Who else
Where we are better, and where we are not.
We had this researched adversarially rather than written by us. Some of what came back was uncomfortable, and it is on this page, because a comparison where the vendor wins every row persuades nobody.
What you can buy today, fairly stated
This is a real market with serious companies in it.
Gates genuinely in the path
Amazon's agent policy engine intercepts every tool call at the gateway and has since March; Google's followed in April. These are not dashboards. They enforce, and they work.
Identity for agents
Microsoft, Okta and Auth0 are giving agents their own credentials and audit identities. Workday and ServiceNow have built real non-human security principals inside their platforms.
Governance platforms
Risk registers, model inventories, framework mapping. If the job is demonstrating diligence to a regulator, that is the right shelf and it is not ours.
Guardrails and evaluation
Classifiers, red-team suites, tracing. Cheap, fast, and they catch a great deal.
Inline blocking is no longer a differentiator. Around thirty products do it and the industry rates it the minimum baseline. If a vendor's headline is that they can stop an action, they are describing table stakes.
Four things we do not claim
Said first, because each one would otherwise be found.
That we invented formal methods for policy
Amazon's policy language has a verified evaluator with mechanised proofs and predates us. Anyone telling you formal methods are novel has not looked.
That a single console is rare
It is a recognised market category with Microsoft, Google, IBM and ServiceNow in it, and one vendor's page is literally titled “One Control Plane.”
That writing a rule in English is new
Rules authored in plain language have been commercially available since 2008. The novelty is what happens to the rule afterwards.
That stopping an action is a differentiator
Around thirty products enforce inline. The industry rates it the minimum baseline, and they are right.
The exception worth naming
Amazon has done more real formal-methods work than anyone in this industry.
Their policy language has a machine-verified evaluator with mechanised proofs. Their automated reasoning can decide whether one policy is more permissive than another. Anyone who calls formal methods exotic has not been paying attention, and we would rather say that than have you discover it.
Two things are true about it. What it proves is a property of an access policy — may this principal reach this resource. It does not prove a rule about the world: whether a disclosure is within minimum necessary, whether something counts as adverse action under Regulation B, whether a payee has been screened. And there is no proof that the shipped engine matches the verified model — that link is covered by randomised differential testing.
Design verified. Implementation tested against the verified design. That gap is the one our method closes.
Who covers which part
Read our column as honestly as the others.
Three of the six rows say not our job, because they are not. Watch the fourth row.
| The life of one AI action | HyperscalersMicrosoft, AWS | Governance platformsCredo AI, Holistic AI | Guardrails & evalsfilters, red teams | SMARTHAUSthe control plane |
|---|---|---|---|---|
| Build & deploymodels, agents, pipelines | Native to the cloud | Inventory and ownership | — | Not our job |
| Assess & documentrisk, frameworks, audit file | Framework mapping | This is their core | — | Not our job |
| Watch the textfilters, classifiers, evals | Content filters | Policy documentation | This is their core | Not our job |
| Decide the actionadmit, refuse, or ask a person | Access policy, verified engine — within one cloud | Describes who should decide; does not decide | A model judging a model | A proved domain rule decides, or a named person does |
| Release the effectmoney, data, code, mail | Outside the policy boundary | — | Advisory only | Refusal means it never executes |
| Leave the evidencewhat a board or regulator asks for | Cloud audit log | The audit file | Traces | Hash-chained receipt: rule, proof, person, result |
What is genuinely ours
Deliberately narrow. Every clause survived a check.
No vendor derives runtime enforcement from machine-checked proofs and ships that enforcement inside a component the customer redistributes — in the AI and agent context. And nobody chains or signs an agent-decision record, or binds a receipt to a proof result.
Every clause in that sentence is there because it survived a check against Amazon, against the formal-methods industry and against the thirty-odd vendors in the agent-security market. What is left after those checks is the part that is genuinely ours.
One more, because it is the most telling. The research team that pioneered commercial formal verification of neural networks founded a company to secure AI agents in 2024. They shipped a policy language rather than a proof toolchain, and sold fourteen months later. If this were easy, they would have done it.
Where the clouds are genuinely better
Four places we would send you to them.
Populations we cannot reach
Contractors, unmanaged devices, personal machines, acquired estates, partner systems. Governing by credential reaches machines nobody can install software on. There is no local answer to that.
Server-side and scheduled agents
The agent that moves money at three in the morning is not on a laptop. That is their home ground, and it carries the larger blast radius.
Reach and reliability
A complete gateway log is a stronger audit position than best-effort telemetry from machines that may be offline, and their availability record is excellent.
Credential custody
Token vaults, short-lived identity-governed credentials and central revocation are genuinely better than credentials sitting on a laptop.
And a fifth, which is ours to solve rather than theirs: a control living inside the agent's own write scope is not a control. That has to be answered with a demonstrable privilege boundary, not a policy statement.
And one asymmetry that is structural
To decide on an action, a gate must read the action.
That is arithmetic, not criticism — a cloud gate sees the recipient, the amount, the file, the rows, because it cannot decide without them. Customer-managed keys protect data at rest; this is data in use, and a local decision point is the only architecture that removes the exposure rather than encrypting it.
The other half is coverage. A gateway governs the tools routed through it. A coding agent writing files, running shell commands and talking to a local tool server is invisible to it — and a gateway's log looks identical to an idle day when an agent goes around it.
We will not claim we cannot be bypassed. Nobody can claim that honestly. What we claim is narrower: we sit where the decision is made, rather than where one route happens to terminate.
Start at one seam
Judge it against the alternative you are actually considering.
Bring the vendor you are already evaluating. Twenty minutes with your own coding agent will tell you more about the difference than any comparison table, including this one.