30 Days Gen AI Risk Trial -Start Now
Skip to main content

Workforce AI Security · Why Aona

  • Aona
  • Cato AI Security

Aona vs Cato AI Security (formerly Aim Security)

Choose Aona for employee AI security.

See what sets Aona apart, compare the details, and try it on your own devices.

30-day free trialSOC 2 Type II

The verdict

The Aona advantage

Aona is built for employee AI security. Its offer includes a guided 30-day trial, a hard block on prompts and file uploads with no user override, layout-preserving DOCX, XLSX and PDF redaction, native coverage of the ChatGPT, Copilot and Claude desktop apps, real-time coaching and seven Aona-managed hosting regions, with a first signal during the agreed evaluation. Cato AI Security, the former Aim Security, is the AI firewall and agent control for the AI you build; since the September 2025 acquisition its capabilities ship inside the Cato SASE Cloud, its end-user controls inspect prompts in the Cato cloud once traffic is steered through a Cato point of presence rather than on the device, and Cato describes modular adoption of the platform, so verify the licence and steering prerequisites before you count on it for the prompt at the keyboard.

About this comparison

Aona secures employees' use of AI tools on the device: the browser plugin for Chrome, Edge, Firefox and Safari and the endpoint app for Windows and macOS inspect the prompt and the upload at submit, block hard when policy says so, redact DOCX, XLSX and PDF files with the layout intact, and coach the employee in the moment. Cato AI Security is the former Aim Security, delivered inside the Cato SASE Cloud since the acquisition announced on 3 September 2025: end-user AI controls enforced on traffic steered through Cato, an AI firewall for the applications and agents you build, and agentic AI security. This page shows where the two differ on the control point, file redaction, desktop coverage, trial and hosting.

The Workforce AI Security platform for any company adopting generative AI, with broader endpoint coverage than the incumbents, a simpler trial, and one of the few that ships hard-block DLP for AI prompts and files.

Cato AI Security (formerly Aim Security): Aim Security's AI security capabilities, sold as Cato AI Security inside the Cato SASE Cloud since the September 2025 acquisition: end-user AI controls, an AI firewall for applications and agentic AI security, demo-led.

What the Cato Networks acquisition changesAcquisition facts verified against Cato's 3 September 2025 announcement, product packaging re-checked September 2026
  • Cato Networks announced on 3 September 2025 that it had acquired Aim Security, calling it Cato's first-ever acquisition. Cato did not disclose the price; press reports put it at about USD 350 million.

  • Cato's announcement said Aim's capabilities would be offered as part of the Cato SASE Cloud Platform in early 2026, with a migration path for customers of the standalone Aim product, and that Cato supports modular and gradual adoption of platform capabilities, now including AI Security (AISEC).

  • As of September 2026, Cato markets the capabilities as Cato AI Security in three parts (AI Security for End Users, AI Security for Applications and Agentic AI Security), licensed as one of five converged solutions on the Cato SASE Cloud and sold through a demo request. aim.security redirected to catonetworks.com as of July 2026.

Questions worth asking before you commit

  • Which licence and steering prerequisites does AI Security for End Users need on your estate: the Cato Client on every device, connected sites, or the Cato browser extension, and what does each add to the licence and the rollout?
  • If you are not a Cato SASE customer, what is the minimum platform footprint to run AI Security, and can it be bought without moving your network to Cato?
  • What did the migration path mean for standalone Aim contracts, and how is the employee AI roadmap prioritised inside a SASE platform agenda?

Where Aona stands

Aona is independent and purpose-built for Workforce AI Security, with no SASE dependency, seven Aona-managed hosting regions (AU, FR, UK, DE, US, SG, HK) and a 30-day guided trial, so you can evaluate the employee surface on your own devices while those questions get answered.

Decision matrix

When to pick Aona

Five buyer scenarios, answered for employee AI use.

01

You need an AI firewall in front of the LLM applications and agents your own teams build.

Cato AI Security (formerly Aim Security)

Cato AI Security for Applications defends the AI apps and agents you build against prompt injection and runtime attacks, a surface Aona does not cover. Verify the commercial prerequisite first: the capability is licensed as one of five converged solutions on the Cato SASE Cloud, with modular adoption described by Cato, and the employee side still needs its own control on the device, which Aona ships with a 30-day guided trial.

02

Your problem is employees pasting client data into ChatGPT, Copilot or Claude.

Aona

Aona inspects the prompt on the device at submit, hard-blocks with no user override, redacts DOCX, XLSX and PDF uploads with the layout intact and coaches the employee in the moment, in Chrome, Edge, Firefox and Safari and in the ChatGPT, Copilot and Claude desktop apps. Cato AI Security for End Users inspects prompts in the Cato cloud once traffic is steered through a Cato point of presence; a device outside that path, or an app whose traffic is not steered, is outside its mechanism.

03

You already run Cato SASE and want the device layer of employee AI use covered too.

Aona

Nothing changes in the Cato tunnel: Aona's plugin and endpoint app are pushed with your existing deployment tooling and add on-device interception of the ChatGPT, Copilot and Claude desktop apps, layout-preserving file redaction and a hard block with no user override, with events streamed to Microsoft Sentinel via OCSF. The 30-day guided trial shows the gap on your own devices before any licence discussion with Cato.

04

You want to evaluate this quarter with a guided trial, not a SASE procurement.

Aona

Aona starts with a 30-day guided trial: IT pushes the plugin and the endpoint app with its existing deployment tooling and the first signal arrives during the agreed evaluation. Cato AI Security is demo-led with no self-serve trial, and it is licensed as one of five converged solutions on the Cato SASE Cloud; Cato describes modular adoption, so confirm the licence scope and onboarding path before you plan a pilot (as of September 2026).

05

Your employee AI data must stay in-region, with SIEM evidence for the security review.

Aona

Aona offers seven Aona-managed hosting regions (Australia, France, the UK, Germany, the US, Singapore and Hong Kong), with prompt processing selected separately, and streams events to Microsoft Sentinel via OCSF with a REST API and HMAC-signed webhooks. For Cato AI Security the storage region of AI security events and the SIEM mapping of those events are not publicly documented; ask Cato for both in writing, then compare with the region you pick in Aona at signup (as of September 2026).

Capability matrix

What each tool actually does

Choose a priority. Compare Aona’s browser plugin and native app with the other product.

CapabilityAona browser pluginAona native appCato AI Security (formerly Aim Security)
Discover
Per-user shadow AI discovery across 10,000+ AI toolsDetection catalog; policy enforcement on the top-tier assistantsSupportedAgentless inventory of AI apps, models and agents from steered traffic
Prompt inspection at submit, before the prompt reaches the AI providerSupportedSupportedInspected in the Cato cloud after the prompt leaves the device
Native desktop AI app interception (ChatGPT, Copilot, Claude desktop)The browser plugin covers the browser onlySupportedOnly for app traffic steered through Cato; desktop apps not named
AI agent and MCP inspection on the endpointNot includedLimited rollout, not general availabilityMCP server discovery, agent actions and tool calls, via the SASE cloud
Govern
Real-time employee coaching at the moment of a risky promptSupportedSupportedBlock, redact or redirect to approved tools; in-prompt coaching not documented
AI policy templates: EU AI Act, ISO 42001, SOC 2, ISO 27001, HIPAA, GDPRSupportedSupportedUsage mapped to EU AI Act, GDPR, NIST and OWASP; template packs not documented
Per-team policy violation trends and AI adoption analyticsSupportedSupportedRisk scoring and usage analytics; per-team violation trends not documented
Protect
Hard block on prompts and file uploads with no user overrideSupportedSupportedBlocks steered prompts and uploads; no-override behaviour not documented
Layout-preserving DOCX, XLSX and PDF redaction on uploadSupportedSupportedInline redaction in prompts and uploads; layout-preserving file redaction not claimed
AI firewall: runtime protection for the AI applications and agents you buildNot includedNot includedCato AI Security for Applications
Operations
Choice of seven Aona-managed hosting regionsSupportedSupportedNot publicly documented
SIEM export: Microsoft Sentinel via OCSF, REST API and webhooksSupportedSupportedViolations logged in the Cato console; export through the platform API
Free 30-day guided trialSupportedSupportedDemo-led; no self-serve trial
Time to first signalAgree during scopingAgree during scopingDays to weeks
Network-edge enforcement on the same platform (SWG, CASB, ZTNA, FWaaS)Not includedNot includedCato SASE Cloud, five converged solutions

Discover

Per-user shadow AI discovery across 10,000+ AI tools

Aona browser pluginDetection catalog; policy enforcement on the top-tier assistants
Aona native appSupported
Cato AI Security (formerly Aim Security)Agentless inventory of AI apps, models and agents from steered traffic

Prompt inspection at submit, before the prompt reaches the AI provider

Aona browser pluginSupported
Aona native appSupported
Cato AI Security (formerly Aim Security)Inspected in the Cato cloud after the prompt leaves the device

Native desktop AI app interception (ChatGPT, Copilot, Claude desktop)

Aona browser pluginThe browser plugin covers the browser only
Aona native appSupported
Cato AI Security (formerly Aim Security)Only for app traffic steered through Cato; desktop apps not named

AI agent and MCP inspection on the endpoint

Aona browser pluginNot included
Aona native appLimited rollout, not general availability
Cato AI Security (formerly Aim Security)MCP server discovery, agent actions and tool calls, via the SASE cloud

Govern

Real-time employee coaching at the moment of a risky prompt

Aona browser pluginSupported
Aona native appSupported
Cato AI Security (formerly Aim Security)Block, redact or redirect to approved tools; in-prompt coaching not documented

AI policy templates: EU AI Act, ISO 42001, SOC 2, ISO 27001, HIPAA, GDPR

Aona browser pluginSupported
Aona native appSupported
Cato AI Security (formerly Aim Security)Usage mapped to EU AI Act, GDPR, NIST and OWASP; template packs not documented

Per-team policy violation trends and AI adoption analytics

Aona browser pluginSupported
Aona native appSupported
Cato AI Security (formerly Aim Security)Risk scoring and usage analytics; per-team violation trends not documented

Protect

Hard block on prompts and file uploads with no user override

Aona browser pluginSupported
Aona native appSupported
Cato AI Security (formerly Aim Security)Blocks steered prompts and uploads; no-override behaviour not documented

Layout-preserving DOCX, XLSX and PDF redaction on upload

Aona browser pluginSupported
Aona native appSupported
Cato AI Security (formerly Aim Security)Inline redaction in prompts and uploads; layout-preserving file redaction not claimed

AI firewall: runtime protection for the AI applications and agents you build

Aona browser pluginNot included
Aona native appNot included
Cato AI Security (formerly Aim Security)Cato AI Security for Applications

Operations

Choice of seven Aona-managed hosting regions

Aona browser pluginSupported
Aona native appSupported
Cato AI Security (formerly Aim Security)Not publicly documented

SIEM export: Microsoft Sentinel via OCSF, REST API and webhooks

Aona browser pluginSupported
Aona native appSupported
Cato AI Security (formerly Aim Security)Violations logged in the Cato console; export through the platform API

Free 30-day guided trial

Aona browser pluginSupported
Aona native appSupported
Cato AI Security (formerly Aim Security)Demo-led; no self-serve trial

Time to first signal

Aona browser pluginAgree during scoping
Aona native appAgree during scoping
Cato AI Security (formerly Aim Security)Days to weeks

Network-edge enforcement on the same platform (SWG, CASB, ZTNA, FWaaS)

Aona browser pluginNot included
Aona native appNot included
Cato AI Security (formerly Aim Security)Cato SASE Cloud, five converged solutions

Based on vendor documentation as of September 2026. Email trust@aona.ai if you find a factual error.

Deployment

From evaluation to rollout.

Aona

Shape
Browser plugin for Chrome, Edge, Firefox and Safari plus a native endpoint app for Windows and macOS, deployed by IT with its existing software deployment tools (Intune is one option). No network routing or DNS changes.
Time to first signal
Agree during scoping
What IT must change
Push the plugin and the endpoint app with your usual deployment tooling and connect Microsoft Entra for admin SSO and user or group sync. Nothing changes on the network, in the SSE or in Microsoft 365.
Prerequisites
  • A software deployment tool for managed devices (Intune, Jamf or equivalent)
  • Microsoft Entra for admin SSO and user or group sync; general OIDC or SAML also works

Cato AI Security (formerly Aim Security)

Shape
Cato AI Security delivered inside the Cato SASE Cloud: traffic is steered through Cato points of presence via the Cato Client, a connected site or the Cato browser extension, and AI usage is inventoried agentlessly from that traffic. Licensed as one of five converged solutions on the platform, with modular adoption described by Cato.
Time to first signal
Weeks
What IT must change
Onboard users or sites to the Cato SASE Cloud (Cato Client rollout, site connection or the browser extension), then define AI policies in the Cato Management Application. Existing Cato customers add the AI Security solution to their licence; new customers start with the platform onboarding.
Prerequisites
  • A Cato SASE Cloud licence that includes AI Security (one of five converged solutions; confirm the packaging)
  • Users or sites steered through Cato (Cato Client, site connectivity or the Cato browser extension)
  • Identity provider for SSO

Scope, stated plainly

Know the scope. Plan with confidence.

Aona

  • Aona secures employees' use of AI tools. It is not an LLM firewall, an AI-SPM tool or a red-teaming product for AI you build.
  • Aona does not enforce at the network edge. It enforces on the device, at the moment of use.
  • Coverage needs the Aona plugin or endpoint app on the device. There is no agentless or network-only mode, so personal and unmanaged devices are out of scope.
  • Aona has a SOC 2 Type II examination report. No FedRAMP, IRAP or ISO 27001 today.
  • Microsoft Entra is the production identity path, with general OIDC and SAML. No native Okta connector or SCIM provisioning today.

Cato AI Security (formerly Aim Security)

  • Inspection happens in the Cato SASE Cloud after the prompt leaves the device: it needs users or sites steered through a Cato point of presence (Cato Client, site connection or the Cato browser extension), so a device outside that path is outside the mechanism (as of September 2026).
  • Commercial prerequisite: AI Security is licensed as one of five converged solutions on the Cato SASE Cloud, demo-led with no self-serve trial. Cato describes modular adoption, so confirm the licence scope and onboarding path before a pilot (as of September 2026).
  • Redaction is described as inline on prompts and uploads; layout-preserving redaction of DOCX, XLSX and PDF files that keeps the document usable is not claimed (as of September 2026).
  • Employee guidance is block, redact or redirect to approved tools; coaching inside the prompt at the moment of the risky action and a block the user cannot override are not documented (as of September 2026).
  • The ChatGPT, Copilot and Claude desktop apps are not named on the AI Security for End Users page; coverage of a desktop app depends on its traffic being steered through Cato (as of September 2026).

Security review facts

Ready for your security review.

Certifications, data handling, and residency for both vendors, answered up front so your GRC and legal review can start from this page.

Certifications

Aona

SOC 2 Type II (observation period to January 2026, report issued March 2026; trust center at trust.aona.ai). No FedRAMP or IRAP today.

Cato AI Security (formerly Aim Security)

Cato's security and compliance page lists SOC 2 and SOC 3, PCI DSS Level 1, ISO 27001, 27017, 27018 and 27701, Cyber Essentials and a CSA STAR self-assessment for the Cato SASE Cloud; no attestation specific to the AI Security module is published. As of September 2026.

Trial

Aona

Free for 30 days. Start with a scoping conversation; access is arranged after deployment requirements are confirmed.

Cato AI Security (formerly Aim Security)

No self-serve trial: the AI Security pages route to a demo request and an interactive tour, and AI Security is licensed as one of five converged solutions on the Cato SASE Cloud. As of September 2026.

Where prompts are processed

Aona

Choose backend hosting separately from Aona prompt processing. Host the backend in your cloud, on your premises or on Aona-managed servers. Process prompts on the user device/on-edge, in your cloud or on-premises, or on Aona-managed servers. Confirm the supported configuration, retention, telemetry and integrations for your rollout; these choices do not change a third-party AI provider's data handling.

Cato AI Security (formerly Aim Security)

Prompts, responses and agent actions are inspected in the Cato SASE Cloud once traffic is steered through a Cato point of presence (Cato Client, connected site or Cato browser extension); inspection is not on the device, and the processing location of AI security events is not publicly documented. As of September 2026.

Data residency

Aona

Aona-managed backend hosting has seven regions: Australia, France, UK, Germany, US, Singapore and Hong Kong. Select prompt processing separately; confirm storage, retention, telemetry and any cross-region transfers for the supported configuration. Third-party AI providers have their own data handling.

Cato AI Security (formerly Aim Security)

Not publicly documented for AI security events: Cato states GDPR compliance and runs a global private backbone, but the storage region of AI security events is not stated. Confirm the data location in writing. As of September 2026.

DPA and security docs

Aona

DPA available on request. Trust center at trust.aona.ai, security overview at aona.ai/security. SOC 2 report under NDA.

Cato AI Security (formerly Aim Security)

Not publicly documented (as of July 2026)

Competitor facts come from public documentation and pricing pages. Where a vendor does not publish a fact, we say so rather than guess. Corrections: trust@aona.ai.

Migrating from Cato AI Security (formerly Aim Security)

Make the move to Aona.

Aona moves employee AI enforcement onto the device: hard-block DLP on prompts and uploads with no user override, layout-preserving DOCX, XLSX and PDF redaction, native ChatGPT, Copilot and Claude desktop app coverage and real-time coaching, pushed with your existing deployment tooling and returning a first signal during the agreed evaluation. Keep Cato SASE for the network edge and, if you build AI, keep Cato AI Security for Applications as the AI firewall; the two surfaces share no component, and the Aona side is proven on a 30-day guided trial before any licence conversation.

01

What you keep

  • Cato SASE for the network edge (SWG, CASB, ZTNA, FWaaS) and, if you build AI, Cato AI Security for Applications
  • Your identity provider: Aona connects Microsoft Entra for admin SSO and user or group sync, or generic OIDC or SAML
  • Your deployment tooling (Intune, Jamf or equivalent), which pushes Aona's plugin and endpoint app
02

What Aona replaces

  • Cloud-side prompt inspection for employee AI use, replaced by inspection on the device at submit, before the prompt leaves it
  • Inline redaction in the tunnel, replaced by layout-preserving DOCX, XLSX and PDF redaction on upload
  • The demo-led, platform-licensed evaluation of the employee surface, replaced by a 30-day guided trial and a first signal during the agreed evaluation
03

What you turn off

  • Duplicate GenAI DLP rules on the same prompts once Aona owns the decision on the device
  • Manual incident triage where Aona's per-team violation trends cover the reporting
Sources & review notes ↗Page updated:

Aona publishes these comparisons to explain its fit for employee AI use. Competitor facts come from public documentation, are dated, and are stated as mechanisms you can verify. Corrections: trust@aona.ai.

  • Cato AI Security documentation

    Product reference: Current product scope and configuration guidance for workforce and application AI security. This overview is not independent test evidence for every granular comparison claim.

  • Aona coverage and deployment scope

    Aona's client and action boundaries; validate the configuration and actual policy result during your Aona pilot.

Start with the trial

See Aona's hard block and file redaction on your own devices, no SASE commitment

Free for 30 days. Start with a scoping conversation; access is arranged after deployment requirements are confirmed.

FAQ

Common questions from Cato AI Security (formerly Aim Security) customers

Do we still need Aona if we already run Cato SASE with Cato AI Security?
Yes, for the device. Cato AI Security for End Users inspects prompts in the Cato cloud once traffic is steered through a Cato point of presence; Aona inspects the prompt on the device at submit, hard-blocks with no user override, redacts DOCX, XLSX and PDF uploads with the layout intact, covers the ChatGPT, Copilot and Claude desktop apps through its endpoint app and coaches the employee in the moment. Nothing changes in the Cato tunnel: push Aona's plugin and endpoint app with your existing deployment tooling, run the 30-day trial on the same devices and compare the decisions.
Is Aona an alternative to Cato AI Security (formerly Aim Security) or a complement?
For employee AI use, Aona is the alternative: on-device prompt inspection at submit, a hard block with no user override, layout-preserving file redaction, native ChatGPT, Copilot and Claude desktop app coverage, real-time coaching and a 30-day guided trial, against end-user controls that inspect in the Cato cloud and are licensed as part of the Cato SASE Cloud. For the AI you build, Cato AI Security for Applications covers the AI firewall surface Aona does not, so organisations with both exposures run Aona for employees and Cato for their own applications and agents.
What did the Cato Networks acquisition of Aim Security change?
Cato Networks announced the acquisition on 3 September 2025 as its first-ever acquisition, at a price it did not disclose and that press reports put at about USD 350 million. Cato said Aim's capabilities would ship as part of the Cato SASE Cloud Platform in early 2026 with a migration path for standalone Aim customers, and that platform capabilities, now including AI Security, can be adopted modularly. As of September 2026 the product is marketed as Cato AI Security, licensed as one of five converged solutions on the Cato SASE Cloud and sold through a demo request. The diligence questions are the licence scope, the steering prerequisites on your devices and the roadmap priority inside a SASE platform. Aona is a standalone Workforce AI Security product with no SASE dependency and a 30-day guided trial.
Does Aona ship an AI firewall or agentic AI security like Cato AI Security?
No. Cato AI Security for Applications protects the AI applications and agents you build at runtime, and its Agentic AI Security discovers MCP servers and profiles agent actions through the SASE cloud. Aona stays on the employee side: shadow AI discovery on the device, a hard block on prompts and uploads with no user override, layout-preserving file redaction, real-time coaching and AI agent inspection on the endpoint in limited rollout. If an AI firewall for your own applications is a hard requirement, that sits with Cato; the employee surface is where Aona wins, with a 30-day guided trial to prove it.
How does Aona's trial compare to Cato AI Security's evaluation path?
Aona starts with a 30-day guided free trial: IT pushes the plugin and the endpoint app with its existing deployment tooling, you pick a hosting region at signup and the first signal arrives during the agreed evaluation. Cato AI Security has no self-serve trial; its pages route to a demo request and an interactive tour, and the capability is licensed as one of five converged solutions on the Cato SASE Cloud, so the evaluation depends on the platform footprint you take. As of September 2026.