As threat actors increasingly use AI to accelerate and develop cyberattacks, enterprise defenders need to rely on both AI and a critical defender’s advantage: Business context that only you possess.
Enterprise cyber defense spans identity, network, endpoint, data, cloud, and application layers, often split across a dozen or more products, each with its own context. At Google Cloud Next, we brought partner-built agents into Gemini Enterprise to give you one place to discover and deploy specialized agents across functions including sales, content and creative workflows, HR, and security.
Today, we’re expanding our catalog of partner-built security offerings in the Gemini Enterprise ecosystem to help you leverage your full security context from one unified interface.
These new security agents and integrations from leading cybersecurity vendors span two areas: partner security agents that your teams invoke directly in Gemini Enterprise, and protections for AI and agentic workloads. By bringing them into Gemini Enterprise, you can now orchestrate multi-step security workflows directly in your Gemini Enterprise environment, bringing AI-powered capabilities to your defenses.
Meet new security agents and agentic defenses built with Gemini Enterprise
Acalvio: The Acalvio ShadowPlex deception agent, accessible through Gemini Enterprise, automates the deployment of decoys and honeytokens across enterprise networks and embeds deception guardrails directly into customer’s operating environment, with no manual configuration required. ShadowPlex deploys network decoys, identity honey accounts, retrieval-augmented generation (RAG) decoys, honey skills, and honeytokens at scale, trapping unauthorized interactions quickly.
Britive: The Britive Emergency Termination Agent, built on Gemini Enterprise, lets security teams contain a compromised human or non-human identity from a single natural-language request instead of working across multiple consoles. The agent confirms the identity, lists all active privileged sessions, revokes all sessions with human approval, disables the identity, and gathers audit context for the incident ticket. The result is significantly lower mean time to containment (MTTC) while maintaining strict governance and least-privilege access for agents.
Check Point: Integrated with the Google Cloud Agent Gateway and Agent Registry, Check Point AI Defense Plane provides the critical security controls and visibility required for your enterprise-scale AI. It allows organizations to discover AI workloads, monitor risk posture, detect non-compliant behavior, and apply real-time guardrails against prompt injection, data exposure, and rogue agentic behavior. Managed through the Check Point Agent in Gemini Enterprise, the unified solution secures and accelerates AI workload deployments on Gemini Enterprise.
CrowdStrike: CrowdStrike Falcon® Guardian extends guardrails and runtime protection by integrating with Agent Gateway to help secure agentic workloads running in Gemini Enterprise against risks including prompt injection, sensitive data leakage, and malicious AI activity. In addition, the CrowdStrike Gemini Enterprise agent enables practitioners to interact with the CrowdStrike platform through Gemini Enterprise, bringing CrowdStrike security context into agentic investigation and response and helping orchestrate SOC workflows across numerous tools.
Cyberhaven: The Cyberhaven Linea agent brings discovery and classification of sensitive data across endpoints, cloud apps, and agentic workflows to Gemini Enterprise. Powered by Cyberhaven’s data lineage model, it can turn plain-language intent into enforceable policies, monitor interactions to catch unmapped risks before they become breaches, and fast-track investigations with automated evidence. Extending across Antigravity in Gemini Enterprise, the Linea agent can eliminate alert fatigue and empowers security teams to protect sensitive assets as fast as autonomous agents move them.
Cyera: Cyera Agent Guardian, built on Gemini Enterprise, secures agents that run on Gemini, providing data security posture management (DSPM) and data loss prevention (DLP). The Cyera agent can correlate machine identities, delegated permissions, and sensitive data classification to verify authorized agentic behavior, so organizations can deploy agents safely and maintain operational compliance at enterprise scale.
Endor Labs: Endor Labs AURI agents bring AI-native application security across the developer and security workflow. Its Static Application Security Testing (SAST) triage agent can automatically classify and prioritize code findings inside developer platforms like Google Antigravity. In Gemini Enterprise, security teams can query and act on those findings conversationally, confirming what’s actually exploitable and tracking fixes, all grounded in the Endor Labs application context.
Exabeam: With Gemini Enterprise as its foundation, Exabeam is introducing the next generation of Exabeam Nova, a unified multi-agent AI system that helps security teams investigate and respond to threats faster. Nova coordinates specialized AI agents that can analyze behavior, prioritize risk, conduct investigations, and guide response actions while maintaining a shared operational context across the entire workflow. The result is a more intelligent and efficient analyst experience that helps organizations get greater value from their existing security operations environment.
Fastly: The Fastly Autonomous Edge Defense Agent (AEDA) can help security teams investigate edge and infrastructure incidents in plain language inside Gemini Enterprise, instead of manually parsing logs. AEDA pairs an organization’s own telemetry with anonymized intelligence from Fastly’s global customer base, determining in seconds whether an anomaly is isolated or part of a broader attack, returning evidence-backed findings with a recommended fix.
Fortinet: Fortinet FortiAIGate delivers large language model (LLM) runtime protection for Google Cloud customers. Integrated with the Gemini Enterprise and deployed in your Google Cloud environment, FortiAIGate can empower organizations to deploy sophisticated, agentic AI applications so that their data, prompts and model interactions are actively protected against emerging threats.
Menlo Security: HEAT Shield Agent, built withGemini, analyzes web content and blocks zero-day threats and prompt injection at runtime. Alongside it, Menlo Security Orchestrator — built on Gemini Enterprise — turns security operations center (SOC) responses into natural-language, agentic workflows. It can reconstruct attacks, identify blast radius, and enforce policy in seconds, not hours. Menlo Agent Runtime Security (MARS) closes the loop, protecting human and agent-to-agent interactions so detection and containment stay unified across agentic workloads.
Obsidian Security: Obsidian Security’s Risk Analyzer and Breach Response agents on Gemini Enterprise can help security analysts assess risk and respond to breaches. Built to secure an organization’s cloud and AI-native application portfolio, Obsidian agents discover AI agents across enterprise environments, assess the risk, flag governance gaps, and answer critical questions like which agents hold escalated privileges or write access.
Palo Alto Networks: Palo Alto Networks’ Cloud, Network, and AI Risk Assessment (CLARA) agent can help security teams protect critical data and compliant AI operations, without slowing down the pace of development. It can find and fix cloud and AI risks before they become breaches by continuously scanning cloud infrastructure and AI workloads, automatically surfacing hidden vulnerabilities and prioritizing fixes so security teams spend less time hunting for threats and more time closing them.
Ping Identity: With Ping Identity’s new PingID self-service agent, now available in Gemini Enterprise, employees can resolve common identity and device issues, including multi-factor authentication (MFA) resets and device recovery, by asking in natural language — no help-desk ticket required. Built on PingOne with secure delegated authentication, the PingID self-service agent gives IT teams an enterprise-ready way to manage workforce identities while reducing support costs and improving onboarding experience.
Qualys: Qualys ROCky for Gemini Enterprise can help security teams manage and patch vulnerabilities using conversation inside Gemini Enterprise. Ask, “How exposed are we to Log4Shell,” “What should we fix first,” or “Are we meeting our CISA KEV deadlines,” and get answers ranked by the Qualys TruRisk score. It runs on each user’s own Qualys entitlements so anyone can self-serve answers without help. It can also stage and deploy the patch.
Splunk, a Cisco company: The Splunk Security AI agent, integrated with Gemini Enterprise, functions as an autonomous system that converts massive telemetry streams into real-time intelligence across security and observability data. By bypassing manual triage to instantly surface critical anomalies and system threats, it shifts teams from reactive investigations to proactive defense, lowering cognitive load during high-pressure incidents and enabling security teams to resolve risks faster.
Synk: Every enterprise building with Gemini Enterprise and Antigravity is shipping code faster than ever, and Snyk makes sure that code is secure from the moment it’s written, not after. Snyk validates what AI agents generate in real time, catching vulnerabilities and insecure dependencies before they ever reach a repo. It’s security built for the speed AI writes code, not the speed humans used to.
Thales: The Thales AI Security Fabric, integrated with Gemini Enterprise, can provide visibility, runtime protection, and centralized governance across agentic AI interactions. Organizations can move agentic AI from pilots to production, enforcing fine-grained access policies and protecting critical data assets right where they run.
Transmit Security: Transmit Security Agent Intelligence built with Gemini Enterprise identifies agentic activity interacting with customer-facing applications. As users increasingly delegate tasks, transactions, and authority to AI agents, organizations need clear visibility into what that activity is, its origin, and its intent. That context allows businesses to distinguish good agents from malicious ones, decide what to allow versus block, and stay ahead of the risk without restricting legitimate commerce.
Zscaler: Zscaler Risk360 provides a comprehensive, actionable framework that ingests data from existing Zscaler deployments to quantify cyber risk, create a detailed view of risk posture, and deliver clear insights to reduce risk. The Risk360 Agent is an AI-powered companion built on the ZAgent Framework with Gemini Enterprise, using natural-language interactions to unify Zscaler and partner signals, analyze Zero Trust risk, quantify financial exposure, recommend mitigations, and deliver decision-ready insights.
With this growing ecosystem of partner-built agents and connectors, Gemini Enterprise works with the security tools you already use — and lets you build custom agentic workflows on top of them. You can explore the security agents available in the Google Cloud Marketplace today.