Public-source research
Vendor evidence
Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.
Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6
Orca claims continuous discovery of managed, unmanaged, and shadow AI models across the entire cloud environment.
including any shadow AI
Related framework references (5)
Orca materials reviewed did not provide a public claim for tenant-level inventory of embedded AI features across enterprise software as a service (SaaS) applications.
No quoted source text is recorded for this claim.
Related framework references (5)
Orca claims a complete inventory and bill of materials for managed and unmanaged AI models and packages in AWS, Azure, and Google Cloud.
complete AI inventory and Bill of Materials (BOM)
Related framework references (5)
Orca materials reviewed did not provide a public claim for workforce allow, coach, restrict, isolate, redirect, or block controls over unapproved AI use.
No quoted source text is recorded for this claim.
Related framework references (5)
Orca claims detection of sensitive information in AI models and training data to prevent unintended exposure.
training data contain sensitive information
Related framework references (5)
Orca materials reviewed did not provide a public claim for browser session controls over AI upload, download, copy, paste, sharing, or form submission.
No quoted source text is recorded for this claim.
Related framework references (5)
Orca claims continuous detection of AI misconfigurations, exposed models, vulnerable packages, sensitive data, identity and access management (IAM) risks, and malware in cloud AI environments.
covering network security, data protection, access controls, and IAM
Related framework references (5)
Orca claims ongoing AI compliance monitoring and a configuration-practices framework covering network, data, access, and identity and access management (IAM) settings.
AI Best Practices compliance framework
Related framework references (5)
Orca materials reviewed did not provide a public product claim for adversarial AI red teaming, evaluation campaigns, or regression release gates.
No quoted source text is recorded for this claim.
Related framework references (5)
Orca claims an AI bill of materials covering models and more than 50 software packages plus detection of vulnerable packages, editable training data, and exposed keys.
50+ AI models and software packages
Related framework references (5)
Orca materials reviewed did not provide a public claim for an AI or Model Context Protocol (MCP) gateway that proxies and enforces prompt, response, tool-call, or Model Context Protocol (MCP) policy at runtime.
No quoted source text is recorded for this claim.
Related framework references (5)
Orca materials reviewed did not provide a public claim for agent identities, tool calls, Model Context Protocol (MCP) actions, delegation, or agent workflow telemetry.
No quoted source text is recorded for this claim.
Related framework references (5)
Orca materials reviewed did not provide a public claim for authenticating, authorizing, logging, or enforcing agent-to-agent communication.
No quoted source text is recorded for this claim.
Related framework references (5)
Orca claims detection of exposed keys and tokens for AI services and software packages in code repositories.
keys and tokens to AI services and software packages
Related framework references (5)
Orca materials reviewed did not provide a public claim for agent registration, ownership, delegated authorization, short-lived credentials, or agent lifecycle.
No quoted source text is recorded for this claim.
Related framework references (5)
Orca materials reviewed did not provide a public claim for coding-agent commands, filesystem or network actions, skills, hooks, extensions, packages, or workstation activity.
No quoted source text is recorded for this claim.
Related framework references (5)
Orca materials reviewed did not provide a public claim for AI spend attribution, budgets, chargeback, rate limits, or token-cost anomaly detection.
No quoted source text is recorded for this claim.
Related framework references (5)
Orca positions AI-SPM as integrated into the Orca Cloud Security Platform rather than a separate point solution.
no point solutions needed
Related framework references (2)
Orca claims AI-SPM within a unified agentless CNAPP covering AWS, Azure, Google Cloud, cloud assets, identities, data, vulnerabilities, and attack paths.
Orca Cloud Security Platform
Related framework references (5)