The first public release
Use cases, risk register, vendor records, and role-based access, with report generation and email invitations.
Use cases, risk register, vendor records, and role-based access, with report generation and email invitations.
ISO 27001 arrives alongside the EU AI Act, and the backend moves to a repository pattern for controls and project scope.
Vendor risk is restructured and expanded, state moves to Redux for a single source of truth, and the dashboard gains search.
A full task page for compliance tracking, model risk management with Swagger API docs, and fairness metric visualizations.
Around 40 merged PRs: icon migration to Lucide, a reusable empty state, a command palette, and SSO via Microsoft Entra ID.
A full automations module with drawer-based workflows, an integrations hub with Slack, and AI incident management for the EU AI Act.
MLflow experiment tracking, Ollama for local inference in bias and fairness, the IBM AI Risk database, and org-level projects.
Model versioning tracks changes over time. NIST AI RMF lands with risk linking, CE marking arrives, and Wise Search covers the app.
A dedicated LLM evaluation module with dashboards and dataset management, plus the in-app user guide and activity history.
An interactive graph of models, risks, vendors, and controls; a code-scanning detection module; and an AI governance advisor.
A plugin marketplace for extensibility, a virtual file manager, real-time notifications over SSE, and a dataset inventory for Article 10.
Shadow AI detection surfaces unauthorized tool usage, agent discovery builds an inventory, and law-aware bias audits arrive.
The AI Gateway centralizes LLM traffic with guardrails, spend tracking, and virtual keys. Policy Radar monitors vendor policy changes.
Owner, reviewer, approver, and due date move up to the EU AI Act control level. Training records accept evidence uploads.
Three modules at once. The Trust Index grades third-party AI apps, AI Apps governs the tools teams use, and Agent Control gates what agents do.
Tiering, staged validation, findings, threshold monitoring, revalidation, and attestation, built for SR 26-2, SS1/23, and OSFI E-23.
Watch vendor terms of service and privacy policies for changes, with clause-level analysis that scores severity and maps each change to the frameworks it affects.
Beyond gating single tool calls: govern agents as a fleet. Path-based write rules, decision provenance on every call, a priority rule engine, and adapters for agents without a native hook.
Controls that test themselves on a schedule and raise a finding when they drift, so posture is a live signal rather than a point-in-time attestation.
The platform adjusts itself as obligations move. New and amended rules map onto your existing controls, and the gaps they open become tracked work instead of a manual re-mapping exercise.
Governance work ordered by exposure rather than by checklist position, so the highest-risk models and obligations surface first and effort follows the actual risk.