Noma Security
Noma Security provides a unified AI security platform that discovers, governs, and protects AI models, agents, and MCP servers across enterprise environments. It serves Fortune 500 organizations across financial services, life sciences, retail, and technology sectors.
- Company typePrivate
- Founded2023
- HeadquartersHerzliya, Israel
- Headcount101–250
- GTM typeB2B
- OfferingSoftware
What Noma Security does
Noma Security is an Israeli-founded (2023) cybersecurity company that has built a unified platform for discovering, governing, and protecting AI applications, agents, large language models, RAG systems, and MCP servers across enterprise environments. Its platform integrates four core modules — AI Security Posture Management (AISPM) for continuous discovery and contextual risk assessment, Agentic Access Control for policy-based runtime enforcement, Red Teaming for offensive AI vulnerability testing, and Runtime Protection for real-time monitoring of every prompt, response, and tool call. The company also operates the RiskRubric.ai standardized AI model risk assessment leaderboard, the Agentic Risk Map visualization tool, and the No Excessive CAP governance framework, with research outputs (GitLost, GrafanaGhost, ForcedLeak vulnerability disclosures) used to establish category authority.
Noma Security operates an enterprise SaaS subscription model with quote-based, annually-billed contracts targeting Fortune 500 organizations across financial services, life sciences and healthcare, retail, and big technology. Distribution combines direct enterprise field sales under CRO Ralph Pisani with a channel-first GTM led by VP of Global Channel Ted Plumis, complemented by marketplace listings (AWS Security Hub Extended plan) and ecosystem co-sell through strategic partnerships with Databricks, Vercel, and Anthropic. The company has raised $132 million across multiple rounds, employs 11-50 staff (with 40+ open roles), and reports 1,300% year-over-year ARR growth since emerging from stealth in November 2024. Named customers include BNP Paribas, Best Buy, Nielsen, UiPath, Endor Labs, and McAfee.
Noma Security firmographics
Firmographics- Name
- Noma Security
- Legal name
- Noma Security Inc.
- Website
- https://noma.security
- Company type
- Private
- Founded year
- 2023
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- Noma Security provides a unified AI security platform that discovers, governs, and protects AI models, agents, and MCP servers across enterprise environments. It serves Fortune 500 organizations across financial services, life sciences, retail, and technology sectors.
- Ownership category
- akta.pro rank
Noma Security industry classification
Industry- Product category
- AI Security
- NAICS
- Security Systems Services (except Locksmiths) (561621), Security Systems Services (56162)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII) (HDAEANAG)
- akta.pro secondary industries
- Identity Threat Detection & Response (ITDR) (HDAEAJAH), Identity & Access Security Services (IAM, PAM, Zero Trust) (BPAKAHAI), Secure Model Deployment & Runtime Protection (sandboxing, isolation) (HDAAAKAH), Attack Surface Management (EASM/CAASM) (HDADAHAC)
Keywords
Where Noma Security is headquartered
LocationHeadquarters
- HQ city
- Herzliya
- HQ country
- Israel
- HQ region
- Middle East
Offices4 records
Markets served
Noma Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Enterprise SaaS Platform Subscription: SaaS-based enterprise platform providing comprehensive AI security and governance capabilities including AI Security Posture Management, Runtime Protection, Red Teaming, and Agent Access Control. Platform is sold to enterprise organizations with per-seat or enterprise-wide licensing models.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise platform pricing - not publicly disclosed |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels10 records
Noma Security product offering
Product offeringCore offering
Noma Security provides a unified AI security and governance platform that discovers, secures, and protects AI models, AI agents, MCP servers, and data sources across enterprise environments. The platform combines AI Security Posture Management (AISPM), Agentic Access Control, automated Red Teaming, and Runtime Protection in a single integrated SaaS product. It serves Fortune 500 customers across financial services, life sciences, retail, and technology sectors.
Product overview
Noma Security is the unified AI security and governance platform for enterprises, combining discovery, security, and protection capabilities across the full AI lifecycle. The core Noma Platform integrates four key modules: AI Security Posture Management (AISPM) for continuous discovery and risk assessment, Agentic Access Control for policy-based approval and runtime enforcement, Red Teaming for offensive security testing, and Runtime Protection for real-time threat monitoring. Built atop this platform, the company offers solution-specific products including AI Agent Security, AI Application Security, AI Governance & Compliance, and MCP Server Security. Named products include the Agentic Risk Map (visualization tool for agent risk exposure) and RiskRubric.ai (standardized AI model risk assessment leaderboard). The company also provides the No Excessive CAP governance framework. Integrations extend the platform to AWS Security Hub, Databricks Unity AI Gateway, Vercel Agent Stack, and major agent platforms (Salesforce AgentForce, Microsoft Copilot Studio, ServiceNow, LangChain, CrewAI, GitHub Copilot, Anthropic Claude).
Differentiator
Problem solved
Functional benefit
Products and services
- Noma Platform The unified AI security and governance platform that discovers, secures, and protects AI and agents across the enterprise. Combines AI Security Posture Management, Agentic Access Control, Red Teaming, and Runtime Protection in a single integrated platform for enterprise customers.
- AI Agent Security Purpose-built solution for securing autonomous AI agents, streamlining incident management with automated workflows. Covers no-code agents (ServiceNow, Salesforce AgentForce, Microsoft Copilot Studio), application agents (LangChain, CrewAI), and coding agents (GitHub Copilot, Claude Code, Cursor).
- AI Application Security
Quantifiable outcome
- 1,300% year-over-year ARR growth
- +4 more outcomes
Companies that use Noma Security
Customer profileNamed customers7 records
Segments5 records
Ideal customer profiles2 records
Noma Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration18 records
AI capability9 records
Feature7 records
Noma Security partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered core, minor and flagship.
- VercelcoreNative integration with Vercel Services bringing industry-leading AI Detection and Response (AIDR) to the Vercel Agent Stack. Noma bridges the security gap in Vercel's AI Gateway by overlaying enterprise AI Detection and Response onto Vercel Services, enabling true third-party guardrails, context-aware tool protection, and advanced prompt injection defense.
- Unity AI Gateway Ecosystem PartnerscoreLaunch partner in Databricks Unity AI Gateway partner ecosystem alongside 13 other companies including CrowdStrike, Cyera, HiddenLayer, Netskope, Palo Alto Networks, Zscaler, Okta, Ping Identity, SailPoint, and Saviynt. Extends governance to runtime interactions between models, agents, MCP servers, skills, and AI tools.
- CalcalistminorNamed among the 50 most promising Israeli startups in Calcalist's 2026 ranking, identified across sectors including AI infrastructure, cybersecurity, quantum computing, fintech, and defense technology.
- RSA ConferenceminorBooth 1261 at RSAC 2026 with lightning talks, fireside chats with industry leaders, and product demonstrations. Sasi Levi presented on 'Trust no input: Securing agentic AI's supply chain from being poisoned' and Diana Kelley on 'Model collapse and idiocracy: Ensuring the future of AI stays intelligent.'
- Forbes IsraelminorFeatured in Forbes Israel's 2025 'Next Billion Dollar Startups' list recognizing 10 promising startups across cybersecurity, AI, and defense technology sectors.
- DatabricksflagshipStrategic partnership and investment from Databricks to enhance AI security and governance for enterprise AI environments. Integration addresses AI security challenges from development to deployment, supporting compliance with emerging regulations like the EU AI Act. At Data + AI Summit 2026, Databricks announced Unity AI Gateway partner ecosystem with Noma as a launch partner.
Scale indicators5 records
Recent moves6 records
Expansion highlights6 records
Noma Security competitors and assessment
Company assessmentDirect peers
- Protect AI: Protect AI built AI/ML model security, red-teaming, and supply-chain scanning for LLMs and agents before being acquired by Cisco in 2024. It is the closest direct competitor to Noma's AISPM and Red Teaming modules, with overlapping F500 financial-services and life-sciences customers.
- HiddenLayer: HiddenLayer provides AI threat detection, model scanning, and red-teaming as a SaaS platform for enterprise AI/ML workloads, and is a fellow launch partner in the Databricks Unity AI Gateway ecosystem alongside Noma. It directly overlaps with Noma's runtime protection, model/agent risk scoring, and OWASP coverage positioning.
- Robust Intelligence: Robust Intelligence offered AI firewall and pre-deployment model validation before being acquired by Cisco in 2024. Its product scope on model and AI-application protection is essentially coextensive with Noma's AISPM and Runtime Protection modules.
- Lakera: Lakera's Gandalf platform secures LLM applications against prompt injection, jailbreaks, and data leakage with real-time guardrails. It is a direct competitor in runtime protection of AI agents and LLM-backed applications, and shares Red Teaming and OWASP-aligned threat research adjacency with Noma.
Emerging players
- Pillar Security: Pillar Security is an emerging startup focused on AI application security and runtime protection for AI agents and copilots. It overlaps with Noma's Agentic Access Control and Runtime Protection modules but has narrower agent-discovery and red-teaming capability today.
- Astrix Security: Astrix Security focuses on securing non-human identities (NHIs) and the agent/service-account connections powering AI workloads. It directly competes for budget with Noma's Agentic Access Control module, particularly around MCP server and tool credentials.
Broad incumbents
- Palo Alto Networks: Palo Alto Networks offers Prisma AIRS and unit 42 AI red-teaming as part of its broader security platform, and is a fellow launch partner in the Databricks Unity AI Gateway ecosystem. It competes indirectly by bundling AI security into existing CNAPP/SIEM spend at F500 customers.
- CrowdStrike: CrowdStrike's Falcon AI Detection and Response and Charlotte AI platform are extending into agent and LLM workload protection, and CrowdStrike is also a Databricks Unity AI Gateway launch partner. It is a broad incumbent competitor for enterprise CISOs standardizing on a single vendor.
- Microsoft: Microsoft Defender for AI and Azure AI Content Safety provide prompt-injection guardrails, model monitoring, and policy controls inside the Microsoft ecosystem, where many Noma F500 customers run Azure OpenAI and Copilot. It is a broad incumbent competitor shaped by platform-level bundling.
- Wiz: Wiz has grown from CNAPP into AI workload security with its Wiz AI Security Posture Management offering, and Noma's VP of Customer Success joined from Wiz. It is a broad-incumbent competitor targeting the same Fortune 500 cloud security and emerging AI security budgets.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks5 records
Key highlights7 records
Customer concentration
Noma Security social profiles
Digital presenceNoma Security compliance and trust
Trust signalCompliance2 records
Noma Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Noma Security leadership team
Management profileNumber of profiles
Profiles11 records
Noma Security funding detail
Funding detailFunding overview
Funding rounds4 records
Investors6 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Noma Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Noma Security
What does Noma Security do?
Noma Security provides a unified AI security and governance platform that discovers, secures, and protects AI models, AI agents, MCP servers, and data sources across enterprise environments. The platform combines AI Security Posture Management (AISPM), Agentic Access Control, automated Red Teaming, and Runtime Protection in a single integrated SaaS product. It serves Fortune 500 customers across financial services, life sciences, retail, and technology sectors.
Is Noma Security a public or private company?
Noma Security is a private company. It is classified as venture growth investor backed and is currently operating.
When was Noma Security founded?
Noma Security was founded in 2023. It employs 101 to 250 people.
Where is Noma Security based?
Noma Security is headquartered in Herzliya, Israel, in the Middle East region.
How does Noma Security make money?
One revenue line is on record: enterprise SaaS Platform Subscription.
Who are Noma Security's main competitors?
Direct peers on record are Protect AI, HiddenLayer, Robust Intelligence and Lakera. Emerging players are Pillar Security and Astrix Security. Broad incumbents are Palo Alto Networks, CrowdStrike, Microsoft and Wiz.
Does Noma Security have an API?
No public API is recorded for Noma Security.
What industry is Noma Security in?
Noma Security's product category is AI Security. Its primary akta.pro industry code is HDAEANAG, Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII), with a secondary code of HDAEAJAH, Identity Threat Detection & Response (ITDR). Its NAICS code is 561621 and its SIC code is 7370.