For compliance, security & IT leadership

"Who approved this AI tool,
and on what basis?"

That question arrives from an auditor, a customer security questionnaire, or your board — usually with a deadline. The Tracker is where employees request AI tools, where each one gets assessed and decided, and where the dated, attributed record of that decision lives.

From $299/month · Onboarding a first group of teams

Your AI tool list lives in someone's head.

Somebody approved Otter.ai for the sales team eleven months ago, over Slack. Nobody wrote down what data it was allowed to touch, nobody has looked at it since the vendor changed its retention terms, and the person who approved it has left. That is the normal state of things — and it is fine right up until someone asks you to evidence it.

The request arrives anyway

People will adopt tools whether or not there is a process. Without one, the decision happens in a DM and leaves no trace.

Approvals go stale silently

A tool approved last year against last year's terms is not approved today. Nothing tells you which ones have drifted.

Evidence is reconstructed under pressure

Assembling a defensible history the week an auditor asks is the most expensive possible time to do it — and the least convincing.

Request, assess, decide, record.

Four steps, and the fourth is the one you are actually buying.

An employee requests a tool

They name it, what they want it for, and what data it would touch. One short form, sent from a link you share.

It gets assessed

The request is classified against the EU AI Act risk tiers and mapped to NIST AI RMF, ISO 42001, SOC 2, GDPR and CCPA, with a risk score and a recommendation. A PDF is generated and filed.

You decide

Approve, approve with conditions, or deny — from a dashboard, with the assessment in front of you. The requester is emailed the outcome automatically.

It becomes the record

The decision, the acting user and the timestamp land in an append-only audit trail, and the tool joins your inventory with a review date.

What this is — and what it isn't.

This is the section a compliance buyer reads first, so it goes near the top rather than in the small print.

What it does
Captures AI tool requests, assesses each against the EU AI Act and your frameworks, routes it to a human decision, and keeps an append-only record of every request, decision, inventory change and export — with the acting user and timestamp.
What it is not
Not a reproducible legal determination. The assessment is AI-assisted triage to inform a human decision, not a deterministic classification you could re-run and expect byte-identical output. What is defensible is the record: who decided, when, and what the assessment said at the time.
Not legal advice
It maps to frameworks and flags obligations; it does not tell you whether you comply. Genuinely legal questions belong with counsel.
Where your data sits
Each organisation's requests, decisions and inventory are isolated at the database level. Decisions are written through a controlled database function rather than direct table access, so a decision cannot bypass the audit trail or be deleted out of it.

The monthly summary is the point.

On the first of each month, every admin gets a posture report for the month just ended: requests received, how they were decided, what joined the inventory — and, leading the email, every approval that has passed its review date. An approval nobody has revisited is the one an auditor pulls on, so it sits at the top rather than under the counts.

Priced per organisation.

Month-to-month. No per-request charge — the point is that people file requests rather than route around the process.

Team
$299/mo
Up to 3 administrators
  • Unlimited tool requests
  • Assessment + PDF per request
  • Append-only audit trail
  • Tool inventory with review dates
  • Monthly posture report
Request access
Enterprise
Custom
Multi-entity, SSO, SLA
  • Everything in Compliance
  • Single sign-on
  • Multiple legal entities
  • Onboarding for your GRC team
Talk to us

Month-to-month, cancel any time · Covered by the same 30-day money-back guarantee as our other plans
Already have an AI policy? The Tracker enforces one — see the policy generator.

We're onboarding a first group of teams.

The Tracker is new. We are starting with a small number of organisations so we can cover the frameworks you are actually audited against and fix what does not survive a real approval queue. Tell us what you are up against and we will come back to you personally, usually within two business days.

What teams ask first

No — and we would rather say so here than have you find out in an audit. The assessment is AI-assisted triage: it classifies a requested tool against the EU AI Act risk tiers and maps it to NIST AI RMF, ISO 42001, SOC 2, GDPR and CCPA, then a human decides. What is defensible is the record — who decided, when, on what basis, and what the assessment said at the time. It is not a reproducible legal determination and should not be presented as one.
Every request, assessment, decision, inventory change and export, with the acting user and a timestamp, in an append-only log. Decisions are written through a controlled database function rather than direct table access, so a decision cannot bypass the trail or be deleted out of it.
No, it enforces one. The policy says what is allowed in principle; the Tracker is where a specific tool gets requested, assessed and approved or denied in practice, and where the evidence of that lives. Most teams run both — you can generate a policy here if you do not have one yet.
A link to a short form. They name the tool, what they want to use it for and what data it would touch. The assessment runs automatically, a PDF is generated and filed, and your admin gets an email. The requester is emailed the outcome once you decide.
Not from the Tracker alone — it records what goes through the process. AI Use Guard is the browser-side companion that shows what is actually being used and blocks what is not approved. They are sold separately and work well together: the Tracker is the decision record, the Guard is the enforcement.
Built and working end to end — request, assessment, PDF, decision, audit trail, inventory, monthly report — and being rolled out to a first group of organisations now. We are not going to tell you it has hundreds of customers; it does not. If being early is a problem for you, that is a fair reason to wait.

Have the answer before you're asked for it.

Two business days to a reply, and a real conversation about what you're audited against.

Request early access