Skip to content
Obligara

Embedded AI

The AI does the boring parts. You stay accountable.

Not a chatbot panel bolted onto the side. Five AI surfaces sit inside the workflow and inside your row-level-security boundary — drafting, mapping and assessing against your live data, never saving without a human.

Gap analysisAI

Control verdicts

  • A.5.1Policies for information securityReady
  • A.8.16Monitoring activitiesPartial
  • A.8.24Use of cryptographyGap

Cited from your evidence — e.g. EVD-104, EVD-098.

Five surfaces

Where the AI shows up

Each surface names exactly what it does — no “powered by AI” hand-waving.

  • Chat assistant

    Answers questions against your live workspace.

    Read-only tools walk your QMS inside the same row-level-security boundary as the rest of the app. It cites record references (CAPA-012, RISK-007) that link straight to the detail page — no vector-search-and-pray.

  • AI gap analysis

    Verdicts each control as ready, partial or gap.

    Per-control verdicts with the cited evidence references behind them, so you can see what is covered and what still needs work before an audit.

  • AI readiness analyser

    Narrative readiness, criterion by criterion.

    Per-criterion narrative verdicts for SOC 2 readiness, persisted as snapshots so you can track how readiness moves over time.

  • AI mapping suggester

    Proposes control → TSC criteria mappings.

    Suggests how each ISO 27001 control maps to SOC 2 Trust Services Criteria — one control at a time, or in bulk across the set.

  • AI form-fill assists

    Drafts the long fields for a human to approve.

    CAPA root-cause, risk treatments, management-review inputs and the SOC 2 system description — drafted from your live data, then edited and signed off by a person.

Why it works

Most “AI for compliance” hallucinates. Ours doesn’t.

Three architectural choices keep the AI grounded in your data and incapable of doing damage.

Read-only tools, not freeform retrieval

The assistant calls typed functions that hit the database inside your row-level-security context. It reads what you can read — nothing more.

AI cannot mutate your records

Every assist fills a form for a human to review and save. The audit log only ever records a person’s signature, never the model’s.

Shaped output, not loose text

Structured suggestions run a tool-using research pass and a schema-bound generation pass, so output is always shaped and checkable.

The two-stage pipeline

Structured suggestions — “suggest a risk”, “verdict this control” — run a tool-using research pass that reads your live records, then a schema-bound generation pass that shapes the output. There’s no vector-search-and-pray step, and the result is always a structured object you can check, not loose prose.

Governance

Built for an audit committee, not a demo

The questions a security reviewer asks about AI, answered before they ask.

Off by default, per workspace

AI is a master toggle each organisation opts into. Every AI route is gated by both that toggle and the user’s per-module access — it can never see more than the person using it.

No training on your data

Supported providers are configured for zero-retention; your prompts and records are never used to fine-tune a model.

Provider-agnostic

Run against OpenAI directly, or route through OpenRouter for Claude, Gemini or Llama — a per-organisation choice, not a lock-in.

What the AI never does: it doesn’t save records, approve documents, sign off audits or write to your audit log. Every assist fills a form for a person to review — the audit log only ever records a human’s signature.

See the AI on your own data

Watch gap analysis, readiness verdicts and the system-description drafter run against a real (or seeded) workspace.