MOUNTAIN THEORY VS SPLX (ZSCALER)

SPLX has the most comprehensive guardrail offering in the prompt-inspection group and now sits inside Zscaler. Guardrails and execution control are the clearest example of two different layers being confused for one.

Mountain Theory compared with SPLX (Zscaler). Competitor detail verified August 2026.
 SPLX (Zscaler)Mountain Theory
What it controlsPrompt and response contentThe action an AI agent is about to take
Where it sitsInline on the content pathInline at execution, between the decision and the action
How policy is setNatural language content policyPlain English, no code
Deployment reachZscaler Zero Trust ExchangeModel and framework agnostic, including custom and on-prem agents
Best fit whenYour AI produces text, not actionsAn AI acting wrongly has physical or regulatory consequences

Why you might pick SPLX (Zscaler)

SPLX combines inline input and output filtering, natural language policy, red teaming and governance in one platform, now carried by Zscaler Zero Trust Exchange distribution into thousands of enterprises. Mature attack telemetry and 5,000+ attack simulations behind it.

Why you might pick Mountain Theory

SPLX filters prompts and outputs, which is content safety. Mountain Theory governs actions, which is execution safety. SPLX stops the model from saying something unsafe. Mountain Theory stops the agent from doing something unsafe. A jailbreak filter does not stop an authenticated agent from deleting a database, because nothing unsafe was said.

The honest verdict

SPLX stops your model saying something it should not. It does not stop your agent doing something it should not, because deleting a database is not an unsafe sentence. If your AI writes text, SPLX may be all you need. If your AI has an API key and permission to use it, content filtering is not the control you are missing.

What we can actually show

Claims in this category are easy to make and hard to check, so here is ours on the record. The same 10 actions were run in the same order under three configurations. Ungoverned, 10 of 10 executed. Under NVIDIA OpenShell alone, all 5 sandbox-boundary crossings were denied at the kernel, and all 3 in-bounds bad decisions still went through, including a secrets read that printed credentials to the screen. Under OpenShell plus Mountain Theory, those same 3 actions returned HOLD, HOLD and BLOCK, and the secrets read was stopped before it executed, so the credentials never printed. Terminal recordings of all three runs are published, including the two actions Mountain Theory has no policy for.

Separately, when a third-party provider updated the foundation model driving an autonomous agent, the agent began attempting multi-step actions it had never tried before. Nothing on our side changed. Every attempt was stopped on 30 and 31 July 2026, the days the behaviour first appeared. No new rule, no signature, no patch.

Watch the three-configuration run against NVIDIA OpenShell

See novel agent behaviour stopped the day it appeared

Ask SPLX (Zscaler), and every other vendor you are evaluating, for the same four things: the exact action set, the ungoverned control condition, the outcome per action including the ones the product did not stop, and the recording. A certification, an integration list or a customer logo answers a different question.

Compare all 56 AI security vendors

Read 31 answers on execution-layer control

Book a demo and see it stop a live agent

Scroll to Top