Coverage · September 2026 research
Coverage compared
Thirty controls for AI use on company computers, scored for seventeen security products from their public documentation, and for Lamplighter from what ships today. Select any cell in the grid to see the evidence behind its score.
| Control | Lamplighter20/30 | Microsoft13/30 | Netskope12/30 | Zscaler9/30 | Cyberhaven7/30 | SentinelOne7/30 | Palo Alto5/30 | Harmonic Security4/30 | Island2/30 | LayerX2/30 | Nightfall2/30 | Noma Security2/30 | Push Security2/30 | Check Point1/30 | CrowdStrike1/30 | Cisco1/30 | Menlo Security0/30 | Cato Networks0/30 |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Discovery and inventory | ||||||||||||||||||
| F01AI app discovery, catalogue and risk scoring | ||||||||||||||||||
| F02Personal vs corporate account (instance) awareness | ||||||||||||||||||
| F03Installed desktop AI app and CLI inventory and control | ||||||||||||||||||
| F04AI browser-extension inventory and control | ||||||||||||||||||
| F05Local LLM runtime detection and exposure | ||||||||||||||||||
| F06Embedded/SaaS AI visibility (feature or compliance API) | ||||||||||||||||||
| F07OS and browser-native AI control (Recall, AI browsers) | ||||||||||||||||||
| Data in motion | ||||||||||||||||||
| F08Paste/typing inspection with block, warn or coach | ||||||||||||||||||
| F09File-upload inspection | ||||||||||||||||||
| F10Sensitivity-label awareness | ||||||||||||||||||
| F11ML/semantic classification beyond regex | ||||||||||||||||||
| F12Redaction before send | ||||||||||||||||||
| F13Desktop-app and IDE/CLI data gates (non-browser) | ||||||||||||||||||
| F14Response/downstream inspection | ||||||||||||||||||
| F15Share-link and public-exposure control | ||||||||||||||||||
| F16Screenshot/image (OCR) assessment | ||||||||||||||||||
| Agents and connectors | ||||||||||||||||||
| F17MCP server and agent discovery | ||||||||||||||||||
| F18MCP gateway and tool-call inspection | ||||||||||||||||||
| F19Agent autonomy and config-file monitoring | ||||||||||||||||||
| F20Agent action guardrails (file, credential, install) | ||||||||||||||||||
| F21API-key-on-disk scanning | ||||||||||||||||||
| F22OAuth grant and agent-credential governance (API side) | ||||||||||||||||||
| F23OAuth consent interception (endpoint side) | ||||||||||||||||||
| F24Prompt-injection and jailbreak detection | ||||||||||||||||||
| Governance and evidence | ||||||||||||||||||
| F25Coaching with justification capture | ||||||||||||||||||
| F26Request, approval and exception workflow | ||||||||||||||||||
| F27ISO 42001 and audit evidence pack | ||||||||||||||||||
| F28Prompt/event logging, audit trail and SIEM export | ||||||||||||||||||
| F29Monitoring lawfulness (metadata-first, DPIA, notice) | ||||||||||||||||||
| Enforcement | ||||||||||||||||||
| F30Browser, isolation or network blocking of AI apps | ||||||||||||||||||
- 0 no evidence found
- 1 partial or limited
- 2 documented
- 3 documented, singled out as a strength
- Lamplighter:
- S shipped
- P scheduled
- + proposed
Cell basis
Select any cell to see the evidence behind its score.
How we scored this
Thirty controls in five groups, drawn from the categories the security research on AI at the endpoint discusses. Each cell is the level of coverage we could evidence from public product documentation and analyst material reviewed in September 2026. A zero means we found no documentation of that control, not that the product lacks it; a few vendor pages could not be reached, so treat each vendor’s score as a floor.
Lamplighter’s column shows what ships today (S), work already scheduled (P) and controls we have proposed but not yet planned (+); only shipped controls count in its score unless you tick the box above. It blocks sending and uploading to AI apps in the browser; whole sites are blocked through the web-gateway and AppLocker lists it exports. The MCP gateway is in early access.
Think we have scored a product wrongly? Tell us and we will check it and correct this page.