AI security vendor
Palo Alto Networks
Commercial parent organization
Palo Alto Networks brings its AI security products together across application development, workforce access, cloud posture, and endpoint protection. Its portfolio spans Prisma AIRS for securing AI applications and models, and AI Access Security for governing employee use of generative AI services.
The broader product group also includes Portkey's AI gateway and observability platform, Koi Security's agentic endpoint security technology, Idira's identity security platform lineage, and Protect AI's open-source security toolkits (LLM Guard, ModelScan). These products retain distinct profiles here so their ownership, evidence, and capabilities remain clear while still appearing as part of the Palo Alto Networks portfolio.
7
Offerings
23
Reviewed claims
15
Capabilities
Domains
Access and GovernanceAgent SecurityData and PrivacyModel and ValidationPosture and RiskRuntime ProtectionSupply Chain and IntegrityActions
PREVENTPOSTUREDETECTAUDITOfferings
Open an offering for reviewed behavior and evidence
Palo Alto Networks · platform
Prisma AIRS
9 claims+
Palo Alto Networks · platform
Prisma AIRS
AI security platform for discovery, posture, model testing, and runtime protection across applications, models, agents, and data.
Official sourcePrisma AIRS applies real-time safeguards to AI prompts, responses, model interactions, agent actions, and data exposure paths.
Prisma AIRS simulates real-world attacks against single-agent and multi-agent AI systems to identify weaknesses before production.
Prisma AIRS scans third-party models for tampering, malicious scripts, and deserialization risks.
Prisma AIRS provides posture visibility and policy management for AI assets, training and inference data, application integrity, and model access.
Prisma AIRS verifies agent identity and enforces real-time security controls for agent actions.
Prisma AIRS maps enterprise, endpoint, and browser agents and surfaces MCP servers, plugins, tool interactions, shadow AI, and unsanctioned agents.
Prisma AIRS scans agent code, MCP servers, and skills for unsafe permissions, hidden vulnerabilities, and indirect injection paths.
Prisma AIRS governs agent tool calls, model access, and external connections through centralized policy and assigns each agent a governed identity with precise permissions and traceability.
Prisma AIRS stops agent-specific tool misuse, memory manipulation, adversarial instructions, and prompt injection before threats propagate across an agent swarm.
Palo Alto Networks · product
AI Access Security
3 claims+
Palo Alto Networks · product
AI Access Security
Prisma SASE product for discovering GenAI use and enforcing workforce access, data, and threat policies.
Official sourceAI Access Security discovers and categorizes GenAI applications, agents, marketplace plugins, usage, and users.
AI Access Security classifies GenAI applications by sanction status and can revoke access or control upload and download actions based on risk and privilege.
AI Access Security classifies sensitive content inline and blocks sensitive text and file transfers to GenAI applications.
Portkey · platform
Portkey
3 claims+
Portkey · platform
Portkey
AI gateway platform providing model access, observability, guardrails, governance, and prompt management.
Official sourcePortkey MCP Gateway centralizes authentication, fine-grained server and tool access, observability, and runtime policy and stops unauthorized tool invocations before execution.
Portkey automatically redacts sensitive data from requests before sending them to an LLM.
Portkey invokes Prisma AIRS guardrail checks before and after model requests and can enforce returned block verdicts.
Koi Security · product
Koi Agentic Endpoint Security
3 claims+
Koi Security · product
Koi Agentic Endpoint Security
Endpoint security product for discovering autonomous software and AI agents, detecting supply-chain shifts, and enforcing tool guardrails.
Official sourceKoi AES discovers and catalogs autonomous software agents, AI agents, browser extensions, software, and AI models on enterprise endpoints.
Koi AES evaluates code differences and behavioral shifts in real time to identify software supply-chain risk.
Koi AES enforces endpoint guardrails that approve, flag, or block autonomous tools.
Idira · product
Idira Secure AI Agents
3 claims+
Idira · product
Idira Secure AI Agents
Idira module that discovers AI agents, brokers task-scoped agent access, and audits agent actions and delegation. A native Prisma AIRS 3.0 integration is publicly announced as coming soon and is not yet reflected in behavior claims.
Official sourceIdira Secure AI Agents scans SaaS, cloud, and developer environments to discover active AI agents and enriches each one with ownership, purpose, status, and permission-level context in a centralized registry.
Idira Secure AI Agents acts as a dynamic agent identity broker that grants an agent access only for the duration of a specific task and automatically revokes permissions once the task completes.
Idira Secure AI Agents logs agent actions and communications, recording which agent performed an action and on behalf of which user, to support governance and compliance review.
Protect AI · project
LLM Guard
1 claims+
Protect AI · project
LLM Guard
Open-source LLM security scanner and guardrails library for real-time prompt sanitization, jailbreak mitigation, and output data leakage prevention.
Official sourceLLM Guard inspects, sanitizes, and evaluates LLM prompts and model completions against prompt injection, jailbreaks, and sensitive data leakage.
Protect AI · project
ModelScan
1 claims+
Protect AI · project
ModelScan
Open-source ML model security scanner that inspects serialized model artifacts (PyTorch, Pickle, Keras, SavedModel) for arbitrary code execution exploits and malicious payloads.
Official sourceModelScan statically analyzes serialized ML model files (PyTorch, Pickle, SavedModel, Keras) to detect embedded code execution exploits and malicious payload injections.