ASAI Security ResearchIndependent public-source research
Public reviewread only

Public-source research

Vendor evidence

Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.

Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6

Showing 1–16 of 16 evidence records

Clear all filters
Upwind AI SecurityUnapproved AI use discoverySource checkedStrong public support for this requirement

Upwind claims it identifies shadow AI usage and unauthorized model network communications in cloud environments.

Identification of shadow AI usage and unauthorized model network communications
Upwind AI SecurityAI-feature discovery in business applicationsNo supporting claim found

Upwind materials reviewed did not provide a public claim for embedded AI discovery across the business-application environment.

No quoted source text is recorded for this claim.
Upwind AI SecurityApproved AI usage monitoringSource checkedStrong public support for this requirement

Upwind claims its AI bill of materials (AI-BOM) inventories models, agent frameworks, libraries, vector stores, cloud AI services, and runtime dependencies.

unified inventory that connects all layers of the AI stack
Upwind AI SecuritySensitive-data protection for generative AISource checkedLimited public support for this requirement

Upwind claims real-time detection of sensitive data in prompts and inference payloads traversing cloud networks.

Real-time detection of sensitive data in prompts and inference payloads
Upwind AI SecurityBrowser and business-application controlsNo supporting claim found

Upwind materials reviewed did not provide a public claim for browser or software as a service (SaaS)-session controls for employee AI use.

No quoted source text is recorded for this claim.
Upwind AI SecurityGenerative AI application securitySource checkedStrong public support for this requirement

Upwind claims AI application testing for prompt injection, jailbreaks, unsafe tool bindings, and hallucination-driven data exposure.

Prompt injection and jailbreak testing
Upwind AI SecurityAI governance, risk, and complianceSource checkedLimited public support for this requirement

Upwind claims model version, lineage, audit-trail, and posture controls for cloud AI services.

maintain lineage, and enforce audit trails
Upwind AI SecurityAI assurance and adversarial testingSource checkedStrong public support for this requirement

Upwind claims AI-specific security testing before deployment and continuously as models evolve.

identify weaknesses before deployment, and continuously as models evolve
Upwind AI SecurityAI model and supply-chain securitySource checkedLimited public support for this requirement

Upwind claims an AI bill of materials (AI-BOM) correlating code, cloud, model registries, agent systems, AI components, and runtime dependencies.

Correlation with runtime evidence to reveal real dependencies
Upwind AI SecurityAI gateway, tool-connection, and runtime controlsSource checkedLimited public support for this requirement

Upwind claims Model Context Protocol (MCP) runtime tracing of prompts, decision chains, tool calls, file actions, application programming interfaces (APIs), and cloud interactions.

MCP Security brings agentic visibility to runtime by tracing AI-driven actions end-to-end.
Upwind AI SecurityAction-taking agent monitoringSource checkedStrong public support for this requirement

Upwind claims end-to-end runtime observation of agent prompts, decisions, tool invocations, file actions, application programming interface (API) calls, and system changes.

Observation of tool invocation and agent function calls
Upwind AI SecurityNon-human identity and service-account securitySource checkedLimited public support for this requirement

Upwind claims discovery of AI application programming interface (API) keys and secrets plus detection of overly permissive identity and access management (IAM) roles used by AI services.

Automatically discover AI API keys and ensure they are not exposed.
Upwind AI SecurityAI agent identity and permissionsNo supporting claim found

Upwind materials reviewed did not provide a public claim for agent registration, delegated authorization, task-scoped access, and revocation.

No quoted source text is recorded for this claim.
Upwind AI SecurityAI coding-agent and workstation securityNo supporting claim found

Upwind materials reviewed did not provide a public claim for coding-agent, integrated development environment (IDE), CLI, workstation, skill, hook, or package-action governance.

No quoted source text is recorded for this claim.