Exaforce Expands Beyond the SOC Into AI Security: Runtime Visibility and Control of AI Agents and Applications, From Endpoint to Cloud

Exaforce, the pioneer in agentic security operations, today announced Exaforce AI Security, a new capability on its Exaforce platform that gives security teams visibility and control over the AI agents and agentic applications operating across their environments. Exaforce AI Security connects each agent and app to the human behind it, the device it runs on, the permissions it has and the actions it takes, helping security teams identify risk and misuse, detect threats and respond in real time. When an agent becomes a threat, Exaforce can stop it with an agent kill switch. There is no new endpoint agent, browser extension, or gateway to deploy.

AI and agentic apps are hard to catalog, attribute, and secure. They are everywhere, hosted with a provider or running on a laptop, living as skills in code repositories and as MCP servers on devices. They replicate quickly; any employee can deploy a new agentic app, and so can an agent. They assume human identities and OAuth tokens, so deciphering agent activity from human activity in standard audit logs is guesswork. And they act fast, with the ability to rotate a key, merge a pull request and, with the right permissions, perform almost any activity a human can. Each action can look legitimate on its own but a series of them may not be.

“Everyone is struggling to rapidly identify and secure the adoption of AI apps & agents in the enterprise. Existing tooling was not built to rapidly ascertain AI adoption against its risks, and existing SaaS and endpoint security tooling,” said Ankur Singla, Co-Founder and CEO of Exaforce. “Security teams need AI activity to land where identity, cloud, and endpoint data exist because they are interconnected and they need it without rolling out one more agent. We use that same data to comprehensively address this new threat surface.”

In June 2026, attackers compromised Klue, an AI-powered competitive-intelligence app, and used its customers’ own OAuth tokens to pull data from their Salesforce environments. Stolen OAuth tokens for Salesloft’s Drift chatbot were used the same way at more than 700 organizations in August 2025. The Nx “s1ngularity” npm attack similarly demonstrated how attackers can turn developers’ own AI coding agents against them, using Claude Code, Gemini CLI and Amazon Q Developer to hunt for credentials.

“AI agents are creating a new operating problem for the SOC: software can now act with human identities, permissions and authority, while operating at machine speed. The security challenge therefore moves beyond simply discovering agents toward understanding behavioral intent and enforcement. In our coverage, Exaforce is the first agentic SOC vendor correlating SOC with AI activity across identity, endpoint, cloud and code context. This is directionally important because this is where agent security and traditional security operations increasingly converge.” – Francis Odum, Founder & CEO, Software Analyst Cyber Research

Exaforce AI Security extends the Claude Compliance API integration Exaforce shipped in June 2026, adding other model providers (OpenAI, Gemini and Microsoft Copilot), OAuth-connected AI apps, and endpoint context, so the team that owns AI security and the team that runs the SOC work from one platform, through five capabilities:

  • Agentless Visibility. A continuous inventory covers the AI apps connected to company accounts, coding agents such as Claude Code and Cursor, hosted agents such as custom GPTs, MCP servers, skills, and IDE plugins, tied to the people and permissions behind them. Visibility includes chats and prompts which are classified as personal or business use ensuring adherence to usage policies.

  • Risks. Every agent, skill, MCP server, and plugin is scored for risk and paired with a recommended fix, so teams can close the most serious exposures, from excessive permissions to unvetted MCP servers, before an attacker finds them.

  • Governance: Enforce governance for safe AI use. Define which AI apps, agents, and models are sanctioned, and for whom, and apply them as rules through the identity, endpoint, and model-provider controls already in place.

  • Threat Detection. Correlate the actions of agents, agentic apps, and prompts with human identities, endpoint data, file access, and code context to derive intent and detect misuse, sensitive-data exposure, and active threats, including threats that may appear legitimate when individual actions are viewed in isolation.

  • Threat Containment. Exaforce contains detected threats before they cause damage: revoking a session, deactivating a model-provider API key, isolating a device, or ending an agent’s process, the agent kill switch, all through existing EDR, identity, and model-provider controls. Teams set each action’s autonomy, from analyst-approved to fully autonomous.

  • Usage monitoring. Visibility into token usage by users across the organization and anomaly detection to identify runaway AI token use, exploitation or misuse.

Under the hood, AI Security ingests endpoint data from EDR, audit and usage logs from model providers, and activity from productivity suites into the Exaforce knowledge graph, alongside the identity, cloud, SaaS, and code data the platform already ingests and correlates. By connecting these sources, Exaforce gives security teams a contextual view of what an AI agent is doing, who is behind it, what it can access and whether its behavior represents a threat, without requiring them to deploy another security tool.

“Exaforce’s entry into agent observability and control is a key development for SOC operations, moving them further toward the critical aspects of machine-vs-machine automation and defense.” – Lawrence Pingree, Head of Research, SACR

Exaforce AI Security is generally available today on the Exaforce Agentic SOC platform, self-operated or through Exaforce MDR. Learn more at https://www.exaforce.com/blogs/introducing-ai-security or request a demo at www.exaforce.com.

About Exaforce

Exaforce is the pioneer in agentic security operations. Its AI-native platform combines a real-time security knowledge graph with AI agents (Exabots). It is supported by an MDR service that helps teams detect, triage, investigate, and respond to threats at machine speed. Backed by $200 million in total funding from HarbourVest, Peak XV, Mayfield, Khosla Ventures, and Seligman Ventures, Exaforce serves security teams at enterprises across healthcare, technology, financial services, and other high-target industries. The company is headquartered in the Bay Area with a growing global presence. Learn more at www.exaforce.com.

Media gallery