ASAI Security ResearchIndependent public-source research
Public reviewread only

Public-source research

Vendor evidence

Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.

Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6

Showing 361–380 of 1280 evidence records

Cisco AI Defense · Security requirement

AI agent identity and permissions

Source checkedLimited public support for this requirement
What the vendor says

Cisco claims runtime policies that detect and block unsafe agent actions, unauthorized tool usage, and privilege escalation.

Exact source quote
Prevent harmful or unintended agent actions by enforcing policies on tool invocation, privilege levels, and action chains.
Cisco AI Defense · Security requirement

AI coding-agent and workstation security

No supporting claim found
Research finding

Cisco AI Defense materials reviewed did not provide a public claim for governing coding-agent commands, developer-workstation files or networks, integrated development environment (IDE) extensions, skills, hooks, secrets, or package actions.

Microsoft native AI security beyond Purview DSPM · Security requirement

AI governance, risk, and compliance

Source checkedStrong public support for this requirement
What the vendor says

Microsoft claims Agent 365 provides a centralized control plane to discover, manage, govern, and secure Microsoft and third-party AI agents.

Exact source quote
Microsoft Agent 365 is a Microsoft 365 service that provides a centralized control plane for AI agents.
Microsoft native AI security beyond Purview DSPM · Security requirement

AI assurance and adversarial testing

Source checkedStrong public support for this requirement
What the vendor says

Microsoft provides open-source RAMPART and PyRIT tooling for repeatable adversarial and regression testing of agent and generative-AI systems.

Exact source quote
RAMPART is an open-source testing framework that brings red teaming techniques directly into the development workflow.
Microsoft native AI security beyond Purview DSPM · Security requirement

AI model and supply-chain security

Source checkedLimited public support for this requirement
What the vendor says

Microsoft Defender for Cloud claims preview scanning of registered Azure Machine Learning models for embedded malware, unsafe operators, and exposed secrets before production.

Exact source quote
AI model scanning provides proactive detection of unsafe or malicious artifacts and continuously monitors models for risk throughout the AI lifecycle.
Microsoft native AI security beyond Purview DSPM · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedStrong public support for this requirement
What the vendor says

Microsoft Foundry claims preview Model Context Protocol (MCP) governance by routing eligible tool traffic through an AI Gateway where Azure application programming interface (API) Management policies enforce authentication, rate limits, IP restrictions, and audit logging.

Exact source quote
An AI gateway provides a single, governed entry point where you can enforce authentication, rate limits, IP restrictions, and audit logging
Microsoft native AI security beyond Purview DSPM · Security requirement

AI agent identity and permissions

Source checkedStrong public support for this requirement
What the vendor says

Microsoft Foundry claims automatic provisioning and lifecycle management of Entra agent identities, with Azure RBAC and token-based access for agent tool calls.

Exact source quote
Microsoft Foundry automatically provisions and manages agent identities throughout the agent lifecycle.
Microsoft native AI security beyond Purview DSPM · Security requirement

AI coding-agent and workstation security

Source checkedLimited public support for this requirement
What the vendor says

Microsoft Defender for Endpoint claims runtime protection that can detect prompt injection and audit or block actions by supported local AI agents, including coding and CLI agents.

Exact source quote
AI agent runtime protection helps you detect prompt injection at the device level and block or audit the agent's action
CrowdStrike AI Security · Security requirement

AI governance, risk, and compliance

Source checkedLimited public support for this requirement
What the vendor says

CrowdStrike claims unified AI visibility, governance, policy enforcement, and compliance logging across users, prompts, models, agents, Model Context Protocol (MCP) servers, endpoints, applications, gateways, and cloud environments.

Exact source quote
AIDR maps relationships between users, prompts, models, agents, and MCP servers, and captures runtime logs for compliance.
CrowdStrike AI Security · Security requirement

AI assurance and adversarial testing

Source checkedStrong public support for this requirement
What the vendor says

CrowdStrike offers AI Red Team Services for organizations implementing generative-AI services and applications.

Exact source quote
falcon-mcp and AI Red Team Services now available in new AI Agents and Tools category of AWS Marketplace.
CrowdStrike AI Security · Security requirement

AI model and supply-chain security

Source checkedLimited public support for this requirement
What the vendor says

CrowdStrike claims discovery of local models, Model Context Protocol (MCP) servers, integrated development environment (IDE) extensions, misconfigured AI tooling, vulnerabilities, and supply-chain risks on engineering endpoints before exploitation.

Exact source quote
This helps security and engineering teams identify supply chain risks and misconfigured AI tooling before they become exploitable vulnerabilities.
CrowdStrike AI Security · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedStrong public support for this requirement
What the vendor says

CrowdStrike Falcon AIDR claims real-time protection for prompts, responses, agent actions, Model Context Protocol (MCP) servers, and AI/application programming interface (API) gateways with policy enforcement and automated response.

Exact source quote
Falcon AIDR secures every prompt, response, and agent action in real time.
CrowdStrike AI Security · Security requirement

AI agent identity and permissions

Source checkedLimited public support for this requirement
What the vendor says

CrowdStrike claims access controls and policy enforcement across relationships among human and non-human identities, agents, models, Model Context Protocol (MCP) servers, and interactions.

Exact source quote
AIDR provides unified visibility, real-time threat detection, data protection, access controls, and automated response.
CrowdStrike AI Security · Security requirement

AI coding-agent and workstation security

Source checkedLimited public support for this requirement
What the vendor says

CrowdStrike claims endpoint discovery and runtime protection for AI assets on engineering machines, including local models, Model Context Protocol (MCP) servers, integrated development environment (IDE) extensions, agent behavior, and sensitive-data flows.

Exact source quote
AI assets that can be deployed on endpoints, especially by developers on engineering machines such as LLMs, MCP servers, and IDE extensions.
Wiz AI-SPM / Google Cloud · Security requirement

AI governance, risk, and compliance

Source checkedLimited public support for this requirement
What the vendor says

Wiz claims centralized AI inventory, posture, ownership context, compliance mapping, security baselines, prioritized risk, and remediation workflows across models, agents, services, data, infrastructure, and applications.

Exact source quote
AI-SPM is designed to secure AI pipelines and accelerate AI adoption while maintaining protection against AI-related risks.
Wiz AI-SPM / Google Cloud · Security requirement

AI assurance and adversarial testing

No supporting claim found
Research finding

Wiz AI-SPM materials reviewed did not provide a public product claim for automated adversarial testing, model or agent red teaming, repeatable attack suites, or release-gate evaluation.

Wiz AI-SPM / Google Cloud · Security requirement

AI model and supply-chain security

Source checkedStrong public support for this requirement
What the vendor says

Wiz claims an AI bill of materials covering models, frameworks, dependencies, and libraries, plus model artifact scanning, repository and pipeline visibility, and attack-path analysis for model and training-data risk.

Exact source quote
Analyze the components powering AI systems including models, frameworks, dependencies, and libraries.
Wiz AI-SPM / Google Cloud · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedLimited public support for this requirement
What the vendor says

Wiz claims runtime detection and response for prompt injection, rogue agents, malicious AI behavior, and Model Context Protocol (MCP)-connected AI systems using sensor and cloud telemetry.

Exact source quote
Stop AI-native threats including prompt injection, rogue agents, and malicious AI behavior at runtime.
Wiz AI-SPM / Google Cloud · Security requirement

AI agent identity and permissions

Source checkedLimited public support for this requirement
What the vendor says

Wiz claims agent inventory and contextual mapping of agents to identities, workloads, data, access, capabilities, owners, and blast radius, with CIEM and secure-baseline checks.

Exact source quote
Contextual Correlation: maps agents to the identities, workloads, and data they touch.
Wiz AI-SPM / Google Cloud · Security requirement

AI coding-agent and workstation security

Source checkedLimited public support for this requirement
What the vendor says

Wiz claims coding-agent and AI-integrated development environment (IDE) integrations that bring cloud and AI context into development, generate code fixes, and prevent cloud and AI risks from reaching production.

Exact source quote
Meet your developers where they are and how they work with coding agent integrations that fix cloud and AI risks at the source.