ASAI Security ResearchIndependent public-source research
Public reviewread only

Public-source research

Vendor evidence

Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.

Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6

Showing 1–19 of 19 evidence records

Clear all filters
CyberhavenAI governance, risk, and complianceSource checkedLimited public support for this requirement

Cyberhaven claims continuous inventory of AI agents, applications, and Model Context Protocol (MCP) servers, multidimensional AI risk scoring, data-lineage chain of custody, behavioral telemetry, and policy enforcement for autonomous systems.

Continuous, automatically maintained inventory of every AI agent, GenAI application, and MCP server across your environment.
CyberhavenAI assurance and adversarial testingNo supporting claim found

Cyberhaven AI Security materials reviewed did not provide a public product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.

No quoted source text is recorded for this claim.
CyberhavenAI model and supply-chain securitySource checkedLimited public support for this requirement

Cyberhaven claims continuous inventory of agents, local models, plugins, Model Context Protocol (MCP) servers, and tools plus AI Risk IQ scoring that includes model integrity and tracks component and version changes through endpoint and data lineage context.

Cyberhaven assigns an AI Risk IQ score across five dimensions: data sensitivity, model integrity, compliance adherence, user access, and security infrastructure.
CyberhavenAI gateway, tool-connection, and runtime controlsSource checkedLimited public support for this requirement

Cyberhaven claims endpoint-resident runtime observability and policy enforcement across agent files, application programming interfaces (APIs), Model Context Protocol (MCP) servers, tools, outputs, and sensitive-data movement using behavioral context and data lineage.

The third pillar is runtime policy enforcement.
CyberhavenAI agent identity and permissionsSource checkedLimited public support for this requirement

Cyberhaven claims user and device attribution, user-access risk scoring, agent activity chain of custody, and visibility into agents operating with user permissions.

Security teams can see which files were accessed, how data moved, and whether sensitive content traveled to an unexpected destination.
CyberhavenAI coding-agent and workstation securitySource checkedStrong public support for this requirement

Cyberhaven claims endpoint inventory and full execution-lifecycle reconstruction for local coding agents across browsers, CLIs, integrated development environments (IDEs), files, Model Context Protocol (MCP) servers, application programming interfaces (APIs), generated outputs, and sensitive-data movement.

Continuously inventories AI agents running across endpoints, browsers, command-line interfaces, and IDEs.
CyberhavenUnapproved AI use discoverySource checkedStrong public support for this requirement

Cyberhaven claims it automatically inventories approved and unapproved AI apps as they appear across an organization.

Cyberhaven automatically inventories sanctioned and unsanctioned AI apps as they appear across the organization, from mainstream SaaS generative AI applications to endpoint coding assistants, open-source agent frameworks, and MCP servers.
CyberhavenAI-feature discovery in business applicationsSource checkedStrong public support for this requirement

Cyberhaven claims it inventories mainstream software as a service (SaaS) generative AI applications as part of AI app discovery.

Cyberhaven automatically inventories sanctioned and unsanctioned AI apps as they appear across the organization, from mainstream SaaS generative AI applications to endpoint coding assistants, open-source agent frameworks, and MCP servers.
CyberhavenApproved AI usage monitoringSource checkedStrong public support for this requirement

Cyberhaven claims usage and adoption insights categorize AI applications as approved, unapproved, tolerated, or restricted.

Usage and Adoption Insights Surfaces AI adoption trends across the enterprise, categorizing applications as Sanctioned, Unsanctioned, Tolerated, or Restricted to support governance decisions.
CyberhavenControls for unapproved AI useSource checkedStrong public support for this requirement

Cyberhaven claims runtime guardrails block high-risk data movement, redirect users to approved tools, and coach employees.

Enforces runtime guardrails at the prompt and response level, blocking high-risk data movement, redirecting users to sanctioned tools, and coaching employees with plain-English policy explanations.
CyberhavenSensitive-data protection for generative AISource checkedStrong public support for this requirement

Cyberhaven claims prompt- and response-level guardrails block high-risk data movement.

Enforces runtime guardrails at the prompt and response level, blocking high-risk data movement, redirecting users to sanctioned tools, and coaching employees with plain-English policy explanations.
CyberhavenBrowser and business-application controlsSource checkedStrong public support for this requirement

Cyberhaven claims Shadow AI Discovery inventories AI agents across endpoints, browsers, CLIs, and integrated development environments (IDEs).

Continuously inventories AI agents running across endpoints, browsers, CLIs, and IDEs, including tools that cloud-only security solutions cannot see.
CyberhavenGenerative AI application securitySource checkedLimited public support for this requirement

Cyberhaven claims prompt- and response-level runtime guardrails with block, redirect, and coaching controls.

Enforces runtime guardrails at the prompt and response level, blocking high-risk data movement, redirecting users to sanctioned tools, and coaching employees with plain-English policy explanations.
CyberhavenAction-taking agent monitoringSource checkedStrong public support for this requirement

Cyberhaven claims Agentic AI Visibility reconstructs agent interaction lifecycles with tool calls, data access, and multi-turn conversation context.

Reconstructs the full execution lifecycle of every agent interaction, capturing tool calls, data access, and multi-turn conversation context in a single view.
CyberhavenAgent-to-agent communication securitySource checkedLimited public support for this requirement

Cyberhaven claims it discovers and monitors Model Context Protocol (MCP) servers and AI connectors across the enterprise.

Discovers and monitors Model Context Protocol servers and AI connectors across the enterprise, surfacing risk from integrations that operate outside traditional security controls.
CyberhavenNon-human identity and service-account securityNo supporting claim found

Cyberhaven materials reviewed did not provide a public claim for non-human identity (NHI), service-account, credential lifecycle, or AI-agent identity governance.

No quoted source text is recorded for this claim.
CyberhavenAI cost and usage controlsNo supporting claim found

Cyberhaven materials reviewed did not provide a public claim for AI spend attribution, model cost routing, budget enforcement, rate limits, or token spend controls.

No quoted source text is recorded for this claim.
CyberhavenApproved AI platform contextSource checkedStrong public support for this requirement

Cyberhaven claims its AI and data security platform protects data across endpoints, cloud, on-prem, software as a service (SaaS), and AI tools.

Cyberhaven’s AI & data security platform unifies DSPM, DLP, Insider Risk, and AI Security to protect data wherever it lives and goes across endpoints, cloud, on-prem, SaaS, and AI tools.