Overview
Loading executive summary…
AI risk posture
Risk breakdown
By category
| Status | Machine | IP | User | Last seen | Agent |
|---|
| Risk | Machine | Category | Name | Detail | Status | Seen | Source | Feedback |
|---|
| Severity | Class | Risk | Machine | Status | Last seen |
|---|
Framework controls currently failing, mapped from your open risks — NIST AI RMF · OWASP LLM Top 10 · ISO 42001 · EU AI Act. Review with your compliance team, then export the audit-ready evidence pack.
Your open AI risks in MITRE's language — ATLAS (AI-specific) and ATT&CK techniques — plus any detected artifact linked to a known malicious-AI campaign or threat actor.
MITRE technique coverage — techniques your open risks map to
| Framework | Technique | Name | Tactic | Open risks |
|---|
APT groups weaponising AI — state actors observed abusing LLM/AI tooling (MS/OpenAI, 2024)
| Actor | Also known as | Attribution | Observed AI use | ATLAS |
|---|
Define which AI tools are approved for your org. Everything discovered is then shown as approved, unsanctioned, or blocked. Block a specific tool or model (e.g. DeepSeek) and — with enforcement on — sensors will block it fleet-wide on their next cycle.
Approved AI tools — one per line or comma-separated
Blocked tools / models — names
Blocked domains — egress hostnames
Enforcement modifies the endpoint (null-routes denied hostnames, terminates denied processes). Strongest on Linux. Leave off to observe-and-report only.
Discovered AI tools by status
Risks triaged as false positives — moved off the main board, retained for audit. Each keeps its full comment trail (who marked it, why, and every edit since).
| Severity | Class | Risk | Machine | Marked by | Notes |
|---|
People ranked by AI-risk exposure. Enrich with your IdP to add name, department, and employment status.
| Person | Department | Status | Devices | Open risks | Posture |
|---|
Every triage, comment, false-positive, directory sync, and quarantine — who did what, when. The tamper-evident record for auditors.
| When | Actor | Action | Detail |
|---|
Push new AI-risk findings straight into the tools your team already lives in. Integrations are config-driven — no credentials are stored in the product; they are read from environment/secrets at runtime.
Accounts with dashboard access. Roles: domain_admin (full + roles), org_admin (manage users), project_manager (triage), org_user (read-only).
| User | Role | MFA | Status | Last login |
|---|
| Status | Machine | OS | IP | User | Enrolled | Last seen | Agent |
|---|
Customer organizations
| Tenant | Slug / subdomain | Plan | License | Sensors |
|---|
Provision a new tenant
Creates the org and its unique enroll key. Configure that key as the sensor's SENSOR_KEY to bind endpoints to this tenant.
| Tenant | Plan | Status | Days left | Expiry | Active users | Users | Devices | Last active | Actions |
|---|
Active = license valid >30 days · Expiring = within 30 days · Expired = past due. A reminder email goes out automatically ~30 days before expiry.