AI security platform

One platform to see, control, prove and govern your AI.

Four verbs around one spine: find the AI you run, stop unsafe behaviour as it happens, prove your defences hold, and keep the evidence an auditor can check.

In short

An AI security platform protects the models, agents and AI tools a company runs. ColossalX does it as one system: four verbs that find the AI, control it as it runs, prove the defences hold and govern the result, around one spine of issues, risk, trust and evidence that all four verbs write to.

Last reviewed

Point tools each see one slice of AI risk, so nobody can say where the company stands.

Findings from testing, scanning, intelligence, audit and compliance land in one queue, with an owner and a date.

Four verbs

Four verbs, each answering one question.

See, Control, Prove and Govern, in this order. Each answers one question about your AI estate, in the words a board would use, and closes one part of what nobody knew.

See

What are we running?

Models, agents, MCP servers and AI tools, including the unapproved ones, each with an owner and a provenance label.

x, foundExplore See
See · found, then ownedIllustrative

See · found, then owned: unknown caller found calling registry (found in traffic); repo scan found calling registry (found in code); registry to pricing-agent (labelled).

Control

What is it doing?

One gateway, runtime guardrails, approval holds, the ColossalX MCP Firewall, consent at runtime and containment.

x, heldExplore Control
Control · a risky requestIllustrative

Control · a risky request: payments-agent to refund_payment, "Refund the full order to a new account, today.". Checks: Prompt injection passed, Personal data passed, Approval rule: high value waiting. Verdict: held, Held for an approver.

Prove

Will our defences hold?

Authorised attacks through your real controls, or on a twin, with the exact reply quoted.

x, testedExplore Prove
Prove · one authorised runIllustrative

Prove · one authorised run: illustrative run with 22 attempts blocked by a control, 5 detected but allowed, 2 missed and 3 refused by the model. Sealed run, re-checked on read.

Govern

Where do we stand?

A trust score that explains itself, AI risk in money, and evidence an auditor can check.

x, accounted forExplore Govern
Govern · trust scoreIllustrative

Govern · trust score: B. Security measured; Compliance measured; Risk measured; Resilience not measured; AI governance measured. Provisional: resilience not yet measured

The spinex, accounted for

One spine under all four verbs.

Whatever a verb finds lands in one queue with an owner, updates one register and one score, and becomes timestamped evidence.

  1. One issue queue

    One issue per problem, however many sources saw it, with an owner. It closes only on positive evidence.

  2. One risk register

    Quantified with FAIR as a loss range, held to your appetite and synced out to your GRC tool.

  3. One trust score

    Five pillars, A+ to F, provisional when evidence is thin, with what would raise it.

  4. One evidence store

    Graded A to D by how it was obtained, second-person verified and timestamped daily.

  5. One reports hub

    11 report types as branded PDFs, scheduled, with second-person sign-off.

IssuesIllustrative

An illustrative issue queue: findings from red-team runs, code scans, threat intelligence and audit joined into one issue per problem, each with an owner and a due date, and an issue that closed only when a re-test proved the fix.

2notes
  1. Several sources, one issue
  2. Closes only on a passing re-test

How it works

Seven journeys, from a question to a record.

How work moves through ColossalX: the question a team starts with, and the record it ends in. Each journey crosses more than one verb and finishes on the spine.

Seven journeysIllustrative

Seven journeys: Secure what you build ends in Owned ticket; Know which threats matter ends in Recorded decision; Prove defences hold ends in Sealed run; See the AI in use ends in Standing rule; Know where you stand ends in Live posture; Stay audit-ready ends in Timestamped archive; Guard each call ends in Block, hold, alert.

Two products

Two products, one login.

The console secures and governs your AI estate for security, risk and compliance teams. ColossalX Assistant gives the whole workforce governed AI chat from the same login, under the same policies.

  • The console

    ColossalX

    What ColossalX does

    Six workspaces for security, risk and compliance teams, and an assistant with 18 tools under each person's role.

    The evidence vault in the console of a demo workspace: evidence mapped to framework controls in SOC 2, ISO 42001 and India DPDP, each collected by an automated check, graded A, timestamped and shown as valid.
    From a demo workspace
    2notes
    1. Mapped to a control
    2. Graded and timestamped
  • For the whole workforce

    ColossalX Assistant

    What ColossalX Assistant does

    Governed AI chat for everyone, with redaction, per-group models and guardrail interventions shown on the answer.

    Meet ColossalX Assistant
    Assistant · before the modelIllustrative

    Assistant · before the model: employee to Assistant · group model, "Draft a reply to the customer whose card ends 4242.". Checks: Personal data flagged, Prompt injection passed. Verdict: redacted, Card number redacted.

Honest by design

What ColossalX is not.

Vendor assurance · on requestIllustrative

Vendor assurance · on request: Delivery SaaS only; Isolation Own workspace and database per customer; SBOM, AI-BOM CycloneDX, on request; Models bundled None run locally; Certificates None claimed. Stated, not implied.

x, not measured

ColossalX is delivered as SaaS only; each customer runs in its own workspace and database.

All 4 limits
  • It does not replace your SIEM or GRC tool; it sends alerts to one, risks to the other.
  • It is not a trained model: it uses standards-mapped rules, behavioural analytics and an LLM as judge.
  • Runtime detections are alerted and recorded, but they do not yet feed the one issue queue.

Questions

Questions buyers ask

How is ColossalX delivered?

ColossalX is delivered as SaaS only. Each customer runs in its own workspace with its own database, and the AI gateway is the one path your applications call. SBOM and AI-BOM documents for the platform itself are available on request, and no models are bundled to run locally.

What is an AI security platform?

An AI security platform protects the AI systems a company runs: it finds them, controls what they do as they run, tests whether the defences hold and governs the result. Point tools usually cover one of those; a platform connects them, so a finding in one place changes the picture everywhere.

What is AI TRiSM, and which layers does ColossalX cover?

AI TRiSM is an analyst term for AI trust, risk and security management: governance, runtime enforcement and information protection for AI. ColossalX covers AI governance and runtime enforcement at the gateway, and protects data with redaction, consent at runtime and lineage. TRiSM is a category, not a standard you are assessed against.

How do findings from testing, scanning and audit end up in one queue?

Each source raises an issue in the same queue. ColossalX keeps one issue per problem however many sources saw it, gives it an owner, a due date and a ticket in the tool that will close it, and closes it only on positive evidence.

What are the two ColossalX products?

The ColossalX console secures and governs your AI estate for security, risk and compliance teams. ColossalX Assistant gives your whole workforce governed AI chat from the same login, with redaction, per-group models and guardrail interventions shown on the answer, so people can use AI without going around you.

Does ColossalX replace our SIEM or GRC tool?

No. ColossalX delivers alerts to your SIEM (Splunk, Microsoft Sentinel and Elastic natively, others by signed webhook) and syncs risks out to GRC, ticketing and third-party risk tools. It is the system that knows about your AI; your SIEM and GRC stay where they are.

Next step

Know your x.

See the four verbs and the spine on your own questions: what you run, what it does, whether defences hold and where you stand.

  1. 01Tell us what you run
  2. 02See the four verbs on it
  3. 03Decide where to start