ASAI Security ResearchIndependent public-source research
Public reviewread only

Public-source research

Vendor evidence

Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.

Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6

Showing 561–580 of 1280 evidence records

Zenity · Security requirement

AI governance, risk, and compliance

Source checkedStrong public support for this requirement
What the vendor says

Zenity claims continuous discovery, inventory, ownership, configuration, permission, dependency, behavior, policy, posture, graph, incident, and audit governance across software as a service (SaaS)-managed, home-grown, and device-based AI agents.

Exact source quote
Security teams gain clear visibility into agent ownership, configurations, permissions, dependencies, and runtime behavior.
Zenity · Security requirement

AI assurance and adversarial testing

No supporting claim found
Research finding

Zenity platform materials reviewed did not provide a public customer-facing product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.

Zenity · Security requirement

AI model and supply-chain security

Source checkedLimited public support for this requirement
What the vendor says

Zenity claims pre-session evaluation of Claude configurations, Model Context Protocol (MCP) servers, skills, plugins, and agent extensions plus dependency and attack-path mapping across agents, tools, knowledge, automations, triggers, and actions.

Exact source quote
Zenity evaluates Claude configuration, MCP servers, skills, plugins, and other agent extensions before sessions begin.
Zenity · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedStrong public support for this requirement
What the vendor says

Zenity claims real-time inline protection and policy enforcement over agent execution, application programming interface (API) calls, tools, prompts, memory, sensitive data, credentials, commands, and multi-step behavior across software as a service (SaaS), cloud, and endpoints.

Exact source quote
Run-time security capabilities provide real-time, inline protection against runtime threats.
Zenity · Security requirement

AI agent identity and permissions

Source checkedLimited public support for this requirement
What the vendor says

Zenity claims ownership, identity relationship, permission, tool-access, and execution-path mapping with policy enforcement against over-privileged agents, unauthorized application programming interface (API) calls, restricted-data access, and privilege escalation.

Exact source quote
Know which agents exist, who owns them, what they can access, and how they behave across your environment.
Zenity · Security requirement

AI coding-agent and workstation security

Source checkedStrong public support for this requirement
What the vendor says

Zenity claims lifecycle visibility, posture evaluation, and runtime enforcement for Claude Code and device-based coding agents across code changes, commits, pull requests, configurations, Model Context Protocol (MCP) servers, skills, plugins, commands, credentials, files, tools, and memory.

Exact source quote
Zenity's agent security platform deliver[s] full-lifecycle visibility, posture management, and runtime enforcement across Claude Code, Cowork, and Chat.
Token Security · Security requirement

AI governance, risk, and compliance

Source checkedStrong public support for this requirement
What the vendor says

Token Security claims lifecycle governance for AI agents with continuous discovery, ownership, intent, access, policy, compliance validation, audit trails, behavioral monitoring, and automated remediation from creation through retirement.

Exact source quote
Token Security unifies Visibility, Control, and Governance into a single platform purpose-built for AI agents and non-human identities.
Token Security · Security requirement

AI assurance and adversarial testing

No supporting claim found
Research finding

Token Security product materials reviewed did not provide a public product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.

Token Security · Security requirement

AI model and supply-chain security

No supporting claim found
Research finding

Token Security product materials reviewed did not establish model artifact scanning, provenance, signing, dependency or Model Context Protocol (MCP) component analysis, tamper detection, or model-registry release controls.

Token Security · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedLimited public support for this requirement
What the vendor says

Token Security claims behavioral monitoring, suspicious-activity alerting, runtime constraints, intent-based permission enforcement, dynamic risk response, and automated remediation for AI agents and their identities.

Exact source quote
Automatically enforce least privilege as agent behavior and intent evolve.
Token Security · Security requirement

AI agent identity and permissions

Source checkedStrong public support for this requirement
What the vendor says

Token Security claims discovery and lifecycle control for agent identities, owners, intent, credentials, tokens, roles, permissions, access paths, behavioral baselines, access reviews, least-privilege enforcement, remediation, and deprovisioning.

Exact source quote
Token Security helps teams manage the full AI agent identity lifecycle.
Token Security · Security requirement

AI coding-agent and workstation security

Source checkedLimited public support for this requirement
What the vendor says

Token Security claims discovery and governance of coding agents, custom GPTs, Model Context Protocol (MCP) servers, cloud and software as a service (SaaS) access, credentials, permissions, owners, intent, activity, and least-privilege boundaries.

Exact source quote
Token automatically discovers and inventories every AI agent, custom GPT, coding agent, MCP server, and non-human identity.
Iterate.ai AgentWatch · Security requirement

AI governance, risk, and compliance

Source checkedStrong public support for this requirement
What the vendor says

Iterate.ai claims centralized policy, observability, compliance controls, audit trails, data classification, retention, cost governance, and usage visibility across employees, applications, business agents, coding agents, models, and providers.

Exact source quote
Monitor and govern models and agents with policy enforcement, audit trails, and cost controls.
Iterate.ai AgentWatch · Security requirement

AI assurance and adversarial testing

No supporting claim found
Research finding

Iterate.ai AgentWatch and AgentOne materials reviewed did not provide a public product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.

Iterate.ai AgentWatch · Security requirement

AI model and supply-chain security

Source checkedLimited public support for this requirement
What the vendor says

Iterate.ai claims repository indexing and code analysis for Model Context Protocol (MCP)-connected workflows with optional Semgrep and Trivy security scanning, dependency management, and Model Context Protocol (MCP) server installation and configuration controls.

Exact source quote
Integrated MCP server for repository indexing and code analysis (Tree-sitter), plus optional security scanning (Semgrep, Trivy).
Iterate.ai AgentWatch · Security requirement

AI gateway, tool-connection, and runtime controls

Source checkedStrong public support for this requirement
What the vendor says

AgentWatch claims a centralized OpenAI-compatible gateway with multi-provider routing, data loss prevention (DLP), prompt screening, guardrails, blocking, authentication, role-based access, encrypted secrets, audit logs, budgets, caching, failover, and real-time policy enforcement.

Exact source quote
One gateway. One policy layer. One source of truth.
Iterate.ai AgentWatch · Security requirement

AI agent identity and permissions

Source checkedLimited public support for this requirement
What the vendor says

AgentWatch claims JWT authentication, role-based access control, organization and team hierarchies, encrypted application programming interface (API)-key management, user and device attribution, correlated request logs, and policy status across business and coding agents.

Exact source quote
Built-In Enterprise Security: encrypted API keys at rest, JWT authentication and role-based access control, comprehensive audit logging for every operation.
Iterate.ai AgentWatch · Security requirement

AI coding-agent and workstation security

Source checkedStrong public support for this requirement
What the vendor says

Iterate.ai claims a private coding-agent environment with code privacy, security review, activity audit, human approval for file changes, Git checkpoints, diff review, repository indexing, Semgrep and Trivy scanning, dependency management, and Model Context Protocol (MCP) server controls.

Exact source quote
The platform prevents proprietary source code exposure, provides governance for AI-generated code, tracks all AI development activity for audit purposes, and enables security teams to review generated code before deployment.
WitnessAI · Security requirement

AI cost and usage controls

Source checkedLimited public support for this requirement
What the vendor says

WitnessAI claims AI-interaction visibility and attribution, intent-based policies that consider risk, cost, and purpose, model routing based on cost, and audit trails supporting financial accountability.

Exact source quote
It applies intent-based machine learning engines and intelligent policies that account for risk, cost, and purpose together.
Apex Security / Tenable · Security requirement

AI cost and usage controls

No supporting claim found
Research finding

Tenable AI Exposure and AI-SPM materials reviewed did not provide a public product claim for AI usage-cost attribution, token or spend metrics, budgets, chargeback, or cost-aware model routing.