Service-as-a-Software in Regulated Markets
Outcome-priced AI service delivery: autonomous workflows execute the bulk of execution-heavy cognitive work while domain specialists act as supervisors, auditors and escalation owners. The compliance consequence is that accountability shifts to measured outcomes — accuracy, escalation rates and evidence — rather than billable effort.
This is the design lens: compliance designed into the system — control objectives, components, patterns and the evidence plan — not audited onto it afterwards.
Enterprise chassis — Four-Layer TRiSM Enterprise Stack
Enterprise-wide chassis (per-workload blueprints plug into layers 2–4)
Vendor market layer
Functional vendor categories (17)
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Credo AI | AI governance platform | Policy packs, risk tiering and evidence workflows mapped across frameworks. Typical: AI registry, policy administration. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | ISO 42001 alignment (claimed)EU AI Act readiness positioning |
| Holistic AI | AI governance & audit | Risk assessment, bias auditing and regulatory reporting workflows. Typical: bias audit, regulatory reporting. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | NYC LL144 audit support (claimed)EU AI Act readiness positioning |
| IBM watsonx.governance | AI governance platform | Governance, factsheets and monitoring integrated with the IBM stack. Typical: factsheets, model monitoring. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | ISO 42001 alignment (claimed)Art. 11 documentation support (claimed) |
| ModelOp | AI/model governance | Model and agent inventory with automated lifecycle controls for large estates. Typical: model inventory, control automation. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | model-risk positioning (SR 11-7 style, claimed)ISO 42001 alignment (claimed) |
| Monitaur | insurance & lending model governance | Model governance and documentation aimed at insurance and lending supervision. Typical: insurance underwriting, credit decisioning. Scope overlap: Its model-governance scope overlaps this platform's own; we have a commercial interest in the comparison. | SaaS (vendor cloud) | NAIC model-governance positioning (claimed)SR 11-7 practice alignment (claimed) |
| OneTrust | GRC & privacy platform | Privacy and AI governance modules extending an existing GRC system of record. Typical: DPIA/FRIA workflow, policy management. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | ISO 27001 (claimed)GDPR-positioned |
| ServiceNow | intake & ITSM workflow | Use-case intake, approval workflow and risk records inside an existing ITSM estate. Typical: AI intake, policy administration. Scope overlap: Its AI-governance module overlaps this platform's own scope; we have a commercial interest in the comparison. | SaaS (vendor cloud) | ISO 42001 alignment (claimed)EU AI Act readiness positioning |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Lakera | guardrail proxy | Inline prompt-injection and content detection at request time. Typical: injection defence, content filtering. | not checked | SOC 2 (claimed)supports Art. 15 robustness measures (claimed) |
| HiddenLayer | model/agent detection & response | Model-layer detection and response with adversarial-attack telemetry. Typical: model threat detection, red-team telemetry. | not checked | SOC 2 (claimed)supports Art. 15 robustness measures (claimed) |
| Palo Alto Prisma AIRS | network-integrated AI security | AI runtime security folded into an existing enterprise network security estate. Typical: enterprise rollout, egress control. | not checked | SOC 2 (claimed)enterprise security integration (claimed) |
| Cisco AI Defense | network-integrated AI security | Discovery of AI usage plus inline enforcement across the corporate network. Typical: shadow-AI discovery, inline enforcement. | not checked | enterprise security integration (claimed) |
| NVIDIA NeMo Guardrails | open guardrail framework | Programmable dialogue and action rails, self-hostable alongside your models. Typical: dialogue rails, action gating. | open source | supports Art. 15 robustness measures (claimed) |
| Guardrails AI | open guardrail framework | Open validator library for structured output checks and policy validators. Typical: output validation, schema enforcement. | open source | OSS, no vendor certification |
| Garak | adversarial scanner | Open-source LLM vulnerability scanner used for pre-deployment probing. Typical: red-teaming, release gating. | not checked | OSS, no vendor certificationsupports Art. 15 testing evidence (claimed) |
| Protect AI | ML supply-chain & model security | Model scanning and ML supply-chain security tooling (Palo Alto Networks acquisition reported 2025). Typical: model scanning, supply-chain security. | SaaS (vendor cloud) | supports Art. 15 cybersecurity measures (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Azure AI Search | managed retrieval | Managed hybrid search with security trimming against tenant identities. Typical: ACL-aware RAG, enterprise search. | not checked | ISO 27001 (claimed)SOC 2 (claimed) |
| Databricks Unity Catalog | governed lakehouse | Catalog and lineage spanning tables, features and RAG chunks. Typical: lineage evidence, governed RAG. | not checked | SOC 2 (claimed)lineage/Art. 10 support (claimed) |
| Relyance AI | code-level data & AI lineage | Parses source repositories to map data and inference flows at code level, with CI checks on changes to those flows. Typical: data lineage, shift-left privacy review. Scope overlap: Its AI-governance reporting scope overlaps this platform's own; we have a commercial interest in the comparison. | SaaS (vendor cloud) | GDPR programme tooling (claimed)EU AI Act readiness positioning |
| Snowflake Cortex | governed lakehouse | Model calls inside the warehouse boundary with masking and clean rooms. Typical: in-warehouse inference, governed analytics. | not checked | SOC 2 (claimed)ISO 27001 (claimed)HIPAA-eligible (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| OpenAI (Enterprise / API) | proprietary frontier | Enterprise tiers offer zero-data-retention and no-training commitments over the commercial API. Typical: general copilots, document reasoning. | not checked | SOC 2 (claimed)ISO 27001 (claimed)zero-data-retention tier (claimed)GDPR-positioned |
| Anthropic Claude (Enterprise) | proprietary frontier | Enterprise/ZDR tiers with published safety and model documentation practice. Typical: regulated assistants, long-context analysis. | not checked | SOC 2 (claimed)ISO 27001 (claimed)zero-data-retention tier (claimed)HIPAA-eligible (claimed) |
| Google Gemini Enterprise | proprietary frontier | Vertex-hosted frontier models with regional grounding and customer-managed keys. Typical: enterprise search, multimodal workflows. | not checked | SOC 2 (claimed)ISO 27001 (claimed)HIPAA-eligible (claimed)EU data-boundary positioning |
| Cohere | proprietary frontier | Private-cloud and on-prem deployment of retrieval-oriented models. Typical: private RAG, enterprise search. | self-hostable | SOC 2 (claimed) |
| Mistral AI | open-weight / EU | EU-headquartered provider; positions its open-weight offering for EU sovereignty and auditability requirements — the open-source exemption question is contested and not treated here as settled. Typical: sovereign deployments, self-hosted inference. | self-hostable | EU sovereignty positioning |
| Meta Llama | open-weight / EU | Openly licensed weights that can be self-hosted under your own jurisdiction and inspection regime. Typical: self-hosted inference, air-gapped deployments. | not checked | open-weight sovereignty positioning |
| Gretel | synthetic data | Synthetic tabular and text generation with privacy metrics for training-data substitution. Typical: bias mitigation, data minimisation. | not checked | Art. 10 data-governance support (claimed)GDPR-positioned |
| Tonic.ai | synthetic data | De-identification and synthetic test data for regulated development environments. Typical: test data, de-identified pipelines. | not checked | SOC 2 (claimed)HIPAA-positioned |
| MOSTLY AI | synthetic data | Synthetic data generation with fairness and representativeness reporting. Typical: bias mitigation, data sharing. | not checked | GDPR-positionedArt. 10 data-governance support (claimed) |
| Scale AI | fine-tuning / data ops | Human labelling, evaluation and RLHF pipelines for enterprise fine-tuning. Typical: fine-tuning, model evaluation. | not checked | SOC 2 (claimed)evaluation-evidence positioning |
| Weights & Biases | fine-tuning / MLOps | Experiment tracking, model registry and evaluation records across training runs. Typical: training records, model registry. | not checked | SOC 2 (claimed)Art. 11 documentation support (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| LangChain / LangGraph | agent framework | Graph-structured agent runtime; interrupt/pause nodes support implementing human approval at defined steps. Typical: multi-step agents, approval workflows. | not checked | supports implementing Art. 14 oversight (claimed)supports Art. 12 step logging (claimed) |
| LlamaIndex | RAG framework | Indexing and query abstractions over documents and structured sources. Typical: enterprise RAG, document agents. | open source | retrieval-governance positioning |
| Microsoft AutoGen | multi-agent framework | Conversational multi-agent patterns with pluggable tool executors. Typical: multi-agent research, code agents. | not checked | research/OSS, no vendor certification |
| CrewAI | multi-agent framework | Role-based agent teams with task delegation and process templates. Typical: process automation, role-based agents. | not checked | vendor-stated security posture |
| DSPy | prompt/program optimisation | Declarative programs with optimisers that make prompt changes reproducible and testable. Typical: evaluated pipelines, model validation. | not checked | model-validation positioning (SR 11-7 style, claimed) |
| Semantic Kernel | enterprise SDK | Microsoft SDK for planners and plugins inside .NET/Java estates. Typical: enterprise copilots, tool plugins. | not checked | enterprise-estate integration (claimed) |
| PydanticAI | typed agent SDK | Type-validated agent outputs and tool signatures for deterministic contracts. Typical: structured outputs, typed tool calls. | not checked | schema-enforcement positioning |
| Model Context Protocol (MCP) | protocol / standard | Open protocol for tool and context exposure; a protocol, not a product — governance sits in the gateway around it. Typical: tool interoperability, gateway mediation. | not checked | open protocol, no certification |
| E2B | sandboxed runtime | Ephemeral cloud sandboxes for agent code execution with isolation per task. Typical: code agents, untrusted execution. | not checked | isolation/sandbox positioning |
| Airia | enterprise agent platform | Enterprise platform for building and running agents with connector, policy and routing layers. Typical: agent orchestration, internal copilots. | SaaS (vendor cloud) | EU AI Act readiness positioningSOC 2 programme positioning (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| eClerx GenAI360 | Outcome-priced domain platform | Turnkey ComplianceOps / CareOps / ContentOps class modules operated by the provider with specialist QA. Typical: compliance operations, customer operations, content operations. | not checked | ISO 42001 (claimed) |
| WNS | Managed AI-enabled business process | Business-process provider delivering AI-assisted domain execution under SLA. Typical: finance operations, customer operations. | not checked | SOC 2 (claimed) |
| workflows.io | AI-native agency OS | AI-native operating system for agency-style delivery of repeatable knowledge work. Typical: content operations, marketing operations. | not checked | GDPR-positioned |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| OVHcloud | native EU | French provider with EU-only jurisdiction and a narrower managed-AI catalog than the hyperscalers. Typical: EU-resident inference, regulated workload hosting. | not checked | ISO 27001 (claimed)SecNumCloud-positionedGDPR-positioned |
| Scaleway | native EU | EU-operated cloud with GPU instances and managed inference under French corporate control. Typical: EU-resident inference, fine-tuning. | not checked | ISO 27001 (claimed)GDPR-positioned |
| STACKIT | native EU | German provider (Schwarz Group) positioned for data residency in Germany. Typical: public sector, retail data platforms. | not checked | C5-positionedGDPR-positioned |
| AWS European Sovereign Cloud | sovereign hyperscaler | Separately operated EU region set with EU-resident personnel and keys; full hyperscaler catalog. Typical: large-scale enterprise AI, regulated hosting. | not checked | ISO 27001 (claimed)SOC 2 (claimed)EU data-boundary positioning |
| Microsoft Azure EU Data Boundary | sovereign hyperscaler | EU processing and storage boundary across Azure and Copilot services with confidential-compute options. Typical: enterprise copilots, regulated hosting. | not checked | ISO 27001 (claimed)SOC 2 (claimed)EU data-boundary positioning |
| Google Cloud Sovereign Controls | sovereign hyperscaler | Partner-operated and data-boundary variants with external key management. Typical: regulated analytics, EU-resident inference. | not checked | ISO 27001 (claimed)SOC 2 (claimed)EU data-boundary positioning |
| Groq | specialized GPU / accelerator | LPU inference hardware marketed on deterministic low latency rather than training throughput. Typical: low-latency agents, real-time decisioning. | not checked | SOC 2 (claimed) |
| CoreWeave | specialized GPU / accelerator | GPU-dense cloud for training and high-throughput inference with dedicated capacity contracts. Typical: model training, batch inference. | not checked | SOC 2 (claimed)ISO 27001 (claimed) |
| Lambda Labs | specialized GPU / accelerator | GPU cloud and on-prem clusters aimed at research and fine-tuning workloads. Typical: fine-tuning, research clusters. | not checked | SOC 2 (claimed) |
| Together AI | inference platform | Hosted open-weight model inference and fine-tuning with per-token pricing. Typical: open-weight inference, fine-tuning. | not checked | SOC 2 (claimed)open-weight sovereignty positioning |
| Fireworks AI | inference platform | Optimised serving of open-weight models with function-calling and structured output support. Typical: agent tool-calling, high-QPS inference. | not checked | SOC 2 (claimed)HIPAA-eligible (claimed) |
| Baseten | inference platform | Model deployment platform with autoscaling endpoints and VPC deployment options. Typical: custom model serving, VPC-isolated inference. | not checked | SOC 2 (claimed)HIPAA-eligible (claimed) |
| Modal | serverless compute | Serverless GPU execution for jobs, batch pipelines and sandboxed agent tasks. Typical: batch pipelines, sandboxed execution. | not checked | SOC 2 (claimed) |
| Replicate | serverless compute | API-first hosting of community and custom models, priced per run. Typical: prototyping, multimodal inference. | not checked | vendor-stated security posture |
| Anyscale | serverless compute | Managed Ray for distributed training, serving and multi-step agent workloads. Typical: distributed training, agent fan-out. | not checked | SOC 2 (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Anjuna | confidential computing | Runs workloads inside hardware enclaves without application rewrites. Typical: data-in-use protection, regulated inference. | not checked | confidential-computing positioningDORA-positioned (claimed) |
| Fortanix | confidential computing & KMS | Enclave runtime plus key management and tokenisation services. Typical: key management, data-in-use protection. | not checked | FIPS 140-2 (claimed)DORA-positioned (claimed)HIPAA-positioned (claimed) |
| Skyflow | privacy vault | Polymorphic data vault de-identifying records before they reach a model. Typical: PII vaulting, pre-model redaction. | not checked | SOC 2 (claimed)HIPAA-positionedGDPR-positioned |
| Private AI | PII detection & redaction | Detection and redaction of identifiers across text, documents and audio. Typical: inline redaction, document de-identification. | not checked | GDPR-positionedHIPAA-positioned |
| IronCore Labs | encrypted vector search | Application-layer encryption for embeddings, addressing vector-reconstruction risk. Typical: encrypted RAG, erasure support. | not checked | GDPR-positionederasure/embedding-risk positioning |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Pillar Security | agent security & inventory | Discovery, inventory and runtime policy for agents in the estate. Typical: agent registry, policy enforcement. | not checked | agent-inventory positioning |
| Lyzr | agent governance & observability | Agent platform with governance, approval and observability features. Typical: agent approval, agent analytics. | not checked | vendor-stated security posture |
| Astrix Security | non-human identity | Lifecycle governance of machine and agent identities and their grants. Typical: credential scoping, NHI inventory. | not checked | SOC 2 (claimed)NHI governance positioning |
| Britive | just-in-time access | Ephemeral, per-task privileges instead of standing credentials. Typical: JIT credentials, privilege reduction. | not checked | SOC 2 (claimed)least-privilege positioning |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Docling | document parser | Open-source layout-aware parsing of PDFs and office formats into structured chunks. Typical: RAG ingestion, air-gapped pipelines. | self-hostable | EU sovereignty positioning |
| LlamaParse | document parser | Managed parsing service tuned for tables and complex documents feeding RAG. Typical: RAG ingestion, table extraction. | not checked | SOC 2 (claimed) |
| Amazon Textract | document parser | OCR and form/table extraction with per-page pricing inside AWS. Typical: document intake, claims processing. | not checked | SOC 2 (claimed)HIPAA-eligible (claimed)ISO 27001 (claimed) |
| Diffbot | web/knowledge extraction | Structured extraction and knowledge-graph construction from web sources. Typical: market monitoring, entity resolution. | not checked | vendor-stated security posture |
| Firecrawl | web/knowledge extraction | Crawling and clean markdown extraction for grounding on public sources. Typical: regulatory monitoring, public-source grounding. | not checked | vendor-stated security posture |
| Voyage AI | embeddings | Domain-tuned embedding models including legal and finance variants. Typical: retrieval quality, domain RAG. | not checked | vendor-stated security posture |
| Nomic | embeddings | Open embedding models with local inference and dataset visualisation. Typical: on-prem retrieval, dataset inspection. | self-hostable | |
| Pinecone | vector database | Managed serverless vector search with namespace isolation. Typical: tenant-isolated RAG, semantic search. | not checked | SOC 2 (claimed)ISO 27001 (claimed)HIPAA-eligible (claimed) |
| Weaviate | vector database | Vector database available managed or self-hosted with hybrid search. Typical: hybrid retrieval, self-hosted RAG. | open source | SOC 2 (claimed) |
| Qdrant | vector database | Open-source vector store with payload filtering and on-prem deployment. Typical: air-gapped RAG, filtered retrieval. | open source | GDPR-positioned |
| Milvus | vector database | Open-source vector database for very large collections. Typical: large-scale retrieval. | open source | |
| pgvector | vector database | Postgres extension keeping vectors under the same RBAC, backup and retention regime as records. Typical: record-bound retrieval, small-scale RAG. | self-hostable | record-retention alignment (claimed) |
| Letta (MemGPT) | agent memory store | Persistent agent memory with explicit memory blocks and editing. Typical: long-running agents, personalisation. | self-hostable | |
| Mem0 | agent memory store | Memory layer extracting durable facts from agent conversations. Typical: personalised agents, support copilots. | not checked | vendor-stated security posture |
| Zep | agent memory store | Temporal knowledge-graph memory with fact validity intervals. Typical: auditable memory, long-running agents. | not checked | GDPR-positionedbitemporal record positioning |
| Cognee | agent memory store | Open-source memory/knowledge pipeline building graphs from agent interactions. Typical: knowledge accumulation, research agents. | self-hostable |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| LangSmith | agent tracing & evaluation | Trace capture and evaluation over LangChain/LangGraph runs with dataset-based scoring. Typical: step tracing, regression evaluation. | not checked | SOC 2 (claimed)supports Art. 12 record-keeping (claimed) |
| Langfuse | agent tracing & evaluation | Open-source tracing, prompt management and evaluation; self-hostable for retention control. Typical: self-hosted tracing, cost/latency analytics. | open source | GDPR-positionedsupports Art. 12 record-keeping (claimed) |
| Arize AI / Phoenix | ML & LLM observability | Production monitoring with drift and performance analysis; Phoenix is the open-source tracing side. Typical: drift monitoring, production analytics. | not checked | SOC 2 (claimed)drift-monitoring positioning (SR 11-7 style, claimed) |
| Helicone | LLM gateway & logging | Proxy-level logging of prompts, costs and latency across providers. Typical: gateway logging, cost control. | not checked | SOC 2 (claimed)supports Art. 12 record-keeping (claimed) |
| MLflow | experiment & model registry | Open-source tracking, model registry and lineage across training and deployment. Typical: model registry, validation records. | open source | model-validation positioning (SR 11-7 style, claimed) |
| Ragas | RAG evaluation | Open evaluation metrics for retrieval faithfulness and answer grounding. Typical: grounding checks, RAG regression. | not checked | OSS, no vendor certification |
| Deepchecks | validation & testing | Continuous validation suites for data and model behaviour. Typical: release gating, data validation. | not checked | evaluation-evidence positioning |
| Fairlearn | fairness toolkit | Open-source fairness assessment and mitigation for classification and regression. Typical: bias testing, fairness reporting. | not checked | OSS, no vendor certificationsupports Art. 10 bias examination (claimed) |
| Fiddler AI | model performance management | Explainability and monitoring platform aimed at regulated model risk teams. Typical: explainability, model monitoring. | not checked | SOC 2 (claimed)model-risk positioning (SR 11-7 style, claimed) |
| ValidMind | model risk management | Model validation documentation and workflow for banking model-risk functions. Typical: validation reports, MRM workflow. | not checked | SOC 2 (claimed)model-risk positioning (SR 11-7 style, claimed) |
| WhyLabs | data & model monitoring | Telemetry and drift monitoring over model inputs and outputs. Typical: drift detection, data quality monitoring. | SaaS (vendor cloud) | supports Art. 72 post-market monitoring (claimed) |
| Evidently AI | evaluation & monitoring | Open-source evaluation and monitoring reports for ML and LLM pipelines. Typical: evaluation reports, drift detection. | open source | supports Art. 72 post-market monitoring (claimed) |
| Galileo AI | LLM evaluation & observability | Evaluation metrics and traces for generative applications. Typical: LLM evaluation, trace inspection. | SaaS (vendor cloud) | supports Art. 15 accuracy measures (claimed) |
| Patronus AI · eingestellt (2026-08-31) | automated LLM evaluation | Automated scoring and adversarial test suites for generative output. Typical: automated evaluation, red teaming. | SaaS (vendor cloud) | supports Art. 15 robustness measures (claimed) |
| Arthur AI | model performance monitoring | Performance, bias and drift monitoring across deployed models. Typical: bias monitoring, performance monitoring. | SaaS (vendor cloud) | supports Art. 72 post-market monitoring (claimed)supports Art. 10 bias examination (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| GitHub Copilot | developer copilot | Code completion and agent modes inside the IDE and repository workflow. Typical: software engineering, code review. | not checked | SOC 2 (claimed)enterprise data-handling commitments (claimed) |
| Microsoft 365 Copilot | productivity copilot | Assistant across mail, documents and meetings inheriting existing tenant permissions. Typical: knowledge work, meeting summaries. | not checked | ISO 27001 (claimed)SOC 2 (claimed)EU data-boundary positioning |
| Perplexity Enterprise | research assistant | Cited web and internal search with source attribution per answer. Typical: market research, citation-backed search. | not checked | SOC 2 (claimed)enterprise data-handling commitments (claimed) |
| Cursor | developer copilot | AI-native editor with repository-wide agent edits. Typical: software engineering, refactoring. | not checked | SOC 2 (claimed)privacy-mode option (claimed) |
| Dropzone AI | security operations agent | Autonomous triage of security alerts with written investigation records. Typical: SOC triage, incident write-ups. | not checked | SOC 2 (claimed) |
| Devin (Cognition) | autonomous software agent | Long-running software agent taking tickets to pull requests. Typical: software engineering, backlog automation. | not checked | vendor-stated security posture |
| Vanta | compliance automation | Continuous control monitoring and evidence collection across frameworks. Typical: evidence automation, audit readiness. | not checked | SOC 2 (claimed)ISO 27001/42001 evidence workflows (claimed) |
| Fin (Intercom) | customer-service agent | Resolution-priced support agent answering from your help content. Typical: customer support, deflection. | not checked | SOC 2 (claimed)GDPR-positioned |
| SAP | embedded enterprise AI | AI features and agents embedded in ERP, HR and procurement suites, governed through the vendor's own AI platform layer. Typical: embedded HR AI, procurement automation, finance automation. | SaaS (vendor cloud) | ISO/IEC 42001 certification claim (claimed)EU AI Act readiness positioning |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Guardrails AI | validation framework | Open-source validator framework for structured output and content policies in the request path. Typical: output validation, structured output. | open source | supports Art. 15 robustness measures (claimed) |
| NVIDIA NeMo Guardrails | dialogue policy rails | Programmable dialogue and topic rails placed around an LLM application. Typical: topic control, dialogue policy. | open source | supports Art. 50 interaction disclosure patterns (claimed) |
| Lakera AI | guardrail proxy | Inline prompt-injection and content detection at request time. Typical: injection defence, content filtering. | SaaS (vendor cloud) | SOC 2 (claimed)supports Art. 15 robustness measures (claimed) |
| Credal AI | enterprise access & policy layer | Permission-aware access layer with data-loss controls in front of enterprise assistants. Typical: access control, DLP. | SaaS (vendor cloud) | SOC 2 (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Fact0 | cryptographic evidence ledger | Positions itself as a tamper-evident ledger for AI decision records. Typical: decision records, audit trail. | not checked | supports Art. 12 record-keeping (claimed) |
| Traccia | audit trail & traceability | Positions itself around traceability of AI pipeline steps and artefacts. Typical: traceability, artifact lineage. | not checked | supports Art. 12 record-keeping (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Truyo | shadow-AI discovery | Discovery of AI usage across SaaS and cloud accounts with intake and governance workflow on top. Typical: shadow-AI inventory, AI intake. Scope overlap: Its governance-workflow scope overlaps this platform's own; we have a commercial interest in the comparison. | SaaS (vendor cloud) | EU AI Act readiness positioningGDPR programme tooling (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Cranium AI | AIBOM & model provenance | AI bill-of-materials generation, model-provenance capture and third-party model risk scanning. Typical: AIBOM, third-party model ingestion. Scope overlap: Its AI-governance reporting scope overlaps this platform's own; we have a commercial interest in the comparison. | SaaS (vendor cloud) | NIST AI RMF alignment (claimed)EU AI Act readiness positioning |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Saidot | public AI register | AI register with published system cards and regulation-mapped documentation workflows. Typical: public AI register, system cards. Scope overlap: Its documentation and register scope overlaps this platform's own; we have a commercial interest in the comparison. | SaaS (vendor cloud) | EU AI Act documentation positioningISO 42001 alignment (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
Reference stacks by regulatory profile
Three illustrative assemblies across the five procurement tiers, taken from the Aug 2026 vendor research compilation. They are starting points for a build-or-buy conversation, not certified stacks: no combination of the products below makes a deployment compliant, and every vendor name here is a community-disputable example rather than an endorsement.
Five procurement tiers (5)
Financial services
Healthcare
Public sector
Delivery models
BPO · SaaS · Service-as-a-Software
Translational pipeline
Use case → risk tier → control layers → vendor stack
SaaS 1.0 vs. Service as Software
The structural shift: software stops being a tool a human operates and becomes the digital labour layer that completes the outcome. Every row changes what a regulator can inspect.
Scroll sideways to compare both models →
| Structural dimension | SaaS 1.0 | Service as Software (SaaS 2.0) |
|---|---|---|
| Primary functional role | System of record / engagement | System of action / digital labour layer |
| Cognitive ownership | Human reasons, software executes commands | AI agent reasons, plans and executes autonomously |
| Monetization architecture | Per-seat subscription licensing | Outcome-based, transaction-based or hybrid-metered |
| Interface & interaction | Dashboard, GUI, web portal | API orchestration, background execution, local MCP |
| Economic value proposition | Efficiency — speeds up human tasks | Task completion — replaces or scales cognitive labour |
| Gross margin profile | 80–90% | 50–60% (inference and compute cost per task) |
| Enterprise integration point | User provisioning and feature adoption | Deep API integration, data pipelines, dynamic governance |
| Regulatory centre of gravity | Access control and data processing | Autonomy bounds, logging, attribution and human oversight |
Unit economics under outcome pricing
Agentic execution stack — seven layers in three tiers
The layered architecture that replaces frontend + database + manual operations, grouped into Engagement (who and what talks to your agents), Capabilities (how they decide and act) and Data (what is kept, and as which kind of record). Each layer carries a specific statutory hook: oversight that is not in the layer where the action happens cannot stop it. The layer taxonomy is adapted from the Al-Risk.ai / Agentico.ai agentic enterprise stack model (2025); the obligations mapping is ours.
Interfaces
Web, app and voice surfaces, digital wallets, social channels, enterprise collaboration tools and marketplace/discovery APIs. Every one of them needs an AI-interaction notice, machine-readable marking of generated or manipulated output, and a disclosure record that survives the session. Public social surfaces add DSA duties; consumer-facing surfaces add accessibility (European Accessibility Act) and sector conduct rules.
Third-party agents
Inbound and outbound agent-to-agent interaction: discovery, authentication of the counterparty, mandate and value limits, and a resolvable answer to 'which external principal caused this transaction'. This is where liability allocation stops being theoretical — an external agent acting on your system can flip roles along the value chain.
Controls
Guardrails, confidence minima, disbursement and margin caps, non-human identity and the fail-safe stop. Breaching a limit halts all sub-agents and reverts to a safe state rather than continuing at degraded confidence; agents hold ephemeral, per-task credentials rather than standing grants.
Orchestration
Goal-directed reasoning, tool selection across enterprise APIs, confidence scoring per step, and the human-machine interface with a global halt control. The orchestration policy is a documented design decision, not an implementation detail.
Intelligence
Model routing between small fine-tuned models and frontier models, inference economics, drift monitoring and explanation surfaces. Which model answered which request is part of the technical documentation trail.
Tools
Agents execute inside the corporate perimeter and reach tools over MCP with context scoped to the minimum attributes required. Every action leaves through one schema-validated boundary that rejects out-of-contract calls and records the attempt either way, instead of shipping raw records to third-party endpoints.
Systems of record
Databases and lakes, tokenisation, vector and graph stores, file systems, agent-workforce accounting — and agent memory treated as a regulated record rather than a cache, with retention schedules, erasure paths that do not break the audit trail, and jurisdictional placement of both data and control plane.
Implementation priorities (5)
Operating model
Scroll sideways to compare all operating models →
| Operating dimension | Legacy BPO / IT services | Traditional SaaS | Service-as-a-Software |
|---|---|---|---|
| Primary value metric | Input (billable hours & FTEs) | Capability (software access) | Outcome (SLA & completed work) |
| Scaling mechanism | Linear headcount expansion | User subscriptions | Algorithmic execution at scale |
| Operational responsibility | Shared / vendor manual labour | Client internal teams | Provider-managed AI systems |
| Unit economics | High variable labour cost | High gross margin, low service | High margin, non-linear revenue |
| Primary exposure risk | Human error & attrition | Implementation / adoption failure | Algorithmic bias & non-compliance |
The four-stage compliant pipeline
Ingestion & data isolation
Personal and health data are detected and tokenised before any payload reaches an inference path; storage, indexes and embeddings are partitioned per client with RBAC and customer-managed keys.
Deterministic prompt & guardrail orchestration
Retrieval is scoped by tenant and caller entitlement; input rails screen for injection and out-of-policy requests before context is assembled.
Multi-model routing & fallback
Routing decisions consider capability, regulatory constraint, cost and latency. Sensitive workloads are pinned to private, zero-data-retention endpoints; health breaches degrade to secondary or locally hosted models instead of failing the workflow.
Output audit & human-in-the-loop gateway
Every execution writes an audit packet — timestamp, model version, prompt, context hash, parameters, output, confidence and any human override — to WORM storage.
Human oversight: where the threshold sits
Human-in-the-loop (confidence-threshold routing)
High-stakes workflows — identity screening, legal clause extraction, anything affecting a person's access to a service — compute C_s per output. Below θ the transaction pauses and a specialist verdict completes it, logged as part of the decision record.
Human-on-the-loop (statistical sampling)
Lower-risk batch work runs autonomously with randomised, statistically representative sampling per batch to measure accuracy, classify errors and detect drift.
ISO/IEC 42001 governance loop
Clause 4 — Context of the organisation
Defines organisational boundaries, per-vertical regulatory requirements and client risk appetite as deployment parameters.
Clauses 5 & 6 — Leadership & planning
AI governance board owns the responsible-AI policy, bias tolerances and risk-treatment strategy.
Clause 8 — Operational control & impact assessment
Pre-deployment risk and impact assessment, data-quality controls and the HITL intervention framework.
Clauses 9 & 10 — Evaluation & improvement
Performance monitoring, drift tracking, internal audit and recertification.
Mandatory compliance artifacts
Artifact set per deployed workflow (6)
Implementation roadmap
Foundational governance & architectural hardening
Establish core compliance policies and secure infrastructure enclaves.
Technical: Deploy zero-trust ingestion with PII/PHI tokenisation; stand up the model-abstraction layer.
Governance: Finalise ISO 42001 AIMS policies; execute zero-data-retention vendor contracts.
Workflow taxonomy & regulatory tiering
Map every vertical workflow to its risk tier.
Technical: Build HITL operator dashboards with confidence-threshold routing (C_s < θ).
Governance: Complete AI Act classifications (high vs. limited vs. minimal) per workflow.
Artifact automation & immutable auditability
Automate production of required compliance documentation.
Technical: Connect transaction pipelines to append-only WORM storage with external trust anchoring.
Governance: Auto-generate AI impact assessments and model cards per deployment.
Scaled outcome-based commercial deployment
Move client contracts to outcome-priced structures.
Technical: Continuous drift monitoring and dynamic multi-model fallback in production.
Governance: Annual ISO 42001 audits; continuous AI Act conformity validation.
Key takeaways
- Certified governance is a procurement advantage, not overhead — ISO 42001 and a defensible evidence trail decide regulated deals.
- Decouple the product from the model: abstraction insulates delivery from outages, deprecations, pricing shifts and regional regulatory divergence.
- Human oversight stays central in high-stakes workflows: confidence thresholds route edge cases to specialists and satisfy Art. 14 without collapsing throughput.
- Compliance artefacts must be generated by the pipeline, not written after the fact — model cards, impact assessments, fairness reports and immutable ledgers in real time.
Every workflow in the use-case catalog marked as a managed service maps into this pipeline — open a profile to see its delivery stack, or run one through the risk & value evaluator.