VerifyWise

From a compliance tool to an AI governance platform

40+releases
Phase 01FoundationJun – Sep 2025
v1.0Jun 11, 2025First

The first public release

Use cases, risk register, vendor records, and role-based access, with report generation and email invitations.

Risk registerVendorsRBAC
v1.1 – v1.2Jun – Aug 2025

ISO 27001 and the repository layer

ISO 27001 arrives alongside the EU AI Act, and the backend moves to a repository pattern for controls and project scope.

ISO 27001Repository layer
v1.2.2Aug 26, 2025

Vendor risk and Redux migration

Vendor risk is restructured and expanded, state moves to Redux for a single source of truth, and the dashboard gains search.

Vendor riskRedux
v1.3 – v1.4Sep 2025

Task management and model risk

A full task page for compliance tracking, model risk management with Swagger API docs, and fairness metric visualizations.

TasksModel riskFairness
Phase 02ExpansionOct 2025 – Jan 2026
v1.5Oct 14, 2025

UI overhaul and enterprise auth

Around 40 merged PRs: icon migration to Lucide, a reusable empty state, a command palette, and SSO via Microsoft Entra ID.

Command paletteSSO
v1.6Oct 28, 2025

Automations and integrations hub

A full automations module with drawer-based workflows, an integrations hub with Slack, and AI incident management for the EU AI Act.

AutomationsSlackIncidents
v1.6.1 – v1.6.4Nov 2025

MLflow, Ollama, IBM risk database

MLflow experiment tracking, Ollama for local inference in bias and fairness, the IBM AI Risk database, and org-level projects.

MLflowOllamaIBM risk DB
v1.7Dec 3, 2025

Model versioning and frameworks

Model versioning tracks changes over time. NIST AI RMF lands with risk linking, CE marking arrives, and Wise Search covers the app.

NIST AI RMFCE markingWise Search
v1.8Dec 19, 2025

LLM evals module and docs sidebar

A dedicated LLM evaluation module with dashboards and dataset management, plus the in-app user guide and activity history.

LLM EvalsUser guide
v1.9Jan 15, 2026

Entity graph and AI detection

An interactive graph of models, risks, vendors, and controls; a code-scanning detection module; and an AI governance advisor.

Entity graphAI DetectionAI advisor
Phase 03PlatformFeb – Jul 2026
v2.0Feb 6, 2026Major

Plugin marketplace and notifications

A plugin marketplace for extensibility, a virtual file manager, real-time notifications over SSE, and a dataset inventory for Article 10.

MarketplaceNotificationsDatasets
v2.1Feb 19, 2026Major

Shadow AI and bias audits

Shadow AI detection surfaces unauthorized tool usage, agent discovery builds an inventory, and law-aware bias audits arrive.

Shadow AIBias auditsJira
v2.2Apr 2, 2026Major

AI Gateway and Policy Radar

The AI Gateway centralizes LLM traffic with guardrails, spend tracking, and virtual keys. Policy Radar monitors vendor policy changes.

AI GatewayGuardrailsCI/CD
v2.3 – v2.3.5Apr – May 2026

Control-level ownership

Owner, reviewer, approver, and due date move up to the EU AI Act control level. Training records accept evidence uploads.

Control workflowTraining evidence
v2.4Jun 22, 2026Major

Trust Index, AI Apps, Agent Control

Three modules at once. The Trust Index grades third-party AI apps, AI Apps governs the tools teams use, and Agent Control gates what agents do.

AI Trust IndexAI AppsAgent Control
v2.4.1Jul 15, 2026Latest

Model risk management

Tiering, staged validation, findings, threshold monitoring, revalidation, and attestation, built for SR 26-2, SS1/23, and OSFI E-23.

MRMOptional frameworksDesign tokens
Shipped ↑ Β· Planned ↓
NextWithin 3 monthsIn progress or scoped
Policy RadarIn progress

Terms and privacy policy monitoring

Watch vendor terms of service and privacy policies for changes, with clause-level analysis that scores severity and maps each change to the frameworks it affects.

Vendor T&CPrivacy policiesClause diffs
Agentic AIPlanned

Agentic AI management

Beyond gating single tool calls: govern agents as a fleet. Path-based write rules, decision provenance on every call, a priority rule engine, and adapters for agents without a native hook.

Path gatingRule engineProvenance
ControlsPlanned

Continuous control monitoring

Controls that test themselves on a schedule and raise a finding when they drift, so posture is a live signal rather than a point-in-time attestation.

Scheduled testsDrift alerts
LaterWithin 6 monthsDirection, not commitment
AdaptiveExploring

Regulation-aware automation

The platform adjusts itself as obligations move. New and amended rules map onto your existing controls, and the gaps they open become tracked work instead of a manual re-mapping exercise.

Auto-mappingObligation trackingGap detection
AssuranceExploring

Risk-driven prioritisation

Governance work ordered by exposure rather than by checklist position, so the highest-risk models and obligations surface first and effort follows the actual risk.

Exposure scoringAdaptive queues
Scroll, drag, or use arrow keys
VerifyWise roadmap: what we shipped and what is next