ASAI Security ResearchIndependent public-source research
Public reviewread only

Public-source research

Vendor evidence

Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.

Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6

Showing 521–540 of 1280 evidence records

Knostic · Security requirement

AI model and supply-chain security

Source checkedStrong public support for this requirement
What the vendor says

Knostic AgentMesh claims continuous discovery, version tracking, SHA-256 artifact identification, static-code scanning, and risk analysis for AI agent skills, Model Context Protocol (MCP) servers, integrated development environment (IDE) extensions, Claude Code plugins, and commands.

Exact source quote
Continuously discovers, tracks, and scans AI agent skills, MCP servers, and IDE extensions for prompt injection and supply chain threats.
Knostic · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedStrong public support for this requirement
What the vendor says

Knostic Kirin claims runtime monitoring, prompt-injection blocking, unsafe-action prevention, least-privilege policy, and consistent guardrail enforcement across software as a service (SaaS), in-house, and Model Context Protocol (MCP) agents.

Exact source quote
Track every agentic action and stop unsafe behavior in real time.
Knostic · Security requirement

AI agent identity and permissions

Source checkedLimited public support for this requirement
What the vendor says

Knostic claims OAuth-based agent authentication, agent-role to privilege mapping, least-privilege and need-to-know boundaries, and policy enforcement across software as a service (SaaS), in-house, and Model Context Protocol (MCP) agents.

Exact source quote
Map agent roles to privileges and enforce need-to-know boundaries.
Knostic · Security requirement

AI coding-agent and workstation security

Source checkedStrong public support for this requirement
What the vendor says

Knostic claims endpoint guardrails plus AgentMesh scanning for coding assistants, Claude and Cursor skills, Model Context Protocol (MCP) servers, integrated development environment (IDE) extensions, plugins, commands, code injection, cryptomining, reverse shells, and other agentic supply-chain threats.

Exact source quote
Scan skills, MCP servers, and extensions before they touch your agents.
Onyx AI · Security requirement

AI governance, risk, and compliance

Source checkedLimited public support for this requirement
What the vendor says

Onyx AI claims a approved self-hosted enterprise AI platform with organization and group sharing, permissions, usage analytics, model controls, auditability, and governed access to enterprise knowledge and actions.

Exact source quote
Give your team an approved AI platform that actually works, so they stop pasting company data into ChatGPT.
Onyx AI · Security requirement

AI assurance and adversarial testing

No supporting claim found
Research finding

Onyx AI materials reviewed did not provide a public product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.

Onyx AI · Security requirement

AI model and supply-chain security

No supporting claim found
Research finding

Onyx AI materials reviewed did not establish model artifact scanning, provenance, signing, dependency or Model Context Protocol (MCP) component analysis, tamper detection, or model-registry release controls.

Onyx AI · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedLimited public support for this requirement
What the vendor says

Onyx AI claims configurable agents with controlled Actions, data access, knowledge sources, and the ability for administrators to enable or disable Model Context Protocol (MCP) and OpenAPI actions.

Exact source quote
Users have the flexibility to turn on or off the Actions that the Agent or LLM has access to.
Onyx AI · Security requirement

AI agent identity and permissions

Source checkedLimited public support for this requirement
What the vendor says

Onyx AI claims organization and group-based agent sharing plus configurable knowledge and action permissions for enterprise agents.

Exact source quote
Publish your Agent to your entire organization or share it with specific users or groups.
Onyx AI · Security requirement

AI coding-agent and workstation security

No supporting claim found
Research finding

Onyx AI materials reviewed did not establish governance of coding-agent commands, developer-workstation files or networks, integrated development environment (IDE) extensions, skills, hooks, secrets, or package actions.

AIM Security / Cato Networks · Security requirement

AI governance, risk, and compliance

Source checkedLimited public support for this requirement
What the vendor says

Cato AI Security claims discovery and inventory of managed, local, and shadow agents, centralized runtime visibility, security posture, compliance-risk remediation, and corporate policy across users, agents, applications, models, and tools.

Exact source quote
Gain visibility into which agents exist, what data sources and tools they can access, and how they behave at runtime.
AIM Security / Cato Networks · Security requirement

AI assurance and adversarial testing

No supporting claim found
Research finding

Cato AI Security and AIM materials reviewed did not provide a public customer-facing product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.

AIM Security / Cato Networks · Security requirement

AI model and supply-chain security

Source checkedLimited public support for this requirement
What the vendor says

Cato and AIM claim continuous AI-SPM scanning of internal models, agent configurations, Model Context Protocol (MCP) connections, training environments, misconfigurations, and vulnerabilities before production.

Exact source quote
Continuously discovers, detects, and remediates AI security and compliance risks before they reach production, and scans internal AI models for misconfigurations and vulnerabilities.
AIM Security / Cato Networks · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedStrong public support for this requirement
What the vendor says

Cato AI Security claims runtime policy across user prompts, model outputs, tool calls, and tool messages, blocking or redacting sensitive data and indirect prompt injection before content reaches an agent or model.

Exact source quote
Enforces runtime policies across all four inspection points: user prompts, model outputs, tool calls, and tool messages.
AIM Security / Cato Networks · Security requirement

AI agent identity and permissions

Source checkedLimited public support for this requirement
What the vendor says

Cato AI Security claims visibility into agent configurations, licenses, data and tool access, plus corporate policy enforcement and blocking of unauthorized access or unsafe actions across managed and local agents.

Exact source quote
Reduce the risk of unauthorized access, sensitive data exposure, and unsafe agent actions.
AIM Security / Cato Networks · Security requirement

AI coding-agent and workstation security

Source checkedStrong public support for this requirement
What the vendor says

Cato claims endpoint discovery and runtime control for Cursor, Claude Code, and other coding agents, covering configurations, licenses, Model Context Protocol (MCP) servers, prompts, model outputs, tool calls, tool messages, credentials, PII, and malicious tool responses.

Exact source quote
Discover and secure AI agents that run on user endpoints, such as coding agents.
JetStream Security · Security requirement

AI governance, risk, and compliance

Source checkedStrong public support for this requirement
What the vendor says

JetStream SAIG claims AI estate discovery, approved design control, accountable ownership, runtime governance, drift detection, audit-ready evidence, policy boundaries, and cost accountability across humans, agents, NHIs, models, tools, Model Context Protocol (MCP), software as a service (SaaS), and cloud.

Exact source quote
Every AI action is attributed to accountable owners and kept inside approved boundaries.
JetStream Security · Security requirement

AI assurance and adversarial testing

No supporting claim found
Research finding

JetStream SAIG materials reviewed did not provide a public product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.

JetStream Security · Security requirement

AI model and supply-chain security

Source checkedLimited public support for this requirement
What the vendor says

JetStream claims visibility into model swaps, toolchain expansion, Model Context Protocol (MCP) servers, open-source components, configurations, credentials, permissions, connections, and runtime drift with Verified Model Context Protocol (MCP) and approved-design governance.

Exact source quote
Surface model changes, new MCP usage, and behavioral deviations the moment they occur.
JetStream Security · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedStrong public support for this requirement
What the vendor says

JetStream claims inline runtime enforcement of approved AI workflow designs across agents, tools, models, Model Context Protocol (MCP) servers, data, permissions, and identities with continuous behavioral telemetry and drift response.

Exact source quote
Enforces approved designs inline and continuously captures behavioral telemetry.