Agentic Index
Agentic AI platforms that meet enterprise security and compliance requirements (2026)
Of the 548 agentic AI platforms in the Agentic Index, 111 document all four enterprise governance capabilities in full. That is 20.3% of the field. This is a bar, not a leaderboard: a platform either documents all four in its own public materials or it does not clear, and Partial evidence on any one of the four does not count.
The finding underneath the list is more useful than the list. The enterprise governance gap in agentic AI is a deployment and data residency gap, not a SOC 2 gap. Observability and auditability is documented in full by 58% of the pool, human oversight and guardrails by 53%, and security and identity governance by 58%. Deployment and data residency is documented in full by only 50%. Of the 138 platforms sitting exactly one capability short of the bar, 54 are short on residency alone.
The bar, and how the 548 platforms score against it
| Capability | What has to be documented | Full | Only blocker |
|---|---|---|---|
| Security and identity governance | SOC 2 or ISO 27001, single sign on (SSO or SAML), role based access control (RBAC) | 320 (58%) | 21 |
| Deployment and data residency | self hosted or private VPC deployment, and documented control over where agent data is processed | 275 (50%) | 54 |
| Observability and auditability | tracing and audit logging across agent runs | 317 (58%) | 10 |
| Human oversight and guardrails | human approval before an agent action executes | 288 (53%) | 53 |
Full means the vendor publishes evidence meeting the capability in its own public materials, under the Agentic Index verification standard. Only blocker counts platforms that document the other three in full and fail on this one alone.
Clears the bar and scores 12.5 or higher of 14 overall
These 31 platforms document all four governance capabilities in full and also sit at the top of the Agentic Index coverage score across all 14 capabilities. Ordered by total coverage, ties broken alphabetically.
-
1.Appian
14.0 / 14 capabilities
enterprise operations agents, agent builders
Process automation that anchors agents inside governed process models, so approval steps and audit trails are properties of the process rather than of each agent.
-
2.FLOWX.AI
14.0 / 14 capabilities
enterprise operations agents, multi-agent platforms, agent builders, agent infrastructure platforms
Enterprise agentic platform with a published trust page: ISO 27001 certified, SOC 2 Type I completed in June 2026 with Type II in progress and the report under NDA, and GDPR. Documents all four governance capabilities inside the platform, with Observatory compliance mappings the customer runs over its own AI estate.
-
3.Gumloop
14.0 / 14 capabilities
agent builders
SOC 2 Type II and GDPR with a public trust center, role based and attribute based access control with per tool authorization policies, and Gumstack tracing every tool call back to a specific user, agent or service principal. Deployment runs as managed SaaS or into the customer's own cloud as a VPC in their chosen region, and the changelog records approval rights widening from the named recipient to anyone who can chat with the agent.
-
4.Mastra
14.0 / 14 capabilities
agent infrastructure platforms
Open source framework whose governance surface is priced on the page: SSO on Teams, RBAC and audit logs on Enterprise, SOC 2 documentation and a hosted trust center. The licensed self hosted edition keeps traces, prompts and outputs in the customer's VPC and the Platform can run on premises, traces record each run step by step, and tools can be held for approval per tool, per request or per call.
-
5.Microsoft
14.0 / 14 capabilities
enterprise operations agents
Copilot Studio's security and governance page names certifications and regulatory compliance beside data loss prevention, environment routing and an automatic security scan, and data residency follows the environment's geography. The Monitor tab reports sessions, quality and errors, and human supervision escalates decisions to a named reviewer.
-
6.ServiceNow
14.0 / 14 capabilities
enterprise operations agents, multi-agent platforms
Enterprise workflow platform whose Now Assist agents automate IT, employee and customer processes inside the existing ServiceNow governance and audit surface.
-
7.UiPath
14.0 / 14 capabilities
enterprise operations agents, multi-agent platforms, agent builders
Agentic automation orchestrating agents, robots and people end to end through Maestro. One of seven platforms on this page documenting all four governance capabilities while scoring 14 of 14 overall.
-
8.Pega
13.5 / 14 capabilities
enterprise operations agents, agent builders
The Pega Trust Center publishes the documents behind its attestations, from a Pega Cloud SOC 2 Type 2 report and ISO 27001 and ISO 42001 certificates to a FedRAMP package and a DoD IL4 authorization. Infinity 26 runs on Pega Cloud or in the client's own managed cloud, with an EU service boundary and AWS GovCloud for US public sector, Agent Tracer records every agent step, and agents pull a person in when an approval is needed.
-
9.StackAI
13.5 / 14 capabilities
enterprise operations agents, agent builders
A security and governance documentation tree rather than a security page: role based access control, groups, workspace and folder access, project controls and admin enforced feature access, with a dedicated On-Premise page and an enterprise CLI for running StackAI on customer infrastructure. Observability has its own section with analytics, manager and evaluator pages plus an analytics REST endpoint, and Human in the Loop ships as a core node.
-
10.Agno
13.0 / 14 capabilities
agent infrastructure platforms
High performance agent runtime, formerly Phidata, Apache 2.0 licensed. The lightest weight thing on this list and it still documents all four, which is unusual for a runtime rather than a suite.
-
11.Base44
13.0 / 14 capabilities
agent builders
A first party trust center names SOC 2 Type II and ISO 27001 alongside GDPR, with encryption in transit and at rest, secrets held in a cloud key service, and penetration testing described. Enterprise workspaces can also choose US, EU or UK storage for app data.
-
12.CrewAI
13.0 / 14 capabilities
multi-agent platforms
Open source multi agent orchestration for collaborative crews. Notable because open source frameworks are the least likely class in the pool to document residency and approval controls, and this one does both.
-
13.Databricks Agent Bricks
13.0 / 14 capabilities
multi-agent platforms
Unity Catalog applies role based access to models, tools and connections, so end users reach only the subagents and data they are granted, and the compliance docs name HIPAA, PCI-DSS and FedRAMP profiles. It runs on AWS, Azure and Google Cloud with a published region list, traces every tool and model call through MLflow, and can hold a destructive MCP call for approval under a service policy in beta.
-
14.Dataiku
13.0 / 14 capabilities
multi-agent platforms, agent builders
SSO through SAML, OIDC, LDAP and Kerberos, per project permissions and an audit trail are documented, with ISO 27001, ISO 27701 and ISO 42001 on the trust page and SOC 2 Type II for Dataiku Cloud. It runs as managed Dataiku Cloud or on the customer's own infrastructure, traces every LLM Mesh call, and lets a tool require human approval before an agent calls it.
-
15.n8n
13.0 / 14 capabilities
agent builders
The open source entry, and the one with a gap stated out loud. The security configuration tree documents SAML and OIDC single sign on, MFA enforcement, a self service security audit, node blocking, encryption key rotation and redaction of execution data, but no attestation appears anywhere in the documentation, so this Full rests on controls with the certificate carrying a verification flag. Install options run from one line setup to Kubernetes on every major cloud, executions are first class objects traceable to OpenTelemetry, and a Guardrails node plus approval before tool execution carry the oversight half.
-
16.Relevance AI
13.0 / 14 capabilities
multi-agent platforms, agent builders
Role based access control, SSO, audit logs and PII masking sit on the enterprise tier, an organization picks its region at signup from the US, EU or Australia, and execution traces and audit logs can stream to the customer's own storage. Approvals are set per edge, so a sensitive action waits for a person.
-
17.Replit Agent
13.0 / 14 capabilities
agent builders
The entry least like its neighbors, and the one whose Full needs reading closely. Security is SOC 2 Type II with SAML single sign on, enterprise audit logs with SIEM integration and an analytics dashboard, but deployment coverage is about what customers publish, autoscale, scheduled, static and always on, rather than self hosting Replit itself. Oversight is the task review loop, where the customer reviews agent work before applying it back to their main version.
-
18.Sim
13.0 / 14 capabilities
multi-agent platforms, agent builders
The Sim Trust Center lists SOC 2 Type II, ISO 27001 and GDPR, and access control is documented in depth: SAML and OIDC single sign on across Okta, Entra ID, Google Workspace and ADFS, plus workspace roles. The platform is open source, so a security team can read the code as well as the reports.
-
19.Tray.ai
13.0 / 14 capabilities
agent infrastructure platforms
Tray states SOC 1 and SOC 2 Type 2, HIPAA, GDPR and CCPA, with roles, an access allowlist and RBAC on Agent Gateway and log masking per step. Instances run in a US, EU or APAC region with an on premise agent and AWS PrivateLink for systems behind the firewall, every run logs each step, and approval steps route to Slack, email or a form.
-
20.Tungsten Automation
13.0 / 14 capabilities
enterprise operations agents, agent builders
TotalAgility Cloud carries US federal, state and local and Australian government authorizations, with SOC 2 Type II, NIST, HIPAA and GDPR on Tungsten's trust center, and TotalAgility also runs on the customer's premises. Agents' AI tool use is logged in full under MCP governance, and exceptions route to a person inside the workflow.
-
21.Warp
13.0 / 14 capabilities
multi-agent platforms
An agentic development environment whose governance is documented for teams: a SOC 2 Type 2 attestation from an accredited third party with the report requestable through a Trust Center, SAML single sign on on Business and enforced sign on through a provider such as Okta, self hosted cloud agents with inference through the customer's own cloud on Enterprise, and a persistent record of every cloud agent run covering its prompt, plan, commands, files changed and outputs.
-
22.Writer
13.0 / 14 capabilities
enterprise operations agents, agent infrastructure platforms
Enterprise platform on its own Palmyra model family with a dedicated developer estate at dev.writer.com. Documents all four governance capabilities, and every cell was re based this month off the vendor's own documentation rather than the June stubs it had been resting on.
-
23.Adopt AI
12.5 / 14 capabilities
enterprise operations agents
A dedicated security page names SOC 2 Type II across all five trust criteria and ISO 27001, with SSO and MFA on every account and support access the customer must approve each time. For agents that reach into finance systems, that last control is the one to confirm in the contract.
-
24.Akka
12.5 / 14 capabilities
multi-agent platforms, agent builders, agent infrastructure platforms
The trust center lists SOC 2 Type II on request, ISO 27001, ISO 42001, PCI DSS and HIPAA among its standards, and Akka runs self managed on the customer's own infrastructure, in the customer's VPC or in Akka's serverless cloud. A hash chained interaction log records every agent interaction, and workflows pause durably for an approval command.
-
25.Boomi
12.5 / 14 capabilities
enterprise operations agents, multi-agent platforms, agent builders
Integration platform with an agent control tower over enterprise systems, which is where its residency and observability evidence comes from.
-
26.Fabrix.ai
12.5 / 14 capabilities
enterprise operations agents, agent builders
SOC 2 certified and deployable on premises or in the customer's private cloud with the model layer included, and AI Personas scope which models, tools and prompts each role reaches. The Agent Control Plane traces every run step by step with PII masking and audit trails, and approvals are a primitive of the orchestration layer.
-
27.Harvey
12.5 / 14 capabilities
enterprise operations agents
The one vertical product in this tier and the fullest attestation set on the page: SOC 2 Type II, ISO 27001, ISO 27701 and ISO 42001 with a public trust center, alongside SAML SSO, IP allow listing and customer set retention. The customer keeps everything in region across EU or Switzerland, US or Australia on separate application hosts, every claim in agent output carries a citation, and the plan gate is Harvey's own mechanism: preview the plan, adjust the scope, approve, then work begins.
-
28.Kestra
12.5 / 14 capabilities
multi-agent platforms, agent infrastructure platforms
Open source orchestration platform whose Enterprise Edition adds SSO, LDAP and SCIM, role based access with a permissions reference, audit logs and a secrets manager, with Kestra Cloud stated SOC 2 compliant. It self hosts under Apache 2.0 and the Enterprise Edition runs on cloud, on premises or air gapped, every execution is inspectable step by step, and a Pause task holds a flow for manual approval.
-
29.OutSystems
12.5 / 14 capabilities
multi-agent platforms, agent builders
The incumbent entry, and it documents the whole bar. A public trust center carries SOC 2 Type II, ISO 27001, ISO 22301, ISO 27017 and ISO 27018; ODC self hosted deployment, published March 2026, runs apps, data and agents in the customer's own private cloud, public cloud or on premises Kubernetes; distributed traces make an agent a filterable asset in its own right; and a Human activity element pauses a workflow for a decision.
-
30.Salesforce
12.5 / 14 capabilities
enterprise operations agents
CRM platform whose Agentforce layer runs autonomous agents across sales, service and marketing, inheriting the Salesforce trust and permissions model the buyer already administers.
-
31.Torq
12.5 / 14 capabilities
enterprise operations agents
Security hyperautomation platform whose HyperSOC agents run triage, investigation and response inside governed workflows. Access runs through roles, scopes and SSO, workspaces sit in the United States, the European Union or Japan, and self hosted step runners keep workflow steps inside the customer's environment; audit logs export to Amazon S3 and approval steps govern response. Qualifies here on secondary lane membership as an enterprise operations platform, which a buyer scanning this list should know.
The remaining 80 platforms that clear the bar
Every one of these documents all four governance capabilities in full. They score below 12.5 of 14 on total coverage, which says something about breadth across the whole taxonomy, not about their governance posture.
| Platform | Lanes | Coverage |
|---|---|---|
| Atomicwork | enterprise operations agents | 12.0 / 14 |
| Augment Code | multi-agent platforms | 12.0 / 14 |
| Beam AI | enterprise operations agents | 12.0 / 14 |
| CrowdStrike | multi-agent platforms, agent builders | 12.0 / 14 |
| Dify | agent builders | 12.0 / 14 |
| dSilo | enterprise operations agents, multi-agent platforms, agent builders | 12.0 / 14 |
| Glean | enterprise operations agents | 12.0 / 14 |
| Haystack | agent infrastructure platforms | 12.0 / 14 |
| Leena AI | enterprise operations agents | 12.0 / 14 |
| Minded | agent builders | 12.0 / 14 |
| Oracle | enterprise operations agents | 12.0 / 14 |
| Peakflo | enterprise operations agents, agent builders | 12.0 / 14 |
| SS&C Blue Prism | enterprise operations agents, agent builders | 12.0 / 14 |
| Windmill | agent builders, agent infrastructure platforms | 12.0 / 14 |
| Workato | enterprise operations agents | 12.0 / 14 |
| xpander.ai | agent infrastructure platforms | 12.0 / 14 |
| Activepieces | agent builders | 11.5 / 14 |
| Automat AI | enterprise operations agents | 11.5 / 14 |
| Coworker | enterprise operations agents, agent builders | 11.5 / 14 |
| Delight.ai | agent infrastructure platforms | 11.5 / 14 |
| Itential | agent infrastructure platforms | 11.5 / 14 |
| LangSmith | agent infrastructure platforms | 11.5 / 14 |
| Legion Intelligence | multi-agent platforms, agent builders | 11.5 / 14 |
| Tines | enterprise operations agents, agent builders | 11.5 / 14 |
| Anchor Browser | agent infrastructure platforms | 11.0 / 14 |
| Artian | enterprise operations agents, multi-agent platforms | 11.0 / 14 |
| Cohere North | agent builders | 11.0 / 14 |
| ContraForce | enterprise operations agents | 11.0 / 14 |
| Ema | enterprise operations agents | 11.0 / 14 |
| Instabase | enterprise operations agents | 11.0 / 14 |
| Joget | enterprise operations agents, agent builders | 11.0 / 14 |
| Leah AI | enterprise operations agents | 11.0 / 14 |
| LexisNexis | enterprise operations agents | 11.0 / 14 |
| Nanonets | enterprise operations agents | 11.0 / 14 |
| Parashift | enterprise operations agents | 11.0 / 14 |
| Serval | enterprise operations agents, agent builders | 11.0 / 14 |
| Thread AI | agent builders, agent infrastructure platforms | 11.0 / 14 |
| Trigger.dev | agent infrastructure platforms | 11.0 / 14 |
| Vibrium AI | enterprise operations agents | 11.0 / 14 |
| Altilia | multi-agent platforms, agent builders | 10.5 / 14 |
| Auditoria | enterprise operations agents | 10.5 / 14 |
| BlinkOps | agent builders | 10.5 / 14 |
| Bluebricks | agent infrastructure platforms | 10.5 / 14 |
| Clio | enterprise operations agents | 10.5 / 14 |
| Drata | enterprise operations agents | 10.5 / 14 |
| Forest | enterprise operations agents, agent infrastructure platforms | 10.5 / 14 |
| Legora | enterprise operations agents | 10.5 / 14 |
| Moderne | agent infrastructure platforms | 10.5 / 14 |
| Netlify | agent infrastructure platforms | 10.5 / 14 |
| OpenRouter | agent infrastructure platforms | 10.5 / 14 |
| Palo Alto Networks | enterprise operations agents | 10.5 / 14 |
| SentinelOne | agent infrastructure platforms | 10.5 / 14 |
| Superblocks | enterprise operations agents, agent builders | 10.5 / 14 |
| Swimlane | agent builders | 10.5 / 14 |
| Workday | enterprise operations agents | 10.5 / 14 |
| Zeron | agent builders | 10.5 / 14 |
| Braintrust | agent infrastructure platforms | 10.0 / 14 |
| Browserbase | agent infrastructure platforms | 10.0 / 14 |
| LangWatch | agent infrastructure platforms | 10.0 / 14 |
| Nexus Intelligence | enterprise operations agents | 10.0 / 14 |
| Variance | enterprise operations agents | 10.0 / 14 |
| Chamber | agent infrastructure platforms | 9.5 / 14 |
| Luminance | enterprise operations agents | 9.5 / 14 |
| Obin AI | enterprise operations agents | 9.5 / 14 |
| TrueFoundry | agent infrastructure platforms | 9.5 / 14 |
| Extend | agent infrastructure platforms | 9.0 / 14 |
| F5 AI Guardrails | agent infrastructure platforms | 9.0 / 14 |
| Galileo | agent infrastructure platforms | 9.0 / 14 |
| Kinaxis | enterprise operations agents | 9.0 / 14 |
| Mentat | enterprise operations agents | 9.0 / 14 |
| Opik | agent infrastructure platforms | 9.0 / 14 |
| W&B Weave | agent infrastructure platforms | 9.0 / 14 |
| Browserless | agent infrastructure platforms | 8.5 / 14 |
| C TWO | enterprise operations agents, agent infrastructure platforms | 8.5 / 14 |
| DraftWise | enterprise operations agents | 8.5 / 14 |
| Fiddler AI | agent infrastructure platforms | 8.5 / 14 |
| Kernel | agent infrastructure platforms | 8.5 / 14 |
| Okta | agent infrastructure platforms | 8.5 / 14 |
| Qorelo | enterprise operations agents | 8.0 / 14 |
| Lakera | agent infrastructure platforms | 7.0 / 14 |
Common questions
Which agentic AI platforms meet enterprise security and compliance requirements?
Of 548 agentic AI platforms in the Agentic Index, 111 document all four enterprise governance capabilities in full: security and identity governance, deployment and data residency, observability and auditability, and human oversight and guardrails. That is 20.3% of the field. The list is ordered by total documented coverage across the Agentic Index 14 point capability taxonomy and is graded from public evidence only.
What counts as meeting enterprise security and compliance requirements for an AI agent platform?
Four things, and a platform has to document all four in public materials to clear the bar used here. A compliance posture such as SOC 2 or ISO 27001 with single sign on (SSO or SAML) and role based access control (RBAC). Self hosted or private VPC deployment with control over where agent data is processed. Tracing and audit logging across agent runs. And a human approval step before an agent action executes. Partial evidence on any one of the four does not clear.
Why do so few agentic AI platforms clear the bar?
Deployment and data residency, not SOC 2. Across the 548 platform pool, observability is documented in full by 58%, human oversight by 53% and security and identity by 58%, but deployment and data residency by only 50%. Of the 138 platforms sitting exactly one capability short of the bar, 54 are short on residency alone. The enterprise governance gap in agentic AI is a residency gap.
Is this ranking paid or sponsored?
No. No vendor pays for placement, no vendor has reviewed this page, and every grade comes from the vendor's own public materials under the Agentic Index verification standard. 956 vendors are graded against the same 14 capabilities. Data last verified October 3, 2026.
Method: membership is the same 548 platform pool used by the best agentic AI platforms in 2026, drawn from 956 researched vendors. Every grade comes from the vendor's own public materials under the Agentic Index verification standard. No vendor pays for placement and no vendor has reviewed this page. Data last verified October 3, 2026. How this evidence is graded
Related: platforms that support Model Context Protocol tools, agent observability platforms, best agentic AI platforms, autonomous AI workforce platforms, agentic security operations platforms ranked for alert triage, production ready AI agents, how every vendor scores on security and identity governance, healthcare agents, where not one vendor clearing the bar publishes data residency, compare platforms side by side.