ASAI Security ResearchIndependent public-source research
Public reviewread only

Solution approach

Endpoint AI application controls

Discover and control desktop AI applications and local agents, including files, processes, commands, network activity, credentials, and tool connections.

Research scopeVendorsPublicly documented vendor profiles
Evaluation guideRequirementsSecurity requirements buyers can verify
Evidence basisSourcesPublic claims linked to their original sources
Unresolved itemsQuestionsMissing support is labeled instead of assumed
View research coverageThese counts describe available public research, not product quality or suitability.Expand
Vendor profiles
11 shown in this view
Security requirements
8 to review
Strong public support
73 requirement records
Limited public support
11 requirement records
Open research
4 with no supporting claim · 0 incomplete

Evaluation guide

What buyers should verify

Foundational security requirement

Unapproved AI use discovery

Discover and monitor workforce AI tools, accounts, prompts, domains, models, users, and usage outside approved controls.

Questions to test
  1. An unmanaged AI app used by a test user appears in discovery inventory with user, app or domain, and timestamp.
  2. The test user's AI usage activity can be filtered or exported with AI-specific context.
  3. Approved and unapproved AI destinations or accounts are distinguishable in the evidence record.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Foundational security requirement

Approved AI usage monitoring

Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.

Questions to test
  1. Approved AI workspace activity appears with user, workspace or tenant, model or provider, and timestamp.
  2. Prompt, model, or admin activity can be exported or correlated for the selected approved AI platform.
  3. Model or provider usage can be filtered for the scoped workspace, tenant, gateway, or platform.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Foundational security requirement

Controls for unapproved AI use

Block, coach, redirect, or contain non-approved AI use and policy-violating AI interactions.

Questions to test
  1. A policy blocks, coaches, redirects, or contains a test interaction with an unapproved AI destination.
  2. The control event records policy reason, user, destination, action, and timestamp.
  3. An allowlist or exception path changes the outcome for an approved AI destination.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Foundational security requirement

Sensitive-data protection for generative AI

Detect, classify, redact, or block sensitive data in prompts, responses, files, retrieval, memory, and AI-connected workflows.

Questions to test
  1. Sensitive prompt, response, or file test data is detected and classified during an AI interaction.
  2. A policy redacts, blocks, coaches, or records the sensitive data event before it leaves the approved path.
  3. The evidence record shows data class, user, app or model, action, and timestamp.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Additional security requirement

Browser and business-application controls

Apply session-level controls in browser and software as a service (SaaS) workflows, including uploads, downloads, copy/paste, sharing, and identity-aware access decisions.

Questions to test
  1. A session-level policy controls upload, download, copy, paste, sharing, or form submission in a browser or software as a service (SaaS) workflow.
  2. The policy decision includes user, app, session, or identity-aware context.
  3. The event record shows affected action, user, app, and timestamp.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Foundational security requirement

AI gateway, tool-connection, and runtime controls

Mediate model, agent, tool, application programming interface (API), connector, and Model Context Protocol (MCP) traffic through an enforcement point that applies identity-aware policy, content controls, routing, rate limits, and auditable allow or deny decisions.

Questions to test
  1. A model, agent, tool, or Model Context Protocol (MCP) request passes through a named policy enforcement point.
  2. A test policy allows, blocks, transforms, redirects, or rate-limits the request with an explicit reason.
  3. The audit event records caller identity, destination, tool or model, policy decision, and timestamp.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Foundational security requirement

Action-taking agent monitoring

Observe and govern agent plans, memory, tool calls, delegated tasks, autonomy, runtime decisions, and outcomes.

Questions to test
  1. A test agent run captures plan, steps, tool calls, outcome, and timestamps.
  2. Agent memory, delegated task, autonomy, or runtime decision detail is visible in a timeline or log.
  3. Out-of-policy or unusual agent behavior can be flagged or filtered for investigation.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Additional security requirement

AI coding-agent and workstation security

Discover and govern AI coding agents, integrated development environment (IDE) assistants, command-line agents, skills, hooks, extensions, Model Context Protocol (MCP) tools, filesystem access, commands, network activity, secrets, and software-supply-chain actions on developer workstations and build environments.

Questions to test
  1. A test coding agent and its skills, hooks, extensions, or Model Context Protocol (MCP) tools appear in an attributable inventory.
  2. A policy blocks or records a dangerous command, sensitive-file access, secret exposure, network action, or risky package installation.
  3. The evidence ties the action to developer, agent, repository or workspace, policy, and timestamp.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Vendor research

Vendors with public research for this approach

Choose vendors to compare →

Vendors are grouped by whether this approach is a core product focus or related coverage, then ordered by documented support across the requirements shown. This organizes public research coverage; it is not a product ranking or recommendation.

Evidence labelsStrong public supportLimited public supportNo supporting claim foundResearch incomplete
VendorUnmanaged AIApproved AI activityUnapproved AI controlPrompt and data protectionBrowser and app controlsAI gateway and tool controlsAgent runtime telemetryCoding-agent securitySourcesAction
Core product focusThis approach is central to how these vendors present the product · 3 vendors
Backslash Agentic AI Endpoint SecurityEmergingSupport found for 7 of 8 requirementsStrong public supportStrong public supportStrong public supportStrong public supportNo supporting claim foundStrong public supportStrong public supportStrong public support3Profile →
CrowdStrike AI SecurityEstablishedSupport found for 8 of 8 requirementsStrong public supportLimited public supportStrong public supportStrong public supportStrong public supportStrong public supportStrong public supportLimited public support4Profile →
Harmonic SecurityEmergingSupport found for 8 of 8 requirementsStrong public supportLimited public supportStrong public supportLimited public supportStrong public supportStrong public supportStrong public supportLimited public support4Profile →
Related coverageThese vendors address the requirements through another core product focus · 8 vendors
AktoEmergingSupport found for 8 of 8 requirementsStrong public supportStrong public supportStrong public supportStrong public supportLimited public supportStrong public supportStrong public supportStrong public support2Profile →
CyberhavenScaledSupport found for 8 of 8 requirementsStrong public supportStrong public supportStrong public supportStrong public supportStrong public supportLimited public supportStrong public supportStrong public support3Profile →
Prompt Security / SentinelOneEstablishedSupport found for 8 of 8 requirementsStrong public supportLimited public supportStrong public supportStrong public supportStrong public supportStrong public supportStrong public supportStrong public support4Profile →
ZenityGrowth stageSupport found for 8 of 8 requirementsStrong public supportStrong public supportLimited public supportStrong public supportStrong public supportStrong public supportStrong public supportStrong public support3Profile →
Zscaler AI SecurityEstablishedSupport found for 8 of 8 requirementsStrong public supportStrong public supportStrong public supportStrong public supportStrong public supportStrong public supportStrong public supportLimited public support3Profile →
Nightfall AIGrowth stageSupport found for 7 of 8 requirementsStrong public supportNo supporting claim foundStrong public supportStrong public supportStrong public supportStrong public supportStrong public supportStrong public support2Profile →
Proofpoint AI Security / AcuvityEstablishedSupport found for 7 of 8 requirementsStrong public supportStrong public supportStrong public supportStrong public supportStrong public supportStrong public supportStrong public supportNo supporting claim found2Profile →
Lakera / Check PointEstablishedSupport found for 7 of 8 requirementsStrong public supportLimited public supportStrong public supportStrong public supportStrong public supportStrong public supportStrong public supportNo supporting claim found4Profile →

Company maturity remains a filter and profile attribute; it does not affect the research-coverage order.