Public-source research
Vendor evidence
Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.
Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6
Wiz claims an AI bill of materials covering models, frameworks, dependencies, and libraries, plus model artifact scanning, repository and pipeline visibility, and attack-path analysis for model and training-data risk.
Analyze the components powering AI systems including models, frameworks, dependencies, and libraries.
Related framework references (5)
Microsoft Purview materials reviewed did not provide a public product claim for model artifact scanning, provenance, signing, tamper analysis, dependency inventory, or registry release controls.
No quoted source text is recorded for this claim.
Related framework references (5)
Noma claims continuous scanning of agent supply chains across tool integrations, Model Context Protocol (MCP) servers, agent frameworks, third-party application programming interfaces (APIs), and model dependencies.
Continuous scanning of agent supply chains for vulnerabilities across toolset integrations, MCP server connections, agent frameworks, third-party APIs, and model dependencies.
Related framework references (5)
WitnessAI claims discovery of agents, Model Context Protocol (MCP) servers, tools, and downstream systems plus Model Context Protocol (MCP) Catalog scoring against OWASP and CVE risk classes before tools are approved.
Scores those tools against OWASP and CVE risk classes through a new MCP Catalog.
Related framework references (5)
Netskope claims an Model Context Protocol (MCP) Catalog and inventory spanning local, containerized, remote, and code-repository Model Context Protocol (MCP) servers with risk assessment and access controls.
An inventory of publicly available MCP servers (remote and code repositories).
Related framework references (5)
Zscaler claims AI BOM discovery of models, Model Context Protocol (MCP) servers, development tools, and data pipelines plus risk scoring, codebase scanning, and Model Context Protocol (MCP) capability exposure analysis.
AI BOM: Discover AI models, MCP servers, development tools, and data pipelines.
Related framework references (5)
Check Point AI Agent Security claims posture detection for unofficial, unknown, or vulnerable Model Context Protocol (MCP) servers, untrusted components, suspicious tool code, and likely-malicious tools.
Flags unofficial, unknown, and vulnerable MCP servers, untrusted components, and suspicious or likely-malicious tool code.
Related framework references (5)
Lasso claims an AI bill of materials (AI-BOM) spanning models, prompts, tools, Model Context Protocol (MCP) servers, frameworks, databases, services, guardrails, identity boundaries, and authorization policies, with continuous CI updates and supply-chain risk assessment.
Inventory every AI component, including models, MCP servers, delegated agents, databases, third-party tool connectors, identity boundaries, and authorization policies.
Related framework references (5)
Pangea AI Guard materials reviewed did not provide a public product claim for model artifact scanning, provenance, signing, dependency inventory, tamper analysis, or registry release controls.
No quoted source text is recorded for this claim.
Related framework references (5)
F5 AI Guardrails and AI Red Team materials reviewed did not establish model artifact scanning, provenance, signing, dependency inventory, tamper analysis, or model-registry release controls.
No quoted source text is recorded for this claim.
Related framework references (5)
Oasis claims security-posture and credential-exposure evaluation for AI providers, Model Context Protocol (MCP) servers, third-party agents, scripts, and tools before access, including allowlisting and onboarding of vetted Model Context Protocol (MCP) components.
Organizations evaluate AI providers, MCP servers, and third-party agents for security posture, data handling, and credential exposure before granting access.
Related framework references (5)
Astrix Agent Control Plane materials reviewed did not establish model artifact scanning, provenance, signing, dependency analysis, Model Context Protocol (MCP) component vetting, tamper detection, or model-registry release controls.
No quoted source text is recorded for this claim.
Related framework references (5)
Entro agent and non-human identity (NHI) security materials reviewed did not establish model artifact scanning, provenance, signing, model dependency analysis, tamper detection, or model-registry release controls.
No quoted source text is recorded for this claim.
Related framework references (5)
Aembit identity and access management (IAM) for Agentic AI materials reviewed did not establish model artifact scanning, provenance, signing, dependency or Model Context Protocol (MCP) component analysis, tamper detection, or model-registry release controls.
No quoted source text is recorded for this claim.
Related framework references (5)
Prompt Security claims dynamic risk scoring of more than 13,000 Model Context Protocol (MCP) servers, vulnerability profiles, certification checks, shadow-server discovery, and agent skill integrity and drift checks.
MCP risk scoring, dynamically assessing over 13,000 MCP servers on GitHub to identify emerging threats.
Related framework references (5)
Harmonic platform materials reviewed did not establish model artifact scanning, provenance, signing, dependency analysis, Model Context Protocol (MCP) component risk scoring, tamper detection, or model-registry release controls.
No quoted source text is recorded for this claim.
Related framework references (5)
Cyberhaven claims continuous inventory of agents, local models, plugins, Model Context Protocol (MCP) servers, and tools plus AI Risk IQ scoring that includes model integrity and tracks component and version changes through endpoint and data lineage context.
Cyberhaven assigns an AI Risk IQ score across five dimensions: data sensitivity, model integrity, compliance adherence, user access, and security infrastructure.
Related framework references (5)
Nightfall claims a registry of more than 20,000 Model Context Protocol (MCP) servers, real-time configuration scanning, version-change monitoring, tool-capability analysis, dependency drift detection, and automatic quarantine of malicious updates before rollout.
Continuous scanning flags new capabilities and auto-quarantines the update for review before rollout.
Related framework references (5)
Island AI Services materials reviewed did not establish model artifact scanning, provenance, signing, dependency or Model Context Protocol (MCP) component analysis, tamper detection, or model-registry release controls.
No quoted source text is recorded for this claim.
Related framework references (5)
LayerX Interaction Security materials reviewed did not establish model artifact scanning, provenance, signing, dependency or Model Context Protocol (MCP) component analysis, tamper detection, or model-registry release controls.
No quoted source text is recorded for this claim.
Related framework references (5)