Workforce AI Security · Why Aona
AonaCato AI Security
Aona vs Cato AI Security (formerly Aim Security)
Choose Aona for employee AI security.
See what sets Aona apart, compare the details, and try it on your own devices.
The verdict
The Aona advantage
Aona is built for employee AI security. Its offer includes a guided 30-day trial, a hard block on prompts and file uploads with no user override, layout-preserving DOCX, XLSX and PDF redaction, native coverage of the ChatGPT, Copilot and Claude desktop apps, real-time coaching and seven Aona-managed hosting regions, with a first signal during the agreed evaluation. Cato AI Security, the former Aim Security, is the AI firewall and agent control for the AI you build; since the September 2025 acquisition its capabilities ship inside the Cato SASE Cloud, its end-user controls inspect prompts in the Cato cloud once traffic is steered through a Cato point of presence rather than on the device, and Cato describes modular adoption of the platform, so verify the licence and steering prerequisites before you count on it for the prompt at the keyboard.
About this comparison
Aona secures employees' use of AI tools on the device: the browser plugin for Chrome, Edge, Firefox and Safari and the endpoint app for Windows and macOS inspect the prompt and the upload at submit, block hard when policy says so, redact DOCX, XLSX and PDF files with the layout intact, and coach the employee in the moment. Cato AI Security is the former Aim Security, delivered inside the Cato SASE Cloud since the acquisition announced on 3 September 2025: end-user AI controls enforced on traffic steered through Cato, an AI firewall for the applications and agents you build, and agentic AI security. This page shows where the two differ on the control point, file redaction, desktop coverage, trial and hosting.
The Workforce AI Security platform for any company adopting generative AI, with broader endpoint coverage than the incumbents, a simpler trial, and one of the few that ships hard-block DLP for AI prompts and files.
Cato AI Security (formerly Aim Security): Aim Security's AI security capabilities, sold as Cato AI Security inside the Cato SASE Cloud since the September 2025 acquisition: end-user AI controls, an AI firewall for applications and agentic AI security, demo-led.
What the Cato Networks acquisition changesAcquisition facts verified against Cato's 3 September 2025 announcement, product packaging re-checked September 2026
Cato Networks announced on 3 September 2025 that it had acquired Aim Security, calling it Cato's first-ever acquisition. Cato did not disclose the price; press reports put it at about USD 350 million.
Cato's announcement said Aim's capabilities would be offered as part of the Cato SASE Cloud Platform in early 2026, with a migration path for customers of the standalone Aim product, and that Cato supports modular and gradual adoption of platform capabilities, now including AI Security (AISEC).
As of September 2026, Cato markets the capabilities as Cato AI Security in three parts (AI Security for End Users, AI Security for Applications and Agentic AI Security), licensed as one of five converged solutions on the Cato SASE Cloud and sold through a demo request. aim.security redirected to catonetworks.com as of July 2026.
Questions worth asking before you commit
- Which licence and steering prerequisites does AI Security for End Users need on your estate: the Cato Client on every device, connected sites, or the Cato browser extension, and what does each add to the licence and the rollout?
- If you are not a Cato SASE customer, what is the minimum platform footprint to run AI Security, and can it be bought without moving your network to Cato?
- What did the migration path mean for standalone Aim contracts, and how is the employee AI roadmap prioritised inside a SASE platform agenda?
Where Aona stands
Aona is independent and purpose-built for Workforce AI Security, with no SASE dependency, seven Aona-managed hosting regions (AU, FR, UK, DE, US, SG, HK) and a 30-day guided trial, so you can evaluate the employee surface on your own devices while those questions get answered.
Decision matrix
When to pick Aona
Five buyer scenarios, answered for employee AI use.
01You need an AI firewall in front of the LLM applications and agents your own teams build.
Cato AI Security for Applications defends the AI apps and agents you build against prompt injection and runtime attacks, a surface Aona does not cover. Verify the commercial prerequisite first: the capability is licensed as one of five converged solutions on the Cato SASE Cloud, with modular adoption described by Cato, and the employee side still needs its own control on the device, which Aona ships with a 30-day guided trial.
02Your problem is employees pasting client data into ChatGPT, Copilot or Claude.
Aona inspects the prompt on the device at submit, hard-blocks with no user override, redacts DOCX, XLSX and PDF uploads with the layout intact and coaches the employee in the moment, in Chrome, Edge, Firefox and Safari and in the ChatGPT, Copilot and Claude desktop apps. Cato AI Security for End Users inspects prompts in the Cato cloud once traffic is steered through a Cato point of presence; a device outside that path, or an app whose traffic is not steered, is outside its mechanism.
03You already run Cato SASE and want the device layer of employee AI use covered too.
Nothing changes in the Cato tunnel: Aona's plugin and endpoint app are pushed with your existing deployment tooling and add on-device interception of the ChatGPT, Copilot and Claude desktop apps, layout-preserving file redaction and a hard block with no user override, with events streamed to Microsoft Sentinel via OCSF. The 30-day guided trial shows the gap on your own devices before any licence discussion with Cato.
04You want to evaluate this quarter with a guided trial, not a SASE procurement.
Aona starts with a 30-day guided trial: IT pushes the plugin and the endpoint app with its existing deployment tooling and the first signal arrives during the agreed evaluation. Cato AI Security is demo-led with no self-serve trial, and it is licensed as one of five converged solutions on the Cato SASE Cloud; Cato describes modular adoption, so confirm the licence scope and onboarding path before you plan a pilot (as of September 2026).
05Your employee AI data must stay in-region, with SIEM evidence for the security review.
Aona offers seven Aona-managed hosting regions (Australia, France, the UK, Germany, the US, Singapore and Hong Kong), with prompt processing selected separately, and streams events to Microsoft Sentinel via OCSF with a REST API and HMAC-signed webhooks. For Cato AI Security the storage region of AI security events and the SIEM mapping of those events are not publicly documented; ask Cato for both in writing, then compare with the region you pick in Aona at signup (as of September 2026).
Capability matrix
What each tool actually does
Choose a priority. Compare Aona’s browser plugin and native app with the other product.
| Capability | Aona browser plugin | Aona native app | Cato AI Security (formerly Aim Security) |
|---|---|---|---|
| Discover | |||
| Per-user shadow AI discovery across 10,000+ AI tools | Detection catalog; policy enforcement on the top-tier assistants | Supported | Agentless inventory of AI apps, models and agents from steered traffic |
| Prompt inspection at submit, before the prompt reaches the AI provider | Supported | Supported | Inspected in the Cato cloud after the prompt leaves the device |
| Native desktop AI app interception (ChatGPT, Copilot, Claude desktop) | The browser plugin covers the browser only | Supported | Only for app traffic steered through Cato; desktop apps not named |
| AI agent and MCP inspection on the endpoint | Not included | Limited rollout, not general availability | MCP server discovery, agent actions and tool calls, via the SASE cloud |
| Govern | |||
| Real-time employee coaching at the moment of a risky prompt | Supported | Supported | Block, redact or redirect to approved tools; in-prompt coaching not documented |
| AI policy templates: EU AI Act, ISO 42001, SOC 2, ISO 27001, HIPAA, GDPR | Supported | Supported | Usage mapped to EU AI Act, GDPR, NIST and OWASP; template packs not documented |
| Per-team policy violation trends and AI adoption analytics | Supported | Supported | Risk scoring and usage analytics; per-team violation trends not documented |
| Protect | |||
| Hard block on prompts and file uploads with no user override | Supported | Supported | Blocks steered prompts and uploads; no-override behaviour not documented |
| Layout-preserving DOCX, XLSX and PDF redaction on upload | Supported | Supported | Inline redaction in prompts and uploads; layout-preserving file redaction not claimed |
| AI firewall: runtime protection for the AI applications and agents you build | Not included | Not included | Cato AI Security for Applications |
| Operations | |||
| Choice of seven Aona-managed hosting regions | Supported | Supported | Not publicly documented |
| SIEM export: Microsoft Sentinel via OCSF, REST API and webhooks | Supported | Supported | Violations logged in the Cato console; export through the platform API |
| Free 30-day guided trial | Supported | Supported | Demo-led; no self-serve trial |
| Time to first signal | Agree during scoping | Agree during scoping | Days to weeks |
| Network-edge enforcement on the same platform (SWG, CASB, ZTNA, FWaaS) | Not included | Not included | Cato SASE Cloud, five converged solutions |
Discover
Prompt inspection at submit, before the prompt reaches the AI provider
Native desktop AI app interception (ChatGPT, Copilot, Claude desktop)
AI agent and MCP inspection on the endpoint
Govern
Real-time employee coaching at the moment of a risky prompt
AI policy templates: EU AI Act, ISO 42001, SOC 2, ISO 27001, HIPAA, GDPR
Per-team policy violation trends and AI adoption analytics
Protect
Hard block on prompts and file uploads with no user override
Layout-preserving DOCX, XLSX and PDF redaction on upload
AI firewall: runtime protection for the AI applications and agents you build
Operations
Choice of seven Aona-managed hosting regions
SIEM export: Microsoft Sentinel via OCSF, REST API and webhooks
Free 30-day guided trial
Time to first signal
Network-edge enforcement on the same platform (SWG, CASB, ZTNA, FWaaS)
Based on vendor documentation as of September 2026. Email trust@aona.ai if you find a factual error.
Deployment
From evaluation to rollout.
Aona
- Shape
- Browser plugin for Chrome, Edge, Firefox and Safari plus a native endpoint app for Windows and macOS, deployed by IT with its existing software deployment tools (Intune is one option). No network routing or DNS changes.
- Time to first signal
- Agree during scoping
- What IT must change
- Push the plugin and the endpoint app with your usual deployment tooling and connect Microsoft Entra for admin SSO and user or group sync. Nothing changes on the network, in the SSE or in Microsoft 365.
- Prerequisites
- A software deployment tool for managed devices (Intune, Jamf or equivalent)
- Microsoft Entra for admin SSO and user or group sync; general OIDC or SAML also works
Cato AI Security (formerly Aim Security)
- Shape
- Cato AI Security delivered inside the Cato SASE Cloud: traffic is steered through Cato points of presence via the Cato Client, a connected site or the Cato browser extension, and AI usage is inventoried agentlessly from that traffic. Licensed as one of five converged solutions on the platform, with modular adoption described by Cato.
- Time to first signal
- Weeks
- What IT must change
- Onboard users or sites to the Cato SASE Cloud (Cato Client rollout, site connection or the browser extension), then define AI policies in the Cato Management Application. Existing Cato customers add the AI Security solution to their licence; new customers start with the platform onboarding.
- Prerequisites
- A Cato SASE Cloud licence that includes AI Security (one of five converged solutions; confirm the packaging)
- Users or sites steered through Cato (Cato Client, site connectivity or the Cato browser extension)
- Identity provider for SSO
Scope, stated plainly
Know the scope. Plan with confidence.
Aona
- Aona secures employees' use of AI tools. It is not an LLM firewall, an AI-SPM tool or a red-teaming product for AI you build.
- Aona does not enforce at the network edge. It enforces on the device, at the moment of use.
- Coverage needs the Aona plugin or endpoint app on the device. There is no agentless or network-only mode, so personal and unmanaged devices are out of scope.
- Aona has a SOC 2 Type II examination report. No FedRAMP, IRAP or ISO 27001 today.
- Microsoft Entra is the production identity path, with general OIDC and SAML. No native Okta connector or SCIM provisioning today.
Cato AI Security (formerly Aim Security)
- Inspection happens in the Cato SASE Cloud after the prompt leaves the device: it needs users or sites steered through a Cato point of presence (Cato Client, site connection or the Cato browser extension), so a device outside that path is outside the mechanism (as of September 2026).
- Commercial prerequisite: AI Security is licensed as one of five converged solutions on the Cato SASE Cloud, demo-led with no self-serve trial. Cato describes modular adoption, so confirm the licence scope and onboarding path before a pilot (as of September 2026).
- Redaction is described as inline on prompts and uploads; layout-preserving redaction of DOCX, XLSX and PDF files that keeps the document usable is not claimed (as of September 2026).
- Employee guidance is block, redact or redirect to approved tools; coaching inside the prompt at the moment of the risky action and a block the user cannot override are not documented (as of September 2026).
- The ChatGPT, Copilot and Claude desktop apps are not named on the AI Security for End Users page; coverage of a desktop app depends on its traffic being steered through Cato (as of September 2026).
Security review facts
Ready for your security review.
Certifications, data handling, and residency for both vendors, answered up front so your GRC and legal review can start from this page.
Certifications
Aona
SOC 2 Type II (observation period to January 2026, report issued March 2026; trust center at trust.aona.ai). No FedRAMP or IRAP today.
Cato AI Security (formerly Aim Security)
Cato's security and compliance page lists SOC 2 and SOC 3, PCI DSS Level 1, ISO 27001, 27017, 27018 and 27701, Cyber Essentials and a CSA STAR self-assessment for the Cato SASE Cloud; no attestation specific to the AI Security module is published. As of September 2026.
Trial
Aona
Free for 30 days. Start with a scoping conversation; access is arranged after deployment requirements are confirmed.
Cato AI Security (formerly Aim Security)
No self-serve trial: the AI Security pages route to a demo request and an interactive tour, and AI Security is licensed as one of five converged solutions on the Cato SASE Cloud. As of September 2026.
Where prompts are processed
Aona
Choose backend hosting separately from Aona prompt processing. Host the backend in your cloud, on your premises or on Aona-managed servers. Process prompts on the user device/on-edge, in your cloud or on-premises, or on Aona-managed servers. Confirm the supported configuration, retention, telemetry and integrations for your rollout; these choices do not change a third-party AI provider's data handling.
Cato AI Security (formerly Aim Security)
Prompts, responses and agent actions are inspected in the Cato SASE Cloud once traffic is steered through a Cato point of presence (Cato Client, connected site or Cato browser extension); inspection is not on the device, and the processing location of AI security events is not publicly documented. As of September 2026.
Data residency
Aona
Aona-managed backend hosting has seven regions: Australia, France, UK, Germany, US, Singapore and Hong Kong. Select prompt processing separately; confirm storage, retention, telemetry and any cross-region transfers for the supported configuration. Third-party AI providers have their own data handling.
Cato AI Security (formerly Aim Security)
Not publicly documented for AI security events: Cato states GDPR compliance and runs a global private backbone, but the storage region of AI security events is not stated. Confirm the data location in writing. As of September 2026.
DPA and security docs
Aona
DPA available on request. Trust center at trust.aona.ai, security overview at aona.ai/security. SOC 2 report under NDA.
Cato AI Security (formerly Aim Security)
Not publicly documented (as of July 2026)
Competitor facts come from public documentation and pricing pages. Where a vendor does not publish a fact, we say so rather than guess. Corrections: trust@aona.ai.
Migrating from Cato AI Security (formerly Aim Security)
Make the move to Aona.
Aona moves employee AI enforcement onto the device: hard-block DLP on prompts and uploads with no user override, layout-preserving DOCX, XLSX and PDF redaction, native ChatGPT, Copilot and Claude desktop app coverage and real-time coaching, pushed with your existing deployment tooling and returning a first signal during the agreed evaluation. Keep Cato SASE for the network edge and, if you build AI, keep Cato AI Security for Applications as the AI firewall; the two surfaces share no component, and the Aona side is proven on a 30-day guided trial before any licence conversation.
What you keep
- Cato SASE for the network edge (SWG, CASB, ZTNA, FWaaS) and, if you build AI, Cato AI Security for Applications
- Your identity provider: Aona connects Microsoft Entra for admin SSO and user or group sync, or generic OIDC or SAML
- Your deployment tooling (Intune, Jamf or equivalent), which pushes Aona's plugin and endpoint app
What Aona replaces
- Cloud-side prompt inspection for employee AI use, replaced by inspection on the device at submit, before the prompt leaves it
- Inline redaction in the tunnel, replaced by layout-preserving DOCX, XLSX and PDF redaction on upload
- The demo-led, platform-licensed evaluation of the employee surface, replaced by a 30-day guided trial and a first signal during the agreed evaluation
What you turn off
- Duplicate GenAI DLP rules on the same prompts once Aona owns the decision on the device
- Manual incident triage where Aona's per-team violation trends cover the reporting
Sources & review notes ↗Page updated:
Aona publishes these comparisons to explain its fit for employee AI use. Competitor facts come from public documentation, are dated, and are stated as mechanisms you can verify. Corrections: trust@aona.ai.
- Cato AI Security documentation
Product reference: Current product scope and configuration guidance for workforce and application AI security. This overview is not independent test evidence for every granular comparison claim.
- Aona coverage and deployment scope
Aona's client and action boundaries; validate the configuration and actual policy result during your Aona pilot.
See Aona's hard block and file redaction on your own devices, no SASE commitment
Free for 30 days. Start with a scoping conversation; access is arranged after deployment requirements are confirmed.
FAQ