AI Dispatch

Browse by what vendors disclose

Categories tell you what a tool does. These tell you what its makers are willing to put in writing — and quote the sentence where they put it. Every entry on these pages carries the page it came from and the date we read it.

AI agents and vendors that state SOC 2

231

Entries whose own published documentation mentions SOC 2. Each one quotes the sentence it came from, so you can see whether the vendor claims SOC 2 Type I, Type II, or simply says the words.

AI agents that support the Model Context Protocol

166

Entries whose documentation states MCP support. Protocol claims are among the easiest to verify and the fastest to go stale, so the retrieval date next to each is worth reading.

AI agents and vendors that state GDPR compliance

209

Entries whose published pages reference GDPR. A mention is not an adequacy decision — read the quote, which is often narrower than the claim implied by the badge on the page it came from.

AI agents and vendors that state HIPAA compliance

106

Entries whose documentation references HIPAA. For anything touching protected health information, the quote matters more than the claim: several of these describe HIPAA-eligible infrastructure rather than a signed BAA.

Open-source AI agents

51

Entries describing themselves as open source. We record the claim and quote it; we do not resolve what licence actually governs the code, which is a question the repository answers better than a marketing page.

Self-hosted and on-premise AI agents

88

Entries that state a self-hosted or on-premise deployment option — the question every buyer with a data-residency constraint asks first, and one general agent directories do not record at all.

AI agents and vendors that state ISO 27001

79

Entries referencing ISO 27001 certification in their own documentation, each with the sentence it was taken from.

AI agents and vendors that reference the EU AI Act

28

The smallest facet here, and the most telling: of more than 750 published entries, only these mention the EU AI Act on their own pages at all.

AI agents and vendors that state SOC 2 Type II

127

A narrower claim than plain SOC 2: Type II means an auditor reviewed controls operating over a period of time, not just their design at a single point. Read the quote — several sources here say only "Type 2" with no further detail.

AI agents and vendors that state CCPA compliance

46

Entries whose documentation references the California Consumer Privacy Act — the one major US state-level privacy law with enough separate mentions in the index to be worth its own page, distinct from GDPR.

AI agents that state a human-in-the-loop control

65

Entries whose own documentation describes requiring human approval or review before the agent acts — the runtime-governance question a buyer asks before letting an agent take an irreversible action. Read the quote: several describe an optional mode rather than an enforced default.

AI agents that state scoped or role-based permissions

76

Entries whose documentation states least-privilege, role-based, or scoped access control on what the agent may do — the containment question a security reviewer asks first. A stated control is not an audited one; the quote is what you get, not an assurance that it is enforced as described.

AI agents that publish an uptime SLA

41

Entries that state a numeric uptime commitment (99.9%, 99.99%, and the like) in their own service terms — an availability claim general directories do not record. A published figure is a promise, not a measured result; the retrieval date next to each says when we read it.

AI agents priced on outcomes, not tokens or seats

13

The sharpest expression of the thesis, and the smallest facet here: entries whose own pricing ties payment to a verified result — pay-per-resolution, success fees, per-outcome billing — rather than to usage or headcount. Of more than 750 published entries, only these state it.

AI agents and vendors that publish a self-reported performance figure

48

Entries whose own documentation states a specific performance number they measured on their own system — uptime, accuracy, latency, time saved, a benchmark score. This is the entity's own claim about itself, not an independent evaluation of it; read the quote for what was actually measured and against what baseline.

AI agents and vendors that state a tamper-evident audit trail

23

The smallest facet here, and the most exacting: entries whose own documentation names an actual mechanism — a hash chain, a cryptographic signature, an append-only or WORM design — behind their audit trail, not just the words "audit trail." Of more than 750 published entries, only these describe how the record resists tampering rather than simply asserting that one exists.