Lasso Security

Full-lifecycle GenAI security, from shadow AI to runtime defense.

Security & Safety Enterprise Has API
Researched · Published · Reviewed
RECATOOLS Score
7.2 / 10
Capability
8.5
Value for money
6
Ease of use
6.5
ASEAN readiness
5.5
API quality
7.5
Founded
2023
HQ
Tel Aviv, Israel
Users
A growing roster of enterprise and public-sector customers, including via Lasso Federal
Launched
Emerged from stealth Nov 2023 with $6M seed
Developer
Independent (Lasso Security Ltd.)

Overview

Tel Aviv-based GenAI security platform covering shadow AI discovery, automated red-teaming, and sub-50ms runtime enforcement across a five-pillar lifecycle. Founded June 2023, it has raised roughly $28M and serves enterprise and US federal customers via Lasso Federal LLC.

Advertisement

Pricing

Pricing shown for reference only. These figures reflect RECATOOLS research as of 11 Jul 2026 and may be out of date or incomplete. This is not financial or purchasing advice — always confirm the current price on the provider’s official website before making any decision.

Secured Gateway
$50,000/yr
LLM gateway product as listed on AWS Marketplace (12-month commit)
  • Annual contract via AWS Marketplace
  • $0.01/unit overage beyond commit

Use cases

Detecting and blocking sensitive data exfiltration through employee use of ChatGPT, Copilot, or Claude Automated red-teaming of internal LLM-powered applications before production deployment Shadow AI discovery across an enterprise — identifying which AI tools are in use without IT approval Runtime protection for production AI agents running on Bedrock, Vertex AI, or Azure OpenAI Public-sector GenAI governance and compliance enforcement (FedRAMP High, ITAR, CJIS environments via Lasso Federal)

What you can produce with Lasso Security

  • Full AI-BOM (Bill of Materials) inventory of every model, agent, and system prompt in the environment
  • Automated adversarial test report with exploitable vulnerability findings across 3,000+ attack scenarios
  • Inline runtime policy enforcement with vendor-cited low-latency at the proxy or API gateway layer
  • Intent-based threat detection alerts for anomalous agentic AI behaviour
  • Shadow AI usage dashboard mapping unsanctioned GenAI tool access across the workforce
  • Compliance gap analysis aligned to NIST AI RMF, OWASP LLM Top 10, and MITRE ATLAS
Advertisement

ASEAN Perspective

Lasso Security in Southeast Asia

Singtel Innov8 — the Singapore telco's strategic venture arm — is a named investor, which signals some ASEAN institutional awareness of the platform and may facilitate regional introductions. However, no publicly documented ASEAN end-customers or regional offices have been confirmed as of mid-2026, and Lasso's marketing, compliance references, and case studies are overwhelmingly US- and Israel-centric. ASEAN enterprises with GenAI governance mandates (particularly under Singapore's MAS FEAT Principles or emerging AI governance frameworks in Indonesia and Thailand) would find Lasso technically capable but should budget for a heavier integration and onboarding effort without local presence or regional support SLAs.

RECATOOLS Verdict

Lasso's five-pillar framework (Discover, Assess, Test, Enforce, Protect) and Intent Security Framework for agentic AI show real engineering depth, not just a slide deck — the open-source MCP Security Gateway (MIT license, 378 GitHub stars) is a genuinely useful, actively maintained project on its own. The Singtel Innov8 investment and API/SDK-first deployment make it approachable for enterprises exploring AI governance outside the US.

The caveats are structural: pricing is entirely quote-based with nothing published, Gartner Peer Insights coverage remains thin as of mid-2026 so independent validation is still catching up, and the July 2025 Lasso Federal LLC pivot toward FedRAMP High and DoD SRG signals the commercial center of gravity is US government and enterprise. No publicly documented ASEAN customers despite the Singtel relationship.

Independent AI-assisted assessment by RECATOOLS.

What people say

Lasso Security prices everything by quote — there's no published plan, no self-serve checkout, just a sales conversation scoped to your organization size and AI footprint. That's standard for enterprise security, but it does mean the five-pillar pitch (Discover, Assess, Test, Enforce, Protect) is hard to shop against competitors without picking up the phone.

What's verifiable: the open-source MCP Security Gateway (MIT license, 378 stars on GitHub) is a real, actively maintained project, not vaporware bolted onto a sales deck, and it's a genuinely useful building block for teams securing their own MCP server fleets. The company's Gartner Peer Insights presence remains thin as of mid-2026, so independent third-party validation is still catching up to the marketing.

Founded in Tel Aviv in June 2023, Lasso has raised roughly $28M from investors including Samsung Next and Singtel Innov8, landed the US Department of Homeland Security as a customer, and stood up Lasso Federal LLC in July 2025 to chase FedRAMP High and DoD SRG compliance. That federal pivot is telling: the commercial center of gravity is North American government and enterprise, not APAC, and there's no publicly documented Southeast Asian customer base despite the Singtel Innov8 relationship — a gap worth watching given that investor tie.

Summary of public user & expert reviews, compiled by RECATOOLS.

Notable facts

  • Former Israeli Prime Minister Naftali Bennett sits on Lasso's board — he previously co-founded cybersecurity firm Cyota, which was acquired by RSA Security.
  • Lasso's open-source MCP Security Gateway, released in April 2025, reached 376 GitHub stars within months and was among the first tools to secure Model Context Protocol traffic for agentic AI.
  • The company positions itself as 'the Wiz of GenAI security' — a deliberate nod to Wiz's cloud-security playbook of comprehensive visibility and rapid enterprise adoption.
  • Lasso claims its runtime enforcement engine is 570x more cost-effective than cloud-native guardrails such as AWS Bedrock Guardrails or Azure AI Content Safety, based on its own benchmarks.

Frequently asked questions

What does the five-pillar Discover–Assess–Test–Enforce–Protect framework actually cover?
Discover inventories every AI agent, model, and shadow AI tool across cloud and CI/CD pipelines. Assess analyses security posture, misconfigurations, and compliance gaps against NIST and OWASP. Test runs automated red-teaming using 3,000+ attack scenarios including multi-turn agentic attacks. Enforce deploys inline policy controls at the proxy, API, or AI Gateway layer in under 50ms. Protect provides continuous detection and termination of live AI threats mapped to MITRE and OWASP taxonomies.
Is Lasso Security open source?
The core commercial platform is proprietary and enterprise-licensed. However, Lasso maintains open-source MIT-licensed tooling on GitHub, most notably the mcp-gateway (a plugin-based security gateway for Model Context Protocol) and claude-hooks (prompt-injection defences for Claude Code). These serve as community on-ramps and do not replace the full commercial product.
How does Lasso handle agentic AI differently from traditional LLM guardrails?
Lasso developed what it calls the Intent Security Framework — a behavioural baseline approach that monitors not just what an AI agent does but what it intends to do, detecting anomalies before a malicious action completes. This goes beyond simple keyword or content filtering and is designed for multi-step agentic workflows where conventional guardrails produce too many false negatives.

About this listing

Researched on
Published on
Last reviewed

This entry was compiled from publicly available data including Lasso Security's official website, press releases, documentation, and reputable third-party publications. RECATOOLS is not affiliated with Lasso Security unless explicitly stated.

Data accuracy

Third-party AI tools update their pricing, features, availability, and policies frequently. Information here may be outdated by the time you read this — we make reasonable efforts to keep listings current, but cannot guarantee absolute accuracy.

For the latest details, please refer to Lasso Security directly →

Spotted something out of date? Suggest an update →

Advertisement