One sentence
Noma surfaces and steers the estate. Cyphrex proves the act: who approved, what was touched, and what stayed blocked.
Who each is for
Noma
Enterprise AI and agent security
A platform for security teams who need to discover agents across endpoint, SaaS, and homegrown AI, score posture and blast radius, control MCP and tool access, detect threats, and red-team agents.
Discover → posture → access → detect → red team.
Cyphrex
Compliance infrastructure for agents
A decide-and-prove layer for teams who will instrument an agent or route its MCP traffic, and who need each decision kept as tamper-evident evidence.
Enforce the action → tamper-evident evidence.
Capability comparison
| Capability | Noma | Cyphrex |
|---|
| Estate-wide discovery (endpoint + SaaS + homegrown) | Strong fit | Not the primary job (sees what you instrument / route) |
|---|
| AI-SPM / blast-radius posture | Strong fit | Policy profiles on registered agents; not a full AI-SPM suite |
|---|
| MCP / tool access control at runtime | Strong fit | MCP gateway: check, block, same audit trail |
|---|
| AI-DR / behavioral threat detection | Strong fit | Policy violations + alerts; not an AI-DR/SOC platform |
|---|
| Adversarial red teaming | Strong fit | Not Cyphrex’s job |
|---|
| Tamper-evident, independently verifiable decision record | Audit trails / compliance reporting for security teams | Ed25519-signed packages + public /verify |
|---|
| Who approved / what touched / what stayed blocked | Session/activity visibility across the AI estate | Compliance receipt for auditors, insurers, legal |
|---|
When Noma is the better fit
- You need one control plane across endpoint coding agents, SaaS agents, and homegrown stacks.
- Security wants AI-SPM, access control, AI-DR, and red teaming sharing context.
- The buying center is SOC, AI TRiSM, or an AI security platform.
- The pain is shadow MCP, coding assistants, and toxic tool combinations.
- You want behavioral detection — prompt injection, exfiltration, and goal drift — as the primary runtime story.
When Cyphrex is the better fit
- Legal, risk, or compliance asks for a receipt a third party can verify.
- Builders will instrument agents or route MCP through a gateway and want decide, enforce, and prove in one path.
- You already have, or will buy, discovery and AI-DR elsewhere. The missing piece is the durable decide-and-prove trail.
- Regulated buyers want a signed, hash-bound action history, not only security-operations telemetry.
- You need blocked steps recorded as blocked, with the rule and timestamp, as compliance infrastructure.
Better together
Noma, or a platform like it, for discovery, posture, and broad runtime steering and detection. Cyphrex for the cryptographically checkable decision record on the actions that matter.
What Cyphrex evidence proves
What a signed report contains
- Agent
- Action and resource
- Allowed or blocked
- Rule and violations
- Timestamp
How verification works
Every Cyphrex evidence package is signed with Ed25519 and bound with SHA-256. On /verify, someone can check it without a Cyphrex login.
Compliance mapping
Evidence artifacts map toward SOC 2 / EU AI Act / HIPAA / SR 26-2 style reporting — not certification; details on Trust.
Limits
Cyphrex signs what flows through the SDK check() or the MCP gateway. It does not invent coverage for a path it never saw. Cyphrex is not your auditor.
Frequently asked
Is Cyphrex a Noma alternative or a complement?▾
Often a complement. Noma surfaces and steers the estate. Cyphrex records what an instrumented agent was allowed to do, and proves it. Cyphrex does not replace Noma.
Does Cyphrex discover shadow SaaS agents?▾
No. Estate-wide discovery across endpoint, SaaS, and homegrown AI is Noma’s job. Cyphrex sees what you instrument with the SDK or route through the MCP gateway.
Are blocked actions recorded as blocked?▾
Yes. Allowed or blocked is part of the decision record, with the agent, action type, resource, rule, and timestamp.