06 AOÛ 2026
GOUVERNANCE

Anaconda buys Enkrypt AI (model/pipeline security) after acquiring Kilo Code — the market bolts governance onto agent orchestration; at AppH it is already native in every module

On 4 August Anaconda announced the acquisition of Enkrypt AI, a specialist in AI pipeline security and compliance, a few weeks after buying Kilo Code (agentic engineering environments, 22 July). The next day, InfoWorld published a 5-criteria guide for evaluating an agent orchestration platform — criterion #1: "observable control, oversight and trust". The same move already seen at XMPro/Gartner, Airia/Bitovi and Oracle: the market buys governance separately rather than building it in.

On 4 August, in Austin (Texas), Anaconda Inc. announced the purchase of Enkrypt AI, an AI security and compliance solution that detects and fixes hidden risks in enterprise pipelines. In the last two months alone, Enkrypt AI says it scanned more than 268,000 tools — the individual functions an AI agent can call — across 25,000 MCP servers, and found more than 143,000 vulnerabilities affecting 73% of those servers. The company also translates regulatory frameworks (the NIST AI Risk Management Framework, the European AI Act) into automatically enforced guardrails. The deal comes two weeks after the Kilo Code acquisition (22 July), which had extended Anaconda into the agentic engineering environments where developers work. Anaconda's CEO, David DeSanto, puts it bluntly: "Enterprises are running AI-native applications that already contain exploitable vulnerabilities… trust cannot be added after an agent is in production, it has to be built into the foundation from the start" — a foundation Anaconda has just bought rather than built itself.

The next day, 5 August, InfoWorld published, under Isaac Sacolick's byline, a five-criteria guide for evaluating an agent orchestration platform — and criterion #1, before interoperability and before the vendor's roadmap, is "observable control, oversight and trust": built-in governance, visibility, and a human layer ("human override") able to interrupt an action. It is the third time in two weeks this same pattern shows up in our digests — XMPro buying to add governance alongside Gartner, Airia partnering with Bitovi, and now Anaconda/Enkrypt: the enterprise market solves agentic governance by bolting it on afterwards, through an acquisition or a third-party partner. AppH went the opposite way last week: `agentic-kill-switch-memory-isolation-audit` (closed on 4 August) gives an AppManager administrator the real ability to interrupt an AI call in progress — not just stop it from starting — across the product's 14 real agentic call points (public chat funnel, follow-ups, invoice/quote/visit reminders, mailbox drafting, lead qualification, progress coach, generator, document intake, enrolment-request qualification, and more), with memory isolated per module and human validation before any action with real consequences. Not one more security vendor to integrate: governance lives in the module the customer already uses every day.

For AppH

  • What Anaconda had to buy (Enkrypt AI, a whole acquisition) to add to its platform, AppH already ships natively: an admin kill-switch that cuts an in-progress AI call across its 14 real agentic call points — verified in the code, not on a roadmap.
  • No extra vendor layer to integrate, no third-party attack surface added after the fact — the audit log and per-agent memory isolation live in the same module the customer already uses, exactly the criterion #1 InfoWorld describes for evaluating an orchestration platform.

Against / what does not hold indefinitely

  • Enkrypt AI operates at enterprise scale (268,000 tools scanned, 25,000 MCP servers in two months); AppH's kill-switch covers its 14 real call points — a real number, but a much smaller one, and claiming otherwise would be dishonest.
  • AppH has not published an independent vulnerability audit like the one Enkrypt AI produces for its customers — the kill-switch and human validation are real and verified internally, but a third-party audit remains a legitimate request, not yet done.

One could read this news as proof that Anaconda is a step ahead — after all, they just bought a whole company for what AppH builds in-house. The more honest point lies elsewhere: agentic governance has a cost, however you cover it. Anaconda pays that cost by buying Enkrypt AI and integrating it into its orchestration platform; AppH pays it in engineering hours directly in Automations, Follow-ups, Messenger and the ten other modules that call an AI model on real customer data. Both approaches have real merit — but for an SMB with neither the budget nor a dedicated security team to evaluate yet another third-party vendor, having governance already inside the tool it uses changes what it has to verify itself. And the part that depends on no acquisition, at anyone: no action with real consequences for a customer or an employee leaves AppManager without a human validating it first — the kill-switch exists precisely for the day that rule alone would not be enough.

Reviewed by a human at AppH
← Previous article (older)Next article (newer) →

← Back to news

Want us to walk you through how this applies to a real case?

Talk to AppH

Get new posts by email

One email when we publish new analysis — never spam, unsubscribe in one click.