Back to the registry
Agent passport

OX AI Native Application Protection Platform (AINAPP)

Ox Security · Cybersecurity & IT

No attestation published

Certification per AWS Marketplace.

Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 4 captures on record

User rating4 ★2 reviews on the listing
Runs onUnknownSaaS
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

OX rewires your security program for the Mythos Age: the era where AI writes the code, chains the exploits, and moves faster than human-built defenses can track.

OX is an AI Native Application Protection Platform (AINAPP) unifying security from Prompt to Runtime. It moves your control surface upstream to the prompt, preventing and governing risk at the source instead of chasing it downstream in runtime.

Show the rest of the publisher’s description (9 more lines)

OX Mind and OX AI Context Lake connect AI-user governance, code security, cloud and runtime enforcement, and agentic pentesting into one system that shares context across the entire Agentic Development Lifecycle (ADLC), replacing fragmented point tools with a single platform.

The platform runs on four connected pillars:

OX VibeSec: Prevents unsafe AI decisions at the point of creation and governs every AI user in the organization, not just developers using coding assistants. Full visibility into which agents, MCPs, skills, and packages run, with what permissions, against what data.

OX Code: Separates exploitable risk from theoretical noise using evidence from your actual deployment, threat model, and threat intelligence.

OX Cloud: Prevents misconfigurations and enforces runtime boundaries that code and agents cannot cross, watching what actually runs in production.

OX Agentic Pentester: Continuously simulates adversarial agent behavior to prove exploit paths back to their exact source, feeding what it finds back into OX VibeSec to sharpen governance.

OX connects to your existing stack and traces every finding back to its origin (the prompt, the AI user, or the endpoint that created it), then fixes issues at the source rather than flagging them after the fact.

For new deployments, OX consolidates governance, code security, cloud enforcement, and pentesting into one platform. For existing stacks, OX layers governance on top and makes current tools smarter through continuous learning, so the same issue never gets created twice.

Visit https://ox.security for more information.

Highlights

Highlighted by the publisher on AWS Marketplace.

Govern the AI user, prevent at the prompt: OX VibeSec governs the AI user ecosystem - agents, MCPs, skills, packages, and the code they generate - steering code as it's generated in real time, blocking insecure patterns and risky open source before they enter the build. Unsafe code never gets written.

Prove what's actually exploitable: OX Code provides full-spectrum coverage across SAST, SCA, SBOM, secrets, IaC, containers, and APIs, with reachability analysis and an evidence engine validating every finding from API entry point through execution path to business impact. OX Cloud enforces runtime boundaries that code and agents cannot cross.

Validate continuously at agent velocity: OX Agentic Pentester autonomously probes the running system the way an attacker would - chaining across layers, testing privilege escalation and business logic - proving exploit paths back to their exact source and feeding findings back to sharpen governance.

Preview

5 images
OX AI Native Application Protection Platform (AINAPP) preview 1OX AI Native Application Protection Platform (AINAPP) preview 2OX AI Native Application Protection Platform (AINAPP) preview 3OX AI Native Application Protection Platform (AINAPP) preview 4OX AI Native Application Protection Platform (AINAPP) preview 5

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Compliance

Government
  • FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Vendor

External enrichment

CompanyOX SecurityAutomated

Plans and pricing as listed

1 listed
OX AppSec Security
  • Users
$100,000.00
P12M

Refund terms

As stated by the publisher on AWS Marketplace.

All fees are non-cancellable and non-refundable except as required by law.

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource
CustomEulaCustomEulaSource

Publisher resources

4 links
See product videodrive.google.comSource
Publisher linkaws.amazon.comSource
Publisher linkaws.amazon.comSource
OX Security - Solution Introductiondocs.ox.securitySource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Paid
1 plan listed
Delivery
SaaS
OX Security - Solution Introduction: https://docs.ox.security/ OX Security Support- support@ox.security OR https://www.ox.security/contact/
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.