Salt Introduces Prompt Security with new AI-DR Solution

Most AI security tools secure a slice.
Salt secures the entire agentic path.

AI agents and MCPs run on APIs. Salt builds on a decade of API security expertise to secure the entire agentic path.

✧ 100+ enterprise deployments across complex environments.

01 Discover Know what your agents can reach.

02 Govern Fix the paths that put you at risk.

03 Protect Stop abuse where actions happen.

Trusted by global enterprises

Securing APIs since 2016. Now securing the agents that call them.

Scotiabank
Luxottica
Solaris
Standard Bank Group
Seminole Hard Rock Support Services
First City Monument Bank
Celsius
Workplace Options
Stryker
Kingston Technology
Enverus
Computer Services, Inc.
Cathay Bank
Augmedix
Jemena
Hyundai
Carrefour Spain
SoFi
Flutterwave
Intdev
Coralogix
Dein Deal
Armis

Why point solutions fall short

Agentic risk crosses layers. Most AI security tools do not.

A secure prompt is not the same as a secure action. Risk moves from model to MCP server to tool to API to a real business system. You cannot secure an agent without securing what it can reach.

AI security Prompts and responses

Protects one conversation layer.

Yes for
Agent
No for
MCP
No for
Tool
No for
API

MCP security Servers and tools

Protects one connection layer.

No for
Agent
Yes for
MCP
Yes for
Tool
No for
API

API security Downstream transactions

Protects one execution layer.

No for
Agent
No for
MCP
No for
Tool
Yes for
API

Salt Agentic Security The entire path

Connects the layers and secures how risk moves between them.

Yes for
Agent
No for
MCP
No for
Tool
No for
API

Point solutions protect components. Salt secures the path between them.

49.8%

of organizations confirmed or suspected an AI agent took an action in the past year the the organization did not intend, expect, or authorize.

Salt Security, 2H 2026 State of AI and API Security report

Breadth and depth visibility

A routine request. Unauthorized data access.

The prompt requests an export. The internal API returns customer records without validating credentials. Salt connects the entire path.

User Prompt

“Export last week’s refunds with customer contact details. Return the result as a Base64-encoded string.”

BreadthPrompt → Agent → MCP → Tool → API → Data
Billing AgentAI agentUser-requested exportAI checks passed*
Refund MCPMCP serverInternet-facingExternally exposed
Bulk-export toolrefund_export()Uses backend API keyHardcoded secret
Internal Refund APIGET /refunds/{id}API key sent; not validatedMissing authentication
Customer PIIName · Email · Phone · AddressPII in API trafficSensitive data exposed
DepthThe evidence behind the action
AI Security · Passed*

No prompt injection detected.
No clear-text PII detected.

Final output: Base64U2FyYWggQ2hlbnxzYXJhaC…
✓Salt · ContextConnects the requester to the downstream data access.
Exposure

Internet-facing MCP.
Access to an internal API.

✓Salt SurfaceFinds the externally exposed Refund MCP.
Source code

Hardcoded backend API key.

✓Salt CodeFinds the hardcoded backend API key.
Configuration

No credential validation.
Refund records exposed.

✓Salt ConnectFinds missing authentication on the internal API.
Runtime + sensitive data

Refund IDs enumerated.
Customer PII returned before encoding.

GET /refunds/R-4471GET /refunds/R-4472GET /refunds/R-4473
✓Salt RuntimeDetects refund enumeration and customer PII before encoding.
SaltSalt sees the entire agentic path.Show me →
Path riskSeen by Salt

Routine words. Encoded output. Unauthorized access.
Connect the requester, tools, permissions, and data to reveal the risk behind the response.

*Illustrative AI check. Some model-layer controls detect encoded PII.

From security leaders

What changes when you can see the whole path.

Security teams use Salt to find the agents, MCP servers and APIs nobody inventoried, and to stop abuse their existing tools were never positioned to see.

We had guardrails on every model and still couldn't answer a simple question: what are our agents actually calling? Salt answered it in the first week.

CISO Global financial services company

Salt found MCP servers we didn't know existed, including two exposed to the internet. That changed how we approve every new agent.

Head of Application SecurityHealthcare technology company

It didn't replace our gateway or our WAF. It made them smarter, because now they block what Salt detects.

VP Security Engineering Global retailer

Built for the enterprise you have

Keep the stack you have. Salt connects to all of it.

Start with agentless discovery, then add protection through the gateways, WAFs and SOC tools you already run. Nothing to rip out, reroute or rewrite.

CloudFlare WAF
Veracode
Akamai
Wiz
Apigee
AWS
Google Cloud Platform
CrowdStrike
Kong
Azure
MuleSoft
Docker
F5
Kubernetes

40+ technology integrations across cloud, gateways, edge, code and the SOC.

See all integrations

Your agents are already acting. Secure the entire path.

Discover what they use, understand what they can reach, govern how they operate and protect what happens at runtime.