Public-source research
Vendor evidence
Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.
Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6
Aurascape claims an AI Proxy and Zero Bypass Model Context Protocol (MCP) Gateway that inspect prompts, responses, intent, tool calls, parameters, data exchanges, and results; sign approved calls; and block or sanitize policy violations before execution.
The Zero Bypass MCP Gateway signs approved tool calls and blocks unsigned ones.
Related framework references (5)
Varonis Atlas claims an AI Gateway in the live request path that inspects prompts, responses, agent actions, tool calls, Model Context Protocol (MCP) invocations, data access, and execution flows and blocks malicious, unsafe, or noncompliant behavior in real time.
Atlas enforces real-time guardrails through an AI Gateway that sits in the live request path.
Related framework references (5)
Operant claims an large language model (LLM) Gateway and Model Context Protocol (MCP) Gateway with routing, request firewall, prompt and response inspection, tool-call blocking, intent guards, data loss prevention (DLP), redaction, threat detection, rate limits, and runtime response.
Tool-call inspection and blocking with full AuthNZ enforcement.
Related framework references (5)
Tenable One AI Exposure claims detection and stopping of prompt injection and jailbreaks, containment and isolation of risky agents, policy enforcement for unsafe tools and actions, and monitoring of AI interactions and data flows.
Detect and stop AI-specific attacks such as prompt injection and jailbreak attempts, and contain risky or compromised AI agents.
Related framework references (5)
Knostic Kirin claims runtime monitoring, prompt-injection blocking, unsafe-action prevention, least-privilege policy, and consistent guardrail enforcement across software as a service (SaaS), in-house, and Model Context Protocol (MCP) agents.
Track every agentic action and stop unsafe behavior in real time.
Related framework references (5)
Onyx AI claims configurable agents with controlled Actions, data access, knowledge sources, and the ability for administrators to enable or disable Model Context Protocol (MCP) and OpenAPI actions.
Users have the flexibility to turn on or off the Actions that the Agent or LLM has access to.
Related framework references (5)
Cato AI Security claims runtime policy across user prompts, model outputs, tool calls, and tool messages, blocking or redacting sensitive data and indirect prompt injection before content reaches an agent or model.
Enforces runtime policies across all four inspection points: user prompts, model outputs, tool calls, and tool messages.
Related framework references (5)
JetStream claims inline runtime enforcement of approved AI workflow designs across agents, tools, models, Model Context Protocol (MCP) servers, data, permissions, and identities with continuous behavioral telemetry and drift response.
Enforces approved designs inline and continuously captures behavioral telemetry.
Related framework references (5)
Singulr claims real-time enforcement across AI interactions at browsers, endpoints, and agentic paths, blocking unapproved services, PII or PHI exposure, prompt injection, unauthorized exfiltration, and agent tool or system access.
Real time enforcement across agents and agentic interactions.
Related framework references (5)
Grip claims AI-specific threat detection for suspicious activity, policy violations, credential abuse, and unauthorized agent behavior with operational remediation workflows across software as a service (SaaS) and Claude environments.
AI-specific threat detection helps identify suspicious activity, policy violations, credential abuse, and unauthorized agent behavior.
Related framework references (5)
Reco claims real-time observability, policy enforcement, misuse and prompt-injection alerting, permission control, and restriction or blocking of AI agents and Model Context Protocol (MCP) paths across connected software as a service (SaaS) environments.
Reco addresses these MCP security challenges through a combination of real-time observability, policy enforcement, and automated control over permissions and tool behavior.
Related framework references (5)
Zenity claims real-time inline protection and policy enforcement over agent execution, application programming interface (API) calls, tools, prompts, memory, sensitive data, credentials, commands, and multi-step behavior across software as a service (SaaS), cloud, and endpoints.
Run-time security capabilities provide real-time, inline protection against runtime threats.
Related framework references (5)
Token Security claims behavioral monitoring, suspicious-activity alerting, runtime constraints, intent-based permission enforcement, dynamic risk response, and automated remediation for AI agents and their identities.
Automatically enforce least privilege as agent behavior and intent evolve.
Related framework references (5)
AgentWatch claims a centralized OpenAI-compatible gateway with multi-provider routing, data loss prevention (DLP), prompt screening, guardrails, blocking, authentication, role-based access, encrypted secrets, audit logs, budgets, caching, failover, and real-time policy enforcement.
One gateway. One policy layer. One source of truth.
Related framework references (5)
Credo AI claims platform and Model Context Protocol (MCP) server governance while describing CI/CD, cloud access security broker (CASB), and application programming interface (API) gateway enforcement integration as planned.
Platform & MCP Server governance
Related framework references (5)
Holistic AI claims runtime enforcement of tool allowlists, access controls, and cost limits across agents and sessions.
enforce tool-calling allowlists, access controls, and cost limits across agents and sessions
Related framework references (5)
Mindgard claims inline runtime enforcement with block, alert, and enrich actions for prompt injection, data leakage, and tool abuse.
configurable block/alert/enrich options
Related framework references (5)
Enkrypt AI claims an inline Model Context Protocol (MCP) gateway that can approve, modify, require approval for, or block tool calls and record policy decisions.
sits inline between agents and MCP servers to approve, modify, or block tool calls
Related framework references (5)
Akto claims guardrails between agents and invoked tools that inspect Model Context Protocol (MCP) calls and enforce policy in real time.
sit between your agents and the tools they invoke, enforcing enterprise policies in real time
Related framework references (5)
Okta claims centralized access policies over agent connections to Model Context Protocol (MCP) servers, application programming interfaces (APIs), and other agents.
from MCP servers to APIs and even other agents
Related framework references (5)