In brief
| Pillar Security | Alice | Credo AI | |
|---|---|---|---|
| Total | Leads | ||
| Rank | 01 | 02 | 03 |
| AI discovery and inventory · 12 | AI Discovery & Posture is one of four platform pillars, and third-party AI discovery is listed on the governance page. | No AI discovery or inventory feature is described on the WonderSuite pages reviewed; Centralized Governance covers the apps WonderFence protects. | Leads Credo AI describes discovering AI across agents, models and apps and keeping an agent registry. |
| Policy to runtime enforcement · 18 | Ties for lead Runtime guardrails block prompt injection, jailbreaking and tool manipulation and mask PII, PHI and secrets; policies cover approved model lists and data sovereignty. | Ties for lead WonderFence intercepts harmful, non-compliant and off-policy responses between external-facing AI and users, configured to the application's own policies. | Credo AI says it enforces policy; runtime blocking of prompts, responses or agent actions is not described on the pages reviewed. |
| Testing evidence · 16 | Ties for lead The RedGraph engine runs multi-turn agentic red teaming with transcripts, and guardrails calibrate from red teaming findings. | Ties for lead WonderBuild tests before launch from custom policies and WonderCheck retests in production with drift and regression detection; findings flow into WonderFence or back to WonderBuild. | Assess and monitor steps are described; adversarial testing or red teaming is not described. |
| Framework mapping and audit-ready reports · 14 | Ties for lead Pillar says it generates audit-ready reports for GDPR, the EU AI Act, ISO 42001 and SOC, and maps findings to OWASP and MITRE ATLAS. | Guardrails are mapped to the EU AI Act, ISO 42001, NIST, MITRE ATLAS and OWASP and every decision is logged; a named audit report product is not described. | Ties for lead The product covers discover, assess, govern, monitor and report against the EU AI Act, NIST and ISO. |
| Regulatory intelligence and expert support · 10 | Pillar publishes its own SAIL 2.0 framework; a regulatory intelligence feed or managed expert service is not described. | The platform combines automated testing with expert-led red teaming, and WonderBuild offers managed red teaming; a regulatory intelligence feed is not described. | Leads A Knowledge Graph of regulatory intelligence and forward-deployed experts are both described. |
| Third-party AI governance · 10 | Third-party AI discovery is listed, and red teaming covers third-party and SaaS AI. | No registry or assessment of third-party or vendor AI is described on the pages reviewed. | Leads A Third-party AI Registry is named on the product page. |
| Languages and modalities · 10 | Language and modality coverage is not described on the pages reviewed. | Leads The platform page lists coverage in 100+ languages, multimodal support and model-agnostic protection. | Language and modality coverage is not described on the pages reviewed. |
| Pricing and trial transparency · 10 | Ties for lead Pricing is not published. | Ties for lead No prices, free tier or self-serve sign-up are published; the route in is Get a Demo. | Ties for lead Pricing is not published. |
| Policy | Policy enforcement covers approved model lists and data sovereignty. Source: Pillar Security governance and compliance page · read 2026-10-01 | Policies are configured to the customer's application: WonderFence is 'Built for Your Policies' and the platform lists adaptive and custom policies. Source: Alice WonderFence product page · read 2026-10-01 | A Knowledge Graph of regulatory intelligence informs policies; Credo AI describes enforcing policy across agents, models and apps. Source: Credo AI home page · read 2026-10-01 |
| Control | Runtime guardrails block prompt injection, jailbreaking and tool manipulation and mask PII, PHI and secrets. Source: Pillar Security runtime guardrails page · read 2026-10-01 | WonderFence sits between external-facing AI and its users and intercepts harmful, non-compliant and off-policy responses in real time. Source: Alice WonderFence product page · read 2026-10-01 | Not described Source: Credo AI product page · read 2026-10-01 |
| Evidence | Every prompt, response and tool call is logged; the RedGraph engine runs multi-turn agentic red teaming with transcripts. Source: Pillar Security red teaming page · read 2026-10-01 | WonderBuild runs thousands of adversarial tests based on custom policies before launch; WonderCheck retests after launch with drift and regression detection; every WonderFence decision is logged. Source: Alice WonderCheck product page · read 2026-10-01 | Assess and monitor steps are described across agents, models and apps. Source: Credo AI product page · read 2026-10-01 |
| Report | Pillar says it generates audit-ready reports for GDPR, the EU AI Act, ISO 42001 and SOC. Source: Pillar Security governance and compliance page · read 2026-10-01 | WonderFence maps guardrails to the EU AI Act, ISO 42001, NIST, MITRE ATLAS and OWASP; WonderBuild maps test documentation to regulatory requirements and tracks launch readiness. Source: Alice WonderBuild product page · read 2026-10-01 | Reporting against the EU AI Act, NIST and ISO is described, alongside a Third-party AI Registry. Source: Credo AI product page · read 2026-10-01 |
| Status | Pricing not published | Pricing not published · Demo only | Pricing not published |
| Pricing | Not published Source: Pillar Security home page · read 2026-10-01 | Not published No free tier or self-serve sign-up was found; the route in is Get a Demo. Source: Alice documentation · read 2026-10-01 | Not published Source: Credo AI product page · read 2026-10-01 |
Two to five at a time.
Yes. The shortlist uses the published weights. To change the weights, use the readiness score.
Because the vendor's public pages we read did not describe that step. It is not a finding that the feature does not exist.