ASAI Security ResearchIndependent public-source research
Public reviewread only

Public-source research

Vendor evidence

Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.

Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6

Showing 401–420 of 1280 evidence records

Netskope AI Security · Security requirement

AI model and supply-chain security

Source checkedLimited public support for this requirement
What the vendor says

Netskope claims an Model Context Protocol (MCP) Catalog and inventory spanning local, containerized, remote, and code-repository Model Context Protocol (MCP) servers with risk assessment and access controls.

Exact source quote
An inventory of publicly available MCP servers (remote and code repositories).
Netskope AI Security · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedStrong public support for this requirement
What the vendor says

Netskope claims an AI Gateway and Agentic Broker with real-time decoding, inspection, data loss prevention (DLP), guardrails, and granular blocking policies for prompts, responses, Model Context Protocol (MCP) servers, tools, and traffic.

Exact source quote
Advanced real-time protection policy controls.
Netskope AI Security · Security requirement

AI agent identity and permissions

Source checkedLimited public support for this requirement
What the vendor says

Netskope claims policy-based access control for autonomous non-human Model Context Protocol (MCP) interactions and visibility across Model Context Protocol (MCP) clients, servers, tools, resources, and prompt requests.

Exact source quote
Scale your autonomous AI, and secure autonomous, non-human interactions, with unified visibility and control of public MCP servers.
Netskope AI Security · Security requirement

AI coding-agent and workstation security

Source checkedLimited public support for this requirement
What the vendor says

Netskope claims real-time protection and data loss prevention (DLP) for Model Context Protocol (MCP) client applications including AI code editors and developer tools, with discovery and blocking of Model Context Protocol (MCP) servers, tools, resources, and requests.

Exact source quote
Real-time protection when using MCP client applications including AI code editors, chat interfaces, and developer tools.
Zscaler AI Security · Security requirement

AI governance, risk, and compliance

Source checkedLimited public support for this requirement
What the vendor says

Zscaler claims AI asset management, AI bill of materials, posture and risk assessment, compliance heat maps, governance status, access policy, and data-lineage visibility across the AI lifecycle.

Exact source quote
Discover and map your entire AI ecosystem, from shadow AI to risky apps, models, and pipelines.
Zscaler AI Security · Security requirement

AI assurance and adversarial testing

Source checkedStrong public support for this requirement
What the vendor says

Zscaler claims automated red teaming across the AI lifecycle, including new adversarial testing for Model Context Protocol (MCP) servers and dynamic risk assessment.

Exact source quote
Introduces AI red teaming for MCP servers, a standalone prompt hardening service, and compliance heat maps.
Zscaler AI Security · Security requirement

AI model and supply-chain security

Source checkedLimited public support for this requirement
What the vendor says

Zscaler claims AI BOM discovery of models, Model Context Protocol (MCP) servers, development tools, and data pipelines plus risk scoring, codebase scanning, and Model Context Protocol (MCP) capability exposure analysis.

Exact source quote
AI BOM: Discover AI models, MCP servers, development tools, and data pipelines.
Zscaler AI Security · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedStrong public support for this requirement
What the vendor says

Zscaler claims Model Context Protocol (MCP) and agent-to-agent (A2A) brokers, fine-grained agent access policy, prompt hardening, AI guardrails, and runtime protection across enterprise AI agents.

Exact source quote
Secure agentic communications through MCP and A2A brokers and enforce fine-grained access policies across every enterprise AI agent.
Zscaler AI Security · Security requirement

AI agent identity and permissions

Source checkedLimited public support for this requirement
What the vendor says

Zscaler claims an AI Access Graph that maps AI-agent use of data and identities and enables fine-grained access policies for enterprise agents across Model Context Protocol (MCP) and agent-to-agent (A2A) communications.

Exact source quote
Get real-time visibility into how AI agents use data and identities, reducing unnecessary access.
Zscaler AI Security · Security requirement

AI coding-agent and workstation security

Source checkedLimited public support for this requirement
What the vendor says

Zscaler claims endpoint discovery and protection for AI activity in browsers, extensions, and plugins plus agentic codebase scanning and Model Context Protocol (MCP) risk analysis for filesystem, network, and code-execution exposure.

Exact source quote
Uncover risks in agentic codebases through code scanning, and extend visibility to AI activity on endpoints.
Lakera / Check Point · Security requirement

AI governance, risk, and compliance

Source checkedLimited public support for this requirement
What the vendor says

Check Point AI Agent Security claims continuous agent inventory, holistic risk ratings, contributing-factor explanations, and risk mappings to OWASP and MITRE ATLAS.

Exact source quote
Every discovered agent gets a holistic risk rating with the contributing factors explained.
Lakera / Check Point · Security requirement

AI assurance and adversarial testing

No supporting claim found
Research finding

Check Point AI Agent Security and Lakera Guard materials reviewed did not provide a public customer-facing product claim for automated adversarial testing, repeatable attack suites, or release-gate red teaming.

Lakera / Check Point · Security requirement

AI model and supply-chain security

Source checkedLimited public support for this requirement
What the vendor says

Check Point AI Agent Security claims posture detection for unofficial, unknown, or vulnerable Model Context Protocol (MCP) servers, untrusted components, suspicious tool code, and likely-malicious tools.

Exact source quote
Flags unofficial, unknown, and vulnerable MCP servers, untrusted components, and suspicious or likely-malicious tool code.
Lakera / Check Point · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedStrong public support for this requirement
What the vendor says

Check Point AI Agent Security claims real-time Guard application programming interface (API) screening and enforcement across prompts, tool calls, tool responses, tool descriptions, data leakage, content violations, and off-policy agent behavior.

Exact source quote
Real-time screening and flagging of prompt attacks, data leakage, content violations, and off-policy agent behavior through the Guard API.
Lakera / Check Point · Security requirement

AI agent identity and permissions

Source checkedLimited public support for this requirement
What the vendor says

Check Point AI Agent Security claims tool allow or deny controls and posture findings for missing authentication, static credentials, and execution under an author’s credentials.

Exact source quote
Tool Allow/Deny List limits available actions.
Lakera / Check Point · Security requirement

AI coding-agent and workstation security

No supporting claim found
Research finding

Check Point AI Agent Security and Lakera Guard materials reviewed did not establish controls specifically for coding-agent commands, developer-workstation files or networks, integrated development environment (IDE) extensions, hooks, secrets, or package actions.

Lasso Security · Security requirement

AI governance, risk, and compliance

Source checkedStrong public support for this requirement
What the vendor says

Lasso claims continuous agent discovery, AI bill of materials (AI-BOM) inventory, risk scoring, ownership, intent-aware policy, compliance mapping, audit logs, and cross-platform governance from code to runtime.

Exact source quote
A single source of truth for governing agentic AI from code to runtime.
Lasso Security · Security requirement

AI assurance and adversarial testing

Source checkedStrong public support for this requirement
What the vendor says

Lasso claims automated agentic red teaming with static, multi-turn, and high-agency attacks, deployment-pipeline integration, adaptive policy generation, and one-click testing.

Exact source quote
Stress-test application logic through static, multi-turn, and high-agency attack to uncover vulnerabilities and build adaptive guardrails.
Lasso Security · Security requirement

AI model and supply-chain security

Source checkedStrong public support for this requirement
What the vendor says

Lasso claims an AI bill of materials (AI-BOM) spanning models, prompts, tools, Model Context Protocol (MCP) servers, frameworks, databases, services, guardrails, identity boundaries, and authorization policies, with continuous CI updates and supply-chain risk assessment.

Exact source quote
Inventory every AI component, including models, MCP servers, delegated agents, databases, third-party tool connectors, identity boundaries, and authorization policies.
Lasso Security · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedStrong public support for this requirement
What the vendor says

Lasso claims an Model Context Protocol (MCP) security gateway and intent-aware runtime policy enforcement across agent actions, tools, application programming interfaces (APIs), external connections, indirect prompt injection, memory poisoning, permissions, and data loss prevention (DLP).

Exact source quote
Lasso's open-source MCP Gateway provides a security layer for MCP connections.