Compliance AI
Nothing moves until it has passed your rules
You write the guardrails. Every request and every answer is screened against them before it reaches a model, a colleague or a client — and what happens next is recorded in a form a regulator can read.
Screening
Before it moves, not after it is logged
Every turn is read against the rules for that person, that department and that workflow — on the way in and on the way out. A match either stops the turn or changes it in place.
Blocking says no and explains why. Sanitising lets the work continue with the parts that could not travel removed, which is the difference between a control people route around and one they keep. Either way, an event is written with who asked, where they asked it and which rule they hit.
Guardrails
Rules in your words, not a vendor's taxonomy
A guardrail is a title, a description, a category and a severity — and under it, the rules that decide whether a match is blocked or sanitised. Five categories ship with it; the ones that matter to your firm you write yourself.
Block, or sanitise in place
Block stops the turn and says why. Sanitise removes only what could not travel and lets the rest through — so the control does not become the reason people work somewhere else.
Critical, high, medium, low
Severity decides how loudly a match is reported and how quickly it has to be reviewed — not whether it is caught. Everything is caught.
Published, not deployed
A policy version is drafted, reviewed and put in force from the admin panel. Nothing ships, nothing restarts, and the version that screened any given event is recorded against it.
Policies
One set of rules, aimed where it belongs
A policy is a named group of guardrails, switched on for the departments and workflows it applies to — with named exceptions where somebody genuinely needs one.
Credit and Risk can be held to different standards without either of them writing their own rules, and a workflow that reaches the open web can carry more than one that only reads your warehouse.
Coverage
The question is who is not covered
Coverage is measured across three dimensions — people, departments and workflows — and snapshotted every day, so a gap that opens on Tuesday is not found in an audit next year.
What it reports is not the percentage but the names: the department created last month with no policy on it, the workflow that reaches the open web unguarded, the contractors excluded from the team they work in. Each with the reason it is exposed.
Compliance score
One number, and the two things behind it
A rating out of a hundred, computed daily from how much of the organisation a policy reaches and how well what it catches holds up under review.
It is deliberately decomposable. Coverage carries most of the weight because an unguarded department is the larger risk; effectiveness is what the review queue teaches it. And the history is kept, because the question in the room is never what the score is — it is whether it has been improving.
Review
Every catch is somebody's to confirm
Screening is not infallible, and the product does not pretend otherwise. Every event lands in a queue where a person confirms it or marks it a false positive.
That verdict is the loop: it is attributed, timestamped, and fed back into the effectiveness half of the score. A control nobody reviews drifts; one that is reviewed gets sharper.
Monitoring & audit
What the agents did, and what the admins changed
Two records, kept separately because they answer different questions. One follows the work; the other follows the people who set the rules for it.
Flags raised by the work itself
Every agent run is watched, and anything it raises is filed by agent and by severity — so a specialist that starts flagging critical matches is visible before it becomes an incident.
Reporting
The report writes itself, from the record
Pick a period and a compliance report is generated from what actually happened: the events, the reviews, the coverage, the score and how it moved.
It is a draft until you say otherwise, it names the model that produced it, and it is regenerated rather than edited — so the report and the record can never quietly disagree.
Reach
Everywhere the work happens
A control that covers the chat but not the document agent is not a control. Every surface a person or an agent can work on is screened by the same policy.
Two-factor, devices, sessions
Who is asking is part of the check — with 2FA, device and session control behind it.
Your own accounts, your own tenancy
Screening runs against sources reached through your logins, in your deployment.
Attributable, timestamped, kept
Every event, review and admin action carries who, what, where and when.
Turn weeks of expert work into minutes
See how Scalata fits your team, your data, and your controls.