Commt
Commt is an AI agent platform on which each agent is bound to the knowledge bases and tools the customer connects to it, with retrieval-augmented generation optional. Agents can run on frontier models from Anthropic, OpenAI and Google or on open-source models such as Llama and Qwen, and the vendor states switching model is a dropdown change that carries instructions and knowledge bases over unchanged. Twenty built-in connectors are listed, spanning messaging and email, work and knowledge tools, and customer and sales tools; agents can be extended with custom MCP servers, which the vendor says run in an isolated environment and are checked for security issues before use. Application, database and document storage run in the EU on private networking, and Enterprise engagements are offered private-server or on-premises deployment with an uptime SLA and named support. On controls, the vendor states that each agent's access to knowledge bases, tools and the internet is set by the customer, that the monthly request limit is checked before each request so a runaway loop cannot consume the remaining allowance, that customers configure refusal topics and low-confidence behaviour, and that every answer cites its sources. By default no message text is written to storage; what is retained is usage metadata such as request counts, latency and which agent answered. Pricing is fixed monthly plans with a defined request allowance rather than metered billing, with the entry plan listed at $244 a month from $349 under a 30% early-access discount. The product was not generally available when captured: it was in an early-access round of 25 seats, with the vendor stating doors open on 12 October 2026. AI Dispatch found no public information, in the source captured, on any compliance certification or attestation (no SOC 2, ISO 27001 or HIPAA claim appears), on any stated EU AI Act or NIST AI RMF posture, on insurance or customer indemnity, or on a tamper-evident audit trail -- the vendor's own statement that message text is not stored by default is inconsistent with a reviewable record of what an agent said. Every field on this entity is evidenced from a single capture of the vendor's own homepage taken on 2026-09-27; no independent or third-party source corroborates these claims, all of which are the vendor's own.
16 fields evidenced · 2 with no public information. Every value below links to the document it came from and the date we checked it.
Also appears in
Trust gap
How this is scoredAre scope, spend, and authority enforced while the agent runs?
Enforced at run time and stated as such: "Commt checks the limit before each request, so an unexpected loop cannot consume the rest of your allowance overnight." Spend is further bounded by an organisation-wide spending cap and per-project spending caps; scope is bounded per agent ("Every agent's access to knowledge bases, tools and the internet is set by you"), with web access off-able at creation and connectors reaching only the configured service; safety guardrails are checked before the answer is returned. Not 3: every statement is vendor self-description on a single marketing capture with no third-party verification, and no enforcement of agent authority beyond connector scoping is published.
Counts Permission scopes, Runtime governance and Safety policy, each cited below.
Is there a tamper-evident record of what it actually did?
No public evidence found. The capture contains no instance of "audit", "tamper" or "hash". The vendor states the opposite of a reviewable action record: "By default, no message text is written to storage. What is kept is the metadata behind your usage report: request counts, latency, which agent answered." The entity_fields row previously filed under audit_trail rested on the single word "logs" inside a bring-your-own-keys FAQ answer and was downgraded to no_public_information in this run. HMAC request signing is listed as an Enterprise bullet, but request signing authenticates a caller; it is not a tamper-evident record of what the agent did. Absence is the finding.
Our automated recount on Sep 29, 2026 counted enough evidenced fields for 1/3. It never reads what those fields say, so it does not overturn the score above, judged on Sep 29, 2026 — but where the two disagree it is a reason to read this dimension again. Why there are two scores
Counts Data handling, each cited below.
How this gap gets closed →Are compliance obligations attached per engagement?
Something published, nothing certified. The Enterprise tier lists "Custom retention and a signed DPA" and "Security review and onboarding" -- contractual undertakings available per engagement. Against that, the capture contains no instance of SOC 2, ISO 27001, HIPAA, GDPR, EU AI Act or NIST. No certification, attestation or audit report is claimed, and no named regulatory framework posture is stated; the regulatory_alignment field was downgraded to no_public_information in this run for exactly that reason. Scored 1 rather than 0 because per-engagement contractual terms are published; 3 would require certification.
Counts Deployment options, each cited below.
How this gap gets closed →Does payment depend on a verified result?
Rubric 0 as written. "Commt uses fixed monthly plans with a defined number of agent requests." Payment is a monthly allowance consumed per request -- "When the allowance is used, your agents stop. No credits, no bundles, no expiring tokens" -- and is in no way conditioned on whether an agent's answer was correct or useful. Nothing in the capture ties any payment or credit to a verified outcome.
Counts Pricing model and Price point, each cited below.
How this gap gets closed →Can the deployment be insured, and is the customer indemnified?
No public evidence found. The capture contains no instance of "insur", "indemnity", "indemnif" or "warrant". No carrier is named, no cover is offered to customers deploying the product, and no customer indemnity is published. Absence is the finding, not a gap in our research.
How this gap gets closed →Assurance
- Audit trail
- no public informationcommt.co · checked Sep 27, 2026 · source did not state this
- Explainability
- Every agent answer cites the specific source passages behind it from the customer's approved knowledge bases.
“Every answer cites its sources in your approved knowledge bases”
commt.co · checked Sep 27, 2026 - Runtime governance
- A monthly request allowance is enforced and checked before each request, so a runaway loop cannot exceed the configured limit.
“Commt checks the limit before each request, so an unexpected loop cannot consume the rest of your allowance overnight.”
commt.co · checked Sep 27, 2026 - Permission scopes
- Each agent's access to knowledge bases, tools and internet browsing is individually scoped by the customer when the agent is created.
“Every agent's access to knowledge bases, tools and the internet is set by you.”
commt.co · checked Sep 27, 2026 - Regulatory alignment
- no public informationcommt.co · checked Sep 27, 2026 · source did not state this
- SLA terms
- Enterprise plan includes an uptime SLA with named support.
“Uptime SLA and named support”
commt.co · checked Sep 27, 2026
Safety
- Safety policy
- Customers can configure guardrails on what an agent may say: refusal topics, data it must never repeat back, and behavior when not confident, checked before the answer is returned.
“Set the topics an agent must refuse, the data it must never repeat back, and what it does when it is not confident.”
commt.co · checked Sep 27, 2026 - Data handling
- By default no message content is stored, only usage metadata (request counts, latency, which agent answered); message text is retained only during an opt-in debug window or when a conversation is flagged.
“By default, no message text is written to storage. What is kept is the metadata behind your usage report: request counts, latency, which agent answered.”
commt.co · checked Sep 27, 2026
Practicality
- Pricing model
- Fixed monthly plans with a defined number of agent requests, rather than metered/usage billing; agents stop when the allowance is used.
“Commt uses fixed monthly plans with a defined number of agent requests.”
commt.co · checked Sep 27, 2026 - Price point
- Entry plan listed at $244/month (from $349) under a 30% early-access discount, including up to 5,000 requests a month. Pro and Enterprise tiers also listed; Enterprise is quoted per contract.
“Entry Startups and Small Teams. Your First Agent in Production. $349 $244 /month Up to 5,000 requests a month.”
commt.co · checked Sep 27, 2026 - Availability
- Not generally available at capture time — early-access/waitlist phase with limited seats, opening 12 October 2026.
“Commt is not open to everyone yet. This round has 25 seats available. Leave your email and we will send you an invitation when it is, along with 30% off the plan you pick, locked for 12 months from the day you join. Doors open 12 October 2026, 09:00 UTC, with 21 of 25 seats left.”
commt.co · checked Sep 27, 2026 - Deployment options
- Enterprise tier offers private server or on-premises deployment, in addition to the standard hosted SaaS offering.
“Private server or on-premises deployment”
commt.co · checked Sep 27, 2026 - Integrations
- Twenty built-in connectors spanning messaging/email, work and knowledge tools, and customer/sales tools -- Zapier among them for reaching further tools. Agents can also be extended with MCP.
“Connect through Commt's built-in integrations or extend an agent with MCP. Slack Microsoft Teams Telegram Jira Confluence Salesforce HubSpot Zapier WhatsApp Instagram Facebook Reddit Google Docs Google Drive Notion Airtable GitHub Zendesk Gmail Outlook Twenty built-in integrations by category”
commt.co · checked Sep 27, 2026 - Supported regions
- EU-hosted: application, database and document storage are kept in the EU on private (non-public-internet) networking.
“Application, database and document storage run in the EU on private networking.”
commt.co · checked Sep 27, 2026
Foundation models
- Base models
- Offers frontier models from Anthropic, OpenAI and Google plus open-source models such as Llama and Qwen, selectable per plan.
“Commt agents can use frontier models from Anthropic, OpenAI and Google, plus open-source models such as Llama and Qwen, through one integration.”
commt.co · checked Sep 27, 2026 - Model swappable
- Switching the underlying model for an agent is a one-click change; instructions and knowledge bases carry over unchanged.
“switching a model is a dropdown change, not a migration, so its instructions and knowledge bases carry over unchanged.”
commt.co · checked Sep 27, 2026
Ecosystem
- Protocols supported
- Supports extending agents via custom MCP servers, which are security-checked in an isolated environment before being enabled.
“A custom MCP server runs in an isolated environment and is checked for security issues before it can be used.”
commt.co · checked Sep 27, 2026 - API access
- Agents can be called directly from a customer's own product via an API key.
“a direct API key for calling the agent from your own product”
commt.co · checked Sep 27, 2026
In the wire
Reporting backed by the same source documents as Commt’s own evidenced fields.