Public-source research
Vendor evidence
Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.
Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6
Showing 421–440 of 1280 evidence records
What the vendor saysLasso claims inventory of identity boundaries and authorization policies, ownership context, role-based permissions, and risk-scored governance of agent access to Model Context Protocol (MCP) servers, application programming interfaces (APIs), and tools.
Exact source quoteInventory every AI component, including identity boundaries and authorization policies.
Related framework references (5)
What the vendor saysLasso claims risk scoring, management, and blocking of Model Context Protocol (MCP) servers, application programming interfaces (APIs), and external tool connections across Claude Code, Claude Desktop, Cursor, and Codex.
Exact source quoteManage or block high-risk tools across Claude Code and Desktop, Cursor, and Codex.
Related framework references (5)
What the vendor saysPangea AI Guard claims customizable security recipes, centralized usage summaries, tamper-resistant activity logging, attribution, webhooks, and audit trails for AI application events.
Exact source quoteRequests to the AI Guard APIs and their processing results are logged in your Pangea project’s audit trail.
Related framework references (5)
Research findingPangea AI Guard and Prompt Guard materials reviewed did not provide a public product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.
Related framework references (5)
Research findingPangea AI Guard materials reviewed did not provide a public product claim for model artifact scanning, provenance, signing, dependency inventory, tamper analysis, or registry release controls.
Related framework references (5)
What the vendor saysPangea AI Guard claims application programming interface (API) and gateway-integrated enforcement across prompts, model responses, retrieval-augmented generation (RAG) ingestion, agent plans, tool inputs, and tool outputs using configurable block, report, redact, encrypt, and defang actions.
Exact source quoteRecipes can be configured to block, report, redact, encrypt, or defang sensitive or malicious content.
Related framework references (5)
Research findingPangea AI Guard materials reviewed did not establish agent identity registration, distinct agent credentials, delegated authorization, ownership, rotation, revocation, or agent access-review lifecycle.
Related framework references (5)
Research findingPangea AI Guard materials reviewed did not establish governance of coding-agent commands, developer-workstation files or networks, integrated development environment (IDE) extensions, skills, hooks, secrets, or package actions.
Related framework references (5)
What the vendor saysF5 claims centralized observability, audit-ready logs, policy enforcement, regulatory assurance, usage tracking, customizable rules, and continuous compliance across AI models and applications.
Exact source quoteComplete traceability of AI decisions for regulatory reviews.
Related framework references (5)
What the vendor saysF5 AI Red Team claims agent-powered adversarial testing, multi-turn agentic attacks, more than 50,000 evolving exploits, and prelaunch stress testing for AI applications.
Exact source quoteThe industry’s first agent-powered adversarial testing platform for AI applications.
Related framework references (5)
Research findingF5 AI Guardrails and AI Red Team materials reviewed did not establish model artifact scanning, provenance, signing, dependency inventory, tamper analysis, or model-registry release controls.
Related framework references (5)
What the vendor saysF5 AI Guardrails claims model-agnostic runtime security for models and agents with real-time input and output protection, data-loss prevention, adversarial-threat blocking, customizable policy, and observability.
Exact source quoteComprehensive runtime security for AI models and agents.
Related framework references (5)
What the vendor saysF5 claims policy-based access controls for administrator-defined users and groups plus rate limits and dynamic guardrails around agent interactions with systems, data, and users.
Exact source quotePolicy-based access controls restrict model accessibility to admin-identified individuals and groups.
Related framework references (5)
Research findingF5 AI Guardrails and AI Red Team materials reviewed did not establish governance of coding-agent commands, developer-workstation files or networks, integrated development environment (IDE) extensions, skills, hooks, secrets, or package actions.
Related framework references (5)
What the vendor saysOasis claims agent discovery, inventory, ownership, credential governance, policy-driven approvals, chain-of-custody evidence, regulator-ready auditability, and lifecycle control for AI agents and non-human identities.
Exact source quoteEvery session generates a complete chain of custody: Human → Agent → Prompt → Intent → Policy → Identity → Actions → Results.
Related framework references (5)
Research findingOasis Agentic Access Management materials reviewed did not provide a public product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.
Related framework references (5)
What the vendor saysOasis claims security-posture and credential-exposure evaluation for AI providers, Model Context Protocol (MCP) servers, third-party agents, scripts, and tools before access, including allowlisting and onboarding of vetted Model Context Protocol (MCP) components.
Exact source quoteOrganizations evaluate AI providers, MCP servers, and third-party agents for security posture, data handling, and credential exposure before granting access.
Related framework references (5)
What the vendor saysOasis claims intent-aware runtime policy that converts prompts, tool calls, and action plans into short-lived least-privilege sessions with allow, warn, deny, or step-up enforcement before execution.
Exact source quoteEvery interaction is turned into a short-lived, least-privilege session with full accountability.
Related framework references (5)
What the vendor saysOasis claims agent lifecycle governance, accountable ownership, just-in-time ephemeral identities, deterministic intent-aware authorization, precise scopes, session expiry, continuous oversight, and end-to-end attribution.
Exact source quoteGranted via just-in-time, ephemeral identities.
Related framework references (5)
What the vendor saysOasis claims Cursor hook and policy integration that attributes coding-agent actions, vets Model Context Protocol (MCP) servers, blocks high-risk shell and Git operations, applies data loss prevention (DLP) to tool payloads, and requires step-up approval for production actions.
Exact source quoteCommand guardrails: detect high-risk shell commands and deny or step-up based on policy.
Related framework references (5)