Tray.ai

Security for AI Governance Risk ComplianceIdentity Access also known as Tray.io

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2012
Last updated 2026-09-11

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

This analysis is scoped to Tray Agent Gateway for MCP.

Tray.ai sells Agent Gateway for MCP, which enterprise IT teams use to govern AI agents' access to business software through the Model Context Protocol (MCP). The teams build MCP servers and tools on Tray's integration platform, which has more than 700 connectors, and publish them for agents to use. The gateway versions and retires those servers, enforces authentication, role-based access, permissions and rate limits, and records agent activity in audit logs. Under its earlier name, Tray.io, the company raised a $50 million Series C led by Meritech Capital, when its customers ranged from small startups to IBM. Snowflake has agreed to acquire Natoma, an enterprise MCP platform for AI agents, and could offer similar controls inside a data platform that buyers already license.

Sourced Details

Description Tray.ai is an enterprise integration and AI orchestration platform whose Agent Gateway governs how AI agents reach business systems through managed MCP servers and tools. [f1]
Founded 2012 [f2]
HQ San Francisco, California, USA [f3]
Latest funding Series C ($50M, November 2019, $600M+ valuation) [f2]

Products

Product What it does
Tray Agent Gateway for MCP Enterprise MCP gateway that versions and publishes MCP servers and tools on a governed path, enforces access policies and permissions, and audits every agent call.
Tray AI Orchestration Platform iPaaS that builds AI agents, integrates 700+ apps, and automates workflows across enterprise systems from one platform.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Tray Agent Gateway for MCP spins up, versions, publishes, and deprecates MCP servers on a managed path, enforces access policies and permissions, and provides centralized visibility and audit across deployed MCP. This product is mapped to the AI Defense Matrix. [f4]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Emerging 24 /40 Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 The 92% exploit rate, the 33% critical-vulnerability figure, and the Gartner 2027 forecast are industry-research numbers relayed on Tray's own use-case page, and the launch press frames the pain qualitatively, so quantified pain is vendor-relayed rather than corroborated across non-vendor sources. [s2, s4, s7]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 Tray's documentation details composite tools, OAuth and API-token authentication, RBAC, rate limiting, and organization-level audit logs, but the record carries no demo, open-source code, third-party evaluation, or benchmark, so depth rests on vendor-page detail without an external product validation point. [s3, s1, s7]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 MCP's rapid adoption is the enabler, and the September 2025 Gartner note on MCP gateways is a single analyst signal without matching buyer-side proof, so timing reads as a credible enabler with indirect demand. [s2, s4, s7]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 4/5 Founders Rich Waldron, Alistair Russell, and Dominic Lewis built Tray.io into a platform valued above $600 million in its 2019 round, a verifiable prior build in the same integration domain that the early-stage MCP-gateway peers cannot match. [s6]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 The Agent Gateway line launched in October 2025 with J.W. Pepper as its one named reference, while Tray's larger iPaaS customer roster is traction for the connector business rather than for the gateway. [s5, s6]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 Scored on the line rather than parent scale, Agent Gateway ships visibly as a native platform capability but its spend, revenue, and margin are not separable from the parent, so output per dollar stays unconfirmed at the line level. [s6, s2]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 MCP gateway and agent governance is a forming category that Gartner placed in a 2025 Innovation Insight note rather than an established slot, so buyers can name it but adjacent platforms still contest it. [s2, s4, s7]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 2/5 MCP tool gating is the exact inline cell a data or model platform can absorb into a suite the buyer already licenses, a move pure-play rivals have already conceded by joining larger platforms, leaving the gateway logic itself broadly reproducible. [s1, s3, s13]
Business Risks A data or model platform could fold inline MCP tool gating into a suite enterprises already license, as Snowflake's agreement to acquire Natoma foreshadows, eroding the standalone gateway's rationale…
  • A data or model platform could fold inline MCP tool gating into a suite enterprises already license, as Snowflake's agreement to acquire Natoma foreshadows, eroding the standalone gateway's rationale.
  • The Agent Gateway could fail to add named references beyond J.W. Pepper, leaving the line dependent on the iPaaS install base rather than independent security demand.
  • Buyers could treat MCP governance as a feature of their model or agent platform rather than a separate purchase, capping how far the gateway sells outside Tray's existing accounts.
  • The A2A and multi-protocol bet could strand effort if enterprises consolidate on a different agent-interoperability standard.
Problem & Market Tray.ai positions the Agent Gateway against ungoverned MCP, the fast-spreading way AI agents reach enterprise tools and data…

Tray.ai positions the Agent Gateway against ungoverned MCP, the fast-spreading way AI agents reach enterprise tools and data. The company describes IT teams discovering shadow MCP servers built in JavaScript, Python, and ad hoc scripts without visibility or guardrails, and frames the gateway as the managed path that replaces them.

Tray quantifies the pain with research it cites. Its use-case page relays industry research putting the exploit rate on unmanaged MCP at 92% with 33% of servers carrying critical vulnerabilities, and a Gartner forecast that 40% of enterprise MCP deployments will face security incidents by 2027. A September 2025 Gartner note on MCP gateways gives the category an external anchor.

The buyer is the IT and platform team standing up agents, the same group that already runs integration and automation on Tray. That overlap sharpens the problem fit and, separately, shapes who actually writes the check. [s2, s4]

Product Capabilities Agent Gateway acts as a controlled bridge between AI clients such as Claude and ChatGPT and a customer's business systems…

Agent Gateway acts as a controlled bridge between AI clients such as Claude and ChatGPT and a customer's business systems. It exposes Tray workflows and connector operations as MCP tools, so an enterprise can publish a small set of governed actions instead of handing agents hundreds of raw tools.

The governance surface is documented in detail. Tray's docs describe OAuth or API-token authentication, role-based access control, per-tool and per-agent permissioning, rate limiting, and audit logs at the organization and workspace level, with every tool call traceable to a user. Composite tools package multi-step logic as a single MCP tool, which Tray says cuts token costs by an order of magnitude and makes agent behavior more predictable.

Tray describes the architecture as built for protocol change, saying Agent Gateway supports MCP today and is engineered for Google's A2A agent-to-agent standard and future interoperability standards. That hedge against a shifting standard is a genuine design choice, though its payoff depends on which protocols enterprises actually adopt. [s3, s1]

Competitive Positioning Tray.ai enters MCP governance as an established integration vendor rather than a security startup…

Tray.ai enters MCP governance as an established integration vendor rather than a security startup. An established integration vendor valued above $600 million in its 2019 round, it brings a 700-plus connector library and iPaaS customers such as IBM and SAP to a category most rivals approach from a standing start.

The closest scored peers are pure-play MCP-gateway and agent-governance companies. MintMCP, Runlayer, and Natoma all build the same control layer, and Snowflake has signed a definitive agreement to acquire Natoma rather than leave it competing alone, a signal of how readily a platform absorbs this function. Tray's connector breadth is the part of its position a rival cannot quickly match, and that breadth belongs to the iPaaS business rather than to the gateway logic.

The gateway's own market position is early. One named reference accompanies a product that launched in October 2025, so the line reads as nascent traction riding an established platform rather than independently proven demand. [s5, s6, s11, s13]

Go-to-Market & Traction The Agent Gateway line's public traction is one named customer…

The Agent Gateway line's public traction is one named customer. J.W. Pepper reduced hundreds of raw MCP tools to roughly twenty governed workflows and reached zero raw database access after rollout, a concrete and useful proof point that is still a single reference for a product launched in October 2025.

Tray's broader customer roster belongs to the integration business. Press from its growth years names IBM, SAP, VMware, and others as iPaaS customers, and those accounts are the natural first audience for the gateway. They are not yet evidence that the gateway sells on its own merits to buyers who were not already on the platform.

The motion sells into existing platform teams. Agent Gateway must be enabled at the organization level through a customer success or account contact, which fits an expansion play within installed accounts more than a new-logo security sale. [s5, s6]

Team & Credibility Tray.ai's founders carry a verifiable track record in the exact domain…

Tray.ai's founders carry a verifiable track record in the exact domain. Rich Waldron, Alistair Russell, and Dominic Lewis founded the company and built it into an integration platform valued above $600 million in its 2019 round, a credential the early-stage MCP-gateway peers cannot match.

That history is integration and automation, not security specifically. The founders' demonstrated expertise is in connecting enterprise systems at scale, which underpins the connector library the gateway exposes, while the security-governance framing of the Agent Gateway is newer ground for the team. [s6, s10, s12]

Trust Readiness Tray publishes a credible enterprise security posture…

Tray publishes a credible enterprise security posture. Its trust page states the company completes SOC 1 and SOC 2 Type 2 audits, runs annual penetration tests, and operates a bug bounty program, and its platform materials list SOC 2 Type II, SOC 1 Type II, HIPAA, GDPR, and CCPA coverage with US, EU, and APAC data residency.

A Conveyor-hosted trust center at trust.tray.ai gates the underlying reports behind a request flow. These attestations are table stakes for an enterprise integration vendor rather than a differentiator, and they apply to the platform broadly rather than to the Agent Gateway specifically. [s9, s8]

Competitors MintMCP, Runlayer, Natoma, Databricks…
Company Relationship Note Compare
MintMCP competes with Single-purpose MCP gateway that authenticates agents and governs their tool access, the pure-play version of what Tray bundles into its platform. N/AWe scored these companies at different scopes, so the totals measure different things.
Runlayer competes with MCP runtime governance for enterprise agents, contesting the same managed-MCP control layer the Agent Gateway sells. N/AWe scored these companies at different scopes, so the totals measure different things.
Natoma competes with Governed MCP gateway with identity-aware authorization over agent tool access, the near-identical product joining forces with Snowflake. N/AWe scored these companies at different scopes, so the totals measure different things.
Databricks adjacent Its Unity AI Gateway governs access to model endpoints and MCP servers inside a platform enterprises already license, the bundling threat to a standalone gateway. N/ADatabricks is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product.

Add analyzed competitors to compare them side by side with Tray.ai.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 13 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

Tray.ai earns the gateway's durability from its position on the route agents take to reach tools, not from any data it accumulates. Once the gateway holds an enterprise's roles, credentials, and connector integrations, replacing it means re-plumbing how every agent reaches every tool. That same tool-gating role is one a data or model platform the buyer already licenses can fold into its own suite, so the position is as bundleable as it is sticky. The gateway's weaknesses are reproducible. Tray sells software the customer runs, holds no proprietary dataset, and clears no compliance mandate a rival could not. Its clearest documented edge is the connector breadth inherited from the iPaaS business rather than the gateway logic.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Agent Gateway is software the customer configures and operates, with no analyst-led accountability layer for outcomes, so delivery sits at the software level.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Once the gateway sits in the agent access path with accumulated roles, policies, credentials, and connector integrations, replacing it means re-plumbing how every agent reaches every tool.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 Tray holds SOC 1 and SOC 2 Type 2 audits and a HIPAA posture for the platform, table-stakes attestations that clear no Agent Gateway-specific mandate a replacement could not.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Governing how heterogeneous agent clients reach enterprise tools across authentication, permissioning, versioning, and audit is genuinely hard engineering.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 The gateway addresses the IT and platform team standing up agents and names one reference customer, so its buyer identity scores a 2, and the parent's iPaaS install base is not credited to the line.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 3/3 The gateway sits on the route agents take to reach tools, so removing it breaks how agents reach systems.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 No named non-public dataset backs the gateway, and the 700-plus connector library, maintained content of real operational value to buyers, is replicable in kind rather than a proprietary corpus.
Strategic Market Segmentation Agent Gateway for MCP targets the enterprise IT and platform team rolling out AI agents, the group responsible for the systems those agents reach…

Agent Gateway for MCP targets the enterprise IT and platform team rolling out AI agents, the group responsible for the systems those agents reach. Tray describes the buyer's problem as shadow MCP, servers and tools built ad hoc without IT visibility or guardrails, and positions the gateway as the managed path that brings them under policy.

Because Agent Gateway is packaged inside Tray's orchestration platform and enabled through account and customer-success channels, it likely skews toward existing Tray platform buyers. Public sources do not show new-logo security traction for the line.

Product Capabilities & AI Advantages The gateway's capability surface is documented and specific…

The gateway's capability surface is documented and specific. Tray exposes workflows and connector operations as MCP tools, applies OAuth or API-token authentication, role-based access control, per-tool permissioning, rate limiting, and organization-level audit logs, with every tool call traceable to a user.

Its distinctive move is consolidation. Composite tools package multi-step logic as a single governed MCP tool, which Tray says cuts token costs by an order of magnitude and steadies agent behavior, and the 700-plus connector library can be published as governed tools in one step. That breadth is an inherited iPaaS asset rather than something the gateway line built.

The advantages are reproducible in kind. The governance primitives, authentication, permissioning, and audit controls, are documented capabilities the cited record does not show as proprietary, so the connector library, an iPaaS asset, is what most distinguishes the line rather than the gateway logic itself.

Sales Engagement & Go-to-Market Tray positions the gateway as an enterprise control layer over agent access to the stack…

Tray positions the gateway as an enterprise control layer over agent access to the stack. Tray describes IT teams building governed MCP servers on its platform and publishing them for agent use. Agent Gateway access must be enabled at the organization level. Permissions, rate limiting and audit logs also sit at the organization and workspace level.

Tray builds the demand case on its own pages. Its MCP governance page cites industry research putting the exploit rate on unmanaged MCP at 92%. It adds a Gartner forecast that 40% of enterprise MCP deployments will experience security incidents by 2027. A published customer story describes the shift Tray sells. Instead of giving one agent 500 different MCP tools, the customer shifted to fine-tuned workflows. Those workflows represent specific actions like looking up an order or updating a ticket. Tray also claims composite tools that reduce token costs by an order of magnitude.

Pricing Model Tray does not publish gateway pricing, and access is gated behind a sales conversation…

Tray does not publish gateway pricing, and access is gated behind a sales conversation. Historically the company sold integration packages with no free tier, which signals a negotiated, enterprise-deal motion rather than self-serve adoption.

The absent public pricing makes the value metric hard to read from outside. Tray does not disclose how the gateway is packaged, so whether it is a bundled capability, an add-on, or a standalone control stays unstated.

Product Delivery & Operations Tray delivers software the customer configures and runs rather than an outcome it accepts accountability for…

Tray delivers software the customer configures and runs rather than an outcome it accepts accountability for. The gateway is a control layer the buyer's own team sets up, populates with tools and policies, and operates, with Tray providing the platform and the connectors.

Operationally the line rides a mature platform. Tray's materials cite high execution uptime and large annual integration volume for the orchestration platform, infrastructure the gateway inherits, though those figures describe the platform broadly rather than the gateway specifically.

Earning Customers' Trust Tray publishes a credible enterprise security posture…

Tray publishes a credible enterprise security posture. Its trust page states the company completes SOC 1 and SOC 2 Type 2 audits, runs annual penetration tests, and operates a bug bounty program, and platform materials add HIPAA, GDPR, and CCPA coverage with US, EU, and APAC data residency.

These attestations are table stakes for an enterprise integration vendor rather than a moat. They apply to the platform broadly, the underlying reports are available through a trust center on request, and no certification specific to the Agent Gateway clears a mandate a rival could not also meet.

Platform Strategy & Ecosystem Positioning The gateway's ecosystem position is its strongest structural asset and its clearest exposure at once…

The gateway's ecosystem position is its strongest structural asset and its clearest exposure at once. Tray's pages state support for Claude, ChatGPT, Copilot Studio, and custom frameworks as MCP clients, and the company says the gateway is engineered for Google's A2A standard, so Tray positions it to serve whatever agent clients an enterprise adopts.

That same gateway role is what a larger platform absorbs. A data or model platform a buyer already licenses can fold MCP tool gating into its own suite, so the layer that makes the gateway sticky is also the layer most exposed to being bundled away by a vendor the customer already pays.

Team & Execution Capability Tray.ai's founders carry a verifiable record in the domain the gateway extends…

Tray.ai's founders carry a verifiable record in the domain the gateway extends. Rich Waldron, Alistair Russell, and Dominic Lewis founded the company and built it into an integration platform valued above $600 million in its 2019 round, per a source close to the company in TechCrunch's report.

That expertise is integration and automation rather than security specifically. The team's demonstrated strength is connecting enterprise systems at scale, which underpins the connector library the gateway governs, while the security-governance framing is newer ground for the company.

Sources

Company Detail Sources (4)
Id Source Tier Accessed
f1 https://tray.ai/platform official 2026-06-25
f2 TechCrunch: Tray.io brings in $50M more at a $600M valuation for its workflow automation tools press 2026-06-25
f3 https://tray.ai/about official 2026-06-25
f4 https://catalog.aidefensematrix.com/products/tray-ai-agent-gateway official 2026-06-25
Profile Analysis Sources (13)
Id Source Tier Accessed
s1 Tray.ai: MCP Gateway and AI Agent Governance
“Agent Gateway for MCP is the enterprise control layer, governed MCP Servers, composite tools that reduce token costs by an order of magnitude, and full observability over every agent interaction with your stack.”
official 2026-06-25
s2 Tray.ai launches Agent Gateway for MCP
“IT teams use Agent Gateway for MCP to build governed, maintainable MCP (Model Context Protocol) servers and MCP tools on Tray and publish them via MCP for stable and secure agent use across the stack.”
official 2026-06-25
s3 Tray.ai Documentation: Agent Gateway Overview
“Built-in Governance - Permissions, rate limiting, and audit logs at organization and workspace level. Enforced Security - OAuth or API token authentication, RBAC, and execution monitoring.”
official 2026-06-25
s4 Tray.ai: MCP governance use case
“Industry research puts the exploit rate on unmanaged MCP at 92%, with 33% of servers having critical vulnerabilities. By 2027, Gartner expects 40% of enterprise MCP deployments to be hit by security incidents.”
official 2026-06-25
s5 Tray.ai: J.W. Pepper customer story
“Instead of trying to give the agent 500 different MCP tools and saying good luck, we shifted to fine-tuned workflows that represent specific actions like looking up an order or updating a ticket.”
official 2026-06-25
s6 TechCrunch: Tray.io brings in $50M at a $600M+ valuation
“Has raised $50 million in funding, at a valuation that a source close to the company tells me is over $600 million post-money. It brings the total raised by Tray.io to just under $110 million. Customers ranging from small startups through to the likes of IBM.”
press 2026-06-25
s7 The AI Journal: Tray.ai Unveils Agent Gateway for Secure MCP Governance
“Tray.ai has unveiled a new capability designed to help enterprises bring order and oversight to the fast-moving world of agent development.”
press 2026-06-25
s8 Tray AI Orchestration Platform
“SOC 2 Type II, SOC 1 Type II, HIPAA, GDPR, CCPA, across everything, by default.”
official 2026-06-25
s9 Tray.ai Trust
“We complete SOC 1 and SOC 2 Type 2 audits, conduct annual penetration tests, and run a bug bounty program with the security community.”
official 2026-06-25
s10 UK Companies House: TRAY.IO INC. director Richard Waldron
“Google Campus 4-5, Bonhill Street, London, England, EC2A 4BX”
regulatory 2026-06-30
s11 SiliconANGLE: Tray.ai unleashes low-code platform for building AI agents
“it boasts a library of more than 700 connectors to packaged and software-as-a-service products”
press 2026-06-30
s12 VentureBeat: Tray.io raises $50 million to automate repetitive business processes
“raised $50 million in a series C round led by Meritech Capital”
press 2026-06-30
s13 Snowflake: Snowflake Announces Intent to Acquire Natoma
“today announced it has signed a definitive agreement to acquire Natoma, an enterprise Model Context Protocol (MCP) platform for AI agents”
press 2026-07-02
Deep-Dive Sources (12)
Id Source Tier Accessed
s1 Tray.ai: MCP Gateway and AI Agent Governance
“Agent Gateway for MCP is the enterprise control layer, governed MCP Servers, composite tools that reduce token costs by an order of magnitude, and full observability over every agent interaction with your stack.”
official 2026-06-25
s2 Tray.ai launches Agent Gateway for MCP
“IT teams use Agent Gateway for MCP to build governed, maintainable MCP (Model Context Protocol) servers and MCP tools on Tray and publish them via MCP for stable and secure agent use across the stack.”
official 2026-06-25
s3 Tray.ai Documentation: Agent Gateway Overview
“Built-in Governance - Permissions, rate limiting, and audit logs at organization and workspace level. Enforced Security - OAuth or API token authentication, RBAC, and execution monitoring. Agent Gateway access must be enabled at the organization level.”
official 2026-06-25
s4 Tray.ai: MCP governance use case
“Industry research puts the exploit rate on unmanaged MCP at 92%, with 33% of servers having critical vulnerabilities. By 2027, Gartner expects 40% of enterprise MCP deployments to be hit by security incidents.”
official 2026-06-25
s5 Tray.ai: J.W. Pepper customer story
“Instead of trying to give the agent 500 different MCP tools and saying good luck, we shifted to fine-tuned workflows that represent specific actions like looking up an order or updating a ticket.”
official 2026-06-25
s6 TechCrunch: Tray.io brings in $50M at a $600M+ valuation
“Has raised $50 million in funding, at a valuation that a source close to the company tells me is over $600 million post-money. It brings the total raised by Tray.io to just under $110 million. Customers ranging from small startups through to the likes of IBM.”
press 2026-06-25
s7 The AI Journal: Tray.ai Unveils Agent Gateway for Secure MCP Governance
“Tray.ai has unveiled a new capability designed to help enterprises bring order and oversight to the fast-moving world of agent development.”
press 2026-06-25
s8 Tray AI Orchestration Platform
“SOC 2 Type II, SOC 1 Type II, HIPAA, GDPR, CCPA, across everything, by default. 700+ connectors.”
official 2026-06-25
s9 Tray.ai Trust
“We complete SOC 1 and SOC 2 Type 2 audits, conduct annual penetration tests, and run a bug bounty program with the security community.”
official 2026-06-25
s10 UK Companies House: TRAY.IO INC. director Richard Waldron
“Google Campus 4-5, Bonhill Street, London, England, EC2A 4BX”
regulatory 2026-06-30
s11 SiliconANGLE: Tray.ai unleashes low-code platform for building AI agents
“it boasts a library of more than 700 connectors to packaged and software-as-a-service products”
press 2026-06-30
s12 VentureBeat: Tray.io raises $50 million to automate repetitive business processes
“raised $50 million in a series C round led by Meritech Capital”
press 2026-06-30

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.