Managed Connectors
Pre-built catalog size
Enterprise Connectors
RSA, service accounts,tenant Azure AD, DWD
RSA, service accounts, DWD, Azure AD
OAuth only, no tenant scoping
Build-Your-Own
Custom connectors & tools
Inherits vault + audit; scoping is manual
Open-source, core to product
Proxy API + OpenAPI import
Tool Bundles
Scoped, Virtual-MCP-style
Persistent config + session-token identity
Persistent config (allowed_tools) + per-user URLs
Triggers / Webhook Events
Agent reacts to external events
Real-time for some, polling for others
Inbound webhooks trigger agent runs
Not offered, pull-based only
Mature, 130+ pre-built triggers
Vault Isolation
One key per secret, or
one key for many?
Unique key per credential
One key covers many credentials
One key covers many credentials
Centrally managed, shared keys
Isolated per user, shared keys
Isolated per tenant, shared keys
OAuth Ownership
Who owns the app/client ID
Default, yours from day one
Opt-in, shared by default
Unclear, conflicting docs
No, one shared app for all
Call-Time Verification
Who owns the app/client ID
Every call, not just connect
Connect-time only at base tier
White-Label UX
Who owns the app/client ID
No branding on hosted widget
Wrapper only, consent isn't
Fully whitelabeled, most polished
Audit & SIEM
Logging + external streaming
SIEM streaming at Enterprise
SIEM export is a paid add-on
ISO 27001
Fewer clear this one
Inconsistent on their own site
HIPAA & GDPR
Healthcare & EU privacy coverage
Both covered, HIPAA BAA is paid
Governance Depth
RBAC, DLP, approvals
Per-tool scoping + role ceiling
RBAC new in 2026, growing
Basic, API keys bypass RBAC
Basic, internal users only
VPC
Runs inside your own cloud account
Yes, enterprise self-host
Self-Hosted / On-Premise
Runs on infrastructure you control
Yes, Enterprise, explicit on-prem
Self-hosted functionally, on-prem unclear
Yes via Helm, full on-prem unconfirmed
No, denied in their own FAQ
Air-Gapped
Fully offline operation
Claimed, not corroborated