Opik

Comet

Open Source

Open-source platform to trace, evaluate and monitor LLM apps, RAG systems and agents, with LLM-as-a-judge metrics and prompt optimization.

Curated by Tiberiu ArvaVerified

Apache 2.0Version 2.2.86Released 2026-09-30

Strengths

  • Apache 2.0 server and UI self-hostable
  • PyTest integration for LLM CI checks
  • Python and TypeScript SDKs plus OpenTelemetry

Practitioner note

The Apache 2.0 license makes self-hosting low-risk, but self-hosted Opik lacks user management, so plan for network-level access control. Comet's docs describe the Docker install as not production-ready and point to Kubernetes/Helm for production.

Governance posture

Reviewed 2026-09-30
YesData residency

Self-hosting on Kubernetes keeps data in the operator's infrastructure. Comet Cloud regions are not stated on the pages reviewed.

Source
YesDeployment model

Comet-hosted cloud, local Docker Compose (not production-ready), or production Kubernetes/Helm. (saas, self-hosted)

Source
UnknownAudit logging

The pages reviewed do not describe audit logs, and self-hosted Opik ships without user management.

YesSOC 2

Comet lists SOC 2 Type 2 on its Trust Center, covering the Comet-hosted service. Self-hosted instances rely on the operator's controls.

Source
YesISO 27001

Comet lists ISO/IEC 27001:2022 on its Trust Center (company and hosted service). Not applicable to self-hosted instances.

Source
UnknownISO 42001

The Comet Trust Center lists ISO 9001, ISO 27001 and SOC 2 but not ISO 42001.

N/AEU AI Act

Observability and evaluation tooling, not an AI system placed on the market. Obligations rest with the deployer. (role: not-applicable)

YesLicense risk

Apache 2.0. The README says the server, web app and core observability and evaluation can be self-hosted without a commercial license. (low)

Source

EU AI Act obligations

Risk tier: Not applicable · as of 2026-08-23

Source-backed information mapped from Opik's tracked risk tier — not legal advice. Obligations depend on how your organisation deploys the system; see the full obligation reference and timeline.

This record's EU AI Act risk tier is marked not applicable, so no tier-specific obligations attach. Deployers embedding it in an AI system in scope of the Act should assess that system's own tier.

Explore the category

Compare this tool against the rest of its category and the cloud platform foundation layer.