Welcome to AUDT
AI-Native Trust, Risk & Compliance Platform — Governance OS
Replace spreadsheets and disconnected tools with a single AI-native platform for vendor governance, compliance, audits, risk, board governance, regulatory intelligence, and more. 32 modules. 259+ tables. Governance built on proof.
Quick Actions
Your First 15 Minutes
- 1✅ Create Organization (/onboarding) — Set up your organization, industry, and company size in the 3-step onboarding wizard.
- 2👥 Invite Team Members (/settings/team) — Add teammates and assign roles: owner, admin, compliance_manager, security_manager, procurement_manager, member, viewer.
- 3🏢 Add Your First Vendor (/vendors → New Vendor) — Create a vendor record with name, website, category, and risk level.
- 4📋 Select Compliance Framework (/compliance/frameworks → New) — Choose from ISO 27001, SOC 2, DPDP, PCI DSS, HIPAA.
- 5📎 Upload Evidence (/compliance/evidence → New Evidence) — Attach evidence items and map them to controls.
- 6📊 Review Dashboard (/dashboard) — See your Org Trust Score™, compliance readiness, and open risks at a glance.
Platform Overview
AUDT replaces spreadsheets and disconnected tools with a single AI-native platform for vendor governance, compliance, audits, risk, and board governance. Every action flows into a unified trust posture that is continuously scored, monitored, and reported.
Vendor Lifecycle
Compliance Lifecycle
Scoring Engines
Org Trust Score™
Vendor Trust Score™
Control Health™
Trust Score™ Deep Dive
The Vendor Trust Score™ is a 0–100 composite signal computed from 7 weighted components. It updates on every meaningful governance action — document upload, assessment completion, risk change, contract update. A score ≥ 90 is Trusted. Below 60 is High Concern.
Score Levels
| Level | Range | Meaning |
|---|---|---|
| Exceptional | 95–100 | Best-in-class governance. All components healthy. |
| Trusted | 90–94 | Strong posture. Minor gaps tolerated. |
| Strong | 80–89 | Good governance. One or two areas need attention. |
| Moderate | 70–79 | Governance present but inconsistent. Prioritise weakest component. |
| Needs Attention | 60–69 | Material gaps. Remediation plan required. |
| High Concern | 0–59 | Critical governance failure. Escalate immediately. |
Components & How to Improve Them
| Component | Weight | How to improve |
|---|---|---|
| Evidence | 20% | Upload more vendor documents. Keep expiry dates current. Map docs to controls. |
| Risk | 20% | Treat open risks. Close critical risks. Remove duplicate risk entries. |
| Compliance | 15% | Improve framework readiness. Close gaps. Map evidence to controls. |
| Assessment | 15% | Run a fresh security assessment. Score ≥ 80 maximises this component. |
| Contract | 10% | Add contract records. Track expiry. Complete open obligations. |
| Operational | 10% | Complete periodic vendor reviews. Respond to document requests promptly. |
| Freshness | 10% | Conduct a review within 30 days. Refresh stale assessments. |
Trust Operations Engine™
The Trust Operations Engine™ (TOE) is the orchestration layer that connects every governance module into an automated, event-driven platform. It transforms AUDT from a record-keeping system into a proactive governance intelligence platform that closes the loop on every governance signal.
The Four Layers
- 1Event Engine — 37 built-in event types. Every vendor action, risk change, evidence expiry, and compliance gap triggers an event automatically.
- 2Workflow Engine — 6 built-in workflows: Vendor Onboarding, Evidence Expiry Response, Trust Score Drop, Contract Renewal, Vendor Offboarding, Critical Risk Escalation. Plus custom workflows via /operations/workflows.
- 3Automation Engine — No-code if-this-then-that rules. Connect any event to any action: create risk, assign task, request evidence, send notification, escalate for approval.
- 4AI Decision Engine — AI generates recommendations with confidence scores and suggested actions. All proposed mutations require human approval at /operations/approvals — no autonomous data changes.
Use Cases
Eight complete, step-by-step workflows covering the most common AUDT operations.
UC1: Onboard a New Vendor
- 1Go to /vendors → New Vendor. Enter name, website, category (SaaS/Cloud/IT Services/etc.), risk level, country.
- 2Assign an owner from your team. Owner receives notifications for expiries and reviews.
- 3Go to vendor detail → Documents tab → Request Documents. Select from required doc types (SOC 2, ISO cert, DPA, etc.).
- 4Vendor receives magic-link portal email. They upload at /portal/[token] — no account needed.
- 5Review uploaded documents. AI auto-extracts: issuer, validity dates, coverage scope, certification body.
- 6Go to Assessment tab → launch Security Assessment (17 questions). Score computed automatically.
- 7Once score ≥ 60 and required docs present, vendor status auto-advances to "approved".
UC2: Assess Vendor Risk
- 1Open vendor detail → Risk tab → Add Risk or /risks/new
- 2Set category (cyber_security, compliance, vendor, privacy, etc.), impact (1–5), likelihood (1–5)
- 3AUDT computes inherent score = impact × likelihood × 4 (max 100)
- 4Add treatment: strategy (mitigate/accept/transfer/avoid), assign owner, set due date
- 5Link risk to vendor, relevant controls, compliance frameworks
- 6Monitor via /risks dashboard — heat map shows all risks by impact × likelihood
UC3: Collect Compliance Evidence
- 1Go to /compliance/evidence → New Evidence
- 2Set title, type (document/assessment/review/policy/other), status (collected/pending/expired)
- 3Upload file OR link from vendor documents (auto-import available)
- 4Map to controls: Evidence → Map to Control
- 5Each mapping contributes to control readiness. Framework readiness = covered/total controls
- 6Check gaps at /compliance/gaps — 5 automated gap rules
UC4: Run a Compliance Assessment
- 1Go to /compliance/frameworks → select framework
- 2Review all controls — each shows: status, linked evidence count, owner
- 3For each control: update status, link evidence, add notes
- 4Run Gap Analysis: /compliance/gaps → 5 gap types: missing evidence, expired evidence, unimplemented controls, no policy coverage, no control owner
- 5Generate report: /compliance/reports → Framework PDF or Executive PDF (AI-narrated)
- 6Share with auditor or board from reports page
UC5: Prepare for an Audit
- 1Go to /audits/new → create audit (name, type, framework link, scope, auditor)
- 2AUDT auto-generates audit program from framework controls
- 3Review each program item: mark reviewed/passed/failed
- 4Add findings: /audits/[id]/findings → AI can convert observations into structured findings
- 5For each finding, create CAPA: assign owner, due date, remediation steps
- 6Generate Audit Package: vendor detail → Audit Package — exports vendor docs, assessment, risk summary
- 7Generate Audit Report PDF: /reports/audits/[id]
UC6: Create & Manage Policies
- 1Go to /compliance/policies → New Policy
- 2Set: title, description, version, category, owner, effective date, review date
- 3Save as Draft → review → change status to Active to publish
- 4Map policy to compliance frameworks and controls
- 5Assign attestation — team members confirm they have read the policy
- 6Track reviews: set next review date. AUDT alerts when review is due.
UC7: Review Compliance Status (Executive View)
- 1Go to /trust-intelligence — Org Trust Score™ ring shows 0–100 score
- 2Drill into components: Vendor Trust, Risk Posture, Control Health, Audit Readiness, Compliance Coverage
- 3Review Recommendations tab for prioritized actions with impact/effort ratings
- 4Check Trends tab for 90-day governance trend sparklines
- 5Generate AI Executive Summary from Executive View tab (Governance Copilot™)
- 6Export board report at /executive-reporting/board-reports
UC8: Automate Governance with Trust Operations Engine™
- 1Go to /operations/events — see the live event stream across all 37 event types (vendor.document_expired, risk.score_critical, control.health_low, etc.)
- 2Go to /operations/workflows — choose from 6 built-in templates: Vendor Onboarding, Evidence Expiry Response, Trust Score Drop Response, Contract Renewal, Vendor Offboarding, Critical Risk Escalation
- 3Click Start Workflow on any template — fill in parameters, assign owner
- 4Monitor active instances at /operations/workflows — each step shows pending/in_progress/completed/failed status
- 5Go to /operations/approvals — review pending approvals and approve or reject with notes
- 6Create automation rules at /operations/automation — define event→action triggers (e.g., 'When trust score drops below 60, create a risk review task')
- 7View /operations/analytics for workflow SLA metrics, completion rates, and historical throughput
UC9: Govern AI Systems
- 1Go to /ai-governance/inventory → Add AI System
- 2Set: name, type (llm/ml_model/automation/decision_support), vendor, deployment env, risk classification
- 3Link AI risks: type (hallucination/bias/privacy_leakage/prompt_injection/etc.), impact, likelihood
- 4Map to AI controls: human oversight, output review, prompt logging, model approval
- 5Check compliance: AUDT maps to ISO 42001, NIST AI RMF, EU AI Act, DPDP AI
- 6Monitor via AI Trust Score™ — Risk(25%), Controls(25%), Compliance(20%), Monitoring(15%), Vendor(10%), Incidents(5%). Set up automation rules at /operations/automation to trigger alerts when AI risk scores breach thresholds.
Module Reference
AUDT ships 32 governance modules across six groups. Each module is self-contained with its own data layer, services, AI assistant, and REST API surface.
Core GRC
Central vendor registry with AI-powered document processing and Trust Score™ engine.
Features: 25-column vendor registry, document management with AI extraction (10 fields), magic-link vendor portal, Trust Score™, NL search.
Workflow: Add vendor → Request documents → Auto-extract fields → Risk assess → Approve
Unified compliance management across 5 frameworks with 174 built-in controls.
Features: 10 compliance tables, 174 built-in controls across 5 frameworks, auto-import from vendors, gap analysis, AI Officer™.
Workflow: Select framework → Map controls → Collect evidence → Run gap analysis → Generate report
End-to-end audit lifecycle from planning to board-ready reports.
Features: Full audit lifecycle, auto-generated audit program, AI finding generator, CAPA tracker, PDF reports.
Workflow: Plan audit → Generate program → Review items → Add findings → Create CAPAs → Generate report
Visual risk intelligence with heat map and AI-powered risk officer.
Features: 5×5 heat map, 13 risk categories, treatment tracking, AI Risk Officer™, treatment strategies.
Workflow: Identify risk → Score impact/likelihood → Add treatment → Link to framework → Monitor
Control effectiveness scoring and continuous testing platform.
Features: Control Health™ scoring (6 components), test logging, AI gap detection, framework mapping.
Workflow: Create control → Link evidence → Run tests → Compute health score → Review gaps
Intelligence
Executive governance command center with Org Trust Score™.
Features: Org Trust Score™ (5 components), 9-tab command center, Governance Copilot™, recommendations engine.
Workflow: View score → Drill components → Review recommendations → Generate summary
90-day governance trend monitoring across 6 key metrics.
Features: 90-day sparklines for 6 metrics, change % vs period start, 30-row score history.
Automated governance monitoring with 7 rule engine.
Features: 7 automated monitoring rules, auto-generated alerts, resolve workflow.
Force-directed governance knowledge graph with AI reasoning.
Features: Force-directed SVG visualization, Root Cause Analysis™, Impact Analysis™, Governance Reasoner™.
Privacy & Legal
Full policy lifecycle with version control and attestation tracking.
Features: Policy lifecycle, versioning, attestations, Policy Health™, review scheduling.
India-specific DPDP Act 2023 compliance platform.
Features: Data inventory, consent records, DSR workflow, retention policies, privacy assessments. Mumbai data residency (ap-south-1).
Contract lifecycle management with obligation tracking and renewal alerts.
Features: Contract library, clause management, obligation tracker, renewals dashboard, Contract Score™.
Operations
Event-driven orchestration layer connecting every governance capability into one intelligent platform.
Features: 37 built-in event types, 6 workflow templates, unified approval queue, automation rules engine, AI Decision Engine, Operations Copilot™.
Workflow: Publish event → Match workflow → Run steps → Approve actions → Monitor analytics
Centralized governance issue registry with SLA tracking.
Features: Issue registry, task management, exception management, escalation engine, SLA tracking.
Governance automation engine with approval workflows.
Features: Workflow definitions, approval workflows, AI workflow generator, run history.
Trust Network
Public trust marketplace for vendor evidence sharing.
Features: Trust profiles, evidence exchange, badges, questionnaire exchange, vendor directory.
Industry peer comparison across 10 governance categories.
Features: 10 category scorecards, percentile ranking, Governance Rankings™, 6-month trends.
Connectivity layer with 35+ pre-built connectors.
Features: 35+ connectors, sync engine, evidence automation, webhook engine, connection health.
Public trust infrastructure aggregating all trust signals.
Features: Trust reputation score, governance maturity ladder, network directory, activity feed.
Enterprise
Role-specific dashboards and predictive governance analytics.
Features: 6 role dashboards (CEO/CRO/CISO/Compliance/Board/Custom), board reports, predictive forecasting, scorecards.
Responsible AI governance platform for AI system risk management.
Features: AI system inventory, AI Trust Score™, EU AI Act compliance, ISO 42001, incident tracking.
Secure external auditor engagement platform.
Features: Secure audit rooms, evidence exchange, external findings, assessment projects, auditor user management.
Trust-as-infrastructure API with 8 products and developer portal.
Features: 8 API products, webhooks, developer portal, usage analytics, AI API builder.
Certification authority for governance trust.
Features: 10 verification programs, 9-step workflow, Trust Certificates™, public /verify/[id] page.
Always-on compliance automation with 21 automated checks.
Features: 21 automated checks, access reviews, attestations, training campaigns, Compliance Health™ score.
AI agents for proactive governance monitoring.
Features: 6 agent types, observations, recommendations, human-approved actions, Governance Copilot™.
Real-time regulatory tracking for 18+ regulations.
Features: 18 built-in regulations (India + global), change monitor, obligations, Compliance Horizon™.
Enterprise asset graph with trust mapping.
Features: 12 asset types, Asset Trust Score™, dependency graph, PII tracking, alerts.
Enterprise security platform for regulated industries.
Features: MFA management, Enterprise SSO, session management, IP allow lists, AI prompt audit, Customer Managed Encryption.
Compliance Framework Center
AUDT ships with 174 built-in controls across five frameworks. Add a framework at /compliance/frameworks to begin tracking readiness.
ISO 27001
Domains
Evidence: Policy documents, access logs, risk assessments, incident records, supplier contracts.
Route: /compliance/frameworks → ISO 27001
SOC 2
Domains
Evidence: SOC 2 reports, penetration test results, access reviews, encryption documentation.
PCI DSS
Domains
Evidence: Network diagrams, scan reports, penetration tests, access control logs, training records.
HIPAA
Domains
Evidence: Risk analysis, workforce training, access controls, audit logs, business associate agreements.
DPDP (India)
Domains
Evidence: Consent records, DSR logs, retention schedules, breach notification records, privacy assessments.
Dedicated module: /privacy · Data residency: Mumbai (ap-south-1).
Role Guides
Recommended workflows tailored to each role in your governance team.
CISO
CISOs use AUDT to maintain end-to-end visibility across vendor risk, compliance posture, and AI governance. Key activities: weekly trust score review, AI system governance, board reporting.
- 1Review Org Trust Score™ at /trust-intelligence (weekly)
- 2Monitor critical risks at /risks — filter by status=critical
- 3Check AI governance posture at /ai-governance
- 4Review Security Command Center™ at /security-center — MFA compliance, active sessions, IP rules
- 5Generate board report at /executive-reporting/board-reports
- 6Review Governance Benchmarking™ at /benchmarking — percentile vs industry
Compliance Manager
Compliance Managers own framework readiness, evidence collection, gap analysis, and policy lifecycle. AUDT automates the evidence pipeline and generates audit-ready reports.
- 1Manage framework readiness at /compliance/frameworks
- 2Collect and map evidence at /compliance/evidence
- 3Run gap analysis at /compliance/gaps
- 4Review and publish policies at /compliance/policies
- 5Prepare compliance reports at /compliance/reports
- 6Track regulatory obligations at /regulatory-intelligence/obligations
Procurement Manager
Procurement Managers use AUDT's Vendor Hub™ to onboard, assess, and continuously monitor third-party vendors. AUDT automates document collection and risk scoring.
- 1Add new vendors at /vendors/new
- 2Request vendor documents at vendor detail → Documents tab
- 3Review vendor risk assessments
- 4Track vendor reviews at vendor detail → Reviews tab
- 5Monitor document expiry at /vendors?expiring=1
- 6Manage contracts at /contract-governance
Internal Auditor
Internal Auditors use AUDT to plan audits, generate programs from compliance controls, track findings, and produce board-ready reports — all in one platform.
- 1Plan audit at /audits/new
- 2Review audit program checklist at /audits/[id]
- 3Add findings at /audits/[id]/findings
- 4Create CAPAs at /audits/[id]/capas
- 5Generate audit report PDF
- 6Collaborate with external auditors at /auditor-collaboration
IT Administrator
IT Administrators manage team access, SSO configuration, MFA enforcement, and integration setup. AUDT's Security Command Center™ provides enterprise-grade identity controls.
- 1Manage team and RBAC at /settings/team — 7 roles available
- 2Configure SSO at /security-center (Entra ID, Okta, Google Workspace, SAML 2.0, OIDC)
- 3Manage MFA enforcement at /security-center (optional / required_admins / required_all)
- 4Set up integrations at /integration-hub — 35+ connectors
- 5Manage API keys at /settings/api-keys
- 6Review IP allow lists and session management at /security-center
Resources
Templates & Checklists
Downloadable templates to accelerate your governance program. New templates are added regularly.
Vendor Templates
Compliance Templates
Audit Templates
Policy Templates
Executive Insights
Why Vendor Governance Matters in 2025
Third-party breaches account for 60%+ of data incidents. Build a proactive vendor governance program before regulators require it.
5 min readBuilding a Third-Party Risk Program from Scratch
A practical 6-step framework for organizations starting their vendor risk journey. Covers scoping, tiering, assessment, and monitoring.
8 min readAudit Readiness Best Practices
How to reduce audit preparation time from weeks to hours. Continuous evidence collection and automated control validation are the keys.
6 min readReducing Compliance Costs with Automation
Manual compliance processes cost enterprises $3.5M annually on average. AUDT's evidence automation and continuous monitoring cut that by 60%+.
7 min readManaging AI Risk: The Governance Imperative
With EU AI Act and DPDP AI provisions in force, governing AI systems is no longer optional. A practical guide to AI inventory and risk scoring.
9 min readVendor Due Diligence in the Age of AI
AI-extracted document fields, automated risk scoring, and Trust Score™ signals are transforming how procurement teams assess vendors.
6 min readAI Agents
AUDT ships two layers of AI: Governance Agents that continuously monitor your posture and propose actions, and Module AI Assistants embedded inside every module for on-demand analysis and NL chat.
How AI Agents Work
All agents follow a four-stage lifecycle designed around human-in-the-loop governance. Agents observe, reason, and recommend — but they never mutate data without an explicit human approval.
Governance Agent Framework™
Six purpose-built agents monitor your governance posture continuously. Each agent has a defined module scope, configurable thresholds, and an execution schedule. Manage them at /agents.
Continuously scans your risk register for posture changes, new critical risks, and overdue treatment plans.
The Risk Monitor Agent runs on a configurable schedule (daily by default) across your entire Risk Lens™ register. It evaluates every open risk for score changes, overdue treatment deadlines, and missing owners. When it detects a deterioration — such as a risk whose inherent score has increased or a treatment plan that has passed its due date — it generates a structured Observation and raises a prioritised Recommendation for a human to act on.
- A risk transitions to Critical (score ≥ 80) with no active treatment plan
- A treatment action passes its due date without being completed
- A risk has had no review in more than 90 days
- A vendor-linked risk has no assigned owner
- More than 5 open Critical risks exist simultaneously
- Observations tagged severity: critical / high / medium / low
- Recommendations: 'Assign owner to risk X', 'Escalate overdue treatment Y'
- Agent Actions (awaiting human approval): auto-create a follow-up treatment, escalate to CISO
Monitors the entire vendor portfolio for document expiry, trust score decline, and missing assessments.
The Vendor Watch Agent tracks every active vendor across document validity, Trust Score™ trajectory, assessment recency, and review schedules. It pulls data from Vendor Hub™, Risk Lens™, and the Trust Score™ engine to build a consolidated health picture per vendor. When a vendor's posture deteriorates — expired SOC 2, declining Trust Score, or an overdue periodic review — the agent generates targeted observations and recommendations before the issue surfaces in an audit.
- A critical document (SOC 2, ISO cert, DPA) expires or will expire within 30 days
- A vendor Trust Score™ drops by more than 10 points in 7 days
- A vendor has had no security assessment in over 180 days
- A vendor review is overdue by more than 14 days
- A High-risk vendor has no linked compliance control
- Observations: 'Vendor Acme Corp SOC 2 expires in 12 days'
- Recommendations: 'Request updated ISO 27001 certificate from Vendor X'
- Agent Actions: auto-trigger a document request to the vendor portal
Watches framework readiness scores, control coverage gaps, and evidence health across all active frameworks.
The Compliance Guardian runs after every evidence upload, control status change, or gap analysis to check whether readiness scores are on track for upcoming audit deadlines. It understands the relationship between evidence, controls, and framework readiness — so when a piece of evidence expires, it immediately identifies which controls lose coverage and which frameworks are affected. It is particularly useful for organisations managing multiple frameworks simultaneously (e.g., ISO 27001 + SOC 2 + DPDP).
- A framework readiness score drops below a configured threshold (default 70%)
- An evidence item expires, leaving one or more controls uncovered
- A control status changes to 'not_implemented' on a critical framework
- A gap analysis detects a new Critical gap
- An audit deadline is within 60 days and readiness is below 80%
- Observations: 'ISO 27001 readiness dropped to 64% — 8 controls now uncovered'
- Recommendations: 'Upload renewed penetration test report to cover A.12.6.1'
- Agent Actions: auto-create evidence collection tasks in Issue Hub™
Ensures policies are current, attested, and linked to the controls and frameworks they govern.
The Policy Enforcer monitors your Policy Governance™ module for stale policies, missing attestations, and broken policy-to-control linkages. It knows that an unattested policy is as dangerous as no policy — so it tracks attestation completion rates per policy and per team member. It also validates that every active compliance control has at least one approved policy backing it, and alerts when that link breaks (e.g., a policy is archived without a replacement).
- A policy's review date has passed without a new version being published
- An active policy has less than 80% attestation completion after 14 days
- A policy is archived and leaves controls without policy coverage
- A new framework control is created with no linked policy
- A policy owner has left the organisation (membership deactivated)
- Observations: 'Acceptable Use Policy — 14 team members have not attested (deadline passed)'
- Recommendations: 'Send attestation reminders for Information Security Policy'
- Agent Actions: auto-send attestation reminder emails via Resend
Validates that all evidence, controls, and CAPAs are in order before an audit milestone.
The Audit Prep Agent is designed to be run 30–60 days before a scheduled audit. It performs a comprehensive pre-audit sweep: checks every audit program item for completion, validates that each finding has an associated CAPA, verifies that CAPAs are on track or completed, confirms evidence is current and mapped, and ensures the audit package documents are generated and up to date. Think of it as an automated audit readiness reviewer that flags every gap before the auditor sees it.
- An audit is within 60 days of its start date
- An audit program item has been pending for more than 14 days
- A finding has no CAPA assigned after 7 days
- A CAPA is overdue by more than its target date
- An audit report has not been generated within 7 days of audit completion
- Observations: 'Audit ISO-2025-Q2 — 6 program items still pending, 2 findings have no CAPA'
- Recommendations: 'Generate audit package for vendor Acme Corp before 15 Jan'
- Agent Actions: auto-generate audit program from framework controls, assign CAPA owners
Build your own governance agent with custom rules, module scope, thresholds, and schedule.
Custom Agents let you define governance automation that goes beyond the five built-in types. Using Agent Studio™ at /agents/studio, you select which modules the agent monitors, write plain-English rules (e.g., 'Alert if any vendor with risk level = High has no active contract'), set numeric thresholds, and choose an execution schedule. The agent runs on your schedule, evaluates your rules against live data, and generates observations and recommendations exactly like the built-in agents — with full audit trail and human-approval gates on any proposed action.
- Any condition you define: module-level data thresholds, status changes, date triggers
- Cross-module rules: e.g., 'Vendor risk is High AND no active contract exists'
- Composite conditions: e.g., 'Control health < 60% AND last test was > 90 days ago'
- Observations with your custom severity and label
- Recommendations with your configured action steps
- Agent Actions queued for human approval in /agents/actions
Module AI Assistants
Every AUDT module has a dedicated AI assistant powered by Google Gemini 2.5 Flash. These assistants provide on-demand analysis, cached executive summaries, and multi-turn NL chat — accessible from each module's AI tab.
Generates AI-written vendor briefs and executive summaries from assessment scores, document coverage, and risk exposure. Also powers NL search — type 'show high-risk SaaS vendors with expired SOC 2' and get filtered results.
A full AI governance advisor for compliance. Explains framework readiness scores, narrates gap findings in plain English, generates executive compliance summaries for board presentations, and answers live NL questions about your compliance posture.
Converts plain-English observations into structured audit findings (severity, description, affected control, recommendation). Generates CAPA suggestions for each finding. Produces board-ready audit executive reports. Answers questions like 'Which CAPAs are overdue?' in real time.
Generates a risk narrative for every risk — explaining the inherent score, linking it to affected assets and vendors, and recommending mitigation strategies. Produces a board-level risk executive report. Handles live questions like 'Summarise our top 5 cyber risks'.
Detects the top 5 control gaps across your entire control library — controls with low health scores, missing evidence, or no recent tests. Generates an executive summary suitable for a board risk committee. Answers live questions about specific controls.
Reviews policy content and suggests improvements, flags policies nearing review dates, and identifies controls that lack policy coverage. Embedded inline on the policy detail page.
Extracts key clauses and obligations from contract text, analyses clause risk levels, and generates an executive contract summary. Answers questions like 'Which contracts expire in Q1?' or 'Show contracts with no DPA clause'.
Converts governance observations into structured issues with severity, source module, and suggested owner. Generates a full remediation task plan for any open issue. Answers questions like 'Show all overdue critical issues' and summarises the overall remediation backlog.
The flagship AI assistant. Generates a comprehensive AI Governance Summary covering all 5 Org Trust Score™ components — suitable for board and executive presentations. Answers free-form questions about your entire governance posture across all modules.
Generates role-specific executive summaries (CEO, CRO, CISO, Compliance, Board), board-ready reports for 8 report types, and trend analysis narratives. Can answer questions like 'What's our governance trajectory over the last 90 days?'.
Specialised AI advisor for responsible AI governance. Reviews your AI system inventory, flags high-risk AI systems with inadequate controls, assesses compliance against ISO 42001 / EU AI Act / NIST AI RMF, and recommends governance actions.
Analyses the health of all connected integrations, identifies connectors that would improve evidence automation coverage, and recommends the highest-ROI integrations based on your compliance framework gaps.
Generates an industry benchmark executive report comparing your governance scores to sector peers, identifies which categories have the most improvement potential, and creates a personalised Improvement Planner™ with ranked actions.
Provides a cached regulatory advisory summary covering your most relevant regulations, analyses individual regulatory changes for impact on your controls and obligations, and generates a 4-panel Compliance Horizon™ forecast covering emerging risks, deadlines, global trends, and recommended actions.
Assesses your organisation's eligibility for each of the 10 verification programs (AUDT Verified™, Privacy Ready™, Enterprise Ready™, etc.), identifies the readiness gaps that would prevent certification, and provides a step-by-step preparation guide.
Reviews your security posture across MFA adoption, SSO configuration, session hygiene, IP allow list coverage, and AI prompt audit logs. Generates 5 prioritised security recommendations and an overall Security Readiness Score™ narrative.
Analyses your asset inventory for coverage gaps, high-criticality assets without owners or risk assessments, and PII assets without DPDP linkage. Performs dependency chain analysis to show the blast radius of a critical asset failure.
A dedicated NL chat interface for querying agent activity across all governance agents. Ask 'Which agents raised critical observations this week?', 'What actions are pending approval?', or 'Summarise the vendor watch agent findings for Q1'.
Reviews your automated check results, access review completions, attestation rates, and training compliance. Generates a Compliance Health™ narrative and per-check remediation guides for any failing checks.
Generates an Operations Advisory covering your event pipeline, active workflow instances, pending approvals, and automation rule effectiveness. Provides AI Decision Engine recommendations and workflow guidance.
Assesses audit readiness across all active audit rooms, identifies the top evidence gaps auditors are likely to flag, and generates AI-drafted findings from room activity. Answers questions about evidence request status and external finding trends.
Generates a Trust Network Reputation™ narrative explaining your 5-component network score, identifies the highest-ROI actions for improving your public trust presence, and provides a Network Improvement Plan™ with 4 prioritised actions.
Generates per-product API documentation, code samples, and integration guides for each of the 8 Trust API Platform™ products. Provides an integration health summary and recommends the highest-value API products for your platform tier.
Agent Lifecycle & Pages
The Governance Agent Framework™ spans 10 pages under /agents:
| Page | Route | What it does |
|---|---|---|
| Hub | /agents | KPI strip — total agents, runs today, pending approvals, observations this week. Recent runs + observations. 9-card module nav. |
| Registry | /agents/registry | All configured agents with type, execution mode, status, and key metrics (avg runs/week, observations generated, acceptance rate). |
| Studio | /agents/studio | Create and configure custom agents — select module scope, write rules in plain English, set thresholds, choose schedule. |
| Runs | /agents/runs | Full execution history — start time, duration, observations generated, recommendations created, actions proposed per run. |
| Observations | /agents/observations | All governance signals with severity badge, source module, linked entity, status (open/actioned/dismissed). Filter by severity, module, date. |
| Recommendations | /agents/recommendations | Prioritised action list — confidence ring (0–100), impact/effort labels, suggested steps. Accept or Dismiss each recommendation. |
| Actions | /agents/actions | Human approval queue — proposed system mutations waiting for Approve or Reject. Full action history below queue. |
| Orchestration | /agents/orchestration | Multi-agent pipelines — sequence agents to pass observations downstream. Run log shows which agents ran in each pipeline. |
| Analytics | /agents/analytics | Agent performance metrics — success rate, MTTR improvement, automation coverage %, observations per run, recommendation acceptance rate. |
| Copilot™ | /agents/copilot | Multi-turn NL governance chat — ask anything about agent activity, observations, recommendations, or posture across all modules. |
API & Integrations
Authentication
AUDT uses Bearer token authentication. Create API keys at /settings/api-keys. Two permission levels are available: read_only and read_write. Keys are shown once at creation and stored as a bcrypt hash.
Rate Limits
| Plan | Limit | Window |
|---|---|---|
| Growth (Trial) | 100 requests | 60 seconds |
| Growth | 300 requests | 60 seconds |
| Business | 1,000 requests | 60 seconds |
| Enterprise | Unlimited | — |
Key Endpoints
| Method | Endpoint | Description | Permission |
|---|---|---|---|
| GET | /api/v1/vendors | List vendors (paginated) | read_only |
| GET | /api/v1/vendors/[id]/trust-score | Vendor Trust Score™ with history | read_only |
| GET | /api/v1/compliance/frameworks | Frameworks with readiness | read_only |
| GET | /api/v1/compliance/gaps | Open compliance gaps | read_only |
| GET | /api/v1/audits | Audit list | read_only |
| POST | /api/v1/audits | Create audit | read_write |
| GET | /api/v1/findings | Org-wide findings | read_only |
| POST | /api/v1/findings | Create finding | read_write |
| GET | /api/v1/capas | Org-wide CAPAs | read_only |
| GET | /api/v1/risks | Risk register | read_only |
| POST | /api/v1/risks | Create risk | read_write |
| GET | /api/v1/risk-treatments | Treatment tracker | read_only |
| GET | /api/v1/trust-intelligence/overview | Full dashboard data | read_only |
| GET | /api/v1/trust-intelligence/org-score | Org Trust Score™ | read_only |
| GET | /api/v1/contracts | Contract list | read_only |
| GET | /api/v1/issues | Issue registry | read_only |
| GET | /api/v1/regulations | Regulation library | read_only |
| GET | /api/v1/obligations | Obligation list | read_only |
| GET | /api/v1/assets | Asset registry | read_only |
| GET | /api/v1/audit-logs | Audit event stream | read_only |
| GET | /api/v1/monitoring/alerts | Governance alerts | read_only |
| GET | /api/v1/registry | Public verification registry | public |
| GET | /api/v1/benchmarking | Governance benchmark dashboard | read_only |
| GET | /api/v1/benchmarking/rankings | Full rankings + maturity level | read_only |
| GET | /api/v1/ai/systems | AI system inventory | read_only |
| GET | /api/v1/agents | Governance agent list | read_only |
| GET | /api/v1/agent-runs | Agent execution history | read_only |
| GET | /api/v1/public/trust-score | Real-time org trust score (Trust API Platform™) | bearer |
| GET | /api/v1/public/verification | Proof-of-governance bundle | bearer |
| GET | /api/v1/public/benchmarking | Industry benchmark snapshot | bearer |
| GET | /api/health | Liveness/readiness probe — DB + config checks | public |
| GET | /api/docs | OpenAPI 3.1 JSON spec | public |
Error Handling
All errors return JSON with an error field. HTTP status codes follow REST conventions.
// AUDT API error response format:
// { "error": "string description", "code": "ERROR_CODE" (optional) }
// HTTP status codes:
// 200 OK
// 201 Created
// 400 Bad Request — invalid body, missing required fields
// 401 Unauthorized — missing or invalid Bearer token
// 403 Forbidden — key lacks required permission (read_write needed for POST/PUT/DELETE)
// 404 Not Found — resource does not exist in your organisation
// 422 Unprocessable Entity — valid JSON but business rule violation
// 429 Too Many Requests — rate limit exceeded (see Retry-After header)
// 500 Internal Server Error — contact support@audt.tech
// Rate limit headers on every response:
// X-RateLimit-Limit: 100
// X-RateLimit-Remaining: 87
// X-RateLimit-Reset: 1720000060
// Retry-After on 429:
// Retry-After: 60 (seconds)
// Example: robust fetch with retry
async function audtFetch(url, options = {}) {
const res = await fetch(url, {
...options,
headers: { Authorization: `Bearer ${AUDT_KEY}`, ...options.headers },
});
if (res.status === 429) {
const wait = parseInt(res.headers.get("Retry-After") ?? "60", 10);
await new Promise(r => setTimeout(r, wait * 1000));
return audtFetch(url, options);
}
if (!res.ok) {
const err = await res.json().catch(() => ({}));
throw new Error(err.error ?? `AUDT API ${res.status}`);
}
return res.json();
}cURL Examples
# Get Org Trust Score
curl -H "Authorization: Bearer tap_your_key" \
https://audt.tech/api/v1/trust-intelligence/org-score
# Create a Risk
curl -X POST -H "Authorization: Bearer tap_your_key" \
-H "Content-Type: application/json" \
-d '{"title":"Vendor data breach risk","category":"cyber_security","impact":4,"likelihood":3}' \
https://audt.tech/api/v1/risks
# Get Vendor Trust Score
curl -H "Authorization: Bearer tap_your_key" \
https://audt.tech/api/v1/vendors/{id}/trust-scoreJavaScript / TypeScript
No SDK required — use native fetch or any HTTP client. The API returns JSON on every endpoint.
// Install: no SDK needed — use fetch or axios
const AUDT_KEY = process.env.AUDT_API_KEY; // tap_...
const BASE = "https://audt.tech";
// Get Org Trust Score
async function getOrgTrustScore() {
const res = await fetch(`${BASE}/api/v1/trust-intelligence/org-score`, {
headers: { Authorization: `Bearer ${AUDT_KEY}` },
});
const data = await res.json();
// data.score: number, data.level: string, data.components: object
return data;
}
// Create a Risk
async function createRisk(title, category, impact, likelihood) {
const res = await fetch(`${BASE}/api/v1/risks`, {
method: "POST",
headers: {
Authorization: `Bearer ${AUDT_KEY}`,
"Content-Type": "application/json",
},
body: JSON.stringify({ title, category, impact, likelihood }),
});
return res.json(); // { id, title, score, ... }
}
// Get Vendor Trust Score with history
async function getVendorTrustScore(vendorId) {
const res = await fetch(`${BASE}/api/v1/vendors/${vendorId}/trust-score`, {
headers: { Authorization: `Bearer ${AUDT_KEY}` },
});
return res.json();
// .score, .level, .components, .history (30 days), .narrative
}
// List open risks (filter by status + category)
async function getOpenRisks() {
const params = new URLSearchParams({ status: "open", category: "cyber_security" });
const res = await fetch(`${BASE}/api/v1/risks?${params}`, {
headers: { Authorization: `Bearer ${AUDT_KEY}` },
});
return res.json(); // { data: Risk[], meta: { page, total } }
}Python
Use the requests library. All endpoints return JSON dictionaries matching the TypeScript types.
import os, requests
AUDT_KEY = os.environ["AUDT_API_KEY"] # tap_...
BASE = "https://audt.tech"
HEADERS = {"Authorization": f"Bearer {AUDT_KEY}"}
# Get Org Trust Score
def get_org_trust_score():
r = requests.get(f"{BASE}/api/v1/trust-intelligence/org-score", headers=HEADERS)
r.raise_for_status()
return r.json() # { score, level, components }
# Create a Risk
def create_risk(title, category, impact, likelihood):
payload = {"title": title, "category": category,
"impact": impact, "likelihood": likelihood}
r = requests.post(f"{BASE}/api/v1/risks", json=payload, headers=HEADERS)
r.raise_for_status()
return r.json() # { id, title, score, ... }
# Get all frameworks with readiness
def get_frameworks():
r = requests.get(f"{BASE}/api/v1/compliance/frameworks", headers=HEADERS)
r.raise_for_status()
return r.json() # [{ id, name, readinessScore, controlCount }]
# Paginate through vendors
def get_all_vendors():
vendors, page = [], 1
while True:
r = requests.get(f"{BASE}/api/v1/vendors?page={page}&pageSize=50",
headers=HEADERS)
data = r.json()
vendors.extend(data["data"])
if page >= data["meta"]["totalPages"]:
break
page += 1
return vendorsWebhooks
Register webhooks at /trust-api/webhooks. AUDT delivers a POST to your endpoint for each subscribed event. Expects a 200 response within 10 seconds, then retries.
// Register a webhook at /trust-api/webhooks
// AUDT delivers POST to your endpoint for each subscribed event.
// 1. Verify the payload (check x-audt-signature header)
// 2. Process the event type
// 3. Return 200 OK within 10 seconds (AUDT retries on timeout)
// Node.js webhook handler (Express)
app.post("/audt-webhook", express.raw({ type: "application/json" }), (req, res) => {
const event = JSON.parse(req.body.toString());
switch (event.event_type) {
case "trust_score.dropped":
// event.data: { vendor_id, old_score, new_score, delta }
console.log("Trust score dropped for", event.data.vendor_id);
break;
case "evidence.expired":
// event.data: { evidence_id, vendor_id, expired_at }
notifyTeam("Evidence expired: " + event.data.evidence_id);
break;
case "risk.critical":
// event.data: { risk_id, title, score, vendor_id }
escalateRisk(event.data);
break;
}
res.status(200).json({ received: true });
});
// Available event types:
// trust_score.dropped trust_score.improved evidence.expired
// evidence.expiring_soon risk.critical vendor.status_changed
// contract.expiring capa.overdue audit.completedTrust Score API
The Trust Score endpoints return structured breakdowns useful for embedding in external dashboards, SIEM integrations, or BI tools.
// Vendor Trust Score™ — full breakdown
GET /api/v1/vendors/{id}/trust-score
Response:
{
"score": 82,
"level": "Strong", // Exceptional | Trusted | Strong | Moderate | Needs Attention | High Concern
"components": {
"evidence": { "score": 75, "weight": 0.20, "weighted": 15.0 },
"risk": { "score": 85, "weight": 0.20, "weighted": 17.0 },
"compliance": { "score": 80, "weight": 0.15, "weighted": 12.0 },
"assessment": { "score": 90, "weight": 0.15, "weighted": 13.5 },
"contract": { "score": 70, "weight": 0.10, "weighted": 7.0 },
"operational": { "score": 80, "weight": 0.10, "weighted": 8.0 },
"freshness": { "score": 90, "weight": 0.10, "weighted": 9.0 }
},
"history": [ // last 30 daily snapshots
{ "date": "2026-06-28", "score": 82 },
{ "date": "2026-06-27", "score": 79 }
],
"narrative": "Vendor X maintains a Strong trust posture...",
"strengths": ["Assessment score 90/100", "Evidence up to date"],
"concerns": ["Contract expires in 45 days", "2 open risks"]
}
// Org Trust Score™
GET /api/v1/trust-intelligence/org-score
Response:
{
"score": 74,
"level": "Moderate",
"components": {
"vendorTrust": { "score": 78, "weight": 0.25, "weighted": 19.5 },
"riskPosture": { "score": 70, "weight": 0.25, "weighted": 17.5 },
"controlHealth": { "score": 75, "weight": 0.20, "weighted": 15.0 },
"auditReadiness": { "score": 65, "weight": 0.15, "weighted": 9.75 },
"complianceCoverage": { "score": 80, "weight": 0.15, "weighted": 12.0 }
}
}Integrations
35+ connectors across 11 categories. Phase 1 connectors cover ~80% of prospect requirements.
Phase 1 Connectors
How to Connect
Go to /integration-hub/marketplace → click connector → Configure → enter credentials → Test Connection → Save. Credentials are stored AES-256-GCM encrypted.