Public-source research
Vendor evidence
Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.
Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6
Showing 881–900 of 1280 evidence records
What the vendor saysOnyx claims fine-grained language-model provider access controls and per-team model approvals inside Onyx, which partially maps to unapproved AI control.
Exact source quoteOnyx provides fine-grained access control for language model providers, allowing administrators to control **who** can use specific models and **which agents** can use them.
Related framework references (5)
What the vendor saysOnyx claims self-hosted deployment, source-permission mirroring, and ACL sync to keep AI access aligned to existing data permissions.
Exact source quoteStrict permission controls and your data never leaves your network.
Related framework references (5)
What the vendor saysOnyx claims permission-aware connectors, document-level permissions, SCIM/IdP integration, and ACL sync for users accessing connected enterprise knowledge.
Exact source quoteEvery query respects who can see what.
Related framework references (5)
What the vendor saysOnyx provides application programming interfaces (APIs), Model Context Protocol (MCP), connectors, and custom agents for building generative AI workflows, but does not publicly claim independent large language model (LLM) application security testing.
Exact source quoteFull REST API, an MCP server, and a connector framework for custom data sources.
Related framework references (5)
What the vendor saysOnyx claims query history and usage analytics for messages and application programming interface (API)-key activity inside its agent/chat platform.
Exact source quoteOn the Query History page, you can see a log of all messages sent to Onyx.
Related framework references (5)
What the vendor saysOnyx claims controlled Model Context Protocol (MCP) actions for AI agents and admin selection of available tools, partially mapping to agent-to-tool security rather than broad agent-to-agent security.
Exact source quoteModel Context Protocol (MCP) enables AI Agents to invoke tools and services in a controlled manner.
Related framework references (5)
What the vendor saysOnyx claims application programming interface (API) keys exist as distinct users so administrators can trace activity and manage permissions for programmatic access.
Exact source quoteAPI Keys exist as distinct users in Onyx, allowing you to trace activity and manage permissions at the key level.
Related framework references (5)
What the vendor saysOnyx claims large language model (LLM) rate limits and throttling settings that can be applied globally, by user, or by user group.
Exact source quoteRate limits can be applied globally, by User, or by User Group.
Related framework references (5)
What the vendor saysOnyx publishes a Business plan price at $20 per user per month and an Enterprise plan with flexible pricing and deployment options.
Exact source quoteper user / month
Related framework references (2)
What the vendor saysOnyx positions itself as a approved enterprise AI platform alternative to ChatGPT Enterprise, Microsoft Copilot, Gemini, and Glean rather than a third-party AI security monitoring layer.
Exact source quoteWhy choose Onyx over ChatGPT, Microsoft Copilot, Google Gemini, or Glean?
Related framework references (5)
What the vendor saysCrowdStrike claims its Shadow AI Visibility Service discovers AI tools, agents, copilots, extensions, and model-connected services across endpoint, cloud, and software as a service (SaaS).
Exact source quoteCrowdStrike Shadow AI Visibility Service discovers AI tools, agents, copilots, extensions, and model-connected services operating across endpoint, cloud, and SaaS
Related framework references (5)
What the vendor saysCrowdStrike claims Falcon Shield provides visibility into AI activity across software as a service (SaaS) applications including Microsoft 365, ChatGPT Enterprise, and Snowflake.
Exact source quoteprovides visibility into AI activity across SaaS applications like Microsoft 365, ChatGPT Enterprise, and Snowflake.
Related framework references (5)
What the vendor saysCrowdStrike claims it protects employee adoption of generative AI tools through a single sensor and console.
Exact source quoteProtect employee adoption of GenAI tools, managed through a single sensor and console.
Related framework references (5)
What the vendor saysCrowdStrike claims it can block unauthorized AI access and topics while masking or encrypting sensitive data before exposure.
Exact source quoteBlock unauthorized access and topics or mask or encrypt sensitive data before exposure
Related framework references (5)
What the vendor saysCrowdStrike claims it can prevent sensitive data from being shared with users, models, agents, or external AI systems.
Exact source quotePrevent sensitive data from being shared with users, models, agents, or external AI systems.
Related framework references (5)
What the vendor saysCrowdStrike claims Falcon Fusion SOAR can disable misbehaving software as a service (SaaS) agents or users via application programming interface (API) while opening tickets.
Exact source quoteWith Falcon Fusion SOAR, it can disable misbehaving agents or users via API while simultaneously opening tickets to ensure accountability and resolution.
Related framework references (5)
What the vendor saysCrowdStrike claims it can detect and stop direct and indirect prompt injection, unsafe content, and attempted model manipulation in real time.
Exact source quoteDetect and stop direct and indirect prompt injection, unsafe content, and attempted model manipulation in real time.
Related framework references (5)
What the vendor saysCrowdStrike claims Falcon Shield identifies hidden agents, maps their usage and access, detects risky behavior, and enables containment.
Exact source quoteIt identifies hidden agents, maps their usage and access, detects risky behavior, and enables containment through Falcon Fusion SOAR.
Related framework references (5)
What the vendor saysCrowdStrike claims its AIDR, Agentic SOAR workflow controls, and AgentWorks guardrails secure agent-to-agent and analyst-to-agent collaboration.
Exact source quotenative AI Detection and Response (AIDR), Agentic SOAR workflow level controls, and AgentWorks guardrails secure agent-to-agent and analyst-to-agent collaboration.
Related framework references (5)
What the vendor saysCrowdStrike claims Continuous Identity for AI Agents eliminates standing privileges and verifies trust for every agent action.
Exact source quoteContinuous Identity for AI Agents introduces a model that eliminates standing privileges and immediately verifies trust for every agent action.
Related framework references (5)