ASAI Security ResearchIndependent public-source research
Public reviewread only

Public-source research

Vendor evidence

Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.

Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6

Showing 41–60 of 67 evidence records

Clear all filters
AurascapeAI coding-agent and workstation securitySource checkedStrong public support for this requirement

Aurascape claims local discovery for Claude Code and Cursor, source-code and unsafe-code protections, predeployment code-path testing, Model Context Protocol (MCP) registry and signing, tool-call enforcement, and data-lineage controls from first code through runtime.

Secure every agent from first line of code through production runtime.
Varonis AI SecurityAI coding-agent and workstation securitySource checkedLimited public support for this requirement

Varonis Atlas claims discovery across code repositories and agentic frameworks plus development-time policy, sensitive-data context, dependency risk, Model Context Protocol (MCP) and tool-chain inspection, and runtime guardrails for code-connected agents.

Policy violations during development.
Operant AIAI coding-agent and workstation securitySource checkedStrong public support for this requirement

Operant claims device-layer controls for Claude Code, Cursor, Copilot, Cline, Windsurf, Aider, and custom agents, covering shell commands, files, repositories, credentials, packages, plugins, skills, prompts, Model Context Protocol (MCP) tools, application programming interfaces (APIs), and proprietary code.

Real-time shell command monitoring distinguishes legitimate developer tooling from injection-driven attacks — and blocks before execution.
Apex Security / TenableAI coding-agent and workstation securitySource checkedLimited public support for this requirement

Tenable claims discovery and risk analysis for AI tools on endpoints, developer libraries, packages, browser extensions, agents, code repositories, model repositories, build environments, and unsafe third-party integrations.

Continuously discover and monitor all AI usage across your organization, including shadow AI, agents, browser plug-ins, and more.
KnosticAI coding-agent and workstation securitySource checkedStrong public support for this requirement

Knostic claims endpoint guardrails plus AgentMesh scanning for coding assistants, Claude and Cursor skills, Model Context Protocol (MCP) servers, integrated development environment (IDE) extensions, plugins, commands, code injection, cryptomining, reverse shells, and other agentic supply-chain threats.

Scan skills, MCP servers, and extensions before they touch your agents.
Onyx AIAI coding-agent and workstation securityNo supporting claim found

Onyx AI materials reviewed did not establish governance of coding-agent commands, developer-workstation files or networks, integrated development environment (IDE) extensions, skills, hooks, secrets, or package actions.

No quoted source text is recorded for this claim.
AIM Security / Cato NetworksAI coding-agent and workstation securitySource checkedStrong public support for this requirement

Cato claims endpoint discovery and runtime control for Cursor, Claude Code, and other coding agents, covering configurations, licenses, Model Context Protocol (MCP) servers, prompts, model outputs, tool calls, tool messages, credentials, PII, and malicious tool responses.

Discover and secure AI agents that run on user endpoints, such as coding agents.
JetStream SecurityAI coding-agent and workstation securitySource checkedLimited public support for this requirement

JetStream claims endpoint scanning for AI applications, Model Context Protocol (MCP) servers, cleartext keys, configuration artifacts, coding-assistant toolchains, permissions, and runtime actions with identity attribution and approved-design enforcement.

The scanner looks throughout user directories to identify AI apps, MCP servers, cleartext API and license keys, and other AI artifacts.
Singulr AIAI coding-agent and workstation securitySource checkedLimited public support for this requirement

Singulr claims browser and endpoint enforcement, agent discovery, Model Context Protocol (MCP) server vulnerability scanning, tool and permission mapping, data-loss prevention, CI/CD red teaming, and runtime controls across agentic execution paths.

Browser and Endpoint Enforcement with Agent Permission Boundaries.
Grip SecurityAI coding-agent and workstation securitySource checkedLimited public support for this requirement

Grip claims visibility into Claude desktop, browser, agents, Model Context Protocol (MCP) servers, prompts, application programming interface (API) keys, connected tools, and developer workflows that generate code and automate tasks.

Visibility into desktop installations, browser based activity, connected MCP servers, AI agents, administrative API keys, and other non human identities.
RecoAI coding-agent and workstation securitySource checkedLimited public support for this requirement

Reco claims discovery of coding agents and their Model Context Protocol (MCP), software as a service (SaaS), repository, OAuth, permission, identity, and data relationships, including Cursor connections to GitHub and other enterprise applications.

An MCP server created a connection between Slack and Cursor, producing a permissions breakdown where two applications share a trust relationship.
ZenityAI coding-agent and workstation securitySource checkedStrong public support for this requirement

Zenity claims lifecycle visibility, posture evaluation, and runtime enforcement for Claude Code and device-based coding agents across code changes, commits, pull requests, configurations, Model Context Protocol (MCP) servers, skills, plugins, commands, credentials, files, tools, and memory.

Zenity's agent security platform deliver[s] full-lifecycle visibility, posture management, and runtime enforcement across Claude Code, Cowork, and Chat.
Token SecurityAI coding-agent and workstation securitySource checkedLimited public support for this requirement

Token Security claims discovery and governance of coding agents, custom GPTs, Model Context Protocol (MCP) servers, cloud and software as a service (SaaS) access, credentials, permissions, owners, intent, activity, and least-privilege boundaries.

Token automatically discovers and inventories every AI agent, custom GPT, coding agent, MCP server, and non-human identity.
Iterate.ai AgentWatchAI coding-agent and workstation securitySource checkedStrong public support for this requirement

Iterate.ai claims a private coding-agent environment with code privacy, security review, activity audit, human approval for file changes, Git checkpoints, diff review, repository indexing, Semgrep and Trivy scanning, dependency management, and Model Context Protocol (MCP) server controls.

The platform prevents proprietary source code exposure, provides governance for AI-generated code, tracks all AI development activity for audit purposes, and enables security teams to review generated code before deployment.
Credo AIAI coding-agent and workstation securityNo supporting claim found

Credo AI materials reviewed did not provide a public claim for controlling coding-agent commands, filesystem or network actions, skills, hooks, integrated development environment (IDE) extensions, packages, or workstation activity.

No quoted source text is recorded for this claim.
Holistic AIAI coding-agent and workstation securityNo supporting claim found

Holistic AI materials reviewed did not provide a public claim for controlling coding-agent commands, filesystem or network actions, skills, hooks, integrated development environment (IDE) extensions, packages, or workstation activity.

No quoted source text is recorded for this claim.
MindgardAI coding-agent and workstation securityNo supporting claim found

Mindgard materials reviewed did not provide a public claim for enforcing coding-agent commands, filesystem or network actions, skills, hooks, extensions, packages, or workstation activity.

No quoted source text is recorded for this claim.
Enkrypt AIAI coding-agent and workstation securitySource checkedLimited public support for this requirement

Enkrypt AI documents installing its Model Context Protocol (MCP) gateway for Cursor so connected tool actions can pass through policy enforcement.

secure-mcp-gateway install --client cursor
AktoAI coding-agent and workstation securitySource checkedStrong public support for this requirement

Akto claims discovery and endpoint guardrails for CLI coding assistants, agent skills, source code, ChatGPT, Claude, and Codex use.

CLI based coding assistant, MCP servers, agent skills
Okta for AI AgentsAI coding-agent and workstation securitySource checkedLimited public support for this requirement

Okta claims access management for code repositories and model registries used by developers.

managing access to the tools, code repositories, and model registries