Where do you stand? › Route 3 · Vendors & stack
I know which systems I need — who supplies them?
Pick the components you have to put in place. For each one you get the build-vs-buy reading and the market layer that supplies it, with the same scored recommendations and confidence the full analysis uses. Nothing is stored; the selection lives in the URL.
Target market(s)European UnionUnited States (federal)change
Legally-driven components are flagged when their requiring regulation sits outside your selected markets.
Step 1 of 2 — pick your components3 selected
Step 2 of 2 — the vendor & stack view
3 of 3 selected components are covered by 6 market layers.
Named vendors are community-maintained, disputable examples — not an endorsement. The stable object is the market layer. Compare with the reference stack for your regulatory profile →
Build or buy, per component (3)
Public Transparency Registers & System Cards — covers 1 of your components
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Saidot | public AI register | AI register with published system cards and regulation-mapped documentation workflows. Typical: public AI register, system cards. Scope overlap: Its documentation and register scope overlaps this platform's own; we have a commercial interest in the comparison. | SaaS (vendor cloud) | EU AI Act documentation positioningISO 42001 alignment (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
- 1 in-scope component of this use case is supplied by this layer (AI Register & Model Registry / Factsheets) — a direct supplied_by path in the graph.
- This layer's graph purpose overlaps strongly with your scope (1 of 2 components it supplies are in scope).
- The catalog use-case match is strong, so the component set this layer was derived from is reliable.
- High-risk tier: this layer carries mandatory Chapter III duties, so some tooling in it is non-optional.
- 1 community-maintained example vendor recorded on the layer node.
- Selection metrics for this layer are documented, so the shortlist can be compared objectively.
- Cryptographic Evidence & Audit Ledger — confidence moderate (68/100, -2 vs. this layer); also covers: WORM / Immutable Audit Vault
- Agentic Applications & Copilots — confidence moderate (67/100, -3 vs. this layer); also covers: Document Intelligence Engine
Cryptographic Evidence & Audit Ledger — covers 1 of your components
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Fact0 | cryptographic evidence ledger | Positions itself as a tamper-evident ledger for AI decision records. Typical: decision records, audit trail. | not checked | supports Art. 12 record-keeping (claimed) |
| Traccia | audit trail & traceability | Positions itself around traceability of AI pipeline steps and artefacts. Typical: traceability, artifact lineage. | not checked | supports Art. 12 record-keeping (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
- 1 in-scope component of this use case is supplied by this layer (WORM / Immutable Audit Vault) — a direct supplied_by path in the graph.
- The catalog use-case match is strong, so the component set this layer was derived from is reliable.
- High-risk tier: this layer carries mandatory Chapter III duties, so some tooling in it is non-optional.
- 2 community-maintained example vendors recorded on the layer node.
- Selection metrics for this layer are documented, so the shortlist can be compared objectively.
- Only 1 of 3 components this layer supplies are in your scope — evaluate a narrow subset of its capabilities.
- Public Transparency Registers & System Cards — confidence strong (70/100, +2 vs. this layer); also covers: AI Register & Model Registry / Factsheets
- Agentic Applications & Copilots — confidence moderate (67/100, -1 vs. this layer); also covers: Document Intelligence Engine
Agentic Applications & Copilots — covers 1 of your components
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| GitHub Copilot | developer copilot | Code completion and agent modes inside the IDE and repository workflow. Typical: software engineering, code review. | not checked | SOC 2 (claimed)enterprise data-handling commitments (claimed) |
| Microsoft 365 Copilot | productivity copilot | Assistant across mail, documents and meetings inheriting existing tenant permissions. Typical: knowledge work, meeting summaries. | not checked | ISO 27001 (claimed)SOC 2 (claimed)EU data-boundary positioning |
| Perplexity Enterprise | research assistant | Cited web and internal search with source attribution per answer. Typical: market research, citation-backed search. | not checked | SOC 2 (claimed)enterprise data-handling commitments (claimed) |
| Cursor | developer copilot | AI-native editor with repository-wide agent edits. Typical: software engineering, refactoring. | not checked | SOC 2 (claimed)privacy-mode option (claimed) |
| Dropzone AI | security operations agent | Autonomous triage of security alerts with written investigation records. Typical: SOC triage, incident write-ups. | not checked | SOC 2 (claimed) |
| Devin (Cognition) | autonomous software agent | Long-running software agent taking tickets to pull requests. Typical: software engineering, backlog automation. | not checked | vendor-stated security posture |
| Vanta | compliance automation | Continuous control monitoring and evidence collection across frameworks. Typical: evidence automation, audit readiness. | not checked | SOC 2 (claimed)ISO 27001/42001 evidence workflows (claimed) |
| Fin (Intercom) | customer-service agent | Resolution-priced support agent answering from your help content. Typical: customer support, deflection. | not checked | SOC 2 (claimed)GDPR-positioned |
| SAP | embedded enterprise AI | AI features and agents embedded in ERP, HR and procurement suites, governed through the vendor's own AI platform layer. Typical: embedded HR AI, procurement automation, finance automation. | SaaS (vendor cloud) | ISO/IEC 42001 certification claim (claimed)EU AI Act readiness positioning |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
- 1 in-scope component of this use case is supplied by this layer (Document Intelligence Engine) — a direct supplied_by path in the graph.
- The catalog use-case match is strong, so the component set this layer was derived from is reliable.
- High-risk tier: this layer carries mandatory Chapter III duties, so some tooling in it is non-optional.
- 9 community-maintained example vendors recorded on the layer node.
- Selection metrics for this layer are documented, so the shortlist can be compared objectively.
- Only 1 of 4 components this layer supplies are in your scope — evaluate a narrow subset of its capabilities.
- Public Transparency Registers & System Cards — confidence strong (70/100, +3 vs. this layer); also covers: AI Register & Model Registry / Factsheets
- Cryptographic Evidence & Audit Ledger — confidence moderate (68/100, +1 vs. this layer); also covers: WORM / Immutable Audit Vault
AI GRC & Governance Platforms — covers 1 of your components
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Credo AI | AI governance platform | Policy packs, risk tiering and evidence workflows mapped across frameworks. Typical: AI registry, policy administration. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | ISO 42001 alignment (claimed)EU AI Act readiness positioning |
| Holistic AI | AI governance & audit | Risk assessment, bias auditing and regulatory reporting workflows. Typical: bias audit, regulatory reporting. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | NYC LL144 audit support (claimed)EU AI Act readiness positioning |
| IBM watsonx.governance | AI governance platform | Governance, factsheets and monitoring integrated with the IBM stack. Typical: factsheets, model monitoring. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | ISO 42001 alignment (claimed)Art. 11 documentation support (claimed) |
| ModelOp | AI/model governance | Model and agent inventory with automated lifecycle controls for large estates. Typical: model inventory, control automation. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | model-risk positioning (SR 11-7 style, claimed)ISO 42001 alignment (claimed) |
| Monitaur | insurance & lending model governance | Model governance and documentation aimed at insurance and lending supervision. Typical: insurance underwriting, credit decisioning. Scope overlap: Its model-governance scope overlaps this platform's own; we have a commercial interest in the comparison. | SaaS (vendor cloud) | NAIC model-governance positioning (claimed)SR 11-7 practice alignment (claimed) |
| OneTrust | GRC & privacy platform | Privacy and AI governance modules extending an existing GRC system of record. Typical: DPIA/FRIA workflow, policy management. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | ISO 27001 (claimed)GDPR-positioned |
| ServiceNow | intake & ITSM workflow | Use-case intake, approval workflow and risk records inside an existing ITSM estate. Typical: AI intake, policy administration. Scope overlap: Its AI-governance module overlaps this platform's own scope; we have a commercial interest in the comparison. | SaaS (vendor cloud) | ISO 42001 alignment (claimed)EU AI Act readiness positioning |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
- 1 in-scope component of this use case is supplied by this layer (AI Register & Model Registry / Factsheets) — a direct supplied_by path in the graph.
- The catalog use-case match is strong, so the component set this layer was derived from is reliable.
- High-risk tier: this layer carries mandatory Chapter III duties, so some tooling in it is non-optional.
- 7 community-maintained example vendors recorded on the layer node.
- Selection metrics for this layer are documented, so the shortlist can be compared objectively.
- Only 1 of 7 components this layer supplies are in your scope — evaluate a narrow subset of its capabilities.
- Public Transparency Registers & System Cards — confidence strong (70/100, +4 vs. this layer); overlapping coverage, no additional selected component
- Cryptographic Evidence & Audit Ledger — confidence moderate (68/100, +2 vs. this layer); also covers: WORM / Immutable Audit Vault
Grounding, Retrieval & Agent Memory — covers 1 of your components
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Docling | document parser | Open-source layout-aware parsing of PDFs and office formats into structured chunks. Typical: RAG ingestion, air-gapped pipelines. | self-hostable | EU sovereignty positioning |
| LlamaParse | document parser | Managed parsing service tuned for tables and complex documents feeding RAG. Typical: RAG ingestion, table extraction. | not checked | SOC 2 (claimed) |
| Amazon Textract | document parser | OCR and form/table extraction with per-page pricing inside AWS. Typical: document intake, claims processing. | not checked | SOC 2 (claimed)HIPAA-eligible (claimed)ISO 27001 (claimed) |
| Diffbot | web/knowledge extraction | Structured extraction and knowledge-graph construction from web sources. Typical: market monitoring, entity resolution. | not checked | vendor-stated security posture |
| Firecrawl | web/knowledge extraction | Crawling and clean markdown extraction for grounding on public sources. Typical: regulatory monitoring, public-source grounding. | not checked | vendor-stated security posture |
| Voyage AI | embeddings | Domain-tuned embedding models including legal and finance variants. Typical: retrieval quality, domain RAG. | not checked | vendor-stated security posture |
| Nomic | embeddings | Open embedding models with local inference and dataset visualisation. Typical: on-prem retrieval, dataset inspection. | self-hostable | |
| Pinecone | vector database | Managed serverless vector search with namespace isolation. Typical: tenant-isolated RAG, semantic search. | not checked | SOC 2 (claimed)ISO 27001 (claimed)HIPAA-eligible (claimed) |
| Weaviate | vector database | Vector database available managed or self-hosted with hybrid search. Typical: hybrid retrieval, self-hosted RAG. | open source | SOC 2 (claimed) |
| Qdrant | vector database | Open-source vector store with payload filtering and on-prem deployment. Typical: air-gapped RAG, filtered retrieval. | open source | GDPR-positioned |
| Milvus | vector database | Open-source vector database for very large collections. Typical: large-scale retrieval. | open source | |
| pgvector | vector database | Postgres extension keeping vectors under the same RBAC, backup and retention regime as records. Typical: record-bound retrieval, small-scale RAG. | self-hostable | record-retention alignment (claimed) |
| Letta (MemGPT) | agent memory store | Persistent agent memory with explicit memory blocks and editing. Typical: long-running agents, personalisation. | self-hostable | |
| Mem0 | agent memory store | Memory layer extracting durable facts from agent conversations. Typical: personalised agents, support copilots. | not checked | vendor-stated security posture |
| Zep | agent memory store | Temporal knowledge-graph memory with fact validity intervals. Typical: auditable memory, long-running agents. | not checked | GDPR-positionedbitemporal record positioning |
| Cognee | agent memory store | Open-source memory/knowledge pipeline building graphs from agent interactions. Typical: knowledge accumulation, research agents. | self-hostable |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
- 1 in-scope component of this use case is supplied by this layer (Document Intelligence Engine) — a direct supplied_by path in the graph.
- The catalog use-case match is strong, so the component set this layer was derived from is reliable.
- High-risk tier: this layer carries mandatory Chapter III duties, so some tooling in it is non-optional.
- 16 community-maintained example vendors recorded on the layer node.
- Selection metrics for this layer are documented, so the shortlist can be compared objectively.
- Only 1 of 8 components this layer supplies are in your scope — evaluate a narrow subset of its capabilities.
- Public Transparency Registers & System Cards — confidence strong (70/100, +4 vs. this layer); also covers: AI Register & Model Registry / Factsheets
- Cryptographic Evidence & Audit Ledger — confidence moderate (68/100, +2 vs. this layer); also covers: WORM / Immutable Audit Vault
Agent Observability & Model Risk Management — covers 1 of your components
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| LangSmith | agent tracing & evaluation | Trace capture and evaluation over LangChain/LangGraph runs with dataset-based scoring. Typical: step tracing, regression evaluation. | not checked | SOC 2 (claimed)supports Art. 12 record-keeping (claimed) |
| Langfuse | agent tracing & evaluation | Open-source tracing, prompt management and evaluation; self-hostable for retention control. Typical: self-hosted tracing, cost/latency analytics. | open source | GDPR-positionedsupports Art. 12 record-keeping (claimed) |
| Arize AI / Phoenix | ML & LLM observability | Production monitoring with drift and performance analysis; Phoenix is the open-source tracing side. Typical: drift monitoring, production analytics. | not checked | SOC 2 (claimed)drift-monitoring positioning (SR 11-7 style, claimed) |
| Helicone | LLM gateway & logging | Proxy-level logging of prompts, costs and latency across providers. Typical: gateway logging, cost control. | not checked | SOC 2 (claimed)supports Art. 12 record-keeping (claimed) |
| MLflow | experiment & model registry | Open-source tracking, model registry and lineage across training and deployment. Typical: model registry, validation records. | open source | model-validation positioning (SR 11-7 style, claimed) |
| Ragas | RAG evaluation | Open evaluation metrics for retrieval faithfulness and answer grounding. Typical: grounding checks, RAG regression. | not checked | OSS, no vendor certification |
| Deepchecks | validation & testing | Continuous validation suites for data and model behaviour. Typical: release gating, data validation. | not checked | evaluation-evidence positioning |
| Fairlearn | fairness toolkit | Open-source fairness assessment and mitigation for classification and regression. Typical: bias testing, fairness reporting. | not checked | OSS, no vendor certificationsupports Art. 10 bias examination (claimed) |
| Fiddler AI | model performance management | Explainability and monitoring platform aimed at regulated model risk teams. Typical: explainability, model monitoring. | not checked | SOC 2 (claimed)model-risk positioning (SR 11-7 style, claimed) |
| ValidMind | model risk management | Model validation documentation and workflow for banking model-risk functions. Typical: validation reports, MRM workflow. | not checked | SOC 2 (claimed)model-risk positioning (SR 11-7 style, claimed) |
| WhyLabs | data & model monitoring | Telemetry and drift monitoring over model inputs and outputs. Typical: drift detection, data quality monitoring. | SaaS (vendor cloud) | supports Art. 72 post-market monitoring (claimed) |
| Evidently AI | evaluation & monitoring | Open-source evaluation and monitoring reports for ML and LLM pipelines. Typical: evaluation reports, drift detection. | open source | supports Art. 72 post-market monitoring (claimed) |
| Galileo AI | LLM evaluation & observability | Evaluation metrics and traces for generative applications. Typical: LLM evaluation, trace inspection. | SaaS (vendor cloud) | supports Art. 15 accuracy measures (claimed) |
| Patronus AI · eingestellt (2026-08-31) | automated LLM evaluation | Automated scoring and adversarial test suites for generative output. Typical: automated evaluation, red teaming. | SaaS (vendor cloud) | supports Art. 15 robustness measures (claimed) |
| Arthur AI | model performance monitoring | Performance, bias and drift monitoring across deployed models. Typical: bias monitoring, performance monitoring. | SaaS (vendor cloud) | supports Art. 72 post-market monitoring (claimed)supports Art. 10 bias examination (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
- 1 in-scope component of this use case is supplied by this layer (AI Register & Model Registry / Factsheets) — a direct supplied_by path in the graph.
- The catalog use-case match is strong, so the component set this layer was derived from is reliable.
- High-risk tier: this layer carries mandatory Chapter III duties, so some tooling in it is non-optional.
- 15 community-maintained example vendors recorded on the layer node.
- Selection metrics for this layer are documented, so the shortlist can be compared objectively.
- Only 1 of 10 components this layer supplies are in your scope — evaluate a narrow subset of its capabilities.
- Public Transparency Registers & System Cards — confidence strong (70/100, +5 vs. this layer); overlapping coverage, no additional selected component
- Cryptographic Evidence & Audit Ledger — confidence moderate (68/100, +3 vs. this layer); also covers: WORM / Immutable Audit Vault