Framework Explorer

NCSC/CISA Guidelines for Secure AI System Development

The complete version 1.0 guidance spans secure design, development, deployment, and operation. AuditaAI mappings identify documented product contributions to individual guidelines; they do not establish implementation, compliance, or conformance.

Official NCSC source

17 of 17

Official guideline items represented

10

Items with reviewed contributions

181

Reviewed product contributions

7 guidelines without reviewed contributions are hidden.

Lifecycle stage 2

Secure development

Protect the AI supply chain, assets, documentation, and long-term maintainability during development.

Guideline 2.1

Secure your supply chain

Assess and monitor AI suppliers and acquire well-secured, documented components from verified sources with contingency options.

9 reviewed contributions
Reviewed product contributions+
Chainguard · Chainguard Secure AI SDLCInferred contributionmedium confidence · 1 source

Chainguard AI Security documents software supply chain coverage across SDLC phases, including trusted dependencies, CI/CD integrity, and hardened runtime foundations.

AuditaAI assessment: trusted dependencies, CI/CD integrity, and hardened runtime foundations across SDLC are supply-chain security controls.

Chainguard · Chainguard LibrariesInferred contributionmedium confidence · 1 source

Chainguard Libraries provides a malware-resistant dependency catalog intended to replace direct reliance on public package registries.

AuditaAI assessment: malware-resistant dependency catalog replacing public registries directly addresses supplier/dependency security.

Chainguard · Chainguard LibrariesInferred contributionmedium confidence · 1 source

Chainguard states that library artifacts are built from source with full provenance and signed SBOMs.

AuditaAI assessment: built-from-source provenance and signed SBOMs are dependency provenance controls.

Chainguard · Chainguard FactoryInferred contributionmedium confidence · 1 source

Chainguard Factory applies SHA-pinned source inputs, isolated SLSA L3 build controls, cryptographic signing, and reproducibility checks when producing artifacts.

AuditaAI assessment: SHA-pinned inputs, SLSA L3 isolation, cryptographic signing, and reproducibility deliver hardened supply-chain build integrity.

HiddenLayer · AI Supply Chain SecurityInferred contributionmedium confidence · 1 source

AI Supply Chain Security analyzes model architectures, layers, weights, and artifacts for tampering or anomalies and tracks model lineage, origin, and licensing.

AuditaAI assessment: analyzing model architectures/weights/artifacts for tampering and tracking model lineage/origin/licensing directly addresses model-artifact supply-chain security.

Lasso Security · AI Security Posture ManagementInferred contributionmedium confidence · 2 sources

Lasso AI Security Posture Management evaluates misconfigurations and policy gaps, including supply-chain-oriented risk indicators before production rollout.

AuditaAI assessment: evaluating supply-chain-oriented risk indicators pre-rollout addresses supplier/dependency assessment.

Palo Alto Networks · Prisma AIRSInferred contributionmedium confidence · 1 source

Prisma AIRS scans third-party models for tampering, malicious scripts, and deserialization risks.

AuditaAI assessment: scanning third-party models for tampering, malicious scripts, and deserialization risks addresses model-artifact supply-chain security.

Palo Alto Networks · Prisma AIRSInferred contributionmedium confidence · 1 source

Prisma AIRS scans agent code, MCP servers, and skills for unsafe permissions, hidden vulnerabilities, and indirect injection paths.

AuditaAI assessment: scanning agent code, MCP servers, and skills for unsafe permissions and hidden vulnerabilities addresses dependency/component supply-chain security.

Koi Security · Koi Agentic Endpoint SecurityInferred contributionmedium confidence · 1 source

Koi AES evaluates code differences and behavioral shifts in real time to identify software supply-chain risk.

AuditaAI assessment: evaluating code differences and behavioural shifts identifies software supply-chain risk in AI-related components.

Guideline 2.2

Identify, track and protect your assets

Inventory, authenticate, version, protect, and restore AI-related models, data, prompts, software, documentation, logs, and assessments.

27 reviewed contributions
Reviewed product contributions+
Cranium AI, Inc. · Cranium AI Security and Governance PlatformInferred contributionmedium confidence · 1 source

Cranium discovers agents across enterprise environments, surfaces shadow AI, and records ownership and usage context in a living system of record.

AuditaAI assessment: cross-environment discovery of agents and shadow AI with ownership/usage context is AI asset inventory.

Tenable Holdings, Inc. · Tenable One AI ExposureInferred contributionmedium confidence · 2 sources

Tenable One AI Exposure provides continuous discovery of AI assets and attack-surface context across software and infrastructure environments.

AuditaAI assessment: continuous discovery of AI assets and attack-surface context is AI asset inventory.

Amazon Web Services · Amazon Bedrock AgentCoreInferred contributionmedium confidence · 1 source

Amazon Bedrock AgentCore Registry catalogs agents and MCP servers for centralized governance and observability.

AuditaAI assessment: registry cataloguing agents and MCP servers for centralized governance is AI asset inventory.

Check Point Software Technologies · AI Agent SecurityInferred contributionmedium confidence · 1 source

AI Agent Security discovers agents and assesses their tool and MCP access surface for security risk.

AuditaAI assessment: discovering agents and their tool/MCP access surface is AI asset inventory.

Cisco · AI Cloud VisibilityInferred contributionmedium confidence · 1 source

AI Cloud Visibility provides discovery and inventory context for AI workloads, models, data, and users.

AuditaAI assessment: discovery and inventory of AI workloads, models, data, and users is AI asset inventory.

Cyera · Cyera AI-SPMInferred contributionmedium confidence · 1 source

Cyera AI-SPM discovers and inventories AI models, applications, agents, knowledge bases, and web applications in enterprise environments.

AuditaAI assessment: discovery and inventory of models, applications, agents, and knowledge bases is AI asset inventory.

Google Cloud · Security Command CenterInferred contributionmedium confidence · 1 source

Security Command Center discovers and inventories AI assets across agents, data, models, applications, platforms, and infrastructure.

AuditaAI assessment: discovery and inventory of AI agents, data, models, applications, platforms, and infrastructure is AI asset inventory.

Wiz · Wiz AI-SPMInferred contributionmedium confidence · 1 source

Wiz AI-SPM discovers and catalogs AI models, agents, services, technologies, SDKs, pipelines, and related cloud infrastructure without agents.

AuditaAI assessment: agentless discovery/cataloguing of AI models, agents, services, SDKs, and pipelines is AI asset inventory.

Wiz · Wiz AI-SPMInferred contributionmedium confidence · 1 source

Wiz AI-SPM identifies and classifies tools that agents can access to show the actions those agents can perform.

AuditaAI assessment: identifying and classifying tools agents can access is inventory of AI-related assets and actions.

Wiz · Wiz AI-BOMInferred contributionmedium confidence · 1 source

Wiz AI-BOM continuously inventories AI models, datasets, frameworks, software dependencies, identities, access paths, and infrastructure.

AuditaAI assessment: continuous inventory of AI models, datasets, frameworks, dependencies, identities, and infrastructure is AI asset inventory.

Wiz · Wiz DSPM for AIInferred contributionmedium confidence · 1 source

Wiz DSPM for AI detects sensitive training data, identifies leakage risk, and exposes attack paths to that data.

AuditaAI assessment: detecting sensitive training data and exposing attack paths inventories and evaluates AI data assets.

HiddenLayer · AI DiscoveryInferred contributionmedium confidence · 1 source

AI Discovery scans cloud accounts, repositories, endpoints, and pipelines to detect AI models and associated agents, and associates assets with ownership, sensitivity, and risk metadata.

AuditaAI assessment: scanning cloud, repos, endpoints, and pipelines to detect AI models/agents and associate ownership and sensitivity metadata is AI asset inventory.

Lasso Security · Discovery and AI-BOMInferred contributionmedium confidence · 2 sources

Lasso Discovery and AI-BOM inventories agents, tools, models, prompts, and guardrails with change tracking across environments.

AuditaAI assessment: inventorying agents, tools, models, prompts, and guardrails with change tracking is AI asset inventory with versioning.

Microsoft · Microsoft Defender for Cloud (AI-SPM)Inferred contributionmedium confidence · 1 source

Defender for Cloud AI posture capabilities discover and inventory AI resources and workloads for security posture visibility.

AuditaAI assessment: discovery and inventory of AI resources and workloads is AI asset inventory.

Microsoft · Microsoft Agent 365Inferred contributionmedium confidence · 2 sources

Microsoft Agent 365 powers a centralized inventory and posture view of Microsoft and supported non-Microsoft agents, including identities, tools, MCP servers, risk indicators, alerts, and recommendations.

AuditaAI assessment: centralized inventory and posture view of agents including identities, tools, and MCP servers is AI asset inventory.

Mindgard · AI Discovery and ReconInferred contributionmedium confidence · 1 source

AI Discovery and Recon identifies models, agents, MCP servers, tools, and shadow AI to map AI attack surface and exposure.

AuditaAI assessment: identifying models, agents, MCP servers, tools, and shadow AI to map attack surface is AI asset inventory.

Palo Alto Networks · Prisma AIRSInferred contributionmedium confidence · 1 source

Prisma AIRS maps enterprise, endpoint, and browser agents and surfaces MCP servers, plugins, tool interactions, shadow AI, and unsanctioned agents.

AuditaAI assessment: mapping enterprise/endpoint/browser agents and MCP servers/plugins/tools is AI asset inventory.

Palo Alto Networks · AI Access SecurityInferred contributionmedium confidence · 1 source

AI Access Security discovers and categorizes GenAI applications, agents, marketplace plugins, usage, and users.

AuditaAI assessment: discovering and categorizing GenAI applications, agents, plugins, and users is AI asset inventory.

Koi Security · Koi Agentic Endpoint SecurityInferred contributionmedium confidence · 1 source

Koi AES discovers and catalogs autonomous software agents, AI agents, browser extensions, software, and AI models on enterprise endpoints.

AuditaAI assessment: discovering and cataloguing autonomous/AI agents, extensions, software, and AI models on endpoints is AI asset inventory.

Straiker · Straiker Discover AIInferred contributionmedium confidence · 1 source

Straiker Discover AI maps AI agents, MCP servers, and agentic workflows and provides posture monitoring and misconfiguration detection.

AuditaAI assessment: mapping AI agents, MCP servers, and agentic workflows is AI asset inventory.

TrojAI · TrojAI Defend for MCPInferred contributionmedium confidence · 1 source

TrojAI Defend for MCP discovers MCP servers and tools and enforces policy on agent-to-model-to-server communications.

AuditaAI assessment: discovering MCP servers and tools is AI asset inventory.

Zenity · AI ObservabilityInferred contributionmedium confidence · 2 sources

Zenity AI Observability builds live inventory of agents, owners, permissions, and touched data across SaaS, cloud, and endpoint environments.

AuditaAI assessment: live inventory of agents, owners, permissions, and touched data across environments is AI asset inventory.

SPLX · SPLX AI Asset ManagementInferred contributionmedium confidence · 2 sources

Zscaler AI Security discovers and maps AI applications, models, MCP servers, development tools, data pipelines, and related risks.

AuditaAI assessment: discovering and mapping AI applications, models, MCP servers, dev tools, and pipelines is AI asset inventory.

Zscaler · Zscaler Data SecurityInferred contributionmedium confidence · 1 source

Zscaler Data Security discovers and classifies sensitive data and uses contextual classification to identify data risk across GenAI and other channels.

AuditaAI assessment: discovering and classifying sensitive data across GenAI and other channels contributes to identifying AI-related data assets.

TrendAI · TrendAI Vision One AI SecurityInferred contributionmedium confidence · 1 source

TrendAI AI-SPM discovers AI-related cloud assets and identifies security misconfigurations and exposure paths in LLM deployments.

AuditaAI assessment: AI-SPM asset discovery and misconfiguration visibility provide inventory and protection context for AI assets.

Verno Labs · Verno Labs AI Agent Security PlatformInferred contributionmedium confidence · 1 source

Verno Labs discovers AI agents and maintains lifecycle-oriented visibility over deployed agent surfaces.

AuditaAI assessment: lifecycle discovery and inventory of deployed AI agents provide AI asset identification and tracking contributions.

Harmonic Security · Harmonic Security PlatformInferred contributionhigh confidence · 1 source

Harmonic Security discovers and catalogs enterprise generative AI application usage (Shadow AI), categorizing application risk posture and data compliance across cloud and endpoint environments.

AuditaAI assessment: continuous discovery and cataloging of enterprise generative AI application usage and model endpoints support identifying and tracking AI assets.

Lifecycle stage 3

Secure deployment

Protect infrastructure and models, prepare for incidents, evaluate releases, and make secure operation easier for users.

Guideline 3.1

Secure your infrastructure

Apply access controls and environment segregation across APIs, models, data, and training and processing pipelines.

27 reviewed contributions
Reviewed product contributions+
Anthropic · Claude Code Security ArchitectureInferred contributionmedium confidence · 1 source

Claude Code constrains command execution with operating-system sandbox boundaries that limit filesystem and network access.

AuditaAI assessment: OS sandbox boundaries around command execution provide environment segregation for AI-driven actions.

Tenable Holdings, Inc. · Tenable One AI ExposureInferred contributionmedium confidence · 2 sources

Tenable One AI Exposure surfaces identity and entitlement risk for AI workloads, including over-permissioned access paths that can increase autonomous abuse risk.

AuditaAI assessment: surfacing identity and entitlement risk (over-permissioned access) supports access-control hygiene across AI workloads.

Amazon Web Services · Amazon Bedrock AgentCoreInferred contributionmedium confidence · 1 source

Amazon Bedrock AgentCore gives agents distinct scoped identities and uses Cedar policy to authorize every tool call and data access independently of model reasoning.

AuditaAI assessment: scoped agent identities and Cedar-policy authorization of tool/data access implement access control across AI APIs and data.

Amazon Web Services · Amazon Bedrock AgentCoreInferred contributionmedium confidence · 1 source

Amazon Bedrock AgentCore applies identity and authorization controls to agents using MCP and A2A communications with external tools and other agents.

AuditaAI assessment: identity/authorization controls over MCP and A2A agent communications implement access control across AI system interfaces.

Check Point Software Technologies · AI Agent SecurityInferred contributionmedium confidence · 1 source

AI Agent Security governs which tools and MCP servers agents can use, and evaluates agent actions in context to help block unsafe or unauthorized behavior at runtime.

AuditaAI assessment: governing which tools and MCP servers agents can use is access control across AI APIs and downstream systems.

Cyera · Cyera AI-SPMInferred contributionmedium confidence · 1 source

Cyera AI-SPM maps AI assets to identities and sensitive data to identify over-permissioned agents, misconfigurations, and unauthorized data paths.

AuditaAI assessment: mapping AI assets to identities and detecting over-permissioned agents/unauthorized data paths supports access-control hygiene.

Wiz · Wiz AI-SPMInferred contributionmedium confidence · 2 sources

Wiz AI-SPM identifies posture gaps involving risky agent permissions and connects identities and access paths to AI-system exposure.

AuditaAI assessment: identifying risky agent permissions and identity/access paths supports access-control hygiene for AI systems.

Microsoft · Microsoft Foundry Agent ServiceInferred contributionmedium confidence · 1 source

Microsoft Foundry provisions distinct Entra agent identities and uses scoped access tokens and RBAC to authorize agent calls to MCP servers and downstream tools.

AuditaAI assessment: distinct Entra agent identities plus scoped tokens and RBAC to authorize agent calls to MCP/tools implement access control across AI APIs.

Microsoft · Microsoft Foundry Agent ServiceInferred contributionmedium confidence · 1 source

Microsoft Foundry uses agent identities and audience-scoped tokens to authenticate Agent-to-Agent endpoints and allow downstream services to grant or deny access through RBAC.

AuditaAI assessment: agent identities and audience-scoped tokens for A2A endpoints, with RBAC on downstream services, implement access control on AI communications.

NVIDIA Corporation · NVIDIA NemoClawInferred contributionhigh confidence · 2 sources

NemoClaw deploys supported autonomous agents from a digest-verified hardened blueprint with restrictive filesystem and process defaults, credential filtering, routed inference, state integrity checks, and operator approval for blocked network endpoints.

AuditaAI assessment: a hardened sandbox with restrictive filesystem, process, credential, and network boundaries contributes environment segregation and access control for agent infrastructure.

NVIDIA Corporation · NVIDIA OpenShellInferred contributionhigh confidence · 2 sources

OpenShell runs autonomous agents in isolated sandboxes and enforces out-of-process filesystem, network, process, inference, credential, and skill policies at binary, destination, method, and path level, with developer-approved policy updates and an audit trail of allow and deny decisions.

AuditaAI assessment: isolated sandboxes and out-of-process filesystem, network, process, inference, and credential policy contribute access control and environment segregation.

Palo Alto Networks · Prisma AIRSInferred contributionmedium confidence · 1 source

Prisma AIRS verifies agent identity and enforces real-time security controls for agent actions.

AuditaAI assessment: verifying agent identity and enforcing real-time security controls implements access controls across agents.

Palo Alto Networks · Prisma AIRSInferred contributionmedium confidence · 1 source

Prisma AIRS governs agent tool calls, model access, and external connections through centralized policy and assigns each agent a governed identity with precise permissions and traceability.

AuditaAI assessment: governing tool calls, model access, and external connections with governed identities implements access control across AI APIs and pipelines.

Palo Alto Networks · AI Access SecurityInferred contributionmedium confidence · 1 source

AI Access Security classifies GenAI applications by sanction status and can revoke access or control upload and download actions based on risk and privilege.

AuditaAI assessment: sanction classification with access-revocation and upload/download controls is access control over AI applications.

Portkey · PortkeyInferred contributionmedium confidence · 2 sources

Portkey MCP Gateway centralizes authentication, fine-grained server and tool access, observability, and runtime policy and stops unauthorized tool invocations before execution.

AuditaAI assessment: centralized authentication, fine-grained server/tool access, and blocking unauthorized tool invocations implement access control across AI APIs.

Pangea · Pangea AI Security PlatformInferred contributionmedium confidence · 1 source

Pangea provides proxy-based MCP integration to apply guardrails and authentication or authorization controls to agent-to-tool and agent-to-agent communications.

AuditaAI assessment: proxy-based authentication/authorization for agent-to-tool and A2A communications implements access control across AI APIs.

Snowflake Inc. · Cortex AI GatewayInferred contributionmedium confidence · 3 sources

Cortex AI Gateway centralizes access policy, authentication, and tool-permission controls across first-party and third-party MCP-connected agent workflows.

AuditaAI assessment: centralized access policy, authentication, and tool-permission across MCP-connected agents implements access control across AI APIs.

TrojAI · TrojAI Defend for MCPInferred contributionmedium confidence · 1 source

TrojAI Defend for MCP discovers MCP servers and tools and enforces policy on agent-to-model-to-server communications.

AuditaAI assessment: enforcing policy on agent-to-model-to-server communications implements access control across AI APIs.

Zenity · AI Security Posture ManagementInferred contributionmedium confidence · 2 sources

Zenity posture workflows evaluate configuration and permission risk for agents before and during deployment.

AuditaAI assessment: evaluating configuration and permission risk for agents supports access-control hygiene for AI systems.

Zenity · Runtime Boundaries and AIDRInferred contributionmedium confidence · 2 sources

Zenity identity-aware runtime boundaries can prevent sensitive data access and exposure by over-permissioned agents.

AuditaAI assessment: identity-aware runtime boundaries limiting over-permissioned agents implement access control for AI data.

Zscaler · Zscaler AI BrokerInferred contributionmedium confidence · 1 source

Zscaler AI Broker secures agentic communications through MCP and A2A brokers and enforces fine-grained access policies across enterprise AI agents.

AuditaAI assessment: mCP/A2A brokering with fine-grained access policies implements access control across enterprise AI agents.

Zscaler · Zscaler AI Access GraphInferred contributionmedium confidence · 1 source

Zscaler AI Access Graph provides real-time visibility into how AI agents use data and identities, identifies unnecessary access, and tracks data lineage across channels.

AuditaAI assessment: identifying unnecessary access and tracking identity paths across AI agent data usage supports access-control hygiene.

Zscaler · Zscaler AI SecurityInferred contributionmedium confidence · 1 source

Zscaler AI Security can warn, block, or isolate user access to AI applications under acceptable-use and data-protection policies.

AuditaAI assessment: warning/blocking/isolating user access to AI applications is access control over AI services.

DeepKeep · DeepKeep AI Security PlatformInferred contributionmedium confidence · 1 source

DeepKeep monitors and controls AI agent gateway usage, identifies active MCP server dependencies, and supports allow or block policy enforcement.

AuditaAI assessment: monitoring and controlling MCP usage with allow/block policies contributes to access control across agent tooling interfaces.

Maxim AI · Bifrost AI GatewayInferred contributionmedium confidence · 2 sources

Bifrost centralizes MCP tool connections and enforces authentication, access-control, and governance policies for agent tool usage.

AuditaAI assessment: centralized MCP governance and authentication boundaries contribute access controls across agent tools and AI APIs.

Votal AI · Votal Runtime Security PlatformInferred contributionmedium confidence · 2 sources

Votal inspects model requests and tool calls in real time, gates tool permissions by tenant and role, and enforces policy decisions at runtime.

AuditaAI assessment: tenant- and role-scoped runtime policy enforcement for tool invocations contributes access control across AI agents and APIs.

Dynamo AI · AgentWardenInferred contributionhigh confidence · 1 source

AgentWarden enforces security and authorization policies at runtime agent action boundaries across prompts, tool calls, tool responses, and final actions to prevent unauthorized execution and goal hijacking.

AuditaAI assessment: runtime authorization and action boundary enforcement across agent tool invocations contribute access control across AI agent APIs and interfaces.

Guideline 3.2

Protect your model continuously

Protect models, data, prompts, and interfaces from unauthorized access, tampering, reconstruction, and exfiltration, including with integrity verification.

70 reviewed contributions
Reviewed product contributions+
Cranium AI, Inc. · Cranium AI Security and Governance PlatformInferred contributionmedium confidence · 2 sources

Cranium AI platform is positioned with runtime policy controls to govern unsafe autonomous agent behavior and over-permissioned execution paths.

AuditaAI assessment: runtime policy controls on agent interfaces contribute to protecting model/agent interfaces from unsafe access and tampering.

Cranium AI, Inc. · Cranium AI Security and Governance PlatformInferred contributionmedium confidence · 2 sources

Cranium AI platform data controls are positioned to prevent sensitive information disclosure across model and agent workflows.

AuditaAI assessment: data controls preventing sensitive disclosure across model/agent flows contribute to exfiltration protection at model/data/interface layer.

Aiceberg · Aiceberg Guardian AgentInferred contributionmedium confidence · 2 sources

Aiceberg Guardian Agent provides runtime visibility and guardrail control over agentic AI decision flows.

AuditaAI assessment: guardrail control over agentic decision interfaces contributes to interface tamper/access protection.

Anthropic · Constitutional ClassifiersInferred contributionmedium confidence · 1 source

Anthropic applies constitutional classifier safeguards to detect and block jailbreak attempts against Claude model behavior.

AuditaAI assessment: classifiers that detect and block jailbreak attempts at the model interface contribute to protecting the model from tampering.

Arthur · Arthur ShieldInferred contributionmedium confidence · 1 source

Arthur Shield identifies and blocks prompt-injection attempts that seek to override intended LLM behavior.

AuditaAI assessment: blocking prompt-injection attempts at the LLM interface protects model behaviour from tampering.

Arthur · Arthur ShieldInferred contributionmedium confidence · 1 source

Arthur Shield applies runtime checks intended to prevent sensitive data leakage through LLM interactions.

AuditaAI assessment: runtime checks that prevent sensitive-data leakage in LLM interactions contribute to data/interface exfiltration protection.

Amazon Web Services · Amazon Bedrock GuardrailsInferred contributionmedium confidence · 1 source

Amazon Bedrock Guardrails applies inline controls that can block prompt-injection and jailbreak-style requests before model outputs are returned.

AuditaAI assessment: inline blocking of prompt-injection/jailbreak before model outputs protects model interface from tampering.

Amazon Web Services · Amazon Bedrock GuardrailsInferred contributionmedium confidence · 1 source

Amazon Bedrock Guardrails includes sensitive-information policy controls to reduce protected-data leakage in prompt and response flows.

AuditaAI assessment: sensitive-information policy controls in prompt/response flows contribute to exfiltration protection at the model interface.

F5, Inc. · F5 AI GuardrailsInferred contributionmedium confidence · 1 source

F5 AI Guardrails applies inline policy controls that can block prompt-injection payloads before requests reach downstream models and tools.

AuditaAI assessment: blocking prompt-injection payloads before downstream models protects model interface from tampering.

F5, Inc. · F5 AI GuardrailsInferred contributionmedium confidence · 1 source

F5 AI Guardrails enforces policies to detect and prevent jailbreak-style attempts that seek to bypass model safety boundaries.

AuditaAI assessment: policies detecting and preventing jailbreak attempts protect model safety boundaries.

F5, Inc. · F5 AI GuardrailsInferred contributionmedium confidence · 1 source

F5 AI Guardrails inspects prompts and responses to redact or block sensitive data and reduce leakage to external AI systems.

AuditaAI assessment: redacting/blocking sensitive data at prompt/response layer contributes to exfiltration protection.

F5, Inc. · F5 AI GuardrailsInferred contributionmedium confidence · 2 sources

F5 AI Guardrails applies agent-focused runtime controls to constrain unsafe autonomous actions and high-risk tool execution paths.

AuditaAI assessment: runtime constraints on unsafe autonomous actions/high-risk tool execution protect the agent interface layer.

Cato Networks · Cato AI Security (AISEC)Inferred contributionmedium confidence · 1 source

Cato AI Security applies inline controls to block sensitive data exfiltration to unauthorized AI services and channels.

AuditaAI assessment: inline blocking of sensitive-data exfiltration to unauthorized AI services protects data/interface flows.

Cato Networks · Cato AI Security (AISEC)Inferred contributionmedium confidence · 2 sources

Cato AI Security governance controls constrain unsafe autonomous actions and high-risk tool usage for AI agents and applications.

AuditaAI assessment: governance constraints on unsafe autonomous actions and high-risk tool usage protect the agent interface.

Check Point Software Technologies · AI Agent SecurityInferred contributionmedium confidence · 1 source

AI Agent Security governs which tools and MCP servers agents can use, and evaluates agent actions in context to help block unsafe or unauthorized behavior at runtime.

AuditaAI assessment: evaluating agent actions in context to block unsafe or unauthorized behaviour protects the agent interface.

Check Point Software Technologies · AI Agent SecurityInferred contributionmedium confidence · 1 source

AI Agent Security helps detect prompt attacks, indirect injection, and sensitive data exposure across agent prompts, responses, and tool use.

AuditaAI assessment: detecting prompt attacks, indirect injection, and sensitive-data exposure across agent flows protects model/prompt/tool interfaces.

Cisco · AI Runtime ProtectionInferred contributionmedium confidence · 1 source

AI Runtime Protection provides runtime guardrails for prompt and response threat mitigation.

AuditaAI assessment: runtime guardrails for prompt/response threat mitigation protect the model interface.

Cyera · Cyera AI GuardianInferred contributionmedium confidence · 1 source

Cyera AI Guardian evaluates data-exposure risk and enforces policies to reduce sensitive-data exposure to AI systems.

AuditaAI assessment: policies to reduce sensitive-data exposure to AI systems protect data at the model interface layer.

Glow · Glow AI-Powered Endpoint Security PlatformInferred contributionmedium confidence · 1 source

Glow autonomous endpoint enforcement can block unsafe agentic tool execution and unauthorized actions initiated from user devices.

AuditaAI assessment: blocking unsafe agentic tool execution and unauthorized actions protects the agent tool interface.

Glow · Glow AI-Powered Endpoint Security PlatformInferred contributionmedium confidence · 1 source

Glow endpoint controls can prevent sensitive information exposure through AI-enabled tools and unmanaged local workflows.

AuditaAI assessment: endpoint controls preventing sensitive-data exposure through AI tools contribute to exfiltration protection.

Google Cloud · Model ArmorInferred contributionmedium confidence · 1 source

Model Armor scans prompts and responses for prompt injection and jailbreak content and can return a block verdict when a violation is detected.

AuditaAI assessment: blocking prompt-injection/jailbreak content in prompts and responses protects the model interface.

Google Cloud · Model ArmorInferred contributionmedium confidence · 1 source

Model Armor can inspect, transform, tokenize, and redact sensitive elements in AI prompts and responses through Sensitive Data Protection integration.

AuditaAI assessment: inspect/transform/tokenize/redact sensitive elements in prompts and responses contributes to exfiltration protection.

Google Cloud · Model ArmorInferred contributionmedium confidence · 1 source

Model Armor sanitizes MCP tool-call requests, responses, and tool execution errors and can block content that violates configured security filters.

AuditaAI assessment: sanitizing MCP tool-call requests/responses at the interface protects the tool interface from tampering.

Google Cloud · Model ArmorInferred contributionmedium confidence · 1 source

Through Agent Gateway, Model Armor screens and can block policy-violating traffic between agents and clients, external systems, MCP servers, third-party AI agents, and other AI agents.

AuditaAI assessment: screening/blocking policy-violating traffic between agents, MCP servers, and other agents protects agent interfaces.

Google Cloud · Sensitive Data ProtectionInferred contributionmedium confidence · 1 source

Sensitive Data Protection classifies and de-identifies sensitive content used for model training, tuning, and generative AI prompts and responses.

AuditaAI assessment: classifying and de-identifying sensitive content in training data and generative AI prompts/responses reduces data exfiltration risk.

HiddenLayer · AI Runtime SecurityInferred contributionmedium confidence · 1 source

AI Runtime Security can detect, block, or redact unsafe actions and sensitive information according to policy and platform capabilities.

AuditaAI assessment: blocking/redacting unsafe actions and sensitive info at runtime protects the model/data interface.

Lasso Security · Runtime Enforcement and AI Detection and ResponseInferred contributionmedium confidence · 2 sources

Lasso runtime enforcement can block prompt-injection attempts and prevent unsafe autonomous agent actions or unauthorized tool invocation.

AuditaAI assessment: blocking prompt injection and preventing unsafe autonomous actions/unauthorized tool invocation protects agent/model interfaces.

Meta Platforms, Inc. · Llama GuardInferred contributionmedium confidence · 1 source

Llama Guard classifies input prompts and model responses against content-safety categories so applications can detect unsafe interactions.

AuditaAI assessment: classifying prompts and responses against safety categories protects the model interface from unsafe interactions.

Meta Platforms, Inc. · Llama Prompt GuardInferred contributionmedium confidence · 1 source

Llama Prompt Guard classifies input text for prompt injection and jailbreak patterns before the text reaches the primary model.

AuditaAI assessment: classifying input text for injection/jailbreak before the primary model protects the model interface.

Microsoft · Azure AI Content Safety and Prompt ShieldsInferred contributionmedium confidence · 1 source

Azure AI Content Safety and Prompt Shields identify direct and indirect prompt injection and related unsafe prompt patterns before they reach downstream model behavior.

AuditaAI assessment: identifying direct and indirect prompt injection before it reaches model behaviour protects the model interface.

Microsoft · Azure AI Content Safety and Prompt ShieldsInferred contributionmedium confidence · 1 source

Azure AI Content Safety applies jailbreak detection and policy filtering to reduce unsafe prompt and response interactions at runtime.

AuditaAI assessment: jailbreak detection and policy filtering of prompt/response interactions protect the model interface at runtime.

Microsoft · Microsoft Purview for AIInferred contributionmedium confidence · 1 source

Microsoft Purview for AI applies DLP and sensitivity controls to reduce unauthorized sensitive data transfer in AI interactions.

AuditaAI assessment: DLP and sensitivity controls that reduce unauthorized sensitive-data transfer in AI interactions protect data at the model interface.

Microsoft · Microsoft Agent 365Inferred contributionmedium confidence · 1 source

Microsoft Agent 365 provides continuous agent threat detection and configurable real-time protection policies that block unsafe behaviors and malicious activity.

AuditaAI assessment: real-time protection policies blocking unsafe agent behaviours protect the agent interface.

Mindgard · AI Runtime Threat Detection and ResponseInferred contributionmedium confidence · 1 source

Runtime guardrails are applied to block prompt injection attack paths before harmful model behavior propagates.

AuditaAI assessment: runtime guardrails blocking prompt-injection paths protect model behaviour from tampering.

NEO · Neo Security PlatformInferred contributionmedium confidence · 1 source

Neo Security Platform is positioned to prevent agentic threats by controlling unsafe runtime action paths and over-permissioned execution conditions.

AuditaAI assessment: controlling unsafe runtime action paths for agentic execution protects the agent interface.

Nightfall AI · AI Application DLPInferred contributionmedium confidence · 1 source

AI Application DLP applies pre-submission filtering and policy controls to block sensitive prompt, upload, and clipboard data before transfer to AI providers.

AuditaAI assessment: pre-submission filtering blocking sensitive prompt/upload/clipboard data before transfer to AI providers protects data exfiltration paths.

Nightfall AI · AI Agent SecurityInferred contributionmedium confidence · 1 source

AI Agent Security uses hook-level interception and tool-call governance to constrain unsafe autonomous actions before execution.

AuditaAI assessment: hook-level interception and tool-call governance constrain unsafe autonomous actions at the agent interface.

NVIDIA Corporation · NVIDIA NeMo GuardrailsInferred contributionmedium confidence · 1 source

NeMo Guardrails applies programmable dialog, topical, and safety rails to inspect and constrain input prompts and model responses in LLM applications.

AuditaAI assessment: dialog/topical/safety rails constraining prompts and responses protect the model interface.

NVIDIA Corporation · NVIDIA OpenShellInferred contributionhigh confidence · 2 sources

OpenShell runs autonomous agents in isolated sandboxes and enforces out-of-process filesystem, network, process, inference, credential, and skill policies at binary, destination, method, and path level, with developer-approved policy updates and an audit trail of allow and deny decisions.

AuditaAI assessment: deny-by-default egress, credential isolation, and controlled inference routing protect model interfaces and data paths from unauthorized access and exfiltration.

OpenAI · OpenAI Moderation APIInferred contributionmedium confidence · 1 source

The OpenAI Moderation API inspects text and image content and returns category classifications for potentially harmful content.

AuditaAI assessment: content classification at the AI interface protects downstream model behaviour from unsafe input/output categories.

OpenAI · OpenAI Guardrails PythonInferred contributionmedium confidence · 1 source

OpenAI Guardrails Python runs configurable checks on application inputs and outputs so failed checks can prevent an unsafe interaction from proceeding.

AuditaAI assessment: configurable input/output checks that prevent unsafe interactions protect the model interface.

Palo Alto Networks · Prisma AIRSInferred contributionmedium confidence · 1 source

Prisma AIRS applies real-time safeguards to AI prompts, responses, model interactions, agent actions, and data exposure paths.

AuditaAI assessment: real-time safeguards on prompts, responses, model interactions, agent actions, and data exposure protect the model/agent interface.

Palo Alto Networks · Prisma AIRSInferred contributionmedium confidence · 1 source

Prisma AIRS verifies agent identity and enforces real-time security controls for agent actions.

AuditaAI assessment: real-time security controls over agent actions protect the agent interface.

Palo Alto Networks · Prisma AIRSInferred contributionmedium confidence · 1 source

Prisma AIRS stops agent-specific tool misuse, memory manipulation, adversarial instructions, and prompt injection before threats propagate across an agent swarm.

AuditaAI assessment: blocking tool misuse, memory manipulation, adversarial instructions, and injection protects the agent interface from tampering.

Palo Alto Networks · AI Access SecurityInferred contributionmedium confidence · 1 source

AI Access Security classifies sensitive content inline and blocks sensitive text and file transfers to GenAI applications.

AuditaAI assessment: inline classification and blocking of sensitive transfers to GenAI apps protects data at the AI interface.

Portkey · PortkeyInferred contributionmedium confidence · 1 source

Portkey automatically redacts sensitive data from requests before sending them to an LLM.

AuditaAI assessment: redacting sensitive data before sending to an LLM protects data at the model interface.

Portkey · PortkeyInferred contributionmedium confidence · 1 source

Portkey invokes Prisma AIRS guardrail checks before and after model requests and can enforce returned block verdicts.

AuditaAI assessment: invoking guardrail checks before/after model requests and enforcing block verdicts protects the model interface.

Koi Security · Koi Agentic Endpoint SecurityInferred contributionmedium confidence · 1 source

Koi AES enforces endpoint guardrails that approve, flag, or block autonomous tools.

AuditaAI assessment: approving/flagging/blocking autonomous tools at the endpoint protects the tool interface.

Pangea · Pangea AI GuardInferred contributionmedium confidence · 2 sources

Pangea AI Guard detects and blocks prompt injection, jailbreak attempts, and malicious content insertion in AI applications.

AuditaAI assessment: detecting and blocking prompt injection, jailbreak, and malicious content insertion protects the model interface.

Pangea · Pangea RedactInferred contributionmedium confidence · 1 source

Pangea Redact detects confidential information and PII in AI workflows and can block, mask, hash, or encrypt the data under configured rules.

AuditaAI assessment: block/mask/hash/encrypt of PII in AI workflows protects data at the interface layer.

Prompt Security · Prompt SecurityInferred contributionmedium confidence · 1 source

Prompt Security runtime enforcement can block prompt-injection attempts in employee and application AI interaction paths.

AuditaAI assessment: runtime blocking of prompt-injection attempts protects the model interface from tampering.

Prompt Security · Prompt SecurityInferred contributionmedium confidence · 1 source

Prompt Security prompt and content controls redact sensitive enterprise data before it is sent to external models.

AuditaAI assessment: redacting sensitive data before it is sent to external models protects data exfiltration paths.

Prompt Security · Prompt SecurityInferred contributionmedium confidence · 2 sources

Prompt Security agent-focused governance restricts risky autonomous tool use and unsafe execution decisions.

AuditaAI assessment: restricting risky autonomous tool use and unsafe execution decisions protects the agent interface.

Snowflake Inc. · Cortex AI GuardrailsInferred contributionmedium confidence · 1 source

Cortex AI Guardrails evaluate runtime prompts and responses to mitigate direct and indirect prompt-injection and jailbreak attempts.

AuditaAI assessment: runtime guardrails mitigating direct/indirect prompt-injection and jailbreak protect the model interface.

Straiker · Straiker Defend AIInferred contributionmedium confidence · 1 source

Straiker Defend AI detects and blocks identity abuse, memory poisoning, data exfiltration, and resource exploitation targeting AI agents at runtime.

AuditaAI assessment: blocking identity abuse, memory poisoning, data exfiltration, and resource exploitation at runtime protects the agent interface.

TrojAI · TrojAI DefendInferred contributionmedium confidence · 1 source

TrojAI Defend blocks prompt injection, jailbreaking, sensitive-data leakage, and toxic content in real time under security policies.

AuditaAI assessment: blocking injection, jailbreaking, leakage, and toxic content in real time protects the model interface.

Zenity · Runtime Boundaries and AIDRInferred contributionmedium confidence · 2 sources

Zenity runtime boundaries can block unsafe agent actions, including risky tool usage and unauthorized task execution.

AuditaAI assessment: runtime boundaries blocking unsafe agent actions and risky tool usage protect the agent interface.

Zenity · Runtime Boundaries and AIDRInferred contributionmedium confidence · 2 sources

Zenity identity-aware runtime boundaries can prevent sensitive data access and exposure by over-permissioned agents.

AuditaAI assessment: preventing sensitive-data access/exposure by agents protects data exfiltration paths.

SPLX · SPLX Runtime GuardrailsInferred contributionmedium confidence · 2 sources

Zscaler AI Security runtime protection blocks prompt injection, data poisoning, and malicious URLs in AI interactions.

AuditaAI assessment: runtime blocking of prompt injection, data poisoning, and malicious URLs protects the model interface.

Zscaler · Zscaler AI SecurityInferred contributionmedium confidence · 1 source

Zscaler AI Security applies data security and content policies to prevent risky AI outputs and govern response safety.

AuditaAI assessment: data-security and content policies to prevent risky AI outputs protect the model response interface.

Zscaler · Zscaler Data SecurityInferred contributionmedium confidence · 1 source

Zscaler Data Security inspects AI usage and prompts and can block risky access or enforce prompt DLP to prevent data loss.

AuditaAI assessment: prompt-DLP inspection and blocking of risky access prevent data loss through AI prompts.

Alice · WonderFenceInferred contributionmedium confidence · 1 source

WonderFence intercepts unsafe model inputs and blocks harmful outputs in production LLM and agentic workflows.

AuditaAI assessment: runtime blocking of unsafe inputs and harmful outputs protects model and agent interaction interfaces.

Gray Swan AI · CygnalInferred contributionmedium confidence · 1 source

Cygnal classifies and blocks adversarial AI inputs and unsafe outputs during production runtime.

AuditaAI assessment: runtime blocking of adversarial inputs and unsafe outputs protects the model interface.

Mirror Security · Mirror Security SuiteInferred contributionmedium confidence · 1 source

Mirror Security keeps prompts, context, and responses encrypted through inference workflows while enforcing decision-time policies.

AuditaAI assessment: encrypted handling of prompt, context, and response data during inference protects model data interfaces from unauthorized disclosure.

Votal AI · Votal Runtime Security PlatformInferred contributionmedium confidence · 2 sources

Votal blocks prompt-injection patterns and PII policy violations through layered runtime guardrail controls.

AuditaAI assessment: runtime blocking of prompt-injection and sensitive-data policy violations protects model interaction paths.

TrendAI · TrendAI Vision One AI SecurityInferred contributionmedium confidence · 2 sources

TrendAI Vision One AI Security inspects and controls enterprise traffic to public and private GenAI services to reduce prompt-injection abuse and unauthorized AI use.

AuditaAI assessment: inline traffic controls and policy enforcement over GenAI interactions protect model and interface behavior from unsafe manipulation.

Verno Labs · Verno Labs AI Agent Security PlatformInferred contributionmedium confidence · 1 source

Verno Labs provides runtime enforcement controls to constrain unsafe or unauthorized AI agent actions.

AuditaAI assessment: runtime enforcement that constrains unauthorized or unsafe agent actions contributes continuous model and interface protection.

Harmonic Security · Harmonic Security PlatformInferred contributionhigh confidence · 1 source

Harmonic Security inspects user prompts in real time to detect sensitive enterprise information (PII, source code, financial data) and enforces redaction or blocking policies prior to transmission to external LLMs.

AuditaAI assessment: real-time prompt DLP and sensitive data redaction protect model interactions and prevent proprietary data exfiltration.

Dynamo AI · DynamoGuardInferred contributionhigh confidence · 1 source

DynamoGuard performs low-latency runtime inspection of prompts and model completions to detect and block prompt injection, jailbreaks, PII leakage, and toxic content.

AuditaAI assessment: low-latency inline guardrails blocking prompt injection, jailbreaks, and PII leakage protect models continuously in production.

Enkrypt AI · SiftInferred contributionhigh confidence · 1 source

Sift intercepts API traffic to foundation models to detect and block prompt injection, jailbreaking, PII leakage, and toxic outputs at the gateway boundary.

AuditaAI assessment: AI security gateway proxy intercepting API traffic to block prompt injection and data leaks protects models continuously.

Guideline 3.3

Develop incident management procedures

Prepare, train, reassess, and equip responders for AI-related incidents, escalation, remediation, backup, and customer investigation.

2 reviewed contributions
Reviewed product contributions+
Mindgard · AI Runtime Threat Detection and ResponseInferred contributionmedium confidence · 1 source

Runtime response workflows support containment and remediation for unsafe agent behavior and unauthorized action chains.

AuditaAI assessment: response workflows for containment and remediation of unsafe agent behaviour are explicit incident-management workflows.

Nightfall AI · Data Detection and ResponseInferred contributionmedium confidence · 1 source

Data Detection and Response performs real-time scanning with automated quarantine, notification, and remediation workflows for risky content flows.

AuditaAI assessment: real-time quarantine/notification/remediation workflows for risky content flows are explicit incident-response procedures.

Guideline 3.4

Release AI responsibly

Use effective security evaluation, benchmarking, and red teaming before release and disclose known limitations and failure modes.

22 reviewed contributions
Reviewed product contributions+
Arthur · Arthur PlatformInferred contributionmedium confidence · 1 source

Arthur Platform performs pre-production and runtime evaluations to monitor AI behavior and policy outcomes.

AuditaAI assessment: pre-production evaluations of AI behaviour and policy outcomes provide pre-release security evaluation.

Check Point Software Technologies · AI Red Teaming and AssessmentInferred contributionmedium confidence · 1 source

AI Red Teaming runs broad and targeted adversarial campaigns to assess AI applications and agents for prompt injection, jailbreak, data leakage, unauthorized actions, and regressions.

AuditaAI assessment: broad/targeted adversarial campaigns for injection, jailbreak, leakage, and regressions provide pre-release red teaming.

Cisco · AI Model and Application ValidationInferred contributionmedium confidence · 1 source

AI Model and Application Validation performs algorithmic red teaming and model vulnerability validation for AI applications and models.

AuditaAI assessment: algorithmic red teaming and model vulnerability validation are pre-release security evaluation.

Google Cloud · Security Command CenterInferred contributionmedium confidence · 1 source

Security Command Center assesses interconnected AI risks and prioritizes high-risk issues using posture analysis and virtual red teaming.

AuditaAI assessment: virtual red teaming for AI risk assessment contributes to pre-release evaluation.

HiddenLayer · AI Attack SimulationInferred contributionmedium confidence · 1 source

AI Attack Simulation tests AI systems for jailbreaks, prompt injection, data leakage, and unsafe agent tool use through automated adversarial simulation.

AuditaAI assessment: automated adversarial simulation for jailbreaks, injection, leakage, and unsafe agent tool use is pre-release red teaming.

Lasso Security · Automated AI Red TeamingInferred contributionmedium confidence · 2 sources

Lasso automated AI red teaming runs adversarial testing against agentic workflows to identify exploitable weaknesses.

AuditaAI assessment: automated adversarial testing of agentic workflows is pre-release red teaming.

Mindgard · AI Red Teaming and AssessmentInferred contributionmedium confidence · 1 source

AI Red Teaming and Assessment runs adversarial workflows to surface jailbreak and guardrail-bypass weaknesses for pre-deployment remediation.

AuditaAI assessment: adversarial workflows surfacing jailbreak/guardrail gaps for pre-deployment remediation are pre-release red teaming.

NVIDIA Corporation · garakInferred contributionmedium confidence · 1 source

garak probes language-model endpoints across attack classes including jailbreaks, prompt injection, and data leakage to identify model security weaknesses.

AuditaAI assessment: adversarial probing of model endpoints for jailbreaks, injection, and leakage is pre-release security evaluation.

Palo Alto Networks · Prisma AIRSInferred contributionmedium confidence · 1 source

Prisma AIRS simulates real-world attacks against single-agent and multi-agent AI systems to identify weaknesses before production.

AuditaAI assessment: simulating attacks against single- and multi-agent systems before production is pre-release red teaming.

Straiker · Straiker Ascend AIInferred contributionmedium confidence · 1 source

Straiker Ascend AI runs automated adversarial testing for prompt injection, MCP tool misuse, agentic exploits, and data exfiltration risks.

AuditaAI assessment: automated adversarial testing for injection, MCP tool misuse, and exfiltration risk is pre-release red teaming.

TrojAI · TrojAI DetectInferred contributionmedium confidence · 1 source

TrojAI Detect runs continuous agent-led red teaming against AI models and agents to identify unsafe behavior before deployment.

AuditaAI assessment: continuous agent-led red teaming of models and agents before deployment is pre-release adversarial testing.

SPLX · SPLX AI Red TeamingInferred contributionmedium confidence · 2 sources

Zscaler AI Security runs configurable attack simulations to identify AI vulnerabilities and provide remediation guidance before and during deployment.

AuditaAI assessment: configurable attack simulations before/during deployment with remediation guidance is pre-release red teaming.

Alice · WonderBuildInferred contributionmedium confidence · 2 sources

WonderBuild performs pre-deployment adversarial testing and red teaming across AI models, applications, and agents.

AuditaAI assessment: pre-deployment adversarial testing and red teaming of AI systems contributes to responsible release evaluation.

DeepKeep · DeepKeep AI Security PlatformInferred contributionmedium confidence · 2 sources

DeepKeep performs AI red teaming and model security scanning to discover vulnerabilities before production impact.

AuditaAI assessment: AI red teaming and model scanning contribute pre-release security evaluation for responsible deployment.

Gray Swan AI · ShadeInferred contributionmedium confidence · 2 sources

Shade runs adversarial red teaming against deployed models, agent workflows, and guardrail configurations to surface exploitable weaknesses.

AuditaAI assessment: adversarial red teaming of model and agent deployments contributes to responsible release security evaluation.

Mirror Security · Mirror Security SuiteInferred contributionmedium confidence · 2 sources

Mirror DiscoveR continuously runs automated red teaming to uncover AI vulnerabilities and validate security controls.

AuditaAI assessment: continuous adversarial evaluation contributes evidence for secure release and validation of AI controls.

TrendAI · TrendAI Vision One AI SecurityInferred contributionmedium confidence · 1 source

TrendAI combines AI Scanner pre-deployment testing with AI Guard runtime controls to detect vulnerabilities and reduce sensitive data leakage in AI applications.

AuditaAI assessment: pre-deployment AI scanning and vulnerability validation contribute security evaluation before release.

Zero Day Investigative Network · 0DIN AI Security ScannerInferred contributionmedium confidence · 2 sources

0DIN AI Security Scanner evaluates LLM and GenAI application behavior against exploit and jailbreak test suites.

AuditaAI assessment: automated exploit testing of LLM and GenAI applications contributes pre-release security evaluation.

Verno Labs · Verno Labs AI Agent Security PlatformInferred contributionmedium confidence · 1 source

Verno Labs performs automated adversarial testing to evaluate AI agent security weaknesses before production impact.

AuditaAI assessment: automated adversarial testing contributes security evaluation evidence for responsible release.

Promptfoo · Promptfoo CoreInferred contributionhigh confidence · 2 sources

Promptfoo executes automated adversarial test fixtures and benchmark assertions against LLM endpoints to evaluate resistance to prompt injection, toxicity, and system prompt extraction.

AuditaAI assessment: automated adversarial probing, jailbreak benchmarking, and vulnerability testing contribute directly to pre-deployment security evaluation for responsible release.

Dynamo AI · DynamoEvalInferred contributionhigh confidence · 1 source

DynamoEval executes automated adversarial attacks, security benchmark evaluations, and regulatory compliance stress-tests on models prior to production release.

AuditaAI assessment: automated adversarial testing, red teaming, and compliance stress-testing contribute pre-release security evaluation.

Enkrypt AI · Enkrypt Red TeamInferred contributionhigh confidence · 1 source

Enkrypt Red Team conducts automated adversarial evaluations against model endpoints across known prompt injection and compliance vulnerability categories.

AuditaAI assessment: automated red teaming and vulnerability benchmarking across attack vectors contribute pre-deployment security evaluation for responsible release.

Guideline 3.5

Make it easy for users to do the right things

Provide secure defaults, misuse controls, usable guidance, responsibility boundaries, and transparency about data handling.

3 reviewed contributions
Reviewed product contributions+
Anthropic · Claude Code Security ArchitectureInferred contributionmedium confidence · 1 source

Claude Code requires permission for state-changing file, command, and network actions before those actions execute.

AuditaAI assessment: requiring explicit user permission for state-changing actions is a secure default and user-responsibility control.

Amazon Web Services · Amazon Bedrock AgentCoreInferred contributionmedium confidence · 1 source

AWS supports human approval hooks for high-consequence agent actions and behavioral monitoring for actions outside an agent's authorized scope.

AuditaAI assessment: human approval hooks for high-consequence agent actions establish secure defaults and user responsibility boundaries.

NVIDIA Corporation · NVIDIA NemoClawInferred contributionmedium confidence · 1 source

NemoClaw deploys supported autonomous agents from a digest-verified hardened blueprint with restrictive filesystem and process defaults, credential filtering, routed inference, state integrity checks, and operator approval for blocked network endpoints.

AuditaAI assessment: restrictive defaults and an explicit operator approval flow for blocked destinations make expansion of agent access an intentional user decision.

Lifecycle stage 4

Secure operation and maintenance

Monitor deployed AI systems, manage updates securely, and share lessons throughout ongoing operation.

Guideline 4.1

Monitor your system's behaviour

Measure model and system outputs and performance to identify security-relevant behavior changes, intrusions, compromises, and drift.

12 reviewed contributions
Reviewed product contributions+
Arthur · Arthur PlatformInferred contributionmedium confidence · 1 source

Arthur Platform performs pre-production and runtime evaluations to monitor AI behavior and policy outcomes.

AuditaAI assessment: runtime evaluations of AI behaviour and policy outcomes provide ongoing behaviour monitoring.

Amazon Web Services · Amazon SageMaker Clarify and Model MonitorInferred contributionmedium confidence · 1 source

SageMaker Clarify and monitoring workflows provide ongoing model and data behavior analysis for drift, quality, and governance evidence.

AuditaAI assessment: ongoing model/data behaviour analysis for drift and quality directly implements behaviour monitoring including drift.

Amazon Web Services · Amazon Bedrock AgentCoreInferred contributionmedium confidence · 1 source

AWS supports human approval hooks for high-consequence agent actions and behavioral monitoring for actions outside an agent's authorized scope.

AuditaAI assessment: behavioural monitoring for actions outside an agent's authorized scope is runtime behaviour monitoring.

Wiz · Wiz AI Runtime ProtectionInferred contributionmedium confidence · 1 source

Wiz AI Runtime Protection detects prompt injection, rogue agents, and malicious behavior targeting AI systems.

AuditaAI assessment: detecting rogue agents and malicious behaviour targeting AI systems is runtime behaviour monitoring.

HiddenLayer · AI Runtime SecurityInferred contributionmedium confidence · 1 source

AI Runtime Security detects and investigates prompt injection, unsafe agent behavior, sensitive data exposure, malicious tool use, and other runtime AI threats.

AuditaAI assessment: detecting/investigating unsafe agent behaviour and other runtime AI threats is runtime behaviour monitoring.

Lasso Security · Runtime Enforcement and AI Detection and ResponseInferred contributionmedium confidence · 2 sources

Lasso AI detection and response workflows identify and triage suspicious AI behavior using contextual attack telemetry.

AuditaAI assessment: identifying suspicious AI behaviour via contextual telemetry is runtime behaviour monitoring.

Microsoft · Microsoft Agent 365Inferred contributionmedium confidence · 1 source

Microsoft Agent 365 provides continuous agent threat detection and configurable real-time protection policies that block unsafe behaviors and malicious activity.

AuditaAI assessment: continuous agent threat detection is runtime behaviour monitoring.

Mindgard · AI Runtime Threat Detection and ResponseInferred contributionmedium confidence · 1 source

AI Runtime Threat Detection and Response monitors production AI execution to detect suspicious outputs and attack behavior.

AuditaAI assessment: monitoring production AI execution to detect suspicious outputs and attack behaviour is runtime behaviour monitoring.

Zenity · Runtime Boundaries and AIDRInferred contributionmedium confidence · 2 sources

Zenity behavioral runtime telemetry supports detection and investigation of unsafe or manipulative AI outcomes.

AuditaAI assessment: behavioural runtime telemetry supporting detection of unsafe/manipulative AI outcomes is runtime behaviour monitoring.

Alice · WonderCheckInferred contributionmedium confidence · 1 source

WonderCheck runs scheduled production evaluations to detect model drift, regressions, and emerging AI vulnerabilities over time.

AuditaAI assessment: scheduled production evaluations for drift and regressions provide ongoing AI behavior monitoring.

Votal AI · Votal Runtime Security PlatformInferred contributionmedium confidence · 2 sources

Votal continuously probes deployed AI guardrails with adversarial testing to identify gaps and improve policy coverage.

AuditaAI assessment: continuous adversarial probing and control-gap detection contributes ongoing behavior monitoring and reassessment.

Dynamo AI · DynamoGuardInferred contributionhigh confidence · 1 source

DynamoGuard performs low-latency runtime inspection of prompts and model completions to detect and block prompt injection, jailbreaks, PII leakage, and toxic content.

AuditaAI assessment: measuring model outputs and completions for toxicity, hallucinations, and safety deviations supports monitoring system behavior.

Guideline 4.2

Monitor your system's inputs

Monitor and log inference requests, queries, and prompts for compliance, audit, investigation, remediation, and adversarial-input detection.

8 reviewed contributions
Reviewed product contributions+
Cato Networks · Cato AI Security (AISEC)Inferred contributionmedium confidence · 1 source

Cato AI Security runtime monitoring detects prompt-injection patterns and policy-violating AI prompt activity.

AuditaAI assessment: runtime monitoring for prompt-injection patterns and policy-violating prompts is adversarial input monitoring.

Glow · Glow AI-Powered Endpoint Security PlatformInferred contributionmedium confidence · 1 source

Glow continuous endpoint monitoring can detect suspicious AI interaction patterns and prompt-driven misuse across local applications and browser activity.

AuditaAI assessment: endpoint monitoring for suspicious AI interaction and prompt-driven misuse is adversarial input monitoring.

Meta Platforms, Inc. · Llama Prompt GuardInferred contributionmedium confidence · 1 source

Llama Prompt Guard classifies input text for prompt injection and jailbreak patterns before the text reaches the primary model.

AuditaAI assessment: classifying incoming text for injection/jailbreak is adversarial input monitoring.

Prompt Security · Prompt SecurityInferred contributionmedium confidence · 1 source

Prompt Security provides enterprise visibility over GenAI usage patterns and interaction channels.

AuditaAI assessment: enterprise visibility over GenAI usage patterns and interaction channels is monitoring of AI queries/prompts for audit and investigation.

Snowflake Inc. · Cortex AI GatewayInferred contributionmedium confidence · 2 sources

Cortex AI Gateway records both agent identity and human delegator context for task-scoped attribution and governance workflows.

AuditaAI assessment: recording agent identity and human delegator context for task-scoped attribution logs inference requests for compliance and investigation.

Harmonic Security · Harmonic Security PlatformInferred contributionhigh confidence · 1 source

Harmonic Security inspects user prompts in real time to detect sensitive enterprise information (PII, source code, financial data) and enforces redaction or blocking policies prior to transmission to external LLMs.

AuditaAI assessment: inspecting, logging, and auditing prompt queries across enterprise AI applications contributes directly to monitoring system inputs.

Dynamo AI · DynamoGuardInferred contributionhigh confidence · 1 source

DynamoGuard performs low-latency runtime inspection of prompts and model completions to detect and block prompt injection, jailbreaks, PII leakage, and toxic content.

AuditaAI assessment: real-time prompt inspection and logging detect adversarial inputs and injection attempts.

Enkrypt AI · SiftInferred contributionhigh confidence · 1 source

Sift intercepts API traffic to foundation models to detect and block prompt injection, jailbreaking, PII leakage, and toxic outputs at the gateway boundary.

AuditaAI assessment: gateway proxy logging and inspecting incoming queries and prompts monitor system inputs for adversarial patterns.

Guideline 4.4

Collect and share lessons learned

Participate in information sharing, support security research and reporting, publish useful disclosures, and remediate issues promptly.

1 reviewed contribution
Reviewed product contributions+
Zero Day Investigative Network · 0DIN GenAI Bug Bounty PlatformInferred contributionmedium confidence · 1 source

0DIN publishes threat-intelligence updates and validated vulnerability patterns for enterprise AI security teams.

AuditaAI assessment: publishing validated AI vulnerability patterns contributes lessons sharing and security knowledge dissemination.