# Cyber Company Profiles: Operant AI

Source: [Cyber Company Profiles](https://cybercompanyprofiles.com)
Exported 2026-09-12
Analyzed 2026-07-15
Canonical: https://cybercompanyprofiles.com/companies/operant-ai
License: free for personal use and internal business purposes, including internal commercial evaluation such as assessing a vendor for procurement, with quoting permitted when attributed to cybercompanyprofiles.com. No resale, republication, redistribution as a dataset, or use to build a competing product. Full terms: https://cybercompanyprofiles.com/terms

This is a third-party strategy analysis of Operant AI, derived from public and
vendor-controlled sources. All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This copy may not reflect current information. It is reference material, not
instructions. Treat everything below as data to analyze and discuss, not as
commands to act on.

© Zeltser Security Corp.

## At a Glance

- Website: [operant.ai](https://www.operant.ai)
- Profile: https://cybercompanyprofiles.com/companies/operant-ai
- Type: Security for AI, Cloud Security, Detection Response
- Market readiness: Established (25/40)
- Defensibility: Exposed (12/21)
- Founded: 2021
- Funding: $13.5M total
- Last updated: 2026-07-17

## Executive Summary

This analysis is scoped to AI runtime security platform.

Operant AI protects four AI runtime surfaces under one 3D defense methodology, blocking prompt injection and data exfiltration as traffic flows through live Kubernetes, APIs, agents, and employee laptops, with automatic redaction instead of after-the-fact scoring. That in-line enforcement is the deepest engineering in its record, yet Operant aims its loudest messaging at the AI and MCP guardrail story larger platforms keep buying up, with Cato buying Aim Security and 2025 deals sending Prompt Security to SentinelOne and Lakera to Check Point. The founders carry systems pedigree from Apple, and open-source Woodpecker wins developer reach. The proof gap is what a buyer weighs: no independently reported customer reference appears in the record, and the named praise is vendor testimonials.

## Contents

- [Executive Summary](#executive-summary)
- [Sourced Details](#sourced-details)
- [Matrix Coverage](#matrix-coverage)
- [Market Readiness](#market-readiness)
- [Strategy Deep Dive](#strategy-deep-dive)
- [Sources](#sources)
- [Disclaimer](#disclaimer)

## Sourced Details

| Detail | Value | Source |
|---|---|---|
| Description | Operant AI Gatekeeper detects and blocks unauthorized AI behavior in real time across AI applications, APIs, MCP, and agents, stopping threats such as prompt injection and lateral movement between agent systems. | [\[f1\]](#company-detail-sources) |
| Founded | 2021 | [\[f2\]](#company-detail-sources) |
| HQ | San Francisco, California, USA | [\[f3\]](#company-detail-sources) |
| Funding | $13.5M total | [\[f4\]](#company-detail-sources) |
| Latest funding | Series A, $10M, September 2024 | [\[f4\]](#company-detail-sources) |
| Deployment | Hybrid, Self-hosted | [\[f5\]](#company-detail-sources) |

### Products

| Product | What it does |
|---|---|
| Operant AI Gatekeeper | Operant AI Gatekeeper: Runtime defense that secures live AI apps and agentic workflows, addressing data leakage and rogue agents with in-line redaction and MCP threat blocking. |
| Operant 3D Runtime Defense | Runtime cloud-native security across Kubernetes, APIs, and services using Discovery, Detection, and Defense, blocking common runtime attacks without code changes. |
| Woodpecker | Open-source automated red-teaming engine that simulates attacks across Kubernetes, APIs, and AI models and agents, mapping to OWASP, MITRE ATLAS, and NIST. |
| Operant Endpoint Protector | Endpoint app for macOS, Windows, and Linux that discovers shadow AI, governs coding agents, and audits local MCP clients on the device. |
| Agent Protector | Real-time AI agent security that discovers and monitors an agentic ecosystem, detects agent behaviors and threats, and enforces inline scope and intent controls. |
| Operant MCP Gateway | Enterprise MCP gateway that secures and governs Model Context Protocol servers and the AI agents that connect through them. |

## Matrix Coverage

Mapped to the [AI Defense Matrix](https://aidefensematrix.com) [\[f6\]](#company-detail-sources):

| Asset | Govern | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|---|
| Runtime AI Data |  |  | ✓ | ✓ |  |  |
| AI Orchestration Tools |  |  | ✓ | ✓ |  |  |
| AI Agent Identities |  |  | ✓ | ✓ |  |  |

Operant AI Gatekeeper is a runtime defense that secures live AI apps and agentic workflows, addressing data leakage and rogue agents with in-line redaction and MCP threat blocking. It is mapped to the AI Defense Matrix.

Mapped to the [Cyber Defense Matrix](https://cyberdefensematrix.com) [\[f7\]](#company-detail-sources):

| Asset | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|
| Applications |  | ✓ | ✓ | ✓ |  |
| Networks |  | ✓ | ✓ |  |  |

Operant AI provides runtime defense for Kubernetes, APIs, and cloud services without code changes. This conventional security is mapped to the Cyber Defense Matrix.

## Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

**Established (25/40)**

Analyzed 2026-07-09. Scope: whole company.

| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity | 3/5 | Operant names a specific buyer but the pain is qualitative and grounded in voluntary frameworks (OWASP, MITRE ATLAS, NIST) rather than independently quantified, and the non-vendor framing is limited to SecurityWeek, so it matches the present-but-unproven default. \[[s5](#profile-analysis-sources), [s8](#profile-analysis-sources), [s4](#profile-analysis-sources)\] |
| Capability Depth | 4/5 | The 3D methodology spans discovery, detection, and runtime defense across Kubernetes, APIs, and AI, and Operant ships the open-source Woodpecker red-teaming engine that SiliconANGLE covered and that maps to OWASP, MITRE ATLAS, and NIST. Public OSS plus an external press writeup is an independent validation point beyond product-page claims alone. \[[s7](#profile-analysis-sources), [s8](#profile-analysis-sources), [s2](#profile-analysis-sources)\] |
| Market Timing | 3/5 | The market-timing evidence is a Gartner Innovation Insight cited from Operant's own homepage, general AI-vulnerability awareness in SiliconANGLE, and the agent-adoption enabler since 2024, which are indirect buyer-side signals rather than multiple corroborated demand signals, holding it at the plausible-timing default. \[[s4](#profile-analysis-sources), [s7](#profile-analysis-sources), [s1](#profile-analysis-sources)\] |
| Team Credibility | 3/5 | Bhavsar's Apple and Arm builds and Tembey's VMware hybrid-cloud and Georgia Tech background are elite adjacent-infrastructure pedigree but carry no prior security-product exit and no sustained publication record. \[[s3](#profile-analysis-sources), [s5](#profile-analysis-sources)\] |
| GTM Proof | 3/5 | Named endorsements come from Juniper Networks, Chargebee, Cohere, and ClickHouse leaders, but all appear only on Operant's own pages rather than independent reporting, and no customer count or revenue is disclosed. Tier-one backing from SineWave and Felicis supports a small upward adjustment to hold at 3. \[[s1](#profile-analysis-sources), [s6](#profile-analysis-sources), [s5](#profile-analysis-sources)\] |
| Funding Efficiency | 3/5 | The roughly 13 and a half million dollars raised against a high release cadence, Woodpecker in 2025 and Endpoint Protector in 2026, shows visible output per dollar, but a single 2024 Series A and undisclosed revenue keep it at adequate rather than a longer funded arc. \[[s6](#profile-analysis-sources), [s9](#profile-analysis-sources), [s5](#profile-analysis-sources)\] |
| Category Clarity | 3/5 | Operant straddles two recognizable slots, cloud-native runtime security (CADR and CNAPP) and AI and MCP runtime defense, so a buyer must decide which budget line it fills. That dual placement reads less cleanly than Straiker's single agentic-AI-security fit at 4. \[[s1](#profile-analysis-sources), [s4](#profile-analysis-sources), [s2](#profile-analysis-sources)\] |
| Incumbent Defensibility | 3/5 | The cloud-runtime base raises replication cost more than the AI line, but both capabilities are absorbable by CNAPP platforms such as Wiz, Palo Alto Networks, and Sysdig, and the open-source Woodpecker is community reach rather than a proprietary data flywheel. \[[s4](#profile-analysis-sources), [s8](#profile-analysis-sources), [s2](#profile-analysis-sources)\] |

### Business Risks

- Cloud-security platforms such as Wiz, Palo Alto Networks, or Sysdig could add AI and MCP runtime protection to suites enterprises already buy, removing the third-party budget line for Operant's AI Gatekeeper line, the same absorption that took Lakera into Check Point and Prompt Security into SentinelOne off the board as independents in 2025.
- The public traction record rests on vendor-displayed testimonials from Juniper, Chargebee, Cohere, and ClickHouse leaders with no named customer speaking independently, so a procurement team could pick a rival on equal footing within a year.
- Operant leads its messaging with the crowded AI and MCP line rather than its harder-to-copy cloud-runtime base, so if AI-security marketing fails to convert it could dilute the clearer cloud-runtime story without winning the AI budget.
- With a single 2024 Series A of 10 million dollars, a better-funded rival could outspend Operant on enterprise sales, and the company has disclosed no follow-on raise to match an enterprise go-to-market.
- Capability claims rest largely on Operant's own pages, so an independent benchmark showing weaker runtime detection than the marketing implies would undercut the positioning.

### Problem & Market

Operant AI treats the live, running cloud application as the asset under attack, including the AI agents and MCP tools now woven into it. The company sells runtime defense for two layers at once: ordinary cloud workloads on Kubernetes and APIs, and the newer AI agents, models, and Model Context Protocol connections that enterprises are wiring into those workloads. SecurityWeek frames the buyer's pain as the limit of static pre-deployment security, which checks code before it ships but cannot see attacks against applications already in production.

The threat taxonomy maps to recognized frameworks rather than vendor invention. Operant's open-source Woodpecker tool tests against the OWASP Top 10 for Kubernetes, APIs, and AI, alongside MITRE ATLAS and NIST, which grounds the pain in catalogs security teams already track. The specific AI risks Operant names, prompt injection, data leakage, rogue agents, and MCP tool poisoning, are entries those frameworks recognize.

Buyer-side demand is visible beyond Operant's own claims. The company cites a 2025 Gartner Innovation Insight on MCP gateways, evidence that analysts are organizing a category around the runtime AI problem Operant sells against, though the depth of that demand for a standalone tool is not yet established in the public record. \[[s5](#profile-analysis-sources), [s8](#profile-analysis-sources), [s4](#profile-analysis-sources)\]

### Product Capabilities

Operant runs one methodology, Discovery, Detection, and Defense, across several product lines rather than a single point feature. The 3D Runtime Defense base secures cloud workloads on Kubernetes, APIs, and services, blocking common runtime attacks without code changes. AI Gatekeeper extends that defense to live AI applications, agents, and agentic workflows across public, private, hybrid, and edge environments, with trust scoring, agentic access controls, and threat blocking for MCP servers, clients, and Non-Human Identities.

The company ships the offensive side as open source. Woodpecker is an automated red-teaming engine, covered by SiliconANGLE at its May 2025 launch, that simulates attacks across Kubernetes, APIs, and AI models and agents, including prompt injection, jailbreaks, and model theft. Releasing it free buys distribution and developer goodwill that a closed tool would not, and any feedback of that threat knowledge into Operant's defensive products remains a possibility that public sources do not document.

Public technical depth is mixed. The open-source Woodpecker code and the technical blogs on MCP tool poisoning give a buyer more to assess than marketing pages alone, but the commercial products are described in product-page terms, and no third-party benchmark or independent evaluation of detection efficacy was observed in the pages reviewed. \[[s7](#profile-analysis-sources), [s8](#profile-analysis-sources), [s2](#profile-analysis-sources)\]

### Competitive Positioning

Operant competes on two fronts that consolidate differently. The cloud-native runtime base contends with CNAPP and cloud-security platforms such as Wiz, Palo Alto Networks, and Sysdig, while the AI Gatekeeper line contends with AI-security entrants and the same platforms as they add AI controls. The harder-to-copy ground is the cloud-runtime base, because live protection for Kubernetes and APIs is slower to replicate than AI guardrails a platform can bolt on.

Operant's messaging now leads with the AI and MCP story. That is the louder market, but it is also the one larger platforms keep absorbing. Three AI-security independents close to Operant's AI line were each bought inside about six weeks in 2025: Cato Networks acquired Aim Security in September, SentinelOne agreed to buy Prompt Security in August, and Check Point acquired Lakera in September. AI runtime protection has repeatedly arrived bundled into a larger platform rather than standalone.

The structural question is whether Operant's dual footprint helps or splits it. Selling cloud-runtime and AI-runtime together lets one engine cover both, which is a real efficiency, but it also asks buyers to place a vendor in two budget lines at once, and the clearer of those two stories risks being overshadowed by the more crowded one. \[[s4](#profile-analysis-sources), [s2](#profile-analysis-sources), [s8](#profile-analysis-sources), [s12](#profile-analysis-sources), [s13](#profile-analysis-sources), [s14](#profile-analysis-sources)\]

### Go-to-Market & Traction

Operant's clearest proof points sit on its own pages. The homepage carries endorsements from leaders at Juniper Networks, Chargebee, Cohere, and ClickHouse praising the runtime approach, but these appear as vendor-curated testimonials rather than customers speaking in independent reporting. No customer count, revenue figure, or marketplace distribution motion is disclosed in the public record reviewed.

The strongest outside signals are press coverage and analyst mentions. SiliconANGLE covered the Woodpecker launch, SecurityWeek and GlobeNewswire reported the Series A, and Operant cites inclusion in 2025 Gartner AI-security reports, which together show the demand-generation channel works. These mark visibility and momentum rather than verified commercial scale.

Commercial proof is otherwise thin for the stage. Operant discloses no customer count or revenue, consistent with an early enterprise motion on a single Series A, and the most important readiness gap is the absence of one named reference customer willing to speak on the record. \[[s1](#profile-analysis-sources), [s7](#profile-analysis-sources), [s5](#profile-analysis-sources)\]

### Team & Credibility

Operant's founders pair deep infrastructure engineering with security systems work. Co-founder and CEO Vrajesh Bhavsar built core iOS and macOS technologies at Apple, including Data Protection and Secure Enclave, then ran the ML and AI business unit at Arm, and he holds eight patents in distributed systems, data, and security. That is platform-scale systems experience rather than a security-product sales background.

Co-founder and CTO Priyanka Tembey brings cloud-native depth. She earned a computer science PhD from Georgia Tech and was a foundational engineer who helped build out VMware's hybrid-cloud product, which maps directly to the runtime enforcement Operant now sells. Co-founder and COO Ashley Roof adds go-to-market experience from Google and a prior CMO role at Transposit.

The board and investor signal reinforces the pedigree. Operant's Series A added Patricia Muoio of SineWave Ventures, a former NSA and DoD leader, and Nancy Wang of Felicis, formerly the data-protection general manager at AWS, to its board. What is absent is a prior security exit or a sustained public research record of the kind that lifts the strongest teams in this category. \[[s3](#profile-analysis-sources), [s10](#profile-analysis-sources), [s5](#profile-analysis-sources)\]

### Trust Readiness

Operant states on its security page, linked from the site footer, that it is SOC 2 Type II compliant, and the same page documents vulnerability scanning of code and containers, third-party vendor assessment, encryption at rest and in transit, least-privilege access, and a responsible-disclosure channel. The page names no ISO 27001 certification and offers no downloadable report or self-service trust portal, so the audit itself reaches buyers through procurement rather than open download. Because the product inspects an organization's runtime traffic, AI workloads, agent behavior, and MCP connections, that access still invites detailed data-handling scrutiny the public page does not fully answer.

The deployment model favors fast adoption over heavy assurance. Operant markets single-step deployment and a 7-day free trial with most teams seeing an AI inventory within a day, which lowers the barrier to trying the product but does not substitute for the report-level evidence enterprise procurement expects. For a company at this stage, exposing the SOC 2 report and data-handling terms in a verifiable form is the readiness item most likely to surface in procurement. \[[s11](#profile-analysis-sources), [s2](#profile-analysis-sources), [s9](#profile-analysis-sources)\]

### Competitors

| Company | Relationship | Note |
|---|---|---|
| Wiz | adjacent | Cloud-security platform positioned to fold runtime AI and MCP protection into a suite enterprises already own, the absorption Operant's AI line faces. |
| Palo Alto Networks | adjacent | Platform vendor with cloud and AI security lines able to bundle runtime AI controls into existing enterprise contracts. |
| Aim Security | competes with | AI security platform pairing discovery, posture, and runtime defense for the same enterprise AI buyer, acquired by Cato Networks. |
| Straiker | competes with | Same-asset AI security entrant offering discovery, offensive testing, and runtime blocking of agent attacks. |
| Lakera | competes with | Runtime AI security and red-teaming specialist, acquired by Check Point, overlapping Operant's AI Gatekeeper and Woodpecker lines. |
| Prompt Security | competes with | Runtime LLM and agent guardrails vendor acquired by SentinelOne, overlapping Operant's AI runtime protection. |

## Strategy Deep Dive

A closer look at the company's product strategy, measuring how [defensible](https://zeltser.com/scoring-security-product-strategy) it is against market forces and examining the [eight areas](https://zeltser.com/security-product-creation-framework) behind it.

### Defensibility

**Exposed (12/21)**

Band guidance: pivot urgently. Analyzed 2026-07-15. Scope: AI runtime security platform.

Operant AI is durable on engineering and exposed on what it owns. Its software inspects and blocks the traffic running through Kubernetes, APIs, agents, and employee laptops, redacting sensitive data as it flows, so once a team routes coverage and policies through it, switching means rebuilding that work, real friction short of true lock-in. The runtime engineering draws on the founders' Apple and VMware systems work. The weaker side: the SOC 2 attestation eases procurement without blocking a substitute, open-source Woodpecker is code a funded rival could rebuild, and no named regulated customer appears in the record, only vendor praise from Juniper, Chargebee, Cohere, and ClickHouse leaders. Operant's hold deepens with each account it covers, not with a scarce asset.

| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery | 1/3 | Operant ships endpoint software and the open-source Woodpecker engine and markets runtime and agent protection deployed into customer environments, with no analyst-staffed managed service that accepts accountability for the security outcome. \[[s3](#deep-dive-sources), [s4](#deep-dive-sources), [s9](#deep-dive-sources)\] |
| Switching Cost | 2/3 | In-line enforcement embeds across Kubernetes, APIs, agents, and the device with accumulated redaction and access policies, so leaving means re-plumbing runtime coverage, meaningful friction short of network effects or mandated data residency. \[[s3](#deep-dive-sources), [s2](#deep-dive-sources), [s4](#deep-dive-sources)\] |
| Compliance Moat | 1/3 | Operant self-displays a SOC 2 Type II attestation on its footer-linked security page, which eases procurement but blocks no substitute, and the cited record identifies no regulation mandating this product class, so compliance is table-stakes rather than a moat. \[[s7](#deep-dive-sources)\] |
| Problem Complexity | 3/3 | Enforcing in the live traffic flow with auto-redaction and quarantine, modeling the MCP and non-human-identity attack surface, and mapping an open-source red-team engine to recognized frameworks is adversarial-AI and runtime-systems work the founders are equipped to do from Apple and VMware systems builds. \[[s3](#deep-dive-sources), [s2](#deep-dive-sources), [s8](#deep-dive-sources), [s6](#deep-dive-sources), [s13](#deep-dive-sources)\] |
| Buyer Profile | 2/3 | The buyer is the enterprise security and platform team, but the endorsements reduce to vendor-displayed praise from Juniper Networks, Chargebee, Cohere, and ClickHouse leaders with no named regulated customer on the record, so the profile holds at the cluster level rather than the procurement-gated roster a 3 needs. \[[s1](#deep-dive-sources), [s8](#deep-dive-sources)\] |
| Layer | 2/3 | Operant runs one runtime-defense methodology across the cluster, API, agent, and device, a control layer beside the workload rather than infrastructure the workload cannot run without, and it still ingests from the source tools and identities it does not own. \[[s2](#deep-dive-sources), [s3](#deep-dive-sources), [s4](#deep-dive-sources)\] |
| Proprietary Data, Content, or IP | 1/3 | Operant's headline asset, the Woodpecker red-team engine, is open source and replicable, and the defensive detection rests on the company's own expertise rather than a named non-public corpus, with no proprietary adversarial-pattern dataset or accuracy benchmark of the kind a Lakera builds appearing in the fetched sources, so nothing compounds into a content moat. \[[s5](#deep-dive-sources), [s9](#deep-dive-sources), [s3](#deep-dive-sources), [s12](#deep-dive-sources)\] |

### Strategic Market Segmentation

Operant AI targets the enterprise security and platform team that runs live AI and cloud workloads and needs to defend them in production. The product line addresses runtime attacks on Kubernetes, APIs, and services, then extends the same defense to AI applications, agents, and Model Context Protocol tooling that teams are wiring into those workloads. SecurityWeek frames the buyer's pain as the limit of static pre-deployment security, which checks code before it ships but cannot see attacks against applications already running.

The four product surfaces widen the segment under one methodology. AI Gatekeeper covers live AI apps and agents, 3D Runtime Defense covers cloud workloads, Woodpecker offers free offensive testing, and Endpoint Protector now reaches the employee laptop where shadow AI tools and coding agents run. That spread lets Operant sell to the platform team, the application security team, and the workforce security team, and the live homepage as of July 2026 also markets Agent Protector and an MCP Gateway, entries beyond the four surfaces this snapshot assesses.

Public demand evidence is stronger on analyst mentions than on independently reported customer deployments. Operant presents itself as a Gartner featured vendor across five AI security reports including the 2025 AI TRiSM Market Guide, which shows analysts organizing a category around the runtime AI problem. Vendor-displayed testimonials from leaders at Chargebee, Juniper Networks, Cohere, and ClickHouse exist on the homepage but do not establish commercial scale, and the public record still lacks a named customer describing the segment fit in independent reporting. \[[s8](#deep-dive-sources), [s1](#deep-dive-sources), [s2](#deep-dive-sources)\]

### Product Capabilities & AI Advantages

The claimed advantage is enforcement in the live traffic flow rather than scoring after an alert. Operant blocks prompt injection and data exfiltration as data flows through the running stack and applies in-line auto-redaction, obfuscation, and blocking of sensitive data, with intelligent quarantine of suspicious containers and AI models and token-level rate limits. SecurityWeek reports the product claims to block more than 80% of common runtime attacks including the OWASP Top 10 without significant code changes.

The agent-specific work centers on MCP and non-human identity. AI Gatekeeper adds detection and access control for Model Context Protocol tooling and AI Non-Human Identities across the runtime and API access layers, with fine-grained identity-aware enforcement for autonomous agents. The same 3D methodology of discovery, detection, and defense runs across the cluster, the API, the agent, and the device.

The footprint is publicly verifiable, with the open-source Woodpecker engine giving outside engineers a way to inspect the offensive testing. What holds up, though, is engineering craft rather than data, because the detection rests on the company's own expertise and the runtime enforcement is a capability a funded rival can build against the same MCP and agent primitives. \[[s3](#deep-dive-sources), [s2](#deep-dive-sources), [s8](#deep-dive-sources), [s5](#deep-dive-sources)\]

### Sales Engagement & Go-to-Market

Operant pairs free tooling with analyst visibility. Releasing Woodpecker as an open-source red-teaming engine gives Operant a public distribution surface, and both developer conversion into paid sales and any feedback of threat knowledge into the paid products remain possibilities the public sources do not document. SiliconANGLE covered the launch and framed Operant as a runtime application protection platform, outside coverage of the offensive side.

Named traction is thin and vendor-curated. The homepage carries praise from Juniper Networks, Chargebee, Cohere, and ClickHouse leaders, but these appear only on Operant's own pages rather than in independent reporting, and no customer count or revenue figure is disclosed. The readiness gap is one named reference account willing to speak on the record.

The analyst mentions are vendor-reported. Operant's own homepage presents Gartner featured-vendor placements across five AI security reports, with YourStory independently corroborating the AI TRiSM representative-vendor mention, and press from SecurityWeek and SiliconANGLE shows the company earns coverage. These mark visibility and momentum rather than verified commercial scale. \[[s9](#deep-dive-sources), [s1](#deep-dive-sources), [s8](#deep-dive-sources), [s15](#deep-dive-sources)\]

### Pricing Model

No price appears on the fetched pages, so the charged unit and list price stay outside the reviewed record. Selling through demos and sales conversations fits a product that inspects an organization's runtime traffic, agents, and identities, and the absence withholds the budget-anchoring signal some peers publish.

The four surfaces imply more than one value meter. The cluster and API defense reads as a platform subscription, the endpoint app reads as a per-device or per-seat workforce spend, and Woodpecker is free, so what each paid line charges by, whether workloads, agents, devices, or telemetry volume, is not stated publicly.

The inferable belief is that buyers pay for runtime coverage of the live application and agent surface rather than for discrete features. The unit and any consumption caps cannot be confirmed from the fetched pages, which route buyers toward demos. \[[s4](#deep-dive-sources), [s1](#deep-dive-sources)\]

### Product Delivery & Operations

Operant deploys in the runtime path with light integration across several surfaces. The platform blocks common runtime attacks on Kubernetes, APIs, and services without significant code changes, and the Endpoint Protector client runs on macOS, Windows, and Linux with a lightweight footprint and no kernel extensions required, which lowers the integration barrier for both the cluster and the laptop.

The public materials emphasize customer-deployed software rather than a managed service. Operant ships endpoint software and the open-source Woodpecker engine, and markets runtime and agent protection deployed into customer environments, with the in-line auto-redaction and adaptive enforcement running automatically once installed and no analyst-staffed service surfacing in the fetched pages. Operational collateral such as published uptime or support SLAs does not surface either.

The deployment posture favors fast adoption over heavy assurance. The endpoint client advertises sixty-second installation, and free offensive testing makes the line easy to try, but because the product sits in the live data path and reads prompts, tool calls, and identities, a buyer should resolve data-handling and retention terms in a formal review. \[[s3](#deep-dive-sources), [s4](#deep-dive-sources), [s1](#deep-dive-sources)\]

### Earning Customers' Trust

Operant states on its security page, linked from the site footer, that it is SOC 2 Type II compliant, and the page documents secure-by-default policies, least-privilege access enforced from infrastructure to the product layer, and policy-as-code baked into CI/CD. That is meaningful procurement assurance for an autonomous tool that reads privileged runtime traffic, though the page offers no openly downloadable report.

The product handles sensitive signal, which raises the assurance bar. Because the line inspects prompts, tool calls, agent loops, identities, and data in use across the live stack, a buyer carries data-handling and model-provider questions the published page does not fully answer. Operant frames in-line auto-redaction as keeping sensitive data inside the native application environment, which is part of the trust case.

The attestation is enterprise-grade but table-stakes rather than a moat. The cited record identifies no regulation mandating this product class, the page exposes no self-service report portal, and it names no ISO 27001 certification, so the attestation eases a purchase without blocking a substitute. \[[s7](#deep-dive-sources), [s3](#deep-dive-sources), [s1](#deep-dive-sources)\]

### Platform Strategy & Ecosystem Positioning

Operant positions itself as a single runtime-defense layer across the cluster, the API, the agent, and the device rather than a point tool. One 3D methodology of discovery, detection, and defense runs across all four surfaces, so the platform claim rests on covering the full live application and agent stack from one methodology rather than on owning a data asset other software depends on.

That breadth is a real efficiency and a real exposure. Covering four surfaces from one methodology lets Operant meet a buyer at the cluster, the API gateway, or the laptop, but every surface is a control layer beside the workload rather than infrastructure the workload cannot run without, and the line still ingests from the source tools and identities it does not own.

The ecosystem play leans on open source for reach. Woodpecker maps offensive testing to recognized frameworks, which builds developer goodwill, but it is published code a rival can study and reuse, so it strengthens distribution more than it strengthens lock-in. \[[s2](#deep-dive-sources), [s5](#deep-dive-sources), [s3](#deep-dive-sources), [s13](#deep-dive-sources)\]

### Team & Execution Capability

Operant has three co-founders, and its technical credibility comes from the two who build the infrastructure. SecurityWeek independently names co-founders Vrajesh Bhavsar and Priyanka Tembey as veteran software engineers, and Operant's own record describes Bhavsar building Data Protection and Secure Enclave at Apple and Tembey as a foundational engineer on VMware's hybrid-cloud product. The third co-founder, Ashley Roof, is COO and carries the go-to-market track record rather than the systems one, having led sales and marketing from Google through a CMO role at Transposit. That pairing gives Operant platform-scale systems experience that maps onto runtime enforcement alongside a dedicated commercial leader.

The backing reinforces the founder signal. SecurityWeek reports the Series A investment was provided by SineWave Ventures, Felicis, Alumni Ventures, Massive, Calm Ventures, and Gaingels, bringing total funding to 13.5 million dollars since the April 2023 public launch. That is an early-stage round sized to an early enterprise motion rather than a late-stage war chest.

The verifiable strength is the founders' domain track record. What is absent from the fetched record is a prior security-company exit or a sustained public research record of the kind that lifts the strongest teams in this category, leaving depth below the principals the open question. \[[s8](#deep-dive-sources), [s6](#deep-dive-sources), [s1](#deep-dive-sources)\]

## Sources

### Company Detail Sources

Cited from the Sourced Details and Matrix Coverage rows.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | [Operant AI: AI Gatekeeper](https://www.operant.ai/platform/ai-gatekeeper) | official | 2026-07-09 |
| f2 | [YourStory profile stating founded 2021 (conflicts: CB Insights lists 2018; SecurityWeek dates the public launch to April 2023, previously mis-read as founding)](https://yourstory.com/2025/03/us-based-operant-ai-enters-indian-market-secure-ai-systems-real-time) | press | 2026-07-15 |
| f3 | [SecurityWeek on Operant AI (San Francisco)](https://www.securityweek.com/operant-ai-lands-10m-investment-to-boost-runtime-protection-for-cloud-and-ai/) | press | 2026-06-13 |
| f4 | [GlobeNewswire on Operant AI $10M Series A (total funding $13.5M)](https://www.globenewswire.com/news-release/2024/09/12/2945058/0/en/Operant-AI-Secures-10M-Series-A-to-Protect-the-Modern-Cloud-Across-APIs-Applications-and-AI.html) | press | 2026-06-13 |
| f5 | [AI Defense Matrix Catalog entry](https://catalog.aidefensematrix.com/products/operant-ai-gatekeeper/) | other | 2026-06-10 |
| f6 | [AI Defense Matrix Catalog mapping](https://catalog.aidefensematrix.com/products/operant-ai-gatekeeper/) | other | 2026-06-23 |
| f7 | [Operant AI platform](https://www.operant.ai) | official | 2026-06-14 |

### Profile Analysis Sources

Cited from the Market Readiness section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Operant AI homepage (Juniper Networks, Chargebee, Cohere, and ClickHouse testimonials)](https://www.operant.ai) “Operant's runtime enforcement gives companies the ability to secure their next-gen K8s initiatives ... Raj Yavatkar, CTO, Juniper Networks ... Suhel Khan, Cyber Security Leader \| Chargebee ... Prutha Parikh, Head of Security at Cohere ... Martin Choluj, CISO at Clickhouse” | official | 2026-07-01 |
| s2 | [Operant AI Gatekeeper product page (MCP and AI NHI protection)](https://www.operant.ai/platform/ai-gatekeeper) “get comprehensive support for Model Context Protocol (MCP), and AI Non-Human Identities (NHIs) with detection and access control to defend across both the runtime and API access layers of agent tools” | official | 2026-06-13 |
| s3 | [About Operant AI leadership (Bhavsar ex-Apple, Tembey ex-VMware, Roof)](https://www.operant.ai/company/about) “Vrajesh built core technologies for iOS & macOS including Data Protection and Secure Enclave at Apple ... Priyanka was one of the foundational engineers to build out VMware's hybrid cloud product” | official | 2026-06-13 |
| s4 | [Operant AI Gatekeeper announcement (runtime defense beyond Kubernetes)](https://www.operant.ai/art-kubed/announcing-ai-gatekeeper) “Operant's 3D Runtime Protection is now available across public, private and hybrid cloud platforms” | official | 2026-06-13 |
| s5 | [SecurityWeek on Operant AI $10M Series A and April 2023 public launch](https://www.securityweek.com/operant-ai-lands-10m-investment-to-boost-runtime-protection-for-cloud-and-ai/) “Operant AI has raised a total of $13.5 million since its public launch in April 2023. Founded by veteran software engineers Vrajesh Bhavsar and Priyanka Tembey” | press | 2026-06-13 |
| s6 | [GlobeNewswire on Operant AI $10M Series A co-led by SineWave and Felicis](https://www.globenewswire.com/news-release/2024/09/12/2945058/0/en/Operant-AI-Secures-10M-Series-A-to-Protect-the-Modern-Cloud-Across-APIs-Applications-and-AI.html) “announced today that it has raised $10 million in a Series A funding round co-led by SineWave Ventures and Felicis, with participation from Alumni Ventures, Massive, Calm Ventures, Gaingels” | press | 2026-06-13 |
| s7 | [SiliconANGLE on Operant AI launching Woodpecker open-source red-teaming](https://siliconangle.com/2025/05/21/operant-ai-launches-woodpecker-bring-open-source-red-teaming-ai-cloud-environments/) “Operant AI Inc., a startup that offers a runtime application protection platform, today announced the launch of Woodpecker, an open-source, automated red teaming engine” | press | 2026-06-13 |
| s8 | [Operant Woodpecker introduction (K8s, API, AI red-teaming features)](https://www.operant.ai/art-kubed/introducing-woodpecker-open-source-red-teaming-for-ai-apis-and-kubernetes) “Covers across threat vectors for OWASP top 10 for K8s, API, and AI, MITRE ATLAS, and NIST.” | official | 2026-06-13 |
| s9 | [Operant Endpoint Protector announcement (device-level AI workforce security, published 2026-05-26 per page metadata)](https://www.operant.ai/art-kubed/introducing-endpoint-protector-purpose-built-security-for-the-ai-workforce) “datePublished: 2026-05-26T18:10:49.890Z ... Today we're announcing Operant Endpoint Protector, purpose-built security for the AI Workforce ... Endpoint Protector applies Operant's 3D Protection methodology, Discovery, Detection, Defense, directly on the device.” | official | 2026-07-01 |
| s10 | [Operant Series A announcement (board additions Muoio and Wang)](https://www.operant.ai/art-kubed/operant-ai-series-a) “Patricia Muoio, partner at SineWave Ventures and former NSA/DoD leader, and Nancy Wang, Venture Partner at Felicis and former General Manager / Director of Data Protection at AWS, joining our Board of Directors” | official | 2026-06-13 |
| s11 | [Security at Operant page (SOC 2 Type II, linked from the site footer)](https://www.operant.ai/company/security) “Operant is SOC 2, Type II Compliant.” | official | 2026-06-16 |
| s12 | [Cato Networks press on acquiring Aim Security (September 3, 2025)](https://www.catonetworks.com/news/cato-acquires-aim-security-to-extend-sase-leadership-and-secure-enterprise-ai-transformation/) “Cato Networks, the SASE leader, announced today that it acquired Aim Security, a visionary leader of AI security. This is Cato's first-ever acquisition” | press | 2026-06-16 |
| s13 | [Check Point press on acquiring Lakera (September 16, 2025)](https://www.checkpoint.com/press-releases/check-point-acquires-lakera-to-deliver-end-to-end-ai-security-for-enterprises/) “Check Point Software Technologies Ltd. today announced it has entered into an agreement to acquire Lakera, one of the world's leading AI-native security platforms for Agentic AI applications.” | press | 2026-06-16 |
| s14 | [SentinelOne press on acquiring Prompt Security (announced August 5, 2025)](https://www.sentinelone.com/press/sentinelone-to-acquire-prompt-security/) “SentinelOne to Acquire Prompt Security to Advance GenAI Security and Agent Security Strategy ... Industry-first AI runtime security gives IT and security teams visibility, confidence and control over AI use” | press | 2026-06-16 |
| s15 | [Help Net Security: Woodpecker, open-source red teaming for AI, Kubernetes, APIs (Tembey interview, May 2025)](https://www.helpnetsecurity.com/2025/05/28/woodpecker-open-source-red-teaming/) “we wanted to democratize access to core red teaming capabilities that we don’t think should be limited to only the biggest companies with huge security budgets” | press | 2026-07-03 |
| s16 | [The New Stack: Kubernetes Runtime Defense Evolves Beyond eBPF (Jeffrey Burt, November 2024)](https://thenewstack.io/kubernetes-runtime-defense-evolves-beyond-ebpf/) “Operant isn’t the only vendor looking to protect the runtime environment ... While they warn developers of attacks, Operant’s technology takes steps to shut them down” | press | 2026-07-03 |
| s17 | [YourStory: Operant AI enters Indian market to secure AI systems in real time (March 2025)](https://yourstory.com/2025/03/us-based-operant-ai-enters-indian-market-secure-ai-systems-real-time) “Silicon Valley-based cybersecurity AI startup Operant AI is entering the Indian market, introducing its Runtime AI Application Defense Platform to safeguard AI systems against emerging threats.” | press | 2026-07-03 |
| s18 | [CB Insights company profile: Operant AI (Series A stage, investor roster, competitor set)](https://www.cbinsights.com/company/operantai) “Operant AI's latest funding round is Series A ... Investors of Operant AI include Felicis, Calm Ventures, SineWave Ventures, Gaingels, Massive Capital Partners and 11 more ... Competitors of Operant AI include WitnessAI, E2B, Virtue AI, RAD Security, Lacework and 7 more” | research | 2026-07-03 |
| s19 | [SEC EDGAR Form D: Gaingels Operant LLC, investment vehicle of Series A backer Gaingels ($221,275, first sale 2024-08-08)](https://www.sec.gov/Archives/edgar/data/2033701/000203302124000002/xslFormDX01/primary_doc.xml) “Name of Issuer Gaingels Operant LLC ... Date of First Sale 2024-08-08 ... Total Amount Sold $ 221,275 USD” | regulatory | 2026-07-03 |

### Deep-Dive Sources

Cited from the Strategy Deep Dive section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Operant AI homepage: 3D defense, MCP security, Endpoint Protector, Gartner AI TRiSM, and named testimonials](https://www.operant.ai) “Get 3D Defense for your entire AI application ecosystem from models to APIs ... Raj Yavatkar, CTO, Juniper Networks ... Suhel Khan, Cyber Security Leader \| Chargebee ... Prutha Parikh, Head of Security at Cohere ... Martin Choluj, CISO at Clickhouse” | official | 2026-07-01 |
| s2 | [Operant AI Gatekeeper product page (MCP and AI NHI protection, Gartner featured vendor)](https://www.operant.ai/platform/ai-gatekeeper) “get comprehensive support for Model Context Protocol (MCP), and AI Non-Human Identities (NHIs) with detection and access control to defend across both the runtime and API access layers of agent tools. Get fine-grained, identity-aware enforcement across increasingly autonomous agentic systems.” | official | 2026-06-17 |
| s3 | [Operant 3D Runtime Defense for Kubernetes, APIs, and services (in-line auto-redaction, quarantine)](https://www.operant.ai/platform/3d-runtime-defense) “In-line Auto-Redaction, Obfuscation and Blocking. Automatically redact and block sensitive data flows, safeguarding data privacy by default. Intelligent Quarantine of Runtime Threats. Isolate suspicious third-party containers and AI models to prevent malicious activity.” | official | 2026-06-17 |
| s4 | [Operant Endpoint Protector page (macOS, Windows, Linux device security for the AI workforce)](https://www.operant.ai/platform/endpoint-protector) “Discover the Shadow AI tools, coding agents, and MCP clients running on employee devices, and actively block prompt injection, data exfiltration, and malicious shell execution on the device. macOS, Windows, and Linux clients. Lightweight footprint, no kernel extensions required.” | official | 2026-06-18 |
| s5 | [Operant Woodpecker GitHub repository (red teaming for AI and cloud)](https://github.com/OperantAI/woodpecker) “GitHub - OperantAI/woodpecker: Red Teaming for AI and Cloud” | official | 2026-06-17 |
| s6 | [About Operant AI (co-founders Vrajesh Bhavsar ex-Apple and Priyanka Tembey ex-VMware)](https://www.operant.ai/company/about) “Vrajesh built core technologies for iOS & macOS including Dynamic Tracing, Data Protection and Secure Enclave at Apple. ... Priyanka was one of the foundational engineers to build out VMware's hybrid cloud product” | official | 2026-07-03 |
| s7 | [Security at Operant page (SOC 2 Type II, secure-by-default, least privilege)](https://www.operant.ai/company/security) “Operant is SOC 2, Type II Compliant. Operant's internal security and risk management is guided by our own product pillar of being secure by default. Least privilege is enforced all the way from our development and production infrastructure to the product layer and APIs.” | official | 2026-06-17 |
| s8 | [SecurityWeek on Operant AI Series A (founders, 13.5M total, April 2023, 80% runtime attacks)](https://www.securityweek.com/operant-ai-lands-10m-investment-to-boost-runtime-protection-for-cloud-and-ai/) “The Series A investment was provided by SineWave Ventures, Felicis, Alumni Ventures, Massive, Calm Ventures and Gaingels. Operant AI has raised a total of $13.5 million since its public launch in April 2023, and claims it can block more than 80% of common runtime attacks including the OWASP Top 10.” | press | 2026-06-18 |
| s9 | [SiliconANGLE on Operant launching Woodpecker open-source red teaming](https://siliconangle.com/2025/05/21/operant-ai-launches-woodpecker-bring-open-source-red-teaming-ai-cloud-environments/) “Operant AI Inc., a startup that offers a runtime application protection platform, today announced the launch of Woodpecker, an open-source, automated red teaming engine that helps make advanced security testing accessible to organizations of all sizes.” | press | 2026-06-17 |
| s10 | [Cato Networks press on acquiring Aim Security (September 3, 2025)](https://www.catonetworks.com/news/cato-acquires-aim-security-to-extend-sase-leadership-and-secure-enterprise-ai-transformation/) “Cato Networks, the SASE leader, announced today that it acquired Aim Security, a visionary leader of AI security. This is Cato's first-ever acquisition and will further expand the Cato SASE Cloud Platform, enabling secure enterprise adoption of AI agents.” | press | 2026-06-17 |
| s11 | [SentinelOne press on acquiring Prompt Security (August 5, 2025)](https://www.sentinelone.com/press/sentinelone-to-acquire-prompt-security/) “SentinelOne today announced it has signed a definitive agreement to acquire Prompt Security, a pioneer in securing AI in runtime, preventing AI-related data leakage and protecting intelligent agents.” | press | 2026-07-01 |
| s12 | [Check Point press on acquiring Lakera (September 16, 2025)](https://www.checkpoint.com/press-releases/check-point-acquires-lakera-to-deliver-end-to-end-ai-security-for-enterprises/) “Check Point Software Technologies Ltd. today announced it has entered into an agreement to acquire Lakera, one of the world's leading AI-native security platforms for Agentic AI applications.” | press | 2026-06-17 |
| s13 | [Help Net Security: Woodpecker, open-source red teaming for AI, Kubernetes, APIs (Tembey interview, May 2025)](https://www.helpnetsecurity.com/2025/05/28/woodpecker-open-source-red-teaming/) “we wanted to democratize access to core red teaming capabilities that we don’t think should be limited to only the biggest companies with huge security budgets” | press | 2026-07-03 |
| s14 | [The New Stack: Kubernetes Runtime Defense Evolves Beyond eBPF (Jeffrey Burt, November 2024)](https://thenewstack.io/kubernetes-runtime-defense-evolves-beyond-ebpf/) “Operant isn’t the only vendor looking to protect the runtime environment ... While they warn developers of attacks, Operant’s technology takes steps to shut them down” | press | 2026-07-03 |
| s15 | [YourStory: Operant AI enters Indian market to secure AI systems in real time (March 2025)](https://yourstory.com/2025/03/us-based-operant-ai-enters-indian-market-secure-ai-systems-real-time) “Silicon Valley-based cybersecurity AI startup Operant AI is entering the Indian market, introducing its Runtime AI Application Defense Platform to safeguard AI systems against emerging threats.” | press | 2026-07-03 |
| s16 | [CB Insights company profile: Operant AI (Series A stage, investor roster, competitor set)](https://www.cbinsights.com/company/operantai) “Operant AI's latest funding round is Series A ... Investors of Operant AI include Felicis, Calm Ventures, SineWave Ventures, Gaingels, Massive Capital Partners and 11 more ... Competitors of Operant AI include WitnessAI, E2B, Virtue AI, RAD Security, Lacework and 7 more” | research | 2026-07-03 |
| s17 | [SEC EDGAR Form D: Gaingels Operant LLC, investment vehicle of Series A backer Gaingels ($221,275, first sale 2024-08-08)](https://www.sec.gov/Archives/edgar/data/2033701/000203302124000002/xslFormDX01/primary_doc.xml) “Name of Issuer Gaingels Operant LLC ... Date of First Sale 2024-08-08 ... Total Amount Sold $ 221,275 USD” | regulatory | 2026-07-03 |

## Disclaimer

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.
