Find and protect AI-related application programming interfaces (APIs), model endpoints, tool servers, and agent traffic.
Research scopeVendorsPublicly documented vendor profilesEvaluation guideRequirementsSecurity requirements buyers can verifyEvidence basisSourcesPublic claims linked to their original sourcesUnresolved itemsQuestionsMissing support is labeled instead of assumed
View research coverageThese counts describe available public research, not product quality or suitability.Expand
Vendor profiles
9 shown in this view
Security requirements
4 to review
Strong public support
27 requirement records
Limited public support
6 requirement records
Open research
3 with no supporting claim · 0 incomplete
Evaluation guide
What buyers should verify
Additional security requirement
Generative AI application security
Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.
Questions to test
A test large language model (LLM) application event records prompt, application programming interface (API), model, retrieval, or tool interaction context.
A prompt-injection or unsafe-output test is detected, blocked, or flagged by the guardrail or large language model (LLM) firewall.
The evidence links the event to an application, endpoint, request identifier, or workflow.
Foundational security requirement
AI gateway, tool-connection, and runtime controls
Mediate model, agent, tool, application programming interface (API), connector, and Model Context Protocol (MCP) traffic through an enforcement point that applies identity-aware policy, content controls, routing, rate limits, and auditable allow or deny decisions.
Questions to test
A model, agent, tool, or Model Context Protocol (MCP) request passes through a named policy enforcement point.
A test policy allows, blocks, transforms, redirects, or rate-limits the request with an explicit reason.
The audit event records caller identity, destination, tool or model, policy decision, and timestamp.
Foundational security requirement
Action-taking agent monitoring
Observe and govern agent plans, memory, tool calls, delegated tasks, autonomy, runtime decisions, and outcomes.
Questions to test
A test agent run captures plan, steps, tool calls, outcome, and timestamps.
Agent memory, delegated task, autonomy, or runtime decision detail is visible in a timeline or log.
Out-of-policy or unusual agent behavior can be flagged or filtered for investigation.
Foundational security requirement
Sensitive-data protection for generative AI
Detect, classify, redact, or block sensitive data in prompts, responses, files, retrieval, memory, and AI-connected workflows.
Questions to test
Sensitive prompt, response, or file test data is detected and classified during an AI interaction.
A policy redacts, blocks, coaches, or records the sensitive data event before it leaves the approved path.
The evidence record shows data class, user, app or model, action, and timestamp.
Vendors are grouped by whether this approach is a core product focus or related coverage, then ordered by documented support across the requirements shown. This organizes public research coverage; it is not a product ranking or recommendation.
Evidence labelsStrong public supportLimited public supportNo supporting claim foundResearch incomplete
VendorGenerative AI app securityAI gateway and tool controlsAgent runtime telemetryPrompt and data protectionSourcesAction
Core product focusThis approach is central to how these vendors present the product · 8 vendors
AktoEmergingSupport found for 4 of 4 requirementsStrong supportStrong public supportStrong supportStrong public supportStrong supportStrong public supportStrong supportStrong public support2Profile →
Cequence AI GatewayScaledSupport found for 4 of 4 requirementsStrong supportStrong public supportStrong supportStrong public supportStrong supportStrong public supportStrong supportStrong public support1Profile →
Kong AI GatewayScaledSupport found for 4 of 4 requirementsStrong supportStrong public supportStrong supportStrong public supportLimited supportLimited public supportStrong supportStrong public support2Profile →
Wallarm AI Control PlatformGrowth stageSupport found for 4 of 4 requirementsStrong supportStrong public supportStrong supportStrong public supportStrong supportStrong public supportLimited supportLimited public support2Profile →
Imperva AI Application SecurityEstablishedSupport found for 3 of 4 requirementsStrong supportStrong public supportStrong supportStrong public supportNo claim foundNo supporting claim foundStrong supportStrong public support1Profile →
Salt Agentic Security PlatformScaledSupport found for 4 of 4 requirementsLimited supportLimited public supportLimited supportLimited public supportStrong supportStrong public supportStrong supportStrong public support2Profile →
Akamai API SecurityEstablishedSupport found for 3 of 4 requirementsStrong supportStrong public supportLimited supportLimited public supportNo claim foundNo supporting claim foundStrong supportStrong public support2Profile →
Harness AI Security / TraceableEstablishedSupport found for 3 of 4 requirementsStrong supportStrong public supportLimited supportLimited public supportNo claim foundNo supporting claim foundStrong supportStrong public support1Profile →
Related coverageThese vendors address the requirements through another core product focus · 1 vendor
Cloudflare AI Security SuiteEstablishedSupport found for 4 of 4 requirementsStrong supportStrong public supportStrong supportStrong public supportStrong supportStrong public supportStrong supportStrong public support2Profile →
Company maturity remains a filter and profile attribute; it does not affect the research-coverage order.