Skip to content
MoorAI
// moorai vs onyx security

MoorAI vs Onyx Security

Last updated

Onyx records what an agent did, in full, inside one enterprise control plane. MoorAI decides on the device and sends no content. Onyx describes itself in one line: “Onyx is the secure control plane for AI agents and models.” (onyx.security) For coding agents it says “Onyx intercepts the tool call at the coding-agent hook and escalates it to a human reviewer before execution.” (onyx.security blog, Tales from the Runtime Layer) MoorAI is a PreToolUse hook inside the coding agent and a Model Context Protocol (MCP) stdio proxy in front of the tool servers. It reads the prompt, the file read into context, the shell command and the MCP arguments and results, and coaches, masks or blocks on what it finds.

Both stop a coding agent’s tool call before it runs. Onyx: “When an agent session attempts a file delete, an out-of-scope database write, or an unapproved shell command, the enforcement layer blocks the call before execution and logs the attempt.” (onyx.security blog, Four Guardrails) It lists “Five enforcement actions: alert, block, mask, steer, or ask (human in-the-loop).” (onyx.security/platform/ai-security) The difference is what each keeps. Onyx: “Every prompt, model response, and tool call is recorded by name, argument, and result, with the reasoning context preserved across turns.” (onyx.security/platform/ai-observability) MoorAI decides against a 77-threat matrix and by default sends only category · risk · keyed one-way hash.

Onyx covers far more ground than MoorAI does. It discovers agents “across SaaS, cloud, endpoints, and code” (onyx.security/platform/ai-observability), reaches Claude Enterprise through Anthropic’s Compliance API and inference hooks, gives each agent its own identity, compiles policy written in natural language, red-teams deployed agents and runs an AI gateway. MoorAI governs what coding agents do on the machines it is installed on. The rows where Onyx covers more ground are further down.

Three things this page does not state. (1) Which coding agents the hook supports, and where it decides. Onyx names the runtimes it sees, “Cursor, Claude Code, self-built stacks, and commercial tools alike,” (onyx.security blog, Four Guardrails) but we found no public product documentation, hook list or install guide, so whether the coding-agent hook decides on the device or calls Onyx’s service is marked unconfirmed. (2) Four solution pages. MCP Security, Runtime and Prompt Injection Defense, AI Discovery and Shadow AI, and Agent Identity and Access Governance are linked in Onyx’s navigation and returned 404 when we read the site, so nothing here comes from them. (3) Pricing. We found no public price list; Onyx’s pages lead to a demo request. Every Onyx statement below is quoted from Onyx’s own site, and the page is named.

The core difference is what leaves the machine: the whole session, for investigation, or a content-free verdict.

01What does each keep?
Onyx keeps the session. On its observability page, “The session is the unit of investigation.” (onyx.security/platform/ai-observability) Its Claude Enterprise integration pulls “conversation content, uploaded files, project data, and activity logs” through Anthropic’s Compliance API. (onyx.security/integrations/anthropic) An investigator gets the prompt, the reasoning and every tool argument in one record. MoorAI keeps none of that off the device. The console receives which rule fired, the risk and a keyed hash, and capture tiers that keep content are opt-in and enabled by an administrator. That is a real trade: MoorAI gives an investigator less, so that prompts and source code never reach a vendor.
02Where does the decision happen?
Onyx decides at several points. Its MCP gateway: “Every tool call an agent makes to an MCP server is evaluated against scope, identity, data class, and policy before the call lands.” (onyx.security/platform/ai-orchestration) For Claude Enterprise, Anthropic’s inference hooks call Onyx AI Guard, and “The enforcement point sits inside Anthropic's infrastructure rather than in a network proxy.” (onyx.security blog, Anthropic inference hooks) Onyx also governs “direct API calls, coding-agent hooks, base-URL integrations, and the MCP ecosystem” under one policy. (onyx.security/platform/ai-governance) MoorAI decides on the device, in the hook and the proxy, and connects to nothing to reach a verdict. For agents with no laptop under them, such as claude -p in CI or an Agent SDK service in a container, MoorAI’s server mode runs the same hook.
03What happens when an action is risky?
Onyx’s “ask” pauses the agent for a person: “The workflow pauses, and a human operator gets an alert” (onyx.security blog, Tales from the Runtime Layer), and its “steer” action does this: “Steer redirects the risky action toward a safe alternative without stopping the workflow.” (onyx.security/platform/ai-orchestration) MoorAI coaches: it tells the developer and, where the agent host supports it, the agent what was flagged and the safer way to do it. A mask replaces a secret or PII span with a content-free tag and lets the call proceed. A device that is not enrolled in a MoorAI console coaches and never blocks; blocking, sign-off and session kill apply once it is enrolled. In server mode a verdict that would wait for sign-off is denied, because no one is there to answer it.
✓ yes ◐ partial — unconfirmed ✗ no

Where MoorAI holds ground Onyx does not

These rows follow from deciding on the machine and sending no content, and from coding-agent detectors Onyx does not describe. Onyx marks are unconfirmed where its public material is silent.

MoorAI Onyx
By default only category · risk · keyed one-way hash leave the device ✓capture tiers are opt-in, admin-enabled ✗session capture records prompts, responses and tool arguments
Coding-agent verdict computed on the device, with nothing sent anywhere to decide ✓ —hook path not described; inference-hook path calls Onyx AI Guard
Gates package installs against typosquatted and hallucinated names ✓slopsquatting firewall —not in public material
Flags a proxy plus CA override that reroutes the agent’s traffic ✓transit-override detection —
Reports the agent’s rules files leaving the device, by fingerprint ✓ —
Knocks an approved MCP server back to pending when its config changes ✓rug-pull detection —routes approval for new servers; re-approval on change not described
Flags a risky action aimed at something the user’s request never named ✓intent alignment; lexical, keyed hashes —
Scans the local files an MCP call names, as if the agent had read them ✓hook and stdio proxy —
Coaches on a device that is not enrolled, and never blocks there ✓ —
Open source, so the data claim can be checked in code ✓agent MIT ✗no public source code found
Public product documentation, no demo call ✓ ✗none found
Free to start and to enforce, without talking to sales ✓agent free; console free to 200 users ✗no public pricing; demo-led

Where Onyx covers ground MoorAI does not

This list is longer. Onyx is a control plane for every enterprise agent surface, from Copilot Studio and Bedrock agents to browser AI, gateways and Claude Enterprise. MoorAI covers coding agents on the machines it is installed on, and nothing else.

MoorAI Onyx
One policy across SaaS agents, cloud agents, browser AI, gateways and coding agents ✗coding agents and MCP only ✓
Claude sessions on unmanaged laptops and phones, with nothing installed ✗needs the hook on the machine ✓Anthropic inference hooks, Claude Enterprise
Claude Enterprise conversations, files and projects through the Compliance API ✗ ✓
Session capture an investigator can read, with the agent’s reasoning across turns ✗by design: no content leaves the device ✓
Each agent its own identity, with actions tied to the invoking user through Okta or Entra ◐knows the agent and a keyed device actor, no identity provider ✓
Policy written in natural language and compiled into enforcement ✗actions set per threat and per tier ✓
Autonomous red teaming of deployed agents ✗ ✓
A posture score per agent across its lifecycle, for release sign-off ✗ ✓
AI gateway with cross-provider routing and cost-aware model selection ✗ ✓

Same capability, different mechanism

Both products do each of these, so the table describes how rather than scoring.

MoorAI does it by… Onyx does it by…
Stopping a coding agent’s action before it runs A PreToolUse hook in the agent’s own process, validated end to end on Claude Code. Codex CLI, Copilot CLI, Gemini CLI and Cursor block through their own pre-tool hooks and are not yet validated against the live agents. An MCP stdio proxy enforces for any host that launches a stdio MCP server. Interception “at the coding-agent hook” (onyx.security blog, Tales from the Runtime Layer) and an “agentless endpoint presence” that “provides access to Claude Desktop, Claude Cowork, Claude Code, and chat in the browser.” (onyx.security/integrations/anthropic) Which agents the hook supports is not published.
Holding an action for a person A sign-off verdict once the device is enrolled. In server mode there is no approver, so the call is denied with a reason and one content-free alert, unless the system file or org policy allows it through with a report. The ask action: “Ask routes the decision to a human in the loop when policy demands review.” (onyx.security/platform/ai-orchestration)
Masking a secret or personal data The mask action rewrites the span to [MOORAI:<tier>:<8 letters>], derived from the keyed hash, in the tool input or tool result, and lets the call proceed. Built from Claude Code’s hooks reference and not yet observed in a live session. “PII, credentials, and confidential content detected in prompt or response are masked in transit.” (onyx.security blog, Four Guardrails)
Discovering agents on devices An on-device AI bill of materials: models, MCP servers, editor extensions, running local model servers and AI keys at rest, checked against your allow-list. Endpoint discovery pushed by device management: “Discovery deploys via Intune, Jamf, or CrowdStrike RTR in under an hour.” (onyx.security blog, Four Guardrails)
Agents with no developer present Server mode runs the same hook for claude -p in CI, the Claude Code GitHub Action or an Agent SDK service. One live claude -p run showed the hooks firing, a .env read denied and content-free reports reaching the console. An Agent SDK service and a GitHub Actions run have not been watched end to end. A gateway in the request path: “Onyx is designed as the routing and enforcement layer for production agents” (onyx.security/platform/ai-orchestration), alongside connectors to agent-building platforms.

MITRE ATLAS, as documented. In our reading of vendor material against the 76 ATLAS techniques tagged Agentic AI, Onyx’s published material documents 7 of the 76 (read 1 October 2026), 4 of them with a limit the vendor states. Onyx says it maps policy to MITRE ATLAS automatically, but it publishes no per-technique mapping, so that statement adds nothing to the count, and several cells rest on blog posts describing customer deployments. That counts what the documentation says, not a test of the product. The method and every quote behind the number are in What vendors actually document against MITRE ATLAS.

Where MoorAI is stronger. Depth on coding agents, with no content leaving the machine. The verdict is reached on the device. Package installs, proxy overrides, rules-file leaks, MCP servers that change after approval, actions aimed outside the user’s request and the files an MCP call names are each checked there. The console receives no content, the code that guarantees that is MIT, and it is free to enforce up to 200 users.

Where Onyx is stronger. Breadth, identity and forensics. One policy over SaaS, cloud, browser, gateway and coding agents; Claude Enterprise covered through the Compliance API and through inference hooks that work on unmanaged laptops and phones with nothing installed; a separate identity per agent tied to the invoking user; policy in natural language; red teaming and a posture score; and a full session record an investigator can read. If the job is one control plane for every agent in the enterprise, Onyx is the larger product and MoorAI is not one.

Which to run where. Run Onyx where the question is enterprise-wide: which agents exist across SaaS, cloud and endpoints, who they act for, and what happened in a session, with the content kept for investigation. Run MoorAI on developer machines and CI runners where the question is what a coding agent is about to read, run or send, and where prompts and source code should not reach a vendor. Both hook coding agents, so on one machine the two would sit in the same hook chain; nothing in either’s public material says they conflict, and we have not run them together.

Questions about MoorAI and Onyx Security

Does Onyx Security keep the content of prompts and tool calls?

Yes, per Onyx. Its observability page says every prompt, model response and tool call is recorded by name, argument and result, with reasoning context kept across turns, and its Claude Enterprise integration pulls conversation content, uploaded files and project data through Anthropic’s Compliance API. MoorAI sends a category, a risk level and a keyed one-way hash by default, and keeps content only if an administrator enables a capture tier.

How does Onyx Security reach Claude Code and other coding agents?

Onyx describes three routes: interception at the coding-agent hook before a tool call runs, an agentless endpoint presence covering Claude Desktop, Cowork, Claude Code and browser chat, and Anthropic’s inference hooks for Claude Enterprise, which call Onyx for a verdict before content reaches Claude. It publishes no list of supported agents or install guide. MoorAI installs a PreToolUse hook in Claude Code, pre-tool hooks in Codex CLI, Copilot CLI, Gemini CLI and Cursor, and an MCP stdio proxy.

Does MoorAI replace Onyx Security, or the other way round?

No. Onyx is a control plane for every enterprise agent surface, with discovery, identity, natural-language policy, red teaming, posture, a gateway and full session capture. MoorAI does none of that beyond coding agents. MoorAI inspects what a coding agent’s actions contain and coaches, masks or blocks on the device, with no content sent to a vendor.

Can I try Onyx Security without talking to sales?

We found no public pricing or self-serve trial; Onyx’s pages lead to a demo request. The MoorAI agent is MIT-licensed and free, and the MoorAI console is free up to 200 users.

Who backs Onyx Security?

Onyx came out of stealth with $40 million in funding from Conviction Partners and Cyberstarts, and on 29 July 2026 announced a $113 million Series B led by Bessemer Venture Partners, with participation from Cyberstarts, TCV, Conviction, FirstMark, Vintage Investment Partners, QuantumLight and G Squared.

Onyx capabilities are taken from Onyx’s own published material, checked on 1 October 2026: onyx.security, onyx.security/platform, AI Security, AI Observability, AI Governance, AI Orchestration, Onyx and Anthropic, Anthropic inference hooks, Four Guardrails, Tales from the Runtime Layer, Introducing Onyx Security and Onyx’s $113M Series B. This is Onyx Security at onyx.security, not the open-source search product at onyx.app. Every quoted phrase is Onyx’s. Blog scenarios Onyx describes as composites of customer work are read as Onyx’s description, not as tested results. ◐ = partial: present but narrower than the other column. — = unconfirmed, not necessarily absent. MoorAI marks reflect shipped capability: hook enforcement is validated end to end on Claude Code; Codex, Copilot CLI, Gemini CLI and Cursor block through their own pre-tool hooks and are not yet validated against the live agents. The agent is MIT and runs on macOS, Windows and Linux; the console is source-available under the Elastic License 2.0 and free up to 200 users. Onyx Security is a trademark of its owner; this page is independent and is not affiliated with or endorsed by Onyx Security. Both products change, so check specifics against current documentation.