ASAI Security ResearchIndependent public-source research
Public reviewread only

Public-source research

Vendor evidence

Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.

Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6

Showing 261–280 of 1280 evidence records

Runlayer · Security requirement

Non-human identity and service-account security

No supporting claim found
Research finding

Runlayer materials reviewed did not provide a public claim for non-human identity, service-account, secret, or workload credential lifecycle controls.

Runlayer · Security requirement

AI agent identity and permissions

Source checkedLimited public support for this requirement
What the vendor says

Runlayer claims identity-aware access policy and scoped permissions for users and agents.

Exact source quote
under which identity, budget, OAuth grant, and runtime conditions
Runlayer · Security requirement

AI coding-agent and workstation security

Source checkedLimited public support for this requirement
What the vendor says

Runlayer claims centralized controls for employees using Claude, Cursor, ChatGPT, Codex, internal agents, Model Context Protocol (MCP) servers, and existing AI clients.

Exact source quote
employees are adopting Claude, Cursor, ChatGPT, Codex, and internal agents
Keycard · Security requirement

Approved AI usage monitoring

Source checkedLimited public support for this requirement
What the vendor says

Keycard claims visibility and attribution for agent actions, tool calls, policy decisions, and data access.

Exact source quote
See every action your agents take. Know exactly who authorized it.
Keycard · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedStrong public support for this requirement
What the vendor says

Keycard claims authentication and task-scoped access controls for Model Context Protocol (MCP), CLI, application programming interface (API), and downstream services.

Exact source quote
Add auth to any agent surface - MCP, CLI, or API.
Keycard · Security requirement

Action-taking agent monitoring

Source checkedStrong public support for this requirement
What the vendor says

Keycard claims a real-time event stream of agent actions, tool calls, policy decisions, and attributed audit events.

Exact source quote
A real-time event stream of every agent action, tool call, and policy decision.
Keycard · Security requirement

Agent-to-agent communication security

Source checkedLimited public support for this requirement
What the vendor says

Keycard claims authentication for agent-to-agent delegation while preserving user identity.

Exact source quote
Announcing Keycard for Multi-Agent Apps
Keycard · Security requirement

Non-human identity and service-account security

Source checkedStrong public support for this requirement
What the vendor says

Keycard claims workload attestation and short-lived credentials that avoid long-lived secrets and over-permissioned service accounts.

Exact source quote
No long-lived secrets, no over-permissioned service accounts.
Keycard · Security requirement

AI agent identity and permissions

Source checkedStrong public support for this requirement
What the vendor says

Keycard claims composite user, device, agent, and task identity with runtime policy and task-scoped credentials.

Exact source quote
Identity = user + device + agent + task
Keycard · Security requirement

AI coding-agent and workstation security

Source checkedStrong public support for this requirement
What the vendor says

Keycard claims governance of coding-agent shell, script, Model Context Protocol (MCP), environment, credential, and audit paths.

Exact source quote
keycard run virtualizes .env and mcp.json so credentials never hit disk, and every execution path is audited.