Secra vs Superagent
55 fields both were evaluated on, 25 of them different — including where one discloses something the other does not. Every value links to the document it came from. 30 further fields are disclosed by neither and are listed at the end rather than tabled.
Assurance
| Field | Secra | Superagent |
|---|---|---|
| Audit trail· | Vendor states audit logs can be exported alongside block-rate tracking “track block rates, and export audit logs”www.sec-ra.com · checked Aug 2, 2026 | no public information superagent.sh · checked Aug 18, 2026 |
| Explainability· | “Every scan returns a 0-100 trust score combining all detection signals.”www.sec-ra.com · checked Aug 2, 2026 | “findings on the exact line, fixes as pull requests.”superagent.sh · checked Aug 4, 2026 Not in our latest capture. We captured this page again on Sep 16, 2026 and this quote was not there. How we re-check citations |
| Runtime governance· | “Layered Scan Policies Apply stricter thresholds for destructive operations (delete, send) vs. safe operations (read).”www.sec-ra.com · checked Aug 2, 2026 | runtime guardrails: deterministic rules that decide what your agent may do “runtime guardrails deterministic rules that decide what your agent may do.”superagent.sh · checked Aug 18, 2026 |
| Permission scopes· | “Permission Context Role-based tool validation. Enforce read-only roles, allowlisted operations, and per-user permission boundaries on tool calls.”www.sec-ra.com · checked Aug 2, 2026 | no public information superagent.sh · checked Aug 4, 2026 |
| Compliance certifications· | “Compliance Reporting Audit-ready compliance reports with threat breakdowns, block rates, and status for your security team.”www.sec-ra.com · checked Aug 2, 2026 | no public information superagent.sh · checked Aug 4, 2026 |
| Regulatory alignment· | “OWASP Agentic Top 10 Explained: Every Risk, Real Attacks, and Fixes”www.sec-ra.com · checked Aug 2, 2026 | no public information superagent.sh · checked Aug 4, 2026 |
| Evaluation coverage· | no public information www.sec-ra.com · checked Aug 2, 2026 | “self-serve red teaming against what you actually run.”superagent.sh · checked Aug 4, 2026 Not in our latest capture. We captured this page again on Sep 16, 2026 and this quote was not there. How we re-check citations |
Safety
| Field | Secra | Superagent |
|---|---|---|
| Safety evaluations· | “OWASP Agentic Top 10 Explained: Every Risk, Real Attacks, and Fixes”www.sec-ra.com · checked Aug 2, 2026 | “self-serve red teaming against what you actually run.”superagent.sh · checked Aug 4, 2026 Not in our latest capture. We captured this page again on Sep 16, 2026 and this quote was not there. How we re-check citations |
| Red teaming· | “Introducing Secra Simulate: Free Adversarial Testing for AI Agents”www.sec-ra.com · checked Aug 2, 2026 | “self-serve red teaming against what you actually run.”superagent.sh · checked Aug 4, 2026 Not in our latest capture. We captured this page again on Sep 16, 2026 and this quote was not there. How we re-check citations |
| Third-party evaluations· | “OWASP Agentic Top 10 Explained: Every Risk, Real Attacks, and Fixes”www.sec-ra.com · checked Aug 2, 2026 | no public information superagent.sh · checked Aug 4, 2026 |
| Data handling· | “API Keys Generate sk_secra_ scoped keys shown once, bcrypt-hashed at rest.”www.sec-ra.com · checked Aug 2, 2026 | no public information superagent.sh · checked Aug 4, 2026 |
Practicality
| Field | Secra | Superagent |
|---|---|---|
| Pricing model· | “Priced like infrastructure, not like an API.”www.sec-ra.com · checked Aug 2, 2026 | no public information superagent.sh · checked Aug 4, 2026 |
| Deployment options· | “Drop them into any HTTP client and you're protected.”www.sec-ra.com · checked Aug 2, 2026 | “you already work in your coding agent and github. so that's where superagent works too — no new workflows or tools to learn.”superagent.sh · checked Aug 4, 2026 |
| Integrations· | “Works with OpenAI, Anthropic, LangChain, LlamaIndex, raw HTTP, and the three frameworks your team will invent next quarter.”www.sec-ra.com · checked Aug 2, 2026 |
Foundation models
| Field | Secra | Superagent |
|---|---|---|
| Base models· | no public information superagent.sh · checked Aug 4, 2026 | |
| Model provider· | no public information superagent.sh · checked Aug 4, 2026 | |
| Context window· | no public information superagent.sh · checked Aug 4, 2026 |
Ecosystem
| Field | Secra | Superagent |
|---|---|---|
| Protocols supported· | Ships MCP-related capability: a "contributor trust" API and MCP integration (per product changelog, 2026-08-11). “contributor trust api and mcp”superagent.sh · checked Aug 18, 2026 Not in our latest capture. We captured this page again on Sep 16, 2026 and this quote was not there. How we re-check citations | |
| Tool use· | “Tool Validation Validate LLM-generated tool calls before execution.”www.sec-ra.com · checked Aug 2, 2026 | Deterministic runtime rules govern what agents may do; sensitive activity is confined to the endpoint “control it where it runs deterministic rules for what agents do, trust scores for everything they consume — and sensitive activity stays on the endpoint.”superagent.sh · checked Aug 18, 2026 Not in our latest capture. We captured this page again on Sep 16, 2026 and this quote was not there. How we re-check citations |
| API access· | “DEVELOPER+ API Keys Generate sk_secra_ scoped keys”www.sec-ra.com · checked Aug 2, 2026 | Contributor Trust API and MCP integration shipped per product changelog (2026-08-11); no separate REST/webhooks API documented on current homepage. “contributor trust api and mcp”superagent.sh · checked Aug 18, 2026 Not in our latest capture. We captured this page again on Sep 16, 2026 and this quote was not there. How we re-check citations |
| Open source· | no public information www.sec-ra.com · checked Aug 2, 2026 |
Impact
| Field | Secra | Superagent |
|---|---|---|
| User base· | ubicloud, evry health, dotenvx, firecrawl, capchase, nango, mastra, paperclip “ubicloud evry health dotenvx firecrawl capchase nango mastra paperclip”superagent.sh · checked Aug 4, 2026 | |
| Deployment scale· | “free for open source. the whole suite, on any public repo. private repos are paid — contact us and we'll set you up.”superagent.sh · checked Aug 4, 2026 Not in our latest capture. We captured this page again on Sep 16, 2026 and this quote was not there. How we re-check citations | |
| Target sectors· | no public information www.sec-ra.com · checked Aug 2, 2026 | |
| Documented incidents· | “One Prompt, 4,000 Machines: The OpenClaw Attack Chain Explained”www.sec-ra.com · checked Aug 2, 2026 | no public information superagent.sh · checked Aug 4, 2026 |
Disclosed by neither
Both Secra and Superagent publish nothing on these 30 fields. That is a finding about the category rather than a difference between them, so it is recorded here instead of as 30 identical table rows. Each is shown with its source check on the individual profiles.
- Autonomy level
- Human oversight
- Goal complexity
- Action space
- Operating environment
- Initiative
- High-risk domains
- Price point
- Availability
- Supported regions
- Support model
- Model swappable
- Open weights
- Fine-tuning
- Multi-agent
- Marketplace presence
- Safety policy
- Usage restrictions
- Model or system card
- Incident reporting
- Insurance available
- Insurance carriers
- Coverage limits
- Indemnification
- Liability cap
- Tamper-evident log
- Outcome-based pricing
- Settlement mechanism
- Dispute process
- SLA terms
Questions
- How do Secra and Superagent compare on audit trail?
- Secra: Vendor states audit logs can be exported alongside block-rate tracking. Superagent: no public information disclosed.