# Most agent tools can't pass a due-diligence questionnaire > Vlad Cealicu on why most agent tools aren't fit for enterprise yet. We asked eight standard due-diligence questions of 760 hosted tools. Nine answer all eight in public, and a third answer three or fewer. - Canonical: https://www.anchorterminal.com/blog/agent-tools-arent-ready-for-enterprise - Markdown: https://www.anchorterminal.com/blog/agent-tools-arent-ready-for-enterprise.md (~2,100 tokens) - Slim: https://www.anchorterminal.com/blog/agent-tools-arent-ready-for-enterprise.min.md (~1,180 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/blog/agent-tools-arent-ready-for-enterprise.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-10 ## The hoops are there for a reason At CryptoCompare I had to fill in a lot of due-diligence questionnaires, from our old partners at MarketVector to all the banks and trading firms we worked with, and some of them had over 300 questions. As much as I hate all the hoops enterprise makes you jump through, most of the agent tools out there are just not fit for purpose for an enterprise, and they will struggle to gain traction unless they take on the clients who would pay them the most money (seriously). Some of it is simple, like where are your servers, and are you training on our data, and what is your security policy, and how do you handle sensitive data. Anyone who has built a due-diligence document knows there's a reason for these questions and it's to assess risk. The Cloud Security Alliance's questionnaire calls itself "a set of Yes/No questions a cloud consumer and cloud auditor may wish to ask of a cloud provider" [[1]](#ref-1), and every procurement team I've seen has its own version of it. A lot of the tools available are just impossible to assess. A company can live with assumed risk as long as it can quantify it, and with most agent tools we can't, because the answers aren't anywhere public. Our numbers back that up. ## What we checked We took every hosted service in the directory, anything where a company would be sending its data to someone else's servers, and asked the eight questions that come first in any review [[2]](#ref-2). A question counts as answered when the vendor's own pages answer it, either way. "We train on your data" answers the training question. Silence doesn't. - 760: hosted services checked - 9: answer all eight questions in public - 259: answer three or fewer - 82: whose terms or privacy policy we couldn't read at all Hosted agent tools on 10 October 2026 | Question | Answered in public | | --- | --- | | Where is the data stored and processed? | 79% | | Is there a vulnerability disclosure route (a valid security.txt, a policy or a bug bounty)? | 70% | | Does it claim SOC 2 or ISO 27001? | 65% | | Is there an uptime commitment? | 51% | | Is there a sub-processor list? | 47% | | Is there a data processing agreement? | 45% | | How long is the data kept, as a period? | 37% | | Is our data used to train models? | 30% | Each of these comes from the evidence on the listing, the research notes behind its grade and our reading of the vendor's terms and privacy policy [[2]](#ref-2) [[3]](#ref-3). A missing answer means our research didn't find it in public. The vendor may well have one, behind a sales call or an NDA, but a security reviewer starts from the same public pages we do, and a question they can't answer from them goes on the risk register as unknown. ## Where it falls apart **Training.** It's the first thing a legal team asks about anything with a model in it, and it's the least answered question overall. Most of the 760 aren't model services, so many have no reason to mention it, but their policies don't say they won't either. Of the 104 hosted model services, 73 say whether they train on your data, so 31 leave you guessing [[2]](#ref-2). **Retention.** We read 645 privacy policies. 181 give a period in their retention clause, and 185 say some version of "as long as necessary" [[3]](#ref-3). That's not an answer you can put in a risk register. **Security contact.** Of the 760, 198 publish a valid security.txt, 49 publish one that has expired, and 483 have none [[4]](#ref-4). Some of those have a disclosure policy or a bug bounty somewhere else, which is why the table says 70%, but an expired security.txt tells a reviewer something on its own. **Unreadable.** For 82 of them our reader couldn't get the terms or the privacy policy at all, because of a bot wall or a page that only draws in a browser [[3]](#ref-3). Some vendors' terms forbid automated reading outright, and we don't grade those. If an agent can't read your terms, an agent can't tell a buyer what's in them either. ## It lines up with the grades None of these questions is the benchmark, but the benchmark's Security and Transparency categories ask about the same things [[5]](#ref-5), so the grades and the answers move together. Listings graded A answer six of the eight on average. BB answer 5.2, C answer 4.2, E answer 2.5 and F answer 1.9 [[2]](#ref-2). Of the 78 hosted services in our top 100, only 39 answer six or more [[2]](#ref-2). The nine that answer all eight are [DeepInfra](/tools/deepinfra), [Groq Speech-to-Text](/tools/groq-speech-to-text), [Kontent.ai](/tools/kontent-ai), [MoEngage](/tools/moengage), the [OpenAI API](/tools/openai-api), [Paperform](/tools/paperform), [Sanity](/tools/sanity), [SeaTable](/tools/seatable) and the [Semrush API](/tools/semrush). Not all of them are big companies, and what they have in common is that someone wrote the answers down where anyone can read them. ## What I'd do If you build a tool and want enterprise money, put the eight answers on one public page. Say where the data lives, whether you train on it, which certifications you hold and how to get the report, how to report a vulnerability, how long you keep data, who your sub-processors are, and link your DPA and your SLA. Most of it you already know. It costs a day, and it's the difference between a questionnaire that takes a week and one that never gets sent back. We'll pick it up on your listing the next time we check, and if you want us to tell you what's missing, that's what [the audit](/audit/) is for. If you're buying, every listing on Anchor Terminal has the facts we found and where we found them, including what the terms and privacy policy say. Start there, and send the questionnaire for what's missing. The hoops aren't going away, and they shouldn't (I know, I said I hate them). A risk you can put a number on is one you can accept, and right now most agent tools don't let you put a number on anything. ## References Read on 10 October 2026. [1] Cloud Security Alliance, STAR Level 1: Security Questionnaire (CAIQ v4), 7 June 2021. Source for the description of a standard cloud security questionnaire. https://cloudsecurityalliance.org/artifacts/star-level-1-security-questionnaire-caiq-v4 [2] Anchor Terminal, the directory, 10 October 2026. Source for the 760 hosted listings and the counts in this post. We read each listing's facts, the research notes behind its grade and its terms and privacy policy for the eight questions, and counted a question answered when the vendor's own pages answer it either way. Each listing links the pages it was graded from. https://www.anchorterminal.com/tools/ [3] Anchor Terminal, our readings of vendors' terms and privacy policies. Source for the 645 privacy policies read, the retention clauses and the 82 hosted listings whose documents couldn't be read. Each listing shows its reading with the quotes. https://www.anchorterminal.com/benchmark/ [4] Anchor Terminal, the security.txt check on every listing, 10 October 2026. Source for the valid, expired and missing counts. https://www.anchorterminal.com/tools/ [5] Anchor Terminal, the benchmark's Security and Transparency checklists. Source for what the grades ask about certifications, disclosure, data handling, retention, sub-processors and data locations. https://www.anchorterminal.com/benchmark/ --- - Older: [The Personal Agent Protocol, read by people who list agent tools](https://www.anchorterminal.com/blog/personal-agent-protocol-first-draft.md) - Newer: [How to make your MCP server discoverable](https://www.anchorterminal.com/blog/how-to-make-your-mcp-server-discoverable.md) - All posts: https://www.anchorterminal.com/blog/index.md