Public-source research
Vendor evidence
Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.
Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6
Cyberhaven claims continuous inventory of AI agents, applications, and Model Context Protocol (MCP) servers, multidimensional AI risk scoring, data-lineage chain of custody, behavioral telemetry, and policy enforcement for autonomous systems.
Continuous, automatically maintained inventory of every AI agent, GenAI application, and MCP server across your environment.
Related framework references (5)
Cyberhaven AI Security materials reviewed did not provide a public product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.
No quoted source text is recorded for this claim.
Related framework references (5)
Cyberhaven claims continuous inventory of agents, local models, plugins, Model Context Protocol (MCP) servers, and tools plus AI Risk IQ scoring that includes model integrity and tracks component and version changes through endpoint and data lineage context.
Cyberhaven assigns an AI Risk IQ score across five dimensions: data sensitivity, model integrity, compliance adherence, user access, and security infrastructure.
Related framework references (5)
Cyberhaven claims endpoint-resident runtime observability and policy enforcement across agent files, application programming interfaces (APIs), Model Context Protocol (MCP) servers, tools, outputs, and sensitive-data movement using behavioral context and data lineage.
The third pillar is runtime policy enforcement.
Related framework references (5)
Cyberhaven claims user and device attribution, user-access risk scoring, agent activity chain of custody, and visibility into agents operating with user permissions.
Security teams can see which files were accessed, how data moved, and whether sensitive content traveled to an unexpected destination.
Related framework references (5)
Cyberhaven claims endpoint inventory and full execution-lifecycle reconstruction for local coding agents across browsers, CLIs, integrated development environments (IDEs), files, Model Context Protocol (MCP) servers, application programming interfaces (APIs), generated outputs, and sensitive-data movement.
Continuously inventories AI agents running across endpoints, browsers, command-line interfaces, and IDEs.
Related framework references (5)
Cyberhaven claims it automatically inventories approved and unapproved AI apps as they appear across an organization.
Cyberhaven automatically inventories sanctioned and unsanctioned AI apps as they appear across the organization, from mainstream SaaS generative AI applications to endpoint coding assistants, open-source agent frameworks, and MCP servers.
Related framework references (5)
Cyberhaven claims it inventories mainstream software as a service (SaaS) generative AI applications as part of AI app discovery.
Cyberhaven automatically inventories sanctioned and unsanctioned AI apps as they appear across the organization, from mainstream SaaS generative AI applications to endpoint coding assistants, open-source agent frameworks, and MCP servers.
Related framework references (5)
Cyberhaven claims usage and adoption insights categorize AI applications as approved, unapproved, tolerated, or restricted.
Usage and Adoption Insights Surfaces AI adoption trends across the enterprise, categorizing applications as Sanctioned, Unsanctioned, Tolerated, or Restricted to support governance decisions.
Related framework references (5)
Cyberhaven claims runtime guardrails block high-risk data movement, redirect users to approved tools, and coach employees.
Enforces runtime guardrails at the prompt and response level, blocking high-risk data movement, redirecting users to sanctioned tools, and coaching employees with plain-English policy explanations.
Related framework references (5)
Cyberhaven claims prompt- and response-level guardrails block high-risk data movement.
Enforces runtime guardrails at the prompt and response level, blocking high-risk data movement, redirecting users to sanctioned tools, and coaching employees with plain-English policy explanations.
Related framework references (5)
Cyberhaven claims Shadow AI Discovery inventories AI agents across endpoints, browsers, CLIs, and integrated development environments (IDEs).
Continuously inventories AI agents running across endpoints, browsers, CLIs, and IDEs, including tools that cloud-only security solutions cannot see.
Related framework references (5)
Cyberhaven claims prompt- and response-level runtime guardrails with block, redirect, and coaching controls.
Enforces runtime guardrails at the prompt and response level, blocking high-risk data movement, redirecting users to sanctioned tools, and coaching employees with plain-English policy explanations.
Related framework references (5)
Cyberhaven claims Agentic AI Visibility reconstructs agent interaction lifecycles with tool calls, data access, and multi-turn conversation context.
Reconstructs the full execution lifecycle of every agent interaction, capturing tool calls, data access, and multi-turn conversation context in a single view.
Related framework references (5)
Cyberhaven claims it discovers and monitors Model Context Protocol (MCP) servers and AI connectors across the enterprise.
Discovers and monitors Model Context Protocol servers and AI connectors across the enterprise, surfacing risk from integrations that operate outside traditional security controls.
Related framework references (5)
Cyberhaven materials reviewed did not provide a public claim for non-human identity (NHI), service-account, credential lifecycle, or AI-agent identity governance.
No quoted source text is recorded for this claim.
Related framework references (5)
Cyberhaven materials reviewed did not provide a public claim for AI spend attribution, model cost routing, budget enforcement, rate limits, or token spend controls.
No quoted source text is recorded for this claim.
Related framework references (5)
Cyberhaven materials reviewed did not provide a public per-user, per-seat, platform, usage-based, or enterprise pricing model.
No quoted source text is recorded for this claim.
Related framework references (2)
Cyberhaven claims its AI and data security platform protects data across endpoints, cloud, on-prem, software as a service (SaaS), and AI tools.
Cyberhaven’s AI & data security platform unifies DSPM, DLP, Insider Risk, and AI Security to protect data wherever it lives and goes across endpoints, cloud, on-prem, SaaS, and AI tools.
Related framework references (5)