ASAI Security ResearchIndependent public-source research
Public reviewread only

Public-source research

Vendor evidence

Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.

Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6

Showing 1–19 of 19 evidence records

Clear all filters
Obsidian AI SecurityAI-feature discovery in business applicationsSource checkedStrong public support for this requirement

Obsidian claims continuous inventory of AI tools and agents across software as a service (SaaS), including software as a service (SaaS) permissions, OAuth connections, and shadow agents.

full visibility into every AI agent, its privileges, SaaS connections, and actions
Obsidian AI SecurityApproved AI usage monitoringSource checkedStrong public support for this requirement

Obsidian claims continuous inventory of every AI tool, agent, large language model (LLM), and Model Context Protocol (MCP) server with ownership and access context.

every AI tool, agent, LLM, and MCP server
Obsidian AI SecurityControls for unapproved AI useSource checkedStrong public support for this requirement

Obsidian claims blocking high-risk unapproved AI use and agent actions through browser and runtime controls.

Block high-risk actions automatically at runtime
Obsidian AI SecuritySensitive-data protection for generative AISource checkedStrong public support for this requirement

Obsidian claims blocking sensitive prompts before proprietary data leaves the browser for third-party generative AI platforms.

catching and blocking sensitive prompts at the source
Obsidian AI SecurityBrowser and business-application controlsSource checkedStrong public support for this requirement

Obsidian claims browser-level AI discovery and source-level blocking of sensitive prompts, including personal accounts and unmanaged devices.

before they ever leave the browser
Obsidian AI SecurityGenerative AI application securitySource checkedStrong public support for this requirement

Obsidian claims execution-time guardrails blocking privilege escalation, excessive data access, and policy violations.

Detect and block high-risk agent actions at execution time
Obsidian AI SecurityAI governance, risk, and complianceSource checkedStrong public support for this requirement

Obsidian claims continuous audit-ready evidence of agent ownership, access, infrastructure, and runtime guardrail operation.

continuous, audit-ready evidence
Obsidian AI SecurityAI assurance and adversarial testingSource checkedLimited public support for this requirement

Obsidian claims continuous OWASP-aligned risk scoring of agents when published or modified.

Continuous assessment maps every agent to OWASP risk factors
Obsidian AI SecurityAI model and supply-chain securitySource checkedLimited public support for this requirement

Obsidian claims detection of risky integrations, unapproved Model Context Protocol (MCP) connections, silent model swaps, and embedded credentials.

silent model swaps
Obsidian AI SecurityAI gateway, tool-connection, and runtime controlsSource checkedStrong public support for this requirement

Obsidian claims fine-grained execution-time guardrails using software as a service (SaaS) and Model Context Protocol (MCP) context to block unapproved actions.

Enforce guardrails directly at execution time
Obsidian AI SecurityAction-taking agent monitoringSource checkedStrong public support for this requirement

Obsidian claims real-time visibility into agent actions, tool calls, Model Context Protocol (MCP) servers, models, permissions, owners, and connected apps.

the actions they take, the tools they call on, and the permissions they are granted in real time
Obsidian AI SecurityAgent-to-agent communication securityNo supporting claim found

Obsidian materials reviewed did not provide a public claim for authenticating or authorizing direct agent-to-agent communication.

No quoted source text is recorded for this claim.
Obsidian AI SecurityNon-human identity and service-account securitySource checkedStrong public support for this requirement

Obsidian claims resolution of agent identity to service accounts, application programming interface (API) tokens, OAuth privileges, embedded credentials, and connected software as a service (SaaS) applications.

the real service accounts it runs as
Obsidian AI SecurityAI agent identity and permissionsSource checkedStrong public support for this requirement

Obsidian claims tying agent actions to owners, executors, service accounts, permissions, OAuth access, and least-privilege enforcement.

Tie actions to the real owner and the executor for each agent
Obsidian AI SecurityAI coding-agent and workstation securitySource checkedLimited public support for this requirement

Obsidian claims runtime monitoring across Cursor, code environments, Model Context Protocol (MCP) servers, tools, and software as a service (SaaS) applications.

across Copilot, Claude, Cursor, and the SaaS apps agents touch
Obsidian AI SecurityAI cost and usage controlsNo supporting claim found

Obsidian materials reviewed did not provide a public claim for AI spend attribution, budgets, chargeback, rate limits, or token-cost anomaly detection.

No quoted source text is recorded for this claim.
Obsidian AI SecurityApproved AI platform contextSource checkedStrong public support for this requirement

Obsidian claims out-of-the-box integrations across major AI platforms, software as a service (SaaS), cloud, endpoints, code, identity, and data systems.

across SaaS, cloud, endpoints, and code