Public-source research
Vendor evidence
Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.
Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6
Obsidian claims browser-level discovery of unapproved AI tools, extensions, personal accounts, and unmanaged-device use.
browser-level discovery
Related framework references (5)
Obsidian claims continuous inventory of AI tools and agents across software as a service (SaaS), including software as a service (SaaS) permissions, OAuth connections, and shadow agents.
full visibility into every AI agent, its privileges, SaaS connections, and actions
Related framework references (5)
Obsidian claims continuous inventory of every AI tool, agent, large language model (LLM), and Model Context Protocol (MCP) server with ownership and access context.
every AI tool, agent, LLM, and MCP server
Related framework references (5)
Obsidian claims blocking high-risk unapproved AI use and agent actions through browser and runtime controls.
Block high-risk actions automatically at runtime
Related framework references (5)
Obsidian claims blocking sensitive prompts before proprietary data leaves the browser for third-party generative AI platforms.
catching and blocking sensitive prompts at the source
Related framework references (5)
Obsidian claims browser-level AI discovery and source-level blocking of sensitive prompts, including personal accounts and unmanaged devices.
before they ever leave the browser
Related framework references (5)
Obsidian claims execution-time guardrails blocking privilege escalation, excessive data access, and policy violations.
Detect and block high-risk agent actions at execution time
Related framework references (5)
Obsidian claims continuous audit-ready evidence of agent ownership, access, infrastructure, and runtime guardrail operation.
continuous, audit-ready evidence
Related framework references (5)
Obsidian claims continuous OWASP-aligned risk scoring of agents when published or modified.
Continuous assessment maps every agent to OWASP risk factors
Related framework references (5)
Obsidian claims detection of risky integrations, unapproved Model Context Protocol (MCP) connections, silent model swaps, and embedded credentials.
silent model swaps
Related framework references (5)
Obsidian claims fine-grained execution-time guardrails using software as a service (SaaS) and Model Context Protocol (MCP) context to block unapproved actions.
Enforce guardrails directly at execution time
Related framework references (5)
Obsidian claims real-time visibility into agent actions, tool calls, Model Context Protocol (MCP) servers, models, permissions, owners, and connected apps.
the actions they take, the tools they call on, and the permissions they are granted in real time
Related framework references (5)
Obsidian materials reviewed did not provide a public claim for authenticating or authorizing direct agent-to-agent communication.
No quoted source text is recorded for this claim.
Related framework references (5)
Obsidian claims resolution of agent identity to service accounts, application programming interface (API) tokens, OAuth privileges, embedded credentials, and connected software as a service (SaaS) applications.
the real service accounts it runs as
Related framework references (5)
Obsidian claims tying agent actions to owners, executors, service accounts, permissions, OAuth access, and least-privilege enforcement.
Tie actions to the real owner and the executor for each agent
Related framework references (5)
Obsidian claims runtime monitoring across Cursor, code environments, Model Context Protocol (MCP) servers, tools, and software as a service (SaaS) applications.
across Copilot, Claude, Cursor, and the SaaS apps agents touch
Related framework references (5)
Obsidian materials reviewed did not provide a public claim for AI spend attribution, budgets, chargeback, rate limits, or token-cost anomaly detection.
No quoted source text is recorded for this claim.
Related framework references (5)
Obsidian materials reviewed did not provide a public per-user, per-agent, event-volume, platform, or usage-based licensing unit for AI Security.
No quoted source text is recorded for this claim.
Related framework references (2)
Obsidian claims out-of-the-box integrations across major AI platforms, software as a service (SaaS), cloud, endpoints, code, identity, and data systems.
across SaaS, cloud, endpoints, and code
Related framework references (5)