Capability navigator

Explore the AI security product landscape

Start with a security domain, open a capability, and inspect the reviewed products and behaviors that support it.

Capability domains

7 domains135 reviewed offerings

Runtime Protection

Controls that inspect and enforce policy during live model and agent interactions.

3 capabilities

Prompt and Response Guardrails

Filters and policy checks that block unsafe prompts, responses, and tool calls at runtime.

40 offerings

Amazon Web Services

Amazon Bedrock Guardrails
PREVENT1 source

Amazon Bedrock Guardrails applies inline controls that can block prompt-injection and jailbreak-style requests before model outputs are returned.

Product page

Check Point Software Technologies / Lakera

Lakera Guard
PREVENT2 sources

Lakera runtime AI security positioning includes prompt attack prevention, data leakage protection, and context-aware runtime security controls.

Product page

Cranium AI, Inc. / Aiceberg

Aiceberg Guardian Agent
PREVENT2 sources

Aiceberg Guardian Agent provides runtime visibility and guardrail control over agentic AI decision flows.

Product page

Dynamo AI

DynamoGuard
PREVENTDETECT1 source

DynamoGuard performs low-latency runtime inspection of prompts and model completions to detect and block prompt injection, jailbreaks, PII leakage, and toxic content.

Product page

Enkrypt AI

Sift
PREVENTDETECT1 source

Sift intercepts API traffic to foundation models to detect and block prompt injection, jailbreaking, PII leakage, and toxic outputs at the gateway boundary.

Product page

F5, Inc.

F5 AI Guardrails
PREVENT1 source

F5 AI Guardrails applies inline policy controls that can block prompt-injection payloads before requests reach downstream models and tools.

F5 AI Guardrails enforces policies to detect and prevent jailbreak-style attempts that seek to bypass model safety boundaries.

Product page

Google / Google Cloud

Model Armor
DETECTPREVENT2 sources

Model Armor scans prompts and responses for prompt injection and jailbreak content and can return a block verdict when a violation is detected.

Model Armor sanitizes MCP tool-call requests, responses, and tool execution errors and can block content that violates configured security filters.

Product page

Maxim AI

Bifrost AI Gateway
PREVENT1 source

Bifrost applies runtime model protection controls that block unsafe outputs and enforce policy on live AI traffic.

Product page

Meta Platforms, Inc.

Llama Guard
DETECT1 source

Llama Guard classifies input prompts and model responses against content-safety categories so applications can detect unsafe interactions.

Product page

Meta Platforms, Inc.

Llama Prompt Guard
DETECT1 source

Llama Prompt Guard classifies input text for prompt injection and jailbreak patterns before the text reaches the primary model.

Product page

Azure AI Content Safety and Prompt Shields identify direct and indirect prompt injection and related unsafe prompt patterns before they reach downstream model behavior.

Azure AI Content Safety applies jailbreak detection and policy filtering to reduce unsafe prompt and response interactions at runtime.

Product page

NEO

Neo Security Platform
PREVENT1 source

Neo Security Platform is positioned to prevent agentic threats by controlling unsafe runtime action paths and over-permissioned execution conditions.

Product page

NVIDIA Corporation

NVIDIA NeMo Guardrails
PREVENT1 source

NeMo Guardrails applies programmable dialog, topical, and safety rails to inspect and constrain input prompts and model responses in LLM applications.

Product page

OpenAI

OpenAI Guardrails Python
PREVENT1 source

OpenAI Guardrails Python runs configurable checks on application inputs and outputs so failed checks can prevent an unsafe interaction from proceeding.

Product page

OpenAI

OpenAI Moderation API
DETECT1 source

The OpenAI Moderation API inspects text and image content and returns category classifications for potentially harmful content.

Product page

Palo Alto Networks / Protect AI

LLM Guard
PREVENTDETECT1 source

LLM Guard inspects, sanitizes, and evaluates LLM prompts and model completions against prompt injection, jailbreaks, and sensitive data leakage.

Product page

Palo Alto Networks / Portkey

Portkey
DETECTPREVENT1 source

Portkey invokes Prisma AIRS guardrail checks before and after model requests and can enforce returned block verdicts.

Product page

Palo Alto Networks

Prisma AIRS
PREVENT1 source

Prisma AIRS applies real-time safeguards to AI prompts, responses, model interactions, agent actions, and data exposure paths.

Product page

SentinelOne, Inc. / Prompt Security

Prompt Security
PREVENT1 source

Prompt Security runtime enforcement can block prompt-injection attempts in employee and application AI interaction paths.

Product page

TrendAI

TrendAI Vision One AI Security
PREVENTDETECT2 sources

TrendAI Vision One AI Security inspects and controls enterprise traffic to public and private GenAI services to reduce prompt-injection abuse and unauthorized AI use.

Product page

Agent Runtime Governance

Controls for autonomous agent behavior, action approval, and runtime policy decisions.

25 offerings

Cato Networks

Cato AI Security (AISEC)
PREVENT2 sources

Cato AI Security governance controls constrain unsafe autonomous actions and high-risk tool usage for AI agents and applications.

Product page

Cranium AI, Inc. / Aiceberg

Aiceberg Guardian Agent
PREVENT2 sources

Aiceberg Guardian Agent provides runtime visibility and guardrail control over agentic AI decision flows.

Product page

CrowdStrike / Pangea

Pangea AI Security Platform
PREVENT1 source

Pangea provides proxy-based MCP integration to apply guardrails and authentication or authorization controls to agent-to-tool and agent-to-agent communications.

Product page

F5, Inc.

F5 AI Guardrails
PREVENT2 sources

F5 AI Guardrails applies agent-focused runtime controls to constrain unsafe autonomous actions and high-risk tool execution paths.

Product page

Google / Google Cloud

Model Armor
PREVENT1 source

Through Agent Gateway, Model Armor screens and can block policy-violating traffic between agents and clients, external systems, MCP servers, third-party AI agents, and other AI agents.

Product page

Microsoft

Microsoft Agent 365
DETECTPREVENT1 source

Microsoft Agent 365 provides continuous agent threat detection and configurable real-time protection policies that block unsafe behaviors and malicious activity.

Product page

NEO

Neo Security Platform
PREVENT1 source

Neo Security Platform is positioned to prevent agentic threats by controlling unsafe runtime action paths and over-permissioned execution conditions.

Product page

Palo Alto Networks

Prisma AIRS
PREVENT2 sources

Prisma AIRS verifies agent identity and enforces real-time security controls for agent actions.

Prisma AIRS stops agent-specific tool misuse, memory manipulation, adversarial instructions, and prompt injection before threats propagate across an agent swarm.

Product page

SentinelOne, Inc. / Prompt Security

Prompt Security
PREVENT2 sources

Prompt Security agent-focused governance restricts risky autonomous tool use and unsafe execution decisions.

Product page

Runtime Threat Detection and Response

Detection signals and response workflows for suspicious model interactions and AI misuse.

16 offerings

DeepKeep

DeepKeep AI Security Platform
PREVENTDETECT1 source

DeepKeep monitors and controls AI agent gateway usage, identifies active MCP server dependencies, and supports allow or block policy enforcement.

Product page

Dynamo AI

DynamoGuard
PREVENTDETECT1 source

DynamoGuard performs low-latency runtime inspection of prompts and model completions to detect and block prompt injection, jailbreaks, PII leakage, and toxic content.

Product page

Enkrypt AI

Sift
PREVENTDETECT1 source

Sift intercepts API traffic to foundation models to detect and block prompt injection, jailbreaking, PII leakage, and toxic outputs at the gateway boundary.

Product page

Google / Google Cloud

Security Command Center
DETECTRESPOND1 source

Security Command Center detects AI-specific threats across the AI stack.

Security Command Center provides response workflows for AI-specific threats across the AI stack.

Product page

Microsoft

Microsoft Agent 365
DETECTPREVENT1 source

Microsoft Agent 365 provides continuous agent threat detection and configurable real-time protection policies that block unsafe behaviors and malicious activity.

Product page

Agent Security

Controls for agent tools, memory, communications, execution, resilience, and human oversight.

6 capabilities

Agent Tool Governance

Discovery, authorization, policy enforcement, and validation for tools and actions available to agents.

25 offerings

Amazon Web Services

Amazon Bedrock AgentCore
PREVENT1 source

Amazon Bedrock AgentCore gives agents distinct scoped identities and uses Cedar policy to authorize every tool call and data access independently of model reasoning.

Product page

Cyera

Cyera Agent Guardian
PREVENTAUDIT2 sources

Cyera Agent Guardian traces and governs agentic data usage across autonomous agent delegation chains, enforcing automated data access perimeters and non-human identity controls.

Product page

DeepKeep

DeepKeep AI Security Platform
PREVENTDETECT1 source

DeepKeep monitors and controls AI agent gateway usage, identifies active MCP server dependencies, and supports allow or block policy enforcement.

Product page

Dynamo AI

AgentWarden
POSTUREPREVENTRESPOND2 sources

AgentWarden analyzes reachable agent tools, external endpoints, and data sources during build time, evaluating tool combinations that present lethal trifecta risks (data access, external egress, and execution authority).

AgentWarden enforces security and authorization policies at runtime agent action boundaries across prompts, tool calls, tool responses, and final actions to prevent unauthorized execution and goal hijacking.

Product page

Google / Google Cloud

Model Armor
PREVENT1 source

Model Armor sanitizes MCP tool-call requests, responses, and tool execution errors and can block content that violates configured security filters.

Product page

Maxim AI

Bifrost AI Gateway
PREVENTAUDIT2 sources

Bifrost centralizes MCP tool connections and enforces authentication, access-control, and governance policies for agent tool usage.

Product page

Microsoft

Microsoft Foundry Agent Service
PREVENT1 source

Microsoft Foundry provisions distinct Entra agent identities and uses scoped access tokens and RBAC to authorize agent calls to MCP servers and downstream tools.

Product page

NVIDIA Corporation

NVIDIA OpenShell
PREVENTAUDIT2 sources

OpenShell runs autonomous agents in isolated sandboxes and enforces out-of-process filesystem, network, process, inference, credential, and skill policies at binary, destination, method, and path level, with developer-approved policy updates and an audit trail of allow and deny decisions.

Product page

Okta

Agent Gateway
PREVENTDETECT1 source

Okta Agent Gateway intercepts agent-to-tool and agent-to-API calls at runtime without requiring upstream application code changes.

Product page

OpenAI

OpenAI Frontier Security Evaluation
AUDITPOSTURE1 source

OpenAI Frontier integrates automated security testing and red teaming to evaluate AI coworkers for prompt injections, jailbreaks, data leaks, tool misuse, and out-of-policy behaviors.

Product page

OpenAI / Promptfoo

Promptfoo Enterprise
POSTURE1 source

Promptfoo simulates multi-turn adaptive attacks, autonomous agent goal hijacking, tool execution vulnerabilities, and unauthorized function calls in pre-deployment CI/CD environments.

Product page

OpenAI / Promptfoo

Promptfoo MCP Proxy
POSTURE1 source

Promptfoo MCP Proxy intercepts Model Context Protocol traffic between clients and tools to evaluate tool-call authorization, parameter tampering, and excessive agency.

Product page

Palo Alto Networks / Idira

Idira Secure AI Agents
PREVENT1 source

Idira Secure AI Agents acts as a dynamic agent identity broker that grants an agent access only for the duration of a specific task and automatically revokes permissions once the task completes.

Product page

Palo Alto Networks / Portkey

Portkey
AUDITPREVENT2 sources

Portkey MCP Gateway centralizes authentication, fine-grained server and tool access, observability, and runtime policy and stops unauthorized tool invocations before execution.

Product page

Palo Alto Networks

Prisma AIRS
PREVENT2 sources

Prisma AIRS verifies agent identity and enforces real-time security controls for agent actions.

Prisma AIRS governs agent tool calls, model access, and external connections through centralized policy and assigns each agent a governed identity with precise permissions and traceability.

Product page

Ping Identity Corporation

Agent Gateway & Runtime Identity
PREVENTDETECT1 source

Ping Agent Gateway intercepts agent invocations across multi-cloud proxies and MCP servers to evaluate runtime authorization policies dynamically before executing tool calls.

Product page

Teleport

Teleport MCP Access & Governance
PREVENT2 sources

Teleport proxies Model Context Protocol (MCP) server traffic and enforces granular role-based access control (RBAC) to allow or block specific tool calls based on string, regex, or glob patterns.

Product page

Agent Memory and Context Integrity

Integrity, provenance, isolation, expiration, and recovery controls for persistent agent memory and context.

4 offerings

Cyera

Cyera Agent Guardian
PREVENTAUDIT2 sources

Cyera Agent Guardian traces and governs agentic data usage across autonomous agent delegation chains, enforcing automated data access perimeters and non-human identity controls.

Product page

Mirror Security

Mirror Security Suite
PREVENT1 source

Mirror Security keeps prompts, context, and responses encrypted through inference workflows while enforcing decision-time policies.

Product page

Palo Alto Networks

Prisma AIRS
PREVENT1 source

Prisma AIRS stops agent-specific tool misuse, memory manipulation, adversarial instructions, and prompt injection before threats propagate across an agent swarm.

Product page

Agent Communication Security

Authentication, authorization, trust enforcement, and message validation across agent communication paths.

4 offerings

Amazon Web Services

Amazon Bedrock AgentCore
PREVENT1 source

Amazon Bedrock AgentCore applies identity and authorization controls to agents using MCP and A2A communications with external tools and other agents.

Product page

Google / Google Cloud

Model Armor
PREVENT1 source

Through Agent Gateway, Model Armor screens and can block policy-violating traffic between agents and clients, external systems, MCP servers, third-party AI agents, and other AI agents.

Product page

Microsoft

Microsoft Foundry Agent Service
PREVENT1 source

Microsoft Foundry uses agent identities and audience-scoped tokens to authenticate Agent-to-Agent endpoints and allow downstream services to grant or deny access through RBAC.

Product page

Agent Execution Isolation

Sandboxing, code validation, constrained execution, and resource boundaries for agent-selected operations.

8 offerings

NVIDIA Corporation

NVIDIA NemoClaw
PREVENT2 sources

NemoClaw deploys supported autonomous agents from a digest-verified hardened blueprint with restrictive filesystem and process defaults, credential filtering, routed inference, state integrity checks, and operator approval for blocked network endpoints.

Product page

NVIDIA Corporation

NVIDIA OpenShell
PREVENTAUDIT2 sources

OpenShell runs autonomous agents in isolated sandboxes and enforces out-of-process filesystem, network, process, inference, credential, and skill policies at binary, destination, method, and path level, with developer-approved policy updates and an audit trail of allow and deny decisions.

Product page

Okta

Agent Gateway
PREVENTDETECT1 source

Okta Agent Gateway intercepts agent-to-tool and agent-to-API calls at runtime without requiring upstream application code changes.

Product page

Ping Identity Corporation

Agent Gateway & Runtime Identity
PREVENTDETECT1 source

Ping Agent Gateway intercepts agent invocations across multi-cloud proxies and MCP servers to evaluate runtime authorization policies dynamically before executing tool calls.

Product page

Teleport

Teleport Beams
PREVENT1 source

Teleport Beams provisions ephemeral Firecracker microVMs with file system and network isolation to execute infrastructure AI agents without static credentials.

Product page

Agent Resilience and Containment

Failure isolation, propagation limits, circuit breaking, containment, and recovery across agent workflows.

4 offerings

Dynamo AI

AgentWarden
PREVENTRESPOND1 source

AgentWarden enforces security and authorization policies at runtime agent action boundaries across prompts, tool calls, tool responses, and final actions to prevent unauthorized execution and goal hijacking.

Product page

Palo Alto Networks

Prisma AIRS
PREVENT1 source

Prisma AIRS stops agent-specific tool misuse, memory manipulation, adversarial instructions, and prompt injection before threats propagate across an agent swarm.

Product page

Agent-Human Oversight

Human approval, identity disclosure, decision provenance, and oversight for consequential agent actions.

8 offerings

Amazon Web Services

Amazon Bedrock AgentCore
PREVENT1 source

AWS supports human approval hooks for high-consequence agent actions and behavioral monitoring for actions outside an agent's authorized scope.

Product page

NVIDIA Corporation

NVIDIA NemoClaw
PREVENT2 sources

NemoClaw deploys supported autonomous agents from a digest-verified hardened blueprint with restrictive filesystem and process defaults, credential filtering, routed inference, state integrity checks, and operator approval for blocked network endpoints.

Product page

Okta

Okta for AI Agents
AUDITPOSTURE2 sources

Okta registers AI agents as first-class identities in Universal Directory with mandatory human owner binding and lifecycle governance.

Product page

Palo Alto Networks / Idira

Idira Secure AI Agents
AUDIT1 source

Idira Secure AI Agents logs agent actions and communications, recording which agent performed an action and on behalf of which user, to support governance and compliance review.

Product page

Ping Identity Corporation

PingOne Agent IAM Core
AUDITPOSTURE1 source

PingOne Agent IAM Core registers AI agents as managed non-human identities with unique IDs, human ownership attribution, and dynamic scoping.

Product page

Access and Governance

Identity, app control, and governance controls that define who can use AI systems and how.

3 capabilities

AI Access Control

Policy enforcement for user, service, and workload access to AI tools and APIs.

8 offerings

Cisco

Cisco AI Defense
PREVENT1 source

Cisco AI Defense includes AI access and policy controls as part of the platform's documented control surface.

Product page

Maxim AI

Bifrost AI Gateway
PREVENTAUDIT2 sources

Bifrost centralizes MCP tool connections and enforces authentication, access-control, and governance policies for agent tool usage.

Product page

Palo Alto Networks

AI Access Security
PREVENTPOSTURE1 source

AI Access Security classifies GenAI applications by sanction status and can revoke access or control upload and download actions based on risk and privilege.

Product page

Palo Alto Networks / Portkey

Portkey
AUDITPREVENT2 sources

Portkey MCP Gateway centralizes authentication, fine-grained server and tool access, observability, and runtime policy and stops unauthorized tool invocations before execution.

Product page

Teleport

Teleport MCP Access & Governance
PREVENT2 sources

Teleport proxies Model Context Protocol (MCP) server traffic and enforces granular role-based access control (RBAC) to allow or block specific tool calls based on string, regex, or glob patterns.

Product page

TrendAI

TrendAI Vision One AI Security
PREVENTDETECT2 sources

TrendAI Vision One AI Security inspects and controls enterprise traffic to public and private GenAI services to reduce prompt-injection abuse and unauthorized AI use.

Product page

Zscaler

Zscaler AI Security
PREVENT1 source

Zscaler AI Security can warn, block, or isolate user access to AI applications under acceptable-use and data-protection policies.

Product page

AI SaaS Governance

Discovery and governance of sanctioned and unsanctioned AI SaaS usage.

5 offerings

Harmonic Security

Harmonic Security Platform
AUDITPOSTURE1 source

Harmonic Security discovers and catalogs enterprise generative AI application usage (Shadow AI), categorizing application risk posture and data compliance across cloud and endpoint environments.

Product page

Microsoft

Microsoft Purview for AI
AUDIT1 source

Microsoft Purview for AI provides classification and compliance tracking artifacts that support governance review of AI information handling.

Product page

Palo Alto Networks

AI Access Security
AUDIT1 source

AI Access Security discovers and categorizes GenAI applications, agents, marketplace plugins, usage, and users.

Product page

Zscaler

Zscaler AI Security
PREVENT1 source

Zscaler AI Security can warn, block, or isolate user access to AI applications under acceptable-use and data-protection policies.

Product page

Identity and Entitlement Control

Least-privilege and entitlement controls for AI components, services, and agent actions.

19 offerings

Amazon Web Services

Amazon Bedrock AgentCore
PREVENT1 source

Amazon Bedrock AgentCore gives agents distinct scoped identities and uses Cedar policy to authorize every tool call and data access independently of model reasoning.

Product page

Microsoft

Microsoft Foundry Agent Service
PREVENT1 source

Microsoft Foundry provisions distinct Entra agent identities and uses scoped access tokens and RBAC to authorize agent calls to MCP servers and downstream tools.

Product page

Okta

Okta for AI Agents
AUDITPOSTURE2 sources

Okta registers AI agents as first-class identities in Universal Directory with mandatory human owner binding and lifecycle governance.

Product page

Palo Alto Networks / Idira

Idira Secure AI Agents
PREVENT1 source

Idira Secure AI Agents acts as a dynamic agent identity broker that grants an agent access only for the duration of a specific task and automatically revokes permissions once the task completes.

Product page

Palo Alto Networks

Prisma AIRS
PREVENT1 source

Prisma AIRS governs agent tool calls, model access, and external connections through centralized policy and assigns each agent a governed identity with precise permissions and traceability.

Product page

Ping Identity Corporation

PingOne Agent IAM Core
AUDITPOSTURE1 source

PingOne Agent IAM Core registers AI agents as managed non-human identities with unique IDs, human ownership attribution, and dynamic scoping.

Product page

SailPoint Technologies, Inc.

SailPoint Machine Identity Security
PREVENTAUDIT1 source

SailPoint Machine Identity Security governs the lifecycle of service accounts, API keys, OAuth tokens, and RPA bots through automated access certifications and cryptographic verification.

Product page

Tenable Holdings, Inc.

Tenable One AI Exposure
POSTURE2 sources

Tenable One AI Exposure surfaces identity and entitlement risk for AI workloads, including over-permissioned access paths that can increase autonomous abuse risk.

Product page

Data and Privacy

Controls that reduce leakage, overexposure, and misuse of sensitive data in AI workflows.

2 capabilities

Prompt and Response DLP

Data loss prevention and content controls for prompt and response channels.

26 offerings

Amazon Web Services

Amazon Bedrock Guardrails
PREVENT1 source

Amazon Bedrock Guardrails includes sensitive-information policy controls to reduce protected-data leakage in prompt and response flows.

Product page

Cyera

Cyera AI Guardian
PREVENT1 source

Cyera AI Guardian evaluates data-exposure risk and enforces policies to reduce sensitive-data exposure to AI systems.

Product page

Dynamo AI

DynamoGuard
PREVENTDETECT1 source

DynamoGuard performs low-latency runtime inspection of prompts and model completions to detect and block prompt injection, jailbreaks, PII leakage, and toxic content.

Product page

Enkrypt AI

Sift
PREVENTDETECT1 source

Sift intercepts API traffic to foundation models to detect and block prompt injection, jailbreaking, PII leakage, and toxic outputs at the gateway boundary.

Product page

F5, Inc.

F5 AI Guardrails
PREVENT1 source

F5 AI Guardrails inspects prompts and responses to redact or block sensitive data and reduce leakage to external AI systems.

Product page

Google / Google Cloud

Model Armor
DETECTPREVENT1 source

Model Armor can inspect, transform, tokenize, and redact sensitive elements in AI prompts and responses through Sensitive Data Protection integration.

Product page

Google / Google Cloud

Sensitive Data Protection
DETECTPREVENT1 source

Sensitive Data Protection classifies and de-identifies sensitive content used for model training, tuning, and generative AI prompts and responses.

Product page

Harmonic Security

Harmonic Security Platform
PREVENTDETECT1 source

Harmonic Security inspects user prompts in real time to detect sensitive enterprise information (PII, source code, financial data) and enforces redaction or blocking policies prior to transmission to external LLMs.

Product page

Microsoft

Microsoft Purview for AI
PREVENT1 source

Microsoft Purview for AI applies DLP and sensitivity controls to reduce unauthorized sensitive data transfer in AI interactions.

Product page

Mirror Security

Mirror Security Suite
PREVENT1 source

Mirror Security keeps prompts, context, and responses encrypted through inference workflows while enforcing decision-time policies.

Product page

Palo Alto Networks

AI Access Security
DETECTPREVENT1 source

AI Access Security classifies sensitive content inline and blocks sensitive text and file transfers to GenAI applications.

Product page

Palo Alto Networks / Protect AI

LLM Guard
PREVENTDETECT1 source

LLM Guard inspects, sanitizes, and evaluates LLM prompts and model completions against prompt injection, jailbreaks, and sensitive data leakage.

Product page

Palo Alto Networks / Portkey

Portkey
PREVENT1 source

Portkey automatically redacts sensitive data from requests before sending them to an LLM.

Product page

Palo Alto Networks

Prisma AIRS
PREVENT1 source

Prisma AIRS applies real-time safeguards to AI prompts, responses, model interactions, agent actions, and data exposure paths.

Product page

SentinelOne, Inc. / Prompt Security

Prompt Security
PREVENT1 source

Prompt Security prompt and content controls redact sensitive enterprise data before it is sent to external models.

Product page

TrendAI

TrendAI Vision One AI Security
POSTUREPREVENT1 source

TrendAI combines AI Scanner pre-deployment testing with AI Guard runtime controls to detect vulnerabilities and reduce sensitive data leakage in AI applications.

Product page

Zscaler

Zscaler AI Security
PREVENT1 source

Zscaler AI Security applies data security and content policies to prevent risky AI outputs and govern response safety.

Product page

Zscaler

Zscaler Data Security
DETECTPREVENT1 source

Zscaler Data Security inspects AI usage and prompts and can block risky access or enforce prompt DLP to prevent data loss.

Product page

Sensitive Data Discovery

Data discovery and classification for AI training, inference, and retrieval sources.

6 offerings

Google / Google Cloud

Sensitive Data Protection
DETECTPREVENT1 source

Sensitive Data Protection continuously discovers and classifies sensitive data across organizational data assets.

Sensitive Data Protection classifies and de-identifies sensitive content used for model training, tuning, and generative AI prompts and responses.

Product page

Harmonic Security

Harmonic Security Platform
PREVENTDETECT1 source

Harmonic Security inspects user prompts in real time to detect sensitive enterprise information (PII, source code, financial data) and enforces redaction or blocking policies prior to transmission to external LLMs.

Product page

Microsoft

Microsoft Purview for AI
PREVENT1 source

Microsoft Purview for AI applies DLP and sensitivity controls to reduce unauthorized sensitive data transfer in AI interactions.

Product page

Zscaler

Zscaler Data Security
DETECT1 source

Zscaler Data Security discovers and classifies sensitive data and uses contextual classification to identify data risk across GenAI and other channels.

Product page

Posture and Risk

Asset inventory, posture assessment, and risk prioritization across AI systems.

3 capabilities

AI Posture Management

Configuration, exposure, and control-gap assessment for AI models, data, and pipelines.

21 offerings

Google / Google Cloud

Security Command Center
POSTURE1 source

Security Command Center assesses interconnected AI risks and prioritizes high-risk issues using posture analysis and virtual red teaming.

Product page

Harmonic Security

Harmonic Security Platform
AUDITPOSTURE1 source

Harmonic Security discovers and catalogs enterprise generative AI application usage (Shadow AI), categorizing application risk posture and data compliance across cloud and endpoint environments.

Product page

Microsoft

Microsoft Agent 365
POSTURE2 sources

Microsoft Agent 365 powers a centralized inventory and posture view of Microsoft and supported non-Microsoft agents, including identities, tools, MCP servers, risk indicators, alerts, and recommendations.

Product page

NEO

Neo Security Platform
POSTURE1 source

Neo Security Platform analyzes security gaps across agentic and non-agentic software to surface exposure conditions that require remediation.

Product page

Palo Alto Networks

Prisma AIRS
POSTURE1 source

Prisma AIRS provides posture visibility and policy management for AI assets, training and inference data, application integrity, and model access.

Product page

Ping Identity Corporation

PingOne Agent Governance
POSTURE2 sources

PingOne Agent Governance discovers and catalogs AI agents across cloud platforms and MCP servers to eliminate shadow agent sprawl.

Product page

Tenable Holdings, Inc.

Tenable One AI Exposure
POSTURE2 sources

Tenable One AI Exposure analyzes AI posture and misconfiguration conditions to prioritize exposure reduction for AI workloads.

Product page

Zscaler

Zscaler Data Security
POSTURE1 source

Zscaler Data Security provides data posture controls for GenAI and adjacent channels by combining contextual classification with risk identification.

Product page

AI Asset Discovery

Discovery of AI models, datasets, endpoints, and agent components in use.

31 offerings

Cato Networks

Cato AI Security (AISEC)
DETECT1 source

Cato AI Security governs sanctioned and unsanctioned enterprise AI usage through interaction-level visibility and policy enforcement.

Product page

Google / Google Cloud

Security Command Center
AUDIT1 source

Security Command Center discovers and inventories AI assets across agents, data, models, applications, platforms, and infrastructure.

Product page

Harmonic Security

Harmonic Security Platform
AUDITPOSTURE1 source

Harmonic Security discovers and catalogs enterprise generative AI application usage (Shadow AI), categorizing application risk posture and data compliance across cloud and endpoint environments.

Product page

Microsoft

Microsoft Agent 365
POSTURE2 sources

Microsoft Agent 365 powers a centralized inventory and posture view of Microsoft and supported non-Microsoft agents, including identities, tools, MCP servers, risk indicators, alerts, and recommendations.

Product page

NEO

Neo Security Platform
DETECT1 source

Neo Security Platform provides visibility into risky misconfigurations and permission issues across enterprise software environments.

Product page

Palo Alto Networks / Idira

Idira Secure AI Agents
POSTURE1 source

Idira Secure AI Agents scans SaaS, cloud, and developer environments to discover active AI agents and enriches each one with ownership, purpose, status, and permission-level context in a centralized registry.

Product page

Palo Alto Networks / Koi Security

Koi Agentic Endpoint Security
AUDIT1 source

Koi AES discovers and catalogs autonomous software agents, AI agents, browser extensions, software, and AI models on enterprise endpoints.

Product page

Palo Alto Networks

Prisma AIRS
AUDIT1 source

Prisma AIRS maps enterprise, endpoint, and browser agents and surfaces MCP servers, plugins, tool interactions, shadow AI, and unsanctioned agents.

Product page

Ping Identity Corporation

PingOne Agent Governance
POSTURE2 sources

PingOne Agent Governance discovers and catalogs AI agents across cloud platforms and MCP servers to eliminate shadow agent sprawl.

Product page

SentinelOne, Inc. / Prompt Security

Prompt Security
DETECT1 source

Prompt Security provides enterprise visibility over GenAI usage patterns and interaction channels.

Product page

Tenable Holdings, Inc.

Tenable One AI Exposure
DETECT2 sources

Tenable One AI Exposure provides continuous discovery of AI assets and attack-surface context across software and infrastructure environments.

Product page

Risk Prioritization

Risk scoring and triage for AI findings using context from identity, runtime, and data.

6 offerings

Google / Google Cloud

Security Command Center
POSTURE1 source

Security Command Center assesses interconnected AI risks and prioritizes high-risk issues using posture analysis and virtual red teaming.

Product page

Tenable Holdings, Inc.

Tenable One AI Exposure
POSTURE2 sources

Tenable One AI Exposure analyzes AI posture and misconfiguration conditions to prioritize exposure reduction for AI workloads.

Product page

Supply Chain and Integrity

Controls for dependency trust, provenance, and AI software supply chain resilience.

3 capabilities

AI-BOM and SBOM Visibility

Inventory and transparency for model, package, and software dependencies in AI systems.

5 offerings

Dependency Integrity

Provenance, signing, and integrity controls for artifacts used in AI build and deployment pipelines.

3 offerings

Palo Alto Networks / Protect AI

ModelScan
POSTUREAUDIT1 source

ModelScan statically analyzes serialized ML model files (PyTorch, Pickle, SavedModel, Keras) to detect embedded code execution exploits and malicious payload injections.

Product page

Model and Tooling Supply Chain Risk

Detection and governance of risky model artifacts, plugins, and AI development tooling.

6 offerings

Chainguard

Chainguard Secure AI SDLC
PREVENT1 source

Chainguard AI Security documents software supply chain coverage across SDLC phases, including trusted dependencies, CI/CD integrity, and hardened runtime foundations.

Product page

Palo Alto Networks

Prisma AIRS
DETECT2 sources

Prisma AIRS scans third-party models for tampering, malicious scripts, and deserialization risks.

Prisma AIRS scans agent code, MCP servers, and skills for unsafe permissions, hidden vulnerabilities, and indirect injection paths.

Product page

Model and Validation

Model-specific assurance activities such as testing, adversarial analysis, and hardening.

1 capability

Model Security Testing

Adversarial testing and validation of model behavior prior to deployment.

29 offerings

Arthur

Arthur Platform
AUDIT1 source

Arthur Platform performs pre-production and runtime evaluations to monitor AI behavior and policy outcomes.

Product page

Check Point Software Technologies / Lakera

Lakera Red
AUDIT1 source

Lakera Red Teaming is positioned as risk-based AI testing with direct and indirect attack simulations and remediation-focused workflows.

Product page

Dynamo AI

DynamoEval
POSTUREAUDIT1 source

DynamoEval executes automated adversarial attacks, security benchmark evaluations, and regulatory compliance stress-tests on models prior to production release.

Product page

Enkrypt AI

Enkrypt Red Team
POSTURE1 source

Enkrypt Red Team conducts automated adversarial evaluations against model endpoints across known prompt injection and compliance vulnerability categories.

Product page

F5, Inc.

F5 AI Guardrails
PREVENT1 source

F5 AI Guardrails enforces policies to detect and prevent jailbreak-style attempts that seek to bypass model safety boundaries.

Product page

Mirror Security

Mirror Security Suite
POSTUREAUDIT2 sources

Mirror DiscoveR continuously runs automated red teaming to uncover AI vulnerabilities and validate security controls.

Product page

NVIDIA Corporation

garak
POSTURE1 source

garak probes language-model endpoints across attack classes including jailbreaks, prompt injection, and data leakage to identify model security weaknesses.

Product page

OpenAI

OpenAI Frontier Security Evaluation
AUDITPOSTURE1 source

OpenAI Frontier integrates automated security testing and red teaming to evaluate AI coworkers for prompt injections, jailbreaks, data leaks, tool misuse, and out-of-policy behaviors.

Product page

OpenAI / Promptfoo

Promptfoo Core
POSTUREAUDIT2 sources

Promptfoo executes automated adversarial test fixtures and benchmark assertions against LLM endpoints to evaluate resistance to prompt injection, toxicity, and system prompt extraction.

Product page

OpenAI / Promptfoo

Promptfoo Enterprise
POSTURE1 source

Promptfoo simulates multi-turn adaptive attacks, autonomous agent goal hijacking, tool execution vulnerabilities, and unauthorized function calls in pre-deployment CI/CD environments.

Product page

Palo Alto Networks / Protect AI

ModelScan
POSTUREAUDIT1 source

ModelScan statically analyzes serialized ML model files (PyTorch, Pickle, SavedModel, Keras) to detect embedded code execution exploits and malicious payload injections.

Product page

Palo Alto Networks

Prisma AIRS
POSTURE1 source

Prisma AIRS simulates real-world attacks against single-agent and multi-agent AI systems to identify weaknesses before production.

Product page

TrendAI

TrendAI Vision One AI Security
POSTUREPREVENT1 source

TrendAI combines AI Scanner pre-deployment testing with AI Guard runtime controls to detect vulnerabilities and reduce sensitive data leakage in AI applications.

Product page

Zero Day Investigative Network

0DIN AI Security Scanner
POSTURE2 sources

0DIN AI Security Scanner evaluates LLM and GenAI application behavior against exploit and jailbreak test suites.

Product page