{
  "schema_version": 2,
  "generated": "2026-09-15T17:12:43.802Z",
  "count": 260,
  "products": [
    {
      "slug": "1password-unified-access",
      "schema_version": 2,
      "name": "1Password Unified Access",
      "vendor": "1Password",
      "url": "https://1password.com/product/unified-access",
      "primary_asset": "ai-agent-identities",
      "description": "1Password Unified Access: Discovers AI tools, agents, and exposed credentials across endpoints, then vaults and governs the secrets that human, agent, and machine identities use.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001",
        "ISO 27017",
        "ISO 27018",
        "ISO 27701"
      ],
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Discovers shadow AI usage, local agents, and exposed credentials such as unencrypted SSH keys and plaintext .env files across endpoints and browsers, maps AI usage to users and devices, and vaults and governs human, agent, and machine credentials under shared policy controls.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "adrian",
      "schema_version": 2,
      "name": "Adrian",
      "vendor": "Secure Agentics",
      "url": "https://secureagentics.ai/",
      "primary_asset": "ai-orchestration-tools",
      "description": "Adrian: Open-source runtime security for AI agents by Secure Agentics that monitors agent actions and reasoning traces, detects malicious or out-of-remit behavior, and pauses or blocks actions.",
      "deployment": [
        "self-hosted",
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Monitors agent actions and chain-of-thought reasoning traces at runtime, detects malicious, misaligned, or out-of-remit actions classified by severity, and can pause or block specific actions before execution with optional human-in-the-loop approval.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "advai-platform",
      "schema_version": 2,
      "name": "Advai Platform",
      "vendor": "Advai",
      "url": "https://www.advai.com/platform",
      "primary_asset": "ai-model",
      "description": "Advai Platform: Independent AI testing and monitoring that benchmarks candidate models, runs adversarial tests to set go-live thresholds, and watches deployed systems for drift and policy breaches.",
      "deployment": [
        "unknown"
      ],
      "status": "active",
      "compliance_attestations": [
        "ISO 27001",
        "Cyber Essentials Plus"
      ],
      "last_reviewed": "2026-08-20",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent",
        "compliance_attestations": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "detect",
            "govern"
          ],
          "maturity": "primary",
          "note": "Adversarial and red-team testing of models before deployment, producing go-live thresholds and an evidence pack for sign-off. Model Arena benchmarks candidate models and configurations under the customer policy, latency, and cost constraints, yielding selection evidence for approvals.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Continuous post-deployment monitoring that assesses AI system logs for performance, risk, and security indicators, raising alerts on policy breaches, data leakage risk, drift, and unexpected cost or tool use.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Tests agentic systems for multi-step behaviour, tool misuse, and unsafe execution paths before go-live, then monitors tool use and escalation signals once the agents are running.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "adversa-ai",
      "schema_version": 2,
      "name": "Adversa AI",
      "vendor": "Adversa AI",
      "url": "https://adversa.ai/ai-red-teaming-agentic-ai/",
      "primary_asset": "ai-orchestration-tools",
      "description": "Adversa AI: Continuous AI red teaming platform for custom AI agents that tests for vulnerability classes across agents, models, and MCP, re-scanning on every model, prompt, or tool update.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "detect"
          ],
          "maturity": "primary",
          "note": "Continuous red teaming engineered for proprietary AI agents, covering more than 60 vulnerability classes across the agent, model, and MCP layers, with re-scans triggered by every model, prompt, or tool update and remediation playbooks in real time.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Autonomous red teaming campaigns cover the OWASP LLM and agentic AI Top 10 lists and run on every model update and prompt change.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "aembit",
      "schema_version": 2,
      "name": "Aembit",
      "vendor": "Aembit",
      "url": "https://aembit.io/iam-for-agentic-ai/",
      "primary_asset": "ai-agent-identities",
      "description": "Identity and access management for AI agents that issues OAuth 2.1 tokens, enforces policy on every MCP request, and brokers credentials so agents reach MCP servers and resources without secrets.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Issues OAuth 2.1 tokens to AI agents, enforces access policy on every MCP request, and brokers credentials so agents never hold them, with visibility into every access attempt.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Gates and brokers agent access to custom and third-party MCP servers and the enterprise systems behind them.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "agent-governance-toolkit",
      "schema_version": 2,
      "name": "Agent Governance Toolkit",
      "vendor": "Microsoft",
      "url": "https://github.com/microsoft/agent-governance-toolkit",
      "primary_asset": "ai-orchestration-tools",
      "description": "Agent Governance Toolkit: Open-source Microsoft project enforcing runtime policy on autonomous agent actions, with zero-trust agent identity, MCP gateway checks, and tamper-evident audit logs.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-04",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect",
            "respond"
          ],
          "maturity": "primary",
          "note": "The policy engine evaluates every governed agent tool call against YAML, OPA, or Cedar rules with fail-closed deny and approval workflows; the MCP Security Gateway detects tool poisoning, drift, and hidden instructions, with privilege rings, a kill switch, and Merkle audit logs.",
          "origin": "agent"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "The AgentMesh identity layer issues agent credentials over SPIFFE, DID, and mTLS with trust scoring and delegation chains, and Shadow AI Discovery locates unregistered agents across processes, configs, and repositories.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect"
          ],
          "maturity": "adjacent",
          "note": "The PromptDefense evaluator and the agt red-team scan command audit prompt files for injection across twelve vectors as an offline check rather than an inline guardrail.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "ai-infra-guard",
      "schema_version": 2,
      "name": "AI-Infra-Guard",
      "vendor": "Tencent",
      "url": "https://github.com/Tencent/AI-Infra-Guard",
      "primary_asset": "ai-orchestration-tools",
      "description": "AI-Infra-Guard: Open-source AI red-team scanner by Tencent that scans MCP servers, agent skills, and AI-infra components for CVEs and evaluates models for jailbreak robustness.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-05",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "primary",
          "note": "Scans MCP servers, agent skills, and agent workflows for security risks and identifies AI-framework CVEs across more than 100 components such as Ollama, vLLM, and Triton.",
          "origin": "agent"
        },
        {
          "asset": "ai-model",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Jailbreak evaluation tests model prompt-security robustness with multiple attack methods and cross-model comparison.",
          "origin": "agent"
        },
        {
          "asset": "ai-workload-platforms",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Fingerprints AI-serving frameworks such as Ollama, vLLM, and Triton and flags known CVE vulnerabilities across more than 100 components.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "aiceberg-guardian-agent",
      "schema_version": 2,
      "name": "Aiceberg Guardian Agent",
      "vendor": "Aiceberg",
      "url": "https://www.aiceberg.ai/",
      "primary_asset": "runtime-ai-data",
      "description": "Aiceberg Guardian Agent: Agentic AI security platform that examines prompts, responses, and agent activity in real time, blocking or redacting policy violations with explainable ML risk signals.",
      "deployment": [
        "saas"
      ],
      "status": "acquired",
      "compliance_attestations": null,
      "acquirer": "Cranium AI",
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "The Guardian Agent examines prompts and LLM responses in real time and blocks, redacts, or passes them per configured Profile policies (Listen and Enforce modes), with ML-based safety and security signals covering prompt injection and sensitive-information exposure.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Monitors agentic AI decisions and actions, including information an agent pulls via RAG, tool use, and memory, with explainable and traceable risk detection across connected AI systems.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "aim-security",
      "schema_version": 2,
      "name": "Aim Security",
      "vendor": "Aim Security",
      "url": "https://www.catonetworks.com/platform/ai-security-for-applications/",
      "primary_asset": "runtime-ai-data",
      "description": "Aim Security: AI security platform that secures employee use of public AI applications, shields private AI apps and agents with an AI firewall, and covers the AI development lifecycle with AI-SPM.",
      "deployment": [
        "saas"
      ],
      "status": "acquired",
      "compliance_attestations": null,
      "acquirer": "Cato Networks",
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovers shadow AI usage and monitors and protects end-user interactions with public AI applications and agents, while the Aim AI Firewall secures internal AI applications and agents against runtime attacks and enforces policy on interactions between users, agents, and models.",
          "origin": "agent"
        },
        {
          "asset": "ai-model",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "AI security posture management covers the AI development lifecycle, from training ML models to building custom AI agents, with continuous discovery.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "aishield",
      "schema_version": 2,
      "name": "AIShield",
      "vendor": "Bosch",
      "url": "https://www.boschaishield.com/",
      "primary_asset": "ai-model",
      "description": "AIShield: Bosch product line pairing AISpectra model vulnerability scanning and red teaming with Guardian runtime guardrails and an ML firewall for GenAI and ML apps.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "detect",
            "protect"
          ],
          "maturity": "primary",
          "note": "AISpectra discovers models and notebooks across cloud platforms and CI/CD pipelines and runs vulnerability assessments and red teaming against ML models and LLMs; Guardian ML Firewall shields deployed models from extraction, evasion, and poisoning attempts with real-time intrusion detection.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Guardian GenAI Guardrails screen LLM inputs and outputs in real time, mitigating prompt injection, jailbreaks, and sensitive data exposure with content filtering and PII anonymization.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "akamai-firewall-for-ai",
      "schema_version": 2,
      "name": "Akamai Firewall for AI",
      "vendor": "Akamai",
      "url": "https://www.akamai.com/products/firewall-for-ai",
      "primary_asset": "runtime-ai-data",
      "description": "Akamai Firewall for AI: Inspects LLM prompts and responses at the edge or via API, blocking prompt injection, toxic output, and sensitive data exposure.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Applies guardrails to both inputs and outputs, detecting and blocking prompt injection, jailbreaks, and harmful queries in real time while filtering model responses for toxic content and sensitive data leakage.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Detects and blocks unauthorized queries and large-scale data scraping attempts that aim to extract proprietary model knowledge, mitigating model theft and data exfiltration.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "akeyless",
      "schema_version": 2,
      "name": "Akeyless",
      "vendor": "Akeyless",
      "url": "https://www.akeyless.io",
      "primary_asset": "ai-agent-identities",
      "description": "Identity security platform for machines and AI agents that issues just-in-time, vaultless secrets and certificates so agents authenticate without hardcoded credentials and act under runtime control.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001",
        "FIPS 140-3",
        "PCI DSS"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Secures AI agents as non-human identities with vaultless, just-in-time secrets and certificates, removing hardcoded credentials and tracking agent access at runtime.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "akto",
      "schema_version": 2,
      "name": "Akto",
      "vendor": "Akto",
      "url": "https://www.akto.io/ai-security",
      "primary_asset": "runtime-ai-data",
      "description": "Akto: AI security platform for LLMs, agents, and MCPs that discovers AI agents and APIs, red-teams them, and detects and blocks prompt injection, data leakage, and real-time agent abuse.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-14",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect",
            "protect"
          ],
          "maturity": "primary",
          "note": "Detects and prevents prompt injection, data leakage, and unsafe AI interactions across LLMs, agents, and GenAI applications.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Auto-discovers AI agents including shadow ones, classifies their behaviors and PII exposure, and detects and stops agent loops and unauthorized tool calls.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Red-teams agent and MCP integrations with thousands of probes for injection, escalation, data leakage, and tool misuse, runnable in CI/CD.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "alation",
      "schema_version": 2,
      "name": "Alation",
      "vendor": "Alation",
      "url": "https://www.alation.com/solutions/artificial-intelligence/",
      "primary_asset": "ai-model",
      "description": "Data intelligence platform that inventories AI models, agents, and tools, traces their data lineage, and curates trusted, compliant data for AI development.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify"
          ],
          "maturity": "primary",
          "note": "Documents and inventories AI models with model cards, end-to-end AI lineage, and compliance evidence for auditability.",
          "origin": "reviewed"
        },
        {
          "asset": "training-data",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "Discovers, tags, and quality-flags the data feeding AI models so teams can validate it before training.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "alice",
      "schema_version": 2,
      "name": "Alice",
      "vendor": "Alice",
      "url": "https://alice.io/",
      "primary_asset": "runtime-ai-data",
      "description": "Alice: Enterprise AI security suite that red-teams customer-facing AI apps and agents before launch, enforces runtime guardrails on their inputs and outputs, and re-tests them continuously.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-03",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "WonderFence inspects every prompt and response inline, blocking harmful inputs and outputs in real time and monitoring which detections triggered across agents and applications.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "WonderBuild red-teams customer-facing AI models, apps, and agents before launch to surface prompt injection, jailbreaking, and data-poisoning weaknesses.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "anjuna-seaglass",
      "schema_version": 2,
      "name": "Anjuna Seaglass",
      "vendor": "Anjuna Security",
      "url": "https://www.anjuna.io/solution/secure-ai",
      "primary_asset": "ai-workload-platforms",
      "description": "Anjuna Seaglass: Confidential-computing platform that runs AI models, training, and agent workloads inside hardware trusted execution environments, keeping them encrypted while in use.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-08-17",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Runs proprietary models and the code around them inside hardware trusted execution environments, so model weights stay confidential and integrity-protected against the host, privileged administrators, and infrastructure operators.",
          "origin": "agent"
        },
        {
          "asset": "ai-workload-platforms",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Packages AI workloads as confidential containers that run on Kubernetes, in major clouds, or on-premises with always-on in-use encryption and policy-based cryptographic attestation before secrets are released.",
          "origin": "agent"
        },
        {
          "asset": "training-data",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Processes training datasets inside the trusted execution environment and in confidential clean rooms, so fine-tuning and model training run on data that is never exposed in the clear to the operator or to collaborating parties.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Isolates agent runtimes and MCP servers in trusted execution environments so only attested code executes, with agent credentials and working data kept encrypted from the underlying cloud operator.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Runs AI workloads under always-on encryption inside the enclave, so inference inputs and working data stay encrypted in memory while the model is serving and remain unreadable to the host and its operators.",
          "origin": "agent"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Gives each agent workload a hardware-rooted attested identity and releases secrets and credentials to it only after attestation succeeds, so an agent proves what it is before it can reach data or tools.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "apiiro-guardian-agent",
      "schema_version": 2,
      "name": "Apiiro Guardian Agent",
      "vendor": "Apiiro",
      "url": "https://apiiro.com/blog/apiiro-guardian-agent/",
      "primary_asset": "ai-generated-code",
      "description": "Apiiro Guardian Agent: AI AppSec agent that grounds AI coding agents in the app architecture and generates AI threat models to prevent vulnerable or non-compliant code before it is written.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-14",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-generated-code",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Grounds AI coding agents in the application architecture, generates architecture-aware AI threat models, enriches coding prompts to prevent vulnerable or non-compliant AI-generated code, and detects drift between design intent and code.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "aqua-secure-ai",
      "schema_version": 2,
      "name": "Aqua Secure AI",
      "vendor": "Aqua Security",
      "url": "https://www.aquasec.com/solutions/ai-application-security/",
      "primary_asset": "ai-workload-platforms",
      "description": "Aqua Secure AI: Lifecycle protection for AI apps in the Aqua Platform, spanning code scanning, AI service posture checks, runtime threat detection, and prompt defense for cloud native workloads.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-workload-platforms",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Runtime detection and response for AI threats identifies unsafe AI usage, detects suspicious activity, and stops malicious activity in cloud native AI workloads without code changes; AI-SPM configuration checks assess the posture of cloud-based AI services.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Prompt-level runtime protection detects prompt injection, jailbreaks, and risky model behavior, enforcing policy in real time and blocking post-compromise activity without additional agents, code changes, or SDKs.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "Discovers which AI models, platforms, and versions are running, where they are used, and whether usage aligns with policy, monitoring in real time at the application layer across SaaS, managed, and self-hosted AI workloads.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "archestra",
      "schema_version": 2,
      "name": "Archestra",
      "vendor": "Archestra",
      "url": "https://archestra.ai/",
      "primary_asset": "ai-orchestration-tools",
      "description": "Archestra: Open-source, self-hosted AI platform that runs MCP servers in isolated Kubernetes containers behind an approval-flow catalog, with deterministic anti-exfiltration guardrails at the proxy.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "agent",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Runs MCP servers in isolated Kubernetes containers with audit trails, applies deterministic guardrails against data exfiltration and prompt injection, and inventories approved servers in a private registry.",
          "origin": "agent"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Enforces per-team and per-user access to MCP servers and LLMs through RBAC, SSO, and OAuth on-behalf-of user-delegated access.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "arize",
      "schema_version": 2,
      "name": "Arize",
      "vendor": "Arize AI",
      "url": "https://arize.com",
      "primary_asset": "runtime-ai-data",
      "description": "AI observability and evaluation platform with run-time guardrails that screen LLM inputs and outputs, blocking jailbreaks, prompt injection, and PII while flagging hallucinated or unsafe responses.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2",
        "ISO 27001",
        "HIPAA",
        "PCI DSS",
        "GDPR"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Run-time guardrails screen LLM inputs and outputs, blocking jailbreaks, prompt injection, and PII and correcting toxic or hallucinated responses.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Evaluations score LLM and agent application outputs in production to flag hallucinations, low quality, and unsafe responses.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "arnica",
      "schema_version": 2,
      "name": "Arnica",
      "vendor": "Arnica",
      "url": "https://www.arnica.io/",
      "primary_asset": "ai-generated-code",
      "description": "Arnica: Application-security product whose Arnie AI enforces version-controlled secure-coding rules inside AI coding agents at generation and scans AI-generated code with an AI-augmented SAST engine.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001"
      ],
      "last_reviewed": "2026-06-15",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-generated-code",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Arnie AI enforces version-controlled secure-coding rules inside AI coding agents (Copilot, Cursor, Claude Code) to prevent insecure code at generation, and its AI SAST engine scans AI-generated code to detect vulnerabilities across repositories and branches.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "arthur",
      "schema_version": 2,
      "name": "Arthur",
      "vendor": "Arthur AI",
      "url": "https://www.arthur.ai/",
      "primary_asset": "runtime-ai-data",
      "description": "AI lifecycle platform with built-in guardrails that screen AI interactions for misuse, off-brand content, and unsafe prompts and responses, plus monitoring for models and agents.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Built-in guardrails screen AI interactions to protect applications against misuse, off-brand content, and unsafe prompts and responses.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Monitors models and agent applications across the AI lifecycle, surfacing performance and reliability issues.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "asenion",
      "schema_version": 2,
      "name": "Asenion",
      "vendor": "Asenion",
      "url": "https://asenion.ai",
      "primary_asset": "ai-model",
      "description": "Asenion: AI trust, risk, and security management platform that continuously assesses, tests, and governs AI models and agents against the EU AI Act, ISO/IEC 42001, and NIST AI RMF.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "govern"
          ],
          "maturity": "primary",
          "note": "Continuously assesses and governs AI models for risk and regulatory compliance across the lifecycle, with automated controls mapped to the EU AI Act, ISO/IEC 42001, and NIST AI RMF.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "govern"
          ],
          "maturity": "secondary",
          "note": "Extends the same assessment and governance controls to AI systems and agents at the application and orchestration layer.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "astrasync",
      "schema_version": 2,
      "name": "AstraSync",
      "vendor": "AstraSync",
      "url": "https://astrasync.ai/",
      "primary_asset": "ai-agent-identities",
      "description": "AstraSync: Know Your Agent platform that registers AI agents as verifiable identities with cryptographic credentials and permission boundaries, plus continuously updated trust scores for verification.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-14",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify"
          ],
          "maturity": "primary",
          "note": "Registers AI agents as verifiable identities with cryptographic credentials and permission boundaries, and maintains continuously updated trust scores so counterparties can verify an agent before and during deployment.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "astrix",
      "schema_version": 2,
      "name": "Astrix",
      "vendor": "Astrix Security",
      "url": "https://astrix.security",
      "primary_asset": "ai-agent-identities",
      "description": "Identity security platform that discovers, secures, and governs AI agents and non-human identities, with posture management and non-human ITDR.",
      "deployment": [
        "saas"
      ],
      "status": "acquired",
      "compliance_attestations": null,
      "acquirer": "Cisco",
      "last_reviewed": "2026-07-17",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect",
            "detect",
            "respond"
          ],
          "maturity": "primary",
          "note": "Agentless discovery and inventory of agents and non-human identities, posture and lifecycle management, and non-human ITDR for detection and response.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Discovers and monitors secrets and credentials inside and outside vaults that agents and non-human identities use at runtime.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "aurascape",
      "schema_version": 2,
      "name": "Aurascape",
      "vendor": "Aurascape",
      "url": "https://aurascape.ai/",
      "primary_asset": "runtime-ai-data",
      "description": "Aurascape: AI security platform that discovers AI apps and agents, inspects prompts and responses inline, and applies data protection and threat prevention policies to enterprise AI activity.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Inspects full prompts and responses inline, classifies and fingerprints sensitive data in real time, and blocks risky activity. Detects phishing, social engineering, and malicious code generation in AI responses before they reach users.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "secondary",
          "note": "Discovers sanctioned and unsanctioned AI apps, copilots, and agents with risk scoring. Maps MCP servers and tool connections, tests agents for prompt injection and data leakage before production, and enforces runtime guardrails and MCP gateway controls on tool use.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "auth0-for-ai-agents",
      "schema_version": 2,
      "name": "Auth0 for AI Agents",
      "vendor": "Okta",
      "url": "https://auth0.com/ai",
      "primary_asset": "ai-agent-identities",
      "description": "Auth0 for AI Agents: Identity and access for AI agents, with dedicated agent identities, a Token Vault for third-party API tokens, async user authorization, and fine-grained authorization for RAG.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001",
        "CSA STAR Level 2"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Gives AI agents dedicated identities and brokered access. A Token Vault stores and refreshes third-party API tokens, asynchronous authorization gets user approval for agent actions, and fine-grained authorization (Auth0 FGA) limits what RAG retrieval can reach.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "autonomous-security",
      "schema_version": 2,
      "name": "Autonomous Security",
      "vendor": "Autonomous Security",
      "url": "https://a16y.ai/",
      "primary_asset": "ai-orchestration-tools",
      "description": "Autonomous Security: Endpoint security platform for AI agents that discovers shadow AI across workstations, assesses risk and credential exposure, and enforces real-time guardrails and policies.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "agent",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovers installed agents and MCP servers across workstations, hosts MCP servers in sandboxed cloud workspaces backed by a vetted pre-scanned catalog, intercepts MCP traffic to block prompt injection and rogue MCP servers, and enforces centralized runtime policies with audit trails.",
          "origin": "agent"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "Exposure analysis surfaces exposed configurations and hardcoded secrets that AI agents accumulate on workstations, mapping the credential sprawl agentic activity creates.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "aws-bedrock-guardrails",
      "schema_version": 2,
      "name": "AWS Bedrock Guardrails",
      "vendor": "Amazon Web Services",
      "url": "https://aws.amazon.com/bedrock/guardrails/",
      "primary_asset": "runtime-ai-data",
      "description": "Configurable safety layer for generative AI applications that filters harmful content, detects prompt-injection attacks, redacts PII, blocks denied topics, and flags ungrounded responses.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "SOC 3",
        "ISO 27001",
        "PCI DSS",
        "FedRAMP"
      ],
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Inspects prompts and model responses to filter harmful content, prompt attacks, PII, and ungrounded output.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "axonius-asset-cloud",
      "schema_version": 2,
      "name": "Axonius Asset Cloud",
      "vendor": "Axonius",
      "url": "https://www.axonius.com/platform",
      "primary_asset": "ai-workload-platforms",
      "description": "Axonius Asset Cloud: Asset intelligence platform that brings AI tools into the asset inventory, pulling Claude Enterprise users, groups, and API keys in to surface shadow AI.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "ISO/IEC 27001:2022",
        "SOC 2",
        "HIPAA",
        "IRAP",
        "CSA STAR",
        "FedRAMP Certified Class C",
        "TX-RAMP Level 2"
      ],
      "last_reviewed": "2026-07-08",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent",
        "compliance_attestations": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-workload-platforms",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "Inventories AI tools as managed assets by pulling Claude Enterprise usage into the asset inventory and comparing installs against the managed user population to surface shadow AI.",
          "origin": "agent"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "Inventories Claude Enterprise API keys, users, roles, and groups, surfacing expired, inactive, or orphaned keys for lifecycle review.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "azure-ai-content-safety",
      "schema_version": 2,
      "name": "Azure AI Content Safety",
      "vendor": "Microsoft",
      "url": "https://azure.microsoft.com/en-us/products/ai-services/ai-content-safety",
      "primary_asset": "runtime-ai-data",
      "description": "Microsoft content-safety service for generative AI that uses Prompt Shields to detect and block jailbreaks and indirect prompt injection, and filters prompts and responses across harm categories.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001",
        "ISO 27017",
        "ISO 27018",
        "ISO 27701"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Prompt Shields detects and blocks user-prompt jailbreaks and indirect (cross-prompt) injection in prompts and grounding documents in real time, and content filters screen prompts and responses for harmful content.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "backslash-security",
      "schema_version": 2,
      "name": "Backslash Security",
      "vendor": "Backslash Security",
      "url": "https://www.backslash.security/",
      "primary_asset": "ai-generated-code",
      "description": "Backslash Security: Secures AI coding agents on developer workstations with MCP server vetting, vibe coding guardrails, and real-time monitoring of agentic activity.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-generated-code",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Centralized guardrails on developer workstations restrict unapproved models, private accounts, and unsafe configurations for AI coding agents, with real-time detection of prompt injection, data exfiltration, and anomalous agent behavior in vibe coding workflows.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Vets, allowlists, and monitors MCP servers at the tool level, blocking unsafe or malicious components; a visibility graph inventories agents, MCPs, skills, hooks, and plugins, and the public MCP Server Security Hub maintains a risk database covering tens of thousands of MCP servers.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "bifrost",
      "schema_version": 2,
      "name": "Bifrost",
      "vendor": "Maxim AI",
      "url": "https://www.getmaxim.ai/bifrost",
      "primary_asset": "ai-gateways-routers",
      "description": "Bifrost: Open-source AI gateway that unifies many LLM providers behind virtual keys with budgets, rate limits, and RBAC, plus enterprise guardrails screening prompts and responses in real time.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2",
        "ISO 27001",
        "HIPAA",
        "GDPR"
      ],
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent",
        "compliance_attestations": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Open-source gateway unifying access to 20+ model providers behind virtual keys that control access permissions, budgets, rate limits, and routing per consumer. The enterprise tier adds OIDC and SCIM provisioning, RBAC, audit logs, and clustering.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Enterprise guardrails validate prompts and responses in real time using CEL rules and provider profiles (native regex and secrets detection plus Presidio, Azure AI Language PII, AWS Bedrock, Azure Content Safety, Google Model Armor, CrowdStrike AIDR, GraySwan, and Patronus AI).",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "bigid",
      "schema_version": 2,
      "name": "BigID",
      "vendor": "BigID",
      "url": "https://bigid.com/",
      "primary_asset": "training-data",
      "description": "Enterprise data security platform that discovers and classifies sensitive data, finds shadow AI, secures the data pipeline for AI training, and governs AI access and risk.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2",
        "SOC 3",
        "CSA STAR Level 1",
        "PCI DSS"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "training-data",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Discovers and classifies sensitive data across many sources, finds shadow AI and unauthorized data use, and cleanses and secures the data pipeline that feeds AI training.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Governs employee AI access by labeling data, applying guardrails, intercepting risky prompts, and enforcing role-based access.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "AI security posture management assesses AI risk and flags model and agent vulnerabilities and unusual access.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "black-duck-signal",
      "schema_version": 2,
      "name": "Black Duck Signal",
      "vendor": "Black Duck",
      "url": "https://www.blackduck.com/signal-ai-appsec.html",
      "primary_asset": "ai-generated-code",
      "description": "Black Duck Signal: Agentic application security solution that detects and fixes flaws in AI-generated code via MCP integrations with coding assistants and pipelines.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-generated-code",
          "functions": [
            "detect",
            "protect"
          ],
          "maturity": "primary",
          "note": "Agentic scans run inside AI coding workflows via MCP for assistants such as Claude Code and GitHub Copilot, detecting security defects in new code and applying verified fixes before commit; exploitability analysis filters noise.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "bonfy-acs",
      "schema_version": 2,
      "name": "Bonfy ACS",
      "vendor": "Bonfy.AI",
      "url": "https://www.bonfy.ai/product",
      "primary_asset": "runtime-ai-data",
      "description": "Bonfy ACS: Inspects content moving through email, SaaS apps, Copilot, and AI agents, blocking or redacting sensitive data, with MCP server guardrails for agents and shadow AI detection.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Applies entity-aware analysis to data entering prompts, content leaving via email or AI outputs, and data agents process. Contextual Data Enforcement intercepts AI retrieval requests and blocks, redacts, or flags sensitive content before it reaches AI clients like Claude or Copilot Studio.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "detect",
            "protect"
          ],
          "maturity": "secondary",
          "note": "Ships an MCP server, API, and agent framework support that agents call during reasoning to evaluate content against policy, enabling workflows to revise, redact, block, or route output for review before data reaches external services.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-workload-platforms",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "A browser extension performs content-aware inspection of web interactions, detects unsanctioned AI usage, maps which AI destinations are in use and what data flows to them, and can warn users or block actions based on policy.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "britive",
      "schema_version": 2,
      "name": "Britive",
      "vendor": "Britive",
      "url": "https://www.britive.com/platform/agentic-ai-identity-security",
      "primary_asset": "ai-agent-identities",
      "description": "Britive: Extends cloud PAM to AI agent identities with just-in-time ephemeral credentials, zero standing privileges, and runtime on-behalf-of policy enforcement.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "CSA STAR Level 1"
      ],
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Issues ephemeral JIT credentials so agents hold zero standing privileges; an MCP tool broker evaluates each tool request at runtime and on-behalf-of policies tie agent actions back to human privilege boundaries; trust scoring and SIEM telemetry surface anomalous agent behavior.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "calypsoai",
      "schema_version": 2,
      "name": "CalypsoAI",
      "vendor": "F5",
      "url": "https://www.f5.com/products/ai-guardrails",
      "primary_asset": "runtime-ai-data",
      "description": "Inference-layer AI security pairing runtime guardrails against prompt injection, jailbreaks, and data leakage with red teaming at scale.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "acquired",
      "compliance_attestations": null,
      "acquirer": "F5",
      "last_reviewed": "2026-07-17",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Inline guardrails screen prompts and responses for prompt injection, jailbreaks, and sensitive data flows.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Red teaming hunts vulnerabilities across AI models, applications, and agents.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "capsule-security",
      "schema_version": 2,
      "name": "Capsule Security",
      "vendor": "Capsule Security",
      "url": "https://www.capsulesecurity.io/",
      "primary_asset": "ai-agent-identities",
      "description": "Capsule Security: Runtime security layer that discovers enterprise AI agents, observes their behavior, and blocks unsafe or risky actions before execution.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Agentless discovery inventories agents across home-grown systems plus SaaS and endpoint environments; Agent Identity Control tracks ownership and least privilege; Runtime Protection detects and blocks unsafe or risky agent behavior before actions execute.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect",
            "protect"
          ],
          "maturity": "primary",
          "note": "Watches agent reasoning and interactions at runtime to catch manipulation and stop data exfiltration; intervenes inline to correct anomalous or unsafe activity without disrupting the AI.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Secures agents built on platforms such as Copilot Studio and Salesforce Agentforce plus coding agents like Cursor; the Agent Security Graph maps relationships among agents, tools, and data to reveal risky paths and control gaps.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "cequence-ai-gateway",
      "schema_version": 2,
      "name": "Cequence AI Gateway",
      "vendor": "Cequence Security",
      "url": "https://www.cequence.ai/products/ai-gateway/",
      "primary_asset": "ai-gateways-routers",
      "description": "Cequence AI Gateway: Agentic-AI security layer that authenticates AI agents, exposes enterprise APIs as MCP tools, and enforces authorization and monitoring policy inline on every agent tool call.",
      "deployment": [
        "hybrid"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-03",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Enforces authorization policy inline on every agent tool call for the full session and provides real-time visibility into AI-API traffic with full audit logging.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Provides token lifecycle management and identity-based access for AI agents, preventing unauthorized agent access to systems and data.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "cerbos",
      "schema_version": 2,
      "name": "Cerbos",
      "vendor": "Cerbos",
      "url": "https://www.cerbos.dev/",
      "primary_asset": "ai-agent-identities",
      "description": "Cerbos: Authorization platform that enforces fine-grained, contextual, continuous access policies for AI agents and MCP servers, defining and revoking what each agent can access at runtime.",
      "deployment": [
        "self-hosted",
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-14",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Enforces fine-grained, contextual authorization for AI agents and MCP servers, defining what each agent can access before it goes live and revoking that access through policy at runtime.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "checkmarx",
      "schema_version": 2,
      "name": "Checkmarx",
      "vendor": "Checkmarx",
      "url": "https://checkmarx.com/product/checkmarx-one-assist/",
      "primary_asset": "ai-generated-code",
      "description": "Application security platform whose Developer Assist secures AI-generated code in real time inside the IDE, detecting SAST, SCA, secret, and IaC flaws and applying validated fixes before commit.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001",
        "GDPR"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-generated-code",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Developer Assist secures AI-generated code as it is written in the IDE, detecting SAST, SCA, secret, IaC, and container flaws and applying validated fixes before commit, alongside Copilot, Cursor, and Windsurf.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "cisco-defenseclaw",
      "schema_version": 2,
      "name": "Cisco DefenseClaw",
      "vendor": "Cisco",
      "url": "https://github.com/cisco-ai-defense/defenseclaw",
      "primary_asset": "ai-orchestration-tools",
      "description": "Cisco DefenseClaw: Open-source security for agentic AI runtimes that scans agent skills, MCP servers, plugins, and code before use, inspects runtime traffic, and blocks unsafe actions by policy.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-05",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Admission control scans skills, MCP servers, plugins, and generated code before they run, runtime guardrails inspect prompts and tool calls, and unsafe capabilities are blocked by policy with durable audit evidence.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "citadel-ai",
      "schema_version": 2,
      "name": "Citadel AI",
      "vendor": "Citadel AI",
      "url": "https://citadel-ai.com",
      "primary_asset": "ai-model",
      "description": "Citadel AI: Maker of Citadel Lens, which tests AI models and datasets against industry standards and generates AI compliance reports for regulations such as the EU AI Act.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "ISO 27001"
      ],
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "detect"
          ],
          "maturity": "primary",
          "note": "Citadel Lens runs customizable test suites that check AI models against industry standards across data slices and robustness scenarios, and generates compliance reports against AI regulations such as the EU AI Act and ISO standards.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Lens for LLMs evaluates LLM application outputs with built-in metrics for factual consistency, toxicity, and jailbreak detection. Evaluation and monitoring only, with no documented inline blocking guardrail.",
          "origin": "agent"
        },
        {
          "asset": "training-data",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Lens test suites also evaluate datasets against industry standards and generate dataset reports alongside model reports.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "cloaked-ai",
      "schema_version": 2,
      "name": "Cloaked AI",
      "vendor": "IronCore Labs",
      "url": "https://ironcorelabs.com/products/cloaked-ai/",
      "primary_asset": "runtime-ai-data",
      "description": "Cloaked AI: IronCore Labs SDK that applies searchable, data-in-use encryption to AI vector embeddings so RAG and vector-search apps run on protected sensitive data.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2"
      ],
      "last_reviewed": "2026-06-25",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Applies searchable, distance-preserving encryption to vector embeddings so they stay encrypted in the vector database yet remain usable for nearest-neighbor search at RAG and inference time.",
          "origin": "reviewed"
        },
        {
          "asset": "training-data",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Encrypts the embedded source data converted into vectors so the sensitive data feeding AI and RAG workflows is protected against embedding-inversion attacks.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "cloudflare-ai-gateway",
      "schema_version": 2,
      "name": "Cloudflare AI Gateway",
      "vendor": "Cloudflare",
      "url": "https://www.cloudflare.com/products/ai-gateway/",
      "primary_asset": "ai-gateways-routers",
      "description": "Hosted gateway that proxies application traffic to LLM providers, adding guardrails to flag or block harmful prompts and responses, plus rate limiting, caching, and usage analytics.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001",
        "ISO 27701",
        "PCI DSS"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Proxies AI traffic with guardrails, rate limiting, and usage analytics for visibility and control.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Guardrails inspect prompts and responses in real time and flag or block harmful content.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "cloudflare-ai-security-for-apps",
      "schema_version": 2,
      "name": "Cloudflare AI Security for Apps",
      "vendor": "Cloudflare",
      "url": "https://www.cloudflare.com/products/ai-security-for-apps/",
      "primary_asset": "ai-gateways-routers",
      "description": "Cloudflare AI Security for Apps: WAF protection for LLM-powered apps that discovers AI endpoints and detects and mitigates prompt injection, data exposure, and unbounded consumption.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001",
        "ISO 27701",
        "PCI DSS"
      ],
      "last_reviewed": "2026-06-13",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Built into the WAF in front of LLM-powered apps, discovering AI endpoints and detecting and mitigating prompt injection, sensitive-data exposure, and unbounded consumption. Threat detection is an Enterprise add-on.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "cloudmatos-prompt-firewall",
      "schema_version": 2,
      "name": "CloudMatos Prompt Firewall",
      "vendor": "CloudMatos",
      "url": "https://cloudmatos.ai/solution/prompt-firewall/",
      "primary_asset": "runtime-ai-data",
      "description": "CloudMatos Prompt Firewall: Inline layer that inspects prompts and model responses for injection, jailbreaks, and sensitive-data leakage across LLM-driven applications.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-09-03",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Sits between users and the model, classifying prompts against policy before the model sees them, rewriting or refusing unsafe input, and redacting secrets and regulated data from responses. Dashboards track prompt traffic, anomalies, and blocked attempts, with logs retained for audit.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Integrates with agent and retrieval frameworks and with generic API gateways, so the same policy layer applies to calls made through an orchestration framework rather than only to a direct chat surface.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "cloudsmith-hugging-face-registry",
      "schema_version": 2,
      "name": "Cloudsmith Hugging Face Registry",
      "vendor": "Cloudsmith",
      "url": "https://cloudsmith.com/product/hugging-face-registry",
      "primary_asset": "ai-model",
      "description": "Cloudsmith Hugging Face Registry: Private, policy-governed registry that proxies and caches Hugging Face models and datasets, applying scanning and access controls before teams use them.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-13",
      "origin": {
        "description": "agent",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Registry of record for ML models that proxies Hugging Face artifacts, surfaces security and compliance signals, and enforces policy to quarantine, block, or approve them before use.",
          "origin": "reviewed"
        },
        {
          "asset": "training-data",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "Extends the same registry, provenance, and policy controls to datasets alongside models.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "clutch",
      "schema_version": 2,
      "name": "Clutch",
      "vendor": "Clutch Security",
      "url": "https://www.clutch.security",
      "primary_asset": "ai-agent-identities",
      "description": "Identity security platform for non-human identities, AI agents, and secrets: discovery, governance, posture and risk management, and threat detection and response across cloud, SaaS, and on-prem.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001"
      ],
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect",
            "detect",
            "respond"
          ],
          "maturity": "primary",
          "note": "Discovers and inventories non-human identities and AI agents, manages their lifecycle, scores posture and risk, and detects and responds to threats.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "secondary",
          "note": "Discovers and contextualizes secrets such as API keys, tokens, and certificates across the environment.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "collibra",
      "schema_version": 2,
      "name": "Collibra",
      "vendor": "Collibra",
      "url": "https://www.collibra.com/products/ai-command-center",
      "primary_asset": "ai-model",
      "description": "Data and AI catalog that inventories AI models, use cases, and agents across their lifecycle, ties them to trusted lineage-tracked data, and maps them to compliance and data policies.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify"
          ],
          "maturity": "primary",
          "note": "Registers and monitors AI models across their lifecycle with documentation and lineage, integrating with ML platforms such as SageMaker, Bedrock, and MLflow.",
          "origin": "reviewed"
        },
        {
          "asset": "training-data",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "secondary",
          "note": "Grounds AI in trusted, lineage-tracked data and protects sensitive data such as PII through integrated data access and privacy policies.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "confident-ai",
      "schema_version": 2,
      "name": "Confident AI",
      "vendor": "Confident AI",
      "url": "https://www.confident-ai.com",
      "primary_asset": "runtime-ai-data",
      "description": "Confident AI: AI quality and LLM evaluation platform from the creators of DeepEval, with the DeepTeam framework adding red teaming and production input and output guardrails.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2"
      ],
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect",
            "protect"
          ],
          "maturity": "primary",
          "note": "DeepTeam guardrails evaluate LLM system inputs and outputs for malicious intent and unsafe behavior, with input guards blocking malicious prompts before they reach the model and output guards stopping unsafe responses before they reach users, covering prompt injection and toxicity.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "detect"
          ],
          "maturity": "primary",
          "note": "DeepTeam red teaming simulates jailbreaking, prompt injection, and multi-turn exploitation attacks to uncover model vulnerabilities such as bias, PII leakage, and prompt leakage, drawing on more than 50 vulnerability types.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Red teaming extends to AI agents, RAG pipelines, and chatbots, probing agentic vulnerabilities such as goal theft, recursive hijacking, excessive agency, and tool orchestration abuse.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "confidential-ai",
      "schema_version": 2,
      "name": "Confidential AI",
      "vendor": "Confidential AI",
      "url": "https://confidential.ai/",
      "primary_asset": "runtime-ai-data",
      "description": "Confidential AI: Confidential-computing stack that runs AI inference, agents, and training inside hardware-encrypted TEEs, keeping prompts, model weights, credentials, and training data protected.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Private inference keeps prompts, responses, and model interactions encrypted in use inside TEEs.",
          "origin": "agent"
        },
        {
          "asset": "ai-model",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Proprietary model weights stay inside hardware-encrypted enclaves during inference, training, and fine-tuning, with attested builds and client-verifiable confidentiality claims.",
          "origin": "agent"
        },
        {
          "asset": "ai-workload-platforms",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Runs AI workloads (inference, agents, training) in TEEs via confidential VMs and the c8s Confidential Kubernetes platform.",
          "origin": "agent"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Confidential Agents run inside TEEs with hardware-enforced credential isolation for agent tokens and API keys.",
          "origin": "agent"
        },
        {
          "asset": "training-data",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Private training runs on sensitive data inside TEEs with cryptographic proof of exactly what data was used.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "confsec",
      "schema_version": 2,
      "name": "CONFSEC",
      "vendor": "Confident Security",
      "url": "https://confident.security/",
      "primary_asset": "runtime-ai-data",
      "description": "CONFSEC: Verifiably-private inference API from Confident Security that wraps prompts, outputs, and logs in encryption and attestation so the operator cannot read them.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-25",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Keeps prompts, outputs, and logs confidential through encryption and attestation, so prompts are never logged, retained, used for training, or sent to third parties.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Sits in front of AI models as a verifiably-private inference API, routing requests through Oblivious HTTP so operators cannot link or read individual requests.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "contextforge-mcp-gateway",
      "schema_version": 2,
      "name": "ContextForge MCP Gateway",
      "vendor": "IBM",
      "url": "https://github.com/IBM/mcp-context-forge",
      "primary_asset": "ai-orchestration-tools",
      "description": "ContextForge MCP Gateway: Open-source IBM gateway, registry, and proxy that fronts MCP, A2A, and REST tools with centralized authentication, guardrail plugins, and governance controls.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Federates MCP, A2A, and REST tool servers behind one authenticated endpoint with JWT and OAuth controls, role-based access control across global, team, and personal scopes, resource visibility flags, scoped API tokens, and rate limits. Permission checks default to deny on error.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Plugin hooks before and after prompt, tool, and resource calls apply PII detection and masking, content moderation, deny lists, and secrets detection to data flowing through the gateway, with an optional external OPA policy integration.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "corridor",
      "schema_version": 2,
      "name": "Corridor",
      "vendor": "Corridor Security",
      "url": "https://www.corridor.dev/",
      "primary_asset": "ai-generated-code",
      "description": "Corridor: Secures AI-generated code at generation through an MCP server and agent hooks in Cursor, Claude Code, and Copilot, plus automated PR security reviews and org-wide AI-code visibility.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type I"
      ],
      "last_reviewed": "2026-06-24",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-generated-code",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "An MCP server and agent hooks scan AI coding-tool edits in real time to block insecure code at generation (protect), automated reviews flag vulnerabilities on every pull request (detect), and a dashboard tracks AI-generated code across tools and developers (identify).",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Discovers and monitors the MCP servers developers connect to AI coding tools and surfaces security-policy violations across the organization.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "cranium",
      "schema_version": 2,
      "name": "Cranium",
      "vendor": "Cranium AI",
      "url": "https://cranium.ai/",
      "primary_asset": "ai-model",
      "description": "Cranium: Platform that discovers and inventories enterprise AI systems, generates AI bills of materials, red teams models, and maps risks to regulations such as the EU AI Act and NIST AI RMF.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2"
      ],
      "last_reviewed": "2026-07-17",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "detect",
            "govern"
          ],
          "maturity": "primary",
          "note": "Sensors discover internal and third-party AI systems; the platform auto-generates AI BOMs, runs agent-based red teaming via Cranium Arena, and authors policy mapped to the EU AI Act, NIST AI RMF, and ISO 42001 through its Govern layer.",
          "origin": "agent"
        },
        {
          "asset": "ai-workload-platforms",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "CloudSensor integrates with cloud environments to discover security alerts, monitor unauthorized changes, and assess role-based access controls; Detect AI scans internal environments for shadow AI.",
          "origin": "agent"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "AgentSensor gives visibility into the agentic layer, automatically detecting AI agents, the tools they invoke, and other agents in the network.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "credal",
      "schema_version": 2,
      "name": "Credal",
      "vendor": "Credal",
      "url": "https://www.credal.ai/products/agent-registry",
      "primary_asset": "ai-orchestration-tools",
      "description": "Credal: Control plane for enterprise AI agents that consolidates agents and MCP servers into a registry, makes each agent inherit source-system permissions, and applies DLP before data leaves.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2"
      ],
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Consolidates all agents and MCP servers into a registry admins manage, and enforces access by making each agent inherit source-system permissions so users see only authorized data.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Detects sensitive data and redacts or blocks it from leaving the platform or customer VPC, with full audit logging of every agent action and data access.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "credo-ai",
      "schema_version": 2,
      "name": "Credo AI",
      "vendor": "Credo AI",
      "url": "https://www.credo.ai",
      "primary_asset": "ai-orchestration-tools",
      "description": "AI governance platform that inventories AI systems, runs risk assessments, and maps controls to policy packs for the EU AI Act, NIST AI RMF, and ISO 42001.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2"
      ],
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "govern",
            "identify"
          ],
          "maturity": "primary",
          "note": "Centralized registry of AI apps and agents with governance workflows and approval gates.",
          "origin": "agent"
        },
        {
          "asset": "ai-model",
          "functions": [
            "govern",
            "identify"
          ],
          "maturity": "primary",
          "note": "Model inventory and risk assessment against policy packs and standards.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "govern"
          ],
          "maturity": "secondary",
          "note": "Agent registry with agent cards covering purpose, tools, data sources, and guardrails.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "curity-access-intelligence",
      "schema_version": 2,
      "name": "Curity Access Intelligence",
      "vendor": "Curity",
      "url": "https://curity.io/product/access-intelligence/",
      "primary_asset": "ai-agent-identities",
      "description": "Curity Access Intelligence: Runtime authorization for AI agents and machines that issues scoped ephemeral tokens and allows, limits, or denies every agent API and tool call in real time.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-05",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Issues scoped, ephemeral tokens to agents and machines and evaluates every request against identity, context, policy, and risk to allow, limit, or deny it at runtime.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Gates the API and tool calls agents make across chains of actions, carrying user and agent identity together and requiring human approval for high-stakes actions.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "cyata",
      "schema_version": 2,
      "name": "Cyata",
      "vendor": "Cyata",
      "url": "https://cyata.ai",
      "primary_asset": "ai-agent-identities",
      "description": "Cyata: Agentic identity control plane that discovers AI agents across SaaS and cloud environments, records each agent interaction for forensics, and enforces least-privilege access policies.",
      "deployment": [
        "saas"
      ],
      "status": "acquired",
      "compliance_attestations": null,
      "acquirer": "Check Point Software Technologies",
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Maps AI agents across SaaS, cloud, and identity infrastructure, including shadow, orphaned, and overly privileged agents; logs every agent interaction for audit and forensics; assigns dynamic identities and enforces least-privilege policy on agent access.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "cyberhaven-ai-security",
      "schema_version": 2,
      "name": "Cyberhaven AI Security",
      "vendor": "Cyberhaven",
      "url": "https://www.cyberhaven.com/product/ai-security",
      "primary_asset": "ai-agent-identities",
      "description": "Cyberhaven AI Security: Endpoint agent that inventories AI tools and agents, monitors their execution, and uses data lineage to block, warn, or redact sensitive data across prompts and responses.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-13",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "primary",
          "note": "Endpoint agent continuously inventories AI tools, coding assistants, agent frameworks, and MCP servers, and reconstructs the execution lifecycle of each agent interaction.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Uses data lineage to block, warn, or redact sensitive data in real time across prompts, responses, and downstream flows, based on data context and tool risk.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "cycode",
      "schema_version": 2,
      "name": "Cycode",
      "vendor": "Cycode",
      "url": "https://cycode.com/adlc-security/",
      "primary_asset": "ai-generated-code",
      "description": "Cycode: Agentic development security that inventories AI models, MCP servers, and code assistants across repositories and applies IDE and CLI guardrails to AI coding agents.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-generated-code",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "AI Guardrails use AI hooks and a Cycode MCP server in the IDE and CLI to intercept prompts, file reads, and tool calls before sensitive data reaches external AI services, and validate coding agent outputs before commit.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "identify"
          ],
          "maturity": "primary",
          "note": "The AI Bill of Materials inventories machine learning models detected in repositories, whether self-hosted or referenced from model hubs, as part of a continuously updated AI and ML inventory.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "AIBOM discovery also catalogs MCP integrations, AI code assistants, LLM gateways, and orchestration frameworks found across the software factory, mapped to repositories and Cycode Projects.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "cyera",
      "schema_version": 2,
      "name": "Cyera",
      "vendor": "Cyera",
      "url": "https://www.cyera.com/",
      "primary_asset": "training-data",
      "description": "Data security platform that discovers and classifies sensitive data across the enterprise, surfaces shadow AI, controls what data AI can reach, and prevents sensitive-data leakage to AI in real time.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2",
        "ISO 27001",
        "HIPAA",
        "PCI DSS",
        "C5",
        "GDPR"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "training-data",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Discovers and classifies sensitive data across cloud and SaaS, surfaces shadow AI, and controls which data AI applications and agents can reach.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Prevents sensitive-data leakage to AI in the moment through AI-aware data-loss controls.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "datadog-llm-observability",
      "schema_version": 2,
      "name": "Datadog LLM Observability",
      "vendor": "Datadog",
      "url": "https://www.datadoghq.com/products/ai/agent-observability/",
      "primary_asset": "runtime-ai-data",
      "description": "Observability for LLM and agent applications that traces prompts, responses, and tool calls, with evaluations that flag prompt injection, unsafe output, and exposure of sensitive data.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect",
            "protect"
          ],
          "maturity": "primary",
          "note": "Evaluations inspect prompts and responses to flag prompt injection, unsafe output, and PII exposure, and a Sensitive Data Scanner integration redacts sensitive data.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Auto-instruments frameworks such as LangChain to trace agent workflows across model calls, retrieval, and tool calls, surfacing failures and anomalies.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "datakrypto-fhenom-for-ai",
      "schema_version": 2,
      "name": "DataKrypto FHEnom for AI",
      "vendor": "DataKrypto",
      "url": "https://www.datakrypto.ai/",
      "primary_asset": "ai-model",
      "description": "DataKrypto FHEnom for AI: Fully-homomorphic-encryption framework that keeps AI model weights, embeddings, and user data encrypted in ciphertext through training, inference, and deployment.",
      "deployment": [
        "hybrid"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-25",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Encrypts model weights, parameters, and architecture with fully homomorphic encryption so they stay in ciphertext in memory and on GPU cores throughout execution.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Encrypts prompts and queries at the trust boundary with an ephemeral session key and computes on ciphertext, returning inference outputs in encrypted form.",
          "origin": "reviewed"
        },
        {
          "asset": "training-data",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Keeps user data and embeddings in ciphertext across training, inference, and deployment, enabling direct computation on encrypted embeddings.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "deepchecks",
      "schema_version": 2,
      "name": "Deepchecks",
      "vendor": "Deepchecks",
      "url": "https://www.deepchecks.com/",
      "primary_asset": "runtime-ai-data",
      "description": "Deepchecks: AI testing, observability, and monitoring platform that evaluates prompts, models, and agents and tracks LLM app quality in production.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "acquired",
      "compliance_attestations": null,
      "acquirer": "Check Point Software Technologies",
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect"
          ],
          "maturity": "primary",
          "note": "Monitors deployed LLM applications in production by sampling interactions and tracking annotation trends and property scores to detect degradation automatically. Scoring is offline evaluation with no documented inline blocking.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "The pentest environment generates curated adversarial prompts covering prompt injection, jailbreaks, PII extraction, and bias triggers, runs the LLM pipeline against them, and scores whether the attacks succeeded.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Evaluates each layer of an agentic pipeline independently, scoring individual agents, tools, and LLM calls to isolate underperforming or failing components.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "deepkeep",
      "schema_version": 2,
      "name": "DeepKeep",
      "vendor": "DeepKeep",
      "url": "https://www.deepkeep.ai/",
      "primary_asset": "runtime-ai-data",
      "description": "DeepKeep: AI security platform with a runtime AI firewall, automated red teaming, and model scanning for LLM and computer vision systems.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "The AI Firewall inspects prompts and responses in real time and can block, redact, or alert on prompt injection, jailbreaks, data leakage, and unsafe outputs, deployed inline or out-of-band.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "primary",
          "note": "Model scanning combines multi-engine static analysis with dynamic testing to surface embedded malware, vulnerable dependencies, tampering, and unsafe behaviors, and builds model inventories using SBOM and MLBOM frameworks.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Automated red teaming continuously simulates prompt injection, jailbreak, and data leakage attacks against custom AI applications and agents, with findings tied to remediation guidance and firewall guardrail updates.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "descope",
      "schema_version": 2,
      "name": "Descope",
      "vendor": "Descope",
      "url": "https://www.descope.com/use-cases/ai",
      "primary_asset": "ai-agent-identities",
      "description": "Identity platform for AI agents and MCP servers that authenticates agents with scoped OAuth tokens, brokers their credentials to external tools, and governs and audits what each agent may do.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001",
        "FedRAMP High",
        "CSA STAR Level 2"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Acts as an OAuth 2.1 authorization server for AI agents and MCP servers, issuing scoped tokens, brokering credentials to downstream tools, and enforcing per-tool scopes with a full audit trail of agent actions.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "dreadnode",
      "schema_version": 2,
      "name": "Dreadnode",
      "vendor": "Dreadnode",
      "url": "https://docs.dreadnode.io/ai-red-teaming/",
      "primary_asset": "ai-model",
      "description": "Dreadnode: AI red teaming tooling that probes foundation models and agentic AI systems for security and safety risks.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "detect"
          ],
          "maturity": "primary",
          "note": "AI Red Teaming probes foundation models and traditional ML models with 45+ attack strategies including jailbreaks and adversarial algorithms, mapping findings to OWASP MITRE ATLAS and NIST AI RMF.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Custom Targets red teams agentic systems including agent loops RAG pipelines and AI applications not just standard model endpoints.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "dynamoguard",
      "schema_version": 2,
      "name": "DynamoGuard",
      "vendor": "Dynamo AI",
      "url": "https://www.dynamo.ai/dynamoguard",
      "primary_asset": "runtime-ai-data",
      "description": "DynamoGuard: Runtime guardrails that turn natural language policies into lightweight models to detect and block prompt injection, data leakage, and unsafe LLM output.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Lightweight guardrail models screen LLM inputs and outputs in real time for prompt injection, jailbreaks, PII leakage, toxicity, and hallucinations, with block or sanitize actions; compliance teams author custom policies in natural language and audit flagged LLM usage in production.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Dynamo AgentWarden evaluates AI agents and MCP tools for risky tool combinations and enforces allow, deny, or human approval decisions per tool call at the agent-tool boundary in real time.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "edera-protect-ai",
      "schema_version": 2,
      "name": "Edera Protect AI",
      "vendor": "Edera",
      "url": "https://edera.dev/gpus",
      "primary_asset": "ai-workload-platforms",
      "description": "Edera Protect AI: Hardened runtime that isolates each AI agent and model workload in its own dedicated-kernel sandbox and partitions shared GPUs, so a compromised workload cannot reach the host.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-14",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-workload-platforms",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Runs each AI agent or model workload in its own hardware-isolated sandbox with a dedicated Linux kernel, containing a compromised workload to its zone so it cannot reach the host or other tenants, and partitions shared GPUs across workloads.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "einstein-trust-layer",
      "schema_version": 2,
      "name": "Einstein Trust Layer",
      "vendor": "Salesforce",
      "url": "https://developer.salesforce.com/docs/ai/agentforce/guide/trust.html",
      "primary_asset": "runtime-ai-data",
      "description": "Einstein Trust Layer: Guardrails between Salesforce applications and LLMs that mask sensitive data, detect toxic output, maintain audit trails, and enforce zero data retention with LLM providers.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Masks sensitive data such as social security numbers before prompts reach LLM providers, runs toxicity detection on LLM generations, and records an audit trail of AI interactions, with zero data retention agreements covering third-party LLM partners.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "endor-labs-ai-model-discovery",
      "schema_version": 2,
      "name": "Endor Labs AI Model Discovery",
      "vendor": "Endor Labs",
      "url": "https://docs.endorlabs.com/secure-ai-coding/",
      "primary_asset": "ai-model",
      "description": "Endor Labs AI Model Discovery: Discovers open-source AI models from Hugging Face and scores them across security, activity, popularity, and operational integrity for informed usage decisions.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-13",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovers open-source AI models from Hugging Face and scores them across security, activity, popularity, and operational integrity to surface model risk.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "enkrypt-ai",
      "schema_version": 2,
      "name": "Enkrypt AI",
      "vendor": "Enkrypt AI",
      "url": "https://www.enkryptai.com/",
      "primary_asset": "runtime-ai-data",
      "description": "Enkrypt AI: Runtime guardrails for LLM apps and agents, automated red teaming, MCP gateway and scanner controls, and compliance evidence mapped to EU AI Act and NIST.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2"
      ],
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Agent Guardrails enforces policy inline at the prompt, retrieval, tool, and output boundaries, with rewrite, block, or escalate decisions and injection filtering across text, image, and audio inputs.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "detect"
          ],
          "maturity": "primary",
          "note": "Agent Red Teaming runs adversarial tests against models, agents, RAG systems, and tools, covering prompt injection and jailbreaks, with CI/CD regression suites and compliance mapping to NIST, OWASP, and the EU AI Act.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "MCP Gateway, an open-source control plane, sits inline between agents and MCP servers to approve, modify, or block tool calls, enforcing least privilege and producing an audit evidence trail.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "entro-security",
      "schema_version": 2,
      "name": "Entro Security",
      "vendor": "Entro Security",
      "url": "https://entro.security/",
      "primary_asset": "ai-agent-identities",
      "description": "Security platform for AI agents and non-human identities that discovers them, monitors agent behavior and intent for threats, and attributes each identity to a human owner.",
      "deployment": [
        "saas"
      ],
      "status": "acquired",
      "compliance_attestations": null,
      "acquirer": "SailPoint",
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovers AI agents, non-human identities, and their secrets, continuously monitors agent behavior and intent for anomalies and threats, and attributes each identity to a human owner.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "envoy-ai-gateway",
      "schema_version": 2,
      "name": "Envoy AI Gateway",
      "vendor": "Envoy AI Gateway community",
      "url": "https://aigateway.envoyproxy.io/",
      "primary_asset": "ai-gateways-routers",
      "description": "Envoy AI Gateway: Open-source gateway on CNCF Envoy that routes traffic to many LLM providers behind one OpenAI-compatible API, with token quotas, provider failover, and an MCP gateway.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-05",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Routes AI traffic to multiple LLM providers behind one API, enforcing token-based quotas and provider failover while producing unified observability across the fleet.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "secondary",
          "note": "MCP gateway mediates how agents reach tools, adding server multiplexing, tool routing, OAuth authentication, and observability for MCP workloads.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "eqty-lab",
      "schema_version": 2,
      "name": "EQTY Lab",
      "vendor": "EQTY Lab",
      "url": "https://www.eqtylab.io/",
      "primary_asset": "ai-agent-identities",
      "description": "EQTY Lab: Verifiable AI governance suite that binds policies to AI agents, tracks cryptographic lineage of AI data and models, and collects compliance evidence across frameworks.",
      "deployment": [
        "hybrid"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-03",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "AI Guardian binds unified controls to AI agents, detecting agent vulnerabilities and enforcing compliance on how each agent operates.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "govern"
          ],
          "maturity": "secondary",
          "note": "Governance Studio provides a policy engine that enforces rules and collects compliance evidence mapped to AI regulatory frameworks.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "Lineage Explorer maintains and audits an inventory of AI agents, models, and data with verifiable provenance.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "fiddler-ai",
      "schema_version": 2,
      "name": "Fiddler AI",
      "vendor": "Fiddler",
      "url": "https://www.fiddler.ai",
      "primary_asset": "runtime-ai-data",
      "description": "Fiddler AI: Observability and guardrails platform for LLM and agent applications that scores prompts and responses and blocks harmful content, PII leaks, and hallucinations in real time.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2"
      ],
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Fiddler Guardrails screen prompts and responses in real time, blocking harmful or jailbreaking content across eleven safety dimensions, detecting and redacting PII and PHI, and flagging hallucinated RAG responses.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Agentic observability traces multi-agent systems through OpenTelemetry and framework integrations, evaluating and monitoring agent behavior for safety and quality in development and production.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "firetail-ai-security",
      "schema_version": 2,
      "name": "FireTail AI Security",
      "vendor": "FireTail",
      "url": "https://www.firetail.ai/ai-security",
      "primary_asset": "ai-model",
      "description": "FireTail AI Security: AI security posture management that discovers AI and LLM integrations, assesses their risk, and detects prompt injection, data leaks, and system-prompt exposure.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-24",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "primary",
          "note": "An AI security posture management engine automatically discovers AI and LLM integrations across code and cloud and assesses their security risks.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect",
            "protect"
          ],
          "maturity": "secondary",
          "note": "Detects and helps block prompt injection, sensitive-data leaks, supply-chain risk, and system-prompt exposure with automated threat detection, policy enforcement, and real-time alerts.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "flint-ai-cli",
      "schema_version": 2,
      "name": "Flint AI CLI",
      "vendor": "SandboxAQ",
      "url": "https://flintai.dev/",
      "primary_asset": "ai-orchestration-tools",
      "description": "Flint AI CLI: Free local-first CLI that scans AI agent source code for risky tool access and missing guardrails and runs adversarial evals against running agents, with findings mapped to OWASP ASI.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "detect"
          ],
          "maturity": "primary",
          "note": "Scans agent source code for security vulnerabilities, misconfigurations, risky tool access, and missing guardrails across major agent frameworks, producing a per-agent reliability score with findings mapped to OWASP ASI and scored with CVSS v4.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Sends adversarial and functional prompts (prompt injection, jailbreaks) to a running agent and scores the responses; offline testing with no inline enforcement.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "fortanix-confidential-ai",
      "schema_version": 2,
      "name": "Fortanix Confidential AI",
      "vendor": "Fortanix",
      "url": "https://www.fortanix.com/platform/confidential-ai",
      "primary_asset": "ai-model",
      "description": "Fortanix Confidential AI: Confidential-computing runtime that runs models in a TEE so model weights and inference data stay encrypted and inaccessible to the underlying infrastructure.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-05",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Runs proprietary models inside a confidential-computing TEE so model IP stays encrypted and inaccessible to the host and cloud operator.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Protects sensitive data and inference in use across the AI lifecycle by keeping it encrypted inside the trusted execution environment.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "fortiaigate",
      "schema_version": 2,
      "name": "FortiAIGate",
      "vendor": "Fortinet",
      "url": "https://www.fortinet.com/products/fortiaigate",
      "primary_asset": "ai-gateways-routers",
      "description": "FortiAIGate: Runtime AI gateway that proxies traffic between apps and LLMs, applying guardrails against prompt injection, jailbreaks, data leakage, and model abuse.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Deploys as a containerized proxy between the app and the model, with API gateway, DDoS protection, intelligent traffic steering, output caching, and visibility mapped to the OWASP Top 10 for LLM Applications.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Guardrails inspect input to each LLM endpoint to detect prompt injection, jailbreaking, and excessive consumption, while a context-aware DLP engine in the critical path blocks PII and sensitive data leakage in both directions.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "The inline DLP engine monitors inbound and outbound traffic to prevent model extraction, and input guardrails detect model poisoning and manipulation attempts.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "frontegg-ai",
      "schema_version": 2,
      "name": "Frontegg.ai",
      "vendor": "Frontegg",
      "url": "https://frontegg.com/product/frontegg-ai",
      "primary_asset": "ai-agent-identities",
      "description": "Frontegg.ai: Identity management for AI agent builders, with user authentication, least-privilege authorization, token rotation, and managed OAuth tokens for third-party tool access.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001",
        "ISO 27017",
        "ISO 27018",
        "ISO 27701"
      ],
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Provides the identity layer for agent products, with multi-tenant user onboarding, least-privilege authorization, and managed third-party OAuth tokens with token rotation, so agents act with scoped refreshable credentials.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "The AgentLink companion product creates a hosted MCP server that translates SaaS APIs into MCP tools, enforces agent-specific guardrails on every action, and keeps audit trails plus analytics of agent tool usage and anomalies.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "future-agi",
      "schema_version": 2,
      "name": "Future AGI",
      "vendor": "Future AGI",
      "url": "https://futureagi.com/",
      "primary_asset": "runtime-ai-data",
      "description": "Future AGI: AI evaluation and observability platform with a Protect guardrails layer that screens prompts and responses in real time, blocking prompt injection, PII exposure, and hallucinations.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001",
        "HIPAA",
        "GDPR",
        "CCPA"
      ],
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent",
        "compliance_attestations": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect",
            "protect"
          ],
          "maturity": "primary",
          "note": "Evaluation and observability for LLM applications and agents with an inline Guard layer of 18+ pre- and post-processing guardrail types (PII, prompt injection, content moderation, hallucination checks, data leakage) and per-rule enforce, monitor, or log modes.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "detect",
            "protect"
          ],
          "maturity": "secondary",
          "note": "Agent evaluation (tool selection, tracing) plus guard types scoped to the agent tool layer, including tool permissions and MCP security checks.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "galileo",
      "schema_version": 2,
      "name": "Galileo",
      "vendor": "Cisco",
      "url": "https://galileo.ai",
      "primary_asset": "runtime-ai-data",
      "description": "Galileo: Evaluates GenAI and agent behavior offline, then reuses those evaluations as runtime controls that screen model and tool traffic in production.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "acquired",
      "compliance_attestations": null,
      "acquirer": "Cisco",
      "last_reviewed": "2026-08-31",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Agent Control evaluates LLM and tool inputs and outputs during agent execution and blocks unsafe content inline.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Luna-2 evaluation models score agent and LLM application behavior, including multi-step agentic workflows.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "garak",
      "schema_version": 2,
      "name": "garak",
      "vendor": "NVIDIA",
      "url": "https://github.com/NVIDIA/garak",
      "primary_asset": "ai-model",
      "description": "garak: Open-source LLM vulnerability scanner from NVIDIA that probes models for prompt injection, jailbreaks, data leakage, toxicity, and misinformation using static, dynamic, and adaptive probes.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "detect"
          ],
          "maturity": "primary",
          "note": "Combines static, dynamic, and adaptive probes, including DAN-style jailbreaks, encoding-based prompt injection, adversarial suffixes, and training-data replay, with per-probe detectors and reporting harnesses.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "genai-protector-plus",
      "schema_version": 2,
      "name": "GenAI Protector Plus",
      "vendor": "Cloudsine",
      "url": "https://www.cloudsine.tech/products/genai-protector-plus/",
      "primary_asset": "runtime-ai-data",
      "description": "GenAI Protector Plus: GenAI firewall by Cloudsine that inspects prompts and LLM outputs to block prompt injection and jailbreaks, prevent sensitive-data leakage, and moderate hazardous content.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "ISO 27001:2022",
        "CSA Cyber Essentials Mark"
      ],
      "last_reviewed": "2026-06-24",
      "origin": {
        "description": "agent",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Inspects incoming prompts to filter direct and indirect prompt injection and jailbreaks, blocks PII and sensitive-data leakage in prompts and responses, and moderates hazardous content.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Deploys as a GPU-powered firewall positioned as a security control gateway between AI applications and the model backend.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "general-analysis",
      "schema_version": 2,
      "name": "General Analysis",
      "vendor": "General Analysis",
      "url": "https://generalanalysis.com/",
      "primary_asset": "runtime-ai-data",
      "description": "General Analysis: Automated red-teaming platform that runs adversarial tests against LLM apps, RAG systems, MCP servers, and production AI agents to surface prompt injection and data-leakage flaws.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-03",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect"
          ],
          "maturity": "primary",
          "note": "Runs automated adversarial tests over prompts and responses to surface prompt injection, tool misuse, data leakage, and multi-step agent attacks before release.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "Discovers the AI systems in the environment, inventorying models, MCP servers, knowledge bases, and agent workflows before testing them.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "geordie",
      "schema_version": 2,
      "name": "Geordie",
      "vendor": "Geordie AI",
      "url": "https://www.geordie.ai/",
      "primary_asset": "ai-orchestration-tools",
      "description": "Geordie: Agent security platform that discovers AI agents, maps their tools and MCP connections, audits behavior, and applies real-time controls through its Beam engine.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify"
          ],
          "maturity": "primary",
          "note": "Discovers agents across cloud, code, and endpoint environments and maps each agent configuration, including tool and MCP connections, plugins, system prompts, and models, with findings mapped to OWASP, NIST, ISO 42001, and the EU AI Act.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect",
            "protect"
          ],
          "maturity": "primary",
          "note": "Keeps an auditable record of every prompt, plan, response, and tool invocation with behavioral baselining and anomaly detection; the Beam engine intervenes at the agent level in real time with deterministic controls.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "Maps agent permissions, user mappings, and system access, and updates the picture as connections and authorizations change.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "giskard",
      "schema_version": 2,
      "name": "Giskard",
      "vendor": "Giskard",
      "url": "https://www.giskard.ai/",
      "primary_asset": "ai-model",
      "description": "Open-source and commercial AI testing platform that red-teams LLMs and ML models with adversarial probes for prompt injection, hallucination, and sensitive-information disclosure.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "detect"
          ],
          "maturity": "primary",
          "note": "Red-teams LLMs and ML models with adversarial probes, detecting prompt injection, hallucination, and sensitive-information disclosure.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "golf-gateway",
      "schema_version": 2,
      "name": "Golf Gateway",
      "vendor": "Golf",
      "url": "https://docs.golf.dev/gateway/overview/golf-gateway",
      "primary_asset": "ai-orchestration-tools",
      "description": "Golf Gateway: Protocol-aware proxy between AI agents and MCP servers that brokers upstream credentials, applies role-based tool access, redacts PII, and logs every call.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type II"
      ],
      "last_reviewed": "2026-07-29",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent",
        "compliance_attestations": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Runs inline as a transparent proxy between MCP clients and MCP servers, surfacing which servers and tools each agent reaches, enforcing access policy per server, tool, and resource, and recording every interaction in an audit trail that exports to Elasticsearch, Sentinel, or OTLP.",
          "origin": "agent"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Agents authenticate once to the gateway, which injects the upstream API keys and OAuth tokens for each MCP server on their behalf, so long-lived credentials are not distributed into local agent configuration files.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Responses returned by MCP servers are matched against configurable sensitive field lists and entity recognizers, and matching values are replaced before the response reaches the calling agent or the audit log.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "google-agent-gateway",
      "schema_version": 2,
      "name": "Google Agent Gateway",
      "vendor": "Google",
      "url": "https://docs.cloud.google.com/gemini-enterprise-agent-platform/govern/gateways/agent-gateway-overview",
      "primary_asset": "ai-orchestration-tools",
      "description": "Google Agent Gateway: Governs agent-to-agent and agent-to-tool traffic by enforcing least-privilege access policies and inspecting MCP and A2A protocol traffic, with integrated Model Armor guardrails.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2",
        "SOC 3",
        "ISO 27001",
        "ISO 27018",
        "ISO 27701",
        "PCI DSS"
      ],
      "last_reviewed": "2026-06-13",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Acts as the network entry and exit point for agent interactions, enforcing least-privilege access policies across agent-to-agent and agent-to-tool connections and parsing MCP request attributes to authorize access to specific tools, with Model Armor guardrails against MCP prompt injection.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Uses each agent identity as the principal for authorization decisions and secures agent-to-tool connectivity with automatic mTLS handshakes and OAuth 2.0 handling.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "google-model-armor",
      "schema_version": 2,
      "name": "Google Model Armor",
      "vendor": "Google",
      "url": "https://cloud.google.com/security/products/model-armor",
      "primary_asset": "runtime-ai-data",
      "description": "Google Cloud runtime security for generative and agentic AI that screens prompts, responses, and agent interactions to block prompt injection, jailbreaks, malicious URLs, and sensitive-data leaks.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2",
        "SOC 3",
        "ISO 27001",
        "ISO 27017",
        "ISO 27018",
        "ISO 27701",
        "PCI DSS"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Screens AI prompts and responses in real time, blocking prompt injection, jailbreaks, malicious URLs, and sensitive-data leaks.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Provides in-line protection for agent interactions across agent platforms and frameworks such as Vertex and LangChain.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "gray-swan-cygnal",
      "schema_version": 2,
      "name": "Gray Swan Cygnal",
      "vendor": "Gray Swan AI",
      "url": "https://www.grayswan.ai/solutions/platform/cygnal",
      "primary_asset": "runtime-ai-data",
      "description": "Gray Swan Cygnal: Inline runtime guardrail that screens prompts, model responses, and agent tool calls, blocking prompt injection, jailbreaks, and unsafe outputs against custom policies.",
      "deployment": [
        "saas",
        "self-hosted",
        "hybrid"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "Cyber Essentials"
      ],
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Sits inline between users and the model, classifying adversarial inputs and unsafe outputs in real time. Blocks policy violations with a refusal message, while a separate monitor endpoint returns violation scores for detection without blocking.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Monitors agent tool calls at runtime and flags agentic risk patterns such as unauthorized tool use, scope violations, and injections delivered through tool output or retrieved content.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "guardion-ai",
      "schema_version": 2,
      "name": "Guardion AI",
      "vendor": "Guardion AI",
      "url": "https://guardion.ai/",
      "primary_asset": "runtime-ai-data",
      "description": "Guardion AI: Runtime guardrail platform and inline security gateway that detects and blocks prompt injection, jailbreaks, and unsafe agent actions, and redacts PII across LLM and MCP calls.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-24",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Runtime guardrails detect and block prompt injection and jailbreaks and redact PII and secrets before prompts or responses leave the organization.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "An inline security gateway enforces guardrails, PII redaction, and policy on every LLM and MCP call, deployable inline or through a guard API.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Observes, enforces, and responds on every AI agent and MCP action, allowing, blocking, or redacting agent behavior across multi-agent frameworks.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "guardrails-ai",
      "schema_version": 2,
      "name": "Guardrails AI",
      "vendor": "Guardrails AI",
      "url": "https://www.guardrailsai.com/",
      "primary_asset": "runtime-ai-data",
      "description": "Guardrails AI: Open-source Python framework that wraps LLM calls in input and output guards, applying validators from the Guardrails Hub to detect and mitigate risks in prompts and responses.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Validators from the Guardrails Hub combine into input and output guards that intercept LLM inputs and outputs and act on failures, with options to block or raise exceptions. A standalone server exposes guards over a REST API.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "harmonic-security",
      "schema_version": 2,
      "name": "Harmonic Security",
      "vendor": "Harmonic Security",
      "url": "https://www.harmonic.security/",
      "primary_asset": "runtime-ai-data",
      "description": "Harmonic Security: Monitors employee and agent AI usage via a browser extension and desktop client, detecting sensitive data in prompts and coaching or blocking risky sharing in real time.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001",
        "ISO 42001",
        "HIPAA",
        "GDPR",
        "CCPA"
      ],
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Inspects employee prompts on the device via browser extension and desktop client, identifies shadow AI tools in use, and makes inline decisions in under 200 ms to warn, coach, or block sensitive data sharing.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Harmonic Command provides visibility into AI agents acting through MCP servers and applies inline interventions that coach the user or agent when sensitive data is about to leave the business.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "hiddenlayer",
      "schema_version": 2,
      "name": "HiddenLayer",
      "vendor": "HiddenLayer",
      "url": "https://hiddenlayer.com",
      "primary_asset": "ai-model",
      "description": "AI security platform with four modules: model supply-chain scanning, real-time runtime monitoring of prompts and responses, automated red teaming, and AI asset discovery.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Static scanning of models before deployment for malware, tampering, and backdoors, with an AI Bill of Materials per scan.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Real-time input and output monitoring that can block prompts to the model or responses to the user.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Agentic and MCP protection within the runtime module.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "Automated discovery and inventory of AI assets, applications, datasets, and dependencies.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "highflame",
      "schema_version": 2,
      "name": "Highflame",
      "vendor": "Highflame",
      "url": "https://www.highflame.com/",
      "primary_asset": "ai-agent-identities",
      "description": "Highflame: Secures AI agents with verifiable agent identity, centralized gateway policy controls, runtime guardrails, and inline policy enforcement on tool and MCP calls.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "agent",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Acts as a centralized control layer across LLM, MCP, A2A, and A2P interactions, enforcing Cedar-based access, safety, and compliance policies inline and generating audit-ready reports.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Inline controls inspect prompts and responses and block malicious inputs such as prompt injection, and strip PII and secrets before they reach the model or any tool.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Enforces one Cedar policy across MCP, tool-gateway, and agent-to-agent traffic, and its signal engine flags tool-risk and MCP poisoning inline.",
          "origin": "agent"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovers agents across the environment and issues each a verifiable, scoped, just-in-time credential with cascade revocation, then risk-scores every agent identity and monitors for mission drift.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "hirundo",
      "schema_version": 2,
      "name": "Hirundo",
      "vendor": "Hirundo",
      "url": "https://www.hirundo.io/",
      "primary_asset": "ai-model",
      "description": "Hirundo: Machine unlearning that removes memorized PII, jailbreak vulnerabilities, and biased behaviors from trained models without retraining.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "detect",
            "respond",
            "recover"
          ],
          "maturity": "primary",
          "note": "Discovers model weaknesses such as jailbreak susceptibility and memorized PII in trained models, then unlearns them by modifying the responsible parameters, returning a corrected model without full retraining.",
          "origin": "reviewed"
        },
        {
          "asset": "training-data",
          "functions": [
            "detect",
            "respond"
          ],
          "maturity": "secondary",
          "note": "Dataset QA surfaces faulty and mislabeled training data for vision and other non-generative models, and unlearning removes the influence of that data without retraining.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "holistic-ai",
      "schema_version": 2,
      "name": "Holistic AI",
      "vendor": "Holistic AI",
      "url": "https://www.holisticai.com/ai-governance-platform",
      "primary_asset": "ai-model",
      "description": "AI governance platform that discovers AI systems including shadow AI, audits models and LLMs for bias, robustness, and data leakage, and enforces regulatory compliance across the AI lifecycle.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "detect",
            "govern"
          ],
          "maturity": "primary",
          "note": "Discovers and inventories AI systems including shadow AI, audits models and LLMs for bias, hallucination, data leakage, toxicity, and robustness, and enforces continuous compliance with audit trails.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "humanbound",
      "schema_version": 2,
      "name": "Humanbound",
      "vendor": "Humanbound",
      "url": "https://www.humanbound.ai/",
      "primary_asset": "ai-orchestration-tools",
      "description": "Humanbound: Open-source engine that runs adversarial attacks against a live AI agent over its API, scores its security posture, and adds a runtime firewall that blocks prompt injection.",
      "deployment": [
        "self-hosted",
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-08-27",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "detect"
          ],
          "maturity": "primary",
          "note": "Points at a running agent over its own HTTP endpoint and drives OWASP-aligned attack chains at the agent and its tool layer, probing tool abuse and scope violations across single-turn, multi-turn, and agentic modes, then grading each conversation with a judge model into a 0 to 100 posture score.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "The companion firewall library sits in front of the agent and blocks or flags injection and out-of-scope input inline before the model sees it, using heuristics, a classifier trained on the agent own test logs, and a judge model, with verdicts available to monitoring and SIEM pipelines.",
          "origin": "agent"
        },
        {
          "asset": "ai-model",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Attack campaigns surface model-behavior failures such as jailbreaks and disclosure, though they reach the model only through the assembled agent rather than testing a model directly.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "hush-security",
      "schema_version": 2,
      "name": "Hush Security",
      "vendor": "Hush Security",
      "url": "https://www.hush.security/platform/",
      "primary_asset": "ai-agent-identities",
      "description": "Hush Security: Discovers AI agents and MCP servers at runtime and replaces their static credentials with just-in-time identity-based access.",
      "deployment": [
        "saas",
        "self-hosted",
        "hybrid"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Continuously discovers AI agents, maps the tools and systems each agent can reach, and enforces just-in-time identity-based policy-controlled access for agents in place of static keys and embedded credentials, with runtime control of over-privileged or orphaned agents.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "Discovers MCP servers, tool connectors, and agent-to-tool integrations across cloud, SaaS, and on-prem environments, and controls risky toolchain combinations and blind agent-to-tool access at runtime.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "hydrox-ai",
      "schema_version": 2,
      "name": "HydroX AI",
      "vendor": "HydroX AI",
      "url": "https://www.hydrox.ai/product",
      "primary_asset": "runtime-ai-data",
      "description": "HydroX AI: Model-agnostic runtime firewall for LLMs and agents that blocks jailbreaks, prompt injection, and data leaks, redacts PII from responses, and red-teams models for vulnerabilities.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-24",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "A model-agnostic runtime firewall intercepts AI inputs and outputs to block jailbreaks and prompt injection and to redact PII and proprietary data from responses.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Adversarial red-teaming and stress-testing uncover model failure modes and vulnerabilities before and after deployment.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "ibm-guardium-ai-security",
      "schema_version": 2,
      "name": "IBM Guardium AI Security",
      "vendor": "IBM",
      "url": "https://www.ibm.com/products/guardium-ai-security",
      "primary_asset": "ai-model",
      "description": "IBM Guardium AI Security: Discovers shadow AI and agents, runs posture checks and automated pen tests on models, and screens prompts with an AI firewall.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovers AI models and shadow AI, including agents, across cloud environments, code repositories, and embedded systems. AI SPM detects vulnerabilities and misconfigurations with automated penetration tests, and maps compliance across frameworks such as the EU AI Act and ISO 42001.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "An AI firewall applies custom security policies that analyze input and output prompts, providing real-time protection against malicious prompts, code injection, sensitive data exposure, and data leakage.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "immuta",
      "schema_version": 2,
      "name": "Immuta",
      "vendor": "Immuta",
      "url": "https://www.immuta.com/product/data-security-ai/",
      "primary_asset": "training-data",
      "description": "Data security platform that discovers and classifies sensitive data, enforces attribute-based access policies and masking at the data layer for AI and RAG workloads, and monitors data usage for risk.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "training-data",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovers and classifies sensitive data and enforces attribute-based access controls and masking at the data layer for RAG and AI workloads, monitoring queries for unusual access.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Vends short-lived, attribute-based database roles to AI agents so a prompt-injected agent stays bound to its permitted data, and access can be revoked instantly.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "impart-ai-runtime-protection",
      "schema_version": 2,
      "name": "Impart AI Runtime Protection",
      "vendor": "Impart Security",
      "url": "https://impart.ai/product/llm-protection",
      "primary_asset": "runtime-ai-data",
      "description": "Impart AI Runtime Protection: Inline runtime enforcement for LLMs, MCP servers, and agents that blocks prompt injection, data exfiltration, unsanctioned tool use, and malicious agent behavior.",
      "deployment": [
        "hybrid"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-24",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "LLM Protection inspects prompts in full session context and blocks or modifies prompt injection and data exfiltration inline before inference.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "MCP Protection catalogs every MCP server and tool from live traffic and enforces policy on caller, scope, and arguments before a tool call runs.",
          "origin": "agent"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Agent Protection fingerprints each agent and runs stateful evaluation of its behavior, blocking privilege escalation and unauthorized tool use inline.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "jetstream-security",
      "schema_version": 2,
      "name": "JetStream Security",
      "vendor": "JetStream Security",
      "url": "https://jetstream.security",
      "primary_asset": "ai-orchestration-tools",
      "description": "JetStream Security: AI governance platform that discovers AI agents, models, and MCP servers, binds them to accountable identities, and enforces approved Blueprint designs at runtime.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "FedRAMP High"
      ],
      "last_reviewed": "2026-07-27",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent",
        "compliance_attestations": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "govern",
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "AI Blueprints define the approved models, tools, identities, and guardrails for each workflow as versioned operational contracts; discovery inventories agents, MCP servers, and AI-enabled apps, and runtime drift from the approved design is flagged for approval or shutdown.",
          "origin": "agent"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect",
            "identify"
          ],
          "maturity": "primary",
          "note": "The Identity Broker binds agents, service accounts, and non-human identities to accountable human owners and replaces raw model-provider secrets with scoped, revocable virtual keys that carry least-privilege authorization across agent hand-offs.",
          "origin": "agent"
        },
        {
          "asset": "ai-model",
          "functions": [
            "protect",
            "detect",
            "identify",
            "govern"
          ],
          "maturity": "secondary",
          "note": "AI Blueprints set the approved-model criteria for each workflow as a versioned operational contract, and the platform discovers and inventories models, enforces Blueprint-scoped models at runtime, prevents unapproved model substitutions, and detects drift from the approved design.",
          "origin": "agent"
        },
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "The AI Hub is a single control point for MCP and model traffic, applying authentication, authorization, and policy at the call boundary, and inspecting content before and after each call.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect",
            "protect",
            "govern"
          ],
          "maturity": "secondary",
          "note": "Runtime governance compares live AI activity against the approved Blueprint, enforces operational and security guardrails, records conformance evidence, and flags drift from the approved design.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "jfrog-xray",
      "schema_version": 2,
      "name": "JFrog Xray",
      "vendor": "JFrog",
      "url": "https://docs.jfrog.com/security/docs/detect-malicious-ai-models",
      "primary_asset": "ai-model",
      "description": "JFrog Xray: Scans machine-learning models uploaded to public repositories such as Hugging Face for malicious code and security risks before they enter the software supply chain.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-13",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "detect",
            "identify"
          ],
          "maturity": "primary",
          "note": "Xray automatically scans ML models from public repositories such as Hugging Face for malicious code and security risks. Flagged models can be managed in the JFrog AI Catalog registry.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "jozu",
      "schema_version": 2,
      "name": "Jozu",
      "vendor": "Jozu",
      "url": "https://www.jozu.com/",
      "primary_asset": "ai-model",
      "description": "Jozu: On-prem AI model registry that secures the model supply chain by scanning, signing, and tamper-proof packaging models, agents, and MCP servers, built on the open-source KitOps project.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-17",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Jozu Hub inventories models as OCI ModelKits and secures the model supply chain by scanning, signing, and tamper-proof packaging them.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Scans agents and MCP servers for supply-chain vulnerabilities, content-safety issues, prompt-injection susceptibility, and backdoors, attaching signed attestations and gating admission by policy.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "kanopy-security",
      "schema_version": 2,
      "name": "Kanopy Security",
      "vendor": "Kanopy Security",
      "url": "https://kanopysecurity.com",
      "primary_asset": "ai-agent-identities",
      "description": "Kanopy Security: Discovers, profiles, and protects AI agents and automations that business users build on platforms such as Copilot Studio, Power Automate, Salesforce, UiPath, and Retool.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "detect",
            "protect"
          ],
          "maturity": "primary",
          "note": "Builds an inventory of agents, copilots, flows, and models with ownership and permission context, profiles each agent to learn its normal behavior, flags off-script activity, and blocks risky agent instructions before they execute.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Adaptive guardrails monitor agent actions at runtime, detect prompt injection and manipulation attempts, and stop sensitive data from leaving approved paths in real time, with coverage for Microsoft Copilot Studio environments.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "Surfaces shadow copilots, unmanaged integrations, and ungoverned agent experiments inside agent-building platforms such as Copilot Studio, and applies access and security policies with audit trails across the agent lifecycle.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "keycard",
      "schema_version": 2,
      "name": "Keycard",
      "vendor": "Keycard",
      "url": "https://keycard.ai/",
      "primary_asset": "ai-agent-identities",
      "description": "Keycard: Control plane for AI agent access that gives each agent an identity and issues short-lived, scoped per-call credentials through runtime policy, logging every authorization decision.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-14",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Gives each AI agent its own identity and issues short-lived, scoped credentials per tool, API, and data request through runtime policy, blocking disallowed actions and recording every authorization decision.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Adds OAuth-based authentication to MCP servers and agent-to-agent calls so each tool call is tied to a verified identity, scoped to explicit permissions, and logged.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "knostic-genai-knowledge-security",
      "schema_version": 2,
      "name": "Knostic GenAI Knowledge Security",
      "vendor": "Knostic",
      "url": "https://www.knostic.ai/the-genai-knowledge-security-platform",
      "primary_asset": "runtime-ai-data",
      "description": "Knostic GenAI Knowledge Security: Detects where AI assistants like Copilot, Glean, and Gemini overshare sensitive knowledge and enforces need-to-know access controls on their answers.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2"
      ],
      "last_reviewed": "2026-06-13",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect",
            "protect"
          ],
          "maturity": "primary",
          "note": "Simulates enterprise user queries against Copilot, Glean, and Gemini to find inference-based oversharing where the assistant recombines data across security boundaries, then applies role-based access policies and automated labeling to constrain what the assistant answers.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Audits enterprise AI assistants including Copilot, Glean, and Gemini, mapping their knowledge-access patterns and producing an audit trail of inferred access for safe rollout.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "knostic-kirin",
      "schema_version": 2,
      "name": "Knostic Kirin",
      "vendor": "Knostic",
      "url": "https://www.getkirin.com",
      "primary_asset": "ai-orchestration-tools",
      "description": "Security for AI coding assistants such as Cursor, Copilot, and Claude Code that inspects MCP connections in real time, monitors IDE extensions and plugins, and blocks risky components.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2"
      ],
      "last_reviewed": "2026-06-13",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Inspects MCP connections in real time and monitors IDE extensions and plugins, blocking untrusted or risky components.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-generated-code",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "In-IDE guardrails and real-time dependency scanning flag vulnerable or malicious libraries in AI-assisted coding.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Redacts and guards sensitive data inside the IDE against prompt injection and oversharing.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "koi",
      "schema_version": 2,
      "name": "Koi",
      "vendor": "Koi",
      "url": "https://www.koi.ai/",
      "primary_asset": "ai-orchestration-tools",
      "description": "Koi: Endpoint security for software supply chains that inventories, risk-scores, and gates installs of MCP servers, AI models, AI agents, extensions, and packages by policy.",
      "deployment": [
        "saas"
      ],
      "status": "acquired",
      "compliance_attestations": null,
      "acquirer": "Palo Alto Networks",
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovers and inventories MCP servers, AI agents, and extensions across endpoints, risk-scores them with the Wings engine, gates risky installs by policy, and detects malicious activity after install.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "The Wings engine and Supply Chain Gateway vet AI models from registries such as Hugging Face, scanning actual code and blocking risky model installs before they reach endpoints.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "kong",
      "schema_version": 2,
      "name": "Kong",
      "vendor": "Kong Inc.",
      "url": "https://konghq.com/products/kong-ai-gateway",
      "primary_asset": "ai-gateways-routers",
      "description": "AI gateway that proxies traffic to many LLM providers and governs it with prompt guards, PII sanitization, and content-safety policies that screen requests and responses.",
      "deployment": [
        "saas",
        "self-hosted",
        "hybrid"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Proxies traffic to many LLM providers and enforces allow and deny lists, prompt guards, and content-safety policies, with visibility over AI usage.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Plugins inspect prompts and responses, redacting PII and filtering unsafe or off-topic content before it reaches a model or user.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "lakera",
      "schema_version": 2,
      "name": "Lakera",
      "vendor": "Lakera",
      "url": "https://www.lakera.ai",
      "primary_asset": "runtime-ai-data",
      "description": "Runtime guardrails plus adversarial testing for LLM and agent apps, screening prompts, responses, and tool calls for prompt injection, jailbreaks, and data leakage.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "acquired",
      "compliance_attestations": [
        "SOC 2 Type II",
        "GDPR",
        "HIPAA"
      ],
      "acquirer": "Check Point Software Technologies",
      "last_reviewed": "2026-07-17",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Inline screening of prompts, responses, and agent tool calls.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": null,
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "lasso-security",
      "schema_version": 2,
      "name": "Lasso Security",
      "vendor": "Lasso Security",
      "url": "https://www.lasso.security/",
      "primary_asset": "runtime-ai-data",
      "description": "Platform that discovers and inventories AI agents and applications, red-teams them, and enforces policy inline at the proxy, API, or gateway to protect AI interactions at runtime.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2"
      ],
      "last_reviewed": "2026-07-17",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Enforces policy inline at the proxy, API, or AI gateway, protecting AI interactions at runtime.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "Discovers and inventories AI agents and applications in an AI bill of materials, mapping their models, prompts, tools, and guardrails.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "latticeflow-ai",
      "schema_version": 2,
      "name": "LatticeFlow AI",
      "vendor": "LatticeFlow AI",
      "url": "https://latticeflow.ai/platform",
      "primary_asset": "ai-model",
      "description": "LatticeFlow AI: AI governance platform that discovers AI systems, runs technical evaluations and automated red-team security scans, and maps evidence to 20+ compliance frameworks.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 1"
      ],
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "govern",
            "identify",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovers AI assets, runs 100+ evaluations mapped to 20+ frameworks such as the EU AI Act and NIST, scans for vulnerabilities via automated red-teaming aligned with OWASP and MITRE, and continuously monitors risk for audit-ready governance evidence.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "govern"
          ],
          "maturity": "secondary",
          "note": "Discovers, evaluates, and governs risk for autonomous agentic AI systems alongside foundation models and custom generative AI applications.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "layerx",
      "schema_version": 2,
      "name": "LayerX",
      "vendor": "LayerX Security",
      "url": "https://layerxsecurity.com/",
      "primary_asset": "runtime-ai-data",
      "description": "LayerX: Browser-extension control of employee AI use that discovers shadow AI tools, applies DLP to prompts and file transfers, and enforces identity-based access policies.",
      "deployment": [
        "saas"
      ],
      "status": "acquired",
      "compliance_attestations": null,
      "acquirer": "Akamai",
      "last_reviewed": "2026-07-03",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "GenAI DLP monitors prompts and responses with conversational context and restricts text input, copy and paste, and file uploads of sensitive data before it reaches AI tools and AI-enabled SaaS applications.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "secondary",
          "note": "Shadow AI discovery detects every AI app in use whether sanctioned, unsanctioned, or embedded in SaaS platforms, maps the accounts behind each tool, and lets security teams enforce responsible AI usage policies across channels.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "legit-security",
      "schema_version": 2,
      "name": "Legit Security",
      "vendor": "Legit Security",
      "url": "https://www.legitsecurity.com/ai-discovery",
      "primary_asset": "ai-model",
      "description": "Legit Security: AI discovery capability that inventories AI models, MCP servers, and coding assistants across development, plus VibeGuard guardrails for AI-generated code in the IDE.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify"
          ],
          "maturity": "primary",
          "note": "The AI Security Command Center keeps a real-time inventory of AI models active across development, adds reputational data for each model, and flags low-reputation or unapproved models even when developers attempt to bypass security controls.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "Inventories MCP servers and AI coding assistants alongside models, surfacing shadow MCP servers that create unmonitored pathways for data exposure and unauthorized AI agent actions, with associated risks tracked per component.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-generated-code",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "VibeGuard integrates with AI IDEs and code assistants such as Cursor and GitHub Copilot, analyzes AI-generated code in real time before commit, restricts which files assistants can access, and blocks untrusted models and secrets exposure to AI systems.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "limina",
      "schema_version": 2,
      "name": "Limina",
      "vendor": "Limina",
      "url": "https://www.getlimina.ai/en/products/data-de-identification",
      "primary_asset": "training-data",
      "description": "Limina: PII, PHI, and PCI detection and redaction that de-identifies text, images, and audio before it reaches a model, via API or a self-hosted container.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-25",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "training-data",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "De-identifies sensitive data by redacting, pseudonymizing, or replacing it with synthetic values before it feeds AI, analytics, and research pipelines, processed inside the customer environment.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Redacts PII in LLM prompts before they reach a model and re-identifies the responses, keeping confidential data out of inference calls.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "liminal",
      "schema_version": 2,
      "name": "Liminal",
      "vendor": "Liminal",
      "url": "https://www.liminal.ai/platform",
      "primary_asset": "runtime-ai-data",
      "description": "Liminal: GenAI data-protection gateway that intercepts prompts to any model, detects PII, PHI, and IP, masks or redacts it before the prompt leaves, and rehydrates protected terms in responses.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 1",
        "SOC 2 Type 2"
      ],
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Detects PII, PHI, PCI, and organization-specific data in prompts before submission to any model, masks or redacts it per policy, and rehydrates protected terms in returned outputs.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Acts as a centralized multi-model gateway routing employee AI traffic and enforcing data-security policy and access privileges on every interaction.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "lineaje-unifai",
      "schema_version": 2,
      "name": "Lineaje UnifAI",
      "vendor": "Lineaje",
      "url": "https://www.lineaje.com/unifai",
      "primary_asset": "ai-orchestration-tools",
      "description": "Lineaje UnifAI: AI policy orchestrator that discovers AI inventory, derives security and compliance policies, and enforces them with runtime guardrails for agentic AI applications.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-13",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "govern",
            "protect"
          ],
          "maturity": "primary",
          "note": "Discovers the AI inventory of agentic applications, derives security and compliance policies, and enforces them with built-in runtime guardrails.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "govern"
          ],
          "maturity": "secondary",
          "note": "Continuously discovers AI models in the inventory and applies the derived security and governance policies.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "litellm",
      "schema_version": 2,
      "name": "LiteLLM",
      "vendor": "BerriAI",
      "url": "https://www.litellm.ai/",
      "primary_asset": "ai-gateways-routers",
      "description": "LiteLLM: Open-source AI gateway and proxy for 100+ LLM providers, adding virtual-key RBAC, budgets, rate limits, guardrails (PII masking, prompt-injection), and enterprise SSO and audit logs.",
      "deployment": [
        "self-hosted",
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Routes 100+ LLM providers behind virtual keys with per-team and per-key budgets, rate limits, and RBAC. The enterprise tier adds SSO, audit logs, secret management, and key rotation.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Configurable guardrails screen prompts and responses for PII (Presidio masking and blocking) and prompt injection, with pre-call and post-call moderation hooks.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "llamafirewall",
      "schema_version": 2,
      "name": "LlamaFirewall",
      "vendor": "Meta",
      "url": "https://meta-llama.github.io/PurpleLlama/LlamaFirewall/",
      "primary_asset": "runtime-ai-data",
      "description": "LlamaFirewall: Open-source guardrail framework from Meta that scans LLM apps and agents with PromptGuard 2, AlignmentCheck, and CodeShield scanners.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "PromptGuard 2 classifies user inputs and untrusted content for direct prompt injection and jailbreaks while AlignmentCheck audits agent chain-of-thought reasoning in real time for goal hijacking and indirect injection; the framework detects and mitigates these risks inline.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-generated-code",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "CodeShield applies Semgrep and regex-based static analysis to LLM-generated code in real time, flagging insecure code across eight programming languages.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "lunar-mcpx",
      "schema_version": 2,
      "name": "Lunar MCPX",
      "vendor": "Lunar.dev",
      "url": "https://www.lunar.dev/product/mcp",
      "primary_asset": "ai-orchestration-tools",
      "description": "Lunar MCPX: Self-hosted MCP gateway that aggregates MCP servers behind one endpoint and applies per-agent access control, OAuth and API key authentication, and tool hardening.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "MCP gateway routes agent tool calls to MCP servers through one endpoint with per-agent access control, tool groups, hardened tool variants, and OAuth and API key auth; audit logs record tool usage and configuration changes.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "secondary",
          "note": "Agent inventory gives a centralized view of every agent connecting through the gateway; the enterprise edition adds centralized user, authentication, and access management over MCP servers and tools.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "The enterprise edition inspects MCP requests and responses inline to redact sensitive data before it leaves the deployment environment.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "manifest-ai-risk",
      "schema_version": 2,
      "name": "Manifest AI Risk",
      "vendor": "Manifest",
      "url": "https://www.manifestcyber.com/ai-risk",
      "primary_asset": "ai-model",
      "description": "Manifest AI Risk: AI bill-of-materials platform that discovers models and datasets across the enterprise, tracks their provenance, and continuously monitors them for vulnerabilities.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-13",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovers and inventories models and dependencies with provenance, including shadow AI, and continuously monitors them for vulnerabilities.",
          "origin": "reviewed"
        },
        {
          "asset": "training-data",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "The AIBOM extends coverage to datasets, documenting their provenance alongside models for compliance.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "manifold-manifest",
      "schema_version": 2,
      "name": "Manifold Manifest",
      "vendor": "Manifold Security",
      "url": "https://manifest.manifold.security",
      "primary_asset": "ai-orchestration-tools",
      "description": "Manifold Manifest: Free intelligence index that scores AI agent skills and plugins for supply chain risk, mapping what each one executes and who published it.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-15",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify"
          ],
          "maturity": "primary",
          "note": "Indexes agent skills and plugins from public registries and issues a per-asset security verdict from an execution graph of what the component runs and an environment graph of its publisher. Assessment only, with no enforcement. Extension and MCP server intelligence is enterprise-only.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "maro",
      "schema_version": 2,
      "name": "Maro",
      "vendor": "Maro",
      "url": "https://seekmaro.com/",
      "primary_asset": "runtime-ai-data",
      "description": "Maro: Browser-extension platform that discovers employee AI-tool usage and applies semantic data-loss policies at each prompt, coaching or blocking risky sharing across AI tools.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-03",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Applies semantic data-loss controls at every prompt and browser interaction, guiding or blocking risky sharing into AI tools in real time.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "Discovers shadow AI usage across the workforce down to the specific tool, use case, data, and prompt.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "matos-ai-spm",
      "schema_version": 2,
      "name": "Matos AI SPM",
      "vendor": "CloudMatos",
      "url": "https://cloudmatos.ai/solution/ai-spm/",
      "primary_asset": "ai-model",
      "description": "Matos AI SPM: Agentless posture management for AI models, training data, and AI services, surfacing misconfigurations and attack paths across AI pipelines.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-09-03",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "detect",
            "protect"
          ],
          "maturity": "primary",
          "note": "Inventories the models and AI services running in a cloud estate without agents, flags risky configurations against policy, and maps the vulnerability and permission chains that lead to them. Runtime insight covers AI package usage, permissions, and threats against deployed models.",
          "origin": "agent"
        },
        {
          "asset": "training-data",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "secondary",
          "note": "Scope extends to the data side of the pipeline, covering exposure of training data alongside the models built from it.",
          "origin": "agent"
        },
        {
          "asset": "ai-workload-platforms",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Checks the managed model services an application builds on for insecure configuration, and extends the same scanning to the infrastructure-as-code that provisions them.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "mcp-manager",
      "schema_version": 2,
      "name": "MCP Manager",
      "vendor": "Usercentrics",
      "url": "https://mcpmanager.ai/",
      "primary_asset": "ai-orchestration-tools",
      "description": "MCP Manager: Gateway that brokers identity between AI clients and MCP servers, applying access rules, response redaction, and per-hop audit logging.",
      "deployment": [
        "saas"
      ],
      "status": "acquired",
      "compliance_attestations": null,
      "acquirer": "Usercentrics",
      "last_reviewed": "2026-07-15",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Governed gateway sits between AI clients and MCP servers, deciding which servers and tools each caller may reach, running configurable rules on every request, and writing an audit-log entry at each hop.",
          "origin": "agent"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "The gateway authenticates the caller and forwards each request to the upstream server under a brokered identity, replacing long-lived tokens pasted into local config files; teams and roles decide which gateways a user can reach.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Responses returned from MCP servers are inspected and redacted inline before reaching the calling AI application, covering sensitive values such as PII carried in a tool result.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "mend-ai",
      "schema_version": 2,
      "name": "Mend AI",
      "vendor": "Mend.io",
      "url": "https://www.mend.io/mend-ai/",
      "primary_asset": "ai-model",
      "description": "Mend AI: Discovers and inventories AI components in applications, assesses their risks, enforces AI policies, and red teams AI behavior for issues like prompt injection.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "primary",
          "note": "Builds a continuously updated inventory of AI models and frameworks, including shadow AI, ties risks to models, runs automated red teaming tests for prompt injection, context leakage, and data exfiltration.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "AI-BOM discovery extends beyond models to MCPs and RAG pipelines, inventorying orchestration components alongside frameworks in SPDX and CycloneDX machine-readable formats.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "microsoft-agent-365",
      "schema_version": 2,
      "name": "Microsoft Agent 365",
      "vendor": "Microsoft",
      "url": "https://www.microsoft.com/en-us/microsoft-agent-365",
      "primary_asset": "ai-agent-identities",
      "description": "Microsoft Agent 365: Control plane that inventories AI agents in a registry, assigns them Entra identities with conditional access, and adds Defender posture and threat detection.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001",
        "ISO 27017",
        "ISO 27018",
        "ISO 27701"
      ],
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Visibility into all agent identities, including shadow agents; Entra Agent ID extends conditional access and identity protection from users to agents, ensuring agents have responsible sponsors and that access does not persist longer than needed.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "detect",
            "protect"
          ],
          "maturity": "secondary",
          "note": "Microsoft Defender provides agent security posture management to find misconfigurations, detects suspicious agent activity, blocks malicious tool invocations in real time, and collects agent observability logs for threat hunting.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "microsoft-purview",
      "schema_version": 2,
      "name": "Microsoft Purview",
      "vendor": "Microsoft",
      "url": "https://www.microsoft.com/en-us/security/business/microsoft-purview",
      "primary_asset": "runtime-ai-data",
      "description": "Data security posture management for AI in Microsoft Purview that discovers sensitive data in AI prompts and responses, enforces data-loss policies on generative AI use, and flags risky AI activity.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001",
        "ISO 27017",
        "ISO 27018",
        "ISO 27701"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovers sensitive data in AI prompts and responses, applies data-loss-prevention policies that warn or block sensitive content sent to generative AI apps, and detects risky AI interactions.",
          "origin": "reviewed"
        },
        {
          "asset": "training-data",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "secondary",
          "note": "Data risk assessments find and help remediate oversharing of the sensitive organizational content that generative AI apps can surface.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "miggo",
      "schema_version": 2,
      "name": "Miggo",
      "vendor": "Miggo Security",
      "url": "https://www.miggo.io",
      "primary_asset": "ai-orchestration-tools",
      "description": "Miggo: Runtime AI defense that maps agents, models, tools, and MCP integrations into an AI-BOM, detects prompt injection and agent hijacking, and enforces guardrails on AI behavior.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Builds a runtime AI-BOM that maps active agents, models, tools, frameworks, and MCP integrations from real execution, exposes shadow AI drift, and enforces guardrails on model usage, tool access, and data permissions while detecting anomalous agent behavior and unauthorized tool chaining.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect",
            "respond"
          ],
          "maturity": "primary",
          "note": "AIDR monitors prompts and model interactions at runtime, detecting manipulation such as prompt injection, model misuse, and unauthorized data access, then contains incidents with a forensic chain from user input to agent decision to system action.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Detects model supply chain compromise, including malicious model files and hidden payloads that execute when external models load into production workflows, plus unapproved model usage and unsafe execution patterns.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "mindgard",
      "schema_version": 2,
      "name": "Mindgard",
      "vendor": "Mindgard",
      "url": "https://mindgard.ai/ai-security-platform",
      "primary_asset": "ai-model",
      "description": "Automated AI red-teaming platform that maps the AI attack surface and continuously tests models and agents for prompt injection, jailbreak, and model-manipulation flaws.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "primary",
          "note": "Maps the AI attack surface including shadow AI, then runs continuous automated red teaming that chains attack techniques across multi-step interactions to find prompt injection, jailbreak, and model-manipulation flaws.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "mintmcp",
      "schema_version": 2,
      "name": "MintMCP",
      "vendor": "MintMCP",
      "url": "https://www.mintmcp.com/",
      "primary_asset": "ai-orchestration-tools",
      "description": "MintMCP: Managed MCP gateway that authenticates AI clients to MCP servers, enforces access policies, and logs every tool call for audit.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Enterprise MCP gateway between AI clients and MCP servers that handles authentication, enforces access policies, and logs every tool call; admins curate a catalog of approved servers with preconfigured credentials, role-based tool sets, and centralized credential management.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Applies enterprise SSO and RBAC controls to MCP access with fine-grained permissions and instant revocation; API keys stay within the gateway so AI clients never hold them.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Exports activity logs covering tool invocations, prompt submissions, and gateway requests to SIEM or observability platforms in real time over the OpenTelemetry Logs protocol.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "mistral-moderation",
      "schema_version": 2,
      "name": "Mistral Moderation",
      "vendor": "Mistral AI",
      "url": "https://docs.mistral.ai/studio-api/conversations/moderation/",
      "primary_asset": "runtime-ai-data",
      "description": "Mistral Moderation: Classifier service that scores prompts and responses across policy categories and applies blocking guardrails in Mistral API requests.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "The moderation service classifies raw text and conversational content across policy categories including jailbreaking, while custom guardrails declared in chat completions and conversations requests enforce per-category thresholds and block violating content with a 403 response.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Agent-level guardrails attach moderation rules to an agent at creation time, and all conversations using that agent automatically inherit the configured thresholds and blocking action.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "modelop",
      "schema_version": 2,
      "name": "ModelOp",
      "vendor": "ModelOp",
      "url": "https://www.modelop.com",
      "primary_asset": "ai-orchestration-tools",
      "description": "ModelOp: System of record for the AI an enterprise builds and buys, mapping controls to regulatory frameworks and applying them across the AI lifecycle.",
      "deployment": [
        "self-hosted",
        "hybrid"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-08-31",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "govern",
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Controls mapped to regulatory frameworks with audit evidence, over a registry of AI applications and agents that continuously discovers unregistered AI, with workflows that gate non-compliant actions.",
          "origin": "agent"
        },
        {
          "asset": "ai-model",
          "functions": [
            "govern",
            "identify",
            "detect"
          ],
          "maturity": "primary",
          "note": "Govern artifact: model cards and validation summaries captured as audit evidence, with risk tiering that decides which controls apply to a model. Inventory synced from registries such as MLflow, Bedrock, SageMaker, Azure ML, and Vertex AI, and continuous monitoring for bias, drift, and performance.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Policy and guardrails applied to live AI traffic through integrations with AI and API gateways at execution time.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "modelred",
      "schema_version": 2,
      "name": "ModelRed",
      "vendor": "ModelRed",
      "url": "https://modelred.ai/",
      "primary_asset": "ai-model",
      "description": "ModelRed: Red-teaming platform for LLMs, agents, and RAG pipelines that catches jailbreaks, prompt injection, data leaks, and unsafe behavior before deployment.",
      "deployment": [
        "saas"
      ],
      "status": "discontinued",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "detect"
          ],
          "maturity": "primary",
          "note": "Continuous adversarial testing of LLMs, agents, and RAG pipelines to catch jailbreaks, prompt injection, data leaks, and unsafe behavior before deployment.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "natoma",
      "schema_version": 2,
      "name": "Natoma",
      "vendor": "Natoma",
      "url": "https://natoma.ai/platform",
      "primary_asset": "ai-agent-identities",
      "description": "Governed MCP gateway that treats AI agents as non-human identities, enforcing identity-aware authorization and per-tool policy over agent access to tools, with shadow-AI discovery and audit.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "acquired",
      "compliance_attestations": null,
      "acquirer": "Snowflake",
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Authenticates AI agents and enforces identity-aware, attribute-based authorization with delegated permissions and Cedar policy, plus a full audit trail of every tool call.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "Provides a hosted gateway for MCP servers and tools, discovers shadow AI and unmanaged MCP connections, and controls which tools each agent may call.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "nemo-guardrails",
      "schema_version": 2,
      "name": "NeMo Guardrails",
      "vendor": "NVIDIA",
      "url": "https://github.com/NVIDIA-NeMo/Guardrails",
      "primary_asset": "runtime-ai-data",
      "description": "NeMo Guardrails: Open-source NVIDIA toolkit that adds programmable input, dialog, retrieval, execution, and output rails to LLM applications, with built-in jailbreak and content safety checks.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Input, retrieval, and output rails can reject or mask user prompts, retrieved chunks, and model responses. The built-in guardrail library adds self-check moderation, hallucination detection, jailbreak and injection detection, and NVIDIA content and topic safety models.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Execution rails screen the input and output of the custom actions and tools that an LLM calls, and the guardrail catalog includes agentic security checks.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "netskope",
      "schema_version": 2,
      "name": "Netskope",
      "vendor": "Netskope",
      "url": "https://www.netskope.com/products/securing-generative-ai",
      "primary_asset": "runtime-ai-data",
      "description": "Cloud security platform that discovers generative-AI use including shadow AI and inspects prompts and responses inline, applying DLP and guardrails to block data leakage and AI threats.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001",
        "ISO 27017",
        "ISO 27018",
        "CSA STAR Level 2",
        "HIPAA",
        "GDPR"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovers generative-AI and shadow-AI use and inspects prompts and responses inline with DLP and guardrails to block sensitive-data leakage.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Assesses the risk of generative-AI apps and MCP servers and runs automated red-team testing of private LLMs to find vulnerabilities.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "neuraltrust",
      "schema_version": 2,
      "name": "NeuralTrust",
      "vendor": "NeuralTrust",
      "url": "https://neuraltrust.ai/",
      "primary_asset": "ai-gateways-routers",
      "description": "NeuralTrust: AI gateway and runtime firewall that screens LLM and agent traffic for injection attacks and data leaks, plus automated red teaming.",
      "deployment": [
        "saas",
        "self-hosted",
        "hybrid"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "TrustGate is a distributed AI gateway that fronts model providers with routing, rate limiting, threat detection, and plugin-based security controls; core gateway functionality is available under an open-source license.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Prompt Guard and the Generative Application Firewall detect and block prompt injection, jailbreaks, and multimodal attacks in real time; sensitive data masking blocks or redacts PII and credentials in prompts and responses.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "detect"
          ],
          "maturity": "primary",
          "note": "Automated red teaming runs a continuously updated adversarial attack catalog informed by OWASP and MITRE ATLAS research, with domain-specific test generation and scheduled reruns when the model or knowledge base changes.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "newcore",
      "schema_version": 2,
      "name": "NewCore",
      "vendor": "NewCore",
      "url": "https://newcore.com/",
      "primary_asset": "ai-agent-identities",
      "description": "NewCore: Identity security platform that discovers, maps, and governs every human, machine, and AI-agent identity, provisioning agents with least-privilege access and full lifecycle control.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-05",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect",
            "govern"
          ],
          "maturity": "primary",
          "note": "Continuously discovers and maps every human, machine, and agent identity across the enterprise, provisions agents with least-privilege access before they operate, and governs the full issue-to-revoke lifecycle.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "nexos-ai",
      "schema_version": 2,
      "name": "Nexos.ai",
      "vendor": "Nexos.ai",
      "url": "https://nexos.ai/ai-gateway/",
      "primary_asset": "ai-gateways-routers",
      "description": "Nexos.ai: Enterprise AI gateway that routes requests across many LLMs through one secure endpoint and enforces security and usage policies, access controls, and budget limits on every interaction.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 1",
        "SOC 2 Type 2",
        "ISO/IEC 27001:2022"
      ],
      "last_reviewed": "2026-06-24",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "A single secure endpoint fronting many LLM providers enforces security and usage policies, access controls, and rate limits, and logs every prompt and response for visibility.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "noma-security",
      "schema_version": 2,
      "name": "Noma Security",
      "vendor": "Noma Security",
      "url": "https://noma.security",
      "primary_asset": "ai-agent-identities",
      "description": "An enterprise platform that discovers, governs, and protects AI and AI agents across the enterprise, spanning homegrown AI, SaaS agents, and coding assistants.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001",
        "ISO 42001",
        "HIPAA",
        "GDPR"
      ],
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovery, posture, and runtime protection for autonomous agents and MCP servers.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "primary",
          "note": null,
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": null,
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "nova-framework",
      "schema_version": 2,
      "name": "NOVA Framework",
      "vendor": "SecurityBreak",
      "url": "https://novahunting.ai",
      "primary_asset": "runtime-ai-data",
      "description": "NOVA Framework: Open source rule engine that matches prompts against YARA-style rules combining keywords, semantic similarity, and LLM scoring to detect adversarial prompt content.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-08-20",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect",
            "protect"
          ],
          "maturity": "primary",
          "note": "Rule engine for prompt content. YARA-inspired rules combine keyword and regex matching, semantic similarity with configurable thresholds, and LLM-scored conditions, run over prompts by the novarun CLI. The Python SDK adds a per-rule policy that blocks or redacts before the model call.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "nudge-security",
      "schema_version": 2,
      "name": "Nudge Security",
      "vendor": "Nudge Security",
      "url": "https://www.nudgesecurity.com/use-cases/ai-security",
      "primary_asset": "ai-workload-platforms",
      "description": "Nudge Security: SaaS security service that inventories shadow AI apps, accounts, and employee-built agents from email and browser signals, then enforces AI use policies in the browser.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2"
      ],
      "last_reviewed": "2026-07-27",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent",
        "compliance_attestations": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-workload-platforms",
          "functions": [
            "identify"
          ],
          "maturity": "primary",
          "note": "Builds a historical and continuous inventory of AI apps and the accounts behind them using email-based discovery, an identity provider integration, and a browser extension, covering tools adopted before deployment.",
          "origin": "agent"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "Discovers agents built on agentic platforms through connected apps and passive browser observation, then records each agent creator, platform, permissions, connected resources, approval status, and risk signals such as public exposure or departed creators. Offered as a research preview.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect",
            "protect"
          ],
          "maturity": "primary",
          "note": "Watches what employees send to AI tools through the browser extension, flagging file uploads, copy and paste of sensitive content, and API key exposure, and applies AI use policies in the browser while allowing risky app-to-AI data integrations to be revoked.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "adjacent",
          "note": "Surfaces the integration paths that give AI tools access to business data, including OAuth grants, API connections, and MCP connections into critical SaaS apps, and lets an administrator revoke a risky grant so the connected tool loses access.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "numbat",
      "schema_version": 2,
      "name": "Numbat",
      "vendor": "Perplexity",
      "url": "https://github.com/perplexityai/numbat",
      "primary_asset": "ai-orchestration-tools",
      "description": "Numbat: Open source endpoint tool that observes AI agent activity through local hooks, evaluates it against a local rule engine, and can block risky actions before they run.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-30",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect",
            "detect",
            "respond"
          ],
          "maturity": "primary",
          "note": "Observes desktop, CLI, IDE, and gateway agents through local hooks, plugins, OTLP logs, and session artifacts, inventories them with the scan and timeline commands, evaluates activity with a local CEL rule engine, optionally blocks at pre-action hooks, and builds forensic case bundles.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "nvidia-openshell",
      "schema_version": 2,
      "name": "NVIDIA OpenShell",
      "vendor": "NVIDIA",
      "url": "https://github.com/NVIDIA/OpenShell",
      "primary_asset": "ai-workload-platforms",
      "description": "NVIDIA OpenShell: Open-source sandbox runtime for autonomous AI agents that isolates agent execution under declarative policies to protect host data, credentials, and infrastructure.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-05",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-workload-platforms",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Runs each autonomous agent in a sandboxed execution environment governed by declarative YAML policies that prevent unauthorized file access, data exfiltration, and uncontrolled network activity.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "oasis",
      "schema_version": 2,
      "name": "Oasis",
      "vendor": "Oasis Security",
      "url": "https://www.oasis.security",
      "primary_asset": "ai-agent-identities",
      "description": "Non-human identity management platform that discovers, governs, and enforces least-privilege access for service accounts, secrets, and AI agents across hybrid cloud.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovers AI agent and non-human identities, ties them to owners, and enforces least-privilege, policy-driven lifecycle controls.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Threat and anomaly detection over agent and identity activity, with continuous audit and policy enforcement.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "obot-mcp-gateway",
      "schema_version": 2,
      "name": "Obot MCP Gateway",
      "vendor": "Obot",
      "url": "https://obot.ai/mcp-gateway-platform/",
      "primary_asset": "ai-orchestration-tools",
      "description": "Obot MCP Gateway: Open-source MCP gateway between AI clients and any MCP server that enforces OAuth and access policies, audits every tool call, and offers a curated catalog of trusted servers.",
      "deployment": [
        "self-hosted",
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-05",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Sits between AI clients and any MCP server, enforcing OAuth and access policies on tool access, auditing every call, and curating a catalog of trusted MCP servers and skills.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "onetrust-ai-governance",
      "schema_version": 2,
      "name": "OneTrust AI Governance",
      "vendor": "OneTrust",
      "url": "https://www.onetrust.com/solutions/ai-governance/",
      "primary_asset": "ai-model",
      "description": "OneTrust AI Governance: Catalogs AI systems, assesses their risk against frameworks such as the EU AI Act and NIST AI RMF, and enforces compliance controls across the AI lifecycle.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO/IEC 27001"
      ],
      "last_reviewed": "2026-07-03",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "govern",
            "identify"
          ],
          "maturity": "primary",
          "note": "Catalogs AI models, datasets, agents, and vendors in a central inventory and maps their risk to control frameworks to maintain ongoing regulatory compliance.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Applies runtime guardrails including prompt and output filtering and policy-based blocking to enforce compliant AI behavior across platforms.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "onyx",
      "schema_version": 2,
      "name": "Onyx",
      "vendor": "Onyx Security",
      "url": "https://onyx.security/",
      "primary_asset": "ai-orchestration-tools",
      "description": "Onyx: Control plane that discovers sanctioned and shadow AI agents, monitors prompts and agent actions in real time, and enforces security policies across enterprise AI use.",
      "deployment": [
        "saas",
        "self-hosted",
        "hybrid"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-30",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "govern",
            "identify",
            "protect",
            "detect",
            "respond"
          ],
          "maturity": "primary",
          "note": "Discovers sanctioned and shadow AI agents, monitors activity with anomaly detection and session replay, lets teams author natural language policies mapped to frameworks such as the EU AI Act, enforces them by sanctioning tools and controlling MCP access, and remediates via the Guardian Agent.",
          "origin": "agent"
        },
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "The Onyx AI Gateway and MCP Gateway centralize cross-provider model traffic and agent tool calls on an inline path, inspecting each request and enforcing tool-call policy, data-class controls, and agent behavior guardrails through alert, block, mask, steer, or ask modes.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Provides visibility into every AI prompt and response across the stack and protects prompts, responses, and agent actions in real time against prompt injection, jailbreaks, data exfiltration, and adversarial manipulation.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Detects shadow AI usage and unapproved model deployments, identifies supply chain risks in agents, MCP servers, models, and AI assets, and probes agents and models for vulnerabilities with automated red teaming.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "opaque",
      "schema_version": 2,
      "name": "Opaque",
      "vendor": "Opaque Systems",
      "url": "https://www.opaque.co/product",
      "primary_asset": "runtime-ai-data",
      "description": "Opaque: Confidential AI platform that runs AI agents and workloads inside hardware-attested confidential VMs in your cloud, keeping data encrypted in memory during processing.",
      "deployment": [
        "hybrid"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-25",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Keeps sensitive AI data encrypted in memory throughout processing inside a hardware-backed trusted execution environment, so data in use stays protected during workload execution.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-workload-platforms",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Runs containerized AI workloads and agents inside confidential computing infrastructure in the customer cloud, with verifiable runtime guarantees for data privacy and policy enforcement.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "openai-guardrails",
      "schema_version": 2,
      "name": "OpenAI Guardrails",
      "vendor": "OpenAI",
      "url": "https://guardrails.openai.com/",
      "primary_asset": "runtime-ai-data",
      "description": "OpenAI Guardrails: Safety framework that validates LLM app inputs and outputs with configurable checks, plus open-weight gpt-oss-safeguard policy classifiers.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Built-in checks screen prompts and model outputs inline through drop-in OpenAI client wrappers, covering moderation, jailbreak detection, PII detection, URL filtering, hallucination detection, off-topic prompts, and custom LLM-based checks configured via a no-code wizard.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "GuardrailAgent applies configured checks to OpenAI Agents SDK agents and raises input and output tripwire exceptions that halt the run when a check fires.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "operant-ai-gatekeeper",
      "schema_version": 2,
      "name": "Operant AI Gatekeeper",
      "vendor": "Operant AI",
      "url": "https://www.operant.ai/platform/ai-gatekeeper",
      "primary_asset": "runtime-ai-data",
      "description": "Operant AI Gatekeeper: Runtime defense that secures live AI apps and agentic workflows, addressing data leakage and rogue agents with in-line redaction and MCP threat blocking.",
      "deployment": [
        "self-hosted",
        "hybrid"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Detects and blocks prompt injections and unauthenticated or unauthorized AI behavior in real time across live AI applications and agents, with in-line enforcement and auto-redaction rather than offline scoring.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Covers Model Context Protocol tooling with detection and access control, defending agent tools built on MCP frameworks across both the runtime and API access layers.",
          "origin": "agent"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Applies trust scoring and fine-grained, identity-aware enforcement to AI non-human identities so only verified entities operate within agentic systems.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "orca",
      "schema_version": 2,
      "name": "Orca",
      "vendor": "Orca Security",
      "url": "https://orca.security/platform/ai-security/ai-spm/",
      "primary_asset": "ai-model",
      "description": "Agentless AI security posture management in the Orca cloud platform that discovers AI models including shadow AI, inventories them, and flags misconfigurations and exposed data.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2",
        "ISO 27001",
        "ISO 27017",
        "ISO 27018",
        "ISO 27701",
        "CSA STAR",
        "FedRAMP Certified Class C",
        "GovRAMP",
        "PCI DSS",
        "GDPR"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "primary",
          "note": "Agentlessly discovers and inventories managed and shadow AI models in an AI and ML bill of materials, and flags model misconfigurations and exposed AI service keys.",
          "origin": "reviewed"
        },
        {
          "asset": "training-data",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Detects sensitive data in AI models and training data and surfaces data-poisoning risk from editable or replaceable training data.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "orcarouter",
      "schema_version": 2,
      "name": "OrcaRouter",
      "vendor": "Continuum AI",
      "url": "https://www.orcarouter.ai/",
      "primary_asset": "ai-gateways-routers",
      "description": "OrcaRouter: AI gateway by Continuum AI that routes prompts across many models through one OpenAI-compatible endpoint, with guardrails and a risk-scored firewall gating agent tool and MCP calls.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-05",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Routes prompts across models through one OpenAI-compatible endpoint and runs a risk-scored agent firewall that grades every tool and MCP call and flags anomalies before actions run.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "oso",
      "schema_version": 2,
      "name": "Oso",
      "vendor": "Oso",
      "url": "https://www.osohq.com/",
      "primary_asset": "ai-agent-identities",
      "description": "Oso: Discovers shadow AI agents across endpoints and browsers, monitors agent sessions through an edge proxy, and alerts on unsanctioned usage and sensitive data.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "primary",
          "note": "Inventories AI agents across endpoints, browsers, and network traffic via EDR scans, a browser extension, and an edge proxy; admins mark agents allowed or disallowed and Oso alerts when unsanctioned agents are detected.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect"
          ],
          "maturity": "primary",
          "note": "Captures prompts, completions, and tool calls for monitored agent sessions and scans them with built-in and custom patterns for secrets and PII such as API keys and credentials.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "palo-alto-ai-spm",
      "schema_version": 2,
      "name": "Palo Alto AI-SPM",
      "vendor": "Palo Alto Networks",
      "url": "https://www.paloaltonetworks.com/prisma/cloud/ai-spm",
      "primary_asset": "ai-model",
      "description": "AI security posture management in Prisma Cloud that discovers and inventories AI models and applications, classifies sensitive training and inference data, and flags data exposure and model risk.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2",
        "ISO 27001",
        "PCI DSS",
        "ENS High"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovers and inventories deployed AI models and their cloud resources, surfaces shadow and unauthorized models, and flags misconfigured or overprivileged models and supply-chain vulnerabilities.",
          "origin": "reviewed"
        },
        {
          "asset": "training-data",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Classifies where sensitive data lives in training and reference data and monitors data flows for exposure and poisoning risk.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "pangea",
      "schema_version": 2,
      "name": "Pangea",
      "vendor": "Pangea",
      "url": "https://pangea.cloud",
      "primary_asset": "runtime-ai-data",
      "description": "AI security guardrails that inspect prompts, responses, and agent activity to block prompt injection, redact sensitive data, and stop malicious content across LLM and agent traffic.",
      "deployment": [
        "saas"
      ],
      "status": "acquired",
      "compliance_attestations": null,
      "acquirer": "CrowdStrike",
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Inspects prompts and responses to detect prompt injection, redact sensitive data, and block malicious content.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Guards agent activity with pre-plan, pre-tool, and post-tool checks and runtime monitoring.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "patronus-ai",
      "schema_version": 2,
      "name": "Patronus AI",
      "vendor": "Patronus AI",
      "url": "https://www.patronus.ai/",
      "primary_asset": "runtime-ai-data",
      "description": "Patronus AI: LLM evaluation and guardrails platform whose point-in-time evaluators detect prompt injection, toxicity, PII, and harmful or hallucinated content in LLM inputs and outputs.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect"
          ],
          "maturity": "primary",
          "note": "Point-in-time guardrail evaluators flag prompt injection, toxicity, PII, and harmful or hallucinated content in LLM inputs and outputs, leaving the blocking decision to the application.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "The same evaluators check the inputs and outputs of individual components in an agentic LLM pipeline.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "permiso-ai-security",
      "schema_version": 2,
      "name": "Permiso AI Security",
      "vendor": "Permiso Security",
      "url": "https://permiso.io/ai-security",
      "primary_asset": "ai-agent-identities",
      "description": "Permiso AI Security: Capability of the Permiso identity platform that discovers AI agents, attributes runs and tool calls to identities, and detects anomalous agent behavior in real time.",
      "deployment": [
        "saas"
      ],
      "status": "acquired",
      "compliance_attestations": null,
      "acquirer": "Okta",
      "last_reviewed": "2026-07-30",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "detect",
            "respond"
          ],
          "maturity": "primary",
          "note": "Discovers AI agents in cloud workloads and code repositories, attributes every run, event, and tool call to a human, non-human, or AI identity through the Universal Identity Graph, detects anomalous agent behavior, and enforces containment including kill switches.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Monitors MCP invocations and tool calls tied to agent identities; the SandyClaw sandbox analyzes agent skills before they run in the environment, recording actions, tool calls, and downstream requests.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "permit-io-ai-access-control",
      "schema_version": 2,
      "name": "Permit.io AI Access Control",
      "vendor": "Permit.io",
      "url": "https://www.permit.io/ai-access-control",
      "primary_asset": "ai-agent-identities",
      "description": "Permit.io AI Access Control: Authorization for AI agents that assigns machine identities, enforces fine-grained access and consent on agent actions and RAG data, and authorizes every MCP tool call.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type II"
      ],
      "last_reviewed": "2026-06-24",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Assigns machine identities to AI agents and enforces per-agent authorization and consent over their access to tools and resources, with humans delegating bounded authority.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "An MCP gateway proxy authorizes every agent tool call against fine-grained policy, blocks denied calls before they reach the server, and logs each decision.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Applies attribute-based access control to RAG queries with pre-query and post-query filtering to prevent unauthorized AI access to retrieved data.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "phala-confidential-ai-cloud",
      "schema_version": 2,
      "name": "Phala Confidential AI Cloud",
      "vendor": "Phala",
      "url": "https://phala.com/",
      "primary_asset": "ai-workload-platforms",
      "description": "Phala Confidential AI Cloud: Runs agents, private LLM inference, and GPU jobs inside hardware-backed TEEs, keeping prompts and model weights private with verifiable attestation.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-05",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-workload-platforms",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Confidential-compute platform that runs agents, private LLM inference, and GPU jobs inside hardware-backed trusted execution environments, with attestation that proves what code ran.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Runs agent backends in confidential VMs with sealed keys and private memory so prompts, secrets, and inference data stay protected in use.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "pillar",
      "schema_version": 2,
      "name": "Pillar",
      "vendor": "Pillar Security",
      "url": "https://www.pillar.security/platform",
      "primary_asset": "runtime-ai-data",
      "description": "AI security platform for the agentic workforce that inventories agents, models, and MCP servers, red-teams them, and runs adaptive runtime guardrails to block prompt attacks and data egress.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Adaptive runtime guardrails inspect AI inputs and outputs, detect malicious intent, and use taint analysis to block PII and secret egress in real time.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Discovers and inventories agents, models, MCP servers, and tools including shadow AI, maps the permissions and connections of each agent, and red-teams them for exploitable flaws.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "ping-identity-for-ai",
      "schema_version": 2,
      "name": "Ping Identity for AI",
      "vendor": "Ping Identity",
      "url": "https://www.pingidentity.com/en/solution/agentic-ai-identity.html",
      "primary_asset": "ai-agent-identities",
      "description": "Ping Identity for AI: Runtime identity for AI agents that onboards them as a first-class identity type, enforces real-time authorization on every action, and detects and risk-scores agents at runtime.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001",
        "ISO 27017",
        "ISO 27018",
        "ISO 22301"
      ],
      "last_reviewed": "2026-06-14",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Onboards AI agents as a first-class identity type, enforces contextual real-time authorization on every agent action through Agent IAM Core and the Agent Gateway, and detects and risk-scores agents at runtime via Agent Detection.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "pluto-security",
      "schema_version": 2,
      "name": "Pluto Security",
      "vendor": "Pluto Security",
      "url": "https://pluto.security/",
      "primary_asset": "ai-orchestration-tools",
      "description": "Pluto Security: AI workspace security platform that agentlessly discovers the AI builders, agents, and MCP tools employees use, scores their risk, and enforces guardrails on AI building activity.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001:2022"
      ],
      "last_reviewed": "2026-06-15",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Connects agentlessly to existing security and infrastructure systems to discover which AI builders, agents, MCP servers, plugins, and IDEs are in use, scores their risk, and enforces real-time guardrails on AI building activity.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Integrates with Claude Enterprise through the Anthropic Compliance API so security and compliance teams can monitor and risk-score enterprise AI assistant activity inside Pluto.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "pointguard-ai",
      "schema_version": 2,
      "name": "PointGuard AI",
      "vendor": "PointGuard AI",
      "url": "https://pointguardai.com/",
      "primary_asset": "ai-orchestration-tools",
      "description": "PointGuard AI: Security platform for AI agents, MCP, and models that discovers AI, runs adversarial testing and posture management, and enforces runtime guardrails via an MCP security gateway.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-13",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovers AI agents and MCP, enforces runtime guardrails via the Agent Control Plane and MCP Security Gateway, and applies centralized policy enforcement across the AI stack.",
          "origin": "agent"
        },
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Adaptive red teaming and security posture management test agents and models for prompt injection, jailbreaks, and misconfigurations before deployment.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "The MCP Security Gateway inspects prompts, tool calls, and responses in real time, blocking unsafe instructions, with integrated AI-native DLP that can block, mask, or redact sensitive data in outbound responses and tool outputs.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "polymer",
      "schema_version": 2,
      "name": "Polymer",
      "vendor": "Polymer",
      "url": "https://www.polymerhq.io/dspm/",
      "primary_asset": "runtime-ai-data",
      "description": "Polymer: Runtime data-security platform whose browser extension applies real-time DLP controls and monitoring to employee interactions with ChatGPT, Claude, and other LLM tools.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type II"
      ],
      "last_reviewed": "2026-06-25",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "A browser extension applies real-time controls and inline redaction over employee prompts to ChatGPT, Claude, and other LLM tools, and audits every AI interaction.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "pomerium",
      "schema_version": 2,
      "name": "Pomerium",
      "vendor": "Pomerium",
      "url": "https://www.pomerium.com/secure-ai-agent-access",
      "primary_asset": "ai-agent-identities",
      "description": "Pomerium: Self-hosted, policy-driven access control that brokers identity-aware, context-based, least-privilege access for AI agents and LLM systems in place of static credentials.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-14",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Brokers identity-aware, context-based, least-privilege access for AI agents and LLM systems, replacing static long-lived credentials with policy-driven scoped access enforced in the customer environment.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "portal26",
      "schema_version": 2,
      "name": "Portal26",
      "vendor": "Portal26",
      "url": "https://portal26.ai/generative-ai-trism-platform/",
      "primary_asset": "ai-orchestration-tools",
      "description": "Portal26: AI TRiSM platform that finds shadow AI and agent usage on the network, inspects prompts inline, and enforces AI usage policy with a forensic audit trail.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-29",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "govern"
          ],
          "maturity": "primary",
          "note": "Evaluates domains appearing on the network to detect AI tools and agents in use, including AI embedded inside other applications, and gives the organization a place to author AI and agent usage policy and enforce it against what the discovery engine finds.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Prompts and responses moving to and from AI tools are inspected inline for sensitive data, attack patterns are recognized as they occur, and the interaction record is retained in a certified audit vault for later investigation.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "portkey",
      "schema_version": 2,
      "name": "Portkey",
      "vendor": "Portkey",
      "url": "https://portkey.ai",
      "primary_asset": "ai-gateways-routers",
      "description": "AI gateway and control plane that routes requests across many LLM providers and runs guardrails on inputs and outputs to catch prompt injection, PII leaks, and unsafe content.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "acquired",
      "compliance_attestations": [
        "SOC 2",
        "ISO 27001",
        "HIPAA",
        "GDPR"
      ],
      "acquirer": "Palo Alto Networks",
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "agent",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Routes traffic to many LLM providers with input and output guardrails and request-level observability.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Guardrails check prompts and responses for prompt injection, PII, and unsafe content.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "pragatix-ai-security-suite",
      "schema_version": 2,
      "name": "Pragatix AI Security Suite",
      "vendor": "AGAT Software",
      "url": "https://agatsoftware.com/ai-security-suite/",
      "primary_asset": "ai-orchestration-tools",
      "description": "Pragatix AI Security Suite: Real-time AI proxy and agent oversight layer that inspects prompts and responses, brokers agent access to MCP tools, routes AI API traffic, and vets models before use.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-08-20",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Prompt Guardian is an in-line proxy over public and private AI services that inspects prompts and responses, classifies sensitive or regulated data, and applies risk-based policy per user, department, and data sensitivity. It also surfaces unsanctioned AI tool usage across the organization.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "detect",
            "protect"
          ],
          "maturity": "primary",
          "note": "Guardian Agent discovers AI agents across SaaS, homegrown, embedded, endpoint, and developer environments, maps them to their connected tools and systems, traces their decisions and data access, and blocks or requires approval for high-risk actions at runtime.",
          "origin": "agent"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "The MCP Gateway brokers agent identities and permissions, granting policy-based access only to approved tools, data, and systems, with just-in-time access and intent-based authorization. Agent ownership is inventoried centrally and agent tool use is tracked in audit trails.",
          "origin": "agent"
        },
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "The AI Gateway concentrates AI API traffic through one access layer, applying policy over which services may be reached and by whom, managing provider credentials across hosted and local model services, and tracking consumption per user, team, project, and model.",
          "origin": "agent"
        },
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "detect",
            "protect"
          ],
          "maturity": "secondary",
          "note": "Model Guardian inventories internal, external, and open-source models, checks their provenance, licensing, and exposure, red teams them against jailbreak and misuse scenarios, and gates their use behind an approval workflow that records the supporting evidence.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "prisma-airs",
      "schema_version": 2,
      "name": "Prisma AIRS",
      "vendor": "Palo Alto Networks",
      "url": "https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security",
      "primary_asset": "runtime-ai-data",
      "description": "Palo Alto Networks’ AI security platform; its AI Runtime Security inspects prompts and responses inline to block prompt injection, data leakage, and unsafe model output.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2",
        "ISO 27001",
        "PCI DSS",
        "ENS High"
      ],
      "last_reviewed": "2026-07-17",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Inline inspection of prompts and responses for injection, leakage, and unsafe output.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "API and network intercept for AI traffic.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "Model scanning via integrated Protect AI technology.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "privasapien-perai",
      "schema_version": 2,
      "name": "PrivaSapien PERAI",
      "vendor": "PrivaSapien",
      "url": "https://privasapien.com/",
      "primary_asset": "runtime-ai-data",
      "description": "PrivaSapien PERAI: Platform pairing privacy-enhancing technologies with AI red teaming, inline inference guardrails, and runtime controls for AI agents and their tool calls.",
      "deployment": [
        "unknown"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-09-03",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "The Safe AI Inference tier places small-language-model guardrails inline on prompts and retrieval pipelines, pseudonymizing personal data before it reaches a model and screening prompts for attacks. Named components include FireLM, PrivacyRAI, SecureRAI, ContextRAI, and SafeRAI.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "The Trusted Agents tier firewalls agent prompts and tool-calling context, checks whether an agent behaves as its description claims, monitors agent-to-model interactions, and routes high-risk actions to a human. Named components include ClawTron, ToolClaw, LLMClaw, ContextClaw, and Claw X-Ray.",
          "origin": "agent"
        },
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "detect",
            "govern"
          ],
          "maturity": "secondary",
          "note": "Agent Turing runs white-box, black-box, and multi-stage adversarial testing against models for privacy, security, safety, fairness, and explainability, and results populate a catalogue of AI assets with risk ratings. EthicsTron turns findings into impact reports mapped to named AI regulations.",
          "origin": "agent"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "secondary",
          "note": "Maintains a listing of trusted tools and agents, analyses an agent description for security problems, and checks at runtime whether an agent is acting within what its description claims before its actions are allowed to proceed.",
          "origin": "agent"
        },
        {
          "asset": "training-data",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Privacy-preserving machine learning supplies training data that has been anonymized or synthesized rather than used raw, drawing on differential privacy, k-anonymity, t-closeness, synthetic generation, and multi-party computation.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "private-pursuit",
      "schema_version": 2,
      "name": "Private Pursuit",
      "vendor": "Lorica Cybersecurity",
      "url": "https://lorica.ai/platform/",
      "primary_asset": "ai-model",
      "description": "Private Pursuit: Lorica Cybersecurity platform that runs confidential AI inference and database queries on encrypted models and data using fully homomorphic encryption, without decrypting them.",
      "deployment": [
        "hybrid"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-25",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Runs confidential AI inference directly on sensitive AI models using fully homomorphic encryption, so the model and queries stay encrypted and private during computation.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Keeps inference and query data encrypted while in use through fully homomorphic encryption, never decrypting it during computation.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "prompt-security",
      "schema_version": 2,
      "name": "Prompt Security",
      "vendor": "Prompt Security",
      "url": "https://prompt.security",
      "primary_asset": "runtime-ai-data",
      "description": "Runtime GenAI security that screens employee AI use, homegrown LLM apps, and agents for prompt injection, data leakage, and shadow AI, with inline blocking and redaction.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "acquired",
      "compliance_attestations": null,
      "acquirer": "SentinelOne",
      "last_reviewed": "2026-07-17",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Inline screening of prompts and responses for prompt injection, jailbreaks, and data leakage, with blocking and redaction.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Protection for homegrown LLM applications via API, SDKs, and a centralized gateway.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Agent runtime controls and MCP gateway security over what agents can do.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "promptarmor",
      "schema_version": 2,
      "name": "PromptArmor",
      "vendor": "PromptArmor",
      "url": "https://www.promptarmor.com/",
      "primary_asset": "ai-orchestration-tools",
      "description": "PromptArmor: AI risk intelligence platform that discovers AI in third-party vendors, scores its risk against frameworks, tests for indirect prompt injection, and monitors vendors for AI changes.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-24",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovers and inventories the AI applications, agents, MCP servers, and connectors that vendors run, scores their risk across 26 vectors mapped to NIST AI RMF, the OWASP LLM Top 10, and MITRE ATLAS, and continuously monitors them for new AI features and emerging vulnerabilities.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Tests vendor AI applications for indirect prompt injection and the data-exfiltration vectors it creates, and gives visibility into which vendors train on customer data and how data flows into AI subprocessors.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "promptfoo",
      "schema_version": 2,
      "name": "Promptfoo",
      "vendor": "Promptfoo",
      "url": "https://www.promptfoo.dev/",
      "primary_asset": "ai-model",
      "description": "Promptfoo: Open-source CLI and library for evaluating and red-teaming LLM applications, generating application-specific attacks such as prompt injections, jailbreaks, and data and PII leaks.",
      "deployment": [
        "self-hosted"
      ],
      "status": "acquired",
      "compliance_attestations": null,
      "acquirer": "OpenAI",
      "last_reviewed": "2026-07-17",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "detect"
          ],
          "maturity": "primary",
          "note": "Automated red teaming simulates real users and generates application-specific attacks, including direct and indirect prompt injections, jailbreaks tailored to deployed guardrails, data and PII leaks, and toxic content generation.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Red teaming targets agents and RAG applications and surfaces insecure tool use and business rule violations. Declarative evaluations benchmark prompts, models, and applications during development.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "promptpurify",
      "schema_version": 2,
      "name": "PromptPurify",
      "vendor": "SecureLayer7",
      "url": "https://github.com/securelayer7/PROMPTPurify",
      "primary_asset": "runtime-ai-data",
      "description": "PromptPurify: Open-source prompt-injection guard for LLM chat applications, pairing a compact CPU-only classifier with a deterministic structural firewall.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-09-03",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Scores each user message before it reaches the model, returning a value the application uses to hard-block above a high threshold and flag for review below it. A separate deterministic firewall neutralizes Unicode tricks, fences roles, and screens output for exfiltration.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "proofpoint-unified-ai-security",
      "schema_version": 2,
      "name": "Proofpoint Unified AI Security",
      "vendor": "Proofpoint",
      "url": "https://www.proofpoint.com/us/platform/ai-security",
      "primary_asset": "runtime-ai-data",
      "description": "Proofpoint Unified AI Security: Runtime visibility and policy enforcement for employee GenAI use, autonomous agents, and MCP servers, built on the acquired Acuvity technology.",
      "deployment": [
        "hybrid"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2",
        "ISO 27001",
        "ISO 42001"
      ],
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "AI Access Security discovers AI tools in use across the enterprise, inspects employee AI interactions at runtime, enforces context-aware policies on prompts and outputs, and records audit evidence of AI usage.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Agentic AI Security applies intent-based detection and behavioral anomaly detection to agent workflows; AI MCP Security discovers shadow MCP servers and enforces authentication and content inspection at the MCP boundary, backed by a registry of approved servers.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "protect-ai",
      "schema_version": 2,
      "name": "Protect AI",
      "vendor": "Protect AI",
      "url": "https://protectai.com",
      "primary_asset": "ai-model",
      "description": "A unified platform that secures the AI lifecycle: model scanning (Guardian), automated red teaming (Recon), and runtime protection (Layer).",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "acquired",
      "compliance_attestations": null,
      "acquirer": "Palo Alto Networks",
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Guardian scans models from registries and hubs for unsafe code and threats.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "primary",
          "note": "Recon runs automated red teaming against AI applications and agents.",
          "origin": "reviewed"
        },
        {
          "asset": "training-data",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": null,
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Layer adds runtime protection for LLM applications.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "protecto",
      "schema_version": 2,
      "name": "Protecto",
      "vendor": "Protecto",
      "url": "https://www.protecto.ai/",
      "primary_asset": "runtime-ai-data",
      "description": "Context security for agentic AI that sits between enterprise data and AI systems, applying role-based access and dynamic masking so agents see only the data each user is permitted at inference.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Sits between enterprise data and LLMs, agents, and MCP pipelines, applying dynamic masking at inference and keeping a full audit trail of who accessed what.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Role-based access for AI agents, so each agent exposes only the data the requesting user is permitted to see.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "pynt-llm-security",
      "schema_version": 2,
      "name": "Pynt LLM Security",
      "vendor": "Pynt",
      "url": "https://www.pynt.io/product/llm-security",
      "primary_asset": "ai-model",
      "description": "Pynt LLM Security: API security testing that discovers LLM APIs hidden in code and scans LLM flows for prompt injection and misuse, generating contextual attacks against the API surface.",
      "deployment": [
        "saas"
      ],
      "status": "acquired",
      "compliance_attestations": null,
      "acquirer": "Radware",
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovers and inventories LLM APIs hidden in code, then scans LLM flows for vulnerabilities such as prompt injection and misuse through the API.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Generates synthetic traffic to drive contextual prompt-injection and misuse tests against live LLM request and response flows.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "pyrit",
      "schema_version": 2,
      "name": "PyRIT",
      "vendor": "Microsoft",
      "url": "https://github.com/microsoft/PyRIT",
      "primary_asset": "ai-model",
      "description": "PyRIT: Open-source Microsoft framework for automated and human-led AI red teaming, assessing the security and safety of generative AI systems with attack strategies, scenarios, and scoring.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "detect"
          ],
          "maturity": "primary",
          "note": "Runs single-turn and multi-turn attack strategies such as Crescendo, TAP, and Skeleton Key against generative AI targets, with standardized scenarios covering content harms and data leakage and flexible scoring of responses.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "qualys-totalai",
      "schema_version": 2,
      "name": "Qualys TotalAI",
      "vendor": "Qualys",
      "url": "https://www.qualys.com/apps/totalai/",
      "primary_asset": "ai-workload-platforms",
      "description": "Qualys TotalAI: Discovers and inventories AI and LLM workloads, then scans models for jailbreak, prompt injection, and other OWASP LLM Top 10 risks.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "FedRAMP Moderate"
      ],
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-workload-platforms",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovers and inventories AI workloads, including software packages and GPU hardware, across production and development environments, and applies AI-specific vulnerability detections prioritized with TruRisk to harden the underlying infrastructure.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "detect"
          ],
          "maturity": "primary",
          "note": "Scans onboarded LLM models for jailbreak susceptibility, prompt injection, bias, unsafe output, and other risks mapped to the OWASP LLM Top 10, with reporting aligned to MITRE ATLAS.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "quilrai-platform",
      "schema_version": 2,
      "name": "QuilrAI Platform",
      "vendor": "Quilr",
      "url": "https://quilr.ai/platform",
      "primary_asset": "ai-orchestration-tools",
      "description": "QuilrAI Platform: Discovers AI agents and shadow AI, then routes every LLM and MCP call through gateways that check identity, redact sensitive data, and block policy violations inline.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type II"
      ],
      "last_reviewed": "2026-07-29",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent",
        "compliance_attestations": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "govern",
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Inventories every agent and shadow AI tool across endpoints, browsers, and MCP chains. Policy is authored in the product as a Guardian Agent definition covering permissions, redaction, and scope, then enforced on each tool call by an MCP gateway that decides the call before it executes.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Every prompt and tool call traverses the platform, where purpose alignment and scope checks run alongside PII redaction, and the request is blocked, allowed, or modified before a result returns to the agent.",
          "origin": "agent"
        },
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "A single OpenAI-compatible endpoint fronts a large model catalog, applying identity checks, rate limits, and guardrails to each request before routing it, and the same guardrails scan the provider response on the return path so a violation is caught in both directions.",
          "origin": "agent"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "secondary",
          "note": "Maintains the record of which agents exist and what scope each holds, then ties every request to a chain running from user to agent to task, so an agent operates within the identity granted for that call instead of inheriting broad standing access.",
          "origin": "agent"
        },
        {
          "asset": "ai-model",
          "functions": [
            "identify"
          ],
          "maturity": "adjacent",
          "note": "Discovery covers the model connections in use alongside agents and MCP servers, so unsanctioned model endpoints reached from endpoints or cloud are surfaced. Inventory only, with no control applied to the model itself.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "radware-agentic-ai-protection",
      "schema_version": 2,
      "name": "Radware Agentic AI Protection",
      "vendor": "Radware",
      "url": "https://www.radware.com/products/agentic-ai-protection/",
      "primary_asset": "ai-agent-identities",
      "description": "Radware Agentic AI Protection: Agentic security posture management that discovers AI agents and uses runtime behavioral analysis to detect and block prompt injection, tool misuse, and rogue agents.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-14",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "detect",
            "protect"
          ],
          "maturity": "primary",
          "note": "Discovers AI agents and the tools they access, then applies runtime behavioral analysis to detect and mitigate prompt injection, tool misuse, and rogue or compromised agents.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "ray-security-shadow-ai",
      "schema_version": 2,
      "name": "Ray Security Shadow AI",
      "vendor": "Ray Security",
      "url": "https://raysecurity.io/use-cases/find-and-manage-shadow-ai/",
      "primary_asset": "ai-agent-identities",
      "description": "Ray Security Shadow AI: Agentless discovery that finds unsanctioned AI tools and agents accessing enterprise data, maps what each accessed, and applies access controls or blocks unsanctioned AI.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-24",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "detect",
            "protect"
          ],
          "maturity": "primary",
          "note": "Continuously and agentlessly discovers AI agents and shadow-AI tools accessing enterprise data, maps what each accessed, and applies access controls, data restrictions, or blocking to unsanctioned AI.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Governs what data AI tools and agents can access based on sensitivity, context, and real usage.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "realmguard",
      "schema_version": 2,
      "name": "RealmGuard",
      "vendor": "Realm Labs",
      "url": "https://www.realmlabs.ai/realmguard",
      "primary_asset": "ai-model",
      "description": "RealmGuard: AI guardrails that read model internal reasoning (Deep Neural Inspection) to catch harmful content, prompt injection, and policy violations across prompts and responses.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "agent",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "detect"
          ],
          "maturity": "primary",
          "note": "Deep Neural Inspection maps model internals and reads activity during inference, catching drift, manipulation, and silent failures while they are still inside the inference loop rather than judging output strings after the fact.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Guardrails inspect prompts and responses in real time and block harmful content, prompt injection, and policy violations before they reach users, across 20-plus categories and multiple modalities.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "reco",
      "schema_version": 2,
      "name": "Reco",
      "vendor": "Reco",
      "url": "https://www.reco.ai/",
      "primary_asset": "ai-agent-identities",
      "description": "Reco: SaaS security platform that discovers shadow AI tools and AI agents, monitors agent permissions and behavior, and governs generative AI usage across enterprise apps.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001",
        "ISO 42001",
        "CSA STAR Level 1",
        "GDPR"
      ],
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-workload-platforms",
          "functions": [
            "identify"
          ],
          "maturity": "primary",
          "note": "Discovers shadow AI tools and embedded AI features across SaaS apps and supports security teams in assessing generative AI usage across the enterprise.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "primary",
          "note": "Maps every AI agent to an owner and a risk score, flags overpermissioned and orphaned agent identities, supports least privilege across the agent fleet, and surfaces policy violations.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Tracks information movement from SaaS apps to unauthorized AI systems and monitors what employees share with AI platforms, classifying exposure risk by data sensitivity.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "rein-security",
      "schema_version": 2,
      "name": "Rein Security",
      "vendor": "Rein Security",
      "url": "https://reinsec.io/",
      "primary_asset": "ai-orchestration-tools",
      "description": "Rein Security: Enterprise AI-agent security platform whose sidecar traces the full execution chain of agent actions and enforces dynamic guardrails against attacks, errors, and hallucinations.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "detect",
            "protect",
            "identify"
          ],
          "maturity": "primary",
          "note": "A sidecar monitors enterprise agents at runtime, capturing the full execution chain (prompts, service calls, tool invocations, resources touched) and enforcing learned-baseline guardrails on deviations. Includes real-time agent inventory and shadow AI detection with auto-discovery.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect",
            "protect"
          ],
          "maturity": "secondary",
          "note": "Screens agent interactions for prompt injection, misconfigured tools, user mistakes, and AI hallucinations, enforcing guardrails on deviations from learned normal behavior rather than known threat signatures.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "relyance-ai-spm",
      "schema_version": 2,
      "name": "Relyance AI-SPM",
      "vendor": "Relyance AI",
      "url": "https://www.relyance.ai/product/ai-spm",
      "primary_asset": "ai-model",
      "description": "Relyance AI-SPM: AI security posture management that discovers AI models, agents, and MCP servers into a unified inventory, maps agent-to-data relationships, and monitors continuously for risk.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001"
      ],
      "last_reviewed": "2026-06-25",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify"
          ],
          "maturity": "primary",
          "note": "Discovers and inventories first-party and third-party AI models alongside other AI assets in a unified inventory.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "Inventories AI agents, tools, and MCP servers alongside non-AI assets and maps their relationships to data.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Continuously monitors AI-to-data flows with policy-based alerting and contextual remediation recommendations.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "repello-ai",
      "schema_version": 2,
      "name": "Repello AI",
      "vendor": "Repello AI",
      "url": "https://repello.ai/",
      "primary_asset": "ai-model",
      "description": "Enterprise AI security and red-teaming platform that discovers AI assets, runs adversarial attack simulations against models and apps, and adds runtime protection and MCP visibility.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovers AI assets and runs ARTEMIS adversarial attack simulations against models and applications across RAG and agent workflows.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "ARGUS adds AI runtime security, and an MCP gateway provides visibility into MCP traffic.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "riscosity",
      "schema_version": 2,
      "name": "Riscosity",
      "vendor": "Riscosity",
      "url": "https://www.riscosity.com/product",
      "primary_asset": "runtime-ai-data",
      "description": "Riscosity: Data-flow firewall that discovers the AI vendors and chatbots applications and employees send data to, and redacts or blocks sensitive data in transit before it reaches them.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type II"
      ],
      "last_reviewed": "2026-06-25",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Detects and redacts or redirects sensitive fields in data flowing to AI vendors and chatbots, blocking flows that violate business rules or regulatory requirements before data leaves.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "Automatically discovers and catalogs every AI vendor, model, and chatbot that applications and end-users communicate with, surfacing shadow AI.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "robust-intelligence",
      "schema_version": 2,
      "name": "Robust Intelligence",
      "vendor": "Cisco",
      "url": "https://www.cisco.com/site/us/en/products/security/ai-defense/index.html",
      "primary_asset": "ai-model",
      "description": "Algorithmic red teaming and runtime guardrails for AI models and apps: tests models against attacks and screens prompts, responses, and agent workflows. Now part of Cisco AI Defense.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "acquired",
      "compliance_attestations": null,
      "acquirer": "Cisco",
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Algorithmic red teaming validates models against attack techniques, with runtime guardrails enforcing protection.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "AI runtime guardrails screen prompts, responses, and agent workflows.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "adjacent",
          "note": "Supply chain scanning of model files, repositories, and MCP servers and tools.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "rubrik-agent-cloud",
      "schema_version": 2,
      "name": "Rubrik Agent Cloud",
      "vendor": "Rubrik",
      "url": "https://www.rubrik.com/products/rubrik-agent-cloud",
      "primary_asset": "runtime-ai-data",
      "description": "Rubrik Agent Cloud: Monitors enterprise AI agents, applies SAGE semantic guardrails in real time, and rewinds destructive agent actions.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "SOC 1 Type 2",
        "ISO 27001",
        "ISO 27017",
        "ISO 27018",
        "ISO 27701",
        "ISO 42001",
        "HIPAA",
        "HITRUST",
        "GDPR"
      ],
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "recover"
          ],
          "maturity": "primary",
          "note": "Agent Monitor discovers deployed agents and tracks how they interact with data, identities, and applications. Agent Rewind undoes unwanted or destructive agent actions.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect",
            "protect"
          ],
          "maturity": "primary",
          "note": "The SAGE engine, unveiled at RSAC 2026, uses a custom small language model to interpret natural language policies, semantically evaluate agent interactions in real time, detect policy violations, and enforce safe boundaries on agent behavior.",
          "origin": "agent"
        },
        {
          "asset": "ai-generated-code",
          "functions": [
            "recover"
          ],
          "maturity": "secondary",
          "note": "Agent Cloud for Claude, generally available as of June 2026, rolls back unintended Claude agent actions and recovers affected code along with the agent configuration, including for Claude Code.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "runlayer",
      "schema_version": 2,
      "name": "Runlayer",
      "vendor": "Runlayer",
      "url": "https://www.runlayer.com/",
      "primary_asset": "ai-orchestration-tools",
      "description": "Runlayer: MCP security gateway that vets servers and skills, screens each tool call for threats, and ties agent access to enterprise SSO with audit logs.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Gateway and private registry for MCP servers, skills, and agents. Scans each server release for vulnerabilities and permission drift before approval, screens calls in real time for tool poisoning, rug pulls, and command injection, and keeps complete audit trails.",
          "origin": "agent"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Replaces personal API keys with SSO, SCIM, and group sync through Okta or Entra, applying conditional access, revocation, and fine-grained permissions to user, team, and agent connections to MCP servers.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect",
            "protect"
          ],
          "maturity": "secondary",
          "note": "Multi-tier detectors inspect tool-call traffic in real time and flag policy, compliance, and data-leak risks before requests reach downstream tools.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "sailpoint-agent-identity-security",
      "schema_version": 2,
      "name": "SailPoint Agent Identity Security",
      "vendor": "SailPoint",
      "url": "https://www.sailpoint.com/products/agent-identity-security",
      "primary_asset": "ai-agent-identities",
      "description": "SailPoint Agent Identity Security: Governs AI agents as first-class identities, aggregating them across clouds and agent platforms, aligning ownership with role changes, and reviewing their access.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 1",
        "SOC 2",
        "SOC 3",
        "ISO 27001",
        "ISO 27017",
        "ISO 27018",
        "ISO 27701",
        "CSA STAR Level 1"
      ],
      "last_reviewed": "2026-06-13",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "govern"
          ],
          "maturity": "primary",
          "note": "Aggregates AI agents across clouds and agent platforms as governed identities, aligns ownership with role changes, and reviews and revokes their access.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "salt-agentic-security-platform",
      "schema_version": 2,
      "name": "Salt Agentic Security Platform",
      "vendor": "Salt Security",
      "url": "https://salt.security/platform",
      "primary_asset": "ai-orchestration-tools",
      "description": "Salt Agentic Security Platform: Discovers and maps the agents, MCP servers, and APIs across an environment, then monitors their runtime behavior to detect and stop abusive agent activity.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-03",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovers and maps every AI agent, MCP server, and API across the environment, stops agents that overstep, and detects abuse and active attacks in real time across the full graph.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "saviynt-identity-security-for-ai-agents",
      "schema_version": 2,
      "name": "Saviynt Identity Security for AI Agents",
      "vendor": "Saviynt",
      "url": "https://saviynt.com/products/identity-security-for-ai",
      "primary_asset": "ai-agent-identities",
      "description": "Saviynt Identity Security for AI Agents: Identity control plane that discovers AI agents and MCP servers, governs their lifecycle and ownership, and enforces real-time authorization for agent access.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "FedRAMP Moderate",
        "SOC 1 Type 2",
        "SOC 2 Type 2",
        "ISO 27001",
        "ISO 27017",
        "PCI DSS"
      ],
      "last_reviewed": "2026-06-14",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "govern",
            "protect"
          ],
          "maturity": "primary",
          "note": "Discovers and inventories AI agents, governs their lifecycle and human ownership with audit-ready compliance, and enforces real-time authorization for agent access to applications and data from one control plane.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "secondary",
          "note": "Discovers the MCP servers and tools agents use and gates agent access to them through the Agent Access Gateway.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "securiti",
      "schema_version": 2,
      "name": "Securiti",
      "vendor": "Securiti",
      "url": "https://securiti.ai/",
      "primary_asset": "training-data",
      "description": "Data and AI security command center that discovers and classifies sensitive data across the enterprise and runs context-aware LLM firewalls over AI prompts, retrieval, and responses.",
      "deployment": [
        "saas"
      ],
      "status": "acquired",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001",
        "ISO 27701"
      ],
      "acquirer": "Veeam",
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "agent",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "training-data",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Discovers and classifies sensitive data across cloud and SaaS, including shadow assets, and governs how that data is used in AI.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Context-aware LLM firewalls inspect prompts, retrieval, and responses to protect AI interactions.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "semgrep",
      "schema_version": 2,
      "name": "Semgrep",
      "vendor": "Semgrep",
      "url": "https://semgrep.dev/products/semgrep-code/",
      "primary_asset": "ai-generated-code",
      "description": "Static analysis platform that scans code regardless of who or what wrote it, with a Guardian mode and Multimodal AI that find and help fix vulnerabilities in AI-generated code as it lands.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-generated-code",
          "functions": [
            "detect",
            "protect"
          ],
          "maturity": "primary",
          "note": "Scans AI-generated code as it is written and combines static analysis with AI reasoning (Multimodal) to find vulnerabilities and suggest fixes in pull requests, with Cursor and Claude Code plugins.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "sentra",
      "schema_version": 2,
      "name": "Sentra",
      "vendor": "Sentra",
      "url": "https://www.sentra.io/",
      "primary_asset": "training-data",
      "description": "Sentra: Agentless DSPM that discovers, classifies, and governs sensitive data across the estate, including the training sets, RAG stores, and Copilot and Bedrock data that AI applications touch.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001",
        "TX-RAMP Level 2",
        "GDPR"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "training-data",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovers and classifies sensitive data across cloud and on-prem at petabyte scale without copying it out of the environment, controls access to it, and adds data detection and response across the datasets AI and Copilot or Bedrock can reach.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "singulr-ai",
      "schema_version": 2,
      "name": "Singulr AI",
      "vendor": "Singulr AI",
      "url": "https://singulr.ai/",
      "primary_asset": "ai-agent-identities",
      "description": "Singulr AI: Enterprise control plane that discovers AI agents and services, maps their tool and data dependencies, and enforces runtime governance and security policy on AI interactions.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO/IEC 27001"
      ],
      "last_reviewed": "2026-07-03",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Discovers every AI agent and its tool, data, and MCP dependencies, then defines and enforces policies scoped by agent type, data sensitivity, and tool access.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Runtime control enforces against unapproved AI services, redacts sensitive data before exposure, and controls prompt injection at the browser and endpoint.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Surfaces control-drift metrics and scans MCP servers for vulnerabilities across the agent topology.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "skyflow-for-genai",
      "schema_version": 2,
      "name": "Skyflow for GenAI",
      "vendor": "Skyflow",
      "url": "https://www.skyflow.com/product/skyflow-for-genai",
      "primary_asset": "runtime-ai-data",
      "description": "Skyflow for GenAI: De-identifies and tokenizes sensitive data across training, RAG, and inference, then re-identifies it for authorized users at runtime, so plaintext PII never reaches an LLM.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type II",
        "ISO 27001:2022",
        "PCI DSS Level 1"
      ],
      "last_reviewed": "2026-06-24",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "De-identifies and tokenizes sensitive PII in prompts, RAG context, and inference so plaintext never reaches the model, then detokenizes for authorized users through fine-grained runtime access controls.",
          "origin": "reviewed"
        },
        {
          "asset": "training-data",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Excludes or de-identifies sensitive data in datasets used for model training and fine-tuning so private data is not retained by the model.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "snyk",
      "schema_version": 2,
      "name": "Snyk",
      "vendor": "Snyk",
      "url": "https://snyk.io",
      "primary_asset": "ai-generated-code",
      "description": "Developer-security platform, now positioned as an AI security fabric, that secures AI-generated code and the AI agents and tools used to build and run AI-native applications.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type II",
        "ISO 27001",
        "ISO 27017"
      ],
      "last_reviewed": "2026-07-17",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-generated-code",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Snyk Studio guides AI coding assistants and Snyk Code scans to find and fix issues in AI-generated code at inception.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "Scans MCP servers for vulnerabilities such as tool poisoning, using technology from the Invariant Labs acquisition.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Runtime guardrails enforce policy on AI agent behavior, restricting data flow and tool access and flagging anomalous decisions.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "sonar-ai-code-assurance",
      "schema_version": 2,
      "name": "Sonar AI Code Assurance",
      "vendor": "Sonar",
      "url": "https://www.sonarsource.com/solutions/ai/ai-code-assurance/",
      "primary_asset": "ai-generated-code",
      "description": "Sonar AI Code Assurance: SonarQube workflow that tags AI-generated code and holds it to an AI-qualified quality gate, with AI CodeFix offering one-click fixes for the issues found.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2"
      ],
      "last_reviewed": "2026-06-23",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-generated-code",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "AI Code Assurance tags AI-generated code and runs it through an AI-qualified quality gate that enforces quality and security standards before it reaches production, with AI CodeFix proposing one-click fixes for the issues found.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "sonatype-repository-firewall",
      "schema_version": 2,
      "name": "Sonatype Repository Firewall",
      "vendor": "Sonatype",
      "url": "https://www.sonatype.com/products/sonatype-repository-firewall",
      "primary_asset": "ai-model",
      "description": "Sonatype Repository Firewall: Identifies and blocks malicious open-source components before they enter development, with Hugging Face support extending that protection to AI/ML models.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2"
      ],
      "last_reviewed": "2026-06-13",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Hugging Face support brings Repository Firewall to AI/ML models, identifying and blocking malicious models before they enter development environments.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "spectra-assure",
      "schema_version": 2,
      "name": "Spectra Assure",
      "vendor": "ReversingLabs",
      "url": "https://www.reversinglabs.com/products/spectra-assure",
      "primary_asset": "ai-model",
      "description": "Spectra Assure: Scans AI and ML model files for malicious code as part of software supply chain analysis and lists detected models in an ML-BOM.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "detect",
            "identify"
          ],
          "maturity": "primary",
          "note": "Identifies AI and ML model files in analyzed software by format signature, scans them with malware analysis to assess whether models are safe to use, and lists discovered models as components in an ML-BOM within the SAFE report.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "splx",
      "schema_version": 2,
      "name": "SPLX",
      "vendor": "SPLX",
      "url": "https://splx.ai/",
      "primary_asset": "ai-model",
      "description": "SPLX: End-to-end platform to test, protect, and govern AI systems that discovers AI assets into an AI-BOM, runs automated red teaming, and applies runtime security across the AI lifecycle.",
      "deployment": [
        "saas"
      ],
      "status": "acquired",
      "compliance_attestations": null,
      "acquirer": "Zscaler",
      "last_reviewed": "2026-06-14",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "detect",
            "protect"
          ],
          "maturity": "primary",
          "note": "Discovers AI models, workflows, and MCP servers into an AI-BOM, continuously red-teams AI systems for vulnerabilities, and applies runtime security and governance across the AI lifecycle.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "Discovers and inventories AI models, workflows, MCP servers, and guardrails into a complete AI-BOM.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "stacklok-toolhive",
      "schema_version": 2,
      "name": "Stacklok ToolHive",
      "vendor": "Stacklok",
      "url": "https://stacklok.com/platform",
      "primary_asset": "ai-orchestration-tools",
      "description": "Stacklok ToolHive: Enterprise MCP platform deployed in your private cloud that adds back-end authentication, authorization, network isolation, and encrypted secrets for MCP servers.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-13",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Adds back-end authentication, authorization, network isolation, and token exchanges to MCP, lets admins permission and pre-configure servers, and manages secrets in an encrypted vault.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "stained-glass-transform",
      "schema_version": 2,
      "name": "Stained Glass Transform",
      "vendor": "Protopia AI",
      "url": "https://protopia.ai/stained-glass-transform/",
      "primary_asset": "runtime-ai-data",
      "description": "Stained Glass Transform: Protopia AI inference privacy layer that converts prompts and inputs into stochastic representations so raw data is never in plaintext on shared GPU infrastructure.",
      "deployment": [
        "hybrid"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-25",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "De-identifies inference inputs into stochastic representations before they reach the model, so the operator never takes custody of plaintext prompts or context on shared infrastructure.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "starfort",
      "schema_version": 2,
      "name": "Starfort",
      "vendor": "AIM Intelligence",
      "url": "https://www.aim-intelligence.com/starfort",
      "primary_asset": "runtime-ai-data",
      "description": "Starfort: Real-time AI guardrail that inspects prompts, responses, tool calls, and agent actions inline, masking sensitive data and enforcing policy across proxy, API, and endpoint deployments.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-08-20",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Inline guardrail over prompts and responses that blocks malicious input and masks sensitive data, using layered detection across regular expressions, named-entity recognition, context, and keywords, extending masking to attached files. Policies are authored from natural-language examples.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Guardrail coverage extends past prompt and response text to the agent action path, inspecting tool calls, function arguments, and agent decisions in line, with request-level logging and audit trails in a central dashboard.",
          "origin": "agent"
        },
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Enforcement can be placed at the model access layer as a server proxy inside the customer infrastructure, inspecting and controlling requests to managed model services and to self-hosted models reached through a routing layer.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "stinger",
      "schema_version": 2,
      "name": "Stinger",
      "vendor": "AIM Intelligence",
      "url": "https://www.aim-intelligence.com/stinger",
      "primary_asset": "ai-model",
      "description": "Stinger: AI red teaming platform that generates and runs automated adversarial scenarios against models, agents, and live applications across text, image, audio, video, and physical AI.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-08-20",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "detect"
          ],
          "maturity": "primary",
          "note": "Automated red teaming that generates adversarial scenarios across text, image, audio, video, and physical AI, spanning single-prompt and multi-turn jailbreak techniques, with a configurable judge and reporting that maps attack technique against vulnerability.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Tests deployed AI applications and agents end to end rather than at the prompt layer, with target crawling and analysis, session handling for authenticated state, and per-endpoint attack goals.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Exercises retrieval pipelines for indirect prompt injection by planting payloads in documents the application trusts, across several payload types, file formats, and stealth injection techniques.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "straiker",
      "schema_version": 2,
      "name": "Straiker",
      "vendor": "Straiker",
      "url": "https://www.straiker.ai",
      "primary_asset": "runtime-ai-data",
      "description": "AI-native security for agentic apps and AI agents, pairing offensive red-team testing with runtime guardrails that detect and block prompt injection, data exfiltration, and agent manipulation.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-17",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discover AI inventories agents and tools; Defend AI screens agentic app traffic inline.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Defend AI guardrails inspect prompts, responses, and tool calls and block threats at runtime.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Ascend AI tests for identity exploitation; Discover AI maps agent connections and posture.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "stytch-connected-apps",
      "schema_version": 2,
      "name": "Stytch Connected Apps",
      "vendor": "Stytch",
      "url": "https://stytch.com/connected-apps",
      "primary_asset": "ai-agent-identities",
      "description": "Stytch Connected Apps: Authorization for AI agent and MCP workflows that connects agents to applications with consent management, scoped permissions, and admin allowlists.",
      "deployment": [
        "saas"
      ],
      "status": "acquired",
      "compliance_attestations": [
        "SOC 2",
        "ISO 27001",
        "PCI DSS"
      ],
      "acquirer": "Twilio",
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "agent",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Authorizes AI agent and MCP workflows against an existing auth stack, presenting permissions in scoped groupings for user consent, limiting grants to permissions the user already holds, and restricting which apps and agents members may connect through allowlists.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "surepath-ai",
      "schema_version": 2,
      "name": "SurePath AI",
      "vendor": "SurePath AI",
      "url": "https://www.surepath.ai/",
      "primary_asset": "runtime-ai-data",
      "description": "SurePath AI: Workforce GenAI governance platform that inspects prompts and responses, redacts sensitive data, controls access to public and private models, and logs AI interactions for audit.",
      "deployment": [
        "saas"
      ],
      "status": "acquired",
      "compliance_attestations": [
        "SOC 2 Type 1"
      ],
      "acquirer": "F5",
      "last_reviewed": "2026-06-15",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "agent",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Inspects AI inputs and outputs in real time and redacts sensitive information before it reaches models, agents, or connected systems, then logs every interaction across public and private models to provide audit trails.",
          "origin": "agent"
        },
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "secondary",
          "note": "Captures AI traffic at the network level without endpoint agents to reveal which AI services are in use, and enforces role- and group-based access policies controlling which models, tools, and data each user can reach.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "sweet-ai-security-platform",
      "schema_version": 2,
      "name": "Sweet AI Security Platform",
      "vendor": "Sweet Security",
      "url": "https://www.sweet.security/ai-security-platform-aisp",
      "primary_asset": "runtime-ai-data",
      "description": "Sweet AI Security Platform: Runtime detection and response for AI systems that inventories models and agents, blocks prompt injection through an AI gateway, and enforces least privilege for agents.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect",
            "protect"
          ],
          "maturity": "primary",
          "note": "AIDR routes AI agent traffic through the Sweet AI Gateway to analyze prompts and block malicious operations such as prompt injection, applying guardrail policies and behavioral baselines that flag deviations in agent activity.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Discovers every AI agent in the environment, including shadow and unmanaged ones, and manages agent permissions with least privilege, blast radius analysis, auditing, and operation-level policy enforcement linked to an MCP gateway.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "Builds an AI BOM that tracks public and fine-tuned models with origin and version details, while AI-SPM posture checks monitor AI components for misconfigurations, exposed endpoints, and vulnerabilities.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "symbiotic-security",
      "schema_version": 2,
      "name": "Symbiotic Security",
      "vendor": "Symbiotic Security",
      "url": "https://www.symbioticsec.ai/products/symbiotic-flow",
      "primary_asset": "ai-generated-code",
      "description": "Symbiotic Security: In-IDE security for AI-generated code that enforces policy before code is written, detects and auto-fixes vulnerabilities in the editor, and gates pull requests and CI/CD.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type II"
      ],
      "last_reviewed": "2026-06-24",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-generated-code",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Enforces security policy before AI-assisted code is written, detects and auto-fixes vulnerabilities directly in the IDE, and gates pull requests and CI/CD; a code-generation agent remediates before returning code.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "symmetry-aiguard",
      "schema_version": 2,
      "name": "Symmetry AIGuard",
      "vendor": "Symmetry Systems",
      "url": "https://www.symmetry-systems.com/news/symmetry-systems-launches-symmetry-aiguard/",
      "primary_asset": "ai-agent-identities",
      "description": "Symmetry AIGuard: Treats AI agent identities as first-class security principals, inventorying each agent, mapping the sensitive data it can reach, and enforcing access policy on it.",
      "deployment": [
        "hybrid"
      ],
      "status": "acquired",
      "compliance_attestations": null,
      "acquirer": "Zscaler",
      "last_reviewed": "2026-07-03",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Inventories every AI agent with type classification and registry, maps each agent permissions, data scope, and blast radius and enforces its policy, and surfaces high-risk agents.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "tailscale-aperture",
      "schema_version": 2,
      "name": "Tailscale Aperture",
      "vendor": "Tailscale",
      "url": "https://tailscale.com/use-cases/securing-ai",
      "primary_asset": "ai-gateways-routers",
      "description": "Tailscale Aperture: AI gateway that authenticates users and agents with Tailscale identity, keeps provider API keys centralized, and tracks LLM usage and spend.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2"
      ],
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Centralized AI gateway that secures, monitors, and routes LLM requests to providers such as OpenAI, Anthropic, and Google. Tailscale identity authenticates users in place of distributed API keys, with controls over reachable models and per-user spending limits.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Dashboards and session logs provide visibility into LLM requests and token usage across the organization, with usage data export, including S3 log export, for monitoring and review.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Identifies connecting users and coding agents such as Claude Code, Codex, and Gemini CLI through Tailscale identities, tying LLM usage to the identity that generated each request rather than shared API keys.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "teleport-beams",
      "schema_version": 2,
      "name": "Teleport Beams",
      "vendor": "Teleport",
      "url": "https://www.beams.run/",
      "primary_asset": "ai-workload-platforms",
      "description": "Teleport Beams: Runs AI agents in isolated Firecracker micro-VMs with built-in identity, per-beam access policy, and audited access to infrastructure and inference services.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001",
        "HIPAA"
      ],
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-workload-platforms",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Runs each agent in an isolated Firecracker micro-VM with an ephemeral filesystem wiped at session end and policy-controlled egress to allowlisted domains; every access event is recorded immutably for audit visibility into what agents reach.",
          "origin": "agent"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Issues a short-lived identity certificate to each beam, scoped to the services it may reach, so agents authenticate to infrastructure and inference endpoints without static secrets; access policy is enforced per beam at the proxy.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "tenable-ai-exposure",
      "schema_version": 2,
      "name": "Tenable AI Exposure",
      "vendor": "Tenable",
      "url": "https://www.tenable.com/products/ai-exposure",
      "primary_asset": "ai-workload-platforms",
      "description": "Tenable AI Exposure: Discovers how employees and agents use AI platforms, surfaces shadow AI and misconfigurations, detects attacks such as prompt injection, and enforces AI acceptable use policies.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "ISO 27001"
      ],
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-workload-platforms",
          "functions": [
            "identify"
          ],
          "maturity": "primary",
          "note": "Discovers how employees and agents interact with AI platforms such as ChatGPT Enterprise and Microsoft Copilot, finds unsafe platform settings and third-party integrations, and enforces AI acceptable use policies.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect",
            "identify"
          ],
          "maturity": "primary",
          "note": "The Explorer page inspects messages in user AI sessions to identify potential data exfiltration or sharing of sensitive information with AI models; the Issues page surfaces detected policy breaches and security gaps.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": "The Inventory page tracks users, deployed AI agents, and AI memories; AI agent assets carry risk scores in Tenable Exposure Management.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "tenet-security",
      "schema_version": 2,
      "name": "Tenet Security",
      "vendor": "Tenet Security",
      "url": "https://www.tenetsecurity.ai/",
      "primary_asset": "ai-orchestration-tools",
      "description": "Tenet Security: Runtime defense for AI agents that simulates where each agent action leads before it executes, preventing dangerous actions from inside the agent runtime without gateways or proxies.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect",
            "identify"
          ],
          "maturity": "primary",
          "note": "Agent-side simulation across OS, network and API, and LLM-reasoning layers runs inside the agent runtime, projecting where each action leads and preventing dangerous actions before execution. Also maps every AI agent, MCP, and tool integration in the environment via lightweight traffic metadata.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "tetrate-agent-router-service",
      "schema_version": 2,
      "name": "Tetrate Agent Router Service",
      "vendor": "Tetrate",
      "url": "https://tetrate.io/agent-router-product",
      "primary_asset": "ai-gateways-routers",
      "description": "Tetrate Agent Router Service: Hosted AI gateway built on Envoy AI Gateway that routes agent and model traffic across providers with token budgets, failover, an MCP gateway, and runtime guardrails.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Routes LLM traffic across agents and providers, enforcing per-team token budgets and automatic failover while producing unified logs for attribution.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Runtime AI guardrails redact PII, filter prompts and responses, and block transactions across model and tool traffic.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "MCP gateway governs how agents connect to tools, with centrally curated server catalogs and per-team, per-role, or per-agent access profiles.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "thales-ai-security-fabric",
      "schema_version": 2,
      "name": "Thales AI Security Fabric",
      "vendor": "Thales",
      "url": "https://cpl.thalesgroup.com/data-security/ai-cybersecurity-solutions",
      "primary_asset": "runtime-ai-data",
      "description": "Thales AI Security Fabric: Runtime security for LLM applications and agents, blocking prompt injection and jailbreaks while protecting the enterprise data that RAG pipelines retrieve.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-29",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Inspects traffic to and from applications built on LLMs at runtime, stopping prompt injection and jailbreak attempts, system prompt leakage, and disclosure of sensitive information, and applying content moderation to responses.",
          "origin": "agent"
        },
        {
          "asset": "training-data",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "secondary",
          "note": "Finds sensitive structured and unstructured enterprise data and applies encryption and key management to it before that data is ingested into retrieval-augmented generation pipelines.",
          "origin": "agent"
        },
        {
          "asset": "ai-model",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Runtime controls are aimed at model-layer abuse as well as application-layer abuse, covering data poisoning and model manipulation alongside denial-of-service attacks directed at the model.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "tinfoil",
      "schema_version": 2,
      "name": "Tinfoil",
      "vendor": "Tinfoil",
      "url": "https://www.tinfoil.sh/inference",
      "primary_asset": "runtime-ai-data",
      "description": "Tinfoil: Verifiably-private AI inference run inside hardware secure enclaves so prompts, responses, and model weights stay confidential from the provider, with an OpenAI-compatible API.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type II"
      ],
      "last_reviewed": "2026-06-25",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Processes prompts and responses inside hardware secure enclaves that even the provider cannot access, keeping inference data confidential and verifiable through remote attestation.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Loads and runs model weights inside the secure enclave so they are not exposed to the host or other parties during inference.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "token-security",
      "schema_version": 2,
      "name": "Token Security",
      "vendor": "Token Security",
      "url": "https://www.token.security/",
      "primary_asset": "ai-agent-identities",
      "description": "Security platform for AI agents and non-human identities that discovers and inventories them, maps their access and risk, and enforces intent-based least-privilege.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Discovers and inventories AI agents and non-human identities, maps their access and risk, and enforces intent-based least-privilege so each agent has only the permissions its purpose needs.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "traceforce",
      "schema_version": 2,
      "name": "Traceforce",
      "vendor": "Traceforce",
      "url": "https://traceforce.ai/",
      "primary_asset": "ai-orchestration-tools",
      "description": "Traceforce: Endpoint AI security that runs on the device to discover browser AI, desktop apps, CLI agents, and MCP connections, stopping dangerous actions and automating remediation.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "ISO 27001",
        "SOC 2"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "agent",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "detect",
            "protect",
            "respond"
          ],
          "maturity": "primary",
          "note": "Endpoint agents discover the AI tools, MCP servers, and skills running locally on each device and flag risk from how AI is actually used, stopping dangerous tool calls with block and warn rules and remediating by auto-patching AI packages on-device and quarantining malicious MCPs.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "On-device policy rules inspect what employees send to AI apps and warn on or block an unsafe transfer, such as pasting a customer list into a chatbot, before it leaves the device.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "tray-ai-agent-gateway",
      "schema_version": 2,
      "name": "Tray.ai Agent Gateway",
      "vendor": "Tray.ai",
      "url": "https://tray.ai/platform/agent-gateway/",
      "primary_asset": "ai-orchestration-tools",
      "description": "Tray.ai Agent Gateway: Enterprise MCP gateway that versions and publishes MCP servers and tools on a governed path, enforces access policies and permissions, and audits every call.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-13",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Spins up, versions, publishes, and deprecates MCP servers on a managed path, enforces access policies and permissions, and provides centralized visibility and audit across deployed MCP.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "trend-vision-one-ai-application-security",
      "schema_version": 2,
      "name": "Trend Vision One AI Application Security",
      "vendor": "Trend Micro",
      "url": "https://www.trendmicro.com/en/business/ai/security-ai-stacks/ai-applications.html",
      "primary_asset": "ai-orchestration-tools",
      "description": "Trend Vision One AI Application Security: Scans LLM applications for vulnerabilities before deployment and guards them at runtime, blocking prompt injection, data leakage, and unsafe output.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001",
        "ISO 27017",
        "PCI DSS"
      ],
      "last_reviewed": "2026-06-13",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "AI Scanner finds vulnerabilities in LLM applications before deployment, and AI Guard provides real-time runtime threat defense in a continuous scan, protect, and validate loop.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "trojai",
      "schema_version": 2,
      "name": "TrojAI",
      "vendor": "TrojAI",
      "url": "https://troj.ai/",
      "primary_asset": "runtime-ai-data",
      "description": "TrojAI: Tools that red team AI models at build time and apply a runtime firewall against prompt injection, data leakage, and rogue MCP servers.",
      "deployment": [
        "self-hosted"
      ],
      "status": "acquired",
      "compliance_attestations": null,
      "acquirer": "A10 Networks",
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "detect"
          ],
          "maturity": "primary",
          "note": "TrojAI Detect runs automated red teaming with more than 150 built-in security and safety tests, finding model weaknesses such as prompt injection, data leakage, and PII exposure before deployment.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "TrojAI Defend is a runtime AI firewall that monitors, alerts, blocks, redacts, and logs, filtering inputs and outputs to AI applications to stop prompt injection, sensitive information disclosure, and other adversarial attacks.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "TrojAI Defend for MCP applies MCP-specific policies that inspect, audit, and enforce security on MCP traffic in real time, blocking unregistered or rogue servers in agentic workflows.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "trust3-ai",
      "schema_version": 2,
      "name": "Trust3 AI",
      "vendor": "Trust3 AI",
      "url": "https://trust3.ai/",
      "primary_asset": "training-data",
      "description": "Trust3 AI: Unified data and AI access governance platform that secures data across cloud and on-premises environments and governs autonomous AI agents.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "training-data",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Scans and classifies fine-tuning and RAG data and filters vector-database and RAG queries so each user inherits the access controls of the source systems.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Applies real-time controls to generative AI prompts and responses with end-to-end observability and audit.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "uber-adr",
      "schema_version": 2,
      "name": "Uber ADR",
      "vendor": "Uber",
      "url": "https://github.com/uber/ADR",
      "primary_asset": "runtime-ai-data",
      "description": "Uber ADR: Open-source agentic AI security system from Uber that captures agent telemetry, benchmarks defenses, and detects risky agent behavior with a two-tier detector.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-08-02",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect"
          ],
          "maturity": "primary",
          "note": "The ADR Detector monitors agent sessions with a two-tier architecture that combines high-recall triage with deeper agentic reasoning, surfacing risky behavior such as prompt injection across coding and support agents. ADR-Bench supplies 303 tasks covering 17 agent attack techniques.",
          "origin": "agent"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "The ADR Sensor collects and normalizes telemetry on agent intent, tool use, and execution traces from AI coding tools such as Claude Code, Cursor, and Codex, as well as internal automation, giving security teams visibility into what enterprise AI agents are doing.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "unbound",
      "schema_version": 2,
      "name": "Unbound",
      "vendor": "Unbound",
      "url": "https://getunbound.ai/product",
      "primary_asset": "ai-orchestration-tools",
      "description": "Unbound: Agent access security broker that discovers AI coding agents and MCP servers and enforces policy to audit, warn, block, or require approval on their commands, tool calls, and data egress.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2"
      ],
      "last_reviewed": "2026-06-24",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovers and inventories AI coding tools, MCP servers, and sub-agents across the organization, and enforces policy to audit, warn, block, or require approval on agent commands and tool calls.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Enforces policy on outbound data egress by agents in real time to block sensitive-data exfiltration.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "unity-ai-gateway",
      "schema_version": 2,
      "name": "Unity AI Gateway",
      "vendor": "Databricks",
      "url": "https://www.databricks.com/product/artificial-intelligence/unity-ai-gateway",
      "primary_asset": "ai-gateways-routers",
      "description": "Unity AI Gateway: Databricks control plane governing access to LLM endpoints, coding agents, and MCP servers, with guardrails for PII and unsafe content, plus permissions, rate limits, and logging.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-14",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-gateways-routers",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Manages and monitors access to model serving endpoints with permissions, rate limits, usage tracking through system tables, fallbacks, and traffic splitting across model backends.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "AI Guardrails enforce safety filtering against harmful content and block or mask PII detected in endpoint requests and responses, with inference tables logging payloads for audit.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Governs MCP servers as the enterprise control plane, with centralized view and management of all MCP servers, access control through Unity Catalog permissions and managed-OAuth credentials, and activity monitoring across servers.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "unity-catalog",
      "schema_version": 2,
      "name": "Unity Catalog",
      "vendor": "Databricks",
      "url": "https://www.databricks.com/product/unity-catalog",
      "primary_asset": "ai-model",
      "description": "Unified catalog layer for Databricks data and AI that manages models, agent tools, and MCP connections as access-controlled objects, with fine-grained policies, column-level lineage, and audit.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "primary",
          "note": "Manages registered ML models, agent-tool functions, and MCP connections as securable objects with grant and revoke privileges, lineage, and audit.",
          "origin": "agent"
        },
        {
          "asset": "training-data",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "secondary",
          "note": "Applies fine-grained, attribute-based access policies with row and column filters and PII autoclassification to the data that feeds models, with end-to-end lineage.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "varonis-atlas",
      "schema_version": 2,
      "name": "Varonis Atlas",
      "vendor": "Varonis",
      "url": "https://www.varonis.com/platform/ai-security",
      "primary_asset": "ai-orchestration-tools",
      "description": "Varonis Atlas: AI security platform that inventories AI and shadow AI, tests AI systems for prompt injection and other vulnerabilities, and enforces runtime guardrails via an in-path AI gateway.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "SOC 3",
        "ISO 27001",
        "ISO 27017",
        "ISO 27018",
        "ISO 27701",
        "CSA STAR Level 1",
        "HIPAA",
        "PCI DSS"
      ],
      "last_reviewed": "2026-06-13",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Inventories AI systems including shadow AI, monitors AI usage, and enforces runtime guardrails via an in-path AI gateway across chatbots, custom LLMs, MCP, and agentic frameworks.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "AI security posture management and AI pen testing scan AI agents, chatbots, and models for vulnerabilities and misconfigurations.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "The AI gateway inspects prompts and model responses in real time to detect and block sensitive-data leakage and malicious use.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "vectorlens",
      "schema_version": 2,
      "name": "VectorLens",
      "vendor": "IronCore Labs",
      "url": "https://ironcorelabs.com/products/vectorlens/",
      "primary_asset": "runtime-ai-data",
      "description": "VectorLens: Command-line scanner that classifies personal and other sensitive data hidden inside AI vector embeddings, so security teams can find PII copied into vector stores without the source text.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-03",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "identify"
          ],
          "maturity": "primary",
          "note": "A local command-line tool exports vectors from any store and runs trained classifiers over the embeddings to surface and label the categories of sensitive data they carry, without needing the original source text, so teams can inventory PII that has been copied into vector databases.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "veza-ai-agent-security",
      "schema_version": 2,
      "name": "Veza AI Agent Security",
      "vendor": "Veza",
      "url": "https://veza.com/product/ai-agent-security/",
      "primary_asset": "ai-agent-identities",
      "description": "Veza AI Agent Security: Discovers AI agents and MCP servers across the enterprise, maps their access and human owners, and enforces least-privilege policies to reduce AI agent risk.",
      "deployment": [
        "saas"
      ],
      "status": "acquired",
      "compliance_attestations": [
        "SOC 2",
        "ISO 27001"
      ],
      "acquirer": "ServiceNow",
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "agent",
        "compliance_attestations": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovers AI agents and MCP servers, maps their data and application access and human owners, enforces least-privilege policies, and supports continuous compliance and audit readiness.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "virtue-ai",
      "schema_version": 2,
      "name": "Virtue AI",
      "vendor": "Virtue AI",
      "url": "https://www.virtueai.com/",
      "primary_asset": "runtime-ai-data",
      "description": "Virtue AI: AI security platform that red-teams models and agents, applies real-time guardrails to prompts and responses, and screens agent tool calls and MCP servers for unsafe actions.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-24",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "VirtueGuard applies real-time multimodal guardrails that inspect prompts and responses and block harmful or out-of-policy content across text, image, audio, video, and code.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "AgentSuite-Blue judges every agent tool call and blocks unsafe or out-of-policy actions before they execute (ActionGuard), and scans MCP tools and source for injections and data-leakage paths (MCP Guard).",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "VirtueRed runs continuous automated red-teaming against AI models and chatbots to surface vulnerabilities and produce audit-ready evidence.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "vorlon",
      "schema_version": 2,
      "name": "Vorlon",
      "vendor": "Vorlon",
      "url": "https://vorlon.io/",
      "primary_asset": "ai-agent-identities",
      "description": "Vorlon: AI Agent Flight Recorder and Action Center capture a cross-application forensic audit trail of agent actions, surface behavioral anomaly findings, and route coordinated response.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2"
      ],
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "detect",
            "respond"
          ],
          "maturity": "primary",
          "note": "The Flight Recorder stitches each agent action across connected apps into a queryable forensic record; the Action Center flags behavioral anomalies against agent usage patterns, routes findings to owners, and tracks remediation through SIEM, SOAR, and ITSM workflows.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Monitors data-in-motion between AI agents, SaaS apps, and integrations, detecting anomalous access to sensitive data using data-layer context.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "wald-ai",
      "schema_version": 2,
      "name": "Wald AI",
      "vendor": "Wald AI",
      "url": "https://wald.ai/",
      "primary_asset": "runtime-ai-data",
      "description": "Wald AI: AI data-loss-prevention and secure LLM-access broker that inspects employee GenAI prompts in real time and uses context-aware redaction to keep sensitive data out of model calls.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type I",
        "SOC 2 Type II"
      ],
      "last_reviewed": "2026-06-25",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Inspects employee prompts in real time with context-aware identification and replaces sensitive data with placeholders before the prompt reaches the model, then restores it locally.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "wallarm-ai-hypervisor",
      "schema_version": 2,
      "name": "Wallarm AI Hypervisor",
      "vendor": "Wallarm",
      "url": "https://www.wallarm.com/product/ai-hypervisor",
      "primary_asset": "ai-orchestration-tools",
      "description": "Wallarm AI Hypervisor: Kernel-level eBPF runtime layer for enterprise AI agents that observes every agent decision, data boundary, and external call, and blocks the ones that violate policy inline.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-05",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "detect",
            "protect"
          ],
          "maturity": "primary",
          "note": "Kernel-level eBPF instrumentation observes every agent decision, data boundary, and external call at runtime, and blocks the actions that violate policy inline.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "identify",
            "protect"
          ],
          "maturity": "secondary",
          "note": "Surfaces sensitive data in motion across agent calls and can stop policy-violating data-boundary crossings inline.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "white-circle",
      "schema_version": 2,
      "name": "White Circle",
      "vendor": "White Circle",
      "url": "https://whitecircle.com/",
      "primary_asset": "runtime-ai-data",
      "description": "White Circle: AI control layer that red-teams AI for failures, applies custom low-latency guardrails to block prompt injection and unsafe outputs, and monitors AI interactions for abuse and drift.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "HIPAA"
      ],
      "last_reviewed": "2026-07-16",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent",
        "compliance_attestations": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Applies custom low-latency guardrails that block prompt injection, unsafe outputs, and sensitive-data leakage, and monitors AI inputs and outputs for harmful content, abuse, and model drift.",
          "origin": "agent"
        },
        {
          "asset": "ai-model",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Automatically red-teams AI systems to surface failures such as jailbreaks and prompt injection before deployment.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "willow",
      "schema_version": 2,
      "name": "Willow",
      "vendor": "Willow",
      "url": "https://withwillow.ai/",
      "primary_asset": "ai-agent-identities",
      "description": "Willow: Identity and access layer for AI agents that discovers every agent, tool, and MCP server, issues each a governed scoped credential tied to a real user, and logs and contains their activity.",
      "deployment": [
        "saas",
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2"
      ],
      "last_reviewed": "2026-06-14",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Discovers every AI agent, tool, and MCP server including unapproved ones, issues each agent a governed scoped credential tied to a real user with role-based least-privilege, and logs and contains agent activity with an org-wide kill switch.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Provides a governed MCP gateway that brokers a single approved connection between agents and the tools they use.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "witnessai",
      "schema_version": 2,
      "name": "WitnessAI",
      "vendor": "WitnessAI",
      "url": "https://witness.ai/",
      "primary_asset": "runtime-ai-data",
      "description": "Network-level AI security and governance platform that discovers AI apps, agents, and MCP servers, enforces use policies, and runs an AI firewall that blocks prompt injection and jailbreaks.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "The Witness Protect AI firewall inspects prompts and responses bidirectionally, blocking prompt injection and jailbreaks and filtering outputs before users or agents act on them.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "identify",
            "detect"
          ],
          "maturity": "secondary",
          "note": "Discovers AI apps, agents, and MCP servers across the network without endpoint agents, and logs all AI activity for governance.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "wiz-ai-spm",
      "schema_version": 2,
      "name": "Wiz AI-SPM",
      "vendor": "Wiz",
      "url": "https://www.wiz.io/solutions/ai-spm",
      "primary_asset": "ai-workload-platforms",
      "description": "Agentless AI security posture management that discovers AI pipelines, models, and data across clouds, then surfaces misconfigurations and attack paths to AI services.",
      "deployment": [
        "saas"
      ],
      "status": "acquired",
      "compliance_attestations": [
        "SOC 2 Type II",
        "SOC 3",
        "ISO 27001",
        "ISO 27017",
        "ISO 27018",
        "ISO 27701",
        "PCI DSS v4.0.1",
        "HIPAA"
      ],
      "acquirer": "Google (Alphabet)",
      "last_reviewed": "2026-07-17",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-workload-platforms",
          "functions": [
            "identify"
          ],
          "maturity": "primary",
          "note": "Agentless discovery and posture for AI services and pipelines.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": null,
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "identify"
          ],
          "maturity": "secondary",
          "note": null,
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "workos-authkit",
      "schema_version": 2,
      "name": "WorkOS AuthKit",
      "vendor": "WorkOS",
      "url": "https://workos.com/mcp",
      "primary_asset": "ai-agent-identities",
      "description": "WorkOS AuthKit: OAuth 2.1 authorization server for MCP applications that handles agent authorization flows and token validation, enabling fine-grained authorization for agentic workflows.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Acts as the OAuth 2.1 authorization server for MCP applications, handling the authorization flows while the MCP server validates the issued tokens, with fine-grained authorization for agentic applications and workflows.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "xygeni-devai",
      "schema_version": 2,
      "name": "Xygeni DevAI",
      "vendor": "Xygeni",
      "url": "https://xygeni.io/dev-ai/",
      "primary_asset": "ai-generated-code",
      "description": "Xygeni DevAI: In-IDE agentic AppSec copilot that scans AI-generated and human-written code in real time for vulnerabilities, secrets, and unsafe APIs, and delivers automated fixes.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-06-13",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-generated-code",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "In-IDE scanning of AI-generated and human-written code for vulnerabilities, secrets, and unsafe APIs, with automated fixes delivered as developers type.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "zenity",
      "schema_version": 2,
      "name": "Zenity",
      "vendor": "Zenity",
      "url": "https://zenity.io/platform",
      "primary_asset": "ai-agent-identities",
      "description": "Zenity: Secures enterprise AI agents with discovery, posture management, and runtime detection and response across agent platforms.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "ISO 27001",
        "ISO 27701",
        "GDPR"
      ],
      "last_reviewed": "2026-06-10",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "ai-agent-identities",
          "functions": [
            "identify"
          ],
          "maturity": "primary",
          "note": "AISPM discovers agents across environments, evaluates configuration and permission risk, and enforces guardrails before agents run, with an inventory of ownership, permissions, and integrations.",
          "origin": "reviewed"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "detect",
            "protect"
          ],
          "maturity": "primary",
          "note": "AIDR monitors step-level agent execution at runtime, detects direct and indirect prompt injection, and blocks sensitive data leakage through agent conversations, tool calls, and memory.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-orchestration-tools",
          "functions": [
            "protect",
            "detect"
          ],
          "maturity": "secondary",
          "note": "MCP security provides visibility into MCP connections, blocks unauthorized agent actions, and enforces security policies over MCP-enabled agents.",
          "origin": "reviewed"
        }
      ]
    },
    {
      "slug": "zerodrift",
      "schema_version": 2,
      "name": "ZeroDrift",
      "vendor": "ZeroDrift",
      "url": "https://www.zerodrift.ai/",
      "primary_asset": "runtime-ai-data",
      "description": "ZeroDrift: Compliance firewall for AI that checks every model and agent output against regulations and firm policy, then rewrites or blocks anything that fails before it ships.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": null,
      "last_reviewed": "2026-07-05",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Validates every AI message and agent output against regulations, firm policy, and security controls, then rewrites or blocks anything that fails before it reaches a customer, employee, or regulator.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "zeroreveal-machine-learning",
      "schema_version": 2,
      "name": "ZeroReveal Machine Learning",
      "vendor": "Enveil",
      "url": "https://www.enveil.com/products/",
      "primary_asset": "ai-model",
      "description": "ZeroReveal Machine Learning: Privacy-enhancing technology product that keeps machine learning models encrypted during evaluation and enables encrypted federated training across data silos.",
      "deployment": [
        "self-hosted"
      ],
      "status": "active",
      "compliance_attestations": [
        "NIAP Common Criteria"
      ],
      "last_reviewed": "2026-07-08",
      "origin": {
        "description": "agent",
        "deployment": "agent",
        "status": "agent",
        "compliance_attestations": "agent"
      },
      "matrix_coverage": [
        {
          "asset": "ai-model",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Encrypted evaluation and inference keep machine learning models and their results encrypted while in use, protecting model confidentiality across third-party and jurisdictional boundaries.",
          "origin": "agent"
        },
        {
          "asset": "training-data",
          "functions": [
            "protect"
          ],
          "maturity": "primary",
          "note": "Encrypted training based on secure multiparty computation protects training data and the model development process in cross-silo federated learning.",
          "origin": "agent"
        },
        {
          "asset": "runtime-ai-data",
          "functions": [
            "protect"
          ],
          "maturity": "secondary",
          "note": "Query results and derived insights remain encrypted during evaluation, protecting runtime AI data as it moves across organizational and jurisdictional boundaries.",
          "origin": "agent"
        }
      ]
    },
    {
      "slug": "zscaler",
      "schema_version": 2,
      "name": "Zscaler",
      "vendor": "Zscaler",
      "url": "https://www.zscaler.com/products-and-solutions/ai-access-security",
      "primary_asset": "runtime-ai-data",
      "description": "Zero-trust platform that uncovers shadow AI, classifies and moderates AI prompts and responses inline, and enforces DLP to block sensitive data from leaving for generative-AI apps and tools.",
      "deployment": [
        "saas"
      ],
      "status": "active",
      "compliance_attestations": [
        "SOC 2 Type 2",
        "SOC 3",
        "ISO 27001",
        "ISO 27017",
        "ISO 27018",
        "ISO 27701",
        "CSA STAR Level 2",
        "HITRUST",
        "HIPAA",
        "GDPR"
      ],
      "last_reviewed": "2026-06-09",
      "origin": {
        "description": "reviewed",
        "deployment": "reviewed",
        "status": "reviewed",
        "compliance_attestations": "reviewed"
      },
      "matrix_coverage": [
        {
          "asset": "runtime-ai-data",
          "functions": [
            "identify",
            "protect",
            "detect"
          ],
          "maturity": "primary",
          "note": "Uncovers shadow AI, classifies and moderates prompt and response content inline, and enforces inline DLP to block sensitive data from leaving for AI apps.",
          "origin": "reviewed"
        },
        {
          "asset": "ai-model",
          "functions": [
            "detect"
          ],
          "maturity": "secondary",
          "note": "Combines automated red teaming and dynamic risk assessment to identify vulnerabilities in AI applications.",
          "origin": "reviewed"
        }
      ]
    }
  ]
}
