Calculator · Scores as of September 2026
AI security tool score calculator
The verdict
Move the sliders to set how much each criterion matters to you, and the table re-ranks all nine tools using our published criterion scores. With our default weights Bay ranks first; if you weight coverage beyond the endpoint and vendor maturity more heavily, tools such as Noma Security and Zenity move up. No vendor in this guide publishes list prices, so the calculator compares scores, not cost.
Our rankings weight endpoint agent control, because that is the topic of this guide. Your priorities may differ. Each slider sets a relative weight from 0 to 30; the default positions are the weights we publish on How we score (22, 20, 15, 12, 13, 8 and 10, summing to 100). Criterion scores do not change, only the weights.
Discovery of AI agents, coding assistants, MCP servers, extensions, tools and exposed credentials on devices, fleet-wide.
Ability to evaluate and stop an individual tool call or MCP connection before it runs, not only to list it.
Rules that use context (user, agent, prior actions, data touched) and actions beyond allow/deny, such as ask, warn, mask or simulate.
Whether the tool records who triggered an action, whether a person was involved, and the chain from prompt to system action.
How the tool reaches devices; credit for deploying through existing EDR or MDM without a new resident agent, and for published deployment detail.
SaaS agents, cloud and homegrown AI apps, browser AI, red teaming.
Time in market, public documentation, compliance attestations, backing, and whether pricing is published.
Weights sum: 100
| Rank | Tool | Re-weighted score | Change vs our ranking | Pricing |
|---|---|---|---|---|
| 1 | Bay | 7.9 7.9 / 10 | no change | Not published, contact sales |
| 2 | Noma Security | 7.5 7.5 / 10 | no change | Not published, contact sales |
| =3 | Onyx Security | 7.4 7.4 / 10 | no change | Not published, contact sales |
| =3 | Zenity | 7.4 7.4 / 10 | no change | Not published, contact sales |
| =5 | Harmonic Security | 7.1 7.1 / 10 | no change | Tier names published (Explore, Guide, Command); prices not published |
| =5 | Koi | 7.1 7.1 / 10 | no change | Not published, contact sales |
| =7 | Lasso Security | 6.6 6.6 / 10 | no change | Not published, contact sales |
| =7 | Prompt Security | 6.6 6.6 / 10 | no change | Not published, contact sales |
| 9 | Bloom Security | 6.0 6.0 / 10 | no change | Not published, contact sales |
Re-weighted score = (visibility x w1 + tool-call control x w2 + policy x w3 + identity and audit x w4 + footprint x w5 + breadth x w6 + maturity x w7) / (w1 + w2 + w3 + w4 + w5 + w6 + w7). Criterion scores are 0-10. Ties at one decimal share a rank.
Why is there no cost column? None of the nine vendors publishes list prices as of September 2026, so any cost figure would be a guess. Harmonic Security publishes its tier names. Ask each vendor for a quote; question 29 of our buyer's checklist covers how pricing is calculated.
Scores are editorial assessments from public vendor material, last reviewed September 2026. Pricing status is as published on vendor sites on the same date.
How do I use the calculator?
What do the sliders change?
Only the weight of each criterion. Each tool's score on each criterion stays as published on its review page; the calculator multiplies each score by your weight and divides by the sum of your weights.
Why does Bay rank first with the default weights?
Our published weights favour endpoint agent visibility and tool-call control, where Bay's public material is the most specific. Bay scores lowest of the nine on maturity and on coverage beyond the endpoint, so raising those weights moves other tools up.
Can I compare prices here?
No. None of the nine vendors publishes list prices, so the table shows pricing status only. Budget with vendor quotes.
Are these scores based on product testing?
No. They are editorial assessments from public vendor pages, documentation and press releases, reviewed September 2026.