Why ColossalX

One system, not a stack of tools.

One queue, one register, one trust score and one evidence store, honest about what it has not measured, with questions to ask any vendor.

Many sources · one spineIllustrative

Many sources · one spine: testing to ColossalX; scanning to ColossalX; intelligence to ColossalX; ColossalX to one queue (owned); ColossalX to one register (in money); ColossalX to one trust score (explained).

In short

Choosing an AI security platform comes down to three tests: does it connect the slices of AI risk into one position, does it say what it has not measured, and can you check its evidence yourself. ColossalX is built around those tests: one spine under four verbs, honest states instead of flattering zeros, and evidence anyone can re-check.

Last reviewed

Each tool sees one slice, and a confident dashboard hides what nobody measured.

One spine joins the slices, and the product labels what it has not measured.

One systemx, accounted for

Four verbs, one spine, one position.

See, Control, Prove and Govern each answer one question, and findings from testing, scanning, intelligence, audit and compliance land on one spine.

  • One issue per problem

    However many sources saw it, with an owner, a due date and a ticket.

  • Closes only on evidence

    A ticket status does not close an issue; positive evidence, such as a verified re-test, does.

  • One position to defend

    Risk in money, a trust score that explains itself and graded evidence.

See the platform
A closed issue in a demo workspace: an audit finding about a control that is deficient by design, joined by any finding about the same control and cause, and closed once a verified re-test resolved it.
From a demo workspace
3notes
  1. Raised from an audit
  2. Findings join one issue
  3. Closed by a re-test

Measuredx, not measured

Measured, never flattering.

A security product that flatters itself is a liability. ColossalX labels what it does not know instead of guessing.

  • Not measured, never zero

    Missing data is labelled, not hidden behind a confident zero.

  • Provisional grades

    A score built on thin evidence says so, and what would raise it.

  • Not assessable is an answer

    A control that cannot be assessed is excluded, not failed.

  • Recorded intent

    A block it cannot enforce is labelled as such.

  • Provenance labels

    Each record says whether it is demonstration data or created by real use.

  • People decide, machines act

    Approvals wait for a named person; containment and re-tests run at machine speed.

Trust score · whyIllustrative

An illustrative trust score, explained: five pillars with the evidence behind each, resilience shown as not measured rather than zero, a passing re-test that lifts the risk pillar and moves the grade (still provisional), and what would raise it next.

3notes
  1. Provisional while evidence is thin
  2. Not measured, never scored zero
  3. What would raise the grade

What it could not reach

It says what it could not reach.

Where a source, a scan or a test fell short, the record says so, so nobody mistakes silence for safety.

  • Exposure status

    Reads incomplete, not all clear, when a source could not be read.

  • Deep scans

    Say what they read and what they could not reach.

  • Red-team runs

    State which layers are attacked and which are not offered.

  • Twin campaigns

    Report what they did and what they never attempted.

  • Threat intelligence

    States plainly what is not collected.

  • The assistant

    Answers within your access and says what it left out.

Deep scan · what it readIllustrative

Deep scan · what it read: Read Source, dependencies, configs; Not reached One private submodule; Result Partial, and labelled so. Stated, not implied.

Ask any vendor

Questions to ask any AI security vendor, including us.

Each answer is something you can check in a walkthrough, not take on trust.

  • What shows when nothing was measured?

    Ours shows not measured and a provisional grade, never a confident zero.

  • Can a finding close without evidence?

    Ours cannot: an issue closes on positive evidence, not on a ticket status.

  • Which layers does testing not attack?

    Ours states which layers are attacked and which are not offered, beside the run.

  • Can we re-check the evidence ourselves?

    Run manifests are sealed and re-checked on read; evidence is timestamped daily.

  • Is it tied to one vendor?

    No: 31 model provider families, including self-hosted, and the SIEM you already run.

One authorised run · sealedIllustrative

One authorised run · sealed: illustrative run with 18 attempts blocked by a control, 6 detected but allowed, 3 missed and 5 refused by the model. Sealed, re-checked on read.

Honest by design

What ColossalX is not.

Trust score · provisionalIllustrative

Trust score · provisional: C. Security measured; Compliance measured; Risk measured; Resilience not measured; AI governance measured. Provisional until resilience is measured

x, not measured

ColossalX holds no certification; frameworks are mapped to and assessed against.

All 4 limits
  • Runtime detections are alerted and recorded, but do not yet feed the one issue queue.
  • It does not replace your SIEM or GRC tool; it sends alerts to one, risks to the other.
  • There are no public customers to cite; judge ColossalX on what you can check.

Questions

Questions buyers ask

How do we choose an AI security platform?

Test it on four questions: does it find the AI you actually run, does it control that AI as it happens, does it prove your defences hold, and does it put the result on one record you can defend. Then ask what it shows when it has not measured something, and check its evidence yourself.

What should an AI security RFP ask?

Ask for mechanisms and evidence, not adjectives: how agents are found and owned, which controls run in the request path, how testing is authorised and scoped, which frameworks controls are mapped to, what the product shows when a source could not be read, and whether a finding can close without positive evidence.

Why one system instead of several point tools?

Because a finding in one place should change the picture everywhere. In ColossalX, findings from testing, scanning, intelligence, audit and compliance land in one queue with an owner, update one risk register and one trust score, and become timestamped evidence. Point tools each keep their own list, and nobody owns the gaps between them.

How does ColossalX avoid overstating its own results?

It labels what it does not know. Missing data shows as not measured, never zero; a grade on thin evidence says provisional; a control that cannot be assessed is excluded, not failed; a block it cannot enforce is labelled recorded intent; and each record says whether it is demonstration data or created by real use.

Is ColossalX tied to one cloud or model vendor?

No. The AI gateway governs 31 model provider families, including self-hosted models, and alerts reach Splunk, Microsoft Sentinel or Elastic natively, others by signed webhook. ColossalX is independent of any one model vendor's stack, delivered as SaaS, with each customer in its own workspace and database.

Next step

Know your x.

See ColossalX on your own questions, and ask it the questions on this page.

  1. 01Tell us what you run
  2. 02See the four verbs on it
  3. 03Decide where to start