Embedded AI
The AI does the boring parts. You stay accountable.
Not a chatbot panel bolted onto the side. Five AI surfaces sit inside the workflow and inside your row-level-security boundary — drafting, mapping and assessing against your live data, never saving without a human.
Control verdicts
- A.5.1Policies for information securityReady
- A.8.16Monitoring activitiesPartial
- A.8.24Use of cryptographyGap
Cited from your evidence — e.g. EVD-104, EVD-098.
Five surfaces
Where the AI shows up
Each surface names exactly what it does — no “powered by AI” hand-waving.
Chat assistant
Answers questions against your live workspace.
Read-only tools walk your QMS inside the same row-level-security boundary as the rest of the app. It cites record references (CAPA-012, RISK-007) that link straight to the detail page — no vector-search-and-pray.
AI gap analysis
Verdicts each control as ready, partial or gap.
Per-control verdicts with the cited evidence references behind them, so you can see what is covered and what still needs work before an audit.
AI readiness analyser
Narrative readiness, criterion by criterion.
Per-criterion narrative verdicts for SOC 2 readiness, persisted as snapshots so you can track how readiness moves over time.
AI mapping suggester
Proposes control → TSC criteria mappings.
Suggests how each ISO 27001 control maps to SOC 2 Trust Services Criteria — one control at a time, or in bulk across the set.
AI form-fill assists
Drafts the long fields for a human to approve.
CAPA root-cause, risk treatments, management-review inputs and the SOC 2 system description — drafted from your live data, then edited and signed off by a person.
Why it works
Most “AI for compliance” hallucinates. Ours doesn’t.
Three architectural choices keep the AI grounded in your data and incapable of doing damage.
Read-only tools, not freeform retrieval
The assistant calls typed functions that hit the database inside your row-level-security context. It reads what you can read — nothing more.
AI cannot mutate your records
Every assist fills a form for a human to review and save. The audit log only ever records a person’s signature, never the model’s.
Shaped output, not loose text
Structured suggestions run a tool-using research pass and a schema-bound generation pass, so output is always shaped and checkable.
The two-stage pipeline
Structured suggestions — “suggest a risk”, “verdict this control” — run a tool-using research pass that reads your live records, then a schema-bound generation pass that shapes the output. There’s no vector-search-and-pray step, and the result is always a structured object you can check, not loose prose.
Governance
Built for an audit committee, not a demo
The questions a security reviewer asks about AI, answered before they ask.
Off by default, per workspace
AI is a master toggle each organisation opts into. Every AI route is gated by both that toggle and the user’s per-module access — it can never see more than the person using it.
No training on your data
Supported providers are configured for zero-retention; your prompts and records are never used to fine-tune a model.
Provider-agnostic
Run against OpenAI directly, or route through OpenRouter for Claude, Gemini or Llama — a per-organisation choice, not a lock-in.
See the AI on your own data
Watch gap analysis, readiness verdicts and the system-description drafter run against a real (or seeded) workspace.