Your AI agents are already in production. Every security tool you have was designed before they existed.
Salt Security is the full-stack Agentic Security Platform, purpose-built to discover, govern, and protect AI agents, MCP servers, and APIs across code, configuration, and runtime. Unlike model guardrails that stop at the conversation, Salt protects the action layer: where agents execute business logic, invoke APIs, and touch your most sensitive systems. Deploys agentlessly across your AWS environment in under 10 minutes.
AI agents are now the connective tissue of modern AWS environments. They invoke APIs, execute through MCP servers, and act on business data with no human in the loop. The tools you already have were built before any of this existed.
Salt Security is the only platform purpose-built to secure the full agentic stack. It connects three sources of truth no other tool connects: what was built in code, how it is configured across your infrastructure, and what is actually happening at runtime. Salt deploys agentlessly across your existing AWS infrastructure, pulling visibility from Lambda, API Gateway, EC2, ELB, EKS, and CloudTrail without requiring new agents, sensors, or changes to your network topology.
AWS gives you the scale and foundation. Salt illuminates and secures the API and agentic layers operating across it. The result is a complete, living map of every agent, MCP server, and API in your environment, with risk scores, posture gaps, and threat context connected in a single platform from the first line of code to every action taken in production.
Highlights
Discover every agent, MCP server, and API you didn't know existed
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You choose one of three contract tiers, scaled by your API traffic and endpoint volume. Starter covers up to 100 million monthly API requests and 1,000 endpoints. Pro covers up to 500 million monthly API requests and 5,000 endpoints. Enterprise covers up to 2 billion monthly API requests. All three tiers include the same core capabilities: agent, API, and MCP discovery, posture governance, and threat protection. As your monthly request volume and endpoint count grow, you move to a higher tier. Pricing scales with the capacity you commit to, not per individual feature.
Top-of-mind questions for buyers
What counts as one API endpoint and one monthly API request for tier limits?
An endpoint is a distinct API path the platform discovers across your environments, including shadow, third-party, and deprecated ones. A monthly API request is a single call made to those endpoints. Both metrics set the ceiling for your chosen tier, covering internal east-west and external north-south traffic.
What happens if my API traffic exceeds the request or endpoint limits in my tier?
Each tier caps the monthly API requests and endpoints it covers. Starter covers 1,000 endpoints, Pro covers 5,000, and Enterprise covers up to 2 billion monthly requests. When your traffic or endpoint count grows past your cap, you move to a higher tier. Contact the vendor to arrange the transition.
Do all three tiers include the same protection features, or do higher tiers add capabilities?
All three tiers include the same core capabilities: agent, API, and MCP discovery, posture governance, and threat protection. The tiers differ only in the volume of monthly API requests and endpoints they cover. You are paying for capacity, not for extra features at higher tiers.
salt.security+1
Helpful?
Vendor refund policy
All fees are non-cancellable and non-refundable except as required by law.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
The Salt Security license includes access to customer support and customer success teams for full onboarding support, including deployment support and technical integrations for alerts, enforcement, remediation tickets, and other security tasks. support@salt.security
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Salt Security protects the APIs that power your business including the APIs behind AI agents, mobile apps, SaaS platforms, and microservices. Our platform delivers deep visibility, threat detection, and runtime protection to stop API attacks and secure your entire API ecosystem leveraging the AWS infrastructure.
Advanced AWS WAF ruleset for API and AI agent security. Blocks API abuse, GraphQL attacks, JWT anomalies, SSRF, and AI-driven threats. Discovers AI agent activity and MCP interactions to strengthen protection across modern agent-driven applications.
Salted CX extracts conversation content and metadata from multiple contact center platforms simultaneously, connecting them across all channels to create comprehensive customer journeys. Using AI, it surfaces the most important moments and opportunities, providing you with actionable business insights you can immediately act upon.
The product has been instrumental in helping us resolve attacks and better understanding vulnerabilities. The responsiveness from Salt team is great.
What do you dislike about the product?
Better root cause findings when issues are identified. However, the product is consistently getting better.
What problems is the product solving and how is that benefiting you?
Helping determine API vulnerabilities and prevent attacks.
Insurance
Amazing API security tool
Reviewed on Jun 05, 2023
Review provided by G2
What do you like best about the product?
First of all, the entire Salt team is a pleasure to work with. They are always responsive and are always eager to assist. Secondly, the Salt Security is the creme de la creme of API security tools. It does so much, and is a valuable tool in assisting with keeping our APIs safe.
What do you dislike about the product?
There is nothing that I dislike about this too.
What problems is the product solving and how is that benefiting you?
Salt Security is solving the issue of API security. As our organization starts to utilize APIs a lot more, we realized that there was a gap in monitoring those APIs. Now that we have brought on Salt, we can rest easy that our APIs are being monitored and protected.
Retail
Good Solution in Changing Landscape
Reviewed on Feb 01, 2022
Review provided by G2
What do you like best about the product?
A very lightweight solution that builds upon existing integrations, a responsive and open-minded support team, and an easy-to-navigate product. Salt isn't trying to solve every problem; they've found a niche and have focused on tightly sealing that gap.
What do you dislike about the product?
The product is still relatively new and missing quite a few bells and whistles. The SIEM logging integrations are missing native action logging, and we've had difficulties getting APIs going through a gateway to report correctly as unique items. However, Salt is a great partner and has been working with us through our requirements to improve the functionality that we need.
What problems is the product solving and how is that benefiting you?
We have not yet finished our implementation, but Salt will help us better secure our APIs without having to rely on heavy customization of some of the larger WAF-like products that are built to protect traditional applications.
Financial Services
Salt Security Survey
Reviewed on Jan 31, 2022
Review provided by G2
What do you like best about the product?
Attack traffic is probably the most consulted screen, however the security insights, sensitive information screens and endpoint autodiscovery are all also very useful
What do you dislike about the product?
I would like to see API compositions and other calls chains (sequences of APIs calling each other) stitched together graphically so the exact specific call chain that each API call was part of is super clear.
What problems is the product solving and how is that benefiting you?
Identifying potentially malicious traffic, tightening up the handling of sensitive information, detecting improper use of authentication and other security details.
Erich Y.
Visibility into All APIs
Reviewed on Jan 28, 2022
Review provided by G2
What do you like best about the product?
we have a centralized view of the APIs and we have alerts generated for events that are not common that could be attacks in our enviroment
What do you dislike about the product?
Salt could generate some detailed reports and also have some link on OAS to show how to fix those appointments
What problems is the product solving and how is that benefiting you?
The visibility of our APIs and alerting us when something different is happening in our enviroment