Framework Explorer

NIST CSF 2.0

Reviewed AuditaAI assessments connect documented offering behavior to NIST CSF outcome functions. These alignments are contextual contribution evidence, not a representation of NIST conformance.

Official NIST source

0 low-confidence alignments are hidden by default.

CSF Function GV

GOVERN

Establish and monitor the organization's cybersecurity risk management strategy, expectations, and policy.

12 reviewed alignments
Reviewed offering assessments+
Tenable Holdings, Inc. · Tenable One AI ExposureInferred alignmentmedium confidence · 2 sources

Tenable One AI Exposure analyzes AI posture and misconfiguration conditions to prioritize exposure reduction for AI workloads.

AuditaAI assessment: posture and misconfiguration analysis supports governance decisions for AI risk treatment.

Amazon Web Services · Amazon Bedrock AgentCoreInferred alignmentmedium confidence · 1 source

AWS supports human approval hooks for high-consequence agent actions and behavioral monitoring for actions outside an agent's authorized scope.

AuditaAI assessment: explicit human approval hooks and out-of-scope behavioral monitoring support risk-governance expectations for high-consequence autonomous actions.

Cato Networks · Cato AI Security (AISEC)Inferred alignmentmedium confidence · 1 source

Cato AI Security governs sanctioned and unsanctioned enterprise AI usage through interaction-level visibility and policy enforcement.

AuditaAI assessment: governance over sanctioned and unsanctioned AI usage supports organizational policy and risk-governance outcomes.

Chainguard · Chainguard Secure AI SDLCInferred alignmentmedium confidence · 1 source

Chainguard AI Security documents software supply chain coverage across SDLC phases, including trusted dependencies, CI/CD integrity, and hardened runtime foundations.

AuditaAI assessment: supply-chain coverage across SDLC phases supports governance and risk-management policy outcomes.

Cisco · AI Supply Chain Risk ManagementInferred alignmentmedium confidence · 1 source

Cisco AI Supply Chain Risk Management provides governance and security over AI models and files used by AI applications and agents.

AuditaAI assessment: governance and security posture over AI models and files supports organizational risk governance for AI supply-chain exposure.

Google Cloud · Security Command CenterInferred alignmentmedium confidence · 1 source

Security Command Center assesses interconnected AI risks and prioritizes high-risk issues using posture analysis and virtual red teaming.

AuditaAI assessment: posture analysis and prioritized remediation support organizational risk-governance decisions for AI exposure.

Lasso Security · AI Security Posture ManagementInferred alignmentmedium confidence · 2 sources

Lasso AI Security Posture Management evaluates misconfigurations and policy gaps, including supply-chain-oriented risk indicators before production rollout.

AuditaAI assessment: evaluating misconfigurations and policy gaps supports organizational risk-governance decisions and treatment planning.

Mindgard · Mindgard AI Security PlatformInferred alignmentmedium confidence · 1 source

Mindgard platform workflows include risk analysis and remediation guidance to prioritize treatment of AI security findings.

AuditaAI assessment: risk analysis and remediation prioritization support governance decisions for AI-security treatment.

Microsoft · Microsoft Defender for Cloud (AI-SPM)Inferred alignmentmedium confidence · 1 source

Defender for Cloud AI posture capabilities provide risk prioritization signals to focus remediation for high-impact AI exposure paths.

AuditaAI assessment: risk-prioritization workflows for high-impact AI exposure support organizational cybersecurity risk governance.

NEO · Neo Security PlatformInferred alignmentmedium confidence · 1 source

Neo Security Platform analyzes security gaps across agentic and non-agentic software to surface exposure conditions that require remediation.

AuditaAI assessment: gap analysis and remediation prioritization support governance and risk-treatment decision making.

Okta · Okta for AI AgentsInferred alignmentmedium confidence · 2 sources

Okta registers AI agents as first-class identities in Universal Directory with mandatory human owner binding and lifecycle governance.

AuditaAI assessment: mandatory human owner binding and identity lifecycle workflows support governance expectations for autonomous-agent risk.

Zenity · AI Security Posture ManagementInferred alignmentmedium confidence · 2 sources

Zenity posture workflows evaluate configuration and permission risk for agents before and during deployment.

AuditaAI assessment: configuration and permission-risk evaluation supports governance and risk-treatment decisions.

CSF Function ID

IDENTIFY

Understand current cybersecurity risks to systems, assets, data, and capabilities.

19 reviewed alignments
Reviewed offering assessments+
Tenable Holdings, Inc. · Tenable One AI ExposureInferred alignmenthigh confidence · 2 sources

Tenable One AI Exposure provides continuous discovery of AI assets and attack-surface context across software and infrastructure environments.

AuditaAI assessment: continuous AI asset discovery and attack-surface context establish cybersecurity risk identification context.

Amazon Web Services · Amazon Bedrock AgentCoreInferred alignmenthigh confidence · 1 source

Amazon Bedrock AgentCore Registry catalogs agents and MCP servers for centralized governance and observability.

AuditaAI assessment: centralized agent and MCP server cataloging provides asset visibility and context needed to identify current cybersecurity risk.

Chainguard · Chainguard LibrariesInferred alignmentmedium confidence · 1 source

Chainguard states that library artifacts are built from source with full provenance and signed SBOMs.

AuditaAI assessment: provenance and SBOM records improve visibility into component makeup and supply-chain risk context.

Check Point Software Technologies · AI Agent SecurityInferred alignmenthigh confidence · 1 source

AI Agent Security discovers agents and assesses their tool and MCP access surface for security risk.

AuditaAI assessment: discovering agents and assessing tool/MCP access surfaces establishes cybersecurity context.

Cisco · AI Cloud VisibilityInferred alignmenthigh confidence · 1 source

AI Cloud Visibility provides discovery and inventory context for AI workloads, models, data, and users.

AuditaAI assessment: AI workload and model inventory establishes context for identifying cybersecurity risk.

Google Cloud · Security Command CenterInferred alignmenthigh confidence · 1 source

Security Command Center discovers and inventories AI assets across agents, data, models, applications, platforms, and infrastructure.

AuditaAI assessment: inventorying agents, data, models, applications, and infrastructure establishes cybersecurity risk context.

Wiz · Wiz AI-SPMInferred alignmenthigh confidence · 1 source

Wiz AI-SPM discovers and catalogs AI models, agents, services, technologies, SDKs, pipelines, and related cloud infrastructure without agents.

AuditaAI assessment: AI model, agent, service, and infrastructure discovery supports identifying risk context across environments.

Harmonic Security · Harmonic Security PlatformInferred alignmenthigh confidence · 1 source

Harmonic Security discovers and catalogs enterprise generative AI application usage (Shadow AI), categorizing application risk posture and data compliance across cloud and endpoint environments.

AuditaAI assessment: discovering shadow AI usage and inventorying AI systems supports identifying organizational cybersecurity and AI risks.

Lasso Security · Discovery and AI-BOMInferred alignmenthigh confidence · 2 sources

Lasso Discovery and AI-BOM inventories agents, tools, models, prompts, and guardrails with change tracking across environments.

AuditaAI assessment: inventory and change tracking for agents, tools, models, prompts, and guardrails establishes AI-system cybersecurity context.

Mindgard · AI Discovery and ReconInferred alignmenthigh confidence · 1 source

AI Discovery and Recon identifies models, agents, MCP servers, tools, and shadow AI to map AI attack surface and exposure.

AuditaAI assessment: discovery of models, agents, MCP servers, and tools establishes AI-system context for cybersecurity risk identification.

Microsoft · Microsoft Defender for Cloud (AI-SPM)Inferred alignmenthigh confidence · 1 source

Defender for Cloud AI posture capabilities discover and inventory AI resources and workloads for security posture visibility.

AuditaAI assessment: AI resource discovery and inventory establish current cybersecurity context for AI systems and workloads.

Microsoft · Microsoft Agent 365Inferred alignmenthigh confidence · 2 sources

Microsoft Agent 365 powers a centralized inventory and posture view of Microsoft and supported non-Microsoft agents, including identities, tools, MCP servers, risk indicators, alerts, and recommendations.

AuditaAI assessment: cross-platform inventory of agent identities, tools, MCP servers, and risk indicators supports identifying current cybersecurity risk.

NEO · Neo Security PlatformInferred alignmentmedium confidence · 1 source

Neo Security Platform provides visibility into risky misconfigurations and permission issues across enterprise software environments.

AuditaAI assessment: visibility into risky misconfiguration and permission conditions establishes context for identifying cybersecurity exposure.

Okta · Okta for AI AgentsInferred alignmenthigh confidence · 2 sources

Okta registers AI agents as first-class identities in Universal Directory with mandatory human owner binding and lifecycle governance.

AuditaAI assessment: registering AI agents as identities with ownership and permission context supports identifying current cybersecurity risk.

Palo Alto Networks · Prisma AIRSInferred alignmenthigh confidence · 1 source

Prisma AIRS provides posture visibility and policy management for AI assets, training and inference data, application integrity, and model access.

AuditaAI assessment: posture visibility for AI assets, data, application integrity, and model access establishes risk context needed to identify cybersecurity risk.

Idira · Idira Secure AI AgentsInferred alignmenthigh confidence · 1 source

Idira Secure AI Agents scans SaaS, cloud, and developer environments to discover active AI agents and enriches each one with ownership, purpose, status, and permission-level context in a centralized registry.

AuditaAI assessment: agent discovery plus contextual registry details support identifying AI-agent asset and permission risk.

Prompt Security · Prompt SecurityInferred alignmentmedium confidence · 1 source

Prompt Security provides enterprise visibility over GenAI usage patterns and interaction channels.

AuditaAI assessment: enterprise visibility over GenAI interaction channels establishes cybersecurity context and exposure identification.

Zenity · AI ObservabilityInferred alignmenthigh confidence · 2 sources

Zenity AI Observability builds live inventory of agents, owners, permissions, and touched data across SaaS, cloud, and endpoint environments.

AuditaAI assessment: live inventory of agents, owners, permissions, and data touchpoints establishes AI cybersecurity context.

SPLX · SPLX AI Asset ManagementInferred alignmenthigh confidence · 2 sources

Zscaler AI Security discovers and maps AI applications, models, MCP servers, development tools, data pipelines, and related risks.

AuditaAI assessment: AI asset and pipeline discovery establishes context for identifying cybersecurity risk across agentic systems.

CSF Function PR

PROTECT

Use safeguards to manage and reduce cybersecurity risk.

39 reviewed alignments
Reviewed offering assessments+
Aiceberg · Aiceberg Guardian AgentInferred alignmenthigh confidence · 2 sources

Aiceberg Guardian Agent provides runtime visibility and guardrail control over agentic AI decision flows.

AuditaAI assessment: runtime visibility and guardrail control over agentic decision flows is a preventive safeguard.

Amazon Web Services · Amazon Bedrock AgentCoreInferred alignmenthigh confidence · 1 source

Amazon Bedrock AgentCore gives agents distinct scoped identities and uses Cedar policy to authorize every tool call and data access independently of model reasoning.

AuditaAI assessment: per-agent scoped identity and Cedar authorization enforce safeguards that reduce unauthorized tool and data access.

Amazon Web Services · Amazon Bedrock AgentCoreInferred alignmenthigh confidence · 1 source

Amazon Bedrock AgentCore applies identity and authorization controls to agents using MCP and A2A communications with external tools and other agents.

AuditaAI assessment: identity and authorization controls over MCP and A2A communications provide safeguards for agent-to-tool and agent-to-agent interactions.

Cato Networks · Cato AI Security (AISEC)Inferred alignmenthigh confidence · 1 source

Cato AI Security applies inline controls to block sensitive data exfiltration to unauthorized AI services and channels.

AuditaAI assessment: inline controls blocking sensitive-data exfiltration are direct preventive safeguards.

Cato Networks · Cato AI Security (AISEC)Inferred alignmenthigh confidence · 2 sources

Cato AI Security governance controls constrain unsafe autonomous actions and high-risk tool usage for AI agents and applications.

AuditaAI assessment: governance controls constraining unsafe actions and high-risk tool usage are preventive safeguards.

Chainguard · Chainguard LibrariesInferred alignmenthigh confidence · 1 source

Chainguard Libraries provides a malware-resistant dependency catalog intended to replace direct reliance on public package registries.

AuditaAI assessment: curated malware-resistant dependencies are preventive safeguards against compromised components.

Chainguard · Chainguard FactoryInferred alignmenthigh confidence · 1 source

Chainguard Factory applies SHA-pinned source inputs, isolated SLSA L3 build controls, cryptographic signing, and reproducibility checks when producing artifacts.

AuditaAI assessment: pinned inputs, isolated builds, signing, and reproducibility checks protect artifact integrity.

Chainguard · Chainguard ContainersInferred alignmentmedium confidence · 1 source

Chainguard Containers is positioned as a built-from-source container catalog designed to minimize known vulnerabilities in development and production pipelines.

AuditaAI assessment: hardened built-from-source container artifacts reduce exposure to known vulnerable components.

Check Point Software Technologies · AI Agent SecurityInferred alignmenthigh confidence · 1 source

AI Agent Security governs which tools and MCP servers agents can use, and evaluates agent actions in context to help block unsafe or unauthorized behavior at runtime.

AuditaAI assessment: controls over tool/MCP access and contextual action blocking are preventive safeguards.

Check Point Software Technologies · AI Agent SecurityInferred alignmenthigh confidence · 1 source

AI Agent Security helps detect prompt attacks, indirect injection, and sensitive data exposure across agent prompts, responses, and tool use.

AuditaAI assessment: runtime protection across prompts, responses, and tool use contributes preventive safeguards.

Check Point Software Technologies · Check Point AI Security SolutionsInferred alignmentmedium confidence · 1 source

Check Point AI Security documents runtime enforcement that includes protection against harmful outputs in AI interactions.

AuditaAI assessment: runtime harmful-output protection is a preventive safeguard over AI interaction outputs.

Cisco · AI Runtime ProtectionInferred alignmenthigh confidence · 1 source

AI Runtime Protection provides runtime guardrails for prompt and response threat mitigation.

AuditaAI assessment: prompt and response guardrails are preventive safeguards in runtime AI interaction flows.

Cisco · Cisco AI DefenseInferred alignmentmedium confidence · 1 source

Cisco AI Defense includes AI access and policy controls as part of the platform's documented control surface.

AuditaAI assessment: AI access and policy controls provide preventative governance over permitted AI use paths.

Google Cloud · Model ArmorInferred alignmenthigh confidence · 1 source

Model Armor scans prompts and responses for prompt injection and jailbreak content and can return a block verdict when a violation is detected.

AuditaAI assessment: prompt and jailbreak inspection with blocking provides runtime safeguards against adversarial interaction paths.

Google Cloud · Sensitive Data ProtectionInferred alignmenthigh confidence · 1 source

Sensitive Data Protection classifies and de-identifies sensitive content used for model training, tuning, and generative AI prompts and responses.

AuditaAI assessment: de-identification and redaction of sensitive AI data are preventive safeguards against exposure.

Harmonic Security · Harmonic Security PlatformInferred alignmenthigh confidence · 1 source

Harmonic Security inspects user prompts in real time to detect sensitive enterprise information (PII, source code, financial data) and enforces redaction or blocking policies prior to transmission to external LLMs.

AuditaAI assessment: inline data redaction and exfiltration prevention are protective data security controls.

Lasso Security · Runtime Enforcement and AI Detection and ResponseInferred alignmenthigh confidence · 2 sources

Lasso runtime enforcement can block prompt-injection attempts and prevent unsafe autonomous agent actions or unauthorized tool invocation.

AuditaAI assessment: runtime blocking of prompt injection and unsafe autonomous actions is a direct preventive safeguard.

Maxim AI · Bifrost AI GatewayInferred alignmenthigh confidence · 2 sources

Bifrost centralizes MCP tool connections and enforces authentication, access-control, and governance policies for agent tool usage.

AuditaAI assessment: centralized MCP tool governance and access-control boundaries are preventive safeguards.

Mindgard · AI Runtime Threat Detection and ResponseInferred alignmenthigh confidence · 1 source

Runtime guardrails are applied to block prompt injection attack paths before harmful model behavior propagates.

AuditaAI assessment: runtime guardrails that block prompt injection are preventive safeguards against adversarial interaction abuse.

Microsoft · Azure AI Content Safety and Prompt ShieldsInferred alignmenthigh confidence · 1 source

Azure AI Content Safety and Prompt Shields identify direct and indirect prompt injection and related unsafe prompt patterns before they reach downstream model behavior.

AuditaAI assessment: prompt-injection and unsafe-prompt filtering provide runtime safeguards that reduce exploitability of AI interactions.

Microsoft · Microsoft Foundry Agent ServiceInferred alignmenthigh confidence · 1 source

Microsoft Foundry provisions distinct Entra agent identities and uses scoped access tokens and RBAC to authorize agent calls to MCP servers and downstream tools.

AuditaAI assessment: scoped tokens and RBAC authorization for MCP and downstream tool calls are preventive access safeguards.

Microsoft · Microsoft Foundry Agent ServiceInferred alignmenthigh confidence · 1 source

Microsoft Foundry uses agent identities and audience-scoped tokens to authenticate Agent-to-Agent endpoints and allow downstream services to grant or deny access through RBAC.

AuditaAI assessment: audience-scoped tokens and RBAC enforcement on A2A endpoints provide communication-path safeguards.

NEO · Neo Security PlatformInferred alignmenthigh confidence · 1 source

Neo Security Platform is positioned to prevent agentic threats by controlling unsafe runtime action paths and over-permissioned execution conditions.

AuditaAI assessment: controlling unsafe runtime action paths and over-permissioned execution conditions is a preventive safeguard.

Okta · Agent GatewayInferred alignmenthigh confidence · 1 source

Okta Agent Gateway intercepts agent-to-tool and agent-to-API calls at runtime without requiring upstream application code changes.

AuditaAI assessment: runtime interception of agent tool and API calls applies safeguards that reduce unauthorized execution pathways.

Okta · Agent GatewayInferred alignmenthigh confidence · 1 source

Okta Agent Gateway brokers dynamic short-lived tokens so AI agents do not handle long-lived static API keys.

AuditaAI assessment: brokering short-lived credentials instead of static API keys is a preventive safeguard for agent access control.

NVIDIA Corporation · NVIDIA NeMo GuardrailsInferred alignmenthigh confidence · 1 source

NeMo Guardrails applies programmable dialog, topical, and safety rails to inspect and constrain input prompts and model responses in LLM applications.

AuditaAI assessment: programmable input and output safety rails are runtime safeguards that reduce unsafe model interaction paths.

NVIDIA Corporation · NVIDIA NemoClawInferred alignmenthigh confidence · 2 sources

NemoClaw deploys supported autonomous agents from a digest-verified hardened blueprint with restrictive filesystem and process defaults, credential filtering, routed inference, state integrity checks, and operator approval for blocked network endpoints.

AuditaAI assessment: hardened defaults, integrity checks, scoped egress controls, and credential filtering enforce preventive safeguards on autonomous-agent execution.

NVIDIA Corporation · NVIDIA OpenShellInferred alignmenthigh confidence · 2 sources

OpenShell runs autonomous agents in isolated sandboxes and enforces out-of-process filesystem, network, process, inference, credential, and skill policies at binary, destination, method, and path level, with developer-approved policy updates and an audit trail of allow and deny decisions.

AuditaAI assessment: out-of-process policy enforcement and sandbox boundaries protect against unauthorized filesystem, network, process, and credential operations.

OpenAI · OpenAI Guardrails PythonInferred alignmenthigh confidence · 1 source

OpenAI Guardrails Python runs configurable checks on application inputs and outputs so failed checks can prevent an unsafe interaction from proceeding.

AuditaAI assessment: configurable input/output checks that can stop unsafe interactions are preventive safeguards.

Palo Alto Networks · Prisma AIRSInferred alignmenthigh confidence · 1 source

Prisma AIRS applies real-time safeguards to AI prompts, responses, model interactions, agent actions, and data exposure paths.

AuditaAI assessment: real-time safeguards over prompts, responses, model interactions, agent actions, and data paths are protective cybersecurity controls.

Palo Alto Networks · AI Access SecurityInferred alignmenthigh confidence · 1 source

AI Access Security classifies GenAI applications by sanction status and can revoke access or control upload and download actions based on risk and privilege.

AuditaAI assessment: sanction-aware access policy and transfer controls are safeguards that reduce GenAI application misuse and data exposure.

Snowflake Inc. · Cortex AI GatewayInferred alignmenthigh confidence · 3 sources

Cortex AI Gateway centralizes access policy, authentication, and tool-permission controls across first-party and third-party MCP-connected agent workflows.

AuditaAI assessment: centralized authentication, access policy, and tool permissions are preventive safeguards over MCP-connected workflows.

Teleport · Teleport MCP Access & GovernanceInferred alignmenthigh confidence · 1 source

Teleport proxies Model Context Protocol (MCP) server traffic and enforces granular role-based access control (RBAC) to allow or block specific tool calls based on string, regex, or glob patterns.

AuditaAI assessment: Zero trust access control, ephemeral credentials, and tool filtering safeguards protect AI infrastructure from unauthorized access.

Zenity · Runtime Boundaries and AIDRInferred alignmenthigh confidence · 2 sources

Zenity runtime boundaries can block unsafe agent actions, including risky tool usage and unauthorized task execution.

AuditaAI assessment: runtime boundaries that block unsafe actions and risky tool usage are preventive safeguards.

Zenity · Runtime Boundaries and AIDRInferred alignmenthigh confidence · 2 sources

Zenity identity-aware runtime boundaries can prevent sensitive data access and exposure by over-permissioned agents.

AuditaAI assessment: identity-aware boundaries preventing over-permissioned sensitive-data access are protective controls.

Zscaler · Zscaler AI BrokerInferred alignmenthigh confidence · 1 source

Zscaler AI Broker secures agentic communications through MCP and A2A brokers and enforces fine-grained access policies across enterprise AI agents.

AuditaAI assessment: MCP and A2A broker access policies provide preventive safeguards across enterprise agent communication paths.

SPLX · SPLX Runtime GuardrailsInferred alignmenthigh confidence · 2 sources

Zscaler AI Security runtime protection blocks prompt injection, data poisoning, and malicious URLs in AI interactions.

AuditaAI assessment: blocking malicious runtime inputs and URLs provides preventive safeguards for AI interaction channels.

Zscaler · Zscaler Data SecurityInferred alignmenthigh confidence · 1 source

Zscaler Data Security inspects AI usage and prompts and can block risky access or enforce prompt DLP to prevent data loss.

AuditaAI assessment: prompt DLP and risky-access blocking enforce preventative safeguards against sensitive-data loss.

Zscaler · Zscaler AI SecurityInferred alignmenthigh confidence · 1 source

Zscaler AI Security can warn, block, or isolate user access to AI applications under acceptable-use and data-protection policies.

AuditaAI assessment: warn, block, and isolate controls are safeguards that reduce unsafe AI-application use.

CSF Function DE

DETECT

Find and analyze possible cybersecurity attacks and compromises.

27 reviewed alignments
Reviewed offering assessments+
Zero Day Investigative Network · 0DIN AI Security ScannerInferred alignmentmedium confidence · 2 sources

0DIN AI Security Scanner evaluates LLM and GenAI application behavior against exploit and jailbreak test suites.

AuditaAI assessment: exploit and jailbreak testing surfaces vulnerabilities and provides detection-relevant findings.

Amazon Web Services · Amazon SageMaker Clarify and Model MonitorInferred alignmenthigh confidence · 1 source

SageMaker Clarify and monitoring workflows provide ongoing model and data behavior analysis for drift, quality, and governance evidence.

AuditaAI assessment: ongoing drift and behavior analysis detects anomalous model and data conditions in production operations.

Cato Networks · Cato AI Security (AISEC)Inferred alignmenthigh confidence · 1 source

Cato AI Security runtime monitoring detects prompt-injection patterns and policy-violating AI prompt activity.

AuditaAI assessment: runtime monitoring that detects prompt-injection patterns aligns with detection outcomes.

Check Point Software Technologies · AI Agent SecurityInferred alignmenthigh confidence · 1 source

AI Agent Security helps detect prompt attacks, indirect injection, and sensitive data exposure across agent prompts, responses, and tool use.

AuditaAI assessment: detection of prompt attacks, indirect injection, and data exposure aligns with detection outcomes.

Check Point Software Technologies · AI Red Teaming and AssessmentInferred alignmentmedium confidence · 1 source

AI Red Teaming runs broad and targeted adversarial campaigns to assess AI applications and agents for prompt injection, jailbreak, data leakage, unauthorized actions, and regressions.

AuditaAI assessment: adversarial testing finds exploitable weaknesses and contributes detection-relevant findings.

Cisco · AI Model and Application ValidationInferred alignmentmedium confidence · 1 source

AI Model and Application Validation performs algorithmic red teaming and model vulnerability validation for AI applications and models.

AuditaAI assessment: algorithmic red teaming and vulnerability validation generate detection-relevant findings on exploitable AI weaknesses.

DeepKeep · DeepKeep AI Security PlatformInferred alignmentmedium confidence · 2 sources

DeepKeep performs AI red teaming and model security scanning to discover vulnerabilities before production impact.

AuditaAI assessment: adversarial model testing and vulnerability scanning produce detection-relevant security findings.

Gray Swan AI · ShadeInferred alignmentmedium confidence · 2 sources

Shade runs adversarial red teaming against deployed models, agent workflows, and guardrail configurations to surface exploitable weaknesses.

AuditaAI assessment: adversarial red teaming surfaces exploitable weaknesses and contributes detection-oriented security findings.

Google Cloud · Security Command CenterInferred alignmentmedium confidence · 1 source

Security Command Center detects AI-specific threats across the AI stack.

AuditaAI assessment: detecting AI-specific threats aligns with cybersecurity detection outcomes.

Wiz · Wiz AI-SPMInferred alignmenthigh confidence · 1 source

Wiz AI-SPM applies built-in configuration rules to detect misconfigured AI services and unsafe deployments.

AuditaAI assessment: built-in rules that identify misconfigured services and unsafe deployments are detection outcomes.

Wiz · Wiz AI Runtime ProtectionInferred alignmenthigh confidence · 1 source

Wiz AI Runtime Protection detects prompt injection, rogue agents, and malicious behavior targeting AI systems.

AuditaAI assessment: runtime detection of prompt injection, rogue agents, and malicious behavior aligns with detection outcomes.

HiddenLayer · AI Attack SimulationInferred alignmentmedium confidence · 1 source

AI Attack Simulation tests AI systems for jailbreaks, prompt injection, data leakage, and unsafe agent tool use through automated adversarial simulation.

AuditaAI assessment: attack simulation and vulnerability testing surface exploitable weaknesses and support detection workflows.

Lasso Security · Runtime Enforcement and AI Detection and ResponseInferred alignmenthigh confidence · 2 sources

Lasso AI detection and response workflows identify and triage suspicious AI behavior using contextual attack telemetry.

AuditaAI assessment: contextual telemetry workflows identify suspicious AI behavior and provide detection signals.

Mindgard · AI Red Teaming and AssessmentInferred alignmentmedium confidence · 1 source

AI Red Teaming and Assessment runs adversarial workflows to surface jailbreak and guardrail-bypass weaknesses for pre-deployment remediation.

AuditaAI assessment: adversarial testing surfaces jailbreak and guardrail-bypass weaknesses, contributing detection-relevant security findings.

Mindgard · AI Runtime Threat Detection and ResponseInferred alignmenthigh confidence · 1 source

AI Runtime Threat Detection and Response monitors production AI execution to detect suspicious outputs and attack behavior.

AuditaAI assessment: production monitoring for suspicious outputs and attack behavior aligns with cybersecurity detection outcomes.

Microsoft · Microsoft Agent 365Inferred alignmenthigh confidence · 1 source

Microsoft Agent 365 provides continuous agent threat detection and configurable real-time protection policies that block unsafe behaviors and malicious activity.

AuditaAI assessment: continuous threat detection over agent behavior aligns with cybersecurity detection outcomes.

Mirror Security · Mirror Security SuiteInferred alignmentmedium confidence · 2 sources

Mirror DiscoveR continuously runs automated red teaming to uncover AI vulnerabilities and validate security controls.

AuditaAI assessment: continuous red teaming uncovers exploitable weaknesses and contributes detection-oriented findings.

Okta · Agent GatewayInferred alignmentmedium confidence · 1 source

Okta Agent Gateway intercepts agent-to-tool and agent-to-API calls at runtime without requiring upstream application code changes.

AuditaAI assessment: the runtime interception layer provides observation points for identifying suspicious or unsafe tool-call activity.

NVIDIA Corporation · garakInferred alignmentmedium confidence · 1 source

garak probes language-model endpoints across attack classes including jailbreaks, prompt injection, and data leakage to identify model security weaknesses.

AuditaAI assessment: adversarial probing identifies exploitable model weakness patterns and contributes detection-oriented risk signals.

Alice · WonderBuildInferred alignmentmedium confidence · 2 sources

WonderBuild performs pre-deployment adversarial testing and red teaming across AI models, applications, and agents.

AuditaAI assessment: pre-deployment adversarial testing identifies exploitable weaknesses and contributes detection findings.

Idira · Idira Secure AI AgentsInferred alignmenthigh confidence · 1 source

Idira Secure AI Agents logs agent actions and communications, recording which agent performed an action and on behalf of which user, to support governance and compliance review.

AuditaAI assessment: action and communication logging tied to acting agent and delegating user supports monitoring and detection of risky activity.

Teleport · Teleport MCP Access & GovernanceInferred alignmenthigh confidence · 2 sources

Teleport captures auditable session logs for every prompt, query, and tool execution traversing protected MCP connections.

AuditaAI assessment: Comprehensive audit logging of MCP sessions and protocol queries supports continuous detection of anomalous agent actions.

TrendAI · TrendAI Vision One AI SecurityInferred alignmentmedium confidence · 1 source

TrendAI combines AI Scanner pre-deployment testing with AI Guard runtime controls to detect vulnerabilities and reduce sensitive data leakage in AI applications.

AuditaAI assessment: pre-deployment testing and runtime controls surface vulnerabilities and attack patterns for detection workflows.

Verno Labs · Verno Labs AI Agent Security PlatformInferred alignmentmedium confidence · 1 source

Verno Labs performs automated adversarial testing to evaluate AI agent security weaknesses before production impact.

AuditaAI assessment: adversarial testing surfaces exploitable weaknesses and contributes detection-oriented findings.

Zenity · Runtime Boundaries and AIDRInferred alignmenthigh confidence · 2 sources

Zenity behavioral runtime telemetry supports detection and investigation of unsafe or manipulative AI outcomes.

AuditaAI assessment: behavioral runtime telemetry supports detection and investigation of manipulative outcomes.

SPLX · SPLX Runtime GuardrailsInferred alignmenthigh confidence · 2 sources

Zscaler AI Security runtime protection blocks prompt injection, data poisoning, and malicious URLs in AI interactions.

AuditaAI assessment: runtime inspection identifies prompt injection, poisoning attempts, and malicious URLs during AI interactions.

SPLX · SPLX AI Red TeamingInferred alignmentmedium confidence · 2 sources

Zscaler AI Security runs configurable attack simulations to identify AI vulnerabilities and provide remediation guidance before and during deployment.

AuditaAI assessment: configurable attack simulations identify vulnerabilities and produce detection-relevant risk signals.

CSF Function RS

RESPOND

Take action regarding detected cybersecurity incidents.

6 reviewed alignments
Reviewed offering assessments+
Google Cloud · Security Command CenterInferred alignmentmedium confidence · 1 source

Security Command Center provides response workflows for AI-specific threats across the AI stack.

AuditaAI assessment: documented response workflows for AI threats align with response outcomes.

Lasso Security · Runtime Enforcement and AI Detection and ResponseInferred alignmentmedium confidence · 2 sources

Lasso AI detection and response workflows identify and triage suspicious AI behavior using contextual attack telemetry.

AuditaAI assessment: triage workflows contribute to coordinated response handling once suspicious behavior is detected.

Mindgard · AI Runtime Threat Detection and ResponseInferred alignmenthigh confidence · 1 source

Runtime response workflows support containment and remediation for unsafe agent behavior and unauthorized action chains.

AuditaAI assessment: containment and remediation workflows for unsafe agent actions align with response outcomes.

Microsoft · Microsoft Copilot for SecurityInferred alignmentmedium confidence · 1 source

Microsoft Copilot for Security supports analyst investigation and response workflows to accelerate triage and containment actions.

AuditaAI assessment: analyst triage and containment workflow support aligns with incident response actions.

Okta · Okta for AI AgentsInferred alignmenthigh confidence · 1 source

Okta provides emergency administrative revocation controls that can invalidate agent sessions and tokens.

AuditaAI assessment: emergency token/session revocation is a direct response action for compromised or unsafe agent activity.

Nightfall AI · Data Detection and ResponseInferred alignmenthigh confidence · 1 source

Data Detection and Response performs real-time scanning with automated quarantine, notification, and remediation workflows for risky content flows.

AuditaAI assessment: automated quarantine, notification, and remediation workflows are direct response outcomes.

CSF Function RC

RECOVER

Restore assets and operations affected by cybersecurity incidents.

0 reviewed alignments

No reviewed offering alignments yet.