Each circle is a guardrail capability. Select one or more vendors to see combined coverage — green where a capability is covered once, amber where two+ vendors duplicate it (paying twice), and red where nothing you've selected covers it (a gap). Goal: full coverage, no duplicate spend.
Nothing selected — showing how many vendors cover each capability. Click vendors below to build a stack.
Inclusion. A vendor appears here if it meets at least one of three gates: (A) Dominant — named a market leader or material enterprise presence in independent, non-vendor coverage; (B) OWASP-listed — appears in the OWASP GenAI Security Project AI Security Solutions Landscape (Q2 2026); (C) New innovator — launched or materially funded within roughly the last twelve months. At least one open-source option is retained per capability cluster, and acquired vendors are named by acquirer.
Read this before relying on "OWASP-listed." The OWASP Solutions Landscape is a self-submitted directory. Vendors nominate themselves through a submission form, and entries are grouped by sponsorship tier. Appearing in it means submitted and accepted — not independently assessed, benchmarked, or ranked by market share. Treat it as evidence of participation in the community, not of product quality.
Deliberate exclusion. AI gateways (Kong, Cloudflare, Portkey, LiteLLM) are left out by design: a gateway is where policy is enforced, not the engine that decides. That is a judgment call, not an oversight.
Scoring. Placement reflects publicly documented or vendor-claimed capability as of July 2026 — not independent testing. A mark means a capability is claimed to exist, not that it is strong or sufficient for your requirements. Validate finalists against your own traffic before contracting.
Maintenance. Reviewed quarterly against the OWASP landscape and current vendor documentation. Last review: July 2026.