Alphabetical, not ranked. Membership includes primary and secondary research categories. These products have different scopes; inspect the evidence profile before comparing capabilities.
Also covers this layer
Configurable safeguard service inside Amazon Bedrock that evaluates user inputs and model responses against content filters, denied topics, sensitive information filters and word filters, including a prompt attack category. It can be applied at inference or via a standalone API, but does not authorize agent tool calls.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me a Bedrock guardrail blocking a prompt attack and masking PII for a Bedrock Agent, then show the same guardrail invoked through ApplyGuardrail for a non-Bedrock model.
Read sources and limitations →
Primary category
BigID's AI-oriented module inside its data security platform. It inventories AI models, agents, copilots, prompts, vector stores and pipelines, classifies the data feeding training, retrieval and inference, and maps lineage of that data. Claims come from vendor product pages; BigID's technical documentation is not publicly reachable.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate how BigID builds an AI asset inventory that links a vector database to the sensitive datasets embedded in it and the identities allowed to query it.
Read sources and limitations →
Also covers this layer
Collibra's AI governance product, evolved from Collibra AI Governance, registering AI use cases, models, model versions and agents as governed assets with lifecycle stages, compliance assessment templates and a per-system trust score. Fits organisations already using Collibra for data governance.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me an AI use case linked to its model versions, agents and datasets, plus how the trust score changes when documentation or lifecycle status degrades.
Read sources and limitations →
Also covers this layer
Application-security capability that discovers AI assets across the software development lifecycle - AI infrastructure, models, coding assistants, packages and associated secrets - by scanning connected repositories and pipeline systems, then producing an AI bill of materials for governance. Buyer is AppSec; it does not observe business users' AI tool usage.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate discovering which AI coding assistants and third-party models our developers introduced last quarter, and show the AIBOM entry with the repository and secret associations.
Read sources and limitations →
Primary category
Cyera's AI-focused extension of its data security posture platform. Its AI-SPM capability inventories AI models, applications, agents and knowledge bases including shadow AI, and links them to sensitive-data classifications produced by the underlying DSPM engine. Runtime protection is described at product level without public technical documentation.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me the live inventory of AI agents and knowledge bases Cyera discovered in my cloud accounts and which sensitive data classifications each one touches.
Read sources and limitations →
Also covers this layer
Runtime governance layer inside the Databricks platform that routes and controls requests to models, agents, MCP services and AI tools using Unity Catalog privileges, service policies, rate limits and spend caps. Controls are strongest for assets governed by Unity Catalog rather than arbitrary external agent traffic.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me Unity Gateway restricting an agent to an approved subset of tools on an MCP service, with the service policy that blocks a request and the resulting inference log.
Read sources and limitations →
Also covers this layer
GitGuardian's module for non-human identity secrets: the ggscout collector inventories secrets and metadata from secrets managers, CI and infrastructure, tracks consumers, rotation dates and permissions, and flags stale or over-privileged credentials. It governs credentials used by machines and agents rather than issuing agent identities.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me every secret outside our vaults, who consumes it, when it was last rotated, and the semi-automated rotation workflow for an over-privileged NHI secret.
Read sources and limitations →
Also covers this layer
Google Cloud service that screens LLM prompts and responses for prompt injection, jailbreaks, unsafe content and sensitive data, optionally returning sanitised text. Integrations extend screening to Google-managed MCP server traffic and the Gemini Enterprise agent platform, while the Agent Gateway integration is documented as preview.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me Model Armor floor settings screening traffic to a Google-managed MCP server, blocking an injected prompt, and clarify which agent integrations are GA versus preview.
Read sources and limitations →
Also covers this layer
Browser-extension product that inventories employee AI usage by monitoring in-browser web traffic: which AI applications are used, whether the session uses a personal or corporate account, embedded AI features in sanctioned SaaS, and AI browsers. It also nudges or blocks sensitive prompt content. Coverage stops where the managed browser does.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me a report distinguishing employees using ChatGPT on personal free accounts from those on our enterprise SSO tenant, and how the extension captured that distinction.
Read sources and limitations →
Primary category
Data access governance platform that centralizes classification, policy authoring and query-time enforcement across warehouses and lakehouses, and can onboard RAG indexes and storage platforms as governed data sources. Its AI-specific evidence is limited to that onboarding capability; retrieval-time enforcement inside AI applications is not documented.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate onboarding a RAG index as an Immuta data source and enforcing a row-level policy so the AI application cannot retrieve restricted records.
Read sources and limitations →
Primary category
Israeli vendor whose platform maps enterprise content into a policy-aware knowledge graph, tests what enterprise LLM assistants will reveal, and adjusts access so answers respect need-to-know. Evidence comes from vendor product pages rather than technical documentation, and enforcement examples centre on Microsoft 365 Copilot content.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate how Knostic detects that a Copilot answer exposed salary data to a user without need-to-know, and show the control change it applies.
Read sources and limitations →
Primary category
Microsoft's Purview module that reports on how organizational data is used by Copilot experiences, agents and third-party AI sites, surfaces oversharing risk, and applies ready-made data-loss policies to AI prompts. Coverage of non-Microsoft AI sites depends on device onboarding and a browser extension, so unmanaged endpoints stay invisible.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me the Apps and agents dashboard listing every agent in my tenant, the sensitive data each one accessed, and which Purview policy protected it.
Read sources and limitations →
Also covers this layer
Module of Netskope One AI Security that discovers AI assets - corporate or personal, managed or shadow, cloud or on-premises - from the vendor's SSE/proxy vantage point and maps them to the identities, data stores and tools they connect to, adding risk correlation and response. Discovery leans on traffic and platform telemetry rather than code scanning.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me the asset-to-identity-to-data-store map for a shadow AI application discovered from our traffic, including any MCP servers it reaches.
Read sources and limitations →
Also covers this layer
Module of Obsidian's SaaS security platform that builds a continuously updated inventory of AI tools and agents by combining a managed browser extension, API integrations into SaaS tenants, and mapping of agent-to-MCP connections. Aimed at security teams; agent coverage depends on which SaaS tenants and endpoints are instrumented.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me an agent discovered only by your browser extension that never appeared in the SaaS platform's own API-reported agent list, with its creator, permissions, and MCP connections.
Read sources and limitations →
Also covers this layer
AI-specific module of OneTrust's privacy and governance suite: central inventory of AI systems, models, datasets, agents and vendors with use-case intake and approval workflows, risk tiering, impact assessments and policy-driven controls intended to produce audit-ready records for security and governance teams.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me the AI use-case intake and approval workflow end to end, and which evidence OneTrust captures automatically versus manually.
Read sources and limitations →
Also covers this layer
OpenSSF-backed specification with an Apache-2.0 library and CLI that signs and verifies machine learning model artifacts using Sigstore, self-signed certificates, public keys or PKCS#11 devices, producing signature bundles that let consumers check model integrity and provenance before deployment or reuse.
open_source · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate signing a multi-gigabyte model with Sigstore and verifying the signature in a deployment pipeline gate, including what the bundle attests to.
Read sources and limitations →
Also covers this layer
SASE-delivered product that identifies which generative AI applications employees are using by matching network traffic against a maintained dictionary of GenAI apps grouped into predefined use cases, then applying access-control and DLP policy. It discovers app usage, not internally built agents or AI components in code.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate the Insights dashboard showing the top GenAI apps by user and use case in our traffic, and how a new app appears once it is added to the app dictionary.
Read sources and limitations →
Primary category
MIT-licensed SDK, originally from Microsoft and now transitioning to community ownership, that detects PII in text, images and structured data using recognizers, regex, rules and checksums, then anonymizes it with configurable operators. It is a developer library with no policy console, access control, lineage or audit features.
open_source · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me a custom recognizer added to Presidio that detects our internal customer ID format and anonymizes it in a prompt before an LLM call.
Read sources and limitations →
Primary category
Canadian vendor providing a container-deployable API that identifies and removes personal identifiers from text before it reaches a model, with optional synthetic replacement and consistent markers. It is a detection and de-identification layer only: no access control, lineage, consent or audit features appear in its API reference.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate the de-identify call redacting 20 PII classes from a prompt and then re-identifying the response, with entity relationships preserved.
Read sources and limitations →
Primary category
India- and US-based vendor offering deterministic tokenization for sensitive values used in LLM prompts and AI pipelines, with policy-controlled unmasking that requires an explicit request and sufficient caller permissions. Documentation covers tokenization mechanics; discovery, lineage, consent and audit logging are not described.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate masking a support ticket before it goes to an LLM, then an unmask request being denied because the active policy does not permit it.
Read sources and limitations →
Primary category
Securiti's pipeline product for building enterprise AI systems on governed data. It catalogs unstructured sources, redacts or masks sensitive values inside AI pipelines, loads permission-aware embeddings into vector databases, and tracks lineage from source file to embedding. Detailed technical documentation was not publicly reachable during review.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me a Gencore AI pipeline where a retrieval answer changes because the requesting user lacks entitlements on the underlying SharePoint file.
Read sources and limitations →
Primary category
Skyflow's pattern for isolating sensitive values in a data privacy vault so prompts, training sets and RAG content carry tokens instead of raw identifiers, with role-based re-identification for authorized processes. It governs sensitive fields rather than discovering data estate-wide, and requires application changes to adopt.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me a RAG flow where the vault de-identifies customer records before embedding and only a privileged role can re-identify the values in the answer.
Read sources and limitations →
Primary category
Tonic.ai's de-identification product for unstructured text. It scans files and strings with named-entity models, then redacts or replaces sensitive values with consistent synthetic substitutes for use in LLM prompts, RAG corpora and training sets, with guided review. Governance features beyond RBAC and SSO are not documented.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me a guided redaction project that de-identifies a folder of PDFs, then the SDK call that redacts a live prompt with the same entity configuration.
Read sources and limitations →