How we assess AI governance platforms

In brief

We score six AI governance platforms from 0 to 10 on eight weighted criteria, using only their own public pages read on 1 October 2026. Totals, ranks and winners are computed from those scores.

By The Charter Desk, Agentic Governance Compare · Published 2026-10-01 · Vendor pages read 1 October 2026 · Editorial assessment

§ 1 What do we measure?

We measure how much of the governance chain each platform documents publicly: from a written policy, to a control that enforces it, to evidence that it worked, to a report an auditor can read. That is why runtime enforcement and testing evidence carry the most weight. A platform that documents only inventory and reporting can still be the right tool for a program that is just starting; the readiness score lets you re-weight for that.

The eight criteria and their weights
CriterionWeightDefinition
AI discovery and inventory12Does the platform find and list the AI models, agents and applications in use, so governance has a register to work from?
Policy to runtime enforcement18Is a written policy turned into a control that acts on live prompts, responses or agent actions, rather than staying a document?
Testing evidence16Does the platform produce adversarial test results (red teaming, drift and regression checks) that feed governance records?
Framework mapping and audit-ready reports14Are controls and findings mapped to the EU AI Act, ISO/IEC 42001, NIST AI RMF, OWASP or MITRE ATLAS, with reports an auditor can use?
Regulatory intelligence and expert support10Does the vendor describe a regulatory knowledge source, managed service or expert-led work alongside the software?
Third-party AI governance10Can the platform register and assess AI that comes from vendors and SaaS tools, not only AI the company builds?
Languages and modalities10Are languages and modalities (text, image, voice, multimodal) stated, so controls cover what customer-facing AI actually receives?
Pricing and trial transparency10Can a buyer see prices, plan contents, a free tier or open-source tooling before talking to sales?

§ 2 What does each score mean?

Scoring scale
ScoreMeaning
0Nothing on the pages reviewed.
1 to 3Mentioned in passing, or a related feature only. 'Not published' pricing scores 1.
4 to 6Described as a feature, with limited detail on how it works.
7 to 8Described in detail, usually on a dedicated page, with named capabilities.
9 to 10Described in detail across several pages, with named frameworks, workflows or outputs that make it usable as evidence.

§ 3 How are totals computed?

Total = sum of (criterion score x weight) / 100. We compute totals in code from the published scores and weights and show them to two decimals. Ranks sort by the exact total; equal totals share a rank. Every 'leads', 'wins', 'trails' and 'beats' statement on the site is computed from the same data.

  1. 01Pillar Security6.886.88
  2. 02Alice6.226.22
  3. 03Credo AI6.006.00
  4. 04SPLX5.965.96
  5. 05Lasso5.605.60
  6. 06Holistic AI5.205.20

§ 4 What sources do we use?

Only the vendors' own public pages, documentation, pricing pages and press releases, plus the official pages of the frameworks we cite (EU AI Act, ISO/IEC 42001, NIST AI RMF, OWASP Top 10 for LLM Applications, MITRE ATLAS). Every score links to the page it came from. All pages were read on 1 October 2026.

§ 5 What are the limitations?

  • Public sources only. We did not use the products.
  • No hands-on testing, no vendor briefings, no customer interviews.
  • A feature we mark 'Not described' may exist; it was not on the pages we read.
  • Vendor numbers (languages, latency, users, funding) are the vendors' own claims. We attribute them and do not verify them.
  • Analyst placements a vendor cites are reported as the vendor's citation, never as our rating.
  • Scores are an editorial assessment and change when vendor pages change.

§ 6 Who writes this site?

The Charter Desk is the editorial name of Agentic Governance Compare. Pages are written from the sources above and dated.

§ 7 How do corrections work?

When a vendor's public page changes, we re-read it, update the score and its reason, and record the change and the date here. No corrections yet: this edition was published on 2026-10-01.

Questions about the method

  • Did you test the products?

    No. Scores come from public vendor material only.

  • Why these six platforms?

    They are the platforms whose public pages describe AI governance for apps and agents in production: inventory-first governance platforms (Credo AI, Holistic AI) and platforms that pair runtime controls with testing and framework mapping (Alice, Pillar Security, SPLX, Lasso).