
AI Security
Lasso AI Security Platform
AI security covering agent discovery, posture, red teaming, and intent-based runtime enforcement.
Lasso AI Security Platform Overview
What it does
Lasso Security LLM Guardian, now part of the broader Lasso Platform, is an enterprise AI security platform spanning discovery, posture management, automated red teaming, and runtime enforcement for LLM-powered applications and autonomous agents. Its distinguishing addition is Intent Security: a behavioral baseline framework that evaluates whether agent actions align with user intent and historical behavior, rather than relying on stateless pattern matching alone.
How it works
The platform connects to cloud AI builders, code repositories, and runtime gateways to inventory every agent via an AI Bill of Materials (AI-BOM), run posture analysis and 3,000+ attack-type red teaming simulations, and enforce inline policies at the proxy, API, or AI gateway layer in under 50 milliseconds. Intent Security monitors the full interaction execution path, validates goal consistency and scope adherence, and blocks or alerts on behavioral deviations across multi-agent chains.
Credentials and traction
Lasso Security is SOC 2 Type 2 compliant for its platform operations. It was named a Gartner Cool Vendor for AI Security in 2024 and designated a Representative Vendor in Gartner's Innovation Guide for GenAI TRiSM, and it won a 2026 Global InfoSec Award. Named customers include the US Department of Homeland Security, eToro, and Kaltura.
Key Capabilities
mapped to solution categoriesDefines organizational AI usage policies and enforces them at the point of use - allowing, blocking, redirecting, or constraining specific AI services, models, and features per user, group, or data context.
Inspects prompts, uploads, and AI-generated responses for sensitive data across modalities, preventing exposure of regulated or proprietary information to third-party AI services.
Enforces AI usage controls through multiple local inspection points - browser, endpoint, and network - coordinated from a cloud-delivered control plane, so coverage does not depend on a single interception path.
Discovers and categorizes the organization's use of third-party AI, whether consumed as a service, installed locally, or embedded inside other applications, building a continuously updated inventory of AI usage including shadow AI.
Discovers MCP servers and AI agent integrations in use, routes agent tool calls through a governed gateway or proxy, and enforces access and data policies on agent-to-tool traffic, extending AI usage control from human prompts to autonomous agent workflows.
Detects and blocks adversarial inputs designed to override system prompts, extract training data, or redirect model behavior. Detection approaches include pattern matching, input semantic analysis, and secondary model classification.
Intercepts prompts and completions to prevent sensitive data (PII, credentials, internal IP), from being transmitted to external LLM services or returned in model responses.
Evaluates model outputs against content policy, data classification rules, and format expectations before delivery to end users, blocking responses containing sensitive data or policy violations.
Enforces IAM-style policies on LLM API access, controlling which users and applications can invoke which models and data sources, with audit logging.
Records prompts, completions, and metadata for all AI interactions with tamper-resistant storage, supporting compliance, forensics, and policy investigation.
Continuously stress-tests the product's own guardrails and filters against jailbreaks, prompt-injection payloads, and data-extraction attempts, then re-tightens policies after model or prompt changes. A self-validation loop within the runtime protection layer, distinct from the standalone AI Red Teaming discipline that tests AI systems end to end.
Secures AI coding assistants and their Model Context Protocol connections against unsafe actions, data exposure and supply-chain risks.
Baselines how a deployed AI agent normally reasons, calls tools and chains actions, then flags or blocks behavioral anomalies such as agent drift, intent manipulation and tool-abuse sequences, at the low latency and low false-positive rate that inline agent traffic tolerates.
Discovers, governs and allowlists the Model Context Protocol servers and tools that AI agents are permitted to invoke, and enforces the connection controls the protocol does not provide by default: transport security, OAuth-based agent authentication, scoped short-lived tokens, and gateway or proxy mediation of external MCP traffic.
Discovers the AI models, agents, MCP servers and AI-enabled applications in use across the organization, including those deployed without IT authorization, and keeps them in an inventory that records type, ownership and criticality. Discovery runs through traffic inspection and code repository scanning at minimum; some products add cloud provider, application server or AI engineering tool integrations. The inventory anchors exposure management and risk scoring.
Maps data lineage and provenance across AI training and inference pipelines, tracing how PII, PHI, and IP move into models and external services.
Scores deployed AI models by risk level based on data sensitivity processed, deployment scope, capability classification, and applicable regulatory requirements.
Detects sensitive or regulated data in AI training, fine-tuning, or third-party LLM flows without appropriate controls, such as unencrypted PII in inputs or PHI sent to external APIs.
Scans the configuration of AI model and inference endpoints, and of the MCP servers and tool endpoints that agents call, and flags public exposure, weak or missing authentication, default credentials and excessive permissions as posture findings. Findings come from configuration and passive scanning rather than inline traffic inspection, which belongs to runtime defense. Products differ in the endpoint types covered and in whether findings carry a severity score.
Maps AI posture findings and the controls in place to AI security and regulatory frameworks such as the EU AI Act, NIST AI RMF and ISO/IEC 42001, and reports coverage and open gaps per framework for audits, regulators and leadership. The reporting draws on the AI inventory and its findings; approval workflows, attestations and evidence management belong to AI governance platforms.
Discovers AI assets, including shadow models, agents, and inference endpoints, and maps the reachable attack surface to scope and target red-team campaigns. Offensive reconnaissance, distinct from posture inventory.
Re-runs red-team campaigns continuously and at release gates in the CI/CD pipeline as models, prompts, and configurations change, catching new exploit paths before and after deployment.
Tests LLMs and AI applications against a library of direct and indirect prompt-injection and jailbreak techniques, reporting which payloads bypass system instructions and safety controls.
Attacks AI agents through their tools, memory, and connected services using multi-step techniques such as tool misuse, goal hijacking, and indirect injection, surfacing exploit paths unique to autonomous agents.
Autonomously plans and executes multi-step adversarial campaigns against AI systems, emulating real attacker workflows across reconnaissance, exploitation, and escalation rather than running a fixed checklist of tests.
Reports validated AI vulnerabilities with reproduction evidence, attacker context, and remediation guidance, mapped to the OWASP LLM Top 10, MITRE ATLAS, EU AI Act, and NIST AI RMF for auditable AI risk reporting.
Tests AI agents and their tool chains for context-poisoning, tool-misuse and indirect prompt-injection vulnerabilities.
Attacks deployed guardrails, system prompts and content filters to measure how reliably they block adversarial inputs, quantifying bypass rates rather than assuming the controls work, and feeds the results back so runtime guardrails can be tuned to the exposures the assessment found.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on October 9, 2026
Buyers
Start a shortlist with Lasso AI Security Platform
Compare options, add your notes, and run informed evaluations.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.