Three Vendors Submitted Tools to Our Directory. Here Is What We Found.
Frenkie
· 10 min read

Three companies asked to be listed this month. All three went on the radar, not into the verified directory — because one is a waitlist, one is pre-GA, and one makes a certification claim that does not work the way its marketing implies.
Look, most directories list whatever gets submitted. We do not, and this article is the proof of it. Below is every claim each vendor made, what I could confirm against a primary source, and what I could not.
Then I will show you how to run the same check yourself in about twenty minutes.
The three submissions at a glance
Tool | What it does | Stage today | Pricing | The claim I could not confirm |
|---|---|---|---|---|
HIPAA-focused AI assistant for healthcare documents, letters, and billing support | Live and selling | $47/mo, API from $45/mo | “The only HIPAA compliant AI Tool hosted on AWS GovCloud” | |
Guided EU AI Act self-assessment for European SMEs; risk classification, gap report, internal AI policy | Waitlist — not live | Free for first 100 companies | That you can run an assessment today | |
OpenTelemetry-native “agent control plane”: agent registry, cost attribution, EU AI Act audit evidence | Pre-GA pilot | Free tier, then $299–$1,999/mo | prEN 18229-1 conformance (it is a target, not a certification) |
Here is the fast version: Hathr.AI is the only one of the three you could actually buy today.
What does “on the radar” actually mean?
A radar listing means we have confirmed the company exists and the product is real, but nothing the vendor claims has been independently verified by us. Radar tools get no compliance score and are excluded from every ranking and comparison on the site.
It is a holding pattern, not a verdict. Tools move to verified when there is something testable — a shipped product, a real certification, a customer we can talk to.
Why publish them at all? Two reasons:
Early-stage tools are often the ones you actually need. The EU AI Act created obligations faster than incumbents shipped features. Some of the best fits are eighteen months old.
Hiding them does not make you safer. You will find these companies on Google anyway. Better you find them next to a plain statement of what we could not confirm.
Fine print, and I mean this
A radar listing is not an endorsement. These are early-stage companies, some pre-launch, and everything on those pages comes from the vendor. Do your own due diligence before you buy, sign a contract, or send them any data. Our full disclaimer applies.
Hathr.AI: what holds up, and what needs a footnote
Hathr.AI is a live, purchasable HIPAA-focused AI assistant at $47 a month that includes a BAA — and the BAA is the part that matters most. It runs Claude models in AWS GovCloud and targets healthcare, billing, legal, and government users who cannot paste protected health information into a consumer chatbot.
The core value proposition checks out. ChatGPT’s consumer tier will not sign a Business Associate Agreement with you. Hathr says it signs BAAs in 24 hours, and the BAA is bundled into every plan including the $47 tier. For a solo practice, that is a real gap being filled at a real price.
Now the footnotes.
“FedRAMP Certified Servers” needs unpacking. AWS GovCloud (US) holds a FedRAMP High authorization. A product running on top of it inherits controls, not the authorization. Using FedRAMP-authorized infrastructure does not automatically make your service FedRAMP compliant, and AWS itself frames this as control inheritance requiring documented analysis. So “hosted in a FedRAMP High environment” is fair. “FedRAMP certified” is not the same statement, and if you work with Medicare or Medicaid data, your auditor will know the difference.
“The only HIPAA compliant AI Tool on AWS GovCloud” is unverifiable. I could not confirm or disprove it. Exclusivity claims of this shape rarely survive contact with a competitor’s legal team, and I would not repeat it in a procurement document without asking Hathr to put it in writing.
One more thing worth knowing: there is no such thing as HIPAA certification. No government body certifies anyone. HIPAA compliance is self-attested and enforced after the fact, which is exactly why the BAA — a contract with liability attached — is the thing to focus on rather than any badge.
If PHI redaction is your actual problem rather than a chat interface, compare against Private AI, Skyflow, Nightfall AI, and the open-source Microsoft Presidio before you decide.
Veriakt: correct about the law, but you cannot use it yet
Veriakt is a Berlin-built EU AI Act self-assessment tool that is not live — the site is a waitlist, and the submission described the product in the present tense. That gap is the single most important fact about this listing.
The idea is sound. European SMEs got handed a 144-page regulation written for enterprises, and their options were a five-figure consultancy or a generic checklist. Veriakt automates the middle: a ten-minute plain-language intake, risk classification per system with the Article or Annex III basis cited, obligations filtered by whether you are a provider or a deployer, gaps ranked by deadline, then a board report and an internal AI policy.
The role-aware filtering is the clever bit. Article 11 technical documentation is a provider duty for high-risk systems — if you are a limited-risk deployer, a good tool marks it not-applicable with a reason instead of scoring you down for it. Checklist tools routinely get this wrong.
Two things earned my respect here. First, the Impressum names a real operator: Yash Soni, trading as a sole proprietorship in Berlin. No ambiguity about who is behind it. Second — and this is rarer than it should be — Veriakt’s public summary of the EU AI Act deadlines is correct on every date I checked:
Article 5 prohibited practices — applicable since 2 February 2025
Article 4 AI literacy — in force since 2 February 2025, at every risk tier
Article 50 transparency — applies from 2 August 2026
Annex III high-risk — deferred from 2 August 2026 to 2 December 2027 under the Digital Omnibus, agreed by the Council and Parliament on 7 May 2026
Article 99 penalties — up to €35M or 7% of global turnover
I check a lot of vendor sites. Most get at least one of these wrong, usually by implying the 2027 delay let you stop worrying. Veriakt says the opposite in writing: “A tool that tells you compliance can wait until 2027 is not doing you a favour.”
It also states plainly that it is not legal advice and tells you to involve a lawyer before CE marking or EU-database registration.
The honest summary: a one-person pre-launch company with an accurate reading of the regulation and nothing yet to test. Join the waitlist if the shape fits. Do not build a compliance plan around a delivery date. If you need something working this quarter, look at FairNow, Holistic AI, or Modulos instead.
MeshAI: real engineering, real citation, not yet generally available
MeshAI sits one layer above your observability stack — it ingests the same OpenTelemetry traces Datadog and Honeycomb already take, then produces the EU AI Act artifacts an APM cannot. Article 12 record-keeping, Annex III classification, Article 26 deployer bundles, Article 73 incident reporting.
The architecture is genuinely well-argued. Your observability platform is a data layer: it collects, stores, queries. MeshAI reads those same traces against a governance policy and emits evidence. You add it as a parallel destination in your OpenTelemetry Collector — one YAML change, no agent code touched.
What it does once the traces arrive:
An agent registry that populates itself. Anything emitting telemetry gets registered, including the shadow agents nobody told you about.
Anomaly detection on a five-minute cadence — cost spikes, reliability decay, silent model swaps, dormant agents waking up.
Token-level cost attribution by team, project, and agent, with budget guardrails.
Policy enforcement at the proxy — eight policy types, human-in-the-loop approvals, an agent kill switch, plus prompt-injection and PII detection inline.
Here is the part I want to flag, because it cuts the other way from most vendor claims I check. MeshAI anchors its central architectural claim to a specific academic source: the twelve-step compliance architecture in AI Agents Under EU Law (Nannini et al., arXiv:2604.04604, 6 April 2026). I pulled the paper. It exists, the authors are as stated, and it does propose that twelve-step architecture. The citation is real.
I check citations because fabricated ones are common. This one held.
Now the limits:
Pre-GA. MeshAI is recruiting five to ten enterprise pilot partners before general availability.
SOC 2 is roadmap, not achieved — stated on their own pricing FAQ.
prEN 18229-1 is a conformance target. It is a January 2026 CEN/CENELEC working draft. Do not read it as a credential.
GitHub traction is thin — five repositories, one star across the whole organisation, no public members, though commits are recent.
Pricing is public and specific, which I will always credit: free forever for one agent, $299/mo for 25, $799/mo for 100, $1,999/mo for 1,000, custom above that. Most vendors in this category make you book a call to learn anything.
How do you vet an early-stage compliance vendor yourself?
Run these five checks before you send an early-stage vendor a single byte of production data. It takes about twenty minutes and it is roughly what I did above.
Find out who legally operates it. EU companies must publish an Impressum. US companies should have a findable entity. If you cannot name the operator, stop.
Separate the certification from the environment it runs in. “Hosted in a FedRAMP High environment” and “FedRAMP authorized” are different sentences. Same for SOC 2 “in progress” versus a report you can read under NDA.
Pull one cited source at random. If a vendor cites a paper, a standard, or an analyst, check that it exists and says what they claim. This catches more than you would expect.
Ask what happens to your data on their worst day. Where is it, who can read it, what is retained, and what does the contract actually oblige them to?
Check whether the thing is purchasable today. Two of the three tools above are not. That is fine — as long as you know it before you plan around them.
Pair that with a real framework rather than vibes. NIST AI RMF and ISO/IEC 42001 both give you vendor-assessment structure for free, and OWASP LLM Top 10 covers the technical failure modes.
Want your tool in the directory?
Submit it at aicompliance.ai/submit. It is free, there is no paid placement, and there never will be.
What happens next, so there are no surprises:
Everything starts on the radar. No exceptions, including for tools I personally like.
I check the operator, the stage, the pricing, and any cited source before the listing goes up.
Claims I cannot confirm get labelled as unconfirmed in the listing itself, not buried.
You move to verified when there is something testable — shipped product, real certification, evidence I can examine.
You are welcome to disagree with a call I make. Several vendors have, and one of them changed my mind.
Your Action Plan
Today: if you are a healthcare team pasting PHI into a consumer chatbot, stop. Whether or not you choose Hathr.AI, the fix is a vendor that signs a BAA. Ask for the BAA before the demo.
This week: if you sell or deploy AI in the EU, confirm your Article 50 transparency disclosures are live. That deadline passed on 2 August 2026 — six days ago.
This week: run the five-check vetting list above against whichever AI vendor you are closest to signing with. Twenty minutes.
This month: if you run more than a handful of AI agents, build the inventory before you buy a tool to manage it. Article 12 record-keeping assumes you know what you are running. Most teams do not.
Before 2 December 2027: if anything you operate lands in Annex III, the delay bought you runway, not a pass. The runway only helps companies that start inside it.
Anytime: submit a tool at aicompliance.ai/submit, or browse all 68 listings in the directory — including everything currently on the radar. Agents and LLMs can read the whole thing at llms.txt.
Disclosure: Hathr.AI, Veriakt and MeshAI were all submitted to this directory by their vendors. No payment was involved and no listing on this site can be bought. Directory figures are as of 8 August 2026.