Most organizations adopt AI tools before policies, monitoring, or ownership are in place - creating hidden risk that grows quietly in the background.
Employees use AI tools on company networks without IT or security team awareness - exposing sensitive data with no controls or oversight in place.
Without structure, organizations face unclear accountability, missing policies, and no mechanism to assess or manage AI-related risk before it escalates.
Customer data, IP, and confidential information fed into unvetted AI tools creates real legal exposure and audit liabilities that compound over time.
Evidence-first — every finding traces back to your log data, not employee memory.
Provide DNS, firewall, or proxy log exports. Files are parsed entirely in your browser — nothing is uploaded to any server.
The log parser matches hostnames against a registry of known AI service domains and assigns each tool a risk tier and category.
A structured questionnaire maps your policies against the NIST AI RMF — producing a maturity score and gap analysis across all four functions.
Three tailored views — IT Security, Executive, and Auditor — each presenting the same findings at the right level of detail for that audience.
Compass is designed around the way security, compliance, and audit teams actually operate - with evidence, clarity, and actionable output at every step.
Business impact, legal exposure, financial risk, and top decisions. Written for leadership - no heavy technical language.
Missing controls, risk severity, source evidence, NIST mapping, and action priority for immediate operational response.
Assessment evidence, framework mapping, dates, scope, and structured findings - ready for formal audit documentation.
Three situations where a 15-minute assessment turns a vague concern into a concrete action plan.
Find AI activity, review risk, and decide what to fix first - backed by full log evidence.
Map AI usage against policy requirements and identify gaps before they become audit findings.
Structured findings with evidence, dates, scope, and framework mapping for formal audit documentation.
Understand business impact and legal exposure without wading through technical security reports.
.log, .txt, .csv, and .json formats. The parser extracts domains, timestamps, categories, and risk tiers automatically — no custom mapping required. See the Log Parser section on the About page for the full field reference.