AI Agent Tools With Documented Enterprise Security Controls
40 of the 70 tools in our index name a specific enterprise security or deployment control — SSO/SAML, a named compliance certification, RBAC, audit logging, or VPC/on-prem deployment — in their own pricing or feature docs. Voice agents remain the only category to clear 100% (7 of 7, Synthflow AI joining); agent frameworks name 4 of 11 through a managed-cloud tier layered on top of an otherwise fully open, self-hosted core.
52 of our 70 listings carry an "enterprise" tag, but a tag alone just means the tool has some kind of high-touch, custom-priced or sales-led tier — it says nothing about whether that tier actually does anything a security-conscious buyer would check for. We read every one of those 52 listings' own pricing tiers, feature lists, pros/cons and sources looking for a SPECIFIC named control, not just the word "Enterprise" on a plan. 40 clear that bar.
Voice agents remain the only category to clear 100%: all 7 listings (Vapi, Retell AI, Bland AI, ElevenLabs Conversational AI, PolyAI, LiveKit Agents, and the newest addition, Synthflow AI) document real controls — SOC 2, HIPAA, PCI DSS and GDPR compliance show up across the category, likely because voice agents routinely handle recorded calls and PII at a scale that forces the compliance conversation early. Synthflow AI documents an unusually complete set for a company still at Series A — SOC 2, HIPAA, GDPR, PCI DSS and ISO 27001 all named together as platform-wide infrastructure, not gated behind a specific tier. LiveKit Agents earns its place one rung earlier than most: RBAC and HIPAA-oriented security reporting already ship on its Scale tier, one step below Enterprise, which adds SSO and a support SLA on top. The single deepest stack in the whole collection, though, still belongs to agent-platforms newcomer Moveworks — FedRAMP, SOC 2 Type II, a full ISO 27001/27017/27018/27701 spread and CSA STAR Level 2 — built for the regulated enterprises that read a compliance list line by line before signing. Its category-mate Glean takes a different angle on the same bar: SOC 2 Type II, ISO/IEC 27001, HIPAA and GDPR, plus ISO/IEC 42001:2023 — a dedicated AI-management-system certification that no other listing in this collection carries, on top of the general controls rather than instead of them.
Coding agents follow at 11 of 19. The newest entrants here skew IDE-first rather than terminal-agent: Cursor's Enterprise tier documents SCIM provisioning and audit logs, Windsurf's adds SSO and admin controls, Cline's adds SSO/OIDC alongside RBAC and centrally-managed JetBrains deployment, and Warp already ships SAML-based SSO one tier below Enterprise (Business), with Enterprise itself adding self-hosted cloud agents on the customer's own infrastructure. Zed is the one member of this whole collection with no "Enterprise"-labeled plan at all — its $30/seat Business tier, a self-serve tier anyone can buy online, names role-based access control and org-wide data-governance policies directly, clearing the bar without a sales call. The earlier cohort — Devin, Replit Agent, Bolt.new, OpenHands, Factory, CodeRabbit — still accounts for most of the category's on-prem or air-gapped deployment options, for codebases that can't leave a customer's network.
Agent frameworks are no longer a blanket exception, and this update is the reason: a fresh read of all 11 framework listings' own pricing docs turns "frameworks name zero" into 4 of 11. CrewAI's AMP Enterprise tier adds VPC deployment and FedRAMP High; LlamaIndex's Enterprise tier for LlamaCloud adds SSO; Letta's Enterprise tier adds SAML/OIDC SSO and role-based access; and Mastra ships two enterprise paths at once — a Mastra Cloud Enterprise tier with RBAC and audit logs, plus a separate Enterprise Self-Hosted tier that keeps RBAC/SSO/IAM while data stays inside the customer's own VPC. The distinction that still holds for the other 7 — LangChain, Microsoft AutoGen, Microsoft Agent Framework, OpenAI Agents SDK, Pydantic AI, Google Agent Development Kit and the newest arrival, Claude Agent SDK — is real: none of them sells a managed-cloud tier of its own naming a control (Google ADK's own Agent Runtime and Claude Agent SDK's own Claude Managed Agents are both metered usage layers with no SSO, RBAC or compliance certification named anywhere in their own docs), so for these, "enterprise-ready" is still a question for whatever platform you deploy them on, not the framework itself.
Agent platforms rise to 8 of 11 — the newest addition, Botpress, joins via SSO and SCIM provisioning plus audit logs on its Enterprise tier, with role-based access control already available one tier down (Team, $495/month). Vecbase and Botsify still don't name a qualifying control, joining Salesforce Agentforce as the three holdouts. n8n's Enterprise tier adds custom-volume self-hosted or cloud deployment with dedicated support and an SLA (its Cloud Business tier, one rung down, already ships SSO/SAML/LDAP); Lindy's Enterprise tier stacks SSO, SCIM, HIPAA/BAA and audit logs; Dify's adds self-hosted deployment with SSO/SAML, RBAC, audit logs and SLAs on top of its already-open Community Edition.
Sales and marketing agents hold at 3 of 8: Clay's Enterprise tier names SSO and RBAC alongside warehouse syncs and a dedicated strategist, alongside Artisan and Rox. The category grew by two since the last count — Warmly and Amplemarket — and neither names a qualifying control: Warmly's three published tiers (all quarterly-billed, topping out at $9,750/quarter) carry no Enterprise plan or named security control at all, and Amplemarket's top Elite tier is priced on seats and credits with no security specifics stated anywhere in its own docs.
Research agents rise to 6 of 8: Genspark joins via a custom-priced Team/Enterprise tier that names SSO sign-in, alongside Elicit's Enterprise tier (SSO/SAML and an unlimited API on top of its largest extraction limits) and Manus's Team tier, which names SSO alongside its otherwise consumer-priced, credit-metered plans — an unusually specific control for a product this self-serve. GC AI and Perplexity round out the six qualifying entries; Undermind's single-control SSO stack is the thinnest confirmed entry in the collection. Microsoft Fabric Data Agent, the category's other newcomer, doesn't clear the bar for a different reason than a simple gap: it bills entirely through a customer's existing Fabric or Power BI Premium capacity rather than its own subscription, and its own docs name no security or deployment control independent of whatever that underlying Azure/Fabric tenant already provides — there's no standalone tier to check. GPT Researcher (open-source, self-hosted) remains the one research-agent holdout with no enterprise tag at all.
12 of the 52 "enterprise"-tagged listings still don't make the cut, and it's worth naming them rather than burying the exclusion. Eight were already here: GitHub Copilot, 11x, Sierra's category-mate Intercom Fin, Cresta, Qualified, Ada, Salesforce Agentforce and Decagon each sell a custom, sales-led Enterprise plan with no specific compliance or deployment control named anywhere in our sourced research. Decagon is a sharper case than a simple gap: G2 reviewers we cited on that listing specifically flag its audit logs as too shallow for compliance tracing — a documented weakness, not just an unstated one. The four newest exclusions each miss for a different reason: Warmly names no Enterprise plan at all; Amplemarket doesn't either; Zendesk AI Agents' Suite Enterprise + Copilot tier promises "advanced security and governance" without naming what that actually is — the same vague-promise pattern the original eight hit, not a new one; and Microsoft Fabric Data Agent, discussed above, has no standalone tier to name a control on in the first place. None of the 12 are necessarily insecure; they simply haven't published — or in Fabric Data Agent's case, don't independently own — the specifics this list requires.
Why this collection
A tool earns a place here only if its own Published, sourced listing text names a SPECIFIC enterprise security or deployment control — single sign-on (SSO/SAML/SCIM), a named compliance certification (SOC 2, HIPAA, GDPR, PCI DSS, ISO 27001, FedRAMP), role-based access control (RBAC), audit logging, or a VPC / on-premises / air-gapped deployment option. A "Contact sales" or custom-priced Enterprise tier with no control named anywhere in the listing's pricing tiers, feature list, pros/cons or sources does not qualify, even though the tier itself is real. Verified against each listing's own already-researched, gate-passed fields, not inferred from company size, funding, or a vendor's general enterprise-readiness marketing claims.
- Sierra
Bret Taylor’s enterprise agent platform, branded AI agents that resolve customer issues end to end, priced on outcomes.
Achieved FedRAMP High certification in June 2026 (with Knox Systems) — the only listing here cleared for the most sensitive US federal government workloads, on top of its existing enterprise customer base.
- Crescendo
Fully-managed AI-native customer service, replaces your entire CX stack with agents, QA and human-in-the-loop support, billed per resolution.
SOC 2 Type II, HIPAA, ISO 27001 and GDPR compliance ship out of the box — the deepest named compliance stack of any support-agent listing here.
- Bland AI
Enterprise voice AI that runs on its own infrastructure, build calls as conversational pathways, priced all-in per minute.
Enterprise deployments get dedicated infrastructure, US/EU/APAC data residency, and self-hosted or on-premises options carrying SOC 2 Type II, HIPAA and PCI DSS v4.0 compliance.
- PolyAI
The pre-LLM-era enterprise voice AI incumbent — $750M-valued, 200+ enterprise customers — that opened a genuine self-serve, free-to-start tier in May 2026.
SOC 2, HIPAA, GDPR and PCI DSS compliance ship with the platform itself, not gated behind a separate custom-only Enterprise tier.
- Vapi
The developer platform for voice AI agents, bring your own model, voice and telephony, and Vapi orchestrates the call.
The Scale tier documents SOC 2, PCI, SSO, RBAC and data residency; HIPAA and Zero Data Retention are available as metered add-ons on top.
- Retell AI
A voice AI platform for human-sounding phone agents, build a call flow, plug in your model and telephony, ship.
SOC 2 Type II, a self-serve HIPAA BAA, and GDPR compliance are named Enterprise-tier features, not just a sales promise.
- Rox
An AI-native revenue operating system, "agent swarms" (one per account) that research, monitor and update your existing CRM across the whole deal lifecycle, with a genuine free self-serve tier.
SOC 2 Type II and GDPR compliance, AES-256 encryption, and a stated policy that customer data is never used to train general-purpose models.
- Factory
Agent-native software development — specialized "Droid" agents that triage, code, test, review, document and ship changes across the SDLC, from a $20/mo CLI to a fully managed enterprise cloud.
SSO and SAML/SCIM provisioning start on the Business tier (with Zero Data Retention and audit logging); Enterprise adds on-premise/air-gapped deployment and customer-managed encryption keys.
- OpenHands
Open source AI agent platform for cloud coding agents, from free local use to enterprise self-hosted deployment.
Enterprise deployments add SSO, RBAC, audit logs and budget controls inside a customer's own VPC or a fully self-hosted environment, so code and data never leave the org.
- CodeRabbit
An AI code-review agent, not a code-writing one — reviews every pull request automatically across GitHub, GitLab, Bitbucket and Azure DevOps, with a genuine free tier for unlimited repos.
The Enterprise tier adds RBAC, SSO and audit logging on top of its already-available self-hosting and multi-org support.
- Relevance AI
Build and run an "AI workforce", teams of no-code agents that do real sales, ops and research work.
RBAC and SSO ship for running agents in production even below the top tier; Enterprise adds full audit logging and a dedicated CSM.
- Devin
Cognition’s autonomous AI software engineer, delegate a ticket, get a reviewed pull request back.
The Enterprise tier adds SSO and VPC deployment on top of Devin's usage-based ACU billing.
- Replit Agent
Describe an app and Replit Agent builds, tests and deploys it in your browser, a full-stack app factory for anyone.
The Enterprise tier adds SSO/SAML alongside custom seat counts and advanced privacy controls.
- Bolt.new
StackBlitz's prompt-to-app builder that runs a real Node.js environment inside the browser tab itself, no remote VM.
The Enterprise tier's own feature list names SSO, audit logs and compliance support directly.
- Artisan
Ava, the AI BDR, an autonomous sales agent that sources leads, runs multi-channel outbound and books meetings without a human writing each message.
The Enterprise tier's advanced security controls and audit logs sit alongside a forward-deployed strategist and full onboarding buildout.
- ElevenLabs Conversational AI
The voice-quality specialist’s own agent layer, 10,000+ voices and instant cloning, with a bring-your-own-LLM brain.
Enterprise adds SSO and a DPA/SLA on top of custom minute pools — thinner on named controls than most of the rest of this voice-agents list.
- Perplexity
The AI answer engine, with agentic Deep Research and the Comet browser that acts on the web for you.
Enterprise Pro ($34/seat/month) adds SSO plus dedicated security and data controls on top of the consumer Pro plan.
- GC AI
An AI platform for in-house legal teams whose Research Agent runs parallel, cross-checked research across 13M+ US case law opinions, statutes and regulations.
The Team tier adds Enterprise SSO alongside managed procurement and onboarding support.
- Moveworks
Enterprise AI assistant that resolves employee IT, HR and finance requests across 100+ systems — acquired outright by ServiceNow for $2.85B, closed December 2025.
The deepest compliance stack in this index — FedRAMP, SOC 2 Type II, a full ISO 27001/27017/27018/27701 spread, CSA STAR Level 2, GDPR and CCPA — built for regulated enterprise IT/HR/finance deployments.
- Glean
Enterprise "Work AI" platform — permission-aware search across 100+ systems, an AI assistant and a no-code agent builder, all grounded in one Knowledge Graph. $7.2B valuation, June 2025.
SOC 2 Type II, ISO/IEC 27001, HIPAA and GDPR compliance, plus ISO/IEC 42001:2023 — an AI-management-system certification no other listing here carries — on top of a general enterprise controls baseline.
- Undermind
An AI literature-discovery agent that reads hundreds of full papers and follows citation trails, then reports how much of the literature it actually covered.
The Enterprise tier documents sitewide organizational login (SSO) alongside a custom terms/SLA security review — a real, named control, though the thinnest stack here, with no compliance certification or audit logging named anywhere else in the listing.
- LiveKit Agents
The open-source, self-hostable voice agent framework, Apache 2.0, provider-agnostic, and the infrastructure behind ChatGPT’s Advanced Voice Mode.
RBAC and HIPAA-oriented security reporting already ship on the Scale tier; Enterprise adds SSO, volume pricing and a support SLA on top — the earliest a control appears in this list, one tier below the top.
- Cursor
The AI code editor, an agent that reads, writes and edits across your whole codebase.
The Enterprise tier documents SCIM provisioning and audit logs alongside pooled usage and priority support.
- Windsurf (now Devin Desktop)
The agentic IDE that was Codeium, then Windsurf, now Cognition’s Devin Desktop, a command centre for coding agents.
The Enterprise tier adds SSO and centralized admin controls on top of its ACU-based usage billing.
- Cline
The open-source coding agent, an autonomous, bring-your-own-key agent that lives in your editor, terminal or SDK.
The Enterprise tier adds SSO/OIDC, RBAC and a dedicated SLA, plus centrally-managed JetBrains deployment and centralized billing — on top of an otherwise fully open, Apache-2.0, bring-your-own-key core.
- Warp
The AI-native terminal that replaces your shell and orchestrates Claude Code, Codex and its own Warp Agent side by side.
SAML-based SSO ships one tier below Enterprise (Business, $50/user/month); Enterprise itself adds self-hosted cloud agents running on the customer's own infrastructure.
- CrewAI
A popular open-source Python framework for role-based, collaborating multi-agent teams, free to self-host, now a stable 1.0 release with an optional managed AMP cloud layer.
The AMP Enterprise tier adds dedicated/private infrastructure, VPC deployment and FedRAMP High on top of the open-source, self-hosted core framework.
- LlamaIndex
The data framework for LLM apps, RAG-first, now with agent workflows and a document-parsing cloud.
The Enterprise tier for LlamaCloud adds SSO, volume discounts and a dedicated account manager on top of the fully open-source core framework.
- Letta
A stateful-agent framework — open-source, memory-first agents whose context, tools and identity persist as a durable server object instead of resetting between sessions.
The Enterprise tier adds SAML/OIDC SSO and role-based access on top of volume-based pricing.
- Mastra
The TypeScript-native agent framework — agents, durable workflows, memory and observability in one Apache-2.0 package, with an optional managed cloud platform.
Ships two enterprise paths at once: a Mastra Cloud Enterprise tier with RBAC and audit logs, plus a separate Enterprise Self-Hosted tier that keeps RBAC/SSO/IAM while data stays inside the customer's own VPC — on top of an Apache-2.0 self-hosted core.
- n8n
Source-available workflow automation with native AI-agent nodes, self-hostable and integration-rich.
The Enterprise tier adds custom-volume self-hosted or cloud deployment with dedicated support and an SLA; its Cloud Business tier, one rung down, already ships SSO/SAML/LDAP.
- Lindy
An AI executive assistant you text over iMessage or SMS, built on a no-code agent platform still available underneath.
The Enterprise tier stacks SSO, SCIM, HIPAA/BAA and audit logs — one of the deepest named compliance stacks outside the voice-agents category.
- Dify
Open-source, visual platform for building production LLM apps and agents, self-host it or run it in the cloud.
The Enterprise tier adds self-hosted deployment with SSO/SAML, RBAC, audit logs and SLAs on top of its already-open Community Edition.
- Clay
GTM data platform with an AI research agent (Claygent), enrich, research and personalise outbound at scale.
The Enterprise tier names SSO and RBAC alongside warehouse syncs and a dedicated strategist.
- Elicit
An AI research agent built for scientific literature, search, screen and extract cited data from 138M+ papers.
The Enterprise tier documents SSO/SAML and an unlimited API on top of its largest systematic-review extraction limits.
- Zed
The open-source, GPU-native code editor built from scratch by Atom's creators — runs Claude Code, Codex and other agents via the open Agent Client Protocol it created. Free forever; Pro from $10/month.
The Business tier — a $30/seat self-serve plan, not a custom Enterprise quote — names role-based access control and org-wide AI model policies directly, on top of the open-source editor's free core.
- Manus
An autonomous general AI agent that plans and executes multi-step tasks end-to-end in its own cloud computer.
The Team tier names SSO alongside per-seat credit pools — a single, narrow control on an otherwise consumer-priced, credit-metered product.
- Synthflow AI
A no-code voice AI platform for enterprise phone agents — a visual Flow Designer and a structured Build-Evaluate-Launch-Learn deployment cycle, billed by the minute in separate components.
SOC 2, HIPAA, GDPR, PCI DSS and ISO 27001 are all named together as platform-wide infrastructure, not gated behind a specific tier — an unusually complete compliance set for a company still at Series A.
- Genspark
A "Super Agent" that orchestrates 9 blended LLMs and 80+ tools to research, build slides/sheets, place phone calls and browse the web from one prompt.
A custom-priced Team/Enterprise tier names SSO sign-in — a single, narrow control on an otherwise consumer-priced, credit-metered product.
- Botpress
An open-source (MIT), developer-first platform for building conversational AI agents with bi-directional MCP support — self-host free, or use the managed cloud from $0/month.
The Enterprise tier names SSO, SCIM and audit logs; role-based access control already ships one tier down on Team ($495/month).