Wallarm
API security platform extending discovery and runtime enforcement to AI agents and Model Context Protocol servers.
Visit Website ↗ + Add to CompareOverview
Wallarm combines API discovery, a web application firewall and API-specific attack detection with a newer ‘AI Control Platform’ that extends the same runtime enforcement model to AI agents, LLM endpoints and Model Context Protocol (MCP) servers. Rather than building a separate product for AI security, Wallarm treats agentic AI traffic as another API surface to be discovered, monitored and governed using its existing telemetry and policy engine.
Founded in 2013 and headquartered in San Francisco, Wallarm has raised roughly $75 million across a Series C round, with reported customers including Panasonic, Samsung, Dropbox, Miro, Semrush and Victoria’s Secret, and claims to protect over 160,000 APIs. Its 2026 API ThreatStats Report identified 315 MCP-related vulnerabilities, representing 14% of all AI vulnerabilities the company analyzed, reflecting a fast-moving pivot toward the emerging agentic-AI threat surface.
Its differentiator is architectural continuity: MCP and agentic-AI protection is built as an extension of Wallarm’s existing API security telemetry and enforcement, rather than a bolt-on model-guardrail product built from scratch.
Innovation Matrix Assessment
Moved quickly to extend its API security platform into MCP and agentic-AI protection as that threat surface emerged through 2025-2026, ahead of many peers.
Gives security teams a single place to discover and govern both traditional APIs and newer AI-agent/MCP traffic, reducing the need for a separate AI-security tool.
Named enterprise customers (Panasonic, Samsung, Dropbox) are a real signal, but disclosed funding (a Series C at an undisclosed valuation, ~$75M total) is modest relative to category leaders, so momentum is scored conservatively.
Extending existing API security infrastructure to MCP and agentic AI is a structurally sensible and timely move, though it remains early and unproven at scale as a distinct discipline.
Wallarm's own API ThreatStats research on MCP vulnerabilities is useful threat intelligence but is self-published; no independent third-party efficacy test was found.
Agentic AI and MCP-based integrations are a rapidly growing attack surface, making this positioning likely to matter more, not less, over the next few years.
Why CISOs Should Care
Extends existing API visibility and enforcement to AI agents and MCP servers, addressing a fast-emerging attack surface without a completely separate tool and workflow.
What Makes It Different
Applies established API security telemetry and enforcement to agentic AI and MCP traffic, rather than building AI security as an isolated, model-focused product.
The Matrix Verdict
60/100 — INCREMENTAL INNOVATOR
An Incremental Innovator: Wallarm has moved genuinely fast into the MCP/agentic-AI security space and has real named enterprise customers, but its funding scale and independent efficacy evidence remain modest for a company its age.
Editorial Note: Claims vs. Verified Findings
The 315 MCP-vulnerability and 160,000-API figures come from Wallarm's own research report and platform metrics, not an independent audit.
Sources
- Wallarm AI Control Platform launch — https://www.wallarm.com/press-releases/wallarm-launches-ai-control-platform-bringing-runtime-visibility-and-enforcement-to-enterprise-ai
- Information Security Buzz (API ThreatStats/MCP vulnerabilities) — https://informationsecuritybuzz.com/apis-wallarm-report-ai-is-charging-cyberattacks/
Alternatives to Wallarm
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…