Cequence Security, Inc - Experts & Thought Leaders

Latest Cequence Security, Inc news & announcements

Agentic AI: Cequence Tackles Enterprise Security Risks

Nearly every enterprise believes its AI agents are properly scoped but only a third have actually made sure of it. New research from Cequence Security, the pioneer in application, API, and agentic AI protection, and Enterprise Management Associates (EMA) found that 94% of enterprise IT and security leaders are confident their AI agents do not have more access than they need, yet only 33% actually provision agents with least-privilege access. The remaining two-thirds run on broad standing permissions that are reviewed periodically, rarely reviewed, or never reviewed at all. The full report, Agents Without Guardrails: The Agentic AI Governance Gap in the Enterprise, is available for download now. Broad standing permissions The gap between confidence and practice is already showing up in production, not as a theoretical risk, but as incidents enterprises are living with right now. Among the organizations surveyed: 65% have experienced an AI agent take an action outside its intended scope, including 29% with measurable business impact such as data exposure, financial loss, operational disruption, or reputational damage. Another 36% caught a near-miss before it caused damage. Only 32% can detect and contain an out-of-scope agent action within minutes through automated means; 55% need hours and manual steps to respond. In approximately 4% of the organizations surveyed, the first sign of trouble came from a customer or outside partner, not an internal system. Customer-facing applications The findings point to one clear story. Governance has not kept pace with the speed of agentic AI deployment, and that gap is showing up at every stage of the agent lifecycle, from how agents are provisioned, to how their actions are authorized, to how they are decommissioned once a pilot ends. Other key findings from the report include: The scale of deployment makes the gap more urgent. 46% of organizations report they are already scaling agentic AI across multiple departments and production workflows, and 79% are running generative and agentic AI simultaneously. Further, more than 92% report an increase in AI and bot-driven traffic targeting customer-facing applications and APIs. That governance gap extends to how access is enforced the moment an agent acts. Only 34% of organizations evaluate an AI agent's authorization at the moment it attempts a specific action. The majority rely on periodic policy reviews or standing permissions set once at provisioning and never revisited, meaning an agent's access can quietly outlive the task it was originally granted for, and keep working long after anyone signed off on it. Additionally, there’s an increasing risk in how enterprises manage agents that don't make it to production. 31% of agentic AI pilots have been paused indefinitely, discontinued, or abandoned. Many were real deployments with real system access and credentials that were never cleaned up. Every abandoned pilot with live credentials is an exposure nobody is actively watching. 14% of organizations allow AI agents to connect to outside tools and data sources via the Model Context Protocol (MCP) without restriction. Among the majority who do limit those connections to an approved list, fewer than half (49%) have a dedicated team actively maintaining and auditing that list on a regular basis. Well past experimentation Christopher M. Steffen, CISSP, CISA, VP of Research at EMA, said: “This research shows enterprises have moved well past experimentation with agentic AI right into production and governance has not kept pace with that shift. The gap isn’t a lack of awareness; most organizations have policies in place and express real confidence in them. The gap is between what’s written down and what’s enforced when an agent takes an action nobody approved. That disconnect shows up most clearly in how organizations authorize agent actions and monitor them once they’re live, and it’s the reason incidents are happening at a rate the industry hasn’t fully reckoned with.” Shreyans Mehta, Co-founder and CTO at Cequence, said: “The number that jumped out to me is the 92% being confident in their governance frameworks. Confidence like that is a trap; its exactly why organizations stop looking for problems, stop investing in monitoring, and let authorization checks lapse until an incident forces the conversation. This is the exact blind spot Cequence is built to close, giving security teams real-time visibility into what AI agents are actually doing and enforcing authorization at the moment an agent acts, not after the fact.” Join Christopher M. Steffen, Vice President of Research at EMA, and Randolph Barr, Chief Information Security Officer at Cequence, for the “Agents Without Guardrails” webinar.

Cequence AI Gateway: Enhance Agentic AI Security

Cequence Security, the pioneer in application, API, and agentic AI protection, today announced four new capabilities for AI Gateway: AI Discovery, API Registry, LLM Registry, and Skill Registry. The release also upgrades Agent Personas, which now bind an agent’s job description directly to its model, tools, access, and guardrails, all enforced automatically through policy. Together, these capabilities let any business user stand up properly secured, governed AI agents, bound to the right tools, data, and protections for their job, without needing technical experience or touching AI Gateway directly. Backend services and data With this release, Cequence becomes the first platform to close the ring around every channel an AI agent uses to communicate with the outside world. MCP governs how an agent discovers and invokes tools. LLM Registry governs every call to and from a language model. API Registry governs how it reaches backend services and data. Agent Personas bind an agent's tools, model, and API access to a single job description, enforcing that boundary as policy rather than manual review. Where other vendors address one piece of that surface, Cequence ties MCP, LLM, and API together under one agent-bound identity, an approach they call Agentic Zero Trust. Nothing an agent touches is implicitly trusted, and every action is scoped to exactly what its job requires. Sandboxed evaluation environment The stakes are no longer hypothetical. OpenAI recently disclosed that two of its models escaped a sandboxed evaluation environment, crossed the open internet, and breached Hugging Face's production infrastructure, chaining stolen credentials and a zero-day to steal a benchmark answer key. Nothing had bound those agents to a job, so nothing stopped them from inventing one. Notably absent was any binding between the agent and its assigned job. Under Cequence, that binding is the Agent Persona, and an agent's models, tools, and APIs are defined by its job description, not by what it can reach once it's loose. Hugging Face's production infrastructure was never going to be on that list, regardless of what credentials the agent got its hands on. A zero-day can still get an agent past a sandbox, but it can't get a persona-bound agent past a policy that was never written to allow it there in the first place. Agentic AI governance Agentic AI adoption has outrun agentic AI governance. Point solutions have addressed pieces of the problem, a scanner here, an API gateway there, and a prompt filter somewhere else. None of them answer the questions every security leader is now asking: which agents does the organization have, what can they reach, what actions can they take, who approved them, and how fast can they be shut down when governance guardrails are violated. Enterprises are recognizing that AI agents with access to applications and data are much more than tools. They are privileged insiders operating at machine speed and require the same governance discipline as any other privileged use inside of the business. Enterprises already secure, manage, and guide human employees whether they work from an office or remotely, and AI agents need the same standard, regardless of whether they run on managed devices or in the cloud. Same governance discipline “Most vendors look at agent governance and build another approval queue. We looked at it and built the persona instead,” said Shreyans Mehta, CTO and Co-Founder at Cequence Security. “An agent’s job should automatically determine what it can touch, without relying on a security team to manually map policy by hand every time someone wants a new use case. That’s what makes broad adoption safe and scalable, and the agent gets exactly what its job requires, and nothing more.” Cequence AI Gateway’s new and improved capabilities include: AI Discovery surfaces every agent, LLM provider, and MCP server already running across the enterprise, pulled from existing SIEM logs whether or not it went through an official process. API Registry lets agents call approved APIs without ever holding the underlying credential. Agents authenticate with a single AI Gateway access key, either through a single invocation tool for web-based agents or natively through AI Gateway’s proxied endpoints. Skill Registry gives security and platform teams a curated, governed set of capabilities to draw from, vetted once and reusable across every agent use case that needs it. Agent Personas bind an agent to a job description. That includes a curated set of tools, APIs, skills, and instructions, the specific LLM model it's approved to use, and the security guardrails that apply to it, all enforceable via policy. Relevant data protection policies apply automatically based on the persona's data surface and job function, including which LLM model it can call, since an ungoverned model is as much a risk as an unvetted API. LLM Registry governs every agent-to-LLM call the same way API Registry governs REST access, brokering credentials across major LLM providers so agents never hold a real provider API key. Built-in Data Loss Prevention inspects every prompt and response for blocked content, including base64-encoded payloads and invisible or non-approved-language Unicode characters used to evade filters. It also governs model use per team, for example defaulting to a cost-effective model while routing advanced engineering tasks to a premium one, with token-level usage visibility and enforceable rate and spend limits tied back to the agent persona driving each request. Cost-effective model “Automatic policy mapping was not possible until now, because there was nothing consistent for a policy engine to reason over," said Abraham Jeevagunta, VP of AI Products at Cequence Security. "Before API Registry and Skill Registry, every tool and API a persona could be bound to was uncatalogued, so mapping policy to persona was a manual judgment call every time. Now, that record exists and the policy engine can read it directly. It is what lets a business user stand up a correctly governed agent without ever touching AI Gateway's policy model themselves." All of these capabilities are immediately available to Cequence customers as part of AI Gateway.

Cequence's Platform 9.0: Transforming API Protection

Cequence Security, the pioneer in application, API, and agentic AI protection, announces general availability of Cequence Platform 9.0, an AI-native release that fundamentally changes how users interact with API security tools. Platform 9.0 ships with a built-in AI Assistant, an open Model Context Protocol (MCP) server that exposes every platform capability to an organization’s agents or automation workflows, a compliance-ready risk rules library mapped to 25 global regulatory frameworks, and a re-architected API security engine built to handle the largest enterprise API estates without performance degradation. Adopting AI agents Agentic AI is transforming how enterprises interact with their customers, and internal IT teams are adopting AI agents faster than their security tools can keep up. Unlike vendors that add a simple chatbot to their existing product, Cequence took the opposite approach; the entire platform is AI-native and open, enabling customers to use Cequence's built-in model or one of their choosing. With Platform 9.0, any practitioner can open a conversation and start asking the questions they actually care about, without knowing the interface, navigating menus, or understanding how the product works. The platform finds the answers. Teams with sophisticated AI workflows can use their own agents to directly drive these same capabilities through the open MCP architecture, with no custom integration required. High-traffic enterprise environments Ameya Talwalkar, CEO and Co-Founder at Cequence, said: “Most vendors looked at the agentic era and added a chatbot. We looked at it and rebuilt the architecture. Cequence Platform 9.0 exposes the entire Cequence platform through an open MCP architecture so any agent can operate it directly, whether through our built-in AI Assistant, or a customer’s own agent. That is what AI-native actually means: the UI becomes optional. We are building for the way the agentic enterprise already works, while making sure a human approves every change along the way.” Cequence Platform 9.0 ships with a built-in AI Assistant that answers plain-language questions such as “What is my biggest risk right now?” with ranked, evidence-backed findings drawn from live platform data. Unlike most security chatbots that only deliver value in the hands of experienced practitioners, the Cequence AI Assistant arrives with skills built on years of application, API, and data protection work in high-traffic enterprise environments, able to guide practitioners of all skill levels from day 1. Broader agentic workflows Agent capabilities in Platform 9.0 include: Drive valuable actions from simple conversation: use plain-English to easily and quickly drive results. The possibilities are endless. Have the AI Assistant classify APIs, identify risks, draft rules, and create reports, all without navigating the UI. Open MCP server: any MCP-capable agent, SOAR platform, or automation workflow can interact with, configure, and pull insights from the platform through an open API contract, with no custom integration, incorporating API security into broader agentic workflows. Human in the loop: read actions run freely; every proposed write shows the exact change and requires explicit human approval before anything happens. Full transparency: every answer exposes the AI Assistant’s reasoning and the underlying tool calls; when it lacks a tool for a task, it says so rather than guessing. Evidence-backed recommendations Shreyans Mehta, CTO and Co-Founder at Cequence, said: “Most security chatbots are only as useful as the person asking the questions, which means they fall flat in the hands of anyone who is not already an expert.” “We built the Platform 9.0 agent differently. It runs a full agentic loop, planning which tools answer the question, calling them, and synthesising ranked, evidence-backed recommendations while showing you exactly how it got there. When it does not have the tool to do something, it tells you instead of guessing. That governance-first design is not an afterthought. It is the same conviction behind the Cequence AI Gateway, and it is what makes this safe to put in front of any practitioner on Day 1.” Custom rule development Compliance is the most common forcing function for an API security purchase, and the most common place programs stall. Platform 9.0 ships the rules, frameworks, and reports to make customers audit-ready immediately, with no professional services and no custom rule development required. Compliance capabilities in Platform 9.0 include: 250+ pre-built risk rules: more than four times the previous version, mapped to 25 global compliance frameworks including OWASP API Security Top 10 (all versions), PCI DSS, GDPR, HIPAA, SOC 2, ISO 27001, NIST CSF, DORA, NIS2, LGPD, SAMA, MAS TRM, and additional regional frameworks across the Americas, EMEA, and APAC One-click audit-ready reports: each report builds from live data, maps findings to the framework’s specific controls, scores risk by control area, and provides remediation guidance for every gap; reports can be company or partner branded Observe mode: see how proposed rules perform for testing purposes without raising formal issues, allowing teams can add frameworks without a flood of unreviewed findings Test panel: validates any rule against sample request and response data before activation Delivering higher performance Agentic AI is accelerating API endpoint growth faster than any prior technology wave. Platform 9.0 includes a complete rebuild of the engine that discovers, catalogues, and scores risk across an organization’s API estate, delivering higher performance at a smaller CPU footprint. API security engine improvements in Platform 9.0 include: 50x increase in API endpoints supported: with sub-five-second page load times across every view regardless of endpoint count Reduced compute costs: dramatic CPU footprint improvements translate directly into lower infrastructure costs, especially for on-premise deployments Availability - Cequence Platform 9.0 is immediately available for new customers.