Anaconda announced the acquisition of the AI security provider Enkrypt AI on August 4, 2026, and is integrating its testing tools into its own development platform. According to its own statements, Enkrypt AI examined 268,000 tools on 25,000 MCP servers over the past two months and found around 143,000 vulnerabilities – at least one on 73 percent of the servers.
Enkrypt AI uncovered vulnerabilities on three-quarters of the servers
The company, founded in 2022 in Boston, offers automated red teaming before the productive deployment of AI models, ongoing protection against jailbreaks – targeted attempts to bypass a model’s security requirements – and data leaks during operation, as well as automation for compliance requirements such as the NIST framework for AI risks, the US health-data law HIPAA, and the EU AI Act. Enkrypt AI was founded by Yale graduates Sahil Agarwal and Prashanth Harshangi; in 2024, the startup raised a seed round of $2.35 million, led by investor Boldcap with participation from Berkeley SkyDeck and other venture capital firms, according to VentureBeat. The scan numbers now published reportedly reflect the period immediately before the acquisition and are meant to demonstrate the need for security checks on MCP servers – interfaces through which AI agents access external tools and data. According to the provider, the tools work independently of any single vendor and can be integrated into development environments for various language models. A purchase price was not disclosed; Enkrypt AI’s scan numbers are independently unverified.
Anaconda builds a comprehensive security layer with the purchase
With the acquisition, Anaconda positions itself as a provider that secures the entire path from a developer’s first prompt to a production-ready AI application. According to the joint announcement by Anaconda CEO David DeSanto and Enkrypt co-founder Sahil Agarwal, customers of the platform will automatically receive a governed testing path for models, agents, and MCP servers, supplemented by runtime protection mechanisms in their own infrastructure. Enkrypt AI will continue to operate as its own brand within Anaconda; the announcement provides no details on team or pricing. The acquisition is part of a series of purchases: just a few weeks earlier, Anaconda had acquired Kilo Code, an open-source programming agent that works independently of any single model provider. Together with Enkrypt AI, this creates a platform that lets companies both build and test AI applications – an additional argument for businesses in regulated industries to deploy AI agents productively instead of limiting them to test environments over security concerns. The announcement does not disclose how many existing customers the Anaconda platform currently serves.
Enterprise customers demand more control over autonomous agents
The acquisition comes as the industry increasingly seeks tools for controlling autonomous systems. Storage service Box likewise justified its own security controls for AI agents in July 2026 by citing its own survey, in which nine out of ten IT decision-makers named security concerns as the biggest hurdle to deploying agents. MCP, as a standard interface between language models and external tools, is spreading rapidly and is also seen in the industry as a new attack vector: security vendor Trend Micro found in its own research around 492 publicly accessible MCP servers on the internet with no authentication at all, through which internal data and systems could be read out. The timing of the acquisition also coincides with growing regulatory pressure: since August 2, 2026, the EU AI Act’s transition period has expired, and the European Commission can now impose fines of up to 35 million euros or 7 percent of global annual revenue on providers of particularly powerful models. What will matter is whether the testing procedures developed by Enkrypt AI can also be independently confirmed, and whether Anaconda promptly builds its commitments on runtime protection and compliance automation into its own platform – the company has not yet given specific timelines for this.


