30 Days Gen AI Risk Trial -Start Now
Skip to main content

Workforce AI Security · Why Aona

  • Aona
  • SurePath AI · F5

Aona vs F5 AI Security / SurePath AI

Choose Aona for employee AI security.

See what sets Aona apart, compare the details, and try it on your own devices.

30-day free trialSOC 2 Type II

The verdict

The Aona advantage

Aona is built for employee AI security. Its offer includes a guided 30-day trial, a hard block on prompts and file uploads with no user override, layout-preserving DOCX, XLSX and PDF redaction, native coverage of the ChatGPT, Copilot and Claude desktop apps, real-time coaching and seven Aona-managed hosting regions. F5 AI Security / SurePath AI, now sold as F5 Workforce AI Security, is a network security product: it discovers AI use from a mirrored traffic stream and redacts prompts inline before they leave the network with no agent or extension, so its policy applies only where a device's traffic is steered through F5; it describes inline redaction and service-level blocking rather than a per-prompt block the employee cannot override or in-place file redaction, does not mention employee coaching, and offers no product trial, as of September 2026.

About this comparison

Aona secures employees' use of AI tools on the device: the browser plugin for Chrome, Edge, Firefox and Safari and the endpoint app for Windows and macOS inspect the prompt and the upload at submit, block hard when policy says so, redact DOCX, XLSX and PDF files with the layout intact, and coach the employee in the moment. SurePath AI is now part of F5: its site redirects to F5 Workforce AI Security, an agentless, network-based product that inventories AI use from a mirrored traffic stream and redacts prompts inline before they leave the network, sold through F5's sales team. This page shows where the two differ on trial, desktop and off-network coverage, file redaction, coaching and hosting.

The Workforce AI Security platform for any company adopting generative AI, with broader endpoint coverage than the incumbents, a simpler trial, and one of the few that ships hard-block DLP for AI prompts and files.

F5 AI Security / SurePath AI: SurePath AI is now part of F5: its site redirects to F5 Workforce AI Security, an agentless, network-based product that inventories AI use from a mirrored traffic stream and redacts prompts inline, inside the F5 AI Security Platform; sales-led.

What the F5 acquisition changesAcquisition facts verified July 2026; product naming re-checked September 2026
  • F5 announced its acquisition of SurePath AI on 24 June 2026. Financial terms were not disclosed.

  • The deal was announced alongside the launch of the F5 AI Security Platform, where F5 says SurePath's network-based AI discovery and shadow AI detection become one of the platform's building blocks. It is F5's second AI-security acquisition, after CalypsoAI in September 2025.

  • As of September 2026, surepath.ai redirects to the F5 Workforce AI Security product page, which describes the product without naming SurePath AI, so buyers researching SurePath should evaluate it under the F5 name.

Questions worth asking before you commit

  • Will SurePath's gateway remain available standalone, or only as a module of the F5 AI Security Platform and its licensing?
  • What happens to existing SurePath contracts, support arrangements, and certifications as the integration proceeds?
  • How will the GenAI governance roadmap be prioritised inside F5's broader application delivery and security portfolio?

Where Aona stands

Aona is independent and purpose-built for Workforce AI Security, with seven Aona-managed hosting regions (AU, FR, UK, DE, US, SG, HK) and a 30-day guided trial, so you can evaluate it on your own devices while the F5 integration takes shape.

Decision matrix

When to pick Aona

Five buyer scenarios, answered for employee AI use.

01

Employees use the ChatGPT, Copilot and Claude desktop apps and work off the corporate network.

Aona

Aona enforces on the device itself: the endpoint app for Windows and macOS inspects the ChatGPT, Copilot and Claude desktop apps and the browser plugin covers Chrome, Edge, Firefox and Safari, at home, in a café or in the office, with no traffic steering. F5 Workforce AI Security inspects prompts before they leave the network and discovers use from a mirrored traffic stream, with no agent or extension, so a laptop off the corporate network is covered only while its traffic is steered through F5 by VPN or SASE (as of September 2026). Count the devices that work outside the office, then put Aona on them.

02

An employee uploads a contract or spreadsheet to an AI assistant and the file must stay usable.

Aona

Aona redacts DOCX, XLSX and PDF files in place on upload, with the layout preserved and length-matched entity replacement, and hard-blocks with no user override when the policy says so. F5 describes inline redaction of sensitive information in prompts and blocking of high-risk or prohibited services; redaction inside an uploaded document with its layout intact, and a per-prompt block the employee cannot override, are not described (as of September 2026). Upload the same document during the Aona trial and compare what the assistant receives.

03

You want to evaluate this quarter without a network change or a sales cycle.

Aona

Aona starts with a 30-day guided trial, deployment through IT's existing tooling, no routing or DNS changes, and the first signal during the agreed evaluation. F5 Workforce AI Security needs AI traffic mirrored or steered to F5 and directory integration before the first signal, and the product page offers on-demand demos and a contact route; its free-trial button leads to F5's general trials page, which lists no Workforce AI Security trial (as of September 2026). Run the Aona trial on a pilot group while the F5 conversation is scheduled.

04

A risky prompt should teach the employee, not only be filtered at the gateway.

Aona

Aona shows guidance at the moment of a risky prompt in the browser and in the desktop apps, pairs it with a hard block that has no user override, ships EU AI Act, ISO 42001, SOC 2, ISO 27001, HIPAA and GDPR policy templates, and reports per-team violation trends that show the coaching working. The F5 Workforce AI Security page describes redaction, routing to approved models and blocking of prohibited services; employee coaching, policy templates and per-team trends are not mentioned (as of September 2026). Ask F5 what the employee sees when a prompt is redacted, then compare with Aona's coaching on the trial.

05

AI egress from servers, pipelines or other systems with no endpoint to install on.

F5 AI Security / SurePath AI

F5 Workforce AI Security inspects AI traffic at the network layer with no agent or extension, so a script or service calling an AI API from a server is in scope once that traffic passes through F5; that is network security, F5's own category. Aona's control point is the employee's device, through the browser plugin and the endpoint app, so it does not inspect server-side egress. Keep that server-side path on the network tool and put Aona on the devices where employees prompt, upload and open desktop apps; verify with F5 which network segments are mirrored or inline, and use Aona's seven hosting regions, SOC 2 Type II and Microsoft Sentinel via OCSF for the employee side of the security review.

Capability matrix

What each tool actually does

Choose a priority. Compare Aona’s browser plugin and native app with the other product.

CapabilityAona browser pluginAona native appF5 AI Security / SurePath AI
Discover
Per-user shadow AI discovery across 10,000+ AI toolsDetection catalog; policy enforcement on the top-tier assistantsSupportedPassive network inventory including shadow AI, per F5
Prompt inspection at submit, before the prompt reaches the AI providerSupportedSupportedInspected at the network before leaving it, not on the device
Native desktop AI app interception (ChatGPT, Copilot, Claude desktop)The browser plugin covers the browser onlySupportedNot named; covered only when traffic is steered through F5
AI agent and MCP inspection on the endpointNot includedLimited rollout, not general availabilityMCP tool calls inspected at the network, not the endpoint
Agentless, network-side inspection of AI egress from systems with no endpointNot includedAona enforces on the device, not at the network edgeMirrored traffic stream, no agents or extensions, per F5
Govern
Real-time employee coaching at the moment of a risky promptSupportedSupportedNot mentioned; actions are redact, route and block
AI policy templates: EU AI Act, ISO 42001, SOC 2, ISO 27001, HIPAA, GDPRSupportedSupportedNot publicly documented
Per-team policy violation trends and AI adoption analyticsSupportedSupportedUsage inventory and intent classification; per-team violation trends not documented
Routing prompts to approved enterprise models at the network layerNot includedNot includedContext-aware policies route requests to approved models, per F5
Protect
Hard block on prompts and file uploads with no user overrideSupportedSupportedInline redaction and service-level blocking; no-override prompt block not documented
Layout-preserving DOCX, XLSX and PDF redaction on uploadSupportedSupportedInline prompt redaction; in-place document redaction not claimed
Operations
Choice of seven Aona-managed hosting regionsSupportedSupportedNot publicly documented
SIEM export: Microsoft Sentinel via OCSF, REST API and webhooksSupportedSupportedAudit-ready logging; SIEM connectors not named on the F5 page
Free 30-day guided trialSupportedSupportedSales-led; no product trial
Time to first signalAgree during scopingAgree during scopingDays to weeks: traffic steering first

Discover

Per-user shadow AI discovery across 10,000+ AI tools

Aona browser pluginDetection catalog; policy enforcement on the top-tier assistants
Aona native appSupported
F5 AI Security / SurePath AIPassive network inventory including shadow AI, per F5

Prompt inspection at submit, before the prompt reaches the AI provider

Aona browser pluginSupported
Aona native appSupported
F5 AI Security / SurePath AIInspected at the network before leaving it, not on the device

Native desktop AI app interception (ChatGPT, Copilot, Claude desktop)

Aona browser pluginThe browser plugin covers the browser only
Aona native appSupported
F5 AI Security / SurePath AINot named; covered only when traffic is steered through F5

AI agent and MCP inspection on the endpoint

Aona browser pluginNot included
Aona native appLimited rollout, not general availability
F5 AI Security / SurePath AIMCP tool calls inspected at the network, not the endpoint

Agentless, network-side inspection of AI egress from systems with no endpoint

Aona browser pluginNot included
Aona native appAona enforces on the device, not at the network edge
F5 AI Security / SurePath AIMirrored traffic stream, no agents or extensions, per F5

Govern

Real-time employee coaching at the moment of a risky prompt

Aona browser pluginSupported
Aona native appSupported
F5 AI Security / SurePath AINot mentioned; actions are redact, route and block

AI policy templates: EU AI Act, ISO 42001, SOC 2, ISO 27001, HIPAA, GDPR

Aona browser pluginSupported
Aona native appSupported
F5 AI Security / SurePath AINot publicly documented

Per-team policy violation trends and AI adoption analytics

Aona browser pluginSupported
Aona native appSupported
F5 AI Security / SurePath AIUsage inventory and intent classification; per-team violation trends not documented

Routing prompts to approved enterprise models at the network layer

Aona browser pluginNot included
Aona native appNot included
F5 AI Security / SurePath AIContext-aware policies route requests to approved models, per F5

Protect

Hard block on prompts and file uploads with no user override

Aona browser pluginSupported
Aona native appSupported
F5 AI Security / SurePath AIInline redaction and service-level blocking; no-override prompt block not documented

Layout-preserving DOCX, XLSX and PDF redaction on upload

Aona browser pluginSupported
Aona native appSupported
F5 AI Security / SurePath AIInline prompt redaction; in-place document redaction not claimed

Operations

Choice of seven Aona-managed hosting regions

Aona browser pluginSupported
Aona native appSupported
F5 AI Security / SurePath AINot publicly documented

SIEM export: Microsoft Sentinel via OCSF, REST API and webhooks

Aona browser pluginSupported
Aona native appSupported
F5 AI Security / SurePath AIAudit-ready logging; SIEM connectors not named on the F5 page

Free 30-day guided trial

Aona browser pluginSupported
Aona native appSupported
F5 AI Security / SurePath AISales-led; no product trial

Time to first signal

Aona browser pluginAgree during scoping
Aona native appAgree during scoping
F5 AI Security / SurePath AIDays to weeks: traffic steering first

Based on vendor documentation as of September 2026. Email trust@aona.ai if you find a factual error.

Deployment

From evaluation to rollout.

Aona

Shape
Browser plugin for Chrome, Edge, Firefox and Safari plus a native endpoint app for Windows and macOS, deployed by IT with its existing software deployment tools (Intune is one option). No network routing or DNS changes.
Time to first signal
Agree during scoping
What IT must change
Push the plugin and the endpoint app with your usual deployment tooling and connect Microsoft Entra for admin SSO and user or group sync. Nothing changes on the network, in the SSE or in Microsoft 365.
Prerequisites
  • A software deployment tool for managed devices (Intune, Jamf or equivalent)
  • Microsoft Entra for admin SSO and user or group sync; general OIDC or SAML also works

F5 AI Security / SurePath AI

Shape
Agentless and network-based, per F5: discovery from a mirrored, out-of-band stream of network traffic and inline inspection of prompts before they leave the network, with directory integration (Azure AD and Okta named). No agent or browser extension. Sold as F5 Workforce AI Security within the F5 AI Security Platform (as of September 2026).
Time to first signal
Days
What IT must change
Mirror or steer AI traffic to F5 and connect the directory for group-based policy; devices that work off the network need a steering path (VPN or SASE) for the policy to apply. Buying goes through F5's sales team.
Prerequisites
  • Network mirroring or inline steering for AI traffic
  • Directory integration (Azure AD or Okta named on the F5 page)
  • A sales-led engagement with F5 (no product trial)

Scope, stated plainly

Know the scope. Plan with confidence.

Aona

  • Coverage needs the Aona plugin or endpoint app on the device. There is no agentless or network-only mode, so personal and unmanaged devices are out of scope.
  • Aona does not enforce at the network edge. It enforces on the device, at the moment of use.
  • No iOS or Android coverage: AI use on phones is out of scope.
  • AI agent and MCP inspection ships in limited rollout on the native endpoint app, not general availability.
  • Aona has a SOC 2 Type II examination report. No FedRAMP, IRAP or ISO 27001 today.

F5 AI Security / SurePath AI

  • Enforcement is at the network: prompts are inspected before they leave the network and discovery uses a mirrored traffic stream, with no agent or extension, so a device off the corporate network is covered only while its traffic is steered through F5 (as of September 2026).
  • Redaction is inline on the prompt and blocking is described for high-risk or prohibited services; redaction inside an uploaded DOCX, XLSX or PDF with its layout intact, and a per-prompt block the employee cannot override, are not described (as of September 2026).
  • Employee coaching at the moment of a risky prompt, policy templates and per-team violation trends are not mentioned on the product page; the actions described are redact, route to approved models and block (as of September 2026).
  • No product trial: the page offers on-demand demos and a contact route, and its free-trial button leads to F5's general trials page, which lists no Workforce AI Security trial (as of September 2026).
  • Certifications, hosting regions, prompt-processing locations and SIEM connectors are not stated on the F5 Workforce AI Security page, and the page does not name SurePath AI; the acquisition facts on this page come from F5's June 2026 announcement (as of September 2026).

Security review facts

Ready for your security review.

Certifications, data handling, and residency for both vendors, answered up front so your GRC and legal review can start from this page.

Certifications

Aona

SOC 2 Type II (observation period to January 2026, report issued March 2026; trust center at trust.aona.ai). No FedRAMP or IRAP today.

F5 AI Security / SurePath AI

Not stated on the F5 Workforce AI Security product page (as of September 2026).

Trial

Aona

Free for 30 days. Start with a scoping conversation; access is arranged after deployment requirements are confirmed.

F5 AI Security / SurePath AI

No product trial; the page offers on-demand demos and a contact route, and its free-trial button leads to F5's general trials page, which lists no Workforce AI Security trial. As of September 2026.

Where prompts are processed

Aona

Choose backend hosting separately from Aona prompt processing. Host the backend in your cloud, on your premises or on Aona-managed servers. Process prompts on the user device/on-edge, in your cloud or on-premises, or on Aona-managed servers. Confirm the supported configuration, retention, telemetry and integrations for your rollout; these choices do not change a third-party AI provider's data handling.

F5 AI Security / SurePath AI

Prompts are inspected inline before they leave the network, and discovery runs on a mirrored, out-of-band traffic stream, per F5; processing regions are not stated (as of September 2026).

Data residency

Aona

Aona-managed backend hosting has seven regions: Australia, France, UK, Germany, US, Singapore and Hong Kong. Select prompt processing separately; confirm storage, retention, telemetry and any cross-region transfers for the supported configuration. Third-party AI providers have their own data handling.

F5 AI Security / SurePath AI

Not stated on the product page (as of September 2026).

DPA and security docs

Aona

DPA available on request. Trust center at trust.aona.ai, security overview at aona.ai/security. SOC 2 report under NDA.

F5 AI Security / SurePath AI

Not stated on the product page (as of September 2026).

Competitor facts come from public documentation and pricing pages. Where a vendor does not publish a fact, we say so rather than guess. Corrections: trust@aona.ai.

Migrating from F5 AI Security / SurePath AI

Make the move to Aona.

Aona replaces a sales-led network evaluation with a 30-day guided trial on your own devices: push the plugin and the endpoint app with your existing deployment tooling, pick a hosting region, and see the first prompt and upload decisions during the agreed evaluation, with no traffic steering. Aona enforces on the device, so it runs alongside any F5 network inspection without touching routing. Compare hard-block behaviour, redacted files, the desktop apps covered and what the employee sees at a risky prompt, then move employee AI enforcement to Aona; server-side egress from systems with no endpoint stays with the network tool, separate from the employee prompt and upload that Aona owns.

01

What you keep

  • Your identity provider: Aona connects Microsoft Entra for admin SSO and user or group sync, or generic OIDC or SAML
  • Your deployment tooling (Intune, Jamf or equivalent), which pushes Aona's plugin and endpoint app
  • Network inspection for server-side AI egress from systems with no endpoint, with Aona owning the employee prompt and upload
02

What Aona replaces

  • The sales-led evaluation, replaced by a 30-day guided trial
  • Inline prompt redaction at the gateway, replaced by layout-preserving DOCX, XLSX and PDF redaction and a hard block with no user override on the device
  • Filtering with no employee feedback, replaced by real-time coaching, policy templates and per-team violation trends
03

What you turn off

  • Duplicate prompt-DLP rules for employee devices once Aona enforces on the device
  • Manual incident triage where Aona's per-team violation trends cover the reporting
Sources & review notes ↗Page updated:

Aona publishes these comparisons to explain its fit for employee AI use. Competitor facts come from public documentation, are dated, and are stated as mechanisms you can verify. Corrections: trust@aona.ai.

Start with the trial

See Aona's hard block and desktop coverage on your own devices

Free for 30 days. Start with a scoping conversation; access is arranged after deployment requirements are confirmed.

FAQ

Common questions from F5 AI Security / SurePath AI customers

Do I need Aona if I already have F5 AI Security / SurePath AI?
Yes, if the policy has to hold on the device: in the ChatGPT, Copilot and Claude desktop apps, on a laptop off the corporate network and on the uploaded file. F5 Workforce AI Security inspects prompts before they leave the network and discovers use from a mirrored traffic stream, with no agent or extension, so its policy applies only where the device's traffic is steered through F5; Aona's browser plugin and endpoint app enforce wherever the device is, hard-block with no user override and redact DOCX, XLSX and PDF uploads in place (as of September 2026). Aona also coaches the employee at the risky prompt, lets you choose one of seven hosting regions and streams to Microsoft Sentinel via OCSF. Run the 30-day trial on the devices whose traffic is not steered through F5 once they leave the office.
Are Aona and SurePath AI solving the same problem?
Partly. Both address employees' use of third-party AI tools, but at different layers. F5 AI Security / SurePath AI works at the network: discovery from a mirrored traffic stream and inline redaction of prompts before they leave the network, which also reaches AI egress from servers and other systems with no endpoint. Aona works on the employee's device and offers a 30-day guided trial, a hard block with no user override, layout-preserving file redaction, native desktop coverage for ChatGPT, Copilot and Claude, real-time coaching and seven hosting regions. Keep the network tool for server-side egress and put Aona on the employee prompt and upload.
Does SurePath AI redact files the way Aona does?
Aona redacts DOCX, XLSX and PDF files on upload with the layout preserved and length-matched entity replacement, so the assistant receives a usable document without the sensitive fields. The F5 Workforce AI Security page describes inline redaction of sensitive information in prompts; redaction inside an uploaded document with its layout intact is not described (as of September 2026). Upload the same contract during the Aona trial and compare what the assistant receives.
How does Aona's evaluation compare to SurePath AI's?
Aona offers a 30-day guided trial, deploys through IT's existing tooling, holds SOC 2 Type II and needs no routing or DNS changes, so the first signal arrives during the agreed evaluation. F5 Workforce AI Security is sold through F5's sales team: the product page offers on-demand demos and a contact route, its free-trial button leads to F5's general trials page with no Workforce AI Security trial, and certifications and hosting regions are not stated (as of September 2026).
Is SurePath AI still a standalone product after the F5 acquisition?
F5 announced its acquisition of SurePath AI on 24 June 2026 (terms undisclosed), alongside the launch of the F5 AI Security Platform, where SurePath provides network-based AI discovery and shadow AI detection; it is F5's second AI-security acquisition after CalypsoAI in September 2025. As of September 2026, surepath.ai redirects to the F5 Workforce AI Security product page, which does not name SurePath AI, so evaluate it under the F5 name and confirm packaging, contracts and certifications with F5. Aona is an independent Workforce AI Security platform with a 30-day guided trial, so you can evaluate it on your own devices while those answers arrive.