AI Agent Tools With Documented Enterprise Security Controls

40 of the 70 tools in our index name a specific enterprise security or deployment control — SSO/SAML, a named compliance certification, RBAC, audit logging, or VPC/on-prem deployment — in their own pricing or feature docs. Voice agents remain the only category to clear 100% (7 of 7, Synthflow AI joining); agent frameworks name 4 of 11 through a managed-cloud tier layered on top of an otherwise fully open, self-hosted core.

52 of our 70 listings carry an "enterprise" tag, but a tag alone just means the tool has some kind of high-touch, custom-priced or sales-led tier — it says nothing about whether that tier actually does anything a security-conscious buyer would check for. We read every one of those 52 listings' own pricing tiers, feature lists, pros/cons and sources looking for a SPECIFIC named control, not just the word "Enterprise" on a plan. 40 clear that bar.

Voice agents remain the only category to clear 100%: all 7 listings (Vapi, Retell AI, Bland AI, ElevenLabs Conversational AI, PolyAI, LiveKit Agents, and the newest addition, Synthflow AI) document real controls — SOC 2, HIPAA, PCI DSS and GDPR compliance show up across the category, likely because voice agents routinely handle recorded calls and PII at a scale that forces the compliance conversation early. Synthflow AI documents an unusually complete set for a company still at Series A — SOC 2, HIPAA, GDPR, PCI DSS and ISO 27001 all named together as platform-wide infrastructure, not gated behind a specific tier. LiveKit Agents earns its place one rung earlier than most: RBAC and HIPAA-oriented security reporting already ship on its Scale tier, one step below Enterprise, which adds SSO and a support SLA on top. The single deepest stack in the whole collection, though, still belongs to agent-platforms newcomer Moveworks — FedRAMP, SOC 2 Type II, a full ISO 27001/27017/27018/27701 spread and CSA STAR Level 2 — built for the regulated enterprises that read a compliance list line by line before signing. Its category-mate Glean takes a different angle on the same bar: SOC 2 Type II, ISO/IEC 27001, HIPAA and GDPR, plus ISO/IEC 42001:2023 — a dedicated AI-management-system certification that no other listing in this collection carries, on top of the general controls rather than instead of them.

Coding agents follow at 11 of 19. The newest entrants here skew IDE-first rather than terminal-agent: Cursor's Enterprise tier documents SCIM provisioning and audit logs, Windsurf's adds SSO and admin controls, Cline's adds SSO/OIDC alongside RBAC and centrally-managed JetBrains deployment, and Warp already ships SAML-based SSO one tier below Enterprise (Business), with Enterprise itself adding self-hosted cloud agents on the customer's own infrastructure. Zed is the one member of this whole collection with no "Enterprise"-labeled plan at all — its $30/seat Business tier, a self-serve tier anyone can buy online, names role-based access control and org-wide data-governance policies directly, clearing the bar without a sales call. The earlier cohort — Devin, Replit Agent, Bolt.new, OpenHands, Factory, CodeRabbit — still accounts for most of the category's on-prem or air-gapped deployment options, for codebases that can't leave a customer's network.

Agent frameworks are no longer a blanket exception, and this update is the reason: a fresh read of all 11 framework listings' own pricing docs turns "frameworks name zero" into 4 of 11. CrewAI's AMP Enterprise tier adds VPC deployment and FedRAMP High; LlamaIndex's Enterprise tier for LlamaCloud adds SSO; Letta's Enterprise tier adds SAML/OIDC SSO and role-based access; and Mastra ships two enterprise paths at once — a Mastra Cloud Enterprise tier with RBAC and audit logs, plus a separate Enterprise Self-Hosted tier that keeps RBAC/SSO/IAM while data stays inside the customer's own VPC. The distinction that still holds for the other 7 — LangChain, Microsoft AutoGen, Microsoft Agent Framework, OpenAI Agents SDK, Pydantic AI, Google Agent Development Kit and the newest arrival, Claude Agent SDK — is real: none of them sells a managed-cloud tier of its own naming a control (Google ADK's own Agent Runtime and Claude Agent SDK's own Claude Managed Agents are both metered usage layers with no SSO, RBAC or compliance certification named anywhere in their own docs), so for these, "enterprise-ready" is still a question for whatever platform you deploy them on, not the framework itself.

Agent platforms rise to 8 of 11 — the newest addition, Botpress, joins via SSO and SCIM provisioning plus audit logs on its Enterprise tier, with role-based access control already available one tier down (Team, $495/month). Vecbase and Botsify still don't name a qualifying control, joining Salesforce Agentforce as the three holdouts. n8n's Enterprise tier adds custom-volume self-hosted or cloud deployment with dedicated support and an SLA (its Cloud Business tier, one rung down, already ships SSO/SAML/LDAP); Lindy's Enterprise tier stacks SSO, SCIM, HIPAA/BAA and audit logs; Dify's adds self-hosted deployment with SSO/SAML, RBAC, audit logs and SLAs on top of its already-open Community Edition.

Sales and marketing agents hold at 3 of 8: Clay's Enterprise tier names SSO and RBAC alongside warehouse syncs and a dedicated strategist, alongside Artisan and Rox. The category grew by two since the last count — Warmly and Amplemarket — and neither names a qualifying control: Warmly's three published tiers (all quarterly-billed, topping out at $9,750/quarter) carry no Enterprise plan or named security control at all, and Amplemarket's top Elite tier is priced on seats and credits with no security specifics stated anywhere in its own docs.

Research agents rise to 6 of 8: Genspark joins via a custom-priced Team/Enterprise tier that names SSO sign-in, alongside Elicit's Enterprise tier (SSO/SAML and an unlimited API on top of its largest extraction limits) and Manus's Team tier, which names SSO alongside its otherwise consumer-priced, credit-metered plans — an unusually specific control for a product this self-serve. GC AI and Perplexity round out the six qualifying entries; Undermind's single-control SSO stack is the thinnest confirmed entry in the collection. Microsoft Fabric Data Agent, the category's other newcomer, doesn't clear the bar for a different reason than a simple gap: it bills entirely through a customer's existing Fabric or Power BI Premium capacity rather than its own subscription, and its own docs name no security or deployment control independent of whatever that underlying Azure/Fabric tenant already provides — there's no standalone tier to check. GPT Researcher (open-source, self-hosted) remains the one research-agent holdout with no enterprise tag at all.

12 of the 52 "enterprise"-tagged listings still don't make the cut, and it's worth naming them rather than burying the exclusion. Eight were already here: GitHub Copilot, 11x, Sierra's category-mate Intercom Fin, Cresta, Qualified, Ada, Salesforce Agentforce and Decagon each sell a custom, sales-led Enterprise plan with no specific compliance or deployment control named anywhere in our sourced research. Decagon is a sharper case than a simple gap: G2 reviewers we cited on that listing specifically flag its audit logs as too shallow for compliance tracing — a documented weakness, not just an unstated one. The four newest exclusions each miss for a different reason: Warmly names no Enterprise plan at all; Amplemarket doesn't either; Zendesk AI Agents' Suite Enterprise + Copilot tier promises "advanced security and governance" without naming what that actually is — the same vague-promise pattern the original eight hit, not a new one; and Microsoft Fabric Data Agent, discussed above, has no standalone tier to name a control on in the first place. None of the 12 are necessarily insecure; they simply haven't published — or in Fabric Data Agent's case, don't independently own — the specifics this list requires.

Why this collection

A tool earns a place here only if its own Published, sourced listing text names a SPECIFIC enterprise security or deployment control — single sign-on (SSO/SAML/SCIM), a named compliance certification (SOC 2, HIPAA, GDPR, PCI DSS, ISO 27001, FedRAMP), role-based access control (RBAC), audit logging, or a VPC / on-premises / air-gapped deployment option. A "Contact sales" or custom-priced Enterprise tier with no control named anywhere in the listing's pricing tiers, feature list, pros/cons or sources does not qualify, even though the tier itself is real. Verified against each listing's own already-researched, gate-passed fields, not inferred from company size, funding, or a vendor's general enterprise-readiness marketing claims.