CNAPP was built for things that sit still. Agents do not sit still. OX just shipped the product claim for that gap.
On September 16 OX Security launched OX Cloud generally available — framed as cloud security for the agentic era. Per the company PR Newswire release: OX Cloud is designed for active, dynamic risks from AI agents that access data, call tools, and take action. Headline capabilities: full CNAPP coverage plus AI Detection and Response (AIDR) and Agentic Attack Surface Management (AASM). Valuation: Undisclosed. Prior funding totals do not set a mark. CyberMerge underwrites the GA and the capability claims as company disclosures — not a priced round.
The product argument, from OX: traditional cloud security shows misconfigurations, vulnerabilities, exposed assets, and excessive permissions. It does not tell teams what an AI agent is actually doing. An agent can call a tool it should not; a model can touch data it should not; an MCP server can operate outside intended scope. AIDR detects and governs AI activity across cloud and runtime in real time. AASM discovers AI agents, models, MCP servers, and non-human identities and maps what they can reach.
CNAPP stack inside OX Cloud, per PR: Cloud Security Posture Management (CSPM), Kubernetes Security Posture Management (KSPM), Data Security Posture Management (DSPM), runtime vulnerability detection, cloud inventory, and graph-based attack path analysis. Reachability-based prioritization filters risks that cannot actually be reached; alerts open into evidence of who or what acted, what they touched, and what else they could have reached. Availability: now, for existing and new OX Security customers (company).
OX’s own product blog (Sep 16) places OX Cloud as the runtime pillar of what it calls the OX AINAPP (AI Native Application Protection Platform), alongside VibeSec, OX Code, and OX Agentic Pentester in the About framing. The blog’s contrast table is the sharpest claim: most CNAPPs run periodic/batch posture; AI add-ons bolt inventory onto the same pile; OX Cloud aims for continuous inventory plus real-time detection on live infrastructure, with reachability cutting unreachable noise. Treat that as vendor POV, not a third-party bake-off.
CEO Neatsun Ziv, via the PR: “Cloud security was built to understand infrastructure – what’s running, how it’s configured and where it’s vulnerable. But AI agents don’t just sit in your environment. They act… Once AI can call tools, access data and take actions autonomously, knowing what exists is no longer enough. Security teams need to know what it’s doing.”
POV: Every CNAPP vendor will ship an “AI agents” slide this cycle. The underwrite question is narrower — does combining CSPM/KSPM/DSPM with live AIDR and AASM on agents, models, MCP, and NHIs change buyer RFPs, or does it become another inventory list next to the existing CNAPP? Shadow AI and unmanaged non-human identities are the buyer pain OX is selling into. GA is real (company Sep 16). Valuation stays Undisclosed. Prior funding totals are not a valuation. Sources: OX / PR Newswire Sep 16 and OX Security blog Sep 16.
Underwrite sheet — sourced only: OX Cloud GA Sep 16, 2026 (PR Newswire); CNAPP + AIDR + AASM; visibility into AI agents, models, MCP servers, NHIs; CSPM/KSPM/DSPM + runtime vuln + inventory + graph attack paths; reachability prioritization; available now to existing/new customers; OX AINAPP runtime pillar (company blog); valuation Undisclosed. CNAPP for agents that act — product claim or category slide? Underwrite the GA. Leave the mark blank.
