The AI security and governance market is usually mapped by funding. That tells you who raised, not who does what. This page maps it by control point — the place in the stack where each product actually intervenes — because that is what determines whether two vendors compete, compose, or never meet at all.
Why control point, and not category
Almost every vendor in this space now says "AI runtime governance," "agentic AI security," or "control plane." The words have stopped discriminating. Two products using identical language can sit in entirely different parts of the stack, see entirely different traffic, and fail in entirely different ways.
One question separates them. Where does the product intervene, and what can it not see from there? Everything else — the feature grid, the funding round, the analyst quadrant — follows from the answer.
What follows is nine control points, the vendors that operate at each, and what each position can and cannot reach. Every placement comes from the vendor's own published documentation, verified in September 2026. Where a vendor operates at more than one point, they appear more than once.
The nine control points
1. The model request path
An inline proxy every model call traverses. Sees the prompt before the model does, and can refuse it. This is where an AI gateway lives, and where policy can be enforced rather than observed.
Operating here: Smartflow, LiteLLM, Portkey, now Prisma AIRS AI Gateway, TrueFoundry, Kong AI Gateway, Cloudflare AI Gateway, Onyx Security, Aurascape, NeuralTrust.
Cannot see: any call not routed through it. A gateway governs what points at it and nothing else.
2. The network path
Interception of AI traffic as it crosses the network, with no integration required. Catches consumer tools in a browser and native desktop applications that no gateway will ever see.
Operating here: WitnessAI.
Cannot see: traffic that never crosses a routable network path — which is precisely where a regulated institution puts its most sensitive workloads.
3. The tool and MCP path
Between an agent and the tools it invokes. Governs what an agent is allowed to reach rather than what it is allowed to say.
Operating here: Smartflow, Aurascape's Zero-Bypass MCP Gateway, Runlayer, Kong's MCP proxy, Portkey's MCP Gateway, TrueFoundry's MCP Gateway, NeuralTrust.
Cannot see: what the model was asked, and what it reasoned, before it decided to call the tool.
4. The agent harness
Inside the agent's own execution loop, via the hooks a coding agent or agent framework exposes. Inline with respect to the agent's decisions; not inline with respect to the model call.
Operating here: HiddenLayer's Agent Harness Security, Credo AI's Agent Governor, Straiker's SDK and sensor.
Cannot see: agents running in harnesses the product does not support, and anything that is not an agent.
5. The agent action layer inside SaaS platforms
Where a low-code or vendor-hosted agent takes an action inside Copilot Studio, Agentforce or a similar platform. A gateway has no insertion point here, which is what makes this a real and separate position.
Operating here: Zenity.
Cannot see: agents and applications outside the supported platforms.
6. The endpoint and browser
At the point a person pastes, uploads or types. Catches the human action rather than the machine call.
Operating here: MIND, and the endpoint and browser components of several platforms above.
Cannot see: anything an application or agent does without a person at a keyboard.
7. The credential path
Between a workload or agent and the secret it needs. Governs what an agent can authenticate to, not what it says to a model.
Operating here: Hush Security, and the non-human identity market generally.
Cannot see: what happens after authentication succeeds.
8. Posture, artifacts and supply chain
Before anything runs. Model files scanned for serialization attacks, agent add-ons vetted before deployment, SaaS and identity configuration assessed for drift.
Operating here: HiddenLayer's model scanning, AIR Security's add-on and context vetting, Obsidian Security for SaaS and identity posture, Oligo Security for application runtime via eBPF, Noma Security's AI-SPM.
Cannot see: what a correctly configured, cleanly scanned system is asked to do at two in the morning.
9. Out-of-band governance, assessment and testing
Alongside the running system rather than inside it. Registry, risk assessment, conformity documentation, red teaming.
Operating here: Credo AI, Noma Security's policy and detection layer, Straiker's red teaming, IBM watsonx.governance.
Cannot see: anything it was not told about, and cannot stop anything at all.
Three things the map makes obvious
Most of these are not competitors
A product at the credential path and a product at the model request path will appear in the same account, in the same budget conversation, and never in the same evaluation. They govern different verbs. The funding table flattens that distinction; the control-point map does not.
The clearest example is Noma Security, which markets an explicit refusal to be the inline control point: decouple governance from any single control point, and enforce through AI gateways, MCP gateways, agent hooks and SDKs. They already ship a plugin for Kong's AI Gateway. That is a vendor looking for gateways to work with, not against.
The security-branded inline vendors are, almost without exception, SaaS
Across WitnessAI, Aurascape, Zenity, Noma, Straiker and HiddenLayer, on-premises deployment is not documented, and air-gapped operation is not documented by any vendor in this list. Onyx Security documents self-hosted deployment for data residency, which is the closest any of them comes.
For most enterprises that is fine. For a defense program inside an accredited enclave, or a bank whose model-risk perimeter forbids third-party transit of prompt content, it removes most of the market before the feature comparison begins. AI sovereignty is not a preference in those environments; it is the entry condition.
Almost nobody gives the agent a name of its own
Every inline vendor examined attributes agent activity back to a human identity or a service account. Onyx correlates activity to the invoking user and the agent owner. WitnessAI markets human-to-agent attribution directly. Aurascape signs approved tool calls, which is closer, but signs the call rather than issuing the agent a credential.
Attribution answers who is responsible. It does not let an agent be revoked without disabling a person, does not let an information barrier be enforced against the agent as a party, and does not produce a supervision record naming the acting entity. Agent identity as a first-class principal is the gap this market has not closed.
How to use this when evaluating
Four questions that cut through the category language faster than any feature grid.
- Where exactly does this intervene, and what does that position not see? Every vendor can answer the first half. The second half is where the evaluation happens.
- Can it run where our data has to stay? Ask for on-premises and air-gapped specifically. "Single-tenant with customer-managed keys" is a different answer to a different question.
- Does an agent get an identity, or borrow one? If the audit record names the person whose key the agent used, agent governance is reconstruction rather than control.
- Can it produce the artifact our regulator asks for? A control-framework mapping is not an examination package. Ask for a sample of each.
Where APERION sits
Smartflow operates at the model request path and the tool path, in one control plane, running on-premises or air-gapped inside the customer's own perimeter. Policy is enforced before the call executes, every agent carries a cryptographic credential of its own, and the enforcement records are what the examination packages are generated from.
That is a deliberate position rather than a complete one. Smartflow does not scan model artifacts, does not red-team agents, does not manage SaaS posture, and does not sit on the endpoint. Several products on this map compose with it well, and a serious AI governance program will run more than one.
Related reading
Head-to-head comparisons · AI control plane guide · Enterprise AI gateway guide · Trust Fabric architecture · Glossary
Every placement on this page was verified against the named vendor's own published documentation in September 2026. Vendors move, and several of these are moving quickly. If a placement here is out of date, tell us and we will correct it.
Put this in the path of your own agents.
Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.
Request a Demo Read the docs