01   HOME

Every AI system in your enterprise.
Mapped in two weeks.

Most enterprises can’t answer “what’s our AI exposure?” with anything more than a guess.

In two weeks — read-only, no agents, nothing in your data path — we’ll give you the list. Every AI tool, model and API touching your enterprise. With owners. And a confidence level we’ll defend.

The report is yours whether we ever speak again.

2 weeksto first report
Read-onlyno agents, no data path
Every channelSaaS · API · browser · expense
Yourswhether you buy or not

02   HOME · THE PROBLEM

Every enterprise has AI
it can’t account for.

AI adoption is outpacing enterprise security.

Employees use AI daily. Developers wire models into production. Most enterprises have no control layer — and no list.

01

Which AI tools are employees using without approval?

02

What sensitive data is leaving the enterprise through AI?

03

Which users and APIs are connected to third-party models?

04

What is being logged, retained, or shared by AI providers?

05

Can we enable AI without signing our own dismissal?

03   HOME · POSITIONING

WHERE EVERYONE ELSE STARTS ONE STEP TOO LATE

Make AI risk visible
before trying to control it.

Blocking AI doesn’t stop its use. It pushes that use onto personal devices you can’t monitor at all.

Every control you’ve bought assumed you already knew where the AI was. A policy is a PDF. A block moves the traffic to a phone. A survey asks people to report their own shadow IT. None of them start with discovery. We do.

04   PLATFORM

We map every system first.
Before an attacker does.

ctrlAIx sits between your people, data and applications — and every AI system they touch. We map the exposure first, then quantify exactly how much risk it creates.

DISCOVER

AI Exposure Scanner

Find every AI system, model, agent and API touching the enterprise — before risk compounds.

  • Shadow AI & agent discovery
  • Unauthenticated inference mapping
  • Sensitive data & egress flows
  • Executive exposure reports

* Full breadth reflects the roadmap — some modules are in active development. Ask about current coverage.

ASSESS

Threat & Posture

Score how exposed each system is, and show the path an attacker takes — mapped to the frameworks.

  • AI-SPM posture scoring
  • Adversarial threat mapping (ATLAS)
  • Exposed credentials, backdoors & CVEs
  • DORA / NIS2 / EU AI Act evidence

05   SOLUTIONS

Enterprise AI security
use cases.

01

Shadow AI Discovery

Find unauthorized AI tools before they become institutional risk.

02

Prompt-Layer Data Protection

Stop sensitive data from reaching unauthorized AI systems — at the paste, not the attachment.

03

AI Access Governance

Control which users and tools connect to AI capabilities.

04

AI Risk Reporting

Give boards and risk committees a clear exposure view they can defend.

06   SECURITY

Read-only by default.

No agents. Nothing in your data path. Nothing you’d have to explain to your architecture board. Enforcement exists — and it stays off until you ask.

01

The assessment doesn’t touch prompts

Metadata only — egress logs, your IdP, cloud API keys, expense data. We find that AI exists, not what was said.

02

Runs in your tenant

If you ever enable the gateway, it deploys in your environment. We redact before transit and retain nothing.

03

Verifiable, not asserted

Architecture, data-flow and named subprocessors are published — so your team can check, not take our word.

04

Visibility before enforcement

Governance has to start with an accurate inventory, not a policy document. We build the inventory first.

07   REPORT

A number you can take
to the board. Unedited.

A redacted sample, open to anyone — no form, no email wall.

Severity-led findings, a posture score, the frameworks you’re failing, the attacker’s path. And the page no one else publishes: what we could not see.

AI SECURITY ASSESSMENT — SAMPLEOVERALL RISK CRITICAL
74AI systems discovered
12Known to security beforehand
31Unauthenticated inference hosts
46 / 100AI-SPM posture score
4 / 7Frameworks failing
WHAT WE COULD NOT SEE

Personal devices on personal networks. On-prem systems with no egress. Identity attribution where directory integration is unconfigured. We map ~80% and name the rest.

Illustrative sample. Structure is real; every figure is invented and represents no client.

08   REPORT · SAMPLE

What the report
actually looks like.

Severity-led. Numbered findings with an owner and an effort estimate. A posture score that trends between runs. The frameworks you’re failing, and the path an attacker takes. Built to be read by a board and survive an auditor.

OVERALL RISKCRITICAL
POSTURE (POOR)46/100
AI SYSTEMS FOUND74
FRAMEWORKS FAILING4 / 7
01

Hardcoded credentials in the security tooling repo

CRIT
02

Public-facing model API, no auth

CRIT
03

Persistence backdoor in a build image

CRIT
04

Agentic pipeline → SQL injection sink

CRIT
05

Unauthenticated inference sprawl

HIGH
06

Shadow-AI SaaS egress, ungoverned

HIGH
FRAMEWORKS

DORA FAIL · NIS2 review · EU AI Act FAIL

ATTACK CHAIN

recon sweep → unauth inference API → pivot to vector DB → exfiltrate business logic

Illustrative sample. Structure is real; every figure and finding is invented and represents no client.

09   WHO IT'S FOR

Built for the people
responsible for AI risk.

CISOs

A number you can defend — and the freedom to enable AI on the record, with evidence.

CIOs

Enterprise AI adoption without uncontrolled technology sprawl. Fewer cleanup meetings.

Risk Leaders

Inventory, reporting and auditability across every business function — the foundational control most programs are still missing.

Boards & Investors

A clear view of one of the fastest-growing enterprise risks — competence, not alarm.

10   COMPANY

Built by enterprise
AI practitioners.

For leaders where AI adoption is a governance, security, compliance and trust problem — not just a technical one. The mission: help enterprises adopt AI responsibly by securing the space between people, data and AI systems.

OPERATING PRINCIPLES

01

Make AI risk visible before trying to control it.

02

Enable innovation without giving up governance.

03

Design for security teams and enterprise operators.

04

Keep marketing separate from product workflows.

11   EARLY ACCESS

Ready to see your
AI exposure?

Two weeks. Read-only. Then you’ll know. Working with selected organizations to assess, govern and control enterprise AI risk.

Every enterprise has AI it can’t account for.