All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Zenity sells a platform that discovers, hardens, and monitors the AI agents employees build across enterprise services, and its own research lab keeps proving the problem is real. Independent reporting from The Register, CSO Online, and Dark Reading has documented its researchers taking over enterprise AI agents on Microsoft, Salesforce, and Google platforms with zero-click and one-click exploits. ServiceNow embeds Zenity controls natively in its security operations product and AWS lists Zenity among curated AI partners, yet its published customer references are anonymized. The tension that defines Zenity is Microsoft. Its venture arm invested in the company, its Copilot and Power Platform are surfaces Zenity protects, and it could ship native controls for them.
| Description | Zenity secures enterprise AI agents at the agent layer, giving security teams discovery and inventory, posture management, and detection and response across the platforms where agents are built and run. | [f1] |
|---|---|---|
| Founded | 2021 | [f2] |
| HQ | Tel Aviv, Israel | [f2] |
| Funding | $55M total | [f3] |
| Latest funding | Series B, $38M (October 2024) | [f3] |
| Deployment | SaaS | [f4] |
| Compliance | GDPR, ISO 27001, ISO 27701, SOC 2 Type 2 | [f4] |
| Product | What it does |
|---|---|
| Zenity | Zenity: Secures enterprise AI agents with discovery, posture management, and runtime detection and response across agent platforms. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Zenity secures enterprise AI agents with discovery, posture management, and runtime detection and response across agent platforms. It is mapped to the AI Defense Matrix. [f5]
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Zenity inventories low-code apps, automations, and flows built across Power Platform, surfaces risks such as hard-coded secrets, and enforces authentication and sharing policy. The Power Platform line is mapped to the Cyber Defense Matrix. [f6]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Zenity names the buyer, the security team that owns the risk of agents business users build, and its Series B research quantifies the sprawl, but those figures are the vendor's own. Independent reporting in CSO Online and The Register corroborates that enterprise AI agents are exploitable across major platforms, which establishes the problem class without independently quantifying the buyer's pain, level with the same-asset peers. [s19, s3, s4, s7] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | Product pages document three modules across buildtime and runtime, including AIDR execution-path and memory tracking, ServiceNow embeds the signals natively in its security operations product, AWS lists Zenity among curated AI partners, and AgentFlayer research covered by CSO Online evidences depth in the agent-attack domain. Public product pages rather than an independent product benchmark keep it short of exceptional. [s8, s9, s10, s18, s16, s3] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | The agent-attack threat is independently documented by CSO Online and The Register as a credible enabler, and Zenity shows analyst recognition in a 2026 Gartner report plus ecosystem validation through ServiceNow's native SecOps embedding and AWS curation, but direct buyer-side demand stays indirect, with customers anonymized and no independently verified adoption or procurement metric. [s17, s18, s16, s3, s4] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | Michael Bargury's record is a sustained pattern of in-domain research independently covered: Black Hat 2024 copilot work reported by Dark Reading, the Black Hat USA 2025 AgentFlayer disclosures reported by CSO Online, RSA Conference 2026 agent takeovers reported by The Register, plus OWASP and MITRE ATLAS contributions that Zenity's announcement of a Gartner report cites. Public evidence of prior exits is absent, short of a category-defining track record. [s2, s3, s4, s17, s11] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | Partnership and marketplace motion is verifiable: ServiceNow embeds Zenity natively in its security operations product, AWS lists Zenity among curated AI partners in its Security Hub, and reputable backers including M12 and Intel Capital support a small indirect-signal adjustment. Customer references in the reviewed sources are anonymized, with no named enterprise, which holds it below the named-customer bar a top mark requires. [s18, s16, s1, s19] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | The 38 million dollar Series B brought total funding to 55 million dollars with visible shipping across three modules and a research program, but no disclosed revenue or customer growth confirms output per dollar, leaving efficiency at the unconfirmed funded-startup default. [s1, s19, s8, s9, s10, s14] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 | A 2026 Gartner report places Zenity at the forefront of the AI agent governance race, but that recognition reaches buyers through Zenity's own announcement rather than independent distribution, and competing labels such as agentic AI security and AI TRiSM persist, so buyers cannot yet place the budget line reflexively. [s17, s6] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | The cross-platform position spans Microsoft, Salesforce, Google, and AWS surfaces, which no single platform owner would replicate for rivals' agents, and the ServiceNow embed adds workflow friction. Each platform owner can still bundle agent security for its own surface, and Microsoft, a strategic investor, is the most adjacent absorber, so the friction is real but short of a structural moat. [s7, s17, s18] |
Enterprises are accumulating AI agents that employees build and adopt outside engineering review, and security teams cannot see them. Zenity frames the buyer as the security team that owns the risk of agents business users create, and its own Series B research put the scale at nearly 80,000 agents, apps, and automations in an average large enterprise, with over 62 percent carrying some security vulnerability. Those figures are the vendor's own research rather than an independent count.
Independent reporting establishes that the underlying problem is real. Zenity Labs research carried by The Register and CSO Online demonstrated attackers taking over enterprise AI agents on ChatGPT, Microsoft Copilot, Salesforce, and Google Gemini without a user click, which shows the exposure the product addresses exists across the major platforms rather than only in vendor marketing.
The problem predates the agent wave. Zenity started in 2021 on citizen development, where business users assemble Power Platform apps and automations without dedicated security review, and autonomous agents sharpen that exposure because they hold credentials, invoke tools, and act without a person approving each step. [s19, s3, s4, s12]
The Zenity platform ships three modules across buildtime and runtime. AI Observability discovers and inventories agents with ownership, permissions, and dependency context. AI Security Posture Management enforces guardrails on agent configuration, permissions, and integrations before agents run. AI Detection and Response monitors agent intent and execution paths at runtime, mapping decision paths, tool invocations, and memory updates to stop risky behavior.
The platform covers the services where enterprises build and run agents, including Microsoft Copilot Studio, Power Platform, Salesforce, AWS Bedrock, ChatGPT Enterprise, and ServiceNow. The original low-code line remains on sale, governing the Power Platform apps, automations, and flows that citizen developers build.
External validation comes from partners and analysts rather than a public documentation portal. ServiceNow embeds Zenity signals natively in its security operations product, AWS lists Zenity among the curated AI partner solutions in its Security Hub, and a 2026 Gartner report credits Zenity's agent-centric architecture and intent-aware detection. The reviewed public pages provide product descriptions rather than an independent benchmark, so buyers verify depth through these descriptions and the research record. [s7, s8, s9, s10, s15, s16, s17]
A 2026 Gartner report names Zenity the company to beat in AI agent governance, crediting its agent-centric architecture and intent-aware detection, and argues that its security research and contributions to OWASP risk lists and MITRE ATLAS create demand the company can then serve. That recognition reaches buyers through Zenity's own announcement of the report rather than independent analyst distribution.
Zenity faces two kinds of competition, cross-platform specialists and platform-native controls. Among specialists, Noma Security, Prompt Security, Lasso Security, and Lakera compete for the same enterprise AI-security budget, while WitnessAI and Knostic work adjacent ground in employee AI governance and access control. Platform owners press from the other side, since each could ship security controls for its own agent surfaces, and Zenity's answer is breadth, because a platform owner protects its own agents and has little reason to protect a rival's.
Zenity's citizen-development history extends its coverage to the Power Platform apps and flows that predate agents, which matters to buyers whose agent sprawl grew out of that earlier low-code wave. [s17, s12, s7]
Platform owners now distribute Zenity's controls. ServiceNow includes Zenity security signals natively in its security operations product under a partnership announced at the RSA Conference in 2026. AWS lists Zenity among the curated AI partner solutions in its Security Hub. Microsoft's venture arm M12 made a strategic investment ahead of the Series B.
Zenity presents its customer evidence in anonymized testimonials, and the reviewed sources name no customer.
Zenity raised $38 million in Series B funding in October 2024, co-led by Third Point Ventures and DTCP, which brought total funding to $55 million. No later raise appears in the reviewed sources, across a period in which its analyst standing and partner roster grew. [s18, s16, s17, s19, s1, s6]
Co-founders Ben Kliger, the CEO, and Michael Bargury, the CTO, started Zenity in Tel Aviv in 2021 and still run it. Michael's research record is the team's defining signal. He presented enterprise-copilot attack research at Black Hat 2024, which Dark Reading covered, and Zenity Labs returned to Black Hat USA 2025 with AgentFlayer, a set of zero-click exploit chains against ChatGPT, Microsoft Copilot Studio, Salesforce Einstein, and other platforms that CSO Online reported.
The research continued into 2026. At the RSA Conference, Michael demonstrated zero-click takeovers of Cursor, Salesforce, ChatGPT, Gemini, and Copilot agents, which The Register covered, and a 2026 Gartner report credits the company's contributions to OWASP risk lists and MITRE ATLAS. The sustained, independently covered research stream supports the capability story as well as the team's reputation, though public evidence of prior founder exits is absent. [s11, s2, s3, s4, s17, s1]
Zenity publishes a trust center that lists SOC 2 Type II, ISO 27001, and ISO 27701 compliance and GDPR adherence, with full reports available on request. OpenCorporates records the operating entity, ZENITY LTD, as an active private company registered in Israel.
The public posture is lighter than the product's sensitivity suggests. The platform holds inventories of customers' agents, their permissions, and their runtime behavior, so a regulated procurement team will likely ask for the underlying reports that the trust center provides only on request. [s13, s5, s6]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Noma Security | competes with | End-to-end AI security platform spanning posture and runtime, sold into the same enterprise AI-security budget. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Prompt Security | competes with | GenAI and agent security platform covering employee AI use and agentic risks. | |
| Lasso Security | competes with | LLM and GenAI security platform whose runtime guardrails overlap Zenity's detection layer. | |
| Lakera | competes with | Runtime security for AI applications and agents, overlapping Zenity's detection and response module. | |
| WitnessAI | adjacent | Governs employee AI usage rather than the agents employees build. | |
| Knostic | adjacent | Need-to-know access control for enterprise AI assistants, closest to Zenity's Copilot oversharing use case. | |
| Microsoft | adjacent | Platform owner whose native Copilot and Power Platform controls could absorb Zenity's core use cases, and a strategic investor through M12. | N/AMicrosoft is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product. |
Add analyzed competitors to compare them side by side with Zenity.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
pivot urgently
Zenity competes on specialized expertise more than on an owned dataset. The hardest part for a rival to reproduce is its runtime detection, where the product reads an agent's intent and execution paths across chained behavior, built on adversarial-AI expertise a rival could not match quickly. Independent outlets including The Register and CSO Online have covered its researchers' demonstrated takeovers of enterprise agents on Microsoft, Salesforce, and Google platforms. That expertise is a head start rather than a settled lead. Its research is published, the product is configured software the customer operates, and the incident corpus its researchers describe is vendor-stated, not independently verified. Watch whether Zenity turns partner embeds into named deployments a buyer can call.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Customers configure and operate a platform that discovers, hardens, and monitors their agents, a software product they run, rather than a service in which Zenity accepts judgment or accountability for the security outcome. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | The platform connects across an enterprise's agent surfaces with accumulated posture policies and a native embed in ServiceNow's security operations product, so leaving means re-plumbing that coverage, meaningful friction in effort rather than network effects or mandated data residency. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | Zenity publishes SOC 2 Type II, ISO 27001, ISO 27701, and GDPR attestations that ease procurement, but no regulation mandates this specific product and a determined rival could clear the same bar, so compliance does not block a replacement here. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Discovering agents across many platforms and detecting risk by reading agent intent, execution paths, and chained behavior at runtime, backed by a lab whose exploit-chain research is independently covered, sits in machine-learning and adversarial-AI territory demanding specialized expertise. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | The references are anonymized large enterprises with no named regulated customer in the reviewed record, so the buyer profile holds at the mid-market-with-governance level rather than the procurement-gated level a named regulated roster would earn. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Zenity integrates across an enterprise's agent surfaces and embeds in security operations, a control layer beside the agents rather than infrastructure those agents cannot run without, since the agents keep functioning if it is removed. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | Zenity's research lead publishes that detection is tuned on visibility across hundreds of thousands of activities and thousands of real incidents spanning enterprises and industries, a vendor-stated corpus rather than an independently verified data asset. No independent evidence documents that corpus compounding into a flywheel, and the lab's research is published, so the evidenced advantage remains expertise rather than owned data. |
Zenity sells to the security team accountable for AI agents that business users build and run outside engineering review, a buyer that emerged from the earlier low-code wave and sharpened as autonomous agents arrived. The platform frames the asset as the agent layer, where risk shifts from what a model produces to how an agent is configured and how its actions propagate at runtime.
The evidenced segment skews to the large enterprise. The customer proof on Zenity's own pages is anonymized large-enterprise references, and Zenity's own Series B research release frames the buyer as the enterprise holding nearly 80,000 agents, apps, and automations, with over 62 percent carrying a vulnerability. No named customer speaks publicly in the reviewed record.
The segmentation is deliberately cross-platform. Because Zenity secures agents at the agent layer across the surfaces where enterprises build them rather than one vendor's, it addresses enterprises across the platforms where they build agents, which widens the market but places it against both specialist rivals and each platform owner's native controls.
Zenity pairs three functions across the agent lifecycle. Observability discovers and inventories agents with ownership, permissions, and dependency context. Posture management enforces guardrails on configuration, permissions, and integrations before agents run. Detection and response monitors agents at runtime, and the company positions all three at the agent layer across buildtime configuration and runtime execution rather than at the model alone.
The runtime layer is the differentiated capability. Zenity describes its detection analyzing agent intent, execution paths, and behavior rather than individual events, mapping decision paths, tool invocations, and memory updates over time, the layer that prompt filtering and event-based detection miss.
Independent outlets have covered the lab's own demonstrations in the threat domain. Zenity Labs work reported by CSO Online and The Register demonstrated zero-click takeovers of enterprise agents on ChatGPT, Microsoft Copilot, Salesforce, and Google Gemini, press documentation of the team's demonstrated attacks, though not an independent test of the product's detection. The reviewed public pages provide product descriptions rather than an independent benchmark, so buyers verify depth through those descriptions and the research record.
Go-to-market runs on research credibility and platform partnerships rather than self-serve. Zenity's own lab generates demand by exposing zero-click exploit chains that take over enterprise AI agents, work independent outlets carry and that establishes the problem the product then sells against.
Platform owners now distribute the controls. ServiceNow's security operations product natively includes Zenity security signals and controls, AWS lists Zenity among the curated AI partner solutions in its Security Hub, and Zenity's own announcement quotes a 2026 Gartner report calling it the front-runner in AI agent governance, a partner and analyst profile unusual for the company's size and funding.
The gap is named-customer proof. Every traction figure in the record is an anonymized large-enterprise reference, and the reviewed record names no enterprise, so the visible demand depends on analyst standing and partner embeds rather than logos a buyer can call.
Zenity publishes no public price, and every product page routes to a demo request rather than a rate card, so cost is negotiated rather than self-serve, consistent with a vendor selling into large regulated enterprises through direct conversations.
The reviewed pages do not state a metering unit, so the basis of the bill is not publicly answerable from the fetched record. Because the platform inventories and governs an enterprise estate of agents, cost would plausibly track the number of agents or the size of the environment covered, but that is inference rather than a published unit.
The absence of a public price suits the named buyer and raises a barrier for smaller teams. A large enterprise folds the cost into a negotiated security agreement, while a smaller buyer has no transparent entry point.
Zenity governs agents through configuration and runtime monitoring. Posture management enforces guardrails on agent configuration, permissions, and integrations before agents run, and detection and response reads agent intent and execution paths once they act, spanning buildtime configuration and runtime execution.
Operations target prevention and continuous coverage. Posture management evaluates permissions, integrations, and constraints early to apply guardrails consistently, while the runtime layer watches execution paths to stop risky behavior before it reaches systems or data.
Partner integration extends the operational reach. ServiceNow's security operations product natively includes Zenity signals and controls so customers govern agents inside existing security operations processes, which embeds the platform in tooling enterprises already run rather than asking them to operate a standalone console.
Zenity's trust posture comes from named attestations, analyst standing, and a research record. Its trust center publishes SOC 2 Type II, ISO 27001, and ISO 27701 compliance and GDPR adherence, and states that full reports are available on request, the posture a buyer expects from a product that inventories agents, their permissions, and their runtime behavior. OpenCorporates records the operating entity, ZENITY LTD, as an active private company in Israel.
Partner and analyst signals reinforce it. Zenity's announcement quotes a 2026 Gartner report calling it the front-runner in agent governance, ServiceNow embedded its controls natively, and independent outlets covered the lab's exploit chains against major enterprise agents, evidence a buyer can weigh beyond vendor marketing alone.
The open trust gap is the depth of public attestation against the platform's sensitivity. The trust center lists the certifications but gates the full reports behind a request, so a regulated procurement team holding the platform to its data access will still ask for the underlying attestations the page provides only on request.
Zenity is built to be the cross-platform control plane for enterprise agents, and that neutrality is the strategic point. It secures agents at the agent layer across the surfaces where enterprises build them, so a buyer governs agents on many platforms from one place rather than relying on each owner's native controls.
Outward, the platform extends into partner environments, and the reviewed record documents no inward third-party ecosystem of its own. ServiceNow's security operations product natively includes Zenity signals and controls, turning an adjacent security platform into a distribution channel and placing Zenity's coverage inside workflows enterprises already operate.
Because the runtime layer observes agent behavior, execution paths, and tool calls across many customer environments, a cross-customer telemetry asset is a latent path the record does not yet evidence as built. Inward, the cross-platform stance is also the exposure, since each platform owner can ship native agent security for its own surface, and the most adjacent owner is Microsoft, whose Copilot surface Zenity protects.
Zenity is led by co-founder and chief executive Ben Kliger, who runs the company alongside Michael Bargury, the CTO and co-founder. The founding thesis grew from enterprise copilots and low-code development, where business users build powerful apps and agents faster than security can keep up.
Michael's research record is the team's defining signal. The lab disclosed zero-click exploit chains that take over enterprise AI agents, in-domain adversarial work covered by Dark Reading, CSO Online, and The Register across 2024 to 2026 rather than asserted on a page.
The research feeds both reputation and product. The same lineage that exposes how enterprise agents break supplies the credibility behind the platform that secures them, and the company's announcement quotes a 2026 Gartner report placing it at the front of agent governance, though public evidence of prior founder exits is absent.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Zenity: AI Agent Security & Governance Platform | official | 2026-07-09 |
| f2 | Zenity Raises $38 Million to Secure Agentic AI (SecurityWeek) | press | 2026-06-28 |
| f3 | Zenity Raises $38M Series B Funding Round to Secure Agentic AI | press | 2026-06-28 |
| f4 | AI Defense Matrix Catalog entry | other | 2026-06-13 |
| f5 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| f6 | Zenity for Microsoft Power Platform | official | 2026-06-12 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | SecurityWeek: Zenity Raises 38 Million to Secure Agentic AI “Israeli startup Zenity today announced closing a $38 million Series B funding round that brings the total raised by the company to $55 million. ... Founded in 2021, the Tel Aviv-based startup is tackling the risks associated with the rapid expansion and adoption of generative AI” | press | 2026-06-28 |
| s2 | Dark Reading: News Desk 2024, Hacking Microsoft Copilot Is Scary Easy “As enterprises in the world embrace Microsoft's AI assistant, researcher Michael Bargury warns its security is lacking.” | press | 2026-06-28 |
| s3 | CSO Online: Black Hat researchers demonstrate zero-click prompt injection attacks in popular AI agents “researchers from security firm Zenity presented a set of zero-click and one-click exploit chains they dubbed AgentFlayer that impact popular enterprise AI tools including ChatGPT, Copilot Studio, Cursor with Jira MCP, Salesforce Einstein, Google Gemini and Microsoft Copilot.” | press | 2026-06-28 |
| s4 | The Register: AI agents are gullible and easy to turn into your minions (RSAC 2026) “I'm going to show similar kinds of attacks on Microsoft Copilot, Google Gemini, Salesforce's Agentforce, and ChatGPT. And the reason behind this is to say, look, even the best out there are extremely vulnerable” | press | 2026-06-28 |
| s5 | OpenCorporates: ZENITY LTD, Israeli Corporations Authority company number 516350972, status active, Tel Aviv “Status Active ... Company Type Private Limited Company ... ZENITY (alternative legal name in EN)” | regulatory | 2026-06-28 |
| s6 | Zenity homepage, Secure AI Agents Everywhere “Gartner named Zenity the Company to Beat in AI Agent Governance” | official | 2026-06-28 |
| s7 | Zenity AI Agent Security and Governance Platform “Autonomous AI agents introduce new behaviors across the enterprise beyond the design of traditional security controls.” | official | 2026-06-28 |
| s8 | Zenity AI Security Posture Management “Enforces guardrails for agent configuration, permissions, and integrations managing vulnerabilities before agents ever run.” | official | 2026-06-28 |
| s9 | Zenity AI Observability “Discover every AI agent across your environment with the context needed to understand ownership, permissions, integrations, and risk.” | official | 2026-06-28 |
| s10 | Zenity AI Detection and Response “Zenity's AI Detection & Response (AIDR) capabilities are purpose-built to monitor agent intent and execution paths at runtime.” | official | 2026-06-28 |
| s11 | About Zenity, leadership “Ben Kliger, Co-Founder & CEO” | official | 2026-06-28 |
| s12 | Zenity for Microsoft Power Platform “Zenity helps ensure that apps, automations, flows, and reports that are built across Power Platform (PowerApps, PowerAutomate, PowerBI) are secure and in line with corporate policy” | official | 2026-06-28 |
| s13 | Zenity Trust Center “We follow and are certified by strict international standards and regulations in order to keep your data safe. Full reports are available upon request. (SOC 2 Type II, ISO 27001, ISO 27701, GDPR)” | official | 2026-06-28 |
| s14 | Zenity Labs: AgentFlayer 0click exploit research “Zenity Labs' latest research exposes how attackers can compromise these AI agents through 0click (no user interaction) exploits.” | official | 2026-06-28 |
| s15 | Zenity for ServiceNow “Zenity secures what those agents do with native integration into SecOps and end-to-end security controls.” | official | 2026-06-28 |
| s16 | AWS Security Hub features, curated partner solutions, Zenity AI Agent Security and Governance “Zenity is the AI security and governance platform” | official | 2026-06-28 |
| s17 | Zenity announcement: Named the Company to Beat in AI Agent Governance in New Gartner Report “Zenity's purpose-built agentic-centric architecture, intent-aware detection and continued end-user interest put it at the forefront of the AI agent governance race. ... contributed to OWASP Top 10 frameworks with risk lists and open-source frameworks like MITRE ATLAS.” | press | 2026-06-28 |
| s18 | Zenity announcement: Partnership With ServiceNow to Operationalize AI Agent Risk Reduction in SecOps “ServiceNow SecOps now natively includes Zenity security signals and controls, giving customers built-in protection and governance for AI agents” | press | 2026-06-28 |
| s19 | Zenity announcement: Raises 38M Series B Funding Round to Secure Agentic AI “the average large enterprise has nearly 80,000 AI agents, apps, and automations that are built using low-code development platforms, with over 62% containing some type of security vulnerability.” | press | 2026-06-28 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Zenity AI Agent Security and Governance Platform “Autonomous AI agents introduce new behaviors across the enterprise beyond the design of traditional security controls.” | official | 2026-06-28 |
| s2 | Zenity AI Security Posture Management “Enforces guardrails for agent configuration, permissions, and integrations managing vulnerabilities before agents ever run.” | official | 2026-06-28 |
| s3 | Zenity AI Observability “Discover every AI agent across your environment with the context needed to understand ownership, permissions, integrations, and risk.” | official | 2026-06-28 |
| s4 | Zenity AI Detection and Response “Zenity's AI Detection & Response (AIDR) capabilities are purpose-built to monitor agent intent and execution paths at runtime.” | official | 2026-06-28 |
| s5 | About Zenity leadership “Ben Kliger, Co-Founder & CEO” | official | 2026-06-28 |
| s6 | Zenity Trust Center “We follow and are certified by strict international standards and regulations in order to keep your data safe. Full reports are available upon request. (SOC 2 Type II, ISO 27001, ISO 27701, GDPR)” | official | 2026-06-28 |
| s7 | SecurityWeek: Zenity Raises 38 Million to Secure Agentic AI “Israeli startup Zenity today announced closing a $38 million Series B funding round that brings the total raised by the company to $55 million.” | press | 2026-06-28 |
| s8 | Zenity announcement: Raises 38M Series B Funding Round to Secure Agentic AI “the average large enterprise has nearly 80,000 AI agents, apps, and automations that are built using low-code development platforms, with over 62% containing some type of security vulnerability.” | press | 2026-06-28 |
| s9 | Zenity announcement: Named the Company to Beat in AI Agent Governance in New Gartner Report “Zenity's intent-aware runtime defense, comprehensive full-life-cycle observability across SaaS and cloud and endpoint environments, shadow AI discovery and posture management make it the front-runner in this race.” | press | 2026-06-28 |
| s10 | Zenity announcement: Partnership With ServiceNow to Operationalize AI Agent Risk Reduction in SecOps “ServiceNow SecOps now natively includes Zenity security signals and controls, giving customers built-in protection and governance for AI agents” | press | 2026-06-28 |
| s11 | CSO Online: Black Hat researchers demonstrate zero-click prompt injection attacks in popular AI agents “researchers from security firm Zenity presented a set of zero-click and one-click exploit chains they dubbed AgentFlayer that impact popular enterprise AI tools including ChatGPT, Copilot Studio, Cursor with Jira MCP, Salesforce Einstein, Google Gemini and Microsoft Copilot.” | press | 2026-06-28 |
| s12 | The Register: AI agents are gullible and easy to turn into your minions (RSAC 2026) “I'm going to show similar kinds of attacks on Microsoft Copilot, Google Gemini, Salesforce's Agentforce, and ChatGPT. And the reason behind this is to say, look, even the best out there are extremely vulnerable” | press | 2026-06-28 |
| s13 | Dark Reading: News Desk 2024, Hacking Microsoft Copilot Is Scary Easy “As enterprises in the world embrace Microsoft's AI assistant, researcher Michael Bargury warns its security is lacking.” | press | 2026-06-28 |
| s14 | OpenCorporates: ZENITY LTD, Israeli Corporations Authority company number 516350972, status active, Tel Aviv “Status Active ... Company Type Private Limited Company ... ZENITY (alternative legal name in EN)” | regulatory | 2026-06-28 |
| s15 | Zenity for ServiceNow “Zenity secures what those agents do with native integration into SecOps and end-to-end security controls.” | official | 2026-06-28 |
| s16 | AWS Security Hub features, curated partner solutions, Zenity AI Agent Security and Governance “Zenity is the AI security and governance platform” | official | 2026-06-28 |
| s17 | Zenity for Microsoft Power Platform “Zenity helps ensure that apps, automations, flows, and reports that are built across Power Platform (PowerApps, PowerAutomate, PowerBI) are secure and in line with corporate policy” | official | 2026-06-28 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.