AIR

Operated by AIR Security · Agent Identity & Security Infrastructure
Documentation reviewed

Agent-fleet governance and "context firewall" that vets skills, MCP servers, and plugins before they reach an agent, and monitors agent actions at runtime.

Operator
AIR Security
Open source
Not indicated
Payment capability
Not indicated
Supports MCP
Not indicated
Supports agent-to-agent protocols
Not indicated
Enterprise-managed
Yes
Cryptographically signed
Not indicated
Independent audit on record
No public independent audit found
Operator confirmed this listing
Not indicated
Last reviewed
2026-09-14
Verification notes: AIR came out of stealth September 1, 2026 with $50M in seed funding (Sequoia Capital led an initial $10M round, Greenoaks Capital followed with $40M, joined by Swish Ventures and Netz), confirmed via the company's own stealth-exit post and corroborated independently by TechCrunch and SecurityWeek. The product is a four-part platform: AIR Control governs the agent fleet against policy on config, identity, and permissions; AIR Filter vets skills, MCP servers, and plugins before installation; AIR Defend monitors agent actions at runtime; AIR Marketplace supplies pre-vetted add-ons. This is a security layer that inspects other agents' MCP servers and skills rather than exposing its own MCP or A2A endpoints, so mcp and a2a are both false here -- don't confuse AIR's role vetting MCP servers with AIR itself being MCP/A2A-reachable. That role puts it in a different lane from Solo.io's agentregistry, which catalogs and versions MCP servers and agents rather than continuously vetting them for malicious behavior, and from identity-issuance platforms like Okta for AI Agents and Auth0's Auth for GenAI, which authenticate an agent's identity rather than inspect what reaches its context; Rubrik's Agent Identity is the closest existing listing in scope, since both grant or vet access per tool call rather than issuing standing credentials. No independently audited certification (SOC 2 or otherwise) for AIR Security itself was found in public sources as of this review; note that a similarly-named but unrelated company, Air (air.inc, a creative-collaboration platform), does publish SOC 2 claims -- that is a different company and is not being attributed here. AIR's own research team has published vulnerability disclosures against the broader MCP ecosystem (e.g. an August 27, 2026 post describing 155 hijackable MCP listings found via expired domains in a public marketplace), which is relevant context for readers evaluating agent supply-chain risk generally but is not itself a claim about AIR's own product security posture. See also the newly added CrowdStrike Agentic Identity Provider listing — a large incumbent's take on a related but distinct problem (issuing agent identity) rather than vetting agent add-ons.

Suggest a correction to this profile →