Where do you stand? › Route 3 · Vendors & stack
I know which systems I need — who supplies them?
Pick the components you have to put in place. For each one you get the build-vs-buy reading and the market layer that supplies it, with the same scored recommendations and confidence the full analysis uses. Nothing is stored; the selection lives in the URL.
Target market(s)European UnionUnited States (federal)change
Legally-driven components are flagged when their requiring regulation sits outside your selected markets.
Step 1 of 2 — pick your components4 selected
Step 2 of 2 — the vendor & stack view
4 of 4 selected components are covered by 5 market layers.
Named vendors are community-maintained, disputable examples — not an endorsement. The stable object is the market layer. Compare with the reference stack for your regulatory profile →
Build or buy, per component (4)
Runtime Security & Guardrail Vendors — covers 2 of your components
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Lakera | guardrail proxy | Inline prompt-injection and content detection at request time. Typical: injection defence, content filtering. | not checked | SOC 2 (claimed)supports Art. 15 robustness measures (claimed) |
| HiddenLayer | model/agent detection & response | Model-layer detection and response with adversarial-attack telemetry. Typical: model threat detection, red-team telemetry. | not checked | SOC 2 (claimed)supports Art. 15 robustness measures (claimed) |
| Palo Alto Prisma AIRS | network-integrated AI security | AI runtime security folded into an existing enterprise network security estate. Typical: enterprise rollout, egress control. | not checked | SOC 2 (claimed)enterprise security integration (claimed) |
| Cisco AI Defense | network-integrated AI security | Discovery of AI usage plus inline enforcement across the corporate network. Typical: shadow-AI discovery, inline enforcement. | not checked | enterprise security integration (claimed) |
| NVIDIA NeMo Guardrails | open guardrail framework | Programmable dialogue and action rails, self-hostable alongside your models. Typical: dialogue rails, action gating. | open source | supports Art. 15 robustness measures (claimed) |
| Guardrails AI | open guardrail framework | Open validator library for structured output checks and policy validators. Typical: output validation, schema enforcement. | open source | OSS, no vendor certification |
| Garak | adversarial scanner | Open-source LLM vulnerability scanner used for pre-deployment probing. Typical: red-teaming, release gating. | not checked | OSS, no vendor certificationsupports Art. 15 testing evidence (claimed) |
| Protect AI | ML supply-chain & model security | Model scanning and ML supply-chain security tooling (Palo Alto Networks acquisition reported 2025). Typical: model scanning, supply-chain security. | SaaS (vendor cloud) | supports Art. 15 cybersecurity measures (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
- 2 in-scope components of this use case are supplied by this layer (Output Rails / Groundedness Check, Interface Transparency & Content-Marking Layer) — a direct supplied_by path in the graph.
- The catalog use-case match is strong, so the component set this layer was derived from is reliable.
- High-risk tier: this layer carries mandatory Chapter III duties, so some tooling in it is non-optional.
- 8 community-maintained example vendors recorded on the layer node.
- Selection metrics for this layer are documented, so the shortlist can be compared objectively.
- Only 2 of 7 components this layer supplies are in your scope — evaluate a narrow subset of its capabilities.
- Public Transparency Registers & System Cards — confidence strong (70/100, -11 vs. this layer); overlapping coverage, no additional selected component
- Cryptographic Evidence & Audit Ledger — confidence moderate (68/100, -13 vs. this layer); also covers: WORM / Immutable Audit Vault
Public Transparency Registers & System Cards — covers 1 of your components
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Saidot | public AI register | AI register with published system cards and regulation-mapped documentation workflows. Typical: public AI register, system cards. Scope overlap: Its documentation and register scope overlaps this platform's own; we have a commercial interest in the comparison. | SaaS (vendor cloud) | EU AI Act documentation positioningISO 42001 alignment (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
- 1 in-scope component of this use case is supplied by this layer (Interface Transparency & Content-Marking Layer) — a direct supplied_by path in the graph.
- This layer's graph purpose overlaps strongly with your scope (1 of 2 components it supplies are in scope).
- The catalog use-case match is strong, so the component set this layer was derived from is reliable.
- High-risk tier: this layer carries mandatory Chapter III duties, so some tooling in it is non-optional.
- 1 community-maintained example vendor recorded on the layer node.
- Selection metrics for this layer are documented, so the shortlist can be compared objectively.
- Runtime Security & Guardrail Vendors — confidence strong (81/100, +11 vs. this layer); also covers: Output Rails / Groundedness Check
- Cryptographic Evidence & Audit Ledger — confidence moderate (68/100, -2 vs. this layer); also covers: WORM / Immutable Audit Vault
Cryptographic Evidence & Audit Ledger — covers 1 of your components
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Fact0 | cryptographic evidence ledger | Positions itself as a tamper-evident ledger for AI decision records. Typical: decision records, audit trail. | not checked | supports Art. 12 record-keeping (claimed) |
| Traccia | audit trail & traceability | Positions itself around traceability of AI pipeline steps and artefacts. Typical: traceability, artifact lineage. | not checked | supports Art. 12 record-keeping (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
- 1 in-scope component of this use case is supplied by this layer (WORM / Immutable Audit Vault) — a direct supplied_by path in the graph.
- The catalog use-case match is strong, so the component set this layer was derived from is reliable.
- High-risk tier: this layer carries mandatory Chapter III duties, so some tooling in it is non-optional.
- 2 community-maintained example vendors recorded on the layer node.
- Selection metrics for this layer are documented, so the shortlist can be compared objectively.
- Only 1 of 3 components this layer supplies are in your scope — evaluate a narrow subset of its capabilities.
- Runtime Security & Guardrail Vendors — confidence strong (81/100, +13 vs. this layer); also covers: Output Rails / Groundedness Check, Interface Transparency & Content-Marking Layer
- Public Transparency Registers & System Cards — confidence strong (70/100, +2 vs. this layer); also covers: Interface Transparency & Content-Marking Layer
Agent Orchestration & SDLC Toolkits — covers 1 of your components
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| LangChain / LangGraph | agent framework | Graph-structured agent runtime; interrupt/pause nodes support implementing human approval at defined steps. Typical: multi-step agents, approval workflows. | not checked | supports implementing Art. 14 oversight (claimed)supports Art. 12 step logging (claimed) |
| LlamaIndex | RAG framework | Indexing and query abstractions over documents and structured sources. Typical: enterprise RAG, document agents. | open source | retrieval-governance positioning |
| Microsoft AutoGen | multi-agent framework | Conversational multi-agent patterns with pluggable tool executors. Typical: multi-agent research, code agents. | not checked | research/OSS, no vendor certification |
| CrewAI | multi-agent framework | Role-based agent teams with task delegation and process templates. Typical: process automation, role-based agents. | not checked | vendor-stated security posture |
| DSPy | prompt/program optimisation | Declarative programs with optimisers that make prompt changes reproducible and testable. Typical: evaluated pipelines, model validation. | not checked | model-validation positioning (SR 11-7 style, claimed) |
| Semantic Kernel | enterprise SDK | Microsoft SDK for planners and plugins inside .NET/Java estates. Typical: enterprise copilots, tool plugins. | not checked | enterprise-estate integration (claimed) |
| PydanticAI | typed agent SDK | Type-validated agent outputs and tool signatures for deterministic contracts. Typical: structured outputs, typed tool calls. | not checked | schema-enforcement positioning |
| Model Context Protocol (MCP) | protocol / standard | Open protocol for tool and context exposure; a protocol, not a product — governance sits in the gateway around it. Typical: tool interoperability, gateway mediation. | not checked | open protocol, no certification |
| E2B | sandboxed runtime | Ephemeral cloud sandboxes for agent code execution with isolation per task. Typical: code agents, untrusted execution. | not checked | isolation/sandbox positioning |
| Airia | enterprise agent platform | Enterprise platform for building and running agents with connector, policy and routing layers. Typical: agent orchestration, internal copilots. | SaaS (vendor cloud) | EU AI Act readiness positioningSOC 2 programme positioning (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
- 1 in-scope component of this use case is supplied by this layer (HITL Escalation Queue & Review UI) — a direct supplied_by path in the graph.
- The catalog use-case match is strong, so the component set this layer was derived from is reliable.
- High-risk tier: this layer carries mandatory Chapter III duties, so some tooling in it is non-optional.
- 10 community-maintained example vendors recorded on the layer node.
- Selection metrics for this layer are documented, so the shortlist can be compared objectively.
- Only 1 of 4 components this layer supplies are in your scope — evaluate a narrow subset of its capabilities.
- Runtime Security & Guardrail Vendors — confidence strong (81/100, +14 vs. this layer); also covers: Output Rails / Groundedness Check, Interface Transparency & Content-Marking Layer
- Public Transparency Registers & System Cards — confidence strong (70/100, +3 vs. this layer); also covers: Interface Transparency & Content-Marking Layer
Runtime Guardrails & Enforcement — covers 1 of your components
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Guardrails AI | validation framework | Open-source validator framework for structured output and content policies in the request path. Typical: output validation, structured output. | open source | supports Art. 15 robustness measures (claimed) |
| NVIDIA NeMo Guardrails | dialogue policy rails | Programmable dialogue and topic rails placed around an LLM application. Typical: topic control, dialogue policy. | open source | supports Art. 50 interaction disclosure patterns (claimed) |
| Lakera AI | guardrail proxy | Inline prompt-injection and content detection at request time. Typical: injection defence, content filtering. | SaaS (vendor cloud) | SOC 2 (claimed)supports Art. 15 robustness measures (claimed) |
| Credal AI | enterprise access & policy layer | Permission-aware access layer with data-loss controls in front of enterprise assistants. Typical: access control, DLP. | SaaS (vendor cloud) | SOC 2 (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
- 1 in-scope component of this use case is supplied by this layer (Output Rails / Groundedness Check) — a direct supplied_by path in the graph.
- The catalog use-case match is strong, so the component set this layer was derived from is reliable.
- High-risk tier: this layer carries mandatory Chapter III duties, so some tooling in it is non-optional.
- 4 community-maintained example vendors recorded on the layer node.
- Selection metrics for this layer are documented, so the shortlist can be compared objectively.
- Only 1 of 4 components this layer supplies are in your scope — evaluate a narrow subset of its capabilities.
- Runtime Security & Guardrail Vendors — confidence strong (81/100, +14 vs. this layer); also covers: Interface Transparency & Content-Marking Layer
- Public Transparency Registers & System Cards — confidence strong (70/100, +3 vs. this layer); also covers: Interface Transparency & Content-Marking Layer