ASAI Security ResearchIndependent public-source research
Public reviewread only

Public-source research

Vendor evidence

Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.

Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6

Showing 881–900 of 1280 evidence records

Onyx AI · Security requirement

Controls for unapproved AI use

Source checkedLimited public support for this requirement
What the vendor says

Onyx claims fine-grained language-model provider access controls and per-team model approvals inside Onyx, which partially maps to unapproved AI control.

Exact source quote
Onyx provides fine-grained access control for language model providers, allowing administrators to control **who** can use specific models and **which agents** can use them.
Onyx AI · Security requirement

Sensitive-data protection for generative AI

Source checkedLimited public support for this requirement
What the vendor says

Onyx claims self-hosted deployment, source-permission mirroring, and ACL sync to keep AI access aligned to existing data permissions.

Exact source quote
Strict permission controls and your data never leaves your network.
Onyx AI · Security requirement

Browser and business-application controls

Source checkedLimited public support for this requirement
What the vendor says

Onyx claims permission-aware connectors, document-level permissions, SCIM/IdP integration, and ACL sync for users accessing connected enterprise knowledge.

Exact source quote
Every query respects who can see what.
Onyx AI · Security requirement

Generative AI application security

Source checkedRelated public context only
What the vendor says

Onyx provides application programming interfaces (APIs), Model Context Protocol (MCP), connectors, and custom agents for building generative AI workflows, but does not publicly claim independent large language model (LLM) application security testing.

Exact source quote
Full REST API, an MCP server, and a connector framework for custom data sources.
Onyx AI · Security requirement

Action-taking agent monitoring

Source checkedLimited public support for this requirement
What the vendor says

Onyx claims query history and usage analytics for messages and application programming interface (API)-key activity inside its agent/chat platform.

Exact source quote
On the Query History page, you can see a log of all messages sent to Onyx.
Onyx AI · Security requirement

Agent-to-agent communication security

Source checkedLimited public support for this requirement
What the vendor says

Onyx claims controlled Model Context Protocol (MCP) actions for AI agents and admin selection of available tools, partially mapping to agent-to-tool security rather than broad agent-to-agent security.

Exact source quote
Model Context Protocol (MCP) enables AI Agents to invoke tools and services in a controlled manner.
Onyx AI · Security requirement

Non-human identity and service-account security

Source checkedLimited public support for this requirement
What the vendor says

Onyx claims application programming interface (API) keys exist as distinct users so administrators can trace activity and manage permissions for programmatic access.

Exact source quote
API Keys exist as distinct users in Onyx, allowing you to trace activity and manage permissions at the key level.
Onyx AI · Security requirement

AI cost and usage controls

Source checkedLimited public support for this requirement
What the vendor says

Onyx claims large language model (LLM) rate limits and throttling settings that can be applied globally, by user, or by user group.

Exact source quote
Rate limits can be applied globally, by User, or by User Group.
Onyx AI · Security requirement

Licensing model

Source checkedStrong public support for this requirement
What the vendor says

Onyx publishes a Business plan price at $20 per user per month and an Enterprise plan with flexible pricing and deployment options.

Exact source quote
per user / month
Onyx AI · Security requirement

Approved AI platform context

Source checkedStrong public support for this requirement
What the vendor says

Onyx positions itself as a approved enterprise AI platform alternative to ChatGPT Enterprise, Microsoft Copilot, Gemini, and Glean rather than a third-party AI security monitoring layer.

Exact source quote
Why choose Onyx over ChatGPT, Microsoft Copilot, Google Gemini, or Glean?
CrowdStrike AI Security · Security requirement

Unapproved AI use discovery

Source checkedStrong public support for this requirement
What the vendor says

CrowdStrike claims its Shadow AI Visibility Service discovers AI tools, agents, copilots, extensions, and model-connected services across endpoint, cloud, and software as a service (SaaS).

Exact source quote
CrowdStrike Shadow AI Visibility Service discovers AI tools, agents, copilots, extensions, and model-connected services operating across endpoint, cloud, and SaaS
CrowdStrike AI Security · Security requirement

AI-feature discovery in business applications

Source checkedStrong public support for this requirement
What the vendor says

CrowdStrike claims Falcon Shield provides visibility into AI activity across software as a service (SaaS) applications including Microsoft 365, ChatGPT Enterprise, and Snowflake.

Exact source quote
provides visibility into AI activity across SaaS applications like Microsoft 365, ChatGPT Enterprise, and Snowflake.
CrowdStrike AI Security · Security requirement

Approved AI usage monitoring

Source checkedLimited public support for this requirement
What the vendor says

CrowdStrike claims it protects employee adoption of generative AI tools through a single sensor and console.

Exact source quote
Protect employee adoption of GenAI tools, managed through a single sensor and console.
CrowdStrike AI Security · Security requirement

Controls for unapproved AI use

Source checkedStrong public support for this requirement
What the vendor says

CrowdStrike claims it can block unauthorized AI access and topics while masking or encrypting sensitive data before exposure.

Exact source quote
Block unauthorized access and topics or mask or encrypt sensitive data before exposure
CrowdStrike AI Security · Security requirement

Sensitive-data protection for generative AI

Source checkedStrong public support for this requirement
What the vendor says

CrowdStrike claims it can prevent sensitive data from being shared with users, models, agents, or external AI systems.

Exact source quote
Prevent sensitive data from being shared with users, models, agents, or external AI systems.
CrowdStrike AI Security · Security requirement

Browser and business-application controls

Source checkedStrong public support for this requirement
What the vendor says

CrowdStrike claims Falcon Fusion SOAR can disable misbehaving software as a service (SaaS) agents or users via application programming interface (API) while opening tickets.

Exact source quote
With Falcon Fusion SOAR, it can disable misbehaving agents or users via API while simultaneously opening tickets to ensure accountability and resolution.
CrowdStrike AI Security · Security requirement

Generative AI application security

Source checkedStrong public support for this requirement
What the vendor says

CrowdStrike claims it can detect and stop direct and indirect prompt injection, unsafe content, and attempted model manipulation in real time.

Exact source quote
Detect and stop direct and indirect prompt injection, unsafe content, and attempted model manipulation in real time.
CrowdStrike AI Security · Security requirement

Action-taking agent monitoring

Source checkedStrong public support for this requirement
What the vendor says

CrowdStrike claims Falcon Shield identifies hidden agents, maps their usage and access, detects risky behavior, and enables containment.

Exact source quote
It identifies hidden agents, maps their usage and access, detects risky behavior, and enables containment through Falcon Fusion SOAR.
CrowdStrike AI Security · Security requirement

Agent-to-agent communication security

Source checkedStrong public support for this requirement
What the vendor says

CrowdStrike claims its AIDR, Agentic SOAR workflow controls, and AgentWorks guardrails secure agent-to-agent and analyst-to-agent collaboration.

Exact source quote
native AI Detection and Response (AIDR), Agentic SOAR workflow level controls, and AgentWorks guardrails secure agent-to-agent and analyst-to-agent collaboration.
CrowdStrike AI Security · Security requirement

Non-human identity and service-account security

Source checkedStrong public support for this requirement
What the vendor says

CrowdStrike claims Continuous Identity for AI Agents eliminates standing privileges and verifies trust for every agent action.

Exact source quote
Continuous Identity for AI Agents introduces a model that eliminates standing privileges and immediately verifies trust for every agent action.