| Service model | SaaS (AI Governance Cloud) · AI Guard SDK runs on-prem in customer infra (Docker / K8s) | SaaS multitenant · Enterprise-tier options for isolated deployments on request |
|---|
| Data residency | Not publicly specified on Platform Overview or AI Governance solution page | US (primary) |
|---|
| Tenant isolation | Not publicly disclosed | Logical (row-level org scoping) |
|---|
| Public API | Platform APIs referenced; AI Guard has a REST API for non-Python callers · full specification not publicly disclosed for AI Governance | REST + MCP (Model Context Protocol) tool graph · OpenAPI 3.0 |
|---|
| SSO / SCIM | Available across the OneTrust platform (privacy heritage); AI-Gov-specific SSO/SCIM details not publicly disclosed | SAML 2.0 · OIDC · SCIM 2.0 |
|---|
| Audit-trail model | Platform-internal audit trail in AI Governance Cloud · exportable · OneTrust proprietary logging | Evidence Graph · hash-chained per-event · RFC 3161 external timestamp anchor · SDK-licensable |
|---|
| Runtime SDK | AI Guard SDK · Python 3.13+ only · custom classifiers not supported · “not recommended for large classification volumes generally seen in externally facing AI applications or agents” per their FAQ[3] | Trustworthy Autonomy (public beta 2026-07-07) · production runtime · published evaluation harness · graduated trust ladder |
|---|
| Conversational LLM surface | AI Policy Manager + workflow-embedded AI assist (Winter ‘26: AI Inventory Analysis, AI Evidence Analysis) · no standalone MCP endpoint disclosed | APRI (AI-Powered Risk Intelligence) · MCP tool graph · answers cite evidence chain · caller-entitlement scoped |
|---|
| Own compliance | SOC 2, ISO 27001 available platform-wide (privacy heritage); AI-Gov-specific certifications not publicly disclosed | SOC 2 Type II · ISO 27001 (in progress) · runs on itself |
|---|
| Positioning relative to broader platform | “One shared data model” with Privacy, TPRM, GRC · AI Governance is a standalone SKU but leans on the platform-wide pitch | AI-Gov + broader compliance program on the same Enterprise SKU · no assumed prior footprint |
|---|