# Most agent tools can't pass a due-diligence questionnaire (slim) > Vlad Cealicu on why most agent tools aren't fit for enterprise yet. We asked eight standard due-diligence questions of 760 hosted tools. Nine answer all eight in public, and a third answer three or fewer. - Full: https://www.anchorterminal.com/blog/agent-tools-arent-ready-for-enterprise.md (~2,100 tokens) · this version ~1,180 tokens · JSON https://www.anchorterminal.com/blog/agent-tools-arent-ready-for-enterprise.json · canonical https://www.anchorterminal.com/blog/agent-tools-arent-ready-for-enterprise - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-10 ## The hoops are there for a reason At CryptoCompare I had to fill in a lot of due-diligence questionnaires, from our old partners at MarketVector to all the banks and trading firms we worked with, and some of them had over 300 questions. As much as I hate all the hoops enterprise makes you jump through, most of the agent tools out there are just not fit for purpose for an enterprise, and they will struggle to gain traction unless they take on the clients who would pay them the most money (seriously). Some of it is simple, like where are your servers, and are you training on our data, and what is your security policy, and how do you handle sensitive data. A lot of the tools available are just impossible to assess. ## What we checked We took every hosted service in the directory, anything where a company would be sending its data to someone else's servers, and asked the eight questions that come first in any review [[2]](#ref-2). - 760: hosted services checked - 9: answer all eight questions in public - 259: answer three or fewer - 82: whose terms or privacy policy we couldn't read at all Hosted agent tools on 10 October 2026 | Question | Answered in public | | --- | --- | | Where is the data stored and processed? | 79% | | Is there a vulnerability disclosure route (a valid security.txt, a policy or a bug bounty)? | 70% | | Does it claim SOC 2 or ISO 27001? | 65% | | Is there an uptime commitment? | 51% | | Is there a sub-processor list? | 47% | | Is there a data processing agreement? | 45% | | How long is the data kept, as a period? | 37% | | Is our data used to train models? | 30% | Each of these comes from the evidence on the listing, the research notes behind its grade and our reading of the vendor's terms and privacy policy [[2]](#ref-2) [[3]](#ref-3). ## Where it falls apart **Training.** It's the first thing a legal team asks about anything with a model in it, and it's the least answered question overall. **Retention.** We read 645 privacy policies. **Security contact.** Of the 760, 198 publish a valid security.txt, 49 publish one that has expired, and 483 have none [[4]](#ref-4). **Unreadable.** For 82 of them our reader couldn't get the terms or the privacy policy at all, because of a bot wall or a page that only draws in a browser [[3]](#ref-3). ## It lines up with the grades None of these questions is the benchmark, but the benchmark's Security and Transparency categories ask about the same things [[5]](#ref-5), so the grades and the answers move together. Of the 78 hosted services in our top 100, only 39 answer six or more [[2]](#ref-2). The nine that answer all eight are [DeepInfra](/tools/deepinfra), [Groq Speech-to-Text](/tools/groq-speech-to-text), [Kontent.ai](/tools/kontent-ai), [MoEngage](/tools/moengage), the [OpenAI API](/tools/openai-api), [Paperform](/tools/paperform), [Sanity](/tools/sanity), [SeaTable](/tools/seatable) and the [Semrush API](/tools/semrush). ## What I'd do If you build a tool and want enterprise money, put the eight answers on one public page. If you're buying, every listing on Anchor Terminal has the facts we found and where we found them, including what the terms and privacy policy say. The hoops aren't going away, and they shouldn't (I know, I said I hate them). ## References Read on 10 October 2026. [1] Cloud Security Alliance, STAR Level 1: Security Questionnaire (CAIQ v4), 7 June 2021. Source for the description of a standard cloud security questionnaire. [2] Anchor Terminal, the directory, 10 October 2026. Source for the 760 hosted listings and the counts in this post. [3] Anchor Terminal, our readings of vendors' terms and privacy policies. [4] Anchor Terminal, the security.txt check on every listing, 10 October 2026. Source for the valid, expired and missing counts. [5] Anchor Terminal, the benchmark's Security and Transparency checklists. --- - Older: [The Personal Agent Protocol, read by people who list agent tools](https://www.anchorterminal.com/blog/personal-agent-protocol-first-draft.md) - Newer: [How to make your MCP server discoverable](https://www.anchorterminal.com/blog/how-to-make-your-mcp-server-discoverable.md) - All posts: https://www.anchorterminal.com/blog/index.md