Compare

The part the closed-source vendors keep behind a moat.

Every funded vendor in close + reconciliation + AP shipped agentic AI in 2025–2026. Every one keeps the policy gate closed. Here's the capability matrix and per-vendor deep-dives.

Capability closegate (OSS) BlackLine · FloQast · Numeric · Trullion Ramp · Brex · Vic.ai · AppZen
Open-source policy gate (readable + auditable chokepoint code) Apache-2.0 closed closed
Per-agent identity + SoD enforced server-side (not at the prompt) X-Actor-Id proprietary proprietary
Materiality + NIST AI RMF tier routing (T0/T1/T2/T3) executable policy.yaml partial partial
Append-only SQLite audit log with DB-layer triggers open SQL schema vendor-controlled vendor-controlled
Verbatim policy clause text + JSON-pointer on every blocked event varies varies
Dual-HITL on irreversible (T3) actions like payment-run submission varies varies
Self-host on your own infra (Docker / Kubernetes / fly.io) SaaS-only SaaS-only
Drop-in MCP server (Claude Desktop · Cursor · OpenAI Apps SDK) no no
Bring-your-own LLM (Claude · GPT-4 · Gemini · open-weight) no no
Per-IdP SSO (Entra ID · Okta · Workspace · SAML · Cloudflare) OIDC + proxy varies varies
Eval harness (matching · policy · adversarial · latency) 4 dims, reproducible no no
Cost Free (self-hosted compute only) $50K–$500K/yr $20K–$200K/yr

Inbound

Actively evaluating? Get the unblinded view.

We won't try to sell you closegate if a SaaS vendor fits your shape better. DM if your RFP framework is half-built and you want a second opinion.