Methodology · Checked against vendor sites, September 2026
How we score AI security tools
The verdict
We score each tool 0-10 on seven weighted criteria that describe control over AI agents on employee devices, using only public vendor material reviewed in September 2026. Totals are computed from the published weights; the rubric is shown below.
What does the score measure?
The endpoint AI control score measures how well a tool documents visibility and control over AI agents, coding assistants and MCP servers on the devices employees and developers use. It rewards the ability to decide on an individual action before it runs. It does not measure overall product quality, and tools built mainly for SaaS or cloud AI apps score lower on some rows for that reason.
What are the seven criteria and weights?
| Criterion | Weight | What we look for |
|---|---|---|
| Endpoint and agent visibility | 22% | Discovery of AI agents, coding assistants, MCP servers, extensions, tools and exposed credentials on devices, fleet-wide. |
| MCP and tool-call control | 20% | Ability to evaluate and stop an individual tool call or MCP connection before it runs, not only to list it. |
| Policy granularity | 15% | Rules that use context (user, agent, prior actions, data touched) and actions beyond allow/deny, such as ask, warn, mask or simulate. |
| Agent vs human identity and audit | 12% | Whether the tool records who triggered an action, whether a person was involved, and the chain from prompt to system action. |
| Deployment footprint | 13% | How the tool reaches devices; credit for deploying through existing EDR or MDM without a new resident agent, and for published deployment detail. |
| Coverage beyond the endpoint | 8% | SaaS agents, cloud and homegrown AI apps, browser AI, red teaming. |
| Maturity and transparency | 10% | Time in market, public documentation, compliance attestations, backing, and whether pricing is published. |
How is the total calculated?
Each criterion is scored 0-10. The total is the sum of each score multiplied by its weight, divided by 100, shown to one decimal place. Vendors are sorted by the unrounded total. Vendors with the same one-decimal total share a rank and are listed alphabetically. The totals on every page are computed by the site from the same score table, so they cannot drift.
| Rank | Vendor | Visibility | Tool-call control | Policy | Identity and audit | Footprint | Breadth | Maturity | Total |
|---|---|---|---|---|---|---|---|---|---|
| 1 | Bay | 9 | 9 | 9 | 8 | 9 | 4 | 3 | 7.9 |
| 2 | Noma Security | 8 | 7 | 7 | 7 | 8 | 9 | 7 | 7.5 |
| =3 | Onyx Security | 7 | 8 | 8 | 7 | 6 | 9 | 7 | 7.4 |
| =3 | Zenity | 8 | 8 | 7 | 7 | 5 | 9 | 8 | 7.4 |
| =5 | Harmonic Security | 7 | 7 | 8 | 6 | 8 | 6 | 7 | 7.1 |
| =5 | Koi | 9 | 7 | 7 | 5 | 6 | 7 | 7 | 7.1 |
| =7 | Lasso Security | 6 | 8 | 7 | 5 | 6 | 8 | 6 | 6.6 |
| =7 | Prompt Security | 7 | 6 | 7 | 5 | 6 | 8 | 8 | 6.6 |
| 9 | Bloom Security | 9 | 6 | 7 | 4 | 4 | 5 | 4 | 6.0 |
What evidence do we use?
Vendor product pages, documentation, blog posts, pricing pages and press releases, fetched and read in September 2026. Each review lists its sources. We credit a capability when a vendor's public material describes it specifically. When a vendor does not publish something, we write "Not published" and score that row conservatively. Vendor-stated metrics are labelled as such.
What are the limitations?
- Public sources only. We did not run the products.
- No hands-on testing, no lab work, and no vendor interviews or briefings.
- Public detail varies. A younger or quieter vendor can score lower because it documents less, not because its product does less. This affects Bay and Bloom Security in particular.
- Acquisitions change products quickly. Koi and Prompt Security now sit inside larger platforms, and their public pages may lag the product.
- Scores are editorial judgement against a published rubric, not user reviews or benchmark results.
How often do we update?
We re-check every vendor's public pages each quarter and after acquisitions or major launches. Each page shows its last reviewed date. The next scheduled review is December 2026.
Frequently asked questions
Did you test these products?
No. This is based on public vendor pages and documentation. There was no hands-on testing and no vendor briefing.
Why does Bay rank first if it is a client?
Because the rubric weights endpoint agent control, where Bay's public material is the most specific of the nine. Bay also scores lowest on maturity and transparency, and those rows are shown everywhere Bay appears.
Can a vendor pay to change its score?
No. Scores change only when public evidence changes.