One defends against prompt injection and tool misuse, the other catches runs that miss the outcome or leave approved scope, so they sit at different layers of the same stack.[1][2]
Prisma AIRS is Palo Alto's security layer for AI: runtime threat detection, model scanning, and red teaming. Prefactor judges each run's outcome: quality, drift, and cost per agent, on any framework. An agent can pass every security check and still fail its task, so the two layers run together.
| Decision factor | Prisma AIRS | Prefactor |
|---|---|---|
| Where it fits | Securing the AI runtime against attacks | Knowing the agent did its job in production |
| Primary question | Is this agent being attacked or compromised? | Did this agent produce the right outcome, at what cost? |
| Scope | Model supply chain through runtime defence | The deployed agent, on any framework |
| What you get | Threat detection, model scanning, red teaming | A quality score per run, drift detection, and cost per agent |
| How it attaches | A security profile in the Palo Alto stack | Native SDK, core SDK, or OpenTelemetry ingest, no rebuild, no gateway in the request path |
| Use them together? | Secure the runtime with Prisma AIRS | Check the work with Prefactor |
Best for security teams that need protection across the AI lifecycle, from the model supply chain to runtime defence.
Best for teams running agents in production who need to know each one is doing its job, and prove it.
| Capability | Prisma AIRS | Prefactor |
|---|---|---|
| Securing the AI runtime | ||
| Runtime threat detection | ✓ | — |
| Model supply chain security | ✓ | — |
| Automated red teaming | ✓ | — |
| Shadow agent discovery | ✓ | — |
| Evaluating agents in production | ||
| Quality score per run | — | ✓ |
| Cost attributed per agent and version | — | ✓ |
| Drift detection against a baseline | — | ✓ |
| Hold or escalate a risky action before a user is affected | On threat signals | On quality and scope signals |
| Across your stack | ||
| Evaluates agents built on any framework | — | ✓ |
| One queryable record per agent | — | ✓ |
| Audit trail for a decision | For security events | ✓ |
We sell the layer this section describes. Read it with that in mind.
Prisma AIRS answers whether an agent is under attack or a model has been tampered with, across the AI lifecycle. It does not say whether the deployed agent did its job, at acceptable quality and cost.
Each run gets a quality score, tracked per agent across versions.
When behaviour shifts after a model update or a prompt edit, Prefactor flags it.
When a score or a scope check crosses a threshold, Prefactor can hold or escalate the action before a user is affected.
Every decision keeps a record you can hand to a customer or an auditor. Prefactor reads the traces you already emit, through a native SDK or any OpenTelemetry source, so it works alongside the security stack you already run.
Reviewed against public product and documentation pages on March 19, 2026. If a vendor has changed a feature, product name, or positioning since then, send a correction and we will update it. Numbered source links in the page body point to the ordered sources below.
Book a demo and we will evaluate a live agent on a fleet like yours: quality per run, drift after a change, and cost per agent.
Prefactor helps teams observe, evaluate, and improve their AI agents in production, across every framework and provider.