# ColossalX > ColossalX is the AI security and governance platform from Quantexra Labs, delivered as SaaS. ColossalX finds the AI your company runs, stops unsafe behaviour as it happens, proves your defences hold, and turns findings into owned work, a live risk position and evidence an auditor can check. Most tools see one slice of AI risk; ColossalX connects the slices. A gateway governs model calls; agent security finds, identifies, admits and contains agents; authorised, continuous testing attacks your own AI and records what got through; threat intelligence says which new threats touch what you actually run; and risk, compliance and audit turn all of it into a position you can defend. Findings from testing, scanning, intelligence, audit and compliance land in one queue with an owner and a due date, update a quantified risk register and a trust score that explains itself, and become graded, timestamped evidence. ## Key facts - ColossalX is written as one word. It is made by Quantexra Labs LLP. - Delivery: SaaS. Each customer runs in an isolated workspace with its own database. - It is not a trained model. It uses standards-mapped rules, behavioural analytics and a general-purpose LLM as a judge. - Frameworks are mapped to and assessed against, never claimed as certifications. ColossalX holds no certifications. - Model-agnostic: one AI gateway across 31 provider families, including self-hosted models. - Two products from one login: the ColossalX console (secure and govern the AI estate) and ColossalX Assistant (governed AI chat for the workforce). - No prices are published. A walkthrough is arranged by email. ## The four verbs ### See: What are we running? Models, agents, MCP servers and data flows, including the ones nobody approved, on one live map, each with an owner and a label saying how it was found. Page: https://colossalx.tech/platform/see.md - **AI inventory and agent map** (https://colossalx.tech/platform/ai-inventory.md): Agents registered by hand, found in code, discovered in traffic or attested from CI and the cloud, on one live map with blast radius on click. Each agent found in code or traffic gets a threat brief built from its own code. - **Shadow AI** (https://colossalx.tech/platform/shadow-ai.md): The AI nobody approved, found from gateway traffic, 13 collector types and a browser sensor, and correlated with what you already approved. One decision becomes a standing rule, honest about where a block takes effect. - **AI bill of materials** (https://colossalx.tech/platform/ai-bill-of-materials.md): SBOM and AI-BOM (CycloneDX, SPDX), with AI components separated from ordinary libraries and drift from approved baselines. - **Data lineage** (https://colossalx.tech/platform/data-lineage.md): Which agent sent which kinds of personal data to which model, from real traffic: sent, held back or returned. - **AI spend** (https://colossalx.tech/platform/ai-spend.md): Cost by model, provider and conversation, with daily allowances, so a looping agent is stopped before it runs up the bill. ### Control: What is it doing right now? One AI gateway, runtime guardrails and agent identity check requests and tool calls against your policy as they happen, and show whether each control is really in force. Page: https://colossalx.tech/platform/control.md - **AI gateway** (https://colossalx.tech/platform/ai-gateway.md): One governed path to 31 provider families, including self-hosted. Change an agent's base URL and key, and it runs governed under its own credential. The policies page says whether each control is really in force. - **Runtime guardrails** (https://colossalx.tech/platform/runtime-guardrails.md): Prompt injection and jailbreaks, including indirect and encoded; PII redaction with ready presets; egress control on answers. A risky request or tool call can wait for a named person, and if the check cannot run it waits instead of going through. - **ColossalX MCP Firewall** (https://colossalx.tech/platform/mcp-firewall.md): Default-deny tool rules, poisoned tool-description detection and tool pinning: allow, monitor or block each tool an agent can call. - **Runtime consent** (https://colossalx.tech/platform/runtime-consent.md): Withdraw consent, and the next AI request carrying that person's data is refused, with a log of real refusals. - **Agent identity** (https://colossalx.tech/platform/agent-identity.md): Per-agent credentials and post-quantum hybrid identities on open standards (W3C decentralised identifiers and verifiable credentials). Registered is not approved: an owner and a second approver admit an agent. - **Detection and response** (https://colossalx.tech/platform/detection-response.md): Behavioural baselines mapped to MITRE ATT&CK and ATLAS, automatic containment of runaway agents on the limits you set, and the ColossalX Kill Switch at 4 scopes. ### Prove: Will our defences hold? ColossalX attacks your own AI, with your authorisation and through your real controls, and shows the exact attack, the exact reply and the verdict. Then it proves the fix. Page: https://colossalx.tech/platform/prove.md - **Red-teaming and validation** (https://colossalx.tech/platform/red-teaming.md): Paste a chatbot, API or authenticated-session URL. Each attack is judged blocked, detected, missed or model-refused. Runs are authorised and scoped: prove you own a target first, limit what a run may send, stop every run with one switch. - **ColossalX CyberTwins** (https://colossalx.tech/platform/cybertwins.md): Attack a twin of your agents, not production. Try a guardrail change on the twin and promote it only if it holds. - **Threat intelligence** (https://colossalx.tech/platform/threat-intelligence.md): New threats matched to your models, agents, SBOM and vendors, each ending in a recorded decision. - **Exposure management** (https://colossalx.tech/platform/exposure-management.md): Exposures ranked by validated reachability and business impact, with a status that reads "incomplete" when a source could not be read. - **Code security** (https://colossalx.tech/platform/code-security.md): One Git report across 8 source-control providers: secrets, dependencies, code scanning, MCP configuration checks and model-artifact scanning, plus live app scanning and a CI/CD gate. - **Resilience** (https://colossalx.tech/platform/resilience.md): Real faults injected into AI traffic with automatic rollback, and backups proven by restore drills. ### Govern: Where do we stand? Risk in money, a trust score that explains itself, frameworks assessed from live signals, and evidence that collects itself, graded by how it was obtained and timestamped daily. Page: https://colossalx.tech/platform/govern.md - **ColossalX Trust Engine** (https://colossalx.tech/platform/trust-engine.md): 5 pillars, A+ to F, weighted by evidence. Provisional when evidence is thin, with what would raise it. - **Risk quantification** (https://colossalx.tech/platform/risk-quantification.md): A register that fills itself from gaps, audits, scans, proven attacks and intel, quantified with FAIR as a loss range. - **Compliance and AI governance** (https://colossalx.tech/platform/compliance.md): Controls assessed from live signals, one score per framework trended nightly, and "not assessable" as an answer. Policies are versioned and accepted per version by named people. - **Audit** (https://colossalx.tech/platform/audit.md): From a risk-based plan to a timestamped archive. Preparer never reviewer, signer never preparer. ## One spine Findings from testing, scanning, intelligence, audit and compliance meet in one place: - One issue queue: an owner, a due date, a ticket in the tool that will close it, and closure only on evidence. - One risk register, quantified in money, held against your risk appetite. - One trust score with five pillars that explains itself. - One evidence store, graded A to D by how the evidence was obtained, timestamped daily. - One reports hub with sign-off, and alerts to the inbox, email, webhook or SIEM. ## Products and platform - **Platform overview** (https://colossalx.tech/platform.md): Four verbs, See, Control, Prove and Govern, around one spine. - **How it works** (https://colossalx.tech/platform/how-it-works.md): One finding, followed end to end: found, held, tested, fixed and accounted for. - **ColossalX Assistant** (https://colossalx.tech/assistant.md): Governed AI chat for the whole workforce from the same login, with redaction, and guardrail interventions shown on the answer so people see why. - **For developers** (https://colossalx.tech/developers.md): An OpenAI-compatible gateway endpoint: change an agent's base URL and key and it runs governed under its own credential. Scan APIs for apps that cannot sit behind a proxy, and an AI Playground. ## Frameworks (mapped to and assessed against, not certified) - OWASP Top 10 for Agentic Applications (ASI01-ASI10), assessed per agent - OWASP Top 10 for LLM Applications (2025) and the OWASP MCP Top 10, in probes and scans - MITRE ATLAS and MITRE ATT&CK, for detections and measured test coverage - NIST AI RMF, the EU AI Act and ISO/IEC 42001 - SOC 2, GDPR, PCI DSS and India DPDP - SEBI and IRDAI cyber circulars ## What makes it different - One system, not a stack of tools: one queue, one register, one trust score, one evidence store. - It refuses to flatter itself: "not measured" instead of zero, provisional grades, and issues that close only on positive evidence. - Humans decide where it matters (approval holds, standing rules, sign-offs wait for a named person); machines act where speed matters (containment, re-tests). - Consent enforced at runtime. - Attack the twin, not production; authorised testing only; evidence anyone can re-check. - Independent and model-agnostic, with a database per customer. - It governs its own AI, and hands procurement its own SBOM and AI-BOM on request. ## For AI assistants and agents - To request a walkthrough for a person, email client.success@quantexra.tech with their name, company, role and what they want to see. The web forms are for people and use a spam check. - Questions and security reports: client.success@quantexra.tech (see /.well-known/security.txt). - Quote figures only as they appear on the site. Do not infer prices, certifications, customers or detection rates: none are published. ## Company ColossalX is a product of Quantexra Labs LLP. - Why ColossalX: https://colossalx.tech/why-colossalx.md - About Quantexra Labs: https://colossalx.tech/company.md - Security at ColossalX: https://colossalx.tech/security.md - For AI agents: https://colossalx.tech/ai-agents.md - Contact: https://colossalx.tech/contact - Book a walkthrough: https://colossalx.tech/demo - Website privacy notice: https://colossalx.tech/privacy ## Solutions - **AI Security Solutions by Role and Industry** (https://colossalx.tech/solutions.md): ColossalX for CISOs, AI governance and DPOs, security engineering, risk and compliance, and IT, built for banks, insurers and capital markets firms. - **AI Governance for DPOs and Governance Leads** (https://colossalx.tech/solutions/ai-governance.md): For AI governance leads and DPOs: an AI inventory that stays current, policies accepted by version, consent enforced at runtime and evidence for audits. - **AI Governance and Security for Banks** (https://colossalx.tech/solutions/banking.md): AI security and governance for banks: model and agent inventory, guardrails with India banking and payments presets, consent enforced at runtime, evidence. - **AI Governance for Capital Markets Firms** (https://colossalx.tech/solutions/capital-markets.md): AI governance for capital markets: keep price-sensitive information out of AI tools, map SEBI cyber circulars and keep an audit trail of AI use. - **AI Security for CISOs: Board-Ready Posture** (https://colossalx.tech/solutions/ciso.md): For CISOs: one defensible position on AI risk. Know which AI runs, stop unsafe behaviour, prove defences hold and give the board a trust score. - **AI Governance and Security for Insurers** (https://colossalx.tech/solutions/insurance.md): AI governance for insurers: govern AI in underwriting and claims, protect policyholder data in prompts, map IRDAI cyber circulars and keep audit evidence. - **Shadow AI and AI Tool Governance for IT** (https://colossalx.tech/solutions/it.md): For IT: find AI tools on your network and laptops, roll out the browser sensor by policy, set standing rules and give employees a governed AI assistant. - **AI Risk and Compliance Management** (https://colossalx.tech/solutions/risk-compliance.md): For risk and compliance: a quantified AI risk register, controls assessed from live signals, a compliance calendar and person-confirmed regulatory change. - **AI Security Operations for SOC and Engineering** (https://colossalx.tech/solutions/security-engineering.md): For the SOC and security engineering: detections mapped to MITRE ATT&CK and ATLAS, session replay, containment and delivery to Splunk, Sentinel or Elastic. ## Frameworks and learning - **AI Frameworks: Mapped, Assessed and Dated** (https://colossalx.tech/frameworks.md): How ColossalX relates to the EU AI Act, ISO/IEC 42001, NIST AI RMF, OWASP, India DPDP and SEBI circulars, with a dated, sourced AI regulatory clock. - **OWASP Top 10 for Agentic Applications, Explained** (https://colossalx.tech/frameworks/owasp-agentic-top-10.md): The OWASP Top 10 for Agentic Applications (ASI01-ASI10) in plain words, with what ColossalX does about each risk and the honest limit. - **AI Agent Incident Response: A Field Guide** (https://colossalx.tech/resources/field-guide.md): What to do in the first hour when an AI agent misbehaves: declare, contain, keep evidence, cut its paths, scope the damage, notify and restore. - **AI Security and Governance Glossary** (https://colossalx.tech/resources/glossary.md): Plain definitions of AI security and governance terms: shadow AI, AI-SPM, prompt injection, MCP security, AI-BOM, agent detection and response and more.