Gateway at the network.
Aona governs AI on the endpoint.
SurePath AI and Aona both govern workforce GenAI use, but they meet it at different points. SurePath is an agentless AI gateway that inspects and redacts AI traffic at the network level, with no agents or extensions to deploy. Aona watches at the endpoint across the browser, the native desktop, and the AI agent, and adds real-time employee coaching and AI upskilling. The differences are deployment model, where coverage reaches, and how AI risk is changed over time.
Enterprise GenAI governance via a network-level AI gateway: agentless inspection, real-time redaction, group-based policy, and audit trails. Now part of the F5 AI Security Platform.
Die Workforce AI Security-Plattform für jedes Unternehmen, das generative KI einführt, mit breiterer Endpunktabdeckung als die etablierten Anbieter, einer einfacheren Testphase und eine der wenigen mit Hard-Block-DLP für KI-Prompts und Dateien.
Wählen Sie Aona, wenn Sie Endpunktabdeckung benötigen, die native Desktop-KI-Apps, lokale KI und die Nutzung außerhalb des Netzwerks auf Geräten mit installiertem Aona erfasst, Echtzeit-Coaching und KI-Weiterbildung der Mitarbeitenden sowie eine 30-tägige Self-Service-Testphase mit Hard-Block-DLP für Prompts und Dateien. Wählen Sie SurePath AI nur dann, wenn Sie eine agentenlose, netzwerkseitige Governance des GenAI-Zugriffs (SASE-, Proxy-, DNS-Ebene) verlangen, die seit der von F5 im Juni 2026 angekündigten Übernahme innerhalb der F5 AI Security Platform vertrieben wird.
Zur Entscheidungsmatrix springenSOC 2 Type II · 30 Tage kostenlos testen · Keine Kreditkarte · In 1 Stunde einsatzbereit
Anbieterfakten zuletzt geprüft: Juli 2026
What the F5 acquisition changes
- F5 kündigte die Übernahme von SurePath AI am 24. Juni 2026 an. Finanzielle Details wurden nicht offengelegt.
- Die Transaktion wurde zusammen mit dem Start der F5 AI Security Platform angekündigt, in der laut F5 SurePaths netzwerkbasierte KI-Erkennung und Shadow-AI-Detektion zu einem der Bausteine werden. Es ist F5s zweite Übernahme im Bereich KI-Sicherheit, nach CalypsoAI im September 2025.
- SurePath AI is now marketed as part of the F5 AI Security Platform, so buyers researching SurePath should evaluate it under both names.
- ?Will SurePath's gateway remain available standalone, or only as a module of the F5 AI Security Platform and its licensing?
- ?What happens to existing SurePath contracts, support arrangements, and certifications as the integration proceeds?
- ?How will the GenAI governance roadmap be prioritised inside F5's broader application delivery and security portfolio?
Aona is independent and purpose-built for Workforce AI Security, with 7-region data residency (AU, FR, UK, DE, US, SG, HK) and a 30-day self-serve trial, so you can evaluate the endpoint approach on your own terms while the F5 integration takes shape.
Wann Sie was wählen
Fünf Szenarien. Die ehrliche Antwort für jedes einzelne.
You want GenAI governance with no agent or browser extension to deploy.
SurePath AI captures AI interactions at the network level with no agents or extensions required, so it sees AI traffic without touching the device. Aona requires its browser plugin or native endpoint on the device. There is no network-only or agentless mode in Aona.
Sie benötigen sowohl serverseitige Netzwerkkontrolle des KI-Egress als auch Endpunkttiefe.
SurePath, inzwischen Teil der F5 AI Security Platform, prüft KI-Datenverkehr auf Netzwerkebene einschließlich serverseitigem Egress, der nie einen verwalteten Browser berührt. Aona erfasst native Desktop-Apps, lokale KI und die Nutzung außerhalb des Netzwerks auf Geräten mit installiertem Aona, die ein Netzwerkpfad übersehen kann. Vollständige Abdeckung kombiniert eine Netzwerkebene mit einer Endpunktebene.
You need to catch native desktop AI apps, local AI, and off-network use on devices where Aona is deployed.
Aona inspects across three layers: browser plugin, native desktop endpoint app, and AI agent inspection (limited rollout). This reaches native desktop apps like ChatGPT, Copilot, and Claude desktop, plus local AI and off-network use on devices where Aona is deployed, which a purely network-layer gateway can miss.
You want to change employee AI behaviour, not just block or redact at the gateway.
Aona delivers real-time employee coaching at the moment of a risky prompt and runs AI upskilling programs. SurePath focuses on gateway-side enforcement and redaction; it does not document an in-the-flow employee coaching or upskilling layer.
Sie möchten eine Self-Service-Testphase, veröffentlichte Preise und eine veröffentlichte Vertrauensbasis.
Aona bietet eine 30-tägige Self-Service-Testphase, veröffentlicht seine Preise und hält SOC 2 Type II. SurePath ist vertriebsgeführt und dokumentiert seine Zertifizierungen nicht öffentlich; es ist inzwischen innerhalb der F5 AI Security Platform positioniert, was zu größeren Enterprise-Käufern passt.
Was jedes Tool tatsächlich leistet
Drei Spalten auf der Aona-Seite, weil die Browser-Erweiterung und die native Endpunkt-App unterschiedliche Bereiche abdecken. Kunden mit nur der Browser-Erweiterung sehen weniger grüne Häkchen als Kunden mit beiden.
| Funktion | Aona Browser-Erweiterung | Aona native App | SurePath AI |
|---|---|---|---|
| Erkennen | |||
| Network-level AI traffic visibility (agentless) | Endpoint-based, not network | Endpoint-based, not network | Core of the platform |
| Shadow AI discovery on endpoints | Browser surface | Browser plus native AI apps | Network-level discovery |
| Native desktop AI app interception (ChatGPT, Copilot, Claude desktop) | Plus generic process-signature detection | Network-visible if traffic is in scope | |
| AI agent / MCP visibility | Limited rollout: process, network, MCP | Network-level agent and MCP policy controls | |
| Steuern | |||
| Group-based policy across models, agents, and tools | Entra group-based policy | Entra group-based policy | Core differentiator |
| Real-time sensitive-data redaction in AI requests and responses | Prompt and file redaction | Prompt and file redaction | Inspects inputs and outputs at the gateway |
| Hard-block DLP on AI prompts | Modal pauses, no override | Gateway-side filtering and redaction | |
| Real-time employee coaching at the moment of a risky prompt | Gateway enforcement, not in-flow coaching | ||
| AI upskilling and adoption programs | |||
| Schützen | |||
| Hard-block DLP on file uploads with layout-preserving redaction (DOCX / Excel) | Length-matched, in production | Length-matched, in production | Gateway redaction, not in-place file redaction |
| Enterprise audit trails of AI interactions | Requests, responses, intent | ||
| SIEM / DLP / IdP integration with existing stack | Microsoft Sentinel (OCSF), Entra | Microsoft Sentinel (OCSF), Entra | Integrates with SIEM, DLP, IdP |
| Betrieb | |||
| Deployment model | Endpoint (browser plugin) | Endpoint (native app) | Agentless network gateway |
| Trial motion | 30-day self-serve | 30-day self-serve | Sales-led evaluation |
| Compliance posture (publicly documented) | SOC 2 Type II | SOC 2 Type II | Not publicly documented |
Basierend auf der Anbieterdokumentation, Stand Juli 2026. Schreiben Sie an trust@aona.ai, wenn Sie einen sachlichen Fehler finden.
Was die Einführung jeder Lösung erfordert
- Microsoft Intune (Windows MDM, only path shipped)
- Microsoft Entra (admin SSO and user / group sync)
- Network routing to send AI traffic through the gateway
- Identity provider for group-based policy
Wo beide an ihre Grenzen stoßen
Aus öffentlichen Dokumenten und Kundengesprächen. Wenn Sie einen sachlichen Fehler finden, schreiben Sie an trust@aona.ai.
- Requires the browser plugin or native endpoint on the device. No agentless or network-only mode.
- Endpoint coverage only sees AI use on managed devices, not server-side or non-browser AI egress across the whole network.
- Die Inspektion von KI-Agenten und MCP befindet sich in einem begrenzten Rollout, und es gibt keine Mobilabdeckung (iOS / Android). macOS wird im Unternehmensmaßstab manuell installiert; nur der Windows-Endpunkt wird über Intune verteilt.
- Agentless network gateway can miss native desktop AI apps, local AI, and off-network use that an endpoint agent on the device still sees.
- No real-time employee coaching or AI upskilling layer to change behaviour over time; enforcement is at the gateway.
- Sales-led evaluation rather than a self-serve trial.
- Certifications such as SOC 2 are not publicly documented on the product site.
Was Ihr Security-Review fragen wird
Zertifizierungen, Preisrealität, Datenverarbeitung und Datenresidenz für beide Anbieter, vorab beantwortet, damit Ihr GRC- und Legal-Review direkt mit dieser Seite starten kann.
| Aona | SurePath AI | |
|---|---|---|
| Zertifizierungen | SOC 2 Type II (Auditzeitraum endete im Februar 2026). Derzeit kein FedRAMP oder IRAP. | Nicht öffentlich dokumentiert (Stand Juli 2026) |
| Preise und Test | Veröffentlichte Preise: Business-Plan 9,99 $ pro Nutzer und Monat, Enterprise individuell. 30-tägige kostenlose Self-Service-Testphase, keine Kreditkarte. Stand Juli 2026. | Keine öffentlichen Preise und keine Self-Service-Testphase. Vertriebsgeführt, inzwischen als Teil der F5 AI Security Platform verkauft. Stand Juli 2026. |
| Wo Prompts verarbeitet werden | Prompt-Inhalte werden serverseitig von der Aona-API in der von Ihnen gewählten Region verarbeitet. Aufbewahrung konfigurierbar: 30, 90 oder 180 Tage. | KI-Datenverkehr wird netzwerkseitig geprüft (SASE-, Proxy-, DNS-Ebene). Die Verarbeitungsregionen sind nicht öffentlich dokumentiert (Stand Juli 2026). |
| Datenresidenz | 7 aktive Regionen: Australien, Frankreich, Großbritannien, Deutschland, USA, Singapur, Hongkong. Prompts, Dateien und Audit-Logs bleiben in der Region. | Nicht öffentlich dokumentiert (Stand Juli 2026) |
| DPA und Sicherheitsunterlagen | DPA auf Anfrage verfügbar. Sicherheitsübersicht unter aona.ai/security. SOC-2-Bericht unter NDA. | Nicht öffentlich dokumentiert (Stand Juli 2026) |
Die Fakten zum Wettbewerber stammen aus öffentlicher Dokumentation und öffentlichen Preisseiten. Wo ein Anbieter eine Angabe nicht veröffentlicht, sagen wir das, statt zu raten. Korrekturen: trust@aona.ai.
Migrating from SurePath AI
SurePath AI and Aona are not mutually exclusive at the architecture level: one watches the network, the other watches the endpoint and coaches the employee. If you are choosing one, the honest path is a 30-day Aona free trial alongside any SurePath evaluation. Pick by where your AI risk actually lives. If most of it is server-side egress, non-browser apps, or unmanaged devices you cannot put an agent on, the agentless gateway matters more. If most of it is native desktop AI apps, browser use, and employees who need coaching in the moment, the endpoint layer matters more.
- Existing identity provider (Microsoft Entra, or any OIDC / SAML provider)
- Existing MDM (Intune)
- Network gateway already routing managed AI traffic
- Sales-led, paid evaluation for AI DLP
- Gateway-only visibility that misses native desktop and off-network AI use on deployed devices
- Block-and-redact-only enforcement with no employee coaching
- Duplicate prompt-DLP rules where the endpoint already enforces them
- Manual incident triage if Aona's policy violation trend reporting covers your board reporting need
Try Aona alongside SurePath AI, on your real traffic
30-day self-serve free trial. Deploys at the endpoint via Intune and Entra in under an hour, so you can see what an agentless gateway misses on native desktop apps and off-network use. No commitment.