Company scale
Established?
EstablishedA provider with at least $1B in annual revenue, at least 1,000 employees, or backing from an established owner.This is a company-maturity signal, not a product-quality rating.
A descriptive band derived from retained public revenue, workforce, ownership, or funding signals.
Company scale is separate from product features, effectiveness, and suitability.- $1B annual revenue (2026-01-31)
- $23M known funding
- 11-50 employees
- Founded 2023
Detailed security-requirement research18 evaluation items · supporting evidence and open research are shown separatelyExpand
Security requirementPublic supportRelated frameworksWhat to verify
Unapproved AI use discoveryDiscover and monitor workforce AI tools, accounts, prompts, domains, models, users, and usage outside approved controls.
Strong public supportAn unmanaged AI app used by a test user appears in discovery inventory with user, app or domain, and timestamp.
AI-feature discovery in business applicationsInventory software as a service (SaaS) applications that embed AI features, expose enterprise data to AI capabilities, or create AI-driven data movement.
No supporting claim foundA software as a service (SaaS) app with an embedded AI feature appears in the software as a service (SaaS) AI inventory with app, provider, and feature context.
Approved AI usage monitoringMonitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.
Limited public supportApproved AI workspace activity appears with user, workspace or tenant, model or provider, and timestamp.
Controls for unapproved AI useBlock, coach, redirect, or contain non-approved AI use and policy-violating AI interactions.
Strong public supportA policy blocks, coaches, redirects, or contains a test interaction with an unapproved AI destination.
Sensitive-data protection for generative AIDetect, classify, redact, or block sensitive data in prompts, responses, files, retrieval, memory, and AI-connected workflows.
Strong public supportSensitive prompt, response, or file test data is detected and classified during an AI interaction.
Browser and business-application controlsApply session-level controls in browser and software as a service (SaaS) workflows, including uploads, downloads, copy/paste, sharing, and identity-aware access decisions.
Strong public supportA session-level policy controls upload, download, copy, paste, sharing, or form submission in a browser or software as a service (SaaS) workflow.
Generative AI application securityProtect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.
Strong public supportA test large language model (LLM) application event records prompt, application programming interface (API), model, retrieval, or tool interaction context.
AI governance, risk, and complianceInventory AI systems and owners, translate policy and regulatory obligations into governed workflows, assess risk, manage approvals and exceptions, and retain audit evidence across the AI lifecycle.
Strong public supportA test AI system is registered with owner, intended use, risk tier, lifecycle state, and applicable obligations.
AI assurance and adversarial testingTest models, applications, retrieval-augmented generation (RAG) systems, and agents before release and continuously thereafter using adversarial probes, evaluation suites, attack simulation, and security release gates.
Strong public supportA controlled test campaign exercises an AI model, application, or agent against named AI attack classes.
AI model and supply-chain securityDiscover, inventory, scan, validate, and monitor models, datasets, model artifacts, registries, dependencies, and AI development assets for tampering, unsafe serialization, provenance gaps, or malicious content.
Limited public supportA test model or AI artifact appears in inventory with origin, version, hash or provenance, and deployment context.
AI gateway, tool-connection, and runtime controlsMediate model, agent, tool, application programming interface (API), connector, and Model Context Protocol (MCP) traffic through an enforcement point that applies identity-aware policy, content controls, routing, rate limits, and auditable allow or deny decisions.
Strong public supportA model, agent, tool, or Model Context Protocol (MCP) request passes through a named policy enforcement point.
Action-taking agent monitoringObserve and govern agent plans, memory, tool calls, delegated tasks, autonomy, runtime decisions, and outcomes.
Strong public supportA test agent run captures plan, steps, tool calls, outcome, and timestamps.
Agent-to-agent communication securityAuthorize, log, and control agent-to-agent, agent-to-tool, Model Context Protocol (MCP), connector, and tool-chain handoffs.
Limited public supportAn agent, tool, connector, or Model Context Protocol (MCP) handoff logs source identity, destination, and authorization decision.
Non-human identity and service-account securityInventory, least privilege, credential hygiene, monitoring, and lifecycle management for non-human identities, workloads, service accounts, application programming interface (API) keys, and machine credentials.
Limited public supportA test service account, agent identity, or non-human identity appears in inventory with owner and privileges.
AI agent identity and permissionsRegister AI agents as accountable identities, bind them to owners and delegating users, authorize task- and tool-level access, issue short-lived credentials, review access, and revoke or suspend agent authority.
Limited public supportA test agent is registered with a unique identity, accountable owner, purpose, and permitted resources.
AI coding-agent and workstation securityDiscover and govern AI coding agents, integrated development environment (IDE) assistants, command-line agents, skills, hooks, extensions, Model Context Protocol (MCP) tools, filesystem access, commands, network activity, secrets, and software-supply-chain actions on developer workstations and build environments.
Strong public supportA test coding agent and its skills, hooks, extensions, or Model Context Protocol (MCP) tools appear in an attributable inventory.
AI cost and usage controlsVisibility, attribution, budgeting, rate limiting, anomaly detection, and optimization for AI usage and spend across models, agents, workflows, and owners.
No supporting claim foundA controlled AI usage event is attributed to user, team, model, workflow, or owner with cost or token metrics.
Licensing modelPublicly discoverable commercial model such as per user, per seat, per app, per token, per integration, or enterprise platform license.
No supporting claim foundThe vendor can map the sourced commercial model to per-user, per-seat, per-app, per-token, per-integration, or platform packaging.
AI governance, risk, and complianceSource checkedStrong public support for this requirement
Prompt Security claims enterprise AI and Model Context Protocol (MCP) discovery, risk scoring, policy enforcement, searchable interaction logs, role-based controls, compliance policy, drift monitoring, and human oversight for agentic systems.
Get complete, searchable logs of every interaction for risk management.
AI assurance and adversarial testingSource checkedStrong public support for this requirement
Prompt Security claims automated preproduction and continuous red teaming for prompt injection, data exposure, privilege escalation, jailbreaks, unsafe agent behavior, drift, and other AI-specific risks with evidence and remediation guidance.
Run pre-production red teaming, prioritize issues using risk scoring and evidence, and confidently ship production-ready AI applications.
AI model and supply-chain securitySource checkedLimited public support for this requirement
Prompt Security claims dynamic risk scoring of more than 13,000 Model Context Protocol (MCP) servers, vulnerability profiles, certification checks, shadow-server discovery, and agent skill integrity and drift checks.
MCP risk scoring, dynamically assessing over 13,000 MCP servers on GitHub to identify emerging threats.
AI gateway, tool-connection, and runtime controlsSource checkedStrong public support for this requirement
Prompt Security claims an AI and Model Context Protocol (MCP) Gateway that inspects requests, responses, prompts, templates, agent actions, and server interactions in real time with allow or block policy, threat intelligence, data loss prevention (DLP), and endpoint enforcement.
Inspecting every request and response in real time to protect sensitive data and information.
AI agent identity and permissionsSource checkedLimited public support for this requirement
Prompt Security claims granular policy by user, group, server, and action plus attribution of AI use, data sharing, agent responses, and Model Context Protocol (MCP) activity.
Allow/block by user, server, or action according to your security policy.
AI coding-agent and workstation securitySource checkedStrong public support for this requirement
Prompt Security claims endpoint and integrated development environment (IDE)-integrated governance for coding assistants, Model Context Protocol (MCP) servers, exposed commands, secrets, PII, generated code, prompt responses, and action-level policy across tools including Cursor and GitHub Copilot.
Fine-grained policies that determine which MCPs are allowed, which commands can be run, and under what circumstances.