Skip to content
MoorAI
// moorai vs above security

MoorAI vs Above Security

Last updated

Above investigates people and the AI they use. MoorAI decides what a coding agent may do on the machine. Above describes itself as “Above Security is an AI-native managed insider-threat platform for proactive risk management that just works.” (above.security/about-us) Its AI investigative agents turn signals into finished cases: “Above's AI agents investigate every signal the moment it appears — and hand your team a finished case, not a queue of alerts to work.” (above.security/platform/ai-investigative-agents) MoorAI is a PreToolUse hook inside the coding agent and an MCP stdio proxy in front of local Model Context Protocol (MCP) servers, deciding before the command, the file read or the MCP call runs.

The two are mostly complementary, and Above’s own material draws the line in the same place. In a joint brief with CrowdStrike, Above writes: “Falcon Guardian secures the agent at the endpoint. Above investigates the human intent behind it, and turns the signal into a resolved case.” and “Guardian contains the hijacked agent at runtime. Above rebuilds who deployed it and what it could reach.” (Above × CrowdStrike, Better Together brief) Runtime control of the agent on the endpoint is the layer MoorAI works at. Investigation of the person behind it, across the rest of the business, is the layer Above works at.

Above covers far more of the company than MoorAI does. Departing employees, data staging, email and SaaS, OAuth grants to third-party AI agents, HR and legal case handling, and connectors across identity, endpoint, cloud and HR systems. MoorAI covers the AI agents on developer machines. The rows where Above covers more ground are further down, and that list is the longer one.

Three things this page does not state. (1) Above’s Claude Code OpenTelemetry path. Above’s Claude integration guide says Above offers a separate Claude Code OpenTelemetry integration. Its documentation is not public, so what that path sees on a developer’s machine, and when, is not described here. (2) What sits behind a login. Above’s customer portal, and the compliance documents its trust center provides on request, were not read. (3) Pricing. We found no public price list; Above’s pages lead to a demo request. Every Above statement below is quoted from Above’s own site or its own PDFs, and the source is named.

The core difference is timing: a decision before the agent acts, or an investigation of what a person and their agents did.

01When does each one act on a coding agent?
Above’s Claude integration reads Claude activity from Anthropic’s Compliance API, covering “claude.ai chats and the session transcripts produced by Claude Code, Cowork, and remote Cowork”. After the first collection, “Above collects new and updated Claude activity hourly.” (Claude Enterprise Integration Guide, v3) Its launch post is plain about the direction: “The integration is read-only.” (above.security/blog, 29 Sep 2026) That suits an investigation, which needs the whole story. MoorAI’s hook runs in the agent’s own process before each Bash, Read, Write or mcp__* call, so a secret in a tool argument or a .env read is decided before it happens.
02What is kept?
Above’s investigations work from retained evidence. Its guide: “Above stores the verbatim text the person typed, for the prompts your capture configuration admits”, while “Claude's own replies, its thinking, and the system prompt are read past and never written.” Every tool call becomes a record, and where the arguments name a target it keeps “the destination's domain plus a keyed digest of the destination and of the resource”. (Claude Enterprise Integration Guide, v3) The launch post says the integration brings in “prompts, responses and tool calls”; per the guide, responses are read and not stored. MoorAI keeps no prompt off the device by default: the console receives a category, a risk level and a keyed HMAC-SHA-256 hash, and content travels only if an administrator turns on a capture tier.
03Who is each one built for?
Above names its users: “Security teams, insider-risk teams, HR, legal, and compliance teams in organizations with sensitive data, IP, SaaS sprawl, AI usage, and complex access.” (above.security/platform/ai-investigative-agents) The unit of work is a case about a person. MoorAI is built for the security team and the developer at the same moment: the unit of work is one agent action, and the developer, and where the agent host supports it the agent, is told what was flagged and the safer way to do it.
✓ yes ◐ partial — unconfirmed ✗ no

Where MoorAI holds ground Above does not

These rows follow from being in the agent’s process, on the machine, before the action. A “—” means the capability is not in Above’s public material, not that it is absent.

MoorAI Above
Decides on a coding agent’s shell command, file read or MCP call before it runs ✓PreToolUse hook in the agent —Claude integration is read-only and collects hourly
Blocks or masks a secret in a tool argument before the call runs ✓block or mask, per policy, on an enrolled device —not in public material
Governs local stdio MCP servers at call time ✓on-device MCP proxy and allow-list —not in public material
No prompt text in the security record by default ✓category · risk · keyed hash; capture tiers opt-in ◐prompt capture is a setting; tool-call records always kept
Claude Code covered however it authenticates (Bedrock, Vertex, a Console API key) ✓the hook runs in the agent, whatever the model provider ◐those sessions are outside the Compliance API source; OTel path not public
Codex CLI, Copilot CLI, Gemini CLI and Cursor at the tool call ✓pre-tool hooks; validated end to end on Claude Code only —not in public material
Open source, so the data claim can be checked in code ✓agent MIT —no platform source in public material
Free to start and to enforce, without talking to sales ✓agent free; console free to 200 users —no public pricing; demo-led

Where Above covers ground MoorAI does not

This list is longer. Above is built to investigate insider risk across a whole company, human and machine, and to hand Security, HR and Legal one case. Its integrations page: “Above connects to your identity, SaaS, endpoint, cloud and AI tools — so every insider-risk investigation arrives with full context, not just another alert.” (above.security/integrations) MoorAI governs the agents on developer machines.

MoorAI Above
Human insider-risk investigation across identity, SaaS, endpoint, cloud and HR ✗ ✓Okta, Entra, Google Workspace, CrowdStrike, SentinelOne, Defender, AWS, Workday and more
Departing-employee and data-staging detection with HR context ✗ ✓Workday, HiBob, Deel signals
Finished cases with timeline, intent and a recommended action, handed to Security, HR and Legal ◐moorai-trace replays one agent’s action chain; no case management ✓investigation workspace and case management
Email, chat and SaaS coverage: Gmail, Outlook, Slack, Teams, Drive, Jira, ServiceNow ✗ ✓
OAuth grants to third-party AI agents: consent, scopes and vendor ✗ ✓
Claude activity that never runs on a managed device: claude.ai chats anywhere, remote Cowork sessions ◐browser extension guards claude.ai on devices that run it ✓Claude Enterprise, via the Compliance API
ChatGPT, Amazon Bedrock, Bedrock AgentCore and Azure AI Foundry activity ◐on-device discovery of AI tools and keys ✓connectors
Intent reasoning over a person’s behaviour across systems and over time ◐intent alignment is lexical, per agent session ✓
Coaching inside email, SaaS and AI tools ◐coaching at the agent’s tool call; browser extension for 8 chat apps ✓

Same capability, different mechanism

Both products do each of these, so the table describes how rather than scoring.

MoorAI does it by… Above does it by…
Coding-agent tool calls A PreToolUse hook that sees each call with its arguments before it runs, on the device. Validated end to end on Claude Code; Codex, Copilot CLI, Gemini CLI and Cursor block through their own pre-tool hooks and are not yet validated against the live agents. A tool-call record per call in the Claude transcripts it reads, holding the tool name, the MCP host where Anthropic reports it, an action class and “the destination's domain plus a keyed digest of the destination and of the resource”, collected hourly.
Coaching At the tool call: the developer, and where the host allows it the agent, sees the category and the safer alternative. A device that is not enrolled only coaches; it never blocks. In the flow of work in email, SaaS and AI tools: “A quiet nudge shows the approved way — with the reason — before anything leaves.” (above.security/platform/real-time-guidance)
Who makes the hard call The org’s policy, on an enrolled device: coach, alert, mask, block, justify or kill the session, per threat. Blocking applies only where the policy says so. The customer’s people: “no enforcement action is taken autonomously on an AI verdict”, and “Account-level actions like disabling access happen in the customer's own identity, SOAR or ticketing systems, where their people make the call.” (above.security/blog, 24 Sep 2026)
Pushing back A justify action that holds the call for a signed justification. An employee who thinks they were stopped in error can answer: “In the event they feel the action was intercepted in error, they have a chance to justify it.” (above.security/blog, 24 Sep 2026)
Keyed digests HMAC-SHA-256 under the tenant’s enrollment token, computed on the device, so the matched value never leaves it. HMAC-SHA256 under a per-company key derived from a server-side secret, over destinations named in the transcripts it has read.
Evidence A hash-chained on-device log that moorai-trace replays as an action chain, signed per-verdict receipts, and OpenTelemetry spans with no content in them. An investigation with timeline, reasoning and recommended action, plus stored evidence snapshots and an audit log in Above’s platform.

The Synthetic Insider Threat Matrix. Above Theory, Above’s research division, built the research behind Forscie’s Synthetic Insider Threat Matrix (repository), a shared vocabulary for AI agents as insiders. It is useful work for both camps. We mapped MoorAI against the matrix.

MITRE ATLAS, as documented. In our reading of vendor material against the 76 ATLAS techniques tagged Agentic AI, Above’s published material documents 2 of the 76: AML.T0103 Deploy AI Agent and AML.T0086 Exfiltration via AI Agent Tool Invocation, both with a limit on what they cover (read 1 October 2026). A low count here reflects the product category, investigation rather than runtime control of an agent, not a weakness: ATLAS describes what an adversary does to an AI system, and Above is built to investigate what people do. The count measures what the documentation says, not the product. The method and every quote behind the number are in What vendors actually document against MITRE ATLAS.

Where MoorAI is stronger. The moment before the agent acts. The shell command, the file read and the local stdio MCP call are decided in the agent’s own process, whichever model provider the agent authenticates to. No prompt leaves the device by default, the code that guarantees that is MIT, and it is free to enforce up to 200 users.

Where Above is stronger. Everything around the agent, and the person behind it. Human insider risk, departing employees, data staging, email and SaaS, OAuth grants to third-party agents, Claude activity that never touches a managed device, connectors across identity, endpoint, cloud and HR, and a case that Security, HR and Legal can act on. If the job is investigating insider risk across a company, Above is the larger product.

Which to run where. Run Above across the company: identity, SaaS, email, HR context, OAuth grants and the Claude Enterprise record, for investigations that end in a decision by people. Run MoorAI on developer machines where coding agents run shell commands, read files and drive local stdio MCP servers, where the decision has to land before the call runs, and where the record should hold no prompt content. They work at different layers, the split Above’s own CrowdStrike brief draws, and can run together.

Questions about MoorAI and Above Security

Does Above block a coding agent’s tool call before it runs?

Not in its public material. Above’s Claude integration is read-only and collects Claude activity, including Claude Code session transcripts, hourly from Anthropic’s Compliance API, and Above states that no enforcement action is taken autonomously on an AI verdict. MoorAI decides before the call runs, through a PreToolUse hook and an on-device MCP proxy.

Does Above keep prompt text?

Above’s Claude integration guide says it stores the verbatim text the person typed, for the prompts the capture configuration admits, and a record of every tool call; Claude’s replies are read and not stored. MoorAI sends only a category, a risk level and a keyed one-way hash by default, and keeps content only if an administrator enables a capture tier.

Is Above a competitor to MoorAI?

Mostly not. Above investigates insider risk across people, SaaS, email, identity and AI tools, and hands Security, HR and Legal a finished case. MoorAI governs what coding agents do on developer machines before each action runs. Above’s own brief with CrowdStrike assigns runtime containment of the agent to the endpoint layer, which is where MoorAI works.

Is Above broader than MoorAI?

Yes. Above covers human insider risk, departing employees, email and SaaS, OAuth grants to third-party AI agents, HR and legal case handling, and connectors across identity, endpoint, cloud and HR systems. MoorAI covers the AI agents on developer machines.

Above Security capabilities are taken from Above’s own published material, checked on 1 October 2026: about-us, AI investigative agents, real-time guidance, integrations, agentic AI, What Happens After the Prompt, The Hardest Part of Real-Time Coaching, the Claude Enterprise Integration Guide (v3, PDF), and the Above and CrowdStrike brief (PDF). The customer portal, the compliance documents behind the trust center and the Claude Code OpenTelemetry integration documentation are not public and were not read. Every quoted phrase is Above’s. ◐ = partial: present but narrower than the other column. — = unconfirmed: not in Above’s public material, not necessarily absent. MoorAI marks reflect shipped capability: hook enforcement is validated end to end on Claude Code; Codex, Copilot CLI, Gemini CLI and Cursor block through their own pre-tool hooks and are not yet validated against the live agents. An unenrolled device coaches and never blocks. The agent is MIT; the console is source-available under the Elastic License 2.0 and free up to 200 users. Above Security is a trademark of its owner; this page is independent and is not affiliated with or endorsed by Above Security. Both products change, so check specifics against current documentation.