AppSecNews
AI Security Commercial Emerging

Lasso Security

by Lasso Security

GenAI security platform covering discovery of AI tools in use, inspection of prompts and responses, and controls on what data reaches a model.

Visit lasso.security (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Lasso Security in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 4 points in this profile are not yet confirmed against vendor documentation.
  • Full product module list and naming, confirm with vendor
  • Deployment options beyond browser extension, confirm
  • Integration and connector coverage, confirm
  • Extent of Model Context Protocol and agent security features, confirm

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Lasso Security works the GenAI problem from two ends. The first is visibility: finding which AI services people and applications in the organization are actually using, including the ones nobody approved. That discovery is typically endpoint and network observed rather than inventory declared, which is the only approach that catches an employee pasting a customer list into a chat interface on a personal account.

The second is inspection of the traffic itself. Prompts and responses are examined for sensitive data leaving the organization, for injection attempts arriving, and for policy violations in either direction, with the option to redact or block rather than only record. The vendor also publishes research on AI-adjacent exposure, including data that remains retrievable through AI-powered interfaces after the source repository was made private, which is a good illustration of the category of risk they are aiming at.

Where it fits

Two placements for two problems. The discovery and employee usage side sits on endpoints and at the network edge, owned by security operations, and is about governing consumption of third-party AI. The application-protection side sits in the request path of your own GenAI services. Most organizations need the first before they need the second, because you cannot write a policy for tools you have not found.

Strengths

  • Addresses shadow AI usage directly, which for many organizations is a larger near-term exposure than anything in their own LLM code.
  • Covers both consumption of external AI and protection of internally built services, so one vendor spans two programs that often get split.
  • Research output on AI data exposure is specific and has surfaced real issues rather than theoretical ones.

Limitations

  • A young vendor in a fast-moving category. Product scope has expanded quickly, so depth varies between modules and should be tested rather than assumed.
  • Endpoint and browser-based enforcement requires deployment to managed devices, and is weak or absent where work happens on unmanaged ones.
  • Inline inspection of prompts means an additional system sees potentially sensitive content, which needs its own data handling review.

Who it suits

Suited to enterprises whose immediate concern is employees using AI tools the organization has no visibility into, and that want discovery and control from one place. Less suited to an engineering-led team that has no shadow AI problem and wants a self-hosted library in the application path, where an open-source guard gives more control and no additional data flow.

Used Lasso Security? Recommend it under your own name and title.

Recommend this tool