Framework Explorer

NIST AI RMF

Reviewed AuditaAI assessments connect documented offering behavior to NIST AI RMF functions. These alignments are not a representation of NIST conformance.

Official NIST source

AI RMF Function

GOVERN

Cultivate and implement a culture of risk management for AI systems.

1 alignments
Reviewed offering assessments+
Portkey · PortkeyInferred alignment

Portkey centralizes authentication, access, and observability for LLM providers and MCP servers through its gateways.

AuditaAI assessment: centralized authentication, access, and observability supports operational AI risk-governance practices.

AI RMF Function

MAP

Establish context and identify risks associated with AI systems.

19 alignments
Reviewed offering assessments+

Tenable One AI Exposure provides continuous discovery of AI assets and attack-surface context across software and infrastructure environments.

AI asset and attack-surface discovery aligns with mapping AI systems, context, and related risk boundaries.

AWS AI Security Framework and Security Hub posture workflows support layered AI control oversight and detection of risky configuration conditions.

Layered AI control oversight and risk visibility align with mapping AI context and exposure boundaries.

Cato AI Security governs sanctioned and unsanctioned enterprise AI usage through interaction-level visibility and policy enforcement.

Visibility and governance over sanctioned and unsanctioned AI interaction channels align with NIST MAP context establishment.

Wiz · Wiz AI-BOMInferred alignment

Wiz AI-BOM continuously inventories AI models, datasets, frameworks, software dependencies, identities, access paths, and infrastructure.

AuditaAI assessment: component inventory establishes risk context for AI systems and their dependencies.

Security Command Center discovers and inventories AI assets across agents, data, models, applications, platforms, and infrastructure.

AuditaAI assessment: inventorying AI assets establishes AI-system context and related risk surfaces.

Sensitive Data Protection continuously discovers and classifies sensitive data across organizational data assets.

AuditaAI assessment: sensitive-data discovery identifies data context relevant to AI risk.

Wiz · Wiz AI-SPMInferred alignment

Wiz AI-SPM discovers and catalogs AI models, agents, services, technologies, SDKs, pipelines, and related cloud infrastructure without agents.

AuditaAI assessment: discovering AI components and infrastructure establishes AI-system context.

Lasso Discovery and AI-BOM inventories agents, tools, models, prompts, and guardrails with change tracking across environments.

AI inventory and observability workflows align with mapping AI context and system boundaries.

AI Discovery and Recon identifies models, agents, MCP servers, tools, and shadow AI to map AI attack surface and exposure.

AI asset and attack-surface discovery aligns with mapping AI systems and risk context.

Defender for Cloud AI posture capabilities discover and inventory AI resources and workloads for security posture visibility.

AI asset discovery and inventory are core activities for mapping AI systems, context, and exposure surfaces.

Neo Security Platform provides visibility into risky misconfigurations and permission issues across enterprise software environments.

Visibility into AI-relevant misconfiguration and permission context supports mapping AI risk surfaces.

Prisma AIRS provides posture visibility and policy management for AI assets, training and inference data, application integrity, and model access.

AuditaAI assessment: visibility into AI assets, data, application integrity, and model access establishes risk context.

AI Access Security discovers and categorizes GenAI applications, agents, marketplace plugins, usage, and users.

AuditaAI assessment: discovering GenAI applications, agents, plugins, usage, and users establishes risk context.

Koi AES discovers and catalogs autonomous software agents, AI agents, browser extensions, software, and AI models on enterprise endpoints.

AuditaAI assessment: endpoint discovery of autonomous software and AI models establishes system context.

Prompt Security provides enterprise visibility over GenAI usage patterns and interaction channels.

Enterprise AI usage visibility aligns with AI context mapping and risk-surface identification.

Zenity · AI ObservabilityInferred alignment

Zenity AI Observability builds live inventory of agents, owners, permissions, and touched data across SaaS, cloud, and endpoint environments.

Agent inventory and observability align with mapping AI context, assets, and risk boundaries.

Zscaler AI Security discovers and maps AI applications, models, MCP servers, development tools, data pipelines, and related risks.

AuditaAI assessment: mapping AI applications, models, MCP servers, and pipelines establishes AI-system context.

Zscaler Data Security discovers and classifies sensitive data and uses contextual classification to identify data risk across GenAI and other channels.

AuditaAI assessment: classifying sensitive data identifies data context for AI risk management.

Zscaler Data Security provides data posture controls for GenAI and adjacent channels by combining contextual classification with risk identification.

AuditaAI assessment: contextual data risk identification contributes to AI-system context and posture mapping.

AI RMF Function

MEASURE

Assess, analyze, benchmark, monitor, and document AI risks.

22 alignments
Reviewed offering assessments+

Tenable One AI Exposure analyzes AI posture and misconfiguration conditions to prioritize exposure reduction for AI workloads.

Posture and misconfiguration analysis provide measurable evidence for AI risk assessment.

SageMaker Clarify and monitoring workflows provide ongoing model and data behavior analysis for drift, quality, and governance evidence.

Ongoing model and data behavior monitoring contributes measurable evidence for AI risk assessment and assurance.

Chainguard states that library artifacts are built from source with full provenance and signed SBOMs.

SBOM and provenance records provide analyzable traceability evidence for AI risk assessment workflows.

AI Red Teaming runs broad and targeted adversarial campaigns to assess AI applications and agents for prompt injection, jailbreak, data leakage, unauthorized actions, and regressions.

Structured adversarial campaigns provide measurable evidence for AI risk assessment and validation.

AI Model and Application Validation performs algorithmic red teaming and model vulnerability validation for AI applications and models.

Algorithmic red teaming and vulnerability validation contribute evidence for assessing AI risks.

Security Command Center assesses interconnected AI risks and prioritizes high-risk issues using posture analysis and virtual red teaming.

AuditaAI assessment: posture analysis, prioritization, and virtual red teaming assess documented AI risk.

Security Command Center detects AI-specific threats across the AI stack.

AuditaAI assessment: detecting AI-specific threats provides ongoing risk measurement signals.

Wiz · Wiz AI-SPMInferred alignment

Wiz AI-SPM applies built-in configuration rules to detect misconfigured AI services and unsafe deployments.

AuditaAI assessment: configuration rules assess unsafe AI-service deployments.

Wiz · Wiz AI-SPMInferred alignment

Wiz AI-SPM connects infrastructure, identity, models, data, and applications to uncover and prioritize exploitable AI attack paths.

AuditaAI assessment: analyzing and prioritizing exploitable attack paths assesses AI risk.

Wiz · Wiz DSPM for AIInferred alignment

Wiz DSPM for AI detects sensitive training data, identifies leakage risk, and exposes attack paths to that data.

AuditaAI assessment: detecting sensitive training data and its exposure paths measures AI data risk.

Wiz AI Runtime Protection detects prompt injection, rogue agents, and malicious behavior targeting AI systems.

AuditaAI assessment: runtime detection of malicious AI behavior measures operational risk.

AI Attack Simulation tests AI systems for jailbreaks, prompt injection, data leakage, and unsafe agent tool use through automated adversarial simulation.

Automated adversarial testing contributes evidence for AI risk measurement.

Lasso AI Security Posture Management evaluates misconfigurations and policy gaps, including supply-chain-oriented risk indicators before production rollout.

Posture and supply-risk assessment workflows provide measurable evidence for AI risk assessment.

Lasso automated AI red teaming runs adversarial testing against agentic workflows to identify exploitable weaknesses.

Adversarial red teaming produces measurement evidence for AI security risk and control effectiveness.

AI Red Teaming and Assessment runs adversarial workflows to surface jailbreak and guardrail-bypass weaknesses for pre-deployment remediation.

Adversarial assessments produce measurable evidence for AI risk assessment and control effectiveness.

Microsoft Purview for AI provides classification and compliance tracking artifacts that support governance review of AI information handling.

Compliance tracking artifacts and classification evidence support measurement and assessment of AI governance controls.

Prisma AIRS simulates real-world attacks against single-agent and multi-agent AI systems to identify weaknesses before production.

AuditaAI assessment: simulated attacks against AI systems assess weaknesses before production.

Prisma AIRS scans third-party models for tampering, malicious scripts, and deserialization risks.

AuditaAI assessment: scanning model artifacts assesses documented tampering and malicious-content risk.

Prisma AIRS provides posture visibility and policy management for AI assets, training and inference data, application integrity, and model access.

AuditaAI assessment: posture visibility and policy management assess documented AI asset risk.

Koi AES evaluates code differences and behavioral shifts in real time to identify software supply-chain risk.

AuditaAI assessment: real-time analysis of code and behavioral shifts measures supply-chain risk.

Zenity posture workflows evaluate configuration and permission risk for agents before and during deployment.

Configuration and permission-risk evaluation provides measurable evidence for agent security posture.

SPLX · SPLX AI Red TeamingInferred alignment

Zscaler AI Security runs configurable attack simulations to identify AI vulnerabilities and provide remediation guidance before and during deployment.

AuditaAI assessment: attack simulation to identify AI vulnerabilities is a risk-assessment activity.

AI RMF Function

MANAGE

Prioritize, respond to, and monitor AI risks.

21 alignments
Reviewed offering assessments+

Aiceberg Guardian Agent provides runtime visibility and guardrail control over agentic AI decision flows.

Runtime guardrail control over agentic decisions contributes to ongoing risk treatment and management activities.

Google Cloud · Model ArmorInferred alignment

Model Armor scans prompts and responses for prompt injection and jailbreak content and can return a block verdict when a violation is detected.

AuditaAI assessment: blocking detected prompt-injection and jailbreak content is a documented risk response.

Google Cloud · Model ArmorInferred alignment

Model Armor can inspect, transform, tokenize, and redact sensitive elements in AI prompts and responses through Sensitive Data Protection integration.

AuditaAI assessment: tokenization and redaction are documented actions to manage sensitive-data exposure risk.

Security Command Center provides response workflows for AI-specific threats across the AI stack.

AuditaAI assessment: response workflows manage AI-specific threats after detection.

Sensitive Data Protection classifies and de-identifies sensitive content used for model training, tuning, and generative AI prompts and responses.

AuditaAI assessment: de-identification is a documented action to manage sensitive-data exposure in AI workflows.

Lasso AI detection and response workflows identify and triage suspicious AI behavior using contextual attack telemetry.

Detection and triage workflows align with ongoing risk treatment and incident management.

Mindgard platform workflows include risk analysis and remediation guidance to prioritize treatment of AI security findings.

Risk analysis and remediation guidance align with ongoing AI risk treatment and management workflows.

Microsoft Copilot for Security supports analyst investigation and response workflows to accelerate triage and containment actions.

Analyst response and triage support aligns with ongoing risk treatment and incident response management workflows.

Neo Security Platform analyzes security gaps across agentic and non-agentic software to surface exposure conditions that require remediation.

Gap analysis and remediation prioritization align with ongoing AI risk treatment and management activities.

Data Detection and Response performs real-time scanning with automated quarantine, notification, and remediation workflows for risky content flows.

Real-time remediation and containment workflows align with ongoing AI risk treatment and management activities.

Prisma AIRS applies real-time safeguards to AI prompts, responses, model interactions, agent actions, and data exposure paths.

AuditaAI assessment: real-time safeguards for prompts, responses, agents, and data paths are documented risk responses.

Prisma AIRS verifies agent identity and enforces real-time security controls for agent actions.

AuditaAI assessment: enforcing real-time controls on agent actions manages documented autonomous-action risk.

AI Access Security classifies GenAI applications by sanction status and can revoke access or control upload and download actions based on risk and privilege.

AuditaAI assessment: revoking access and controlling transfer actions manage application-use risk.

AI Access Security classifies sensitive content inline and blocks sensitive text and file transfers to GenAI applications.

AuditaAI assessment: inline classification and blocking manage sensitive-data transfer risk.

Portkey · PortkeyInferred alignment

Portkey automatically redacts sensitive data from requests before sending them to an LLM.

AuditaAI assessment: pre-request redaction manages sensitive-data disclosure risk.

Koi AES enforces endpoint guardrails that approve, flag, or block autonomous tools.

AuditaAI assessment: tool approval and blocking are documented actions to manage autonomous-action risk.

Cortex AI Gateway centralizes access policy, authentication, and tool-permission controls across first-party and third-party MCP-connected agent workflows.

Centralized policy, access, and governance controls for live agent interactions align with NIST AI RMF MANAGE operations.

Zenity behavioral runtime telemetry supports detection and investigation of unsafe or manipulative AI outcomes.

Detection and investigation workflows support ongoing treatment and management of AI runtime risk.

Zscaler Data Security inspects AI usage and prompts and can block risky access or enforce prompt DLP to prevent data loss.

AuditaAI assessment: inline DLP enforcement is a documented response to identified data-loss risk.

Zscaler AI Security can warn, block, or isolate user access to AI applications under acceptable-use and data-protection policies.

AuditaAI assessment: warning, blocking, and isolating application access is a documented risk response.

Zscaler AI Security runtime protection blocks prompt injection, data poisoning, and malicious URLs in AI interactions.

AuditaAI assessment: runtime blocking manages documented malicious AI interaction risk.