ASAI Security ResearchIndependent public-source research
Public reviewread only

Solution approach

Coding-agent and developer workstation security

Control coding assistants and agents across developer tools, commands, files, repositories, packages, networks, and credentials.

Research scopeVendorsPublicly documented vendor profiles
Evaluation guideRequirementsSecurity requirements buyers can verify
Evidence basisSourcesPublic claims linked to their original sources
Unresolved itemsQuestionsMissing support is labeled instead of assumed
View research coverageThese counts describe available public research, not product quality or suitability.Expand
Vendor profiles
13 shown in this view
Security requirements
3 to review
Strong public support
22 requirement records
Limited public support
12 requirement records
Open research
5 with no supporting claim · 0 incomplete

Evaluation guide

What buyers should verify

Additional security requirement

AI coding-agent and workstation security

Discover and govern AI coding agents, integrated development environment (IDE) assistants, command-line agents, skills, hooks, extensions, Model Context Protocol (MCP) tools, filesystem access, commands, network activity, secrets, and software-supply-chain actions on developer workstations and build environments.

Questions to test
  1. A test coding agent and its skills, hooks, extensions, or Model Context Protocol (MCP) tools appear in an attributable inventory.
  2. A policy blocks or records a dangerous command, sensitive-file access, secret exposure, network action, or risky package installation.
  3. The evidence ties the action to developer, agent, repository or workspace, policy, and timestamp.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Foundational security requirement

AI model and supply-chain security

Discover, inventory, scan, validate, and monitor models, datasets, model artifacts, registries, dependencies, and AI development assets for tampering, unsafe serialization, provenance gaps, or malicious content.

Questions to test
  1. A test model or AI artifact appears in inventory with origin, version, hash or provenance, and deployment context.
  2. A malicious, tampered, unsafe, or policy-violating artifact produces a finding before deployment.
  3. The finding links the artifact to its registry, pipeline, owner, affected workload, and remediation action.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Foundational security requirement

AI gateway, tool-connection, and runtime controls

Mediate model, agent, tool, application programming interface (API), connector, and Model Context Protocol (MCP) traffic through an enforcement point that applies identity-aware policy, content controls, routing, rate limits, and auditable allow or deny decisions.

Questions to test
  1. A model, agent, tool, or Model Context Protocol (MCP) request passes through a named policy enforcement point.
  2. A test policy allows, blocks, transforms, redirects, or rate-limits the request with an explicit reason.
  3. The audit event records caller identity, destination, tool or model, policy decision, and timestamp.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Vendor research

Vendors with public research for this approach

Choose vendors to compare →

Vendors are grouped by whether this approach is a core product focus or related coverage, then ordered by documented support across the requirements shown. This organizes public research coverage; it is not a product ranking or recommendation.

Evidence labelsStrong public supportLimited public supportNo supporting claim foundResearch incomplete
VendorCoding-agent securityModel supply chainAI gateway and tool controlsSourcesAction
Core product focusThis approach is central to how these vendors present the product · 4 vendors
Backslash Agentic AI Endpoint SecurityEmergingSupport found for 3 of 3 requirementsStrong public supportStrong public supportStrong public support2Profile →
KnosticEmergingSupport found for 3 of 3 requirementsStrong public supportStrong public supportStrong public support3Profile →
AktoEmergingSupport found for 3 of 3 requirementsStrong public supportLimited public supportStrong public support3Profile →
Snyk EvoScaledSupport found for 2 of 3 requirementsStrong public supportStrong public supportNo supporting claim found1Profile →
Related coverageThese vendors address the requirements through another core product focus · 9 vendors
Nightfall AIGrowth stageSupport found for 3 of 3 requirementsStrong public supportStrong public supportStrong public support1Profile →
ZenityGrowth stageSupport found for 3 of 3 requirementsStrong public supportLimited public supportStrong public support2Profile →
KeycardGrowth stageSupport found for 2 of 3 requirementsStrong public supportNo supporting claim foundStrong public support1Profile →
CyberhavenScaledSupport found for 3 of 3 requirementsStrong public supportLimited public supportLimited public support2Profile →
Enkrypt AIEmergingSupport found for 3 of 3 requirementsLimited public supportLimited public supportStrong public support2Profile →
Zscaler AI SecurityEstablishedSupport found for 3 of 3 requirementsLimited public supportLimited public supportStrong public support2Profile →
Harmonic SecurityEmergingSupport found for 2 of 3 requirementsLimited public supportNo supporting claim foundStrong public support2Profile →
RunlayerGrowth stageSupport found for 2 of 3 requirementsLimited public supportNo supporting claim foundStrong public support1Profile →
Salt Agentic Security PlatformScaledSupport found for 2 of 3 requirementsLimited public supportNo supporting claim foundLimited public support3Profile →

Company maturity remains a filter and profile attribute; it does not affect the research-coverage order.