Public-source research
Vendor evidence
Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.
Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6
Showing 441–460 of 1280 evidence records
What the vendor saysAstrix claims real-time inventory of agents, Model Context Protocol (MCP) servers, and NHIs with ownership, business context, policy-at-creation, automated attestation, activity trails, and lifecycle governance.
Exact source quoteApply policy as agents are deployed to establish clear ownership and automate attestation.
Related framework references (5)
Research findingAstrix Agent Control Plane materials reviewed did not provide a public product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.
Related framework references (5)
Research findingAstrix Agent Control Plane materials reviewed did not establish model artifact scanning, provenance, signing, dependency analysis, Model Context Protocol (MCP) component vetting, tamper detection, or model-registry release controls.
Related framework references (5)
What the vendor saysAstrix claims policy-driven runtime access enforcement for agents using precisely scoped, short-lived, just-in-time credentials and pre-approved connectivity.
Exact source quoteEvery agent and workload gets policy-driven, short-lived credentials delivered with precisely scoped and just-in-time access.
Related framework references (5)
What the vendor saysAstrix claims secure agent provisioning with ownership, automated attestation, precisely scoped least privilege, short-lived credentials, just-in-time access, pre-approved policy, and per-agent audit trails.
Exact source quoteProvision secure-by-design AI agents with short-lived credentials, just-in-time, precisely scoped access, and policy at creation.
Related framework references (5)
Research findingAstrix Agent Control Plane materials reviewed did not establish governance of coding-agent commands, developer-workstation files or networks, integrated development environment (IDE) extensions, skills, hooks, secrets, or package actions.
Related framework references (5)
What the vendor saysEntro claims discovery, ownership, lineage, blast-radius mapping, approval workflow, lifecycle provisioning and offboarding, continuous policy, segregation of duties, compliance dashboards, and audit-ready reports for agents and NHIs.
Exact source quoteEvery discovered agent and identity is mapped with ownership, permissions, lineage, and blast radius.
Related framework references (5)
Research findingEntro agent and non-human identity (NHI) security materials reviewed did not provide a public product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.
Related framework references (5)
Research findingEntro agent and non-human identity (NHI) security materials reviewed did not establish model artifact scanning, provenance, signing, model dependency analysis, tamper detection, or model-registry release controls.
Related framework references (5)
What the vendor saysEntro claims real-time identity policy across agents and NHIs, just-in-time scoped access, intent monitoring, anomaly detection, and Model Context Protocol (MCP) session auditing for prompts, servers, and agent contacts.
Exact source quoteEntro’s AI Detection and Response monitors agent intent in real time, and catches threats at the identity layer.
Related framework references (5)
What the vendor saysEntro claims automated agent and non-human identity (NHI) provisioning, accountable ownership, minimum permissions, approval routing, just-in-time access, time bounds, continuous policy, access change, and offboarding.
Exact source quoteEntro extends IGA to every AI agent and NHI in your environment.
Related framework references (5)
What the vendor saysEntro claims Claude Code intent and Model Context Protocol (MCP) session auditing, endpoint discovery of local agents and Model Context Protocol (MCP) configurations, secret scanning across the SDLC, and identity context for vibe-coding access paths.
Exact source quoteThe MCP Audit plugin tracks Claude Code sessions and every MCP server each agent contacts.
Related framework references (5)
What the vendor saysAembit claims centralized agent access policy, cryptographically verifiable identity, per-request policy decisions, and audit logs tying agent identity, user identity, target server, credential, and resource access together.
Exact source quoteEvery MCP request is logged with agent identity, user identity, target server, and policy decision.
Related framework references (5)
Research findingAembit identity and access management (IAM) for Agentic AI materials reviewed did not provide a public product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.
Related framework references (5)
Research findingAembit identity and access management (IAM) for Agentic AI materials reviewed did not establish model artifact scanning, provenance, signing, dependency or Model Context Protocol (MCP) component analysis, tamper detection, or model-registry release controls.
Related framework references (5)
What the vendor saysAembit claims an Model Context Protocol (MCP) Identity Gateway that validates workload identity, enforces per-request policy, approves or denies access, exchanges credentials, and logs agent-to-resource communications.
Exact source quoteThe gateway authenticates the agent, enforces policy, and performs token exchange.
Related framework references (5)
What the vendor saysAembit claims cryptographically verified blended agent and user identity, OAuth 2.1 authorization, secure token exchange, ephemeral just-in-time credentials, least privilege, immediate revocation, and full access attribution.
Exact source quoteAembit IAM for Agentic AI assigns each agent a cryptographically verified identity, issues ephemeral credentials, enforces policy at runtime.
Related framework references (5)
Research findingAembit identity and access management (IAM) for Agentic AI materials reviewed did not establish governance of coding-agent commands, developer-workstation files or networks, integrated development environment (IDE) extensions, skills, hooks, secrets, or package actions.
Related framework references (5)
What the vendor saysPrompt Security claims enterprise AI and Model Context Protocol (MCP) discovery, risk scoring, policy enforcement, searchable interaction logs, role-based controls, compliance policy, drift monitoring, and human oversight for agentic systems.
Exact source quoteGet complete, searchable logs of every interaction for risk management.
Related framework references (5)
What the vendor saysPrompt Security claims automated preproduction and continuous red teaming for prompt injection, data exposure, privilege escalation, jailbreaks, unsafe agent behavior, drift, and other AI-specific risks with evidence and remediation guidance.
Exact source quoteRun pre-production red teaming, prioritize issues using risk scoring and evidence, and confidently ship production-ready AI applications.
Related framework references (5)