AI-Assisted Tax Advisory & Research (Practitioner-Regulated)
AI used inside a tax practice — a CPA, enrolled agent, tax attorney or Steuerberater — to research tax questions and draft technical tax memos and replies to the IRS or Finanzamt under the responsibility of a named professional of record. Scope limit: the professional of record, not the taxpayer, answers for every output, and the system decides nothing about a taxpayer's entitlements; output delivered straight to taxpayers with no professional reviewing it is outside this base reading.
Indicative decision support, not legal advice. Risk classification depends on your concrete deployment context and can change with scope drift — validate the result with qualified counsel.
Target market(s)European UnionUnited States (federal)change
Changes which instruments below count as in scope for this profile.
Target markets: European Union, United States (federal)
Regulatory footprint
7 instruments across 3 of 7 regulatory domains, plus 5 standards references- AI law1 instrument
- Data protection1 instrument
- Cyber & resiliencenone triggered
- Online safety & platformsnone triggered
- Product safetynone triggered
- Financial servicesnone triggered
- Sector & employment5 instruments
- Standards5 references
By jurisdiction
- EU2European UnionEU AI Act, GDPR
- US3United States (federal)Circular 230 — Regulations Governing Practice before the IRS (31 CFR Part 10), FTC Safeguards Rule (16 CFR Part 314), IRC §§ 7216 & 6713 — Preparer Disclosure and Use of Tax Return Information
- DE2thinGermany§ 203 StGB — Violation of Private Secrets (professional secrecy, DE), Steuerberatungsgesetz (StBerG) — Tax Advisers Act (DE)
The AI Act is one dimension of this footprint, not the whole of it — every domain above carries its own obligations and deadlines. See the instruments in the graph →
The chain holds, but at least one hop rests on a secondary source, an ageing verification or a practice-derived step. Check the flagged hops before you rely on them.
Computed weakest-link over 23 evaluated hops across 1 target market: a chain is only as strong as its weakest step, so the band follows the worst hop rather than an average that would hide it. Five factors per hop — source tier, verification age, status certainty, community hardening, derivation kind — all read from graph data, never from a hand-set score.
Why this band8 factors lowered the band — each links to the claim behind it
- Source tier: Steuerberatungsgesetz (StBerG) — Tax Advisers Act (DE) carries no resolvable citation — the claim is uncited. open node →
- Source tier: § 203 StGB — Violation of Private Secrets (professional secrecy, DE) carries no resolvable citation — the claim is uncited. open node →
- Source tier: JTC 21 Technical Package (prEN 18228/18229/18281–83) rests on a secondary source (tracker or summary), not on the primary text. open node → primary source →
- Source tier: IEEE CertifAIEd™ carries no resolvable citation — the claim is uncited. open node →
- Source tier: prEN 18229-1 (Trustworthiness Framework, part 1) rests on a secondary source (tracker or summary), not on the primary text. open node → primary source →
- Status certainty: JTC 21 Technical Package (prEN 18228/18229/18281–83) is "draft", not settled in-force law. open node → primary source →
- Status certainty: prEN 18229-1 (Trustworthiness Framework, part 1) is "enquiry", not settled in-force law. open node → primary source →
- Verification age: IEEE CertifAIEd™ has no recorded verification date. open node →
Compliance brief
This use case is minimal-risk under the EU AI Act (Minimal Risk); no product-specific obligations beyond general AI literacy apply.
What is owed
- Art. 4. Providers and deployers must ensure sufficient AI literacy of staff dealing with AI systems.
- GDPR Art. 22. Right not to be subject to solely automated decisions with legal/similar effect; requires meaningful human involvement or explicit legal basis + safeguards.
- GDPR Art. 27. A controller or processor not established in the Union that falls within Art.
- GDPR Art. 17. Right to erasure collides with AI Act Art.
- GDPR Art. 25. Privacy by design & default: minimisation, pseudonymisation, PII filters in pipelines and vector stores.
Dates that bind
- 2024-08-01 — AI Act enters into force. Regulation (EU) 2024/1689 in force; countdown for all staged obligations starts.
- 2025-02-02 — Prohibitions + AI literacy. Art. 5 prohibited practices ban applies (manipulation, social scoring, untargeted face scraping, workplace emotion recognition); Art. 4 AI literacy duty.
Maximum exposure
- EU AI Act: Tiered: €35m / 7% (prohibited practices); €15m / 3% (Art. 9–15 high-risk obligations incl. data governance, documentation, logging); €7.5m / 1% (Art. 99(5) — incorrect, incomplete or misleading information to notified bodies or national competent authorities)
- GDPR: Up to €20m or 4% of worldwide annual turnover
- Circular 230: After notice and an opportunity for a proceeding, censure, suspension or disbarment from practice before the IRS, and a monetary penalty not exceeding the gross income derived (or to be derived) from the conduct; the penalty may also be imposed on the employer, firm or entity if it knew or reasonably should have known of the conduct (31 CFR § 10.50(a), (c)).
- IRC §§ 7216 & 6713: Criminal (§ 7216(a), for a knowing or reckless disclosure or use): misdemeanour, fine of up to $1,000 ($100,000 where § 6713(b) applies) or imprisonment of up to one year, or both, plus the costs of prosecution. Civil (§ 6713(a)): $250 for each disclosure or use, capped at $10,000 per calendar year ($1,000 and $50,000 where the disclosure or use is made in connection with a crime relating to the misappropriation of another person's taxpayer identity, § 6713(b)).
- FTC Safeguards Rule (16 CFR Part 314): Enforced by the Federal Trade Commission against financial institutions not subject to another regulator's enforcement authority under section 505 of the Gramm-Leach-Bliley Act (§ 314.1(b)). Part 314 itself sets no penalty amount; IRS Publication 4557 (Rev. 6-2024) states that failure to create and enact the required security plan 'may result in an FTC investigation'.
- Steuerberatungsgesetz (StBerG): A Steuerberater or Steuerbevollmächtigter who culpably breaches the duties set in the Act or in the professional rules faces a professional-court measure (§ 89(1)); a recognised professional practice company faces one where a leading person breaches them, or another person does so in the company's affairs and appropriate organisational, personnel or technical measures could have prevented or substantially impeded the breach (§ 89(3)). Where the tax authorities or Steuerberaterkammern learn facts giving rise to a suspicion that a person provides help in tax matters geschäftsmäßig contrary to § 5(1), they pass the information to the body responsible for fine proceedings under § 20(1) no. 1 of the Rechtsdienstleistungsgesetz (§ 5(2)).
- § 203 StGB: Imprisonment of up to one year or a fine (§ 203(1) and (4)); imprisonment of up to two years or a fine where the offender acts for payment or with the intention of enriching themselves or another or of harming another (§ 203(6)).
First five actions
- Confirm in writing whether this organisation builds/places the system on the market (provider) or only operates it (deployer), since the role is not yet established.
- Commission and confirm the Art. 4, GDPR Art. 22, GDPR Art. 27 obligations named above as active workstreams with an accountable owner.
- Design and document a human-oversight procedure appropriate to how this system is used.
- Produce the technical documentation and evidence artefacts already mapped to this use case (HITL Escalation Queue & Review UI, Adverse-Decision Reason Generator, Bitemporal Memory (GDPR×Art.12)) before they are requested.
- Put 2024-08-01 — AI Act enters into force — into the compliance calendar with an owner and lead time.
Terms used above: · · ·
Consensus reading: Minimal Risk open in the graph →
The professional of record, not the AI vendor or the taxpayer, answers for what the tool produces. In the US, Circular 230 requires an attorney, CPA or enrolled agent to exercise due diligence (31 CFR § 10.22), to be competent (10.35), to base written advice on reasonable factual and legal assumptions (10.37(a)) and, for those in charge of a firm, to take reasonable steps to ensure adequate compliance procedures (10.36); IRS OPR Alert 2026-19 (24 June 2026) sets out how those sections and the tax-information rules of IRC §§ 7216 and 6713 bear on generative AI, and passing client tax data to an AI vendor is a disclosure those rules restrict. A firm that is a financial institution under the FTC Safeguards Rule (16 CFR § 314.1(b) lists tax preparation firms) must also oversee its service providers (314.4(f)). In Germany, § 57(1) StBerG requires a Steuerberater to practise independently, on their own responsibility and confidentially, § 62a StBerG conditions a service provider's access to confidential facts on careful selection and a written secrecy undertaking, and § 203 StGB makes unauthorised disclosure of client secrets a crime. The BStBK's FAQ of 27 January 2026 treats a Steuerberater using AI on their own responsibility as, as a rule, a deployer under AI Act Art. 3(4) and describes research, bookkeeping support and drafting as not high-risk, so the pattern is classified as minimal risk; a variant that reaches taxpayers directly with no professional reviewing the output falls under the Art. 50(1) duty to inform the person of the AI interaction (unless obvious from the circumstances and context of use) and, in Germany, has to be assessed against §§ 2(1) and 5(1) StBerG, which reserve Hilfeleistung in Steuersachen to authorised persons.
What the reading rests on — the provisions this classification actually pulls in:
- Art. 4 — AI Literacy
- EU AI Act (Regulation (EU) 2024/1689)
- GDPR (Regulation (EU) 2016/679)
- Circular 230 — Regulations Governing Practice before the IRS (31 CFR Part 10) (Department of the Treasury Circular No. 230, 31 CFR Part 10 — Regulations Governing Practice before the Internal Revenue Service)
- IRC §§ 7216 & 6713 — Preparer Disclosure and Use of Tax Return Information (26 U.S.C. § 7216 (criminal) and § 6713 (civil), with 26 CFR §§ 301.7216-1 to 301.7216-3 — Disclosure or use of information by preparers of returns)
- FTC Safeguards Rule (16 CFR Part 314) (Standards for Safeguarding Customer Information, 16 CFR Part 314 (implementing sections 501 and 505(b)(2) of the Gramm-Leach-Bliley Act))
- Steuerberatungsgesetz (StBerG) — Tax Advisers Act (DE) (Steuerberatungsgesetz (StBerG) in der Fassung der Bekanntmachung vom 4. November 1975 (BGBl. I S. 2735), zuletzt geändert durch Artikel 1 des Gesetzes vom 29. Juni 2026 (BGBl. 2026 I Nr. 197))
- § 203 StGB — Violation of Private Secrets (professional secrecy, DE) (Strafgesetzbuch (StGB) § 203 Verletzung von Privatgeheimnissen, in der Fassung der Bekanntmachung vom 13. November 1998 (BGBl. I S. 3322), zuletzt geändert durch Artikel 1 des Gesetzes vom 20. März 2026 (BGBl. 2026 I Nr. 95))
Baseline: of 100+, 40% were not definitively classifiable (18% clearly high-risk, 42% clearly low-risk). appliedAI Institute — AI Act risk classification of AI systems from a practical perspective
Applicable Regulations (7)
Legal Obligations (10)
Control Objectives (2)
Standards & Evidence
Evidence you will need (10)
The concrete deliverables this use case's obligations ask for — grouped by what kind of artifact they are. Documentation is the largest single conformity cost block, so the list is a work plan, not a reading list. Full evidence matrix →
Assessments (2)
A structured judgement about risk, rights or a management system.
Test reports (2)
Measured results from testing, evaluation or red-teaming.
Log records (2)
Machine-generated records produced while the system runs.
Process records (4)
Traces that a process actually happened, and who did it.
Architecture Blueprint
Required Technical Components (30)
Build or Buy — Vendor Layer (10)
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| LangChain / LangGraph | agent framework | Graph-structured agent runtime; interrupt/pause nodes support implementing human approval at defined steps. Typical: multi-step agents, approval workflows. | not checked | supports implementing Art. 14 oversight (claimed)supports Art. 12 step logging (claimed) |
| LlamaIndex | RAG framework | Indexing and query abstractions over documents and structured sources. Typical: enterprise RAG, document agents. | open source | retrieval-governance positioning |
| Microsoft AutoGen | multi-agent framework | Conversational multi-agent patterns with pluggable tool executors. Typical: multi-agent research, code agents. | not checked | research/OSS, no vendor certification |
| CrewAI | multi-agent framework | Role-based agent teams with task delegation and process templates. Typical: process automation, role-based agents. | not checked | vendor-stated security posture |
and 6 more in the stack advisor →
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| LangSmith | agent tracing & evaluation | Trace capture and evaluation over LangChain/LangGraph runs with dataset-based scoring. Typical: step tracing, regression evaluation. | not checked | SOC 2 (claimed)supports Art. 12 record-keeping (claimed) |
| Langfuse | agent tracing & evaluation | Open-source tracing, prompt management and evaluation; self-hostable for retention control. Typical: self-hosted tracing, cost/latency analytics. | open source | GDPR-positionedsupports Art. 12 record-keeping (claimed) |
| Arize AI / Phoenix | ML & LLM observability | Production monitoring with drift and performance analysis; Phoenix is the open-source tracing side. Typical: drift monitoring, production analytics. | not checked | SOC 2 (claimed)drift-monitoring positioning (SR 11-7 style, claimed) |
| Helicone | LLM gateway & logging | Proxy-level logging of prompts, costs and latency across providers. Typical: gateway logging, cost control. | not checked | SOC 2 (claimed)supports Art. 12 record-keeping (claimed) |
and 11 more in the stack advisor →
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Credo AI | AI governance platform | Policy packs, risk tiering and evidence workflows mapped across frameworks. Typical: AI registry, policy administration. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | ISO 42001 alignment (claimed)EU AI Act readiness positioning |
| Holistic AI | AI governance & audit | Risk assessment, bias auditing and regulatory reporting workflows. Typical: bias audit, regulatory reporting. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | NYC LL144 audit support (claimed)EU AI Act readiness positioning |
| IBM watsonx.governance | AI governance platform | Governance, factsheets and monitoring integrated with the IBM stack. Typical: factsheets, model monitoring. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | ISO 42001 alignment (claimed)Art. 11 documentation support (claimed) |
| ModelOp | AI/model governance | Model and agent inventory with automated lifecycle controls for large estates. Typical: model inventory, control automation. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | model-risk positioning (SR 11-7 style, claimed)ISO 42001 alignment (claimed) |
and 3 more in the stack advisor →
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Docling | document parser | Open-source layout-aware parsing of PDFs and office formats into structured chunks. Typical: RAG ingestion, air-gapped pipelines. | self-hostable | EU sovereignty positioning |
| LlamaParse | document parser | Managed parsing service tuned for tables and complex documents feeding RAG. Typical: RAG ingestion, table extraction. | not checked | SOC 2 (claimed) |
| Amazon Textract | document parser | OCR and form/table extraction with per-page pricing inside AWS. Typical: document intake, claims processing. | not checked | SOC 2 (claimed)HIPAA-eligible (claimed)ISO 27001 (claimed) |
| Diffbot | web/knowledge extraction | Structured extraction and knowledge-graph construction from web sources. Typical: market monitoring, entity resolution. | not checked | vendor-stated security posture |
and 12 more in the stack advisor →
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Anjuna | confidential computing | Runs workloads inside hardware enclaves without application rewrites. Typical: data-in-use protection, regulated inference. | not checked | confidential-computing positioningDORA-positioned (claimed) |
| Fortanix | confidential computing & KMS | Enclave runtime plus key management and tokenisation services. Typical: key management, data-in-use protection. | not checked | FIPS 140-2 (claimed)DORA-positioned (claimed)HIPAA-positioned (claimed) |
| Skyflow | privacy vault | Polymorphic data vault de-identifying records before they reach a model. Typical: PII vaulting, pre-model redaction. | not checked | SOC 2 (claimed)HIPAA-positionedGDPR-positioned |
| Private AI | PII detection & redaction | Detection and redaction of identifiers across text, documents and audio. Typical: inline redaction, document de-identification. | not checked | GDPR-positionedHIPAA-positioned |
and 1 more in the stack advisor →
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Azure AI Search | managed retrieval | Managed hybrid search with security trimming against tenant identities. Typical: ACL-aware RAG, enterprise search. | not checked | ISO 27001 (claimed)SOC 2 (claimed) |
| Databricks Unity Catalog | governed lakehouse | Catalog and lineage spanning tables, features and RAG chunks. Typical: lineage evidence, governed RAG. | not checked | SOC 2 (claimed)lineage/Art. 10 support (claimed) |
| Relyance AI | code-level data & AI lineage | Parses source repositories to map data and inference flows at code level, with CI checks on changes to those flows. Typical: data lineage, shift-left privacy review. Scope overlap: Its AI-governance reporting scope overlaps this platform's own; we have a commercial interest in the comparison. | SaaS (vendor cloud) | GDPR programme tooling (claimed)EU AI Act readiness positioning |
| Snowflake Cortex | governed lakehouse | Model calls inside the warehouse boundary with masking and clean rooms. Typical: in-warehouse inference, governed analytics. | not checked | SOC 2 (claimed)ISO 27001 (claimed)HIPAA-eligible (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Fact0 | cryptographic evidence ledger | Positions itself as a tamper-evident ledger for AI decision records. Typical: decision records, audit trail. | not checked | supports Art. 12 record-keeping (claimed) |
| Traccia | audit trail & traceability | Positions itself around traceability of AI pipeline steps and artefacts. Typical: traceability, artifact lineage. | not checked | supports Art. 12 record-keeping (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Lakera | guardrail proxy | Inline prompt-injection and content detection at request time. Typical: injection defence, content filtering. | not checked | SOC 2 (claimed)supports Art. 15 robustness measures (claimed) |
| HiddenLayer | model/agent detection & response | Model-layer detection and response with adversarial-attack telemetry. Typical: model threat detection, red-team telemetry. | not checked | SOC 2 (claimed)supports Art. 15 robustness measures (claimed) |
| Palo Alto Prisma AIRS | network-integrated AI security | AI runtime security folded into an existing enterprise network security estate. Typical: enterprise rollout, egress control. | not checked | SOC 2 (claimed)enterprise security integration (claimed) |
| Cisco AI Defense | network-integrated AI security | Discovery of AI usage plus inline enforcement across the corporate network. Typical: shadow-AI discovery, inline enforcement. | not checked | enterprise security integration (claimed) |
and 4 more in the stack advisor →
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Guardrails AI | validation framework | Open-source validator framework for structured output and content policies in the request path. Typical: output validation, structured output. | open source | supports Art. 15 robustness measures (claimed) |
| NVIDIA NeMo Guardrails | dialogue policy rails | Programmable dialogue and topic rails placed around an LLM application. Typical: topic control, dialogue policy. | open source | supports Art. 50 interaction disclosure patterns (claimed) |
| Lakera AI | guardrail proxy | Inline prompt-injection and content detection at request time. Typical: injection defence, content filtering. | SaaS (vendor cloud) | SOC 2 (claimed)supports Art. 15 robustness measures (claimed) |
| Credal AI | enterprise access & policy layer | Permission-aware access layer with data-loss controls in front of enterprise assistants. Typical: access control, DLP. | SaaS (vendor cloud) | SOC 2 (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| OVHcloud | native EU | French provider with EU-only jurisdiction and a narrower managed-AI catalog than the hyperscalers. Typical: EU-resident inference, regulated workload hosting. | not checked | ISO 27001 (claimed)SecNumCloud-positionedGDPR-positioned |
| Scaleway | native EU | EU-operated cloud with GPU instances and managed inference under French corporate control. Typical: EU-resident inference, fine-tuning. | not checked | ISO 27001 (claimed)GDPR-positioned |
| STACKIT | native EU | German provider (Schwarz Group) positioned for data residency in Germany. Typical: public sector, retail data platforms. | not checked | C5-positionedGDPR-positioned |
| AWS European Sovereign Cloud | sovereign hyperscaler | Separately operated EU region set with EU-resident personnel and keys; full hyperscaler catalog. Typical: large-scale enterprise AI, regulated hosting. | not checked | ISO 27001 (claimed)SOC 2 (claimed)EU data-boundary positioning |
and 11 more in the stack advisor →
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.