Secure the AI Your Organisation Is Already Running
Pillar 1 of the overlay. Find the AI your organisation actually runs (shadow tools, agents, third‑party AI and OAuth grants) through the identity provider you already have. Then put a gate on what ships, and read the threat surface we cover next to the part we do not.
- UAE PDPL
- NESA/SIA
- ADHICS
- DIFC/ADGM
- SAMA
- EU AI Act
- NIST AI RMF
- ISO 42001
- Singapore PDPA (roadmap)
- MAS (roadmap)
Spearhead 01 · Discover
Your AI Attack Surface Is Wider Than Your Inventory
Discovery is the first step in the chain and the one that pays on day one. It runs against Entra ID or Okta on read-only scopes: sign-in activity and OAuth consent grants, resolved into an inventory with owners attached. No agent on an endpoint, and nothing for the platform team to schedule.
Attack Techniques Against AI Are Documented and In Use
Prompt injection, leakage, supply-chain and agentic abuse are catalogued in OWASP LLM and MITRE ATLAS. The techniques are public; whether your controls answer them is the open question.
Shadow AI Reaches Your Data Before Anyone Reviews It
Tools adopted outside IT hold real credentials and real data from the day they are installed. Nothing in the security stack is watching a system it was never told about.
Prompts Carry Sensitive Data Out Through Tools You Do Not Control
Proprietary code, client records and strategy documents leave in the body of a prompt, past controls that inspect files and network paths rather than conversations.
Attack Techniques Against AI Are Documented and In Use
Prompt injection, leakage, supply-chain and agentic abuse are catalogued in OWASP LLM and MITRE ATLAS. The techniques are public; whether your controls answer them is the open question.
Vendor AI Arrives With Access You Never Granted Directly
SaaS platforms enable AI features by default and inherit the scopes their app already holds. Each vendor update can widen what a model can read without a review being raised.
One Compromised Model Reaches Data, Code and Customers
A single unreviewed system sits close to production data, ships into code paths, and speaks to customers, so one weakness in it is not contained to one place.
How it works
Find It, Read It, Gate It
Three stations in the security pillar: find the AI that is running, read what its behaviour and exposure amount to, and gate what ships. Beside each station, what the security team gets from it.
- 01
Find the AI That Is Running
AI Discovery · Shadow AI Detection · Model Registry
Inventory approved, unapproved, and shadow AI across your entire stack: cloud platforms, code repos, API gateways, and internal environments.
What changesSurface the AI Nobody Registered
Approved, unapproved and shadow AI resolved into one inventory with owners attached, before an incident or an audit finds it for you.
- 02
Read Behaviour, Exposure and Explainability
Explainability Lab · Compliance Mapping · Risk Scoring
Understand model behaviour, policy fit, bias exposure, and governance gaps, with evidence you can show a board or regulator.
What changesCollect the Evidence as You Go
Findings, decisions and overrides are recorded against the controls they touch as the work happens, so evidence is assembled rather than reconstructed.
- 03
Gate What Reaches Production
Policy Engine · Deployment Gates · Enforcement Center
Enforce at the decision point: gate risky AI before it ships, and route enforcement into the controls you already run.
What changesStop a Risky Release at the Gate
Checks run at the release point, and a model that fails them does not pass. An override is a named human decision and it is logged.
Work Through the Stack You Already Run
Cloud, on-prem and MLOps tools are read and acted on through the controls you already operate, with no rip-and-replace.
Threat surface
What We Cover, and What We Don’t
Every AI-security vendor publishes a threat list. Most do not tell you which half is actually running. Ours is split, on the page, before you buy, because the alternative is finding out during an incident.
Shipped today
Shadow-AI discovery
On demandA scan you run against Entra ID or Okta: sign-in activity and OAuth consent grants resolved into an inventory of AI tools, agents and third-party AI, with owners attached. A scan, not a live feed, and we would rather say so than let you assume otherwise.
OWASP LLM Top 10 and MITRE ATLAS catalogue
Mapped to controlsA maintained catalogue of LLM and AI attack techniques (prompt injection, leakage, supply chain, evasion, agentic abuse), each mapped to the controls and frameworks it touches, so a threat lands somewhere in your register instead of in a slide.
Red-team result ingest
garak · advisoryWe ingest results from garak and comparable external red-team runs and raise them as advisory findings against the system they belong to. We ingest the results. We do not launch the attacks; see below the line.
DLP and content inspection
Gateway-routed trafficPrompt and response inspection for sensitive-data egress on the AI traffic that routes through the gateway. Traffic that does not route through us is not inspected.
Inline enforcement
Gateway-routed trafficBlock, redact or route in line, at the gateway, on the traffic that passes through it. This is the one place we act rather than advise, and its boundary is exactly that traffic.
Tamper-evident audit chain
ContinuousEvery discovery, finding, decision and override written to a hash-chained log with a signed head, verifiable after the fact. The trail is continuous; that is not the same claim as monitoring your whole estate.
Not shipped · named, not omitted
Live adversarial probing
RoadmapToday we ingest external red-team results. We do not run attacks against your models ourselves. Running our own probes is on the roadmap and is not sold as present.
Membership inference
PartialCovered only as far as garak covers it, through ingest. Not a standalone capability, and not something we would put on an invoice.
Model inversion and extraction
Not builtNo inversion or extraction testing exists in the product. If you need it this quarter, we are the wrong answer.
Training-data poisoning checks
Not builtOur model scanning inspects the artefact for unsafe code and serialisation, which is a different question from whether the training data was poisoned. We do not answer the second one.
Attack range and sandbox
Not builtThere is no Solas-hosted range for detonating models or replaying attacks. Nothing on this page depends on one.
In action
Where the Exposure Actually Concentrates
See where AI is being used, which systems are non-compliant, where risk is concentrated, and what actions need executive attention, now.
Why Solas
Built for the Way Security Teams Actually Work
Examples below illustrate platform capabilities; values shown are demonstrative.
See the AI Running Outside Your Security Controls
Discover unauthorised AI deployments across your organisation: continuously scanning cloud platforms, internal networks, and edge infrastructure so nothing stays hidden.
A Broken Connector Doesn’t Fail Silently
Every connector reports its own state, and a failed one is surfaced rather than swallowed, so a dead feed shows up as a gap in coverage instead of as an all-clear you had no reason to doubt.
Write the Policy Your Controls Are Meant to Enforce
Describe what you need in plain English. Solas generates governance policies mapped to frameworks, scored for quality, and ready for review.
A Hard Gate at Your Release Point
The gate sits in the pipeline you already run and blocks promotion on evidenced risk. We decide and evidence; your existing controls enforce. A named human can override it (that is deliberate), and the override is logged with the name attached rather than quietly swallowed.
What it is not: an autonomous kill switch. We do not reach around your change control and stop production AI on your behalf. Any vendor offering that is describing a change-management problem, not a feature.
- DevelopmentUnit tests · Bias scan · 12 models · pass
- StagingIntegration · Compliance · 8 models · pass
- ProductionFull audit · Sign-off · 5 models · blocked
- GlobalRegional · Regulatory · 0 models · pending
- Blocked on evidenced riskoverride: named human, logged
Track Where Every Connected Model and Agent Runs
See, govern, and prove every model and agent you bring into Solas, in one place, wherever it runs.
Scan the Artefact Before It Enters the Registry
Model files are inspected for unsafe code and serialisation (pickle execution, embedded payloads, malformed formats) before they are admitted. This is a check on the artefact. Whether the training data behind it was poisoned is a different question, and one we do not answer today.
Ecosystem
Runs Through the Controls You Already Operate
Connect Solas to your AI, security, ticketing, and data platforms, without rip-and-replace.
- ML PlatformsAWS SageMaker · Google Vertex AI · Azure ML · MLflow · Hugging Face
- Identity & AccessOkta · Azure AD · Auth0 · LDAP / AD
- CommunicationsSlack · Microsoft Teams · Email (SMTP)
- Ticketing & GRCJira · ServiceNow GRC
- Data & ObservabilityPostgreSQL · Snowflake · Splunk
Compliance
Findings Are Half the Record. The Proof Lives Next Door.
Spearheads 02 and 04 (posture tied to findings, and the tamper-evident chain that proves the sequence) are the second pillar. Same chain, same record, read by your auditor instead of your security team.
- See framework coverage in one place
- Track open gaps and remediation
- Produce audit evidence faster
Who this is for
Built for Teams Answering to a Regulator and an Attacker
“We built this platform because we saw enterprise after enterprise deploying AI without a governance layer. The risk isn’t theoretical. It’s operational, legal, and reputational. We wanted to give security teams a way to get ahead of it.”
- 01Battle-Tested
- Built with real enterprise governance use cases, not academic theory
- 02Regulation-Ready
- Designed for regulated and high-assurance environments from day one
- 03Partner-Validated
- In active conversations with design partners across security and risk functions
practitioner-built, partner-validated
Start here
See the AI Actually Running in Your Environment
The free 30-day pilot starts with discovery: connect your identity provider in about fifteen minutes and see the AI actually in use on day one. Read-only to start, no endpoint agent, and the out-of-scope list is published before you sign.
- Day 1 · Connect + inventoryread-only · about fifteen minutes
- Mapsystems → the frameworks that reach you
- Gatelive in your pipeline, override logged
- Day 30 · Recordyours either way · no obligation
