Public-source research
Vendor evidence
Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.
Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6
Showing 361–380 of 1280 evidence records
What the vendor saysCisco claims runtime policies that detect and block unsafe agent actions, unauthorized tool usage, and privilege escalation.
Exact source quotePrevent harmful or unintended agent actions by enforcing policies on tool invocation, privilege levels, and action chains.
Related framework references (5)
Research findingCisco AI Defense materials reviewed did not provide a public claim for governing coding-agent commands, developer-workstation files or networks, integrated development environment (IDE) extensions, skills, hooks, secrets, or package actions.
Related framework references (5)
What the vendor saysMicrosoft claims Agent 365 provides a centralized control plane to discover, manage, govern, and secure Microsoft and third-party AI agents.
Exact source quoteMicrosoft Agent 365 is a Microsoft 365 service that provides a centralized control plane for AI agents.
Related framework references (5)
What the vendor saysMicrosoft provides open-source RAMPART and PyRIT tooling for repeatable adversarial and regression testing of agent and generative-AI systems.
Exact source quoteRAMPART is an open-source testing framework that brings red teaming techniques directly into the development workflow.
Related framework references (5)
What the vendor saysMicrosoft Defender for Cloud claims preview scanning of registered Azure Machine Learning models for embedded malware, unsafe operators, and exposed secrets before production.
Exact source quoteAI model scanning provides proactive detection of unsafe or malicious artifacts and continuously monitors models for risk throughout the AI lifecycle.
Related framework references (5)
What the vendor saysMicrosoft Foundry claims preview Model Context Protocol (MCP) governance by routing eligible tool traffic through an AI Gateway where Azure application programming interface (API) Management policies enforce authentication, rate limits, IP restrictions, and audit logging.
Exact source quoteAn AI gateway provides a single, governed entry point where you can enforce authentication, rate limits, IP restrictions, and audit logging
Related framework references (5)
What the vendor saysMicrosoft Foundry claims automatic provisioning and lifecycle management of Entra agent identities, with Azure RBAC and token-based access for agent tool calls.
Exact source quoteMicrosoft Foundry automatically provisions and manages agent identities throughout the agent lifecycle.
Related framework references (5)
What the vendor saysMicrosoft Defender for Endpoint claims runtime protection that can detect prompt injection and audit or block actions by supported local AI agents, including coding and CLI agents.
Exact source quoteAI agent runtime protection helps you detect prompt injection at the device level and block or audit the agent's action
Related framework references (5)
What the vendor saysCrowdStrike claims unified AI visibility, governance, policy enforcement, and compliance logging across users, prompts, models, agents, Model Context Protocol (MCP) servers, endpoints, applications, gateways, and cloud environments.
Exact source quoteAIDR maps relationships between users, prompts, models, agents, and MCP servers, and captures runtime logs for compliance.
Related framework references (5)
What the vendor saysCrowdStrike offers AI Red Team Services for organizations implementing generative-AI services and applications.
Exact source quotefalcon-mcp and AI Red Team Services now available in new AI Agents and Tools category of AWS Marketplace.
Related framework references (5)
What the vendor saysCrowdStrike claims discovery of local models, Model Context Protocol (MCP) servers, integrated development environment (IDE) extensions, misconfigured AI tooling, vulnerabilities, and supply-chain risks on engineering endpoints before exploitation.
Exact source quoteThis helps security and engineering teams identify supply chain risks and misconfigured AI tooling before they become exploitable vulnerabilities.
Related framework references (5)
What the vendor saysCrowdStrike Falcon AIDR claims real-time protection for prompts, responses, agent actions, Model Context Protocol (MCP) servers, and AI/application programming interface (API) gateways with policy enforcement and automated response.
Exact source quoteFalcon AIDR secures every prompt, response, and agent action in real time.
Related framework references (5)
What the vendor saysCrowdStrike claims access controls and policy enforcement across relationships among human and non-human identities, agents, models, Model Context Protocol (MCP) servers, and interactions.
Exact source quoteAIDR provides unified visibility, real-time threat detection, data protection, access controls, and automated response.
Related framework references (5)
What the vendor saysCrowdStrike claims endpoint discovery and runtime protection for AI assets on engineering machines, including local models, Model Context Protocol (MCP) servers, integrated development environment (IDE) extensions, agent behavior, and sensitive-data flows.
Exact source quoteAI assets that can be deployed on endpoints, especially by developers on engineering machines such as LLMs, MCP servers, and IDE extensions.
Related framework references (5)
What the vendor saysWiz claims centralized AI inventory, posture, ownership context, compliance mapping, security baselines, prioritized risk, and remediation workflows across models, agents, services, data, infrastructure, and applications.
Exact source quoteAI-SPM is designed to secure AI pipelines and accelerate AI adoption while maintaining protection against AI-related risks.
Related framework references (5)
Research findingWiz AI-SPM materials reviewed did not provide a public product claim for automated adversarial testing, model or agent red teaming, repeatable attack suites, or release-gate evaluation.
Related framework references (5)
What the vendor saysWiz claims an AI bill of materials covering models, frameworks, dependencies, and libraries, plus model artifact scanning, repository and pipeline visibility, and attack-path analysis for model and training-data risk.
Exact source quoteAnalyze the components powering AI systems including models, frameworks, dependencies, and libraries.
Related framework references (5)
What the vendor saysWiz claims runtime detection and response for prompt injection, rogue agents, malicious AI behavior, and Model Context Protocol (MCP)-connected AI systems using sensor and cloud telemetry.
Exact source quoteStop AI-native threats including prompt injection, rogue agents, and malicious AI behavior at runtime.
Related framework references (5)
What the vendor saysWiz claims agent inventory and contextual mapping of agents to identities, workloads, data, access, capabilities, owners, and blast radius, with CIEM and secure-baseline checks.
Exact source quoteContextual Correlation: maps agents to the identities, workloads, and data they touch.
Related framework references (5)
What the vendor saysWiz claims coding-agent and AI-integrated development environment (IDE) integrations that bring cloud and AI context into development, generate code fixes, and prevent cloud and AI risks from reaching production.
Exact source quoteMeet your developers where they are and how they work with coding agent integrations that fix cloud and AI risks at the source.
Related framework references (5)