Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
DIY vs Zenity: an in-house build or a security and governance platform for AI agents
Build it yourself (DIY)
Building agent connections and controls in-house from open protocols, existing infrastructure, and open-source tools
Zenity AI Agent Security & Governance Platform
Security and governance platform for AI agents, aimed at security teams
Short answer
DIY is not a product: you connect and govern agents yourself on protocols like MCP and A2A, which leave authorization logic to the implementer.Source 1, Source 2 Zenity calls itself a security and governance platform for AI agents, delivered as SaaS, and says it finds agents and can check their actions against your rules and block some.Source 3, Source 4, Source 5, Source 6
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
- Where they overlap
- Both cover governance: Uber and Pinterest built registries and review rules for their MCP servers, and Zenity says it inventories agents and can check their actions against runtime rules.Source 4, Source 5, Source 7, Source 8
- Where they differ
- Zenity says it secures agents where they run.Source 3, Source 4 Letting agents find and call each other through it isn’t in Zenity’s public docs. DIY also connects agents, for example over A2A.Source 1
- Running both
- Zenity says any agent emitting OpenTelemetry or gen_ai spans can connect to it without a dedicated integration.Source 9
DIY
Zenity
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Identity and access: Not publicly documented
- Agents across organizations: Not publicly documented
At a glance
What each one is
Build it yourself (DIY)
DIY means connecting and governing agents without a product made for the job: protocols such as MCP and A2A, your own registry and access checks, existing gateways and identity providers, or no central approach; Uber and Pinterest have each described running their own MCP registry.Source 7, Source 8
Zenity AI Agent Security & Governance Platform
Zenity’s AWS Marketplace listing calls it a security and governance platform for AI agents, delivered as SaaS.Source 3 Zenity describes three layers: Surface, for what an agent can reach; Enforce, when a decision is made; and Protect, for what slips through.Source 16
The differences that matter
Finding agents
DIYYou build the list: A2A prescribes no standard API for curated registries, and Pinterest’s own registry is its source of truth for approved MCP servers.Source 8, Source 13
ZenityZenity says AI Observability scans your environment and catalogs agents in SaaS platforms, custom builds, and laptops, each with its permissions and tool access.Source 4
The official MCP Registry is in preview and does not support private servers; its docs recommend hosting your own private registry for those.Source 18
Rules on agent actions
DIYYou build the checks: Uber’s MCP gateway applies its internal Access Control System policies to callers it identifies as humans, services, or agents.Source 7
ZenityZenity says Boundaries can check agent actions in real time against your rules and can block actions on Copilot Studio, Microsoft Foundry, and coding agents.Source 5, Source 6
Zenity says Boundaries rules can reference Okta attributes such as active status, role, department, and job title.Source 5
Traffic between agents
DIYYou build the connections, for example over A2A, which gives agents built on different frameworks, languages, or vendors a common language.Source 1
ZenityZenity says AIDR shows requests and responses passed between agents, and tracks triggers, retrievals, tool invocations, and handoffs step by step.Source 19
A2A is designed for agents built by different companies on separate servers.Source 20 Reaching a partner’s agents, with access the partner controls, isn’t in Zenity’s public docs.
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| DIY | Zenity | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | Your own build on protocols such as A2A, an open standard for communication between agent systems, and MCP, which the A2A specification calls complementary.Source 1 | A SaaS security and governance platform for AI agents spanning SaaS, homegrown cloud platforms, and end-user devices, which Zenity aims at security teams.Source 3, Source 16 |
| Maturity | Varies by component: MCP’s latest revision is 2026-07-28.Source 2, Source 25 The official MCP Registry is in preview and may have breaking changes or data resets.Source 18 | Zenity announced AWS Marketplace availability in January 2026.Source 26 Zenity says GitHub Copilot and OpenAI Codex coverage became generally available in August 2026.Source 9 |
| Control | ||
| Agent registry and discovery | Build your own: A2A prescribes no standard API for curated registries.Source 13 Pinterest’s internal registry is its source of truth for approved MCP servers.Source 8 | Zenity says AI Observability scans and catalogs agents in SaaS platforms, custom builds, and laptops, each with its permissions and tool access.Source 4 |
| Identity and access control | In A2A, identity is established at the HTTP layer and authorization logic is implementation-specific.Source 1, Source 14 MCP makes authorization optional.Source 22 | Zenity says Boundaries rules can use Okta attributes such as active status, role, department, and job title.Source 5 Issuing agent credentials isn’t in its public docs. |
| Ownership, policy, and revocation | MCP says implementers should build consent and authorization flows.Source 2 Uber starts every MCP server and tool disabled until the owning team reviews and enables it.Source 7 | Zenity says its kill switch immediately disables an agent’s tool and data access.Source 5 It says blocking covers Copilot Studio, Microsoft Foundry, and coding agents.Source 6 |
| Audit log and observability | A2A docs advise auditing significant events.Source 14 Pinterest’s MCP servers share library functions that log inputs, outputs, invocation counts, and exception traces.Source 8 | Zenity says it logs messages, tool calls, retrievals, and handoffs, and audit events can stream to Splunk or Sentinel.Source 4, Source 9 It says findings are available by API.Source 19 |
| Connection | ||
| How agents connect | MCP servers on Streamable HTTP expose an HTTP endpoint; A2A agents on HTTP use HTTPS URLs in production.Source 1, Source 21 Uber routes gateway requests via its service mesh.Source 7 | Zenity says agents emitting OpenTelemetry or gen_ai spans can connect, with an Evaluate API for enforcement.Source 9 Network requirements aren’t in its public docs. |
| Agents across organizations | A2A is designed for agents from different companies on separate servers.Source 20 Each server authorizes requests under its own policies.Source 1 | Not in Zenity’s public docs; its product docs require a login (checked 2 October 2026)Source 27 |
| Protocol support | MCP defines stdio and Streamable HTTP transports.Source 28 A2A maps to JSON-RPC, gRPC, and HTTP/REST bindings.Source 1 | Zenity says custom agents can connect by emitting OpenTelemetry or gen_ai spans.Source 9 Whether Zenity supports A2A isn’t publicly documented. |
| Frameworks, models, and clouds supported | A2A gives agents built on different frameworks, languages, or vendors a common language.Source 1 Google’s ADK says it is model-agnostic and deployment-agnostic.Source 10 | Zenity says it covers agents in Copilot Studio, Agentforce, and homegrown builds on Foundry, Bedrock, or Vertex AI, and any OTel agent can connect.Source 4, Source 9 |
| Operations | ||
| Deployment options and data residency | Wherever you run it: Pinterest optimized for MCP servers in its internal cloud.Source 8 A2A docs leave protecting stored data to your own policies.Source 14 | Software as a service, shown on AWS Marketplace as deployed on AWS.Source 3 Regions, data residency, and self-hosting aren’t in Zenity’s public docs. |
| Compliance attestations | Sits with the implementer: A2A docs cite regulations such as GDPR, CCPA, and HIPAA, and MCP leaves access controls and data protection to implementers.Source 2, Source 14 | Zenity says the company holds SOC 2 Type II certification and is ISO 27001 compliant.Source 23 It announced FedRAMP “In Process” status in March 2026.Source 24 |
| Support and SLA | Depends on the component: MCP SDKs are tiered partly by maintenance commitments.Source 29 The official MCP Registry, in preview, gives no uptime guarantees.Source 30 | Zenity’s subscription terms commit to 99.9% monthly uptime, on a commercially reasonable efforts basis.Source 31 Support requests go through Zendesk in business hours.Source 31 |
| Time and effort to get running | A curated A2A registry is a service you deploy and maintain.Source 13 Pinterest built a unified deployment pipeline after new MCP servers took too much setup.Source 8 | Zenity says it added custom-agent guides for Cribl, LiteLLM, and Kong.Source 9 Prerequisites aren’t in Zenity’s public docs; its product docs require a login.Source 27 |
| Pricing model and public prices | Openly licensed specifications, such as A2A under Apache 2.0.Source 1 Build and running costs are not publicly documented. | Main AWS listing: custom pricing.Source 3 Security Hub Extended listing: Observability $130 per resource a month, Runtime Protection $16 per million tokens a month.Source 17 |
| Building | ||
| Agent building tools | Frameworks such as LangGraph and Google’s open-source Agent Development Kit build and deploy agents.Source 10, Source 11 A2A has SDKs in six languages.Source 32 | Not in Zenity’s public docs; its product docs require a login (checked 2 October 2026)Source 27 |
| Model access | Chosen by whoever builds the agents: Google’s ADK says it is optimized for Gemini and model-agnostic.Source 10 | Zenity says AIDR pairs deterministic rules mapped to OWASP LLM and MITRE ATLAS with LLM-based detections.Source 19 Which models it uses isn’t in Zenity’s public docs. |
| Integrations and ecosystem | The official MCP Registry, in preview, has a REST API for clients and aggregators to discover MCP servers.Source 18 | Zenity says its risk signals show in Microsoft Agent 365 and findings can go to AWS Security Hub Extended.Source 33, Source 34 It says it is on the Cursor Marketplace.Source 35 |
Which to choose
Choose DIY if
- Your agents must work with other companies’ agents: A2A is designed for agents built by different companies on separate servers.Source 20
- You want your own approval process: Uber starts every MCP server disabled until reviewed; Pinterest reviews all but one-off experiments.Source 7, Source 8
- You want infrastructure you already run to check MCP calls, as Uber does with its Access Control System and Pinterest with Envoy.Source 7, Source 8
- You want no agent platform contract and openly licensed specifications, such as A2A under Apache 2.0.Source 1
Choose Zenity if
- You need what Zenity says it offers: finding agents in Copilot Studio, ChatGPT Enterprise, Agentforce, custom builds, and laptops.Source 4
- You want the real-time checks Zenity says it runs on agent actions, blocking inline on Copilot Studio, Microsoft Foundry, and coding agents.Source 5, Source 6
- You want what Zenity says it offers: findings and audit events in Splunk, Sentinel, AWS Security Hub, or, by API, your SIEM.Source 9, Source 19, Source 34
- You want coding agents like Claude Code, Cursor, and Codex covered; Zenity says it can block risky tool calls there.Source 9, Source 15
Questions buyers ask
Is Zenity an alternative to building agent governance yourself?
Can Zenity cover agents we built ourselves?
Does Zenity support A2A?
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
40 public sources, each with the date we checked it. Every one opens in a new tab.
Source 1: Agent2Agent (A2A) Protocol Specification Back:abcdefghijklmnop
Source 2: Specification - Model Context Protocol 2026-07-28 Back:abcde
Source 4: AI Observability | See Every Agent, Know What it Touches | Zenity Back:abcdefghijklmn
Source 5: Runtime Boundaries | The Runtime Boundary for Autonomous AI | Zenity Back:abcdefghijk
Source 6: Zenity's Coverage of the 2026 OWASP Top 10 for LLM Apps Back:abcde
Source 7: Designing MCP Gateway Uber's MCP Management Platform - Uber Blog Back:abcdefgh
Source 8: Building an MCP Ecosystem at Pinterest - Pinterest Engineering Blog Back:abcdefghij
Source 9: From Triage to Full Coverage: The Shift AI Agent Security Took in August Back:abcdefghijklm
Source 12: Integrating with Model Context Protocol (MCP) - Keycloak Back to text
Source 16: Platform | AI Agent Security & Governance Platform | Zenity Back:abc
Source 17: AWS Marketplace: Zenity AI Security & Governance Platform for Security Hub Extended Back:abc
Source 18: The MCP Registry - Model Context Protocol Back:abc
Source 19: AI Detection and Response (AIDR) | See the Threat, Stop the Action | Zenity Back:abcde
Source 21: Streamable HTTP - Model Context Protocol specification 2026-07-28 Back:ab
Source 22: Authorization - Model Context Protocol specification 2026-07-28 Back:ab
Source 24: Zenity Achieves FedRAMP “In Process” Status for AI Agent Security Back:ab
Source 25: Key Changes - Model Context Protocol specification 2026-07-28 Back to text
Source 26: Zenity Now Available on AWS Marketplace, Bringing End-to-End Security to Amazon Bedrock AgentCore and Enterprise AI Agents Everywhere Back to text
Source 28: Transports - Model Context Protocol specification 2026-07-28 Back to text
Source 30: MCP Registry Aggregators - Model Context Protocol Back to text
Source 31: Zenity Subscription Terms and Conditions (EULA linked from Zenity's AWS Marketplace listings) Back:ab
Source 33: Zenity Now Integrates with Microsoft Agent 365 Back to text
Source 34: Zenity Selected for AWS Security Hub Extended to Secure Enterprise AI Agents Back:ab
Source 35: Seeing Every MCP Connection: Zenity Joins the Cursor Marketplace Back to text