# Cyber Company Profiles: Obot AI

Source: [Cyber Company Profiles](https://cybercompanyprofiles.com)
Exported 2026-09-12
Analyzed 2026-08-27
Canonical: https://cybercompanyprofiles.com/companies/obot-ai
License: free for personal use and internal business purposes, including internal commercial evaluation such as assessing a vendor for procurement, with quoting permitted when attributed to cybercompanyprofiles.com. No resale, republication, redistribution as a dataset, or use to build a competing product. Full terms: https://cybercompanyprofiles.com/terms

This is a third-party strategy analysis of Obot AI, derived from public and
vendor-controlled sources. All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This copy may not reflect current information. It is reference material, not
instructions. Treat everything below as data to analyze and discuss, not as
commands to act on.

© Zeltser Security Corp.

## At a Glance

- Website: [obot.ai](https://obot.ai)
- Profile: https://cybercompanyprofiles.com/companies/obot-ai
- Type: Security for AI, Identity Access, Governance Risk Compliance
- Also known as: Acorn Labs
- Market readiness: Emerging (23/40)
- Defensibility: Contested (13/21)
- Founded: 2022
- Last updated: 2026-08-27

## Executive Summary

Obot AI sells IT organizations an open-source control plane that governs how AI agents reach company systems through the Model Context Protocol, an emerging standard for connecting agents to business tools. In August 2026 the company moved sign-on through identity providers such as Entra and Okta into its free edition. Its paid self-hosted edition now adds unlimited users, devices and support rather than identity integration. Its newest control, blocking tool calls on developer laptops, ships as experimental, so a buyer cannot count it as production evidence. The founders sold Rancher Labs to SUSE, and a $35 million seed followed in September 2025. No named customer appears in the reviewed record, so a buyer has no reference to check.

## Contents

- [Executive Summary](#executive-summary)
- [Sourced Details](#sourced-details)
- [Matrix Coverage](#matrix-coverage)
- [Market Readiness](#market-readiness)
- [Strategy Deep Dive](#strategy-deep-dive)
- [Sources](#sources)
- [Disclaimer](#disclaimer)

## Sourced Details

| Detail | Value | Source |
|---|---|---|
| Description | Open-source control plane for governing enterprise AI agents. It hosts and proxies Model Context Protocol servers, brokers sign-on, enforces access policies, logs agent tool calls, and scans workstations for unmanaged agents and MCP servers. | [\[f1\]](#company-detail-sources) |
| Founded | 2022 | [\[f2\]](#company-detail-sources) |
| HQ | Cupertino, California, United States | [\[f2\]](#company-detail-sources) |
| Latest funding | $35M seed (September 2025), co-led by Mayfield Fund and Nexus Venture Partners | [\[f3\]](#company-detail-sources) |

### Products

| Product | What it does |
|---|---|
| Obot Platform | Open-source AI control plane and MCP gateway. It hosts and proxies MCP servers, brokers sign-on, enforces access policies, audits tool calls, and scans devices for unmanaged agents. |

## Matrix Coverage

Mapped to the [AI Defense Matrix](https://aidefensematrix.com) [\[f1\]](#company-detail-sources):

| Asset | Govern | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|---|
| AI Orchestration Tools |  | ✓ | ✓ | ✓ |  |  |
| AI Agent Identities |  |  | ✓ |  |  |  |

The Obot Platform hosts and proxies MCP servers behind a central control plane, puts sign-on in front of every connection, enforces role-scoped access policies, logs every MCP call for audit, and finds shadow agents and MCP servers. These capabilities are mapped to the AI Defense Matrix.

## Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

**Emerging (23/40)**

Analyzed 2026-08-27. Scope: whole company.

| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity | 3/5 | Independent launch coverage names the buyer, the IT organizations that must securely manage MCP adoption, and OWASP's MCP Top 10 lists shadow MCP servers, insufficient authentication and missing audit among the protocol's top risks. No cited source puts a number on what that costs a buyer, so the pain is described rather than measured. \[[s9](#profile-analysis-sources), [s15](#profile-analysis-sources), [s7](#profile-analysis-sources)\] |
| Capability Depth | 4/5 | Versioned documentation at v0.25.0, an MIT-licensed codebase open to inspection, and dated release notes describing allowlisted tool calls, outbound tunnels and scoped agent credentials give an evaluator checkable detail. SD Times separately reports the same catalog, registry and gateway architecture, and no third-party technical evaluation appears in the record, so an evaluator checks the code rather than a benchmark. \[[s3](#profile-analysis-sources), [s8](#profile-analysis-sources), [s5](#profile-analysis-sources), [s11](#profile-analysis-sources)\] |
| Market Timing | 3/5 | The enabler is dated: SiliconANGLE records Anthropic releasing the Model Context Protocol in late 2024, which created the ungoverned agent-to-tool surface this platform fronts. One kind of buyer-side signal is documented, SD Times reporting in April 2026 that Amazon, Uber, Duolingo, Nordstrom and Bloomberg described active production deployments. A July 2026 Forbes contributor column calls the category fragmented and advises buyers to treat it as a diligence exercise rather than a purchase. No second independent kind of demand signal appears in the reviewed record. \[[s7](#profile-analysis-sources), [s11](#profile-analysis-sources), [s13](#profile-analysis-sources)\] |
| Team Credibility | 4/5 | TechTarget independently places Shannon Williams and Sheng Liang as president and CEO of the venture they founded after selling Rancher Labs to SUSE, and both hold those roles at Obot AI today. SD Times separately records the company donating its MCP Dev Summit events to the Linux Foundation body that hosts the protocol. \[[s10](#profile-analysis-sources), [s2](#profile-analysis-sources), [s12](#profile-analysis-sources)\] |
| GTM Proof | 2/5 | The reviewed record names no customer, reference or marketplace listing. Obot AI's release notes describe operating Obot Cloud for an unnamed customer, and the company asks for design partners for its newest control, which is the unnamed-customer level of evidence. A $35 million seed and the founders' Rancher Labs record are indirect signals rather than disclosed traction. \[[s5](#profile-analysis-sources), [s7](#profile-analysis-sources), [s10](#profile-analysis-sources)\] |
| Funding Efficiency | 2/5 | The $35 million seed arrived weeks after the gateway's August 2025 launch, and the record still discloses no revenue, margin or named deployment. Shipping is visible across releases through v0.25.0, but the raise outruns the commercial results a buyer can verify. \[[s6](#profile-analysis-sources), [s18](#profile-analysis-sources), [s5](#profile-analysis-sources), [s7](#profile-analysis-sources)\] |
| Category Clarity | 3/5 | A July 2026 Forbes contributor column calls the agent gateway a product category that had no name a year earlier and says its vendors entered from different directions, so the definitions still look fragmented. Buyers can place the platform next to identity and API products, but the boundaries are still being drawn, so a buyer still needs the vendor to explain where it sits. \[[s13](#profile-analysis-sources), [s11](#profile-analysis-sources), [s1](#profile-analysis-sources)\] |
| Incumbent Defensibility | 2/5 | Obot AI publishes the whole platform under an MIT license and gives away the corporate sign-on its paid edition once sold, so a funded rival can reproduce its differentiators. A Forbes contributor column records Palo Alto Networks folding the AI gateway it bought in May 2026 into its security platform and Amazon building agent governance into its own cloud, while noting that the MCP governance features across several such products are still tech preview. \[[s8](#profile-analysis-sources), [s4](#profile-analysis-sources), [s13](#profile-analysis-sources)\] |

### Business Risks

- Amazon could make the agent governance it is building into its own cloud the default for teams already running agents there, removing the reason to add a separate control plane.
- Palo Alto Networks folded the AI gateway it bought in May 2026 into its security platform, and could extend those controls to MCP governance in a platform enterprises already license.
- The Apache-licensed agentgateway project hosted at the Agentic AI Foundation could become the neutral layer buyers standardize on, since more than 300 contributors across 60 organizations already work on it.
- The MIT license lets a cloud provider offer the same software as a managed service without paying Obot AI.
- Obot AI moved corporate sign-on into its free edition, so its paid self-hosted edition now has to justify its price on unlimited users, unlimited devices and support alone.
- Obot AI ships workstation tool-call enforcement as experimental and is recruiting design partners for it, so a rival could reach production with that control first.

### Problem & Market

Enterprises rolling out AI agents need a governed path for the connections those agents use. SiliconANGLE records Anthropic releasing the Model Context Protocol in late 2024 as an open standard for wiring models to external tools and data. Help Net Security described MCP servers as becoming the standard way AI agents reach real-world systems.

The risk side is now documented outside the vendor. OWASP's MCP Top 10, in beta, lists shadow MCP servers, insufficient authentication and authorization, and missing audit and telemetry among the protocol's top risks. SD Times reported in April 2026 from the MCP Dev Summit that security is the top enterprise concern for MCP, covering identity management, data exfiltration, supply chain attacks and privilege escalation.

Obot AI addresses the IT organizations that want to allow MCP adoption rather than block it, and describes the problem as fragmented and risky AI integration. No cited source puts a number on what that fragmentation costs, so the pain is described rather than measured. \[[s7](#profile-analysis-sources), [s9](#profile-analysis-sources), [s15](#profile-analysis-sources), [s11](#profile-analysis-sources), [s2](#profile-analysis-sources)\]

### Product Capabilities

The Obot Platform is a control plane for an organization's AI agents and the MCP servers they call. It hosts and proxies those servers, puts sign-on and role-scoped access policies in front of every connection, and logs every call with exportable request and response trails. Obot Sentry extends the same controls to developer workstations, scanning endpoints for unmanaged agents, MCP servers and skills. The documentation marks that device management as beta.

Version 0.25.0, published on 2 August 2026, added three capabilities. Tool-call enforcement checks each call a coding agent makes against an allowlist through the agent's pre-tool hook, supporting Claude Code, Codex and Cursor. Tunnels reach MCP servers on private networks over an outbound connection, and Agent Auth Scopes issue scoped credentials to agents that cannot complete an interactive sign-in. Obot AI states that tool-call enforcement is experimental and not yet recommended for production use, so a buyer evaluating that control is testing it rather than deploying it.

Packaging changed in the same release. All three editions ship from one container image: the default edition supports up to 100 users and 100 devices without enterprise auth providers, the free Obot Community edition adds Entra, Okta, JumpCloud and Auth0 after a one-time registration, and Obot Enterprise adds unlimited users and devices plus support. The platform is MIT-licensed and open to inspection, and the reviewed record carries no third-party benchmark, so a buyer cannot check its performance against an independent test. \[[s1](#profile-analysis-sources), [s5](#profile-analysis-sources), [s4](#profile-analysis-sources), [s8](#profile-analysis-sources), [s3](#profile-analysis-sources)\]

### Competitive Positioning

Obot AI positions the platform as one open-source package spanning control plane, gateway and catalog. Its GitHub repository describes the project as a complete AI governance platform, and the company gives the software away and charges for scale and support.

A July 2026 Forbes contributor column describes the agent gateway as a category that had no name a year earlier, entered by vendors from several directions and still fragmented in its definitions. The same column records Palo Alto Networks completing its purchase of the AI gateway company Portkey in May 2026, AWS building agent runtime and governance into Bedrock AgentCore, and Solo.io donating the Apache-licensed agentgateway project to the Agentic AI Foundation, where more than 300 contributors across 60 organizations work on it.

Obot AI answers with position in the standard rather than exclusive technology. SD Times reported that the company donated its MCP Dev Summit events and podcast to that same Linux Foundation body, and its April 2026 report from the MCP Dev Summit named Amazon, Uber, Docker, Nordstrom and Obot as describing the same catalog, registry and gateway architecture. A Forbes contributor column advises buyers to treat an agent gateway as a diligence exercise rather than a purchase, advice that applies to Obot AI along with the vendors that column names. \[[s8](#profile-analysis-sources), [s13](#profile-analysis-sources), [s12](#profile-analysis-sources), [s11](#profile-analysis-sources)\]

### Go-to-Market & Traction

The reviewed record names no Obot AI customer, so a buyer has no reference to check. The motion is bottom-up: a free MIT-licensed edition a team can self-host, a hosted Obot Cloud, and an Enterprise edition sold on unlimited scale and support. Version 0.25.0 moved every authentication and model provider into the free tiers, so the self-hosted Enterprise edition no longer sells identity integration. The homepage lists enterprise authentication and no user limit among what the hosted Obot Cloud adds.

What the record does show is investor and ecosystem signal. The $35 million seed announced in September 2025 and co-led by Mayfield Fund and Nexus Venture Partners is the loudest commercial signal available, and SD Times reported that Obot.ai donated its MCP Dev Summit events and podcast to the Linux Foundation's Agentic AI Foundation. Neither tells a buyer who is paying.

Obot AI is still recruiting. Its August 2026 release notes ask for design partners and early adopters for workstation tool-call enforcement, and its one reference to an Obot Cloud customer names no one, so the paying side of the business stays unverifiable from public sources. \[[s1](#profile-analysis-sources), [s5](#profile-analysis-sources), [s8](#profile-analysis-sources), [s7](#profile-analysis-sources), [s12](#profile-analysis-sources)\]

### Team & Credibility

Obot AI's about page names four leaders: Sheng Liang as CEO, Will Chan as CPO, Darren Shepherd as Chief Architect and Shannon Williams as President. Independent press covers two of them, and only in earlier roles. TechTarget covered the earlier Acorn Labs as a venture from Rancher Labs co-founders who had sold that company to SUSE, interviewing Shannon as president and Sheng as CEO of that venture.

The record supports prior enterprise open-source infrastructure builds rather than a specific playbook. The cited leadership sources emphasize open-source and infrastructure backgrounds rather than security credentials. Its careers section calls the company an early-stage startup. \[[s2](#profile-analysis-sources), [s10](#profile-analysis-sources), [s12](#profile-analysis-sources)\]

### Trust Readiness

Obot AI publishes a trust center whose contents are not public. A probe on 27 August 2026 recorded a trust center at trust.obot.ai open only on an access request, together with 404 responses at /trust and /compliance. The archived homepage carries legal documents in its footer and names no attestation.

The reviewed record therefore does not show which attestations Obot AI holds. The contracting surface is conventional, with an end-user license agreement naming Obot AI, Inc. as licensor. A buyer with a formal vendor-risk review has to request access before it can read anything about the company's controls. \[[s20](#profile-analysis-sources), [s16](#profile-analysis-sources), [s1](#profile-analysis-sources)\]

### Competitors

| Company | Relationship | Note |
|---|---|---|
| MintMCP | competes with | Obot AI's own comparison of enterprise MCP gateways lists MintMCP among the products it is measured against. |
| Runlayer | competes with | Obot AI's own comparison of enterprise MCP gateways lists Runlayer among the products it is measured against. |
| Arcade | competes with | Obot AI's own comparison of enterprise MCP gateways lists Arcade among the products it is measured against, calling it a per-user OAuth tool runtime rather than a governance plane. |
| Lunar.dev | competes with | Obot AI's own comparison of enterprise MCP gateways lists Lunar.dev among the products it is measured against. |
| Kong | competes with | Obot AI's own comparison of enterprise MCP gateways lists Kong's AI Gateway for MCP among the products it is measured against. |

## Strategy Deep Dive

A closer look at the company's product strategy, measuring how [defensible](https://zeltser.com/scoring-security-product-strategy) it is against market forces and examining the [eight areas](https://zeltser.com/security-product-creation-framework) behind it.

### Defensibility

**Contested (13/21)**

Band guidance: reinforce or reposition. Analyzed 2026-08-27. Scope: whole company.

Obot AI publishes its platform under an MIT license, so a rival can reuse the source code. The platform carries sign-on, access policies and audit logs for the servers that connect AI agents to business tools, and the record does not size what replacing that setup would cost. Its trust center opens only on an access request, so the record does not show what it certifies, and the cited sources name no proprietary dataset for a rival to rebuild. Palo Alto Networks folded the AI gateway it bought in May 2026 into its security platform, and Amazon is building agent governance into its own cloud. Either can shrink the reason to buy a separate product. Obot AI fits organizations that will run the platform themselves or on its hosted service and judge it without a public reference.

| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery | 1/3 | Obot AI delivers software the customer's own team operates and owns the outcomes for, free under an MIT license or as a licensed build. Support and a hosted instance are options offered alongside it. \[[s1](#deep-dive-sources), [s4](#deep-dive-sources), [s8](#deep-dive-sources)\] |
| Switching Cost | 2/3 | Once the platform carries sign-on, access policies and audit logs for an organization's MCP servers, leaving means rebuilding that setup, which is meaningful friction in effort rather than in broken operations. MCP is a standard interface, so a replacement can serve the same clients, and the cited record does not size the migration. \[[s1](#deep-dive-sources), [s3](#deep-dive-sources), [s7](#deep-dive-sources)\] |
| Compliance Moat | 1/3 | A probe on 27 August 2026 found a trust center gated behind an access request, so the reviewed record does not show which attestations Obot AI holds. Nothing in the cited record ties the product to a mandate, authorization or retained liability that a funded competitor could not assume through ordinary enterprise preparation. \[[s20](#deep-dive-sources), [s16](#deep-dive-sources)\] |
| Problem Complexity | 3/3 | Hosting and proxying live agent traffic, outbound authenticated tunnels into private networks, and pre-tool-hook enforcement inside coding agents are real-time systems work. The vendor's release notes describe the enforcement failing closed when it cannot identify the MCP server behind a tool call, which takes specialized expertise to build. \[[s5](#deep-dive-sources), [s3](#deep-dive-sources), [s1](#deep-dive-sources)\] |
| Buyer Profile | 2/3 | The stated buyer is the IT organization in enterprises adopting MCP, and the free edition caps at 100 users and 100 devices. The reviewed record names no regulated-enterprise or government buyer of the product, so the evidenced buyer class does not reach the regulated-enterprise level. \[[s4](#deep-dive-sources), [s9](#deep-dive-sources), [s5](#deep-dive-sources)\] |
| Layer | 3/3 | The platform is infrastructure other applications depend on. AI clients such as Claude, Cursor and VS Code reach MCP servers through it, and the platform hosts and distributes those servers itself. \[[s3](#deep-dive-sources), [s1](#deep-dive-sources)\] |
| Proprietary Data, Content, or IP | 1/3 | The cited record evidences no retained asset. The platform is MIT-licensed public code, the record shows curated or Git-backed catalogs rather than a vendor-retained non-public corpus, and the audit trails it produces are exportable to the customer's own storage. No dataset, content licence or granted patent appears in the reviewed record. \[[s8](#deep-dive-sources), [s1](#deep-dive-sources), [s3](#deep-dive-sources)\] |

### Strategic Market Segmentation

Obot AI sells to the IT organizations adopting AI agents, not to end users. Launch coverage frames the buyer as IT organizations that must manage and scale MCP adoption securely. The free edition caps at 100 users and 100 devices, which bounds the size of team it serves without a paid licence.

Who actually buys is unproven. No case study, named deployment or industry focus appears in the reviewed record, so segment and sector cannot be read from public evidence. The company's own account of the Ai4 conference describes teams installing the free edition during the show, which is adoption interest rather than purchase. \[[s9](#deep-dive-sources), [s4](#deep-dive-sources), [s17](#deep-dive-sources), [s1](#deep-dive-sources)\]

### Product Capabilities & AI Advantages

The platform supplies governance around AI systems. It hosts and proxies MCP servers, applies sign-on and role-scoped policies to every connection, records every call for audit, and scans developer workstations for unmanaged agents and MCP servers, a device-management capability the documentation marks as beta. Agent Auth Scopes issue bounded credentials to agents that cannot sign in interactively.

Obot AI claims no data or model advantage and none appears in the reviewed record. What it offers is breadth in one MIT-licensed package plus a team that has shipped enterprise open-source infrastructure before. Its newest control, tool-call enforcement on workstations, is described by the vendor as experimental and not recommended for production use. \[[s1](#deep-dive-sources), [s5](#deep-dive-sources), [s8](#deep-dive-sources), [s2](#deep-dive-sources)\]

### Sales Engagement & Go-to-Market

Obot AI runs a bottom-up open-source motion. The free edition is the acquisition channel, a hosted Obot Cloud lowers the cost of trying it, and Obot Enterprise converts organizations that need unlimited scale and support. Version 0.25.0 moved every authentication and model provider into the free tiers, so the self-hosted Enterprise edition no longer sells identity integration. The homepage lists enterprise authentication and no user limit among what the hosted Obot Cloud adds.

Conversion is not visible. The reviewed record names no customer, reference or case study, and Obot AI is asking for design partners and early adopters for its workstation enforcement, so a buyer cannot tell whether free users become paying ones.

Ecosystem position stands in for disclosed traction. SD Times reported that Obot.ai donated its MCP Dev Summit events and podcast to the Linux Foundation's Agentic AI Foundation, and named Obot alongside Amazon, Uber, Docker and Nordstrom as describing the same catalog, registry and gateway architecture. \[[s1](#deep-dive-sources), [s5](#deep-dive-sources), [s12](#deep-dive-sources), [s11](#deep-dive-sources)\]

### Pricing Model

Obot AI publishes no price list. The reviewed record describes what each edition includes rather than what any of them costs: the default edition caps at 100 users and 100 devices, the free Obot Community edition adds enterprise auth providers after a one-time registration, and Obot Enterprise adds unlimited users and devices with support, obtained by contacting the company.

The self-hosted paid edition's basis changed in August 2026. Corporate sign-on through providers such as Entra and Okta moved into the free tier, so what the self-hosted Enterprise edition still adds is unlimited users, unlimited devices and support. The homepage also presents a hosted Obot Cloud with enterprise authentication and no user limit, offered as a free trial. No pricing unit is disclosed for either, so the record does not show what Obot AI believes a buyer pays for. \[[s4](#deep-dive-sources), [s5](#deep-dive-sources), [s1](#deep-dive-sources)\]

### Product Delivery & Operations

Obot AI documents two production paths. A buyer self-hosts the platform in its own cloud or on premises, and the vendor runs a hosted Obot Cloud it offers as a free trial with no infrastructure to set up. All three editions ship from one container image and upgrade in the app, so moving between them needs no redeployment. Versioned documentation covers the platform at v0.25.0.

Running a gateway that carries live agent traffic is work the buyer takes on. In the self-hosted model the customer runs the platform on its own infrastructure and administers its access policies. Tunnels let Obot reach MCP servers inside a private network over an outbound connection, without an inbound port or a firewall change. \[[s1](#deep-dive-sources), [s4](#deep-dive-sources), [s3](#deep-dive-sources), [s5](#deep-dive-sources)\]

### Earning Customers' Trust

Obot AI publishes a trust center whose contents are not public. A probe on 27 August 2026 recorded a trust center at trust.obot.ai open only on an access request, together with 404 responses at /trust and /compliance. The archived homepage carries legal documents in its footer and names no attestation.

The reviewed record therefore does not show which attestations Obot AI holds, which is a gap a buyer has to close by asking. The contracting documents exist, including an end-user license agreement naming Obot AI, Inc. as licensor. \[[s20](#deep-dive-sources), [s16](#deep-dive-sources), [s1](#deep-dive-sources)\]

### Platform Strategy & Ecosystem Positioning

Obot AI is native to the MCP ecosystem. The platform fronts MCP servers for MCP-compatible clients such as Claude, Cursor and VS Code, and distributes approved servers and skills from a catalog. SD Times names the company as a member of the Linux Foundation's Agentic AI Foundation, which now hosts the protocol itself.

The ecosystem is also the dependency and the competition. SD Times reported that Anthropic donated MCP to that foundation in December 2025 alongside projects from Block and OpenAI. A Forbes contributor column records Solo.io donating the Apache-licensed agentgateway project to the same body in June 2026, where more than 300 contributors across 60 organizations work on it, and AWS building agent runtime and governance into Bedrock AgentCore. \[[s12](#deep-dive-sources), [s3](#deep-dive-sources), [s13](#deep-dive-sources), [s5](#deep-dive-sources)\]

### Team & Execution Capability

Four named leaders run Obot AI: Sheng Liang as CEO, Will Chan as CPO, Darren Shepherd as Chief Architect and Shannon Williams as President. TechTarget covered the earlier Acorn Labs as a venture from Rancher Labs co-founders who had sold that company to SUSE, interviewing Shannon as president and Sheng as CEO of that venture.

The leadership record is also a concentration of the bet. The cited leadership sources emphasize open-source and infrastructure backgrounds rather than security credentials. Its careers section calls the company an early-stage startup. \[[s2](#deep-dive-sources), [s10](#deep-dive-sources), [s12](#deep-dive-sources)\]

## Sources

### Company Detail Sources

Cited from the Sourced Details and Matrix Coverage rows.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | [Obot AI: homepage](https://obot.ai/) | official | 2026-08-27 |
| f2 | [CB Insights: Obot AI company profile](https://www.cbinsights.com/company/acorn-labs) | research | 2026-08-27 |
| f3 | [SiliconANGLE: Obot AI raises $35M to help companies manage standardized access for AI agents](https://siliconangle.com/2025/09/23/obot-ai-raises-35m-help-companies-manage-standardized-access-ai-agents/) | press | 2026-08-27 |

### Profile Analysis Sources

Cited from the Market Readiness section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Obot AI homepage: Enterprise AI Control Plane and MCP Gateway](https://obot.ai/) “Build, connect, and govern AI agents with complete visibility, policy enforcement, and audit trails.” | official | 2026-08-27 |
| s2 | [Obot AI: About us and leadership team](https://obot.ai/about-us/) “Obot AI is led by a team of proven builders with deep experience scaling open-source and enterprise infrastructure.” | official | 2026-08-27 |
| s3 | [Obot Docs: Overview (v0.25.0)](https://docs.obot.ai/) “Obot is an open-source platform for organizations to manage, secure, and govern their AI ecosystems.” | official | 2026-08-27 |
| s4 | [Obot Docs: Obot Editions (v0.25.0)](https://docs.obot.ai/enterprise/overview/) “Obot is available in three editions. They are all delivered in the same container image, and you can upgrade from one to the next in the app.” | official | 2026-08-27 |
| s5 | [Obot AI blog (August 2, 2026): Announcing Obot Platform v0.25.0](https://obot.ai/blog/announcing-obot-platform-v0-25-0-tool-call-enforcement-mcp-tunnels-and-agent-auth-scopes/) “Obot Platform v0.25.0 is out. This release adds tool call enforcement for coding agents, MCP tunnels for securely reaching servers on private networks, and Agent Auth Scopes for issuing scoped credentials to autonomous agents.” | official | 2026-08-27 |
| s6 | [Obot AI blog (September 23, 2025): Obot AI Secures $35M Seed to Build Enterprise MCP Gateway](https://obot.ai/blog/obot-ai-secures-35m-seed-to-build-enterprise-mcp-gateway/) “Published: September 23, 2025” | official | 2026-08-27 |
| s7 | [SiliconANGLE (September 23, 2025): Obot AI raises $35M to help companies manage standardized access for AI agents](https://siliconangle.com/2025/09/23/obot-ai-raises-35m-help-companies-manage-standardized-access-ai-agents/) “UPDATED 08:00 EDT / SEPTEMBER 23 2025” | press | 2026-08-27 |
| s8 | [GitHub: obot-platform/obot repository](https://github.com/obot-platform/obot) “Complete AI Governance Platform from Obot AI” | official | 2026-08-27 |
| s9 | [Help Net Security (August 15, 2025): Obot MCP Gateway, open-source platform to manage the adoption of MCP servers](https://www.helpnetsecurity.com/2025/08/15/obot-mcp-gateway-adoption-mcp-servers/) “Obot MCP Gateway is a free, open-source gateway that enables IT organizations to securely manage and scale adoption of Model Context Protocol (MCP) servers.” | press | 2026-08-27 |
| s10 | [TechTarget (October 26, 2023): Rancher founders' new venture recasts Kubernetes management](https://www.techtarget.com/it-infrastructure/news/366557217/Rancher-founders-new-venture-recasts-Kubernetes-management) “Three years after selling their Kubernetes management company to SUSE, Rancher Labs co-founders are unveiling a new venture -- one that hides Kubernetes within a developer-friendly package.” | press | 2026-08-27 |
| s11 | [SD Times (April 21, 2026): Main themes from MCP Dev Summit](https://sdtimes.com/ai/main-themes-from-mcp-dev-summit/) “Amazon, Uber, Duolingo, Nordstrom, Bloomberg all shared information about their active production deployments.” | press | 2026-08-27 |
| s12 | [SD Times (December 9, 2025): Linux Foundation forms Agentic AI Foundation as new home for MCP](https://sdtimes.com/ai/linux-foundation-forms-agentic-ai-foundation-to-be-new-home-for-mcp-goose-and-agents-md/) “The Linux Foundation today announced that it is forming the Agentic AI Foundation (AAIF) to promote transparent and collaborative evolution of agentic AI.” | press | 2026-08-27 |
| s13 | [Forbes contributor column (July 5, 2026): Agent Gateways Are Becoming The Control Plane For Enterprise AI](https://www.forbes.com/sites/janakirammsv/2026/07/05/agent-gateways-are-becoming-the-control-plane-for-enterprise-ai/) “By Janakiram MSV, Senior Contributor. Forbes contributors publish independent expert analyses and insights.” | press | 2026-08-27 |
| s14 | [CB Insights: Obot AI company profile](https://www.cbinsights.com/company/acorn-labs) “Obot AI was formerly known as Acorn Labs. It was founded in 2022 and is based in Cupertino, California.” | research | 2026-08-27 |
| s15 | [OWASP Foundation: OWASP MCP Top 10 project page](https://owasp.org/www-project-mcp-top-10/) “This OWASP Top 10 for MCP outlines the most critical security concerns arising in the lifecycle of MCP-enabled systems” | research | 2026-08-27 |
| s16 | [Obot AI: End User License Agreement](https://obot.ai/eula/) “This End User License Agreement ("Agreement") is a legal agreement between You (an entity or a person) and Obot AI, Inc. ("Licensor").” | official | 2026-08-27 |
| s17 | [Obot AI blog (August 19, 2026): AI Governance in 2026, notes from Ai4](https://obot.ai/blog/ai-governance-in-2026-what-i-learned-from-talking-to-cisos-and-platform-teams-at-ai4/) “We made Obot free for up to 100 users, fully open source, no strings attached.” | official | 2026-08-27 |
| s18 | [PR Newswire (September 23, 2025): Obot AI Secures $35M Seed to Build Enterprise MCP Gateway](https://www.prnewswire.com/news-releases/obot-ai-secures-35m-seed-to-build-enterprise-mcp-gateway-302563687.html) “Launched in August 2025, the Obot MCP Gateway offers a unified, open-source control plane that enables IT teams to manage and secure MCP servers and build MCP-enabled AI solutions.” | official | 2026-08-27 |
| s19 | [Obot AI blog: The 13 Best MCP Gateways for Enterprise Teams in 2026 (vendor comparison page)](https://obot.ai/blog/the-13-best-mcp-gateways-for-enterprise-teams/) “Overview: MintMCP is a commercial MCP gateway optimized for the AI-coding-assistant use case.” | official | 2026-08-27 |
| s20 | [Obot AI trust surface probe, 2026-08-27: a trust center at trust.obot.ai gated by an access request, /trust and /compliance 404](https://trust.obot.ai/) | other | 2026-08-27 |

### Deep-Dive Sources

Cited from the Strategy Deep Dive section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Obot AI homepage: Enterprise AI Control Plane and MCP Gateway](https://obot.ai/) “Build, connect, and govern AI agents with complete visibility, policy enforcement, and audit trails.” | official | 2026-08-27 |
| s2 | [Obot AI: About us and leadership team](https://obot.ai/about-us/) “Obot AI is led by a team of proven builders with deep experience scaling open-source and enterprise infrastructure.” | official | 2026-08-27 |
| s3 | [Obot Docs: Overview (v0.25.0)](https://docs.obot.ai/) “Obot is an open-source platform for organizations to manage, secure, and govern their AI ecosystems.” | official | 2026-08-27 |
| s4 | [Obot Docs: Obot Editions (v0.25.0)](https://docs.obot.ai/enterprise/overview/) “Obot is available in three editions. They are all delivered in the same container image, and you can upgrade from one to the next in the app.” | official | 2026-08-27 |
| s5 | [Obot AI blog (August 2, 2026): Announcing Obot Platform v0.25.0](https://obot.ai/blog/announcing-obot-platform-v0-25-0-tool-call-enforcement-mcp-tunnels-and-agent-auth-scopes/) “Obot Platform v0.25.0 is out. This release adds tool call enforcement for coding agents, MCP tunnels for securely reaching servers on private networks, and Agent Auth Scopes for issuing scoped credentials to autonomous agents.” | official | 2026-08-27 |
| s6 | [Obot AI blog (September 23, 2025): Obot AI Secures $35M Seed to Build Enterprise MCP Gateway](https://obot.ai/blog/obot-ai-secures-35m-seed-to-build-enterprise-mcp-gateway/) “Published: September 23, 2025” | official | 2026-08-27 |
| s7 | [SiliconANGLE (September 23, 2025): Obot AI raises $35M to help companies manage standardized access for AI agents](https://siliconangle.com/2025/09/23/obot-ai-raises-35m-help-companies-manage-standardized-access-ai-agents/) “UPDATED 08:00 EDT / SEPTEMBER 23 2025” | press | 2026-08-27 |
| s8 | [GitHub: obot-platform/obot repository](https://github.com/obot-platform/obot) “Complete AI Governance Platform from Obot AI” | official | 2026-08-27 |
| s9 | [Help Net Security (August 15, 2025): Obot MCP Gateway, open-source platform to manage the adoption of MCP servers](https://www.helpnetsecurity.com/2025/08/15/obot-mcp-gateway-adoption-mcp-servers/) “Obot MCP Gateway is a free, open-source gateway that enables IT organizations to securely manage and scale adoption of Model Context Protocol (MCP) servers.” | press | 2026-08-27 |
| s10 | [TechTarget (October 26, 2023): Rancher founders' new venture recasts Kubernetes management](https://www.techtarget.com/it-infrastructure/news/366557217/Rancher-founders-new-venture-recasts-Kubernetes-management) “Three years after selling their Kubernetes management company to SUSE, Rancher Labs co-founders are unveiling a new venture -- one that hides Kubernetes within a developer-friendly package.” | press | 2026-08-27 |
| s11 | [SD Times (April 21, 2026): Main themes from MCP Dev Summit](https://sdtimes.com/ai/main-themes-from-mcp-dev-summit/) “Amazon, Uber, Duolingo, Nordstrom, Bloomberg all shared information about their active production deployments.” | press | 2026-08-27 |
| s12 | [SD Times (December 9, 2025): Linux Foundation forms Agentic AI Foundation as new home for MCP](https://sdtimes.com/ai/linux-foundation-forms-agentic-ai-foundation-to-be-new-home-for-mcp-goose-and-agents-md/) “The Linux Foundation today announced that it is forming the Agentic AI Foundation (AAIF) to promote transparent and collaborative evolution of agentic AI.” | press | 2026-08-27 |
| s13 | [Forbes contributor column (July 5, 2026): Agent Gateways Are Becoming The Control Plane For Enterprise AI](https://www.forbes.com/sites/janakirammsv/2026/07/05/agent-gateways-are-becoming-the-control-plane-for-enterprise-ai/) “By Janakiram MSV, Senior Contributor. Forbes contributors publish independent expert analyses and insights.” | press | 2026-08-27 |
| s14 | [CB Insights: Obot AI company profile](https://www.cbinsights.com/company/acorn-labs) “Obot AI was formerly known as Acorn Labs. It was founded in 2022 and is based in Cupertino, California.” | research | 2026-08-27 |
| s15 | [OWASP Foundation: OWASP MCP Top 10 project page](https://owasp.org/www-project-mcp-top-10/) “This OWASP Top 10 for MCP outlines the most critical security concerns arising in the lifecycle of MCP-enabled systems” | research | 2026-08-27 |
| s16 | [Obot AI: End User License Agreement](https://obot.ai/eula/) “This End User License Agreement ("Agreement") is a legal agreement between You (an entity or a person) and Obot AI, Inc. ("Licensor").” | official | 2026-08-27 |
| s17 | [Obot AI blog (August 19, 2026): AI Governance in 2026, notes from Ai4](https://obot.ai/blog/ai-governance-in-2026-what-i-learned-from-talking-to-cisos-and-platform-teams-at-ai4/) “We made Obot free for up to 100 users, fully open source, no strings attached.” | official | 2026-08-27 |
| s18 | [PR Newswire (September 23, 2025): Obot AI Secures $35M Seed to Build Enterprise MCP Gateway](https://www.prnewswire.com/news-releases/obot-ai-secures-35m-seed-to-build-enterprise-mcp-gateway-302563687.html) “Launched in August 2025, the Obot MCP Gateway offers a unified, open-source control plane that enables IT teams to manage and secure MCP servers and build MCP-enabled AI solutions.” | official | 2026-08-27 |
| s19 | [Obot AI blog: The 13 Best MCP Gateways for Enterprise Teams in 2026 (vendor comparison page)](https://obot.ai/blog/the-13-best-mcp-gateways-for-enterprise-teams/) “Overview: MintMCP is a commercial MCP gateway optimized for the AI-coding-assistant use case.” | official | 2026-08-27 |
| s20 | [Obot AI trust surface probe, 2026-08-27: a trust center at trust.obot.ai gated by an access request, /trust and /compliance 404](https://trust.obot.ai/) | other | 2026-08-27 |

## Disclaimer

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.
