Layer 3 · Pre-Deployment Testing & Ongoing Monitoring
Layers 1 and 2 are runtime shields. Layer 3 spans everything you do before go-live and continuously after — red-teaming and jailbreak-testing your own AI, scanning models for tampering, producing audit-grade compliance evidence, and monitoring production for drift, quality loss and new attacks. Select vendors (or a preset) to see combined coverage — green where covered once, amber where duplicated, red where you have a gap.
Nothing selected — showing how many vendors cover each capability. Click vendors below to build a stack.
Inclusion. A vendor appears here if it meets at least one of three gates: (A) Dominant — named a market leader or material enterprise presence in independent, non-vendor coverage; (B) OWASP-listed — appears in the OWASP GenAI Security Project AI Security Solutions Landscape (Q2 2026); (C) New innovator — launched or materially funded within roughly the last twelve months. At least one open-source option is retained per capability cluster, and acquired vendors are named by acquirer.
Read this before relying on "OWASP-listed." The OWASP Solutions Landscape is a self-submitted directory. Vendors nominate themselves through a submission form, and entries are grouped by sponsorship tier. Appearing in it means submitted and accepted — not independently assessed, benchmarked, or ranked by market share. Treat it as evidence of participation in the community, not of product quality.
Deliberate exclusion. AI gateways (Kong, Cloudflare, Portkey, LiteLLM) are left out by design: a gateway is where policy is enforced, not the engine that decides. That is a judgment call, not an oversight.
Scoring. Placement reflects publicly documented or vendor-claimed capability as of July 2026 — not independent testing. A mark means a capability is claimed to exist, not that it is strong or sufficient for your requirements. Validate finalists against your own traffic before contracting.
Governance plane, added Aug 2026, expanded Aug 22. Gartner published its first Magic Quadrant for AI Governance Platforms on June 16, 2026 — 13 of 100+ evaluated vendors qualified against 8 mandatory capabilities (discovery/registry, risk management, policy enforcement, dynamic risk scoring, evidence collection, interoperability, workflow/approvals, audit trail). Alongside Alation, all 13 Gartner-qualified vendors are now on this map, tagged by MQ placement (MQ-Leader: IBM watsonx.governance, ServiceNow AI Control Tower, Truyo · MQ-Visionary: Airia, Credo AI, ModelOp, Monitaur, OneTrust · MQ-Challenger: Holistic AI · MQ-Niche: Cranium AI, Relyance AI, Saidot, SAP AI Agent Hub). These are system-of-record platforms, not testing tools: expect strength on compliance evidence and policy enforcement, weak-to-none on red-teaming or model scanning. Scoring for the 11 added Aug 22 is a first pass from public positioning, not vendor documentation — thinner evidence than the rest of this map; treat as directional until reviewed against each vendor's docs. Full detail: internal note `AI-GOV~1.MD` §2a.
Red Hat asago, added Aug 25 2026. Launched Aug 4, 2026 — Apache 2.0, backed by IBM, NVIDIA, Microsoft, MIT Lincoln Lab, and the Alan Turing Institute. It reads a written governance policy, maps requirements to NIST AI RMF / OWASP LLM Top 10 / EU AI Act, generates safety tests from that mapping, recommends guardrails, and emits deployment-ready configs — keeping an audit trail from every control back to the policy line. Scored strong on Compliance and Safety (its core function), partial on Red-Teaming, Privacy and Monitoring (it generates tests and an audit trail but doesn't execute attacks or run continuous production monitoring itself), no Model/Supply-Chain Scan capability. It's a free alternative for the compliance-mapping/evidence slice of this layer, not a full-layer replacement — and it needs an actual written governance policy as input, which most organizations don't have yet.
Maintenance. Reviewed quarterly against the OWASP landscape and current vendor documentation. Last review: August 2026.