Research
Bold Featured in SACR's Endpoint Control and Prevention Market Report

Get our take on why the ECP category is important right now and how Bold fits in.

Software Analyst Cyber Research (SACR) is betting on the endpoint. Their newest research, The CISO Guide to Endpoint Control and Prevention (ECP): The Next Architecture for Endpoint Security, outlines a world where work is moving back to the endpoint, and legacy tools built for the network and cloud eras weren't designed to see it. That's the gap ECP is built to close.

TL;DR

We're thrilled to be featured in Software Analyst Cyber Research's (SACR) new market map on Endpoint Control and Prevention (ECP). SACR placed us in Zones 4 and 5, recognizing our intent-aware, data-centric approach to protecting sensitive data on the endpoint. Below, we break down what the ECP market is according to their report, why the category matters right now, and how Bold fits into it.

"Bold is a critical vendor leading the way for what intent-aware enforcement should look like in the ECP market. Running data classification directly on the device and for more threat analysis in the future, rather than depending on cloud decisions, is exactly the architecture and outcome security teams need to be able to keep up in this rapidly evolving AI risk landscape on the endpoint."
— Lawrence Pingree, Head of Data Security and AI Research, SACR

About the Report

SACR is an independent cybersecurity research firm covering the cybersecurity landscape, providing free, ungated research (which we highly appreciate). This new Endpoint Control and Prevention market guide maps the vendors and architectures defining how sensitive data is protected on the device in the AI era. 

First, What Is ECP?

If you haven't read the report, here's the short version: Endpoint Control and Prevention is SACR's framework for the technologies protecting data, behavior, and AI activity directly on the device. It's organized into five “zones:”

  • Zone 1: Software Posture & Governance: Inventories and assesses the software running on the endpoint, including browser extensions, MCP servers, packages, and models, to catch risk before it can execute.
  • Zone 2: Application Layer Enforcement: Sits between native apps and AI agents to gate risky tool calls or data sharing mid-flow, without ending the session.
  • Zone 3: Agent Runtime Visibility (AI-EDR): Builds endpoint telemetry and behavioral baselines above the OS layer to catch anomalies in how agents act.
  • Zone 4: Intent-Aware Behavioral Analysis: Evaluates the intent behind an action, not just the action itself, replacing binary blocking with real-time, adaptive guardrails.
  • Zone 5: Data-Centric Enforcement: Classifies, traces, and intercepts sensitive data movement at the moment of creation, use, or exfiltration, wherever it happens on the device.

Our Take on Why This Category Matters Now

The endpoint is where people, AI, and data now converge. Every new AI tool, agent, and MCP connection is another way for sensitive data to leave, and it's happening faster than most security teams can keep up with.

That's created a real blind spot. Network, cloud, and browser tools go dark the moment data reaches the device: it's the one layer they were never built to reach. Desktop AI apps encrypt their own traffic, so some of the riskiest activity on the endpoint today never touches a network inspection point at all.

Legacy tools make that worse, not better. Regex-based classification can't see anything past predictable formats like SSNs and credit card numbers, so the data that causes the most damage (source code, financial models, proprietary work) is usually the data the tool is least equipped to catch. What it can see, it floods with false positives. Faced with that noise, most security teams quietly turn blocking off, which turns a prevention tool into a detection tool. The result is a tradeoff no one should have to make: block everything and disrupt real work, or monitor only and accept the risk.

How Bold Fits into the ECP Market

SACR placed Bold in two zones, and we think that's the right read on where our architecture actually delivers value.

Zone 5: Data-Centric Enforcement

This is the core of what Bold does. Bold runs on-device AI models directly on the endpoint to classify data by meaning, not pattern. That means source code, financial models, and other proprietary data get classified without a single regex rule, and it means classification happens at the moment data is created, used, or moved, not after a round trip to the cloud. Because Bold's models run locally, they keep classifying and enforcing even when a device is offline or the data is moving through an AI app that encrypts its own traffic and never reaches a network proxy.

Zone 4: Intent-Aware Behavioral Analysis

Classifying the data is only half the picture. Bold also reasons about the intent behind an action: what's being done with the data, by whom, and whether it fits the moment. That's what lets Bold replace a binary block-or-allow decision with real-time coaching, a redirect to a safe alternative, or a hard block reserved for the clearest cases of exfiltration. It's also what makes it possible to tell a human's action apart from an AI agent's by reading the endpoint's process tree, a distinction most tools in the market can't make at all.

Together, these two zones are why Bold can act at the point of action instead of only detecting after the fact: real-time prevention, not next-day alerts.

Where We See This Market Going

Point tools solving one zone at a time will keep leaving gaps for attackers and shadow AI to exploit. We expect the market to consolidate around vendors who can connect data, behavior, and intent from a single, shared context on the endpoint, rather than stitching those signals together across separate tools after the fact.

Endpoint Control and Prevention is a name for something we've believed since we started Bold: the endpoint is where data, people, and AI now converge, and it's the one layer legacy tools were never built to protect. Huge thanks to our friends Lawrence Pingree and Francis Odum for all the work that went into mapping this category so thoughtfully and for representing us so accurately. 

Read the full SACR Endpoint Control and Prevention report to see the complete vendor landscape. Talk to Bold to see what real-time, on-device data protection looks like against your own environment.