Control & trust
Which AI agent platforms document SOC 2, SSO, RBAC and audit controls?
Of 946 vendors, 516 document full security and identity coverage: role based access control (RBAC), single sign on (SSO), audit trails, encryption, least privilege tool access, a compliance posture such as SOC 2 or ISO 27001, and a stated data handling policy. Another 323 document partial coverage and 107 document none at all.
Every vendor in the index is assessed against the same 14 point taxonomy from public documentation, and no vendor pays for placement. Counts on this page were measured across all 946 public vendors on September 30, 2026.
How the 946 vendors split
No public evidence means the reviewed sources did not document the capability. On this index that is a statement about the evidence, not proof that the capability is absent. See methodology.
What counts as full coverage
Full coverage means both halves are published: a documented access surface, meaning identity integration such as SSO or SAML or a named access model such as RBAC, together with a compliance posture, meaning an attestation, a certification or a trust center naming the controls. Either half alone is Partial, so a SOC 2 badge with nothing documented about who inside your organization can make an agent do what sits at Partial, as does a deep control surface with no attestation unless that gap is stated openly. Audit logging is credited on observability rather than here, and sovereign, air gapped or on premises delivery is credited on deployment rather than here.
How to read these numbers
117 vendors document nothing here, and the lane pattern explains most of it. The security and SOC lane leads at 70 percent because it sells to the people who write the questionnaire. Data analyst agents at 34 percent and browser at 35 trail, with GTM at 40, and these are lanes where individual teams often buy without a security review, so the documentation never gets written. Note the direction of causation before penalizing a small vendor: this axis measures published evidence, and a startup with real controls but no published SOC 2 report and no trust center scores the same as one with neither.
Leading platform for security, identity & governance in each use case
Picked mechanically: the highest total coverage vendor in each lane that documents full evidence on this axis, one vendor per row. Scores are out of 14.
-
1. Appian, for enterprise operations agents
14 / 14Full enterprise operations agents ranking · Compare the whole lane on all 14 axes
-
2. FLOWX.AI, for multi-agent platforms
14 / 14Full multi-agent platforms ranking · Compare the whole lane on all 14 axes
-
3. Gumloop, for GTM and revenue agents
14 / 14Full GTM and revenue agents ranking · Compare the whole lane on all 14 axes
-
4. Mastra, for agent infrastructure platforms
14 / 14Full agent infrastructure platforms ranking · Compare the whole lane on all 14 axes
-
5. ServiceNow, for customer support agents
14 / 14Full customer support agents ranking · Compare the whole lane on all 14 axes
-
6. UiPath, for agent builders
14 / 14Full agent builders ranking · Compare the whole lane on all 14 axes
-
7. GitHub Copilot, for coding agents
13.5 / 14Full coding agents ranking · Compare the whole lane on all 14 axes
-
8. Dataiku, for data analyst agents
13 / 14Full data analyst agents ranking · Compare the whole lane on all 14 axes
-
9. HappyRobot, for voice agents
13 / 14Full voice agents ranking · Compare the whole lane on all 14 axes
-
10. Adopt AI, for browser and computer-use agents
12.5 / 14Full browser and computer-use agents ranking · Compare the whole lane on all 14 axes
-
11. Torq, for security and SOC agents
12.5 / 14Full security and SOC agents ranking · Compare the whole lane on all 14 axes
-
12. Edge Delta, for SRE and DevOps agents
12 / 14Full SRE and DevOps agents ranking · Compare the whole lane on all 14 axes
-
13. Innovaccer, for healthcare agents
11.5 / 14Full healthcare agents ranking · Compare the whole lane on all 14 axes
Documented coverage by use case
Share of each lane documenting full coverage on this axis. Vendors that sit in two lanes count in both, the same rule the rankings and matrices use.
| Use case | Full coverage | Share |
|---|---|---|
| SRE and DevOps agents | 28 of 37 | 76% |
| agent builders | 75 of 115 | 65% |
| multi-agent platforms | 32 of 52 | 62% |
| customer support agents | 69 of 113 | 61% |
| agent infrastructure platforms | 114 of 186 | 61% |
| coding agents | 37 of 64 | 58% |
| enterprise operations agents | 173 of 297 | 58% |
| browser and computer-use agents | 22 of 42 | 52% |
| voice agents | 41 of 83 | 49% |
| security and SOC agents | 39 of 85 | 46% |
| GTM and revenue agents | 55 of 138 | 40% |
| data analyst agents | 23 of 59 | 39% |
| healthcare agents | 26 of 69 | 38% |
Recent verified changes from the vendors named above
Capability coverage is not a static picture. These are the most recent sourced change log entries for the platforms listed above, newest first, one per vendor. Scores on this page update as entries like these are verified.
-
ServiceNow security / enterprise
High impactServiceNow's August and September updates to AI Control Tower add an AI Asset Inventory with domain separation, integrations for governance and monitoring, and expanded oversight features.
September 17, 2026 · Partially Verified · All ServiceNow changes
-
UiPath security / enterprise
Medium impactOrganization Administrators can now use the Check access API to retrieve effective access permissions for users, groups, or external applications across the entire organization. The results include both organization-scoped and tenant-level assignments.
August 5, 2026 · Verified · All UiPath changes
-
GitHub Copilot security / enterprise
Medium impactGitHub is retiring the Copilot Billing Preview app. Users are now directed to review and manage their Copilot spend directly in their native billing settings, which include AI usage pages, budget caps, and raw usage data exports.
August 4, 2026 · Verified · All GitHub Copilot changes
-
Gumloop security / enterprise
Medium impactGumloop 9.11.0 added the ability to add skills from Shared With Me and Organization tabs directly to agents, and introduced skill permission roles — Editor, Viewer, and Use Only — so teams can govern who can update, inspect, or use skills inside agents.
June 2, 2026 · Verified · All Gumloop changes
-
Mastra deployment / data residency
Medium impactAny environment on Mastra's hosted platform can now get a Postgres database that accepts connections only from inside the same private network. It is created with one CLI command or at deploy time, placed in the environment's region and wired in automatically.
October 1, 2026 · Verified · All Mastra changes
Full change log · updated weekly across the whole index
Questions buyers ask
Does a full score mean the vendor holds SOC 2?
Not by itself. Certification is one form of evidence among several, and this axis also weighs access control, identity integration and auditability. Always confirm the specific certification, its type and its date directly with the vendor.
What is the most common gap?
Agent level permissioning. Plenty of vendors document company level RBAC and SSO while saying nothing about constraining which tools an individual agent may call, which is the control that matters once agents act on their own.
How does this differ from the oversight axis?
Security governs who and what may act. Human oversight governs whether a person has to approve the action. A platform can score well on one and poorly on the other, and enterprise buyers usually need both.
The other 13 axes
No single axis decides a shortlist. Buyers who care about this one usually check human oversight & guardrails and observability & auditability next, or open the full taxonomy to see how the 14 axes fit together.