We surveyed n8n, LangChain/LangGraph, Tines, Blink Ops, Torq, and the major iPaaS players against what security operations on sensitive data requires. They sell the easy 40%. The four capabilities they all lack are the expensive 60%, and you build that yourself either way.
Everyone is BYO-API-key or hosted frontier models. Your prompts, customer data included, still leave the boundary.
Absent on every platform surveyed. Tenant privacy is not redaction.
Platform RBAC exists, often paywalled. Policy gating of what an agent may touch does not.
The platform's SOC 2 is not the SOC 2 of the thing you build on it.
| Capability | n8n | LangGraph | Security automation (Tines · Blink · Torq) | Kindo |
|---|---|---|---|---|
| Security-tuned model in your boundary | ◐ | ◐ | ◐ | ✓ |
| DLP/PII redaction on model traffic | ✗ | ✗ | ✗ | ✓ |
| Per-resource agent authorization | ◐ | ✗ | ◐ | ✓ |
| Compliance-grade agent audit | ◐ | ✗ | ✓ | ✓ |
| On-prem / air-gapped deployment | ◐ | ◐ | ◐ | ✓ |
✓ native · ◐ partial, BYO, or paid-tier · ✗ absent, build it yourself. Grouped cells show the best case across those vendors (e.g. only Tines self-hosts). The ◐ cells are the hidden-cost argument: possible, with effort and spend that never appears on the pricing page.
Their price buys integrations and workflow ergonomics; the security control plane is left for you to build and staff. Kindo ships all four missing capabilities as product, at $250k/yr list for SaaS, bring your own inference: less than one loaded platform engineer.