
16 Sep 2026
OX Security ships OX Cloud — AIDR for AI agents in the cloud
OX Security’s company newsroom and PR Newswire said it launched OX Cloud, a cloud security product built for risks from AI agents that access data, call tools, and act in production. The company says OX Cloud is available now to existing and new customers; AI-native pieces include AIDR (AI Detection and Response) and Agentic Attack Surface Management (AASM).
SAFETY desk — same-day company primary that a cloud/AppSec vendor put an AI-agent-aware cloud security product (AIDR + agentic attack-surface inventory) into available-now status as enterprises run agents with tool and data access in production clouds.
Availability, company: “OX Cloud is available now to existing and new OX Security customers.” File that available-now / existing-and-new line as OX Security’s. This desk did not open a customer account. The release does not print a list price. This desk is not inventing one.
AI-native capabilities named on the same wire, still company: AIDR — AI Detection and Response — detects and governs AI activity across cloud and runtime environments in real time. AASM — Agentic Attack Surface Management — discovers AI agents, models, MCP servers, and non-human identities and maps what they can reach, exposing hidden access and risky behavior. MCP here means Model Context Protocol servers — the tool doors an agent can call. A non-human identity is a machine account, not a person. File that AIDR / AASM / agents-models-MCP picture as OX Security’s. This desk did not inventory an agent or watch a runtime session. Do not confuse this AIDR with eSentire’s already-filed Atlas AIDR — that is a different company and a different product.
CNAPP coverage, company: OX Cloud also provides what the company calls modern CNAPP coverage — Cloud Security Posture Management (CSPM), Kubernetes Security Posture Management (KSPM), Data Security Posture Management (DSPM), runtime vulnerability detection, cloud inventory, and graph-based attack path analysis — with reachability-based prioritization that filters out risks that cannot actually be reached. Alerts, the company says, open into evidence showing who or what acted, what they touched, and what else they could have reached. CNAPP is a cloud-native application protection platform — the usual cloud misconfiguration, vulnerability, and posture stack. File that CNAPP / reachability / evidence picture as OX Security’s. This desk did not open an alert or walk an attack path.
Problem framing, as OX Security tells it: cloud environments no longer just run infrastructure — they run agents. Traditional cloud security can see misconfigurations, vulnerabilities, exposed assets, and excessive permissions. It does not tell a team what an AI agent is actually doing: an agent can call a tool it should not, a model can touch data it should not, or an MCP server can operate outside its intended scope. File that infrastructure-vs-what-the-agent-is-doing picture as OX Security’s. This desk did not sit with a cloud security team.
Named voice on the release: Neatsun Ziv, cofounder and CEO of OX Security. He says traditional cloud security was built to understand infrastructure — what is running, how it is configured, and where it is vulnerable — and that once AI can call tools, access data, and take actions, knowing what exists is no longer enough: teams need to know what it is doing. File the name, title, and that infrastructure-vs-what-it-is-doing line as his, via OX Security. His other quotes are color only and stay in Sources.
Context only, not today’s dateline: OX previously described OX Cloud as part of its July 2026 AINAPP / prompt-to-runtime platform. AINAPP is the company’s name for an AI-native application protection platform — prompt-to-runtime meaning from the instruction an agent is given through to the action it takes in production. Today’s wire is the dated company launch that frames AIDR and AASM and says OX Cloud is available now as agentic cloud security. Do not date this filing as that earlier July platform describe. This filing is the 16 Sep 2026 available-now launch only.
About-box context, optional and company-attributed: OX Security calls itself the first AI-native application security platform built to secure software from prompt to production runtime. The about box names VibeSec, OX Code, OX Cloud, and OX Agentic Pentester as parts of that platform. File those names and the “first” line as OX Security’s about-box — company positioning, not a desk ranking. This desk is not inventing named customers, annual recurring revenue, or independent usage metrics.
Plain English for the rest of the card: AIDR = watch what AI agents and models are doing in the cloud and flag when they cross intended boundaries. AASM = an inventory of agents, models, and MCP servers and what they can reach. MCP = Model Context Protocol servers that give agents tool access. CNAPP = cloud-native application protection platform, the usual cloud misconfig / vulnerability / posture stack. CSPM / KSPM / DSPM = posture management for cloud accounts, Kubernetes clusters, and data. non-human identity = a machine account, not a person. reachability = whether an attacker or an agent can actually get to a risk. GA / available now = offered to existing and new customers now, not a beta or a 2027 preview.
PRIMARY here: OX Security’s 16 Sep 2026 PR Newswire company release — Tier A PRIMARY company source, the original record — plus the same-day company blog carrying the same originating text. The ox.security/ox-cloud product page is product-home context, not a second originating newsroom. The OX Cloud launch, the available-now / existing-and-new-customers line, AIDR (AI Detection and Response) and AASM (Agentic Attack Surface Management), visibility into AI agents, models, and MCP servers, the CNAPP / CSPM / KSPM / DSPM / runtime-vulnerability / cloud-inventory / graph-based-attack-path coverage, reachability-based prioritization, the Ziv title and infrastructure-vs-what-it-is-doing line, July 2026 AINAPP / prompt-to-runtime as earlier context — not today’s dateline — and the VibeSec / OX Code / OX Agentic Pentester about-box names are company-attributed. Product claims stay company-attributed — not independently audited here. NOT claimed: list prices, independent penetration-test scores, named new customers, ARR, that OX Cloud stops all rogue agents, that this desk tested OX Cloud, a stock tip, or investment advice. Distinct from the already-filed pindrop-botstopper, archer-evolv-ai-compliance, cloneguard-private-ai, esentire-atlas-aidr (do not confuse OX Cloud AIDR with eSentire Atlas AIDR), postman-passport-ga, digicert-ai-trust-manager, and wso2-agent-manager-ga.
RELATED
- Pindrop ships BotStopper — detect AI voice agents on the call line
- Archer ships Evolv AI Compliance so Bedrock guardrails enforce policy before the model answers
- Clone Systems rebuilds CloneGuard with private AI that ranks what to fix first
- eSentire buys stealth AI security startup, ships Atlas AIDR
- DigiCert launches AI Trust Manager with agent passports and a kill switch
- WSO2 ships Agent Manager GA to govern enterprise AI agents without locking to one stack
- Postman ships Passport GA so AI agents can call APIs without holding real secrets
On 16 Sep 2026 OX Security said it launched OX Cloud, a next-generation cloud security solution built for the agentic era — risks from AI agents operating in the cloud with identities and permissions, accessing data, calling tools, and taking actions. The company PRIMARY is OX Security’s PR Newswire release “OX Security Launches OX Cloud, Redefining Cloud Security for the Agentic Era,” dated September 16, 2026, 07:05 ET, SOURCE OX Security, and datelined NEW YORK. The same-day company blog carries the same originating text. That company wire is the filing event. These are company claims. This desk did not run OX Cloud.