Koi (Palo Alto Networks)
Agentic Endpoint Security — discover, assess, and govern all non-binary software including AI agents, MCP servers, extensions, and packages.
What it does
The pioneer of Agentic Endpoint Security. Koi provides full visibility, risk assessment, and policy enforcement for all non-binary software on enterprise endpoints — AI agents, MCP servers, browser extensions, code packages, AI models, and containers. The Wings AI risk engine scans actual code (not just reputation), correlating code diffs, runtime behavior, ownership changes, and update channels to detect malware, impersonation, and policy drift. 500k+ endpoints protected across Fortune 50 companies. Being acquired by Palo Alto Networks (announced Feb 2026) for integration into Prisma AIRS and Cortex XDR.
Security relevance
Traditional EDR tools are blind to non-binary software — the dominant attack surface on modern endpoints. Koi fills this gap by inventorying every extension, package, MCP server, and AI agent the moment it appears, assessing risk with LLM-powered code analysis, and enforcing policies automatically. The Supply Chain Gateway blocks risky installs before they reach endpoints. Agentless deployment means no endpoint agent required.
When to use it
Deploy when AI agents and MCP servers are proliferating across developer endpoints and you need visibility and governance. Particularly relevant as agents gain tool-use capabilities that bypass traditional security controls. Enterprise platform requiring procurement and policy configuration. The Palo Alto Networks acquisition signals deep integration with Prisma AIRS and Cortex XDR.
OWASP coverage
Risks addressed — mapped to both OWASP Top 10 standards. 4 in LLM, 3 in Agentic.
The raw record
What Yuntona stores. Single source of truth — fork it on GitHub.
name: Koi (Palo Alto Networks) slug: koi-palo-alto-networks type: Mixed category: AI Guardrails & Firewalls url: https://www.koi.ai reviewed: 2026-04 added: 2026-04 updated: 2026-04 risks: llm: [LLM03, LLM05, LLM07, LLM08] asi: [ASI01, ASI02, ASI04] complexity: Enterprise Only pricing: — audience: Blue Team lifecycle: [govern] tags: [Agentic, Endpoint, Enterprise, MCP, Shadow AI, Supply Chain]