Reference
How to read the research
Plain-language definitions for company scale, public-evidence states, solution areas, and security-framework relationships used throughout the site.
Research boundary
What this research shows
We record vendor claims from public sources, connect them to a consistent set of security requirements, note company-scale signals, and show where a supporting claim was not found or research is incomplete. This can help you ask better questions; it does not establish product fit, contract coverage, customer outcomes, or effectiveness in your environment.
Definition group
Company scale
- Established
- A provider with at least $1B in annual revenue, at least 1,000 employees, or backing from an established owner.This is a company-maturity signal, not a product-quality rating.
- Scaled
- A private provider with at least $100M in known funding or at least 250 employees.This is a company-scale signal, not a product-quality rating.
- Growth stage
- A provider with at least $25M in known funding or at least 51 employees that has not reached the scaled threshold.This is a company-scale signal, not a product-quality rating.
- Emerging
- An early-stage provider with less than $25M in known funding, or 50 or fewer employees without at least $50M in known funding.This is a company-scale signal, not a product-quality rating.
- More research needed
- The retained sources do not establish enough operating-scale, capital, revenue, or profitability evidence to classify company maturity.The missing company evidence does not imply a positive or negative product conclusion.
Definition group
Public evidence
- Source checked
- The research record includes a retained public source that passed the project's source and evidence checks.This checks the research record, not the product's effectiveness in a customer environment.
- Needs verification
- A source is present, but a researcher still needs to confirm what it supports, how broadly it applies, or whether it is current.
- Source captured
- A potential public-source record has been saved but has not completed the project's evidence checks.
- Strong public support
- The cited source clearly addresses the full security requirement being evaluated.Strong public support can still be a vendor's public claim. It does not prove effectiveness in a customer environment.
- Limited public support
- The cited source supports only part of the security requirement or a narrower version of it.
- No supporting claim found
- The research process looked for a qualifying public claim and did not find one in the reviewed sources.This is different from a topic that has not yet been researched.
- Research incomplete
- The public-source review is incomplete for this vendor and security requirement.Do not draw a positive or negative product conclusion from an incomplete record.
- Evidence match
- How closely the retained source language supports the security requirement being evaluated: strong public support, limited public support, or no supporting claim found.
Definition group
How solutions are organized
- Breadth of public support
- The number of security requirements for which reviewed public sources provide strong or limited support for a vendor.
- Strength of source match
- The share of a vendor's security requirements with public support where the source language addresses the full requirement instead of only part of it.
- Core product focus
- A solution area that is central to how the vendor presents its product. A vendor can have more than one core product focus.This taxonomy label describes product positioning; it does not rank vendors or establish fit for a use case.
- Related coverage
- A solution area the vendor addresses beyond the areas presented as core product focuses.This taxonomy label does not imply weaker public evidence, lower product quality, or fit for a use case.
- Foundational security requirement
- A security requirement treated as foundational when evaluating this solution area.
- Additional security requirement
- A security requirement that adds meaningful coverage but is not treated as foundational for this solution area.
- Cross-cutting control layer
- A broad policy or enforcement layer that can apply across several AI security needs and parts of the technology environment.
- Focused solution area
- A focused security product or control designed for a narrower AI security problem.
Definition group
Security frameworks
- Closely aligned
- The framework reference closely addresses the enterprise requirement used in this research.This does not establish vendor implementation or framework conformance.
- Contributes
- The framework reference helps address the requirement but is not equivalent to it.
Continue exploring