HomeProductsAIServicesIntegrationsCompany
The AI, without the hand-waving

5 agents. One job each.
A person still decides.

Most companies selling AI for compliance put a language model in front of everything. That is expensive, and for this product it would also make things worse. We already store the answers to most questions: how many controls you have, which policies cover which rules, what a control scored last month. All of that is a lookup. It is instant, it is free, and it gives the same answer every time you ask, which matters more than it sounds, because an auditor has to be able to redo the arithmetic themselves.

There is one thing a lookup cannot do. It cannot read a document somebody uploaded and decide whether it actually proves anything. That takes judgement, and it is the most repeated task in a compliance team's working life. So the rule is simple: the database calculates, and the AI judges.

5agents, one job each
14mechanical checks on every file · no AI
30+file types read, ZIP bundles opened
40automated tests before release · 28 of them stop it
How one actually works

Five steps.
One of them costs anything.

Nothing mysterious. Each step is either a database lookup, a mechanical file check, or one narrow question to a model in a fixed answer shape. The agent does not browse, does not search around, and does not call itself over and over. And if an answer cannot be traced back to a real quoted source, it is thrown away before anyone sees it.

01

Something happens

A file is uploaded, a policy is requested, a questionnaire arrives, or a monthly reminder fires. The agent waits to be triggered. It does not hunt for work.

free
02

The platform collects the facts

A lookup pulls the requirement, the control, its current score, the policy in force and the file with its check results. Exact, instant, and free.

free
03

Personal details are stripped

Names, emails and ID numbers are removed before anything leaves our systems. We attach your identity ourselves, so an agent cannot ask to see someone else’s data.

free
04

One question, in a fixed shape

We hand over the facts and ask one narrow question. The answer must come back as a decision, a confidence score, a quote and a reason. It cannot ramble.

one AI question
05

We check it, then a person decides

We confirm the quote really appears in the file and every requirement it named is real. If it cannot be traced to a source, it is thrown away before anyone sees it.

free
Before any agent runs

The cheapest thing here
catches the most.

It works out what the file really is, when it was made, whether it has been edited since, whether we have seen it before, and whether it covers the whole audit period. No AI is involved, so it gives the same answer every time.

FOR-GATE

File Checkerno AI

Inspects every uploaded file before any agent sees it. Fourteen mechanical checks across 30+ file types.

The most common reason an auditor rejects evidence has nothing to do with forgery. A screenshot proves a setting was right on one day. The audit needs six months. Comparing two dates is free and certain.

It grades every file
APulled straight from the system, signed, covers the period.
BA system export with dates, covering the period.
CA report an auditor could re-check.
DA screenshot. Proves one moment, not a period.
ENo date, unreadable, or a duplicate of something already sent.
5 agents, 5 modules

Each one lives
somewhere specific.

Every agent sits inside a module of Purplecop One GRC that you already use. None of them wanders around. An agent with one job can be tested properly, and an agent that can be tested properly is one we are willing to sell.

AGT-01

Evidence Examiner

lives in Evidence

Reads a document against the requirement and says whether it really proves the control — then quotes the exact sentence that made it decide.

About 12,000 documents a year get opened and asked the same question.

Never marks evidence approved. Never moves the workflow forward.

AGT-02

Policy Drafter

lives in Policies

Finds the right template out of the 1,605 we already own and tailors it to that customer’s departments, systems and review cycle.

It never writes a policy from scratch. A two-day job becomes twenty minutes.

Never publishes. Never approves. Never starts the sign-off.

AGT-03

Risk Challenger

lives in Risk Register

Once a month, compares every risk rating against how its controls are actually performing, and raises a challenge where the two disagree.

A register that has quietly gone out of date gets caught between audits instead of during one.

Never changes a rating. It raises a task for the risk owner.

AGT-04

Audit Reviewer

lives in Audit Management

Acts as a sceptical outside auditor on one requirement and gives a second opinion before the real auditor arrives.

Customers usually find out what an auditor thinks when the auditor tells them. By then it is on the record.

Never writes to the audit record. Never overrides your own conclusion.

AGT-05

Questionnaire Responder

lives in Trust Center

Drafts an answer to every question in a security questionnaire from your live compliance data — and refuses to answer where the proof is missing.

A 300-question questionnaire takes minutes instead of the week a security engineer normally loses to it.

Never sends an answer to the buyer. Never publishes to your Trust Center page.

The lines it will not cross

Six things we guarantee.

Every file is checked before an AI sees itFourteen mechanical checks, 30+ file types, no AI, the same answer every time.
Every answer quotes a real sentenceFrom your own file. If it cannot find support, it says so instead of guessing, and the answer never reaches you.
No AI can change a recordAll five suggest. A person approves. Nothing is marked complete, re-rated, signed off or sent by an agent.
Zero AI in your compliance scoreIt stays a plain calculation an auditor can redo on paper. Two of its six inputs simply get better information.
Switch it off and nothing breaksEvery screen works exactly as it does today with the AI disabled. An agent that has not passed its tests ships switched off.
One customer can never reach anotherTested with two real accounts on every single build. Every one of those tests stops a release.
What we are deliberately not building

The refusals are
most of the design.

Every item below is something a competitor demonstrates well and a customer stops using within a month. Saying no to them is most of the reason this costs what it does, and all of the reason it survives an audit.

A general compliance chatbotEvery question worth asking already has a screen showing the answer. Asking an AI is slower, costs more and is less accurate than the report we already built.
AI-generated scoresOur scores can be checked by hand today. Swapping them for a number you cannot reproduce is a downgrade dressed up as an upgrade, and auditors will say so.
Any AI that changes a record by itselfAll five suggest, a person approves. This is the most important line in the design, and we do not intend to cross it later.
AI that detects AI-made evidenceThe best detectors are right about 84% of the time and wrongly accuse a genuine image once in every 18. We prove where a file came from instead of guessing how it was made.
An AI that collects the evidence itselfCollecting a document is scheduled, ordinary software. Something that always works beats something that usually works.
Training our own modelIt would need retraining every time a framework updates, would still need all forty tests, and would not answer any better.
How we know it works

40 tests run automatically,
28 of them stop a release.

They run against a fixed set of example files where the right answer is already known: made-up claims, one customer reaching another's data, instructions hidden inside an uploaded document in white-on-white text, the same file answered differently twice, a runaway bill, deliberately broken files, and the model provider going down mid-request. Nothing counts as passing without saved proof that it passed. If a test cannot run somewhere, it is recorded as not verified, and not verified never counts as a pass.

What we will not claim

We do not claim zero AI errors. Nobody honestly can.

What we do claim

Every file is checked before an AI sees it. Every answer can be traced to a real quoted source. No customer can reach another customer’s data. No AI can change a record. And when the evidence is not there, the AI refuses to answer rather than guessing.

Watch one read your own evidence.

The fastest way to judge any of this is to hand it a document you already argued about with an auditor, and see whether it reaches the same conclusion and quotes the same sentence.