Skip to content

The 11 LangSmith security checks Black Cat runs

Black Cat SSPM evaluates 11 security policies against your LangSmith configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.

How to connect LangSmith — what access Black Cat needs, and why.

AI governance (4)

Lifecycle & offboarding (3)

Other checks (4)

severity: medium LangSmith Agent High Tool Diversity fix difficulty: medium #

Review and reduce the number of tools used by the agent

  1. Review the agent code for unnecessary tool bindings
  2. Remove tools that are not actively used

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3

severity: high LangSmith Agent External API Tools fix difficulty: medium #

Review external API tool access

  1. Identify which external APIs the agent calls
  2. Ensure API keys have minimum required permissions
  3. Add rate limiting where possible

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3

severity: low LangSmith Agent Dataset Access fix difficulty: medium #

Review dataset contents for sensitive data

  1. Open LangSmith > Datasets
  2. Review linked datasets for PII or sensitive content
  3. Apply data masking if needed

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium LangSmith Agent Retriever Tools fix difficulty: medium #

Review vector store and retriever tool access

  1. Identify which knowledge bases the retriever queries
  2. Ensure data classification matches agent access level
  3. Restrict retriever to necessary data scopes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial