← DIRECTORY
AI TOOL

AIR

Enterprise context firewall and governance platform for AI agents, covering agent discovery, add-on vetting, runtime action protection and a vetted marketplace for skills/plugins/MCPs.

7.6OUT OF 10

Product facts

Category
Pricing
No public self-serve price verified; current AIR access is demo/contact-sales, with AWS Marketplace as an enterprise procurement route.
Free access
NO
Platforms
Web, Enterprise infrastructure
API
Not confirmed
Open source
NO
Integrations
Not confirmed
Last updated
2026-09-01
PRODUCT / PRICING SOURCE ↗

AIR review

Updated 2026-09-01

Product & capabilities

Product & capabilities

AIR is an enterprise security platform built around a specific new attack surface: the skills, plugins, MCP servers, sub-agents, websites and data sources that autonomous AI agents can ingest or act through. Its current product is organized into four modules. AIR Control discovers agents and governs configuration, identity and permissions; AIR Filter vets add-ons before installation and as they change; AIR Defend monitors and protects runtime actions; AIR Marketplace provides a source of pre-vetted external and internally approved add-ons. 1

The useful distinction is that AIR is not only a static package scanner. Its core product claim is continuous re-verification: an add-on that was safe when approved can later fetch different instructions, change ownership or depend on a compromised resource. TechCrunch independently describes that positioning and reports that AIR emerged from stealth with more than 20 customers. 2

AIR also exposes a public add-on scanner, but the broader enterprise proposition is fleet governance rather than one-off file checking. The platform is meant to sit between agents and external context so policy can apply before untrusted material reaches an agent and while the agent takes actions. 1

Current integrations show how that control plane can work. AIR’s Anthropic Compliance API integration uses read-only access to organization governance, usage and audit records and explicitly says it does not read prompt or response content; the signals feed posture and runtime policy. AIR also lists an AWS Marketplace procurement route for enterprise deployment. 34

Pricing & access

Pricing & access

AIR is currently sales-led. The primary public CTA is “Book a Demo,” and no stable self-service monetary plan is published on the current product surface. AiToolMap therefore does not invent a per-seat or platform price. 1

The AWS Marketplace route gives enterprises another procurement path, but it does not make the public economics transparent enough to normalize a recurring price. Funding coverage is also not a proxy for customer pricing. 42

For buyers, total cost is likely to depend on fleet size, deployment scope, integrations and which Control/Filter/Defend/Marketplace capabilities are contracted. That makes proof-of-value testing especially important: a security layer can be valuable even at a high contract price if it blocks consequential agent-supply-chain risk, but current public information does not let AiToolMap quantify that trade-off.

Evidence & trust

Evidence & trust

AIR launched into a real and fast-moving problem. Independent TechCrunch and Calcalist reporting corroborate the company, funding and agent-security positioning rather than relying only on AIR’s own launch copy. TechCrunch reports $50 million raised across two seed rounds and more than 20 customers, while Calcalist independently covers the same company and product category. 25

The evidence for defensive efficacy is thinner. AIR publishes research about malicious skills, MCP hijacking and scanner blind spots, but those vulnerability counts and claims remain provider research unless independently reproduced. Resilient Cyber’s June practitioner newsletter separately discussed AIR researchers’ malicious-skill demonstration and used it to illustrate time-of-check/time-of-use risk in the agent supply chain; that is useful independent context, not a replication of AIR’s results. 6

The fixed 50-source panel found one current independent exact-product editorial source, TechCrunch, but no eligible exact numeric user-rating family. An App Store search produced unrelated products and was explicitly excluded; several major sources were inaccessible and the remainder produced no attributable current exact-product result. Missing evidence is not scored as zero.

AIR’s Anthropic integration has a useful least-privilege property: the documented connector is read-only for administrative/compliance metadata and says it does not access prompts or responses, while stored API credentials are encrypted and can be rotated or revoked. These are first-party architectural claims and should be verified in a customer security review before deployment. 3

The central governance question is blast radius. AIR itself becomes part of the control path for systems that can act on enterprise data and applications. Buyers should therefore verify tenant isolation, credential handling, audit completeness, failure modes, incident response, policy override controls and the behavior of Defend when AIR itself or an upstream integration is unavailable.

Who it's for

Who it's for

AIR is most relevant to organizations that have moved beyond a few isolated copilots and now operate many agents, plugins, skills or MCP servers across departments. Security, identity and AI-platform teams need a way to discover those components, distinguish sanctioned from shadow agents and apply policy to what agents can ingest and do. 1

It is especially relevant where add-ons change independently of the core model. Traditional application allowlisting is not enough if an approved skill later references a hostile domain or if an MCP server changes after initial review. AIR’s continuous-vetting design is aimed at that gap. 26

It is less compelling for a small team with a tightly controlled set of agents and no meaningful third-party add-on ecosystem. Without public pricing, such teams cannot easily determine whether the platform is economical relative to simpler network, identity and manual review controls.

Organizations evaluating AIR should test it against their own agent stack rather than rely on provider attack demonstrations: malicious instruction updates, compromised MCP dependencies, over-permissioned identities, prompt-injection paths, data-exfiltration attempts and false-positive behavior under normal operations.

Strengths & weaknesses

Strengths

AIR’s strongest feature is architectural coherence. Discovery, pre-install vetting, continuous context filtering, runtime policy and a vetted marketplace cover different points in the same agent-supply-chain lifecycle rather than treating prompt injection as only a model problem. 1

A second strength is the early integration direction. Read-only Anthropic governance telemetry and AWS Marketplace procurement make the platform easier to fit into enterprise control and purchasing workflows without requiring prompt-content access for the documented Anthropic connector. 34

The weaknesses are maturity and evidence. AIR is newly out of stealth; independent exact-product coverage is sparse; there is no eligible numeric user-rating family; and provider security research is not the same thing as independent proof that AIR will detect the same classes of attack reliably in customer environments. 26

Pricing is another weakness because it is entirely sales-led in the current public surface. Enterprises can tolerate custom pricing when the governance problem is important enough, but public comparison and value normalization remain difficult. 1

Overall, AIR earns 7.6/10 as a credible, well-scoped answer to agent context and add-on risk, not as a proven category winner. The rating is LOW-confidence and not rank-eligible because the external evidence layer is qualitative only and the product has a short operating history.

Weaknesses

Not separately stated in the source review.

SOURCES

Sources & references

6 sources
  1. Official sourceAIR — The Context Firewall for AI Agents
    OFFICIAL
  2. TechCrunchTechCrunch — AIR raises $50M to help companies vet AI-agent skills and add-ons
    NEWS2026-09-01
  3. Official sourceAIR — Anthropic Compliance API integration
    OFFICIAL2026-06-01
  4. Official sourceAIR and AWS Marketplace
    OFFICIAL2026-08-19
  5. SourceCalcalist — AIR raises $50M for AI-agent security
    NEWS2026-09-01
  6. SourceResilient Cyber Newsletter #103
    EXPERT ANALYSIS2026-06-25
MAJORAIR emerged from stealth on 2026-09-01 with a context-firewall platform for AI agents and $50M seed funding.

News & updates about AIR

Recent AiToolMap coverage linked to this product.

Related AI tools

Products matched by shared tasks, audience, workflow, product type and capabilities.