ASAI Security ResearchIndependent public-source research
Public reviewread only

Public-source research

Vendor evidence

Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.

Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6

Showing 461–480 of 1280 evidence records

Prompt Security / SentinelOne · Security requirement

AI model and supply-chain security

Source checkedLimited public support for this requirement
What the vendor says

Prompt Security claims dynamic risk scoring of more than 13,000 Model Context Protocol (MCP) servers, vulnerability profiles, certification checks, shadow-server discovery, and agent skill integrity and drift checks.

Exact source quote
MCP risk scoring, dynamically assessing over 13,000 MCP servers on GitHub to identify emerging threats.
Prompt Security / SentinelOne · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedStrong public support for this requirement
What the vendor says

Prompt Security claims an AI and Model Context Protocol (MCP) Gateway that inspects requests, responses, prompts, templates, agent actions, and server interactions in real time with allow or block policy, threat intelligence, data loss prevention (DLP), and endpoint enforcement.

Exact source quote
Inspecting every request and response in real time to protect sensitive data and information.
Prompt Security / SentinelOne · Security requirement

AI agent identity and permissions

Source checkedLimited public support for this requirement
What the vendor says

Prompt Security claims granular policy by user, group, server, and action plus attribution of AI use, data sharing, agent responses, and Model Context Protocol (MCP) activity.

Exact source quote
Allow/block by user, server, or action according to your security policy.
Prompt Security / SentinelOne · Security requirement

AI coding-agent and workstation security

Source checkedStrong public support for this requirement
What the vendor says

Prompt Security claims endpoint and integrated development environment (IDE)-integrated governance for coding assistants, Model Context Protocol (MCP) servers, exposed commands, secrets, PII, generated code, prompt responses, and action-level policy across tools including Cursor and GitHub Copilot.

Exact source quote
Fine-grained policies that determine which MCPs are allowed, which commands can be run, and under what circumstances.
Harmonic Security · Security requirement

AI governance, risk, and compliance

Source checkedLimited public support for this requirement
What the vendor says

Harmonic claims organization-wide AI discovery, interaction visibility, team-level intent analysis, unified policy for humans and agents, governance analytics, auditability, and real-time controls across browser, desktop, embedded, and Model Context Protocol (MCP) surfaces.

Exact source quote
Every interaction visible. Every interaction governable.
Harmonic Security · Security requirement

AI assurance and adversarial testing

No supporting claim found
Research finding

Harmonic platform materials reviewed did not provide a public product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.

Harmonic Security · Security requirement

AI model and supply-chain security

No supporting claim found
Research finding

Harmonic platform materials reviewed did not establish model artifact scanning, provenance, signing, dependency analysis, Model Context Protocol (MCP) component risk scoring, tamper detection, or model-registry release controls.

Harmonic Security · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedStrong public support for this requirement
What the vendor says

Harmonic claims a locally installed Model Context Protocol (MCP) Gateway and endpoint controls that intercept Model Context Protocol (MCP) traffic, inspect prompt and tool interactions, block risky actions, prevent sensitive-data exfiltration, and apply intent-aware policy in under 200 milliseconds.

Exact source quote
Transparently intercepts all MCP traffic enabling security teams to discover what clients and servers are in use, enforce granular policies to block risky actions.
Harmonic Security · Security requirement

AI agent identity and permissions

Source checkedLimited public support for this requirement
What the vendor says

Harmonic claims a common policy plane for agents and humans with contextual, team-based controls over agent tool and server actions.

Exact source quote
Agents and humans on the same policy plane.
Harmonic Security · Security requirement

AI coding-agent and workstation security

Source checkedLimited public support for this requirement
What the vendor says

Harmonic claims device and Model Context Protocol (MCP) gateway controls for integrated development environment (IDE) coding assistants, local development environments, agent tool calls, source code, internal identifiers, infrastructure configuration, and sensitive-data flows.

Exact source quote
The ability to apply policy controls at the point where the AI agent interacts with internal systems.
Cyberhaven · Security requirement

AI governance, risk, and compliance

Source checkedLimited public support for this requirement
What the vendor says

Cyberhaven claims continuous inventory of AI agents, applications, and Model Context Protocol (MCP) servers, multidimensional AI risk scoring, data-lineage chain of custody, behavioral telemetry, and policy enforcement for autonomous systems.

Exact source quote
Continuous, automatically maintained inventory of every AI agent, GenAI application, and MCP server across your environment.
Cyberhaven · Security requirement

AI assurance and adversarial testing

No supporting claim found
Research finding

Cyberhaven AI Security materials reviewed did not provide a public product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.

Cyberhaven · Security requirement

AI model and supply-chain security

Source checkedLimited public support for this requirement
What the vendor says

Cyberhaven claims continuous inventory of agents, local models, plugins, Model Context Protocol (MCP) servers, and tools plus AI Risk IQ scoring that includes model integrity and tracks component and version changes through endpoint and data lineage context.

Exact source quote
Cyberhaven assigns an AI Risk IQ score across five dimensions: data sensitivity, model integrity, compliance adherence, user access, and security infrastructure.
Cyberhaven · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedLimited public support for this requirement
What the vendor says

Cyberhaven claims endpoint-resident runtime observability and policy enforcement across agent files, application programming interfaces (APIs), Model Context Protocol (MCP) servers, tools, outputs, and sensitive-data movement using behavioral context and data lineage.

Exact source quote
The third pillar is runtime policy enforcement.
Cyberhaven · Security requirement

AI agent identity and permissions

Source checkedLimited public support for this requirement
What the vendor says

Cyberhaven claims user and device attribution, user-access risk scoring, agent activity chain of custody, and visibility into agents operating with user permissions.

Exact source quote
Security teams can see which files were accessed, how data moved, and whether sensitive content traveled to an unexpected destination.
Cyberhaven · Security requirement

AI coding-agent and workstation security

Source checkedStrong public support for this requirement
What the vendor says

Cyberhaven claims endpoint inventory and full execution-lifecycle reconstruction for local coding agents across browsers, CLIs, integrated development environments (IDEs), files, Model Context Protocol (MCP) servers, application programming interfaces (APIs), generated outputs, and sensitive-data movement.

Exact source quote
Continuously inventories AI agents running across endpoints, browsers, command-line interfaces, and IDEs.
Nightfall AI · Security requirement

AI governance, risk, and compliance

Source checkedStrong public support for this requirement
What the vendor says

Nightfall claims agent and Model Context Protocol (MCP) inventory, user and device attribution, usage mapping, audit-ready reports, full request and response logs, approval status, and consistent generative AI governance across software as a service (SaaS), endpoints, and agentic workflows.

Exact source quote
Export audit-ready reports for compliance teams.
Nightfall AI · Security requirement

AI assurance and adversarial testing

No supporting claim found
Research finding

Nightfall Model Context Protocol (MCP) and agent security materials reviewed did not provide a public product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.

Nightfall AI · Security requirement

AI model and supply-chain security

Source checkedStrong public support for this requirement
What the vendor says

Nightfall claims a registry of more than 20,000 Model Context Protocol (MCP) servers, real-time configuration scanning, version-change monitoring, tool-capability analysis, dependency drift detection, and automatic quarantine of malicious updates before rollout.

Exact source quote
Continuous scanning flags new capabilities and auto-quarantines the update for review before rollout.
Nightfall AI · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedStrong public support for this requirement
What the vendor says

Nightfall claims protocol-level interception, full request visibility, granular server and tool control, sensitive-data detection, auto-redaction, blocking, anomaly detection, and quarantine across Model Context Protocol (MCP) prompts, files, application programming interface (API) calls, responses, and tools.

Exact source quote
Monitor every MCP tool call in real-time.