MoorAI vs Virtue AI
Last updated
Virtue AI hooks Claude Code and GitHub Copilot and sends each event to its Guard endpoint. MoorAI hooks the same events and decides on the machine. Virtue’s documentation lists “Existing desktop agents (e.g., Claude Code, GitHub Copilot, AMP agents) — protected via the hooks or gateway.” (docs.virtueai.com, AgentSuite-Blue) Its Claude Code guide adds HTTP hooks that post each prompt and tool call to a Virtue Guard URL, and “AgentGuard evaluates each request against your configured policies and returns a decision (allow / deny / ask) that Claude Code enforces.” (docs.virtueai.com, Claude Code) MoorAI is a PreToolUse hook inside the coding agent and an MCP stdio proxy in front of local Model Context Protocol (MCP) servers. Its detection engine runs inside the hook, so no call to a service is needed to reach a verdict.
Virtue AI is now part of Fortinet. Fortinet “announced it has acquired Virtue AI, an innovator in AI runtime protection, automated AI validation, and security for autonomous AI systems.” and says “This acquisition complements FortiAIGate and further strengthens Fortinet’s AI runtime security capabilities with Virtue AI’s automated validation and real-time protection.” (Fortinet press release, 17 August 2026) Virtue’s runtime record holds content: “Dynamic observability captures the full execution trajectory of an agent at runtime, including input prompts, intermediate tool calls, tool results, and final outputs.” (docs.virtueai.com, AgentSuite-Blue) MoorAI decides against a 77-threat matrix and by default sends only category · risk · keyed one-way hash.
Virtue covers more ground than MoorAI does. Purpose-built guard models across text, images, audio, video and code; red teaming of agents in simulated enterprise environments and of models and chatbots; static scans of MCP tools and agent skills; Shadow AI discovery tied to EDR; and code scanning in the IDE. MoorAI governs what coding agents do on endpoints and goes deeper into what they read, install and load. The rows where Virtue covers more ground are further down.
Three things this page does not state. (1) Where a customer’s Guard endpoint runs. Virtue says “We provide SaaS and on-premise deployment options for the Agent Gateway.” (docs.virtueai.com, AgentSuite-Blue) The hook’s event leaves the developer’s machine either way; whether it leaves the customer’s network depends on the deployment. (2) What changes under Fortinet. Fortinet’s release does not describe packaging, pricing or product changes, so this page describes Virtue’s own pages and documentation as they read today. (3) Pricing. We found no public price list; Virtue’s pages lead to a demo request. Every Virtue statement below is quoted from Virtue’s own site or documentation, or from Fortinet’s release, and the source is named.
The core difference is where the guard runs: behind an endpoint the hook calls, or inside the hook.
.github/hooks/ that post each event, plus a transcript hook that forwards the assistant’s messages. That lets Virtue judge with its own models: “The models are optimized for low latency — adding as little as 100ms per call”. (docs.virtueai.com, AgentSuite-Blue) MoorAI’s engine runs in the hook process on the device, and the console receives which rule fired, the risk and a keyed hash. Virtue’s design sends each prompt and tool call to the Guard; MoorAI’s detectors are limited to what runs on a laptop..env or key read into context, a near-miss package name at install time, an MCP server whose config changed after approval, a skill file carrying hidden instructions, an upload to a host the user’s request never named. Its verdicts are mostly per call; its multi-step coverage is a per-session record of what the user asked for and a crescendo-trajectory analyzer for persuasion-style jailbreaks.Where MoorAI holds ground Virtue does not
These rows follow from deciding inside the hook, and from rules written for what coding agents read, install and load.
Scroll sideways →
| MoorAI | Virtue AI | |
|---|---|---|
| Reaches the verdict on the device, with no call to a service | ✓engine runs in the hook | ✗hooks call a Virtue Guard endpoint |
| By default only category · risk · keyed one-way hash leave the device | ✓capture tiers are opt-in, admin-enabled | ✗dynamic observability captures prompts, tool calls, results and outputs |
| Masks a secret or PII span in a coding agent’s tool call and lets it proceed | ✓mask action; not yet observed in a live Claude Code session | —Action Guard can modify a call; masking not described |
| Coaching with the safer alternative, shown to the developer and the agent | ✓ | ◐the block reason is fed back to Claude |
| Codex CLI, Gemini CLI and Cursor | ◐adapters; not yet validated against the live agents | —not in its integration list |
| Coding-agent rules: slopsquatting, MCP rug-pull knock-back, local secret-value fingerprints, rules-file leaks | ✓ | —not in public material |
| Flags a risky action aimed at something the user’s request never named | ✓intent alignment; lexical, keyed hashes | —history-aware Action Guard; method not public |
| Enforces for any host that launches a stdio MCP server, with no gateway | ✓MCP stdio proxy | ◐web agents connect through its gateway |
| Open source, so the data claim can be checked in code | ✓agent MIT | —no published product source found |
| Free to start and to enforce, without talking to sales | ✓agent free; console free to 200 users | ✗no public pricing; demo-led |
Where Virtue covers ground MoorAI does not
This list is longer. Virtue secures agents, models and chatbots from testing to runtime, now inside Fortinet’s platform. MoorAI governs coding agents on endpoints.
Scroll sideways →
| MoorAI | Virtue AI | |
|---|---|---|
| Purpose-built guard models across text, images, audio, video and code, in 100+ languages | ◐deterministic detectors, optional local model, OCR of pasted images | ✓VirtueGuard |
| Each tool call judged against the agent’s execution history, for multi-step attacks | ◐verdicts mostly per call | ✓Action Guard |
| Agent red teaming in 50+ simulated enterprise environments, with an injection MCP server | ◐moorai-redteam tests MoorAI’s own policy | ✓AgentSuite-Red |
| Continuous red teaming of models and chatbots | ✗ | ✓VirtueRed |
| Hooks for agent frameworks: Google ADK, OpenAI Agents SDK, LangChain, Strands, Microsoft 365 Agents | ◐Claude Agent SDK through the shell hook in server mode | ✓AgentSuite SDK |
| Shadow AI discovery that reconstructs each session’s activity and plugs into EDR | ◐on-device AI bill of materials and shadow-AI inventory; no EDR integration documented | ✓Microsoft Defender, CrowdStrike Falcon |
| Vulnerability scanning of code in the developer’s IDE | ◐AI output review flags insecure code the agent generates | ✓CodeGuard |
| Policies from 50+ compliance frameworks, written in natural language and tuned against a labelled set | ✗ | ✓PolicyGuard, Policy Lab |
Same capability, different mechanism
Both products do each of these, so the table describes how rather than scoring.
Scroll sideways →
| MoorAI does it by… | Virtue AI does it by… | |
|---|---|---|
| Stopping a coding agent’s action before it runs | A PreToolUse hook in the agent’s own process, validated end to end on Claude Code. Codex CLI, Copilot CLI, Gemini CLI and Cursor block through their own pre-tool hooks and are not yet validated against the live agents. An MCP stdio proxy enforces for any host that launches a stdio MCP server. | HTTP hooks in a Claude Code settings file pointing at the Guard; for Copilot, hook files under .github/hooks/. On PostToolUse, “Action Guard inspects tool output for sensitive data leaks or policy violations.” (docs.virtueai.com, Claude Code) |
| Scanning MCP tools and agent skills before they are used | Checks on MCP tool descriptions (including ones that ask for a credential file), an invisible-payload scanner, Skill Analysis when the agent loads a skill, and moorai-scan, a content-free pre-install verdict with CI exit codes. | “MCP Guard statically scans the tool descriptions of all the tools and detects the tools with injected prompts.” and “Skill Guard statically scans agent skills, analyzing their contents to detect malicious instructions and injected prompts before the skill is loaded by an agent.” (docs.virtueai.com, AgentSuite-Blue) Both are also standalone endpoints for CI/CD. |
| Least privilege for agents | An entitlement envelope per agent: authorised tools, path prefixes and MCP servers. An action outside it is flagged as entitlement drift and alerted or blocked. | “Administrators can configure fine-grained access rules for each agent, and the Access Control will continuously monitor all tool call and resource invocations to block any unauthorized access.” (docs.virtueai.com, AgentSuite-Blue) |
| Agents that run without a developer’s laptop | Server mode runs the same hook in CI, containers and Agent SDK services, with the workload as the actor and a headless ask denied. Proven on one live claude -p run; an Agent SDK service and a GitHub Actions run have not been watched end to end. |
In-process hooks through the AgentSuite SDK for agent frameworks, including the Claude Agent SDK, and a gateway that connects web agents as MCP connectors. |
| Evidence of a decision | A signed, content-free decision receipt per verdict (tool, category, risk, decision and one-way hashes, signed with ed25519) and a hash-chained on-device log. | A dashboard monitor per guard and a recorded trajectory of prompts, tool calls, tool results and outputs. |
MITRE ATLAS, as documented. In our reading of vendor material against the 76 ATLAS techniques tagged Agentic AI, Virtue AI’s published material documents 6 of the 76 (read 1 October 2026), 3 of them with a limit the vendor states, such as MCP Guard scanning tool descriptions statically rather than tool responses at runtime, and prompt injection described for red-team testing rather than as a named runtime detection. That counts what the documentation says; Virtue’s runtime Prompt Guard is described only as detecting malicious prompts, which names no technique. The method and every quote behind the number are in What vendors actually document against MITRE ATLAS.
Where MoorAI is stronger. Nothing leaves the device to be judged, and the rules know coding agents. The file read into context, the package being installed, the MCP server that changed after approval, the skill file the agent loads and the upload to a host the user never named are judged in the hook, and the console receives no content. A secret can be masked instead of blocked, the developer is coached instead of just refused, adapters reach Codex CLI, Copilot CLI, Gemini CLI and Cursor, and the engine is MIT code, free to enforce up to 200 users.
Where Virtue AI is stronger. Models, multi-step judgement, testing and reach. “VirtueGuard secures text, image, audio, video, and code across 100+ languages” (virtueai.com/virtueguard), and Action Guard judges each call against the agent’s history. Its red teaming runs agents through simulated enterprise systems: “Agent ForgingGround simulates 50+ enterprise environments across 14 high-stakes domains including Databricks, Gmail, PayPal, ServiceNow, and Atlassian.” and “An Injection MCP Server replays real attacks against any MCP-tool-using agent so you can continue to test against known vulnerabilities.” (virtueai.com/agentsuite-red) It hooks agent frameworks MoorAI does not, discovers shadow AI through the EDR a company already runs, and, in Fortinet’s words, will enhance the Fortinet AI-Native Security Fabric. If the job is securing every agent, model and chatbot a company runs, Virtue is the larger product and MoorAI is not one.
Which to run where. Run Virtue where the question is the whole agent estate: agents built on frameworks, chatbots and models, tested before release and guarded at runtime, especially in a Fortinet shop. Run MoorAI on developer machines where prompts, files and commands should not leave the machine to be judged, and where the risk is specific to coding agents. Both hook the same Claude Code events, so running both means two hooks on every action; neither’s public material addresses that, and we have not run them together.
Questions about MoorAI and Virtue AI
Is Virtue AI part of Fortinet?
Yes. Fortinet announced on 17 August 2026 that it has acquired Virtue AI, and says the acquisition complements FortiAIGate and strengthens its AI runtime security. Financial terms were not disclosed.
How does Virtue AI connect to Claude Code?
Through Claude Code’s lifecycle hooks. Virtue’s guide adds HTTP hooks for PreToolUse, PostToolUse and UserPromptSubmit to a Claude Code settings file, each pointing at a Virtue Guard endpoint with an API key; the Guard returns allow, deny or ask, and Claude Code enforces it. MoorAI also hooks Claude Code, but its engine runs inside the hook on the device.
Does Virtue AI see the prompts and tool calls of a coding agent?
Yes, per its documentation: Prompt Guard inspects every incoming prompt and agent response, Action Guard inspects every tool call, and dynamic observability captures input prompts, intermediate tool calls, tool results and final outputs. The Guard can run as SaaS or on premises. MoorAI sends a category, a risk level and a keyed one-way hash by default, and keeps content only if an administrator enables a capture tier.
Does MoorAI replace Virtue AI, or the other way round?
Not as a whole. Virtue also sells guard models for models and chatbots, red teaming of agents, models and chatbots, Shadow AI discovery and code scanning, and MoorAI does none of that. On coding agents the two overlap, and the difference is whether each event is sent to a Guard or judged on the device.
Virtue AI capabilities are taken from Virtue AI’s own published material and Fortinet’s release, checked on 1 October 2026: docs: AgentSuite-Blue, docs: Hook Integration, docs: Claude Code, docs: GitHub Copilot, virtueai.com, platform, AgentSuite-Blue, AgentSuite-Red, VirtueGuard, VirtueRed and Fortinet’s acquisition release. Every quoted phrase is Virtue’s or Fortinet’s. ◐ = partial: present but narrower than the other column. — = unconfirmed, not necessarily absent. MoorAI marks reflect shipped capability: hook enforcement is validated end to end on Claude Code; Codex, Copilot CLI, Gemini CLI and Cursor block through their own pre-tool hooks and are not yet validated against the live agents. The agent is MIT and runs on macOS, Windows and Linux; the console is source-available under the Elastic License 2.0 and free up to 200 users. Virtue AI is a trademark of its owner; this page is independent and is not affiliated with or endorsed by Virtue AI. Both products change, so check specifics against current documentation.