Skip to content

Wallarm

API security platform extending discovery and runtime enforcement to AI agents and Model Context Protocol servers.

Visit Website ↗ + Add to Compare
60/100Incremental Innovator

Overview

Wallarm combines API discovery, a web application firewall and API-specific attack detection with a newer ‘AI Control Platform’ that extends the same runtime enforcement model to AI agents, LLM endpoints and Model Context Protocol (MCP) servers. Rather than building a separate product for AI security, Wallarm treats agentic AI traffic as another API surface to be discovered, monitored and governed using its existing telemetry and policy engine.

Founded in 2013 and headquartered in San Francisco, Wallarm has raised roughly $75 million across a Series C round, with reported customers including Panasonic, Samsung, Dropbox, Miro, Semrush and Victoria’s Secret, and claims to protect over 160,000 APIs. Its 2026 API ThreatStats Report identified 315 MCP-related vulnerabilities, representing 14% of all AI vulnerabilities the company analyzed, reflecting a fast-moving pivot toward the emerging agentic-AI threat surface.

Its differentiator is architectural continuity: MCP and agentic-AI protection is built as an extension of Wallarm’s existing API security telemetry and enforcement, rather than a bolt-on model-guardrail product built from scratch.

Innovation Matrix Assessment

Innovation Velocity 7/10

Moved quickly to extend its API security platform into MCP and agentic-AI protection as that threat surface emerged through 2025-2026, ahead of many peers.

Operational Value 6/10

Gives security teams a single place to discover and govern both traditional APIs and newer AI-agent/MCP traffic, reducing the need for a separate AI-security tool.

Market Momentum 5/10

Named enterprise customers (Panasonic, Samsung, Dropbox) are a real signal, but disclosed funding (a Series C at an undisclosed valuation, ~$75M total) is modest relative to category leaders, so momentum is scored conservatively.

Category Disruption 6/10

Extending existing API security infrastructure to MCP and agentic AI is a structurally sensible and timely move, though it remains early and unproven at scale as a distinct discipline.

Real-World Efficacy 5/10

Wallarm's own API ThreatStats research on MCP vulnerabilities is useful threat intelligence but is self-published; no independent third-party efficacy test was found.

Enduring Relevance 7/10

Agentic AI and MCP-based integrations are a rapidly growing attack surface, making this positioning likely to matter more, not less, over the next few years.

Why CISOs Should Care

Extends existing API visibility and enforcement to AI agents and MCP servers, addressing a fast-emerging attack surface without a completely separate tool and workflow.

What Makes It Different

Applies established API security telemetry and enforcement to agentic AI and MCP traffic, rather than building AI security as an isolated, model-focused product.

The Matrix Verdict

60/100 — INCREMENTAL INNOVATOR

An Incremental Innovator: Wallarm has moved genuinely fast into the MCP/agentic-AI security space and has real named enterprise customers, but its funding scale and independent efficacy evidence remain modest for a company its age.

Editorial Note: Claims vs. Verified Findings

The 315 MCP-vulnerability and 160,000-API figures come from Wallarm's own research report and platform metrics, not an independent audit.

Sources