Loading…
Loading…
Tools · Vendor Scorecard
Compare 15 AI vendors across 11 governance dimensions — data retention, SOC 2, HIPAA BAA, ISO 27001, EU residency, and more. Filter by vendor type, use case, and compliance requirements.
Filters
Vendor type
Use case
Minimum green checks
15 vendors
✓ = confirmed · ✗ = not available · ? = unknown
GPT-4o, o1, and DALL·E via API. The most widely deployed foundation model provider.
Zero data retention available via API with opt-in header. HIPAA BAA available for eligible API customers.
Claude 3.5 and Claude 4 via API. Strong safety focus, used widely for enterprise reasoning tasks.
API prompts and outputs are not used for training by default. No HIPAA BAA currently offered.
Gemini 1.5 and 2.0 via Vertex AI or AI Studio. Deep integration with Google Cloud.
EU data residency and HIPAA BAA available via Vertex AI with region selection.
European-built foundation models via API. Strong EU data residency story as a French company.
Headquartered in Paris — EU data residency by default. SOC 2 and ISO 27001 status not publicly confirmed.
Enterprise-focused embeddings and generation models. Strong on retrieval and RAG use cases.
Specialises in enterprise search and RAG pipelines. HIPAA BAA available for enterprise customers.
OpenAI models hosted on Microsoft Azure with enterprise data controls. Best for orgs already in Azure.
Your data is not used to train OpenAI or Microsoft models by default.
Access to multiple foundation models (Claude, Titan, Mistral, Llama) via AWS with enterprise security controls.
Model provider data policies vary — check per-model docs. HIPAA BAA available under AWS BAA.
OpenAI's consumer chat product. Widely used by individuals and small teams for everyday AI tasks.
Disable chat history in Settings to stop conversation storage. Not HIPAA-eligible — use API or Enterprise instead.
Anthropic's consumer chat interface. Distinct governance terms from the Anthropic API.
Consumer plan conversations may be used to improve models unless opted out. No HIPAA BAA for consumer tier.
AI assistant integrated into Word, Excel, Teams, and Outlook. Enterprise-grade data controls.
EU Data Boundary available. Data is not used to train foundation models. Requires Microsoft 365 E3/E5 licence.
AI-native code editor built on VS Code. Privacy Mode prevents code from being stored or used for training.
Enable Privacy Mode in Settings → General to prevent code from leaving your machine for storage.
AI writing and Q&A features built into Notion workspaces. Add-on to existing Notion plans.
EU data hosting available. AI content is not used to train third-party foundation models. No HIPAA BAA.
AI writing assistant for grammar, style, and tone. Widely used across browser, desktop, and Office integrations.
Text you write may be used to improve Grammarly's models. EU data processing available via DPA. No HIPAA.
AI code completion and chat in your IDE. Built on OpenAI models, integrated into GitHub.
Org admins can disable telemetry and code snippet sharing. No HIPAA BAA.
AI-powered search and research assistant. Answers questions with cited web sources in real time.
Queries may be used to improve models. No SOC 2, DPA, or HIPAA BAA currently available.
Data reflects publicly available vendor documentation as of the verified date shown on each card. Verify directly with vendors before procurement decisions. See vendor analysis posts →