Connect with us

Technology

Harness and Kong Expand Strategic Partnership to Deliver Comprehensive API and AI Security

Published

on

Joint solution extends proven API gateway security to the AI era — with automated AI discovery and runtime AI protection

SAN FRANCISCO, July 23, 2026 /PRNewswire/ — Harness, the AI Software Delivery Platform™ company, and Kong Inc., a leading developer of API and AI connectivity technologies, today announced an expansion of their strategic partnership to address the growing security challenges posed by AI-driven architectures, autonomous agents, and Model Context Protocol (MCP) deployments.

According to The State of AI-Native Application Security 2025 report, as enterprises race to deploy AI at scale, 62% have no visibility into where LLMs are in use across their environment, and 74% say AI sprawl will outpace API sprawl when it comes to risk — making embedded, infrastructure-level security more critical than ever. And companies are now deploying agents into their operations at an exponentially increasing rate, making it a necessity to protect the agents themselves and the systems interacting with those agents.

The two companies are extending their joint solution from Kong API Gateway to also include Kong AI Gateway, bringing Harness’s AI security intelligence directly into the AI infrastructure layer and enabling enterprises to discover, monitor, and protect every agent, AI asset, LLM-powered service, and MCP-connected workflow that traverses it.

A Proven Foundation: Harness and Kong API Gateway

Harness and Kong have been jointly trusted by enterprises to deliver best-in-class API security for years. The existing Harness and Kong API Gateway integration provides:

Comprehensive API traffic visibility and behavioral analysis across all Kong-managed servicesReal-time detection and blocking of API threats, including OWASP API Security Top 10 risks, credential stuffing attacks, and business logic abuseContinuous sensitive data tracking to identify PII exposure and regulatory riskZero-friction deployment alongside existing Kong configurations

This new offering of the AI Gateway solution applies the same level of security depth to AI infrastructure, ensuring that security teams are not left behind as their organizations adopt AI and agentic operations.

“Our partnership with Harness has given joint customers production-grade API security that works with the way they build, not against it,” said Ken Kim, Senior Vice President, Business Development at Kong Inc. “Extending to include Kong AI Gateway is a natural next step. The same enterprises are now moving AI into production through our gateway and need the same depth of visibility and control they’ve come to rely on for their APIs for all AI traffic types including LLM, MCP, and A2A. That’s exactly what this delivers and is crucial for organizations scaling in the agentic era.”

The New Frontier: Kong AI Gateway and Harness AI Security

As enterprises accelerate AI adoption, the attack surface has fundamentally shifted. AI agents, LLM-powered microservices, and MCP-enabled integrations introduce new vectors that traditional security tools were not designed to address. Unlike traditional software, AI agents are non-deterministic — the same agent can behave differently on consecutive runs, making it impossible to secure them the way you’d secure a static API. The new Harness and Kong AI Gateway integration directly tackles these challenges across two critical domains: AI discovery and AI protection.

AI Discovery
Harness automatically inventories every AI asset, API, MCP server, tool, prompt, and resource routed through Kong AI Gateway — providing security teams with a continuously updated catalog of their AI attack surface. No manual documentation. No blind spots.

AI Protection
Harness applies behavioral analysis and anomaly detection to AI traffic in real time, identifying prompt injection attacks, data exfiltration through AI responses, jailbreaking, malicious code in prompts, and other AI-specific threats. Enterprises gain the same depth of observability and protection for their agents and AI workloads that they already rely on for traditional APIs, with full prompt and response details available for incident investigation and inline policy enforcement through Kong AI Gateway.

“Shadow AI has become the defining security blind spot for enterprises today. Traditional tools were built for static code and predictable systems, not for adaptive AI models, agent-to-agent communication, and MCP-connected workflows that evolve continuously,” said Rahul Sood, GM of Application Security at Harness. “This integration of Harness AI Security with Kong puts security intelligence directly into the connectivity layer where AI traffic flows. Joint customers now have the visibility and control they need to move fast without losing sight of what’s happening across their AI infrastructure.”

Availability

The Harness and Kong API Gateway integration is generally available today for all joint customers. The Kong AI Gateway integration, including AI Discovery and AI Protection, is also generally available now. Joint customers can contact their account team or request a demo.

About Harness
Harness is the AI Software Delivery Platform™ company, enabling engineering teams to build, test, and deliver software faster and more securely. Powered by Harness AI and the Software Delivery Knowledge Graph, the platform brings intelligent automation to every stage of the software delivery lifecycle after code — removing toil and freeing developers from manual, repetitive work. Companies like United Airlines, Morningstar, and Choice Hotels use Harness to accelerate releases by up to 75%, cut cloud costs by 60%, and achieve 10x efficiency across DevOps. Based in San Francisco, Harness is backed by Goldman Sachs, Menlo Ventures, IVP, Unusual Ventures, and Citi Ventures.

About Kong

Kong Inc., a leading developer of API and AI connectivity technologies, is building the connectivity layer of AI. Trusted by the Fortune 500® and AI-native startups alike, Kong’s unified API and AI platform enables organizations to secure, manage, accelerate, govern, and monetize the flow of intelligence across APIs and AI traffic — on any model, any cloud. For more information, visit www.konghq.com.

View original content to download multimedia:https://www.prnewswire.com/news-releases/harness-and-kong-expand-strategic-partnership-to-deliver-comprehensive-api-and-ai-security-302833414.html

SOURCE Harness

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

Control-First Security Design Creates Friction and Limits Business Value, Finds Info-Tech Research Group

Published

on

By

Many security programs are designed around controls rather than the key services they are meant to enable. Info-Tech Research Group explains that when security controls are introduced without the context, alignment, or defined outcomes tied to how the organization operates, they create friction and fail to deliver intended value. The firm’s blueprint Build Security Services for Business Value introduces a service-centric framework for designing security as a built-in enabler, not an add-on control layer.

ARLINGTON, Va., July 23, 2026 /PRNewswire/ — As organizations face rising security threats and growing dependence on digital operations, security leaders are under pressure to protect the business without slowing it down. Yet many security teams continue to implement controls in isolation from the business services they are meant to protect, according to Info-Tech Research Group. To help address this challenge, the global research and advisory firm has published its Build Security Services for Business Valueblueprint,designed to help CISOs and IT leaders define security as a service with clear context, measurable outcomes, and business value.

Info-Tech’s research shows that when security is not aligned to the business services it supports, leaders struggle to articulate what security is meant to achieve, who it serves, and how it creates value. Controls introduced without this alignment are more likely to disrupt operations, be bypassed, or go underused, reinforcing the perception of security as a barrier rather than an enabler. Over time, this erodes trust, makes investment harder to justify, and reduces the organization’s ability to sustain effective security practices.

“Security that isn’t designed in the context of the business will always struggle to gain traction,” says Diana MacPherson, research director at Info-Tech Research Group. “CISOs need to stop leading with controls and start leading with a service story, one that makes the purpose, the stakeholders, and the value explicit. That’s what earns trust and investment.”

Info-Tech’s Three-Phase Framework for Designing Security Services That Enable Business Outcomes

To help security leaders move from control-first design to service-based enablement, Info-Tech’s Build Security Services for Business Value blueprint outlines a three-phase framework for defining, aligning, and operationalizing security services:

Phase 1: Map Your Security Service Context
Define the security service by clarifying its purpose, stakeholders, dependencies, risks, and value within the broader business environment.Phase 2: Align Security Services to Business Services
Ensure that security services are aligned to business workflows, customers, capabilities, governance, and risk so that security supports how the organization delivers outcomes.Phase 3: Analyze, Finalize, and Communicate the Service
Translate insights into a fundable plan by defining outcomes, estimating resources and costs, and communicating value through clear narratives and roadmaps.

“Business leaders fund what they understand,” adds MacPherson. “If security leaders can’t articulate what a service costs, what it delivers, and who it protects, they’ll keep losing the budget conversation. This framework gives them the language to change that.”

Info-Tech’s Build Security Services for Business Value blueprint equips CISOs and security leaders with a phased framework, supported by a Security Service Workbook, Communication Document, and Roadmap Tool, to help organizations define service context, align security to business services, and translate insights into actionable plans. By applying this approach, security leaders can position security as a measurable business enabler rather than a control layer disconnected from the business.

For exclusive and timely commentary from Info-Tech’s experts, including Diana MacPherson, and access to the complete Build Security Services for Business Value blueprint, please contact pr@infotech.com.

About Info-Tech Research Group
Info-Tech Research Group is the “get things done” partner for over 30,000 IT, HR, and marketing leaders worldwide. The fastest growing research and advisory firm, Info-Tech enables leaders to make well-informed decisions and transform their organizations through AI, strategic foresight, step-by-step methodologies, practical tools, industry-leading advisory, and training programs. For nearly 30 years, tens of thousands of private and public organizations have trusted Info-Tech to lead their most important initiatives through periods of change and deliver outcomes that truly matter.

To learn more about Info-Tech’s HR research and advisory services, visit McLean & Company, and for data-driven software buying insights and vendor evaluations, visit the firm’s SoftwareReviews platform.

Media professionals can register for unrestricted access to research across IT, HR, and software, and hundreds of industry analysts through the firm’s Media Insiders program. To gain access, contact pr@infotech.com.

For information about Info-Tech Research Group or to access the latest research, visit infotech.com and connect via LinkedIn and X.

View original content to download multimedia:https://www.prnewswire.com/news-releases/control-first-security-design-creates-friction-and-limits-business-value-finds-info-tech-research-group-302833463.html

SOURCE Info-Tech Research Group

Continue Reading

Technology

Control-First Security Design Creates Friction and Limits Business Value, Finds Info-Tech Research Group

Published

on

By

Many security programs are designed around controls rather than the key services they are meant to enable. Info-Tech Research Group explains that when security controls are introduced without the context, alignment, or defined outcomes tied to how the organization operates, they create friction and fail to deliver intended value. The firm’s blueprint Build Security Services for Business Value introduces a service-centric framework for designing security as a built-in enabler, not an add-on control layer.

ARLINGTON, Va., July 23, 2026 /PRNewswire/ — As organizations face rising security threats and growing dependence on digital operations, security leaders are under pressure to protect the business without slowing it down. Yet many security teams continue to implement controls in isolation from the business services they are meant to protect, according to Info-Tech Research Group. To help address this challenge, the global research and advisory firm has published its Build Security Services for Business Valueblueprint,designed to help CISOs and IT leaders define security as a service with clear context, measurable outcomes, and business value.

Info-Tech’s research shows that when security is not aligned to the business services it supports, leaders struggle to articulate what security is meant to achieve, who it serves, and how it creates value. Controls introduced without this alignment are more likely to disrupt operations, be bypassed, or go underused, reinforcing the perception of security as a barrier rather than an enabler. Over time, this erodes trust, makes investment harder to justify, and reduces the organization’s ability to sustain effective security practices.

“Security that isn’t designed in the context of the business will always struggle to gain traction,” says Diana MacPherson, research director at Info-Tech Research Group. “CISOs need to stop leading with controls and start leading with a service story, one that makes the purpose, the stakeholders, and the value explicit. That’s what earns trust and investment.”

Info-Tech’s Three-Phase Framework for Designing Security Services That Enable Business Outcomes

To help security leaders move from control-first design to service-based enablement, Info-Tech’s Build Security Services for Business Value blueprint outlines a three-phase framework for defining, aligning, and operationalizing security services:

Phase 1: Map Your Security Service Context
Define the security service by clarifying its purpose, stakeholders, dependencies, risks, and value within the broader business environment.Phase 2: Align Security Services to Business Services
Ensure that security services are aligned to business workflows, customers, capabilities, governance, and risk so that security supports how the organization delivers outcomes.Phase 3: Analyze, Finalize, and Communicate the Service
Translate insights into a fundable plan by defining outcomes, estimating resources and costs, and communicating value through clear narratives and roadmaps.

“Business leaders fund what they understand,” adds MacPherson. “If security leaders can’t articulate what a service costs, what it delivers, and who it protects, they’ll keep losing the budget conversation. This framework gives them the language to change that.”

Info-Tech’s Build Security Services for Business Value blueprint equips CISOs and security leaders with a phased framework, supported by a Security Service Workbook, Communication Document, and Roadmap Tool, to help organizations define service context, align security to business services, and translate insights into actionable plans. By applying this approach, security leaders can position security as a measurable business enabler rather than a control layer disconnected from the business.

For exclusive and timely commentary from Info-Tech’s experts, including Diana MacPherson, and access to the complete Build Security Services for Business Value blueprint, please contact pr@infotech.com.

About Info-Tech Research Group
Info-Tech Research Group is the “get things done” partner for over 30,000 IT, HR, and marketing leaders worldwide. The fastest growing research and advisory firm, Info-Tech enables leaders to make well-informed decisions and transform their organizations through AI, strategic foresight, step-by-step methodologies, practical tools, industry-leading advisory, and training programs. For nearly 30 years, tens of thousands of private and public organizations have trusted Info-Tech to lead their most important initiatives through periods of change and deliver outcomes that truly matter.

To learn more about Info-Tech’s HR research and advisory services, visit McLean & Company, and for data-driven software buying insights and vendor evaluations, visit the firm’s SoftwareReviews platform.

Media professionals can register for unrestricted access to research across IT, HR, and software, and hundreds of industry analysts through the firm’s Media Insiders program. To gain access, contact pr@infotech.com.

For information about Info-Tech Research Group or to access the latest research, visit infotech.com and connect via LinkedIn and X.

View original content to download multimedia:https://www.prnewswire.com/news-releases/control-first-security-design-creates-friction-and-limits-business-value-finds-info-tech-research-group-302833463.html

SOURCE Info-Tech Research Group

Continue Reading

Technology

NIX United Achieves AWS AI Competency After Rigorous Audit

Published

on

By

AI-enabled software development company NIX United has officially achieved the AWS AI Competency designation from Amazon Web Services (AWS). The recognition validates NIX’s proven expertise in architecting, securing, and deploying enterprise-grade artificial intelligence and machine learning solutions on AWS.

TAMPA, Fla., July 23, 2026 /PRNewswire-PRWeb/ — For enterprise organizations, the designation provides independent validation of NIX’s end-to-end AI capabilities across solution architecture, data security, governance, and operational excellence. It is based on successful production deployments, including a generative AI customer feedback analytics platform and an AI-powered medical education solution. The competency also provides eligible customers with access to AWS-validated frameworks, specialized technical resources, and AWS GenAI Innovation Funding programs.

“AI must be engineered for long-term production value,” said Artur Bakulin, Head of RnD and Innovation at NIX United. “Earning the AWS AI Competency reflects our commitment to building AI architectures grounded in verifiable return on investment.”

Moving Beyond AI Demos to Production Value

While AI adoption accelerates, organizations face a critical barrier: transitioning from impressive proofs of concept to production-grade applications. Building AI for the modern enterprise requires solving complex challenges around regulatory compliance and seamless system integration.

To earn the AWS AI Competency, NIX completed a comprehensive technical audit demonstrating its ability to deliver scalable AI solutions. The evaluation covered engineering practices, security controls, governance frameworks, and operational excellence, while highlighting NIX’s experience applying generative AI to complex business workflows.

Strategic Benefits for Enterprise Clients

“AI must be engineered for long-term production value,” said Artur Bakulin, Head of RnD and Innovation at NIX United. “Earning the AWS AI Competency reflects our commitment to building AI architectures grounded in verifiable return on investment.”

For NIX clients, this designation provides:

Reduced project risk through AWS-validated architectures that support data privacy, security, and regulatory compliance.Faster project execution with access to eligible AWS funding programs, including subsidized AI assessments, Proofs of Concept (PoCs), and AWS GenAI Innovation Funding.Long-term scalability with solutions engineered to move seamlessly from pilot projects to business-critical production environments.

Organizations exploring generative AI initiatives can work with NIX experts to evaluate their eligibility for the AWS GenAI Innovation Funding Program and identify opportunities to accelerate adoption.

Frequently Asked Questions

Q: What specific competency did NIX United achieve?

A: NIX achieved the AWS AI Competency, a formal designation by Amazon Web Services verifying a partner’s technical proficiency and robust customer success in delivering generative AI solutions.

Q: What criteria did AWS use to evaluate NIX United?

A: AWS conducted a comprehensive technical audit covering NIX’s solution architecture, security controls, governance frameworks, and delivery methodology.

Q: How can enterprise clients fund their AI initiatives with NIX United?

A: Through NIX’s status as an advanced AWS partner, eligible clients can access the AWS GenAI Innovation Funding Program to offset costs for AI assessments, proofs-of-concept, and full-scale implementations.

Media Contact

Yevheniia Kryvenko, NIX United, 1 7272563558, yevheniia.kryvenko@nixs.com, NIX United

View original content:https://www.prweb.com/releases/nix-united-achieves-aws-ai-competency-after-rigorous-audit-302831769.html

SOURCE NIX United

Continue Reading

Trending