PyxGrant / Compare

How PyxGrant compares, question by question.

Five vendors a security team is likely to shortlist for controlling what AI agents do, set against the questions we think matter. Their column comes from their own public pages. Ours comes from building the product and running it. Where they are ahead, the table says so.

Sources read 27 September 2026

pyxgrant bypassreal output
1. two routine calls, through the gateway
   → allowed and recorded
2. wipe_all, through the gateway
   → REFUSED by policy
3. wipe_all, straight at the server
   → performed; PyxGrant never saw it

Reconciliation: 2 allowed action(s)
                vs 3 server event(s)
  matched      2
  BYPASS       1

PASS: the out-of-band call was named:
      [wipe_all]

An inline gateway cannot see a call that never reaches it. Comparing its record with the provider's own log can.

The comparison

Nine questions, six products.

“Not found” means we did not find it on the vendor's public pages on the date above. It does not mean the product can't do it. If you know otherwise, tell us and we'll correct the row.

  • YesStated, and specific
  • PartlySome of it, or only in some setups
  • Not foundNot on their public pages
  • NoWe don't do this
Question PyxGrant Prisma AIRSPalo Alto Networks Zenity Noma Security Okta for AI Agents Lasso Security
Where we built for depth
Can it stop a coding agent's own shell and file actions before they run? Yes

Answers the Claude Code and Cursor PreToolUse hook with allow, ask, or deny. PostToolUse scans a document the agent just read for macros and injected text. By default a path outside the workspace is held for a person.

Partly

Agentic endpoint security arrived with the Koi acquisition in April 2026. Hook-level blocking is not described.

Yes

Native hooks for Claude Code, Cursor Enterprise, and GitHub Copilot. Policies ship in Detect mode; blocking is switched on per policy.

Yes

Lists agent hooks among its enforcement points, and discovers Claude Code, Cursor, and Codex on endpoints.

Partly

Tool calls that go through its MCP gateway. An agent's built-in shell and file tools are not described.

Partly

MCP traffic through its gateway. Built-in agent tools are not described.

Can the decision run with no vendor cloud in the path? Yes

One Go binary on your machine. The self-test and the full walkthrough run offline.

Partly

A software firewall that can run on your own KVM hosts, alongside a managed service.

Not found

Delivered as a platform; homegrown agents call its Evaluate API.

Not found Partly

MCP Bridge runs in your own infrastructure, offered through Okta Professional Services.

Partly

The MIT-licensed gateway is self-hosted. Its advanced guardrail calls Lasso's API.

Does it name actions that went around it? Yes

Compares what it allowed with the provider's own audit export and names each action it never saw. You supply the export.

Not found Not found Not found Not found Not found
Can an outsider check a decision record without access to your systems? Yes

Signed receipts, a standalone verifier, and verifiers in JavaScript and Python. Keep the signing key off the audit disk, or a local admin could re-sign a shortened log.

Not found Not found Not found Not found Not found
Can delegated authority only narrow, and does revoking it cut off every child? Yes

A child grant can't exceed its parent. Revoking walks the tree and signs a record of each grant it ends. Delegation across organizations verifies without a shared secret.

Not found Not found Not found Partly

Short-lived, task-scoped tokens that carry the delegation chain. Revoking at the gateway is planned for Q4 2026.

Not found
Does it check a payment against what a person approved? Yes

A swapped cart, a tainted cart, or an amount over the cap is refused. pay reverse closes only after a registered provider confirms the money is gone. The core binary ships no live Stripe or Adyen connector. It decides; your payment rail moves the money.

Not found Not found Not found Not found Not found
Where they are ahead
Does it find agents across SaaS and cloud platforms? Partly

Pulls or imports inventories from Microsoft Graph, Okta, and Amazon Bedrock, and scans laptops, including ungoverned local model ports. No Copilot Studio, Agentforce, or ServiceNow connector.

Yes

Agents, apps, and models across the environment.

Yes

SaaS, cloud agent platforms, and endpoints.

Yes

Cloud platforms, SaaS agent builders, endpoints, and code repositories.

Yes

A registry of agents with human owners, plus shadow agent discovery.

Partly

GenAI discovery and monitoring in the paid platform.

Does detection use trained models, not only patterns? No

Injection scoring is pattern- and structure-based, so novel phrasing can pass. An optional local model helps the data classifier.

Yes

Its Precision AI engine.

Yes

Deterministic rules plus LLM-based intent detection, run asynchronously.

Yes

Its own AI security models.

Not found

Identity and policy, not content detection.

Yes

Through Lasso's detection API.

Is there an established company behind it? Early

A young company with no public customers yet. Judge the build, and ask us about support terms.

Yes Yes Yes Yes Yes

Signed decision records are not rare in general. Open-source projects such as Signet and Agent Receipts, and Traefik Hub's Sovereign Trust Plane, also sign agent actions for offline checking. The row above covers only these five vendors.

Check our column

Every “Yes” in our column has a command behind it.

Output below comes from runs of the product, condensed to fit. The hook answers in JSON; it is shown here as a table.

pyxgrant hook claude-code
# Claude Code asks: may the agent run this?
Bash  rm -rf / --no-preserve-root
→ ask    workspace-escape: / resolves outside
         the workspace root

Read  ~/.ssh/id_rsa
→ ask    workspace-escape

Edit  ./a.txt   → allow
Bash  ls        → allow

Ordinary work goes straight through. A step outside the workspace waits for a person, and policy can make it a flat deny.

pyxgrant demo · grants
PASS attenuate a child grant (scope ⊆ parent)
PASS call runs while the grant is alive
PASS revoke walks the tree and kills the child
     (2 grants killed)
PASS the bound session is refused once the
     grant is dead
PASS GrantDead receipt verifies with the
     store key (offline)
PASS re-delegation cannot widen scope beyond
     the parent grant

Two of the 26 sections in the built-in walkthrough, which runs 90 checks against a hostile MCP server.

pyxgrant demo · payments
PASS the authorized cart is paid
     ($19.99 to shop.example)
PASS a swapped cart is refused
PASS a tainted cart cannot pay
PASS a payment over the per-payment cap
     is refused

It binds the payment to the cart a person approved. The model cannot talk its way past the ceiling.

What we ran on 25 September 2026

  • go test ./...132 packages pass. One failed on a Windows temp-folder cleanup and passed on three reruns.
  • pyxgrant demo90 of 90 checks pass.
  • pyxgrant selftest19 of 19 checks pass.
  • pyxgrant bypassThe out-of-band call is named.
Our limits

From pyxgrant boundaries, the product's own list.

The binary prints what each control does not do. A sample:

Kernel confinement is Linux only

Landlock is applied by pyxgrant sandbox contain, not by the gateway inline. It can restrict files on Linux 5.13 and later, and outbound TCP on 6.7 and later. UDP and DNS are not covered. Other systems report that nothing was enforced.

The egress cage is a proxy

A client that ignores the proxy settings or opens a raw socket is not caught by it. The Linux network rule above is what closes that gap.

Injection scoring is patterns

Novel phrasing that matches no pattern or structure passes the scorer. Pinning, taint, the blast-radius gate, and a human hold sit behind it.

A log sealed on its own disk

Any edit, reorder, or drop is detected. But if the signing key sits beside the log, a local admin can shorten and re-sign it. Keep the key elsewhere.

Streams that already left stay sent

A restricted or irreversible tool result on SSE is buffered until the verdict; a deny releases no bytes. Other streams that already left the process stay sent. For identities that must hard-block those, turn streaming off.

Post-quantum is opt-in

The default build signs with Ed25519. ML-DSA-65 (FIPS 204) is a separate module you build in.

Sources

Where each column came from.

Prisma AIRS

Prisma AIRS product pageKoi acquisition completed, 14 April 2026

Zenity

Coding and personal agentsHow Zenity implements the OWASP Top 10

Noma Security

AI runtime protectionAgentic risk map

Okta for AI Agents

Agent Gateway documentationOktane 2026 announcements

Lasso Security

Open-source MCP gatewaySecured gateway on AWS Marketplace

PyxGrant

The source, its test suite, and the commands on this page. Ask for a walkthrough and we'll run them in front of you.

Ask every vendor the same nine questions.

Then ask us to run the commands on this page against your own policy.