Consider a perfectly ordinary enterprise AI pilot. A team builds an assistant that answers questions from a sales database. It has an owner, a test set, and an approval. Then someone adds a calendar tool. Someone else gives it a service account. A third team connects it to a second agent that can retrieve customer records. Each change is small. Together, they create a system whose permissions are harder to describe than its purpose.
Trust3 AI is in the business of describing that system, then deciding what it may do. The company discovers agents across connected platforms, maps their owners and identities, records their prompts and tool calls, and applies access rules when an agent reaches for a tool or a piece of data. Its most pointed idea is that an agent's initial approval is only a photograph. The risk is a moving picture.
The short version
- Trust3 AI sells a control plane for agent discovery, observability, security and data access.
- Its customers are enterprise security, platform, data and compliance teams, especially where sensitive data crosses several clouds.
- The ancestry matters: its founders helped create the technology behind Apache Ranger and Apache Atlas.
- Public pricing is custom. The company offers guided pilots for qualifying teams.
The guest list is the product
A security team cannot govern an agent it has never seen. Trust3's first move is to collect signals from platforms such as Databricks, Microsoft Copilot Studio and Azure Foundry, then turn those fragments into an inventory. The record can include an owner, the identity under which the agent runs, its reachable data, and a Trust Score. The company's documentation puts that score on a 1.0 to 10.0 scale and ties it to policy checks. It is a triage device, not a moral verdict on the machine.
The second move is to observe the chain. The platform describes traces that follow prompts, retrievals, tool calls and responses, with policy decisions attached. If an agent delegates to another agent, the interesting question is whether identity and authority travel with the request. An audit log that says only “service account accessed table” is a thin answer when a dozen agents share the account.
Find agents, owners, identities and what they can reach.
Trace prompts, tool calls, data access and policy verdicts.
Check purpose and permissions before the next action.
The third move is the one with consequences. Trust3 says it can evaluate purpose-based access on each request and enforce controls at runtime, including for MCP tools and agent-to-agent handoffs. A policy might allow a finance agent to read a revenue table for a quarter-end task, with a time-limited grant, while masking fields outside that purpose. The decision must happen before the query runs. A beautiful dashboard after the data leaves is merely attractive evidence.

An old key for a new lock
The Trust3 name can make the company sound newly assembled. The lineage is longer and slightly untidy. Balaji Ganesan and Don Bosco Durai worked on XA Secure, whose technology became Apache Ranger after Hortonworks acquired it. Their work is also associated with Apache Atlas, a metadata and lineage project. They founded Privacera in 2016 to carry data governance across cloud platforms. In March 2021, Privacera raised a $50 million Series B led by Insight Partners. Trust3 says total funding reached $63.5 million.
The branding arrived in chapters. PAIG AI announced a change to Trust3 AI in June 2025, aiming at AI reliability, governance and security. In March 2026, Privacera announced a broader Trust3 AI platform and rebrand. Legal terms now name Privacera, Inc. as doing business as Trust3 AI. The company dates its specific agent-governance push to 2024. That is more useful than pretending the whole operation sprang from nowhere in a single year.
One useful inheritance is public: Privacera maintains an open-source PAIG project on GitHub for generative AI security, safety and observability. It gives a technical team a way to inspect an earlier piece of the company's thinking. The current Trust3 control plane is sold as enterprise software, so a repository demo and a production deployment should not be confused.
This history explains the company's favorite boundary: the data source. Many AI safety products inspect a model's answer or watch cloud resources. Trust3 argues that the permission to read a Snowflake table, call an MCP server or export a tagged field should be checked where the action happens. Its data security layer advertises fine-grained, native enforcement across Snowflake, Databricks, BigQuery and other sources, with centralized policy administration. It is a credible distinction in a crowded market, though its reach depends on the connectors, deployment and policy design a customer actually implements.
“Your gate can’t refuse what was never submitted.”
Who would pay for a guest list?
The likely buyer has several AI teams and more than one data platform. A single agent in a sandbox does not create the same coordination problem as hundreds of agents across finance, healthcare or retail operations. Trust3 describes five anonymized Fortune 500 production deployments. Its Privacera predecessor published customer cases in financial services, healthcare, media and retail, generally without naming the company. The anonymity is familiar in security software; it also limits what an outsider can independently verify about scale or outcomes.
Trust3 sells through enterprise subscriptions and proposals. The company says price depends on environment, integrations and scale, and it supports SaaS, private cloud and self-hosted installations. Its FAQ describes a guided proof of concept, typically two to four weeks, that scopes one or two agents, end-to-end discovery and observation, and a representative purpose-based policy. There is no public list price. A buyer should therefore compare the full cost of connectors, implementation, policy maintenance and evidence review, not just the software line item.
The product set follows the work. Agent Discovery builds the inventory. Agent Observability produces the trace. Agent Security controls access and can intervene at runtime. Data Security applies fine-grained rules to the underlying platforms. A Governance Intelligence Agent lets a user ask plain-language questions about inventory, violations and next steps. Trust3 IQ, announced in the earlier brand chapter, addresses AI accuracy and evaluation. A regulator may care about the evidence packet; a developer may care that a policy catches an excessive grant before deployment; a CISO may care that the two views agree.
Pick one agent that crosses a tool boundary and one sensitive data source. List its owner, human requester, service identity, declared purpose and maximum data scope. Then change one tool permission mid-pilot. If the inventory, trace and access decision do not update together, the governance process has a gap.
The approval meeting is not the finish line
Trust3 has announced integrations or collaborations with Google Cloud, Snowflake and Dell Technologies, and lists a broad partner ecosystem. In 2026 it released Trustscore, MCP Security, and new multi-engine data access capabilities. Those moves place it between two markets: data governance, where Privacera has years of experience, and agent security, where vendors from cloud posture to model observability are racing toward the same buying committee. Wiz, Fiddler, Zenity and native controls from the large cloud and data platforms are different kinds of alternatives, often used together rather than swapped one-for-one.
What failed first, in Trust3's telling, was the approval gate. Agents appeared outside the register, gained broad standing credentials, and changed after sign-off. That diagnosis is plausible even without adopting every claim in the company's marketing. The copyable lesson is concrete: inventory first, trace the full chain second, and make permissions short-lived and tied to a declared task. Put an owner on exceptions and rehearse the evidence request before an incident asks for it.
The approach has boundaries. It works best when the relevant platforms expose reliable metadata and enforcement points, identities can be mapped to real people or teams, and someone will maintain the policies. A connector cannot discover what it cannot see. A score cannot repair a false owner. A purpose field typed by an agent is weak unless the surrounding system can verify it. In a small, isolated pilot with no sensitive data, a full enterprise control plane may be more machinery than the job requires.
Still, the question Trust3 asks will outlive any particular dashboard: when software can act on a company's behalf, who gave it the key, for what purpose, and who can take it back? The interesting answer is not a policy document. It is a decision made at the instant the agent reaches for the door.