Compliance AI

Nothing moves until it has passed your rules

You write the guardrails. Every request and every answer is screened against them before it reaches a model, a colleague or a client — and what happens next is recorded in a form a regulator can read.

0out of 100
Very good▲ 4 since last month
Coverage60%91How much of the org a policy reaches
Effectiveness40%81Whether what it catches is real
Twelve months
EveryTurn screened
0Point compliance score
0Severity levels
0+Surfaces covered
YoursRules and categories

Screening

Before it moves, not after it is logged

Every turn is read against the rules for that person, that department and that workflow — on the way in and on the way out. A match either stops the turn or changes it in place.

Blocking says no and explains why. Sanitising lets the work continue with the parts that could not travel removed, which is the difference between a control people route around and one they keep. Either way, an event is written with who asked, where they asked it and which rule they hit.

On the way inOn the way outPer departmentPer workflow

Guardrails

Rules in your words, not a vendor's taxonomy

A guardrail is a title, a description, a category and a severity — and under it, the rules that decide whether a match is blocked or sanitised. Five categories ship with it; the ones that matter to your firm you write yourself.

CategoriesData privacyIdentifiers, personal data, anything that names a personCriticalRegulatory complianceThe rules your regulator holds you toHighFinancial dataFigures that are not yours to move yetHighSecurityCredentials, keys, and the systems behind themCriticalContent safetyLanguage that should never leave the buildingMediumAdd your ownWhatever your regulator, your clients or your board requireCustom
Two actions

Block, or sanitise in place

Block stops the turn and says why. Sanitise removes only what could not travel and lets the rest through — so the control does not become the reason people work somewhere else.

Four severities

Critical, high, medium, low

Severity decides how loudly a match is reported and how quickly it has to be reviewed — not whether it is caught. Everything is caught.

Versioned

Published, not deployed

A policy version is drafted, reviewed and put in force from the admin panel. Nothing ships, nothing restarts, and the version that screened any given event is recorded against it.

Policies

One set of rules, aimed where it belongs

A policy is a named group of guardrails, switched on for the departments and workflows it applies to — with named exceptions where somebody genuinely needs one.

Credit and Risk can be held to different standards without either of them writing their own rules, and a workflow that reaches the open web can carry more than one that only reads your warehouse.

Baseline policyIn force · v4
GuardrailsData privacyFinancial dataSecurity+2
DepartmentsCreditRiskResearchFinanceLegal
WorkflowsGlobal chatDocument AIGrid AIDeep research+8
Exceptions2 named people

Coverage

The question is who is not covered

Coverage is measured across three dimensions — people, departments and workflows — and snapshotted every day, so a gap that opens on Tuesday is not found in an audit next year.

What it reports is not the percentage but the names: the department created last month with no policy on it, the workflow that reaches the open web unguarded, the contractors excluded from the team they work in. Each with the reason it is exposed.

Users118/1260%
Departments7/80%
Workflows17/190%
Priority gaps
HighTreasury · DepartmentNo policy assigned since it was created
HighDeep research · WorkflowReaches the open web with no rule attached
Medium4 contractors · UsersExcluded from the department they work in

Compliance score

One number, and the two things behind it

A rating out of a hundred, computed daily from how much of the organisation a policy reaches and how well what it catches holds up under review.

It is deliberately decomposable. Coverage carries most of the weight because an unguarded department is the larger risk; effectiveness is what the review queue teaches it. And the history is kept, because the question in the room is never what the score is — it is whether it has been improving.

0out of 100
Very good▲ 4 since last month
Coverage60%91How much of the org a policy reaches
Effectiveness40%81Whether what it catches is real
Twelve months

Review

Every catch is somebody's to confirm

Screening is not infallible, and the product does not pretend otherwise. Every event lands in a queue where a person confirms it or marks it a false positive.

That verdict is the loop: it is attributed, timestamped, and fed back into the effectiveness half of the score. A control nobody reviews drifts; one that is reviewed gets sharper.

PendingConfirmedFalse positiveReviewed by · when

Monitoring & audit

What the agents did, and what the admins changed

Two records, kept separately because they answer different questions. One follows the work; the other follows the people who set the rules for it.

Agent monitoring

Flags raised by the work itself

Every agent run is watched, and anything it raises is filed by agent and by severity — so a specialist that starts flagging critical matches is visible before it becomes an incident.

AgentCriticalHighMediumDeep research364Document AI157Global chat139Grid AI025Code execution013
By agentBy severityFlag detail
Audit logPolicy v4 publishedR. Alvarez · Owner09:12Guardrail added — “No client names externally”R. Alvarez · Owner09:08Treasury assigned to Baseline policyM. Okafor · AdminYesterdayEvent marked false positiveJ. Doe · CreditYesterdayTwo-factor reset for a memberR. Alvarez · OwnerMon

Reporting

The report writes itself, from the record

Pick a period and a compliance report is generated from what actually happened: the events, the reviews, the coverage, the score and how it moved.

It is a draft until you say otherwise, it names the model that produced it, and it is regenerated rather than edited — so the report and the record can never quietly disagree.

Q3 compliance reviewGenerated
Period90 daysEvents1,284Reviewed100%Score87 ▲4
Written by qa · re-generated any time from the same record

Reach

Everywhere the work happens

A control that covers the chat but not the document agent is not a control. Every surface a person or an agent can work on is screened by the same policy.

Global chatWidget chatPortfolio chatDocument AITable AIGrid AIChart AIStatistical AIPortfolio AIDeep researchCode executionApps
Identity

Two-factor, devices, sessions

Who is asking is part of the check — with 2FA, device and session control behind it.

Data

Your own accounts, your own tenancy

Screening runs against sources reached through your logins, in your deployment.

Evidence

Attributable, timestamped, kept

Every event, review and admin action carries who, what, where and when.

Turn weeks of expert work into minutes

See how Scalata fits your team, your data, and your controls.

Contact Sales