| Status | Meaning | Requirements |
|---|---|---|
| CONFORMANT | Product satisfies AARM specification requirements | Complete testing protocol, verify R1-R7 (Core) or R1-R9 (Extended) |
| ALIGNED | Building in the same problem space | Working on runtime action security, self-declared |
Conformant Companies

A unified platform to secure and govern your AI and agents, delivering the safety, security, and compliance needed to unlock AI’s full potential with enterprise-grade protection.
Aligned Companies

One platform for MCPs, Skills, and Agents, with purpose-built security, fine-grained governance, and complete observability built in from day one.
Enterprise governance platform for AI agents and MCP servers. Real-time observability, security controls, and compliance for agent infrastructure.
The easy and secure way for people and agents to use MCP. Autonomous runtime security for modern AI infrastructure.

Formal enforce least-privilege at the wire protocol layer for humans and AI agents

AI Detection and Response Platform

Discover, Detect, and Defend your AI, Agents, and MCP in real-time. Operant secures your agentic ecosystem against the most relevant AI threats with a private mode deployment, inline auto-redaction, scope or intent drift, and more.

Runtime Assurance for AI Agents. Complete visibility and control so your teams can move fast and stay safe.

Thoth enforces behavioral policies on AI agent tool calls at the SDK layer blocking anomalous sequences before execution in under 100ms and generating tamper-proof, hash-chained evidence for every enforcement decision.

Agentic AI governance and security gateway for enterprises. Centralized policy enforcement, full audit trails, and compliance controls for every AI agent and MCP connection across your organization.

Intent is the new perimeter

Aegis is a runtime security control plane for AI agents that governs what they can do, what they access, and what actually executes—before anything goes wrong.

Intent-to-action control layer for AI agents. Intercepts every tool call, evaluates it against policy, and blocks, allows, or escalates for human approval — with a full audit trail.

Repello delivers end-to-end security for autonomous AI systems through continuous discovery, automated red teaming, and adaptive runtime protection.

Agentic Access Management for fast-moving companies. Control access to every app and AI agent while enabling your teams.

Enforcement layer for agents that blocks malicious or accidental actions before data leaks or regulatory violations.

DecisionGuard provides pre-execution assurance for automated and AI-driven systems. It records intent, evaluates context and risk, and produces audit-ready verdicts before changes execute.
A local, Rust-based runtime firewall for AI agents. Acts as the mediation layer to intercept and block dangerous tool calls in real-time.

Clevr Security authorizes AI agent actions in real time by evaluating intent and business context, applying allow/deny/step-up approvals with audit-ready receipts.

Assury MoCoP is a self-hosted runtime control plane that enforces AARM-conformant policy over AI agent actions. Deployed as a proxy between agents and tools, it intercepts tool calls, evaluates them against OPA/Rego policy, applies risk scoring, and emits tamper-evident audit logs to SIEM.
Runtime enforcement platform for AI agents. Evaluates and authorizes agent actions before execution using identity-aware policy controls, generating compliance-grade audit receipts.

Runtime security platform that gives teams deterministic control over autonomous agents in production.
Dev tool giving control and visibility over their agents and their MCP actions.

AI Security and Governance for laptops
Preemptive cybersecurity platform for AI agents. Deploys a mentor agent that intercepts tool calls at the protocol and kernel layers, enforces policies against behavioral baselines, and blocks dangerous actions before execution.

Highflame is a unified enterprise Agent security platform that provides real-time protection and multi-turn behavioral control across AI models, autonomous agents, and MCP ecosystems, helping organizations safely adopt and scale AI.

Runtime governance for AI-era systems

Shadow AI and ungoverned agents are accumulating risk you can’t quantify. ARIS finds what’s running, measures the exposure, and gives you control where it matters.
How to Get Listed
AARM Conformant
- Satisfy all MUST requirements (R1-R7) as defined in the Conformance Requirements
- Complete the Testing Protocol and provide evidence
- Submit verification results via GitHub
AARM Aligned
- Your product addresses one or more aspects of the AI runtime security problem
- Submit a brief description of what you’re building
- No conformance testing required