ASAI Security ResearchIndependent public-source research
Public reviewread only

Public-source research

Vendor evidence

Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.

Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6

Showing 601–620 of 1280 evidence records

Entro Security · Security requirement

AI cost and usage controls

No supporting claim found
Research finding

Entro Security platform materials reviewed did not provide a public product claim for AI usage-cost attribution, token or spend metrics, budgets, chargeback, or cost-aware model routing.

Netskope AI Security · Security requirement

Licensing model

Source checkedStrong public support for this requirement
What the vendor says

Netskope documents AI Gateway as a subscription licensed by gateway instances and monthly transaction allocations, with separate tenant entitlements and add-on packages for more gateways or transactions.

Exact source quote
Each Subscription Unit entitles the Customer to one Gateway instance and a fixed allocation of Transactions per calendar month.
Palo Alto Networks Prisma AIRS · Security requirement

Licensing model

Source checkedStrong public support for this requirement
What the vendor says

Palo Alto Networks documents Prisma AIRS as bring-your-own-license funded through Software NGFW credits, with runtime firewall capacity based on instances and vCPUs and runtime application programming interface (API) usage measured in monthly token allocations.

Exact source quote
Prisma AIRS uses a bring-your-own license (BYOL) model.
Zscaler AI Security · Security requirement

Licensing model

Source checkedStrong public support for this requirement
What the vendor says

Zscaler documents AI Guard as a software as a service (SaaS) subscription with a platform fee and purchased token allocation for the subscription term, with additional tokens ordered through sales or a channel partner.

Exact source quote
AI Guard is a Software as a Service product licensed based on a platform subscription fee and the number of tokens purchased.
Cisco AI Defense · Security requirement

Licensing model

Source checkedStrong public support for this requirement
What the vendor says

Cisco documents AI Defense as a software subscription offered in packages, including an AI Validation package, with ordering quantities and software subscription terms defined in official offer and ordering materials.

Exact source quote
If You purchase an AI Defense subscription package with AI Validation
Microsoft Purview DSPM for AI · Security requirement

Licensing model

Source checkedStrong public support for this requirement
What the vendor says

Microsoft documents data security posture management (DSPM) access through Microsoft 365 E5 or Microsoft Purview Suite, while managing some AI-agent interactions can additionally require pay-as-you-go billing.

Exact source quote
To access and use DSPM, you need a Microsoft 365 E5 or Microsoft Purview Suite license.
Noma Security · Security requirement

Unapproved AI use discovery

Source checkedStrong public support for this requirement
What the vendor says

Noma claims it discovers, governs, and protects enterprise AI and agents across homegrown AI, software as a service (SaaS) agents, and coding assistants.

Exact source quote
Noma discovers, governs, and protects AI and Agents across the enterprise, from homegrown AI to SaaS agents and coding assistants.
Noma Security · Security requirement

AI-feature discovery in business applications

Source checkedStrong public support for this requirement
What the vendor says

Noma claims coverage for commercial AI and software as a service (SaaS) agent platforms already embedded in workflows, including major enterprise agent platforms.

Exact source quote
Extend coverage to commercial AI and agent platforms already embedded in your workflows. Native integrations with Microsoft Copilot Studio, Salesforce AgentForce, ServiceNow, and 80+ other. Agentless deployment, with no code changes required.
Noma Security · Security requirement

Sensitive-data protection for generative AI

Source checkedStrong public support for this requirement
What the vendor says

Noma claims runtime privacy policies can prevent sensitive data from leaving the environment during AI usage.

Exact source quote
Privacy policies block sensitive data from leaving your environment.
Noma Security · Security requirement

Generative AI application security

Source checkedStrong public support for this requirement
What the vendor says

Noma claims it can discover, test, and protect custom AI applications and agents through application programming interfaces (APIs), SDKs, and centralized gateway enforcement.

Exact source quote
Discover, test, and protect custom-built AI applications and agents through our REST API, native Python and JavaScript SDKs for frameworks like LangChain and CrewAI, or our centralized gateway for unified policy enforcement.
Noma Security · Security requirement

Action-taking agent monitoring

Source checkedStrong public support for this requirement
What the vendor says

Noma claims discovery provides visibility and context across models, agents, Model Context Protocol (MCP) servers, data sources, and their dependency chains.

Exact source quote
Discovery provides visibility and deep context for your entire AI landscape: every model, every agent, every MCP server, every data source, and crucially, how they all connect.
Noma Security · Security requirement

Agent-to-agent communication security

Source checkedStrong public support for this requirement
What the vendor says

Noma claims it can monitor AI and agentic communication in real time and enforce runtime policies.

Exact source quote
See all AI and agentic communication as it happens and enforce policies at runtime.
Noma Security · Security requirement

Non-human identity and service-account security

Source checkedLimited public support for this requirement
What the vendor says

Noma claims it supports identity and access controls for AI applications and agents as part of pre-deployment boundaries.

Exact source quote
setting proper identity and access controls for every AI application and agent
JetStream Security · Security requirement

Unapproved AI use discovery

Source checkedStrong public support for this requirement
What the vendor says

JetStream claims AI Visibility continuously discovers and inventories AI agents, models, tools, and workflows across software as a service (SaaS), endpoints, cloud, application programming interfaces (APIs), and internal systems.

Exact source quote
Continuously discover and inventory AI agents, models, tools, and workflows across SaaS, endpoints, cloud, APIs, and internal systems.
JetStream Security · Security requirement

AI-feature discovery in business applications

Source checkedStrong public support for this requirement
What the vendor says

JetStream claims it can uncover shadow AI and inventory AI agents, models, tools, and workflows across software as a service (SaaS), endpoints, cloud, application programming interfaces (APIs), and internal systems.

Exact source quote
Uncover shadow AI. Continuously discover and inventory AI agents, models, tools, and workflows across SaaS, endpoints, cloud, APIs, and internal systems.
JetStream Security · Security requirement

Approved AI usage monitoring

Source checkedStrong public support for this requirement
What the vendor says

JetStream claims it lets organizations see every AI action, tie actions to accountable owners, and keep workflows within approved boundaries.

Exact source quote
See every AI action, tie actions to accountable owners, keep workflows inside approved boundaries, and turn AI from a black box into a managed system.
JetStream Security · Security requirement

Controls for unapproved AI use

Source checkedStrong public support for this requirement
What the vendor says

JetStream claims Runtime Governance enforces operational and security guardrails and lets teams approve changes or stop runs when behavior varies from an approved Blueprint.

Exact source quote
JetStream watches live AI activity and compares that to the approved design within each AI Blueprint. It enforces operational and security guardrails, records evidence, and flags drift from each workflow’s operational contract the moment behavior varies from the Blueprint. Teams can approve the change or stop the run—without losing auditability.
JetStream Security · Security requirement

Action-taking agent monitoring

Source checkedStrong public support for this requirement
What the vendor says

JetStream claims Design Control maps agents, models, tools, datasets, and identities and how they interact, then compares intended design to runtime reality as systems evolve.

Exact source quote
Design Control turns raw discovery into an approved design by mapping how your AI actually works—agents, models, tools, datasets, and identities—and how they interact. It becomes a living operational contract with versioning and change control, so teams can document intent and compare it to reality as systems evolve.
JetStream Security · Security requirement

Agent-to-agent communication security

Source checkedLimited public support for this requirement
What the vendor says

JetStream claims least-privilege authorization travels with workflows across agent hand-offs and keeps behavior inside approved designs.

Exact source quote
Least‑privilege, just‑in‑time authorization travels with the workflow across agent hand‑offs, keeping behavior inside the approved design.
JetStream Security · Security requirement

Non-human identity and service-account security

Source checkedStrong public support for this requirement
What the vendor says

JetStream claims every AI workflow is tied to a provable owner by binding people, agents, NHIs, and model usage into an accountable identity fabric.

Exact source quote
Every AI workflow is tied to a provable owner by binding people, agents, NHIs, and model usage into one accountable identity fabric. Raw model provider secrets are replaced with virtual, revocable keys scoped to the approved Blueprint design, so you can rotate, rate‑limit, or kill access without code changes.