Tool review · Checked against vendor sites, September 2026
Onyx Security review (2026): inline control for AI agents across surfaces
The verdict
Onyx Security is the pick for teams that want one control plane inspecting every prompt, tool call and model response inline, with more enforcement actions than any other tool here. It covers browser AI, coding assistants, desktop agents, cloud workloads and MCP servers, and uses endpoint agents and browser extensions to do it.
What does Onyx Security do?
- Describes itself as "The Secure AI Control Plane for the Agentic Era", covering SaaS, cloud, endpoint and code environments.
- Inspects every prompt, tool call and model response inline.
- Five enforcement actions: alert, block, mask, steer, or ask (human in the loop).
- Agent posture management for misconfigurations, excessive permissions and credential handling.
- Solutions for agent identity and access governance, AI discovery and shadow AI, MCP security, and runtime and prompt injection defense.
- Autonomous agentic red teaming.
- Lists SOC 2 Type II and ISO 27001, with NIST AI RMF and OWASP LLM Top 10 mapping (vendor-stated).
- Announced a $113M Series B led by Bessemer Venture Partners on 29 July 2026.
Source: onyx.security · Onyx AI security · Onyx Series B · Reviewed Sep 2026
How does Onyx Security deploy?
Onyx says it needs no SDK changes and works across endpoint agents, browser extensions, APIs and gateways. It integrates with Okta, Entra, Splunk and CrowdStrike. On devices this means a resident component, which is why it scores lower on footprint than tools that deploy through EDR or MDM.
Source: onyx.security · Onyx AI security · Onyx Series B · Reviewed Sep 2026
How does Onyx Security score?
Discovers AI agents across SaaS, cloud, endpoint and code; endpoint inventory detail is lighter than endpoint-first tools.
Inspects every prompt, tool call and model response inline.
Five enforcement actions: alert, block, mask, steer, or ask a human.
Agent identity and access governance is a named solution.
Works across endpoint agents, browser extensions, APIs and gateways; the endpoint component is a resident agent or extension.
Browser AI, coding assistants, desktop agents, cloud workloads and MCP servers, plus agentic red teaming.
$113M Series B announced 29 July 2026; SOC 2 Type II and ISO 27001 listed; pricing not published.
Where is Onyx Security strongest?
- Richest set of enforcement actions (alert, block, mask, steer, ask).
- Inline inspection of tool calls and model responses, not only prompts.
- Broad surface coverage plus red teaming.
What should buyers check before choosing Onyx Security?
- Endpoint inventory depth is described less specifically than endpoint-first tools.
- Several deployment components (endpoint agent, browser extension, gateway).
- Pricing is not published.
Who should shortlist Onyx Security?
Shortlist Onyx Security if you want a single inline control point across browser AI, coding assistants and cloud agents, with masking and steering rather than only blocking.
What does Onyx Security cost?
Contact sales. Onyx Security does not publish pricing.
Frequently asked questions
Which Onyx is this?
Onyx Security (onyx.security), headquartered in Tel Aviv with an office in New York.
Related
- MCP security
- Buyer's checklist
- Alternatives to Onyx Security
- Compare Onyx Security with the top-ranked tools
Head to head
Sources
- onyx.security · Reviewed Sep 2026
- Onyx AI security · Reviewed Sep 2026
- Onyx Series B · Reviewed Sep 2026