Browse by what vendors disclose
Categories tell you what a tool does. These tell you what its makers are willing to put in writing — and quote the sentence where they put it. Every entry on these pages carries the page it came from and the date we read it.
AI agents and vendors that state SOC 2
231Entries whose own published documentation mentions SOC 2. Each one quotes the sentence it came from, so you can see whether the vendor claims SOC 2 Type I, Type II, or simply says the words.
AI agents that support the Model Context Protocol
166Entries whose documentation states MCP support. Protocol claims are among the easiest to verify and the fastest to go stale, so the retrieval date next to each is worth reading.
AI agents and vendors that state GDPR compliance
209Entries whose published pages reference GDPR. A mention is not an adequacy decision — read the quote, which is often narrower than the claim implied by the badge on the page it came from.
AI agents and vendors that state HIPAA compliance
106Entries whose documentation references HIPAA. For anything touching protected health information, the quote matters more than the claim: several of these describe HIPAA-eligible infrastructure rather than a signed BAA.
Open-source AI agents
51Entries describing themselves as open source. We record the claim and quote it; we do not resolve what licence actually governs the code, which is a question the repository answers better than a marketing page.
Self-hosted and on-premise AI agents
88Entries that state a self-hosted or on-premise deployment option — the question every buyer with a data-residency constraint asks first, and one general agent directories do not record at all.
AI agents and vendors that state ISO 27001
79Entries referencing ISO 27001 certification in their own documentation, each with the sentence it was taken from.
AI agents and vendors that reference the EU AI Act
28The smallest facet here, and the most telling: of more than 750 published entries, only these mention the EU AI Act on their own pages at all.
AI agents and vendors that state SOC 2 Type II
127A narrower claim than plain SOC 2: Type II means an auditor reviewed controls operating over a period of time, not just their design at a single point. Read the quote — several sources here say only "Type 2" with no further detail.
AI agents and vendors that state CCPA compliance
46Entries whose documentation references the California Consumer Privacy Act — the one major US state-level privacy law with enough separate mentions in the index to be worth its own page, distinct from GDPR.
AI agents that state a human-in-the-loop control
65Entries whose own documentation describes requiring human approval or review before the agent acts — the runtime-governance question a buyer asks before letting an agent take an irreversible action. Read the quote: several describe an optional mode rather than an enforced default.
AI agents that state scoped or role-based permissions
76Entries whose documentation states least-privilege, role-based, or scoped access control on what the agent may do — the containment question a security reviewer asks first. A stated control is not an audited one; the quote is what you get, not an assurance that it is enforced as described.
AI agents that publish an uptime SLA
41Entries that state a numeric uptime commitment (99.9%, 99.99%, and the like) in their own service terms — an availability claim general directories do not record. A published figure is a promise, not a measured result; the retrieval date next to each says when we read it.
AI agents priced on outcomes, not tokens or seats
13The sharpest expression of the thesis, and the smallest facet here: entries whose own pricing ties payment to a verified result — pay-per-resolution, success fees, per-outcome billing — rather than to usage or headcount. Of more than 750 published entries, only these state it.
AI agents and vendors that publish a self-reported performance figure
48Entries whose own documentation states a specific performance number they measured on their own system — uptime, accuracy, latency, time saved, a benchmark score. This is the entity's own claim about itself, not an independent evaluation of it; read the quote for what was actually measured and against what baseline.
AI agents and vendors that state a tamper-evident audit trail
23The smallest facet here, and the most exacting: entries whose own documentation names an actual mechanism — a hash chain, a cryptographic signature, an append-only or WORM design — behind their audit trail, not just the words "audit trail." Of more than 750 published entries, only these describe how the record resists tampering rather than simply asserting that one exists.