One finds shadow agents and flags injection or leakage, the other evaluates each outcome for quality, cost, and approved scope, so they sit at different layers.[1]
Zenity is the security layer for deployed agents: shadow discovery, threat detection, and posture management. Prefactor evaluates each run's outcome: quality per agent and version, drift after a change, and cost. A secure agent can still return the wrong answer, so many teams run both.
| Decision factor | Zenity | Prefactor |
|---|---|---|
| Where it fits | Securing the agent against attacks | Knowing the agent did its job in production |
| Primary question | Is this agent being attacked or misused? | Did this agent produce the right outcome, at what cost? |
| Threat model | Adversarial: someone misusing the agent | Operational: drift and scope creep, no attacker required |
| What you get | Threat detection and response across agents | A quality score per run, drift detection, and cost per agent |
| How it attaches | Security monitoring across your agent estate | Native SDK, core SDK, or OpenTelemetry ingest, no rebuild, no gateway in the request path |
| Use them together? | Watch for attacks with Zenity | Evaluate the work with Prefactor |
Best for security teams that need to detect and respond to threats across their deployed agents.
Best for teams running agents in production who need to know each one is doing its job, and prove it.
| Capability | Zenity | Prefactor |
|---|---|---|
| Securing the agent | ||
| Shadow agent discovery | ✓ | — |
| Runtime threat detection (prompt injection, data leakage) | ✓ | — |
| Security posture management (OWASP, MITRE ATLAS) | ✓ | — |
| Evaluating agents in production | ||
| Quality score per run | — | ✓ |
| Cost attributed per agent and version | — | ✓ |
| Drift detection against a baseline | — | ✓ |
| Hold or escalate a risky action before a user is affected | On threat signals | On quality and scope signals |
| Across your stack | ||
| Evaluates agents built on any framework | — | ✓ |
| One queryable record per agent | — | ✓ |
| Audit trail for a decision | For security incidents | ✓ |
We sell the layer this section describes. Read it with that in mind.
Zenity answers whether an agent is under attack or acting outside its permissions, and it does that work well. It does not say whether the agent did its job, at acceptable quality and cost, with evidence you can show.
Each run is measured against the agent's job, and the quality score is tracked per agent across versions.
When behaviour shifts after a model update or a prompt edit, Prefactor flags it.
When a score or a scope check crosses a threshold, Prefactor can hold or escalate the action before a user is affected.
Every decision keeps a record you can give to a customer or an auditor. Prefactor reads the traces you already emit, through a native SDK or any OpenTelemetry source, so it runs alongside Zenity rather than replacing it.
Reviewed against public product and documentation pages on March 19, 2026. If a vendor has changed a feature, product name, or positioning since then, send a correction and we will update it. Numbered source links in the page body point to the ordered sources below.
Book a demo and we will evaluate a live agent on a fleet like yours: quality per run, drift after a change, and cost per agent.
Prefactor helps teams observe, evaluate, and improve their AI agents in production, across every framework and provider.