The Vannus record — who legally controls 376 AI vendors.
Every entry records the entity you actually contract with, the country that entity is incorporated in, and the law that governs the agreement — and therefore which government can compel the data that vendor holds. Hosting is where the data sits; control is who can be made to hand it over. Built to be quoted into a DPA, a security questionnaire or a Transfer Impact Assessment.
A second, separate verdict: whether the vendor runs its own foundation model or resells another company's. It is a recorded field, not the point of the record, and the two are never conflated. For 252 tools that determination traces to the vendor's own published documentation — so you can check the claim at the source. A further 98 were established to run no foundation model at all, so there is nothing to cite — that is an answer, not a gap. For the remaining 26 the product uses AI and the vendor does not name the provider, and the entry says exactly that rather than a guess. We do not claim to know which without having looked.
Vannus publishes no score, letter grade or tier. Each entry states what the vendor’s own documents say about the entity you contract with, the governing law of its terms, and which model it runs — quoted, sourced and dated.
A tier is a claim about what a product runs on, so we withhold it rather than guess. Where provenance was never established we say Provenance not establishedWhere a vendor’s own evidence does not establish which model it runs, the entry says so rather than inferring one.Tier withheld. Tools with no commercial vendor behind them are Not rated, because the resilience questions do not apply to them.
All Tools
| Tool \u2195 | Model provenance \u2195 | Upstream dependency | Category | Compliance | Pricing |
|---|