Updated July 21, 2026
TL;DR: Noma Security delivers broad AI Security Posture Management (AISPM), native integrations with Microsoft Copilot Studio and Salesforce AgentForce, and runtime policy enforcement via its Kong Gateway plugin. For organizations without strict data sovereignty requirements, that breadth is genuinely useful. The structural trade-off is architectural: Noma's Kong plugin routes traffic and telemetry outbound to
api.noma.security:443, placing enforcement decisions and audit logs outside the customer's perimeter by default. Regulated enterprises in defense-adjacent, financial services, and manufacturing sectors that require every governance artefact inside their own infrastructure need a 100% self-hosted sovereign AI control plane, not a SaaS-managed enforcement layer.
When evaluating AI governance platforms, the most critical question is not what policies they can write, but where data flows when those policies are enforced. Noma Security is a capable, well-integrated platform and deserves an honest assessment that acknowledges its real strengths alongside its structural trade-offs. For organizations under strict data sovereignty obligations, the architectural detail that matters most is this: Noma's Kong Gateway plugin requires outbound HTTPS access on port 443 to api.noma.security to function. For a Cybersecurity Maturity Model Certification (CMMC) Third-Party Assessment Organization (C3PAO) or a Federal Financial Institutions Examination Council (FFIEC) examiner reviewing your AI audit trail, it matters whether that boundary is inside or outside your perimeter.
This assessment covers Noma's genuine capabilities, the sectors where it fits well, the scenarios where its architecture creates compliance friction, and how a 100% self-hosted sovereign AI control plane resolves the gap.
Noma Security at a glance
Noma Security positions itself as an enterprise AISPM platform. Its core value proposition is continuous discovery, assessment, and governance of AI assets across an organization's environment, including models, agents, data pipelines, Model Context Protocol (MCP) servers, and AI-powered tools, with native integrations spanning 80+ platforms.
The table below captures the operational trade-offs most relevant to security and compliance leaders evaluating Noma for regulated-industry deployments.
| Dimension | Noma Security | Prediction Guard |
|---|---|---|
| Control plane location | External SaaS (api.noma.security:443) | Self-hosted (on-premises, Virtual Private Cloud (VPC), or air-gapped) |
| Telemetry routing | Outbound to Noma's external infrastructure | No outbound transit |
| Audit log storage | Third-party infrastructure (default), on-premises deployment available | Generated locally, consumed by customer Security Information and Event Management (SIEM) |
| Runtime enforcement | Yes, via Kong Gateway integration | Yes, entirely within customer perimeter |
| Developer integration | Kong plugin setup with network egress required | OpenAI/Anthropic-compatible, base_url change only |
| Pricing model | Custom enterprise pricing (based on agents, MCPs, integrations, deployment scope) | Custom-quoted enterprise |
| Framework mapping | NIST RMF, OWASP Top 10, MITRE ATLAS, EU AI Act | NIST AI RMF, OWASP, AIUC-1, EU AI Act, ISO/IEC 42001 |
| Vendor portability | Policies configured in Noma's environment (on-premises or SaaS) | Policies stored inside customer infrastructure |
Noma is a strong choice for organizations that need comprehensive AI asset discovery, posture management, and integration breadth without hard data sovereignty constraints. For enterprises where every governance artefact must remain inside their own infrastructure, the architectural trade-off is the central evaluation question.
Key Noma Security governance features
Noma's AISPM capability continuously discovers AI models, agents, and data pipelines across the environment, maps where models are deployed, identifies who has access, and surfaces unapproved AI tools and agentic systems automatically. That inventory breadth is genuinely useful for organizations conducting their first structured AI asset census.
Runtime protection is delivered through the Kong Gateway integration, which allows Noma to inspect prompts and responses in real time, apply security guardrails, redact PCI and PII, and block non-compliant requests. Noma's agentic controls include MCP Server Security with policy-based approval and runtime enforcement for MCP connections, context-aware access control that can constrain an agent's capabilities per environment, and detection of over-permissive or potentially destructive agent capabilities.
Key scenarios for AI risk mitigation
Noma performs well in environments where the primary governance challenge is visibility rather than perimeter enforcement. Specific scenarios where it fits include:
- Tracking ungoverned agent interactions across SaaS tools: Native integrations with Microsoft Copilot Studio and Salesforce AgentForce let security teams discover and monitor AI activity inside those ecosystems without building custom connectors.
- AI asset discovery in rapid-deployment environments: Engineering teams that deploy AI integrations faster than governance can track benefit from Noma's automated discovery and asset inventory outputs.
- Organizations with existing Kong Gateway deployments: Teams already running Kong can enable Noma's runtime protection plugin with relatively low integration overhead, provided the outbound egress requirement to
api.noma.security:443is permitted within the network environment.
Core Noma Security capabilities for AI oversight
Noma's technical capability set is broad. The table below maps Noma's stated features against NIST AI RMF functions and the OWASP Top 10 for Agentic Applications 2026, which is the more operationally relevant community guidance standard for agentic deployments, in the table below.
| Noma capability | NIST AI RMF function | OWASP framework alignment |
|---|---|---|
| AI asset discovery (AISPM) | Map (asset enumeration) | Agentic AI Top 10 (framework level) |
| AI asset inventory export | Map (inventory), Govern (accountability) | Agentic AI Top 10 (framework level) |
| Runtime enforcement (Kong plugin) | Manage (risk response) | OWASP LLM Top Ten (LLM01) |
| Prompt injection detection | Manage (risk response) | OWASP LLM Top Ten (LLM01) |
| Sensitive data redaction | Manage, Govern (data governance) | OWASP LLM Top Ten (LLM02) |
| MCP governance and tool calls | Manage (risk response) | Agentic AI Top 10 (framework level) |
| Framework posture mapping | Govern (policy), Measure (monitoring) | NIST AI RMF, EU AI Act, MITRE ATLAS |
Posture mapping to NIST AI RMF and the EU AI Act functions well at the discovery and reporting layer. Where the trade-off emerges is at the Manage function: because enforcement decisions execute in Noma's external cloud rather than locally, the evidence chain for a conformity assessor evaluating ISO/IEC 42001 or AIUC-1 alignment includes a third-party processing step that the organization does not control.
Runtime enforcement and hybrid environment support
Noma does provide runtime policy enforcement, and characterizing the platform as monitoring-only would be inaccurate. The Kong Runtime Protection plugin operates in monitor mode (asynchronous) or synchronous enforcement that blocks non-compliant requests before completion. Sensitive data redaction, PCI and PII masking, and jailbreak blocking are live capabilities.
The architectural question is not whether enforcement happens, but where. Per Kong's documented integration, the plugin "streams AI traffic data to the Noma Security Console" and "enables Noma to inspect prompts and responses in real time and apply critical security guardrails," meaning the decision logic executes in Noma's external infrastructure and returns to the local gateway node. The enforcement action (allow, block, or rewrite) occurs at the local Kong node, but the policy decision that drives it has already transited api.noma.security. Noma's integration catalogue spans multiple cloud providers and model endpoints, so it handles hybrid environments through that breadth, but every path through the Kong plugin still requires the outbound connection to Noma's control plane. The Practical AI episode 360, co-hosted by Prediction Guard founder Daniel Whitenack, covers why vendor-mediated telemetry crossings break the trust boundary that regulated data depends on.
Architectural limits for sovereignty-constrained deployments
The capabilities above are real. The limitations below are structural, not operational, which means they do not resolve with additional configuration within the current architecture.
Overcoming industry-specific barriers
Defense-adjacent organizations handling Controlled Unclassified Information (CUI) under CMMC requirements or technical data under ITAR face a direct compliance question with Noma's default architecture. ITAR compliance requires 100% auditability, strict data residency, and access controls that prevent unauthorized third-party processing of controlled technical data. An implementation that routes AI governance telemetry to an external SaaS endpoint introduces a third-party processing step that a C3PAO assessor will scrutinize during a CMMC Level 2 or Level 3 review.
Financial services organizations subject to the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule must implement administrative, technical, and physical safeguards to protect customer information. When AI security telemetry is managed by third-party vendors under the default configuration, financial institutions must ensure contractual obligations and oversight mechanisms enforce GLBA-compliant safeguards throughout the data lifecycle. FFIEC examiners evaluate whether these vendor relationships maintain appropriate control and audit capabilities for security events involving nonpublic personal information.
Visibility gaps in AI audit logs
If an organization cannot verify that governance artefacts were generated and retained locally, it does not fully own them. For ISO/IEC 42001 conformity assessment, the third-party conformity assessor evaluates not just whether logs exist, but where they originated, who could access them during transit, and whether the retention chain is entirely within the organization's control.
Noma's default SaaS architecture stores and processes telemetry in Noma's external infrastructure. Organizations that require the audit log chain to remain inside their perimeter may need to evaluate deployment configurations that support on-premises requirements. Prediction Guard generates SIEM-ready structured audit logs locally inside the customer's infrastructure and formats them natively for Splunk, Datadog, and generic syslog forwarders, with the customer's own ingestion pipeline handling delivery. Prediction Guard does not hold SIEM credentials, API keys, or HTTP Event Collector (HEC) tokens: it configures output formatting only.
Handling cross-border data transfers and hidden costs
The EU AI Act creates explicit obligations for organizations with EU operations, customers, or supply chains, including requirements around data governance, risk management documentation, and conformity assessment for high-risk AI systems. When AI governance telemetry transits a US-based SaaS vendor's infrastructure, EU-resident organizations must evaluate whether that transit triggers data transfer obligations under GDPR and EU AI Act accountability requirements.
Three cost categories are frequently underestimated in Noma evaluations. First, outbound HTTPS traffic to api.noma.security from cloud environments generates egress costs that scale with call volume and may not appear in initial vendor proposals. Second, enabling the Kong plugin typically requires DevOps work to configure the Kong service and route, and security team review of the outbound network rule. Third, if a Defense Counterintelligence and Security Agency (DCSA) assessor or FFIEC examiner scrutinizes the outbound telemetry pathway, the compliance team may need to produce additional documentation justifying the external transit or invest in evaluating deployment configurations that support on-premises requirements.
Benchmarking Noma against industry rivals
The comparison below evaluates Noma Security and Prediction Guard across the dimensions that matter most to security, compliance, and infrastructure teams: where the control plane lives, how audit evidence is generated, and how governance policies align to the frameworks regulators actually use.
Architecture, evidence collection, and developer ergonomics
The fundamental difference between Noma and Prediction Guard is not feature breadth. It is where the control plane lives and where the evidence chain runs.
Noma operates as a SaaS-managed control plane. The Kong Gateway node runs locally, but it defers to Noma's external infrastructure for the policy decision that determines whether a call is allowed, blocked, or flagged. Prediction Guard deploys a sovereign AI control plane inside the customer's own infrastructure: self-hosted on-premises, in a cloud VPC, or in an air-gapped environment. Every element of the governance stack, including enforcement logic, audit log generation, and policy configuration, executes locally.
| Dimension | Noma Security | Prediction Guard |
|---|---|---|
| Audit log generation | Noma's external infrastructure (default) | Customer infrastructure (local) |
| SIEM delivery mechanism | Vendor-managed routing | Customer ingestion pipeline |
| Credential handling | Configured by vendor | No vendor credential access |
| Log format | OpenTelemetry export to SIEM, SOAR, and observability pipelines | Native Splunk, Datadog, or syslog formatting |
| Evidence chain for examiners | Includes third-party processing step | Entirely within customer perimeter |
| Exclusive customer control | Shared with default config | Exclusive (customer controls generation and retention) |
Developers building on Prediction Guard do not change their code. Existing OpenAI-compatible and Anthropic-compatible SDK calls continue working unchanged: only the base_url is repointed at the Prediction Guard control plane endpoint. Security and compliance teams configure governance policies on the Govern page of the Admin Console independently of the development workflow. That separation of duties means developers ship features without rebuilding their toolchain, and governance teams enforce controls without blocking delivery cycles.
For a detailed walkthrough of how Prediction Guard maps system-level controls to specific NIST AI RMF functions, the NIST AI RMF implementation playbook publishes explicit control-to-function tables that a FFIEC examiner or AIUC-1 assessor can validate line by line because the evidence artefacts are generated locally.
Framework alignment: NIST AI RMF, OWASP, and AIUC-1
Noma reportedly maps its out-of-the-box policies to NIST AI RMF, MITRE ATLAS, OWASP LLM Top Ten, and the EU AI Act. That coverage is genuine and reduces the manual work of translating asset inventory into framework-mapped risk documentation.
For agentic AI deployments, the OWASP Top 10 for Agentic Applications 2026 is the more operationally relevant community guidance standard than the OWASP LLM Top Ten, because it addresses the threat landscape of multi-step agent workflows, tool calls, and MCP server interactions. Noma covers agentic-specific controls including MCP governance, injection prevention, and exfiltration detection. The Practical AI episode 358 covers how enterprise Kubernetes stacks are being restructured to support governed AI systems with MCP integrations inside the customer's own infrastructure.
Where Noma's framework alignment trails is at the system-level Manage function. AIUC-1, structured across six pillars (Data and Privacy, Security, Safety, Reliability, Accountability, and Society), specifically addresses where AI processing and related records reside under its Data and Privacy pillar. The Practical AI episode 361 covers how the enterprise flywheel of standards, certification, audit, and insurance is being applied to agentic AI systems under AIUC-1. When enforcement decisions and audit logs transit an external SaaS environment by default, an AIUC-1 assessor conducting enterprise vendor due diligence will evaluate whether that transit is consistent with the organization's Data and Privacy obligations. Prediction Guard's self-hosted control plane keeps the entire enforcement chain inside the customer's jurisdiction. Noblis, a leading nonprofit science and technology organization supporting defense and intelligence missions, is both an investor in and customer of Prediction Guard. As Noblis CEO Mile Corrigan stated in July 2025: "This alignment offers significant opportunities for strategic collaboration on secure deployment of AI systems, including through Noblis' Artificial Intelligence Assurance Implementation (AI2) solution for AI safety, and further strengthens our ability to help customers navigate AI adoption while safeguarding sensitive data."
Vendor portability
Noma's governance policies are configured within Noma's environment. Organizations evaluating migration to a different AI governance system should assess policy portability requirements and transition costs. Prediction Guard's control plane is CPU-only and hardware agnostic, deployable across on-premises servers, cloud VPCs, and air-gapped environments regardless of underlying hardware vendor, and model agnostic across open-source families, closed-vendor endpoints, and self-hosted models, with inference workloads able to run on GPU or CPU depending on the deployment. Governance policies defined in the Admin Console are stored inside the customer's own infrastructure and are portable across deployment environments.
Book a deployment scoping call to assess whether a fully self-hosted deployment fits your infrastructure and compliance requirements.
FAQs
The questions below address the most common decision points raised during enterprise evaluations of Noma Security, focusing on audit evidence, log residency, real-time enforcement behaviour, and deployment lock-in.
Does Noma Security replace manual evidence collection for audits?
Noma automates AI asset discovery and posture reporting, which reduces the manual effort of building an initial asset inventory and framework mapping. Compliance teams still need to map Noma's posture outputs to specific regulatory controls and verify the evidence chain satisfies their particular examiner's requirements, especially for DCSA or FFIEC reviews where the location of log generation is material.
Where are Noma Security's audit logs stored?
By default, Noma's architecture routes telemetry and security event data to Noma's external infrastructure for processing and analysis, as documented in its Kong Gateway integration. Organizations that require logs to reside exclusively within their own infrastructure should evaluate Noma's on-premises deployment option, as the default implementation routes telemetry to Noma's external infrastructure.
Can Noma block policy violations in real time?
Yes, Noma's Kong plugin supports synchronous enforcement mode that blocks non-compliant requests before they complete. The policy decision is made by Noma's external infrastructure after receiving traffic context from the local Kong node, meaning enforcement executes locally but the policy decision transits api.noma.security.
Does deploying Noma lock us into specific AI models or clouds?
Noma's integration catalogue spans multiple cloud providers and model endpoints without restricting which AI services you use. The portability question is at the governance layer: whether policies configured within Noma's environment, whether deployed as SaaS or on-premises, can be exported or must be reconstructed when migrating to another system is not publicly documented, and organisations should raise this explicitly during vendor evaluation to understand the transition cost.
Key terms glossary
MCP (Model Context Protocol): A protocol that enables AI agents to interact with external tools, databases, and services through standardized server interfaces, allowing controlled access to resources beyond the base model's capabilities.
SIEM (Security Information and Event Management): A system that aggregates, analyzes, and stores security event logs from across an organization's infrastructure, enabling real-time monitoring, threat detection, and compliance reporting.
VPC (Virtual Private Cloud): An isolated cloud computing environment within a public cloud infrastructure where organizations can deploy resources with custom network configurations and security controls.
C3PAO (CMMC Third-Party Assessment Organization): An accredited entity authorized to conduct Cybersecurity Maturity Model Certification assessments for defense contractors handling Controlled Unclassified Information.
FFIEC (Federal Financial Institutions Examination Council): A U.S. interagency body that prescribes uniform principles, standards, and report forms for federal examination of financial institutions and makes recommendations to promote uniformity in supervision.
GLBA (Gramm-Leach-Bliley Act): U.S. federal legislation requiring financial institutions to explain information-sharing practices and implement safeguards to protect customer data.
DCSA (Defense Counterintelligence and Security Agency): The U.S. federal agency responsible for security oversight of the defense industrial base, including CMMC assessments for organizations handling classified or controlled information.
HEC (HTTP Event Collector): A token-based HTTP input mechanism in Splunk that allows applications to send event data directly to Splunk Enterprise or Splunk Cloud over HTTPS.
Sovereign AI control plane: A governance infrastructure component that executes policy enforcement, model access controls, and audit log generation entirely within the customer's own infrastructure, with no outbound transit to a third-party vendor's systems.
AIBOM (AI Bill of Materials): A structured inventory of AI assets (models, datasets, MCP servers, and dependencies) exported in CycloneDX format, produced as a byproduct of AI System registration, and used to satisfy auditor requests for a complete AI asset record.
Runtime enforcement: The act of evaluating an AI interaction against governance policy at the moment the call occurs, allowing, blocking, or rewriting the response before it reaches downstream systems, as opposed to retrospective log analysis after the interaction completes.
AIUC-1: A cross-framework AI governance standard structured across six pillars (Data and Privacy, Security, Safety, Reliability, Accountability, and Society), with crosswalks to major frameworks available at aiuc-1.com/crosswalks, used by enterprise procurement teams for vendor due diligence and by insurers writing AI liability policies as a documented control reference.