{
  "tools": [
    {
      "slug": "alignmt-ai",
      "name": "ALIGNMT AI",
      "vendor": "ALIGNMT AI",
      "tagline": "Healthcare-focused AI governance with real-time risk monitoring and audit-ready reporting.",
      "description": "ALIGNMT AI monitors healthcare AI systems for compliance with HIPAA, CHAI transparency standards, ONC HTI-1, and the EU AI Act, automating risk flags and reporting for hospitals and payers. Raised a $6.5M seed in August 2025 led by AIX Ventures. Vendor-claimed; pending verification.",
      "website": "https://alignmt.ai",
      "categories": [
        "ai-governance"
      ],
      "tags": [
        "enterprise",
        "chai"
      ],
      "frameworks": [
        "HIPAA",
        "EU_AI_ACT"
      ],
      "lastVerified": "2026-07-19",
      "listing_status": "radar"
    },
    {
      "slug": "alinia-ai",
      "name": "Alinia AI",
      "vendor": "Alinia AI",
      "tagline": "Real-time AI compliance guardrails for regulated industries, focused on financial services.",
      "description": "Alinia AI embeds policy enforcement, real-time auditing, and risk monitoring into enterprise AI systems via a vendor-agnostic Guardrails API, working with institutions including Santander Group. Raised a $7.5M seed in December 2025 led by Mouro Capital. Vendor-claimed; pending verification.",
      "website": "https://alinia.ai",
      "categories": [
        "ai-governance"
      ],
      "tags": [
        "enterprise",
        "mifid-ii"
      ],
      "frameworks": [
        "EU_AI_ACT"
      ],
      "lastVerified": "2026-07-19",
      "listing_status": "radar"
    },
    {
      "slug": "aurascape",
      "name": "Aurascape",
      "vendor": "Aurascape",
      "tagline": "AI-traffic security that decodes AI app protocols natively, enforcing policy at the tool-call level with cross-action data lineage.",
      "description": "AI-traffic security that decodes AI app protocols natively, enforcing policy at the tool-call level with cross-action data lineage.",
      "website": "https://aurascape.ai",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "enterprise"
      ],
      "frameworks": [],
      "lastVerified": "2026-07-20",
      "listing_status": "radar"
    },
    {
      "slug": "azure-ai-content-safety",
      "name": "Azure AI Content Safety",
      "vendor": "Azure AI Content Safety",
      "tagline": "Microsoft's managed content-safety API with prompt-shield protection for Azure-hosted AI workloads.",
      "description": "Azure AI Content Safety is Microsoft's managed moderation layer for generative AI: classification of harmful content across severity levels, Prompt Shields for injection and jailbreak detection, and groundedness detection for hallucination checks. It is the path of least resistance for teams already standardized on Azure.\n\n- Prompt Shields for direct and indirect injection\n- Harm-category classification with severity scores\n- Groundedness detection against source documents\n- Regional deployments for data-residency requirements",
      "website": "https://azure.microsoft.com/en-us/products/ai-services/ai-content-safety",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "paid"
      ],
      "frameworks": [
        "SOC2",
        "ISO27001",
        "GDPR",
        "EU_AI_ACT"
      ],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "braintrust",
      "name": "Braintrust",
      "vendor": "Braintrust",
      "tagline": "Evaluation platform for LLM apps: evals, logging, and prompt experiment tracking.",
      "description": "Braintrust gives AI teams systematic evals, prompt playgrounds, and production logging to ship reliable LLM products — increasingly used as evidence for AI quality processes. Vendor-claimed; pending verification.",
      "website": "https://www.braintrust.dev",
      "categories": [
        "model-evaluation"
      ],
      "tags": [
        "paid"
      ],
      "frameworks": [],
      "lastVerified": "2026-07-19",
      "listing_status": "radar"
    },
    {
      "slug": "calypsoai",
      "name": "CalypsoAI",
      "vendor": "CalypsoAI",
      "tagline": "AI security platform for model-agnostic guardrails, red-teaming, and inference protection — part of F5 since Sep 2025.",
      "description": "CalypsoAI provides enterprise guardrails, automated red-teaming, and security scoring for GenAI deployments across model providers. Vendor-claimed; pending verification.",
      "website": "https://calypsoai.com",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "enterprise",
        "owasp-llm-top-10"
      ],
      "frameworks": [
        "NIST_AI_RMF"
      ],
      "lastVerified": "2026-07-21",
      "listing_status": "radar"
    },
    {
      "slug": "cisco-ai-defense",
      "name": "Cisco AI Defense",
      "vendor": "Cisco AI Defense",
      "tagline": "Cisco's end-to-end AI security: asset discovery, model testing, and runtime guardrails covering prompts, responses, and MCP traffic.",
      "description": "Cisco's end-to-end AI security: asset discovery, model testing, and runtime guardrails covering prompts, responses, and MCP traffic.",
      "website": "https://www.cisco.com/site/us/en/products/security/ai-defense/index.html",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "enterprise"
      ],
      "frameworks": [],
      "lastVerified": "2026-07-20",
      "listing_status": "radar"
    },
    {
      "slug": "comp-ai",
      "name": "Comp AI",
      "vendor": "Comp AI",
      "tagline": "Open-source compliance automation (AGPLv3) for SOC 2, ISO 27001, HIPAA, and GDPR — a self-hostable Vanta alternative.",
      "description": "Comp AI automates evidence collection, policy management, and monitoring with AI agents; ~99% of the codebase is open source and self-hostable, with a managed cloud tier. Launched from stealth on Product Hunt in April 2025; $2.6M pre-seed led by OSS Capital. Vendor-claimed; pending verification.",
      "website": "https://trycomp.ai",
      "categories": [
        "ai-governance"
      ],
      "tags": [
        "open-source"
      ],
      "frameworks": [
        "SOC2",
        "ISO27001",
        "HIPAA",
        "GDPR"
      ],
      "lastVerified": "2026-07-19",
      "listing_status": "radar"
    },
    {
      "slug": "conductorone",
      "name": "ConductorOne",
      "vendor": "ConductorOne",
      "tagline": "AI-native identity security and governance for human, non-human, and AI agent identities — access reviews, least-privilege automation, and agent access control at enterprise scale.",
      "description": "AI-native identity security and governance for human, non-human, and AI agent identities — access reviews, least-privilege automation, and agent access control at enterprise scale.",
      "website": "https://www.conductorone.com",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "enterprise"
      ],
      "frameworks": [],
      "lastVerified": "2026-07-22",
      "listing_status": "radar"
    },
    {
      "slug": "coval",
      "name": "Coval",
      "vendor": "Coval",
      "tagline": "Simulation and evaluation platform for AI voice and chat agents (YC-backed; $28M Series A, Jun 2026): pre-launch stress testing plus production monitoring, built by Waymo eval alumni.",
      "description": "Simulation and evaluation platform for AI voice and chat agents (YC-backed; $28M Series A, Jun 2026): pre-launch stress testing plus production monitoring, built by Waymo eval alumni.",
      "website": "https://www.coval.dev",
      "categories": [
        "model-evaluation"
      ],
      "tags": [
        "enterprise"
      ],
      "frameworks": [],
      "lastVerified": "2026-07-22",
      "listing_status": "radar"
    },
    {
      "slug": "credal",
      "name": "Credal",
      "vendor": "Credal",
      "tagline": "Secure enterprise AI platform with data permissions, DLP, and audit logging built in.",
      "description": "Credal lets enterprises build AI assistants and agents on internal data with permission-aware access, DLP controls, and full audit logs. Vendor-claimed; pending verification.",
      "website": "https://www.credal.ai",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "enterprise"
      ],
      "frameworks": [
        "SOC2"
      ],
      "lastVerified": "2026-07-19",
      "listing_status": "radar"
    },
    {
      "slug": "credo-ai",
      "name": "Credo AI",
      "vendor": "Credo AI",
      "tagline": "AI governance platform for model registries, risk assessments, and EU AI Act conformity.",
      "description": "Credo AI gives compliance and ML teams a shared system of record for AI use cases. Model and vendor inventories, risk scoring, policy packs (EU AI Act, NIST AI RMF, ISO/IEC 42001, NYC LL 144), and conformity workflows produce reviewer-ready evidence. Integrates with MLflow, Databricks, SageMaker, and Vertex AI to pull model metadata automatically.",
      "website": "https://www.credo.ai",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "enterprise",
        "iso-iec-42001",
        "nyc-local-law-144"
      ],
      "frameworks": [
        "SOC2",
        "ISO27001",
        "EU_AI_ACT",
        "NIST_AI_RMF"
      ],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "csa-ai-controls-matrix",
      "name": "CSA AI Controls Matrix",
      "vendor": "CSA AI Controls Matrix",
      "tagline": "Cloud Security Alliance's AI Controls Matrix v1.0.1 (Jul 2025): 243 controls across 18 domains with a five-role shared-responsibility model, crosswalked to NIST AI 600-1.",
      "description": "Cloud Security Alliance's AI Controls Matrix v1.0.1 (Jul 2025): 243 controls across 18 domains with a five-role shared-responsibility model, crosswalked to NIST AI 600-1.",
      "website": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix",
      "categories": [
        "policy-management"
      ],
      "tags": [
        "free"
      ],
      "frameworks": [
        "NIST_AI_RMF"
      ],
      "lastVerified": "2026-07-21",
      "listing_status": "verified"
    },
    {
      "slug": "deepeval",
      "name": "DeepEval",
      "vendor": "DeepEval",
      "tagline": "Open-source LLM evaluation framework with pytest-style unit testing for AI applications.",
      "description": "DeepEval brings unit testing discipline to LLM outputs: research-backed metrics (G-Eval, hallucination, answer relevancy, RAG faithfulness) exposed as pytest-style assertions that run locally or in CI. It has become the default open-source harness for teams that want regression gates on model quality.\n\n- 30+ research-backed evaluation metrics\n- Pytest integration for CI/CD gates\n- RAG-specific metrics (faithfulness, contextual recall)\n- Synthetic dataset generation",
      "website": "https://docs.confident-ai.com",
      "categories": [
        "model-evaluation"
      ],
      "tags": [
        "open-source",
        "github"
      ],
      "frameworks": [],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "deepteam",
      "name": "DeepTeam",
      "vendor": "DeepTeam",
      "tagline": "Open-source LLM red-teaming framework with 40+ vulnerability scans and attack methods.",
      "description": "DeepTeam, from the makers of DeepEval, packages LLM red teaming into a developer-friendly framework: declare vulnerabilities to test (bias, PII leakage, injection, unauthorized access), pick attack enhancements, and run automated campaigns against your app with pass/fail results suitable for CI gates.\n\n- 40+ built-in vulnerability types\n- Attack enhancements (encoding, roleplay, multi-turn)\n- Pytest-style integration for CI/CD\n- OWASP LLM Top 10 aligned reporting",
      "website": "https://github.com/confident-ai/deepteam",
      "categories": [
        "red-teaming"
      ],
      "tags": [
        "open-source",
        "github",
        "owasp-llm-top-10"
      ],
      "frameworks": [],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "dynamo-ai",
      "name": "Dynamo AI",
      "vendor": "Dynamo AI",
      "tagline": "Compliance-focused AI evaluation, guardrails, and privacy testing for regulated industries.",
      "description": "Dynamo AI offers evaluation suites, guardrails, and privacy attack testing designed for banks and regulated enterprises deploying LLMs. Vendor-claimed; pending verification.",
      "website": "https://dynamo.ai",
      "categories": [
        "ai-governance"
      ],
      "tags": [
        "enterprise"
      ],
      "frameworks": [
        "EU_AI_ACT",
        "NIST_AI_RMF"
      ],
      "lastVerified": "2026-07-19",
      "listing_status": "radar"
    },
    {
      "slug": "enkrypt-ai",
      "name": "Enkrypt AI",
      "vendor": "Enkrypt AI",
      "tagline": "AI red-teaming and guardrails platform with compliance-mapped risk scoring for LLMs.",
      "description": "Enkrypt AI combines automated red-teaming, guardrails, and risk scoring mapped to frameworks like NIST AI RMF and the EU AI Act. Vendor-claimed; pending verification.",
      "website": "https://www.enkryptai.com",
      "categories": [
        "red-teaming"
      ],
      "tags": [
        "paid",
        "owasp-llm-top-10"
      ],
      "frameworks": [
        "EU_AI_ACT",
        "NIST_AI_RMF"
      ],
      "lastVerified": "2026-07-19",
      "listing_status": "radar"
    },
    {
      "slug": "eu-gpai-code-of-practice",
      "name": "EU GPAI Code of Practice",
      "vendor": "EU GPAI Code of Practice",
      "tagline": "The EU's Code of Practice for general-purpose AI models (Jul 2025): transparency, copyright, and safety & security chapters that operationalize AI Act Chapter V obligations.",
      "description": "The EU's Code of Practice for general-purpose AI models (Jul 2025): transparency, copyright, and safety & security chapters that operationalize AI Act Chapter V obligations.",
      "website": "https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai",
      "categories": [
        "policy-management"
      ],
      "tags": [
        "free"
      ],
      "frameworks": [
        "EU_AI_ACT"
      ],
      "lastVerified": "2026-07-21",
      "listing_status": "verified"
    },
    {
      "slug": "fairly-trained",
      "name": "Fairly Trained",
      "vendor": "Fairly Trained",
      "tagline": "Independent certification that a generative model was trained on licensed or public-domain data.",
      "description": "Fairly Trained issues the Licensed Model (L) certification to generative AI providers that can demonstrate their training data was licensed, public-domain, or otherwise consented to. The certification is increasingly cited by enterprise procurement teams who need defensible answers on copyright provenance, and complements vendor indemnification programs from Microsoft, Adobe, and Anthropic.",
      "website": "https://www.fairlytrained.org",
      "categories": [
        "policy-management"
      ],
      "tags": [
        "paid",
        "independent-audit",
        "us-copyright-office-guidance"
      ],
      "frameworks": [
        "EU_AI_ACT"
      ],
      "lastVerified": "2026-06-17",
      "listing_status": "verified"
    },
    {
      "slug": "fairnow",
      "name": "FairNow",
      "vendor": "FairNow",
      "tagline": "AI governance software for compliance tracking, bias audits, and risk management across jurisdictions.",
      "description": "FairNow focuses on making AI compliance tractable for mid-market and enterprise teams: a centralized AI registry, jurisdiction-aware compliance mappings (EU AI Act, Colorado SB 205, NYC LL 144), and automated bias testing workflows, with an emphasis on HR and talent AI use cases where regulation bites first.\n\n- Jurisdiction-aware regulatory mappings\n- Automated bias audit workflows\n- AI vendor risk assessments\n- Registry with risk tiering per use case",
      "website": "https://fairnow.ai",
      "categories": [
        "ai-governance"
      ],
      "tags": [
        "paid"
      ],
      "frameworks": [
        "SOC2",
        "EU_AI_ACT",
        "NIST_AI_RMF"
      ],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "garak",
      "name": "Garak",
      "vendor": "Garak",
      "tagline": "NVIDIA's open-source LLM vulnerability scanner with a modular probe library for injection, jailbreaks, and leakage.",
      "description": "Garak is the nmap of LLM security: a command-line scanner that fires a modular library of probes — prompt injection, jailbreak patterns, encoding attacks, data leakage, toxicity elicitation — at any target model or endpoint and reports which ones landed. Maintained by NVIDIA, it supports local and hosted models and runs in CI with modest setup.\n\n- Modular probe and detector architecture\n- Coverage for OWASP LLM Top 10 attack classes\n- Works against local models and hosted APIs\n- Report generation for tracking regressions",
      "website": "https://github.com/NVIDIA/garak",
      "categories": [
        "red-teaming"
      ],
      "tags": [
        "open-source",
        "github",
        "owasp-llm-top-10",
        "mitre-atlas"
      ],
      "frameworks": [],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "giskard",
      "name": "Giskard",
      "vendor": "Giskard",
      "tagline": "Open-source testing framework that scans ML models and LLM apps for vulnerabilities and quality issues.",
      "description": "Giskard scans LLM applications for hallucination, harmful generation, injection susceptibility, and bias, producing structured test suites from detected issues. Backed by European research funding, it aligns its checks with EU AI Act expectations, which makes it popular with teams preparing for conformity assessments.\n\n- Automated vulnerability scanning for LLM apps\n- Test suite generation from findings\n- RAG evaluation toolkit\n- EU AI Act aligned quality checks",
      "website": "https://www.giskard.ai",
      "categories": [
        "model-evaluation"
      ],
      "tags": [
        "open-source",
        "github",
        "owasp-llm-top-10"
      ],
      "frameworks": [
        "EU_AI_ACT"
      ],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "guardrails-ai",
      "name": "Guardrails AI",
      "vendor": "Guardrails AI",
      "tagline": "Open-source framework for validating and structuring LLM outputs with composable validators.",
      "description": "Guardrails AI validates LLM outputs against declared schemas and quality checks. Its hub of composable validators covers PII, toxicity, hallucination heuristics, and format enforcement, making it the default choice when an LLM must return reliable structured data such as forms, API payloads, or reports.\n\n- Validator hub with dozens of community checks\n- Pydantic-style structured output enforcement\n- Streaming validation support\n- Re-ask and self-correction loops on failure",
      "website": "https://www.guardrailsai.com",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "open-source",
        "github",
        "owasp-llm-top-10"
      ],
      "frameworks": [],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "hiddenlayer",
      "name": "HiddenLayer",
      "vendor": "HiddenLayer",
      "tagline": "Enterprise platform for ML model security: scanning, detection, and response for AI assets.",
      "description": "HiddenLayer secures the machine-learning supply chain itself: scanning model artifacts for embedded malware and backdoors, detecting adversarial attacks against deployed models, and providing MLDR (machine learning detection and response) for enterprise AI estates — model-level security that complements prompt-level guardrails.\n\n- Model artifact scanning for tampering and malware\n- Adversarial attack detection at inference time\n- AI asset discovery and inventory\n- Integrations with enterprise SOC workflows",
      "website": "https://hiddenlayer.com",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "enterprise",
        "mitre-atlas"
      ],
      "frameworks": [
        "SOC2",
        "NIST_AI_RMF"
      ],
      "lastVerified": "2026-07-20",
      "listing_status": "verified"
    },
    {
      "slug": "holistic-ai",
      "name": "Holistic AI",
      "vendor": "Holistic AI",
      "tagline": "AI governance platform for auditing, risk management, and regulatory compliance tracking.",
      "description": "Holistic AI provides an enterprise governance command center: AI system inventory, risk assessments, bias audits, and continuous conformity tracking against the EU AI Act, NYC Local Law 144, and emerging state regulations. It grew out of algorithmic auditing practice, which shows in its assessment depth.\n\n- AI inventory and third-party risk tracking\n- Bias and efficacy audits\n- EU AI Act readiness and conformity workflows\n- Policy packs for emerging regulations",
      "website": "https://www.holisticai.com",
      "categories": [
        "ai-governance"
      ],
      "tags": [
        "enterprise",
        "iso-42001"
      ],
      "frameworks": [
        "SOC2",
        "EU_AI_ACT",
        "NIST_AI_RMF"
      ],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "ibm-watsonx-governance",
      "name": "IBM watsonx.governance",
      "vendor": "IBM watsonx.governance",
      "tagline": "IBM's enterprise AI governance platform for lifecycle monitoring, risk management, and regulatory compliance.",
      "description": "watsonx.governance is IBM's answer to enterprise AI oversight: automated model documentation, drift and bias monitoring, and compliance workflows that map AI systems to the EU AI Act, NIST AI RMF, and internal policy. Its strength is incumbency — it plugs into the IBM data and AI stack that many regulated enterprises already run.\n\n- Automated model cards and factsheets\n- Bias, drift, and quality monitoring in production\n- Regulatory mapping for EU AI Act obligations\n- Works with non-IBM models and clouds",
      "website": "https://www.ibm.com/products/watsonx-governance",
      "categories": [
        "ai-governance"
      ],
      "tags": [
        "enterprise",
        "iso-42001"
      ],
      "frameworks": [
        "SOC2",
        "ISO27001",
        "EU_AI_ACT",
        "NIST_AI_RMF"
      ],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "iso-iec-42001",
      "name": "ISO/IEC 42001",
      "vendor": "ISO/IEC 42001",
      "tagline": "The first certifiable international standard for AI management systems (AIMS).",
      "description": "ISO/IEC 42001 defines the requirements for an AI management system — the AI analogue of ISO 27001. It is the only certifiable AI governance standard, covering risk assessment, impact assessment, lifecycle controls, and continuous improvement. Certification is increasingly appearing in enterprise RFPs as a table-stakes requirement, and published crosswalks map it onto EU AI Act obligations.\n\n- Certifiable AIMS requirements standard\n- Clause 8 risk and impact assessment processes\n- Crosswalks to EU AI Act and NIST AI RMF\n- Audited by accredited certification bodies",
      "website": "https://www.iso.org/standard/42001",
      "categories": [
        "policy-management"
      ],
      "tags": [
        "paid",
        "iso-42001"
      ],
      "frameworks": [
        "EU_AI_ACT"
      ],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "keycard",
      "name": "Keycard",
      "vendor": "Keycard",
      "tagline": "Identity and access management for AI agents (a16z-backed, $38M): ephemeral task-scoped tokens replace static keys, with delegation chains, policy enforcement, and MCP/OAuth 2.1 standards support.",
      "description": "Identity and access management for AI agents (a16z-backed, $38M): ephemeral task-scoped tokens replace static keys, with delegation chains, policy enforcement, and MCP/OAuth 2.1 standards support.",
      "website": "https://keycard.ai",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "enterprise"
      ],
      "frameworks": [],
      "lastVerified": "2026-07-22",
      "listing_status": "radar"
    },
    {
      "slug": "lakera-guard",
      "name": "Lakera Guard",
      "vendor": "Lakera Guard",
      "tagline": "Runtime LLM firewall for prompt injection, jailbreaks, and data leakage — now part of Check Point.",
      "description": "Lakera Guard is a low-latency security layer for GenAI applications. It inspects every prompt and model response for prompt injection, jailbreak attempts, toxic content, and unintended PII or secret disclosure, and returns a deterministic block/allow decision. Detectors are continuously updated from Lakera's Gandalf-driven attack dataset (now over 100M adversarial samples). Deployable as a hosted API or in-VPC, with full audit logs for compliance reviews.",
      "website": "https://www.lakera.ai",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "paid",
        "owasp-llm-top-10"
      ],
      "frameworks": [
        "SOC2",
        "ISO27001",
        "GDPR",
        "EU_AI_ACT",
        "NIST_AI_RMF"
      ],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "langfuse",
      "name": "Langfuse",
      "vendor": "Langfuse",
      "tagline": "Open-source LLM engineering platform (YC W23, MIT license): tracing, LLM-as-judge evals, prompt management, and datasets — the most widely adopted OSS option; part of ClickHouse since Jan 2026.",
      "description": "Open-source LLM engineering platform (YC W23, MIT license): tracing, LLM-as-judge evals, prompt management, and datasets — the most widely adopted OSS option; part of ClickHouse since Jan 2026.",
      "website": "https://langfuse.com",
      "categories": [
        "model-evaluation"
      ],
      "tags": [
        "open-source",
        "github"
      ],
      "frameworks": [],
      "lastVerified": "2026-07-22",
      "listing_status": "radar"
    },
    {
      "slug": "lasso-security",
      "name": "Lasso Security",
      "vendor": "Lasso Security",
      "tagline": "LLM-focused security monitoring for shadow AI, data leakage, and prompt-level threats.",
      "description": "Lasso Security monitors employee and application LLM usage, detecting data leakage, shadow AI, and prompt-based attacks in real time. Vendor-claimed; pending verification.",
      "website": "https://www.lasso.security",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "enterprise",
        "owasp-llm-top-10"
      ],
      "frameworks": [],
      "lastVerified": "2026-07-19",
      "listing_status": "radar"
    },
    {
      "slug": "llm-guard",
      "name": "LLM Guard",
      "vendor": "LLM Guard",
      "tagline": "Archived open-source toolkit of 35+ input/output scanners. Read-only since Jul 2026 after Palo Alto Networks folded Protect AI into Prisma AIRS.",
      "description": "LLM Guard, maintained under Protect AI (now part of Palo Alto Networks), chains security scanners as middleware around any LLM call. With more than 35 scanners spanning PII, secrets, toxicity, bias, and code detection, it offers the broadest open-source scanning coverage available, with full data control since everything runs in your infrastructure.\n\n- 35+ chainable input and output scanners\n- Secrets and PII detection with redaction\n- Prompt-injection and jailbreak heuristics\n- Self-hosted; no data leaves your environment",
      "website": "https://protectai.com/llm-guard",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "open-source",
        "github",
        "owasp-llm-top-10"
      ],
      "frameworks": [
        "GDPR"
      ],
      "lastVerified": "2026-07-20",
      "listing_status": "verified"
    },
    {
      "slug": "presidio",
      "name": "Microsoft Presidio",
      "vendor": "Microsoft Presidio",
      "tagline": "Microsoft's open-source SDK for detecting and anonymizing PII in text, images, and structured data.",
      "description": "Presidio is the open-source workhorse of PII detection: an analyzer that combines named-entity recognition, regex patterns, and checksum validation, plus an anonymizer supporting redaction, masking, hashing, and encryption. It is the default building block for self-hosted PII pipelines in LLM applications — wired before context assembly, after tool calls, and on retrieved RAG chunks.\n\n- NER + regex + checksum hybrid detection\n- Redact, mask, hash, or encrypt operators\n- Image and DICOM redaction support\n- Custom recognizers for domain-specific IDs\n- Fully self-hosted, no data egress",
      "website": "https://microsoft.github.io/presidio/",
      "categories": [
        "pii-detection",
        "data-privacy"
      ],
      "tags": [
        "open-source",
        "github"
      ],
      "frameworks": [
        "HIPAA",
        "GDPR",
        "EU_AI_ACT"
      ],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "mindgard",
      "name": "Mindgard",
      "vendor": "Mindgard",
      "tagline": "Continuous automated red teaming and security testing for AI systems.",
      "description": "Mindgard, a University of Lancaster spin-out, provides continuous automated red teaming (CART) for AI: scheduled adversarial testing of deployed models and applications, mapped to MITRE ATLAS and OWASP taxonomies, so security teams get an ongoing view of AI attack surface rather than a point-in-time pentest.\n\n- Continuous scheduled adversarial testing\n- MITRE ATLAS and OWASP mapped findings\n- Coverage for LLMs, image, and audio models\n- Integrates with existing vulnerability management",
      "website": "https://mindgard.ai",
      "categories": [
        "red-teaming"
      ],
      "tags": [
        "enterprise",
        "mitre-atlas"
      ],
      "frameworks": [
        "SOC2",
        "NIST_AI_RMF"
      ],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "mitre-atlas",
      "name": "MITRE ATLAS",
      "vendor": "MITRE ATLAS",
      "tagline": "Knowledge base of adversarial tactics and techniques against AI systems, modeled on ATT&CK.",
      "description": "MITRE ATLAS (Adversarial Threat Landscape for AI Systems) catalogs real-world attack tactics and techniques against machine learning — the AI counterpart to ATT&CK. Security teams use it to structure AI threat models, and red-teaming tools like Garak, PyRIT, and Mindgard map their findings to ATLAS technique IDs.\n\n- Tactics and techniques matrix for AI attacks\n- Real-world case studies of AI incidents\n- Mitigations catalog\n- Free and community-maintained",
      "website": "https://atlas.mitre.org",
      "categories": [
        "policy-management"
      ],
      "tags": [
        "free",
        "mitre-atlas"
      ],
      "frameworks": [],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "modulos",
      "name": "Modulos",
      "vendor": "Modulos",
      "tagline": "ETH Zurich spin-out; first AI governance platform with ISO/IEC 42001 product conformity certification.",
      "description": "Modulos operationalizes EU AI Act and ISO/IEC 42001 compliance with quantitative risk management workflows. It reports being the first AI governance platform to achieve ISO/IEC 42001 product-conformity certification, and serves regulated European enterprises across finance, defense, and critical infrastructure.\n\n- ISO/IEC 42001-aligned AI management system workflows\n- Quantitative risk scoring and treatment\n- EU AI Act obligation mapping per system\n- Audit-ready evidence generation",
      "website": "https://www.modulos.ai",
      "categories": [
        "ai-governance"
      ],
      "tags": [
        "enterprise",
        "iso-42001"
      ],
      "frameworks": [
        "SOC2",
        "EU_AI_ACT",
        "NIST_AI_RMF"
      ],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "nemo-guardrails",
      "name": "NeMo Guardrails",
      "vendor": "NeMo Guardrails",
      "tagline": "NVIDIA's open-source toolkit for programmable conversational rails and safety policies inside LLM applications.",
      "description": "NeMo Guardrails is NVIDIA's Apache 2.0 toolkit for adding programmable safety rails to LLM applications. Policies are written in Colang, a domain-specific language that defines topical boundaries, dialog flows, and safety checks across five pipeline stages, with bidirectional screening of both inputs and outputs.\n\n- Colang DSL for declarative rail definitions\n- Jailbreak detection and content-safety checks\n- Native LangChain, LangGraph, and LlamaIndex integrations\n- Custom Python actions for arbitrary validation logic\n- Vendor-neutral: works with local and hosted models",
      "website": "https://github.com/NVIDIA/NeMo-Guardrails",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "open-source",
        "github",
        "owasp-llm-top-10"
      ],
      "frameworks": [
        "NIST_AI_RMF"
      ],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "nexos-ai",
      "name": "nexos.ai",
      "vendor": "nexos.ai",
      "tagline": "AI workspace and gateway giving enterprises governed access to 200+ models with guardrails.",
      "description": "Founded by the Nord Security founders, nexos.ai acts as a secure layer between employees and AI models — an AI Workspace plus AI Gateway with visibility, access controls, and cost governance to fight shadow AI. Raised a EUR 30M Series A in October 2025. Vendor-claimed; pending verification.",
      "website": "https://nexos.ai",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "enterprise"
      ],
      "frameworks": [
        "GDPR",
        "EU_AI_ACT"
      ],
      "lastVerified": "2026-07-19",
      "listing_status": "radar"
    },
    {
      "slug": "nightfall-ai",
      "name": "Nightfall AI",
      "vendor": "Nightfall AI",
      "tagline": "AI-native data loss prevention that detects sensitive data across SaaS apps and LLM traffic.",
      "description": "Nightfall applies machine-learning detectors to data loss prevention: scanning SaaS applications, logs, and AI pipelines for credentials, PHI, and PII with higher precision than regex-only DLP. Its API mode inserts detection into LLM request paths, though sovereignty-sensitive teams should note detection runs in Nightfall's cloud.\n\n- ML-based detectors for PII, PHI, secrets\n- SaaS integrations (Slack, GitHub, Jira, and more)\n- API for scanning LLM prompts and outputs\n- Automated remediation workflows",
      "website": "https://www.nightfall.ai",
      "categories": [
        "pii-detection",
        "data-privacy"
      ],
      "tags": [
        "paid"
      ],
      "frameworks": [
        "SOC2",
        "HIPAA",
        "GDPR",
        "PCI_DSS"
      ],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "nist-ai-600-1",
      "name": "NIST AI 600-1 (Generative AI Profile)",
      "vendor": "NIST AI 600-1 (Generative AI Profile)",
      "tagline": "NIST's Generative AI Profile (Jul 2024): 12 GenAI risk categories with 200+ suggested actions, layered on the AI RMF's govern/map/measure/manage functions.",
      "description": "NIST's Generative AI Profile (Jul 2024): 12 GenAI risk categories with 200+ suggested actions, layered on the AI RMF's govern/map/measure/manage functions.",
      "website": "https://doi.org/10.6028/NIST.AI.600-1",
      "categories": [
        "policy-management"
      ],
      "tags": [
        "free"
      ],
      "frameworks": [
        "NIST_AI_RMF"
      ],
      "lastVerified": "2026-07-21",
      "listing_status": "verified"
    },
    {
      "slug": "nist-ai-rmf",
      "name": "NIST AI RMF",
      "vendor": "NIST AI RMF",
      "tagline": "The US reference framework for AI risk management: Govern, Map, Measure, Manage.",
      "description": "The NIST AI Risk Management Framework (AI RMF 1.0) is the de facto US governance standard, organizing AI risk work into four functions — Govern, Map, Measure, Manage — with a companion Playbook and a Generative AI Profile. It is voluntary but increasingly cited in procurement, enterprise policy, and US federal guidance, and most governance platforms map controls to it.\n\n- Four-function risk structure with subcategories\n- Generative AI Profile for LLM-specific risks\n- Crosswalks to ISO 42001 and EU AI Act\n- Free and publicly available",
      "website": "https://www.nist.gov/itl/ai-risk-management-framework",
      "categories": [
        "policy-management"
      ],
      "tags": [
        "free"
      ],
      "frameworks": [
        "NIST_AI_RMF"
      ],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "noma-security",
      "name": "Noma Security",
      "vendor": "Noma Security",
      "tagline": "Platform securing the AI lifecycle: supply chain, posture, and runtime threat detection.",
      "description": "Noma Security covers the data and AI supply chain — model scanning, AI posture management, and runtime protection for enterprise AI pipelines. Vendor-claimed; pending verification.",
      "website": "https://noma.security",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "enterprise",
        "mitre-atlas"
      ],
      "frameworks": [
        "NIST_AI_RMF"
      ],
      "lastVerified": "2026-07-19",
      "listing_status": "radar"
    },
    {
      "slug": "norm-ai",
      "name": "Norm Ai",
      "vendor": "Norm Ai",
      "tagline": "Regulatory AI agents that convert regulations into computer code for automated compliance checks.",
      "description": "Norm Ai builds AI agents that transform regulatory requirements into executable compliance logic, used by financial institutions and enterprises for automated regulatory analysis. Vendor-claimed; pending verification.",
      "website": "https://www.norm.ai",
      "categories": [
        "ai-governance"
      ],
      "tags": [
        "enterprise",
        "sec",
        "finra"
      ],
      "frameworks": [],
      "lastVerified": "2026-07-19",
      "listing_status": "radar"
    },
    {
      "slug": "oneleet",
      "name": "Oneleet",
      "vendor": "Oneleet",
      "tagline": "Security-first compliance platform: pentesting, code scanning, and SOC 2 / ISO 27001 automation in one.",
      "description": "Oneleet, built by career penetration testers, positions compliance as the byproduct of real security — bundling pentests, attack-surface monitoring, and evidence automation for SOC 2, ISO 27001, HIPAA, and GDPR. Raised a $33M Series A in October 2025 at $9M ARR. Vendor-claimed; pending verification.",
      "website": "https://www.oneleet.com",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "paid"
      ],
      "frameworks": [
        "SOC2",
        "ISO27001",
        "HIPAA",
        "GDPR"
      ],
      "lastVerified": "2026-07-19",
      "listing_status": "radar"
    },
    {
      "slug": "onetrust-ai-governance",
      "name": "OneTrust AI Governance",
      "vendor": "OneTrust AI Governance",
      "tagline": "AI governance module of the OneTrust trust intelligence platform.",
      "description": "OneTrust extends its privacy and GRC platform into AI governance: AI use-case intake, risk classification under the EU AI Act, vendor AI assessments, and evidence collection — attractive for the thousands of enterprises that already run privacy programs on OneTrust and want AI oversight in the same system of record.\n\n- AI intake and use-case registry\n- EU AI Act risk classification workflows\n- Vendor and third-party AI assessments\n- Ties into existing OneTrust privacy records",
      "website": "https://www.onetrust.com/products/ai-governance/",
      "categories": [
        "ai-governance"
      ],
      "tags": [
        "enterprise"
      ],
      "frameworks": [
        "SOC2",
        "ISO27001",
        "GDPR",
        "EU_AI_ACT",
        "NIST_AI_RMF"
      ],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "owasp-agentic-ai-security",
      "name": "OWASP Agentic AI Security & Governance",
      "vendor": "OWASP Agentic AI Security & Governance",
      "tagline": "OWASP's State of Agentic AI Security and Governance 2.0 (2026): frameworks and controls for securing autonomous agents, including the Top 10 for Agentic Applications.",
      "description": "OWASP's State of Agentic AI Security and Governance 2.0 (2026): frameworks and controls for securing autonomous agents, including the Top 10 for Agentic Applications.",
      "website": "https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/",
      "categories": [
        "policy-management"
      ],
      "tags": [
        "free",
        "owasp-llm-top-10"
      ],
      "frameworks": [],
      "lastVerified": "2026-07-21",
      "listing_status": "verified"
    },
    {
      "slug": "owasp-llm-top-10",
      "name": "OWASP LLM Top 10",
      "vendor": "OWASP LLM Top 10",
      "tagline": "Community-maintained checklist of the ten most critical risks for LLM applications.",
      "description": "The OWASP Top 10 for LLM Applications is the de-facto threat checklist for AI/ML engineers shipping GenAI features. The 2025 edition covers prompt injection, sensitive information disclosure, supply-chain risks, data and model poisoning, improper output handling, excessive agency, system-prompt leakage, vector and embedding weaknesses, misinformation, and unbounded consumption. Free, vendor-neutral, and widely referenced by NIST, the EU AI Office, and enterprise security programs.",
      "website": "https://genai.owasp.org/llm-top-10/",
      "categories": [
        "policy-management"
      ],
      "tags": [
        "free",
        "github",
        "open-standard",
        "owasp-llm-top-10",
        "mitre-atlas"
      ],
      "frameworks": [
        "NIST_AI_RMF"
      ],
      "lastVerified": "2026-06-17",
      "listing_status": "verified"
    },
    {
      "slug": "patronus-ai",
      "name": "Patronus AI",
      "vendor": "Patronus AI",
      "tagline": "Automated evaluation and guardrails platform for scoring and monitoring LLM system failures.",
      "description": "Patronus AI provides managed evaluation infrastructure: proprietary scoring models like Lynx for hallucination detection, the Glider judge model, and continuous monitoring that catches failures in production. It sits at the commercial end of the eval spectrum where teams pay for evaluator quality rather than building their own.\n\n- Lynx hallucination detection model\n- Custom evaluator training\n- Production monitoring and alerting\n- Benchmark suites (FinanceBench and others)",
      "website": "https://www.patronus.ai",
      "categories": [
        "model-evaluation"
      ],
      "tags": [
        "paid"
      ],
      "frameworks": [
        "SOC2",
        "NIST_AI_RMF"
      ],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "pillar-security",
      "name": "Pillar Security",
      "vendor": "Pillar Security",
      "tagline": "Security platform covering the AI lifecycle from posture management to runtime guardrails.",
      "description": "Pillar Security offers AI asset discovery, posture management, red-teaming, and adaptive runtime guardrails for enterprise AI applications. Vendor-claimed; pending verification.",
      "website": "https://www.pillar.security",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "enterprise",
        "owasp-llm-top-10",
        "mitre-atlas"
      ],
      "frameworks": [],
      "lastVerified": "2026-07-19",
      "listing_status": "radar"
    },
    {
      "slug": "prisma-airs",
      "name": "Prisma AIRS",
      "vendor": "Prisma AIRS",
      "tagline": "Palo Alto Networks' end-to-end AI security platform: runtime firewall, model scanning, AI red teaming, and agent security (v3.0, Mar 2026) — where Protect AI and LLM Guard's lineage landed after the 2025 acquisition.",
      "description": "Palo Alto Networks' end-to-end AI security platform: runtime firewall, model scanning, AI red teaming, and agent security (v3.0, Mar 2026) — where Protect AI and LLM Guard's lineage landed after the 2025 acquisition.",
      "website": "https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "enterprise"
      ],
      "frameworks": [],
      "lastVerified": "2026-07-21",
      "listing_status": "radar"
    },
    {
      "slug": "private-ai",
      "name": "Private AI",
      "vendor": "Private AI",
      "tagline": "On-prem PII, PHI, and PCI detection and redaction across 50+ languages and unstructured formats.",
      "description": "Private AI provides container-deployable models that identify and de-identify over 50 entity types — names, addresses, MRNs, payment data, IPs — in text, PDFs, images, audio, and transcripts. Because everything runs inside the customer environment, sensitive data never leaves the network, making it a common building block for HIPAA-regulated and EU healthcare deployments. REST and gRPC APIs integrate with LLM pre-processors, data warehouses, and DLP pipelines.",
      "website": "https://www.private-ai.com",
      "categories": [
        "pii-detection",
        "data-privacy"
      ],
      "tags": [
        "enterprise",
        "ccpa",
        "nist-privacy-framework",
        "iso-iec-27701"
      ],
      "frameworks": [
        "SOC2",
        "HIPAA",
        "GDPR"
      ],
      "lastVerified": "2026-06-17",
      "listing_status": "verified"
    },
    {
      "slug": "prompt-security",
      "name": "Prompt Security",
      "vendor": "Prompt Security",
      "tagline": "Real-time GenAI security for employee and agent AI use, with an MCP gateway — part of SentinelOne since Sep 2025.",
      "description": "Real-time GenAI security for employee and agent AI use, with an MCP gateway — part of SentinelOne since Sep 2025.",
      "website": "https://prompt.security",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "enterprise"
      ],
      "frameworks": [],
      "lastVerified": "2026-07-20",
      "listing_status": "radar"
    },
    {
      "slug": "promptarmor",
      "name": "PromptArmor",
      "vendor": "PromptArmor",
      "tagline": "LLM application security (YC W24): real-time threat detection for prompt injection, data exfiltration, and agent manipulation, plus AI vendor risk assessments.",
      "description": "LLM application security (YC W24): real-time threat detection for prompt injection, data exfiltration, and agent manipulation, plus AI vendor risk assessments.",
      "website": "https://promptarmor.com",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "enterprise"
      ],
      "frameworks": [],
      "lastVerified": "2026-07-22",
      "listing_status": "radar"
    },
    {
      "slug": "promptfoo",
      "name": "Promptfoo",
      "vendor": "Promptfoo",
      "tagline": "CLI and library for systematic LLM testing, red-teaming, and eval-driven development — acquired by OpenAI in 2026.",
      "description": "Promptfoo is a developer-first tool for testing prompts, models, and agents against quality, safety, and security assertions. It ships built-in red-team plugins mapped to the OWASP LLM Top 10 and NIST AI RMF (prompt injection, PII leakage, harmful content, hallucination), runs locally or in CI, and produces structured reports suitable for evidence collection. Used by teams at more than 25% of the Fortune 500. OpenAI announced its acquisition of Promptfoo on March 9, 2026; the open-source project continues, and the technology is being integrated into OpenAI's Frontier enterprise agent platform. Teams with strict vendor-independence requirements for auditing OpenAI models may want to pair it with a provider-neutral scanner such as Garak or PyRIT.",
      "website": "https://www.promptfoo.dev",
      "categories": [
        "model-evaluation"
      ],
      "tags": [
        "open-source",
        "github",
        "self-hosted",
        "owasp-llm-top-10",
        "mitre-atlas"
      ],
      "frameworks": [
        "NIST_AI_RMF"
      ],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "pyrit",
      "name": "PyRIT",
      "vendor": "PyRIT",
      "tagline": "Microsoft's Python Risk Identification Toolkit for automated generative-AI red teaming.",
      "description": "PyRIT (Python Risk Identification Toolkit) is the framework Microsoft's own AI Red Team uses to probe generative AI systems. Rather than a fixed scanner, it is a composable library for building multi-turn attack strategies, scoring model responses, and orchestrating large-scale adversarial campaigns against LLM applications.\n\n- Composable attack orchestrators and converters\n- Multi-turn adversarial conversation support\n- Automated scoring of attack success\n- Battle-tested by Microsoft's internal AI Red Team",
      "website": "https://github.com/Azure/PyRIT",
      "categories": [
        "red-teaming"
      ],
      "tags": [
        "open-source",
        "github",
        "owasp-llm-top-10",
        "mitre-atlas"
      ],
      "frameworks": [
        "NIST_AI_RMF"
      ],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "ragas",
      "name": "Ragas",
      "vendor": "Ragas",
      "tagline": "Open-source evaluation framework purpose-built for retrieval-augmented generation pipelines.",
      "description": "Ragas is the reference open-source toolkit for RAG evaluation: faithfulness, answer relevancy, context precision, and context recall metrics that quantify whether a pipeline retrieves the right evidence and stays grounded in it. Lightweight and notebook-friendly, it is often the first eval a RAG team adopts.\n\n- RAG-specific metric suite\n- Testset generation from documents\n- LangChain and LlamaIndex integrations\n- Works with any LLM as judge",
      "website": "https://docs.ragas.io",
      "categories": [
        "model-evaluation"
      ],
      "tags": [
        "open-source",
        "github"
      ],
      "frameworks": [],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "scan-ninja",
      "name": "Scan Ninja",
      "vendor": "Scan Ninja",
      "tagline": "AI-driven vulnerability management that turns scanner output into prioritized fixes and audit-ready compliance evidence.",
      "description": "Scan Ninja (Scan Ninja Inc, Austin, TX) ingests findings from scanners like Tenable, Nessus, and Qualys, uses AI to prioritize real risk over noise, and generates remediation playbooks with verifiable closure reports. Its compliance side claims evidence automation for SOC 2, ISO 27001, PCI DSS, and HIPAA, plus FedRAMP/TX-RAMP readiness support and optional expert-assisted audit preparation. Offers a free self-service trial tier alongside expert-assisted plans, with cloud and on-premise deployment options. All details are vendor-claimed and pending independent verification.",
      "website": "https://scanninja.ai",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "paid"
      ],
      "frameworks": [
        "SOC2",
        "ISO27001",
        "HIPAA",
        "PCI_DSS",
        "FedRAMP"
      ],
      "lastVerified": "2026-07-19",
      "listing_status": "radar"
    },
    {
      "slug": "skyflow",
      "name": "Skyflow",
      "vendor": "Skyflow",
      "tagline": "Data privacy vault that isolates and tokenizes sensitive data for AI and application workloads.",
      "description": "Skyflow takes a vault architecture approach: sensitive data is isolated in a dedicated privacy vault, applications and LLMs work with tokens, and polymorphic encryption lets workflows run on data without exposing it. Its LLM privacy vault targets exactly the problem of keeping PII out of prompts, fine-tuning sets, and vector stores.\n\n- Tokenization with format preservation\n- Polymorphic encryption for computation on protected data\n- LLM privacy vault for prompts and training data\n- Data-residency controls per region",
      "website": "https://www.skyflow.com",
      "categories": [
        "pii-detection",
        "data-privacy"
      ],
      "tags": [
        "enterprise"
      ],
      "frameworks": [
        "SOC2",
        "HIPAA",
        "GDPR",
        "PCI_DSS"
      ],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "spawning",
      "name": "Spawning",
      "vendor": "Spawning",
      "tagline": "Consent infrastructure for AI training data: Do Not Train registry and dataset opt-outs.",
      "description": "Spawning builds the consent layer between content creators and AI training: the Do Not Train registry, the Have I Been Trained search across major datasets, and APIs that let model builders respect opt-outs at scale. As EU AI Act transparency obligations for training data harden, consent infrastructure moves from ethics to compliance.\n\n- Do Not Train domain and work registry\n- Have I Been Trained dataset search\n- API for honoring opt-outs during data collection\n- ai.txt standard for machine-readable permissions",
      "website": "https://spawning.ai",
      "categories": [
        "policy-management"
      ],
      "tags": [
        "free"
      ],
      "frameworks": [
        "EU_AI_ACT"
      ],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "straiker",
      "name": "Straiker",
      "vendor": "Straiker",
      "tagline": "AI-native security for agentic AI: agent discovery and posture, continuous red teaming, and runtime guardrails against prompt injection and tool abuse.",
      "description": "AI-native security for agentic AI: agent discovery and posture, continuous red teaming, and runtime guardrails against prompt injection and tool abuse.",
      "website": "https://www.straiker.ai",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "enterprise"
      ],
      "frameworks": [],
      "lastVerified": "2026-07-20",
      "listing_status": "radar"
    },
    {
      "slug": "trustible",
      "name": "Trustible",
      "vendor": "Trustible",
      "tagline": "AI governance platform for inventory, risk assessment, policy, and regulatory compliance workflows.",
      "description": "Trustible, a Washington DC-area public benefit corporation, helps enterprises inventory AI use cases, assess risk, and generate compliance evidence against frameworks like the EU AI Act and NIST AI RMF. Raised a $4.6M seed in June 2025 with participation from the Office of Eric Schmidt. Vendor-claimed; pending verification.",
      "website": "https://trustible.ai",
      "categories": [
        "ai-governance"
      ],
      "tags": [
        "enterprise"
      ],
      "frameworks": [
        "EU_AI_ACT",
        "NIST_AI_RMF"
      ],
      "lastVerified": "2026-07-19",
      "listing_status": "radar"
    },
    {
      "slug": "vanta",
      "name": "Vanta",
      "vendor": "Vanta",
      "tagline": "Automated compliance platform covering ISO 42001, NIST AI RMF, and EU AI Act alongside SOC 2.",
      "description": "Vanta automates evidence collection and continuous control monitoring for compliance certifications, and now covers AI frameworks — ISO/IEC 42001, NIST AI RMF, and EU AI Act readiness — alongside its core SOC 2 and ISO 27001 programs. For startups selling AI products into enterprises, it is often the fastest path to an auditable AI governance posture.\n\n- ISO/IEC 42001 automated evidence collection\n- Continuous control monitoring with integrations\n- Combined SOC 2 + AI framework programs\n- Auditor network for certification",
      "website": "https://www.vanta.com",
      "categories": [
        "ai-governance"
      ],
      "tags": [
        "paid",
        "iso-42001"
      ],
      "frameworks": [
        "SOC2",
        "ISO27001",
        "EU_AI_ACT",
        "NIST_AI_RMF"
      ],
      "lastVerified": "2026-07-18",
      "listing_status": "verified"
    },
    {
      "slug": "witnessai",
      "name": "WitnessAI",
      "vendor": "WitnessAI",
      "tagline": "Enterprise AI observability and policy guardrails for safe employee and app AI usage.",
      "description": "WitnessAI provides visibility into enterprise AI activity with identity-based policy controls, data protection, and audit trails. Vendor-claimed; pending verification.",
      "website": "https://witness.ai",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "enterprise"
      ],
      "frameworks": [
        "NIST_AI_RMF"
      ],
      "lastVerified": "2026-07-19",
      "listing_status": "radar"
    },
    {
      "slug": "zania",
      "name": "Zania",
      "vendor": "Zania",
      "tagline": "AI agents for security compliance: risk assessments, audits, and questionnaire automation.",
      "description": "Zania deploys AI agents that automate security reviews, compliance assessments, and vendor questionnaires for GRC teams. Vendor-claimed; pending verification.",
      "website": "https://www.zania.ai",
      "categories": [
        "ai-governance"
      ],
      "tags": [
        "paid"
      ],
      "frameworks": [
        "SOC2",
        "ISO27001"
      ],
      "lastVerified": "2026-07-19",
      "listing_status": "radar"
    },
    {
      "slug": "zenity",
      "name": "Zenity",
      "vendor": "Zenity",
      "tagline": "Security and governance for AI agents and low-code copilots across the enterprise.",
      "description": "Zenity secures AI agents, copilots, and low-code automations with posture management, threat detection, and governance policies. Vendor-claimed; pending verification.",
      "website": "https://zenity.io",
      "categories": [
        "ai-governance",
        "red-teaming"
      ],
      "tags": [
        "enterprise",
        "owasp-llm-top-10",
        "mitre-atlas"
      ],
      "frameworks": [],
      "lastVerified": "2026-07-19",
      "listing_status": "radar"
    }
  ],
  "generatedAt": "2026-07-27T02:10:47.204Z",
  "count": 65
}