Preloop vs Varonis Atlas: agent control next to data security

Preloop is the open-source AI agent control plane: an MCP firewall, an AI model gateway with budgets, human approvals, runtime observability, and an audit trail in one self-hostable service. Varonis Atlas is the AI security platform of Varonis, the data security company. Varonis announced the acquisition of AllTrue.ai on February 3, 2026 and announced general availability of Atlas on May 28, 2026, built on the Varonis Data Security Platform.

The honest one-liner: Varonis protects the data AI can reach. Preloop governs what agents do, what they cost, and who approved it, open source and on your own infrastructure. We do not position Preloop as a Varonis replacement. Varonis is strongest on the data side: classification, permissions, and who can reach which file share or SharePoint site. Preloop is a cross-vendor agent control layer. For many organizations the right answer is both, and for some the price gap decides it.

At a glance

Capability Preloop Varonis Atlas
What it is Agent control plane: gateway, MCP firewall, approvals, sessions, cost, audit AI security across the lifecycle: inventory and shadow AI, posture, runtime protection, compliance, on top of a data security platform
License and deployment Apache 2.0 core, self-hosted on any infrastructure; Cloud and Enterprise plans Commercial; listed on AWS Marketplace
List price Open source free; Cloud and Enterprise priced per plan USD 108,000 per AI system per year; 162,000 with Guardrails; 202,500 for Complete (Guardrails and Complete include up to 200,000 prompts per month per AI system)
Inline gateway OpenAI-, Anthropic- and Gemini-compatible model gateway AI Gateway in the live request path, inspecting prompts and responses
Tool and agent policy Ordered allow / deny / require-approval rules with CEL conditions on tool arguments Agent Intent-Based Access Control: alert, block, modify, log, route to a person for approval, or quarantine
Coding agents Claude Code, Codex CLI, Cursor, Copilot CLI, OpenCode, Gemini CLI, Hermes, OpenClaw, any MCP client Claude Code and Claude Cowork, alongside Claude Enterprise and Claude Platform
Human approvals Per call on mobile, watch, Slack, Mattermost, email, webhook, or the CLI Routing an action "to a person for approval" (IBAC post); channel not stated publicly
Data classification, permissions, DLP Not in scope; redaction of sensitive values on governed traffic only Core strength: visualize AI's sensitive data access, revoke excessive permissions, apply sensitivity labels
Microsoft 365 Copilot and ChatGPT Enterprise GitHub Copilot usage import only Copilot coverage: blast radius, prompt monitoring, labels
Cost and budgets Token spend per agent, session, model, and key, with budgets "Unusual token usage" detection
Compliance reporting Evidence exports (for example DORA agent slices and CRA product evidence); hash-chained audit with signed checkpoints EU AI Act, NIST AI RMF, and ISO 42001 frameworks with downloadable reports

What Varonis does well

Varonis brings something Preloop does not try to build:

If your first risk is sensitive data exposure through Copilot, ChatGPT Enterprise, or internal AI apps, Varonis is built for that.

Where Preloop fits

Atlas and Preloop overlap more than they used to: both put a gateway inline, both police tool calls, both can route a decision to a person. The differences are in scope, shape, and price:

  • Agent-native, cross-vendor control. Preloop was built around the agent loop. Native action gates for Claude Code, Codex CLI, Cursor, Copilot CLI, OpenCode, and others put shell commands and file edits on the same approval path as MCP calls. One policy covers every governed agent, on laptops, servers, and in Preloop flows.
  • Approvals people actually answer. One-tap decisions on phone and watch, plus Slack, Mattermost, email, and webhook, with the tool, arguments, and agent reasoning in front of the reviewer. Async approval mode keeps long-running agents from holding connections open.
  • Cost governance. Budgets per agent, flow, key, and account in the open-source core; per user and team in Cloud and Enterprise. Spend per session and model. Varonis's public pages mention detecting unusual token usage; we found no budget feature there.
  • Open source and self-hosted. The governance core is Apache 2.0. A security team or a reseller can run it on a VM in the customer's network and read the enforcement code.
  • Evidence, not certification. Audit rows are sealed into a per-account hash chain with signed checkpoints, and evidence exports are files an auditor can read. Preloop generates evidence that can be used for compliance; it is not a compliance platform.
  • Price. The Atlas list price on AWS Marketplace starts at USD 108,000 per AI system per year. The Preloop core is free. For teams that cannot justify six figures per AI system, that is the whole difference.

What Preloop does not do: data classification at rest, data access governance across file shares and SaaS, DLP, Microsoft 365 Copilot and ChatGPT Enterprise monitoring through vendor audit APIs, human behavior analytics, or a managed detection service. If you need those, you need a data security platform.

When to choose Varonis Atlas

  • Your main AI risk is sensitive data exposure through Copilot, ChatGPT Enterprise, or AI apps connected to large data estates.
  • You already run the Varonis Data Security Platform and want AI coverage in the same console.
  • You need framework reports for ISO 42001 or NIST AI RMF out of the box, and the budget fits a per-AI-system price.

When to choose Preloop

  • Your agents are coding agents and automations where approvals, budgets, and session evidence matter more than file-share classification.
  • You need open-source, self-hosted governance you can audit, or a price that works for a team rather than an enterprise program.
  • You run several agent vendors and want one policy and approval layer across them.

How they combine

Run them side by side, each on its own layer:

  1. Varonis on the data. Keep Varonis for classification, permissions, DLP, and Copilot coverage.
  2. Preloop on the agents. Route coding agents and automations through Preloop's gateway and MCP firewall for approvals, budgets, and session timelines.
  3. One security record. Preloop can POST signed events (approvals raised or decided, policy denials, budget crossings, closed sessions) to a URL you own, and export OpenTelemetry spans, so its decisions can land next to Varonis alerts in your SIEM.

We have not built or tested a Varonis-specific integration. This is a deployment pattern.

FAQ

Is Preloop a Varonis alternative? For data security, no. For governing what coding agents and automations do and spend, Preloop is a lower-cost, open-source option that can run next to Varonis.

We already have Varonis. What does Preloop add? Per-call approvals on mobile and Slack, budgets per agent, native action gates for coding agents, governed event-driven flows, and hash-chained session evidence, self-hosted.

What is Varonis Atlas? The AI security platform Varonis launched after acquiring AllTrue.ai, generally available since May 28, 2026.

Try Preloop

Last reviewed: 2026-10-08.