Operant AI

Security for AI Cloud SecurityDetection Response

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software.
Founded 2021
Funding $13.5M
Last updated 2026-07-17

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

This analysis is scoped to AI runtime security platform.

Operant AI protects four AI runtime surfaces under one 3D defense methodology, blocking prompt injection and data exfiltration as traffic flows through live Kubernetes, APIs, agents, and employee laptops, with automatic redaction instead of after-the-fact scoring. That in-line enforcement is the deepest engineering in its record, yet Operant aims its loudest messaging at the AI and MCP guardrail story larger platforms keep buying up, with Cato buying Aim Security and 2025 deals sending Prompt Security to SentinelOne and Lakera to Check Point. The founders carry systems pedigree from Apple, and open-source Woodpecker wins developer reach. The proof gap is what a buyer weighs: no independently reported customer reference appears in the record, and the named praise is vendor testimonials.

Sourced Details

Description Operant AI Gatekeeper detects and blocks unauthorized AI behavior in real time across AI applications, APIs, MCP, and agents, stopping threats such as prompt injection and lateral movement between agent systems. [f1]
Founded 2021 [f2]
HQ San Francisco, California, USA [f3]
Funding $13.5M total [f4]
Latest funding Series A, $10M, September 2024 [f4]
Deployment Hybrid, Self-hosted [f5]

Products

Product What it does
Operant AI Gatekeeper Operant AI Gatekeeper: Runtime defense that secures live AI apps and agentic workflows, addressing data leakage and rogue agents with in-line redaction and MCP threat blocking.
Operant 3D Runtime Defense Runtime cloud-native security across Kubernetes, APIs, and services using Discovery, Detection, and Defense, blocking common runtime attacks without code changes.
Woodpecker Open-source automated red-teaming engine that simulates attacks across Kubernetes, APIs, and AI models and agents, mapping to OWASP, MITRE ATLAS, and NIST.
Operant Endpoint Protector Endpoint app for macOS, Windows, and Linux that discovers shadow AI, governs coding agents, and audits local MCP clients on the device.
Agent Protector Real-time AI agent security that discovers and monitors an agentic ecosystem, detects agent behaviors and threats, and enforces inline scope and intent controls.
Operant MCP Gateway Enterprise MCP gateway that secures and governs Model Context Protocol servers and the AI agents that connect through them.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Operant AI Gatekeeper is a runtime defense that secures live AI apps and agentic workflows, addressing data leakage and rogue agents with in-line redaction and MCP threat blocking. It is mapped to the AI Defense Matrix. [f6]

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

Operant AI provides runtime defense for Kubernetes, APIs, and cloud services without code changes. This conventional security is mapped to the Cyber Defense Matrix. [f7]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 25 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Operant names a specific buyer but the pain is qualitative and grounded in voluntary frameworks (OWASP, MITRE ATLAS, NIST) rather than independently quantified, and the non-vendor framing is limited to SecurityWeek, so it matches the present-but-unproven default. [s5, s8, s4]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 4/5 The 3D methodology spans discovery, detection, and runtime defense across Kubernetes, APIs, and AI, and Operant ships the open-source Woodpecker red-teaming engine that SiliconANGLE covered and that maps to OWASP, MITRE ATLAS, and NIST. Public OSS plus an external press writeup is an independent validation point beyond product-page claims alone. [s7, s8, s2]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 The market-timing evidence is a Gartner Innovation Insight cited from Operant's own homepage, general AI-vulnerability awareness in SiliconANGLE, and the agent-adoption enabler since 2024, which are indirect buyer-side signals rather than multiple corroborated demand signals, holding it at the plausible-timing default. [s4, s7, s1]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 Bhavsar's Apple and Arm builds and Tembey's VMware hybrid-cloud and Georgia Tech background are elite adjacent-infrastructure pedigree but carry no prior security-product exit and no sustained publication record. [s3, s5]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 Named endorsements come from Juniper Networks, Chargebee, Cohere, and ClickHouse leaders, but all appear only on Operant's own pages rather than independent reporting, and no customer count or revenue is disclosed. Tier-one backing from SineWave and Felicis supports a small upward adjustment to hold at 3. [s1, s6, s5]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 The roughly 13 and a half million dollars raised against a high release cadence, Woodpecker in 2025 and Endpoint Protector in 2026, shows visible output per dollar, but a single 2024 Series A and undisclosed revenue keep it at adequate rather than a longer funded arc. [s6, s9, s5]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Operant straddles two recognizable slots, cloud-native runtime security (CADR and CNAPP) and AI and MCP runtime defense, so a buyer must decide which budget line it fills. That dual placement reads less cleanly than Straiker's single agentic-AI-security fit at 4. [s1, s4, s2]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 The cloud-runtime base raises replication cost more than the AI line, but both capabilities are absorbable by CNAPP platforms such as Wiz, Palo Alto Networks, and Sysdig, and the open-source Woodpecker is community reach rather than a proprietary data flywheel. [s4, s8, s2]
Business Risks Cloud-security platforms such as Wiz, Palo Alto Networks, or Sysdig could add AI and MCP runtime protection to suites enterprises already buy, removing the third-party budget line for Operant's AI Gatekeeper line, the same absorption that took Lakera into Check Point and Prompt Security into SentinelOne off the board as independents in 2025…
  • Cloud-security platforms such as Wiz, Palo Alto Networks, or Sysdig could add AI and MCP runtime protection to suites enterprises already buy, removing the third-party budget line for Operant's AI Gatekeeper line, the same absorption that took Lakera into Check Point and Prompt Security into SentinelOne off the board as independents in 2025.
  • The public traction record rests on vendor-displayed testimonials from Juniper, Chargebee, Cohere, and ClickHouse leaders with no named customer speaking independently, so a procurement team could pick a rival on equal footing within a year.
  • Operant leads its messaging with the crowded AI and MCP line rather than its harder-to-copy cloud-runtime base, so if AI-security marketing fails to convert it could dilute the clearer cloud-runtime story without winning the AI budget.
  • With a single 2024 Series A of 10 million dollars, a better-funded rival could outspend Operant on enterprise sales, and the company has disclosed no follow-on raise to match an enterprise go-to-market.
  • Capability claims rest largely on Operant's own pages, so an independent benchmark showing weaker runtime detection than the marketing implies would undercut the positioning.
Problem & Market Operant AI treats the live, running cloud application as the asset under attack, including the AI agents and MCP tools now woven into it…

Operant AI treats the live, running cloud application as the asset under attack, including the AI agents and MCP tools now woven into it. The company sells runtime defense for two layers at once: ordinary cloud workloads on Kubernetes and APIs, and the newer AI agents, models, and Model Context Protocol connections that enterprises are wiring into those workloads. SecurityWeek frames the buyer's pain as the limit of static pre-deployment security, which checks code before it ships but cannot see attacks against applications already in production.

The threat taxonomy maps to recognized frameworks rather than vendor invention. Operant's open-source Woodpecker tool tests against the OWASP Top 10 for Kubernetes, APIs, and AI, alongside MITRE ATLAS and NIST, which grounds the pain in catalogs security teams already track. The specific AI risks Operant names, prompt injection, data leakage, rogue agents, and MCP tool poisoning, are entries those frameworks recognize.

Buyer-side demand is visible beyond Operant's own claims. The company cites a 2025 Gartner Innovation Insight on MCP gateways, evidence that analysts are organizing a category around the runtime AI problem Operant sells against, though the depth of that demand for a standalone tool is not yet established in the public record. [s5, s8, s4]

Product Capabilities Operant runs one methodology, Discovery, Detection, and Defense, across several product lines rather than a single point feature…

Operant runs one methodology, Discovery, Detection, and Defense, across several product lines rather than a single point feature. The 3D Runtime Defense base secures cloud workloads on Kubernetes, APIs, and services, blocking common runtime attacks without code changes. AI Gatekeeper extends that defense to live AI applications, agents, and agentic workflows across public, private, hybrid, and edge environments, with trust scoring, agentic access controls, and threat blocking for MCP servers, clients, and Non-Human Identities.

The company ships the offensive side as open source. Woodpecker is an automated red-teaming engine, covered by SiliconANGLE at its May 2025 launch, that simulates attacks across Kubernetes, APIs, and AI models and agents, including prompt injection, jailbreaks, and model theft. Releasing it free buys distribution and developer goodwill that a closed tool would not, and any feedback of that threat knowledge into Operant's defensive products remains a possibility that public sources do not document.

Public technical depth is mixed. The open-source Woodpecker code and the technical blogs on MCP tool poisoning give a buyer more to assess than marketing pages alone, but the commercial products are described in product-page terms, and no third-party benchmark or independent evaluation of detection efficacy was observed in the pages reviewed. [s7, s8, s2]

Competitive Positioning Operant competes on two fronts that consolidate differently…

Operant competes on two fronts that consolidate differently. The cloud-native runtime base contends with CNAPP and cloud-security platforms such as Wiz, Palo Alto Networks, and Sysdig, while the AI Gatekeeper line contends with AI-security entrants and the same platforms as they add AI controls. The harder-to-copy ground is the cloud-runtime base, because live protection for Kubernetes and APIs is slower to replicate than AI guardrails a platform can bolt on.

Operant's messaging now leads with the AI and MCP story. That is the louder market, but it is also the one larger platforms keep absorbing. Three AI-security independents close to Operant's AI line were each bought inside about six weeks in 2025: Cato Networks acquired Aim Security in September, SentinelOne agreed to buy Prompt Security in August, and Check Point acquired Lakera in September. AI runtime protection has repeatedly arrived bundled into a larger platform rather than standalone.

The structural question is whether Operant's dual footprint helps or splits it. Selling cloud-runtime and AI-runtime together lets one engine cover both, which is a real efficiency, but it also asks buyers to place a vendor in two budget lines at once, and the clearer of those two stories risks being overshadowed by the more crowded one. [s4, s2, s8, s12, s13, s14]

Go-to-Market & Traction Operant's clearest proof points sit on its own pages…

Operant's clearest proof points sit on its own pages. The homepage carries endorsements from leaders at Juniper Networks, Chargebee, Cohere, and ClickHouse praising the runtime approach, but these appear as vendor-curated testimonials rather than customers speaking in independent reporting. No customer count, revenue figure, or marketplace distribution motion is disclosed in the public record reviewed.

The strongest outside signals are press coverage and analyst mentions. SiliconANGLE covered the Woodpecker launch, SecurityWeek and GlobeNewswire reported the Series A, and Operant cites inclusion in 2025 Gartner AI-security reports, which together show the demand-generation channel works. These mark visibility and momentum rather than verified commercial scale.

Commercial proof is otherwise thin for the stage. Operant discloses no customer count or revenue, consistent with an early enterprise motion on a single Series A, and the most important readiness gap is the absence of one named reference customer willing to speak on the record. [s1, s7, s5]

Team & Credibility Operant's founders pair deep infrastructure engineering with security systems work…

Operant's founders pair deep infrastructure engineering with security systems work. Co-founder and CEO Vrajesh Bhavsar built core iOS and macOS technologies at Apple, including Data Protection and Secure Enclave, then ran the ML and AI business unit at Arm, and he holds eight patents in distributed systems, data, and security. That is platform-scale systems experience rather than a security-product sales background.

Co-founder and CTO Priyanka Tembey brings cloud-native depth. She earned a computer science PhD from Georgia Tech and was a foundational engineer who helped build out VMware's hybrid-cloud product, which maps directly to the runtime enforcement Operant now sells. Co-founder and COO Ashley Roof adds go-to-market experience from Google and a prior CMO role at Transposit.

The board and investor signal reinforces the pedigree. Operant's Series A added Patricia Muoio of SineWave Ventures, a former NSA and DoD leader, and Nancy Wang of Felicis, formerly the data-protection general manager at AWS, to its board. What is absent is a prior security exit or a sustained public research record of the kind that lifts the strongest teams in this category. [s3, s10, s5]

Trust Readiness Operant states on its security page, linked from the site footer, that it is SOC 2 Type II compliant, and the same page documents vulnerability scanning of code and containers, third-party vendor assessment, encryption at rest and in transit, least-privilege access, and a responsible-disclosure channel…

Operant states on its security page, linked from the site footer, that it is SOC 2 Type II compliant, and the same page documents vulnerability scanning of code and containers, third-party vendor assessment, encryption at rest and in transit, least-privilege access, and a responsible-disclosure channel. The page names no ISO 27001 certification and offers no downloadable report or self-service trust portal, so the audit itself reaches buyers through procurement rather than open download. Because the product inspects an organization's runtime traffic, AI workloads, agent behavior, and MCP connections, that access still invites detailed data-handling scrutiny the public page does not fully answer.

The deployment model favors fast adoption over heavy assurance. Operant markets single-step deployment and a 7-day free trial with most teams seeing an AI inventory within a day, which lowers the barrier to trying the product but does not substitute for the report-level evidence enterprise procurement expects. For a company at this stage, exposing the SOC 2 report and data-handling terms in a verifiable form is the readiness item most likely to surface in procurement. [s11, s2, s9]

Competitors Wiz, Palo Alto Networks, Aim Security, Straiker, Lakera, Prompt Security…
Company Relationship Note Compare
Wiz adjacent Cloud-security platform positioned to fold runtime AI and MCP protection into a suite enterprises already own, the absorption Operant's AI line faces.
Palo Alto Networks adjacent Platform vendor with cloud and AI security lines able to bundle runtime AI controls into existing enterprise contracts. N/AWe scored these companies at different scopes, so the totals measure different things.
Aim Security competes with AI security platform pairing discovery, posture, and runtime defense for the same enterprise AI buyer, acquired by Cato Networks.
Straiker competes with Same-asset AI security entrant offering discovery, offensive testing, and runtime blocking of agent attacks.
Lakera competes with Runtime AI security and red-teaming specialist, acquired by Check Point, overlapping Operant's AI Gatekeeper and Woodpecker lines.
Prompt Security competes with Runtime LLM and agent guardrails vendor acquired by SentinelOne, overlapping Operant's AI runtime protection.

Add analyzed competitors to compare them side by side with Operant AI.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Exposed 12 /21 Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software. pivot urgently

Operant AI is durable on engineering and exposed on what it owns. Its software inspects and blocks the traffic running through Kubernetes, APIs, agents, and employee laptops, redacting sensitive data as it flows, so once a team routes coverage and policies through it, switching means rebuilding that work, real friction short of true lock-in. The runtime engineering draws on the founders' Apple and VMware systems work. The weaker side: the SOC 2 attestation eases procurement without blocking a substitute, open-source Woodpecker is code a funded rival could rebuild, and no named regulated customer appears in the record, only vendor praise from Juniper, Chargebee, Cohere, and ClickHouse leaders. Operant's hold deepens with each account it covers, not with a scarce asset.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Operant ships endpoint software and the open-source Woodpecker engine and markets runtime and agent protection deployed into customer environments, with no analyst-staffed managed service that accepts accountability for the security outcome.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 In-line enforcement embeds across Kubernetes, APIs, agents, and the device with accumulated redaction and access policies, so leaving means re-plumbing runtime coverage, meaningful friction short of network effects or mandated data residency.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 Operant self-displays a SOC 2 Type II attestation on its footer-linked security page, which eases procurement but blocks no substitute, and the cited record identifies no regulation mandating this product class, so compliance is table-stakes rather than a moat.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Enforcing in the live traffic flow with auto-redaction and quarantine, modeling the MCP and non-human-identity attack surface, and mapping an open-source red-team engine to recognized frameworks is adversarial-AI and runtime-systems work the founders are equipped to do from Apple and VMware systems builds.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 The buyer is the enterprise security and platform team, but the endorsements reduce to vendor-displayed praise from Juniper Networks, Chargebee, Cohere, and ClickHouse leaders with no named regulated customer on the record, so the profile holds at the cluster level rather than the procurement-gated roster a 3 needs.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 Operant runs one runtime-defense methodology across the cluster, API, agent, and device, a control layer beside the workload rather than infrastructure the workload cannot run without, and it still ingests from the source tools and identities it does not own.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 Operant's headline asset, the Woodpecker red-team engine, is open source and replicable, and the defensive detection rests on the company's own expertise rather than a named non-public corpus, with no proprietary adversarial-pattern dataset or accuracy benchmark of the kind a Lakera builds appearing in the fetched sources, so nothing compounds into a content moat.
Strategic Market Segmentation Operant AI targets the enterprise security and platform team that runs live AI and cloud workloads and needs to defend them in production…

Operant AI targets the enterprise security and platform team that runs live AI and cloud workloads and needs to defend them in production. The product line addresses runtime attacks on Kubernetes, APIs, and services, then extends the same defense to AI applications, agents, and Model Context Protocol tooling that teams are wiring into those workloads. SecurityWeek frames the buyer's pain as the limit of static pre-deployment security, which checks code before it ships but cannot see attacks against applications already running.

The four product surfaces widen the segment under one methodology. AI Gatekeeper covers live AI apps and agents, 3D Runtime Defense covers cloud workloads, Woodpecker offers free offensive testing, and Endpoint Protector now reaches the employee laptop where shadow AI tools and coding agents run. That spread lets Operant sell to the platform team, the application security team, and the workforce security team, and the live homepage as of July 2026 also markets Agent Protector and an MCP Gateway, entries beyond the four surfaces this snapshot assesses.

Public demand evidence is stronger on analyst mentions than on independently reported customer deployments. Operant presents itself as a Gartner featured vendor across five AI security reports including the 2025 AI TRiSM Market Guide, which shows analysts organizing a category around the runtime AI problem. Vendor-displayed testimonials from leaders at Chargebee, Juniper Networks, Cohere, and ClickHouse exist on the homepage but do not establish commercial scale, and the public record still lacks a named customer describing the segment fit in independent reporting.

Product Capabilities & AI Advantages The claimed advantage is enforcement in the live traffic flow rather than scoring after an alert…

The claimed advantage is enforcement in the live traffic flow rather than scoring after an alert. Operant blocks prompt injection and data exfiltration as data flows through the running stack and applies in-line auto-redaction, obfuscation, and blocking of sensitive data, with intelligent quarantine of suspicious containers and AI models and token-level rate limits. SecurityWeek reports the product claims to block more than 80% of common runtime attacks including the OWASP Top 10 without significant code changes.

The agent-specific work centers on MCP and non-human identity. AI Gatekeeper adds detection and access control for Model Context Protocol tooling and AI Non-Human Identities across the runtime and API access layers, with fine-grained identity-aware enforcement for autonomous agents. The same 3D methodology of discovery, detection, and defense runs across the cluster, the API, the agent, and the device.

The footprint is publicly verifiable, with the open-source Woodpecker engine giving outside engineers a way to inspect the offensive testing. What holds up, though, is engineering craft rather than data, because the detection rests on the company's own expertise and the runtime enforcement is a capability a funded rival can build against the same MCP and agent primitives.

Sales Engagement & Go-to-Market Operant pairs free tooling with analyst visibility…

Operant pairs free tooling with analyst visibility. Releasing Woodpecker as an open-source red-teaming engine gives Operant a public distribution surface, and both developer conversion into paid sales and any feedback of threat knowledge into the paid products remain possibilities the public sources do not document. SiliconANGLE covered the launch and framed Operant as a runtime application protection platform, outside coverage of the offensive side.

Named traction is thin and vendor-curated. The homepage carries praise from Juniper Networks, Chargebee, Cohere, and ClickHouse leaders, but these appear only on Operant's own pages rather than in independent reporting, and no customer count or revenue figure is disclosed. The readiness gap is one named reference account willing to speak on the record.

The analyst mentions are vendor-reported. Operant's own homepage presents Gartner featured-vendor placements across five AI security reports, with YourStory independently corroborating the AI TRiSM representative-vendor mention, and press from SecurityWeek and SiliconANGLE shows the company earns coverage. These mark visibility and momentum rather than verified commercial scale.

Pricing Model No price appears on the fetched pages, so the charged unit and list price stay outside the reviewed record…

No price appears on the fetched pages, so the charged unit and list price stay outside the reviewed record. Selling through demos and sales conversations fits a product that inspects an organization's runtime traffic, agents, and identities, and the absence withholds the budget-anchoring signal some peers publish.

The four surfaces imply more than one value meter. The cluster and API defense reads as a platform subscription, the endpoint app reads as a per-device or per-seat workforce spend, and Woodpecker is free, so what each paid line charges by, whether workloads, agents, devices, or telemetry volume, is not stated publicly.

The inferable belief is that buyers pay for runtime coverage of the live application and agent surface rather than for discrete features. The unit and any consumption caps cannot be confirmed from the fetched pages, which route buyers toward demos.

Product Delivery & Operations Operant deploys in the runtime path with light integration across several surfaces…

Operant deploys in the runtime path with light integration across several surfaces. The platform blocks common runtime attacks on Kubernetes, APIs, and services without significant code changes, and the Endpoint Protector client runs on macOS, Windows, and Linux with a lightweight footprint and no kernel extensions required, which lowers the integration barrier for both the cluster and the laptop.

The public materials emphasize customer-deployed software rather than a managed service. Operant ships endpoint software and the open-source Woodpecker engine, and markets runtime and agent protection deployed into customer environments, with the in-line auto-redaction and adaptive enforcement running automatically once installed and no analyst-staffed service surfacing in the fetched pages. Operational collateral such as published uptime or support SLAs does not surface either.

The deployment posture favors fast adoption over heavy assurance. The endpoint client advertises sixty-second installation, and free offensive testing makes the line easy to try, but because the product sits in the live data path and reads prompts, tool calls, and identities, a buyer should resolve data-handling and retention terms in a formal review.

Earning Customers' Trust Operant states on its security page, linked from the site footer, that it is SOC 2 Type II compliant, and the page documents secure-by-default policies, least-privilege access enforced from infrastructure to the product layer, and policy-as-code baked into CI/CD…

Operant states on its security page, linked from the site footer, that it is SOC 2 Type II compliant, and the page documents secure-by-default policies, least-privilege access enforced from infrastructure to the product layer, and policy-as-code baked into CI/CD. That is meaningful procurement assurance for an autonomous tool that reads privileged runtime traffic, though the page offers no openly downloadable report.

The product handles sensitive signal, which raises the assurance bar. Because the line inspects prompts, tool calls, agent loops, identities, and data in use across the live stack, a buyer carries data-handling and model-provider questions the published page does not fully answer. Operant frames in-line auto-redaction as keeping sensitive data inside the native application environment, which is part of the trust case.

The attestation is enterprise-grade but table-stakes rather than a moat. The cited record identifies no regulation mandating this product class, the page exposes no self-service report portal, and it names no ISO 27001 certification, so the attestation eases a purchase without blocking a substitute.

Platform Strategy & Ecosystem Positioning Operant positions itself as a single runtime-defense layer across the cluster, the API, the agent, and the device rather than a point tool…

Operant positions itself as a single runtime-defense layer across the cluster, the API, the agent, and the device rather than a point tool. One 3D methodology of discovery, detection, and defense runs across all four surfaces, so the platform claim rests on covering the full live application and agent stack from one methodology rather than on owning a data asset other software depends on.

That breadth is a real efficiency and a real exposure. Covering four surfaces from one methodology lets Operant meet a buyer at the cluster, the API gateway, or the laptop, but every surface is a control layer beside the workload rather than infrastructure the workload cannot run without, and the line still ingests from the source tools and identities it does not own.

The ecosystem play leans on open source for reach. Woodpecker maps offensive testing to recognized frameworks, which builds developer goodwill, but it is published code a rival can study and reuse, so it strengthens distribution more than it strengthens lock-in.

Team & Execution Capability Operant has three co-founders, and its technical credibility comes from the two who build the infrastructure…

Operant has three co-founders, and its technical credibility comes from the two who build the infrastructure. SecurityWeek independently names co-founders Vrajesh Bhavsar and Priyanka Tembey as veteran software engineers, and Operant's own record describes Bhavsar building Data Protection and Secure Enclave at Apple and Tembey as a foundational engineer on VMware's hybrid-cloud product. The third co-founder, Ashley Roof, is COO and carries the go-to-market track record rather than the systems one, having led sales and marketing from Google through a CMO role at Transposit. That pairing gives Operant platform-scale systems experience that maps onto runtime enforcement alongside a dedicated commercial leader.

The backing reinforces the founder signal. SecurityWeek reports the Series A investment was provided by SineWave Ventures, Felicis, Alumni Ventures, Massive, Calm Ventures, and Gaingels, bringing total funding to 13.5 million dollars since the April 2023 public launch. That is an early-stage round sized to an early enterprise motion rather than a late-stage war chest.

The verifiable strength is the founders' domain track record. What is absent from the fetched record is a prior security-company exit or a sustained public research record of the kind that lifts the strongest teams in this category, leaving depth below the principals the open question.

Sources

Company Detail Sources (7)
Id Source Tier Accessed
f1 Operant AI: AI Gatekeeper official 2026-07-09
f2 YourStory profile stating founded 2021 (conflicts: CB Insights lists 2018; SecurityWeek dates the public launch to April 2023, previously mis-read as founding) press 2026-07-15
f3 SecurityWeek on Operant AI (San Francisco) press 2026-06-13
f4 GlobeNewswire on Operant AI $10M Series A (total funding $13.5M) press 2026-06-13
f5 AI Defense Matrix Catalog entry other 2026-06-10
f6 AI Defense Matrix Catalog mapping other 2026-06-23
f7 Operant AI platform official 2026-06-14
Profile Analysis Sources (19)
Id Source Tier Accessed
s1 Operant AI homepage (Juniper Networks, Chargebee, Cohere, and ClickHouse testimonials)
“Operant's runtime enforcement gives companies the ability to secure their next-gen K8s initiatives ... Raj Yavatkar, CTO, Juniper Networks ... Suhel Khan, Cyber Security Leader | Chargebee ... Prutha Parikh, Head of Security at Cohere ... Martin Choluj, CISO at Clickhouse”
official 2026-07-01
s2 Operant AI Gatekeeper product page (MCP and AI NHI protection)
“get comprehensive support for Model Context Protocol (MCP), and AI Non-Human Identities (NHIs) with detection and access control to defend across both the runtime and API access layers of agent tools”
official 2026-06-13
s3 About Operant AI leadership (Bhavsar ex-Apple, Tembey ex-VMware, Roof)
“Vrajesh built core technologies for iOS & macOS including Data Protection and Secure Enclave at Apple ... Priyanka was one of the foundational engineers to build out VMware's hybrid cloud product”
official 2026-06-13
s4 Operant AI Gatekeeper announcement (runtime defense beyond Kubernetes)
“Operant's 3D Runtime Protection is now available across public, private and hybrid cloud platforms”
official 2026-06-13
s5 SecurityWeek on Operant AI $10M Series A and April 2023 public launch
“Operant AI has raised a total of $13.5 million since its public launch in April 2023. Founded by veteran software engineers Vrajesh Bhavsar and Priyanka Tembey”
press 2026-06-13
s6 GlobeNewswire on Operant AI $10M Series A co-led by SineWave and Felicis
“announced today that it has raised $10 million in a Series A funding round co-led by SineWave Ventures and Felicis, with participation from Alumni Ventures, Massive, Calm Ventures, Gaingels”
press 2026-06-13
s7 SiliconANGLE on Operant AI launching Woodpecker open-source red-teaming
“Operant AI Inc., a startup that offers a runtime application protection platform, today announced the launch of Woodpecker, an open-source, automated red teaming engine”
press 2026-06-13
s8 Operant Woodpecker introduction (K8s, API, AI red-teaming features)
“Covers across threat vectors for OWASP top 10 for K8s, API, and AI, MITRE ATLAS, and NIST.”
official 2026-06-13
s9 Operant Endpoint Protector announcement (device-level AI workforce security, published 2026-05-26 per page metadata)
“datePublished: 2026-05-26T18:10:49.890Z ... Today we're announcing Operant Endpoint Protector, purpose-built security for the AI Workforce ... Endpoint Protector applies Operant's 3D Protection methodology, Discovery, Detection, Defense, directly on the device.”
official 2026-07-01
s10 Operant Series A announcement (board additions Muoio and Wang)
“Patricia Muoio, partner at SineWave Ventures and former NSA/DoD leader, and Nancy Wang, Venture Partner at Felicis and former General Manager / Director of Data Protection at AWS, joining our Board of Directors”
official 2026-06-13
s11 Security at Operant page (SOC 2 Type II, linked from the site footer)
“Operant is SOC 2, Type II Compliant.”
official 2026-06-16
s12 Cato Networks press on acquiring Aim Security (September 3, 2025)
“Cato Networks, the SASE leader, announced today that it acquired Aim Security, a visionary leader of AI security. This is Cato's first-ever acquisition”
press 2026-06-16
s13 Check Point press on acquiring Lakera (September 16, 2025)
“Check Point Software Technologies Ltd. today announced it has entered into an agreement to acquire Lakera, one of the world's leading AI-native security platforms for Agentic AI applications.”
press 2026-06-16
s14 SentinelOne press on acquiring Prompt Security (announced August 5, 2025)
“SentinelOne to Acquire Prompt Security to Advance GenAI Security and Agent Security Strategy ... Industry-first AI runtime security gives IT and security teams visibility, confidence and control over AI use”
press 2026-06-16
s15 Help Net Security: Woodpecker, open-source red teaming for AI, Kubernetes, APIs (Tembey interview, May 2025)
“we wanted to democratize access to core red teaming capabilities that we don’t think should be limited to only the biggest companies with huge security budgets”
press 2026-07-03
s16 The New Stack: Kubernetes Runtime Defense Evolves Beyond eBPF (Jeffrey Burt, November 2024)
“Operant isn’t the only vendor looking to protect the runtime environment ... While they warn developers of attacks, Operant’s technology takes steps to shut them down”
press 2026-07-03
s17 YourStory: Operant AI enters Indian market to secure AI systems in real time (March 2025)
“Silicon Valley-based cybersecurity AI startup Operant AI is entering the Indian market, introducing its Runtime AI Application Defense Platform to safeguard AI systems against emerging threats.”
press 2026-07-03
s18 CB Insights company profile: Operant AI (Series A stage, investor roster, competitor set)
“Operant AI's latest funding round is Series A ... Investors of Operant AI include Felicis, Calm Ventures, SineWave Ventures, Gaingels, Massive Capital Partners and 11 more ... Competitors of Operant AI include WitnessAI, E2B, Virtue AI, RAD Security, Lacework and 7 more”
research 2026-07-03
s19 SEC EDGAR Form D: Gaingels Operant LLC, investment vehicle of Series A backer Gaingels ($221,275, first sale 2024-08-08)
“Name of Issuer Gaingels Operant LLC ... Date of First Sale 2024-08-08 ... Total Amount Sold $ 221,275 USD”
regulatory 2026-07-03
Deep-Dive Sources (17)
Id Source Tier Accessed
s1 Operant AI homepage: 3D defense, MCP security, Endpoint Protector, Gartner AI TRiSM, and named testimonials
“Get 3D Defense for your entire AI application ecosystem from models to APIs ... Raj Yavatkar, CTO, Juniper Networks ... Suhel Khan, Cyber Security Leader | Chargebee ... Prutha Parikh, Head of Security at Cohere ... Martin Choluj, CISO at Clickhouse”
official 2026-07-01
s2 Operant AI Gatekeeper product page (MCP and AI NHI protection, Gartner featured vendor)
“get comprehensive support for Model Context Protocol (MCP), and AI Non-Human Identities (NHIs) with detection and access control to defend across both the runtime and API access layers of agent tools. Get fine-grained, identity-aware enforcement across increasingly autonomous agentic systems.”
official 2026-06-17
s3 Operant 3D Runtime Defense for Kubernetes, APIs, and services (in-line auto-redaction, quarantine)
“In-line Auto-Redaction, Obfuscation and Blocking. Automatically redact and block sensitive data flows, safeguarding data privacy by default. Intelligent Quarantine of Runtime Threats. Isolate suspicious third-party containers and AI models to prevent malicious activity.”
official 2026-06-17
s4 Operant Endpoint Protector page (macOS, Windows, Linux device security for the AI workforce)
“Discover the Shadow AI tools, coding agents, and MCP clients running on employee devices, and actively block prompt injection, data exfiltration, and malicious shell execution on the device. macOS, Windows, and Linux clients. Lightweight footprint, no kernel extensions required.”
official 2026-06-18
s5 Operant Woodpecker GitHub repository (red teaming for AI and cloud)
“GitHub - OperantAI/woodpecker: Red Teaming for AI and Cloud”
official 2026-06-17
s6 About Operant AI (co-founders Vrajesh Bhavsar ex-Apple and Priyanka Tembey ex-VMware)
“Vrajesh built core technologies for iOS & macOS including Dynamic Tracing, Data Protection and Secure Enclave at Apple. ... Priyanka was one of the foundational engineers to build out VMware's hybrid cloud product”
official 2026-07-03
s7 Security at Operant page (SOC 2 Type II, secure-by-default, least privilege)
“Operant is SOC 2, Type II Compliant. Operant's internal security and risk management is guided by our own product pillar of being secure by default. Least privilege is enforced all the way from our development and production infrastructure to the product layer and APIs.”
official 2026-06-17
s8 SecurityWeek on Operant AI Series A (founders, 13.5M total, April 2023, 80% runtime attacks)
“The Series A investment was provided by SineWave Ventures, Felicis, Alumni Ventures, Massive, Calm Ventures and Gaingels. Operant AI has raised a total of $13.5 million since its public launch in April 2023, and claims it can block more than 80% of common runtime attacks including the OWASP Top 10.”
press 2026-06-18
s9 SiliconANGLE on Operant launching Woodpecker open-source red teaming
“Operant AI Inc., a startup that offers a runtime application protection platform, today announced the launch of Woodpecker, an open-source, automated red teaming engine that helps make advanced security testing accessible to organizations of all sizes.”
press 2026-06-17
s10 Cato Networks press on acquiring Aim Security (September 3, 2025)
“Cato Networks, the SASE leader, announced today that it acquired Aim Security, a visionary leader of AI security. This is Cato's first-ever acquisition and will further expand the Cato SASE Cloud Platform, enabling secure enterprise adoption of AI agents.”
press 2026-06-17
s11 SentinelOne press on acquiring Prompt Security (August 5, 2025)
“SentinelOne today announced it has signed a definitive agreement to acquire Prompt Security, a pioneer in securing AI in runtime, preventing AI-related data leakage and protecting intelligent agents.”
press 2026-07-01
s12 Check Point press on acquiring Lakera (September 16, 2025)
“Check Point Software Technologies Ltd. today announced it has entered into an agreement to acquire Lakera, one of the world's leading AI-native security platforms for Agentic AI applications.”
press 2026-06-17
s13 Help Net Security: Woodpecker, open-source red teaming for AI, Kubernetes, APIs (Tembey interview, May 2025)
“we wanted to democratize access to core red teaming capabilities that we don’t think should be limited to only the biggest companies with huge security budgets”
press 2026-07-03
s14 The New Stack: Kubernetes Runtime Defense Evolves Beyond eBPF (Jeffrey Burt, November 2024)
“Operant isn’t the only vendor looking to protect the runtime environment ... While they warn developers of attacks, Operant’s technology takes steps to shut them down”
press 2026-07-03
s15 YourStory: Operant AI enters Indian market to secure AI systems in real time (March 2025)
“Silicon Valley-based cybersecurity AI startup Operant AI is entering the Indian market, introducing its Runtime AI Application Defense Platform to safeguard AI systems against emerging threats.”
press 2026-07-03
s16 CB Insights company profile: Operant AI (Series A stage, investor roster, competitor set)
“Operant AI's latest funding round is Series A ... Investors of Operant AI include Felicis, Calm Ventures, SineWave Ventures, Gaingels, Massive Capital Partners and 11 more ... Competitors of Operant AI include WitnessAI, E2B, Virtue AI, RAD Security, Lacework and 7 more”
research 2026-07-03
s17 SEC EDGAR Form D: Gaingels Operant LLC, investment vehicle of Series A backer Gaingels ($221,275, first sale 2024-08-08)
“Name of Issuer Gaingels Operant LLC ... Date of First Sale 2024-08-08 ... Total Amount Sold $ 221,275 USD”
regulatory 2026-07-03

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.