NIST AI RMF Aligned

AI Governance.
Risk Clarity.

Compass discovers AI tools running in your environment, maps governance gaps to the NIST AI Risk Management Framework, and produces clear dashboards for security, compliance, and leadership teams.

Client-side only No data uploaded NIST AI RMF aligned OWASP LLM Top 10
4
Step Workflow
4
NIST Functions
3
Report Audiences
COMPASS - RISK DASHBOARD
3 HIGH-RISK AI TOOLS DETECTED
14
AI Tools Found
8
Gaps Found
2
Actions Needed
Detected AI Tools
ChatGPT (openai.com)
High Risk
GitHub Copilot
High Risk
Grammarly AI
Medium
Notion AI
Low

AI is already in your organization.
You just don't know where.

Most organizations adopt AI tools before policies, monitoring, or ownership are in place - creating hidden risk that grows quietly in the background.

Shadow AI Usage

Employees use AI tools on company networks without IT or security team awareness - exposing sensitive data with no controls or oversight in place.

No Governance Framework

Without structure, organizations face unclear accountability, missing policies, and no mechanism to assess or manage AI-related risk before it escalates.

Legal & Compliance Risk

Customer data, IP, and confidential information fed into unvetted AI tools creates real legal exposure and audit liabilities that compound over time.

From logs to actionable reports
in four clear steps

Evidence-first — every finding traces back to your log data, not employee memory.

01
Upload Logs
Evidence First

Provide DNS, firewall, or proxy log exports. Files are parsed entirely in your browser — nothing is uploaded to any server.

02
Detect AI Tools
Log Analysis

The log parser matches hostnames against a registry of known AI service domains and assigns each tool a risk tier and category.

03
Assess Controls
NIST Mapping

A structured questionnaire maps your policies against the NIST AI RMF — producing a maturity score and gap analysis across all four functions.

04
Generate Reports
Multi-Audience

Three tailored views — IT Security, Executive, and Auditor — each presenting the same findings at the right level of detail for that audience.

Built for how
real teams work

Compass is designed around the way security, compliance, and audit teams actually operate - with evidence, clarity, and actionable output at every step.

Evidence First
Start with DNS, firewall, and proxy logs - not employee surveys. Every inventory item links back to its source log entry.
Plain Language Throughout
Risk explained in business terms first. Technical detail is available when needed - never forced on every reader.
NIST AI RMF Aligned
Assessment maps to Govern, Map, Measure, and Manage. Each gap shows the NIST area, risk reason, and action item.
Action Oriented
Every high-risk finding leads to a clear next step. Block risky tools, add monitoring - and know exactly where to start.
Executive Report
Leadership

Business impact, legal exposure, financial risk, and top decisions. Written for leadership - no heavy technical language.

Security Report
Security Team

Missing controls, risk severity, source evidence, NIST mapping, and action priority for immediate operational response.

Auditor Report
Compliance

Assessment evidence, framework mapping, dates, scope, and structured findings - ready for formal audit documentation.

When teams reach for Compass

Three situations where a 15-minute assessment turns a vague concern into a concrete action plan.

Pre-Audit

"Audit is in six weeks. What AI is actually running here?"

A compliance officer uploads 90 days of proxy logs before a third-party audit. Compass detects 9 unsanctioned AI tools, maps each to NIST GOVERN and MAP controls, and generates a structured findings report the auditors can review directly.

Compliance Officer ~20 min
Output
AI inventory · NIST gap report · Auditor PDF
Post-Incident

"We had a data incident. Was AI in the chain?"

After a suspected data leak, the security lead uploads firewall logs from the incident window. Compass narrows the scope to 3 AI tools active during the event, surfaces OWASP LLM06 (sensitive info disclosure) findings, and timestamps each connection for the IR report.

Security Lead ~15 min
Output
Scoped timeline · OWASP findings · IR-ready evidence
Quarterly Governance

"What AI tools have employees adopted since last quarter?"

A security lead runs Compass every quarter with a fresh 30-day log pull. The tool highlights 2 newly adopted AI tools that weren't in last quarter's inventory, assigns risk levels, and flags which NIST controls need updating before the next board review.

Security Lead ~10 min
Output
Delta inventory · Board-ready summary · Updated registry

One platform. Every stakeholder.

Security Lead
Primary MVP User

Find AI activity, review risk, and decide what to fix first - backed by full log evidence.

Compliance Officer
Policy & Oversight

Map AI usage against policy requirements and identify gaps before they become audit findings.

Auditor
Structured Evidence

Structured findings with evidence, dates, scope, and framework mapping for formal audit documentation.

Business Leader
Executive View

Understand business impact and legal exposure without wading through technical security reports.

Common questions

What log formats does Compass accept?
Compass parses DNS query logs, HTTP proxy logs, and firewall exports in .log, .txt, .csv, and .json formats. The parser extracts domains, timestamps, categories, and risk tiers automatically — no custom mapping required. See the Log Parser section on the About page for the full field reference.
Does my data ever leave my browser?
No. Every log file you upload is processed entirely inside your browser — nothing is transmitted to a server or stored in the cloud. Once you close the tab, the data is gone. Compass is designed for environments where log data is sensitive and must stay on-premise.
Do I need an IT team to use it?
No installation, infrastructure, or IT support is required. Compass runs in any modern browser. Upload a log file, answer a few guided questions about your org context, and you have a full risk report in minutes. It is designed for security leads, compliance officers, and auditors — not just engineers.
Which governance frameworks does Compass map to?
Risk findings are mapped to the NIST AI Risk Management Framework (GOVERN, MAP, MEASURE, MANAGE), NIST SP 800-218A secure software development practices, and the OWASP LLM Top 10 2025. See the Compliance reference page for the full mapping and how Compass addresses each control.
Can I try it without creating an account?
Yes. Click Try Live Demo on this page to run a complete assessment using built-in sample log data — no account, no sign-up, no data upload. You will see real detection results, risk scoring, and a sample report in the same interface used for live assessments.
Compass

Ready to see what AI is
running in your org?

Upload your logs. Compass detects AI tools, maps governance gaps, and generates reports your security team and leadership can act on - all in minutes.

NIST AI RMF Evidence First Action Oriented