ASAI Security ResearchIndependent public-source research
Public reviewread only

Public-source research

Vendor evidence

Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.

Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6

Showing 41–60 of 67 evidence records

Clear all filters
AurascapeAI model and supply-chain securitySource checkedStrong public support for this requirement

Aurascape claims discovery of agents and Model Context Protocol (MCP) servers, a vetted custom registry, tool-poisoning detection, approved-call signing, unsigned-call blocking, and project-configuration supply-chain protection.

Whitelist approved MCP servers and tools in a custom registry so only vetted endpoints are reachable.
Varonis AI SecurityAI model and supply-chain securitySource checkedLimited public support for this requirement

Varonis Atlas claims inventory and lineage for models, agents, tools, Model Context Protocol (MCP) servers, dependencies, infrastructure, and third-party AI plus risk analysis for vulnerable dependencies, tool poisoning, misconfiguration, and supply-chain use.

Atlas inventories agents, models, tools, MCP servers, dependencies, and supporting infrastructure.
Operant AIAI model and supply-chain securitySource checkedStrong public support for this requirement

Operant claims an enterprise Model Context Protocol (MCP) and skills registry, trust scoring, trust zones, artifact quarantine, component and relationship mapping, and blocking of untrusted servers, tools, skills, plugins, packages, and supply-chain behavior.

Map trust scores and enforce trust boundaries, ensuring only verified entities operate within your AI agent supply chain.
Apex Security / TenableAI model and supply-chain securitySource checkedLimited public support for this requirement

Tenable claims discovery and vulnerability analysis for AI software components, packages, browser extensions, model repositories, third-party tools, integrations, workloads, and dependencies across cloud and enterprise AI environments.

Detect AI-related packages in systems and web applications, along with browser extensions, associated vulnerabilities, data leakage and unauthorized resource consumption.
KnosticAI model and supply-chain securitySource checkedStrong public support for this requirement

Knostic AgentMesh claims continuous discovery, version tracking, SHA-256 artifact identification, static-code scanning, and risk analysis for AI agent skills, Model Context Protocol (MCP) servers, integrated development environment (IDE) extensions, Claude Code plugins, and commands.

Continuously discovers, tracks, and scans AI agent skills, MCP servers, and IDE extensions for prompt injection and supply chain threats.
Onyx AIAI model and supply-chain securityNo supporting claim found

Onyx AI materials reviewed did not establish model artifact scanning, provenance, signing, dependency or Model Context Protocol (MCP) component analysis, tamper detection, or model-registry release controls.

No quoted source text is recorded for this claim.
AIM Security / Cato NetworksAI model and supply-chain securitySource checkedLimited public support for this requirement

Cato and AIM claim continuous AI-SPM scanning of internal models, agent configurations, Model Context Protocol (MCP) connections, training environments, misconfigurations, and vulnerabilities before production.

Continuously discovers, detects, and remediates AI security and compliance risks before they reach production, and scans internal AI models for misconfigurations and vulnerabilities.
JetStream SecurityAI model and supply-chain securitySource checkedLimited public support for this requirement

JetStream claims visibility into model swaps, toolchain expansion, Model Context Protocol (MCP) servers, open-source components, configurations, credentials, permissions, connections, and runtime drift with Verified Model Context Protocol (MCP) and approved-design governance.

Surface model changes, new MCP usage, and behavioral deviations the moment they occur.
Singulr AIAI model and supply-chain securitySource checkedLimited public support for this requirement

Singulr claims dataset licensing validation, agent dependency topology, model and tool connection mapping, Model Context Protocol (MCP) configuration risk, Model Context Protocol (MCP) server vulnerability scanning, and continuous model and control drift monitoring.

MCP server vulnerability scanning.
Grip SecurityAI model and supply-chain securityNo supporting claim found

Grip AI and software as a service (SaaS) security materials reviewed did not establish model artifact scanning, provenance, signing, dependency or Model Context Protocol (MCP) component analysis, tamper detection, or model-registry release controls.

No quoted source text is recorded for this claim.
RecoAI model and supply-chain securitySource checkedLimited public support for this requirement

Reco claims discovery and mapping of Model Context Protocol (MCP) servers, tools, external integrations, OAuth grants, application programming interface (API) connections, data paths, scopes, and unauthorized trust relationships across AI agents and software as a service (SaaS) applications.

Reco makes them visible, showing exactly which systems are connected, what data flows between them, and where permission breakdowns exist.
ZenityAI model and supply-chain securitySource checkedLimited public support for this requirement

Zenity claims pre-session evaluation of Claude configurations, Model Context Protocol (MCP) servers, skills, plugins, and agent extensions plus dependency and attack-path mapping across agents, tools, knowledge, automations, triggers, and actions.

Zenity evaluates Claude configuration, MCP servers, skills, plugins, and other agent extensions before sessions begin.
Token SecurityAI model and supply-chain securityNo supporting claim found

Token Security product materials reviewed did not establish model artifact scanning, provenance, signing, dependency or Model Context Protocol (MCP) component analysis, tamper detection, or model-registry release controls.

No quoted source text is recorded for this claim.
Iterate.ai AgentWatchAI model and supply-chain securitySource checkedLimited public support for this requirement

Iterate.ai claims repository indexing and code analysis for Model Context Protocol (MCP)-connected workflows with optional Semgrep and Trivy security scanning, dependency management, and Model Context Protocol (MCP) server installation and configuration controls.

Integrated MCP server for repository indexing and code analysis (Tree-sitter), plus optional security scanning (Semgrep, Trivy).
Credo AIAI model and supply-chain securitySource checkedLimited public support for this requirement

Credo AI claims third-party model tracking, model and vendor lineage graphs, and model metadata in its agent governance inventory.

Model + vendor lineage graphs
Holistic AIAI model and supply-chain securitySource checkedLimited public support for this requirement

Holistic AI claims lineage and dependency mapping across data sources, models, application programming interfaces (APIs), pipelines, and AI outputs.

Full lineage tracking from data source to AI output
MindgardAI model and supply-chain securitySource checkedLimited public support for this requirement

Mindgard claims runtime model scanning for security vulnerabilities, safety risks, exploitable behaviors, and harmful outputs.

scans AI models for both security vulnerabilities and safety risks
Enkrypt AIAI model and supply-chain securitySource checkedLimited public support for this requirement

Enkrypt AI claims Model Context Protocol (MCP) scanner coverage for untrusted servers, tools, and poisoned tool catalogs as agentic supply-chain risk.

untrusted MCP servers/tools and poisoned tool catalogs are treated as supply-chain risk
Okta for AI AgentsAI model and supply-chain securitySource checkedLimited public support for this requirement

Okta claims access management for tools, code repositories, and model registries to reduce unauthorized access and tampering.

tools, code repositories, and model registries