| Runtime action interception | On documented harness surfaces, intercepts supported shell, file, MCP, skill, and package actions before execution. | API Intercept screens agent requests and responses before execution. | Guard API screens requests at runtime; Agent Behavior Defense flags tool calls; action-level interception not documented. | MCP Gateway secures interactions in production; action-level interception not documented. | Runtime security detects and stops AI threats in production. | Runtime protection for agentic systems documented; action-level interception not detailed. |
|---|
| Policy enforcement | Local and team policy can allow, observe, ask, or block on supported action surfaces. | Policy enforcement model not detailed at cited sources. | Policy-based guardrails with configurable flagging sensitivity levels. | Policy enforcement model not detailed at cited source. | Policy enforcement model not detailed at cited source. | Policy enforcement model not detailed at cited sources. |
|---|
| Human review workflow | Dedicated review workbench with queue, decision controls, and routing. | Dedicated human review workflow not documented at cited sources. | Dedicated human review workflow not documented at cited sources. | Dedicated human review workflow not documented at cited source. | Dedicated human review workflow not documented at cited source. | Dedicated human review workflow not documented at cited sources. |
|---|
| MCP and tool coverage | Screens supported MCP, shell, file, package, and skill surfaces. | Agent protection via API Intercept documented; MCP-specific coverage not detailed. | Tool message roles, Tool Allow/Deny List, and tool description screening documented; full MCP server coverage not detailed. | MCP Gateway secures Model Context Protocol interactions in production. | MCP or tool coverage not detailed at cited source. | Agentic and MCP security solution documented. |
|---|
| Routing and failover | Primary and failover route lanes with health monitoring and decision preview. | Routing or failover model not documented at cited sources. | Routing or failover model not documented at cited sources. | Routing or failover model not documented at cited source. | Routing or failover model not documented at cited source. | Routing or failover model not documented at cited sources. |
|---|
| Evidence and audit | Retains local receipts, an evidence timeline, and decision replay; configured exports can include an integrity digest. | API reference and agent discovery documented; receipt or audit model not detailed. | Results logging and SIEM export documented; receipt model not detailed. | Compliance-ready audit trails mentioned; receipt model not detailed. | Runtime visibility documented; audit trail model not detailed. | Visibility for agentic systems documented; audit trail model not detailed. |
|---|
| Deployment model | Local-first on macOS, Linux, and Windows; optional Cloud sync. | Cloud-based API Intercept. | SaaS or self-hosted deployment. | SaaS platform with open-source MCP Gateway; deployment architecture partially detailed. | SaaS runtime security; now part of Palo Alto Networks. | SaaS platform; deployment architecture partially detailed. |
|---|