Skip to content

The datasheet for every AI agent

Curated collection

AI Agent Tools With Documented Enterprise Security Controls

49 of the 126 tools in our index name a specific enterprise security or deployment control — SSO/SAML, a named compliance certification, RBAC, audit logging, or VPC/on-prem deployment — in their own pricing or feature docs. Voice agents clear the bar at 10 of 20 and agent frameworks at 7 of 16, the frameworks only through an enterprise tier or deployment mode layered on top of an otherwise open core.

49 of the 126 AI agent tools in this index name a specific enterprise security or deployment control in their own pricing or feature documentation. 62 of our listings carry an "enterprise" tag, but a tag alone just means the tool has some kind of high-touch, custom-priced or sales-led tier. It says nothing about whether that tier actually does anything a security-conscious buyer would check for. This page is not that tag. It is the result of reading each listing's own pricing tiers, feature lists, pros/cons and sources for a SPECIFIC named control, not just the word "Enterprise" on a plan, and the two rosters differ in both directions: some tagged listings name no control anywhere, and some listings that name one carry no tag at all.

At a glance

agents
49
curated for this set
Free to start
36 of 49
a free or freemium entry tier
Public API
35 of 49
10 more only on a paid tier
Publish a price
46 of 49
an anchor price on their own page
What this collection covers

Voice agents are 10 of 20, and the reason is structural: voice agents routinely handle recorded calls and PII at a scale that forces the compliance conversation early, so SOC 2, HIPAA, PCI DSS and GDPR compliance show up across the category. Vapi, Retell AI, Bland AI, ElevenLabs Conversational AI, PolyAI, LiveKit Agents, Synthflow AI, Cartesia, the Deepgram Voice Agent API and the OpenAI Realtime API each document a real control. Synthflow AI documents an unusually complete set for a company still at Series A: SOC 2, HIPAA, GDPR, PCI DSS and ISO 27001 all named together as platform-wide infrastructure, not gated behind a specific tier. Cartesia carries a comparable spread: SOC 2 Type II, PCI Level 1, GDPR and HIPAA eligibility with a signed BAA, named on its own enterprise-security docs rather than on a pricing bullet. Its Enterprise tier adds SSO plus deployment of the Sonic and Ink speech models into a customer-controlled cloud or on-premise environment; the Line agent runtime itself stays Cartesia-hosted, a limit its own listing states rather than glosses. The Deepgram Voice Agent API qualifies on the same platform-wide basis: SOC 2 Type II, signed HIPAA BAAs, and both a customer-owned VPC and a fully self-hosted install. The OpenAI Realtime API is the thinnest case admitted here and is worth stating plainly. It is a metered endpoint with no plan structure at all, so it gates no control behind a tier, but the bar on this page is a named control rather than a plan that gates one, and OpenAI's own SOC 2 Type 2 and ISO 27001-family compliance is named platform-wide. LiveKit Agents earns its place one rung earlier than most: RBAC and HIPAA-oriented security reporting already ship on its Scale tier, one step below Enterprise, which adds SSO and a support SLA on top.

Coding agents follow at 12 of 27, and the IDE-first tools carry most of the named access controls: Cursor's Enterprise tier documents SCIM provisioning and audit logs, Windsurf's adds SSO and admin controls, Cline's adds SSO/OIDC alongside RBAC and centrally-managed JetBrains deployment, and Warp already ships SAML-based SSO one tier below Enterprise (Business), with Enterprise itself adding self-hosted cloud agents on the customer's own infrastructure. Zed clears the bar without a sales call at all: its $30/seat Business tier, which anyone can buy online, names role-based access control and org-wide data-governance policies directly. Devin, Bolt.new, OpenHands, Factory and CodeRabbit carry the deployment controls (on-prem, air-gapped or customer-VPC) for codebases that cannot leave a customer's network, and Replit Agent's Enterprise tier now names the same shape from the vendor side: SSO/SAML and VPC peering, alongside single-tenant environments and custom seat limits. One coding agent is deliberately absent, and is named here so the exclusion is not mistaken for an oversight: Junie's AI Enterprise tier is real and custom-priced, but JetBrains' own docs describe it only as "organization-wide admin and security controls" with no specific SSO, RBAC, audit-log or compliance certification named.

Agent frameworks are 7 of 16, and they clear the bar through an enterprise tier or a deployment mode layered on top of an otherwise open core rather than through the framework library itself. CrewAI's AMP Enterprise tier adds VPC deployment and FedRAMP High; LlamaIndex's Enterprise tier for LlamaCloud adds SSO; Letta's Enterprise tier adds SAML/OIDC SSO and role-based access; Mastra ships two enterprise paths at once: a Mastra Cloud Enterprise tier with RBAC and audit logs, plus a separate Enterprise Self-Hosted tier that keeps RBAC/SSO/IAM while data stays inside the customer's own VPC; Agno names audit logging and role-based access control with a BYOC deployment into an airgapped environment; and AgentsKit, which sells no tier at all, ships an air-gap-capable self-hosted desktop under an MIT licence. The remaining framework listings name no control of their own: LangChain, LangGraph, Microsoft AutoGen, Microsoft Agent Framework, OpenAI Agents SDK, Pydantic AI, Google Agent Development Kit and Claude Agent SDK. None of them sells a managed tier naming one (Google ADK's Agent Runtime and Claude Agent SDK's Claude Managed Agents are both metered usage layers with no SSO, RBAC or compliance certification named anywhere in their own docs), so for these "enterprise-ready" is a question for whatever platform you deploy them on, not for the framework.

Agent platforms are 16 of 29. Moveworks names an unusually broad compliance stack: FedRAMP, SOC 2 Type II, a full ISO 27001/27017/27018/27701 spread and CSA STAR Level 2, a list built for the regulated enterprises that read a compliance list line by line before signing. Glean takes a different angle on the same bar: SOC 2 Type II, ISO/IEC 27001, HIPAA and GDPR, plus ISO/IEC 42001:2023, an AI-management-system certification that no other listing in this index names anywhere in its text, on top of the general controls rather than instead of them. Botpress joins via SSO and SCIM provisioning plus audit logs on its Enterprise tier, with role-based access control already available one tier down on Team, which is now listed at $750/month. n8n's Enterprise tier adds custom-volume self-hosted or cloud deployment with dedicated support and an SLA (its Cloud Business tier, one rung down, already ships SSO/SAML/LDAP); Lindy's Enterprise tier stacks SSO, SCIM, HIPAA/BAA and audit logs; Dify's adds self-hosted deployment with SSO/SAML, RBAC, audit logs and SLAs on top of its already-open Community Edition. MindStudio names SOC 2 Type II certification, GDPR compliance, SSO and audit logs as platform-wide Enterprise controls, plus self-hosting on custom infrastructure with custom domains gated behind its Business plan. Sim, itself open source, names SOC 2 compliance and offers self-hosting as an alternative to its cloud product, a pairing its own listing frames as targeting security-conscious deployments. Botsify, OpenClaw, Salesforce Agentforce and Vecbase are the platforms that name no qualifying control, and OpenClaw is the instructive one: it is fully self-hostable open source, and self-hosting on its own is not a control this page counts.

Agent tools are 2 of 7: Browserbase names HIPAA compliance, a DPA and SSO on its custom-priced Scale plan, and SalesTouch names a 90-day audit log retaining every MCP call, LinkedIn action and scheduled task. This is much the smallest category in the index, so the two named controls say more than the rate does.

Sales and marketing agents are 2 of 11: Artisan and Rox name SSO and RBAC alongside warehouse syncs and dedicated strategists. Warmly and Amplemarket name none. Warmly's three published tiers (all quarterly-billed, topping out at $9,750/quarter) carry no Enterprise plan or named security control at all, and Amplemarket's top Elite tier is priced on seats and credits with no security specifics stated anywhere in its own docs.

Research agents are 7 of 12. Genspark qualifies via a custom-priced Team/Enterprise tier naming SSO sign-in; Elicit's Enterprise tier adds SSO/SAML and an unlimited API on top of its largest extraction limits; Manus's Team tier names SSO alongside otherwise consumer-priced, credit-metered plans, an unusually specific control for a product this self-serve; Julius AI qualifies on the company's own SOC 2 Type II certification rather than on any tier; and GC AI and Perplexity complete the set, with Undermind's single-control SSO stack the thinnest confirmed entry here. Microsoft Fabric Data Agent misses for a structural reason rather than a gap: it bills entirely through a customer's existing Fabric or Power BI Premium capacity rather than its own subscription, and its own docs name no security or deployment control independent of whatever that underlying Azure/Fabric tenant already provides, so there is no standalone tier to check. GPT Researcher, open-source and self-hosted, names no control of its own either.

The listings that carry an "enterprise" tag and still do not make the cut are worth naming rather than burying, because in almost every case the tier is real and only the specifics are missing. GitHub Copilot, 11x, Intercom Fin, Cresta, Qualified, Ada, Salesforce Agentforce, Zendesk AI Agents, Gemini Code Assist, Warmly, Amplemarket, LangGraph, Junie, Microsoft Fabric Data Agent and Decagon each sell, or sit inside, a custom, sales-led enterprise offering with no specific compliance or deployment control named anywhere in our sourced research. Zendesk AI Agents is the clearest example of the pattern: its Suite Enterprise + Copilot tier promises "advanced security and governance" without ever naming what that actually is. Decagon is sharper than a simple gap, and points the other way: G2 reviewers we cited on that listing specifically flag its audit logs as too shallow for compliance tracing, a documented weakness rather than an unstated one. None of these tools is necessarily insecure; they simply have not published the specifics this list requires.

How these 49 agents were picked

A tool earns a place here only if its own Published, sourced listing text names a SPECIFIC enterprise security or deployment control: single sign-on (SSO/SAML/SCIM), a named compliance certification (SOC 2, HIPAA, GDPR, PCI DSS, ISO 27001, FedRAMP), role-based access control (RBAC), audit logging, or a VPC / on-premises / air-gapped deployment option. A "Contact sales" or custom-priced Enterprise tier with no control named anywhere in the listing's pricing tiers, feature list, pros/cons or sources does not qualify, even though the tier itself is real. Self-hosting or an open-source licence on its own is not a control either: the listing must name a specific one, which is why some fully self-hostable tools are absent. A control named platform-wide counts the same as one gated behind a tier. Verified against each listing's own already-researched, quality-gated fields, not inferred from company size, funding, or a vendor's general enterprise-readiness marketing claims. Membership is derived from that listing text and not from this site's "enterprise" tag, so this page is neither a subset nor a superset of the tag.

The 49 agents on this shelf

Browse wider than this shelf

A collection is one cut through the index. These are the full categories the agents above sit in, unfiltered.

Advertise here

Reach buyers mid-decision. Reach builders choosing their next agent. Promote your brand with a display placement or bring your listing into focus with Featured.

Explore owner options →Advertise on this page →

The digestFree

Which agents actually ship.

What we re-checked, what got added, and one number from the index. Tuesdays.

One-click unsubscribe