ASAI Security ResearchIndependent public-source research
Public reviewread only

Solution approach

AI asset and configuration security

Find AI assets and review security settings, identities, exposed data, cloud configuration, and vulnerabilities.

Research scopeVendorsPublicly documented vendor profiles
Evaluation guideRequirementsSecurity requirements buyers can verify
Evidence basisSourcesPublic claims linked to their original sources
Unresolved itemsQuestionsMissing support is labeled instead of assumed
View research coverageThese counts describe available public research, not product quality or suitability.Expand
Vendor profiles
39 shown in this view
Security requirements
5 to review
Strong public support
119 requirement records
Limited public support
54 requirement records
Open research
22 with no supporting claim · 0 incomplete

Evaluation guide

What buyers should verify

Foundational security requirement

Approved AI usage monitoring

Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.

Questions to test
  1. Approved AI workspace activity appears with user, workspace or tenant, model or provider, and timestamp.
  2. Prompt, model, or admin activity can be exported or correlated for the selected approved AI platform.
  3. Model or provider usage can be filtered for the scoped workspace, tenant, gateway, or platform.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Foundational security requirement

Unapproved AI use discovery

Discover and monitor workforce AI tools, accounts, prompts, domains, models, users, and usage outside approved controls.

Questions to test
  1. An unmanaged AI app used by a test user appears in discovery inventory with user, app or domain, and timestamp.
  2. The test user's AI usage activity can be filtered or exported with AI-specific context.
  3. Approved and unapproved AI destinations or accounts are distinguishable in the evidence record.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Foundational security requirement

Action-taking agent monitoring

Observe and govern agent plans, memory, tool calls, delegated tasks, autonomy, runtime decisions, and outcomes.

Questions to test
  1. A test agent run captures plan, steps, tool calls, outcome, and timestamps.
  2. Agent memory, delegated task, autonomy, or runtime decision detail is visible in a timeline or log.
  3. Out-of-policy or unusual agent behavior can be flagged or filtered for investigation.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Foundational security requirement

AI model and supply-chain security

Discover, inventory, scan, validate, and monitor models, datasets, model artifacts, registries, dependencies, and AI development assets for tampering, unsafe serialization, provenance gaps, or malicious content.

Questions to test
  1. A test model or AI artifact appears in inventory with origin, version, hash or provenance, and deployment context.
  2. A malicious, tampered, unsafe, or policy-violating artifact produces a finding before deployment.
  3. The finding links the artifact to its registry, pipeline, owner, affected workload, and remediation action.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Additional security requirement

Generative AI application security

Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.

Questions to test
  1. A test large language model (LLM) application event records prompt, application programming interface (API), model, retrieval, or tool interaction context.
  2. A prompt-injection or unsafe-output test is detected, blocked, or flagged by the guardrail or large language model (LLM) firewall.
  3. The evidence links the event to an application, endpoint, request identifier, or workflow.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Vendor research

Vendors with public research for this approach

Choose vendors to compare →

Vendors are grouped by whether this approach is a core product focus or related coverage, then ordered by documented support across the requirements shown. This organizes public research coverage; it is not a product ranking or recommendation.

Evidence labelsStrong public supportLimited public supportNo supporting claim foundResearch incomplete
VendorApproved AI activityUnmanaged AIAgent runtime telemetryModel supply chainGenerative AI app securitySourcesAction
Core product focusThis approach is central to how these vendors present the product · 14 vendors
BigID AI Security and GovernanceScaledSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportLimited public supportStrong public support2Profile →
KnosticEmergingSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportStrong public supportLimited public support3Profile →
Upwind AI SecurityScaledSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportLimited public supportStrong public support1Profile →
Apex Security / TenableEstablishedSupport found for 5 of 5 requirementsStrong public supportStrong public supportLimited public supportLimited public supportStrong public support2Profile →
CrowdStrike AI SecurityEstablishedSupport found for 5 of 5 requirementsLimited public supportStrong public supportStrong public supportLimited public supportStrong public support3Profile →
JetStream SecurityGrowth stageSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportLimited public supportLimited public support3Profile →
Singulr AIEmergingSupport found for 5 of 5 requirementsLimited public supportStrong public supportStrong public supportLimited public supportStrong public support4Profile →
Varonis AI SecurityEstablishedSupport found for 5 of 5 requirementsStrong public supportStrong public supportLimited public supportLimited public supportStrong public support3Profile →
HiddenLayerGrowth stageSupport found for 4 of 5 requirementsLimited public supportNo supporting claim foundStrong public supportStrong public supportStrong public support4Profile →
Orca AI-SPMScaledSupport found for 4 of 5 requirementsStrong public supportStrong public supportNo supporting claim foundStrong public supportLimited public support1Profile →
Wiz AI-SPM / Google CloudEstablishedSupport found for 4 of 5 requirementsLimited public supportNo supporting claim foundStrong public supportStrong public supportStrong public support2Profile →
Snyk EvoScaledSupport found for 4 of 5 requirementsLimited public supportNo supporting claim foundStrong public supportStrong public supportLimited public support1Profile →
Veeam / Securiti AIEstablishedSupport found for 4 of 5 requirementsStrong public supportStrong public supportLimited public supportNo supporting claim foundLimited public support2Profile →
LatticeFlow AIEmergingSupport found for 3 of 5 requirementsLimited public supportNo supporting claim foundStrong public supportNo supporting claim foundStrong public support1Profile →
Related coverageThese vendors address the requirements through another core product focus · 25 vendors
AurascapeGrowth stageSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportStrong public supportStrong public support2Profile →
Backslash Agentic AI Endpoint SecurityEmergingSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportStrong public supportStrong public support2Profile →
Palo Alto Networks Prisma AIRSEstablishedSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportStrong public supportStrong public support2Profile →
AktoEmergingSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportLimited public supportStrong public support3Profile →
Cloudflare AI Security SuiteEstablishedSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportLimited public supportStrong public support1Profile →
Holistic AIEmergingSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportLimited public supportStrong public support1Profile →
MindgardEmergingSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportLimited public supportStrong public support4Profile →
Obsidian AI SecurityGrowth stageSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportLimited public supportStrong public support3Profile →
Proofpoint AI Security / AcuvityEstablishedSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportLimited public supportStrong public support2Profile →
Noma SecurityScaledSupport found for 4 of 5 requirementsNo supporting claim foundStrong public supportStrong public supportStrong public supportStrong public support3Profile →
Credo AIGrowth stageSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportLimited public supportLimited public support2Profile →
CyberhavenScaledSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportLimited public supportLimited public support2Profile →
Iterate.ai AgentWatchEmergingSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportLimited public supportLimited public support1Profile →
Okta for AI AgentsEstablishedSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportLimited public supportLimited public support1Profile →
ZenityGrowth stageSupport found for 5 of 5 requirementsStrong public supportStrong public supportStrong public supportLimited public supportLimited public support2Profile →
CyberArk Secure AI AgentsEstablishedSupport found for 4 of 5 requirementsStrong public supportStrong public supportStrong public supportNo supporting claim foundLimited public support1Profile →
F5 AI Security PlatformEstablishedSupport found for 4 of 5 requirementsLimited public supportStrong public supportStrong public supportNo supporting claim foundStrong public support2Profile →
RecoGrowth stageSupport found for 4 of 5 requirementsStrong public supportStrong public supportStrong public supportLimited public supportNo supporting claim found3Profile →
Enkrypt AIEmergingSupport found for 5 of 5 requirementsLimited public supportLimited public supportStrong public supportLimited public supportStrong public support3Profile →
Microsoft Purview DSPM for AIEstablishedSupport found for 4 of 5 requirementsStrong public supportStrong public supportLimited public supportNo supporting claim foundLimited public support2Profile →
Wallarm AI Control PlatformGrowth stageSupport found for 4 of 5 requirementsLimited public supportNo supporting claim foundStrong public supportLimited public supportStrong public support2Profile →
Onyx AIEmergingSupport found for 4 of 5 requirementsStrong public supportLimited public supportLimited public supportNo supporting claim foundLimited public support2Profile →
Pangea / CrowdStrike Falcon AIDREstablishedSupport found for 3 of 5 requirementsLimited public supportNo supporting claim foundLimited public supportNo supporting claim foundStrong public support5Profile →
Harness AI Security / TraceableEstablishedSupport found for 2 of 5 requirementsLimited public supportNo supporting claim foundNo supporting claim foundNo supporting claim foundStrong public support1Profile →
ModelOpEmergingSupport found for 2 of 5 requirementsStrong public supportNo supporting claim foundLimited public supportNo supporting claim foundNo supporting claim found1Profile →

Company maturity remains a filter and profile attribute; it does not affect the research-coverage order.