ASAI Security ResearchIndependent public-source research
Public reviewread only

Public-source research

Vendor evidence

Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.

Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6

Showing 421–440 of 1280 evidence records

Lasso Security · Security requirement

AI agent identity and permissions

Source checkedLimited public support for this requirement
What the vendor says

Lasso claims inventory of identity boundaries and authorization policies, ownership context, role-based permissions, and risk-scored governance of agent access to Model Context Protocol (MCP) servers, application programming interfaces (APIs), and tools.

Exact source quote
Inventory every AI component, including identity boundaries and authorization policies.
Lasso Security · Security requirement

AI coding-agent and workstation security

Source checkedLimited public support for this requirement
What the vendor says

Lasso claims risk scoring, management, and blocking of Model Context Protocol (MCP) servers, application programming interfaces (APIs), and external tool connections across Claude Code, Claude Desktop, Cursor, and Codex.

Exact source quote
Manage or block high-risk tools across Claude Code and Desktop, Cursor, and Codex.
Pangea / CrowdStrike Falcon AIDR · Security requirement

AI governance, risk, and compliance

Source checkedLimited public support for this requirement
What the vendor says

Pangea AI Guard claims customizable security recipes, centralized usage summaries, tamper-resistant activity logging, attribution, webhooks, and audit trails for AI application events.

Exact source quote
Requests to the AI Guard APIs and their processing results are logged in your Pangea project’s audit trail.
Pangea / CrowdStrike Falcon AIDR · Security requirement

AI assurance and adversarial testing

No supporting claim found
Research finding

Pangea AI Guard and Prompt Guard materials reviewed did not provide a public product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.

Pangea / CrowdStrike Falcon AIDR · Security requirement

AI model and supply-chain security

No supporting claim found
Research finding

Pangea AI Guard materials reviewed did not provide a public product claim for model artifact scanning, provenance, signing, dependency inventory, tamper analysis, or registry release controls.

Pangea / CrowdStrike Falcon AIDR · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedStrong public support for this requirement
What the vendor says

Pangea AI Guard claims application programming interface (API) and gateway-integrated enforcement across prompts, model responses, retrieval-augmented generation (RAG) ingestion, agent plans, tool inputs, and tool outputs using configurable block, report, redact, encrypt, and defang actions.

Exact source quote
Recipes can be configured to block, report, redact, encrypt, or defang sensitive or malicious content.
Pangea / CrowdStrike Falcon AIDR · Security requirement

AI agent identity and permissions

No supporting claim found
Research finding

Pangea AI Guard materials reviewed did not establish agent identity registration, distinct agent credentials, delegated authorization, ownership, rotation, revocation, or agent access-review lifecycle.

Pangea / CrowdStrike Falcon AIDR · Security requirement

AI coding-agent and workstation security

No supporting claim found
Research finding

Pangea AI Guard materials reviewed did not establish governance of coding-agent commands, developer-workstation files or networks, integrated development environment (IDE) extensions, skills, hooks, secrets, or package actions.

F5 AI Security Platform · Security requirement

AI governance, risk, and compliance

Source checkedLimited public support for this requirement
What the vendor says

F5 claims centralized observability, audit-ready logs, policy enforcement, regulatory assurance, usage tracking, customizable rules, and continuous compliance across AI models and applications.

Exact source quote
Complete traceability of AI decisions for regulatory reviews.
F5 AI Security Platform · Security requirement

AI assurance and adversarial testing

Source checkedStrong public support for this requirement
What the vendor says

F5 AI Red Team claims agent-powered adversarial testing, multi-turn agentic attacks, more than 50,000 evolving exploits, and prelaunch stress testing for AI applications.

Exact source quote
The industry’s first agent-powered adversarial testing platform for AI applications.
F5 AI Security Platform · Security requirement

AI model and supply-chain security

No supporting claim found
Research finding

F5 AI Guardrails and AI Red Team materials reviewed did not establish model artifact scanning, provenance, signing, dependency inventory, tamper analysis, or model-registry release controls.

F5 AI Security Platform · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedStrong public support for this requirement
What the vendor says

F5 AI Guardrails claims model-agnostic runtime security for models and agents with real-time input and output protection, data-loss prevention, adversarial-threat blocking, customizable policy, and observability.

Exact source quote
Comprehensive runtime security for AI models and agents.
F5 AI Security Platform · Security requirement

AI agent identity and permissions

Source checkedLimited public support for this requirement
What the vendor says

F5 claims policy-based access controls for administrator-defined users and groups plus rate limits and dynamic guardrails around agent interactions with systems, data, and users.

Exact source quote
Policy-based access controls restrict model accessibility to admin-identified individuals and groups.
F5 AI Security Platform · Security requirement

AI coding-agent and workstation security

No supporting claim found
Research finding

F5 AI Guardrails and AI Red Team materials reviewed did not establish governance of coding-agent commands, developer-workstation files or networks, integrated development environment (IDE) extensions, skills, hooks, secrets, or package actions.

Oasis Security · Security requirement

AI governance, risk, and compliance

Source checkedStrong public support for this requirement
What the vendor says

Oasis claims agent discovery, inventory, ownership, credential governance, policy-driven approvals, chain-of-custody evidence, regulator-ready auditability, and lifecycle control for AI agents and non-human identities.

Exact source quote
Every session generates a complete chain of custody: Human → Agent → Prompt → Intent → Policy → Identity → Actions → Results.
Oasis Security · Security requirement

AI assurance and adversarial testing

No supporting claim found
Research finding

Oasis Agentic Access Management materials reviewed did not provide a public product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.

Oasis Security · Security requirement

AI model and supply-chain security

Source checkedLimited public support for this requirement
What the vendor says

Oasis claims security-posture and credential-exposure evaluation for AI providers, Model Context Protocol (MCP) servers, third-party agents, scripts, and tools before access, including allowlisting and onboarding of vetted Model Context Protocol (MCP) components.

Exact source quote
Organizations evaluate AI providers, MCP servers, and third-party agents for security posture, data handling, and credential exposure before granting access.
Oasis Security · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedStrong public support for this requirement
What the vendor says

Oasis claims intent-aware runtime policy that converts prompts, tool calls, and action plans into short-lived least-privilege sessions with allow, warn, deny, or step-up enforcement before execution.

Exact source quote
Every interaction is turned into a short-lived, least-privilege session with full accountability.
Oasis Security · Security requirement

AI agent identity and permissions

Source checkedStrong public support for this requirement
What the vendor says

Oasis claims agent lifecycle governance, accountable ownership, just-in-time ephemeral identities, deterministic intent-aware authorization, precise scopes, session expiry, continuous oversight, and end-to-end attribution.

Exact source quote
Granted via just-in-time, ephemeral identities.
Oasis Security · Security requirement

AI coding-agent and workstation security

Source checkedStrong public support for this requirement
What the vendor says

Oasis claims Cursor hook and policy integration that attributes coding-agent actions, vets Model Context Protocol (MCP) servers, blocks high-risk shell and Git operations, applies data loss prevention (DLP) to tool payloads, and requires step-up approval for production actions.

Exact source quote
Command guardrails: detect high-risk shell commands and deny or step-up based on policy.