Noma Security serves security teams at enterprises adopting AI applications and autonomous agents, offering one platform that spans discovery and inventory of AI assets, access control for agents, automated red teaming of AI applications, and runtime detection and response for agent sessions. Its approach couples a single policy set with enforcement at the agent control points an organization already runs, such as gateways, hooks, SDKs, and APIs, rather than routing traffic through one dedicated gateway.
The category is sometimes called AI application security or AI TRiSM, and Noma positions itself among the startup vendors shaping it. Its Noma Labs research arm publishes vulnerability research, including the GitLost prompt-injection disclosure affecting GitHub Agentic Workflows, responsibly disclosed to GitHub. Its customers include Kantar, UiPath, Endor Labs, and Best Buy, including Fortune 500 environments.