PLATFORM OVERVIEW

One system for the work behind the decision.

Stop rebuilding the same story in every tool. ComplAI keeps the facts, evidence, and decisions in one place your team can inspect.

Govern · discover · correlate · act · deploy
Request a platform working session

01 · GOVERN

See why a control looks the way it does.

Each requirement stays tied to its implementation, evidence, findings, owners, and review history. A status is only useful if you can check the basis.

  1. 01

    Keep each requirement’s meaning distinct.

  2. 02

    Tie implementation notes to current evidence and an owner.

  3. 03

    Keep SSP, POA&M, and authorization context in the same record.

  4. 04

    Show what changed since the last review. A person still decides.

02 · DISCOVER

Find where regulated data lives. That's DSPM.

See where CUI and other regulated data sit, how they relate to the boundary, and which access questions need a look. DSPM here means discovery, classification, lineage, and access context. Exact data paths are confirmed for each deployment.

DSPM

Find the repositories that matter

See which systems and services sit with the data they depend on.

CLASSIFICATION

Keep the handling rules attached

Connect classification and lineage to the requirements they can inform.

ACCESS

See who and what can reach it

Look at identities, privileges, vendors, and access paths next to the data they affect.

03 · CORRELATE

Know what is actually in scope.

A control record is only as good as the inventory under it. ComplAI brings devices, workloads, services, identities, vendors, and repositories together so you can see what is in scope and why.

  1. 01

    Pull context from cloud, identity, security, operations, and data systems.

  2. 02

    See how duplicate or changing records affect the boundary.

  3. 03

    Connect assets and identities to controls, evidence, and owners.

  4. 04

    Confirm connectors, adapters, APIs, and file paths during scoping.

04 · ACT

Keep ITSM work attached to the requirement.

Findings, tickets, owners, and approvals stay tied to the requirement that caused them. ComplAI routes the work. People decide what to accept, change, or escalate. ServiceNow can contribute when that path is confirmed. ComplAI does not replace your ITSM system.

ITSM

Send the ticket to an owner

Keep the requirement, scope, due date, and role with the ticket.

REVIEW

Bring the evidence back

Attach the finished work to the finding that started it.

PRESERVE

Keep the history

Record what changed, who reviewed it, and which artifacts need an update.

05 · DEPLOY

Choose the host and the model you approve.

Self-hosted, air-gapped, customer-hosted, commercial cloud, AWS GovCloud, or Azure Government. You bring the model your boundary allows. ComplAI does not require a public model. We confirm hosting, model use, and who owns what before regulated data is connected.

  1. 01

    Start with the real boundary, not a default hosting choice.

  2. 02

    Bring the model you approve. We confirm it during scoping.

  3. 03

    Write down sources, storage, model use, and outbound flows.

  4. 04

    Keep product, service, customer, assessor, and authority roles separate.

NEXT DECISION

See how this maps to the program you run.

Bring the current boundary, source systems, and who decides. We’ll go from there.

Request a platform working session