# Credo AI

> Keeps every AI use case, model and AI vendor in one register, attaches to each entry the approvals and evidence a regulation or a customer asks for, and records who decided what and when.

- Vendor: Credo.AI Corp.
- Canonical URL: https://www.convios.com/en/toolbox/credo-ai
- Language version: https://www.convios.com/de/werkzeugkasten/credo-ai
- Area: Governance & security · Cluster: AI governance and model registry
- Role: Off-the-shelf product · Origin: AI-native
- As of: 2026-08-24 · Reviewed: 2026-08-24 · Author: Dr. Oliver Gausmann, Convios GmbH
- Toolbox: https://www.convios.com/en/toolbox — Markdown: https://www.convios.com/en/toolbox.md

## Verdict

Prevents falling behind: An auditor, a corporate procurement team and a customer with reporting duties of their own all ask the same thing: which AI systems run here, who approved them, and what the approval rests on. A company without an answer loses the deal or the certificate. A register closes that gap. It carries nobody further than that, because the competitor buys the same platform and has the same register within the week. What sets a company apart are the decisions it draws from that register, and no software makes those.

## Suitability by company size

- Solo: not suitable — Sales runs through an enterprise agreement and an advisory engagement. There is no pricing page and no self-service entry. Three use cases go into a spreadsheet faster than the first sales call takes.
- Mid-market: suitable with caveats — It becomes interesting once a use case falls under Annex III of the AI Regulation, credit scoring or pricing in life and health insurance for instance, or once customers start sending supplier questionnaires about AI use. The Annex III duties apply from 02.12.2027. Until then a documented approval process plus a maintained spreadsheet carries further than a licence with no public price to negotiate against.
- Enterprise: suitable — This is where the tool belongs: many units, many models, an internal audit function that wants evidence, and a procurement team asking suppliers about their AI use. IBM has shipped Credo AI's policy content inside its own product since 28.04.2025, and McKinsey's QuantumBlack has taken the platform to clients since 02.04.2024. Three points stay open before signing because they are not publicly documented: storage location, subprocessors, and the model provider behind the built-in assistant.

## Vendor staying power

Funded: Six years since founding, two years since the last round. The Series B of 21 million US dollars dated 30.07.2024 and the OEM agreement with IBM carry current operations; what is missing for the established rating is seven years in market, a corporate owner and demonstrated profit. On top of that a trademark dispute is running: Credo Technology Group, Ltd. has been suing Credo.AI Corp. over the Credo mark since 03.04.2024, the case is open, last docket entry 17.08.2026.

- Founded and launched: founded in March 2020, platform generally available since April 2022, based in Los Altos, California; both year figures per the vendor's own account (source: https://www.credo.ai/news/credo-ai-announces-12-8-million-series-a-funding-round-for-responsible-ai, as of 2026-08-24)
- Funding: 12.8 million US dollars Series A dated 17.05.2022, led by Sands Capital; 21 million US dollars Series B dated 30.07.2024 with CrimsoNox Capital, Mozilla Ventures and FPV Ventures; 41.3 million US dollars in total per the vendor (source: https://www.credo.ai/blog/accelerating-global-growth-and-innovation-in-ai-governance-with-21-million-in-new-capital, as of 2026-08-24)
- Routes to market: OEM agreement with IBM since 28.04.2025: Credo AI's Policy Packs supply the content for the Compliance Accelerators add-on in IBM watsonx.governance. Alliance with QuantumBlack, AI by McKinsey, since 02.04.2024 (source: https://www.credo.ai/blog/credo-ai-and-ibm-empowering-trustworthy-ai-through-oem-collaboration, as of 2026-08-24)
- Analyst placement: placed as a Visionary in Gartner's first Magic Quadrant for AI governance platforms on 16.06.2026; named a Leader in the Forrester Wave on AI Governance Solutions for the third quarter of 2025 per the vendor (source: https://www.credo.ai/recognition/gartner-magic-quadrant-ai-governance-platforms-2026, as of 2026-08-24)
- Legal entity and pending case: Credo.AI Corp., service address 4546 El Camino Real B10 #795, Los Altos, California; venue per the terms of use is San Francisco County. Trademark case 3:24-cv-02032-CRB has been pending before the United States District Court for the Northern District of California since 03.04.2024, last docket entry 17.08.2026 (source: https://cand.uscourts.gov/cases-e-filing/cases/324-cv-02032-crb/credo-technology-group-ltd-v-credoai-corp, as of 2026-08-24)

## Cost of leaving

High: The terms of use grant 60 days for export after the contract ends, after which the vendor may delete. Your own entries can be retrieved. What is missing after the export is the ordering that turned them into evidence: the risk library, the control catalogue and the policy packs are the vendor's content and partly licensed to IBM. The approval chain survives as a file, its mapping to controls and legal provisions does not. Anyone switching after two years rebuilds the evidence base and explains the gap in between to an auditor.

## Regulation and data

| Point | Finding | Evidence | As of |
|---|---|---|---|
| Data processing agreement | available on request, no separate document published — Section 6.4 of the terms of use promises to enter into the standard data processing agreement on request, where the customer is subject to a data protection law such as the GDPR. The text is nowhere publicly retrievable; credo.ai/legal/dpa returns 404 and the sitemap lists no such page. | partially evidenced | 2026-08-24 |
| Storage location | unclear — Neither the privacy policy nor the terms of use name a storage location, a region or an infrastructure provider. No region choice is offered anywhere and there is no security or trust page; credo.ai/security and credo.ai/trust return 404. All 500 addresses listed in the sitemap were checked as well. | not evidenced | 2026-08-24 |
| Subprocessors | no public list; individual services named in the terms of use — There is no maintained subprocessor list; credo.ai/subprocessors returns 404. Section 6.8 of the terms of use names ChatGPT Enterprise, Gemini Enterprise, Claude Enterprise and Microsoft Copilot as tools with which the vendor's staff support the service, and states in the same paragraph that user data does not leave the vendor's own environment. Having both side by side belongs in contract negotiations. Which model provider runs the built-in governance assistant appears in none of the public documents. | partially evidenced | 2026-08-24 |
| Third-country transfer | transfer to the United States, standard contractual clauses named — The vendor is based in the United States, so a transfer takes place. The privacy policy names the European Union standard contractual clauses or other applicable mechanisms as the basis, without assigning which recipient works on which basis. No representative in the Union under Article 27 GDPR is named, nor any establishment in the Union. | partially evidenced | 2026-08-24 |
| Training on customer data | contractually excluded for customer content, expressly reserved for site and account data — Two documents give two different answers here, and that is the most important finding in this profile. Section 6.8 of the terms of use rules out using user data to train, develop or improve models. The privacy policy dated 08.04.2026 reserves the opposite for personal information collected through the site and the service, including disclosure to third parties for model training. Section 6.7 additionally permits the use of aggregated and anonymised derivations of usage for the vendor's own purposes, new products included. The commitment does not extend to the model provider behind the built-in assistant, because that provider is named nowhere. | partially evidenced | 2026-08-24 |
| Retention and deletion | 60 days for export after the contract ends, deletion thereafter phrased as an option — Section 6.6 of the terms of use quantifies the period: for 60 days after the contract ends the data stays available for export. After that the vendor may delete but is not obliged to; excluded is whatever is required by law or for the vendor's legitimate business purposes. Nothing is said about backups. The text promises no confirmation of deletion. | partially evidenced | 2026-08-24 |
| Certifications | SOC 2 Type II for security, availability and confidentiality; report on request — The vendor states a SOC 2 Type II report and names the categories reviewed: security, availability and confidentiality. Processing integrity and privacy are not among them. The audit period and the auditing firm are not named, the report is handed out on request, and an annual repeat is promised. No ISO 27001 certificate is mentioned. The asymmetry around ISO/IEC 42001 is worth noting: the vendor sells readiness for that standard, while no certificate of its own under it is shown on the public pages. | partially evidenced | 2026-08-24 |
| EU AI Act, Article 50 | extensive statements on the customer's duty, no named commitment on its own — The vendor runs a dedicated page on the AI Regulation which addresses the customer's duties throughout. On its own duties under Article 50 for the built-in governance assistant, which produces suggestions and pre-fills questionnaires, no commitment appears. What is checkable, and awkward for a tool of this kind, is the legal footing of that page: as of 24.08.2026 it still argues on the 2024 timetable and omits the high-risk deadlines shifted by amending Regulation (EU) 2026/1744, so neither 02.12.2027 for Annex III nor 02.08.2028 for Annex I. From the outside this says nothing about how current the policy packs inside the product are. | partially evidenced | 2026-08-24 |
| Audit logging | audit trail over the governed AI objects advertised, reach and retention open — Audit trails and reporting are part of the advertised scope per the product navigation and refer to the governed use cases, models and approvals. Whether the customer additionally receives an auditable log of access and changes within their own tenant, how long it is retained, and whether it can be exported into their own systems, is not publicly substantiated. There is no documentation site and no plan overview from which this could be read. | partially evidenced | 2026-08-24 |

## Cost

- Entry: The vendor publishes no price. The address credo.ai/pricing returns 404, and among the 500 addresses checked in the sitemap on 24.08.2026 there is no pricing page. Entry runs through a sales conversation and an enterprise agreement; advisory services sit alongside as a separate engagement per the terms of use. (as of 2026-08-24)
- Where it gets expensive: In three places worth knowing before the first negotiation. First, there is no list price to negotiate against; the vendor knows the other side's willingness to pay better than the other way round. Second, rolling a register out across several units is project work, and the vendor keeps its own advisory offering for it, billed alongside the licence. Third, the AI assistant was given to design partners free of charge until general availability, and the vendor expressly left the terms after that open in the same document.

## Three routes compared

### GRC suite that absorbs AI as one more domain

The established names are OneTrust, ServiceNow, MetricStream and Archer. Corporates stay with them because the AI register then sits next to the processing register and the risk register, uses the same approval chain and has long been cleared by procurement. A second tool means a second permissions process, a second supplier review and a second invoice. Anyone already running IBM watsonx.governance has had access to Credo AI's policy content through the Compliance Accelerators add-on since 28.04.2025, without signing a contract with Credo AI at all.

### Evidence automation with an AI module rather than an AI platform with evidence

Vanta and Drata come from evidence automation for SOC 2 and ISO 27001 and have added an AI governance module on top, with a use case register and mapping to ISO/IEC 42001, the NIST framework and the AI Regulation. The difference is the way in: both run a public pricing page and a route to a trial without a sales appointment. Drata has shown an ISO 42001 certificate of its own since 02.12.2025, though without naming the certification body or the scope. What you give up is depth on models and vendors: the risk library, the vendor transparency reports and the per-model evaluation evidence are what Credo AI gets bought for.

### Build the register yourself and draw evidence from your own operations

The building blocks are in our own catalogue. LiteLLM as a model gateway records which application calls which model. Langfuse logs the calls with input, output and cost, and thereby produces the evidence trail an auditor wants to see. Nudge Security finds the AI services nobody registered. Supabase carries the register with use case, model, vendor and approval status, n8n routes approvals through the chain, and Claude Code builds the whole thing. For a company with twenty to thirty use cases that comes to ten to fifteen person-days in our own experience, plus ongoing upkeep. It fails in four places: the legal work of mapping a control to a legal provision and re-doing that mapping when deadlines shift; tenant separation as soon as several legal entities use it; the immutability of the evidence an auditor takes for granted; and the day the person who built it leaves.

Recommendation by size:

- Solo: A spreadsheet and a fixed quarterly slot. This vendor's route to market does not fit this size.
- Mid-market: Build it yourself first and document the approval process. Buy once a use case falls under Annex III or a major customer demands evidence.
- Enterprise: Buying is the right answer. But get the storage location, the subprocessor list and the model provider behind the assistant into the contract in writing, because nothing on any of the three is public.

## Context

- Implements method: [Regulatory Density Test](https://www.convios.com/en/methods/regulatory-density-test) — The test clarifies whether a rule hits this company harder than everyone else, and that decides whether a register stays a duty or becomes the ticket into a regulated segment.
- Implements method: [DORA AI Capabilities Model (Seven AI Capabilities)](https://www.convios.com/en/methods/dora-ai-capabilities) — The assessment asks for a clear stance on AI and for reachable internal data, and a register of use cases is the reality check on whether that stance holds in daily work at all.
- Implements method: [Operating Model Grid (Standardization and Integration)](https://www.convios.com/en/methods/operating-model-raster) — A central AI register is a decision about process standardisation and data integration between units, and the grid answers beforehand how much of that the business actually needs.
- Displaces: Spreadsheet of AI systems in use, maintained by one person, Approvals living as an email thread in the legal team's inbox, Supplier questionnaires answered by hand from scratch for every customer

## Evidence

- Data processing agreement on request, 60-day export window after contract end, aggregated derivations for the vendor's own purposes, training exclusion for user data, named AI tools used in support, venue and service address — https://www.credo.ai/legal/terms-of-use (as of 2026-08-24)
- Effective 08.04.2026, training reservation for personal information collected through site and service, standard contractual clauses as transfer basis, no representative in the Union, no storage location named — https://www.credo.ai/legal/privacy-policy (as of 2026-08-24)
- SOC 2 Type II, categories reviewed are security, availability and confidentiality, report on request, annual repeat promised — https://www.credo.ai/legal/soc-2-type-ii-compliance (as of 2026-08-24)
- Dedicated page on the AI Regulation aimed at the customer's duties, still on the 2024 timetable, without the shifted high-risk deadlines — https://www.credo.ai/eu-ai-act (as of 2026-08-24)
- Separate design tenant, recommendation to use non-production data only, general availability announced for the first quarter of 2026, commercial terms after release left open, no model provider named — https://www.credo.ai/legal/credo-ai-design-partnership-brief-ai-powered-governance-assistant (as of 2026-08-24)
- Series B of 21 million US dollars dated 30.07.2024, investors, 41.3 million US dollars in total per the vendor — https://www.credo.ai/blog/accelerating-global-growth-and-innovation-in-ai-governance-with-21-million-in-new-capital (as of 2026-08-24)
- Series A of 12.8 million US dollars dated 17.05.2022, founded in March 2020, platform generally available since April 2022 — https://www.credo.ai/news/credo-ai-announces-12-8-million-series-a-funding-round-for-responsible-ai (as of 2026-08-24)
- OEM agreement with IBM dated 28.04.2025, Policy Packs as the content of the Compliance Accelerators add-on in IBM watsonx.governance — https://www.credo.ai/blog/credo-ai-and-ibm-empowering-trustworthy-ai-through-oem-collaboration (as of 2026-08-24)
- Alliance with QuantumBlack, AI by McKinsey, dated 02.04.2024 — https://www.credo.ai/blog/credo-ai-and-mckinsey-company-join-forces-to-deliver-ai-governance-risk-management-and-compliance-at-scale (as of 2026-08-24)
- Placement as a Visionary in Gartner's first Magic Quadrant for AI governance platforms dated 16.06.2026 — https://www.credo.ai/recognition/gartner-magic-quadrant-ai-governance-platforms-2026 (as of 2026-08-24)
- Trademark case 3:24-cv-02032-CRB before the United States District Court for the Northern District of California, filed 03.04.2024, open, last docket entry 17.08.2026 — https://cand.uscourts.gov/cases-e-filing/cases/324-cv-02032-crb/credo-technology-group-ltd-v-credoai-corp (as of 2026-08-24)
- No pricing page, no trust page, no subprocessor list and no separate data processing document among the 500 sitemap addresses checked — https://www.credo.ai/sitemap.xml (as of 2026-08-24)
- Named connections of the integrations hub for use cases, models, evidence and datasets — https://www.credo.ai/blog/connect-to-the-responsible-ai-ecosystem-through-the-credo-ai-integrations-hub (as of 2026-08-24)
- AI governance module with a use case register and mapping to ISO/IEC 42001, the NIST framework and the AI Regulation at a vendor from evidence automation — https://www.vanta.com/products/iso-42001 (as of 2026-08-24)
