Skip to content

Methodology

What gets listed

A vendor is listed when it ships a product, generally available or in documented public beta, whose main purpose falls in one of the 12 categories, and when at least one claim about it can be sourced to the vendor's own website. Platform suites are listed when they sell a named agent or AI security product. Companies that build AI agents for security operations are out of scope. Vendors cannot pay to appear, to be removed, or to change a score, and nothing here is sponsored.

How claims are sourced

The signal score

A 0 to 100 visibility signal, compared within a category only. It is not a quality rating or a recommendation.

ComponentPointsInputs
Capital35Disclosed private funding on a log scale, normalised across the dataset. Public companies score the maximum. Undisclosed funding scores 0. Acquired vendors keep their last disclosed total.
Product evidence2510 for a generally available product with public documentation (products the vendor labels beta, preview, or early access score 0), 2 per identity primitive the vendor claims in its own docs (up to 10), and 5 for a free tier or open source.
Standards participation205 per verifiable contribution (OWASP AI security landscape listing, CoSAI membership, MCP specification or extension authorship, MITRE ATLAS contribution, IETF draft), up to 20. Standards participation is assessed from public member lists and specification credits; a zero means no verified entry yet, not a finding against the vendor.
Momentum2010 for a funding round, general availability, or major release in the last 12 months. 10 more for an active open source repository (not archived, pushed in the last 90 days) or, for closed products, a dated release in the last 6 months.

GitHub stars, review sites, and analyst labels are excluded from the score. Ties are ordered alphabetically.

Freshness

The build refuses to publish when data is older than its limit: open acquisitions after 45 days, funding after 120 days, the open source snapshot after 30 days, and any vendor record after 180 days. Every vendor page shows when it was last verified.

Corrections

Found an error? Send a correction with a link to a primary source. Corrections are logged on the changelog.