Runtime report Endpoint Protector extends controls to coding agents and shadow AI Signal $13.5M reported funding · San Francisco · founded 2020 Runtime report Endpoint Protector extends controls to coding agents and shadow AI Signal $13.5M reported funding · San Francisco · founded 2020

Company profile / AI security

The Most Dangerous Second in AI

Operant AI is betting that the decisive moment in cybersecurity is no longer before software ships or after an alarm rings. It is the instant an AI agent decides to act.

The quick read
  • Operant guards AI at four live surfaces: employee endpoints, cloud agents, MCP connections, and model traffic.
  • Its software can allow, block, or redact actions while they happen - a different job from static scanning or after-the-fact logging.
  • The company has raised $13.5 million, including a $10 million Series A co-led by SineWave Ventures and Felicis.
  • Prices are not public. Plans are tailored to endpoints, production agents, coverage, and governance needs.
  • The idea to copy: make customers prove the product on their own live traffic quickly, then expand from one exposed surface.

The curious thing about an AI agent is that its most dangerous move may look perfectly ordinary. It calls an approved tool. It uses a valid credential. It asks for a customer file that, technically, it has permission to read. The network sees green lights. The kernel sees permitted activity. Only the meaning is wrong: a poisoned document has nudged the agent toward a task nobody intended. Somewhere between the decision and the action sits a sliver of time. Operant AI has built a company in that sliver.

This is a useful way to understand the San Francisco startup because “AI security” has become a baggy label. Operant's version is specific. Its software watches running systems and makes an inline decision - allow, block, or redact - before a prompt, tool call, command, or piece of sensitive data completes its journey. The company calls the broader approach 3D Runtime Defense: discovery, detection, defense.

The old guard arrived after the plot

Traditional security products know where activity comes from and whether the actor holds permission. Static scanners inspect code before it runs. Logging systems reconstruct events after they run. That division worked better when software behaved predictably and humans clicked the important buttons. Agents collapse those assumptions. They choose tools, chain requests, retrieve data, and change course faster than a person can review each step.

Earlier runtime application protection products tried to sit close to executing code, but often reached what co-founder Ashley Roof has called a “trough of despair”: installation friction, performance worries, and noisy results made a clever concept hard to operate. That is what failed first in the category - not the observation that runtime matters, but the buyer experience around it.

Operant's response is almost aggressively practical. Its core cloud product is Kubernetes-native and claims a single-step Helm deployment without modifying application code. A trial runs for seven days. The purpose is to let a security team see its own APIs, data flows, models, and threats rather than admire a sample dashboard. For an early company selling unfamiliar infrastructure, speed-to-proof is part of the product.

“The network can approve an action that the business would never authorize. Operant is selling the missing judgment in between.”YesPress analysis

Four doors into the same room

The product line now follows AI wherever it appears. Endpoint Protector watches employee devices for unsanctioned chatbots, coding agents, plugins, skills, and MCP servers. Agent Protector traces cloud agents through their loops and can enforce identity, intent, and scope. Cloud MCP Gateway catalogs servers and inspects tool calls. AI Gatekeeper routes model traffic while checking prompts, responses, and sensitive data.

That breadth is Operant's distinction and its test. Cloudflare AI Gateway, Portkey, or Kong may cover a gateway layer. AI-security specialists attack model and prompt risks. Wiz, Prisma Cloud, Sysdig, and Aqua come from cloud posture or runtime security. Native cloud vendors protect their own estates. Operant is wagering that a buyer wants one policy plane across the endpoint, agent loop, MCP layer, model call, API, and Kubernetes workload.

Operant AI co-founders Ashley Roof, Priyanka Tembey, and Vrajesh Bhavsar standing together outdoors
Three founders, one suspicious instinct: Roof, Tembey, and Bhavsar built for the moment when perfectly valid infrastructure begins doing something nobody asked for.

The founding mix helps explain the architecture. CEO Vrajesh Bhavsar worked deep in Apple's operating systems, including security technologies associated with the iPhone, then built Arm's machine-learning business. CTO Priyanka Tembey, a Georgia Tech computer-science PhD, helped architect VMware's hybrid-cloud control plane. COO Ashley Roof began at Google and built go-to-market teams. This is systems engineering joined to the less glamorous art of getting a new category bought.

$13.5MTotal funding reported
7 daysCurrent trial window
4Primary protected surfaces

The market moved toward the thesis

Operant began with cloud-native sprawl: Kubernetes workloads, ephemeral services, and APIs that made the old perimeter feel quaint. Then generative AI added models. Agents added autonomy. MCP gave those agents standardized hands. What changed the company's mind was not a rejection of runtime security; it was evidence that runtime had become the larger problem. The same control-plane thinking could govern a container talking to an API and an agent deciding to query payroll.

The commercial path was similarly iterative. The founders worked in stealth with design partners, reportedly reaching a first customer conversation within six months. During the transition from seed financing to the Series A, design partners became paying customers. The company raised $10 million in September 2024 from SineWave Ventures and Felicis, with Alumni Ventures, Massive, Calm Ventures, Gaingels, and industry angels participating.

Public customer counts are not disclosed, and logos require care: an endorsement is not always a contract. But the ecosystem is visible. Operant has paired Agent Protector with LangChain and LangSmith, put MCP Gateway on the Okta Integration Network, listed through AWS Marketplace, and announced infrastructure work with Cerebras and Tenstorrent. Its open-source Woodpecker tool lets teams attack-test AI applications before buying the larger defense platform.

What the invoice reveals

There is no public dollar price. Pro, Scale, and Enterprise plans vary with endpoints under management, production agents, product coverage, deployment model, and governance depth. Monthly contracts are available; annual and volume commitments receive discounts. AWS Marketplace can shorten procurement. The absence of a sticker price is ordinary enterprise software behavior, but the pricing dimensions tell a story: Operant monetizes the spread of AI through an organization.

A team might start with Endpoint Protector to discover shadow AI, or Agent Protector around one production application. As usage expands, it can add MCP Gateway and AI Gatekeeper. That land-and-expand motion also answers the question of what a reader can copy. Do not sell an abstract platform first. Find the live surface where the customer is already nervous, produce evidence on their own system, and widen from there.

The fit is operational, not fashionable

This approach earns its keep when agents or cloud applications are live, touch sensitive data, and can take consequential actions. It is less persuasive for a team with no production AI, one that needs only static code scanning, or an environment that cannot tolerate an inline decision point. The Kubernetes runtime layer also presumes a supported modern cluster; endpoint and gateway products follow different deployment paths.

The brake pedal has to feel invisible

The hard part is not drawing the box in an architecture diagram. It is making the box fast, accurate, and boring. A security layer in the live path can become its own source of latency or failure. Intent is also slippery: block too little and the product becomes an expensive witness; block too much and employees route around it. Operant's enterprise options - custom detectors, air-gapped deployment, identity integrations, audit trails, and scope controls - exist because judgment varies by company.

Still, the timing is good. Coding agents now hold shell access. Coworking agents touch finance, HR, and legal files. MCP servers connect models to tools their creators did not anticipate. In that world, the useful security question is no longer merely, “Was this actor authenticated?” It is, “Should this particular action happen, for this purpose, with this data, right now?”

Operant AI may be small, but that question is large. If agents become ordinary enterprise workers, the company does not need every prediction about autonomous software to come true. It only needs one mundane fact to persist: software with hands requires a brake. And the brake must work before the crash report.