Akto
Akto is a San Francisco-based cybersecurity vendor founded in 2022 that provides API security and agentic AI/MCP security platforms for Fortune 500 security teams, featuring Akto Atlas for employee endpoints and Akto Argus for homegrown AI applications.
- Company typePrivate
- Founded2022
- HeadquartersSan Francisco, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Akto does
Akto is a San Francisco-headquartered cybersecurity company founded in 2022 (with an engineering office in Bengaluru, India) that sells an AI Agent Security and API Security platform targeting Fortune 500 security teams. The company was originally positioned as a plug-and-play API security platform and raised a $4.5 million seed round led by Accel India in November 2022; since 2024 it has repositioned around agentic AI and MCP security, with a current product surface that includes Akto Atlas (security and guardrails for LLMs, AI agents, and MCP tools used on employee endpoints), Akto Argus (security and runtime guardrails for homegrown AI applications and cloud-deployed agents across Bedrock, Vertex AI, Azure AI Foundry, Databricks, Snowflake, Salesforce, IBM Watsonx, and Hugging Face), the Akto API Security Platform (API discovery, posture management, threat detection, 1000+ pre-built API security tests), MCP Security (MCP Attack Matrix covering tool poisoning, line jumping, tool shadowing, prompt injection via tool output, broken authorization, and rug pull attacks), and AktoGPT for generative-AI test authoring.
The technical architecture centers on a transparent mitmproxy-based Sidecar Egress Proxy that intercepts outbound AI API calls (OpenAI, Anthropic, Amazon Bedrock) with zero code changes to agent code, an agent-proxy for MCP servers that inspects every request and response inline, an Agent Guard decision engine returning Allow/Modify/Blocked actions, GitOps policy sync from repositories, and an Agent Context Graph that maps agent-tool-resource relationships. Akto maintains 100+ native integrations across AI agent frameworks (LangChain, Portkey, TrueFoundry, Arcade.dev, LiteLLM, Microsoft Copilot Studio), LLM providers, MDM/EDR systems (SentinelOne, Intune, Jamf, Kandji, Automox, NinjaOne), and traditional AppSec tooling (Kong, Istio, Envoy, NGINX, Cloudflare, Apigee, Mulesoft, Burp Suite, Postman), and operates open-source components (akto-api-security/akto, akto-api-security/akto-ai-egress, Akto Burp Extension, Akto CLI).
Revenue is generated via enterprise SaaS subscriptions (Akto Cloud) plus a newly introduced usage-based pricing model, with a freemium entry point via Akto Open Source on GitHub and a free trial landing page. Go-to-market is hybrid: enterprise demo-driven field sales targeting Fortune 500 security teams, product-led growth through 60-second self-hosted deploy, AWS Marketplace availability, a developer/community motion anchored on Aktonomy'26 and OWASP partnerships, and heavy conference presence at RSA, Black Hat USA, DEF CON, OWASP Global AppSec, and Gartner Security & Risk Management Summit. Vertical packages exist for Financial Services, SaaS, Healthcare, Public Sector, and E-Commerce, and Akto holds GDPR, ISO, SOC2, and HIPAA compliance badges and Trust Center disclosures.
Akto firmographics
Firmographics- Name
- Akto
- Legal name
- Akto
- Website
- https://akto.io
- Company type
- Private
- Founded year
- 2022
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Akto is a San Francisco-based cybersecurity vendor founded in 2022 that provides API security and agentic AI/MCP security platforms for Fortune 500 security teams, featuring Akto Atlas for employee endpoints and Akto Argus for homegrown AI applications.
- Ownership category
- akta.pro rank
Akto industry classification
Industry- Product category
- API and AI Agent Security
- NAICS
- Computer Systems Design Services (541512), Custom Computer Programming Services (541511), Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- API Security & Governance (Policy, Threat Protection) (HDAEAIAI)
- akta.pro secondary industries
- Model Serving, Inference & Deployment Platforms (APIs, Edge/On-Prem) (HDAEANAC), API Management Platforms (API Gateways, Developer Portals) (HDAEAIAA), Enterprise Risk Management (ERM) (HDADAIAC)
Keywords
Where Akto is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
Akto business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations
Revenue model
- Subscription (Enterprise SaaS): Enterprise SaaS subscriptions via demo-driven sales motion targeting Fortune 500 security teams. Has pricing tiers indicated by /pricing landing page, self-hosted option, and Akto Cloud (app.akto.io).
- Usage-based pricing: Blog references "Akto introduces new usage-based flexible pricing model", indicating a usage-based revenue component alongside subscriptions.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Pay-as-you-go | Free trial / Free-tier entry point |
| Usage-based | Pay-as-you-go | Usage-based paid tier |
| Subscription | Annual | Enterprise SaaS (Akto Cloud) |
Go-to-market motion5 records
Distribution channels5 records
Marketing channels8 records
Akto product offering
Product offeringCore offering
Akto provides an enterprise security platform that discovers, tests, and protects APIs, MCP servers, and AI agents against agentic and traditional API threats. The platform combines API discovery, automated red-teaming, runtime guardrails, and posture management, delivered through two flagship products — Akto Atlas for AI usage on employee endpoints and Akto Argus for homegrown AI applications — and made available as Akto Cloud, Akto Self-hosted, or Akto Open Source deployments.
Product overview
Akto offers a unified platform-plus-modules architecture for AI Agent Security and API Security. The core platform centers on two flagship products: Akto Atlas, which secures AI usage across employees and devices, and Akto Argus, which secures homegrown AI applications and cloud-deployed agents. Both products run on top of Akto's API Security Platform (also deployable as Akto Open Source, Akto Cloud, or Akto Self-hosted), which provides foundational API discovery, testing, posture management, and threat detection. Specialized modules extend the platform with MCP Security, AktoGPT (generative AI testing), the Sidecar Egress Proxy for transparent agent guardrails, Agent Context Graph, NHI Governance, Shadow AI Discovery, AgentForce integration for Salesforce, Agent Probe for automated red teaming, and Akto AgentGuard. DAST and developer tools (CLI, Burp Extension, Code for source-code API discovery) round out the offering. Together, these products allow Akto to discover every AI agent and MCP tool, run continuous red teaming, and enforce guardrails at scale for Fortune 500 security teams.
Differentiator
Problem solved
Functional benefit
Brands
- Akto Atlas: Agentic AI Security for Employee Endpoints — secures AI usage across employees and devices, including AI agent activity discovery, guardrails, and skill governance.
- Akto Argus
- AktoGPT
Products and services
- Akto Atlas AI Agent Security product for employee endpoints that delivers visibility and guardrails for LLMs, AI agents, and MCP tools used across employee devices, with personal account detection and skill governance capabilities. Intended for enterprise security teams responsible for safe AI usage at the individual user level.
- Akto Argus Agentic AI Security product for homegrown AI applications and cloud-deployed agents that traces AI agent traffic end-to-end, syncs policies from Git, connects to Bedrock, Vertex AI, Databricks, Azure AI Foundry and other platforms, and enforces runtime guardrails via the Sidecar Egress Proxy. Built for enterprise engineering and security teams building or deploying internal AI agents.
- Akto API Security Platform Foundational API security platform providing API discovery, API security posture, sensitive data exposure detection, API security testing, threat detection, and authentication and authorization testing in a plug-and-play deployment model.
- Agentic AI Security Platform Overarching Agentic AI Security Platform that maps every AI agent and MCP tool, provides visibility, runs continuous red-teaming, and enforces guardrails at scale across enterprise infrastructure. Combines Agentic AI Discovery, Automated Agentic Red Teaming, Agentic Security Posture Management, MCP and AI Agent Guardrails, and Agentic Runtime Protection.
- MCP Security Security solution purpose-built for Model Context Protocol (MCP) servers and tool-using agents. Addresses MCP attack matrix threats including tool poisoning, line jumping, tool shadowing, prompt injection via tool output, broken authorization, and rug pull attacks through runtime inspection and policy enforcement.
- AktoGPT Generative AI-powered testing assistant for API security that generates test content, assists with test authoring, and accelerates API vulnerability detection through natural-language interaction. Part of Akto's GenAI Security Testing Solution.
- Akto Open Source Free, open-source version of the Akto platform available on GitHub, providing community-driven API security testing and discovery capabilities for developers and security teams.
Quantifiable outcome
- 100x better Agentic actions visibility Coverage vs. alternatives
- +3 more outcomes
Companies that use Akto
Customer profileNamed customers2 records
Segments7 records
Ideal customer profiles4 records
Akto technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration62 records
AI capability12 records
Feature11 records
Akto partnerships and signals
Strategic signalPartnerships
17 partnerships are on record, tiered core.
- LangChaincoreAkto announced a technology partnership and native integration with LangChain to enhance AI agent security. The integration focuses on real-time defense against risks such as prompt injection and data leakage across various stages of AI agent deployment. Akto Argus also lists LangChain as a supported AI Agent Connector.
- PortkeycoreAkto announced a technology partnership and native integration with Portkey to enhance AI agent security. Akto Argus lists Portkey as a supported AI Agent Connector for securing AI gateways and agent routing implemented using Portkey.
- TrueFoundrycoreAkto announced a technology partnership and native integration with TrueFoundry to enhance AI agent security. Akto Argus lists TrueFoundry as a supported AI Agent Connector for securing AI agents deployed on the TrueFoundry ML platform.
- Arcade.devcoreAkto announced a technology partnership and native integration with Arcade.dev to enhance AI agent security and runtime governance. The partnership secures AI agents in production by combining Arcade.dev's runtime infrastructure with permission management and Akto's monitoring and threat detection tools for agent actions and tool interactions. Akto Argus lists Arcade as a supported AI Agent Connector.
- LiteLLMcoreAkto announced a technology partnership and native integration with LiteLLM to enhance AI agent security. Akto Argus lists LiteLLM as a supported AI Agent Connector for monitoring and securing AI agents using LiteLLM for multi-model routing and management.
- SentinelOnecoreAkto partnered with SentinelOne to secure AI agents at endpoints (referenced in Akto blog: akto-partners-with-sentinelone-to-secure-ai-agents-at-endpoints). Integration enables Akto's AI agent security at endpoint layer in conjunction with SentinelOne's endpoint security platform.
- Microsoft Copilot StudiocoreAkto integrates with Microsoft Copilot Studio in three modes: Async Mode (polls Dataverse transcripts for detection), Block Mode (inline request/response guardrails added inside the agent topics), and Proxy MCP Server via Akto's agent-proxy. Three modes can run side-by-side.
- AWS BedrockcoreAkto Argus supports AWS Bedrock (and AWS Bedrock AgentCore) as AI Agent Connectors to secure and monitor AI agents built using AWS Bedrock managed foundation models. Bedrock is also supported by the Sidecar Egress Proxy for outbound LLM call guardrails.
- Azure AI FoundrycoreAkto Argus supports Azure AI Foundry as an AI Agent Connector to protect AI agents developed and deployed via Azure AI Foundry.
- Google Vertex AIcoreAkto Argus supports Google Vertex AI as an AI Agent Connector to protect AI agents deployed using Google Vertex AI.
- IBM WatsonxcoreAkto Argus supports IBM Watsonx to import and monitor Watsonx AI agents seamlessly.
- DatabrickscoreAkto Argus supports Databricks as an AI Agent Connector to monitor and secure AI agents running on Databricks platforms.
- SnowflakecoreAkto Argus supports Snowflake as an AI Agent Connector with both regular and Block Mode options to secure AI agents and data-driven workflows built within Snowflake, including distributed tracing via Snowflake Agent Tracing.
- SalesforcecoreAkto Argus supports Salesforce as an AI Agent Connector to protect AI agents built on or integrated with Salesforce platforms (referenced in akto-agentforce-secure-salesforce-agents-runtime blog).
- OWASPcoreAkto actively partners with OWASP across multiple chapters (Bay Area, Orange County, LA, SF, Singapore). Co-presents hands-on workshops, meetups, and the LLM Security Roundtable at OWASP Global AppSec. Akto is recognized in the OWASP Gen AI Security Landscape.
- Cloud Security AlliancecoreAkto joined Cloud Security Alliance as an AI Corporate Member (referenced in akto-joins-cloud-security-alliance-ai-corporate-member blog).
- Salesforce (Agentforce)coreAkto Agentforce secures Salesforce agents at runtime (referenced in akto-agentforce-secure-salesforce-agents-runtime blog).
Scale indicators3 records
Recent moves6 records
Expansion highlights5 records
Akto competitors and assessment
Company assessmentDirect peers
- 42Crunch: API security platform focused on API contract security (OpenAPI validation), testing, and runtime protection. Competes with Akto's API security testing and posture management capabilities for enterprise customers.
- Salt Security: Direct API security competitor offering API discovery, runtime protection, and posture management. Acquired by Palo Alto Networks in 2024, validating the API security category and intensifying platform competition for Akto. Listed alongside Akto in gbhackers Top 10 API Security Providers 2026.
- Traceable AI: API security platform with strong AI/ML-driven threat detection focus. Competes head-to-head with Akto in API discovery, testing, and runtime protection for enterprise AppSec teams. Listed alongside Akto in Top 10 API Security Providers 2026.
- Noname Security: API security platform offering API posture management and runtime protection. Acquired by Akamai in 2023, demonstrating the consolidation pattern in API security that creates both opportunity and competitive pressure for independent players like Akto.
- Cequence Security: API security and bot management platform targeting enterprise customers. Competes with Akto on API discovery, fraud prevention, and runtime protection. Listed alongside Akto in Top 10 API Security Providers 2026.
- Wallarm: API security and WAAP platform with API discovery, testing, and threat protection. Overlaps directly with Akto's core API security platform offering for enterprise DevSecOps teams. Listed alongside Akto in Top 10 API Security Providers 2026.
- APIsec: API security testing platform specializing in automated API vulnerability scanning. Direct competitor in API security testing category, listed alongside Akto in Top 10 API Security Providers 2026.
Emerging players
- Astrix Security: Emerging player focused on non-human identity (NHI) and AI agent security. Directly comparable to Akto's emerging NHI Governance for AI Agents and agentic discovery capabilities, both targeting the agent identity attack surface.
Broad incumbents
- Palo Alto Networks (Prisma Cloud / API Security): Broad cybersecurity incumbent that acquired Salt Security (2024) to add API security to its Prisma Cloud platform. Represents platform competition that could bundle API/agent security at scale, pressuring independent players like Akto.
- Akamai (App & API Protector): Broad incumbent in CDN and edge security that acquired Noname Security (2023) for API protection. Competes with Akto in API security for enterprise customers via bundled platform offerings, listed alongside Akto in Top 10 API Security Providers 2026.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Akto social profiles
Digital presenceAkto compliance and trust
Trust signalCompliance4 records
Akto financial estimates
Financial estimateRevenue estimate
Valuation estimate
Akto leadership team
Management profileNumber of profiles
Akto funding detail
Funding detailFunding overview
Funding rounds2 records
Investors3 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Akto M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Akto
What does Akto do?
Akto provides an enterprise security platform that discovers, tests, and protects APIs, MCP servers, and AI agents against agentic and traditional API threats. The platform combines API discovery, automated red-teaming, runtime guardrails, and posture management, delivered through two flagship products — Akto Atlas for AI usage on employee endpoints and Akto Argus for homegrown AI applications — and made available as Akto Cloud, Akto Self-hosted, or Akto Open Source deployments.
Is Akto a public or private company?
Akto is a private company. It is classified as venture growth investor backed and is currently operating.
When was Akto founded?
Akto was founded in 2022. It employs 11 to 50 people.
Where is Akto based?
Akto is headquartered in San Francisco, United States, in the North America region.
How does Akto make money?
Two revenue lines are on record. Subscription (Enterprise SaaS) is the primary driver. The others are usage-based pricing.
Who are Akto's main competitors?
Direct peers on record are 42Crunch, Salt Security, Traceable AI, Noname Security, Cequence Security, Wallarm and APIsec. Astrix Security is listed as an emerging player. Broad incumbents are Palo Alto Networks (Prisma Cloud / API Security) and Akamai (App & API Protector).
Does Akto have an API?
Yes. Akto offers an API reference (https://ai-security-docs.akto.io/api-reference/api-reference) covering Agentic Discovery, AI Red Teaming, Scan results, Agentic Guardrails, User Management, System Settings, and Integration endpoints. The Sidecar Egress Proxy exposes an HTTP proxy endpoint (/api/http-proxy) for AI guardrail decisions (Allowed/Modified/Blocked). An MCP server is also available for agentic integrations. SDKs available in Python, Node.js, Java, and Go. Developer documentation is at ai-security-docs.akto.io/api-reference/api-reference.
What industry is Akto in?
Akto's product category is API and AI Agent Security. Its primary akta.pro industry code is HDAEAIAI, API Security & Governance (Policy, Threat Protection), with a secondary code of HDAEANAC, Model Serving, Inference & Deployment Platforms (APIs, Edge/On-Prem). Its NAICS code is 541512 and its SIC code is 7373.