Gateway at the network.
Aona governs AI on the endpoint.
SurePath AI and Aona both govern workforce GenAI use, but they meet it at different points. SurePath is an agentless AI gateway that inspects and redacts AI traffic at the network level, with no agents or extensions to deploy. Aona watches at the endpoint across the browser, the native desktop, and the AI agent, and adds real-time employee coaching and AI upskilling. The differences are deployment model, where coverage reaches, and how AI risk is changed over time.
Enterprise GenAI governance via a network-level AI gateway: agentless inspection, real-time redaction, group-based policy, and audit trails. Now part of the F5 AI Security Platform.
La plataforma Workforce AI Security para cualquier empresa que adopta la IA generativa, con una cobertura de endpoints más amplia que la de los actores establecidos, una prueba más sencilla y una de las pocas que ofrece DLP de bloqueo estricto para los prompts y archivos de IA.
Elija Aona si necesita una cobertura de endpoints que capte aplicaciones de IA de escritorio nativas, IA local y el uso fuera de la red en los dispositivos donde Aona está desplegado, orientación en tiempo real y formación en IA para los empleados, y una prueba self-service de 30 días con DLP de bloqueo estricto para prompts y archivos. Elija SurePath AI solo si exige una gobernanza sin agente, del lado de la red, del acceso a GenAI (capa SASE, proxy, DNS), que desde el anuncio de la adquisición por F5 en junio de 2026 se vende dentro de la F5 AI Security Platform.
Ir a la matriz de decisiónSOC 2 Type II · Prueba gratuita de 30 días · Sin tarjeta de crédito · Operativo en 1 hora
Datos de proveedores verificados en julio de 2026
What the F5 acquisition changes
- F5 anunció la adquisición de SurePath AI el 24 de junio de 2026. Los términos financieros no se divulgaron.
- La operación se anunció junto con el lanzamiento de la F5 AI Security Platform, donde, según F5, el descubrimiento de IA basado en red y la detección de Shadow AI de SurePath se convierten en uno de los componentes de la plataforma. Es la segunda adquisición de F5 en seguridad de IA, después de CalypsoAI en septiembre de 2025.
- SurePath AI is now marketed as part of the F5 AI Security Platform, so buyers researching SurePath should evaluate it under both names.
- ?Will SurePath's gateway remain available standalone, or only as a module of the F5 AI Security Platform and its licensing?
- ?What happens to existing SurePath contracts, support arrangements, and certifications as the integration proceeds?
- ?How will the GenAI governance roadmap be prioritised inside F5's broader application delivery and security portfolio?
Aona is independent and purpose-built for Workforce AI Security, with 7-region data residency (AU, FR, UK, DE, US, SG, HK) and a 30-day self-serve trial, so you can evaluate the endpoint approach on your own terms while the F5 integration takes shape.
Cuándo elegir cada opción
Cinco escenarios. La respuesta honesta para cada uno.
You want GenAI governance with no agent or browser extension to deploy.
SurePath AI captures AI interactions at the network level with no agents or extensions required, so it sees AI traffic without touching the device. Aona requires its browser plugin or native endpoint on the device. There is no network-only or agentless mode in Aona.
Necesita tanto el control de red del egress de IA del lado del servidor como profundidad en el endpoint.
SurePath, ahora parte de la F5 AI Security Platform, inspecciona el tráfico de IA a nivel de red, incluido el egress del lado del servidor que nunca toca un navegador gestionado. Aona capta las aplicaciones de escritorio nativas, la IA local y el uso fuera de la red en los dispositivos donde Aona está desplegado, algo que una ruta de red puede pasar por alto. La cobertura completa combina una capa de red con una capa de endpoint.
You need to catch native desktop AI apps, local AI, and off-network use on devices where Aona is deployed.
Aona inspects across three layers: browser plugin, native desktop endpoint app, and AI agent inspection (limited rollout). This reaches native desktop apps like ChatGPT, Copilot, and Claude desktop, plus local AI and off-network use on devices where Aona is deployed, which a purely network-layer gateway can miss.
You want to change employee AI behaviour, not just block or redact at the gateway.
Aona delivers real-time employee coaching at the moment of a risky prompt and runs AI upskilling programs. SurePath focuses on gateway-side enforcement and redaction; it does not document an in-the-flow employee coaching or upskilling layer.
Quiere una prueba self-service, precios publicados y una postura de confianza publicada.
Aona ofrece una prueba self-service de 30 días, publica sus precios y cuenta con SOC 2 Type II. SurePath está dirigido por ventas y no documenta públicamente sus certificaciones; ahora está posicionado dentro de la F5 AI Security Platform, lo que encaja con compradores empresariales de mayor tamaño.
Lo que cada herramienta hace realmente
Tres columnas en el lado de Aona porque la extensión de navegador y la aplicación nativa de endpoint cubren áreas distintas. Los clientes que solo tienen la extensión verán menos marcas verdes que quienes disponen de ambas.
| Capacidad | Extensión de navegador de Aona | Aplicación nativa de Aona | SurePath AI |
|---|---|---|---|
| Descubrir | |||
| Network-level AI traffic visibility (agentless) | Endpoint-based, not network | Endpoint-based, not network | Core of the platform |
| Shadow AI discovery on endpoints | Browser surface | Browser plus native AI apps | Network-level discovery |
| Native desktop AI app interception (ChatGPT, Copilot, Claude desktop) | Plus generic process-signature detection | Network-visible if traffic is in scope | |
| AI agent / MCP visibility | Limited rollout: process, network, MCP | Network-level agent and MCP policy controls | |
| Gobernar | |||
| Group-based policy across models, agents, and tools | Entra group-based policy | Entra group-based policy | Core differentiator |
| Real-time sensitive-data redaction in AI requests and responses | Prompt and file redaction | Prompt and file redaction | Inspects inputs and outputs at the gateway |
| Hard-block DLP on AI prompts | Modal pauses, no override | Gateway-side filtering and redaction | |
| Real-time employee coaching at the moment of a risky prompt | Gateway enforcement, not in-flow coaching | ||
| AI upskilling and adoption programs | |||
| Proteger | |||
| Hard-block DLP on file uploads with layout-preserving redaction (DOCX / Excel) | Length-matched, in production | Length-matched, in production | Gateway redaction, not in-place file redaction |
| Enterprise audit trails of AI interactions | Requests, responses, intent | ||
| SIEM / DLP / IdP integration with existing stack | Microsoft Sentinel (OCSF), Entra | Microsoft Sentinel (OCSF), Entra | Integrates with SIEM, DLP, IdP |
| Operaciones | |||
| Deployment model | Endpoint (browser plugin) | Endpoint (native app) | Agentless network gateway |
| Trial motion | 30-day self-serve | 30-day self-serve | Sales-led evaluation |
| Compliance posture (publicly documented) | SOC 2 Type II | SOC 2 Type II | Not publicly documented |
Basado en la documentación de los proveedores a fecha de julio de 2026. Escriba a trust@aona.ai si detecta un error factual.
Lo que requiere poner en marcha cada uno
- Microsoft Intune (Windows MDM, only path shipped)
- Microsoft Entra (admin SSO and user / group sync)
- Network routing to send AI traffic through the gateway
- Identity provider for group-based policy
Dónde se queda corto cada uno
A partir de documentos públicos y entrevistas con clientes. Si detecta un error factual, escriba a trust@aona.ai.
- Requires the browser plugin or native endpoint on the device. No agentless or network-only mode.
- Endpoint coverage only sees AI use on managed devices, not server-side or non-browser AI egress across the whole network.
- La inspección de agentes de IA y MCP está en despliegue limitado, y no hay cobertura móvil (iOS / Android). A escala empresarial, macOS se instala manualmente; solo el endpoint de Windows se distribuye vía Intune.
- Agentless network gateway can miss native desktop AI apps, local AI, and off-network use that an endpoint agent on the device still sees.
- No real-time employee coaching or AI upskilling layer to change behaviour over time; enforcement is at the gateway.
- Sales-led evaluation rather than a self-serve trial.
- Certifications such as SOC 2 are not publicly documented on the product site.
Lo que preguntará su revisión de seguridad
Certificaciones, realidad de precios, tratamiento de datos y residencia para ambos proveedores, respondidos de antemano para que su revisión de GRC y legal pueda partir de esta página.
| Aona | SurePath AI | |
|---|---|---|
| Certificaciones | SOC 2 Type II (periodo de auditoría finalizado en febrero de 2026). Sin FedRAMP ni IRAP por ahora. | No documentado públicamente (a julio de 2026) |
| Precios y prueba | Precios publicados: plan Business de 9,99 $ por usuario al mes, Enterprise a medida. Prueba gratuita self-service de 30 días, sin tarjeta de crédito. A julio de 2026. | Sin precios públicos ni prueba self-service. Venta dirigida por el equipo comercial, ahora como parte de la F5 AI Security Platform. A julio de 2026. |
| Dónde se procesan los prompts | El contenido de los prompts se procesa del lado del servidor mediante la API de Aona en la región que elija. Retención configurable: 30, 90 o 180 días. | El tráfico de IA se inspecciona del lado de la red (capa SASE, proxy, DNS). Las regiones de procesamiento no están documentadas públicamente (a julio de 2026). |
| Residencia de datos | 7 regiones activas: Australia, Francia, Reino Unido, Alemania, EE. UU., Singapur, Hong Kong. Los prompts, los archivos y los registros de auditoría permanecen en la región. | No documentado públicamente (a julio de 2026) |
| DPA y documentación de seguridad | DPA disponible bajo petición. Resumen de seguridad en aona.ai/security. Informe SOC 2 bajo NDA. | No documentado públicamente (a julio de 2026) |
Los datos del competidor proceden de documentación y páginas de precios públicas. Cuando un proveedor no publica un dato, lo decimos en lugar de adivinar. Correcciones: trust@aona.ai.
Migrating from SurePath AI
SurePath AI and Aona are not mutually exclusive at the architecture level: one watches the network, the other watches the endpoint and coaches the employee. If you are choosing one, the honest path is a 30-day Aona free trial alongside any SurePath evaluation. Pick by where your AI risk actually lives. If most of it is server-side egress, non-browser apps, or unmanaged devices you cannot put an agent on, the agentless gateway matters more. If most of it is native desktop AI apps, browser use, and employees who need coaching in the moment, the endpoint layer matters more.
- Existing identity provider (Microsoft Entra, or any OIDC / SAML provider)
- Existing MDM (Intune)
- Network gateway already routing managed AI traffic
- Sales-led, paid evaluation for AI DLP
- Gateway-only visibility that misses native desktop and off-network AI use on deployed devices
- Block-and-redact-only enforcement with no employee coaching
- Duplicate prompt-DLP rules where the endpoint already enforces them
- Manual incident triage if Aona's policy violation trend reporting covers your board reporting need
Try Aona alongside SurePath AI, on your real traffic
30-day self-serve free trial. Deploys at the endpoint via Intune and Entra in under an hour, so you can see what an agentless gateway misses on native desktop apps and off-network use. No commitment.