ASAI Security ResearchIndependent public-source research
Public reviewread only

Public-source research

Vendor evidence

Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.

Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6

Showing 21–40 of 67 evidence records

Clear all filters
Wiz AI-SPM / Google CloudAI agent identity and permissionsSource checkedLimited public support for this requirement

Wiz claims agent inventory and contextual mapping of agents to identities, workloads, data, access, capabilities, owners, and blast radius, with CIEM and secure-baseline checks.

Contextual Correlation: maps agents to the identities, workloads, and data they touch.
Microsoft Purview DSPM for AIAI agent identity and permissionsSource checkedLimited public support for this requirement

Microsoft Purview claims dedicated visibility and data-security or compliance coverage for supported agents, including Entra-registered and Foundry agents, while inheriting protections from the parent AI application.

AI agents have the same security and compliance protections for AI interactions as their parent AI app.
Noma SecurityAI agent identity and permissionsSource checkedStrong public support for this requirement

Noma claims a distinct attributable identity for each autonomous agent, owner and permission context, and policy-based authorization for agents, Model Context Protocol (MCP) servers, and tools.

Noma Agent Access Control gives each autonomous agent a distinct, attributable identity when it connects to MCP servers and tools.
WitnessAIAI agent identity and permissionsSource checkedLimited public support for this requirement

WitnessAI claims role and team-based AI access, human attribution for agent activity, and organization-wide authorization policies for agent access to approved Model Context Protocol (MCP) servers and tools.

Attribute AI agent activity to human identities.
Netskope AI SecurityAI agent identity and permissionsSource checkedLimited public support for this requirement

Netskope claims policy-based access control for autonomous non-human Model Context Protocol (MCP) interactions and visibility across Model Context Protocol (MCP) clients, servers, tools, resources, and prompt requests.

Scale your autonomous AI, and secure autonomous, non-human interactions, with unified visibility and control of public MCP servers.
Zscaler AI SecurityAI agent identity and permissionsSource checkedLimited public support for this requirement

Zscaler claims an AI Access Graph that maps AI-agent use of data and identities and enables fine-grained access policies for enterprise agents across Model Context Protocol (MCP) and agent-to-agent (A2A) communications.

Get real-time visibility into how AI agents use data and identities, reducing unnecessary access.
Lakera / Check PointAI agent identity and permissionsSource checkedLimited public support for this requirement

Check Point AI Agent Security claims tool allow or deny controls and posture findings for missing authentication, static credentials, and execution under an author’s credentials.

Tool Allow/Deny List limits available actions.
Lasso SecurityAI agent identity and permissionsSource checkedLimited public support for this requirement

Lasso claims inventory of identity boundaries and authorization policies, ownership context, role-based permissions, and risk-scored governance of agent access to Model Context Protocol (MCP) servers, application programming interfaces (APIs), and tools.

Inventory every AI component, including identity boundaries and authorization policies.
Pangea / CrowdStrike Falcon AIDRAI agent identity and permissionsNo supporting claim found

Pangea AI Guard materials reviewed did not establish agent identity registration, distinct agent credentials, delegated authorization, ownership, rotation, revocation, or agent access-review lifecycle.

No quoted source text is recorded for this claim.
F5 AI Security PlatformAI agent identity and permissionsSource checkedLimited public support for this requirement

F5 claims policy-based access controls for administrator-defined users and groups plus rate limits and dynamic guardrails around agent interactions with systems, data, and users.

Policy-based access controls restrict model accessibility to admin-identified individuals and groups.
Oasis SecurityAI agent identity and permissionsSource checkedStrong public support for this requirement

Oasis claims agent lifecycle governance, accountable ownership, just-in-time ephemeral identities, deterministic intent-aware authorization, precise scopes, session expiry, continuous oversight, and end-to-end attribution.

Granted via just-in-time, ephemeral identities.
Astrix Security / CiscoAI agent identity and permissionsSource checkedStrong public support for this requirement

Astrix claims secure agent provisioning with ownership, automated attestation, precisely scoped least privilege, short-lived credentials, just-in-time access, pre-approved policy, and per-agent audit trails.

Provision secure-by-design AI agents with short-lived credentials, just-in-time, precisely scoped access, and policy at creation.
Entro SecurityAI agent identity and permissionsSource checkedStrong public support for this requirement

Entro claims automated agent and non-human identity (NHI) provisioning, accountable ownership, minimum permissions, approval routing, just-in-time access, time bounds, continuous policy, access change, and offboarding.

Entro extends IGA to every AI agent and NHI in your environment.
AembitAI agent identity and permissionsSource checkedStrong public support for this requirement

Aembit claims cryptographically verified blended agent and user identity, OAuth 2.1 authorization, secure token exchange, ephemeral just-in-time credentials, least privilege, immediate revocation, and full access attribution.

Aembit IAM for Agentic AI assigns each agent a cryptographically verified identity, issues ephemeral credentials, enforces policy at runtime.
Prompt Security / SentinelOneAI agent identity and permissionsSource checkedLimited public support for this requirement

Prompt Security claims granular policy by user, group, server, and action plus attribution of AI use, data sharing, agent responses, and Model Context Protocol (MCP) activity.

Allow/block by user, server, or action according to your security policy.
Harmonic SecurityAI agent identity and permissionsSource checkedLimited public support for this requirement

Harmonic claims a common policy plane for agents and humans with contextual, team-based controls over agent tool and server actions.

Agents and humans on the same policy plane.
CyberhavenAI agent identity and permissionsSource checkedLimited public support for this requirement

Cyberhaven claims user and device attribution, user-access risk scoring, agent activity chain of custody, and visibility into agents operating with user permissions.

Security teams can see which files were accessed, how data moved, and whether sensitive content traveled to an unexpected destination.
Nightfall AIAI agent identity and permissionsSource checkedLimited public support for this requirement

Nightfall claims employee and device attribution, agent-to-system access mapping, allowlisted Model Context Protocol (MCP) servers, granular tool authorization, and blocking of unapproved tools and connections.

Map which employees use which agents, what systems they access, and track usage patterns over time.
Island Enterprise BrowserAI agent identity and permissionsSource checkedLimited public support for this requirement

Island claims governed agents with defined workflows, scoped permissions, enterprise identity and policy inheritance, human-in-the-loop controls, and complete auditability.

Build, run, and share AI agents with full oversight, scoped permissions, and complete auditability.
LayerX SecurityAI agent identity and permissionsSource checkedLimited public support for this requirement

LayerX claims contextual correlation of users, agents, identities, applications, and data with granular policy based on identity, data sensitivity, and risk.

Correlate prompts, actions, identities, applications, and data exchanges into a single security context.