A list, not a review: nothing is ranked, and a tool missing from it was not evaluated and rejected. Nobody looked. Rendered 2026-10-03.
| Tool | What it is | Compliance | Type | Read |
|---|---|---|---|---|
| coder/coder (opens in a new tab) | A self-hosted control plane that provisions workspaces from Terraform templates you write. | You run it, so you answer these. | repository | observed 2026-09-03 |
| Daytona (opens in a new tab) | A hosted sandbox cloud for agent-run code, the same shape of product as E2B: disposable, isolated workspaces obtained on demand rather than a template-defined workspace a person provisions once. | SOC 2 Type II, period stated as 2025-12-16 to 2026-03-15 ISO 27001 (marked †, explained in the key)Unverified after 2026-12-26 |
hosted service | observed 2026-09-24 |
| E2B (opens in a new tab) | A hosted cloud of disposable Firecracker microVMs, one per sandbox, reached over an SDK call rather than provisioned as a template-defined workspace: an agent gets an isolated machine to run code, browse and use tools in, and the sandbox can be paused and forked. | SOC 2 Type II HIPAA BAA* (only on Enterprise. marked †, explained in the key) DPAUnverified after 2026-12-26 |
hosted service | observed 2026-09-24 |
Data handling: what the vendor’s pages sayData residency (only on Managed) E2B's page: its managed sandboxes are hosted on Google Cloud, and their storage is encrypted at rest with the default encryption Google Cloud applies. e2b.dev (opens in a new tab), Google Cloud, encrypted by default. Read 2026-09-27. | ||||
| GitHub Codespaces (opens in a new tab) | A workspace defined by a file in the repository and hosted by the vendor. | Not shown to hold.Unverified after 2026-12-26 |
hosted service | reasoned 2026-09-08 |
Data handling: what the vendor’s pages sayData residency (marked †, explained in the key) GitHub's page: personal information is stored and processed by GitHub in many places: the user's own region, the United States, plus other countries where GitHub or a subsidiary, affiliate or subprocessor of it operates. docs.github.com (opens in a new tab), International data transfers, read 2026-09-27. Default retention (marked †, explained in the key) GitHub's page: GitHub keeps personal information while the account is active, and beyond that for as long as contracts, legal requirements, dispute resolution or enforcing agreements need it. docs.github.com (opens in a new tab), Security and Retention, read 2026-09-27. Telemetry GitHub's page: in its list of whom it may share personal information with, GitHub says GitHub Codespaces and github.dev run Visual Studio Code in the browser and collect some telemetry by default. docs.github.com (opens in a new tab), Sharing of Personal Data, in a list, read 2026-09-27. GitHub's page: telemetry in the browser-based VS Code is turned off from the File > Preferences > Settings menu at its top left, and that choice is then synced to every later browser session of github.dev and GitHub Codespaces. docs.github.com (opens in a new tab), Sharing of Personal Data, in a list, read 2026-09-27. | ||||
| Runloop (opens in a new tab) | A hosted sandbox cloud for agents, comparable to E2B and Daytona: persistent Devboxes so an agent can analyze data or work across a long task without losing context, marketed explicitly for autonomous-agent workloads, model evaluation against real workloads, and agentic-commerce use cases. | SOC 2Unverified after 2026-12-26 |
hosted service | observed 2026-09-24 |
Data handling: what the vendor’s pages sayZero-retention option Runloop's trust center lists, under its data and privacy controls, that customer data is deleted when a customer leaves. compliance.runloop.ai (opens in a new tab), Controls › Data and privacy, read 2026-09-27. | ||||
| Tool | What it is | Compliance | Type | Read |
|---|---|---|---|---|
| Amazon SageMaker (opens in a new tab) | A managed hosting and tooling surface: notebooks, training jobs and inference endpoints. | SOC 2 (marked †, explained in the key) ISO 27001:2022 (marked †, explained in the key) HIPAA BAA (marked †, explained in the key) HIPAA* (only under SageMaker AI other than Studio Lab, Ground Truth Plus, Public Workforce and Vendor Workforce) GDPR DPA (marked †, explained in the key)Unverified after 2026-12-23 |
hosted service | reasoned 2026-09-03 |
Data handling: what the vendor’s pages sayData residency (marked †, explained in the key) AWS's page: customers pick the AWS Regions where their content is stored and may replicate or back it up across more than one, and AWS says it will not move or copy that content out of the chosen Regions without the customer's agreement. aws.amazon.com (opens in a new tab), At AWS, customer trust is our top priority › Commitments, read 2026-09-27. | ||||
| Baseten (opens in a new tab) | A hosted platform for deploying and scaling open-source and custom models in production, comparable to Together AI, Fireworks AI and Groq. | SOC 2 ISO 27001:2022Unverified after 2026-12-26 |
hosted service | observed 2026-09-24 |
| deepseek-ai/DeepSeek-V4-Flash (opens in a new tab) | DeepSeek’s V4 Flash text model, stored mostly in 8-bit and FP8 formats across 46 safetensors shards (about 291 billion parameters as the Hugging Face hub counts them), MIT-licensed and ungated. | You run it, so you answer these. | model weights | observed 2026-09-11 |
| Fireworks AI (opens in a new tab) | A hosted training-and-inference platform positioned around turning open models into a buyer’s own specialized intelligence, fine-tuning and serving in one vendor, the same competitive set as Together AI and Baseten. | Not shown to hold.Unverified after 2026-12-26 |
hosted service | observed 2026-09-24 |
Data handling: what the vendor’s pages sayDefault retention (marked †, explained in the key) (only under Fireworks AI's privacy notice, which does not cover its processing as a service provider for other businesses) Fireworks AI's page: it keeps personal information only while that is reasonably needed for the purposes its privacy notice describes. fireworks.ai (opens in a new tab), above the page's first section heading, read 2026-09-27. Zero-retention option (marked †, explained in the key) Fireworks AI's page, among its key privacy commitments under zero data retention: for any open model, prompts and generated outputs are not logged or stored unless the user has explicitly opted in; the sentence ends in an asterisk that links to a separate page on data handling. fireworks.ai (opens in a new tab), above the page's first section heading, in a list, read 2026-09-27. Training use (marked †, explained in the key) (only under Fireworks AI's privacy notice, which does not cover its processing as a service provider for other businesses) Fireworks AI's page: among the key privacy commitments in its privacy notice, it does not train or improve its AI models on a user's API inputs, prompts or training data without that user's explicit opt-in. fireworks.ai (opens in a new tab), above the page's first section heading, in a list, read 2026-09-27. | ||||
| google/gemma-3-27b-it (opens in a new tab) | Google’s 27-billion-parameter instruction-tuned Gemma 3 model, taking images as well as text, 12 safetensors shards, under Google’s own Gemma terms and behind a manual approval gate; the card body returned 401 without a login on 2026-09-03. | You run it, so you answer these. | model weights | observed 2026-09-11 |
| google/gemma-4-31B-it (opens in a new tab) | The Gemma 4 successor at about 31 billion parameters, images and text, two safetensors shards, Apache-2.0 as the hub reports it, and ungated. | You run it, so you answer these. | model weights | observed 2026-09-11 |
| Groq (opens in a new tab) | A hosted inference platform built on Groq’s own custom chips (LPUs), marketed on inference speed. | Not shown to hold. |
hosted service | observed 2026-09-24 |
| huggingface/text-generation-inference (opens in a new tab)archived | A server process that holds weights and answers completion calls, the same role as vLLM. | You run it, so you answer these. | repository | observed 2026-09-11 |
| LM Studio (opens in a new tab) | A closed desktop application that downloads and serves models on a workstation. | Not shown to hold.Unverified after 2026-12-26 |
desktop application | observed 2026-09-03 |
Data handling: what the vendor’s pages sayDefault retention LM Studio's desktop app privacy policy: retention periods are kept short by design, and the prompts a user sends and the responses produced are not kept. lmstudio.ai (opens in a new tab), Data retention and security, read 2026-09-27. Zero-retention option LM Studio's page: when its Cloud Services are used, a request is processed transiently in the cloud so the response can come back to the device, and every party involved works under Zero Data Retention terms or ones substantially equivalent. lmstudio.ai (opens in a new tab), What we process and why › When You Use Cloud Services, read 2026-09-27. Training use LM Studio's page: for cloud-service requests, web search and cloud models being examples, neither the request nor the response is kept once the request finishes, and the data goes to no other use, training included. lmstudio.ai (opens in a new tab), What we process and why › When You Use Cloud Services, read 2026-09-27. Telemetry LM Studio's page, for local use of the software: because telemetry and user-specific tracking are absent from the application, LM Studio says it cannot fulfill requests from data subjects, such as for a copy of their personal information or its deletion. lmstudio.ai (opens in a new tab), Data Subject Rights, read 2026-09-27. | ||||
| meta-llama/Llama-3.1-8B-Instruct (opens in a new tab) | Meta’s 8-billion-parameter instruction-tuned text model, tagged for eight languages, published as four safetensors shards plus one PyTorch checkpoint under Meta’s own Llama 3.1 license and behind a manual approval gate; the card body returned 401 without a login on 2026-09-03. | You run it, so you answer these. | model weights | observed 2026-09-11 |
| mistralai/Mistral-7B-Instruct-v0.3 (opens in a new tab) | Mistral’s 7-billion-parameter instruction-tuned text model, Apache-2.0 as the Hugging Face hub reports it, ungated, four safetensors shards, and tagged for vLLM rather than for the transformers library; its card says it is the instruct fine-tune of Mistral-7B-v0.3. | You run it, so you answer these. | model weights | observed 2026-09-11 |
| Modal (opens in a new tab) | A general-purpose serverless compute platform for running arbitrary code on CPU or GPU at scale, used heavily for model serving and batch inference, and also offering sandboxed execution primitives that overlap with hosted agent sandboxes such as E2B, Daytona and Runloop. | HIPAA BAA* (only on Enterprise)Unverified after 2026-12-26 |
hosted service | observed 2026-09-24 |
Data handling: what the vendor’s pages sayDefault retention Modal's docs: function inputs and outputs, whether held inline in Modal's metadata store (payloads of 2 MiB or less) or in object storage (larger ones), are deleted within 7 days at most. modal.com (opens in a new tab), Data privacy › Data retention › Function inputs and outputs, read 2026-09-27. Zero-retention option Modal's docs: Modal Inference endpoints operate under zero data retention, meaning payloads of requests and responses never touch disk and cross Modal's infrastructure only while in flight over the network. modal.com (opens in a new tab), Data privacy › Data retention › Modal Inference endpoints, read 2026-09-27. Model provider Modal's docs: for inference endpoints, TLS ends at Modal's edge proxy, which then passes requests straight to the customer's containers through an internal tunnel. modal.com (opens in a new tab), Data privacy › Data retention › Modal Inference endpoints, read 2026-09-27. Where it can run Modal's docs: Modal runs compute jobs in containers virtualized with gVisor, a sandboxing technology Google developed and uses in its Google Kubernetes Engine and Google Cloud Run services. modal.com (opens in a new tab), Network and infrastructure security (InfraSec), in a list, read 2026-09-27. | ||||
| ollama/ollama (opens in a new tab) | A local server plus CLI that pulls a packaged model and serves it on a workstation. | You run it, so you answer these. | repository | observed 2026-09-03 |
| openai/gpt-oss-120b (opens in a new tab) | The larger of OpenAI’s two open-weight text models, about 117 billion parameters in the same 4-bit mxfp4 packing as openai/gpt-oss-20b, 22 safetensors shards, Apache-2.0, ungated. | You run it, so you answer these. | model weights | observed 2026-09-11 |
| openai/gpt-oss-20b (opens in a new tab) | OpenAI’s smaller open-weight text model, about 21 billion parameters, most of them stored in the 4-bit packing the Hugging Face hub tags as mxfp4 so the shards weigh far less than the count suggests; Apache-2.0, ungated, tagged for vLLM and transformers. | You run it, so you answer these. | model weights | observed 2026-09-11 |
| Qwen/Qwen3-8B (opens in a new tab) | An 8-billion-parameter dense text model from Alibaba’s Qwen team, Apache-2.0, ungated, five safetensors shards, configuration model type qwen3; its card places Qwen3 within a broader family that spans both dense and MoE (mixture-of-experts) architectures, of which this is a small dense member. | You run it, so you answer these. | model weights | observed 2026-09-11 |
| Qwen/Qwen3.8-2.4T-A95B (opens in a new tab) | A mixture-of-experts text model of about 2.4 trillion parameters in 213 safetensors shards, under a vendor-named license (qwen3.8-max) the hub reports as ‘other’, ungated. | You run it, so you answer these. | model weights | observed 2026-09-11 |
| Qwen/Qwen3.8-Flash-Next (opens in a new tab) | A Qwen model that takes images as well as text (the Hugging Face hub files it as image-text-to-text), about 180 billion parameters in 131 safetensors shards, under a vendor-named license (Qwen Community 1.0) the hub classifies as an other-type license rather than a standard one. | You run it, so you answer these. | model weights | observed 2026-09-11 |
| Together AI (opens in a new tab) | A hosted inference API for open-weight models, positioned as the AI native cloud: serving, fine-tuning and (per its own broader marketing) training infrastructure for teams that do not want to run vLLM or similar themselves. | SOC 2 Type II ISO 27001:2022 DPAUnverified after 2026-12-26 |
hosted service | observed 2026-09-24 |
Data handling: what the vendor’s pages sayData residency (only on Enterprise, Dedicated, Serverless) Together AI's docs: region cannot be chosen for serverless endpoints; the same sentence points customers to a dedicated endpoint or to contacting Together about the setup their workload needs. docs.together.ai (opens in a new tab), Enterprise data residency and private networking, read 2026-09-27. Zero-retention option Together AI's docs, on the data Together stores: customers can delete it whenever they choose, and the same sentence says it is not passed to third parties. docs.together.ai (opens in a new tab), What Together stores, read 2026-09-27. Together AI's docs, on organization-level settings that only admins of the organization may change: storing prompts and model responses is on by default and keeps them for product improvement; switching it off gives zero data retention, and also disables passthrough models, since those need prompts stored. docs.together.ai (opens in a new tab), Organization privacy settings, in a list, read 2026-09-27. Training use Together AI's docs: sharing data to train other models is not switched on by default and happens only if a customer opts in. docs.together.ai (opens in a new tab), Training opt-in, read 2026-09-27. Model provider Together AI's docs: certain models run as passthrough, meaning Together relays prompts and responses straight to the provider upstream, whose own policy then covers the data. docs.together.ai (opens in a new tab), Passthrough third-party models, read 2026-09-27. Together AI's docs: models from third-party authors such as DeepSeek, Qwen and Mistral that Together hosts run on its own infrastructure, make no calls to their authors, and give those authors no access to customers' requests or API calls. docs.together.ai (opens in a new tab), Third-party model providers, read 2026-09-27. Where it can run (only on Enterprise, Dedicated) Together AI's docs, in the section named above: for customers facing regulatory, compliance or data-residency requirements, with GDPR-driven deployments in EU regions as its example, Together offers the networking option that section's heading names and deployments based on a VPC, EU regions included. docs.together.ai (opens in a new tab), Enterprise data residency and private networking, read 2026-09-27. | ||||
| vllm-project/vllm (opens in a new tab) | A Python library and a server process that holds model weights in GPU memory and answers completion calls over an OpenAI-shaped API. | You run it, so you answer these. | repository | observed 2026-09-03 |
| Tool | What it is | Compliance | Type | Read |
|---|---|---|---|---|
| Anthropic API (opens in a new tab) | Anthropic’s own hosted API for the Claude models, what Anthropic’s support documentation calls the first-party API, separate from Claude Code, Cowork, or a model reached through a cloud platform like Bedrock, Microsoft Foundry or Google Cloud’s Agent Platform. | Claude APISOC 2 Type II ISO 27001 ISO 42001 HIPAA BAA* (only on Commercial, Enterprise. only under the Claude API arrangement Anthropic calls HIPAA readiness) DPA (marked †, explained in the key)A restriction below.Unverified after 2026-12-23 |
hosted service | observed 2026-09-24 |
Restriction, Claude API: Government at FedRAMP High, DoD IL4 and DoD IL5. From the vendor’s table, not a reviewed summary: Anthropic's table excludes this row and column; its mark reads "N/A" (the symbol the cell shows). trust.anthropic.com (opens in a new tab), table "Welcome to the Anthropic Trust Center", row "Claude via Anthropic's API", columns "FedRAMP High", "DoD IL4" and "DoD IL5", read 2026-09-27. | ||||
Data handling, Claude API: what the vendor’s pages sayZero-retention option Anthropic's page: with a ZDR arrangement in place, Anthropic keeps neither customer prompts nor responses at rest once the API has returned its response. platform.claude.com (opens in a new tab), Zero data retention (ZDR), read 2026-09-24. Training use Anthropic's page: among the commitments it makes for features that have to store data, retained data is not used for model training unless the customer has expressly allowed it. platform.claude.com (opens in a new tab), How Anthropic approaches data retention, in a list, read 2026-09-24. Model provider Anthropic's page: Anthropic is the data processor for the Claude API, for Claude Platform on AWS and for Claude in Microsoft Foundry, the three offerings this page covers. platform.claude.com (opens in a new tab), above the page's first section heading, read 2026-09-24. | ||||
| AWS Bedrock (opens in a new tab) | A managed API in front of many vendors’ models. | Amazon Bedrock from AWSSOC 2 (marked †, explained in the key) ISO 27001:2022 (marked †, explained in the key) HIPAA BAA (marked †, explained in the key) HIPAA GDPR DPA (marked †, explained in the key)Unverified after 2026-12-23 Claude in Amazon Bedrock from AnthropicSOC 2* (only under the condition noted under this row’s items) Type II ISO 27001* (only under the condition noted under this row’s items) ISO 42001* (only under the condition noted under this row’s items)Applies to every item above: Anthropic's footnote on this row: its marks cover only the model and the containers Anthropic supplies to partners.A restriction below.Unverified after 2026-12-23 |
hosted service | reasoned 2026-09-03 |
Restriction, Claude in Amazon Bedrock from Anthropic: Government at FedRAMP High, DoD IL4 and DoD IL5. From the vendor’s table, not a reviewed summary: Anthropic's table excludes this row and column; its mark reads "N/A" (the symbol the cell shows). trust.anthropic.com (opens in a new tab), table "Welcome to the Anthropic Trust Center", row "Claude in Amazon Bedrock *", columns "FedRAMP High", "DoD IL4" and "DoD IL5", read 2026-09-27. | ||||
Data handling, Amazon Bedrock from AWS: what the vendor’s pages sayData residency AWS's page: for models in the default mode, where data may be kept for abuse detection, once cross-region inference has been turned on, whatever inputs and outputs are retained are kept in the destination Region, meaning the Region that processes the inference request. docs.aws.amazon.com (opens in a new tab), What data is retained and for how long, read 2026-09-24. On AWS GovCloud (US): AWS's page: in its section on export-controlled content, for services built in the AWS GovCloud (US) Regions, data that the page's list does not name stays inside those Regions. docs.aws.amazon.com (opens in a new tab), Export-controlled content, read 2026-09-24. Default retention (marked †, explained in the key) AWS's page: in the default mode the model's own retention policy governs and earlier behavior is unchanged, so if ZDR applied before, it still applies; actual retention varies by model, whose terms it points to, AWS may hold the data for abuse prevention and safety, it is not passed to the model provider, and for the Responses API, store is true by default and either setting is allowed. docs.aws.amazon.com (opens in a new tab), Data retention modes, table "Data retention modes", row "default", column "Behavior", read 2026-09-24. Zero-retention option (marked †, explained in the key) AWS's page: in the none mode, which it calls zero data retention, AWS keeps nothing from requests or responses in durable storage and passes none of it to the model provider; the Responses API defaults store to false and refuses store=true, background mode is unavailable, and requests to Chat Completions and to Messages are never kept. docs.aws.amazon.com (opens in a new tab), Data retention modes, table "Data retention modes", row "none", column "Behavior", read 2026-09-24. Ask sales Under models that require data retention: AWS's page: some models keep data to guard against abuse and for safety, and if an organization needs zero data retention for reasons of compliance and wants those models, it should raise eligibility with its AWS account manager. docs.aws.amazon.com (opens in a new tab), Zero data retention (ZDR) access, read 2026-09-24. Model provider AWS's page: model providers have no access to the accounts Amazon Bedrock deploys their models into; after a provider delivers a model to AWS, Amazon Bedrock makes a deep copy of the provider's training and inference software in those accounts for deployment, and because providers cannot reach the accounts, they cannot reach Amazon Bedrock logs or customers' prompts and completions either. docs.aws.amazon.com (opens in a new tab), above the page's first section heading, read 2026-09-24. Where it can run AWS's page: Amazon Bedrock is described as a fully managed service giving access to foundation models from AI companies, for building and scaling generative AI applications. docs.aws.amazon.com (opens in a new tab), above the page's first section heading, read 2026-09-28. On AWS GovCloud (US): AWS's page: Amazon Bedrock is available in AWS GovCloud (US), and the page goes on to list the GovCloud Regions where it runs. docs.aws.amazon.com (opens in a new tab), Region availability, read 2026-09-24. Data handling, Claude in Amazon Bedrock from Anthropic: what the vendor’s pages sayModel provider Anthropic's page: on Google Cloud's Agent Platform and on Amazon Bedrock the data processor is the cloud provider, and readers are pointed to each platform's own documentation on data retention and compliance for the equivalent controls. platform.claude.com (opens in a new tab), above the page's first section heading, read 2026-09-24. | ||||
| Azure AI Foundry / Azure OpenAI (opens in a new tab) | Microsoft’s platform for deploying third-party and first-party models (including Anthropic’s Claude family and OpenAI’s models) inside an Azure tenant, with two hosting options for Claude specifically: Hosted on Azure and Hosted on Anthropic Infrastructure. | Microsoft Foundry from MicrosoftISO 27001 (marked †, explained in the key) HIPAA BAA (marked †, explained in the key) HITRUST (marked †, explained in the key) GDPR (marked †, explained in the key) DPA (marked †, explained in the key)Unverified after 2026-12-23 Claude in Microsoft Foundry, hosted on Anthropic from AnthropicSOC 2 Type II ISO 27001 ISO 42001Restrictions below.Unverified after 2026-12-23 Claude in Microsoft Foundry, hosted on Azure from AnthropicRestrictions below.Unverified after 2026-12-23 Azure from MicrosoftISO 27001 HIPAA BAA HITRUST (marked †, explained in the key) Government FedRAMP High GDPR (marked †, explained in the key) DPA (marked †, explained in the key)Unverified after 2026-12-23 |
hosted service | observed 2026-09-24 |
Restriction, Claude in Microsoft Foundry, hosted on Anthropic from Anthropic: HIPAA (under the Claude API arrangement Anthropic calls HIPAA readiness). Anthropic's page: HIPAA readiness is not offered on Claude Platform on AWS or on Microsoft Foundry. platform.claude.com (opens in a new tab), HIPAA readiness › What HIPAA readiness does not cover, read 2026-09-24. Also: From the vendor’s table, not a reviewed summary: HIPAA, marked by the maker, kind of evidence not stated. Anthropic's table marks this row and column "✅" (the symbol the cell shows). trust.anthropic.com (opens in a new tab), above the page's first section heading, table "Welcome to the Anthropic Trust Center", row "Claude in Microsoft Foundry, hosted on Anthropic", column "HIPAA", read 2026-09-27. Restriction, Claude in Microsoft Foundry, hosted on Anthropic from Anthropic: Government at FedRAMP High, DoD IL4 and DoD IL5. From the vendor’s table, not a reviewed summary: Anthropic's table excludes this row and column; its mark reads "N/A" (the symbol the cell shows). trust.anthropic.com (opens in a new tab), table "Welcome to the Anthropic Trust Center", row "Claude in Microsoft Foundry, hosted on Anthropic", columns "FedRAMP High", "DoD IL4" and "DoD IL5", read 2026-09-27. Restriction, Claude in Microsoft Foundry, hosted on Azure from Anthropic: HIPAA (under the Claude API arrangement Anthropic calls HIPAA readiness). Anthropic's page: HIPAA readiness is not offered on Claude Platform on AWS or on Microsoft Foundry. platform.claude.com (opens in a new tab), HIPAA readiness › What HIPAA readiness does not cover, read 2026-09-24. Also: Anthropic's page: its trust-center table shows HIPAA for Claude in Microsoft Foundry, hosted on Azure, as in process, marked Q4 2026. trust.anthropic.com (opens in a new tab), above the page's first section heading, table "Welcome to the Anthropic Trust Center", row "Claude in Microsoft Foundry, hosted on Azure", column "HIPAA", read 2026-09-27. Restriction, Claude in Microsoft Foundry, hosted on Azure from Anthropic: Government at FedRAMP High, DoD IL4 and DoD IL5. From the vendor’s table, not a reviewed summary: Anthropic's table excludes this row and column; its mark reads "N/A" (the symbol the cell shows). trust.anthropic.com (opens in a new tab), table "Welcome to the Anthropic Trust Center", row "Claude in Microsoft Foundry, hosted on Azure", columns "FedRAMP High", "DoD IL4" and "DoD IL5", read 2026-09-27. | ||||
Data handling, Microsoft Foundry from Microsoft: what the vendor’s pages sayData residency (only on Hosted on Azure) Microsoft's page, for Claude models Hosted on Azure in Microsoft Foundry: data at rest is kept in the Azure geography the customer selects, and processing is limited to whichever Global or DataZone deployment options apply in Microsoft Foundry. learn.microsoft.com (opens in a new tab), Hosted on Azure, read 2026-09-24. Default retention (only under Models sold by Azure) Microsoft's page: Models sold by Azure keep and process data both to deliver the service and to watch for uses that break the applicable product terms. learn.microsoft.com (opens in a new tab), above the page's first section heading, read 2026-09-24. Training use (only under Models sold by Azure) Microsoft's page: for Models sold by Azure, a customer's prompts, completions, embeddings and training data do not go into training generative AI foundation models of any kind unless the customer permits or instructs it. learn.microsoft.com (opens in a new tab), above the page's first section heading, in a list, in a box labeled "Important", read 2026-09-24. Model provider Under Models sold by Azure: Microsoft's page: Microsoft hosts Models sold by Azure within its own Azure environment, Foundry being one of Azure's services, and those models have no interaction with services that their providers operate, OpenAI's ChatGPT and API being its example. learn.microsoft.com (opens in a new tab), above the page's first section heading, in a box labeled "Important", read 2026-09-24. On Hosted on Anthropic, Hosted on Azure: Microsoft's page: under both of its hosting options, Anthropic sells and runs the Claude models offered in Microsoft Foundry and is, for the prompts and outputs tied to those models, an independent data processor. learn.microsoft.com (opens in a new tab), above the page's first section heading, read 2026-09-24. Data handling, Claude in Microsoft Foundry, hosted on Anthropic from Anthropic: what the vendor’s pages sayModel provider Anthropic's page: Anthropic is the data processor for the Claude API, for Claude Platform on AWS and for Claude in Microsoft Foundry, the three offerings this page covers. platform.claude.com (opens in a new tab), above the page's first section heading, read 2026-09-24. Data handling, Claude in Microsoft Foundry, hosted on Azure from Anthropic: what the vendor’s pages sayModel provider Anthropic's page: Anthropic is the data processor for the Claude API, for Claude Platform on AWS and for Claude in Microsoft Foundry, the three offerings this page covers. platform.claude.com (opens in a new tab), above the page's first section heading, read 2026-09-24. | ||||
| BerriAI/litellm (opens in a new tab) | Two shapes in one repository: a Python SDK you import, and a proxy server you deploy in front of many providers. | You run it, so you answer these. | repository | observed 2026-09-03 |
| Cloudflare AI Gateway (opens in a new tab) | A gateway feature on Cloudflare’s existing edge/CDN platform: usage analytics, response caching, rate limiting and automatic model fallback in front of one or more providers, reached through Cloudflare’s own network rather than a standalone company’s infrastructure. | SOC 2 (marked †, explained in the key) Type II ISO 27001 (marked †, explained in the key) ISO 27701 (marked †, explained in the key)Unverified after 2026-12-26 |
hosted service | observed 2026-09-24 |
| Google Vertex AI / Gemini Enterprise Agent Platform (opens in a new tab) | Google’s rebrand of Vertex AI: the platform product itself was renamed, and the whole naming table under it renamed correspondingly (the studio, the API, the model garden, and so on). | Gemini Enterprise Agent Platform from GoogleSOC 2 ISO 27001 HIPAA* (only under requests to a locational endpoint. marked †, explained in the key) GDPR* (only under requests to a locational endpoint. marked †, explained in the key) DPA (marked †, explained in the key)Unverified after 2026-12-23 Claude on Google Cloud's Vertex AI from AnthropicSOC 2* (only under the condition noted under this row’s items) Type II ISO 27001* (only under the condition noted under this row’s items) ISO 42001* (only under the condition noted under this row’s items)Applies to every item above: Anthropic's footnote on this row: its marks cover only the model and the containers Anthropic supplies to partners.A restriction below.Unverified after 2026-12-23 Google Cloud from GoogleSOC 2 ISO 27001 HIPAA BAA Government FedRAMP High DPA (marked †, explained in the key)Unverified after 2026-12-26 |
hosted service | observed 2026-09-24 |
Restriction, Claude on Google Cloud's Vertex AI from Anthropic: Government at FedRAMP High, DoD IL4 and DoD IL5. From the vendor’s table, not a reviewed summary: Anthropic's table excludes this row and column; its mark reads "N/A" (the symbol the cell shows). trust.anthropic.com (opens in a new tab), table "Welcome to the Anthropic Trust Center", row "Claude on Google Cloud's Vertex AI *", columns "FedRAMP High", "DoD IL4" and "DoD IL5", read 2026-09-27. | ||||
Data handling, Gemini Enterprise Agent Platform from Google: what the vendor’s pages sayData residency Google's page: data at rest in the location a customer selects stays there, whichever Agent Platform endpoint the customer's request calls. docs.cloud.google.com (opens in a new tab), above the page's first section heading, read 2026-09-27. Under requests submitted to a global endpoint: Google's page: a request to a Gemini Enterprise Agent Platform global endpoint may be handled anywhere Google Cloud operates worldwide, so such requests come with no data residency assurance. docs.cloud.google.com (opens in a new tab), above the page's first section heading, read 2026-09-27. Default retention Google's page: Gemini models that Google publishes cache inputs, outputs and data derived from them by default, kept in memory alone and not at rest, isolated at project level, with a 24-hour lifetime. docs.cloud.google.com (opens in a new tab), Google models › In-memory data caching, read 2026-09-24. Zero-retention option Google's page: for Gemini Enterprise Agent Platform, if a customer's prompts are logged to monitor abuse and it wants zero data retention, it can request an exception to that monitoring. docs.cloud.google.com (opens in a new tab), Customer data retention and achieving zero data retention, in a list, read 2026-09-24. Google's page: on Gemini Enterprise Agent Platform, customer data for its MaaS offering is kept for limited periods in the scenarios the page lists, and zero data retention needs the customer to act in each of those areas. docs.cloud.google.com (opens in a new tab), Customer data retention and achieving zero data retention, read 2026-09-24. Training use Google's page: as the Training Restriction in its Service Specific Terms sets out, Google does not use a customer's data to train any AI/ML model, or to fine-tune one, unless the customer has given permission or instruction beforehand. docs.cloud.google.com (opens in a new tab), Training restriction, read 2026-09-24. Data handling, Claude on Google Cloud's Vertex AI from Anthropic: what the vendor’s pages sayModel provider Anthropic's page: on Google Cloud's Agent Platform and on Amazon Bedrock the data processor is the cloud provider, and readers are pointed to each platform's own documentation on data retention and compliance for the equivalent controls. platform.claude.com (opens in a new tab), above the page's first section heading, read 2026-09-24. Data handling, Google Cloud from Google: what the vendor’s pages sayData residency (marked †, explained in the key) Google's page: section 10.1 of its Cloud DPA says Customer Data may be handled in whatever country Google or a subprocessor keeps facilities in, subject to the location commitments Google makes in its Service Specific Terms and, where they apply, the transfer commitments in Appendix 3. cloud.google.com (opens in a new tab), above the page's first section heading, read 2026-09-27. Default retention (marked †, explained in the key) Google's page: in its Cloud DPA, the customer's instruction is that Google delete all remaining Customer Data, copies included, when the term ends; once a recovery window of as long as 30 days has passed, Google does so as soon as it reasonably can and within 180 days, unless European or other applicable law requires storage, and subject to the deferred-deletion terms of section 6.3. cloud.google.com (opens in a new tab), above the page's first section heading, read 2026-09-27. | ||||
| JuliusBrussee/caveman (opens in a new tab) | A repository with three parts, per its README: a skill telling a coding agent to write tersely, a local proxy between the agent and its model provider that shrinks tool output, logs and diffs before they are sent, and a middleware for an application’s own model calls. | You run it, so you answer these. | repository | observed 2026-10-02 |
| Kong/kong (opens in a new tab) | A general-purpose, open-source API gateway (Apache-2.0) whose AI Gateway capability is a set of plugins on top of the same runtime, semantic caching, multi-LLM routing, prompt guardrails and MCP-related routing, rather than a separate product from a different codebase. | You run it, so you answer these. | repository | observed 2026-09-24 |
| Martian (opens in a new tab) | Classified here as a model router. | MartianNot shown to hold. Martian GatewayNot shown to hold.Unverified after 2026-12-26 |
hosted service | observed 2026-09-06 |
Data handling, Martian Gateway: what the vendor’s pages sayWhere it can run (only on Hosted API) Martian's docs: the Martian Gateway puts 200+ AI models behind a single API, so a customer can pick the model most effective for a use case. docs.withmartian.com (opens in a new tab), Gateway, read 2026-09-27. | ||||
| Not Diamond (opens in a new tab) | A router that chooses which model answers, sold on cost against frontier quality. | Not shown to hold.Unverified after 2026-12-26 |
hosted service | reasoned 2026-09-06 |
Data handling: what the vendor’s pages sayData residency Not Diamond's page: Derived Data sent to Not Diamond is stored on infrastructure that Not Diamond or its service providers operate, with the United States among its locations, along with other places that applicable law, a customer's agreement or the service's configuration permits. www.notdiamond.ai (opens in a new tab), 7. Derived Data, read 2026-09-27. Not Diamond's privacy policy: Not Diamond has its base in the United States, where it generally processes personal information, including on infrastructure run by Not Diamond and by its service providers. www.notdiamond.ai (opens in a new tab), 12. Data Location and International Transfers, read 2026-09-27. Default retention (marked †, explained in the key) Not Diamond's page: Derived Data, API logs and telemetry are kept for as long as 18 months after they are collected, for product development, evaluation, security and the quality of the service. www.notdiamond.ai (opens in a new tab), 13. Data Retention, read 2026-09-27. Zero-retention option (marked †, explained in the key) (only on Enterprise) Not Diamond's page: Enterprise customers may seek a shorter retention period through negotiation. www.notdiamond.ai (opens in a new tab), 13. Data Retention, read 2026-09-27. Training use (only on Enterprise, Pay-as-you-go) Not Diamond's privacy policy: Customer Data is not used by Not Diamond to train third-party foundation models that are generally available. www.notdiamond.ai (opens in a new tab), 5. AI Systems and Model Training, read 2026-09-27. | ||||
| OpenAI API (opens in a new tab) | OpenAI’s own hosted API for its models, configurable per organization with data controls including Zero Data Retention, Modified Abuse Monitoring, and a Business Associate and Healthcare Addendum for PHI processing, per its own documentation (developers.openai.com, as of 2026-09-24). | ISO 27001:2022 ISO 27701:2019 HIPAA BAA* (only on “Private Retention with PSP”) Government* (only under OpenAI's FedRAMP 20x Services and Features card: only the ChatGPT features and API endpoints it lists as Class C (Moderate)) FedRAMP 20x Moderate DPA (marked †, explained in the key)Unverified after 2026-12-23 |
hosted service | observed 2026-09-24 |
Data handling: what the vendor’s pages sayData residency OpenAI's page: data residency controls, set per project, let a customer configure where the infrastructure OpenAI uses to provide its services is located. developers.openai.com (opens in a new tab), Data residency controls, read 2026-09-24. Zero-retention option OpenAI's page: customers it has approved may choose Modified Abuse Monitoring or Zero Data Retention, for an API Organization or for a project. developers.openai.com (opens in a new tab), Data retention controls for abuse monitoring, read 2026-09-24. OpenAI's page: the ZDR variant this section is named for lets OpenAI run automated safety monitoring while the Zero Data Retention protections stay in place. developers.openai.com (opens in a new tab), Data retention controls for abuse monitoring › ZDR with Private Safety Processing, read 2026-09-24. OpenAI's page: as Modified Abuse Monitoring does, Zero Data Retention keeps customer content out of the abuse monitoring logs. developers.openai.com (opens in a new tab), Data retention controls for abuse monitoring › Zero Data Retention, read 2026-09-24. On “Private Retention with PSP”: OpenAI's page: once a customer that has signed an OpenAI Business Associate and Healthcare Addendum has its org ID provisioned with the retention option this section is named for, endpoints that are BAA-eligible can process PHI, and this holds even if the data is retained. developers.openai.com (opens in a new tab), Data retention controls for abuse monitoring › Private Retention with Private Safety Processing (fka Eyes Off), read 2026-09-24. Training use OpenAI's page: from March 1, 2023, OpenAI does not use data a customer sends to the OpenAI API to train or improve its models, unless the customer explicitly opts in to sharing data with OpenAI. developers.openai.com (opens in a new tab), Operations, read 2026-09-24. Model provider OpenAI's page: OpenAI relies on sub-processors to deliver its services. developers.openai.com (opens in a new tab), Data residency controls › Sub-processors and regional request processing, read 2026-09-24. | ||||
| OpenRouter (opens in a new tab) | A hosted gateway in front of many vendors’ models. | SOC 2 Type IIUnverified after 2026-12-26 |
hosted service | reasoned 2026-09-06 |
Data handling: what the vendor’s pages sayData residency (only on Enterprise) OpenRouter's docs: enterprise customers can have requests routed within a region, the EU or the US; once that is turned on for an account, its prompts and completions are handled inside the chosen region and do not go outside it. openrouter.ai (opens in a new tab), Enterprise in-region routing, read 2026-09-27. Training use OpenRouter's docs: if an account opts out of training in its settings, OpenRouter does not send its requests to any provider that trains. openrouter.ai (opens in a new tab), Provider Policies › Training on Prompts, read 2026-09-27. Model provider OpenRouter's docs: every AI provider reachable through OpenRouter sets its own logging and retention policies, and the page describes how a customer can choose which providers may access their data. openrouter.ai (opens in a new tab), above the page's first section heading, read 2026-09-27. Where it can run (marked †, explained in the key) (only on Enterprise) OpenRouter's docs, under enterprise in-region routing: the page tells customers to send EU requests to https://eu.openrouter.ai and US requests to https://us.openrouter.ai. openrouter.ai (opens in a new tab), Enterprise in-region routing, read 2026-09-27. | ||||
| Perplexity (opens in a new tab) | An API platform that puts several vendors’ models behind one key and adds web search to them: a Router API for open-weight models Perplexity hosts (private preview), an Agent API that reaches Anthropic, Google, OpenAI and xAI models with web search, remote MCP servers and a code sandbox, a Search API, and embeddings. | Perplexity APISOC 2 (marked †, explained in the key) ISO 27001:2022 (marked †, explained in the key) Government (marked †, explained in the key) FedRAMP 20x LowUnverified after 2026-12-28 |
hosted service | observed 2026-09-29 |
| Portkey (opens in a new tab) | A hosted gateway whose distinguishing claim is what it records about each call rather than what it routes. | hosted service | reasoned 2026-09-06 | |
Data handling: what the vendor’s pages sayData residency (only on Enterprise, Hybrid) Portkey's docs, for the AI Gateway in the Data Plane: every LLM request stays inside the customer's network perimeter. docs.portkey.ai (opens in a new tab), Core Architecture Components › Data Plane (Your VPC), table "Data Plane (Your VPC)", row "AI Gateway", column "Security Benefit", read 2026-09-27. Default retention (marked †, explained in the key) Portkey's page: personal information is kept only as long as the notice's stated purposes need it, unless law requires or allows longer retention, for example tax or accounting rules or other legal requirements. app.termly.io (opens in a new tab), the page marks up no section headings, read 2026-09-27. Zero-retention option (only on Enterprise) Portkey's enterprise offering docs: retention periods can be set per user, customized to the customer's data storage needs. docs.portkey.ai (opens in a new tab), Custom Retention Periods, read 2026-09-27. Where it can run (only on Enterprise, Hybrid) Portkey's docs, on the hybrid deployment Portkey Enterprise offers: the Data Plane runs inside the customer's VPC, so AI traffic and sensitive LLM data remain in the customer's own environment. docs.portkey.ai (opens in a new tab), above the page's first section heading, in a list, read 2026-09-27. | ||||
| Tool | What it is | Compliance | Type | Read |
|---|---|---|---|---|
| andrewyng/context-hub (opens in a new tab) | A curated set of reference documentation for third-party SDKs and APIs, reached through a CLI (chub) or an MCP server (chub-mcp), with entries annotated and corrected by pull request. | You run it, so you answer these. | repository | observed 2026-09-09 |
| Atlan (opens in a new tab) | A hosted SaaS that connects to an organization’s business systems (the homepage names Slack, Teams and other unspecified systems) and builds what it calls an Enterprise Data Graph unifying metadata, lineage, glossary, quality signals and business semantics, queryable by humans and agents through Slack, Teams, Claude, ChatGPT, MCP, APIs and SQL. | SOC 2 ISO 27001:2022 ISO 27701:2019 ISO 42001:2023Unverified after 2026-12-26 |
hosted service | observed 2026-09-25 |
Data handling: what the vendor’s pages sayModel provider Atlan's page: its subprocessor list describes Open AI as a frontier model provider that processes Customer Data to deliver the services agreed. security.atlan.com (opens in a new tab), Subprocessors, read 2026-09-27. | ||||
| DeepWiki (opens in a new tab) | A hosted product, built by Cognition (Devin’s maker) and explicitly described by the vendor as powered by Devin, that generates conversational, browsable documentation for any public GitHub repository, a per-repository knowledge tier a team can point an agent’s context-gathering at instead of, or alongside, the repository itself. | SOC 2 (marked †, explained in the key) Type II DPA (marked †, explained in the key)Unverified after 2026-12-26 |
hosted service | observed 2026-09-24 |
Data handling: what the vendor’s pages sayDefault retention (marked †, explained in the key) Cognition's page: Cognition holds on to personal information while it is needed to provide its Service, to meet legal obligations, or to protect its own or others' interests. cognition.com (opens in a new tab), 5. Retention, read 2026-09-27. | ||||
| DeusData/codebase-memory-mcp (opens in a new tab) | A native executable with a small verified runtime-asset set (no hosted service, no API key) that the vendor states indexes a codebase into a persistent, local knowledge graph via tree-sitter AST parsing, exposed to agents as 17 MCP tools including semantic search, call-chain and architecture-decision-record queries. | You run it, so you answer these. | repository | observed 2026-09-25 |
| Factory AutoWiki (opens in a new tab) | A feature of Factory that generates a structured wiki for a repository, architecture overviews, module breakdowns, cross-linked pages, and keeps it current as the code changes, rather than a one-time snapshot. | hosted service | observed 2026-09-24 | |
Data handling: what the vendor’s pages sayData residency (marked †, explained in the key) Factory's page: the customer accepts that Factory carries out its main processing in the United States. factory.com (opens in a new tab), 7. Transfers of Customer Personal Data, read 2026-09-27. Factory's page: the personal information Factory collects is held mainly on Amazon Web Services in the US West region, and it processes all of it in the United States as well as at facilities run by the third parties the policy goes on to name. factory.com (opens in a new tab), How and why we use your data › Where do we store the data? Read 2026-09-27. Default retention (marked †, explained in the key) Factory's page: a control listed under data and privacy says customer data is deleted when a customer leaves. trust.factory.ai (opens in a new tab), Controls › Data and privacy, read 2026-09-28. Factory's page: personal information is kept while the user holds an account and is deleted from archives no more than 10 years after the user last used the service, or on terms a separate contract sets. factory.com (opens in a new tab), How and why we use your data › How long do we store your data? Read 2026-09-27. Factory's page: in its DPA's description of the transfer, customer personal data is kept as long as the purpose of processing needs, within applicable law, statute-of-limitations rules and data protection law included. factory.com (opens in a new tab), Exhibit A › 2. Description of the Transfer, table "2. Description of the Transfer", row "Duration of Processing and Retention (or the criteria to determine such period)", column "Description", read 2026-09-27. Factory's page: in its Business Associate Agreement, once the services agreement or the BAA terminates, Factory must give back or destroy the PHI it holds for the customer and keep no copies, subject to an infeasibility exception (section 5.3.2). factory.com (opens in a new tab), Section 5. Term and Termination, read 2026-09-27. Factory's page: when the Services end, Factory will return or delete the customer's Personal Data as the customer chooses and at the customer's cost, unless applicable law requires or permits keeping it longer. factory.com (opens in a new tab), 2. Relationship of the Parties; Processing of Data, read 2026-09-27. On Enterprise: Factory's page: an organization-managed setting sets how many days cloud sessions are kept, from 14 up to 365. docs.factory.ai (opens in a new tab), Org-managed settings schema › Network, sync, and retention, read 2026-09-24. Training use (marked †, explained in the key) (only under Factory's dedicated hosting, with its agreements with Azure) Factory's page: in its entry for Microsoft Azure, Factory says its dedicated hosting and its agreements with Azure mean customer data and IP are not to be used for training either Factory's models or Azure's. trust.factory.ai (opens in a new tab), Subprocessors, read 2026-09-28. Model provider (marked †, explained in the key) Factory's page: the model endpoints Factory uses are dedicated ones on Azure OpenAI Service. trust.factory.ai (opens in a new tab), Subprocessors, read 2026-09-28. Factory's page: Mistral is contracted to supply AI model processing for Factory's customers, beginning no earlier than August 26, 2026. trust.factory.ai (opens in a new tab), Updates › New subprocessor: Mistral, read 2026-09-28. Factory's page: Factory has engaged Together for AI model processing on behalf of its customers, from August 26, 2026 at the earliest. trust.factory.ai (opens in a new tab), Updates › New subprocessor: Together, read 2026-09-28. Factory's page: Snowflake has been contracted to handle AI model processing for Factory's customers, with a start on August 27, 2026 or later. trust.factory.ai (opens in a new tab), Updates › New subprocessor: Snowflake, read 2026-09-28. Factory's page: from October 21, 2026 at the earliest, a date still ahead when the page was read, Databricks is contracted to supply AI model processing for Factory's customers and to hold sensitive internal data. trust.factory.ai (opens in a new tab), Updates › New subprocessor: Databricks, read 2026-09-28. On Enterprise, Custom API keys (BYOK): Factory's page: the allowedBaseUrls org-managed setting names the base URLs custom models are permitted to reach, and can be used to force every piece of custom-model traffic through an LLM gateway the organization has approved. docs.factory.ai (opens in a new tab), Org-managed settings schema › Models and BYOK, read 2026-09-24. Where it can run (marked †, explained in the key) On Enterprise: Factory's page: its Enterprise feature list includes options for deployment at the customer's premises. factory.com (opens in a new tab), Enterprise, in a list, read 2026-09-27. On Pro: Factory's page: its Pro plan, at $20 a month, lists background agents that work in the cloud and on the local machine. factory.com (opens in a new tab), $20, in a list, read 2026-09-27. Telemetry (marked †, explained in the key) (only on Enterprise) Factory's page: in the organization's telemetry settings, exported message content goes only to the customer's own collector, never to Factory's, and with no sink set up it is not recorded at all. docs.factory.ai (opens in a new tab), Org-managed settings schema › Telemetry, read 2026-09-24. | ||||
| Glean (opens in a new tab) | A hosted index over an organization’s own SaaS sources, reached as a service. | SOC 2 ISO 27001:2022 ISO 42001:2023Unverified after 2026-12-27 |
hosted service | reasoned 2026-09-03 |
Data handling: what the vendor’s pages sayModel provider Glean's page: its subprocessor list marks Amazon Web Services as optional, applying only to customers who opt to use AWS. trust.glean.com (opens in a new tab), Subprocessors, read 2026-09-28. | ||||
| HipAI (opens in a new tab) | A hosted SaaS (dashboard at dashboard.gethip.ai) that connects to a customer’s existing structured and unstructured data sources, the vendor names relational databases, internal documents and chat, and automatically builds a schema-free context graph of entities and relationships, which the customer’s own agents and LLMs then query as a tool call, without the customer designing an ontology or running an ETL pipeline first. | Not shown to hold.Unverified after 2026-12-26 |
hosted service | observed 2026-09-24 |
Data handling: what the vendor’s pages sayDefault retention HipAI's privacy policy: Customer Data that HipAI handles as a processor is kept as the applicable agreement with the customer and its DPA provide; the passage states no retention period of its own and defers to that contract. gethip.ai (opens in a new tab), Data Retention, read 2026-09-27. Training use HipAI's privacy policy: HipAI does not train its general-purpose models on Customer Data, the page's term, and uses Customer Data only to provide the Services for the customer that submitted it, not even to profile third parties. gethip.ai (opens in a new tab), How We Use Personal Data › 2.2 Processor Purposes, read 2026-09-27. | ||||
| Lore (opens in a new tab) | A free, currently hosted product (Lore Cloud) that ingests a project’s documents (meeting notes, research, decisions, and files in common document, data and image formats) and makes them queryable by any MCP-compatible AI tool (Claude, ChatGPT, Cursor, Codex, CLI, TUI) with citations back to the original source, distinguished on its own FAQ from AI-memory systems that compress and lose detail. | Not shown to hold. |
hosted service | observed 2026-09-25 |
| open-metadata/OpenMetadata (opens in a new tab) | A self-hostable, open-source (Apache-2.0) platform that ingests technical metadata, lineage, ownership, usage, glossaries and data quality signals from 130+ connectors into a unified knowledge graph, then exposes that graph to humans and agents through an MCP server, semantic search, APIs and SDKs. | You run it, so you answer these. | repository | observed 2026-09-25 |
| upstash/context7 (opens in a new tab) | An MCP server that supplies up-to-date library documentation to a coding agent. | You run it, so you answer these. | repository | reasoned 2026-09-09 |
| Tool | What it is | Compliance | Type | Read |
|---|---|---|---|---|
| ag2ai/ag2 (opens in a new tab) | A multi-agent conversation framework that its GitHub description calls formerly AutoGen, now developed under its own AG2 organization; the GitHub API reports it as a separate repository, not a GitHub fork of microsoft/autogen (checked 2026-09-26). | You run it, so you answer these. | repository | observed 2026-09-24 |
| Amazon Bedrock AgentCore (opens in a new tab) | A set of modular, independently-usable managed services for running agents built with any open-source framework (CrewAI, LangGraph, LlamaIndex, Google ADK, OpenAI Agents SDK, Strands) and any foundation model, in or outside Bedrock: Runtime is a serverless, session-isolated execution environment for the agent process itself; Gateway turns APIs and Lambda functions into MCP-compatible tools; Identity is agent-scoped authentication against existing identity providers; Code Interpreter is a separate isolated sandbox for the agent to execute code in, distinct from Runtime’s own isolation. | hosted service | observed 2026-09-24 | |
Data handling: what the vendor’s pages sayData residency (marked †, explained in the key) AWS's page: customers pick the AWS Regions where their content is stored and may replicate or back it up across more than one, and AWS says it will not move or copy that content out of the chosen Regions without the customer's agreement. aws.amazon.com (opens in a new tab), At AWS, customer trust is our top priority › Commitments, read 2026-09-27. | ||||
| Augment Code (Cosmos) (opens in a new tab) | A platform (branded Cosmos) explicitly positioned around organizational scale rather than one developer’s own editor: it connects agents across code review, test coverage, incident investigation, ticket-to-PR, large projects and security remediation. | Not shown to hold. |
hosted service | observed 2026-09-24 |
| Claude Agent SDK (opens in a new tab) | A harness you import rather than a process you deploy, so the party sitting in front of it is your own program rather than a person typing. | hosted service | reasoned 2026-09-08 | |
| Claude Managed Agents (opens in a new tab) | A hosted service from Anthropic, in beta, that runs an agent for you: it holds the loop that decides the next step, and it supplies the sandbox the agent’s tools run in, either in Anthropic’s cloud or on your own infrastructure through a worker process you run. | SOC 2 (marked †, explained in the key) Type II ISO 27001:2022 (marked †, explained in the key) ISO 42001:2023 (marked †, explained in the key) DPA (marked †, explained in the key)Restrictions below.Unverified after 2026-12-23 |
hosted service | observed 2026-09-09 |
Restriction: HIPAA (under the Claude API arrangement Anthropic calls HIPAA readiness). Anthropic's page: its feature-eligibility table marks Claude Managed Agents as not eligible for HIPAA readiness. platform.claude.com (opens in a new tab), Feature eligibility, table "Feature eligibility", row "Claude Managed Agents", column "HIPAA eligible", read 2026-09-24. Also: Anthropic's page: in its table of which Claude API features are eligible for ZDR and HIPAA readiness, the row for Claude Managed Agents gives as its details that sessions are stateful and transcripts are kept until the customer deletes them, for every Managed Agents sub-feature, "Self-hosted sandboxes" included. platform.claude.com (opens in a new tab), Feature eligibility, table "Feature eligibility", row "Claude Managed Agents", column "Details", read 2026-09-24. Restriction: zero retention. Anthropic's page: its feature-eligibility table marks Claude Managed Agents as not eligible for zero data retention (ZDR). platform.claude.com (opens in a new tab), Feature eligibility, table "Feature eligibility", row "Claude Managed Agents", column "ZDR eligible", read 2026-09-24. Also: Anthropic's page: in its table of which Claude API features are eligible for ZDR and HIPAA readiness, the Claude Managed Agents row says sessions are stateful, with transcripts kept until the customer deletes them, and that this holds for every Managed Agents sub-feature, "Self-hosted sandboxes" included. platform.claude.com (opens in a new tab), Feature eligibility, table "Feature eligibility", row "Claude Managed Agents", column "Details", read 2026-09-24. Restriction: zero retention. Anthropic's page, listing what zero data retention (ZDR) leaves out: Claude Managed Agents keeps state, and its session transcripts remain stored until the customer deletes them. platform.claude.com (opens in a new tab), Zero data retention (ZDR) › What ZDR does not cover, read 2026-09-24. | ||||
Data handling: what the vendor’s pages sayData residency (only on “Self-hosted sandboxes”) Anthropic's page: Anthropic stores the skills the agent uses and what is held in any memory store the session has attached, copying them into the customer's sandbox for that session; changes to memory files made by the agent are synced back to the store. platform.claude.com (opens in a new tab), above the page's first section heading, read 2026-09-27. Zero-retention option Ruled out Ruled out Anthropic's page: its feature-eligibility table marks Claude Managed Agents as not eligible for zero data retention (ZDR). platform.claude.com (opens in a new tab), Feature eligibility, table "Feature eligibility", row "Claude Managed Agents", column "ZDR eligible", read 2026-09-24. Ruled out Anthropic's page: in its table of which Claude API features are eligible for ZDR and HIPAA readiness, the Claude Managed Agents row says sessions are stateful, with transcripts kept until the customer deletes them, and that this holds for every Managed Agents sub-feature, "Self-hosted sandboxes" included. platform.claude.com (opens in a new tab), Feature eligibility, table "Feature eligibility", row "Claude Managed Agents", column "Details", read 2026-09-24. Ruled out Anthropic's page, listing what zero data retention (ZDR) leaves out: Claude Managed Agents keeps state, and its session transcripts remain stored until the customer deletes them. platform.claude.com (opens in a new tab), Zero data retention (ZDR) › What ZDR does not cover, read 2026-09-24. Where it can run Anthropic's page: by default, Managed Agents runs tools and code in cloud sandboxes that Anthropic manages. platform.claude.com (opens in a new tab), above the page's first section heading, read 2026-09-27. (marked †, explained in the key) On “Self-hosted sandboxes”: Anthropic's page: the option Anthropic calls "Self-hosted sandboxes" leaves orchestration with Anthropic and runs tool execution on infrastructure the customer controls, so that the agent's code, its filesystem and its network egress stay inside the customer's environment. platform.claude.com (opens in a new tab), above the page's first section heading, read 2026-09-27. | ||||
| crewAIInc/crewAI (opens in a new tab) | A Python library you import. | You run it, so you answer these. | repository | observed 2026-09-03 |
| google/adk-python (opens in a new tab) | A code-first Python toolkit from Google for constructing, checking and shipping agents, positioned by its own maintainers as covering the checking step in the same package rather than as a separate purchase: its docs list an eval workflow (test files, a CLI, a web UI for reviewing runs) alongside the construction API. | You run it, so you answer these. | repository | observed 2026-09-24 |
| langchain-ai/langgraph (opens in a new tab) | A library you import into your own process, in Python or TypeScript. | You run it, so you answer these. | repository | observed 2026-09-03 |
| mastra-ai/mastra (opens in a new tab) | A TypeScript framework you import, shipped as one bundle rather than assembled parts, deployable as a standalone server. | You run it, so you answer these. | repository | observed 2026-09-03 |
| Microsoft Foundry Agent Service (opens in a new tab) | Microsoft’s managed platform for constructing, running and scaling agents, spanning several capabilities under one name: an Agent Runtime that hosts and scales prompt agents and hosted agents, which package a team’s own code; Toolboxes sharing tools (web search, file search, code execution, MCP servers, custom functions) across agents through one managed MCP endpoint; built-in observability with tracing, metrics and scored runs plus a preview optimizer that rewrites an agent’s own instructions, skills, tool descriptions and model choice based on those scored runs, a scoring-and-improvement loop built into an orchestration platform; and a publishing surface that versions agents and registers them centrally, distinct from a self-run marketplace with a vendoring step. | Microsoft Foundry Agent ServiceISO 27001 (marked †, explained in the key) HIPAA BAA (marked †, explained in the key) HITRUST (marked †, explained in the key) GDPR (marked †, explained in the key) DPA (marked †, explained in the key)Unverified after 2026-12-23 AzureISO 27001 HIPAA BAA HITRUST (marked †, explained in the key) Government FedRAMP High GDPR (marked †, explained in the key) DPA (marked †, explained in the key)Unverified after 2026-12-23 |
hosted service | observed 2026-09-24 |
Data handling, Microsoft Foundry Agent Service: what the vendor’s pages sayWhere it can run Microsoft's page: Foundry Agent Service is offered as a managed platform on which AI agents are built, deployed and scaled. learn.microsoft.com (opens in a new tab), above the page's first section heading, read 2026-09-27. | ||||
| microsoft/agent-framework (opens in a new tab) | A library you import, in .NET and Python. | You run it, so you answer these. | repository | observed 2026-09-03 |
| openai/openai-agents-python (opens in a new tab) | A lightweight Python framework for building multi-agent workflows: agents, handoffs between them, and guardrails, provider-agnostic despite the vendor. | You run it, so you answer these. | repository | observed 2026-09-24 |
| pydantic/pydantic-ai (opens in a new tab) | A typed Python agent framework from the team behind Pydantic, positioned around type safety end to end across models, tools and structured output, rather than around a particular orchestration topology. | You run it, so you answer these. | repository | observed 2026-09-24 |
| run-llama/llama_index (opens in a new tab) | Originally an agent-and-retrieval framework; GitHub’s own description of the project as of this read reframes it around ingesting and indexing documents, with agent construction now one capability inside that broader positioning rather than the project’s own headline. | You run it, so you answer these. | repository | observed 2026-09-24 |
| temporalio/temporal (opens in a new tab) | A server you run, plus per-language client SDKs you import. | You run it, so you answer these. | repository | observed 2026-09-03 |
| Vertex AI Agent Engine (Gemini Enterprise Agent Platform) (opens in a new tab) | Google’s managed agent runtime, formerly branded standalone as Vertex AI Agent Engine; its former URL now redirects into the documentation for the renamed Gemini Enterprise Agent Platform. | Gemini Enterprise Agent PlatformSOC 2 ISO 27001 HIPAA* (only under requests to a locational endpoint. marked †, explained in the key) GDPR* (only under requests to a locational endpoint. marked †, explained in the key) DPA (marked †, explained in the key)Unverified after 2026-12-23 Google CloudSOC 2 ISO 27001 HIPAA BAA Government FedRAMP High DPA (marked †, explained in the key)Unverified after 2026-12-26 |
hosted service | observed 2026-09-24 |
Data handling, Gemini Enterprise Agent Platform: what the vendor’s pages sayData residency Google's page: data at rest in the location a customer selects stays there, whichever Agent Platform endpoint the customer's request calls. docs.cloud.google.com (opens in a new tab), above the page's first section heading, read 2026-09-27. Under requests submitted to a global endpoint: Google's page: a request to a Gemini Enterprise Agent Platform global endpoint may be handled anywhere Google Cloud operates worldwide, so such requests come with no data residency assurance. docs.cloud.google.com (opens in a new tab), above the page's first section heading, read 2026-09-27. Default retention Google's page: Gemini models that Google publishes cache inputs, outputs and data derived from them by default, kept in memory alone and not at rest, isolated at project level, with a 24-hour lifetime. docs.cloud.google.com (opens in a new tab), Google models › In-memory data caching, read 2026-09-24. Zero-retention option Google's page: for Gemini Enterprise Agent Platform, if a customer's prompts are logged to monitor abuse and it wants zero data retention, it can request an exception to that monitoring. docs.cloud.google.com (opens in a new tab), Customer data retention and achieving zero data retention, in a list, read 2026-09-24. Google's page: on Gemini Enterprise Agent Platform, customer data for its MaaS offering is kept for limited periods in the scenarios the page lists, and zero data retention needs the customer to act in each of those areas. docs.cloud.google.com (opens in a new tab), Customer data retention and achieving zero data retention, read 2026-09-24. Training use Google's page: as the Training Restriction in its Service Specific Terms sets out, Google does not use a customer's data to train any AI/ML model, or to fine-tune one, unless the customer has given permission or instruction beforehand. docs.cloud.google.com (opens in a new tab), Training restriction, read 2026-09-24. Data handling, Google Cloud: what the vendor’s pages sayData residency (marked †, explained in the key) Google's page: section 10.1 of its Cloud DPA says Customer Data may be handled in whatever country Google or a subprocessor keeps facilities in, subject to the location commitments Google makes in its Service Specific Terms and, where they apply, the transfer commitments in Appendix 3. cloud.google.com (opens in a new tab), above the page's first section heading, read 2026-09-27. Default retention (marked †, explained in the key) Google's page: in its Cloud DPA, the customer's instruction is that Google delete all remaining Customer Data, copies included, when the term ends; once a recovery window of as long as 30 days has passed, Google does so as soon as it reasonably can and within 180 days, unless European or other applicable law requires storage, and subject to the deferred-deletion terms of section 6.3. cloud.google.com (opens in a new tab), above the page's first section heading, read 2026-09-27. | ||||
| Tool | What it is | Compliance | Type | Read |
|---|---|---|---|---|
| aaif-goose/goose (opens in a new tab) | An open-source, model-agnostic agent that installs, executes, edits and tests code, extensible through MCP. | You run it, so you answer these. | repository | observed 2026-09-24 |
| Aider-AI/aider (opens in a new tab) | A terminal coding agent that edits files in a local git repository and commits its own changes, driven from the command line with the user’s own model key. | You run it, so you answer these. | repository | observed 2026-09-24 |
| Amazon Q Developer (opens in a new tab) | An AWS-side coding assistant with an editor plugin, a CLI and a hosted surface. | editor extension | observed 2026-09-03 | |
Data handling: what the vendor’s pages sayData residency (marked †, explained in the key) AWS's page: customers pick the AWS Regions where their content is stored and may replicate or back it up across more than one, and AWS says it will not move or copy that content out of the chosen Regions without the customer's agreement. aws.amazon.com (opens in a new tab), At AWS, customer trust is our top priority › Commitments, read 2026-09-27. | ||||
| Amp (opens in a new tab) | A coding agent with both an interactive mode (CLI, web, macOS/iOS) and an unattended cloud mode called Orbs that keeps working after the person who started it stops watching, per the vendor’s own manual (ampcode.com/docs, read 2026-09-23). | SOC 2 Type IIUnverified after 2026-12-26 |
hosted service | observed 2026-09-23 |
Data handling: what the vendor’s pages sayData residency Amp's page: Amp's primary infrastructure sits in the US on Google Cloud Platform; it serves ampcode.com, holds user and thread data, partial code data included though not an entire codebase, and proxies LLM inference to the other providers it lists. ampcode.com (opens in a new tab), Infrastructure & Service Providers, in a list, read 2026-09-27. Amp's page: none of Amp's infrastructure or service providers is based in China. ampcode.com (opens in a new tab), Infrastructure & Service Providers, read 2026-09-27. Default retention Amp's page: once a thread is deliberately deleted, all of that thread's data is gone within 30 days. ampcode.com (opens in a new tab), Data Security & Retention › Thread Data, read 2026-09-27. On Enterprise: Amp's page: threads in an Enterprise workspace, and the user data tied to them, are deleted only once the enterprise's agreement with Amp comes to an end. ampcode.com (opens in a new tab), Data Security & Retention › Thread Data, in a list, read 2026-09-27. On Enterprise: Amp's security page: audit logs are kept for at least 30 days. ampcode.com (opens in a new tab), Audit Logging, read 2026-09-27. Zero-retention option Amp's page: every Amp user can use Minimal Data Retention; for requests that go over provider connections Amp manages and bills in Amp credits, Amp's contracts with the major model providers confine retention to a few narrow exceptions for safety, abuse and legal needs. ampcode.com (opens in a new tab), Data Security & Retention › Minimal Data Retention, read 2026-09-27. Training use Amp's page: Amp and its subprocessors do not train models on a user's data, unless that user has explicitly chosen to opt in. ampcode.com (opens in a new tab), Model Training, read 2026-09-27. On Enterprise: Amp's security page: for workspaces on the Amp Enterprise plan, paid or trial, model training can never be turned on. ampcode.com (opens in a new tab), Model Training, read 2026-09-27. Model provider Amp's page: in its provider list, most of Amp's LLM inference currently runs on Claude models from Anthropic, hosted on Anthropic's servers in the US. ampcode.com (opens in a new tab), Infrastructure & Service Providers, in a list, read 2026-09-27. Amp's page: models from OpenAI, on OpenAI's servers in the US, may serve part of Amp's LLM inference. ampcode.com (opens in a new tab), Infrastructure & Service Providers, in a list, read 2026-09-27. | ||||
| anomalyco/opencode (opens in a new tab) | A terminal coding agent, installed as a binary or an npm package. | You run it, so you answer these. | repository | observed 2026-09-03 |
| Antigravity (opens in a new tab) | Google’s command center for driving several local coding agents at once; not itself a hosted agent, and its Remote Control reaches machines the buyer already owns (laptops, servers, desktops) rather than compute Google supplies. | Not shown to hold. |
editor | observed 2026-09-23 |
| Bolt (opens in a new tab) | A hosted, browser-based builder that generates and runs a full-stack web application from a prompt, executing the generated code in-browser via StackBlitz’s WebContainers technology rather than a server-side sandbox, a different execution shape from Replit Agent or v0, which run generated code on servers their vendors operate. | Not shown to hold. |
hosted service | observed 2026-09-24 |
| ChatGPT (opens in a new tab) | A hosted assistant reached in a browser, a desktop application and mobile clients. | ISO 42001:2023* (only on ChatGPT Edu, ChatGPT Enterprise. marked †, explained in the key) Government* (only on ChatGPT Enterprise. only under OpenAI's FedRAMP 20x Services and Features card: only the ChatGPT features and API endpoints it lists as Class C (Moderate)) FedRAMP 20x Moderate DPA (marked †, explained in the key)Unverified after 2026-12-29 |
chat assistant | observed 2026-09-23 |
| Claude Code (opens in a new tab) | A coding agent from Anthropic that you run in a terminal or an editor, among four surfaces: you state work in words and it holds the conversation, chooses which tools to call, runs commands and manages its own context until the work is done or it stops to ask. | SOC 2 (marked †, explained in the key) Type II ISO 27001:2022 (marked †, explained in the key) ISO 42001:2023 (marked †, explained in the key) HIPAA BAA* (only on Commercial, Enterprise. only under Claude Code with ZDR enabled; Claude Code with ZDR enabled, on a qualified account) DPA (marked †, explained in the key)Restrictions below.Unverified after 2026-12-23 |
terminal agent | reasoned 2026-09-03 |
Restriction: HIPAA (under the Claude API arrangement Anthropic calls HIPAA readiness). Anthropic's page: Claude Code falls outside HIPAA readiness. platform.claude.com (opens in a new tab), HIPAA readiness › What HIPAA readiness does not cover, read 2026-09-24. Restriction: HIPAA (under the Claude API arrangement Anthropic calls HIPAA readiness, on Commercial). Anthropic's page: for reaching Covered Models in configurations the BAA covers, it notes that Claude Code is not an Eligible Service for an API organization that is HIPAA-ready. support.claude.com (opens in a new tab), How to access Covered Models under the BAA, in a list, read 2026-09-24. | ||||
Data handling: what the vendor’s pages sayData residency (only on Hosted on Anthropic, Hosted on Azure) Anthropic's page, in the Microsoft Foundry row of its table, under encryption at rest: the answer turns on the hosting option; with Hosted on Azure, prompts and completions stay within Azure and only usage metadata, plus content Anthropic's safety systems flag, goes out to Anthropic, while with Hosted on Anthropic, requests go to Anthropic infrastructure that uses AES-256 disk encryption. code.claude.com (opens in a new tab), Local Claude Code: Data flow and dependencies, table "Local Claude Code: Data flow and dependencies", row "Microsoft Foundry", column "Encryption at rest", read 2026-09-24. Default retention Under transcripts shared through /feedback, /bug or /share: Anthropic's page: Claude Code transcripts sent through /feedback, or through /bug and /share, which use the same reporting path, are kept for 5 years. code.claude.com (opens in a new tab), Data policies › Feedback using the /feedback command, read 2026-09-24. On Commercial, Enterprise: Anthropic's page, for Claude Code's commercial users, a group whose list includes Enterprise: the standard retention period is 30 days. code.claude.com (opens in a new tab), Data policies › Data retention, in a list, read 2026-09-24. On Consumer: Anthropic's page: for Consumer users (the Free, Pro and Max plans) who let their data be used to improve models, Claude Code data is kept for 5 years, for model development and safety improvement. code.claude.com (opens in a new tab), Data policies › Data retention, in a list, read 2026-09-24. On Consumer: Anthropic's page: for Consumer users (the Free, Pro and Max plans) who do not allow their data to be used for model improvement, Claude Code data is kept for 30 days. code.claude.com (opens in a new tab), Data policies › Data retention, in a list, read 2026-09-24. Zero-retention option On Commercial, Enterprise: Anthropic's page, on what ZDR covers: ZDR extends to Claude Code when it runs on API keys that come from a Commercial organization, one under Anthropic's Commercial Terms of Service rather than a consumer Claude account, or when it is used through Claude Enterprise with ZDR turned on. platform.claude.com (opens in a new tab), Zero data retention (ZDR) › What ZDR covers, read 2026-09-24. On Enterprise: Anthropic's page, for Claude Code's commercial users: zero data retention (ZDR) is open only to accounts that qualify, for Claude Code used on Claude for Enterprise; it is not part of the standard Enterprise plan, and Anthropic's account team turns it on organization by organization once eligibility is confirmed. code.claude.com (opens in a new tab), Data policies › Data retention, in a list, read 2026-09-24. Training use On Commercial, Enterprise: Anthropic's page, for commercial users, a group whose list includes Enterprise: code or prompts that reach Claude Code on commercial terms are not used by Anthropic to train generative models, unless the customer has opted to give its data for model improvement, as in the Developer Partner Program. code.claude.com (opens in a new tab), Data policies › Data training policy, read 2026-09-24. On Consumer: Anthropic's page, for consumer users: when the setting that lets data be used to improve future models is on, Anthropic trains new models on the data of Free, Pro and Max accounts, their use of Claude Code included. code.claude.com (opens in a new tab), Data policies › Data training policy, read 2026-09-24. (marked †, explained in the key) On Consumer: Anthropic's page: Anthropic may train and improve its AI models on a user's Inputs and Outputs unless the user opts out in account settings. www.anthropic.com (opens in a new tab), 2. Uses of Personal Data Permitted Under Applicable Data Protection Laws, read 2026-09-27. Model provider Anthropic's page: to reach the model, Claude Code sends data across the network, all prompts and model outputs among it, encrypted in transit with TLS 1.2 or later. code.claude.com (opens in a new tab), Local Claude Code: Data flow and dependencies, read 2026-09-24. On Hosted on Azure: Anthropic's page: for Hosted on Azure deployments, the only data Anthropic receives is usage metadata and content that its safety systems flag. code.claude.com (opens in a new tab), Local Claude Code: Data flow and dependencies, table "Local Claude Code: Data flow and dependencies", row "Microsoft Foundry", column "Encryption at rest", read 2026-09-24. Where it can run Anthropic's page, in its section on local Claude Code's data flow: Claude Code runs on the local machine. code.claude.com (opens in a new tab), Local Claude Code: Data flow and dependencies, read 2026-09-24. Telemetry Anthropic's page: Claude Code's metrics, covering latency, reliability and how it is used, go over TLS both to Anthropic and to logging infrastructure run by third parties. code.claude.com (opens in a new tab), Telemetry services, read 2026-10-01. Anthropic's page: Claude Code's error reports, carrying stack traces and the messages of errors raised inside its own code, go over TLS to an error-tracking service that a third party runs. A few lines on, the page limits this: error reporting is active only if the user has signed in on a Pro or Max subscription, the Claude Code version in use is 2.1.198 or later, the connection goes straight to the Claude API, and the user's organization has no HIPAA or zero data retention agreement. code.claude.com (opens in a new tab), Telemetry services, read 2026-10-01. Anthropic's page: Claude Code sends operational telemetry of two kinds, usage metrics and error reports. A few lines on, the page limits the error reports: error reporting is active only if the user has signed in on a Pro or Max subscription, the Claude Code version in use is 2.1.198 or later, the connection goes straight to the Claude API, and the user's organization has no HIPAA or zero data retention agreement. code.claude.com (opens in a new tab), Telemetry services, read 2026-09-24. Anthropic's page: each of the two kinds of telemetry can be switched off on its own through environment variables the page lists, and setting CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC turns off all non-essential traffic together. code.claude.com (opens in a new tab), Telemetry services, read 2026-09-24. Anthropic's page: WebFetch's domain safety check and session quality surveys are exceptions to the provider-based defaults and run whichever provider is in use. code.claude.com (opens in a new tab), Default behaviors by API provider, read 2026-09-24. Under running Claude Code through Amazon Bedrock, Google Cloud's Agent Platform, Microsoft Foundry or Claude Platform on AWS: Anthropic's page: on Microsoft Foundry, Amazon Bedrock, Claude Platform on AWS or Google Cloud's Agent Platform, Claude Code turns off telemetry, error reporting and bug reporting by default. code.claude.com (opens in a new tab), Default behaviors by API provider, read 2026-09-24. | ||||
| cline/cline (opens in a new tab) | A coding agent shipped as several front ends onto one core: a VS Code / JetBrains extension, an installable CLI, a desktop app, and an SDK. | You run it, so you answer these. | repository | observed 2026-09-24 |
| Codex cloud (opens in a new tab) | OpenAI’s hosted, asynchronous counterpart to the openai/codex CLI: tasks run in parallel cloud environments started from chatgpt.com, GitHub, GitLab, Linear or Slack, continue while the person who started them does something else, and end with a diff to review and a pull request to open. | DPA (marked †, explained in the key)Unverified after 2026-12-23 |
hosted service | observed 2026-09-23 |
Data handling: what the vendor’s pages sayWhere it can run OpenAI's page: among the parts of a rollout to give an owner, it lists Codex cloud, covering hosted environments, connections to repositories and the runtime policy for the cloud. learn.chatgpt.com (opens in a new tab), Step 1: Assign owners and choose a rollout, in a list, read 2026-09-24. | ||||
| Copilot cloud agent (opens in a new tab) | GitHub Copilot’s hosted, asynchronous surface, separate from its editor extension, chat surface and CLI: a person assigns it a whole task. | hosted service | observed 2026-09-23 | |
Data handling, GitHub Copilot: what the vendor’s pages sayData residency (marked †, explained in the key) GitHub's page: personal information is stored and processed by GitHub in many places: the user's own region, the United States, plus other countries where GitHub or a subsidiary, affiliate or subprocessor of it operates. docs.github.com (opens in a new tab), International data transfers, read 2026-09-27. Default retention (marked †, explained in the key) GitHub's page: GitHub keeps personal information while the account is active, and beyond that for as long as contracts, legal requirements, dispute resolution or enforcing agreements need it. docs.github.com (opens in a new tab), Security and Retention, read 2026-09-27. Training use (only on Copilot Business, Enterprise) GitHub's page: data from Copilot Business or Enterprise customers is not used by GitHub to train AI models. copilot.github.trust.page (opens in a new tab), FAQ, read 2026-09-29. Model provider On Custom API keys (BYOK): GitHub's page: enabling custom models lets teams use the LLM providers the organization prefers in IDEs, Copilot Chat and Copilot CLI. docs.github.com (opens in a new tab), above the page's first section heading, read 2026-09-24. On GitHub Enterprise Cloud with data residency: GitHub's page: if an enterprise is on GitHub Enterprise Cloud with data residency in the US, it can enable a policy under which users on its Copilot plan may use only models that hold FedRAMP Moderate certification. docs.github.com (opens in a new tab), Who can use this feature? Read 2026-09-24. Where it can run On Copilot cloud agent: GitHub's page: Copilot cloud agent, while on a coding task, gets a short-lived development environment of its own, powered by GitHub Actions, in which it can explore and change code and run automated tests and linters. docs.github.com (opens in a new tab), Overview of Copilot cloud agent, read 2026-09-27. On Custom API keys (BYOK): GitHub's page: the Enable custom models policy has to be turned on by an enterprise owner first. docs.github.com (opens in a new tab), Prerequisites, read 2026-09-24. | ||||
| Cursor (opens in a new tab) | An editor with an agent built into it, which is why it sits on the line between something a person sits in front of and the thing holding the loop. | SOC 2 (marked †, explained in the key) Type II ISO 27001:2022 (marked †, explained in the key) ISO 42001:2023 (marked †, explained in the key) HIPAA BAA* (only on Enterprise. only under Privacy Mode enabled and locked organization-wide. marked †, explained in the key) DPA (marked †, explained in the key)A restriction below.Unverified after 2026-12-23 |
editor | observed 2026-09-03 |
Restriction: zero retention (on Custom API keys (BYOK)). Cursor's page: its Zero Data Retention policy is not in effect for requests made with a customer's own API keys. cursor.com (opens in a new tab), Does Cursor's Zero Data Retention policy apply when using my own API keys? Read 2026-09-24. | ||||
Data handling: what the vendor’s pages sayData residency Cursor's page: Cursor's infrastructure sits mainly in an AWS US region, and some services where latency matters are in Europe and Singapore. trust.cursor.com (opens in a new tab), Subprocessors, read 2026-09-27. Zero-retention option (marked †, explained in the key) Under Privacy Mode: Cursor's page, if a user turns on Privacy Mode among Cursor's settings: Cursor has agreements providing zero data retention (ZDR) with all of its providers, and the providers of AI models do not store the user's data or train on it. The page then qualifies this: subject to their own policies, providers, Cursor among them, may run risk classifiers, and data that trips an abuse detector may be kept for investigation and deleted under their retention policies; a model without ZDR is marked as such or can be enabled only once an admin opts in. cursor.com (opens in a new tab), the page marks up no section headings, in a list, read 2026-09-27. Ruled out On Custom API keys (BYOK): Cursor's page: its Zero Data Retention policy is not in effect for requests made with a customer's own API keys. cursor.com (opens in a new tab), Does Cursor's Zero Data Retention policy apply when using my own API keys? Read 2026-09-24. Training use (marked †, explained in the key) (only under Privacy Mode) Cursor's page, on how data handling follows the privacy settings a user picks: if Privacy Mode is turned on in Cursor's settings, Cursor does not use Customer Data for training. cursor.com (opens in a new tab), the page marks up no section headings, in a list, read 2026-09-27. Model provider (marked †, explained in the key) (marked †, explained in the key) Cursor's page: when AI features are in use, it passes code context and prompts on to providers of language models, for example OpenAI, Anthropic and Google. cursor.com (opens in a new tab), Two data flows › 1. LLM requests, read 2026-09-27. On Custom API keys (BYOK): Cursor's page: with a customer's own API keys in place, Tab completion still runs on Cursor's built-in models. cursor.com (opens in a new tab), What providers are supported? Read 2026-09-24. On Custom API keys (BYOK): Cursor's page: if a team depends on Zero Data Retention, it should rely on Cursor's built-in models rather than its own API keys. cursor.com (opens in a new tab), Does Cursor's Zero Data Retention policy apply when using my own API keys? Read 2026-09-24. Where it can run On Custom API keys (BYOK): Cursor's page: Custom API keys are usable with chat models only. cursor.com (opens in a new tab), What providers are supported? Read 2026-09-24. (marked †, explained in the key) On “Self-Hosted Machines”: Cursor's page: under the option this page describes, the tools a Cloud Agent uses run on a machine the customer manages. cursor.com (opens in a new tab), above the page's first section heading, read 2026-09-28. (marked †, explained in the key) On “Self-Hosted Machines”: Cursor's page, on cloud agents the customer hosts: while a run is under way, the worker passes Cursor what the agent needs, for example diffs, file contents, screenshots, terminal output, routing metadata and results from local MCP servers. cursor.com (opens in a new tab), What leaves your network, read 2026-09-28. | ||||
| Cursor Cloud Agents (opens in a new tab) | Cursor’s hosted, asynchronous mode, separate from the Cursor editor: a task is handed to it and left running in a cloud VM rather than on the local machine. | CursorSOC 2 (marked †, explained in the key) Type II ISO 27001:2022 (marked †, explained in the key) ISO 42001:2023 (marked †, explained in the key) HIPAA BAA* (only on Enterprise. only under Privacy Mode enabled and locked organization-wide. marked †, explained in the key) DPA (marked †, explained in the key)A restriction below.Unverified after 2026-12-23 |
hosted service | observed 2026-09-23 |
Restriction, Cursor: zero retention (on Custom API keys (BYOK)). Cursor's page: its Zero Data Retention policy is not in effect for requests made with a customer's own API keys. cursor.com (opens in a new tab), Does Cursor's Zero Data Retention policy apply when using my own API keys? Read 2026-09-24. | ||||
Data handling, Cursor: what the vendor’s pages sayData residency Cursor's page: Cursor's infrastructure sits mainly in an AWS US region, and some services where latency matters are in Europe and Singapore. trust.cursor.com (opens in a new tab), Subprocessors, read 2026-09-27. Zero-retention option (marked †, explained in the key) Under Privacy Mode: Cursor's page, if a user turns on Privacy Mode among Cursor's settings: Cursor has agreements providing zero data retention (ZDR) with all of its providers, and the providers of AI models do not store the user's data or train on it. The page then qualifies this: subject to their own policies, providers, Cursor among them, may run risk classifiers, and data that trips an abuse detector may be kept for investigation and deleted under their retention policies; a model without ZDR is marked as such or can be enabled only once an admin opts in. cursor.com (opens in a new tab), the page marks up no section headings, in a list, read 2026-09-27. Ruled out On Custom API keys (BYOK): Cursor's page: its Zero Data Retention policy is not in effect for requests made with a customer's own API keys. cursor.com (opens in a new tab), Does Cursor's Zero Data Retention policy apply when using my own API keys? Read 2026-09-24. Training use (marked †, explained in the key) (only under Privacy Mode) Cursor's page, on how data handling follows the privacy settings a user picks: if Privacy Mode is turned on in Cursor's settings, Cursor does not use Customer Data for training. cursor.com (opens in a new tab), the page marks up no section headings, in a list, read 2026-09-27. Model provider (marked †, explained in the key) (marked †, explained in the key) Cursor's page: when AI features are in use, it passes code context and prompts on to providers of language models, for example OpenAI, Anthropic and Google. cursor.com (opens in a new tab), Two data flows › 1. LLM requests, read 2026-09-27. On Custom API keys (BYOK): Cursor's page: with a customer's own API keys in place, Tab completion still runs on Cursor's built-in models. cursor.com (opens in a new tab), What providers are supported? Read 2026-09-24. On Custom API keys (BYOK): Cursor's page: if a team depends on Zero Data Retention, it should rely on Cursor's built-in models rather than its own API keys. cursor.com (opens in a new tab), Does Cursor's Zero Data Retention policy apply when using my own API keys? Read 2026-09-24. Where it can run On Custom API keys (BYOK): Cursor's page: Custom API keys are usable with chat models only. cursor.com (opens in a new tab), What providers are supported? Read 2026-09-24. (marked †, explained in the key) On “Self-Hosted Machines”: Cursor's page: under the option this page describes, the tools a Cloud Agent uses run on a machine the customer manages. cursor.com (opens in a new tab), above the page's first section heading, read 2026-09-28. (marked †, explained in the key) On “Self-Hosted Machines”: Cursor's page, on cloud agents the customer hosts: while a run is under way, the worker passes Cursor what the agent needs, for example diffs, file contents, screenshots, terminal output, routing metadata and results from local MCP servers. cursor.com (opens in a new tab), What leaves your network, read 2026-09-28. | ||||
| Devin Cloud (opens in a new tab) | A hosted agent that takes a task, a ticket, a Slack mention, an on-call page, clones the target repository, plans the change and carries it out, then works review feedback and CI results on the pull request until it is approved and merged. | DevinSOC 2 (marked †, explained in the key) Type II DPA (marked †, explained in the key)Unverified after 2026-12-26 |
hosted service | observed 2026-09-23 |
Data handling, Devin: what the vendor’s pages sayDefault retention Cognition's page: data processed through Devin is kept by Cognition only while the customer relationship lasts, unless something else has been specified. docs.devin.ai (opens in a new tab), Privacy & Intellectual Property, read 2026-09-27. Training use Cognition's page: as a default, customer data and code are not used by Cognition to train its models. docs.devin.ai (opens in a new tab), Privacy & Intellectual Property, read 2026-09-27. Where it can run On Outposts: Cognition's page: Devin Outposts can be used on every Pro, Max and Teams account. docs.devin.ai (opens in a new tab), Limitations, read 2026-09-27. On Enterprise: Cognition's page: for Enterprise customers whose deployment is dedicated, or at the customer's premises, all customer data stays inside the customer's tenant. docs.devin.ai (opens in a new tab), Privacy & Intellectual Property, read 2026-09-27. | ||||
| Devin Desktop (opens in a new tab) | An editor the vendor frames as an agent command center: one Kanban-style interface driving local agents and opening sessions in Devin Cloud, rather than a hosted agent itself. | DevinSOC 2 (marked †, explained in the key) Type II DPA (marked †, explained in the key)Unverified after 2026-12-26 |
editor | observed 2026-09-23 |
Data handling, Devin: what the vendor’s pages sayDefault retention Cognition's page: data processed through Devin is kept by Cognition only while the customer relationship lasts, unless something else has been specified. docs.devin.ai (opens in a new tab), Privacy & Intellectual Property, read 2026-09-27. Training use Cognition's page: as a default, customer data and code are not used by Cognition to train its models. docs.devin.ai (opens in a new tab), Privacy & Intellectual Property, read 2026-09-27. Where it can run On Outposts: Cognition's page: Devin Outposts can be used on every Pro, Max and Teams account. docs.devin.ai (opens in a new tab), Limitations, read 2026-09-27. On Enterprise: Cognition's page: for Enterprise customers whose deployment is dedicated, or at the customer's premises, all customer data stays inside the customer's tenant. docs.devin.ai (opens in a new tab), Privacy & Intellectual Property, read 2026-09-27. | ||||
| Factory (opens in a new tab) | A hosted, multi-agent software-delivery platform: an agent the vendor calls a Droid is given a task from the terminal, an IDE, a browser, or Slack, and the result is a code change to review. | hosted service | observed 2026-09-23 | |
Data handling, Factory: what the vendor’s pages sayData residency (marked †, explained in the key) Factory's page: the customer accepts that Factory carries out its main processing in the United States. factory.com (opens in a new tab), 7. Transfers of Customer Personal Data, read 2026-09-27. Factory's page: the personal information Factory collects is held mainly on Amazon Web Services in the US West region, and it processes all of it in the United States as well as at facilities run by the third parties the policy goes on to name. factory.com (opens in a new tab), How and why we use your data › Where do we store the data? Read 2026-09-27. Default retention (marked †, explained in the key) Factory's page: a control listed under data and privacy says customer data is deleted when a customer leaves. trust.factory.ai (opens in a new tab), Controls › Data and privacy, read 2026-09-28. Factory's page: personal information is kept while the user holds an account and is deleted from archives no more than 10 years after the user last used the service, or on terms a separate contract sets. factory.com (opens in a new tab), How and why we use your data › How long do we store your data? Read 2026-09-27. Factory's page: in its DPA's description of the transfer, customer personal data is kept as long as the purpose of processing needs, within applicable law, statute-of-limitations rules and data protection law included. factory.com (opens in a new tab), Exhibit A › 2. Description of the Transfer, table "2. Description of the Transfer", row "Duration of Processing and Retention (or the criteria to determine such period)", column "Description", read 2026-09-27. Factory's page: in its Business Associate Agreement, once the services agreement or the BAA terminates, Factory must give back or destroy the PHI it holds for the customer and keep no copies, subject to an infeasibility exception (section 5.3.2). factory.com (opens in a new tab), Section 5. Term and Termination, read 2026-09-27. Factory's page: when the Services end, Factory will return or delete the customer's Personal Data as the customer chooses and at the customer's cost, unless applicable law requires or permits keeping it longer. factory.com (opens in a new tab), 2. Relationship of the Parties; Processing of Data, read 2026-09-27. On Enterprise: Factory's page: an organization-managed setting sets how many days cloud sessions are kept, from 14 up to 365. docs.factory.ai (opens in a new tab), Org-managed settings schema › Network, sync, and retention, read 2026-09-24. Training use (marked †, explained in the key) (only under Factory's dedicated hosting, with its agreements with Azure) Factory's page: in its entry for Microsoft Azure, Factory says its dedicated hosting and its agreements with Azure mean customer data and IP are not to be used for training either Factory's models or Azure's. trust.factory.ai (opens in a new tab), Subprocessors, read 2026-09-28. Model provider (marked †, explained in the key) Factory's page: the model endpoints Factory uses are dedicated ones on Azure OpenAI Service. trust.factory.ai (opens in a new tab), Subprocessors, read 2026-09-28. Factory's page: Mistral is contracted to supply AI model processing for Factory's customers, beginning no earlier than August 26, 2026. trust.factory.ai (opens in a new tab), Updates › New subprocessor: Mistral, read 2026-09-28. Factory's page: Factory has engaged Together for AI model processing on behalf of its customers, from August 26, 2026 at the earliest. trust.factory.ai (opens in a new tab), Updates › New subprocessor: Together, read 2026-09-28. Factory's page: Snowflake has been contracted to handle AI model processing for Factory's customers, with a start on August 27, 2026 or later. trust.factory.ai (opens in a new tab), Updates › New subprocessor: Snowflake, read 2026-09-28. Factory's page: from October 21, 2026 at the earliest, a date still ahead when the page was read, Databricks is contracted to supply AI model processing for Factory's customers and to hold sensitive internal data. trust.factory.ai (opens in a new tab), Updates › New subprocessor: Databricks, read 2026-09-28. On Enterprise, Custom API keys (BYOK): Factory's page: the allowedBaseUrls org-managed setting names the base URLs custom models are permitted to reach, and can be used to force every piece of custom-model traffic through an LLM gateway the organization has approved. docs.factory.ai (opens in a new tab), Org-managed settings schema › Models and BYOK, read 2026-09-24. Where it can run (marked †, explained in the key) On Enterprise: Factory's page: its Enterprise feature list includes options for deployment at the customer's premises. factory.com (opens in a new tab), Enterprise, in a list, read 2026-09-27. On Pro: Factory's page: its Pro plan, at $20 a month, lists background agents that work in the cloud and on the local machine. factory.com (opens in a new tab), $20, in a list, read 2026-09-27. Telemetry (marked †, explained in the key) (only on Enterprise) Factory's page: in the organization's telemetry settings, exported message content goes only to the customer's own collector, never to Factory's, and with no sink set up it is not recorded at all. docs.factory.ai (opens in a new tab), Org-managed settings schema › Telemetry, read 2026-09-24. Data handling, Droid: what the vendor’s pages sayData residency (marked †, explained in the key) Factory's page: the customer accepts that Factory carries out its main processing in the United States. factory.com (opens in a new tab), 7. Transfers of Customer Personal Data, read 2026-09-27. Factory's page: the personal information Factory collects is held mainly on Amazon Web Services in the US West region, and it processes all of it in the United States as well as at facilities run by the third parties the policy goes on to name. factory.com (opens in a new tab), How and why we use your data › Where do we store the data? Read 2026-09-27. Default retention (marked †, explained in the key) Factory's page: a control listed under data and privacy says customer data is deleted when a customer leaves. trust.factory.ai (opens in a new tab), Controls › Data and privacy, read 2026-09-28. Factory's page: personal information is kept while the user holds an account and is deleted from archives no more than 10 years after the user last used the service, or on terms a separate contract sets. factory.com (opens in a new tab), How and why we use your data › How long do we store your data? Read 2026-09-27. Factory's page: in its DPA's description of the transfer, customer personal data is kept as long as the purpose of processing needs, within applicable law, statute-of-limitations rules and data protection law included. factory.com (opens in a new tab), Exhibit A › 2. Description of the Transfer, table "2. Description of the Transfer", row "Duration of Processing and Retention (or the criteria to determine such period)", column "Description", read 2026-09-27. Factory's page: in its Business Associate Agreement, once the services agreement or the BAA terminates, Factory must give back or destroy the PHI it holds for the customer and keep no copies, subject to an infeasibility exception (section 5.3.2). factory.com (opens in a new tab), Section 5. Term and Termination, read 2026-09-27. Factory's page: when the Services end, Factory will return or delete the customer's Personal Data as the customer chooses and at the customer's cost, unless applicable law requires or permits keeping it longer. factory.com (opens in a new tab), 2. Relationship of the Parties; Processing of Data, read 2026-09-27. On Enterprise: Factory's page: an organization-managed setting sets how many days cloud sessions are kept, from 14 up to 365. docs.factory.ai (opens in a new tab), Org-managed settings schema › Network, sync, and retention, read 2026-09-24. Training use (marked †, explained in the key) (only under Factory's dedicated hosting, with its agreements with Azure) Factory's page: in its entry for Microsoft Azure, Factory says its dedicated hosting and its agreements with Azure mean customer data and IP are not to be used for training either Factory's models or Azure's. trust.factory.ai (opens in a new tab), Subprocessors, read 2026-09-28. Model provider (marked †, explained in the key) (marked †, explained in the key) Factory's page: the model endpoints Factory uses are dedicated ones on Azure OpenAI Service. trust.factory.ai (opens in a new tab), Subprocessors, read 2026-09-28. (marked †, explained in the key) Factory's page: Mistral is contracted to supply AI model processing for Factory's customers, beginning no earlier than August 26, 2026. trust.factory.ai (opens in a new tab), Updates › New subprocessor: Mistral, read 2026-09-28. (marked †, explained in the key) Factory's page: Factory has engaged Together for AI model processing on behalf of its customers, from August 26, 2026 at the earliest. trust.factory.ai (opens in a new tab), Updates › New subprocessor: Together, read 2026-09-28. (marked †, explained in the key) Factory's page: Snowflake has been contracted to handle AI model processing for Factory's customers, with a start on August 27, 2026 or later. trust.factory.ai (opens in a new tab), Updates › New subprocessor: Snowflake, read 2026-09-28. (marked †, explained in the key) Factory's page: from October 21, 2026 at the earliest, a date still ahead when the page was read, Databricks is contracted to supply AI model processing for Factory's customers and to hold sensitive internal data. trust.factory.ai (opens in a new tab), Updates › New subprocessor: Databricks, read 2026-09-28. On Custom API keys (BYOK): Factory's page: with BYOK, the Droid CLI can use keys the customer holds for OpenAI or Anthropic, connect to providers of open-source models, or use models hosted on the customer's own hardware. docs.factory.ai (opens in a new tab), above the page's first section heading, read 2026-09-24. (marked †, explained in the key) On Enterprise, Custom API keys (BYOK): Factory's page: the allowedBaseUrls org-managed setting names the base URLs custom models are permitted to reach, and can be used to force every piece of custom-model traffic through an LLM gateway the organization has approved. docs.factory.ai (opens in a new tab), Org-managed settings schema › Models and BYOK, read 2026-09-24. Where it can run Factory's page: of the two kinds of Droid Computers it offers, the managed kind is one where Factory provisions and runs the cloud compute environment on the customer's behalf. docs.factory.ai (opens in a new tab), Droid Computer types, in a list, read 2026-09-27. On BYOM: Factory's page: Bring Your Own Machine (BYOM) is one of two ways it offers to use Droid Computers, in which the customer registers a machine it already manages, for example a VPS, a workstation or a server on its own premises. docs.factory.ai (opens in a new tab), Droid Computer types, in a list, read 2026-09-27. On Custom API keys (BYOK): Factory's page: custom models can be used in the desktop app and the Droid CLI, both of which read the user's local settings.json, and do not show up on the web or mobile platforms Factory hosts. docs.factory.ai (opens in a new tab), above the page's first section heading, read 2026-09-24. On Enterprise: Factory's page: stating policy a single time at the proper settings level means Droid can run in cloud, hybrid and fully disconnected environments, cut off from outside networks, without drift between machines or one-off setup. docs.factory.ai (opens in a new tab), Putting it all together, read 2026-09-24. (marked †, explained in the key) On Enterprise: Factory's page: its Enterprise feature list includes options for deployment at the customer's premises. factory.com (opens in a new tab), Enterprise, in a list, read 2026-09-27. On Plus: Factory's page: its Plus plan, at $100 a month, adds Droid Computers, giving remote Droids access to cloud computers that Factory manages. factory.com (opens in a new tab), $100, in a list, read 2026-09-27. (marked †, explained in the key) On Pro: Factory's page: its Pro plan, at $20 a month, lists background agents that work in the cloud and on the local machine. factory.com (opens in a new tab), $20, in a list, read 2026-09-27. Telemetry (marked †, explained in the key) (only on Enterprise) Factory's page: in the organization's telemetry settings, exported message content goes only to the customer's own collector, never to Factory's, and with no sink set up it is not recorded at all. docs.factory.ai (opens in a new tab), Org-managed settings schema › Telemetry, read 2026-09-24. | ||||
| FlowiseAI/Flowise (opens in a new tab)archived | A Node server you run with a visual builder over it. | You run it, so you answer these. | repository | observed 2026-09-03 |
| Gemini Code Assist (opens in a new tab) | Google’s editor-side coding assistant, sold to organizations rather than to the browser user of Google Gemini, the chat assistant. | SOC 2 ISO 27001 HIPAA BAA DPA (marked †, explained in the key)Unverified after 2026-12-26 |
editor extension | observed 2026-09-03 |
Data handling: what the vendor’s pages sayData residency (marked †, explained in the key) Google's page: section 10.1 of its Cloud DPA says Customer Data may be handled in whatever country Google or a subprocessor keeps facilities in, subject to the location commitments Google makes in its Service Specific Terms and, where they apply, the transfer commitments in Appendix 3. cloud.google.com (opens in a new tab), above the page's first section heading, read 2026-09-27. Default retention (marked †, explained in the key) Google's page: in its Cloud DPA, the customer's instruction is that Google delete all remaining Customer Data, copies included, when the term ends; once a recovery window of as long as 30 days has passed, Google does so as soon as it reasonably can and within 180 days, unless European or other applicable law requires storage, and subject to the deferred-deletion terms of section 6.3. cloud.google.com (opens in a new tab), above the page's first section heading, read 2026-09-27. Telemetry Google's page: in an IDE, when Gemini Code Assist is used through Google Cloud Code, the usage statistics Cloud Code gathers fall under Google's Privacy Policy. docs.cloud.google.com (opens in a new tab), above the page's first section heading, read 2026-09-27. | ||||
| GitHub Copilot (opens in a new tab) | Several products under one name: an inline completion extension, a chat surface, a CLI, and Copilot cloud agent, a hosted agent a whole task can be assigned to. | SOC 2 Type II ISO 42001:2023Unverified after 2026-12-23 |
editor extension | observed 2026-09-23 |
Data handling: what the vendor’s pages sayData residency (marked †, explained in the key) GitHub's page: personal information is stored and processed by GitHub in many places: the user's own region, the United States, plus other countries where GitHub or a subsidiary, affiliate or subprocessor of it operates. docs.github.com (opens in a new tab), International data transfers, read 2026-09-27. Default retention (marked †, explained in the key) GitHub's page: GitHub keeps personal information while the account is active, and beyond that for as long as contracts, legal requirements, dispute resolution or enforcing agreements need it. docs.github.com (opens in a new tab), Security and Retention, read 2026-09-27. Training use (only on Copilot Business, Enterprise) GitHub's page: data from Copilot Business or Enterprise customers is not used by GitHub to train AI models. copilot.github.trust.page (opens in a new tab), FAQ, read 2026-09-29. Model provider On Custom API keys (BYOK): GitHub's page: enabling custom models lets teams use the LLM providers the organization prefers in IDEs, Copilot Chat and Copilot CLI. docs.github.com (opens in a new tab), above the page's first section heading, read 2026-09-24. On GitHub Enterprise Cloud with data residency: GitHub's page: if an enterprise is on GitHub Enterprise Cloud with data residency in the US, it can enable a policy under which users on its Copilot plan may use only models that hold FedRAMP Moderate certification. docs.github.com (opens in a new tab), Who can use this feature? Read 2026-09-24. Where it can run On Copilot cloud agent: GitHub's page: Copilot cloud agent, while on a coding task, gets a short-lived development environment of its own, powered by GitHub Actions, in which it can explore and change code and run automated tests and linters. docs.github.com (opens in a new tab), Overview of Copilot cloud agent, read 2026-09-27. On Custom API keys (BYOK): GitHub's page: the Enable custom models policy has to be turned on by an enterprise owner first. docs.github.com (opens in a new tab), Prerequisites, read 2026-09-24. | ||||
| Google Gemini (opens in a new tab) | Google’s hosted chat assistant, the consumer product rather than the developer tooling. | Google GeminiNot shown to hold.Unverified after 2026-12-26 GeminiNot shown to hold.Unverified after 2026-12-26 |
chat assistant | observed 2026-09-03 |
Data handling, Google Gemini: what the vendor’s pages sayDefault retention Google's page: the Gemini Apps Activity auto-delete setting defaults to 18 months, and a user can switch it to indefinite, 36 months or 3 months; the page adds that retention periods vary with the kind of data and its use. support.google.com (opens in a new tab), Gemini Apps Privacy Notice › Information we collect as you use Gemini Apps, in a list, read 2026-09-27. Under Gemini chats that human reviewers have looked at: Google's page: Gemini chats that human reviewers have looked at, with related data such as language, device type, location and feedback, are not removed when a user deletes activity, and are kept for as long as three years. support.google.com (opens in a new tab), Gemini Apps Privacy Notice › Information we collect as you use Gemini Apps, in a list, read 2026-09-27. Zero-retention option (only under Keep Activity off) Google's page: with Keep Activity turned off, later chats are still kept for 72 hours, so that Gemini can reply, process feedback, and protect the public, Google's users and Google itself. support.google.com (opens in a new tab), Privacy questions › If the Keep Activity setting is off:, read 2026-09-27. Training use Under Gemini Live: Google's page: by default, Google does not use a user's Gemini Live audio, video or screen shares to improve its services. support.google.com (opens in a new tab), Privacy questions › Gemini Live › Gemini Live audio, videos & screenshares, read 2026-09-27. Under Keep Activity off: Google's page: with Keep Activity turned off, a user's later chats do not show in their Activity, and Google does not use them to train its AI models, unless the user chooses to send Google feedback. support.google.com (opens in a new tab), Privacy questions › If the Keep Activity setting is off:, read 2026-09-27. Under Keep Activity on: Google's page: with Keep Activity on, a user's Gemini activity feeds the provision, development and improvement of Google's services, generative AI model training among them, and also protection of Google, of its users and of the public, which human reviewers help with. support.google.com (opens in a new tab), Privacy questions › If the Keep Activity setting is on: › How your activity is used, read 2026-09-27. Under temporary chats: Google's page: Google does not train its AI models on temporary chats in Gemini. support.google.com (opens in a new tab), Privacy questions › General › How you can control what’s shared with reviewers, read 2026-09-27. Telemetry Google's page: among what it collects when Gemini Apps are used, Google lists how a user's apps, browsers and devices interact with them, for example logs of interactions, performance metrics, and crash and debug data. support.google.com (opens in a new tab), Gemini Apps Privacy Notice › Information we collect as you use Gemini Apps, read 2026-09-27. Data handling, Gemini: what the vendor’s pages sayDefault retention Google's page: the Gemini Apps Activity auto-delete setting defaults to 18 months, and a user can switch it to indefinite, 36 months or 3 months; the page adds that retention periods vary with the kind of data and its use. support.google.com (opens in a new tab), Gemini Apps Privacy Notice › Information we collect as you use Gemini Apps, in a list, read 2026-09-27. Under Gemini chats that human reviewers have looked at: Google's page: Gemini chats that human reviewers have looked at, with related data such as language, device type, location and feedback, are not removed when a user deletes activity, and are kept for as long as three years. support.google.com (opens in a new tab), Gemini Apps Privacy Notice › Information we collect as you use Gemini Apps, in a list, read 2026-09-27. Zero-retention option (only under Keep Activity off) Google's page: with Keep Activity turned off, later chats are still kept for 72 hours, so that Gemini can reply, process feedback, and protect the public, Google's users and Google itself. support.google.com (opens in a new tab), Privacy questions › If the Keep Activity setting is off:, read 2026-09-27. Training use Under Gemini Live: Google's page: by default, Google does not use a user's Gemini Live audio, video or screen shares to improve its services. support.google.com (opens in a new tab), Privacy questions › Gemini Live › Gemini Live audio, videos & screenshares, read 2026-09-27. Under Keep Activity off: Google's page: with Keep Activity turned off, a user's later chats do not show in their Activity, and Google does not use them to train its AI models, unless the user chooses to send Google feedback. support.google.com (opens in a new tab), Privacy questions › If the Keep Activity setting is off:, read 2026-09-27. Under Keep Activity on: Google's page: with Keep Activity on, a user's Gemini activity feeds the provision, development and improvement of Google's services, generative AI model training among them, and also protection of Google, of its users and of the public, which human reviewers help with. support.google.com (opens in a new tab), Privacy questions › If the Keep Activity setting is on: › How your activity is used, read 2026-09-27. Under temporary chats: Google's page: Google does not train its AI models on temporary chats in Gemini. support.google.com (opens in a new tab), Privacy questions › General › How you can control what’s shared with reviewers, read 2026-09-27. Telemetry Google's page: among what it collects when Gemini Apps are used, Google lists how a user's apps, browsers and devices interact with them, for example logs of interactions, performance metrics, and crash and debug data. support.google.com (opens in a new tab), Gemini Apps Privacy Notice › Information we collect as you use Gemini Apps, read 2026-09-27. | ||||
| google-gemini/gemini-cli (opens in a new tab) | A terminal agent installed from npm or a package manager, holding the loop and calling tools, extensible over MCP. | You run it, so you answer these. | repository | observed 2026-09-03 |
| JetBrains Junie (opens in a new tab) | JetBrains’ coding agent, available inside JetBrains IDEs and, since its general availability in June 2026, as a standalone Junie CLI reached from a terminal, any IDE or CI/CD (JetBrains, March 2026), which can optionally connect to a running JetBrains IDE for its code intelligence (JetBrains, April 2026; JetBrains’ announcement, as of 2026-09-26). | Not shown to hold. |
editor extension | observed 2026-09-24 |
| Jules (opens in a new tab) | A hosted agent that clones a GitHub repository into a Cloud VM, plans and makes a change, a bug fix, a version bump, a test, a feature, and opens a pull request for review. | Not shown to hold.Unverified after 2026-12-26 |
hosted service | observed 2026-09-23 |
Data handling: what the vendor’s pages sayTraining use Google's page: what is in a user's non-public repositories is not something Jules trains on, and Google does not use those repositories for model training. jules.google (opens in a new tab), Does Jules train on private repos? Read 2026-09-27. Where it can run Google's page: code run in Jules executes in a cloud virtual machine that has internet access. jules.google (opens in a new tab), How does Jules run code, and what should I know about security? Read 2026-09-27. | ||||
| Kiro (opens in a new tab) | An editor that owns the editing surface, like Cursor, and frames its workflow around specs rather than around chat. | Kiro from AWSNot shown to hold. |
editor | observed 2026-09-03 |
Data handling, Kiro from Kiro: what the vendor’s pages sayData residency On Enterprise: Kiro's page: if someone is a Kiro enterprise user, their prompts, responses and other content may be kept in the Region in which their profile is configured, so that the service can be provided and maintained (prompt logging and daily activity reports are its examples). kiro.dev (opens in a new tab), Data storage › AWS regions where content is stored and processed, read 2026-09-27. On Free, Individual: Kiro's page: if a user is on the Kiro Free Tier or is a Kiro individual subscriber, their content, prompts and responses among it, is kept in the AWS Region US East (N. Virginia). kiro.dev (opens in a new tab), Data storage › AWS regions where content is stored and processed, read 2026-09-27. Default retention Under Kiro's abuse detection through Amazon Bedrock, whose retention the page sets model by model: Kiro's page: under the abuse detection that runs through Amazon Bedrock for every Kiro user, all traffic to Anthropic Claude Fable 5.1 (Preview) is kept for as long as 30 days for automated abuse detection performed after the fact, unless the law requires otherwise. kiro.dev (opens in a new tab), Kiro Abuse Detection, in a list, read 2026-09-27. Under Kiro's abuse detection through Amazon Bedrock, whose retention the page sets model by model: Kiro's page: under the same Amazon Bedrock abuse detection, OpenAI GPT traffic that a classifier flags is kept for as long as 30 days for automated abuse detection performed after the fact, unless the law requires otherwise. kiro.dev (opens in a new tab), Kiro Abuse Detection, in a list, read 2026-09-27. On Free: Kiro's page, for a Kiro Free Tier user: besides possible use for service improvement, Kiro may also keep inputs, for further abuse detection, up to 60 days, and retention rules specific to a model may apply as well; the page points to its Abuse detection section. kiro.dev (opens in a new tab), Data storage › Storage by user type, read 2026-09-27. Training use On Enterprise: Kiro's page: content from a Kiro enterprise user is not used to improve the service. kiro.dev (opens in a new tab), Data storage › Storage by user type, read 2026-09-27. On Free: Kiro's page: for a Kiro Free Tier user, content may be used to improve the service unless the user has opted out. kiro.dev (opens in a new tab), Data storage › Storage by user type, read 2026-09-27. On Free, Individual: Kiro's page: content from Free Tier users and individual subscribers may be used for model training, alongside other purposes such as better answers to common questions, fixing operational issues and debugging. kiro.dev (opens in a new tab), Service improvement › Kiro content used for service improvement, read 2026-09-27. On Individual: Kiro's page: for a Kiro individual subscriber, whether paid or signed in through a social login or an AWS Builder ID, content may be used to improve the service unless the subscriber has opted out. kiro.dev (opens in a new tab), Data storage › Storage by user type, read 2026-09-27. Model provider Kiro's page: Kiro runs on Amazon Bedrock and spreads its traffic over several AWS Regions through cross-region inference, for better performance and reliability in its LLM inference. kiro.dev (opens in a new tab), Cross-region processing › Cross-region inference, read 2026-09-27. Where it can run (only on Cloud sessions) Kiro's page: a cloud session runs Kiro's agent harness inside a managed sandbox in the cloud, rather than on the user's own machine. kiro.dev (opens in a new tab), above the page's first section heading, read 2026-09-24. Telemetry On Enterprise: Kiro's page: AWS automatically excludes Kiro enterprise users from both telemetry and content collection. kiro.dev (opens in a new tab), Opt out of data sharing, read 2026-09-27. On Free, Individual: Kiro's page: for Free Tier users and individual subscribers, Kiro by default collects telemetry (usage, error and crash data, and other metrics) and also content, for improving the service. kiro.dev (opens in a new tab), Opt out of data sharing, read 2026-09-27. On Free, Individual: Kiro's page: in the Kiro IDE, Free Tier users and individual subscribers turn telemetry off by clearing the checkbox for usage analytics and performance metrics in the data-sharing settings. kiro.dev (opens in a new tab), Opt out of data sharing › Opting out of sharing data, in a list, read 2026-09-27. | ||||
| Kiro Cloud Sessions (opens in a new tab) | Kiro’s hosted mode, separate from the Kiro specification-driven editor: a long task is handed to it and keeps running after the laptop closes. | Not shown to hold. Why | hosted service | observed 2026-09-23 |
| langflow-ai/langflow (opens in a new tab) | A server you run with a visual authoring surface, which also exposes every workflow as an API and an MCP server, so a workflow drawn there can also be called by other programs and by agents. | You run it, so you answer these. | repository | observed 2026-09-03 |
| langgenius/dify (opens in a new tab) | A server you run, or a hosted tier, presenting a builder over a workflow engine, a RAG pipeline and model management. | You run it, so you answer these. | repository | observed 2026-09-03 |
| lmstudio-ai/lms (opens in a new tab) | A CLI that ships with the LM Studio desktop application and drives it. | You run it, so you answer these. | repository | observed 2026-09-03 |
| Lovable (opens in a new tab) | A hosted full-stack app builder generating real, exportable code from natural-language prompts, with its own docs describing enterprise governance features alongside the consumer-facing build flow. | Not shown to hold.Unverified after 2026-12-26 |
hosted service | observed 2026-09-24 |
Data handling: what the vendor’s pages sayData residency (marked †, explained in the key) Lovable's page: Lovable and its service providers process personal information in several countries, the United States among them. lovable.dev (opens in a new tab), above the page's first section heading, read 2026-09-27. Default retention (marked †, explained in the key) Lovable's page: of the personal information it holds, account details and Customer Content are kept while the account stays open, and afterwards removed or de-identified once it closes or following a verified request to delete, unless the law requires keeping them longer. lovable.dev (opens in a new tab), above the page's first section heading, in a list, read 2026-09-27. Training use (marked †, explained in the key) On Enterprise and Business: Lovable's page: in its list of what it does not train on, Lovable includes Customer Content and Usage Data from Business and Enterprise customers, and says its Data Processing Agreement sets out that prohibition. lovable.dev (opens in a new tab), above the page's first section heading, in a list, read 2026-09-27. On Enterprise and Business, Free, Pro: Lovable's page: on every plan, a user may turn off model training in account settings at any moment, at no charge, and doing so leaves AI features usable. lovable.dev (opens in a new tab), above the page's first section heading, read 2026-09-27. On Free, Pro: Lovable's page: Lovable trains, fine-tunes, develops and improves its AI models and features on its Customer Content and its Usage Data, either of which may hold personal information; that covers models run inside its services and models it may offer to customers, the AI Gateway given as an example. lovable.dev (opens in a new tab), above the page's first section heading, read 2026-09-27. Telemetry Lovable's page: under analytics and performance, one of the groups into which it sorts the cookies, pixels, SDKs and like tools it and selected partners use, Lovable lists feature adoption, diagnosing errors and how the service performs, served by analytics providers, first-party as well as third-party. Further down, the page says that in the EEA, the UK and Switzerland it gets consent before setting cookies that are not essential, and that in the United States it honors GPC and other opt-out preference signals. lovable.dev (opens in a new tab), above the page's first section heading, in a list, read 2026-10-01. Lovable's page: with the user's consent where required, Lovable records a sample of sessions through a session-replay provider working on its behalf, to learn how people use the product and to repair problems with its usability. lovable.dev (opens in a new tab), above the page's first section heading, in a list, read 2026-10-01. Lovable's page: for session recording, a user can, where the law requires consent, withdraw it through the Cookie Preferences panel, and that halts further recording. lovable.dev (opens in a new tab), above the page's first section heading, in a list, read 2026-09-27. | ||||
| Microsoft Copilot Studio (opens in a new tab) | A hosted builder for agents, licensed inside Microsoft 365 rather than bought separately. | hosted service | reasoned 2026-09-03 | |
| n8n-io/n8n (opens in a new tab) | A server you run (or a hosted tier) with a visual canvas over it. | You run it, so you answer these. | repository | observed 2026-09-03 |
| openai/codex (opens in a new tab) | A coding agent installed as a local binary, with an IDE extension and a cloud surface named separately by the same README. | You run it, so you answer these. | repository | observed 2026-09-03 |
| OpenHands/OpenHands (opens in a new tab) | An open-source coding agent that plans and executes multi-step changes with terminal, browser and code-editing tools, run locally or self-hosted. | OpenHands CloudNot shown to hold.Unverified after 2026-12-29 The software itself: you run it, so you answer these. |
repository | observed 2026-09-24 |
Data handling, OpenHands Cloud: what the vendor’s pages sayDefault retention (marked †, explained in the key) OpenHands' privacy policy, in a sentence that gives no retention period: personal information is kept for whichever is longest of what the policy's own purposes reasonably need, a business need, or what the law requires, for example for tax, legal or accounting purposes. www.openhands.dev (opens in a new tab), Other sites, mobile applications and services › Retention, read 2026-09-30. Training use (marked †, explained in the key) OpenHands' privacy policy, among the ways it uses personal information to develop and improve its Site and Services: OpenHands may train and tune its AI models on content and feedback that come from a user's use of the Services, so as to make the Services more capable. www.openhands.dev (opens in a new tab), How we use personal information › To develop and improve the Site and Services. Read 2026-09-30. Model provider (marked †, explained in the key) OpenHands' privacy policy, under the service providers it shares personal information with: OpenHands uses outside providers of AI services, none of them named, which may receive a user's content subject to OpenHands' agreements with them, to help it provide the Site and Services. www.openhands.dev (opens in a new tab), How we share your personal information › Service providers. Read 2026-09-30. Where it can run The OpenHands documentation, on getting started with its cloud offering: OpenHands Cloud is OpenHands run as a hosted cloud service. docs.openhands.dev (opens in a new tab), Accessing OpenHands Cloud, read 2026-09-30. Telemetry (marked †, explained in the key) OpenHands' privacy policy, under its marketing and advertising uses: OpenHands uses outside analytics providers, naming Posthog and Google Analytics as examples, to learn how people use its Site and Services, gauge engagement and improve how they perform. www.openhands.dev (opens in a new tab), How we use personal information › For marketing and advertising., in a list, read 2026-09-30. OpenHands' privacy policy, among the ways it lists for a user to limit online tracking: a user can opt out of Google Analytics by installing a browser add-on, a step taken in the user's own browser; the sentence covers Google Analytics alone. www.openhands.dev (opens in a new tab), Your choices › Limit online tracking: Here are some of the ways you can limit online tracking:, read 2026-09-30. OpenHands' privacy policy, as a negative, in its section on Do Not Track: OpenHands does not, at present, act on a browser's Do Not Track signal or on signals like it. www.openhands.dev (opens in a new tab), Your choices › Do Not Track. Read 2026-09-30. | ||||
| Relevance AI (opens in a new tab) | A hosted builder aimed at business functions rather than at engineering. | SOC 2 Type IIUnverified after 2026-12-26 |
hosted service | reasoned 2026-09-06 |
Data handling: what the vendor’s pages sayDefault retention (marked †, explained in the key) Relevance AI's page: personal information is kept as long as needed for marketing purposes or to provide the Services. relevanceai.com (opens in a new tab), 10. Security and Retention, read 2026-09-27. Zero-retention option Relevance AI's trust center lists, under its data and privacy controls, that customer data is deleted when a customer leaves. trust.relevanceai.com (opens in a new tab), Controls › Data and privacy, read 2026-09-27. | ||||
| Replit Agent (opens in a new tab) | A hosted, browser-based agent that plans, writes, tests and deploys a full application from a natural-language description, with Replit supplying the compute, deployment and hosting end to end, closer in shape to Bolt, v0 and Lovable (build-and-ship a whole app in the vendor’s own environment) than to a coding assistant added to a repository you already own. | Not shown to hold.Unverified after 2026-12-26 |
hosted service | observed 2026-09-24 |
Data handling: what the vendor’s pages sayData residency (marked †, explained in the key) Replit's docs: Replit keeps data mainly in United States data centers of Google Cloud Platform (GCP), and offers an optional region in India to those users who choose it. docs.replit.com (opens in a new tab), Data protection › Hosting and infrastructure, read 2026-09-27. | ||||
| Sourcegraph Cody (opens in a new tab) | A coding assistant that pulls context from Sourcegraph’s own code-search index across local and remote repositories, available as extensions for VS Code, JetBrains and Visual Studio, a web app, and a CLI. | Sourcegraph CodySOC 2 (marked †, explained in the key) ISO 27001:2022 (marked †, explained in the key)Unverified after 2026-12-26 SourcegraphSOC 2 (marked †, explained in the key) ISO 27001:2022 (marked †, explained in the key)Unverified after 2026-12-26 |
editor extension | observed 2026-09-24 |
| Stack AI (opens in a new tab) | A hosted drag-and-drop builder aimed at enterprise deployment. | hosted service | reasoned 2026-09-08 | |
Data handling: what the vendor’s pages sayDefault retention (marked †, explained in the key) Stack AI's page: a control states that customer data is retained according to requirements agreed with the customer or according to its information security policies. trust.stackai.com (opens in a new tab), Compliance › Confidentiality, read 2026-09-28. | ||||
| v0 (opens in a new tab) | Vercel’s hosted builder for full-stack web applications, generating both UI and backend code from natural language and deploying directly onto Vercel’s own platform, a build tool whose deployment target is its maker’s own platform. | SOC 2 (marked †, explained in the key) Type II, period stated as 2025-07-01 to 2026-06-30 ISO 27001:2022 (marked †, explained in the key) HIPAA* (only on Enterprise. marked †, explained in the key) GDPR (marked †, explained in the key) DPA (marked †, explained in the key)Unverified after 2026-12-26 |
hosted service | observed 2026-09-24 |
Data handling: what the vendor’s pages sayData residency (marked †, explained in the key) Vercel's page, as a negative: no data is kept permanently in EU regions. vercel.com (opens in a new tab), Challenge Mode › Frequently asked questions. Read 2026-09-27. | ||||
| Vellum (opens in a new tab) | Filed as an agent-evaluation service, but its own page, read 2026-09-03, describes a personal AI assistant with persistent memory and says nothing about evaluation. | HIPAAUnverified after 2026-12-26 |
hosted service | observed 2026-09-03 |
Data handling: what the vendor’s pages sayDefault retention (marked †, explained in the key) Vellum's page: as the default, interaction data is kept with no time limit. docs.vellum.ai (opens in a new tab), Interaction Storage › Retention Policies, read 2026-09-27. Zero-retention option (marked †, explained in the key) (only on Enterprise) Vellum's page: Enterprise customers can set retention policies that delete monitoring data automatically once a chosen period has passed, with 30, 60, 90 and 365 days as the options, to meet their own internal data governance requirements. docs.vellum.ai (opens in a new tab), Interaction Storage › Retention Policies, read 2026-09-27. Training use Vellum's docs: Vellum does not forward a customer's feedback or interactions to model providers for them to train on. docs.vellum.ai (opens in a new tab), Training and Model Improvement › Use of Interaction Data, read 2026-09-27. Model provider Vellum's docs: when a prompt or workflow runs, Vellum passes the prompt's content, variables and context included, to whichever LLM provider was chosen, such as OpenAI or Anthropic, as needed to produce a response. docs.vellum.ai (opens in a new tab), Data Transmission to LLM Providers › How Vellum Handles Your Data, in a list, read 2026-09-27. | ||||
| Warp (opens in a new tab) | A terminal application rebuilt around agents: it can drive one or more coding agents, run them against a task queue, and (per its own newer positioning) automate work across the SDLC rather than only completing commands interactively. | SOC 2 Type IIUnverified after 2026-12-26 |
terminal agent | observed 2026-09-24 |
Data handling: what the vendor’s pages sayData residency Warp's page: data for Warp Drive and for block sharing and embedding is kept on Google Cloud Platform (GCP). www.warp.dev (opens in a new tab), What is Warp? › AI and Cloud-enabled features, read 2026-09-27. Warp's security page: data that users or companies give Warp is held on Google Cloud Platform, with databases located in the United States. www.warp.dev (opens in a new tab), Data › Where does Warp store user or company data? Read 2026-09-27. Zero-retention option (only on Enterprise) Warp's security page: customers on Warp's Enterprise plan can take up Zero Data Retention as a policy. www.warp.dev (opens in a new tab), What is Warp? › AI and Cloud-enabled features, read 2026-09-27. Model provider Warp's security page: Warp AI passes all data through a proxy on its way to APIs hosted in the US, which the page calls enterprise-level. www.warp.dev (opens in a new tab), What is Warp? › AI and Cloud-enabled features, read 2026-09-27. | ||||
| zed-industries/zed (opens in a new tab) | A native code editor, built by the team behind Atom and Tree-sitter, with a built-in agent panel that can plan and execute multi-file edits alongside its original real-time collaborative editing. | You run it, so you answer these. | repository | observed 2026-09-24 |
| Tool | What it is | Compliance | Type | Read |
|---|---|---|---|---|
| addyosmani/agent-skills (opens in a new tab) | 25 skill directories under skills/, named for lifecycle phases, planning, TDD, code review, debugging, security, shipping. | You run it, so you answer these. | repository | observed 2026-09-03 |
| agentskills/agentskills (opens in a new tab) | The specification plus a validator. | You run it, so you answer these. | repository | observed 2026-09-10 |
| anthropics/skills (opens in a new tab) | A repository of skill directories. | You run it, so you answer these. | repository | observed 2026-09-03 |
| ComposioHQ/awesome-claude-skills (opens in a new tab) | Both a list and an implementation, which is why one word for it is wrong. | You run it, so you answer these. | repository | observed 2026-09-03 |
| garrytan/gstack (opens in a new tab) | A set of Markdown slash commands for Claude Code, each a role such as product review, engineering review, design review, code review, QA, security audit or release, which the README says is 23 specialists and eight power tools and calls the maintainer’s own software factory. | You run it, so you answer these. | repository | observed 2026-10-02 |
| github/spec-kit (opens in a new tab) | A CLI that writes a scaffold of prompts and templates into a repository, agent-agnostic across many coding agents. | You run it, so you answer these. | repository | observed 2026-09-03 |
| jax-ml/jax (opens in a new tab) | A Python library for array computation and program transformation, with automatic differentiation and compilation to accelerators. | You run it, so you answer these. | repository | observed 2026-09-03 |
| mattpocock/skills (opens in a new tab) | 37 skill directories under skills/, grouped engineering/, productivity/, misc/ and in-progress/, published as a Claude Code plugin with a .claude-plugin/marketplace.json. | You run it, so you answer these. | repository | observed 2026-09-03 |
| ml-explore/mlx (opens in a new tab) | An array framework you import, targeting Apple silicon’s unified memory, for build-time and on-device use at once. | You run it, so you answer these. | repository | observed 2026-09-03 |
| ml-explore/mlx-lm (opens in a new tab) | A Python package built over mlx, covering both text generation and fine-tuning of language models on Apple silicon. | You run it, so you answer these. | repository | observed 2026-09-03 |
| obra/superpowers (opens in a new tab) | A methodology shipped as files. | You run it, so you answer these. | repository | observed 2026-09-03 |
| pytorch/pytorch (opens in a new tab) | A Python package you import, with compiled kernels underneath. | You run it, so you answer these. | repository | observed 2026-09-03 |
| tensorflow/tensorflow (opens in a new tab) | A framework you import, with a large surrounding ecosystem of tools and libraries. | You run it, so you answer these. | repository | observed 2026-09-03 |
| Tool | What it is | Compliance | Type | Read |
|---|---|---|---|---|
| Arize-ai/phoenix (opens in a new tab) | An open-source tracing and evaluation library: it instruments an application (via OpenTelemetry) to capture traces, then runs LLM-graded and code-graded evals against recorded runs or a curated dataset. | You run it, so you answer these. | repository | observed 2026-09-24 |
| Braintrust (opens in a new tab) | A hosted platform for running production agents under observation: capturing traces from live traffic, scoring recorded runs against a dataset, and flagging a regression before it reaches a user, positioned by the vendor as built specifically for agents rather than adapted from a general APM tool. | Not shown to hold. |
hosted service | observed 2026-09-24 |
| confident-ai/deepeval (opens in a new tab) | An LLM evaluation framework structured like a unit-test library (assertions, metrics, pytest integration) rather than a hosted dashboard, with a companion hosted platform (Confident AI) this read did not open. | You run it, so you answer these. | repository | observed 2026-09-24 |
| Galileo (opens in a new tab) | A hosted observability and evaluation platform marketed at enterprise scale, framing itself around guarding a GenAI application in production as much as scoring it offline. | Not shown to hold. |
hosted service | observed 2026-09-24 |
| langfuse/langfuse (opens in a new tab) | An open-source platform combining tracing, dataset-based evaluation, prompt versioning and a hosted cloud tier, which puts an evaluation harness and prompt versioning in one product. | Langfuse CloudSOC 2 Type II ISO 27001 HIPAA* (only under Langfuse Cloud's HIPAA data region) GDPR DPAUnverified after 2026-12-26 The software itself: you run it, so you answer these. |
repository | observed 2026-09-24 |
| promptfoo/promptfoo (opens in a new tab) | A declarative, config-driven CLI for testing prompts and agents against a case set, comparing several models’ outputs, and red-teaming for vulnerabilities, closer to what a CI pipeline would call a test runner than a dashboard-first observability platform. | You run it, so you answer these. | repository | observed 2026-09-24 |
| wandb/weave (opens in a new tab) | Weights & Biases’ toolkit for tracing and evaluating LLM applications, built on the same company’s established experiment-tracking product for traditional ML training. | You run it, so you answer these. | repository | observed 2026-09-24 |
| Tool | What it is | Compliance | Type | Read |
|---|---|---|---|---|
| agentic-community/mcp-gateway-registry (opens in a new tab) | An MCP gateway and registry: one governed address that agents discover MCP servers from once those servers are scattered. | You run it, so you answer these. | repository | reasoned 2026-09-09 |
| LangSmith Context Hub (opens in a new tab) | A hosted registry for the prompts and contexts an agent loads, versioned and environment-tagged. | SOC 2 Type II, period stated as 2025-07-01 to 2026-06-30 ISO 27001:2022Unverified after 2026-12-26 |
hosted service | reasoned 2026-09-06 |
Data handling: what the vendor’s pages sayDefault retention (marked †, explained in the key) LangChain's docs: from September 14, 2026, the longest retention SaaS customers can have for long-lived traces becomes 180 days. docs.langchain.com (opens in a new tab), Usage and billing › Data retention › How it works, read 2026-09-27. On Enterprise: LangChain's docs: Enterprise customers can still choose, workspace by workspace, how long extended retention lasts, up to the new maximum of 180 days that the preceding sentence sets. docs.langchain.com (opens in a new tab), Usage and billing › Data retention › How it works, read 2026-09-27. Model provider LangChain's page: in its subprocessor list, GCP hosts LangChain's cloud and also runs LLM inference behind AI-powered features, on the features and plans where that applies. trust.langchain.com (opens in a new tab), Subprocessors, read 2026-09-27. LangChain's page: its subprocessor list names AWS as a cloud hosting provider for LangChain that also serves LLM inference to AI-powered features, on the features and plans it applies to. trust.langchain.com (opens in a new tab), Subprocessors, read 2026-09-27. | ||||
| Microsoft Agent 365 (opens in a new tab) | A hosted place to register and manage agents. | hosted service | reasoned 2026-09-08 | |
| mlflow/mlflow (opens in a new tab) | A server plus client libraries. | You run it, so you answer these. | repository | observed 2026-09-03 |
| modelcontextprotocol/registry (opens in a new tab) | A registry service for MCP servers, developed by volunteers under the same GitHub organization that maintains the Model Context Protocol specification itself. | You run it, so you answer these. | repository | observed 2026-09-24 |
| Smithery (opens in a new tab) | A hosted directory of MCP servers plus a managed layer in front of them: the vendor states that it handles authentication, credentials and sessions on the adopting team’s behalf, so an agent can call a listed tool without that team standing up its own session/credential handling for that server. | Not shown to hold. |
hosted service | observed 2026-09-24 |
| Tool | What it is | Compliance | Type | Read |
|---|---|---|---|---|
| Claude Code plugin marketplaces (opens in a new tab) | A feature of Claude Code: a marketplace is a marketplace.json catalog, kept in a git repository or a local path, that lists plugins (skills, agents, hooks, MCP servers, LSP servers) for a team or a community to install from. | Claude CodeSOC 2 (marked †, explained in the key) Type II ISO 27001:2022 (marked †, explained in the key) ISO 42001:2023 (marked †, explained in the key) HIPAA BAA* (only on Commercial, Enterprise. only under Claude Code with ZDR enabled; Claude Code with ZDR enabled, on a qualified account) DPA (marked †, explained in the key)Restrictions below.Unverified after 2026-12-23 |
product feature | observed 2026-09-29 |
Restriction, Claude Code: HIPAA (under the Claude API arrangement Anthropic calls HIPAA readiness). Anthropic's page: Claude Code falls outside HIPAA readiness. platform.claude.com (opens in a new tab), HIPAA readiness › What HIPAA readiness does not cover, read 2026-09-24. Restriction, Claude Code: HIPAA (under the Claude API arrangement Anthropic calls HIPAA readiness, on Commercial). Anthropic's page: for reaching Covered Models in configurations the BAA covers, it notes that Claude Code is not an Eligible Service for an API organization that is HIPAA-ready. support.claude.com (opens in a new tab), How to access Covered Models under the BAA, in a list, read 2026-09-24. | ||||
Data handling, Claude Code: what the vendor’s pages sayData residency (only on Hosted on Anthropic, Hosted on Azure) Anthropic's page, in the Microsoft Foundry row of its table, under encryption at rest: the answer turns on the hosting option; with Hosted on Azure, prompts and completions stay within Azure and only usage metadata, plus content Anthropic's safety systems flag, goes out to Anthropic, while with Hosted on Anthropic, requests go to Anthropic infrastructure that uses AES-256 disk encryption. code.claude.com (opens in a new tab), Local Claude Code: Data flow and dependencies, table "Local Claude Code: Data flow and dependencies", row "Microsoft Foundry", column "Encryption at rest", read 2026-09-24. Default retention Under transcripts shared through /feedback, /bug or /share: Anthropic's page: Claude Code transcripts sent through /feedback, or through /bug and /share, which use the same reporting path, are kept for 5 years. code.claude.com (opens in a new tab), Data policies › Feedback using the /feedback command, read 2026-09-24. On Commercial, Enterprise: Anthropic's page, for Claude Code's commercial users, a group whose list includes Enterprise: the standard retention period is 30 days. code.claude.com (opens in a new tab), Data policies › Data retention, in a list, read 2026-09-24. On Consumer: Anthropic's page: for Consumer users (the Free, Pro and Max plans) who let their data be used to improve models, Claude Code data is kept for 5 years, for model development and safety improvement. code.claude.com (opens in a new tab), Data policies › Data retention, in a list, read 2026-09-24. On Consumer: Anthropic's page: for Consumer users (the Free, Pro and Max plans) who do not allow their data to be used for model improvement, Claude Code data is kept for 30 days. code.claude.com (opens in a new tab), Data policies › Data retention, in a list, read 2026-09-24. Zero-retention option On Commercial, Enterprise: Anthropic's page, on what ZDR covers: ZDR extends to Claude Code when it runs on API keys that come from a Commercial organization, one under Anthropic's Commercial Terms of Service rather than a consumer Claude account, or when it is used through Claude Enterprise with ZDR turned on. platform.claude.com (opens in a new tab), Zero data retention (ZDR) › What ZDR covers, read 2026-09-24. On Enterprise: Anthropic's page, for Claude Code's commercial users: zero data retention (ZDR) is open only to accounts that qualify, for Claude Code used on Claude for Enterprise; it is not part of the standard Enterprise plan, and Anthropic's account team turns it on organization by organization once eligibility is confirmed. code.claude.com (opens in a new tab), Data policies › Data retention, in a list, read 2026-09-24. Training use On Commercial, Enterprise: Anthropic's page, for commercial users, a group whose list includes Enterprise: code or prompts that reach Claude Code on commercial terms are not used by Anthropic to train generative models, unless the customer has opted to give its data for model improvement, as in the Developer Partner Program. code.claude.com (opens in a new tab), Data policies › Data training policy, read 2026-09-24. On Consumer: Anthropic's page, for consumer users: when the setting that lets data be used to improve future models is on, Anthropic trains new models on the data of Free, Pro and Max accounts, their use of Claude Code included. code.claude.com (opens in a new tab), Data policies › Data training policy, read 2026-09-24. (marked †, explained in the key) On Consumer: Anthropic's page: Anthropic may train and improve its AI models on a user's Inputs and Outputs unless the user opts out in account settings. www.anthropic.com (opens in a new tab), 2. Uses of Personal Data Permitted Under Applicable Data Protection Laws, read 2026-09-27. Model provider Anthropic's page: to reach the model, Claude Code sends data across the network, all prompts and model outputs among it, encrypted in transit with TLS 1.2 or later. code.claude.com (opens in a new tab), Local Claude Code: Data flow and dependencies, read 2026-09-24. On Hosted on Azure: Anthropic's page: for Hosted on Azure deployments, the only data Anthropic receives is usage metadata and content that its safety systems flag. code.claude.com (opens in a new tab), Local Claude Code: Data flow and dependencies, table "Local Claude Code: Data flow and dependencies", row "Microsoft Foundry", column "Encryption at rest", read 2026-09-24. Where it can run Anthropic's page, in its section on local Claude Code's data flow: Claude Code runs on the local machine. code.claude.com (opens in a new tab), Local Claude Code: Data flow and dependencies, read 2026-09-24. Telemetry Anthropic's page: Claude Code's metrics, covering latency, reliability and how it is used, go over TLS both to Anthropic and to logging infrastructure run by third parties. code.claude.com (opens in a new tab), Telemetry services, read 2026-10-01. Anthropic's page: Claude Code's error reports, carrying stack traces and the messages of errors raised inside its own code, go over TLS to an error-tracking service that a third party runs. A few lines on, the page limits this: error reporting is active only if the user has signed in on a Pro or Max subscription, the Claude Code version in use is 2.1.198 or later, the connection goes straight to the Claude API, and the user's organization has no HIPAA or zero data retention agreement. code.claude.com (opens in a new tab), Telemetry services, read 2026-10-01. Anthropic's page: Claude Code sends operational telemetry of two kinds, usage metrics and error reports. A few lines on, the page limits the error reports: error reporting is active only if the user has signed in on a Pro or Max subscription, the Claude Code version in use is 2.1.198 or later, the connection goes straight to the Claude API, and the user's organization has no HIPAA or zero data retention agreement. code.claude.com (opens in a new tab), Telemetry services, read 2026-09-24. Anthropic's page: each of the two kinds of telemetry can be switched off on its own through environment variables the page lists, and setting CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC turns off all non-essential traffic together. code.claude.com (opens in a new tab), Telemetry services, read 2026-09-24. Anthropic's page: WebFetch's domain safety check and session quality surveys are exceptions to the provider-based defaults and run whichever provider is in use. code.claude.com (opens in a new tab), Default behaviors by API provider, read 2026-09-24. Under running Claude Code through Amazon Bedrock, Google Cloud's Agent Platform, Microsoft Foundry or Claude Platform on AWS: Anthropic's page: on Microsoft Foundry, Amazon Bedrock, Claude Platform on AWS or Google Cloud's Agent Platform, Claude Code turns off telemetry, error reporting and bug reporting by default. code.claude.com (opens in a new tab), Default behaviors by API provider, read 2026-09-24. | ||||
| Tool | What it is | Compliance | Type | Read |
|---|---|---|---|---|
| Infisical/infisical (opens in a new tab) | A self-hosted service (with a managed tier) that holds secrets and brokers credentials on an outbound call, so the agent holds a placeholder and never the real value. | You run it, so you answer these. | repository | observed 2026-09-03 |
Not a compliance determination. Each item repeats what the vendor’s own page says, and links to it. Check that page, and your own agreement, before relying on it.
As the authors of the compliance record wrote them, in the file this page is built from. Where they mention the tool list or a list of pages read, those are parts of the record this site does not publish. What they call a row’s dataHandling is the Data handling line under each tool here, their marks.null is the definition shown here as Blank, and their also is the list of further entries under each restriction. This page leaves out items marked No, as it does blank ones, and the record's sentences that only describe its own file format: the keys each entry carries, and when the format number changes.
One row for each hosted product group in a tool's data and compliance block (the block is under the tool's "Tool-list entry" heading in the regulated-data statements, and each group is a "For …" line there naming a product), so a block with two such groups has two rows; one mark per compliance item, from what the maker's own pages state, each linked to the page behind it. Not a compliance determination: read the linked page before relying on a mark. An empty mark means no current statement taken for this product from what was read marks the item, and the cell's blank gives the reason in one word: the status word of the line that left it empty, or PARTLY-EXCLUDED, which no line reads. It never means the item does not hold. Retention, training use, residency and the other data-handling questions are in each row's dataHandling, never among the marks, and the full data and compliance block for each tool (called the block below) is in the regulated-data statements document, under that tool's 'Tool-list entry: <entry>' heading, where <entry> is the row's entry; the tool list entry gives only a short summary. For HIPAA and GDPR a mark reads only the maker's own claim that its product complies with or supports the law: a definition of the law, a bare badge or a data processing addendum never marks either. On the GDPR and HIPAA columns the word comes from a reading of the maker's claim alone, which the block prints as no line of its own, so it can differ from the word on the block's GDPR or HIPAA BAA line. For HIPAA, a page read for the block's HIPAA BAA line counts as read for the claim, because that line shows the HIPAA sentences taken from the page, not only BAA offers. HIPAA BAA is marked Y only where the maker offers a Business Associate Agreement, and No where its page places the product outside one. A plan, deployment option or region shown in quotation marks is the maker's own name for it, and the marks are part of the value: keep them wherever the value is shown. A row resting on pages that speak for another product, whether or not another entry holds it, is not confirmed by being listed: its product names whose marks it carries.
A tool resting on several products passes the filter when they carry the checked items between them. For where customer data goes, model by model, see customer data by cloud.
Kiro Cloud Sessions shows nothing because the pages it rests on do not fully cover it. The reason is in the record’s own words below.
Entries run by their operator (open-source software and model weights) are not listed: whoever runs them answers these questions for their own deployment. Where the maker also runs the same software as a hosted service, that hosted tier is a separate product and gets its own row once one of the maker's pages establishing it has been read; until then it has no row, and its absence says nothing about it. Also not listed: entries whose block rests on the same pages as an entry listed here, where a read of those pages found part of that record outside the entry. No marks are shown for them, and the listed entry's marks should not be read as theirs; each reason says what the pages show: Kiro Cloud Sessions. AWS's HIPAA eligible services reference lists Kiro with Kiro Web carved out; Kiro's documentation describes cloud sessions as the environment that runs Kiro Web and Mobile, so part of what cloud sessions run falls on the side AWS carves out. The IDE and CLI can also attach to them, and no page read says whether a session reached that way counts as eligible. aws.amazon.com/compliance/hipaa-eligible-services-reference (opens in a new tab), read 2026-09-24; kiro.dev/docs/cloud-sessions (opens in a new tab), read 2026-09-24.
These keep working on tools that never appear here.
Stars. Attention accumulated over a repository's whole life, so age is part of what it measures: an older project out-stars a better younger one by default. Nothing prompts anybody to un-star a project they stopped using.
Last push. When a commit last reached the default branch. A bot bumping a dependency and a rewrite of the scheduler are the same date here, and a project whose real work happens on release branches looks quieter than it is.
Archived. The owner set a flag, which is a fact rather than an inference. What it means is ambiguous: a project that moved to a new organization leaves a tombstone identical to one that stopped. Check whether the same name is alive somewhere else before concluding anything.
The license, twice. What the host reports and what is actually in the tree are not always the same answer. For anything you copy into your own repository, the directory you copy is the unit to check, at the revision you copy it from.
Open issues. The count rises with adoption and falls with triage policy, so a low number means few problems, or no queue, or a bot closing them on a timer. A signal with opposite readings is not a signal until you know which regime you are in.
And read the date, never the interval. Somebody else's "updated three months ago" was computed once, and it goes wrong while every input to it stays right. Do the subtraction yourself, against today.