Skip to main content
Favicon of Lasso Security

Lasso Security

What is Lasso Security?

Lasso Security is an AI security platform for security teams that discovers AI agents, tools, MCP servers, and connected resources, then scores risk and enforces protections across the execution path. Its core features include AI Discovery & Inventory, AI Red Teaming, Intent Security, Runtime Enforcement, and Explainable Compliance Reporting. It supports enterprise AI stacks across Vertex AI, Microsoft Copilot, AWS Bedrock, and Salesforce Agentforce, and appears in customer stories from the US department of homeland security, Optibus, Guesty, and Kaltura.

Last verifiedHow we evaluate

Screenshot of Lasso Security website

At a glance

Best for
Lasso Security is best for security teams who need to govern agents, apps, and MCPs across the AI lifecycle.

What it actually does

Lasso is a runtime security and governance platform for LLM and agent traffic, not a single tool. The product spans five stages: discovery of AI agents and MCP connections across an org (an "AI-BOM"), posture assessment against frameworks like NIST and OWASP, automated red-teaming of agents with a vendor-claimed library of 3,000+ attack techniques, inline policy enforcement at the proxy/gateway layer, and detection/response for live attacks (prompt injection, tool poisoning, data exfiltration). It sits as a proxy in front of LLM calls and MCP servers rather than as a code-scanning or model-training tool.

The one thing you can try before buying

Lasso publishes an open-source MCP Gateway (github.com/lasso-security/mcp-gateway, MIT license, 385 stars, 38 forks) that any team can pip install mcp-gateway and run today, without a sales call. It's a genuine plugin-based proxy for MCP servers with three built-in guardrail plugins — basic secret-masking, Microsoft Presidio PII detection, and a lasso plugin that calls Lasso's paid API for the fuller feature set (prompt-injection detection, custom policy, harmful-content filtering). This is unusual for the category: most AI-security vendors sell nothing you can evaluate without a demo call. The free-tier plugins alone (secret masking + PII) are a real, no-cost starting point for MCP hygiene.

Independent research track record

Lasso's research team has produced findings that were picked up by outlets outside its own blog: an investigation that found over 1,500 exposed HuggingFace API tokens (including from Meta, Microsoft, Google, VMware), covered by The Decoder (Dec 2023); and earlier research on "AI package hallucination" — LLMs recommending non-existent open-source packages that attackers could register and weaponize, including a documented case where a hallucinated PyPI package the researcher registered as a honeypot got 30,000+ downloads in three months. Both are genuine, methodologically described findings, not just marketing claims.

Company stage and what that means for a buyer

Lasso was founded in 2023 by CEO Elad Schulman (previously co-founded Segasec, a phishing-protection company acquired by Mimecast for $50M in 2020) and CTO Lior Ziv. Its only publicly disclosed funding is a $6M seed round (Nov 2023) led by Entrée Capital with participation from Samsung Next — SiliconAngle put total outside funding at "just over $7.5M" at that time. No Series A or later round is publicly disclosed as of this check. StartupHub.ai estimates ~50 employees (a third-party estimate, not vendor-confirmed). The company lists enterprise logos including the U.S. Department of Homeland Security, Optibus, Fiverr, and eToro on its site, and says it was named a Gartner Cool Vendor in AI Security for 2024 — a claim repeated in multiple PR write-ups (GlobalSecurityMag, Swish Data) but not independently confirmed against a Gartner primary source in this check.

Pricing and what the vendor discloses

No public pricing anywhere on the site — the entire commercial motion is "Book a Demo." There is no self-serve tier, published "from $X" figure, or free trial mentioned outside the open-source MCP Gateway. A real Information Security Policy PDF is published (last approved by the company's COO, references SOC 2/ISO 27001/PCI DSS/GDPR as compliance targets the company says it works toward) — but this is a policy statement, not a certificate; no SOC 2 report, trust portal, or third-party audit attestation is linked from the site.

Open-source repo activity, plainly

The MCP Gateway repo was created April 2025 and last had a commit pushed January 22, 2026 — over seven months before this check, despite the repo remaining open and actively discussed in third-party MCP-gateway comparison posts (MintMCP, AimMultiple, Zuplo). The matching PyPI package (mcp-gateway) last released v1.2.1 the same day. 12 open issues, no recent releases since. This isn't abandoned, but it's not under active weekly development either.

Frequently asked questions

What is Lasso Security?

Lasso Security is an AI security platform for security teams that discovers AI agents, tools, MCP servers, and connected resources, then scores risk and enforces protections across the execution path. Its core features include AI Discovery & Inventory, AI Red Teaming, Intent Security, Runtime Enforcement, and Explainable Compliance Reporting. It supports enterprise AI stacks across Vertex AI, Microsoft Copilot, AWS Bedrock, and Salesforce Agentforce, and appears in customer stories from the US department of homeland security, Optibus, Guesty, and Kaltura.

What is Lasso Security used for? Who is it for?

Lasso Security is used for AI Security Platform, Intent Security, and AI Discovery & Inventory. It's built for Security operations teams, AI platform owners, and AppSec teams.

Does Lasso Security have an API and what does it integrate with?

Lasso Security doesn't publish a public API. It integrates with CI, AI Gateway, Vertex AI, Microsoft Copilot, AWS Bedrock, and 6 more.

Filed under:Security AI Agents

Share:

Sponsored
Favicon

 

  
 

Explore other Security AI Agents

Favicon

 

  
  
Favicon

 

  
  
Favicon