and July 2026, among them ForcedLeak in Salesforce Agentforce, an indirect prompt injection in Google Gemini Enterprise, a Context7 MCP server flaw, a GitHub AI agent flaw and RufRoot in an MCP bridge. The CVE record for RufRoot rates that flaw 10.0 and lists it fixed upstream. The same index carries three general security research posts dated between July and August 2026. In the reviewed record, independent coverage names Noma as the discloser of one of the seven: The Hacker News and Infosecurity Magazine both covered the Salesforce finding.
The security executives Noma publishes are advisors rather than investors. Its About page groups Vijay Bolina of Google DeepMind, Caleb Sima of the CSA AI Security Alliance and Varun Badhwar of Endor Labs under a strategic advisors heading, while the investors Calcalist names are firms: Evolution Equity Partners, Ballistic Ventures and Glilot Capital Partners. [s4, s7, s3, s8, s16, s9, s10, s17]
The Trust Center publishes six active certifications. It lists SOC 2 Type II audited by EY, ISO 27001, HIPAA and ISO/IEC 42001, alongside 104 security controls.
The underlying documents stay gated. The portal records zero public documents and 31 available on request, so an evaluator can see which reports exist and has to ask Noma for the reports themselves.
Noma’s Gartner Peer Insights listing carries no reviews. Its company details block there records an April 2026 update, while the product information and company description on the same page record November 2025. [s14, s8]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| HiddenLayer | competes with | TechCrunch's coverage of Noma's launch named it among the startups working the same AI-defense problem. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Protect AI | competes with | TechCrunch's coverage of Noma's launch named it among the startups working the same AI-defense problem. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Cranium | competes with | TechCrunch's coverage of Noma's launch named it as covering AI visibility, which Noma's discovery product also covers. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Zenity | competes with | Competes for the same buyer as Noma's agent access control and MCP governance. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Lakera | adjacent | Adjacent because it works the runtime guardrail layer while Noma sells discovery, access control and testing alongside it. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
Add analyzed competitors to compare them side by side with Noma Security.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
Noma Security draws durability from its buyers and the difficulty of the problem rather than from anything it has accumulated. Noma reports buyers among large enterprises in regulated sectors, where procurement and legal review sit between a customer and a replacement. Detection across whole agent sessions and multi-turn adversarial testing need scarce expertise, which the Noma Labs disclosures show in public. Against that, customers buy renewable term contracts they can decline to renew. The reviewed record names no dataset, licence or patent Noma retains, and the research that builds its reputation is published. Enforcement rides on control points customers already run, and the cited record does not size what an exit would cost beyond the loss of Noma’s own coverage.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Customers buy the platform as software on a term contract through AWS Marketplace or directly, and their own teams operate it and own the outcomes. Red teaming and runtime detection run as automated product features, and the reviewed record describes no service layer that Noma staffs or accountability that Noma accepts. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Configured agent and MCP registries, per-agent identities and tuned access policies create real friction, and Noma enforces at control points the customer already runs. The cited record neither sizes a migration nor documents what an exit costs beyond losing Noma’s detection and governance coverage. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | SOC 2 Type II, ISO 27001, HIPAA and ISO/IEC 42001 ease procurement, with a Trust Center indexing 31 documents available on request. The reviewed certification record carries commercial attestations rather than an authorization or a mandate that would block a replacement. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Detecting a threat that appears only across a chain of agent actions, and running multi-turn adversarial campaigns against live agents, take specialized expertise against techniques that keep moving. Noma Labs shows that depth in public, with independent coverage putting its Salesforce finding at a 9.4 severity score and the CVE record for an MCP bridge finding on its Labs index rating that flaw 10.0. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | Calcalist reports adoption by Fortune 500 companies in financial services and life sciences, and the named public references are UiPath, Kantar and Best Buy. A $200,000 annual list price on AWS Marketplace matches an enterprise purchase with procurement behind it rather than a mid-market one. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | The product is a security platform layered onto AI infrastructure rather than infrastructure that other applications call. Its access control gates how agents reach MCP servers and tools, and by Noma's own description that enforcement rides on hooks, gateways and SDKs the customer already runs. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The cited record evidences no dataset, content licence or patent that Noma retains. Discovery and posture findings describe each customer's own estate, and the research that distinguishes the team is published on Noma's pages and in the CVE record. Prebuilt red-team scan profiles are the closest named artifact, and no cited source states what they accumulate from. |
Noma Security sells to the security team at large enterprises that already run agents in more than one place. Calcalist reports adoption by Fortune 500 companies in financial services, life sciences, retail and high tech, on the company’s own account, and the named public references are UiPath, Kantar and Best Buy.
The segmentation splits by who builds the agent. Employees run coding agents such as Claude Code, Cursor and Codex on their own machines, business teams build agents on Microsoft Copilot Studio, Salesforce AgentForce and ServiceNow, and engineering teams build on AWS Bedrock, Azure AI Foundry, Databricks and frameworks including LangChain and CrewAI. Noma describes each of the three as carrying different builders and different risks.
Urgency rests on adoption forecasts rather than on incident history in the reviewed sources. Calcalist relays UBS Research forecasting that 53% of surveyed organizations plan to adopt agentic AI by 2026 and 83% by 2028, so the segmentation pays out as enterprise agent estates grow.
Four products share intelligence and feed into each other, by Noma’s own description. SecurityWeek describes continuous discovery across AI assets, infrastructure, agents and cloud environments, plus runtime protection that blocks malicious prompts, rogue outputs and unauthorized agents. Noma adds that red-teaming findings become enforced runtime patterns, so testing and protection work from one policy set.
Runtime detection works on sequences rather than on single actions. The homepage describes tracking the full behavioral chain of an agent session covering prompts, tool calls, data access and actions, and the platform page names prompt injection, data exfiltration, scope violations and intent drift as what the detection product catches.
Noma Labs is the public evidence of research depth. Its index lists seven dated vulnerability disclosures since September 2025, aimed at enterprise agent platforms and MCP tooling, including Salesforce Agentforce, Google Gemini Enterprise, a Context7 MCP server and a GitHub AI agent. The Hacker News and Infosecurity Magazine covered the Salesforce finding at a 9.4 severity score, and the Labs index carries an MCP bridge finding whose CVE record rates that flaw 10.0 and lists it fixed upstream.
In the reviewed sources, capability detail comes primarily from marketing pages and research writeups. The documentation subdomain at docs.noma.security returns a login page, so a reader without an account cannot check the depth those pages claim.
Noma pairs a founder-fronted story with a hired go-to-market organization. The About page lists Ralph Pisani as chief revenue officer, while Niv Braun remains the voice in company announcements such as the AWS partnership post.
Named validation leans on the homepage. Five voices appear under a customers heading, of which UiPath’s CISO and Kantar’s insights technology chief describe using the platform, while Varun Badhwar and Chris Hatter also appear on Noma’s strategic advisors roster and so are not arm’s-length references.
AWS is the differentiated motion. AWS’s own February 2026 announcement names Noma among the curated Security Hub Extended partner solutions, Security Boulevard reported the same roster quoting an AWS director of security services, and AWS states the plan carries pre-negotiated pricing, a single bill and no long-term commitments.
Independent confirmation of scale is absent from the reviewed record. Calcalist records that Noma discloses no revenue while reporting significant year-over-year growth, and the Gartner Peer Insights listing carries no reviews.
The reviewed Noma pages publish no prices, and AWS Marketplace carries a public benchmark. The listing prices a 12-month Noma Platform contract at $200,000, sets cost by the duration and terms of the contract, and takes private offers for custom quotes.
The metered unit stays undefined even on that listing. Its one 12-month dimension is named Noma Platform, with no metric such as protected AI assets, agents or users attached. The listing’s AI Insights block says the mapping of a unit to those metrics is not defined in the available data. A comparing buyer gets a price anchor without a unit behind it.
Entitlements end when a contract ends. The listing states that access expires if a customer does not renew or replace the contract before it ends, which sets what a departing buyer gives up.
Noma enforces at control points the customer already runs. The homepage describes Open Enforcement as decoupling policy from infrastructure and enforcing at agent hooks, MCP gateways, AI gateways, agent SDKs and direct APIs, instead of routing agent traffic through one gateway.
Coverage spans the three environments from one platform. The platform page describes discovery, posture management, access control, adversarial testing and runtime detection across all three, and SecurityWeek describes discovery reaching data platforms, infrastructure, agents and cloud environments.
AWS shortens the path for cloud-centric buyers. AWS states that its Extended plan gives customers pre-negotiated pay-as-you-go pricing, a single bill and no long-term commitments across the curated roster Noma sits in.
The Trust Center publishes six active certifications and gates the documents behind them. It lists SOC 2 Type II audited by EY, ISO 27001, HIPAA and ISO/IEC 42001, alongside 104 security controls.
The reports themselves stay behind a request. The portal records zero public documents and 31 available on request, so an evaluator sees which reports exist and asks Noma for the evidence.
Noma also gives security buyers a named counterpart. Its About page lists Diana Kelley as the company’s own chief information security officer.
Noma built its ecosystem story around AWS. AWS’s February 2026 announcement names Noma among the curated partner solutions in Security Hub Extended, a roster spanning endpoint, identity, email, network, data, browser, cloud, AI and security operations, and Noma’s blog states that it was named the AI Security partner for that plan.
Integrations reach beyond AWS. Noma says it is now available as a native guardrail at two points in the TrueFoundry stack, the AI Gateway that governs every request in and out of a model and the open-sourced Agent Harness that governs what an agent does once it acts.
The same ecosystem is the exposure. Microsoft Copilot Studio, Salesforce AgentForce, ServiceNow, AWS Bedrock and Databricks are environments Noma covers and each is run by the vendor that owns it, and Noma Labs has published a flaw in one of them, Salesforce Agentforce.
Niv Braun and Alon Tron founded Noma Security in 2023 after meeting in the IDF’s 8200 intelligence unit. Calcalist recorded 40 people at the Series B, and Gartner Peer Insights now lists a band of 51 to 200 employees.
Noma publishes a named executive team. The About page lists Ralph Pisani as chief revenue officer and Diana Kelley as chief information security officer.
Research is where the team’s public record is thickest. The Noma Labs index lists seven dated vulnerability disclosures between September 2025 and July 2026, credited to named researchers including Sasi Levi and Eli Ainhorn, and The Hacker News quotes Levi as Noma’s security research lead. The same index carries three general security research posts dated between July and August 2026, credited to Omer Holtzman, Ori Abargil and Gal Pnini.
The security executives Noma publishes are advisors rather than investors. Its About page groups Vijay Bolina of Google DeepMind, Caleb Sima of the CSA AI Security Alliance and Varun Badhwar of Endor Labs under a strategic advisors heading, while Calcalist names Evolution Equity Partners, Ballistic Ventures and Glilot Capital Partners as the investors in the round.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Noma Security: AI Security Platform for LLMs, RAG, & AI Agents | official | 2026-08-27 |
| f2 | SecurityWeek on the Noma Series B round | press | 2026-08-27 |
| f3 | Gartner Peer Insights company details for Noma Security | research | 2026-08-27 |
| f4 | CTech: Noma Security raises $100 million to defend against AI agent vulnerabilities | press | 2026-08-27 |
| f5 | AI Defense Matrix Catalog entry | other | 2026-06-13 |
| f6 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Noma Security homepage “"Noma helped us, in a systematic way, to detect issues and make them actionable in a way that we had struggled to do on our own. We felt we found a partner who could work with us and improve and constantly evolve as new threats emerge in the market."” | official | 2026-08-27 |
| s2 | Noma platform overview “AI agents run in three distinct environments across your organization, each with different architecture, different builders, and different risks.” | official | 2026-08-27 |
| s3 | About Noma Security “Strategic advisors” | official | 2026-08-27 |
| s4 | CTech: Noma Security raises $100 million to defend against AI agent vulnerabilities “The new capital brings Noma’s total funding to $132 million in less than two years.” | press | 2026-08-27 |
| s5 | TechCrunch: Noma is building tools to spot security issues with AI apps “Per a recent poll of over 350 IT leaders, more than half of the executives surveyed said the complexity of AI applications weakened their organization’s cybersecurity posture.” | press | 2026-08-27 |
| s6 | SecurityWeek: Noma Security raises $100 million for AI security platform “Israeli cybersecurity firm Noma Security announced on Thursday that it has raised $100 million in Series B funding for its AI and AI agent security platform.” | press | 2026-08-27 |
| s7 | SecurityWeek: Noma Security raises $32 million to safeguard gen-AI applications “Noma, headquartered in Herzliya, Tel Aviv, Israel, was founded in 2023 by Niv Braun (CEO) and Alon Tron (CTO). Both are former members of the IDF’s 8200 intelligence unit.” | press | 2026-08-27 |
| s8 | Gartner Peer Insights: Noma Security company details and review count “Company type Private Year Founded 2023 Head office location New York, United States Number of employees 51 - 200” | research | 2026-08-27 |
| s9 | The Hacker News: Salesforce patches critical ForcedLeak bug exposing CRM data “The vulnerability has been codenamed ForcedLeak (CVSS score: 9.4) by Noma Security, which discovered and reported the problem on July 28, 2025.” | press | 2026-08-27 |
| s10 | Infosecurity Magazine: Critical vulnerability in Salesforce AgentForce exposed “The flaw, known as ForcedLeak, carried a severity score of 9.4 and could have allowed attackers to steal sensitive CRM data through indirect prompt injection.” | press | 2026-08-27 |
| s11 | AWS News Blog: Security Hub Extended curated partner solutions “you can expand your security portfolio beyond AWS to help protect your enterprise estate through a curated selection of AWS Partner solutions, including 7AI, Britive, CrowdStrike, Cyera, Island, Noma, Okta, Oligo, Opti, Proofpoint, SailPoint, Splunk, a Cisco company, Upwind, and Zscaler.” | other | 2026-08-27 |
| s12 | Noma blog: AWS and Noma, building the foundation for secure enterprise AI “That's the problem Noma was built to solve, and it's why our partnership with AWS matters.” | official | 2026-08-27 |
| s13 | Help Net Security: Noma brings visibility and access governance to AI agents and MCP servers “Security teams configure each agent and MCP connection in one of three states: Approved, Requires Review, or Blocked.” | press | 2026-08-27 |
| s14 | Noma Security Trust Center “Certifications & audits 6 active [img alt: ] HIPAA HIPAA [img alt: ] SOC 2 Type II EY [img alt: ] ISO 27001 [img alt: ] ISO/IEC 42001” | official | 2026-08-27 |
| s15 | AWS Marketplace: Noma Security Platform listing “Noma Platform Noma Security Platform $200,000.00” | other | 2026-08-27 |
| s16 | Noma Labs research index “Noma Labs is an elite team of AI security researchers dedicated to uncovering enterprise AI vulnerabilities before attackers do.” | official | 2026-08-27 |
| s17 | CVE Program record: CVE-2026-59726 “cvssV3_1: baseScore 10 baseSeverity CRITICAL vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H” | other | 2026-08-27 |
| s18 | Security Boulevard: AWS extends reach of Security Hub to include third-party partners “Michael Fuller, director of security services for AWS, said an AWS Security Hub Extended offering provides access to cloud security offerings from partners such as 7AI, Britive, CrowdStrike, Cyera, Island, Noma, Okta, Oligo, Opti, Proofpoint, SailPoint, Splunk, Upwind, and Zscaler.” | press | 2026-08-27 |
| s19 | Rising in Cyber 2026: honoree list published by Notable Capital “The annual Rising in Cyber List showcases the most promising private cybersecurity companies, as selected by 150 leading CISOs and operating security executives across the industry.” | other | 2026-08-27 |
| s20 | Probe: docs.noma.security returns a login page “Loading Login Page...” | official | 2026-08-27 |
| s21 | Noma blog: Noma is now a native guardrail across the TrueFoundry stack “Noma Security is now available as a native guardrail across two points in the TrueFoundry stack: the AI Gateway, which governs every request in and out of a model, and the newly open sourced Agent Harness, which governs what an agent does once it starts taking action.” | official | 2026-08-27 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Noma Security homepage “"Noma helped us, in a systematic way, to detect issues and make them actionable in a way that we had struggled to do on our own. We felt we found a partner who could work with us and improve and constantly evolve as new threats emerge in the market."” | official | 2026-08-27 |
| s2 | Noma platform overview “AI agents run in three distinct environments across your organization, each with different architecture, different builders, and different risks.” | official | 2026-08-27 |
| s3 | About Noma Security “Strategic advisors” | official | 2026-08-27 |
| s4 | CTech: Noma Security raises $100 million to defend against AI agent vulnerabilities “The new capital brings Noma’s total funding to $132 million in less than two years.” | press | 2026-08-27 |
| s5 | TechCrunch: Noma is building tools to spot security issues with AI apps “Per a recent poll of over 350 IT leaders, more than half of the executives surveyed said the complexity of AI applications weakened their organization’s cybersecurity posture.” | press | 2026-08-27 |
| s6 | SecurityWeek: Noma Security raises $100 million for AI security platform “Israeli cybersecurity firm Noma Security announced on Thursday that it has raised $100 million in Series B funding for its AI and AI agent security platform.” | press | 2026-08-27 |
| s7 | SecurityWeek: Noma Security raises $32 million to safeguard gen-AI applications “Noma, headquartered in Herzliya, Tel Aviv, Israel, was founded in 2023 by Niv Braun (CEO) and Alon Tron (CTO). Both are former members of the IDF’s 8200 intelligence unit.” | press | 2026-08-27 |
| s8 | Gartner Peer Insights: Noma Security company details and review count “Company type Private Year Founded 2023 Head office location New York, United States Number of employees 51 - 200” | research | 2026-08-27 |
| s9 | The Hacker News: Salesforce patches critical ForcedLeak bug exposing CRM data “The vulnerability has been codenamed ForcedLeak (CVSS score: 9.4) by Noma Security, which discovered and reported the problem on July 28, 2025.” | press | 2026-08-27 |
| s10 | Infosecurity Magazine: Critical vulnerability in Salesforce AgentForce exposed “The flaw, known as ForcedLeak, carried a severity score of 9.4 and could have allowed attackers to steal sensitive CRM data through indirect prompt injection.” | press | 2026-08-27 |
| s11 | AWS News Blog: Security Hub Extended curated partner solutions “you can expand your security portfolio beyond AWS to help protect your enterprise estate through a curated selection of AWS Partner solutions, including 7AI, Britive, CrowdStrike, Cyera, Island, Noma, Okta, Oligo, Opti, Proofpoint, SailPoint, Splunk, a Cisco company, Upwind, and Zscaler.” | other | 2026-08-27 |
| s12 | Noma blog: AWS and Noma, building the foundation for secure enterprise AI “That's the problem Noma was built to solve, and it's why our partnership with AWS matters.” | official | 2026-08-27 |
| s13 | Help Net Security: Noma brings visibility and access governance to AI agents and MCP servers “Security teams configure each agent and MCP connection in one of three states: Approved, Requires Review, or Blocked.” | press | 2026-08-27 |
| s14 | Noma Security Trust Center “Certifications & audits 6 active [img alt: ] HIPAA HIPAA [img alt: ] SOC 2 Type II EY [img alt: ] ISO 27001 [img alt: ] ISO/IEC 42001” | official | 2026-08-27 |
| s15 | AWS Marketplace: Noma Security Platform listing “Noma Platform Noma Security Platform $200,000.00” | other | 2026-08-27 |
| s16 | Noma Labs research index “Noma Labs is an elite team of AI security researchers dedicated to uncovering enterprise AI vulnerabilities before attackers do.” | official | 2026-08-27 |
| s17 | CVE Program record: CVE-2026-59726 “cvssV3_1: baseScore 10 baseSeverity CRITICAL vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H” | other | 2026-08-27 |
| s18 | Security Boulevard: AWS extends reach of Security Hub to include third-party partners “Michael Fuller, director of security services for AWS, said an AWS Security Hub Extended offering provides access to cloud security offerings from partners such as 7AI, Britive, CrowdStrike, Cyera, Island, Noma, Okta, Oligo, Opti, Proofpoint, SailPoint, Splunk, Upwind, and Zscaler.” | press | 2026-08-27 |
| s19 | Rising in Cyber 2026: honoree list published by Notable Capital “The annual Rising in Cyber List showcases the most promising private cybersecurity companies, as selected by 150 leading CISOs and operating security executives across the industry.” | other | 2026-08-27 |
| s20 | Probe: docs.noma.security returns a login page “Loading Login Page...” | official | 2026-08-27 |
| s21 | Noma blog: Noma is now a native guardrail across the TrueFoundry stack “Noma Security is now available as a native guardrail across two points in the TrueFoundry stack: the AI Gateway, which governs every request in and out of a model, and the newly open sourced Agent Harness, which governs what an agent does once it starts taking action.” | official | 2026-08-27 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.