LESSON · 24 SEPTEMBER 2026
How to read AI security vendor claims
The verdict
Treat every number on a vendor page as vendor-stated until you see it on your own devices, read "Not published" as a question to ask rather than a missing feature, and turn each claim into a request to watch it work. This site labels claims that way so you can do the same.
By Best AI Security editors · 24 September 2026 · 2 min read
What does "vendor-stated" mean?
It means the figure comes from the vendor's own page and has not been checked by us. Examples on this site include Bay's stated deployment time and false positive rate and Lasso Security's throughput and latency figures for LEAP. They may be accurate, but they were measured by the vendor, on its chosen workload.
What does "Not published" mean?
It means we could not find the information on the vendor's public pages when we checked in September 2026. It does not prove the capability is absent. Pricing is the most common example: none of the nine vendors on this site publishes list prices, so their price rows say "Contact sales".
How should analyst mentions be read?
Several vendors cite Gartner, Latio or other analyst reports. In September 2026, for instance, both Zenity and Noma Security said they were named Market Shapers in Gartner's Emerging Market Quadrant for AI Application Security, Startup Vendors. These are the vendors' own summaries of reports we have not read in full, and our news page presents them that way.
How do you turn a claim into a test?
- Ask to see the claim on a device you choose, not a prepared demo machine.
- Ask which agents and operating systems the claim covers.
- Ask for the same test with a rule in simulation, then enforced.
Our scoring method explains how we weigh documented and undocumented capabilities.
What should you ask when a page says nothing?
Silence on a vendor page can mean the feature exists but is not documented publicly, that it is on the roadmap, or that it does not exist. Only the vendor can say which, and only a demonstration settles it. On this site, examples include deployment methods that are not published for Zenity and Bloom Security, per-tool-call enforcement that is not detailed for Prompt Security, and the list of supported agent surfaces for Bay. Put each gap on your list of demo requests. Our buyer's checklist has 30 questions grouped by the four checkpoints.
Next lesson
Related
Sources
- How we score · Reviewed Sep 2026
- Zenity newsroom, 23 Sep 2026 · Reviewed Sep 2026
- Noma Security blog, 23 Sep 2026 · Reviewed Sep 2026
- Lasso Security, LEAP · Reviewed Sep 2026