Operant AI
San Francisco, US · 42 employees on LinkedIn · 7 known investors
Operant AI provides a runtime defense platform that protects cloud and AI applications across infrastructure and APIs through continuous discovery, detection, and defense capabilities. The platform defends against runtime attacks including data exfiltration, supply chain attacks, model theft, and prompt injection for development, security, and operations teams.
Also known as Operant
Founders & leadership




Investors · 7
Funding
SEC filings, press & company announcements$10M disclosed across 1 of 3 rounds · 2024
- $10MSeries ASep 2024 · 2 sourcesSource ↗
Source: company announcements and press reports — follow each round's link for the claim.
Company profile
researched Aug 2026Operant AI is a San Francisco-based security company that describes itself as a Runtime AI Application Protection Platform. Its platform applies what the company calls "3D" protection — discovery, detection and defense — across the layers of live application environments, from infrastructure and Kubernetes workloads to services, APIs, LLMs, AI agents and employee endpoints. Rather than static analysis, the approach centers on runtime enforcement of data-in-use as it flows through application stacks, using components the company calls Adaptive Internal Firewalls and Proactive Protection Guardrails together with instant live blueprints of every application layer, from processes to services to APIs.
The product line as presented on the company website comprises Endpoint Protector (discovery and blocking of shadow AI tools, coding agents and MCP clients on employee laptops, with prompt injection, data exfiltration and malicious shell execution controls), Agent Protector (discovery and runtime defense for managed and unmanaged agents across cloud, SaaS and developer tools), an MCP Gateway (visibility and controls for MCP servers, clients, tools and connections, including registries, allow/deny lists and non-human-identity access controls), AI Gatekeeper (LLM and GenAI threat protection with inline auto-redaction of sensitive data), and API & Cloud Protector (discovery and protection of internal, external, ghost and zombie APIs and blocking of OWASP Top 10 API attacks without VPC mirroring). Adjacent capabilities marketed include runtime CADR (cloud application detection and response) and Kubernetes-native cloud security. The company also references Woodpecker, described in a customer quote as open-source red teaming for AI applications.
At the time of its Series A, the company stated that its shielding technology blocks more than 80% of OWASP Top 10 attacks across APIs, LLMs and Kubernetes without instrumentation or application code changes.
Founding story
Co-founders Vrajesh Bhavsar (CEO) and Dr. Priyanka Tembey (CTO) had worked together more than a decade earlier at Qualcomm Research, using machine learning to secure apps on Android devices during a period when rapid Android adoption was creating new attack opportunities. Bhavsar began his career as a kernel engineer at Apple building core security functionality for the iPhone, later founding the machine learning business unit at Arm; Tembey used her Georgia Tech PhD in computer science to help architect VMware's hybrid cloud product. Ashley Roof joined as a co-founder and CMO in 2021, bringing go-to-market experience from Google and startups including a CMO role at Transposit. The company started in stealth and, per the founders, held its first customer conversation within about six months.
Business model
Operant AI sells software to enterprise security, platform and operations teams. Its site offers a self-serve "Start Now" path alongside demo requests, and the company has described running proof-of-concept programs with customers; the FAQ page positions deployment as skipping the POC via a single-step helm install. Specific pricing terms are not disclosed in the sources.
Traction
Public traction indicators are limited. The company reported converting design partners into paying customers before its Series A, holds SOC 2 compliance per a podcast episode summary, and publishes named endorsements from security leaders at Chargebee, Cohere, ClickHouse and Juniper Networks, as well as from Latio Tech, a CoSAI board member and a former NIST cybersecurity chief. Analyst recognition includes inclusion in multiple 2024-2025 Gartner guides and Forrester's 2024 Zero Trust Landscape. No customer counts, revenue or headcount figures are disclosed in the sources.
Latest developments
The most recent publicly promoted development is the launch of Endpoint Protector, described as purpose-built security for the AI workforce, covering shadow AI discovery, agent-loop monitoring and on-device blocking of prompt injection, data exfiltration and malicious shell execution. The company is also promoting a "2026 Guide to Securing MCP" and positions itself around five 2025-era Gartner AI security reports. A customer quote references Operant's detection and blocking of a "Shadow Escape" attack involving MCP and agentic identities.
▸Full profile — market position, technology, go-to-market, geography, history, risks & controversies
Market position
The company positions itself as the only Runtime AI Application Protection Platform and claims to be the only vendor featured across five Gartner AI security reports (AI TRiSM Market Guide 2025, API Protection Market Guide, Innovation Insight on MCP Gateways, How to Secure Custom-Built AI Agents, and the LLM Supply Chain Security Playbook). It was also cited in Gartner's 2024 API Threat Protection Market Guide, Gartner's Emerging Tech Kubernetes Runtime Security Report, and Forrester's 2024 Zero Trust Landscape. Its framing places it adjacent to, and consolidating across, AppSec, API security, cloud/Kubernetes runtime security and AI/LLM security categories.
Stated differentiators are multidimensional runtime coverage spanning endpoint, agent, MCP, LLM, API and Kubernetes layers in a single platform; active blocking rather than static analysis or detection-only; protection of internal east-west traffic and internal APIs beyond the perimeter WAF; inline auto-redaction of sensitive data for privacy and governance; and deployment without instrumentation, code changes or VPC mirroring. Founders have also noted that the team does not come from prior security-vendor backgrounds.
Technology
The platform runs at runtime inside customer environments and is Kubernetes-native, deployed via a single-step helm install with no instrumentation, integrations or application code changes, and stated to work in under five minutes. Core technical elements include live blueprints of every application layer (processes, services, APIs), Adaptive Internal Firewalls, Proactive Protection Guardrails, inline auto-redaction of sensitive data, non-human-identity access controls for MCP, and monitoring of agent loops with full prompt and tool-call context on endpoints. The company emphasizes east-west (internal) protection beyond the WAF and without the overhead of VPC mirroring.
Go-to-market
Early go-to-market relied on working with design partner teams while the company was in stealth, followed by customer education efforts; converting design partners into paying customers was described by the founders as part of the seed-to-Series A transition. Current motion combines a low-friction technical trial (single-step helm install, no instrumentation or integrations) with demo requests, published guides and whitepapers, third-party analyst recognition, and endorsements from security leaders at companies including Chargebee, Cohere, ClickHouse and Juniper Networks.
Enterprise security engineers, platform, DevOps and development teams operating cloud-native and Kubernetes environments and deploying AI, LLM, agentic and MCP-based applications. Cited endorsers work at technology companies such as Chargebee, Cohere, ClickHouse and Juniper Networks.
Geography
Headquartered in San Francisco, California, per the Series A press release dateline. No other locations are disclosed in the sources.
History
Operant AI began in stealth, working with design partner teams before converting them into paying customers ahead of its Series A. Ashley Roof joined as a third co-founder in 2021. In September 2024 the company announced a $10 million Series A co-led by SineWave Ventures and Felicis that brought total funding to $13.5 million and added Patricia Muoio and Nancy Wang to its board. Since then the product line has expanded from API, Kubernetes and LLM runtime protection into agentic AI, MCP and endpoint security, with Endpoint Protector as the most recently introduced offering.
Risks & controversies
No controversies, litigation or negative events appear in the sources. Several prominent claims — including being the "only" runtime AI application protection platform, the "only" vendor across five Gartner AI security reports, and blocking more than 80% of OWASP Top 10 attacks — originate from the company's own website and press release and are not independently verified in the material reviewed. Key operating metrics such as revenue, customer count and headcount are undisclosed.
Compiled by commissioned research from 8 cited public sources — announcements, filings, and press listed under research sources below.
Key figures
latest reportedCompany-reported or press-reported figures, each dated to when it was claimed — not independently audited.
Competitors · 7
by search overlapCompanies competing with Operant AI for the same Google search keywords, organic and paid, via search-intersection analysis.
Timeline · 7
launches, deals, and filingsThe company states it is the only vendor featured across five Gartner AI security reports: the 2025 Market Guide for AI TRiSM, the API Protection Market Guide, Innovation Insight: MCP Gateways, How to Secure Custom-Built AI Agents, and the LLM Supply Chain Security Playbook.
Operant AI introduced Endpoint Protector, an endpoint security product for AI-enabled employee devices that discovers shadow AI tools, coding agents and MCP clients, monitors agent loops with prompt and tool-call context, and blocks prompt injection, data exfiltration and malicious shell execution on the device.
A quote from Cohere's Head of Security references Operant's Woodpecker, described as open-source red teaming for testing AI applications.
Operant AI announced a $10 million Series A co-led by SineWave Ventures and Felicis, with participation from Alumni Ventures, Massive, Calm Ventures, Gaingels and industry-expert angels, bringing total funding to $13.5 million. Proceeds were earmarked for team and product expansion.
$10M source ↗
Patricia Muoio, partner at SineWave Ventures and former NSA/DoD leader, and Nancy Wang, Venture Partner at Felicis and former GM/Director of Data Protection at AWS, joined Operant AI's Board of Directors in connection with the Series A.
Operant AI's capabilities were recognized in Gartner's 2024 API Threat Protection Market Guide, Gartner's Emerging Tech Kubernetes Runtime Security Report, and Forrester's 2024 Zero Trust Landscape.
Ashley Roof joined co-founders Vrajesh Bhavsar and Priyanka Tembey as a co-founder and CMO in 2021, bringing go-to-market experience from Google and other tech startups.
Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.
In the news
▸Research sources · 8
primary sources listed
- Operant AIoperant.ai · web
8 public sources were cited for this profile; the first-party ones are listed here.
Frequently asked questions
- What does Operant AI do?
- Operant AI sells a runtime protection platform that discovers, detects and blocks attacks across AI, APIs, cloud and endpoints.
- Who founded Operant AI?
- Operant AI was founded by Vrajesh, Priyanka, Ashley, Priyanka Tembey, Vrajesh B.
- Who are Operant AI's investors?
- Operant AI's investors include Beat Ventures, Felicis Ventures, SINEWAVE VENTURES, Calm Ventures, Gaingels, Massive, The Fund.
- How much funding has Operant AI raised?
- Operant AI has disclosed $10M raised across 1 of its 3 known rounds.
- Where is Operant AI headquartered?
- Operant AI is headquartered in San Francisco, US.


__Twitter.png)






