Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

DIY vs Zenity: an in-house build or a security and governance platform for AI agents

Build it yourself (DIY)

Building agent connections and controls in-house from open protocols, existing infrastructure, and open-source tools

Zenity AI Agent Security & Governance Platform

Security and governance platform for AI agents, aimed at security teams

Short answer

DIY is not a product: you connect and govern agents yourself on protocols like MCP and A2A, which leave authorization logic to the implementer.⁠Source 1, Source 2 Zenity calls itself a security and governance platform for AI agents, delivered as SaaS, and says it finds agents and can check their actions against your rules and block some.⁠Source 3, Source 4, Source 5, Source 6

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both cover governance: Uber and Pinterest built registries and review rules for their MCP servers, and Zenity says it inventories agents and can check their actions against runtime rules.⁠Source 4, Source 5, Source 7, Source 8
Where they differ
Zenity says it secures agents where they run.⁠Source 3, Source 4 Letting agents find and call each other through it isn’t in Zenity’s public docs. DIY also connects agents, for example over A2A.⁠Source 1
Running both
Zenity says any agent emitting OpenTelemetry or gen_ai spans can connect to it without a dedicated integration.⁠Source 9
Public sources · checked 2 October 2026
  • Offered
  • You build it
  • Not publicly documented

DIY

  • Build agents: You build itOpen-source frameworks like ADK⁠Source 10
  • Host and run agents: You build itSelf-hosted, like LangGraph⁠Source 11
  • Identity and access: You build itYour own identity provider⁠Source 12
  • Registry and governance: You build itYour own agent registry⁠Source 13
  • Traffic between agents, tools, and models: You build itYour gateway and service mesh⁠Source 7
  • Agents across organizations: You build itA2A with API management⁠Source 14

Zenity

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: Not publicly documented
  • Registry and governance: OfferedAI Observability agent inventory⁠Source 4
  • Traffic between agents, tools, and models: OfferedTool-call blocking for coding agents⁠Source 15
  • Agents across organizations: Not publicly documented

At a glance

TopicDIYZenity
What it isAn in-house build on protocols such as A2A and MCP, which the A2A specification calls complementary.⁠Source 1A SaaS security and governance platform for AI agents, which Zenity aims at security teams.⁠Source 3, Source 16
Finding agentsYours to build: A2A prescribes no standard API for curated registries, and a curated registry means deploying and maintaining a registry service.⁠Source 13By scanning: Zenity says AI Observability catalogs agents in SaaS platforms, custom builds, and laptops, and flags agents outside sanctioned deployment channels.⁠Source 4
Rules on agent actionsYours to build: MCP itself cannot enforce its security principles at the protocol level; implementers should build consent and authorization flows.⁠Source 2Zenity says it can block actions inline on Copilot Studio, Microsoft Foundry, and coding agents (through hooks); elsewhere, such as Agentforce and M365 Copilot, it offers detection and posture only.⁠Source 6
Where it runsWherever you run it: Pinterest optimized for MCP servers hosted in its internal cloud.⁠Source 8Software as a service; its AWS Marketplace listing shows it deployed on AWS.⁠Source 3
PricingOpenly licensed specifications, such as A2A under Apache 2.0.⁠Source 1 Build and running costs are not publicly documented.Custom pricing or a private contract on its main AWS Marketplace listing.⁠Source 3 A Security Hub Extended listing shows per-resource and per-token prices.⁠Source 17

What each one is

Build it yourself (DIY)

DIY means connecting and governing agents without a product made for the job: protocols such as MCP and A2A, your own registry and access checks, existing gateways and identity providers, or no central approach; Uber and Pinterest have each described running their own MCP registry.⁠Source 7, Source 8

Zenity AI Agent Security & Governance Platform

Zenity’s AWS Marketplace listing calls it a security and governance platform for AI agents, delivered as SaaS.⁠Source 3 Zenity describes three layers: Surface, for what an agent can reach; Enforce, when a decision is made; and Protect, for what slips through.⁠Source 16

The differences that matter

  1. Finding agents

    DIY

    You build the list: A2A prescribes no standard API for curated registries, and Pinterest’s own registry is its source of truth for approved MCP servers.⁠Source 8, Source 13

    Zenity

    Zenity says AI Observability scans your environment and catalogs agents in SaaS platforms, custom builds, and laptops, each with its permissions and tool access.⁠Source 4

    The official MCP Registry is in preview and does not support private servers; its docs recommend hosting your own private registry for those.⁠Source 18

  2. Rules on agent actions

    DIY

    You build the checks: Uber’s MCP gateway applies its internal Access Control System policies to callers it identifies as humans, services, or agents.⁠Source 7

    Zenity

    Zenity says Boundaries can check agent actions in real time against your rules and can block actions on Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 5, Source 6

    Zenity says Boundaries rules can reference Okta attributes such as active status, role, department, and job title.⁠Source 5

  3. Traffic between agents

    DIY

    You build the connections, for example over A2A, which gives agents built on different frameworks, languages, or vendors a common language.⁠Source 1

    Zenity

    Zenity says AIDR shows requests and responses passed between agents, and tracks triggers, retrievals, tool invocations, and handoffs step by step.⁠Source 19

    A2A is designed for agents built by different companies on separate servers.⁠Source 20 Reaching a partner’s agents, with access the partner controls, isn’t in Zenity’s public docs.

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicDIYZenity
Network exposureMCP servers on Streamable HTTP expose an HTTP endpoint; A2A agents on HTTP use HTTPS URLs in production.⁠Source 1, Source 21SaaS, deployed on AWS per its AWS Marketplace listing.⁠Source 3 Network requirements for monitored agents aren’t in Zenity’s public docs.
IdentityIn A2A, identity is established at the HTTP layer and credentials are obtained out of band.⁠Source 1, Source 14 MCP authorization is optional.⁠Source 22Zenity says rules can use Okta attributes such as role.⁠Source 5 Issuing agent credentials isn’t in Zenity’s public docs.
Access changes and revocationEach A2A server authorizes requests under its own policies, and the specification calls that logic implementation-specific.⁠Source 1Zenity says its kill switch immediately disables an agent’s tool and data access.⁠Source 5 It says rules can shut agents down.⁠Source 5
Audit trailA2A docs advise auditing task creation, critical state changes, and agent actions, and tracing, for example with OpenTelemetry.⁠Source 14Zenity says it logs agent messages and tool calls, and can stream audit log events to Splunk or Microsoft Sentinel.⁠Source 4, Source 9
ComplianceSits with the implementer: A2A docs say to ensure compliance with regulations such as GDPR, CCPA, and HIPAA.⁠Source 14Company-wide, Zenity cites SOC 2 Type II and ISO 27001 compliance.⁠Source 23 It announced FedRAMP “In Process” status in March 2026.⁠Source 24

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

DIY and Zenity compared on 18 criteria
DIYZenity
What it is
What it is and who it’s forYour own build on protocols such as A2A, an open standard for communication between agent systems, and MCP, which the A2A specification calls complementary.⁠Source 1A SaaS security and governance platform for AI agents spanning SaaS, homegrown cloud platforms, and end-user devices, which Zenity aims at security teams.⁠Source 3, Source 16
MaturityVaries by component: MCP’s latest revision is 2026-07-28.⁠Source 2, Source 25 The official MCP Registry is in preview and may have breaking changes or data resets.⁠Source 18Zenity announced AWS Marketplace availability in January 2026.⁠Source 26 Zenity says GitHub Copilot and OpenAI Codex coverage became generally available in August 2026.⁠Source 9
Control
Agent registry and discoveryBuild your own: A2A prescribes no standard API for curated registries.⁠Source 13 Pinterest’s internal registry is its source of truth for approved MCP servers.⁠Source 8Zenity says AI Observability scans and catalogs agents in SaaS platforms, custom builds, and laptops, each with its permissions and tool access.⁠Source 4
Identity and access controlIn A2A, identity is established at the HTTP layer and authorization logic is implementation-specific.⁠Source 1, Source 14 MCP makes authorization optional.⁠Source 22Zenity says Boundaries rules can use Okta attributes such as active status, role, department, and job title.⁠Source 5 Issuing agent credentials isn’t in its public docs.
Ownership, policy, and revocationMCP says implementers should build consent and authorization flows.⁠Source 2 Uber starts every MCP server and tool disabled until the owning team reviews and enables it.⁠Source 7Zenity says its kill switch immediately disables an agent’s tool and data access.⁠Source 5 It says blocking covers Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 6
Audit log and observabilityA2A docs advise auditing significant events.⁠Source 14 Pinterest’s MCP servers share library functions that log inputs, outputs, invocation counts, and exception traces.⁠Source 8Zenity says it logs messages, tool calls, retrievals, and handoffs, and audit events can stream to Splunk or Sentinel.⁠Source 4, Source 9 It says findings are available by API.⁠Source 19
Connection
How agents connectMCP servers on Streamable HTTP expose an HTTP endpoint; A2A agents on HTTP use HTTPS URLs in production.⁠Source 1, Source 21 Uber routes gateway requests via its service mesh.⁠Source 7Zenity says agents emitting OpenTelemetry or gen_ai spans can connect, with an Evaluate API for enforcement.⁠Source 9 Network requirements aren’t in its public docs.
Agents across organizationsA2A is designed for agents from different companies on separate servers.⁠Source 20 Each server authorizes requests under its own policies.⁠Source 1Not in Zenity’s public docs; its product docs require a login (checked 2 October 2026)⁠Source 27
Protocol supportMCP defines stdio and Streamable HTTP transports.⁠Source 28 A2A maps to JSON-RPC, gRPC, and HTTP/REST bindings.⁠Source 1Zenity says custom agents can connect by emitting OpenTelemetry or gen_ai spans.⁠Source 9 Whether Zenity supports A2A isn’t publicly documented.
Frameworks, models, and clouds supportedA2A gives agents built on different frameworks, languages, or vendors a common language.⁠Source 1 Google’s ADK says it is model-agnostic and deployment-agnostic.⁠Source 10Zenity says it covers agents in Copilot Studio, Agentforce, and homegrown builds on Foundry, Bedrock, or Vertex AI, and any OTel agent can connect.⁠Source 4, Source 9
Operations
Deployment options and data residencyWherever you run it: Pinterest optimized for MCP servers in its internal cloud.⁠Source 8 A2A docs leave protecting stored data to your own policies.⁠Source 14Software as a service, shown on AWS Marketplace as deployed on AWS.⁠Source 3 Regions, data residency, and self-hosting aren’t in Zenity’s public docs.
Compliance attestationsSits with the implementer: A2A docs cite regulations such as GDPR, CCPA, and HIPAA, and MCP leaves access controls and data protection to implementers.⁠Source 2, Source 14Zenity says the company holds SOC 2 Type II certification and is ISO 27001 compliant.⁠Source 23 It announced FedRAMP “In Process” status in March 2026.⁠Source 24
Support and SLADepends on the component: MCP SDKs are tiered partly by maintenance commitments.⁠Source 29 The official MCP Registry, in preview, gives no uptime guarantees.⁠Source 30Zenity’s subscription terms commit to 99.9% monthly uptime, on a commercially reasonable efforts basis.⁠Source 31 Support requests go through Zendesk in business hours.⁠Source 31
Time and effort to get runningA curated A2A registry is a service you deploy and maintain.⁠Source 13 Pinterest built a unified deployment pipeline after new MCP servers took too much setup.⁠Source 8Zenity says it added custom-agent guides for Cribl, LiteLLM, and Kong.⁠Source 9 Prerequisites aren’t in Zenity’s public docs; its product docs require a login.⁠Source 27
Pricing model and public pricesOpenly licensed specifications, such as A2A under Apache 2.0.⁠Source 1 Build and running costs are not publicly documented.Main AWS listing: custom pricing.⁠Source 3 Security Hub Extended listing: Observability $130 per resource a month, Runtime Protection $16 per million tokens a month.⁠Source 17
Building
Agent building toolsFrameworks such as LangGraph and Google’s open-source Agent Development Kit build and deploy agents.⁠Source 10, Source 11 A2A has SDKs in six languages.⁠Source 32Not in Zenity’s public docs; its product docs require a login (checked 2 October 2026)⁠Source 27
Model accessChosen by whoever builds the agents: Google’s ADK says it is optimized for Gemini and model-agnostic.⁠Source 10Zenity says AIDR pairs deterministic rules mapped to OWASP LLM and MITRE ATLAS with LLM-based detections.⁠Source 19 Which models it uses isn’t in Zenity’s public docs.
Integrations and ecosystemThe official MCP Registry, in preview, has a REST API for clients and aggregators to discover MCP servers.⁠Source 18Zenity says its risk signals show in Microsoft Agent 365 and findings can go to AWS Security Hub Extended.⁠Source 33, Source 34 It says it is on the Cursor Marketplace.⁠Source 35

Which to choose

Choose DIY if

  • Your agents must work with other companies’ agents: A2A is designed for agents built by different companies on separate servers.⁠Source 20
  • You want your own approval process: Uber starts every MCP server disabled until reviewed; Pinterest reviews all but one-off experiments.⁠Source 7, Source 8
  • You want infrastructure you already run to check MCP calls, as Uber does with its Access Control System and Pinterest with Envoy.⁠Source 7, Source 8
  • You want no agent platform contract and openly licensed specifications, such as A2A under Apache 2.0.⁠Source 1

Choose Zenity if

  • You need what Zenity says it offers: finding agents in Copilot Studio, ChatGPT Enterprise, Agentforce, custom builds, and laptops.⁠Source 4
  • You want the real-time checks Zenity says it runs on agent actions, blocking inline on Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 5, Source 6
  • You want what Zenity says it offers: findings and audit events in Splunk, Sentinel, AWS Security Hub, or, by API, your SIEM.⁠Source 9, Source 19, Source 34
  • You want coding agents like Claude Code, Cursor, and Codex covered; Zenity says it can block risky tool calls there.⁠Source 9, Source 15

Questions buyers ask

Is Zenity an alternative to building agent governance yourself?

For discovery, runtime rules, and activity logs, it can be: Zenity says it inventories agents, can check agent actions against your rules, and logs agent interactions.⁠Source 4, Source 5 Letting agents find and call each other through it isn’t in Zenity’s public docs.

Can Zenity cover agents we built ourselves?

Zenity says yes: any agent emitting OpenTelemetry or gen_ai spans can connect without a dedicated integration, and discovery extends to homegrown agents built on platforms such as Azure AI Foundry, AWS Bedrock, or Google Vertex AI.⁠Source 4, Source 9

Does Zenity support A2A?

Whether Zenity supports A2A isn’t publicly documented. Zenity says its AIDR shows requests and responses passed between agents, and AI Observability logs handoffs between agents.⁠Source 4, Source 19

How is Zenity priced?

Its main AWS Marketplace listing points to custom pricing or a private contract.⁠Source 3 Its Security Hub Extended listing shows usage prices, such as $130 per resource a month for Observability, and a 30-day free trial.⁠Source 17

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

40 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Agent2Agent (A2A) Protocol Specification a2a-protocol.org · checked Back:abcdefghijklmnop

  2. Source 2: Specification - Model Context Protocol 2026-07-28 modelcontextprotocol.io · checked Back:abcde

  3. Source 3: AWS Marketplace: Zenity Zenity · checked Back:abcdefghijk

  4. Source 4: AI Observability | See Every Agent, Know What it Touches | Zenity Zenity · checked Back:abcdefghijklmn

  5. Source 5: Runtime Boundaries | The Runtime Boundary for Autonomous AI | Zenity Zenity · checked Back:abcdefghijk

  6. Source 6: Zenity's Coverage of the 2026 OWASP Top 10 for LLM Apps Zenity · checked Back:abcde

  7. Source 7: Designing MCP Gateway Uber's MCP Management Platform - Uber Blog uber.com · checked Back:abcdefgh

  8. Source 8: Building an MCP Ecosystem at Pinterest - Pinterest Engineering Blog medium.com · checked Back:abcdefghij

  9. Source 9: From Triage to Full Coverage: The Shift AI Agent Security Took in August Zenity · checked Back:abcdefghijklm

  10. Source 10: google/adk-python README (GitHub) github.com · checked Back:abcd

  11. Source 11: langchain-ai/langgraph README (GitHub) github.com · checked Back:ab

  12. Source 12: Integrating with Model Context Protocol (MCP) - Keycloak keycloak.org · checked Back to text

  13. Source 13: Agent Discovery - A2A Protocol a2a-protocol.org · checked Back:abcde

  14. Source 14: Enterprise Features - A2A Protocol a2a-protocol.org · checked Back:abcdefgh

  15. Source 15: Coding and Personal Agents | Zenity Zenity · checked Back:ab

  16. Source 16: Platform | AI Agent Security & Governance Platform | Zenity Zenity · checked Back:abc

  17. Source 17: AWS Marketplace: Zenity AI Security & Governance Platform for Security Hub Extended Zenity · checked Back:abc

  18. Source 18: The MCP Registry - Model Context Protocol modelcontextprotocol.io · checked Back:abc

  19. Source 19: AI Detection and Response (AIDR) | See the Threat, Stop the Action | Zenity Zenity · checked Back:abcde

  20. Source 20: a2aproject/A2A README (GitHub) github.com · checked Back:abc

  21. Source 21: Streamable HTTP - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back:ab

  22. Source 22: Authorization - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back:ab

  23. Source 23: Zenity Trust Center Zenity · checked Back:ab

  24. Source 24: Zenity Achieves FedRAMP “In Process” Status for AI Agent Security Zenity · checked Back:ab

  25. Source 25: Key Changes - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back to text

  26. Source 26: Zenity Now Available on AWS Marketplace, Bringing End-to-End Security to Amazon Bedrock AgentCore and Enterprise AI Agents Everywhere Zenity · checked Back to text

  27. Source 27: Zenity Documentation (login) Zenity · checked Back:abc

  28. Source 28: Transports - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back to text

  29. Source 29: SDK Tiers - Model Context Protocol modelcontextprotocol.io · checked Back to text

  30. Source 30: MCP Registry Aggregators - Model Context Protocol modelcontextprotocol.io · checked Back to text

  31. Source 31: Zenity Subscription Terms and Conditions (EULA linked from Zenity's AWS Marketplace listings) Zenity · checked Back:ab

  32. Source 32: A2A protocol roadmap a2a-protocol.org · checked Back to text

  33. Source 33: Zenity Now Integrates with Microsoft Agent 365 Zenity · checked Back to text

  34. Source 34: Zenity Selected for AWS Security Hub Extended to Secure Enterprise AI Agents Zenity · checked Back:ab

  35. Source 35: Seeing Every MCP Connection: Zenity Joins the Cursor Marketplace Zenity · checked Back to text

  36. Source 36: Your company's private network Blocks.ai · checked Back to text

  37. Source 37: Network requirements Blocks.ai · checked Back to text

  38. Source 38: Solutions: Agent sprawl Blocks.ai · checked Back to text

  39. Source 39: Solutions: Partner networks Blocks.ai · checked Back to text

  40. Source 40: Pricing Blocks.ai · checked Back to text