ASAI Security ResearchIndependent public-source research
Public reviewread only

Solution approach

AI gateway and tool-connection controls

Inspect and enforce policy on traffic between AI applications, models, tools, application programming interfaces (APIs), and connections.

Research scopeVendorsPublicly documented vendor profiles
Evaluation guideRequirementsSecurity requirements buyers can verify
Evidence basisSourcesPublic claims linked to their original sources
Unresolved itemsQuestionsMissing support is labeled instead of assumed
View research coverageThese counts describe available public research, not product quality or suitability.Expand
Vendor profiles
31 shown in this view
Security requirements
4 to review
Strong public support
75 requirement records
Limited public support
37 requirement records
Open research
12 with no supporting claim · 0 incomplete

Evaluation guide

What buyers should verify

Foundational security requirement

AI gateway, tool-connection, and runtime controls

Mediate model, agent, tool, application programming interface (API), connector, and Model Context Protocol (MCP) traffic through an enforcement point that applies identity-aware policy, content controls, routing, rate limits, and auditable allow or deny decisions.

Questions to test
  1. A model, agent, tool, or Model Context Protocol (MCP) request passes through a named policy enforcement point.
  2. A test policy allows, blocks, transforms, redirects, or rate-limits the request with an explicit reason.
  3. The audit event records caller identity, destination, tool or model, policy decision, and timestamp.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Foundational security requirement

Agent-to-agent communication security

Authorize, log, and control agent-to-agent, agent-to-tool, Model Context Protocol (MCP), connector, and tool-chain handoffs.

Questions to test
  1. An agent, tool, connector, or Model Context Protocol (MCP) handoff logs source identity, destination, and authorization decision.
  2. An allowed or denied access attempt produces an audit event with agent or tool identity.
  3. Rapid or anomalous inter-agent communication can be filtered, investigated, or alerted on.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Additional security requirement

Generative AI application security

Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.

Questions to test
  1. A test large language model (LLM) application event records prompt, application programming interface (API), model, retrieval, or tool interaction context.
  2. A prompt-injection or unsafe-output test is detected, blocked, or flagged by the guardrail or large language model (LLM) firewall.
  3. The evidence links the event to an application, endpoint, request identifier, or workflow.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Foundational security requirement

Sensitive-data protection for generative AI

Detect, classify, redact, or block sensitive data in prompts, responses, files, retrieval, memory, and AI-connected workflows.

Questions to test
  1. Sensitive prompt, response, or file test data is detected and classified during an AI interaction.
  2. A policy redacts, blocks, coaches, or records the sensitive data event before it leaves the approved path.
  3. The evidence record shows data class, user, app or model, action, and timestamp.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Vendor research

Vendors with public research for this approach

Choose vendors to compare →

Vendors are grouped by whether this approach is a core product focus or related coverage, then ordered by documented support across the requirements shown. This organizes public research coverage; it is not a product ranking or recommendation.

Evidence labelsStrong public supportLimited public supportNo supporting claim foundResearch incomplete
VendorAI gateway and tool controlsAgent/tool trustGenerative AI app securityPrompt and data protectionSourcesAction
Core product focusThis approach is central to how these vendors present the product · 13 vendors
Cequence AI GatewayScaledSupport found for 4 of 4 requirementsStrong public supportStrong public supportStrong public supportStrong public support1Profile →
Kong AI GatewayScaledSupport found for 4 of 4 requirementsStrong public supportStrong public supportStrong public supportStrong public support2Profile →
Palo Alto Networks Prisma AIRSEstablishedSupport found for 4 of 4 requirementsStrong public supportStrong public supportStrong public supportStrong public support4Profile →
Cloudflare AI Security SuiteEstablishedSupport found for 4 of 4 requirementsStrong public supportLimited public supportStrong public supportStrong public support2Profile →
Enkrypt AIEmergingSupport found for 4 of 4 requirementsStrong public supportLimited public supportStrong public supportStrong public support3Profile →
F5 AI Security PlatformEstablishedSupport found for 4 of 4 requirementsStrong public supportLimited public supportStrong public supportStrong public support2Profile →
Operant AIEmergingSupport found for 4 of 4 requirementsStrong public supportLimited public supportStrong public supportStrong public support3Profile →
Speakeasy AI Control PlaneGrowth stageSupport found for 4 of 4 requirementsStrong public supportLimited public supportStrong public supportStrong public support2Profile →
AktoEmergingSupport found for 3 of 4 requirementsStrong public supportNo supporting claim foundStrong public supportStrong public support2Profile →
Backslash Agentic AI Endpoint SecurityEmergingSupport found for 3 of 4 requirementsStrong public supportNo supporting claim foundStrong public supportStrong public support3Profile →
Iterate.ai AgentWatchEmergingSupport found for 4 of 4 requirementsStrong public supportLimited public supportLimited public supportStrong public support1Profile →
Wallarm AI Control PlatformGrowth stageSupport found for 4 of 4 requirementsStrong public supportLimited public supportStrong public supportLimited public support1Profile →
RunlayerGrowth stageSupport found for 3 of 4 requirementsStrong public supportNo supporting claim foundLimited public supportLimited public support1Profile →
Related coverageThese vendors address the requirements through another core product focus · 18 vendors
Holistic AIEmergingSupport found for 4 of 4 requirementsStrong public supportStrong public supportStrong public supportStrong public support2Profile →
Zscaler AI SecurityEstablishedSupport found for 4 of 4 requirementsStrong public supportStrong public supportStrong public supportStrong public support2Profile →
Cisco AI DefenseEstablishedSupport found for 3 of 4 requirementsStrong public supportNo supporting claim foundStrong public supportStrong public support2Profile →
Imperva AI Application SecurityEstablishedSupport found for 3 of 4 requirementsStrong public supportNo supporting claim foundStrong public supportStrong public support1Profile →
Proofpoint AI Security / AcuvityEstablishedSupport found for 3 of 4 requirementsStrong public supportNo supporting claim foundStrong public supportStrong public support2Profile →
AembitEmergingSupport found for 4 of 4 requirementsStrong public supportStrong public supportLimited public supportLimited public support3Profile →
CyberArk Secure AI AgentsEstablishedSupport found for 4 of 4 requirementsStrong public supportStrong public supportLimited public supportLimited public support2Profile →
KnosticEmergingSupport found for 4 of 4 requirementsStrong public supportLimited public supportLimited public supportStrong public support2Profile →
Nightfall AIGrowth stageSupport found for 4 of 4 requirementsStrong public supportLimited public supportLimited public supportStrong public support2Profile →
ZenityGrowth stageSupport found for 4 of 4 requirementsStrong public supportLimited public supportLimited public supportStrong public support3Profile →
Akamai API SecurityEstablishedSupport found for 3 of 4 requirementsLimited public supportNo supporting claim foundStrong public supportStrong public support2Profile →
MindgardEmergingSupport found for 3 of 4 requirementsLimited public supportNo supporting claim foundStrong public supportStrong public support2Profile →
CyberhavenScaledSupport found for 4 of 4 requirementsLimited public supportLimited public supportLimited public supportStrong public support2Profile →
Okta for AI AgentsEstablishedSupport found for 4 of 4 requirementsLimited public supportStrong public supportLimited public supportLimited public support1Profile →
Salt Agentic Security PlatformScaledSupport found for 4 of 4 requirementsLimited public supportLimited public supportLimited public supportStrong public support2Profile →
Harmonic SecurityEmergingSupport found for 3 of 4 requirementsStrong public supportLimited public supportNo supporting claim foundLimited public support2Profile →
Upwind AI SecurityScaledSupport found for 3 of 4 requirementsLimited public supportNo supporting claim foundStrong public supportLimited public support2Profile →
KeycardGrowth stageSupport found for 2 of 4 requirementsStrong public supportLimited public supportNo supporting claim foundNo supporting claim found1Profile →

Company maturity remains a filter and profile attribute; it does not affect the research-coverage order.