ASAI Security ResearchIndependent public-source research
Public reviewread only

Research release 2026.07

July 2026 research update

A dated summary of changes to the solution map, vendor research coverage, and research process in this private pilot.

ReleaseJuly 2026 research expansionPrivate evaluation pilot
Vendors in the research3866+28
Security requirements1319+6
Solution approaches1420+6

Research direction

How the research process changed

Before

A three-step guide that started with a problem and returned a vendor-focused result.

Now

A research workspace that connects overlapping security needs to solution approaches, public evidence, and clear research limits.

Public-source review status

Research coverage is explicit and measurable

Each completed check contains strong or limited public support, or records that no supporting public claim was found. These findings describe available research, not product validation.

99%1174 / 1188 research checks completed
Vendor reviews complete
58 / 66
Strong public support
475
Limited public support
314
No supporting claim found
385
Research incomplete
14

Existing-vendor research update

Completing research for 6 new security requirements

An existing vendor review is up to date only when every new requirement has supporting public evidence or an explicit finding that no supporting claim was found.

100%228 of 228 checks completed
Existing vendors
38
Reviews up to date
38
Vendor reviews remaining
0
Security checks remaining
0
AI governance, risk, and compliance38 completed · 0 remaining
AI assurance and adversarial testing38 completed · 0 remaining
AI model and supply-chain security38 completed · 0 remaining
AI gateway, tool-connection, and runtime controls38 completed · 0 remaining
AI agent identity and permissions38 completed · 0 remaining
AI coding-agent and workstation security38 completed · 0 remaining

How the research connects

From a public claim to a question to verify

The research connects vendor language to consistent security requirements. Public statements and framework references inform the evaluation; effectiveness still requires separate testing.

  1. 01Public vendor statement

    The exact statement and its source.

  2. 02Research finding

    Strong support, limited support, no supporting claim found, or research incomplete.

  3. 03Security requirement

    A consistent evaluation question, independent of vendor wording.

  4. 04Solution approach

    Where the product acts and which security problem it addresses.

  5. 05Framework reference and test

    Relevant guidance and a testable question to verify.

6 new security requirements

Expanded security requirements

These additions cover governance, assurance, model and software supply chains, controls that act while AI runs, agent identity, and coding-agent risk.

Foundational security requirementNew

AI governance, risk, and compliance

Inventory AI systems and owners, translate policy and regulatory obligations into governed workflows, assess risk, manage approvals and exceptions, and retain audit evidence across the AI lifecycle.

Public support found56 / 66 vendors reviewed
Strong public support
36
Limited public support
20
No supporting claim found
10
Research incomplete
0
Representative question to verify

A test AI system is registered with owner, intended use, risk tier, lifecycle state, and applicable obligations.

Review matching evidence →
Foundational security requirementNew

AI assurance and adversarial testing

Test models, applications, retrieval-augmented generation (RAG) systems, and agents before release and continuously thereafter using adversarial probes, evaluation suites, attack simulation, and security release gates.

Public support found27 / 66 vendors reviewed
Strong public support
24
Limited public support
3
No supporting claim found
39
Research incomplete
0
Representative question to verify

A controlled test campaign exercises an AI model, application, or agent against named AI attack classes.

Review matching evidence →
Foundational security requirementNew

AI model and supply-chain security

Discover, inventory, scan, validate, and monitor models, datasets, model artifacts, registries, dependencies, and AI development assets for tampering, unsafe serialization, provenance gaps, or malicious content.

Public support found41 / 66 vendors reviewed
Strong public support
13
Limited public support
28
No supporting claim found
25
Research incomplete
0
Representative question to verify

A test model or AI artifact appears in inventory with origin, version, hash or provenance, and deployment context.

Review matching evidence →
Foundational security requirementNew

AI gateway, tool-connection, and runtime controls

Mediate model, agent, tool, application programming interface (API), connector, and Model Context Protocol (MCP) traffic through an enforcement point that applies identity-aware policy, content controls, routing, rate limits, and auditable allow or deny decisions.

Public support found61 / 66 vendors reviewed
Strong public support
42
Limited public support
19
No supporting claim found
5
Research incomplete
0
Representative question to verify

A model, agent, tool, or Model Context Protocol (MCP) request passes through a named policy enforcement point.

Review matching evidence →
Foundational security requirementNew

AI agent identity and permissions

Register AI agents as accountable identities, bind them to owners and delegating users, authorize task- and tool-level access, issue short-lived credentials, review access, and revoke or suspend agent authority.

Public support found54 / 66 vendors reviewed
Strong public support
15
Limited public support
39
No supporting claim found
12
Research incomplete
0
Representative question to verify

A test agent is registered with a unique identity, accountable owner, purpose, and permitted resources.

Review matching evidence →
Additional security requirementNew

AI coding-agent and workstation security

Discover and govern AI coding agents, integrated development environment (IDE) assistants, command-line agents, skills, hooks, extensions, Model Context Protocol (MCP) tools, filesystem access, commands, network activity, secrets, and software-supply-chain actions on developer workstations and build environments.

Public support found41 / 66 vendors reviewed
Strong public support
14
Limited public support
27
No supporting claim found
25
Research incomplete
0
Representative question to verify

A test coding agent and its skills, hooks, extensions, or Model Context Protocol (MCP) tools appear in an attributable inventory.

Review matching evidence →

Solution relationship map

How the new security requirements connect to solution approaches

A connection means the requirement is commonly relevant when evaluating that type of solution. Vendor-level support is recorded separately.

Security requirementAI API and web application protectionAI testing and adversarial assuranceAI gateway and tool-connection controlsAgent identity and permissionsCoding-agent and developer workstation securityAI governance, risk, and compliance
AI governance56 vendors with public supportCommonly relevant
AI assurance27 vendors with public supportCommonly relevant
Model supply chain41 vendors with public supportCommonly relevantCommonly relevant
AI gateway and tool controls61 vendors with public supportCommonly relevantCommonly relevantCommonly relevant
Agent identity54 vendors with public supportCommonly relevant
Coding-agent security41 vendors with public supportCommonly relevant

Security for models and their related software components is treated as a cross-cutting requirement across configuration, protection while AI runs, assurance, and governance research.

6 new solution approaches

Expanded solution map

These additions make previously grouped product approaches visible and easier to compare.

28-vendor research expansion

Newly added vendors

Inclusion adds a vendor to the research set. It does not rate product quality, effectiveness, or suitability for an organization.

VendorRepresentative core focusWhy it was includedPublic supportAction
Credo AIInitial research expansion · July 2026AI governance, risk, and complianceExtends the market model into enterprise AI governance, policy workflow, risk ownership, and compliance evidence.13requirements with public support · 2 sourcesVendor research →
Backslash Agentic AI Endpoint SecurityInitial research expansion · July 2026Coding-agent and developer workstation securityAdds a focused view of coding-agent, developer-workstation, Model Context Protocol (MCP) tool, and agentic endpoint controls.12requirements with public support · 7 sourcesVendor research →
Orca AI-SPMInitial research expansion · July 2026AI asset and configuration securityExpands AI security posture and cloud/data context for AI assets and workloads.8requirements with public support · 2 sourcesVendor research →
Cloudflare AI Security SuiteInitial research expansion · July 2026Network and cloud access controlsAdds a broad network, application-runtime, AI gateway, and access-control perspective.16requirements with public support · 4 sourcesVendor research →
Obsidian AI SecurityInitial research expansion · July 2026Business-application configuration securityExtends software as a service (SaaS) security posture research into AI applications, identities, and connected-agent activity.15requirements with public support · 5 sourcesVendor research →
BigID AI Security and GovernanceInitial research expansion · July 2026Sensitive-data discovery and accessDeepens data-security, data security posture management (DSPM), generative AI data loss prevention (DLP), AI posture, and governance coverage.13requirements with public support · 4 sourcesVendor research →
CyberArk Secure AI AgentsInitial research expansion · July 2026Agent identity and permissionsAdds privileged access, non-human identity, and agent authorization context.13requirements with public support · 3 sourcesVendor research →
Okta for AI AgentsInitial research expansion · July 2026Agent identity and permissionsAdds agent identity, delegated authorization, and lifecycle-governance context.13requirements with public support · 1 sourcesVendor research →
AktoInitial research expansion · July 2026AI API and web application protectionExpands application programming interface (API), agentic runtime, gateway, coding-agent, and assurance research.14requirements with public support · 4 sourcesVendor research →
Enkrypt AIInitial research expansion · July 2026AI testing and adversarial assuranceAdds assurance, red teaming, runtime protection, and gateway enforcement coverage.13requirements with public support · 7 sourcesVendor research →
MindgardInitial research expansion · July 2026AI testing and adversarial assuranceAdds focused AI assurance, adversarial testing, and application-security research.11requirements with public support · 5 sourcesVendor research →
Holistic AIInitial research expansion · July 2026AI governance, risk, and complianceAdds governance, risk, compliance, and AI assurance coverage.14requirements with public support · 2 sourcesVendor research →
Upwind AI SecurityFollow-on research expansion · July 2026AI asset and configuration securityAdds cloud AI posture, AI bill of materials (AI-BOM), Model Context Protocol (MCP) runtime visibility, and AI application testing coverage.10requirements with public support · 2 sourcesVendor research →
Proofpoint AI Security / AcuvityFollow-on research expansion · July 2026Employee AI access and usage controlsAdds workforce AI, agent intent, browser, endpoint, Model Context Protocol (MCP), application, and data-security coverage under current Proofpoint ownership.11requirements with public support · 2 sourcesVendor research →
Veeam / Securiti AIFollow-on research expansion · July 2026Sensitive-data discovery and accessAdds data and AI discovery, governance, risk, compliance, and agent-control research under current Veeam ownership.8requirements with public support · 2 sourcesVendor research →
Snyk EvoFollow-on research expansion · July 2026Coding-agent and developer workstation securityAdds coding-agent security, AI bill of materials (AI-BOM), action guardrails, generated-code validation, and offensive testing coverage.7requirements with public support · 1 sourcesVendor research →
ModelOpFollow-on research expansion · July 2026AI governance, risk, and complianceAdds AI system-of-record, lifecycle governance, risk, approval, monitoring, audit, cost, and value-management coverage.5requirements with public support · 1 sourcesVendor research →
LatticeFlow AIFollow-on research expansion · July 2026AI testing and adversarial assuranceAdds technical evaluation, adversarial testing, framework mapping, agent assessment, and continuous-monitoring coverage.5requirements with public support · 1 sourcesVendor research →
RunlayerFollow-on research expansion · July 2026AI gateway and tool-connection controlsAdds Model Context Protocol (MCP) and agent discovery, governed catalog, identity-aware policy, runtime inspection, audit, and spend visibility.10requirements with public support · 1 sourcesVendor research →
KeycardFollow-on research expansion · July 2026Agent identity and permissionsAdds composite agent identity, runtime authorization, task-scoped credentials, revocation, and attributed audit coverage.7requirements with public support · 1 sourcesVendor research →
Akamai API SecurityAPI security expansion · July 2026AI API and web application protectionAdds AI-, large language model (LLM)-, and Model Context Protocol (MCP)-aware application programming interface (API) discovery, posture, testing, and separately bounded AI firewall controls under current Akamai ownership.4requirements with public support · 2 sourcesVendor research →
Salt Agentic Security PlatformAPI security expansion · July 2026AI API and web application protectionAdds application programming interface (API) action-layer discovery, posture, runtime protection, Model Context Protocol (MCP), agent-to-agent (A2A), agent, and AI-assisted development policy coverage.9requirements with public support · 3 sourcesVendor research →
Harness AI Security / TraceableAPI security expansion · July 2026AI API and web application protectionAdds Traceable-lineage AI asset discovery, AI application testing, sensitive-data inspection, guardrails, and runtime protection under Harness.5requirements with public support · 1 sourcesVendor research →
Wallarm AI Control PlatformAPI security expansion · July 2026AI API and web application protectionAdds AI- and application programming interface (API)-runtime discovery, Model Context Protocol (MCP) policy, agent-session enforcement, supply-chain evidence, and bounded assurance coverage.9requirements with public support · 2 sourcesVendor research →
Cequence AI GatewayAPI security expansion · July 2026AI API and web application protectionAdds Model Context Protocol (MCP) and application programming interface (API) mediation, trusted registries, agent personas, tool-scoped authorization, runtime guardrails, and auditability.10requirements with public support · 1 sourcesVendor research →
Imperva AI Application SecurityAPI security expansion · July 2026AI API and web application protectionAdds a purpose-built inline generative AI application control for prompt, output, sensitive-data, and abusive-consumption risk.5requirements with public support · 1 sourcesVendor research →
Kong AI GatewayAPI security expansion · July 2026AI gateway and tool-connection controlsAdds large language model (LLM), Model Context Protocol (MCP), and agent-to-agent (A2A) traffic governance with guardrails, authorization, observability, quotas, and usage attribution.9requirements with public support · 2 sourcesVendor research →
Speakeasy AI Control PlaneAPI security expansion · July 2026AI gateway and tool-connection controlsAdds identity-aware Model Context Protocol (MCP) and agent access, tool permissions, runtime inspection, data loss prevention (DLP), threat controls, audit, tracing, and usage attribution.11requirements with public support · 2 sourcesVendor research →

Release boundaries

Known limits in this research update

These items remain visible so readers can distinguish completed public-source research from evidence observed by a buyer.

Public-source boundary

This research records published vendor statements and where no supporting statement was found. Tenant configuration, contract rights, implementation quality, and deployed performance require separate evidence.

Live source verification

Sources are checked again before release. Changed or dynamic pages, blocked retrieval, and quote mismatches remain flagged for review; affected claims should not be treated as buyer-ready evidence until they are rechecked.

Pilot feedback data

Reviewer feedback is tied to the signed-in account and stored separately from the research. Do not include client or other confidential information.

Structured evaluation

Review the release in six passes

Progress is stored only in this browser. Use the feedback control after each pass to record what was clear, missing, or difficult.

0 / 6 complete
  1. Understand the release

    Review the changes to vendors, security requirements, solution approaches, and the research experience.

    Open →
  2. Explore the market

    Use the Market map to understand each vendor's public support and solution-area reach.

    Open →
  3. Inspect vendor research

    Open at least one vendor profile and follow its source links and open evaluation questions.

    Open →
  4. Trace the evidence

    Follow a vendor statement from its source into a security requirement and solution area.

    Open →
  5. Review a security framework

    Open a framework page and confirm that framework relationships, public-evidence limits, and evaluation questions remain distinct.

    Open →
  6. Compare public evidence

    Compare vendors while keeping public evidence separate from product assessment.

    Open →