ASAI Security ResearchIndependent public-source research
Public reviewread only

Public-source research

Vendor evidence

Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.

Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6

Showing 1–19 of 19 evidence records

Clear all filters
Lasso SecurityAI governance, risk, and complianceSource checkedStrong public support for this requirement

Lasso claims continuous agent discovery, AI bill of materials (AI-BOM) inventory, risk scoring, ownership, intent-aware policy, compliance mapping, audit logs, and cross-platform governance from code to runtime.

A single source of truth for governing agentic AI from code to runtime.
Lasso SecurityAI assurance and adversarial testingSource checkedStrong public support for this requirement

Lasso claims automated agentic red teaming with static, multi-turn, and high-agency attacks, deployment-pipeline integration, adaptive policy generation, and one-click testing.

Stress-test application logic through static, multi-turn, and high-agency attack to uncover vulnerabilities and build adaptive guardrails.
Lasso SecurityAI model and supply-chain securitySource checkedStrong public support for this requirement

Lasso claims an AI bill of materials (AI-BOM) spanning models, prompts, tools, Model Context Protocol (MCP) servers, frameworks, databases, services, guardrails, identity boundaries, and authorization policies, with continuous CI updates and supply-chain risk assessment.

Inventory every AI component, including models, MCP servers, delegated agents, databases, third-party tool connectors, identity boundaries, and authorization policies.
Lasso SecurityAI gateway, tool-connection, and runtime controlsSource checkedStrong public support for this requirement

Lasso claims an Model Context Protocol (MCP) security gateway and intent-aware runtime policy enforcement across agent actions, tools, application programming interfaces (APIs), external connections, indirect prompt injection, memory poisoning, permissions, and data loss prevention (DLP).

Lasso's open-source MCP Gateway provides a security layer for MCP connections.
Lasso SecurityAI agent identity and permissionsSource checkedLimited public support for this requirement

Lasso claims inventory of identity boundaries and authorization policies, ownership context, role-based permissions, and risk-scored governance of agent access to Model Context Protocol (MCP) servers, application programming interfaces (APIs), and tools.

Inventory every AI component, including identity boundaries and authorization policies.
Lasso SecurityAI coding-agent and workstation securitySource checkedLimited public support for this requirement

Lasso claims risk scoring, management, and blocking of Model Context Protocol (MCP) servers, application programming interfaces (APIs), and external tool connections across Claude Code, Claude Desktop, Cursor, and Codex.

Manage or block high-risk tools across Claude Code and Desktop, Cursor, and Codex.
Lasso SecurityAI cost and usage controlsNo supporting claim found

Lasso Security platform materials reviewed did not provide a public product claim for AI usage-cost attribution, token or spend metrics, budgets, chargeback, or cost-aware model routing.

No quoted source text is recorded for this claim.
Lasso SecurityUnapproved AI use discoverySource checkedStrong public support for this requirement

Lasso Security claims it discovers AI agents and homegrown AI applications via platform integration and CI.

Discover AI agents via platform integration. Connect via CI to automatically discover homegrown applications.
Lasso SecurityControls for unapproved AI useSource checkedStrong public support for this requirement

Lasso Security claims runtime policy enforcement through proxy, application programming interface (API), or AI gateway controls.

Enforce policies inline at the proxy, API, or AI Gateway layer with runtime protection that adapts as your application evolves.
Lasso SecuritySensitive-data protection for generative AISource checkedLimited public support for this requirement

Lasso Security claims it analyzes what sensitive data agents can reach and enforces policies inline at the proxy, application programming interface (API), or AI Gateway layer.

Analyze your security posture by understanding what your agents are exposed to, what actions they can perform, what sensitive data can they reach, and more.
Lasso SecurityAction-taking agent monitoringSource checkedStrong public support for this requirement

Lasso Security claims it maps models, system prompts, tools, and guardrails and provides full context on attacks including which agent was targeted.

Maps models, system prompts, tools and guardrails
Lasso SecurityAgent-to-agent communication securitySource checkedLimited public support for this requirement

Lasso Security claims AI detection and response coverage for agent threats, including tool-chain manipulation and abnormal AI behavior.

what actions they can perform, what sensitive data can they reach
Lasso SecurityNon-human identity and service-account securitySource checkedLimited public support for this requirement

Lasso Security claims AI agent inventory includes exposed actions and sensitive data reachability to support agent risk analysis.

what actions they can perform, what sensitive data can they reach
Lasso SecurityGenerative AI application securitySource checkedStrong public support for this requirement

Lasso Security claims it enforces policies inline at the proxy, application programming interface (API), or AI Gateway layer with runtime protection that adapts as the application evolves.

Enforce policies inline at the proxy, API, or AI Gateway layer with runtime protection that adapts as your application evolves.