Best AI Security markBest AI Security

Tool review · Checked against vendor sites, September 2026

Onyx Security review (2026): inline control for AI agents across surfaces

The verdict

Onyx Security is the pick for teams that want one control plane inspecting every prompt, tool call and model response inline, with more enforcement actions than any other tool here. It covers browser AI, coding assistants, desktop agents, cloud workloads and MCP servers, and uses endpoint agents and browser extensions to do it.

Rank =3 of 9

Best for inline control across many AI surfaces

Visit Onyx Security

What does Onyx Security do?

  • Describes itself as "The Secure AI Control Plane for the Agentic Era", covering SaaS, cloud, endpoint and code environments.
  • Inspects every prompt, tool call and model response inline.
  • Five enforcement actions: alert, block, mask, steer, or ask (human in the loop).
  • Agent posture management for misconfigurations, excessive permissions and credential handling.
  • Solutions for agent identity and access governance, AI discovery and shadow AI, MCP security, and runtime and prompt injection defense.
  • Autonomous agentic red teaming.
  • Lists SOC 2 Type II and ISO 27001, with NIST AI RMF and OWASP LLM Top 10 mapping (vendor-stated).
  • Announced a $113M Series B led by Bessemer Venture Partners on 29 July 2026.

Source: onyx.security · Onyx AI security · Onyx Series B · Reviewed Sep 2026

How does Onyx Security deploy?

Onyx says it needs no SDK changes and works across endpoint agents, browser extensions, APIs and gateways. It integrates with Okta, Entra, Splunk and CrowdStrike. On devices this means a resident component, which is why it scores lower on footprint than tools that deploy through EDR or MDM.

Source: onyx.security · Onyx AI security · Onyx Series B · Reviewed Sep 2026

How does Onyx Security score?

Endpoint and agent visibilityWeight 22%7/10

Discovers AI agents across SaaS, cloud, endpoint and code; endpoint inventory detail is lighter than endpoint-first tools.

MCP and tool-call controlWeight 20%8/10

Inspects every prompt, tool call and model response inline.

Policy granularityWeight 15%8/10

Five enforcement actions: alert, block, mask, steer, or ask a human.

Agent vs human identity and auditWeight 12%7/10

Agent identity and access governance is a named solution.

Deployment footprintWeight 13%6/10

Works across endpoint agents, browser extensions, APIs and gateways; the endpoint component is a resident agent or extension.

HIGHEST IN GUIDE
Coverage beyond the endpointWeight 8%9/10

Browser AI, coding assistants, desktop agents, cloud workloads and MCP servers, plus agentic red teaming.

Maturity and transparencyWeight 10%7/10

$113M Series B announced 29 July 2026; SOC 2 Type II and ISO 27001 listed; pricing not published.

Total

How we score

Where is Onyx Security strongest?

  • Richest set of enforcement actions (alert, block, mask, steer, ask).
  • Inline inspection of tool calls and model responses, not only prompts.
  • Broad surface coverage plus red teaming.

What should buyers check before choosing Onyx Security?

  • Endpoint inventory depth is described less specifically than endpoint-first tools.
  • Several deployment components (endpoint agent, browser extension, gateway).
  • Pricing is not published.

Who should shortlist Onyx Security?

Shortlist Onyx Security if you want a single inline control point across browser AI, coding assistants and cloud agents, with masking and steering rather than only blocking.

What does Onyx Security cost?

Contact sales. Onyx Security does not publish pricing.

Frequently asked questions

Which Onyx is this?

Onyx Security (onyx.security), headquartered in Tel Aviv with an office in New York.

Related

Head to head

Sources