ASAI Security ResearchIndependent public-source research
Public reviewread only

Public-source research

Vendor evidence

Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.

Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6

Showing 1–19 of 19 evidence records

Clear all filters
Onyx AIAI governance, risk, and complianceSource checkedLimited public support for this requirement

Onyx AI claims a approved self-hosted enterprise AI platform with organization and group sharing, permissions, usage analytics, model controls, auditability, and governed access to enterprise knowledge and actions.

Give your team an approved AI platform that actually works, so they stop pasting company data into ChatGPT.
Onyx AIAI assurance and adversarial testingNo supporting claim found

Onyx AI materials reviewed did not provide a public product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.

No quoted source text is recorded for this claim.
Onyx AIAI model and supply-chain securityNo supporting claim found

Onyx AI materials reviewed did not establish model artifact scanning, provenance, signing, dependency or Model Context Protocol (MCP) component analysis, tamper detection, or model-registry release controls.

No quoted source text is recorded for this claim.
Onyx AIAI gateway, tool-connection, and runtime controlsSource checkedLimited public support for this requirement

Onyx AI claims configurable agents with controlled Actions, data access, knowledge sources, and the ability for administrators to enable or disable Model Context Protocol (MCP) and OpenAPI actions.

Users have the flexibility to turn on or off the Actions that the Agent or LLM has access to.
Onyx AIAI agent identity and permissionsSource checkedLimited public support for this requirement

Onyx AI claims organization and group-based agent sharing plus configurable knowledge and action permissions for enterprise agents.

Publish your Agent to your entire organization or share it with specific users or groups.
Onyx AIAI coding-agent and workstation securityNo supporting claim found

Onyx AI materials reviewed did not establish governance of coding-agent commands, developer-workstation files or networks, integrated development environment (IDE) extensions, skills, hooks, secrets, or package actions.

No quoted source text is recorded for this claim.
Onyx AIUnapproved AI use discoverySource checkedRelated public context only

Onyx claims it can reduce shadow AI by giving users an approved AI platform, but it does not publicly claim independent discovery of third-party AI usage outside Onyx.

Give your team an approved AI platform that actually works, so they stop pasting company data into ChatGPT.
Onyx AIApproved AI usage monitoringSource checkedStrong public support for this requirement

Onyx claims usage analytics, query logs, feedback tracking, and query history for activity inside the Onyx AI platform.

Usage analytics, query logs, and feedback tracking across every team.
Onyx AIControls for unapproved AI useSource checkedLimited public support for this requirement

Onyx claims fine-grained language-model provider access controls and per-team model approvals inside Onyx, which partially maps to unapproved AI control.

Onyx provides fine-grained access control for language model providers, allowing administrators to control **who** can use specific models and **which agents** can use them.
Onyx AISensitive-data protection for generative AISource checkedLimited public support for this requirement

Onyx claims self-hosted deployment, source-permission mirroring, and ACL sync to keep AI access aligned to existing data permissions.

Strict permission controls and your data never leaves your network.
Onyx AIBrowser and business-application controlsSource checkedLimited public support for this requirement

Onyx claims permission-aware connectors, document-level permissions, SCIM/IdP integration, and ACL sync for users accessing connected enterprise knowledge.

Every query respects who can see what.
Onyx AIGenerative AI application securitySource checkedRelated public context only

Onyx provides application programming interfaces (APIs), Model Context Protocol (MCP), connectors, and custom agents for building generative AI workflows, but does not publicly claim independent large language model (LLM) application security testing.

Full REST API, an MCP server, and a connector framework for custom data sources.
Onyx AIAction-taking agent monitoringSource checkedLimited public support for this requirement

Onyx claims query history and usage analytics for messages and application programming interface (API)-key activity inside its agent/chat platform.

On the Query History page, you can see a log of all messages sent to Onyx.
Onyx AIAgent-to-agent communication securitySource checkedLimited public support for this requirement

Onyx claims controlled Model Context Protocol (MCP) actions for AI agents and admin selection of available tools, partially mapping to agent-to-tool security rather than broad agent-to-agent security.

Model Context Protocol (MCP) enables AI Agents to invoke tools and services in a controlled manner.
Onyx AINon-human identity and service-account securitySource checkedLimited public support for this requirement

Onyx claims application programming interface (API) keys exist as distinct users so administrators can trace activity and manage permissions for programmatic access.

API Keys exist as distinct users in Onyx, allowing you to trace activity and manage permissions at the key level.
Onyx AIAI cost and usage controlsSource checkedLimited public support for this requirement

Onyx claims large language model (LLM) rate limits and throttling settings that can be applied globally, by user, or by user group.

Rate limits can be applied globally, by User, or by User Group.
Onyx AILicensing modelSource checkedStrong public support for this requirement

Onyx publishes a Business plan price at $20 per user per month and an Enterprise plan with flexible pricing and deployment options.

per user / month
Onyx AIApproved AI platform contextSource checkedStrong public support for this requirement

Onyx positions itself as a approved enterprise AI platform alternative to ChatGPT Enterprise, Microsoft Copilot, Gemini, and Glean rather than a third-party AI security monitoring layer.

Why choose Onyx over ChatGPT, Microsoft Copilot, Google Gemini, or Glean?