Control & trust

Which AI agent platforms document SOC 2, SSO, RBAC and audit controls?

Of 946 vendors, 516 document full security and identity coverage: role based access control (RBAC), single sign on (SSO), audit trails, encryption, least privilege tool access, a compliance posture such as SOC 2 or ISO 27001, and a stated data handling policy. Another 323 document partial coverage and 107 document none at all.

Every vendor in the index is assessed against the same 14 point taxonomy from public documentation, and no vendor pays for placement. Counts on this page were measured across all 946 public vendors on September 30, 2026.

How the 946 vendors split

Full coverage516 vendors, 54.5%
Partial coverage323 vendors, 34.1%
No public evidence107 vendors, 11.3%

No public evidence means the reviewed sources did not document the capability. On this index that is a statement about the evidence, not proof that the capability is absent. See methodology.

What counts as full coverage

Full coverage means both halves are published: a documented access surface, meaning identity integration such as SSO or SAML or a named access model such as RBAC, together with a compliance posture, meaning an attestation, a certification or a trust center naming the controls. Either half alone is Partial, so a SOC 2 badge with nothing documented about who inside your organization can make an agent do what sits at Partial, as does a deep control surface with no attestation unless that gap is stated openly. Audit logging is credited on observability rather than here, and sovereign, air gapped or on premises delivery is credited on deployment rather than here.

How to read these numbers

117 vendors document nothing here, and the lane pattern explains most of it. The security and SOC lane leads at 70 percent because it sells to the people who write the questionnaire. Data analyst agents at 34 percent and browser at 35 trail, with GTM at 40, and these are lanes where individual teams often buy without a security review, so the documentation never gets written. Note the direction of causation before penalizing a small vendor: this axis measures published evidence, and a startup with real controls but no published SOC 2 report and no trust center scores the same as one with neither.

Leading platform for security, identity & governance in each use case

Picked mechanically: the highest total coverage vendor in each lane that documents full evidence on this axis, one vendor per row. Scores are out of 14.

  1. 1. Appian, for enterprise operations agents

    14 / 14

    Full enterprise operations agents ranking · Compare the whole lane on all 14 axes

  2. 2. FLOWX.AI, for multi-agent platforms

    14 / 14

    Full multi-agent platforms ranking · Compare the whole lane on all 14 axes

  3. 3. Gumloop, for GTM and revenue agents

    14 / 14

    Full GTM and revenue agents ranking · Compare the whole lane on all 14 axes

  4. 4. Mastra, for agent infrastructure platforms

    14 / 14

    Full agent infrastructure platforms ranking · Compare the whole lane on all 14 axes

  5. 5. ServiceNow, for customer support agents

    14 / 14

    Full customer support agents ranking · Compare the whole lane on all 14 axes

  6. 6. UiPath, for agent builders

    14 / 14

    Full agent builders ranking · Compare the whole lane on all 14 axes

  7. 7. GitHub Copilot, for coding agents

    13.5 / 14

    Full coding agents ranking · Compare the whole lane on all 14 axes

  8. 8. Dataiku, for data analyst agents

    13 / 14

    Full data analyst agents ranking · Compare the whole lane on all 14 axes

  9. 9. HappyRobot, for voice agents

    13 / 14

    Full voice agents ranking · Compare the whole lane on all 14 axes

  10. 10. Adopt AI, for browser and computer-use agents

    12.5 / 14

    Full browser and computer-use agents ranking · Compare the whole lane on all 14 axes

  11. 11. Torq, for security and SOC agents

    12.5 / 14

    Full security and SOC agents ranking · Compare the whole lane on all 14 axes

  12. 12. Edge Delta, for SRE and DevOps agents

    12 / 14

    Full SRE and DevOps agents ranking · Compare the whole lane on all 14 axes

  13. 13. Innovaccer, for healthcare agents

    11.5 / 14

    Full healthcare agents ranking · Compare the whole lane on all 14 axes

Documented coverage by use case

Share of each lane documenting full coverage on this axis. Vendors that sit in two lanes count in both, the same rule the rankings and matrices use.

Use case Full coverage Share
SRE and DevOps agents 28 of 37 76%
agent builders 75 of 115 65%
multi-agent platforms 32 of 52 62%
customer support agents 69 of 113 61%
agent infrastructure platforms 114 of 186 61%
coding agents 37 of 64 58%
enterprise operations agents 173 of 297 58%
browser and computer-use agents 22 of 42 52%
voice agents 41 of 83 49%
security and SOC agents 39 of 85 46%
GTM and revenue agents 55 of 138 40%
data analyst agents 23 of 59 39%
healthcare agents 26 of 69 38%

Recent verified changes from the vendors named above

Capability coverage is not a static picture. These are the most recent sourced change log entries for the platforms listed above, newest first, one per vendor. Scores on this page update as entries like these are verified.

  1. ServiceNow security / enterprise

    High impact

    ServiceNow's August and September updates to AI Control Tower add an AI Asset Inventory with domain separation, integrations for governance and monitoring, and expanded oversight features.

    September 17, 2026 · Partially Verified · All ServiceNow changes

  2. UiPath security / enterprise

    Medium impact

    Organization Administrators can now use the Check access API to retrieve effective access permissions for users, groups, or external applications across the entire organization. The results include both organization-scoped and tenant-level assignments.

    August 5, 2026 · Verified · All UiPath changes

  3. GitHub Copilot security / enterprise

    Medium impact

    GitHub is retiring the Copilot Billing Preview app. Users are now directed to review and manage their Copilot spend directly in their native billing settings, which include AI usage pages, budget caps, and raw usage data exports.

    August 4, 2026 · Verified · All GitHub Copilot changes

  4. Gumloop security / enterprise

    Medium impact

    Gumloop 9.11.0 added the ability to add skills from Shared With Me and Organization tabs directly to agents, and introduced skill permission roles — Editor, Viewer, and Use Only — so teams can govern who can update, inspect, or use skills inside agents.

    June 2, 2026 · Verified · All Gumloop changes

  5. Mastra deployment / data residency

    Medium impact

    Any environment on Mastra's hosted platform can now get a Postgres database that accepts connections only from inside the same private network. It is created with one CLI command or at deploy time, placed in the environment's region and wired in automatically.

    October 1, 2026 · Verified · All Mastra changes

Full change log · updated weekly across the whole index

Questions buyers ask

Does a full score mean the vendor holds SOC 2?

Not by itself. Certification is one form of evidence among several, and this axis also weighs access control, identity integration and auditability. Always confirm the specific certification, its type and its date directly with the vendor.

What is the most common gap?

Agent level permissioning. Plenty of vendors document company level RBAC and SSO while saying nothing about constraining which tools an individual agent may call, which is the control that matters once agents act on their own.

How does this differ from the oversight axis?

Security governs who and what may act. Human oversight governs whether a person has to approve the action. A platform can score well on one and poorly on the other, and enterprise buyers usually need both.

The other 13 axes

No single axis decides a shortlist. Buyers who care about this one usually check human oversight & guardrails and observability & auditability next, or open the full taxonomy to see how the 14 axes fit together.

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.