ASAI Security ResearchIndependent public-source research
Public reviewread only

Public-source research

Vendor evidence

Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.

Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6

Showing 441–460 of 1280 evidence records

Astrix Security / Cisco · Security requirement

AI governance, risk, and compliance

Source checkedStrong public support for this requirement
What the vendor says

Astrix claims real-time inventory of agents, Model Context Protocol (MCP) servers, and NHIs with ownership, business context, policy-at-creation, automated attestation, activity trails, and lifecycle governance.

Exact source quote
Apply policy as agents are deployed to establish clear ownership and automate attestation.
Astrix Security / Cisco · Security requirement

AI assurance and adversarial testing

No supporting claim found
Research finding

Astrix Agent Control Plane materials reviewed did not provide a public product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.

Astrix Security / Cisco · Security requirement

AI model and supply-chain security

No supporting claim found
Research finding

Astrix Agent Control Plane materials reviewed did not establish model artifact scanning, provenance, signing, dependency analysis, Model Context Protocol (MCP) component vetting, tamper detection, or model-registry release controls.

Astrix Security / Cisco · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedLimited public support for this requirement
What the vendor says

Astrix claims policy-driven runtime access enforcement for agents using precisely scoped, short-lived, just-in-time credentials and pre-approved connectivity.

Exact source quote
Every agent and workload gets policy-driven, short-lived credentials delivered with precisely scoped and just-in-time access.
Astrix Security / Cisco · Security requirement

AI agent identity and permissions

Source checkedStrong public support for this requirement
What the vendor says

Astrix claims secure agent provisioning with ownership, automated attestation, precisely scoped least privilege, short-lived credentials, just-in-time access, pre-approved policy, and per-agent audit trails.

Exact source quote
Provision secure-by-design AI agents with short-lived credentials, just-in-time, precisely scoped access, and policy at creation.
Astrix Security / Cisco · Security requirement

AI coding-agent and workstation security

No supporting claim found
Research finding

Astrix Agent Control Plane materials reviewed did not establish governance of coding-agent commands, developer-workstation files or networks, integrated development environment (IDE) extensions, skills, hooks, secrets, or package actions.

Entro Security · Security requirement

AI governance, risk, and compliance

Source checkedStrong public support for this requirement
What the vendor says

Entro claims discovery, ownership, lineage, blast-radius mapping, approval workflow, lifecycle provisioning and offboarding, continuous policy, segregation of duties, compliance dashboards, and audit-ready reports for agents and NHIs.

Exact source quote
Every discovered agent and identity is mapped with ownership, permissions, lineage, and blast radius.
Entro Security · Security requirement

AI assurance and adversarial testing

No supporting claim found
Research finding

Entro agent and non-human identity (NHI) security materials reviewed did not provide a public product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.

Entro Security · Security requirement

AI model and supply-chain security

No supporting claim found
Research finding

Entro agent and non-human identity (NHI) security materials reviewed did not establish model artifact scanning, provenance, signing, model dependency analysis, tamper detection, or model-registry release controls.

Entro Security · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedLimited public support for this requirement
What the vendor says

Entro claims real-time identity policy across agents and NHIs, just-in-time scoped access, intent monitoring, anomaly detection, and Model Context Protocol (MCP) session auditing for prompts, servers, and agent contacts.

Exact source quote
Entro’s AI Detection and Response monitors agent intent in real time, and catches threats at the identity layer.
Entro Security · Security requirement

AI agent identity and permissions

Source checkedStrong public support for this requirement
What the vendor says

Entro claims automated agent and non-human identity (NHI) provisioning, accountable ownership, minimum permissions, approval routing, just-in-time access, time bounds, continuous policy, access change, and offboarding.

Exact source quote
Entro extends IGA to every AI agent and NHI in your environment.
Entro Security · Security requirement

AI coding-agent and workstation security

Source checkedLimited public support for this requirement
What the vendor says

Entro claims Claude Code intent and Model Context Protocol (MCP) session auditing, endpoint discovery of local agents and Model Context Protocol (MCP) configurations, secret scanning across the SDLC, and identity context for vibe-coding access paths.

Exact source quote
The MCP Audit plugin tracks Claude Code sessions and every MCP server each agent contacts.
Aembit · Security requirement

AI governance, risk, and compliance

Source checkedLimited public support for this requirement
What the vendor says

Aembit claims centralized agent access policy, cryptographically verifiable identity, per-request policy decisions, and audit logs tying agent identity, user identity, target server, credential, and resource access together.

Exact source quote
Every MCP request is logged with agent identity, user identity, target server, and policy decision.
Aembit · Security requirement

AI assurance and adversarial testing

No supporting claim found
Research finding

Aembit identity and access management (IAM) for Agentic AI materials reviewed did not provide a public product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.

Aembit · Security requirement

AI model and supply-chain security

No supporting claim found
Research finding

Aembit identity and access management (IAM) for Agentic AI materials reviewed did not establish model artifact scanning, provenance, signing, dependency or Model Context Protocol (MCP) component analysis, tamper detection, or model-registry release controls.

Aembit · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedStrong public support for this requirement
What the vendor says

Aembit claims an Model Context Protocol (MCP) Identity Gateway that validates workload identity, enforces per-request policy, approves or denies access, exchanges credentials, and logs agent-to-resource communications.

Exact source quote
The gateway authenticates the agent, enforces policy, and performs token exchange.
Aembit · Security requirement

AI agent identity and permissions

Source checkedStrong public support for this requirement
What the vendor says

Aembit claims cryptographically verified blended agent and user identity, OAuth 2.1 authorization, secure token exchange, ephemeral just-in-time credentials, least privilege, immediate revocation, and full access attribution.

Exact source quote
Aembit IAM for Agentic AI assigns each agent a cryptographically verified identity, issues ephemeral credentials, enforces policy at runtime.
Aembit · Security requirement

AI coding-agent and workstation security

No supporting claim found
Research finding

Aembit identity and access management (IAM) for Agentic AI materials reviewed did not establish governance of coding-agent commands, developer-workstation files or networks, integrated development environment (IDE) extensions, skills, hooks, secrets, or package actions.

Prompt Security / SentinelOne · Security requirement

AI governance, risk, and compliance

Source checkedStrong public support for this requirement
What the vendor says

Prompt Security claims enterprise AI and Model Context Protocol (MCP) discovery, risk scoring, policy enforcement, searchable interaction logs, role-based controls, compliance policy, drift monitoring, and human oversight for agentic systems.

Exact source quote
Get complete, searchable logs of every interaction for risk management.
Prompt Security / SentinelOne · Security requirement

AI assurance and adversarial testing

Source checkedStrong public support for this requirement
What the vendor says

Prompt Security claims automated preproduction and continuous red teaming for prompt injection, data exposure, privilege escalation, jailbreaks, unsafe agent behavior, drift, and other AI-specific risks with evidence and remediation guidance.

Exact source quote
Run pre-production red teaming, prioritize issues using risk scoring and evidence, and confidently ship production-ready AI applications.