Best AI Security markBest AI Security

Methodology · Checked against vendor sites, September 2026

How we score AI security tools

The verdict

We score each tool 0-10 on seven weighted criteria that describe control over AI agents on employee devices, using only public vendor material reviewed in September 2026. Totals are computed from the published weights; the rubric is shown below.

What does the score measure?

The endpoint AI control score measures how well a tool documents visibility and control over AI agents, coding assistants and MCP servers on the devices employees and developers use. It rewards the ability to decide on an individual action before it runs. It does not measure overall product quality, and tools built mainly for SaaS or cloud AI apps score lower on some rows for that reason.

What are the seven criteria and weights?

Endpoint AI control score (editorial assessment, 0-10). Measures how well a tool documents visibility and control over AI agents, coding assistants and MCP servers on employee devices. It is not a measure of overall product quality. Tools built for SaaS, cloud or homegrown AI apps score lower on some rows because this rubric weights the endpoint.
CriterionWeightWhat we look for
Endpoint and agent visibility22%Discovery of AI agents, coding assistants, MCP servers, extensions, tools and exposed credentials on devices, fleet-wide.
MCP and tool-call control20%Ability to evaluate and stop an individual tool call or MCP connection before it runs, not only to list it.
Policy granularity15%Rules that use context (user, agent, prior actions, data touched) and actions beyond allow/deny, such as ask, warn, mask or simulate.
Agent vs human identity and audit12%Whether the tool records who triggered an action, whether a person was involved, and the chain from prompt to system action.
Deployment footprint13%How the tool reaches devices; credit for deploying through existing EDR or MDM without a new resident agent, and for published deployment detail.
Coverage beyond the endpoint8%SaaS agents, cloud and homegrown AI apps, browser AI, red teaming.
Maturity and transparency10%Time in market, public documentation, compliance attestations, backing, and whether pricing is published.

How is the total calculated?

Each criterion is scored 0-10. The total is the sum of each score multiplied by its weight, divided by 100, shown to one decimal place. Vendors are sorted by the unrounded total. Vendors with the same one-decimal total share a rank and are listed alphabetically. The totals on every page are computed by the site from the same score table, so they cannot drift.

Endpoint AI control score, editorial assessment 0-10. Weights: visibility 22%, tool-call control 20%, policy 15%, identity and audit 12%, footprint 13%, breadth 8%, maturity 10%.
RankVendorVisibilityTool-call controlPolicyIdentity and auditFootprintBreadthMaturityTotal
1Bay99989437.9
2Noma Security87778977.5
=3Onyx Security78876977.4
=3Zenity88775987.4
=5Harmonic Security77868677.1
=5Koi97756777.1
=7Lasso Security68756866.6
=7Prompt Security76756886.6
9Bloom Security96744546.0

What evidence do we use?

Vendor product pages, documentation, blog posts, pricing pages and press releases, fetched and read in September 2026. Each review lists its sources. We credit a capability when a vendor's public material describes it specifically. When a vendor does not publish something, we write "Not published" and score that row conservatively. Vendor-stated metrics are labelled as such.

What are the limitations?

How often do we update?

We re-check every vendor's public pages each quarter and after acquisitions or major launches. Each page shows its last reviewed date. The next scheduled review is December 2026.

Frequently asked questions

Did you test these products?

No. This is based on public vendor pages and documentation. There was no hands-on testing and no vendor briefing.

Why does Bay rank first if it is a client?

Because the rubric weights endpoint agent control, where Bay's public material is the most specific of the nine. Bay also scores lowest on maturity and transparency, and those rows are shown everywhere Bay appears.

Can a vendor pay to change its score?

No. Scores change only when public evidence changes.