Find the repositories that matter
See which systems and services sit with the data they depend on.
PLATFORM OVERVIEW
Stop rebuilding the same story in every tool. ComplAI keeps the facts, evidence, and decisions in one place your team can inspect.
01 · GOVERN
Each requirement stays tied to its implementation, evidence, findings, owners, and review history. A status is only useful if you can check the basis.
Keep each requirement’s meaning distinct.
Tie implementation notes to current evidence and an owner.
Keep SSP, POA&M, and authorization context in the same record.
Show what changed since the last review. A person still decides.
02 · DISCOVER
See where CUI and other regulated data sit, how they relate to the boundary, and which access questions need a look. DSPM here means discovery, classification, lineage, and access context. Exact data paths are confirmed for each deployment.
See which systems and services sit with the data they depend on.
Connect classification and lineage to the requirements they can inform.
Look at identities, privileges, vendors, and access paths next to the data they affect.
03 · CORRELATE
A control record is only as good as the inventory under it. ComplAI brings devices, workloads, services, identities, vendors, and repositories together so you can see what is in scope and why.
Pull context from cloud, identity, security, operations, and data systems.
See how duplicate or changing records affect the boundary.
Connect assets and identities to controls, evidence, and owners.
Confirm connectors, adapters, APIs, and file paths during scoping.
04 · ACT
Findings, tickets, owners, and approvals stay tied to the requirement that caused them. ComplAI routes the work. People decide what to accept, change, or escalate. ServiceNow can contribute when that path is confirmed. ComplAI does not replace your ITSM system.
Keep the requirement, scope, due date, and role with the ticket.
Attach the finished work to the finding that started it.
Record what changed, who reviewed it, and which artifacts need an update.
05 · DEPLOY
Self-hosted, air-gapped, customer-hosted, commercial cloud, AWS GovCloud, or Azure Government. You bring the model your boundary allows. ComplAI does not require a public model. We confirm hosting, model use, and who owns what before regulated data is connected.
Start with the real boundary, not a default hosting choice.
Bring the model you approve. We confirm it during scoping.
Write down sources, storage, model use, and outbound flows.
Keep product, service, customer, assessor, and authority roles separate.
NEXT DECISION
Bring the current boundary, source systems, and who decides. We’ll go from there.