Method · Edition 2026.09
How we score AI compliance software
By the Signal Desk, AI Compliance Compare · Reviewed 2026-09-29
Short answer
Each platform gets a 0 to 10 editorial score on eight criteria, each with a one-line reason and a source link. The total is a weighted average computed from the weights below. Everything comes from vendors’ public pages read on 2026-09-29; we did no hands-on testing and interviewed no vendors.
What are the criteria and weights?
| Criterion | Weight | Question |
|---|---|---|
| AI agent coverage | 18 | What do the vendor's AI agents actually do, task by task, on its own pages? |
| Human expert involvement | 16 | Is a named human expert assigned and proactive, or is help reactive or routed to partners? |
| Multi-framework depth | 16 | How many frameworks does the vendor state, and does it describe cross-mapping or a common control set? |
| Audit path clarity | 10 | Does the vendor explain who audits you and how the audit is run? We score this instead of speed claims. |
| Integrations (published count) | 12 | How many integrations does the vendor publish, as a stated number? |
| Openness | 8 | Can a buyer inspect how the product works, for example through published source code? |
| Pricing transparency | 10 | Can a buyer see prices, or at least plan contents and limits, before a sales call? |
| Maturity | 10 | How large is the stated customer base and how broad is the published product set? |
| Sum of weights | 100 |
What earns a high or low score?
AI agent coverage
8 to 10: the vendor's pages name what its agents do across most of the five tasks we track, including remediation. 6.5 to 7.5: several tasks named. 5 to 6: automation or agents claimed without a task breakdown. 0 to 4: little or no AI described.
Human expert involvement
9 to 10: a named or dedicated expert is assigned and runs readiness and the audit. 6 to 8: direct access to vendor experts on request, such as a Slack channel. 3 to 5.5: expert help through partners, or standard support channels. 0 to 2: none described.
Multi-framework depth
9 to 10: 150+ stated frameworks with a described common control set or cross-mapping. 6.5 to 8: 30 to 100 stated frameworks, or cross-mapping stated. 4 to 6: 5 to 15 frameworks named, no mapping described. 0 to 3: fewer than five.
Audit path clarity
9 to 10: the vendor explains who audits you and manages the audit process with you. 6 to 8.5: an auditor network or in-platform audit management is described. 3 to 5: readiness or speed is claimed but auditors are not described. 0 to 2: nothing about compliance outcomes at all.
Integrations (published count)
9 to 10: 400+ stated. 7 to 8: 250 to 399. 5 to 6: 100 to 249, or 'hundreds' without a number. 3 to 4: no count published. We score the number a vendor publishes; where its own pages disagree we use the range.
Openness
9 to 10: product source code is published. 3: no source code published (the default for closed products). Values in between would apply to published APIs or documented agent actions, which no vendor here earned on the pages reviewed.
Pricing transparency
9 to 10: prices published. 5 to 6: no prices, but plan contents with numeric limits or allowances published. 4 to 4.5: plan names and contents without numeric limits, or named price drivers. 0 to 3: no pricing page or plan information.
Maturity
9 to 10: 10,000+ stated customers and a broad product set. 7 to 8: 4,000 to 9,999. 5 to 6: 1,000 to 3,999. 3 to 4: under 1,000 or not stated.
How are totals computed?
Total = sum of (score x weight) / sum of weights. Totals are shown to two decimals because the top two platforms are close. Platforms are ranked by the exact value; equal values are shown as ties. A criterion winner is the platform with the highest score in that row; tied top scores are all marked. Every total, rank, winner and ‘scores higher on’ line on this site is computed in code from the same data file, so the ranking, the versus pages, the line-up and the stack builder always agree.
Which evidence do we use?
- Each vendor’s own public website, read on 2026-09-29 (source links sit next to every score).
- One press report where a vendor’s own site links to it (TechCrunch on Comp AI’s Series A, 2026-09-17).
- Standards bodies’ own pages for definitions (iso.org for ISO/IEC 27001:2022; aicpa-cima.com for the SOC suite).
- Where a vendor’s pages do not describe something, we write ‘Not described’ or ‘Not published’. That is a statement about the page, not a finding that the feature is missing.
What do we leave out?
- Speed claims such as ‘audit-ready in days’ or ‘85% faster’. They are shown as attributed vendor claims and carry no points.
- Review-site ratings and review counts quoted on vendor pages.
- Superlatives such as ‘the only’ or ‘world’s first’; where we mention them we attribute them.
- Anything we could not read on a public page: private pricing, contract terms, product behaviour behind a login.
What are the limitations?
Public sources only: no hands-on testing, no trials, no vendor interviews, no customer interviews. Vendor pages change; everything here reflects 2026-09-29. Counts are as stated by vendors and are not audited by us. Criteria and weights are editorial choices; the stack builder lets you replace ours with yours.
How do we handle corrections?
Vendors and readers can contact us with a link to a public page. If the page supports the correction, we update the data file, the scores recompute, and the change is logged below with its date.
Changelog
2026-09-29: First edition. Six platforms, eight criteria.
Questions buyers ask
Did you test the products?
No. The scores are an editorial assessment of public vendor material read on 2026-09-29.
Why don't you score speed claims?
We cannot check them from public pages, and time to an audit report depends on the company and the auditor as much as on the tool. We score how clearly the vendor explains the audit path instead.