ASAI Security ResearchIndependent public-source research
Public reviewread only

Public-source research

Vendor evidence

Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.

Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6

Showing 541–560 of 1280 evidence records

JetStream Security · Security requirement

AI agent identity and permissions

Source checkedStrong public support for this requirement
What the vendor says

JetStream claims an accountable identity fabric binding humans, agents, service accounts, and models with short-lived identity-scoped keys, ownership attribution, permission monitoring, and runtime enforcement.

Exact source quote
Bind every AI action to an accountable identity using short-lived, identity-scoped keys.
JetStream Security · Security requirement

AI coding-agent and workstation security

Source checkedLimited public support for this requirement
What the vendor says

JetStream claims endpoint scanning for AI applications, Model Context Protocol (MCP) servers, cleartext keys, configuration artifacts, coding-assistant toolchains, permissions, and runtime actions with identity attribution and approved-design enforcement.

Exact source quote
The scanner looks throughout user directories to identify AI apps, MCP servers, cleartext API and license keys, and other AI artifacts.
Singulr AI · Security requirement

AI governance, risk, and compliance

Source checkedStrong public support for this requirement
What the vendor says

Singulr claims policy authoring, ownership, risk thresholds, compliance scoring, lifecycle risk records, dataset licensing validation, agent topology and drift, and closed-loop governance across clouds, software as a service (SaaS), agents, models, data, and tools.

Exact source quote
Define enforceable intent, ownership, and risk thresholds across AI systems and agents.
Singulr AI · Security requirement

AI assurance and adversarial testing

Source checkedStrong public support for this requirement
What the vendor says

Singulr claims continuous, application-aware AI red teaming against OWASP large language model (LLM), NIST, and MITRE scenarios integrated into CI/CD.

Exact source quote
Application-aware AI red teaming runs continuously against OWASP LLM Top 10, NIST, and MITRE scenarios, built into CI/CD.
Singulr AI · Security requirement

AI model and supply-chain security

Source checkedLimited public support for this requirement
What the vendor says

Singulr claims dataset licensing validation, agent dependency topology, model and tool connection mapping, Model Context Protocol (MCP) configuration risk, Model Context Protocol (MCP) server vulnerability scanning, and continuous model and control drift monitoring.

Exact source quote
MCP server vulnerability scanning.
Singulr AI · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedStrong public support for this requirement
What the vendor says

Singulr claims real-time enforcement across AI interactions at browsers, endpoints, and agentic paths, blocking unapproved services, PII or PHI exposure, prompt injection, unauthorized exfiltration, and agent tool or system access.

Exact source quote
Real time enforcement across agents and agentic interactions.
Singulr AI · Security requirement

AI agent identity and permissions

Source checkedLimited public support for this requirement
What the vendor says

Singulr claims agent discovery, ownership and intent, topology and permission mapping, enforceable boundaries based on agent type, data sensitivity, tool access, and scope, plus runtime restriction of unauthorized system access.

Exact source quote
Define enforceable policies based on agent type, data sensitivity, tool access, and scope.
Singulr AI · Security requirement

AI coding-agent and workstation security

Source checkedLimited public support for this requirement
What the vendor says

Singulr claims browser and endpoint enforcement, agent discovery, Model Context Protocol (MCP) server vulnerability scanning, tool and permission mapping, data-loss prevention, CI/CD red teaming, and runtime controls across agentic execution paths.

Exact source quote
Browser and Endpoint Enforcement with Agent Permission Boundaries.
Grip Security · Security requirement

AI governance, risk, and compliance

Source checkedStrong public support for this requirement
What the vendor says

Grip claims centralized discovery and governance for AI applications, tenants, users, agents, Model Context Protocol (MCP) servers, prompts, activity, application programming interface (API) keys, integrations, permissions, posture, policy violations, remediation, and compliance workflows.

Exact source quote
Transforms that data into actionable insights across discovery, posture management, AI governance, and threat detection.
Grip Security · Security requirement

AI assurance and adversarial testing

No supporting claim found
Research finding

Grip AI and software as a service (SaaS) security materials reviewed did not provide a public product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.

Grip Security · Security requirement

AI model and supply-chain security

No supporting claim found
Research finding

Grip AI and software as a service (SaaS) security materials reviewed did not establish model artifact scanning, provenance, signing, dependency or Model Context Protocol (MCP) component analysis, tamper detection, or model-registry release controls.

Grip Security · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedLimited public support for this requirement
What the vendor says

Grip claims AI-specific threat detection for suspicious activity, policy violations, credential abuse, and unauthorized agent behavior with operational remediation workflows across software as a service (SaaS) and Claude environments.

Exact source quote
AI-specific threat detection helps identify suspicious activity, policy violations, credential abuse, and unauthorized agent behavior.
Grip Security · Security requirement

AI agent identity and permissions

Source checkedLimited public support for this requirement
What the vendor says

Grip claims discovery and posture analysis for AI agents as non-human identities, including permissions, authentication, OAuth grants, application programming interface (API) keys, service accounts, access scopes, machine identities, and connected applications.

Exact source quote
Security teams need visibility into AI agents, permissions, OAuth grants, and machine identities operating across SaaS environments.
Grip Security · Security requirement

AI coding-agent and workstation security

Source checkedLimited public support for this requirement
What the vendor says

Grip claims visibility into Claude desktop, browser, agents, Model Context Protocol (MCP) servers, prompts, application programming interface (API) keys, connected tools, and developer workflows that generate code and automate tasks.

Exact source quote
Visibility into desktop installations, browser based activity, connected MCP servers, AI agents, administrative API keys, and other non human identities.
Reco · Security requirement

AI governance, risk, and compliance

Source checkedStrong public support for this requirement
What the vendor says

Reco claims continuous inventory, ownership and permission mapping, policy enforcement, audit visibility, posture assessment, and governance for approved and shadow AI agents across software as a service (SaaS) environments.

Exact source quote
The platform automatically inventories every AI agent operating across your connected SaaS applications.
Reco · Security requirement

AI assurance and adversarial testing

No supporting claim found
Research finding

Reco AI agent and Model Context Protocol (MCP) security materials reviewed did not provide a public product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.

Reco · Security requirement

AI model and supply-chain security

Source checkedLimited public support for this requirement
What the vendor says

Reco claims discovery and mapping of Model Context Protocol (MCP) servers, tools, external integrations, OAuth grants, application programming interface (API) connections, data paths, scopes, and unauthorized trust relationships across AI agents and software as a service (SaaS) applications.

Exact source quote
Reco makes them visible, showing exactly which systems are connected, what data flows between them, and where permission breakdowns exist.
Reco · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedLimited public support for this requirement
What the vendor says

Reco claims real-time observability, policy enforcement, misuse and prompt-injection alerting, permission control, and restriction or blocking of AI agents and Model Context Protocol (MCP) paths across connected software as a service (SaaS) environments.

Exact source quote
Reco addresses these MCP security challenges through a combination of real-time observability, policy enforcement, and automated control over permissions and tool behavior.
Reco · Security requirement

AI agent identity and permissions

Source checkedLimited public support for this requirement
What the vendor says

Reco claims mapping of each AI agent to authorizing users, connected applications, OAuth grants, application programming interface (API) identities, permissions, data access, ownership, and policy status with least-privilege controls.

Exact source quote
For each agent, Reco maps which SaaS applications it connects to, what permissions it holds, who authorized it, and what data it can access.
Reco · Security requirement

AI coding-agent and workstation security

Source checkedLimited public support for this requirement
What the vendor says

Reco claims discovery of coding agents and their Model Context Protocol (MCP), software as a service (SaaS), repository, OAuth, permission, identity, and data relationships, including Cursor connections to GitHub and other enterprise applications.

Exact source quote
An MCP server created a connection between Slack and Cursor, producing a permissions breakdown where two applications share a trust relationship.