AI that shows its work

Sixteen AI capabilities embedded across the platform. Your data stays in the EU. AI processes in-context only.

01

Understand

01.1
Regulatory Q&A

Ask about any enabled framework in plain language. The copilot answers from your workspace context — risks, controls, incidents, vendors — with cited sources, footnoted rather than asserted.

"What are the NIS2 incident-reporting deadlines for an essential entity?"

01.2
Gap analysis

Scan a framework's controls against your implementation status and evidence to surface where coverage is thin — before an auditor does.

Gap scan across ISO 27001: 12 controls flagged with missing or expiring evidence.

02

Assess

02.1
Evidence analysis

Drop documents into the repository and AI proposes control links, tags and sensitivity levels. OCR handles scanned documents. You confirm — nothing links itself silently.

Pen test report uploaded → proposed links to 5 controls across NIS2 and ISO 27001.

02.2
Control mapping

Map a control to the framework requirements it satisfies — suggested automatically, confirmed by you.

New access-control policy mapped to ISO A.5.15 and NIS2 Art. 21(2)(i).

02.3
Cross-framework mapping

Find control equivalences across NIS2, ISO 27001, NIST CSF and CIS Controls — implement once, satisfy each.

NIS2 ART. 21(2)(d) ↔ ISO A.5.19 ↔ NIST CSF GV.SC ↔ CIS CONTROL 15

02.4
Vendor analysis

Questionnaire responses analysed for risk drivers and follow-up material, feeding the vendor's risk score — with the reasoning shown.

3 risk drivers identified in a cloud provider's responses; score updated with reasoning attached.

02.5
Questionnaire auto-response

Inbound security questionnaires answered from your policies, controls and approved answer library. Every draft is held for your review.

A 42-question customer questionnaire drafted in minutes — prior approved answers reused where they match.

02.6
Vendor claim verification

Cross-checks a vendor's questionnaire claims against the posture scan's own findings — contradicted, unverifiable, a disclosed gap, or corroborated — with the citing evidence shown.

A vendor's claim that DMARC is enforced, checked against the scan's DNS findings and cited by rule ID — corroborated, contradicted, unverifiable or only disclosed as a gap.

02.7
Policy-to-control suggestions

Reads an uploaded policy and proposes which existing controls it already addresses, each suggestion grounded in a verbatim quote from the policy text.

A data-retention policy checked against the control library — each suggested link quotes the exact clause it's grounded in; anything unsupported is withheld, not guessed.

02.8
Audit-finding extraction

Extracts findings from an uploaded audit report — title, description and a citation back to the source page — then proposes which controls each one touches.

An external auditor's PDF uploaded → findings extracted with page citations, and candidate control links proposed for review.

03

Act

03.1
Remediation planning

Prioritised action plans with owners, effort estimates and timelines, built from your actual gaps.

A 90-day NIS2 plan: 23 tasks across 4 workstreams.

03.2
Report generation

Board packs, executive summaries and compliance reports drafted from live workspace data.

A 2-page board briefing on NIS2 readiness with risk highlights and open actions.

03.3
Risk recommendations

Context-aware risk suggestions from your assets, controls and vendor landscape — with proposed likelihood and impact, reasoned.

3 supply-chain risks proposed from vendor questionnaire responses.

03.4
Policy generation

Draft policies aligned to your frameworks and organisation profile — a reviewed starting point, not a rubber stamp.

Access-control policy drafted against ISO A.5.15 for your review.

03.5
Follow-up questionnaires

Targeted follow-up questions generated from a vendor's previous answers — chase the gaps, not the checklist.

6 follow-up questions generated from a vendor's incomplete encryption answers.

03.6
Posture digest

A narrative summary of your compliance posture drawn from workspace signals, delivered on a daily or weekly cadence with its sources cited.

A weekly digest emailed to admins: a short narrative plus the signals behind it, each traceable to its source.

Drafts are always held for human review, and inventing certifications or audit findings is forbidden at the prompt level.
04

AI Copilot Chat

An always-available GRC assistant embedded in every page. Ask questions about risks, controls, compliance gaps, or regulatory requirements — and get contextual answers grounded in your organization's data.

  • 04.1Context-aware answers from your GRC data
  • 04.2Risk assessment and gap analysis
  • 04.3Regulatory guidance for NIS2, ISO 27001, GDPR
  • 04.4Available on every page via floating button
AI Copilot conversation
FIG. 01AI Copilot conversation

Experience AI-powered GRC

See the assistants working on your frameworks.