Unbound

Security for AI Application SecurityData SecurityGovernance Risk Compliance also known as Web Sentry, Inc.

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software.
Founded 2023
Funding $4M
Last updated 2026-08-29

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Unbound sells security teams software that finds the AI coding agents running inside their company. It scores how risky each agent's setup is, then blocks or holds for approval what an agent tries to run. That broker arrived in March 2026. Unbound's earlier product kept staff data out of the public AI tools employees used. The press and analyst coverage in the reviewed record still describes that earlier product, and the broker's customer and usage figures come from Unbound alone. CEO Raj Srinivasan spent nearly a decade building the data-loss and cloud-access controls he now says agents outgrow. That background gives Unbound a head start. It is not a lasting advantage, because the agents it governs ship their own guardrails and its seed coverage names five rival vendors.

Sourced Details

Description Unbound is an Agent Access Security Broker for enterprises running AI coding agents. It discovers the agents and MCP servers in use, flags risky configurations, and enforces policy to audit, warn, block, or require approval on agent commands, tool calls, and data egress. [f1]
Founded 2023 [f2]
HQ San Francisco, California, United States [f3]
Funding $4M total [f2]
Latest funding Seed of 4 million dollars (May 2025), led by Race Capital with Y Combinator and Massive Tech Ventures [f3]

Products

Product What it does
Unbound Agent Access Security Broker that discovers AI coding agents and MCP servers, flags risky configs, and enforces policy to audit, warn, block, or approve agent commands and data egress.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Unbound discovers and inventories AI coding tools, MCP servers, and sub-agents across the organization, enforces policy to audit, warn, block, or require approval on agent commands and tool calls, and blocks sensitive data egress in real time. These capabilities are mapped to the AI Defense Matrix. [f4]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Emerging 23 /40 Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Enterprise security teams own a concrete exposure, because coding agents run terminal commands, connect to MCP servers and hold developer credentials. The buyer and the problem are stated precisely. The figures that size the pain reach the reviewed record inside Unbound's own announcement rather than from research a buyer can check separately. [s1, s2, s8]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 Unbound documents a command-line discovery scan, lifecycle hooks, a gateway and a policy engine with allow and deny rules, plus a public documentation site with a CLI reference, and it publishes its client on the npm registry. No third-party technical evaluation or benchmark of these capabilities appears in the reviewed record. [s2, s5, s18, s14]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 Coding agents that execute shell commands and connect over MCP are the enabler, dated to the March 2026 launch coverage, and the demand evidence is that launch plus 2025 press interest in AI governance. Those are one launch and press attention rather than several independent buyer-side signals. The 2024 Omdia note and the 2025 Forbes article both predate the coding-agent product. [s8, s9, s12]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 Raj Srinivasan led product for data-loss prevention, cloud-access security and cloud data protection at Palo Alto Networks and Imperva, and Vignesh Subbiah built sub-millisecond advertising systems at Adobe before founding-engineer roles at Tophatter and Shogun. Those prior builds are attested by Unbound's own pages and its Y Combinator listing. Neither founder's record in the reviewed sources shows an exit or a sustained publication record. [s3, s10]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 Unbound's homepage publishes seven named organizations under a trusted-by heading, and security executives at THG Ingenuity and Exterro give quoted endorsements. A 2025 Forbes article carries the THG Ingenuity relationship independently, which lifts this above unnamed design partners. The AWS Marketplace listing covers a discovery product and carries no reviews, and the tool-call and prevented-incident figures are Unbound's own. [s1, s9, s13, s8]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 The $4 million seed of May 2025 is proportional to a two-founder company selling bottom-up, and the shipping is visible in a self-serve trial, a published documentation site and a client at version 1.15.2 across 63 npm releases. No revenue, margin or growth-efficiency figure appears in the reviewed record. The amount, round, date and lead investor are all on the record, so the capital side is documented rather than silent. [s6, s7, s9, s14, s5]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Buyers can place the product against the AI gateway, cloud-access and data-loss budgets that Unbound's own comparison table names, and the cloud-access-broker analogy makes the slot legible. The Agent Access Security Broker label is Unbound's own coinage, and no analyst note or buyer in the reviewed record uses it, so placement still runs through the vendor's explanation. [s1, s8, s12]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 2/5 Unbound's own answer to the objection that Claude Code already warns users concedes that Claude Code ships a warning of its own. Trade coverage of the seed round names Palo Alto Networks and Netskope as rivals. Nothing in the reviewed record shows the capability slowing an incumbent. [s1, s2, s6]
Business Risks Anthropic could extend Claude Code's built-in warnings into org-wide policy enforcement, and the makers of the other agents Unbound supports could add equivalent controls, which would remove the reason to buy a separate broker…
  • Anthropic could extend Claude Code's built-in warnings into org-wide policy enforcement, and the makers of the other agents Unbound supports could add equivalent controls, which would remove the reason to buy a separate broker.
  • Palo Alto Networks and Netskope, named as rivals in trade coverage of Unbound's seed round, could add agent governance to their own platforms.
  • Most of Unbound's named customers appear only on its own pages, so if those names are trials rather than paying references, the traction is thinner than the site suggests.
  • Agent Access Security Broker is Unbound's own label, and if analysts file the capability under an existing category, Unbound loses the early-mover framing its positioning depends on.
  • Unbound's Pro tier drops to audit-only mode once its pooled allowance of 5,000 tool-use evaluations per user is spent, so a team that outgrows the allowance loses enforcement until it upgrades.
  • The $4 million raised in May 2025 is small for a category Unbound says will be foundational, and a better-funded entrant could outspend it.
Problem & Market Unbound targets the gap that opened when enterprises let AI coding agents run with real developer permissions…

Unbound targets the gap that opened when enterprises let AI coding agents run with real developer permissions. Agents such as Claude Code, Cursor and Copilot execute terminal commands, reach internal APIs and connect to external tool servers over MCP, and the controls already in place were built for human users. The buyer is the enterprise security team that owns the resulting exposure.

The problem is concrete and current, and the reviewed record contains no independent measure of it. The developer-adoption and MCP-exposure figures Unbound cites, from a JetBrains survey and from research by Astrix Security, reach this record inside Unbound's own announcement. That announcement also recounts a December 2025 outage it attributes to an AWS coding agent deleting an environment, and no independent account of that event appears in the reviewed sources. [s1, s2, s8]

Product Capabilities Unbound packages discovery, risk scoring and policy enforcement for AI coding agents into one product…

Unbound packages discovery, risk scoring and policy enforcement for AI coding agents into one product. A single command-line scan inventories the agents, MCP servers, sub-agents and risky configurations in an environment. Two enforcement modes then apply policy, with lifecycle hooks for immediate coverage and a gateway for request and response visibility. Policy can audit, warn, block or require approval on terminal commands, MCP tool calls and outbound data.

The capability detail is specific, and a buyer can test it without a sales call. A 30-day trial opens the full Pro plan with no credit card, and the documentation site publishes a command-line reference, policy management and export guides. What the reviewed record lacks is an outside validation point. No third-party technical evaluation or benchmark of the discovery or enforcement claims appears in it, so those claims rest on Unbound's own documentation. [s2, s5, s18, s4]

Competitive Positioning Unbound coined its own category, the Agent Access Security Broker, and positions it as the successor to cloud-access security brokers for AI coding agents…

Unbound coined its own category, the Agent Access Security Broker, and positions it as the successor to cloud-access security brokers for AI coding agents. That framing is a bet rather than a market fact. The label is Unbound's alone in the reviewed record, and the underlying function, governing what coding agents can do, sits next to several adjacent moves.

Trade coverage of the seed round named Palo Alto Networks, Netskope, Symantec, Lasso and Aim Security as rivals. A second pressure comes from the agent makers themselves. Unbound's own site answers the objection that Claude Code already warns users before risky operations, which concedes that Claude Code already ships a warning of its own. [s6, s8, s1]

Go-to-Market & Traction Unbound's go-to-market runs through a self-serve trial, per-seat pricing and a listing on AWS Marketplace, and its homepage publishes seven named organizations under a trusted-by heading, including WeWork, Siemens and Flipkart…

Unbound's go-to-market runs through a self-serve trial, per-seat pricing and a listing on AWS Marketplace, and its homepage publishes seven named organizations under a trusted-by heading, including WeWork, Siemens and Flipkart. The homepage carries those names in its image tags rather than in text, and all of them sit on Unbound's own site. Security executives at THG Ingenuity and Exterro give quoted endorsements, and a March 2026 case study quotes the THG Ingenuity security chief by name.

One customer relationship reaches the record independently. A 2025 Forbes article names THG Ingenuity as an early adopter and quotes the same executive, though it describes Unbound's earlier gateway rather than the coding-agent broker, so no outside source names a customer of the broker itself. Its command-line client is published on the npm registry at version 1.15.2 across 63 releases, which shows shipping cadence rather than adoption. Unbound's own figures, over a million agent tool calls evaluated each month and more than ten prevented incidents, come from its March 2026 announcement. [s1, s4, s5, s9, s13, s14, s15, s8]

Team & Credibility Unbound's two founders bring directly relevant experience…

Unbound's two founders bring directly relevant experience. Raj Srinivasan spent nearly a decade in data security at Palo Alto Networks and Imperva, where he led product for data-loss prevention, cloud-access security and cloud data protection, which is the control class his broker argument builds on. Vignesh Subbiah built sub-millisecond advertising systems at Adobe, then was a founding engineer at Tophatter and an early engineer at Shogun.

The pedigree is on-thesis and it stops short of a category-defining record. Both accounts of these prior builds come from Unbound's own about page and its Y Combinator listing, neither founder has a disclosed exit, and the team is small. Raj Srinivasan holds a master's degree from MIT and sits on the Forbes Technology Council, which are credentials rather than shipped outcomes. [s3, s10, s7]

Trust Readiness Unbound states SOC 2 compliance on its pricing, homepage and about pages, and lists the enterprise controls buyers expect at scale, including role-based access control, single sign-on, SCIM and SIEM export…

Unbound states SOC 2 compliance on its pricing, homepage and about pages, and lists the enterprise controls buyers expect at scale, including role-based access control, single sign-on, SCIM and SIEM export. The SOC 2 statement is the company's own claim rather than an attestation a buyer can inspect. The badge is not a link on any of those three pages, so it leads to no report.

The trust surfaces carry nothing further. The trust subdomain returns a server error, the security subdomain does not resolve, and the /security, /trust and /compliance paths return nothing. The posture is a credibility floor. No audited report, regulated-industry authorization or mandate that would make the claim hard for a rival to match appears in the reviewed record. [s4, s11, s1]

Competitors Palo Alto Networks, Netskope, Symantec, Lasso Security, Aim Security…
Company Relationship Note Compare
Palo Alto Networks competes with Named as a rival in trade coverage of Unbound's seed round. N/AWe scored these companies at different scopes, so the totals measure different things.
Netskope competes with Named as a rival in trade coverage of Unbound's seed round. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Symantec competes with Named as a rival in trade coverage of Unbound's seed round.
Lasso Security competes with Named as a rival in trade coverage of Unbound's seed round. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Aim Security competes with Named as a rival in trade coverage of Unbound's seed round, in generative-AI security. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.

Add analyzed competitors to compare them side by side with Unbound.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Exposed 12 /21 Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software. pivot urgently

Unbound is software a customer installs, configures and runs, and the cited record shows it holding no dataset, licence or patent of its own. Its public skill scanner publishes its results to anyone, and no retained corpus behind that scanning appears in the record. The SOC 2 badge links to no report and the probed trust surfaces carry none, so the compliance claim is vendor-stated in the reviewed record. The record does not describe or size what leaving would cost. Judging every agent command inline without slowing developers is hard engineering. The asset that is not a commodity is Raj Srinivasan, who spent nearly a decade building data-loss and cloud-access security at Palo Alto Networks and Imperva.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Unbound is software the customer installs, configures and runs, and the public offer carries no managed service or human review that accepts accountability for an outcome. Automated audit, warn, block and approve decisions are software output, which places the offer at the software-product level.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 The broker sits in the path of agent traffic through hooks and a gateway tied to the customer's single sign-on, with retained audit history. That the broker sits in the path of that traffic is documented, the cited record does not describe or size an exit from it, and the case study shows session data being exported out of the platform.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 Unbound states SOC 2 compliance on its own pages, which a funded competitor obtains through ordinary enterprise-market preparation. The badge links to no report, and the reviewed record shows no authorization, mandate or retained liability attached to the product that would block a substitute.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Evaluating every agent terminal command and MCP tool call against policy in real time, across eight named coding agents and arbitrary MCP servers without adding latency, is real-time-systems engineering. Unbound reports over a million tool-call evaluations a month in production, and both founders built sub-millisecond systems at Adobe before starting the company.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 Unbound's enterprise names sit in the image tags of its own homepage rather than in independent reporting, and only THG Ingenuity is corroborated elsewhere. A 30-day trial with no credit card and no sales call, beside a $10 per seat plan with no user minimum, puts a self-serve path next to the Enterprise tier's sales conversation, which blends the buyer profile below the regulated-enterprise level.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 Unbound is a governance layer that security teams install onto developer machines through device management, and its own product page describes it as a layer between the agents and the systems, files and tools they reach. Nothing in the cited record shows other software depending on Unbound to run, so it is a platform with application features.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 No dataset, content licence or granted patent that Unbound retains appears in the cited record. Its SkillShield scanner has covered 18,435 agent skills across 5,902 repositories and publishes its results on an open site, and the cited record identifies no retained corpus behind that scanning. Unbound reports observing agent behaviour across customers, and the cited record does not identify a retained corpus built from it.
Strategic Market Segmentation Unbound sells to enterprise security teams that must govern developers using AI coding agents…

Unbound sells to enterprise security teams that must govern developers using AI coding agents. The segment is defined by the buyer's exposure rather than by an industry, meaning any organization where engineers run Claude Code, Cursor or Copilot with enterprise permissions. Trade coverage of the seed round describes mid-market and enterprise customers in technology and healthcare, and the pricing covers both a self-serve team and an organization above 100 developers.

The segmentation is coherent and broad, and it carries a positioning question. Whether agent governance is bought as a separate product or absorbed as a feature of tools the same buyer already owns is not settled by anything in the reviewed record.

Product Capabilities & AI Advantages Unbound's core capability is runtime control over what an AI coding agent can do, delivered without changing developer workflow…

Unbound's core capability is runtime control over what an AI coding agent can do, delivered without changing developer workflow. A command-line scan discovers agents, MCP servers, sub-agents and risky settings. Lifecycle hooks and a gateway then evaluate each terminal command, tool call and data transfer against policy, and can audit, warn, block or require approval. Unbound says its engine evaluates over a million agent tool calls a month in production.

What the reviewed record does not describe is a proprietary data or model advantage. The evaluation logic and policy engine are Unbound's own engineering, and no non-public dataset, trained model or detection corpus appears in the cited sources. Its SkillShield scanner has covered 18,435 agent skills across 5,902 repositories, and it publishes its scan results, flagged entries included, on an open site, while the cited record identifies no retained corpus behind them.

Sales Engagement & Go-to-Market Unbound's motion is developer-friendly and self-serve first…

Unbound's motion is developer-friendly and self-serve first. A 30-day trial opens the full Pro plan with no credit card and no sales call, discovery runs from a single command, and paid tiers convert teams that want enforcement. This bottom-up entry fits a product whose first value is visibility a security team can get in minutes.

The homepage publishes seven named organizations under a trusted-by heading, including WeWork, Siemens and Flipkart, carried in the page's image tags on Unbound's own site. A March 2026 case study quotes THG Ingenuity's security chief by name, and a 2025 Forbes article names the same company and quotes the same executive about Unbound's earlier gateway. Its command-line client is published on the npm registry at version 1.15.2 across 63 releases. The tool-call volume Unbound reports comes from its own announcement.

Pricing Model Unbound's own pricing page starts per developer seat…

Unbound's own pricing page starts per developer seat. The Pro tier is $10 per user each month with 5,000 pooled tool-use evaluations per user, and the Enterprise tier starts at $18 per user and adds role-based access control, single sign-on, environment segregation, longer audit retention and a usage-linked fee of 10% of model passthrough.

Charging per developer aligns price with the unit a buyer measures, which is the number of engineers running agents, and the published entry price lowers the barrier to a first purchase. The Enterprise passthrough fee ties Unbound's revenue to how heavily customers use their agents. Pro drops to audit-only mode once the pooled evaluation allowance runs out, so enforcement stops when the allowance is spent.

Product Delivery & Operations Unbound is built to deploy without disrupting developers…

Unbound is built to deploy without disrupting developers. It installs through device-management tools such as Jamf, Intune, JumpCloud and Kandji, or through a lightweight agent, and Unbound promises full visibility within a week and no code changes. Hooks give immediate coverage, and the gateway adds request and response inspection when a team wants it.

This low-friction delivery is an adoption advantage. Exit is a separate cost, and the cited record does not describe or size it, and the case study shows session data being exported out of the platform.

Earning Customers' Trust Unbound presents the enterprise-readiness posture a security buyer expects and little more…

Unbound presents the enterprise-readiness posture a security buyer expects and little more. Its higher tier lists role-based access control, single sign-on, SCIM, SIEM export and approval workflows, and the pricing page states SOC 2 compliance and cloud-marketplace availability.

The depth behind those claims is not visible. The SOC 2 badge is not a link on the homepage, the pricing page or the about page, so it leads to no report. The trust subdomain returns a server error, the security subdomain does not resolve, and the /security, /trust and /compliance paths return nothing. Trust is a checklist Unbound has cleared rather than a difference a buyer can weigh.

Platform Strategy & Ecosystem Positioning Unbound's value depends on breadth of agent coverage, and that is where it invests…

Unbound's value depends on breadth of agent coverage, and that is where it invests. It supports Cursor, Claude Code, Cline, Roo Code, Gemini CLI, Codex, GitHub Copilot and Windsurf, plus any tool that speaks MCP, and it integrates with device-management and SIEM systems enterprises already run.

The same position is a dependency. Unbound's hook enforcement runs through interfaces the agent makers define, and those makers can change the interfaces, tighten their own built-in controls or bundle governance. Its gateway mode does not run on those hooks. Unbound's own site answers the objection that Claude Code already warns users, which concedes that the platforms it governs ship overlapping controls.

Team & Execution Capability Unbound is a two-founder company with directly relevant pedigree and a small team…

Unbound is a two-founder company with directly relevant pedigree and a small team. Raj Srinivasan spent nearly a decade in data security at Palo Alto Networks and Imperva, leading product for data-loss prevention, cloud-access security and cloud data protection. Vignesh Subbiah built sub-millisecond advertising systems at Adobe, was a founding engineer at Tophatter and an early engineer at Shogun, and now leads Unbound's gateway, hooks and policy engine.

The founder-market fit is strong, because the CEO built the human-era controls that Unbound argues coding agents have outgrown. What the record does not show is independent confirmation. Both accounts of these prior builds come from Unbound's own about page and its Y Combinator listing, neither founder has a disclosed exit, and the team is small.

Sources

Company Detail Sources (4)
Id Source Tier Accessed
f1 Unbound: AI Coding Agent Security Broker official 2026-08-29
f2 The AI Insider: Unbound Lands $4M Seed Investment press 2026-08-29
f3 The SaaS News: Unbound Raises $4 Million in Seed Round press 2026-08-29
f4 Unbound (AI Defense Matrix Catalog) other 2026-08-29
Profile Analysis Sources (19)
Id Source Tier Accessed
s1 Unbound: homepage for the Agent Access Security Broker
“The Agent Access Security Broker (AASB) built for AI coding agents. Discover, assess, and enforce policy across every agent in your org.”
official 2026-08-29
s2 Unbound: product page for discovery, risk assessment and policy enforcement
“The governance layer for AI coding agents. Unbound helps enterprises discover AI coding agents, understand their risk, and enforce guardrails over what those agents can see, touch, and do.”
official 2026-08-29
s3 Unbound: about page with founder biographies and investor list
“Raj spent nearly a decade building data security products at Palo Alto Networks and Imperva, where he led product efforts across DLP, CASB, and cloud data protection.”
official 2026-08-29
s4 Unbound: pricing page with Pro and Enterprise tiers
“$ 10 /user/mo Billed annually No user minimum 5,000 tool use evals/user/month pooled”
official 2026-08-29
s5 Unbound: free plan page
“The full Pro plan, free for 30 days”
official 2026-08-29
s6 The AI Insider: Unbound lands $4M seed investment
“Race Capital led a $4 million seed round for Unbound, joined by Massive Tech Ventures, Y Combinator, Wayfinder Ventures and other angels across three continents.”
press 2026-08-29
s7 The SaaS News: Unbound raises $4 million in seed round
“Headquartered in San Francisco, California, Unbound’s mission is to ensure every organization can embrace AI without losing control.”
press 2026-08-29
s8 PR Newswire: Unbound AI announcement of the Agent Access Security Broker category
“News provided by Unbound AI Mar 20, 2026, 09:05 ET”
other 2026-08-29
s9 Forbes: Governance start-ups boom in the battle to keep AI honest
“One company hoping to benefit from this driver is Unbound, a San Francisco-based start-up with a particular focus on data privacy and security.”
press 2026-08-29
s10 Y Combinator: Unbound company page, Summer 2024 batch
“Vignesh and Raj worked together at Adobe on the same Engineering team for 5+ years, solving some of the most complex problems in the digital advertising space”
other 2026-08-29
s11 Unbound trust-surface and SOC 2 badge-anchor probe, 2026-08-29, with DNS and path controls
“trust.getunbound.ai resolves to 104.18.22.59”
official 2026-08-29
s12 Omdia: On the Radar report on Unbound Security, abstract page
“On the Radar: Unbound Security enables corporate workers to access GenAI safely Report 18 Nov 2024 Rik Turner”
research 2026-08-29
s13 AWS Marketplace: Unbound discover AI listing
“Security Software as a Service (SaaS) Unbound discover AI [img alt: Listing Thumbnail] Unbound discover AI Info Sold by: Unbound”
other 2026-08-29
s14 npm: unbound-cli package listing
“unbound-cli 1.15.2 • Public • Published 12 days ago”
other 2026-08-29
s15 Unbound: THG Ingenuity case study
“How THG Ingenuity's CISO Used Unbound AI to Accelerate AI Adoption March 10, 2026”
official 2026-08-29
s16 Unbound: news and press page
“Press Release March 2026 Unbound AI Announces Agent Access Security Broker (AASB), a New Market Category for Governing AI Coding Agents”
official 2026-08-29
s17 Unbound SkillShield: public agent-skill scanner
“Scanning 18,435 skills across 5,902 repositories”
official 2026-08-29
s18 Unbound: documentation index
“Control What AI Agents Can Do with Unbound Discover, assess, and enforce policy for AI coding agents across your org.”
official 2026-08-29
s19 AI Defense Matrix Catalog: Unbound product entry
“Agent access security broker that discovers AI coding agents and MCP servers and enforces policy to audit, warn, block, or require approval on their commands, tool calls, and data egress.”
other 2026-08-29
Deep-Dive Sources (19)
Id Source Tier Accessed
s1 Unbound: homepage for the Agent Access Security Broker
“The Agent Access Security Broker (AASB) built for AI coding agents. Discover, assess, and enforce policy across every agent in your org.”
official 2026-08-29
s2 Unbound: product page for discovery, risk assessment and policy enforcement
“The governance layer for AI coding agents. Unbound helps enterprises discover AI coding agents, understand their risk, and enforce guardrails over what those agents can see, touch, and do.”
official 2026-08-29
s3 Unbound: about page with founder biographies and investor list
“Raj spent nearly a decade building data security products at Palo Alto Networks and Imperva, where he led product efforts across DLP, CASB, and cloud data protection.”
official 2026-08-29
s4 Unbound: pricing page with Pro and Enterprise tiers
“$ 10 /user/mo Billed annually No user minimum 5,000 tool use evals/user/month pooled”
official 2026-08-29
s5 Unbound: free plan page
“The full Pro plan, free for 30 days”
official 2026-08-29
s6 The AI Insider: Unbound lands $4M seed investment
“Race Capital led a $4 million seed round for Unbound, joined by Massive Tech Ventures, Y Combinator, Wayfinder Ventures and other angels across three continents.”
press 2026-08-29
s7 The SaaS News: Unbound raises $4 million in seed round
“Headquartered in San Francisco, California, Unbound’s mission is to ensure every organization can embrace AI without losing control.”
press 2026-08-29
s8 PR Newswire: Unbound AI announcement of the Agent Access Security Broker category
“News provided by Unbound AI Mar 20, 2026, 09:05 ET”
other 2026-08-29
s9 Forbes: Governance start-ups boom in the battle to keep AI honest
“One company hoping to benefit from this driver is Unbound, a San Francisco-based start-up with a particular focus on data privacy and security.”
press 2026-08-29
s10 Y Combinator: Unbound company page, Summer 2024 batch
“Vignesh and Raj worked together at Adobe on the same Engineering team for 5+ years, solving some of the most complex problems in the digital advertising space”
other 2026-08-29
s11 Unbound trust-surface and SOC 2 badge-anchor probe, 2026-08-29, with DNS and path controls
“trust.getunbound.ai resolves to 104.18.22.59”
official 2026-08-29
s12 Omdia: On the Radar report on Unbound Security, abstract page
“On the Radar: Unbound Security enables corporate workers to access GenAI safely Report 18 Nov 2024 Rik Turner”
research 2026-08-29
s13 AWS Marketplace: Unbound discover AI listing
“Security Software as a Service (SaaS) Unbound discover AI [img alt: Listing Thumbnail] Unbound discover AI Info Sold by: Unbound”
other 2026-08-29
s14 npm: unbound-cli package listing
“unbound-cli 1.15.2 • Public • Published 12 days ago”
other 2026-08-29
s15 Unbound: THG Ingenuity case study
“How THG Ingenuity's CISO Used Unbound AI to Accelerate AI Adoption March 10, 2026”
official 2026-08-29
s16 Unbound: news and press page
“Press Release March 2026 Unbound AI Announces Agent Access Security Broker (AASB), a New Market Category for Governing AI Coding Agents”
official 2026-08-29
s17 Unbound SkillShield: public agent-skill scanner
“Scanning 18,435 skills across 5,902 repositories”
official 2026-08-29
s18 Unbound: documentation index
“Control What AI Agents Can Do with Unbound Discover, assess, and enforce policy for AI coding agents across your org.”
official 2026-08-29
s19 AI Defense Matrix Catalog: Unbound product entry
“Agent access security broker that discovers AI coding agents and MCP servers and enforces policy to audit, warn, block, or require approval on their commands, tool calls, and data egress.”
other 2026-08-29

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.