A three-step guide that started with a problem and returned a vendor-focused result.
Research release 2026.07
July 2026 research update
A dated summary of changes to the solution map, vendor research coverage, and research process in this private pilot.
Research direction
How the research process changed
A research workspace that connects overlapping security needs to solution approaches, public evidence, and clear research limits.
Public-source review status
Research coverage is explicit and measurable
Each completed check contains strong or limited public support, or records that no supporting public claim was found. These findings describe available research, not product validation.
- Vendor reviews complete
- 58 / 66
- Strong public support
- 475
- Limited public support
- 314
- No supporting claim found
- 385
- Research incomplete
- 14
Existing-vendor research update
Completing research for 6 new security requirements
An existing vendor review is up to date only when every new requirement has supporting public evidence or an explicit finding that no supporting claim was found.
- Existing vendors
- 38
- Reviews up to date
- 38
- Vendor reviews remaining
- 0
- Security checks remaining
- 0
How the research connects
From a public claim to a question to verify
The research connects vendor language to consistent security requirements. Public statements and framework references inform the evaluation; effectiveness still requires separate testing.
- 01Public vendor statement
The exact statement and its source.
- 02Research finding
Strong support, limited support, no supporting claim found, or research incomplete.
- 03Security requirement
A consistent evaluation question, independent of vendor wording.
- 04Solution approach
Where the product acts and which security problem it addresses.
- 05Framework reference and test
Relevant guidance and a testable question to verify.
6 new security requirements
Expanded security requirements
These additions cover governance, assurance, model and software supply chains, controls that act while AI runs, agent identity, and coding-agent risk.
AI governance, risk, and compliance
Inventory AI systems and owners, translate policy and regulatory obligations into governed workflows, assess risk, manage approvals and exceptions, and retain audit evidence across the AI lifecycle.
- Strong public support
- 36
- Limited public support
- 20
- No supporting claim found
- 10
- Research incomplete
- 0
AI assurance and adversarial testing
Test models, applications, retrieval-augmented generation (RAG) systems, and agents before release and continuously thereafter using adversarial probes, evaluation suites, attack simulation, and security release gates.
- Strong public support
- 24
- Limited public support
- 3
- No supporting claim found
- 39
- Research incomplete
- 0
AI model and supply-chain security
Discover, inventory, scan, validate, and monitor models, datasets, model artifacts, registries, dependencies, and AI development assets for tampering, unsafe serialization, provenance gaps, or malicious content.
- Strong public support
- 13
- Limited public support
- 28
- No supporting claim found
- 25
- Research incomplete
- 0
AI gateway, tool-connection, and runtime controls
Mediate model, agent, tool, application programming interface (API), connector, and Model Context Protocol (MCP) traffic through an enforcement point that applies identity-aware policy, content controls, routing, rate limits, and auditable allow or deny decisions.
- Strong public support
- 42
- Limited public support
- 19
- No supporting claim found
- 5
- Research incomplete
- 0
AI agent identity and permissions
Register AI agents as accountable identities, bind them to owners and delegating users, authorize task- and tool-level access, issue short-lived credentials, review access, and revoke or suspend agent authority.
- Strong public support
- 15
- Limited public support
- 39
- No supporting claim found
- 12
- Research incomplete
- 0
AI coding-agent and workstation security
Discover and govern AI coding agents, integrated development environment (IDE) assistants, command-line agents, skills, hooks, extensions, Model Context Protocol (MCP) tools, filesystem access, commands, network activity, secrets, and software-supply-chain actions on developer workstations and build environments.
- Strong public support
- 14
- Limited public support
- 27
- No supporting claim found
- 25
- Research incomplete
- 0
Solution relationship map
How the new security requirements connect to solution approaches
A connection means the requirement is commonly relevant when evaluating that type of solution. Vendor-level support is recorded separately.
Security for models and their related software components is treated as a cross-cutting requirement across configuration, protection while AI runs, assurance, and governance research.
6 new solution approaches
Expanded solution map
These additions make previously grouped product approaches visible and easier to compare.
AI API and web application protection
Find and protect AI-related application programming interfaces (APIs), model endpoints, tool servers, and agent traffic.
- Vendors researched
- 9
- Security requirements
- 4
AI testing and adversarial assurance
Test models, AI applications, knowledge-retrieval systems, and agents for failures and adversarial behavior before and after release.
- Vendors researched
- 16
- Security requirements
- 3
AI gateway and tool-connection controls
Inspect and enforce policy on traffic between AI applications, models, tools, application programming interfaces (APIs), and connections.
- Vendors researched
- 31
- Security requirements
- 4
Agent identity and permissions
Register agents, assign accountable owners, control delegated permissions, and support access review and revocation.
- Vendors researched
- 13
- Security requirements
- 3
Coding-agent and developer workstation security
Control coding assistants and agents across developer tools, commands, files, repositories, packages, networks, and credentials.
- Vendors researched
- 13
- Security requirements
- 3
AI governance, risk, and compliance
Inventory AI systems, assign owners, manage policies and risk reviews, track exceptions, and retain audit evidence.
- Vendors researched
- 19
- Security requirements
- 4
28-vendor research expansion
Newly added vendors
Inclusion adds a vendor to the research set. It does not rate product quality, effectiveness, or suitability for an organization.
Release boundaries
Known limits in this research update
These items remain visible so readers can distinguish completed public-source research from evidence observed by a buyer.
Public-source boundary
This research records published vendor statements and where no supporting statement was found. Tenant configuration, contract rights, implementation quality, and deployed performance require separate evidence.
Live source verification
Sources are checked again before release. Changed or dynamic pages, blocked retrieval, and quote mismatches remain flagged for review; affected claims should not be treated as buyer-ready evidence until they are rechecked.
Pilot feedback data
Reviewer feedback is tied to the signed-in account and stored separately from the research. Do not include client or other confidential information.
Structured evaluation
Review the release in six passes
Progress is stored only in this browser. Use the feedback control after each pass to record what was clear, missing, or difficult.
- Understand the releaseOpen →
Review the changes to vendors, security requirements, solution approaches, and the research experience.
- Explore the marketOpen →
Use the Market map to understand each vendor's public support and solution-area reach.
- Inspect vendor researchOpen →
Open at least one vendor profile and follow its source links and open evaluation questions.
- Trace the evidenceOpen →
Follow a vendor statement from its source into a security requirement and solution area.
- Review a security frameworkOpen →
Open a framework page and confirm that framework relationships, public-evidence limits, and evaluation questions remain distinct.
- Compare public evidenceOpen →
Compare vendors while keeping public evidence separate from product assessment.