Features

Every tool you need to catch risk, then prove governance.

From real time copy checking to governance assessment to forensic proof. Infrastructure built for marketers, agencies, CFOs, and compliance teams alike.

Regulatory mapping last reviewed: 26 July 2026

What we're tracking

May 2026FTC settled with Cox Media Group and two other firms for ~$1M over deceptive claims about an AI powered marketing service. First major "AI washing" settlement of the year.
May 2026EU AI Act timeline revised: high risk system deadlines pushed to Dec 2027 (Annex III) and Aug 2028 (Annex I), but prohibited practice and GPAI rules are already enforceable now, with fines up to €35M / 7% of turnover.
Jan 2026SEC named AI governance a cross cutting 2026 exam priority. Examiners will test whether firms' AI disclosures and controls match what their systems actually do, and scrutinise "AI washing" claims directly.

The proof layer

Anyone can write a policy. This proves one was followed.

Every governance product will tell you it keeps a record. The question worth asking is whether that record could survive someone checking it. These are the parts built for that.

The governance lifecycle

Every AI decision moves through eight stages.

Most governance programs stop at stage one, a document describing intent. The record only becomes real evidence once it survives stages two through eight.

1

Discover

Find where AI already makes or shapes decisions, including tools nobody formally approved. The free governance assessment scores six dimensions; the shadow AI audit surfaces the unauthorised tools already touching real decisions.

Free governance assessment + Shadow AI audit
2

Authorize

Every system gets a boundary authorization record: who approved it, what role they held, what options were weighed, what risk was knowingly accepted, and the exact date and named condition that voids the grant. A decision, not a policy.

Boundary authorization record — who / when / whether
3

Compliance

Marketing copy, claims and disclosures checked against the actual rules regulators enforce, across ten jurisdictions and thirty risk categories, before a complaint does the checking for you.

Compliance check — 10 jurisdictions, 30 categories

One of two pillars. Compliance checks what's said, run before the copy goes out, not after a complaint does it for you.

4

Governance

Every governance decision is checked and sealed the moment it happens, chained cryptographically with SHA-256, so editing, deleting or backdating a past entry breaks the chain and is provable, not just unlikely. Compliance checks what's said; governance seals what's decided.

Governance decision, cryptographically sealed live

The other pillar. Governance seals what's decided, a distinct check from compliance and just as load-bearing.

5

Review

A named person's honest first read is sealed before the AI's own reasoning is shown, so a sign-off can never be a rubber stamp on what the AI already said. Pushback rate and average time to sign-off are tracked, not just the final answer.

Commit-before-reveal + reviewer signal
6

Remediate

Disposing of a flag isn't the same as fixing it. Whether something was actually remediated, and when, is a separate, later confirmation, sealed on its own so a judgment call and a genuine fix can never be collapsed into one event.

Remediation record, sealed separately from disposition
7

Decay

Authorization isn't permanent by default. Every grant carries a named condition or date that voids it, and unreviewed, unbounded or overdue grants are surfaced as the live risk they are, not left to quietly expire unnoticed.

Falsifier conditions + authorization decay tracking
8

Prove

High value records carry an independent RFC 3161 trusted timestamp from a third party authority, and are cross sealed inside the Witness Network, so separate companies vouch for each other's evidence. Anyone can verify a record publicly, no account, without trusting our word for it.

RFC 3161 timestamp + Witness Network

Read the reasoning behind each stage in the whitepaper, or see every free tool.

This is the accountability layer: proof of who decided, when, and whether it holds up. It isn't a substitute for a formal conformity assessment, live model monitoring, or a regulatory filing. The linked tools above prepare real documents; none of them submit or certify anything on your behalf.

01

Boundary authorization records

One sealed record per AI system: what was approved, who approved it, in what role, when it expires, and the specific observable conditions that void it early. Covers API keys and agent credentials too, since a credential is standing authority the same way a decision is.

Every field, and why it exists

02

The decision authority map

Across every system you have authorized: how many decisions a human still makes, how many the AI recommends and a human clears, and how many the system now makes outright. Plus the ones where nobody ever said, which is usually the largest group at first.

How the map works

03

Commit before reveal

A reviewer records their own read of a flag before the AI's reasoning is shown to them, sealed in that order. You cannot rubber stamp a conclusion you have not seen yet. Enforced in the system, not promised in the interface.

04

Reviewer signal, not just sign-offs

How long a reviewer took before signing, and how often their sign-offs actually push back on a flag rather than accepting it. A clean approval history can mean careful judgment, or it can mean nobody looked. These tell them apart.

05

Sealed lapses and expiry

When an authorization passes its expiry, the lapse is sealed as its own dated event before any successor exists. A gap in coverage becomes a recorded fact rather than something reconstructed later, if anyone thinks to look.

What happens when one lapses

06

Independent witnessing

Records are hash chained and independently timestamped, and separate companies witness each other's chains so the proof does not rest on our word alone. There is a live tamper test you can run yourself.

See the witness network

07

Remediation tracking

A flag being found and disposed of is not the end of the record. Whether it was actually fixed, and when, is a separate, later confirmation, sealed on its own so a judgment call and a genuine fix can never be collapsed into one event.

08

Authority health, at a glance

Whether a scope decision still holds should never depend on someone remembering to ask. Every authorization you've recorded shows as a running count, still valid, unbounded, or already lapsed, so a gap in coverage is a visible fact on your dashboard, not something waiting to be discovered.

See how it's scored

The proof layer is part of Sentinel. Read the thinking behind it in the whitepaper.

Core Capabilities

All Tiers Include

01

Real Time Compliance Checking

11 jurisdictions, up to 30 risk categories. Paste copy or a URL and get a flagged result in under 60 seconds.

02

6-Dimension Assessment

Strategy & Decision Rights, Tool & Data Governance, Policy & Documentation, Monitoring & Outcome Accountability, Vendor Risk, Regulatory Readiness.

03

Instant Maturity Scoring

0-100 governance score. Dimension breakdown (0-30 each). Risk level classification (Critical/Moderate/Managed/Mature).

04

Critical Gap Identification

Top 3 to 5 gaps ranked by severity. Each flagged with regulatory context (Munir, SEC, EU AI Act, FTC, GDPR).

05

Strategic Roadmap

90 day quick wins, 6 month medium term, 12 month strategic plan. Owner + timeline for each action.

06

Board Ready PDF

Six page report: cover, dimension breakdown, red flags, strategic roadmap, executive summary, regulatory mapping.

07

Peer Benchmarking

Compare your score to industry average. See top quartile. Know where you stand relative to peers.

08

Your Full History, Not Just Today's Flags

Every result lists the categories checked that came back clean, not only the ones that flagged, and shows your score against your previous check automatically. A clean result is evidence too, and improvement is visible without anyone having to go looking for it.

09

18 Free Tools, No Account

Fine calculator, DPIA generator, FRIA assistant, EU database registration assistant, contract red flags checker, accessibility scorer, shadow AI audit and more. Free, and they stay free.

GROWTH Tier (£999/mo)

Ongoing Monitoring & Proof

01

Monthly Governance Reassessment

Quarterly governance score updates. Track improvement over time. Measure progress against roadmap.

02

Vendor AI Risk Tracking

Track all third party AI tools. Risk assessment scores. Data flow mapping. Contract checklist per vendor.

03

Monthly Compliance Dashboard

Dimension trends. Gap closure progress. Vendor risk overview. Policy compliance metrics.

04

Policy to Practice Gap Detection

Identify where policy differs from actual desk behavior. Governance drift alerts. Non compliance flags.

05

Evidence Package Generation

Auto generated audit ready artifacts. Governance logs. Compliance checklist. Regulatory framework mapping.

06

Quarterly Improvement Roadmaps

Updated strategic plan every 90 days. Adjust based on progress. New quick wins. Reorder by impact.

SENTINEL Tier (custom pricing)

Managed Governance + Forensic Proof

01

Managed Implementation

We build governance for you. Framework selection. Process design. Team training. Deployment support.

02

Automated Audit Logging

Every governance action is sealed into a cryptographic hash chain, verifiable on demand. Report downloads, vendor reviews, policy changes, stored server side, never editable by a user.

03

Ongoing Governance Monitoring

Monthly vendor and governance review reminders. Track drift between policy and practice. Flag gaps before they're tested by a regulator.

04

Financial Impact Modeling

Compliance cost calculator. Penalty risk modeling. ROI of governance investment. Board ready financial impact.

05

Governance Enforcement Support

We help you design and roll out real guardrails: policy enforcement, tool approval processes, data flow controls, with your team.

06

Board Ready Reporting

Governance scorecard. Risk trends. Compliance status. Built into a report you can take straight into your next board meeting.

07

Regulatory Readiness Review

Your governance mapped to EU AI Act, SEC, GDPR, Munir. Audit ready evidence package showing exactly where you stand against each framework.

08

API Access

Programmatic access to your check and assessment data, build it into your own vendor management, security or finance workflows.

09

Dedicated Governance Advisor

Quarterly strategy calls. Roadmap updates. Best practice guidance. Regulatory news briefings. Continuous improvement.

The tools find the risk.
The record proves you dealt with it.

Ready to know where you stand?

Start with a free assessment. See your score, gaps, and roadmap. Then choose Pro, Growth, or Sentinel.

Start assessment