Public-source research
Vendor evidence
Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.
Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6
Cisco claims AI Access can enforce policies that limit sensitive data exposure and protect against external threats for third-party AI applications.
Enforce policies that limit sensitive data exposure and protect against external threats.
Related framework references (5)
Microsoft says Endpoint data loss prevention (DLP) policies can warn or block users from sharing sensitive information with third-party generative AI sites accessed through a browser.
warn or block users from sharing sensitive information with third-party generative AI sites that are accessed via a browser.
Related framework references (5)
JetStream claims Runtime Governance enforces operational and security guardrails and lets teams approve changes or stop runs when behavior varies from an approved Blueprint.
JetStream watches live AI activity and compares that to the approved design within each AI Blueprint. It enforces operational and security guardrails, records evidence, and flags drift from each workflow’s operational contract the moment behavior varies from the Blueprint. Teams can approve the change or stop the run—without losing auditability.
Related framework references (5)
Netskope claims it can enforce policies across generative AI use and provide access controls for enterprise AI adoption.
Gain complete visibility and enforce policies across your entire genAI footprint: personal to corporate, sanctioned to shadow.
Related framework references (5)
Singulr claims Runtime Control can enforce against unapproved AI services, redact PII and PHI before exposure, control prompt injection, and bound agent permissions.
Enforce against unapproved AI services, redact PII and PHI before exposure, control prompt injection, and bound agent permissions at the browser, the endpoint, and across agentic execution paths.
Related framework references (5)
SentinelOne Prompt Security claims granular, role-based controls for who can use AI, how, and with what data.
Set granular, role-based controls for who can use AI, how, and with what data.
Related framework references (5)
AIM Security (Cato) claims it enforces granular access controls, prevents data leakage, and limits AI misuse via policy enforcement.
enforce granular access controls, and detect unauthorized data exchange with public AI services in real-time.
Related framework references (5)
Oasis Security claims policy guardrails can approve or block agent actions and enforce least-privilege access at runtime.
blocking risky actions before they reach your data.
Related framework references (5)
Grip Security claims it can identify unapproved AI and risky apps and trigger workflows or notifications for risky behavior.
Identify unsanctioned AI and risky apps immediately
Related framework references (5)
WitnessAI claims it can enforce control of approved Model Context Protocol (MCP) servers and tools across agents, integrated development environments (IDEs), and agentic apps.
Enforce control of approved MCP servers and tools across every agent, IDE, and agentic app
Related framework references (5)
Lasso Security claims runtime policy enforcement through proxy, application programming interface (API), or AI gateway controls.
Enforce policies inline at the proxy, API, or AI Gateway layer with runtime protection that adapts as your application evolves.
Related framework references (5)
Harmonic claims teams can block risky AI actions in real time, warn employees with context, or log silently for review.
You can block in real time, warn the employee with context about why the action is risky, or log silently for security team review.
Related framework references (5)
Reco claims teams can sanction approved agents, block unauthorized ones, and enforce least-privilege policies across the enterprise ecosystem.
Sanction approved agents, block unauthorized ones, and enforce least-privilege policies across your enterprise ecosystem.
Related framework references (5)
Lakera claims security teams need policy by app, user, data type, and action for employee AI usage.
Security teams need policy by app, user, data type, and action — not blanket allow or block decisions.
Related framework references (5)
Zenity claims intent-based detection examines execution paths, including tool calls, memory access, data usage, and control flow, to identify malicious or unintended outcomes.
By examining the full execution path - including tool calls, memory access, data usage, and control flow - Zenity identifies malicious or unintended outcomes even when inputs look harmless. This intent-focused approach exposes attacks that prompt-based firewalls miss.
Related framework references (5)
Nightfall claims it automatically blocks secrets, credentials, PHI, PCI, and other confidential information through file uploads and clipboard actions.
Nightfall automatically blocks secrets, credentials, PHI, PCI, or other confidential information via file uploads or clipboard copy/paste actions.
Related framework references (5)
LayerX claims AI governance and control over user and agentic interactions across applications, browsers, and integrated development environments (IDEs).
LayerX provides AI governance and control over all user and agentic interactions, across any application, browser and IDE
Related framework references (5)
Astrix claims it identifies and remediates AI agents and NHIs with excessive privileges, vulnerable configurations, abnormal activity, and policy violations.
Identify and remediate AI agents and NHIs with excessive privileges, vulnerable configurations, abnormal activity, and policy violations.
Related framework references (5)
Entro claims it can enforce least-privilege access, right-size excessive access, detect unapproved deployments, and remediate risky agent/non-human identity (NHI) behavior.
Detect and fix unsanctioned agent deployments, rogue MCP servers, and other unwanted behaviors before they escalate.
Related framework references (5)
Token Security claims AI-agent access control, right-sizing, least privilege, intent-aware enforcement, and automated remediation.
Token applies intent-aware least-privilege to agents, ensuring they have only the permissions needed for their purpose, and only for the time required.
Related framework references (5)