Skip to content
Motion

Following your device setting.

ColossalX
  • Platform overview Four verbs around one spine
    • How it worksOne finding, from found to accounted for
    • ColossalX AssistantGoverned AI chat for your workforce
    • For developersGateway endpoint, scan APIs, Playground
    See What are we running?
    • AI inventory and agent mapAgents from code and traffic, on one map
    • Shadow AIThe AI nobody approved, then a standing rule
    • AI bill of materialsSBOM and AI-BOM, with drift from baselines
    • Data lineageWhich personal data reached which model
    • AI spendCost by model, with daily allowances
    Control What is it doing right now?
    • AI gatewayOne governed path to 31 provider families
    • Runtime guardrailsInjection, data leaks and approval holds
    • ColossalX MCP FirewallAllow, monitor or block each tool
    • Runtime consentConsent checked when the request is made
    • Agent identityPost-quantum identity and admission
    • Detection and responseContainment and the ColossalX Kill Switch
    Prove Will our defences hold?
    • Red-teaming and validationAuthorised attacks, sealed runs
    • ColossalX CyberTwinsAttack a twin, not production
    • Threat intelligenceMatched to what you actually run
    • Exposure managementExposures ranked by validated reachability
    • Code securityRepositories, apps and the CI/CD gate
    • ResilienceInjected faults and restore drills
    Govern Where do we stand?
    • ColossalX Trust EngineA trust score that explains itself
    • Risk quantificationAI risk in money, as a loss range
    • Compliance and AI governanceMapped frameworks, policies and evidence
    • AuditFrom a plan to a sealed archive

    How it works

    Follow one finding end to end
    1. found
    2. held
    3. tested
    4. fixed
    5. accounted for
    Watch the film
  • By role

    • For CISOsWhich AI could hurt us?
    • For AI governance and DPOsWhat personal data reaches which model?
    • For security engineeringWhat is this agent doing right now?
    • For risk and complianceWhere do we stand against our frameworks?
    • For ITWhich AI tools are on our laptops?

    By industry

    • Banking
    • Insurance
    • Capital markets
    All solutions

    Frameworks

    The AI regulatory clock
    • 13 Nov 2026India DPDP
    • 13 May 2027India DPDP
    • 2 Dec 2027EU AI Act
  • Mapped to
    • NIST AI RMF
    • EU AI Act
    • ISO/IEC 42001
    • SOC 2
    • GDPR
    • India DPDP
    • SEBI cyber circulars
    • IRDAI cyber circulars
    • PCI DSS
    • NIS2
    Assessed against
    • OWASP Agentic Top 10
    • OWASP LLM and MCP Top 10
    • MITRE ATLAS
    • MITRE ATT&CK
    All frameworks

    Explorer

    OWASP Agentic Top 10

    ASI01 to ASI10, in plain words

    • Agent incident field guideThe first hour when an agent misbehaves
    • AI security glossaryPlain definitions, each with a picture
    • For AI agentsPlain facts for assistants and answer engines

    Explained

    OWASP Agentic Top 10

    ASI01 to ASI10, in plain words

    • Why ColossalX
    • About Quantexra Labs
    • Security at ColossalX
    • For AI agents
    • Contact
Sign inBook a walkthrough
ColossalX
Motion

Following your device setting.

Platform

Platform overview
  • How it worksOne finding, from found to accounted for
  • ColossalX AssistantGoverned AI chat for your workforce
  • For developersGateway endpoint, scan APIs, Playground
SeeWhat are we running?
  • See overview
  • AI inventory and agent mapAgents from code and traffic, on one map
  • Shadow AIThe AI nobody approved, then a standing rule
  • AI bill of materialsSBOM and AI-BOM, with drift from baselines
  • Data lineageWhich personal data reached which model
  • AI spendCost by model, with daily allowances
ControlWhat is it doing right now?
  • Control overview
  • AI gatewayOne governed path to 31 provider families
  • Runtime guardrailsInjection, data leaks and approval holds
  • ColossalX MCP FirewallAllow, monitor or block each tool
  • Runtime consentConsent checked when the request is made
  • Agent identityPost-quantum identity and admission
  • Detection and responseContainment and the ColossalX Kill Switch
ProveWill our defences hold?
  • Prove overview
  • Red-teaming and validationAuthorised attacks, sealed runs
  • ColossalX CyberTwinsAttack a twin, not production
  • Threat intelligenceMatched to what you actually run
  • Exposure managementExposures ranked by validated reachability
  • Code securityRepositories, apps and the CI/CD gate
  • ResilienceInjected faults and restore drills
GovernWhere do we stand?
  • Govern overview
  • ColossalX Trust EngineA trust score that explains itself
  • Risk quantificationAI risk in money, as a loss range
  • Compliance and AI governanceMapped frameworks, policies and evidence
  • AuditFrom a plan to a sealed archive
How it worksFollow one finding end to end Watch the film

Solutions

All solutions

By role

  • For CISOsWhich AI could hurt us?
  • For AI governance and DPOsWhat personal data reaches which model?
  • For security engineeringWhat is this agent doing right now?
  • For risk and complianceWhere do we stand against our frameworks?
  • For ITWhich AI tools are on our laptops?

By industry

  • Banking
  • Insurance
  • Capital markets
FrameworksThe AI regulatory clock

Frameworks

All frameworks

Mapped to

  • NIST AI RMF
  • EU AI Act
  • ISO/IEC 42001
  • SOC 2
  • GDPR
  • India DPDP
  • SEBI cyber circulars
  • IRDAI cyber circulars
  • PCI DSS
  • NIS2

Assessed against

  • OWASP Agentic Top 10
  • OWASP LLM and MCP Top 10
  • MITRE ATLAS
  • MITRE ATT&CK
ExplorerOWASP Agentic Top 10

Resources

  • Agent incident field guideThe first hour when an agent misbehaves
  • AI security glossaryPlain definitions, each with a picture
  • For AI agentsPlain facts for assistants and answer engines
ExplainedOWASP Agentic Top 10

Company

  • Why ColossalX
  • About Quantexra Labs
  • Security at ColossalX
  • For AI agents
  • Contact
Sign inBook a walkthrough

Website privacy

Website privacy notice

How this website handles what you send through its forms. It covers colossalx.tech only, not the ColossalX product, whose data handling is set out in each customer's agreement.

Last updated 7 October 2026.

On this page

  1. Who we are
  2. What the forms collect
  3. Why we use it
  4. Where it goes
  5. The spam check
  6. Cookies, storage and analytics
  7. How long we keep it
  8. Your choices
  9. Contact

Who we are

This website is run by Quantexra Labs LLP ("Quantexra Labs", "we"), which makes ColossalX. You can reach us at client.success@quantexra.tech.

Quantexra Labs LLP is a registered company based in Bangalore, India. We handle personal data under Indian law, including the Digital Personal Data Protection Act, 2023, and the courts at Bangalore, Karnataka have jurisdiction.

What the forms collect

Only what you type in, and only for the form you use:

  • Book a walkthrough: your name, work email, company, the role closest to yours, what you want to see, and a note if you add one.
  • Contact: your name, email, a subject if you add one, and your message.

To keep automated spam out, the website also handles:

  • your IP address, used for the spam check and to count how many messages arrive from one connection. The count is kept under a scrambled key (a one-way hash), never the address itself;
  • a timestamp token, issued when the form loads, that shows how long the form took to fill in;
  • a hidden field that people never see. If a script fills it in, the message is discarded.

We do not ask for a phone number, a budget or anything that is not needed to reply to you.

Why we use it

To reply to you and arrange what you asked for, and to keep the forms free of automated spam. We do not sell it, and we do not add you to a marketing list from these forms.

We rely on your consent, which you give when you send the form. You can withdraw it at any time by writing to us, and we will stop using your details.

Where it goes

The website is hosted on Cloudflare Pages. When you send a form, a small Cloudflare function checks it and passes it to Quantexra Labs' enquiry inbox, which runs on the ColossalX platform's servers. Those servers are in India, with a backup in the United States.

The inbox emails our team to say a message has arrived, and may send you one automatic receipt with a reference number. That receipt contains nothing you typed. Replies come from a person, from client.success@quantexra.tech.

The function does not record your name, email, message or IP address in its logs. It logs only which form was used and whether the message got through.

The spam check

The forms use Cloudflare Turnstile to tell people from automated scripts, usually without asking you to do anything. Turnstile reads signals from your browser to do this. Cloudflare describes what it processes in its Turnstile privacy addendum.

Cookies, storage and analytics

This website sets no cookies of its own. If you choose a Motion setting, your choice is remembered in your browser's local storage; it never leaves your device.

Cloudflare, which hosts the site, may set strictly necessary security cookies.

No analytics are switched on. If we switch them on, they will be Cloudflare Web Analytics, which does not use cookies, and this notice will say so.

How long we keep it

Enquiries: while we are in touch with you, and no longer than 12 months after our last exchange. You can ask us to remove yours sooner.

The spam-check counters expire on their own: the per-connection count within about an hour, the per-address count within about a day.

Your choices

You do not have to use the forms: you can write to client.success@quantexra.tech instead.

To ask what we hold about you, or to have it corrected or removed, write to the same address. A person reads each request, and we reply within 5 to 10 days.

Contact

Questions about this notice: client.success@quantexra.tech.

If this notice changes, the date at the top changes with it.

ColossalX

Know your x.

The x in ColossalX is the unknown in your AI estate - raised, because it compounds.

Write to us at client.success@quantexra.tech

Motion

Following your device setting.

Platform

  • Platform overview
  • How it works
  • ColossalX Assistant
  • For developers
  • See
  • Control
  • Prove
  • Govern

Solutions

  • All solutions
  • For CISOs
  • For AI governance and DPOs
  • For security engineering
  • For risk and compliance
  • For IT
  • Banking
  • Insurance
  • Capital markets

Frameworks

  • All frameworks
  • Mapped to
  • Assessed against
  • OWASP Agentic Top 10

Resources

  • Agent incident field guide
  • AI security glossary
  • For AI agents

Company

  • Why ColossalX
  • About Quantexra Labs
  • Security at ColossalX
  • For AI agents
  • Contact

ColossalX is a product of Quantexra Labs LLP.

Website privacy notice·© 2026 Quantexra Labs LLP. All rights reserved.