ASAI Security ResearchIndependent public-source research
Public reviewread only

Solution approach

AI governance, risk, and compliance

Inventory AI systems, assign owners, manage policies and risk reviews, track exceptions, and retain audit evidence.

Research scopeVendorsPublicly documented vendor profiles
Evaluation guideRequirementsSecurity requirements buyers can verify
Evidence basisSourcesPublic claims linked to their original sources
Unresolved itemsQuestionsMissing support is labeled instead of assumed
View research coverageThese counts describe available public research, not product quality or suitability.Expand
Vendor profiles
19 shown in this view
Security requirements
4 to review
Strong public support
52 requirement records
Limited public support
14 requirement records
Open research
10 with no supporting claim · 0 incomplete

Evaluation guide

What buyers should verify

Foundational security requirement

AI governance, risk, and compliance

Inventory AI systems and owners, translate policy and regulatory obligations into governed workflows, assess risk, manage approvals and exceptions, and retain audit evidence across the AI lifecycle.

Questions to test
  1. A test AI system is registered with owner, intended use, risk tier, lifecycle state, and applicable obligations.
  2. A policy, assessment, approval, exception, or remediation workflow changes the governed state of the test system.
  3. The system produces dated, exportable evidence linking the decision, reviewer, policy, and affected AI system.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Foundational security requirement

Approved AI usage monitoring

Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.

Questions to test
  1. Approved AI workspace activity appears with user, workspace or tenant, model or provider, and timestamp.
  2. Prompt, model, or admin activity can be exported or correlated for the selected approved AI platform.
  3. Model or provider usage can be filtered for the scoped workspace, tenant, gateway, or platform.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Foundational security requirement

AI-feature discovery in business applications

Inventory software as a service (SaaS) applications that embed AI features, expose enterprise data to AI capabilities, or create AI-driven data movement.

Questions to test
  1. A software as a service (SaaS) app with an embedded AI feature appears in the software as a service (SaaS) AI inventory with app, provider, and feature context.
  2. The inventory shows which users, data classes, integrations, or providers are associated with the AI-enabled software as a service (SaaS) app.
  3. Third-party AI service use is flagged separately from generic software as a service (SaaS) application discovery.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Foundational security requirement

Action-taking agent monitoring

Observe and govern agent plans, memory, tool calls, delegated tasks, autonomy, runtime decisions, and outcomes.

Questions to test
  1. A test agent run captures plan, steps, tool calls, outcome, and timestamps.
  2. Agent memory, delegated task, autonomy, or runtime decision detail is visible in a timeline or log.
  3. Out-of-policy or unusual agent behavior can be flagged or filtered for investigation.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Vendor research

Vendors with public research for this approach

Choose vendors to compare →

Vendors are grouped by whether this approach is a core product focus or related coverage, then ordered by documented support across the requirements shown. This organizes public research coverage; it is not a product ranking or recommendation.

Evidence labelsStrong public supportLimited public supportNo supporting claim foundResearch incomplete
VendorAI governanceApproved AI activityBusiness-app AI inventoryAgent runtime telemetrySourcesAction
Core product focusThis approach is central to how these vendors present the product · 9 vendors
Holistic AIEmergingSupport found for 4 of 4 requirementsStrong public supportStrong public supportStrong public supportStrong public support1Profile →
BigID AI Security and GovernanceScaledSupport found for 4 of 4 requirementsStrong public supportStrong public supportLimited public supportStrong public support2Profile →
Credo AIGrowth stageSupport found for 4 of 4 requirementsStrong public supportStrong public supportLimited public supportStrong public support1Profile →
Singulr AIEmergingSupport found for 4 of 4 requirementsStrong public supportLimited public supportStrong public supportStrong public support4Profile →
Veeam / Securiti AIEstablishedSupport found for 4 of 4 requirementsStrong public supportStrong public supportStrong public supportLimited public support2Profile →
WitnessAIGrowth stageSupport found for 4 of 4 requirementsStrong public supportLimited public supportStrong public supportStrong public support2Profile →
Iterate.ai AgentWatchEmergingSupport found for 3 of 4 requirementsStrong public supportStrong public supportNo supporting claim foundStrong public support2Profile →
LatticeFlow AIEmergingSupport found for 3 of 4 requirementsStrong public supportLimited public supportNo supporting claim foundStrong public support1Profile →
ModelOpEmergingSupport found for 3 of 4 requirementsStrong public supportStrong public supportNo supporting claim foundLimited public support1Profile →
Related coverageThese vendors address the requirements through another core product focus · 10 vendors
Obsidian AI SecurityGrowth stageSupport found for 4 of 4 requirementsStrong public supportStrong public supportStrong public supportStrong public support2Profile →
CyberArk Secure AI AgentsEstablishedSupport found for 4 of 4 requirementsStrong public supportStrong public supportLimited public supportStrong public support1Profile →
MindgardEmergingSupport found for 4 of 4 requirementsStrong public supportStrong public supportLimited public supportStrong public support3Profile →
AktoEmergingSupport found for 3 of 4 requirementsStrong public supportStrong public supportNo supporting claim foundStrong public support2Profile →
Backslash Agentic AI Endpoint SecurityEmergingSupport found for 3 of 4 requirementsStrong public supportStrong public supportNo supporting claim foundStrong public support1Profile →
Okta for AI AgentsEstablishedSupport found for 3 of 4 requirementsStrong public supportStrong public supportNo supporting claim foundStrong public support1Profile →
Microsoft Purview DSPM for AIEstablishedSupport found for 4 of 4 requirementsLimited public supportStrong public supportStrong public supportLimited public support2Profile →
Enkrypt AIEmergingSupport found for 3 of 4 requirementsStrong public supportLimited public supportNo supporting claim foundStrong public support4Profile →
Orca AI-SPMScaledSupport found for 2 of 4 requirementsStrong public supportStrong public supportNo supporting claim foundNo supporting claim found2Profile →
Snyk EvoScaledSupport found for 3 of 4 requirementsLimited public supportLimited public supportNo supporting claim foundStrong public support1Profile →

Company maturity remains a filter and profile attribute; it does not affect the research-coverage order.