Compare

Cyphrex vs Zenity

Zenity is see-and-steer.

Cyphrex is decide-and-prove.

One sentence

Zenity surfaces and steers the agent; Cyphrex proves who approved the step, what was touched, and whether a blocked action stayed blocked.

Who each is for

Zenity

Agent security and governance

A platform for security teams who need to find agents they did not build, score how those agents are configured, steer what they can do at runtime, and investigate threats.

Discover → posture → runtime → detect.

Cyphrex

Compliance infrastructure for agents

A decide-and-prove layer for teams who will instrument an agent or route its MCP traffic, and who need each decision kept as tamper-evident evidence.

Enforce the action → tamper-evident evidence.

Capability comparison

CapabilityZenityCyphrex
Agent discovery / inventory across SaaS, cloud, endpointStrong fitNot the primary job (sees what you instrument / route)
Pre-deploy posture (config, permissions, integrations)AISPMPolicy profiles on registered agents; not a full AISPM suite
Runtime allow / blockRuntime Boundaries (allow / block / quarantine)check() + MCP gateway before execution
Identity correlation (IdP ↔ agent)AI IAM (Okta / Entra)Per-agent identity
Threat detection / responseAIDR + Guardian AgentsPolicy violations + alerts; not an AIDR/SOC platform
MCP tool governanceNative MCP SecurityMCP gateway: check, block, same audit trail
Tamper-evident, independently verifiable evidenceObservability / findings / API exportEd25519-signed packages + public verify
Who approved / what touched / what stayed blockedSession/activity visibility for security teamsDesigned as the compliance receipt for auditors, insurers, legal

When Zenity is the better fit

  • You need estate-wide discovery of agents you did not build (SaaS copilots, low-code, endpoint agents).
  • Security wants AISPM and exposure scoring before agents hit production.
  • The buying center is SOC / AI TRiSM and wants AIDR-style detection mapped to OWASP / MITRE.
  • You are standardizing one policy plane across Copilot, ChatGPT Enterprise, Foundry, Bedrock, Agentforce, and similar agent surfaces.
  • You need identity correlation from Okta or Entra into agent sessions as the primary pain.

When Cyphrex is the better fit

  • Legal, risk, or compliance asks for the receipt: what the agent was allowed to do, and proof a blocked step stayed blocked.
  • You need evidence a third party can verify without trusting Cyphrex’s UI.
  • Regulated buyers in health, finance, or insurance want a signed, hash-bound action history, not only operational logs.
  • Builders will instrument agents with the SDK or route MCP through a gateway and want decide, enforce, and prove in one path.
  • You already have, or will buy, discovery and posture elsewhere, and the missing piece is the durable decide-and-prove trail.

Better together

Zenity, or a platform like it, for discover, posture, and broad runtime steering. Cyphrex for the cryptographically checkable decision record on the actions that matter. The two jobs are different, and they can sit on the same estate.

What Cyphrex evidence proves

What a signed report contains

  • Agent
  • Action and resource
  • Allowed or blocked
  • Rule and violations
  • Timestamp

How verification works

Every Cyphrex evidence package is signed with Ed25519 and bound with SHA-256. On /verify, someone can check it without a Cyphrex login.

Compliance mapping

Evidence artifacts map toward SOC 2 / EU AI Act / HIPAA / SR 26-2 style reporting — not certification; details on Trust.

Limits

Cyphrex signs what flows through the SDK check() or the MCP gateway. It does not invent coverage for a path it never saw. Cyphrex is not your auditor.

Frequently asked

Does Cyphrex discover shadow SaaS agents?

No. Discovery of agents you did not build is Zenity’s strength. Cyphrex sees what you instrument with the SDK or route through the MCP gateway.

Can Zenity’s logs replace a signed evidence package?

No. A Cyphrex package is Ed25519-signed and SHA-256-bound, so someone can check the decision without a Cyphrex login. What that check covers is on the Trust Center.

Do blocked actions show up as blocked?

Yes. Allowed or blocked is part of the decision record, with the agent, action type, resource, rule, and timestamp.

Keep going

Message the founder