AI Tools
Is your AI tool safe for work?
Curated privacy, security, and AI-governance risk profiles for the AI tools your team uses — data residency, training practices, certifications, and the EU AI Act angle. A curated assessment, not a certification.
ChatGPT
OpenAI OpCo, LLC
OpenAI's general-purpose conversational LLM — the most widely used AI tool at work, and the #1 shadow-AI risk.
Perplexity
Perplexity AI, Inc.
An AI answer engine that searches the web and cites sources — popular for research, and a common route for work queries to leave the org.
Claude
Anthropic PBC
Anthropic's LLM assistant, positioned around safety — its commercial tiers don't train on your data, which simplifies the governance story.
Gemini
Google LLC
Google's LLM, available both as a standalone consumer app and inside Google Workspace — the two have very different data terms.
Microsoft Copilot
Microsoft Corporation
Microsoft's AI assistant embedded in Microsoft 365 (Word, Outlook, Teams) — enterprise-grade when it's the M365 tenant version.
Grok
X.AI Corp.
xAI's chatbot, standalone and built into the X platform — trains on your interactions by default and is under EU regulatory scrutiny.
Notion AI
Notion Labs, Inc.
An in-app AI assistant inside Notion that writes, summarises and answers over your workspace — and doesn't train on your data by default.
DeepSeek
Hangzhou DeepSeek Artificial Intelligence Co., Ltd.
A Chinese-developed AI chatbot and LLM — its privacy policy stores your data in China, and it drew a wave of government bans in 2025.
Mistral Le Chat
Mistral AI
Mistral AI's chat assistant — a French, EU-jurisdiction, GDPR-native alternative to the US and Chinese LLMs.
Cursor
Anysphere, Inc.
An AI code editor that edits code and runs tasks from natural language — it sends your code context to third-party models to do it.
Qwen Chat
Alibaba Cloud (Alibaba Cloud Computing Ltd.)
Alibaba Cloud's Qwen (Tongyi Qianwen) chat assistant — a capable LLM under Chinese jurisdiction.
Kling AI
Kuaishou (Beijing Kuaishou Technology Co., Ltd.)
Kuaishou's text- and image-to-video generator — creates short AI video clips, hosted in China.
Manus
Butterfly Effect Pte. Ltd.
An autonomous AI agent that plans and executes multi-step tasks — browsing, coding and tool use — largely on its own.
Character.ai
Character Technologies, Inc.
A consumer chatbot for open-ended conversations with AI personas — with documented minor-safety incidents and litigation.
Codex
OpenAI OpCo, LLC
OpenAI's AI coding agent that writes, edits and runs code from natural-language tasks, in the terminal and the cloud.
Copilot
GitHub, Inc. (Microsoft)
GitHub's AI pair-programmer that suggests and completes code and answers coding questions inside the editor.
Midjourney
Midjourney, Inc.
A generative image tool that creates images from text prompts, used via Discord and the web.
HuggingChat
Hugging Face, Inc.
Hugging Face's open chat interface that serves community and open-source models in one place.
ElevenLabs
ElevenLabs Inc.
An AI voice platform for text-to-speech, voice cloning and dubbing across many languages.
Devin
Cognition AI, Inc.
Cognition's autonomous software-engineering agent that plans and completes coding tasks end to end.
Phind
Phind (Hello Cognition, Inc.)
An AI answer engine aimed at developers that searches the web and returns technical, cited answers.
Pi by Inflection
Inflection AI, Inc.
Inflection AI's personal-companion chatbot, designed for supportive, conversational back-and-forth.
Poe
Quora, Inc.
Quora's multi-model AI app that gives access to many chatbots and models in one interface.
Replit Agent
Replit, Inc.
Replit's AI agent that builds, edits and deploys apps from natural language inside the Replit IDE.
Suno
Suno, Inc.
An AI music generator that creates full songs — vocals and instrumentation — from text prompts.
v0
Vercel Inc.
Vercel's generative UI tool that turns prompts into React and Tailwind interface code.
How we rate
How we rate — a transparent, sourced rubric
Every risk level below is derived from primary-source facts — the vendor's own trust center, privacy policy, DPA, and sub-processor list, plus regulator actions where they exist. We weigh seven factors, and each tool page shows the reasoning behind its rating. Ratings are provisional and re-checked as vendors change terms; unknowns are marked, not guessed.
- •Does the default (consumer) tier train on your data — and can enterprise opt out?
- •Is EU data residency available, or is processing outside the EU?
- •Are a DPA and GDPR terms offered, and on which tier?
- •Certification posture — SOC 2, ISO 27001, ISO 42001, CSA STAR.
- •Vendor jurisdiction — EU, US, or China — for sensitive data.
- •Consumer-vs-enterprise readiness — is there a governed tier at all?
- •Incident, regulatory, or ban history from official sources.
We map these factors to Low, Medium, or High and show a short 'why this rating' on each tool, citing the sources it rests on. A tool shows no definitive risk pill until its rating is sourced — until then it reads 'assessment in progress'.
Risk levels are Qadar AI's curated assessment from cited primary sources — a curated assessment, not a certification, and not legal advice. Verify a tool's current terms before relying on them.