Onyx vs Neo: Runtime Agent Control Plane vs Agentic Software Control
Choose Onyx when agent steps need runtime inspection, session replay, and policy approval before they take effect. Choose Neo when SecOps needs inventory plus native enforcement across agents, AI apps, browsers, identities, and MCP.
Choose Onyx when the buying committee needs a Secure AI Control Plane that discovers agents, models, and MCP tools, then inspects prompts, tool calls, and actions with session replay and policy that can approve, redirect, or block a step before it lands. Choose Neo when the seat is an agentic-software control layer: continuous inventory of AI agents, AI-enabled applications, browsers, identities, and MCP servers, with attribution and native enforcement on the endpoint.
Between these two, Onyx productizes runtime governance of what an agent is about to do. Neo productizes breadth across the agentic software surface so SecOps can see what is running and enforce policy without handing the block to another tool. Shared "agent control" language does not make them one interchangeable buy.
Related AI security coverage lives under AI Security; the compare index is at Compare.
| Job | Secure AI Control Plane: discover agents/models/MCP; runtime inspect; session replay; policy enforce | Agentic software control: inventory agents, AI apps, browsers, identities, MCP; native enforcement |
|---|---|---|
| How a risk closes | Guardian-style inspection of agent reasoning and tool calls; approve, redirect, or block before effect; replay sessions for forensics | Discover and score agentic assets; attribute actions to human/agent/app; enforce tool calls, data movement, and workflows natively |
| CI fail | Not a classic PR SAST gate; runtime and gateway policy on agent steps and MCP traffic | Not a classic PR SAST gate; inventory posture and native blocks feed SecOps queues |
| Deploy | Browser, endpoint, SaaS, and cloud surfaces; cloud, hybrid, or self-hosted; demo-gated | Endpoint-oriented sensor and control layer across agentic software; demo-gated |
| License/pricing | Talk with / demo; no public dollar SKU (checked 5 Sep 2026) | Get a Demo; no public dollar SKU (checked 5 Sep 2026) |
| Who operates it | CISO and AI security owning runtime agent governance and session audit | SecOps owning agentic software inventory, attribution, and native policy |
Funding marks parallel 2026 control-plane bets rather than erase the job split. On 29 July 2026 Onyx announced a $113M Series B led by Bessemer Venture Partners, bringing total funding to $153M after an earlier $40M stealth launch for the Secure AI Control Plane. On 20 July 2026 Neo emerged from stealth with $100M from Andreessen Horowitz and Bessemer Venture Partners to build a real-time control layer for agentic software.
That specification gap is why both products talk policy. Between these two, ask whether the first win is step-level runtime approval with replay (Onyx) or estate-wide inventory with native blocks across apps and browsers (Neo).
We reviewed first-party documentation, funding notices, product pages, and live community threads. We did not test the products in paid production environments, so this is not a hands-on benchmark.
Onyx Security

Neo

Editions and pricing
Neither publishes a self-serve dollar table. Both route buyers to demo or talk-to-sales paths. Onyx is a Series B Secure AI Control Plane company with $153M total capital after the July 2026 round. Neo launched with $100M from a16z and Bessemer as an agentic software control company. Funding is a durability signal, not proof the products compete for the same seat.
| Owner (2026) | Independent. Secure AI Control Plane; CEO Maxim Bar Kogan; TLV and New York | Independent. Agentic Software Control; CEO Nick Warner; Boston launch |
|---|---|---|
| How you buy it now | Talk with / demo; no public dollar SKU (checked 5 Sep 2026) | Get a Demo; no public dollar SKU (checked 5 Sep 2026) |
| Public units | No public self-serve dollar SKU | No public self-serve dollar SKU |
| Funding signal | $40M stealth then $113M Series B Bessemer; $153M total (Jul 2026 first-party) | $100M from a16z and Bessemer at launch; Craft and Merlin participating (Jul 2026) |
If procurement needs a published monthly number before a call, neither page ships one today. POC design should start from the job: runtime step control versus inventory-plus-native enforcement breadth.
Runtime control plane and step approval
| Primary surface | Inline inspection of prompts, responses, and agent actions; session replay and audit trail | Real-time attribution and policy on tool calls, API access, data movement, and agentic workflows |
|---|---|---|
| Step decision | Approve, redirect, or block before the action takes effect; natural-language policies | Block risky activity, malicious models, or pause for review; native enforcement without a handoff product |
| MCP and models | Discover MCP servers and models; proxy MCP traffic with guardrails; governed routing | MCP servers appear inside Neoverse inventory and capability intelligence alongside agents and apps |
| What teams argue about | Whether step-level control plane depth is the seat when estate inventory already exists | Whether native endpoint enforcement covers the same session-replay and Guardian-style step story |
Between these two, do not buy a shared "runtime" checkbox. Buy the operating surface: Onyx when every agent step needs inspect-and-decide with replay; Neo when policy must fire natively across a wide agentic software inventory.
Inventory and native enforcement across agentic software
| Discovery breadth | Agents, models, MCP tools, copilots, and embedded AI across SaaS, cloud, endpoint, and code | AI agents, AI-enabled apps, plugins, extensions, MCP servers, and traditional software becoming agentic |
|---|---|---|
| Intelligence layer | Risk scoring, shadow AI, posture, and ROI dashboards beside the control plane | Neoverse knowledge base of agentic capabilities, risks, and behaviors; posture and configuration safety |
| Enforcement path | Control plane and gateway path that governs the actor where it lives | Endpoint-native enforcement marketed as true block, not only a report after the fact |
| What teams argue about | Whether control-plane discovery is enough without an endpoint inventory of every agentic app | Whether inventory-plus-native blocks replace a dedicated Secure AI Control Plane for step replay |
Between these two, Neo owns the wider agentic-software estate story. Onyx stays centered on runtime governance of agent actors even when discovery covers MCP and models.
Where they overlap
Both sell agent control. Both talk MCP, policy, and real-time enforcement. Both raised large 2026 rounds with Bessemer on the cap table. Overlap is category timing and shared vocabulary, not identical product centers. Treating them as interchangeable duplicates spend without covering both jobs.
When to use both
Running both can be honest when jobs stay separate: Onyx for step-level runtime approval and session replay on production agents, Neo for inventory and native enforcement across browsers, AI-enabled apps, identities, and MCP sprawl. Keep ownership clear so two policy engines do not fight the same ticket.
Skip Neo for this pair if the urgent buy is a Secure AI Control Plane for inspect-and-approve agent steps and estate inventory already has an owner. Skip Onyx for this pair if the buying committee standardized on one agentic-software control layer with native endpoint enforcement and step replay is only a checkbox inside that suite.
Decide the job first. If the product must govern agent steps at runtime with replay and policy approval, that is Onyx. If the product must inventory agentic software and enforce natively across the estate, that is Neo. Only then book the demos.
FAQs
Are Onyx and Neo the same agent security product?
No. Both touch agents, MCP, and policy language, but between these two Onyx leads with a Secure AI Control Plane for runtime step governance and session replay, and Neo leads with inventory plus native enforcement across agentic software surfaces.
Do either publish list prices?
No public self-serve dollar SKUs on either first-party site as of 5 Sep 2026. Both route to demo or talk-to-sales.
What funding should buyers note?
Onyx raised $113M Series B in Jul 2026 led by Bessemer, bringing total funding to $153M after a $40M stealth launch. Neo launched Jul 2026 with $100M from a16z and Bessemer. Funding is relevant for roadmap durability; it does not make the jobs identical.
Is Neo at neo.security?
No. First-party site is neo.ai.
Is this a scored bake-off?
No. Order is editorial.