Public-source research
Vendor evidence
Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.
Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6
Wiz claims coding-agent and AI-integrated development environment (IDE) integrations that bring cloud and AI context into development, generate code fixes, and prevent cloud and AI risks from reaching production.
Meet your developers where they are and how they work with coding agent integrations that fix cloud and AI risks at the source.
Related framework references (5)
Microsoft Purview materials reviewed did not provide a public product claim for governing coding-agent commands, developer-workstation files or networks, integrated development environment (IDE) extensions, skills, hooks, secrets, or package actions.
No quoted source text is recorded for this claim.
Related framework references (5)
Noma claims discovery, inventory, permission context, access control, and runtime protection for local and coding agents including Claude Code, Cursor, and GitHub Copilot.
Continuous, automatic inventory of every AI agent, MCP server, and tool across local and coding agents.
Related framework references (5)
WitnessAI claims controls for AI coding tools and agents, source code, intellectual property, secrets, integrated development environment (IDE) activity, and coding-agent interactions with Model Context Protocol (MCP) servers and tools.
Enforce control over AI coding agents’ interactions with MCP servers and tools.
Related framework references (5)
Netskope claims real-time protection and data loss prevention (DLP) for Model Context Protocol (MCP) client applications including AI code editors and developer tools, with discovery and blocking of Model Context Protocol (MCP) servers, tools, resources, and requests.
Real-time protection when using MCP client applications including AI code editors, chat interfaces, and developer tools.
Related framework references (5)
Zscaler claims endpoint discovery and protection for AI activity in browsers, extensions, and plugins plus agentic codebase scanning and Model Context Protocol (MCP) risk analysis for filesystem, network, and code-execution exposure.
Uncover risks in agentic codebases through code scanning, and extend visibility to AI activity on endpoints.
Related framework references (5)
Check Point AI Agent Security and Lakera Guard materials reviewed did not establish controls specifically for coding-agent commands, developer-workstation files or networks, integrated development environment (IDE) extensions, hooks, secrets, or package actions.
No quoted source text is recorded for this claim.
Related framework references (5)
Lasso claims risk scoring, management, and blocking of Model Context Protocol (MCP) servers, application programming interfaces (APIs), and external tool connections across Claude Code, Claude Desktop, Cursor, and Codex.
Manage or block high-risk tools across Claude Code and Desktop, Cursor, and Codex.
Related framework references (5)
Pangea AI Guard materials reviewed did not establish governance of coding-agent commands, developer-workstation files or networks, integrated development environment (IDE) extensions, skills, hooks, secrets, or package actions.
No quoted source text is recorded for this claim.
Related framework references (5)
F5 AI Guardrails and AI Red Team materials reviewed did not establish governance of coding-agent commands, developer-workstation files or networks, integrated development environment (IDE) extensions, skills, hooks, secrets, or package actions.
No quoted source text is recorded for this claim.
Related framework references (5)
Oasis claims Cursor hook and policy integration that attributes coding-agent actions, vets Model Context Protocol (MCP) servers, blocks high-risk shell and Git operations, applies data loss prevention (DLP) to tool payloads, and requires step-up approval for production actions.
Command guardrails: detect high-risk shell commands and deny or step-up based on policy.
Related framework references (5)
Astrix Agent Control Plane materials reviewed did not establish governance of coding-agent commands, developer-workstation files or networks, integrated development environment (IDE) extensions, skills, hooks, secrets, or package actions.
No quoted source text is recorded for this claim.
Related framework references (5)
Entro claims Claude Code intent and Model Context Protocol (MCP) session auditing, endpoint discovery of local agents and Model Context Protocol (MCP) configurations, secret scanning across the SDLC, and identity context for vibe-coding access paths.
The MCP Audit plugin tracks Claude Code sessions and every MCP server each agent contacts.
Related framework references (5)
Aembit identity and access management (IAM) for Agentic AI materials reviewed did not establish governance of coding-agent commands, developer-workstation files or networks, integrated development environment (IDE) extensions, skills, hooks, secrets, or package actions.
No quoted source text is recorded for this claim.
Related framework references (5)
Prompt Security claims endpoint and integrated development environment (IDE)-integrated governance for coding assistants, Model Context Protocol (MCP) servers, exposed commands, secrets, PII, generated code, prompt responses, and action-level policy across tools including Cursor and GitHub Copilot.
Fine-grained policies that determine which MCPs are allowed, which commands can be run, and under what circumstances.
Related framework references (5)
Harmonic claims device and Model Context Protocol (MCP) gateway controls for integrated development environment (IDE) coding assistants, local development environments, agent tool calls, source code, internal identifiers, infrastructure configuration, and sensitive-data flows.
The ability to apply policy controls at the point where the AI agent interacts with internal systems.
Related framework references (5)
Cyberhaven claims endpoint inventory and full execution-lifecycle reconstruction for local coding agents across browsers, CLIs, integrated development environments (IDEs), files, Model Context Protocol (MCP) servers, application programming interfaces (APIs), generated outputs, and sensitive-data movement.
Continuously inventories AI agents running across endpoints, browsers, command-line interfaces, and IDEs.
Related framework references (5)
Nightfall claims controls for Cursor, VS Code, Claude, and custom Model Context Protocol (MCP) integrations including source-code and file inspection, embedded-secret redaction, server and tool allowlisting, version monitoring, request logging, and malicious-update quarantine.
Automatically discover and catalog all MCP servers across Claude Desktop, Cursor, VS Code, and custom integrations.
Related framework references (5)
Island claims browser, desktop, extension, network, data loss prevention (DLP), and AI policy controls that protect proprietary source code and govern AI applications, locally running agents, outputs, and developer data movement.
Sensitive data is safeguarded before it ever reaches an AI provider, and AI responses are protected before they reach the user.
Related framework references (5)
LayerX claims discovery and governance of AI desktop apps, integrated development environments (IDEs), integrated development environment (IDE) extensions, browser extensions, on-device agents, prompts, actions, file transfers, copy and paste, and sensitive-data exchanges.
LayerX Endpoint Agent extends coverage to AI desktop apps, IDEs, IDE extensions, and on-device agents.
Related framework references (5)