Best AI Security markBest AI Security

NOTE · 6 AUGUST 2026

What AI agent security tools cost, and why no vendor publishes a price

The verdict

As of September 2026, none of the nine vendors on this site publishes list prices, so every pricing row says contact sales. Harmonic Security publishes three tier names without prices, and Koi and Prompt Security are sold inside larger platforms. To compare costs, ask every vendor to quote the same unit, scope and term, and ask what is included.

Pricing is the one row every vendor on this site leaves blank. Here is what is published, and how to get numbers you can compare.

By Best AI Security editors · 6 August 2026 · 4 min read

What do the nine vendors publish about price?

From public vendor pages reviewed September 2026.
ToolWhat is published about price
BayNo pricing page. Demo requests go through bay.io/demo.
Noma SecurityNot published.
ZenityNot published.
Onyx SecurityNot published.
Harmonic SecurityThree named tiers, Explore, Guide and Command. No prices.
Koi (Palo Alto Networks)Not published. Offered as a Cortex XDR module or standalone.
Prompt SecurityNot published. Built into the SentinelOne Singularity Platform.
Lasso SecurityNot published.
Bloom SecurityNot published.

Why is nothing published?

We can describe what the pages show, not the vendors' reasons. Three patterns are visible. Several of these companies are young: Onyx Security came out of stealth in March 2026, and Bloom Security published its launch post in July 2026. Two products now sit inside larger platforms, where the price of one module usually depends on the rest of the contract. And most tools span several parts of a company's estate, from laptops to SaaS platforms, so the scope of a deal varies widely. Enterprise security software is often sold through quotes, and this category follows that pattern.

Which pricing units might a quote use?

Question 29 of our buyer's checklist asks how pricing is calculated: per user, per device or per agent, and what is included. None of the nine publishes its unit, so ask. Each unit behaves differently as AI use grows:

  • Per user: predictable when headcount is stable. Check whether contractors and service accounts count.
  • Per device: tracks the endpoints you deploy to. Check how shared machines, virtual desktops and remote development environments are counted.
  • Per agent or per AI app: tracks AI use directly, but can rise quickly as teams add agents and MCP servers.
  • Platform bundle: for products sold inside an EDR or security platform, the price may depend on what else you buy from that vendor.

What should a quote include?

  • The unit and the count, and what happens when the count grows mid-term.
  • Which capabilities are included: inventory only, or inventory plus enforcement, audit records and integrations.
  • Which agents and operating systems are supported at the quoted price.
  • Deployment and support: whether rollout help, policy tuning and a simulation period are included.
  • The term, and how renewal pricing is set.

How do you compare quotes fairly?

Ask every shortlisted vendor to quote the same scope: the same number of users or devices, the same agents and the same capabilities, for the same term. Then set each price beside the criteria that matter to you. Our score calculator re-weights the seven criteria so you can see which tools lead on your priorities before prices arrive, and the side-by-side comparison lists each vendor's pricing status and deployment route.

Two costs rarely appear on a quote. The first is rollout effort: a tool that deploys through the EDR or MDM you already run avoids rolling out a new agent, which is one reason deployment footprint is one of our seven criteria. The second is the cost of a rule that blocks legitimate work; simulation modes and ask answers reduce it. Both belong in the comparison.

Will prices be published?

We will update this note if any vendor publishes list prices. Our next scheduled review of every vendor's public pages is December 2026.

Related

Sources