ApexClaw
Home › Registry
Registry

The Agent Readiness Registry

39 real organizations' public pages, scored with the same deterministic engine that scores this site — standards bodies, government AI pages, AI agent vendors, and AI security & governance tools. Only scores of 70 or above are named. Full evidence for every named score, one click away.

Engine: ARB/1.0 (spec date 2026-08-24) · Run date: 2026-08-26 · Method: audit.apexclawai.com/methodology · Machine mirror: /registry.json

What this measures, and what it does not. Every score on this page is the ARB/1.0 engine's read of one public page — whether it carries structured data, machine-readable dates, discoverable APIs, FAQ markup, citations, and the other signals that make a page legible to an AI agent. It says nothing about the organization's actual security posture, product quality, or trustworthiness. NIST scoring low here is not a statement about NIST's cybersecurity guidance; it is a statement about whether nist.gov's homepage happens to carry the specific markup this engine checks for. Treat every number below as "how machine-readable is this one page," full stop.

The naming rule

Only entries scoring 70 or above are named on this page, with their score and a link to full evidence. Entries scoring below 70 are still counted in their cohort's aggregate numbers below — n, min, median, max, distribution — but are never named. This threshold was fixed before any organization was scored, and it is stated here in plain language so the page cannot read as cherry-picking the entries that make us look interesting: 3 of the 39 organizations measured are named, under 8%. By cohort: 0% of Standards and Governance Bodies, 0% of Government AI Pages, 8.3% of AI Agent Vendors, 20% of AI Security and Governance Tools. The full check-by-check rubric behind every one of these percentages is published at audit.apexclawai.com/methodology.

Named entries (score ≥ 70)

78.0

Credo AI

AI Security and Governance Tools cohort. credo.ai

Full evidence →
76.5

Arize AI

AI Security and Governance Tools cohort. arize.com

Full evidence →
73.0

Mistral AI

AI Agent Vendors cohort. mistral.ai

Full evidence →

Cohort A — Standards and Governance Bodies

n=10. Two of the twelve candidates named in scope could not be measured and were dropped, not silently excluded: iso.org (Cloudflare JS challenge on both / and /robots.txt), oecd.org (403 to both a bot and a browser user-agent despite robots.txt technically permitting /). Neither was attempted to be bypassed.

nminmedianmaxnamed (≥70)
1014.554.868.00

Distribution: 0–20: 1 · 20–40: 2 · 40–60: 3 · 60–80: 4 · 80–100: 0

Cohort B — Government AI Pages

n=7. Three candidates in scope were dropped: meti.go.jp (403 to a bot user-agent, 200 to a browser user-agent — an explicit automated-access block, not bypassed), digital.gov.au (connection timeout on repeated attempts), and a separately-listed "canada.ca AI strategy page" that turned out to be the same live page as the ised-isde.canada.ca entry already counted — not double-counted as two members.

nminmedianmaxnamed (≥70)
721.757.069.00

Distribution: 0–20: 0 · 20–40: 1 · 40–60: 4 · 60–80: 2 · 80–100: 0

Cohort C — AI Agent Vendors

n=12. Two candidates were dropped: openai.com (403 to both a bot and a browser user-agent despite robots.txt permitting /, not bypassed), ServiceNow (connection timeout on repeated attempts).

Correction made before publish. UiPath scored 71.0 on first pass and was briefly treated as a named entry while this page was being built. A pre-publish reproducibility re-check found their homepage had genuinely changed — Organization JSON-LD, sameAs and contactPoint markup that was present on the first pass was absent on six consecutive fresh re-runs, all returning 61.0. The number below reflects that re-check, and UiPath is correctly unnamed. Full disclosure on its evidence page.

nminmedianmaxnamed (≥70)
1234.560.873.01

Distribution: 0–20: 0 · 20–40: 1 · 40–60: 4 · 60–80: 7 · 80–100: 0

Cohort D — AI Security and Governance Tools

n=10. Four candidates were dropped: CalypsoAI and Robust Intelligence (connection timeouts — both have been absorbed into larger acquirers, F5 and Cisco respectively, and their standalone domains no longer resolve reliably), Drata (403 to a bot user-agent, not bypassed), Aporia (connection timeout on repeated attempts).

nminmedianmaxnamed (≥70)
1042.558.578.02

Distribution: 0–20: 0 · 20–40: 0 · 40–60: 7 · 60–80: 3 · 80–100: 0

Method, briefly

Every score is produced by calling the same ARB/1.0 engine this site's own audit tool runs, directly against the target's public homepage (or the most specific public AI-strategy page where the brief named one) — no login, no scraping behind auth, one page per organization. robots.txt was fetched and checked for each target before scoring; any target disallowing / for User-agent: * would have been skipped (none of the 39 scored targets did). Sites that blocked automated fetches outright (Cloudflare JS challenges, WAF rules that 403 both a bot and a browser user-agent) were dropped rather than bypassed. Reproducibility was checked by re-running every score at or near the naming threshold multiple times, including a final pass immediately before publish. One entry, Arize AI, showed run-to-run variance from what looks like a rotating content block on their homepage; see its evidence page for how the published number was chosen. A second, UiPath, scored 71.0 on the first pass but a stable 61.0 on six consecutive re-runs done right before publish, and was moved out of the named tier as a result — see its evidence page for the full record. Both corrections happened before this page went live, not after.

Licensed CC-BY 4.0. Machine mirror: /registry.json.

Common questions

Does a low score mean an organization is insecure?

No. It means the page this engine fetched was missing some of the 36 machine-readability signals it checks for — structured data, dates, citations, that kind of thing. It is not a statement about security, product quality, or trustworthiness.

Why are two whole cohorts unnamed?

Because nobody in Cohort A (standards bodies) or Cohort B (government AI pages) reached 70. That is the rule working as designed, not an omission — their aggregate numbers are published above either way.

Can an organization ask to be re-scored?

There is nothing to ask for. The engine is deterministic and re-runs against the live page on request; the same page will produce the same evidence.

Why were some candidates dropped instead of scored?

A handful of pages blocked automated fetches outright (Cloudflare challenges, WAF rules) or timed out repeatedly. Rather than try to defeat that protection, they were dropped and the reason is stated next to their cohort above.

What does embedding the badge actually do?

It links back to that organization's evidence page on this site — nothing more. It is not a certification mark and does not imply an ongoing relationship.