Public-source research
Vendor evidence
Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.
Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6
Aurascape claims context-aware tool policy based on user identity, account type, agent intent, entitlement, data sensitivity, OAuth roles and scopes, and approved-call signatures.
Context-aware policy on identity, intent, entitlement, and data sensitivity.
Related framework references (5)
Varonis Atlas claims visibility into identities and intent interacting with AI, agent permissions and data access, policy verification for every action and Model Context Protocol (MCP) call, and continuous enforcement of least-privilege outcomes.
The identities and their intent interacting with AI systems.
Related framework references (5)
Operant claims AI non-human identity detection, agent identity and access control, fine-grained identity-aware Model Context Protocol (MCP) enforcement, least privilege, authorization validation, trust scores, and per-agent tool restrictions.
Detect and block unauthenticated and unauthorized AI agent behavior in real time.
Related framework references (5)
Tenable claims agent ownership and access inventory, identity and entitlement correlation, least-privilege remediation, risky permission detection, and agent isolation or access-level changes.
View agent owner, access level, tools, knowledge, and isolate the agent from the agent details panel.
Related framework references (5)
Knostic claims OAuth-based agent authentication, agent-role to privilege mapping, least-privilege and need-to-know boundaries, and policy enforcement across software as a service (SaaS), in-house, and Model Context Protocol (MCP) agents.
Map agent roles to privileges and enforce need-to-know boundaries.
Related framework references (5)
Onyx AI claims organization and group-based agent sharing plus configurable knowledge and action permissions for enterprise agents.
Publish your Agent to your entire organization or share it with specific users or groups.
Related framework references (5)
Cato AI Security claims visibility into agent configurations, licenses, data and tool access, plus corporate policy enforcement and blocking of unauthorized access or unsafe actions across managed and local agents.
Reduce the risk of unauthorized access, sensitive data exposure, and unsafe agent actions.
Related framework references (5)
JetStream claims an accountable identity fabric binding humans, agents, service accounts, and models with short-lived identity-scoped keys, ownership attribution, permission monitoring, and runtime enforcement.
Bind every AI action to an accountable identity using short-lived, identity-scoped keys.
Related framework references (5)
Singulr claims agent discovery, ownership and intent, topology and permission mapping, enforceable boundaries based on agent type, data sensitivity, tool access, and scope, plus runtime restriction of unauthorized system access.
Define enforceable policies based on agent type, data sensitivity, tool access, and scope.
Related framework references (5)
Grip claims discovery and posture analysis for AI agents as non-human identities, including permissions, authentication, OAuth grants, application programming interface (API) keys, service accounts, access scopes, machine identities, and connected applications.
Security teams need visibility into AI agents, permissions, OAuth grants, and machine identities operating across SaaS environments.
Related framework references (5)
Reco claims mapping of each AI agent to authorizing users, connected applications, OAuth grants, application programming interface (API) identities, permissions, data access, ownership, and policy status with least-privilege controls.
For each agent, Reco maps which SaaS applications it connects to, what permissions it holds, who authorized it, and what data it can access.
Related framework references (5)
Zenity claims ownership, identity relationship, permission, tool-access, and execution-path mapping with policy enforcement against over-privileged agents, unauthorized application programming interface (API) calls, restricted-data access, and privilege escalation.
Know which agents exist, who owns them, what they can access, and how they behave across your environment.
Related framework references (5)
Token Security claims discovery and lifecycle control for agent identities, owners, intent, credentials, tokens, roles, permissions, access paths, behavioral baselines, access reviews, least-privilege enforcement, remediation, and deprovisioning.
Token Security helps teams manage the full AI agent identity lifecycle.
Related framework references (5)
AgentWatch claims JWT authentication, role-based access control, organization and team hierarchies, encrypted application programming interface (API)-key management, user and device attribution, correlated request logs, and policy status across business and coding agents.
Built-In Enterprise Security: encrypted API keys at rest, JWT authentication and role-based access control, comprehensive audit logging for every operation.
Related framework references (5)
Credo AI claims agent cards containing purpose, tools, data sources, and guardrails, with ownership and accountability in the Agent Registry.
Agent Registry with agent cards (purpose, tools, data sources, guardrails)
Related framework references (5)
Holistic AI claims tracking of agent identity, reasoning chains, and tool calls with runtime access controls.
Track every agent's identity, reasoning chain, and tool calls
Related framework references (5)
Mindgard materials reviewed did not provide a public claim for agent registration, delegated authorization, short-lived credential issuance, or agent identity lifecycle controls.
No quoted source text is recorded for this claim.
Related framework references (5)
Enkrypt AI claims role- and tenant-aware rules using SSO, identity and access management (IAM), and identity claims to constrain tools, data sources, and actions.
Role/tenant-based rules
Related framework references (5)
Akto claims access governance by user, team, and tool plus actor-aware monitoring for agent and Model Context Protocol (MCP) actions.
AI access governance by user, team and tool
Related framework references (5)
Okta claims unique agent registration, human ownership, short-lived credentials, runtime policies, governance, audit, and retirement.
temporary, short-lived credentials
Related framework references (5)