Public-source research
Vendor evidence
Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.
Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6
Akamai application programming interface (API) Security materials reviewed did not provide a public claim for model and AI-artifact supply-chain inspection.
No quoted source text is recorded for this claim.
Related framework references (5)
Salt Security materials reviewed did not provide a public claim for model and AI-artifact supply-chain inspection.
No quoted source text is recorded for this claim.
Related framework references (5)
Imperva AI Application Security materials reviewed did not provide a public claim for model and AI-artifact supply-chain inspection.
No quoted source text is recorded for this claim.
Related framework references (5)
Kong AI Gateway materials reviewed did not provide a public claim for model and AI-artifact supply-chain inspection.
No quoted source text is recorded for this claim.
Related framework references (5)
Speakeasy AI Control Plane materials reviewed did not provide a public claim for model and AI-artifact supply-chain inspection.
No quoted source text is recorded for this claim.
Related framework references (5)
Harness AI Security materials reviewed did not provide a public claim for model and AI-artifact supply-chain inspection.
No quoted source text is recorded for this claim.
Related framework references (5)
Wallarm AI Hypervisor claims an AI software bill of materials for observed AI workloads.
AI software bill of materials (AI-SBOM)
Related framework references (5)
Cequence AI Gateway materials reviewed did not provide a public claim for model and AI-artifact supply-chain inspection.
No quoted source text is recorded for this claim.
Related framework references (5)
Upwind claims an AI bill of materials (AI-BOM) correlating code, cloud, model registries, agent systems, AI components, and runtime dependencies.
Correlation with runtime evidence to reveal real dependencies
Related framework references (5)
Proofpoint claims security-posture checks for services in the AI supply chain at the Model Context Protocol (MCP) boundary.
checks the security posture of every service in the AI supply chain
Related framework references (5)
Securiti AI materials reviewed did not provide a public claim for model and AI component supply-chain inspection.
No quoted source text is recorded for this claim.
Related framework references (5)
Snyk Evo claims discovery of models, agents, Model Context Protocol (MCP) servers, datasets, and plugins in repositories plus AI supply-chain security.
identifies models, agents, MCP servers, datasets, and plugins across your repositories
Related framework references (5)
ModelOp materials reviewed did not provide a public claim for model and AI component supply-chain inspection.
No quoted source text is recorded for this claim.
Related framework references (5)
LatticeFlow AI materials reviewed did not provide a public claim for model and AI component supply-chain inspection.
No quoted source text is recorded for this claim.
Related framework references (5)
Runlayer materials reviewed did not provide a public claim for model and AI component supply-chain inspection.
No quoted source text is recorded for this claim.
Related framework references (5)
Keycard materials reviewed did not provide a public claim for model and AI component supply-chain inspection.
No quoted source text is recorded for this claim.
Related framework references (5)
Palo Alto Networks claims predeployment model and agent-artifact scanning across models, source code, Model Context Protocol (MCP) servers, and skills.
Scan supply chain vulnerabilities in agent artifacts, including agent code, MCP servers, and skills.
Related framework references (5)
Cisco claims scanning of model files, repositories, datasets, Model Context Protocol (MCP) servers, and tools for malicious code, poisoning, backdoors, and compromised components before production.
Scan AI model files, repositories, and MCP servers for hidden risks before they are introduced into development or production.
Related framework references (5)
Microsoft Defender for Cloud claims preview scanning of registered Azure Machine Learning models for embedded malware, unsafe operators, and exposed secrets before production.
AI model scanning provides proactive detection of unsafe or malicious artifacts and continuously monitors models for risk throughout the AI lifecycle.
Related framework references (5)
CrowdStrike claims discovery of local models, Model Context Protocol (MCP) servers, integrated development environment (IDE) extensions, misconfigured AI tooling, vulnerabilities, and supply-chain risks on engineering endpoints before exploitation.
This helps security and engineering teams identify supply chain risks and misconfigured AI tooling before they become exploitable vulnerabilities.
Related framework references (5)