Lasso Security
Full-lifecycle GenAI security, from shadow AI to runtime defense.
Overview
Tel Aviv-based GenAI security platform covering shadow AI discovery, automated red-teaming, and sub-50ms runtime enforcement across a five-pillar lifecycle. Founded June 2023, it has raised roughly $28M and serves enterprise and US federal customers via Lasso Federal LLC.
Pricing
Pricing shown for reference only. These figures reflect RECATOOLS research as of 11 Jul 2026 and may be out of date or incomplete. This is not financial or purchasing advice — always confirm the current price on the provider’s official website before making any decision.
- Annual contract via AWS Marketplace
- $0.01/unit overage beyond commit
- Discover, assess, test, enforce, protect modules
- Shadow-AI discovery + agentic workload coverage
- Demo and proof-of-value on request
Use cases
What you can produce with Lasso Security
- Full AI-BOM (Bill of Materials) inventory of every model, agent, and system prompt in the environment
- Automated adversarial test report with exploitable vulnerability findings across 3,000+ attack scenarios
- Inline runtime policy enforcement with vendor-cited low-latency at the proxy or API gateway layer
- Intent-based threat detection alerts for anomalous agentic AI behaviour
- Shadow AI usage dashboard mapping unsanctioned GenAI tool access across the workforce
- Compliance gap analysis aligned to NIST AI RMF, OWASP LLM Top 10, and MITRE ATLAS
ASEAN Perspective
Lasso Security in Southeast Asia
Singtel Innov8 — the Singapore telco's strategic venture arm — is a named investor, which signals some ASEAN institutional awareness of the platform and may facilitate regional introductions. However, no publicly documented ASEAN end-customers or regional offices have been confirmed as of mid-2026, and Lasso's marketing, compliance references, and case studies are overwhelmingly US- and Israel-centric. ASEAN enterprises with GenAI governance mandates (particularly under Singapore's MAS FEAT Principles or emerging AI governance frameworks in Indonesia and Thailand) would find Lasso technically capable but should budget for a heavier integration and onboarding effort without local presence or regional support SLAs.
Lasso's five-pillar framework (Discover, Assess, Test, Enforce, Protect) and Intent Security Framework for agentic AI show real engineering depth, not just a slide deck — the open-source MCP Security Gateway (MIT license, 378 GitHub stars) is a genuinely useful, actively maintained project on its own. The Singtel Innov8 investment and API/SDK-first deployment make it approachable for enterprises exploring AI governance outside the US.
The caveats are structural: pricing is entirely quote-based with nothing published, Gartner Peer Insights coverage remains thin as of mid-2026 so independent validation is still catching up, and the July 2025 Lasso Federal LLC pivot toward FedRAMP High and DoD SRG signals the commercial center of gravity is US government and enterprise. No publicly documented ASEAN customers despite the Singtel relationship.
What people say
Lasso Security prices everything by quote — there's no published plan, no self-serve checkout, just a sales conversation scoped to your organization size and AI footprint. That's standard for enterprise security, but it does mean the five-pillar pitch (Discover, Assess, Test, Enforce, Protect) is hard to shop against competitors without picking up the phone.
What's verifiable: the open-source MCP Security Gateway (MIT license, 378 stars on GitHub) is a real, actively maintained project, not vaporware bolted onto a sales deck, and it's a genuinely useful building block for teams securing their own MCP server fleets. The company's Gartner Peer Insights presence remains thin as of mid-2026, so independent third-party validation is still catching up to the marketing.
Founded in Tel Aviv in June 2023, Lasso has raised roughly $28M from investors including Samsung Next and Singtel Innov8, landed the US Department of Homeland Security as a customer, and stood up Lasso Federal LLC in July 2025 to chase FedRAMP High and DoD SRG compliance. That federal pivot is telling: the commercial center of gravity is North American government and enterprise, not APAC, and there's no publicly documented Southeast Asian customer base despite the Singtel Innov8 relationship — a gap worth watching given that investor tie.
Summary of public user & expert reviews, compiled by RECATOOLS.
Notable facts
- Former Israeli Prime Minister Naftali Bennett sits on Lasso's board — he previously co-founded cybersecurity firm Cyota, which was acquired by RSA Security.
- Lasso's open-source MCP Security Gateway, released in April 2025, reached 376 GitHub stars within months and was among the first tools to secure Model Context Protocol traffic for agentic AI.
- The company positions itself as 'the Wiz of GenAI security' — a deliberate nod to Wiz's cloud-security playbook of comprehensive visibility and rapid enterprise adoption.
- Lasso claims its runtime enforcement engine is 570x more cost-effective than cloud-native guardrails such as AWS Bedrock Guardrails or Azure AI Content Safety, based on its own benchmarks.
Frequently asked questions
About this listing
This entry was compiled from publicly available data including Lasso Security's official website, press releases, documentation, and reputable third-party publications. RECATOOLS is not affiliated with Lasso Security unless explicitly stated.
Third-party AI tools update their pricing, features, availability, and policies frequently. Information here may be outdated by the time you read this — we make reasonable efforts to keep listings current, but cannot guarantee absolute accuracy.
For the latest details, please refer to Lasso Security directly →
Spotted something out of date? Suggest an update →
Lasso Security in the news
AI & ML
Meta Ships Muse Spark 1.1 — Its First Frontier API With a Price Tag, and a Shift Away From...
ASEAN Tech
MAS's SAFR Framework Puts the Safeguard Where the Money Moves — At the Point an AI Agent A...
Finance
The FCA's Mills Review: No New AI Rulebook for Finance — but Targeted New Powers, Includin...
More in Security & Safety