ASAI Security ResearchIndependent public-source research
Public reviewread only

Public-source research

Vendor evidence

Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.

Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6

Showing 301–320 of 1280 evidence records

Microsoft native AI security beyond Purview DSPM · Security requirement

Approved AI usage monitoring

Source checkedStrong public support for this requirement
What the vendor says

Microsoft claims Foundry Control Plane provides visibility, governance, and control for AI agents, models, and tools across a Foundry enterprise.

Exact source quote
provides visibility, governance, and control for AI agents, models, and tools across your Foundry enterprise.
Microsoft native AI security beyond Purview DSPM · Security requirement

Controls for unapproved AI use

No supporting claim found
Research finding

Microsoft Foundry and Agent ID native-control materials reviewed did not provide a public claim for blocking arbitrary unapproved employee AI app use.

Microsoft native AI security beyond Purview DSPM · Security requirement

Sensitive-data protection for generative AI

Source checkedStrong public support for this requirement
What the vendor says

Microsoft claims Foundry guardrail controls cover protected material and personally identifiable information for models and agents.

Exact source quote
Protected material for code ✅ ✅ Protected material for text ✅ ✅ Groundedness (Preview) ✅ ❌ Personally identifiable information (Preview) ✅ ✅
Microsoft native AI security beyond Purview DSPM · Security requirement

Browser and business-application controls

No supporting claim found
Research finding

Microsoft Foundry and Agent ID native-control materials reviewed did not provide a public claim for browser or software as a service (SaaS) user-activity protection.

Microsoft native AI security beyond Purview DSPM · Security requirement

Generative AI application security

Source checkedStrong public support for this requirement
What the vendor says

Microsoft claims Prompt Shields are Foundry guardrail controls for model deployments and agents.

Exact source quote
Prompt Shields are part of the Foundry guardrails and controls system
Microsoft native AI security beyond Purview DSPM · Security requirement

Action-taking agent monitoring

Source checkedStrong public support for this requirement
What the vendor says

Microsoft claims Foundry tracing captures agent inputs, outputs, tool usage, retries, latencies, and costs during an agent run.

Exact source quote
It captures key details during an agent run, such as inputs, outputs, tool usage, retries, latencies, and costs.
Microsoft native AI security beyond Purview DSPM · Security requirement

Agent-to-agent communication security

Source checkedStrong public support for this requirement
What the vendor says

Microsoft claims Entra Agent ID supports OAuth 2.0, Model Context Protocol (MCP), and agent-to-agent (A2A) for authentication and agent-to-agent communication.

Exact source quote
supports standard protocols such as OAuth 2.0, MCP, and A2A for authentication and agent-to-agent communication.
Microsoft native AI security beyond Purview DSPM · Security requirement

Non-human identity and service-account security

Source checkedStrong public support for this requirement
What the vendor says

Microsoft claims Entra Agent ID provides a platform for creating and managing agent identities and agent identity blueprints.

Exact source quote
provides the platform for creating and managing agent identities and agent identity blueprints.
Microsoft native AI security beyond Purview DSPM · Security requirement

AI cost and usage controls

Source checkedLimited public support for this requirement
What the vendor says

Microsoft claims Foundry AI Gateway uses Azure application programming interface (API) Management to apply token limits, quotas, and governance to model deployments.

Exact source quote
AI Gateway uses Azure API Management behind the scenes to provide token limits, quotas, and governance for model deployments.
Microsoft native AI security beyond Purview DSPM · Security requirement

Licensing model

Source checkedStrong public support for this requirement
What the vendor says

Microsoft says extending Entra security features to agents requires Microsoft 365 E7 or Microsoft 365 E5 paired with a Microsoft Agent 365 license.

Exact source quote
Extending Microsoft Entra security features to agents requires Microsoft 365 E7 (includes Agent 365 and Microsoft Entra Suite) or Microsoft 365 E5 paired with a Microsoft Agent 365 license.
Zscaler AI Security · Security requirement

Unapproved AI use discovery

Source checkedStrong public support for this requirement
What the vendor says

Zscaler claims AI Asset Management discovers and maps the AI ecosystem, including shadow AI, risky apps, models, and pipelines.

Exact source quote
Discover and map your entire AI ecosystem, from shadow AI to risky apps, models, and pipelines.
Zscaler AI Security · Security requirement

AI-feature discovery in business applications

Source checkedStrong public support for this requirement
What the vendor says

Zscaler claims AI Access Security detects and classifies AI apps, including embedded AI in software as a service (SaaS) applications.

Exact source quote
Detect and classify thousands of AI apps including AI embedded in popular SaaS applications.
Zscaler AI Security · Security requirement

Approved AI usage monitoring

Source checkedStrong public support for this requirement
What the vendor says

Zscaler claims AI Access Security provides visibility into user interaction with AI apps, including prompt and response extraction and classification.

Exact source quote
Get a clear view of how users interact with your apps, including deep insights with prompt/response extraction and classification.
Zscaler AI Security · Security requirement

Controls for unapproved AI use

Source checkedStrong public support for this requirement
What the vendor says

Zscaler claims AI Access Security can warn, block, isolate, and restrict copy-paste actions within AI applications.

Exact source quote
Use flexible policies to warn, block, or enforce browser isolation, giving you full control over copy-paste actions within AI applications.
Zscaler AI Security · Security requirement

Sensitive-data protection for generative AI

Source checkedStrong public support for this requirement
What the vendor says

Zscaler claims AI Access Security blocks sensitive data loss in prompts using inline data loss prevention (DLP) dictionaries for source code, PII, PCI, PHI, and other data types.

Exact source quote
Block the loss of sensitive data in prompts with powerful inline DLP across 100+ DLP dictionaries like Source Code, PII, PCI, PHI, and more.
Zscaler AI Security · Security requirement

Browser and business-application controls

Source checkedStrong public support for this requirement
What the vendor says

Zscaler claims Endpoint AI Security detects AI threats on employee devices across browsers, extensions, and plugins.

Exact source quote
Find and stop AI threats on employee devices in browsers, extensions, and plugins that traditional EDRs were never built to see.
Zscaler AI Security · Security requirement

Generative AI application security

Source checkedStrong public support for this requirement
What the vendor says

Zscaler claims AI red teaming can conduct vulnerability assessments and simulate attacks on AI systems.

Exact source quote
Conduct vulnerability assessments and simulate attacks on your AI systems.
Zscaler AI Security · Security requirement

Action-taking agent monitoring

Source checkedStrong public support for this requirement
What the vendor says

Zscaler claims AI Access Graph provides real-time visibility into how AI agents use data and identities.

Exact source quote
Get real-time visibility into how AI agents use data and identities, reducing unnecessary access and tracking data lineage across every channel.
Zscaler AI Security · Security requirement

Agent-to-agent communication security

Source checkedStrong public support for this requirement
What the vendor says

Zscaler claims AI Broker secures agentic communications through Model Context Protocol (MCP) and agent-to-agent (A2A) brokers with fine-grained access policies.

Exact source quote
Secure agentic communications through MCP and A2A brokers and enforce fine-grained access policies across every enterprise AI agent.
Zscaler AI Security · Security requirement

Non-human identity and service-account security

Source checkedLimited public support for this requirement
What the vendor says

Zscaler claims AI Access Graph tracks AI agent use of identities and data, but the reviewed source does not describe full non-human identity (NHI) credential lifecycle management.

Exact source quote
Get real-time visibility into how AI agents use data and identities, reducing unnecessary access and tracking data lineage across every channel.