Credo AI vs Holistic AI: how they compare in 2026

C
Credo AI profile
H
Holistic AI profile
Last verifiedSeptember 26, 2026

Credo AI and Holistic AI both sell platforms that find the AI an organization runs, test and score its risk, and map it to the EU AI Act, NIST and ISO 42001. Credo AI sits in the top two bands on nine of fifteen axes and Holistic AI on four of fifteen, identical on nine. Credo AI's lead is on paper. Its terms of use are public, with a clause barring training on customer data and a sixty day export window before deletion. They promise breach notice without undue delay and cap liability at a year's fees beside an intellectual property indemnity. It also names Mastercard and Principal as customers. Holistic AI publishes no customer agreement, names no customer and gives no hosting region. Its counterweight is a published account of what its agents may do alone. Sentinel agents only observe and alert, while Operative agents act inline once a risk threshold the customer sets is crossed, with kill switches, deployment blocks and human approvals named.

At a glance

Category
Credo AIRegulatory & Compliance Counsel
Holistic AIRegulatory & Compliance Counsel
Founded
Credo AINot published
Holistic AINot published
Headquarters
Credo AILos Altos, California, United States
Holistic AILondon, United Kingdom
Last verified
Credo AISep 7, 2026
Holistic AISep 7, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Credo AI
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

Generative capability is the engine of a core capability layered on a governance system of record that would function without it. The platform's spine is an inventory and a workflow: an AI registry with agent cards and dependency graphs, a risk and control library, policy packs mapped to named regulations, approval gates, audit trails and evidence generation. That is a system of record a customer could run with human analysts filling it in, and the vendor's own account of its history says as much, describing a 2020 to 2023 phase whose breakthrough was replacing spreadsheets and ad-hoc reviews with a policy engine. What the models add is GAIA, a set of governance agents that perform intake and registration, retrieve evidence, assess risk, draft governance plans and remediate, plus automated red-teaming, drift detection and shadow AI classification. Remove them and the registry, the policy packs and the workflows remain. Product page and Terms of Use read 7 September 2026.

Holistic AI
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

The models are the engine of the core capabilities, layered on a governance system of record that would survive without them. Holistic AI states that every capability in the platform is powered by Guardian Agents, and the capabilities that clearly depend on models are substantial: agentic and language model red teaming for jailbreak, prompt injection, toxicity, hallucination and counterfactual bias; automated testing for bias, robustness, efficacy, privacy and transparency; automated discovery and classification of AI assets across cloud, code and SaaS; drift detection and agent observability. Strip those out and what remains is still a product: a centralised AI inventory with custom schemas and ownership tracking, a governance ontology, framework assessments against named regulations, configurable sign-off workflows, and audit-grade documentation. That is what most of this lane sells on its own. The vendor's claim of total dependence is recorded and not adopted, because the registry, the workflows and the compliance evidence layer do not require a model to function. Platform page and homepage read 7 September 2026.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Credo AI
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Accuracy is asserted in numbers and measured in none of them, and the agreement disclaims it outright. The product page carries 10x faster compliance, 70 per cent reduced time in engineering bottleneck, 100 per cent AI visibility and 360-degree risk coverage, none with a basis, method or test set, and a customer quote repeats the 10x figure for EU AI Act compliance. Section 8.6 of the Terms of Use states in terms that Credo AI makes no warranties or representations regarding the accuracy, reliability, timeliness or completeness of the services. Several limbs of this band do not bite and are named rather than penalised: the platform produces risk scores, control mappings and evidence artefacts rather than legal assertions citing authority, so there is no citator and no reported case to open. What does bite is the limb that matters most for a product whose output is a compliance conclusion mapped to a named statute: nothing published lets a buyer test how often GAIA's evidence retrieval or risk mapping is right, and no grounding method is described. Product page and Terms of Use read 7 September 2026.

Holistic AI
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Accuracy is asserted in absolute terms and measured nowhere. The claims are unusually strong: identify every AI system, full visibility into every AI system, a complete and always-current AI inventory, continuously discover and inventory every model, agent, API and pipeline. No figure, evaluation, test set or false-negative rate is published for discovery or classification, and a third-party buyer's guide notes separately that coverage depends on the integrations, data sources, permissions and configuration in use and that the platform should not be assumed to identify every AI system, which is described rather than credited. The irony worth recording is that this product tests other systems for hallucination and publishes no measurement of its own output. Most limbs of this band do not bite and are named rather than penalised, since the outputs are inventories, risk scores and evidence artefacts rather than legal assertions citing authority. What bites is the limb that a completeness claim is the product's central promise and nothing published lets a buyer test it. Platform page and homepage read 7 September 2026.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Credo AI
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

A written commitment that the agents work alongside a person, with real review surfaces, short of the threshold. The product page states that GAIA's specialised agents automate the most time-consuming governance tasks while maintaining human oversight for critical decisions, and the mechanisms are named rather than gestured at: governance workflows with approval gates in the compliance module, human-in-the-loop escalation workflows in production monitoring, and human-in-the-loop escalation specifically for high-risk actions in the agentic monitoring phase. Continuous evaluation of agent traces feeds those escalations. That is more than most records on this axis publish, and it is worth crediting on a product whose own agents can run remediation. What is not published is the control structure behind it: no statement of which actions GAIA may take unattended, no threshold or criterion that defines a critical decision or a high-risk action, and nothing on what happens after a remediation agent acts wrongly. That is precisely the limb this band names as commonly absent. Product page read 7 September 2026.

Holistic AI
AA on Autonomy and Oversight ModelWhat the system runs alone, what constrains it, and how a lawyer checks it are all published: modes, thresholds, review surfaces, and the route a matter takes back to human judgment. A categorical limit on a named mode or tier, stating what its output may not be used for, meets the threshold limb without a number.

What the system runs alone, what constrains it and how a person checks it are all published, and the division is drawn explicitly rather than asserted. Guardian Agents operate in two named modes with different powers. Sentinel agents continuously monitor what a customer's AI says in production, detecting prompt injection, jailbreak, data leakage, hallucination, toxicity and bias, and the vendor states in terms that Sentinels provide visibility, do not interfere and inform. Operative agents act only when risk crosses a defined threshold, and what they may then do is enumerated rather than gestured at: govern which tools the system calls, what it can access, how much it can spend, and agent identity, with kill switches and deployment blocks listed separately under policy enforcement. The review surfaces are named alongside: human-in-the-loop approvals, configurable sign-offs, intake and review workflows, escalations and notifications, mitigation tasks, remediation tracking, and full audit trails with version history and on-demand reports. The enterprise section states that workflows, risk thresholds, policies and approval processes are customer-configurable, so the threshold is a control the buyer sets rather than a number the vendor hides. Two things are not published and are recorded here: no default threshold value appears anywhere, and nothing states what happens when an Operative agent intervenes wrongly. Platform page read 7 September 2026.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Credo AI
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Named customers with named people, short of dates and method. The product page carries attributed statements from Andrew Reiskind, Chief Data Officer at Mastercard, on managing AI risk and implementing generative AI at speed and scale using the AI Registry and Vendor Registry; Renee Langeness, Director of Data Governance at Principal, on standing up an enterprise AI governance workflow; Parth Patel, Executive Director for AI and Data Science, on complementing internal processes; Kathleen Cachel, Senior Data Scientist at AdeptID, on centralised support for annual technical audits; and Brad Mallard, a CTO, on using the platform internally for compliance with its own policies and the EU AI Act. Partner statements from Microsoft's Chief Product Officer for Responsible AI and IBM add substance about what the integration does. One figure appears inside a customer quote, compliance with the EU AI Act at ten times the speed of doing it manually, with no method attached, and the page's own counters carry no basis. No deployment is dated. The customers and case studies page was not read and is the route to more. Product page read 7 September 2026.

Holistic AI
DD on Operational and Outcome EvidenceNo production evidence located. Announcements, funding and launch coverage are not deployment evidence.

No production evidence was located. No customer is named on any surface read, no deployment is dated, no figure for what changed is published, and no customer story or case study surface was located in the site material returned. The outcome claims that do appear are unattributed and carry no basis, such as the homepage statement that projects which sat blocked for months now get approved in days. Two third-party observations are described and not credited: a buyer's guide notes that named enterprise customer references in Holistic AI's public documentation are less specific than for comparable platforms and puts the company at roughly fifty employees, and the OECD AI catalogue carries a vendor-supplied entry describing the platform's research basis without naming a deployment. This grade records what is establishable on the date rather than a finding that no customers exist; a named, dated deployment with a figure on the vendor's own surface is the route to a higher grade. Platform page, homepage and search index checked 7 September 2026.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Credo AI
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Substantive published commitments, including one that is unusually specific, short of segregation and of a limb the agreement itself complicates. What is committed: section 6.8 of the Terms of Use bars Credo AI from using, processing or otherwise accessing User Data to train, develop or improve any machine learning or artificial intelligence model, and confines its access to providing, maintaining and supporting the service; the same clause names the enterprise AI tools Credo AI's staff may use to deliver the service, states that use is confined to Credo AI's own enterprise environment and team members, that no user data leaves it, and that such data is deleted at the end of the engagement. Section 11.3 makes User Content the customer's Confidential Information, 11.4 limits disclosure to those with a need to know under equivalent obligations, and 6.6 sets a sixty-day post-termination window followed by deletion. Two things hold it here. Nothing published addresses segregation between customers or between teams inside a tenant. And section 5.2 grants Credo AI a worldwide, sublicensable, transferable licence to use, reproduce, modify, adapt, publish, translate, create derivative works from, distribute, perform and display User Content in connection with providing and improving the services: the purpose limitation is narrow but the verbs are not, and a governance platform holds a customer's AI risk assessments and incident records. Terms of Use read in full 7 September 2026.

Holistic AI
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Confidentiality is asserted in general terms and no commitment a buyer could read before signing was located. What exists: the privacy policy states that a secure protocol is adopted, that databases are encrypted, and that the cloud databases comply with ISO 27001, all written from the controller side about personal data of website visitors and contacts rather than about customer content in the platform; the product page promises enterprise-grade protection and, more usefully, describes the discovery connectors as read-only with no agents to install, which is a real limitation on what the platform can do inside a customer estate. What is absent is the substance this axis grades. No customer agreement or data processing agreement was located, so there is no published confidentiality obligation over the material the platform ingests, which extends to code, data, models and documents. Nothing addresses training on customer content, segregation between customers, what model providers behind the vendor's own agents may retain, or the handling of privileged or work-product material a discovery scan might reach. Privacy policy, platform page and homepage read 7 September 2026.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.

Credo AI
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

A boilerplate disclaimer sits in the terms while the marketing describes regulatory conclusions, and nothing addresses where the output stops and a legal judgement begins. The product is sold on full alignment with European AI regulation including risk classification and conformity assessments, complete NIST Risk Management Framework compliance, and audit-ready documentation for every major AI regulation. Classifying a system's risk tier under the EU AI Act is a legal characterisation with consequences, and the company also sells advisory services described as strategic advisory related to AI governance. The counterweight located is section 8.6, disclaiming any representation as to accuracy, reliability, timeliness or completeness, which is a warranty disclaimer rather than a statement about advice. Nothing published says that a policy pack mapping, a risk classification or a conformity artefact is not legal advice, that counsel remains responsible for the determination, or which jurisdictions the regulatory content is maintained for. The audience is unambiguous and professional, which is recorded rather than credited. Same grade and same reasoning as the comparable records in this lane. Terms of Use and product page read 7 September 2026.

Holistic AI
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

Boilerplate disclaimers sit in the website terms while the marketing describes regulatory conclusions, and nothing addresses where the output stops and a legal judgement begins. The platform is sold on enforcing regulatory compliance, generating the compliance proof that legal and boards require, framework assessments against the EU AI Act with risk classification, and New York City Local Law 144 bias audits. Classifying a system's risk tier under the EU AI Act and producing a Local Law 144 bias audit are characterisations with legal consequence, and Local Law 144 requires an independent auditor, which makes the boundary between tool and attestation worth stating. Nothing published states that these outputs are not legal advice, that counsel remains responsible for the determination, or what jurisdictional coverage the framework content carries. The only disclaimer language located is in the website terms and conditions, which govern the website rather than the platform and do not grade it. Same grade and reasoning as the comparable records in this lane. Platform page, homepage and website terms read 7 September 2026.

AI Governance and Bias Disclosure

Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Credo AI
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

Principles and a commitment are published; a governance framework for the vendor's own AI is not. Credo AI publishes an ethos page, runs an annual AI trust summit, maintains a public governance insights hub and glossary, and positions itself as the company that pioneered the category, so responsible AI language is abundant. One commitment goes further than language and is credited here as real substance: section 6.8 of the Terms of Use is a binding statement about how Credo AI handles customer data in relation to AI models, including which enterprise AI tools its own staff may use. What is still absent is the governance half. Nothing published names who inside Credo AI is accountable for GAIA's behaviour, describes what is evaluated before a governance agent ships, reports any result from such evaluation, or discloses anything about uneven output across sectors, jurisdictions or populations. The company sells ISO 42001 policy packs and does not claim the certification for itself, and the trust centre that might carry more returns no body on this channel and is named as the rebuttal route. Terms of Use, product page and trust centre attempted 7 September 2026.

Holistic AI
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

A published methodology for assessing other people's AI, and nothing published about governance of the vendor's own. Holistic AI is research-led and the substance is real on the product side: the platform's risk taxonomy derives from published academic work on bias, robustness, privacy and transparency, framework alignment is named down to the instrument, and bias testing including counterfactual testing is a core capability rather than a claim. None of that is a governance position for the vendor's own Guardian Agents, which observe production traffic and intervene inline. Nothing located names who inside Holistic AI is accountable for their behaviour, describes what is evaluated before an agent ships, publishes any result from such evaluation, or discloses whether the vendor's own bias detection performs unevenly across languages, sectors or populations. No responsible AI policy, model card or system card for the platform's own models was located. The company sells ISO 42001 alignment and does not claim the certification for itself. Platform page and homepage read 7 September 2026.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Credo AI
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

Substantive published policy across most of the ground, short of the security detail and the subprocessor list. What is published in the Terms of Use: retention and deletion are specific, with User Data retained as long as needed to provide the services, a sixty-day post-termination window for export using standard export features, and deletion after it (6.6); access is confined by 6.8 to providing, maintaining and supporting the service, with the enterprise AI tools used by staff named and their data deleted at the end of the engagement; incident practice is stated, with notice without undue delay after becoming aware, reasonable steps to mitigate and minimise damage, and an express statement that notification is not an admission of fault (6.9); aggregated and anonymised use is permitted but conditioned on non-attribution (6.7); and confidential information must be returned or destroyed on request with written certification (11.7). What is missing is the specificity the top band needs. Security is described only as reasonable administrative, technical and physical safeguards, with no encryption standard, access control, testing regime or logging commitment; no subprocessor list was located; and the data processing agreement is provided on request rather than published. The Vanta-hosted trust centre would be the route to the security detail and returns no body on this channel. Terms of Use read in full 7 September 2026.

Holistic AI
CC on AI Safety and Data StewardshipA generic privacy policy covers the product without addressing what happens to documents and prompts after processing.

A generic privacy policy covers the company and nothing addresses what happens to customer content after processing. The privacy policy is written from the controller side about personal data of website visitors and business contacts: it states that a variety of security measures are implemented including a secure protocol and encrypted databases, that the cloud databases comply with ISO 27001, and that personal data is retained for as long as reasonably necessary and longer where a complaint or prospective litigation exists. That is a policy about the vendor's own contact data, not a stewardship commitment for the AI inventories, code scan results, model artefacts and documents the platform ingests. None of the five things this axis grades is published for customer content: no retention period, no deletion commitment or timeline, no access control statement, no subprocessor list, and no incident notification practice. The platform page carries a SOC 2 badge and describes read-only connectors, which limits ingestion but is not a stewardship term. No security page, trust centre or data processing agreement was located on any surface. Privacy policy and platform page read 7 September 2026.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Credo AI
AA on AI Liability and RecourseWhat the vendor stands behind when its output is wrong is published and specific: indemnity scope, caps, carve outs, and any insurance or warranty a buyer can actually invoke.

What the vendor stands behind is published and specific, including the places where it stands behind nothing. Section 10.1 of the Terms of Use gives a defence and indemnity against third-party claims that the services infringe or misappropriate intellectual property rights, with six named exclusions at 10.2 and the mitigation ladder at 10.3 of obtaining the right, modifying or replacing the services with substantially equivalent functionality, or terminating with a pro-rated refund. Section 9.2 caps each party's aggregate liability at the total paid in the twelve months preceding the incident, and 9.3 lifts the cap and the exclusion of indirect damages for breach of confidentiality and for the customer's breach of the licence and acceptable use terms. Two express warranties carry stated remedies: the SaaS products will perform materially in accordance with the documentation, remedied by correction or termination with a pro-rated refund (8.4), and advisory services will be performed in a professional and workmanlike manner, remedied by re-performance or refund (8.5), each declared the exclusive remedy. Section 8.6 disclaims everything else and states plainly that no representation is made about the accuracy, reliability, timeliness or completeness of the services, and 14.1 gives a termination right with a pro-rated refund if a change materially reduces functionality. No insurance is stated, the indemnity is not carved out of the cap, and the service level agreement is referred to as mutually agreed rather than published. Terms of Use read in full 7 September 2026.

Holistic AI
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

Nothing published states who bears the loss when the product is wrong, because no customer agreement was located on any surface. There is no indemnity, no liability cap, no warranty, no service level commitment, no exclusive remedy and no insurance statement to read, and no order form, subscription terms or master agreement was found published. That matters more than usual on this record: the platform's Operative agents intervene inline in a customer's production systems, activating kill switches, blocking requests and revoking privileges, and a buyer contemplating that has no published answer to what happens if an intervention is wrongly triggered against a working system. The only liability language located is in the website terms and conditions, which limit liability for the use of the website and its comment features; under the standing rule those terms govern the website rather than the platform and do not grade it. This records what is establishable on the date, with the cause named rather than assumed: the agreement may exist and be provided in a sales process, and nothing located says so. Website terms and all located surfaces checked 7 September 2026.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Credo AI
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Named integrations across the systems the work actually lives in, short of an implementer's description. The product page lists them by category: cloud and AI operations with AWS, Azure, GCP, Databricks and Snowflake; agent platforms with Azure AI Foundry, LangChain, CrewAI and AutoGen; governance, risk and security with ServiceNow, Archer, OneTrust and Qualys; development and MLOps with GitHub, MLflow, Jira, Confluence and Slack; and custom APIs, webhooks, SDKs and connectors, with a separate SDK documentation site and a stated ecosystem of more than thirty partners. One integration is described in enough detail to see what moves, and by the counterparty: Microsoft's Chief Product Officer for Responsible AI states that it delivers prescriptive guidance to governance leaders on what to evaluate and lets developers run governance-aligned evaluations inside their own workflow. The registry also governs MCP servers and platform connections. What is not published on the page read is per-integration depth, direction or configuration; the SDK documentation was not read and is not credited by its title. Product page read 7 September 2026.

Holistic AI
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Real integrations, named in quantity, with a genuine statement of posture, short of per-connector documentation. The platform page enumerates the enterprise surface it connects to: AWS, Azure and Google Cloud; GitHub, GitLab and Bitbucket; Databricks, MLflow and Weights and Biases; OpenAI, Anthropic and Google AI as model providers in the customer estate; LangGraph, CrewAI and AutoGen as agent frameworks; ServiceNow, Jira, Confluence and SharePoint as SaaS tools; plus MCP, REST APIs, webhooks, SDKs, endpoints and custom connectors, with counts given as fifteen or more on one module and twenty or more on the homepage. Two statements go beyond a logo wall and are worth crediting: the connectors are described as read-only with no agents to install, which tells an implementer what the platform will and will not do inside their environment, and inline enforcement is described as running through a named SDK rather than an unspecified integration. What is not published is per-connector depth: what each reads, at what frequency, and what a customer must configure or permission. Platform page read 7 September 2026.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Credo AI
DD on Deployment Model and Data ResidencyNothing published on where the software runs or where client data sits.

Nothing published on where the software runs or where customer data sits was located on any readable surface. The Terms of Use describe SaaS products accessed through a browser or API and say nothing about hosting region, data residency, tenancy or a deployment choice; the product page describes architecture in functional layers rather than infrastructure; no region selector, residency commitment or single-tenant option appears anywhere read. Two things are recorded so this reads as what it is. First, the vendor's trust centre at trust.credo.ai is a Vanta-hosted portal that returns page metadata with no body on this channel, so the surface most likely to carry hosting and residency detail could not be read; that is a retrieval limit under the standing convention, it is named here as the rebuttal route, and it would move this grade on a read. Second, the agreement does disclose one adjacent fact, at 15.9, that the services may be subject to United States and other export laws, which places the vendor in the US but is not a residency statement. This grade records what is establishable on the date. Terms of Use and product page read, trust centre attempted, 7 September 2026.

Holistic AI
DD on Deployment Model and Data ResidencyNothing published on where the software runs or where client data sits.

Nothing published on where the software runs or where customer data sits was located. The platform page describes the customer's infrastructure at length, naming the cloud providers, code repositories and data platforms it connects to, and says nothing about Holistic AI's own hosting: no region, no residency commitment, no tenancy model, no single-tenant or self-hosted option, and no statement of where processing happens as distinct from where data is stored. The enterprise section promises to be infrastructure-aware, which is about the customer's stack rather than the vendor's. Two adjacent facts are recorded without being credited as residency statements: the privacy policy describes databases as cloud-based and complying with ISO 27001, and first-party material places the company in London with the OECD catalogue describing a US presence. No security page, trust centre or data processing agreement was located that would ordinarily carry this. Platform page and privacy policy read 7 September 2026.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Credo AI
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

A certification is named by the vendor and no scope, date or reachable report was located. The trust centre at trust.credo.ai states, in the vendor's own words, that Credo AI maintains a SOC 2 Type II examination and invests continuously in its security program so that the platform its customers rely on meets the same governance standards it helps them achieve. The platform's own compliance module lists SOC 2 among the frameworks it supports for customers, which is a product capability and is not counted here. What is missing is everything that would make the attestation checkable: no auditor, no examination period, no report date, no scope statement, and no route to the report that could be established, since the trust centre is a Vanta-hosted portal returning page metadata with no body on this channel. That is recorded as a retrieval limit rather than as an absence, the portal is the rebuttal route, and the lower tier is graded with the reason stated. Trust centre attempted and Terms of Use read 7 September 2026.

Holistic AI
CC on Security Certifications and Trust CenterBadges appear on the site with no scope, no date, and no report available.

A badge appears with no scope, no date and no report available. The platform page marks the product as a SOC 2 platform in a feature strip, and the privacy policy states that the cloud databases comply with ISO 27001, which is a claim about database infrastructure rather than a certification of the company. Neither is accompanied by a type, a trust services criteria set, an auditor, an examination period, a certificate number or a scope statement, and no route to a report was located: there is no trust centre, no security page, and no statement that a report is available on request. The gap is worth stating on this record rather than passing over, because the product's own value proposition is generating audit-ready evidence and continuous assurance for other organisations, and the vendor publishes none of the equivalent evidence about itself. This grade records what is establishable on the date; a trust portal or a security page would move it. Platform page and privacy policy read, no trust surface located, 7 September 2026.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Credo AI
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

The vendor describes a proprietary intelligence layer and governance agents without identifying what sits underneath them. GAIA is presented as a set of AI agents performing evidence retrieval, risk assessment, incident response and remediation, powered by what the product page calls a proprietary governance knowledge graph; no model, provider, hosting location or change-notification commitment for those agents was located anywhere. Two adjacent facts are deliberately not credited here, because each belongs to a different arrow. The models named on the site, ChatGPT, Claude and Gemini, are the customer's deployments that the product governs through generative AI guardrails, not Credo AI's supply chain. And the enterprise AI tools named in clause 6.8 of the Terms of Use are the tools Credo AI's own staff use to support the service, which is a statement about internal operations and is credited on the training and confidentiality rows instead. No subprocessor list was located. The trust centre is the likely route to a supply chain disclosure and returns no body on this channel. Product page, Terms of Use and trust centre attempted 7 September 2026.

Holistic AI
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

The vendor refers to proprietary agents and research-based methods without identifying what sits underneath them. Guardian Agents, in both Sentinel and Operative modes, perform hallucination and toxicity detection, red teaming, jailbreak and prompt injection testing and counterfactual bias analysis, and nothing published names a model, a provider, a hosting location or a change-notification commitment for any of it. The model providers that do appear on the platform page, OpenAI, Anthropic and Google AI, are listed under Enterprise AI Surface Area as part of the customer's estate that the platform discovers and governs, which is the opposite arrow and is deliberately not credited here. No subprocessor list was located on any surface, and no data processing agreement is published that would carry one. A buyer therefore cannot establish which third party, if any, sees the code, model artefacts and documents that flow through discovery and red teaming. Platform page and homepage read 7 September 2026.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Credo AI
CC on Commercial TransparencyPricing is gated behind a demo request while tier names and feature splits are published, so the shape is visible and the number is not.

The shape is partly visible and no number is published at any level. There is no pricing page; every path ends at Talk to an Expert or a personalised demo, offered without a credit card. What a buyer can see before that conversation is the modular structure, which the vendor makes a selling point: AI Registry and Discovery, Risk Intelligence, Compliance and Policy Engine, and Governance are named as modules that work independently, with the advice to land with the registry and add the others as adoption grows, alongside separately sold advisory services. The Terms of Use add the mechanics: fees are set in an order form or statement of work, based on services purchased rather than actual usage, non-cancellable and non-refundable, invoiced in advance and payable within thirty days, with 1.5 per cent monthly interest on late amounts, automatic renewal unless either party gives thirty days' notice, and price changes effective at renewal on reasonable prior notice. Section 3.4 confirms account tiers exist with varying features and usage limitations, and 4.3 warns that exceeding them may incur charges at then-current rates, though neither the tiers nor the limits are named publicly. No VendorPricing row is written, since a row belongs to vendors graded A or B on this axis. Terms of Use and product page read 7 September 2026.

Holistic AI
CC on Commercial TransparencyPricing is gated behind a demo request while tier names and feature splits are published, so the shape is visible and the number is not.

The shape is visible and the number is not, at any level. Three modules are named and described as separable, Identify, Protect and Enforce, with their component capabilities listed in detail, so a buyer can see what is grouped with what and the vendor emphasises modular entry points for organisations at different stages. No price, band, unit of charge or tier name is published anywhere, and every path ends at a demo request. Nothing published states whether the licence is priced by AI systems inventoried, by connector, by seat or by enterprise, and no usage limits or overage terms were located because no agreement was located. Third-party buyer's guides confirm that pricing is not publicly listed and require a demo to obtain it, which is described rather than credited. No VendorPricing row is written, since a row belongs to vendors graded A or B on this axis. Platform page and homepage read 7 September 2026.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Credo AI
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Coverage is described with substance across buyers and regulations, and the boundaries are left open. The platform architecture names five stakeholder types it connects, the governance lead, the business user, product and engineering, legal and compliance, and information security and third-party risk management, which is a published account of who sits in the workflow. Regulatory coverage is named rather than gestured at, with pre-built policy packs for the EU AI Act, the NIST AI Risk Management Framework, ISO 42001 and SOC 2, and the knowledge graph described as distinguishing a model used in EU healthcare from one used in US financial services. The customer evidence spans payments, insurance, professional services and a technology vendor, and the vendor states Fortune 500 adoption. What is not stated is any limit: no jurisdiction, regulation, sector or organisation size is named as out of scope, no coverage boundary is given for the regulatory content, and nothing describes what a law firm rather than an in-house function would do with the platform. Product page read 7 September 2026.

Holistic AI
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Coverage is described with substance on both the buyer and the regulatory side, and the boundaries are left open. The platform page publishes its own list of users, naming the governance lead, risk and compliance, data and machine learning engineers, business owners, and information security and third-party risk management, and lists the outputs each expects, from board dashboards to audit evidence. Regulatory coverage is named down to the instrument: the EU AI Act, the NIST AI Risk Management Framework, ISO 42001, New York City Local Law 144 and custom frameworks. Coverage of the AI estate itself is enumerated by system type, from static models to multi-agent workflows, and by environment. Two limits are worth recording. Nothing states what is out of scope: no jurisdiction, sector, organisation size or regulation is named as unsupported, and no coverage boundary is given for the framework content. And legal does not appear in the vendor's own list of platform users, which for an index of legal buyers is the boundary that matters most and is recorded rather than inferred away. Platform page and homepage read 7 September 2026.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Credo AI
Never, in the contract

The published agreement prohibits training, in the agreement rather than on a policy page. Section 6.8 of the Terms of Use, effective 21 April 2026, states that Credo AI will not use, process or otherwise access User Data to train, develop or improve any machine learning or artificial intelligence models, and that its access to User Data is solely to provide, maintain and support the services. The same clause discloses something no other record in this index carries: it names the enterprise AI tools Credo AI's own staff use in delivering the service, including ChatGPT Enterprise and custom GPTs, Gemini Enterprise, Claude Enterprise and Microsoft Copilot, and commits that such use stays inside Credo AI's enterprise account environment and team, that no User Data leaves that environment, and that the data is deleted at the end of the engagement.

Two qualifiers travel with the value and are recorded rather than smoothed over. Section 5.2 grants a broad content license over User Content, including rights to modify, publish, distribute and create derivative works, scoped to providing and improving the services. And section 6.7 permits Credo AI to use aggregated and anonymized data derived from use of the services for its own business purposes, including developing new products, provided it cannot be attributed to the customer. Neither displaces 6.8, which is the specific clause and names the thing. Terms of Use read in full 7 September 2026.

Holistic AI
No agreement published

No customer agreement was located on any surface, and no policy page states a position on training. The search ladder was run to exhaustion before this was recorded. What exists is a website terms and conditions page governing use of the website and its comment features, which grants a license over visitor comments and says nothing about the platform, customer data or a subscription, and a privacy policy written from the controller side about personal data of website visitors and business contacts.

Neither addresses whether customer content flowing through discovery scans, red teaming or the AI inventory may be used to train or improve models, in either direction. No subscription terms, master agreement, data processing agreement or security page was located. This records an absence in the published record, with the surfaces checked and the date named; it is not a finding that the vendor trains on customer data, and an agreement provided in a sales process would answer it. Website terms, privacy policy, platform page and homepage checked 7 September 2026.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Credo AI
Disclosed fixed window

A specific period is published for the end of the relationship and the customer cannot change it. Section 6.6 of the Terms of Use sets a sixty-day window after termination or expiry during which the customer may export using standard export features, after which Credo AI may delete User Data except as required by law or for its legitimate business purposes, and it recommends regular customer-side backups. Two limits on that are stated here so the row is not read as more than it is.

In-term retention is not a period at all but a standard, User Data kept as long as needed to provide the services and to meet legal, dispute and enforcement needs, so a customer cannot read off how long a GAIA prompt or a generated governance artifact persists while the subscription runs. And no zero-retention or customer-configurable window is offered anywhere located. Section 6.7 separately permits indefinite use of aggregated and anonymized derivatives.

A reader could hold the vaguer value on the in-term half; the specific published period is what the value records. Terms of Use read in full 7 September 2026.

Holistic AI
Not addressed

No located public material states how long prompts, outputs or ingested customer content are retained. The only retention language found is in the privacy policy and concerns personal data the company holds as controller, kept for as long as reasonably necessary to fulfill the purpose collected for and longer where a complaint or the prospect of litigation exists. That says nothing about the material the platform actually processes: discovery scan results across cloud and code repositories, model artifacts, agent traces, red teaming transcripts and the documents a scan reaches.

No deletion commitment, export window, in-term period or zero-retention option was located, and no data processing agreement is published that would carry them. Privacy policy, website terms and platform page checked 7 September 2026.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Credo AI
Not addressed

No located public material addresses segregation between users, teams or customers. The Terms of Use put administrative users in charge of managing access levels and permissions for their organization at 3.3, which is a customer-side control over its own people rather than a statement about how the platform separates one organization's governance records from another's, or whether a business user registering an AI system can see assessments belonging to a different part of the enterprise.

The product page describes connecting every stakeholder to every AI system, which is the opposite emphasis. Nothing read describes tenancy, isolation or permission enforcement at retrieval time, including for GAIA's evidence retrieval across a customer's records. The trust center would be the likely route and returns no body on this channel. Terms of Use and product page checked 7 September 2026.

Holistic AI
Not addressed

No located public material addresses segregation between customers, teams or matters. The platform page describes role-based documentation, ownership tracking and responsibility assignment, which are features for organizing a customer's own governance records rather than statements about how one customer's AI inventory, scan results and red teaming transcripts are separated from another's. Nothing read describes tenancy, isolation, or permission enforcement at retrieval time, including for the Guardian Agents that observe production behavior.

No security page, trust center or data processing agreement was located that would ordinarily carry it. Platform page, privacy policy and website terms checked 7 September 2026.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Credo AI
Notice committed

The agreement commits to prior written notice where legally permitted, with minimization. Section 11.6 of the Terms of Use permits disclosure of confidential information to the extent required by law, regulation or court order only on condition that the receiving party gives prior written notice so the disclosing party may seek a protective order or other appropriate remedy, and discloses only the portion legally required; if no protective order is obtained, it must furnish only what is legally required and use commercially reasonable efforts to obtain assurance of confidential treatment.

Section 11.3 makes User Content the customer's confidential information, so the clause reaches the governance records and assessments a customer holds in the platform rather than only account data. No transparency report, request statistics or law-enforcement guidelines page was located, which is what separates this from the top value, and there is no separate law-enforcement protocol of the kind some records in this pull carry. Terms of Use read in full 7 September 2026.

Holistic AI
Disclosure addressed, notice absent

Disclosure to authorities is addressed and customer notice is not. The privacy policy states that Holistic AI may share personal data at any time if required for legal reasons or in order to enforce its terms or the policy, and separately that data may be transferred, sold or assigned to a third party in a sale of the business. Neither statement carries any commitment or reservation about notifying the affected party, seeking a protective order, narrowing the disclosure to what is legally required, or challenging a request.

No confidentiality clause was located, because no customer agreement was located, so there is no compelled-disclosure provision of the kind that ordinarily carries this commitment. The policy is written from the controller side about personal data rather than about customer content in the platform, which makes the gap wider rather than narrower. Privacy policy and website terms read 7 September 2026.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Credo AI
Sources named, basis unstated

The sources behind the product's compliance content are identified by name and no license or rights basis is stated for any of them. The compliance and policy engine ships pre-built policy packs for the EU AI Act, the NIST AI Risk Management Framework, ISO 42001 and SOC 2, and the governance knowledge graph is described as connecting regulations, risks, controls and business context into a proprietary intelligence layer, with a separately published regulatory insights hub and risk and control library.

So a buyer can see which instruments the content derives from, which is more than the signal's lowest value describes. What is absent is the rest: no statement of the license or rights basis for the standards content, which matters because ISO 42001 and the SOC 2 trust services criteria are copyrighted works rather than public law; no update cadence for the packs as regulations change, in a domain where the EU framework has been amended; and no statement of jurisdictional coverage depth. Product page and Terms of Use read 7 September 2026.

Holistic AI
Sources named, basis unstated

The instruments behind the product's assessments are named and no license basis or update cadence is stated for any of them. The platform assesses systems against the EU AI Act, the NIST AI Risk Management Framework, ISO 42001, New York City Local Law 144 and custom frameworks, and carries a controls and risk library plus a governance ontology built on the vendor's published research into bias, robustness, privacy and transparency.

So a buyer can see which sources the content derives from, which is more than the lowest value describes. What is absent is the rest: no statement of the license or rights basis for the standards content, which matters because ISO 42001 is a copyrighted standard rather than public law; no update cadence for the framework packs as instruments change, in a field where the EU framework has been amended and its high-risk timetable moved; and no statement of how a customer learns that an assessment was completed against a superseded version. Platform page and homepage read 7 September 2026.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Credo AI
Not addressed

No located public material addresses whether the authority behind the product's outputs is checked for currency. The signal's ordinary subject, subsequent history of reported cases, does not bite for a platform whose outputs are risk classifications and control mappings rather than citations to case law, and that is recorded rather than penalized. The analog that would bite is whether the policy packs and control library track amendments to the instruments they encode, and nothing read commits to it: the vendor publishes regulatory intelligence and an explainer on changes to the EU framework, which shows the content is being maintained, but no statement describes how a customer learns that a pack has changed, when it was last aligned, or what happens to an assessment completed under a superseded version. Product page, Terms of Use and regulatory materials checked 7 September 2026.

Holistic AI
Not addressed

No located public material addresses whether the authority behind the product's assessments is checked for currency. The signal's ordinary subject, the subsequent history of reported cases, does not bite for a platform whose outputs are inventories, risk classifications and control mappings rather than citations to case law, and that is recorded rather than penalized. The analog that does bite is whether the framework assessments track amendments to the instruments they encode, and nothing published commits to it: the platform promises real-time alignment and continuous monitoring in a feature strip, without stating what is monitored, how a customer is told that a framework mapping has changed, or when each pack was last aligned. Platform page, homepage and privacy policy checked 7 September 2026.

Refusal and Uncertainty Behavior

What does the product do when the answer is not in the corpus?

Credo AI
Not addressed

No located public material describes what the governance agents do when they cannot ground an answer. The published material addresses oversight rather than uncertainty: human oversight is maintained for critical decisions, workflows carry approval gates, and high-risk actions escalate to a person. Those are controls over what an agent is allowed to finish, not a description of what it does when the evidence it needs is missing or ambiguous.

Nothing read exposes a confidence or grounding score, describes an abstention path for GAIA's evidence retrieval or risk assessment, or reports any evaluation in which the system declined. The distinction matters on a product whose agents draft governance plans and remediate incidents. Product page and Terms of Use checked 7 September 2026.

Holistic AI
Not addressed

No located public material describes what the vendor's own agents do when they cannot reach a confident finding. The platform detects hallucination and uncertainty in a customer's AI systems, which is the product's function rather than a statement about its own behavior. On the vendor's side the published material addresses authority rather than uncertainty: Sentinel agents observe and alert without interfering, Operative agents act once a risk threshold is crossed.

Nothing states what happens between those two positions, whether a confidence or coverage score is exposed for a discovery scan or a risk classification, or whether the system has an explicit unknown state. That matters here because the actions downstream include kill switches and deployment blocks. Platform page and homepage checked 7 September 2026.

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

Credo AI
None located

No court order, opinion or disciplinary record naming Credo AI or GAIA was located as of 7 September 2026. The AI Hallucination Cases database maintained by Damien Charlotin was searched on both names alongside a general search of the sanctions coverage; the decisions naming specific tools name general-purpose chatbots and legal research products. This is a statement about the public record, not a finding about the product.

Exposure is structurally remote for a platform whose outputs are internal governance artifacts rather than filings, though the artifacts it generates are designed to be shown to regulators and auditors, which is a different audience carrying its own accuracy expectations.

Holistic AI
None located

No court order, opinion or disciplinary record naming Holistic AI or its Guardian Agents was located as of 7 September 2026. The AI Hallucination Cases database maintained by Damien Charlotin was searched on the company name alongside a general search of the sanctions coverage; the decisions naming specific tools name general-purpose chatbots and legal research products. This is a statement about the public record, not a finding about the product.

Exposure is structurally remote for a platform whose outputs are inventories and governance artifacts rather than filings, though the bias audit artifacts it produces are designed to be filed with or shown to regulators, which carries its own accuracy expectations.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Credo AI
Not addressed

No located public material engages with bar or ethics guidance, or with lawyers' professional obligations in general terms. Credo AI engages regulation heavily and at a high level of specificity, publishing policy packs, a regulatory insights hub, an explainer on changes to the EU AI framework and an annual trust summit, and it names legal and compliance as a stakeholder group in the platform. All of that concerns the obligations of the organizations that buy the product.

Nothing names an ethics opinion, a bar association guidance document or a regulator's guidance on lawyers' use of AI, and nothing addresses the duties of a lawyer relying on a governance artifact the platform generated. The lower value was tested before this one was taken: a generic reference would need some engagement with professional responsibility as such, and none was located. Product page, Terms of Use, legal pages and resource listings checked 7 September 2026.

Holistic AI
Not addressed

No located public material engages with bar or ethics guidance, or with lawyers' professional obligations in general terms. Holistic AI engages regulation in detail, including a statutory bias audit obligation under New York City Local Law 144, and names legal among the audiences for its compliance evidence on the homepage. All of that concerns the obligations of the organizations that buy the product and of their AI systems.

Nothing names an ethics opinion, a bar association guidance document or a regulator's guidance on lawyers' use of AI, and nothing addresses the duties of a lawyer relying on an artifact the platform generated. The lower value was tested before this one was taken: a generic reference would require some engagement with professional responsibility as such, and none was located. Platform page, homepage, website terms and privacy policy checked 7 September 2026.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Credo AI
Outside the fee relationship

The product does not touch a fee between a lawyer and a client. Credo AI is licensed by an enterprise to govern its own AI systems, and the stakeholders named in the platform are governance leads, business users, engineering, legal and compliance, and information security, all of them internal functions that bill no client for the work. The efficiency claims on the product page, ten times faster compliance and seventy percent less time in engineering bottlenecks, are aimed at the buyer's own cost and cycle time, which the value text records as not making the row a savings claim.

Advisory services are sold alongside the platform but are Credo AI's own consulting engagement rather than a lawyer-to-client matter. Nothing addresses billing, fee or disclosure treatment because there is no client invoice for it to address. Product page and Terms of Use checked 7 September 2026.

Holistic AI
Outside the fee relationship

The product does not touch a fee between a lawyer and a client. Holistic AI is licensed by an enterprise to govern its own AI estate, and the users the vendor names are the governance lead, risk and compliance, engineers, business owners and information security, all internal functions that bill no client for the work. The outcomes the platform page lists, including return on investment and savings reporting, are the buyer's own cost measures.

Nothing addresses billing, fee or disclosure treatment because there is no client invoice for it to address, and no fee terms of any kind were located because no customer agreement was located. Platform page, homepage and located legal surfaces checked 7 September 2026.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Credo AI
On request only

The material exists and sits behind a request. Section 6.4 of the Terms of Use states that where a customer is subject to data protection laws requiring one, Credo AI will enter into its standard data processing agreement upon request, so the artifact a buyer would forward is not published. No subprocessor list was located on any surface, and no model provider behind the platform's own governance agents is named anywhere, so the question a client's AI clause actually asks, whose models see our content, has no published answer.

What is public and forwardable is narrower but real and should not be overlooked: the Terms of Use themselves carry the no-training commitment at 6.8, the named list of enterprise AI tools Credo AI staff may use with the confinement and deletion conditions attached, the sixty-day retention position, and the breach notification commitment. The trust center, which is where a subprocessor list would ordinarily sit, returns page metadata with no body on this channel and is the rebuttal route. Terms of Use read in full and trust center attempted 7 September 2026.

Holistic AI
Not addressed

No located public material would answer a client's AI clause. Three things a buyer would need are all absent from the published record: no subprocessor list on any surface; no data processing agreement, and no statement that one is available on request, since no customer agreement was located at all; and no model provider named for the vendor's own Guardian Agents. The model providers that appear on the platform page, OpenAI, Anthropic and Google AI, are listed as part of the customer's own AI estate that the platform discovers and governs, so crediting them here would point the arrow the wrong way.

The only forwardable document located is a privacy policy written from the controller side about website and contact data, which does not describe processing of customer content in the platform. Privacy policy, website terms, platform page and homepage checked, no trust center or security page located, 7 September 2026.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Credo AI
Not addressed

No located public material addresses court disclosure of AI use or a verification certification. The platform generates a great deal of evidence, including automated evidence generation, audit trails, audit-ready documentation and conformity artifacts, and it is worth being precise about whose that evidence is: it records what the customer's AI systems are and how they were governed, for regulators and auditors, not what Credo AI's own governance agents did to produce a given output.

Crediting it here would credit the customer's own mechanism to the vendor. Nothing read offers a per-item export covering which model or agent produced an assessment, what it retrieved and what a person verified, and nothing addresses a court's standing order on AI use or a disclosure a filer could attach. Product page and Terms of Use checked 7 September 2026.

Holistic AI
Not addressed

No located public material addresses court disclosure of AI use or a verification certification. The platform generates a great deal of evidence, including audit-grade documentation, regulatory reports, evidence collection, full audit trails and version history, and it is worth being precise about whose that evidence is: it records what the customer's AI systems are and how they were governed, for regulators and auditors, not what Holistic AI's own agents did to produce a given finding.

Crediting it here would credit the customer's mechanism to the vendor. Nothing read offers a per-item export covering which agent produced an assessment, what it examined and what a person verified, and nothing addresses a court's standing order on AI use or a disclosure a filer could attach. Platform page and homepage checked 7 September 2026.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.

Axes where neither earns credit
  • Deployment Model and Data Residency
Signals neither addresses in public material
  • Ethical Walls and Matter Segregation
  • Good Law Verification
  • Refusal and Uncertainty Behavior
  • Bar Guidance Alignment
  • Court Disclosure Support

Which one fits

Choose Credo AI if

  • Procurement needs contract terms before a demo. Credo AI publishes its terms of use, including a bar on training models with customer data, a sixty day export window before deletion, breach notice without undue delay, and a liability cap of twelve months' fees.
  • You want customer references to check. Credo AI quotes named data and governance leaders at Mastercard, Principal and AdeptID, with Microsoft and IBM describing what their integrations do.
  • You need governance mapped to several frameworks with evidence generated. Credo AI ships policy packs for the EU AI Act, the NIST AI RMF, ISO 42001 and SOC 2, with approval gates and automated evidence generation in its compliance engine.

Choose Holistic AI if

  • You want AI agents that can stop a risky system, under limits you set. Holistic AI's Operative agents act inline only once a customer set risk threshold is crossed, controlling which tools a system calls, what it accesses and how much it spends, with kill switches and deployment blocks.
  • You want monitoring that never interferes. Holistic AI's Sentinel agents watch production AI for prompt injection, jailbreaks, data leakage, hallucination, toxicity and bias, and alert without intervening.
  • You want discovery without installing software. Holistic AI finds models, agents, APIs and pipelines across AWS, Azure, Google Cloud, GitHub, Databricks, ServiceNow and SharePoint through read only connectors that need no installed agent.

In summary

Credo AI

Credo AI, a Los Altos, California company, sells an AI governance platform that registers an organization's models and agents, discovers shadow AI, scores and red teams risk, maps controls to the EU AI Act, NIST AI RMF, ISO 42001 and SOC 2, and monitors agents in production. Its GAIA agents draft governance plans and run remediation with approval gates. The AI Legal Index grades it in the top two bands on nine of fifteen capability axes, with an A on liability. Its published terms bar model training on customer data, and it states a SOC 2 Type II examination. As of 7 September 2026 the index located no hosting region, named model or price.

Source: AI Legal Index, 2026

Holistic AI

Holistic AI, from Holistic AI Limited of London, sells an AI governance platform in three modules: Identify discovers models, agents and pipelines through read only connectors; Protect tests them for bias, robustness and privacy and red teams language models and agents; and Enforce turns policy into workflows with approvals, kill switches and framework assessments against the EU AI Act, NIST AI RMF, ISO 42001 and New York City Local Law 144. The AI Legal Index grades it in the top two bands on four of fifteen capability axes, with an A on autonomy and oversight. As of 7 September 2026 the index located no customer agreement, named customer, hosting region or price.

Source: AI Legal Index, 2026

Questions buyers ask

Credo AI vs Holistic AI: which AI governance platform is better?

On published evidence Credo AI sits in the top two bands on nine of fifteen AI Legal Index capability axes and Holistic AI on four of fifteen, identical on nine. Credo AI publishes its terms and names customers. Holistic AI publishes a detailed account of what its monitoring and intervention agents may do. Buyers who need contract terms early have more to read from Credo AI.

What are Holistic AI's Sentinel and Operative agents?

They are the two modes of its Guardian Agents. Sentinel agents monitor production AI for prompt injection, jailbreaks, data leakage, hallucination, toxicity and bias, and alert without interfering. Operative agents act only when a risk threshold is crossed, controlling tools, access, spend and agent identity, with kill switches and deployment blocks. Customers configure the thresholds. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.

Does Credo AI or Holistic AI train on customer data?

Credo AI's terms of use state that it will not use customer data to train, develop or improve any AI model, and name the enterprise AI tools its own staff may use under confinement and deletion conditions. Holistic AI publishes no customer agreement and no policy statement on training, so its position cannot be read. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.

Does Holistic AI run New York City bias audits?

Holistic AI lists New York City Local Law 144 among the frameworks it assesses systems against and sells bias testing, including counterfactual testing. Local Law 144 requires an independent auditor, and nothing Holistic AI publishes states where its tool ends and an auditor's attestation begins. Credo AI's published policy packs do not list Local Law 144. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.

What do Credo AI and Holistic AI both leave unpublished?

A hosting region, a named model and a price. Neither states where customer data is stored or processed, neither names the model behind its own agents, and neither publishes a rate. Neither describes governance of its own AI, such as an accountable owner or testing before release, although both sell exactly that to others. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.

Disclosure

Three readings to weigh. Holistic AI publishes no customer agreement, data processing agreement or trust center, so its low grades record what could be reached; an agreement provided in a sales process may answer them. Credo AI's terms grant a broad license over customer content for providing and improving its services, beside its training bar. Holistic AI tests other systems for hallucination and publishes no accuracy measure for its own discovery. Credo AI and Holistic AI were both verified on 7 September 2026. Neither vendor reviewed this page.

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 303 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 24, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746