Methodology
What gets listed
A vendor is listed when it ships a product, generally available or in documented public beta, whose main purpose falls in one of the 12 categories, and when at least one claim about it can be sourced to the vendor's own website. Platform suites are listed when they sell a named agent or AI security product. Companies that build AI agents for security operations are out of scope. Vendors cannot pay to appear, to be removed, or to change a score, and nothing here is sponsored.
How claims are sourced
- Product and identity-primitive claims link to the vendor's own documentation.
- Funding and acquisitions link to a press release, an SEC filing, or an established trade publication. Private-market databases are not used.
- Where the docs were read and a capability was not claimed, the page says "No public claim found". That is a statement about the documentation, not about the product.
- Analyst mentions and customer or revenue claims are shown with their source and are never scored.
- Capabilities announced but not yet generally available are not counted as claims.
The signal score
A 0 to 100 visibility signal, compared within a category only. It is not a quality rating or a recommendation.
| Component | Points | Inputs |
|---|---|---|
| Capital | 35 | Disclosed private funding on a log scale, normalised across the dataset. Public companies score the maximum. Undisclosed funding scores 0. Acquired vendors keep their last disclosed total. |
| Product evidence | 25 | 10 for a generally available product with public documentation (products the vendor labels beta, preview, or early access score 0), 2 per identity primitive the vendor claims in its own docs (up to 10), and 5 for a free tier or open source. |
| Standards participation | 20 | 5 per verifiable contribution (OWASP AI security landscape listing, CoSAI membership, MCP specification or extension authorship, MITRE ATLAS contribution, IETF draft), up to 20. Standards participation is assessed from public member lists and specification credits; a zero means no verified entry yet, not a finding against the vendor. |
| Momentum | 20 | 10 for a funding round, general availability, or major release in the last 12 months. 10 more for an active open source repository (not archived, pushed in the last 90 days) or, for closed products, a dated release in the last 6 months. |
GitHub stars, review sites, and analyst labels are excluded from the score. Ties are ordered alphabetically.
Freshness
The build refuses to publish when data is older than its limit: open acquisitions after 45 days, funding after 120 days, the open source snapshot after 30 days, and any vendor record after 180 days. Every vendor page shows when it was last verified.
Corrections
Found an error? Send a correction with a link to a primary source. Corrections are logged on the changelog.