PyxGrant / Compare

How PyxGrant compares, question by question.

Five vendors a security team is likely to shortlist for controlling what AI agents do, set against the questions we think matter. Below the table: AIR Security, Runlayer, free open-source coding-agent guardrails, and Anthropic's enterprise MCP controls — names buyers bring, answered before the meeting. Their column comes from their own public pages. Ours comes from building the product and running it. Where they are ahead, the page says so.

Sources read 27 September 2026

pyxgrant bypassreal output
1. two routine calls, through the gateway
   → allowed and recorded
2. wipe_all, through the gateway
   → REFUSED by policy
3. wipe_all, straight at the server
   → performed; PyxGrant never saw it

Reconciliation: 2 allowed action(s)
                vs 3 server event(s)
  matched      2
  BYPASS       1

PASS: the out-of-band call was named:
      [wipe_all]

An inline gateway cannot see a call that never reaches it. Comparing its record with the provider's own log can.

The comparison

Nine questions, six products.

“Not found” means we did not find it on the vendor's public pages on the date above. It does not mean the product can't do it. If you know otherwise, tell us and we'll correct the row.

  • YesStated, and specific
  • PartlySome of it, or only in some setups
  • Not foundNot on their public pages
  • NoWe don't do this
Question PyxGrant Prisma AIRSPalo Alto Networks Zenity Noma Security Okta for AI Agents Lasso Security
Where we built for depth
Can it stop a coding agent's own shell and file actions before they run? Yes

Answers the Claude Code and Cursor PreToolUse hook with allow, ask, or deny. PostToolUse scans a document the agent just read for macros and injected text. By default a path outside the workspace is held for a person.

Partly

Agentic endpoint security arrived with the Koi acquisition in April 2026. Hook-level blocking is not described.

Yes

Native hooks for Claude Code, Cursor Enterprise, and GitHub Copilot. Policies ship in Detect mode; blocking is switched on per policy.

Yes

Lists agent hooks among its enforcement points, and discovers Claude Code, Cursor, and Codex on endpoints.

Partly

Tool calls that go through its MCP gateway. An agent's built-in shell and file tools are not described.

Partly

MCP traffic through its gateway. Built-in agent tools are not described.

Can the decision run with no vendor cloud in the path? Yes

One Go binary on your machine. The self-test and the full walkthrough run offline.

Partly

A software firewall that can run on your own KVM hosts, alongside a managed service.

Not found

Delivered as a platform; homegrown agents call its Evaluate API.

Not found Partly

MCP Bridge runs in your own infrastructure, offered through Okta Professional Services.

Partly

The MIT-licensed gateway is self-hosted. Its advanced guardrail calls Lasso's API.

Does it name actions that went around it? Yes

Compares what it allowed with the provider's own audit export and names each action it never saw. You supply the export.

Not found Not found Not found Not found Not found
Can an outsider check a decision record without access to your systems? Yes

Signed receipts, a standalone verifier, and verifiers in JavaScript and Python. Keep the signing key off the audit disk, or a local admin could re-sign a shortened log.

Not found Not found Not found Not found Not found
Can delegated authority only narrow, and does revoking it cut off every child? Yes

A child grant can't exceed its parent. Revoking walks the tree and signs a record of each grant it ends. Delegation across organizations verifies without a shared secret.

Not found Not found Not found Partly

Short-lived, task-scoped tokens that carry the delegation chain. Revoking at the gateway is planned for Q4 2026.

Not found
Does it check a payment against what a person approved? Yes

A swapped cart, a tainted cart, or an amount over the cap is refused. pay reverse closes only after a registered provider confirms the money is gone. The core binary ships no live Stripe or Adyen connector. It decides; your payment rail moves the money.

Not found Not found Not found Not found Not found
Where they are ahead
Does it find agents across SaaS and cloud platforms? Partly

Pulls or imports inventories from Microsoft Graph, Okta, and Amazon Bedrock, and scans laptops, including ungoverned local model ports. No Copilot Studio, Agentforce, or ServiceNow connector.

Yes

Agents, apps, and models across the environment.

Yes

SaaS, cloud agent platforms, and endpoints.

Yes

Cloud platforms, SaaS agent builders, endpoints, and code repositories.

Yes

A registry of agents with human owners, plus shadow agent discovery.

Partly

GenAI discovery and monitoring in the paid platform.

Does detection use trained models, not only patterns? No

Injection scoring is pattern- and structure-based, so novel phrasing can pass. An optional local model helps the data classifier.

Yes

Its Precision AI engine.

Yes

Deterministic rules plus LLM-based intent detection, run asynchronously.

Yes

Its own AI security models.

Not found

Identity and policy, not content detection.

Yes

Through Lasso's detection API.

Is there an established company behind it? Early

A young company with no public customers yet. Judge the build, and ask us about support terms.

Yes Yes Yes Yes Yes

Signed decision records are not rare in general. Open-source projects such as Signet and Agent Receipts, and Traefik Hub's Sovereign Trust Plane, also sign agent actions for offline checking. The table above covers only these five vendors. Four more names sit below.

Also on the shortlist

Four more names buyers bring. Answered here.

Read 27 September 2026. “Not found” means we did not see it on their public pages that day. It does not mean the product can't do it.

AIR SecurityCame out of stealth 1 September 2026 with $50M (Sequoia, then Greenoaks)

AIR calls itself a context firewall: it sits between agents and the outside world and vets skills, plugins, MCP servers, and other add-ons before they land in an agent's context. It also sells discovery of sanctioned and shadow agents, runtime protection, and a marketplace of pre-vetted add-ons.

Where they are ahead. Add-on and skill supply-chain vetting, and a marketplace, are the product. We pin and quarantine a tool after it is already on the machine. We do not run a marketplace, and we do not claim a $50M company behind us.

What we did not find. A Claude Code or Cursor PreToolUse hook, a grant that can only narrow, cascade revocation of child grants and bound sessions, a payment checked against an approved cart, or a receipt an outsider verifies without their cloud. Their public pages describe a platform, not a binary you run offline.

RunlayerMCP control plane and gateway · $11M seed, November 2025 (Khosla, Felicis)

Runlayer is the funded MCP-gateway startup. Requests to approved servers go through its gateway so identity, policy, threat detection, and audit stay attached. Docs describe Okta and Entra, human-approval rules, and a choice of Runlayer-operated AWS or a gateway you host.

Where they are ahead. An enterprise MCP catalog with IdP-backed access, a named launch roster in the press, and a company that has already raised for this exact job. If the question is “who already sells a hosted MCP gateway,” it is them, not us.

What we did not find. A grant that can only narrow and whose revoke ends every child and bound session. Receipts an outsider verifies without their systems. A payment bound to a cart a person approved. Built-in Claude Code and Cursor shell and file tools — their public pages describe MCP traffic and an endpoint visibility agent, not the PreToolUse hook.

Open-source coding-agent guardrailsSideguard, Aperion Shield, Lasso's MIT gateway, and others

Free local proxies and hooks that sit in front of Cursor, Claude Code, and MCP servers. Typical features: YAML or rule packs, fail-closed deny of rm -rf and DROP TABLE, optional human approval, source you can read tonight.

Where they are ahead. Price is zero. You can install one this afternoon. If the only requirement is “don't let the agent wipe the disk,” one of these may be enough, and we should say so.

Where they stop. We have not found a narrow-only grant tree, a check against who the agent acts for from an IdP export, a signed evidence pack a third party verifies without the binary, or a payment bound to an approved cart. Lasso's MIT gateway is already in the table above: the open core is self-hosted; its advanced guardrail calls Lasso's API.

Anthropic enterprise MCP controlsEnterprise-managed auth for MCP connectors, generally available 24 August 2026

On Claude Team and Enterprise, an admin provisions official MCP connectors through the identity provider (Okta at launch). Users inherit access from IdP groups. The same grant applies across Claude chat, Claude Code, and Cowork. It replaces the per-person OAuth consent screen. It is authorization for who may connect, not a decision on each Bash or Read once they have.

Where they are ahead. Already inside Claude. No extra binary. Revocation follows the IdP. If the question is “can we stop people wiring personal Slack into work Claude,” this is the control that shipped.

What it is not. It does not answer the Claude Code hook, scan a tool result, hold a high-impact call for a signed approval, or write a receipt you verify offline. Use it for connector access. Use PyxGrant for what that connected agent then tries to do.

Check our column

Every “Yes” in our column has a command behind it.

Output below comes from runs of the product, condensed to fit. The hook answers in JSON; it is shown here as a table.

pyxgrant hook claude-code
# Claude Code asks: may the agent run this?
Bash  rm -rf / --no-preserve-root
→ ask    workspace-escape: / resolves outside
         the workspace root

Read  ~/.ssh/id_rsa
→ ask    workspace-escape

Edit  ./a.txt   → allow
Bash  ls        → allow

Ordinary work goes straight through. A step outside the workspace waits for a person, and policy can make it a flat deny.

pyxgrant demo · grants
PASS attenuate a child grant (scope ⊆ parent)
PASS call runs while the grant is alive
PASS revoke walks the tree and kills the child
     (2 grants killed)
PASS the bound session is refused once the
     grant is dead
PASS GrantDead receipt verifies with the
     store key (offline)
PASS re-delegation cannot widen scope beyond
     the parent grant

Two of the 26 sections in the built-in walkthrough, which runs 90 checks against a hostile MCP server.

pyxgrant demo · payments
PASS the authorized cart is paid
     ($19.99 to shop.example)
PASS a swapped cart is refused
PASS a tainted cart cannot pay
PASS a payment over the per-payment cap
     is refused

It binds the payment to the cart a person approved. The model cannot talk its way past the ceiling.

What we ran on 25 September 2026

  • go test ./...132 packages pass. One failed on a Windows temp-folder cleanup and passed on three reruns.
  • pyxgrant demo90 of 90 checks pass.
  • pyxgrant selftest19 of 19 checks pass.
  • pyxgrant bypassThe out-of-band call is named.
Our limits

From pyxgrant boundaries, the product's own list.

The binary prints what each control does not do. A sample:

Kernel confinement is Linux only

Landlock is applied by pyxgrant sandbox contain, not by the gateway inline. It can restrict files on Linux 5.13 and later, and outbound TCP on 6.7 and later. UDP and DNS are not covered. Other systems report that nothing was enforced.

The egress cage is a proxy

A client that ignores the proxy settings or opens a raw socket is not caught by it. The Linux network rule above is what closes that gap.

Injection scoring is patterns

Novel phrasing that matches no pattern or structure passes the scorer. Pinning, taint, the blast-radius gate, and a human hold sit behind it.

A log sealed on its own disk

Any edit, reorder, or drop is detected. But if the signing key sits beside the log, a local admin can shorten and re-sign it. Keep the key elsewhere.

Streams that already left stay sent

A restricted or irreversible tool result on SSE is buffered until the verdict; a deny releases no bytes. Other streams that already left the process stay sent. For identities that must hard-block those, turn streaming off.

Post-quantum is opt-in

The default build signs with Ed25519. ML-DSA-65 (FIPS 204) is a separate module you build in.

Ask every vendor the same nine questions.

Then ask us to run the commands on this page against your own policy.