AAUDTDocs

Welcome to AUDT

AI-Native Trust, Risk & Compliance Platform — Governance OS

Replace spreadsheets and disconnected tools with a single AI-native platform for vendor governance, compliance, audits, risk, board governance, regulatory intelligence, and more. 32 modules. 259+ tables. Governance built on proof.

Quick Actions

🏢Onboard a Vendor
⚠️Assess Vendor Risk
🛡️Collect Compliance Evidence
🔍Run a Compliance Assessment
📋Prepare for an Audit
📝Create & Manage Policies
📊Review Compliance Status
Automate Governance (TOE)
🤖Govern AI Systems

Your First 15 Minutes

GoalGet a working AUDT workspace with a vendor, a framework, and a populated dashboard.
Time Required15 minutes
PrerequisitesA new AUDT account and your team members' emails.
Expected OutcomeAn organization with team, a first vendor, a selected framework, and a live Org Trust Score™.
  1. 1✅ Create Organization (/onboarding) — Set up your organization, industry, and company size in the 3-step onboarding wizard.
  2. 2👥 Invite Team Members (/settings/team) — Add teammates and assign roles: owner, admin, compliance_manager, security_manager, procurement_manager, member, viewer.
  3. 3🏢 Add Your First Vendor (/vendors → New Vendor) — Create a vendor record with name, website, category, and risk level.
  4. 4📋 Select Compliance Framework (/compliance/frameworks → New) — Choose from ISO 27001, SOC 2, DPDP, PCI DSS, HIPAA.
  5. 5📎 Upload Evidence (/compliance/evidence → New Evidence) — Attach evidence items and map them to controls.
  6. 6📊 Review Dashboard (/dashboard) — See your Org Trust Score™, compliance readiness, and open risks at a glance.

Platform Overview

AUDT replaces spreadsheets and disconnected tools with a single AI-native platform for vendor governance, compliance, audits, risk, and board governance. Every action flows into a unified trust posture that is continuously scored, monitored, and reported.

Vendor Lifecycle

1
Discover
2
Assess
3
Onboard
4
Monitor
5
Review
6
Offboard

Compliance Lifecycle

1
Framework
2
Controls
3
Evidence
4
Assessment
5
Remediation
6
Audit

Scoring Engines

Org Trust Score™

Vendor Trust (25%)Risk Posture (25%)Control Health (20%)Audit Readiness (15%)Compliance Coverage (15%)

Vendor Trust Score™

Evidence (20%)Risk (20%)Compliance (15%)Assessment (15%)Contract (10%)Operational (10%)Freshness (10%)

Control Health™

Evidence (30%)Testing (25%)Audit (15%)Policy (10%)Freshness (10%)Risk Reduction (10%)

Trust Score™ Deep Dive

The Vendor Trust Score™ is a 0–100 composite signal computed from 7 weighted components. It updates on every meaningful governance action — document upload, assessment completion, risk change, contract update. A score ≥ 90 is Trusted. Below 60 is High Concern.

Score Levels

LevelRangeMeaning
Exceptional95–100Best-in-class governance. All components healthy.
Trusted90–94Strong posture. Minor gaps tolerated.
Strong80–89Good governance. One or two areas need attention.
Moderate70–79Governance present but inconsistent. Prioritise weakest component.
Needs Attention60–69Material gaps. Remediation plan required.
High Concern0–59Critical governance failure. Escalate immediately.

Components & How to Improve Them

ComponentWeightHow to improve
Evidence20%Upload more vendor documents. Keep expiry dates current. Map docs to controls.
Risk20%Treat open risks. Close critical risks. Remove duplicate risk entries.
Compliance15%Improve framework readiness. Close gaps. Map evidence to controls.
Assessment15%Run a fresh security assessment. Score ≥ 80 maximises this component.
Contract10%Add contract records. Track expiry. Complete open obligations.
Operational10%Complete periodic vendor reviews. Respond to document requests promptly.
Freshness10%Conduct a review within 30 days. Refresh stale assessments.
💡The Vendor Trust Score™ feeds into the Org Trust Score™ as the Vendor Trust component (25% weight). Improving your bottom 3 vendor scores has the highest leverage on the org-level number.

Trust Operations Engine™

The Trust Operations Engine™ (TOE) is the orchestration layer that connects every governance module into an automated, event-driven platform. It transforms AUDT from a record-keeping system into a proactive governance intelligence platform that closes the loop on every governance signal.

1
Event Occurs
2
Event Published
3
Workflow Triggered
4
Approvals Requested
5
AI Decision
6
Action Taken
7
Audit Trail

The Four Layers

  1. 1Event Engine — 37 built-in event types. Every vendor action, risk change, evidence expiry, and compliance gap triggers an event automatically.
  2. 2Workflow Engine — 6 built-in workflows: Vendor Onboarding, Evidence Expiry Response, Trust Score Drop, Contract Renewal, Vendor Offboarding, Critical Risk Escalation. Plus custom workflows via /operations/workflows.
  3. 3Automation Engine — No-code if-this-then-that rules. Connect any event to any action: create risk, assign task, request evidence, send notification, escalate for approval.
  4. 4AI Decision Engine — AI generates recommendations with confidence scores and suggested actions. All proposed mutations require human approval at /operations/approvals — no autonomous data changes.
💡Start with the Vendor Onboarding workflow template at /operations/workflows. It automates document requests, assessment scheduling, and approval routing for every new vendor.

Use Cases

Eight complete, step-by-step workflows covering the most common AUDT operations.

UC1: Onboard a New Vendor

GoalRegister, assess, and approve a new third-party vendor.
Time Required20–30 minutes
PrerequisitesOwner or procurement_manager role; vendor contact email.
Expected OutcomeAn approved vendor with documents collected, fields extracted, and a security assessment score.
1
Create Vendor
2
Assign Owner
3
Request Documents
4
Review Responses
5
Risk Assessment
6
Approval
  1. 1Go to /vendors → New Vendor. Enter name, website, category (SaaS/Cloud/IT Services/etc.), risk level, country.
  2. 2Assign an owner from your team. Owner receives notifications for expiries and reviews.
  3. 3Go to vendor detail → Documents tab → Request Documents. Select from required doc types (SOC 2, ISO cert, DPA, etc.).
  4. 4Vendor receives magic-link portal email. They upload at /portal/[token] — no account needed.
  5. 5Review uploaded documents. AI auto-extracts: issuer, validity dates, coverage scope, certification body.
  6. 6Go to Assessment tab → launch Security Assessment (17 questions). Score computed automatically.
  7. 7Once score ≥ 60 and required docs present, vendor status auto-advances to "approved".
💡Use Vendor Types (templates) to pre-define required document checklists for each vendor category.

UC2: Assess Vendor Risk

GoalIdentify, score, and treat a risk associated with a vendor.
Time Required10–15 minutes
PrerequisitesAn existing vendor record.
Expected OutcomeA scored risk with a treatment plan, linked to relevant entities and visible on the heat map.
1
Open Risk Tab
2
Set Impact/Likelihood
3
Score Computed
4
Add Treatment
5
Link Entities
6
Monitor
  1. 1Open vendor detail → Risk tab → Add Risk or /risks/new
  2. 2Set category (cyber_security, compliance, vendor, privacy, etc.), impact (1–5), likelihood (1–5)
  3. 3AUDT computes inherent score = impact × likelihood × 4 (max 100)
  4. 4Add treatment: strategy (mitigate/accept/transfer/avoid), assign owner, set due date
  5. 5Link risk to vendor, relevant controls, compliance frameworks
  6. 6Monitor via /risks dashboard — heat map shows all risks by impact × likelihood

UC3: Collect Compliance Evidence

GoalGather and map evidence to compliance controls.
Time Required15 minutes
PrerequisitesAt least one compliance framework added.
Expected OutcomeEvidence items mapped to controls, improving framework readiness coverage.
1
New Evidence
2
Set Type
3
Upload/Link
4
Map to Controls
5
Check Coverage
6
Review Gaps
  1. 1Go to /compliance/evidence → New Evidence
  2. 2Set title, type (document/assessment/review/policy/other), status (collected/pending/expired)
  3. 3Upload file OR link from vendor documents (auto-import available)
  4. 4Map to controls: Evidence → Map to Control
  5. 5Each mapping contributes to control readiness. Framework readiness = covered/total controls
  6. 6Check gaps at /compliance/gaps — 5 automated gap rules
💡Go to Evidence → Auto-Import from Vendors to pull approved vendor docs as evidence automatically.

UC4: Run a Compliance Assessment

GoalAssess readiness against a framework and produce a report.
Time Required30–60 minutes
PrerequisitesA framework with controls selected.
Expected OutcomeA complete readiness assessment with gap analysis and a shareable PDF report.
1
Select Framework
2
Review Controls
3
Update Status
4
Run Gap Analysis
5
Generate Report
6
Share
  1. 1Go to /compliance/frameworks → select framework
  2. 2Review all controls — each shows: status, linked evidence count, owner
  3. 3For each control: update status, link evidence, add notes
  4. 4Run Gap Analysis: /compliance/gaps → 5 gap types: missing evidence, expired evidence, unimplemented controls, no policy coverage, no control owner
  5. 5Generate report: /compliance/reports → Framework PDF or Executive PDF (AI-narrated)
  6. 6Share with auditor or board from reports page

UC5: Prepare for an Audit

GoalPlan an audit, track findings, and produce a board-ready report.
Time Required1–2 hours
PrerequisitesA compliance framework and collected evidence.
Expected OutcomeA completed audit with findings, CAPAs, and an exportable audit report.
1
Create Audit
2
Auto-Generate Program
3
Review Items
4
Add Findings
5
Create CAPAs
6
Generate Report
  1. 1Go to /audits/new → create audit (name, type, framework link, scope, auditor)
  2. 2AUDT auto-generates audit program from framework controls
  3. 3Review each program item: mark reviewed/passed/failed
  4. 4Add findings: /audits/[id]/findings → AI can convert observations into structured findings
  5. 5For each finding, create CAPA: assign owner, due date, remediation steps
  6. 6Generate Audit Package: vendor detail → Audit Package — exports vendor docs, assessment, risk summary
  7. 7Generate Audit Report PDF: /reports/audits/[id]

UC6: Create & Manage Policies

GoalAuthor, publish, and track attestation of organizational policies.
Time Required20 minutes
Prerequisitescompliance_manager or admin role.
Expected OutcomeA published policy with attestation tracking and a scheduled review date.
1
New Policy
2
Set Metadata
3
Draft
4
Review
5
Publish
6
Attest
7
Track Reviews
  1. 1Go to /compliance/policies → New Policy
  2. 2Set: title, description, version, category, owner, effective date, review date
  3. 3Save as Draft → review → change status to Active to publish
  4. 4Map policy to compliance frameworks and controls
  5. 5Assign attestation — team members confirm they have read the policy
  6. 6Track reviews: set next review date. AUDT alerts when review is due.

UC7: Review Compliance Status (Executive View)

GoalGet a board-level view of organizational governance posture.
Time Required10 minutes
PrerequisitesOrg with vendors, risks, and compliance data populated.
Expected OutcomeAn executive summary and board-ready report covering all trust dimensions.
1
View Trust Score
2
Drill Components
3
Check Recommendations
4
Review Trends
5
Generate Summary
6
Export Report
  1. 1Go to /trust-intelligence — Org Trust Score™ ring shows 0–100 score
  2. 2Drill into components: Vendor Trust, Risk Posture, Control Health, Audit Readiness, Compliance Coverage
  3. 3Review Recommendations tab for prioritized actions with impact/effort ratings
  4. 4Check Trends tab for 90-day governance trend sparklines
  5. 5Generate AI Executive Summary from Executive View tab (Governance Copilot™)
  6. 6Export board report at /executive-reporting/board-reports

UC8: Automate Governance with Trust Operations Engine™

GoalConnect governance events across modules to automated workflows and approval queues.
Time Required15–20 minutes
PrerequisitesActive vendors, risks, or compliance frameworks in the platform.
Expected OutcomeGovernance events automatically trigger workflows, route approvals, and fire automation rules — reducing manual follow-up.
1
Review Event Stream
2
Choose Workflow Template
3
Start Instance
4
Monitor Steps
5
Approve Actions
6
View Analytics
  1. 1Go to /operations/events — see the live event stream across all 37 event types (vendor.document_expired, risk.score_critical, control.health_low, etc.)
  2. 2Go to /operations/workflows — choose from 6 built-in templates: Vendor Onboarding, Evidence Expiry Response, Trust Score Drop Response, Contract Renewal, Vendor Offboarding, Critical Risk Escalation
  3. 3Click Start Workflow on any template — fill in parameters, assign owner
  4. 4Monitor active instances at /operations/workflows — each step shows pending/in_progress/completed/failed status
  5. 5Go to /operations/approvals — review pending approvals and approve or reject with notes
  6. 6Create automation rules at /operations/automation — define event→action triggers (e.g., 'When trust score drops below 60, create a risk review task')
  7. 7View /operations/analytics for workflow SLA metrics, completion rates, and historical throughput
💡Use /operations/command-center for a real-time cross-module governance snapshot — critical items needing attention surface automatically.

UC9: Govern AI Systems

GoalInventory, risk-assess, and monitor AI systems for responsible governance.
Time Required20–30 minutes
Prerequisitesadmin or security_manager role.
Expected OutcomeAn AI system in the inventory with linked risks, controls, and an AI Trust Score™.
1
Add AI System
2
Set Classification
3
Link Risks
4
Map Controls
5
Check Compliance
6
Monitor Trust Score
  1. 1Go to /ai-governance/inventory → Add AI System
  2. 2Set: name, type (llm/ml_model/automation/decision_support), vendor, deployment env, risk classification
  3. 3Link AI risks: type (hallucination/bias/privacy_leakage/prompt_injection/etc.), impact, likelihood
  4. 4Map to AI controls: human oversight, output review, prompt logging, model approval
  5. 5Check compliance: AUDT maps to ISO 42001, NIST AI RMF, EU AI Act, DPDP AI
  6. 6Monitor via AI Trust Score™ — Risk(25%), Controls(25%), Compliance(20%), Monitoring(15%), Vendor(10%), Incidents(5%). Set up automation rules at /operations/automation to trigger alerts when AI risk scores breach thresholds.

Module Reference

AUDT ships 32 governance modules across six groups. Each module is self-contained with its own data layer, services, AI assistant, and REST API surface.

Core GRC

Vendor Hub™/vendors

Central vendor registry with AI-powered document processing and Trust Score™ engine.

Features: 25-column vendor registry, document management with AI extraction (10 fields), magic-link vendor portal, Trust Score™, NL search.

Workflow: Add vendor → Request documents → Auto-extract fields → Risk assess → Approve

Evidence Vault™/compliance

Unified compliance management across 5 frameworks with 174 built-in controls.

Features: 10 compliance tables, 174 built-in controls across 5 frameworks, auto-import from vendors, gap analysis, AI Officer™.

Workflow: Select framework → Map controls → Collect evidence → Run gap analysis → Generate report

Audit Management/audits

End-to-end audit lifecycle from planning to board-ready reports.

Features: Full audit lifecycle, auto-generated audit program, AI finding generator, CAPA tracker, PDF reports.

Workflow: Plan audit → Generate program → Review items → Add findings → Create CAPAs → Generate report

Risk Lens™/risks

Visual risk intelligence with heat map and AI-powered risk officer.

Features: 5×5 heat map, 13 risk categories, treatment tracking, AI Risk Officer™, treatment strategies.

Workflow: Identify risk → Score impact/likelihood → Add treatment → Link to framework → Monitor

Control Center™/controls

Control effectiveness scoring and continuous testing platform.

Features: Control Health™ scoring (6 components), test logging, AI gap detection, framework mapping.

Workflow: Create control → Link evidence → Run tests → Compute health score → Review gaps

Intelligence

Trust Intelligence™/trust-intelligence

Executive governance command center with Org Trust Score™.

Features: Org Trust Score™ (5 components), 9-tab command center, Governance Copilot™, recommendations engine.

Workflow: View score → Drill components → Review recommendations → Generate summary

Governance Trends™

90-day governance trend monitoring across 6 key metrics.

Features: 90-day sparklines for 6 metrics, change % vs period start, 30-row score history.

Continuous Monitoring™

Automated governance monitoring with 7 rule engine.

Features: 7 automated monitoring rules, auto-generated alerts, resolve workflow.

Trust Graph™

Force-directed governance knowledge graph with AI reasoning.

Features: Force-directed SVG visualization, Root Cause Analysis™, Impact Analysis™, Governance Reasoner™.

Operations

Trust Operations Engine™/operations

Event-driven orchestration layer connecting every governance capability into one intelligent platform.

Features: 37 built-in event types, 6 workflow templates, unified approval queue, automation rules engine, AI Decision Engine, Operations Copilot™.

Workflow: Publish event → Match workflow → Run steps → Approve actions → Monitor analytics

Issue & Remediation Hub™/issue-hub

Centralized governance issue registry with SLA tracking.

Features: Issue registry, task management, exception management, escalation engine, SLA tracking.

Workflow Studio™

Governance automation engine with approval workflows.

Features: Workflow definitions, approval workflows, AI workflow generator, run history.

Trust Network

Third-Party Risk Exchange™/trust-exchange

Public trust marketplace for vendor evidence sharing.

Features: Trust profiles, evidence exchange, badges, questionnaire exchange, vendor directory.

Governance Benchmarking™/benchmarking

Industry peer comparison across 10 governance categories.

Features: 10 category scorecards, percentile ranking, Governance Rankings™, 6-month trends.

Integration Hub™/integration-hub

Connectivity layer with 35+ pre-built connectors.

Features: 35+ connectors, sync engine, evidence automation, webhook engine, connection health.

Trust Network™

Public trust infrastructure aggregating all trust signals.

Features: Trust reputation score, governance maturity ladder, network directory, activity feed.

Enterprise

Executive Reporting & Analytics™/executive-reporting

Role-specific dashboards and predictive governance analytics.

Features: 6 role dashboards (CEO/CRO/CISO/Compliance/Board/Custom), board reports, predictive forecasting, scorecards.

AI Governance™/ai-governance

Responsible AI governance platform for AI system risk management.

Features: AI system inventory, AI Trust Score™, EU AI Act compliance, ISO 42001, incident tracking.

Auditor Collaboration™/auditor-collaboration

Secure external auditor engagement platform.

Features: Secure audit rooms, evidence exchange, external findings, assessment projects, auditor user management.

Trust API Platform™/trust-api

Trust-as-infrastructure API with 8 products and developer portal.

Features: 8 API products, webhooks, developer portal, usage analytics, AI API builder.

Trust Verification Authority™/trust-verification

Certification authority for governance trust.

Features: 10 verification programs, 9-step workflow, Trust Certificates™, public /verify/[id] page.

Continuous Compliance™

Always-on compliance automation with 21 automated checks.

Features: 21 automated checks, access reviews, attestations, training campaigns, Compliance Health™ score.

Governance Agent Framework™/agents

AI agents for proactive governance monitoring.

Features: 6 agent types, observations, recommendations, human-approved actions, Governance Copilot™.

Regulatory Intelligence™/regulatory-intelligence

Real-time regulatory tracking for 18+ regulations.

Features: 18 built-in regulations (India + global), change monitor, obligations, Compliance Horizon™.

Asset Intelligence™/asset-intelligence

Enterprise asset graph with trust mapping.

Features: 12 asset types, Asset Trust Score™, dependency graph, PII tracking, alerts.

Security Command Center™/security-center

Enterprise security platform for regulated industries.

Features: MFA management, Enterprise SSO, session management, IP allow lists, AI prompt audit, Customer Managed Encryption.

Compliance Framework Center

AUDT ships with 174 built-in controls across five frameworks. Add a framework at /compliance/frameworks to begin tracking readiness.

ISO 27001

93 controls · 14 domains

Domains

Information Security PoliciesOrganizationHuman Resource SecurityAsset ManagementAccess ControlCryptographyPhysical SecurityOperations SecurityCommunications SecuritySystem AcquisitionSupplier RelationshipsIncident ManagementBusiness ContinuityCompliance

Evidence: Policy documents, access logs, risk assessments, incident records, supplier contracts.

Route: /compliance/frameworks → ISO 27001

SOC 2

33 controls · 5 Trust Services Criteria

Domains

Security (CC)Availability (A)Processing Integrity (PI)Confidentiality (C)Privacy (P)

Evidence: SOC 2 reports, penetration test results, access reviews, encryption documentation.

PCI DSS

12 controls

Domains

Network securityCardholder data protectionVulnerability managementAccess controlMonitoringSecurity policy

Evidence: Network diagrams, scan reports, penetration tests, access control logs, training records.

HIPAA

18 controls · 3 safeguard groups

Domains

AdministrativePhysicalTechnical

Evidence: Risk analysis, workforce training, access controls, audit logs, business associate agreements.

DPDP (India)

18 controls · DPDP Act 2023

Domains

Consent managementData principal rights (DSR)Data fiduciary obligationsCross-border transfer restrictionsBreach notification

Evidence: Consent records, DSR logs, retention schedules, breach notification records, privacy assessments.

Dedicated module: /privacy · Data residency: Mumbai (ap-south-1).

Role Guides

Recommended workflows tailored to each role in your governance team.

CISO

CISOs use AUDT to maintain end-to-end visibility across vendor risk, compliance posture, and AI governance. Key activities: weekly trust score review, AI system governance, board reporting.

  1. 1Review Org Trust Score™ at /trust-intelligence (weekly)
  2. 2Monitor critical risks at /risks — filter by status=critical
  3. 3Check AI governance posture at /ai-governance
  4. 4Review Security Command Center™ at /security-center — MFA compliance, active sessions, IP rules
  5. 5Generate board report at /executive-reporting/board-reports
  6. 6Review Governance Benchmarking™ at /benchmarking — percentile vs industry

Compliance Manager

Compliance Managers own framework readiness, evidence collection, gap analysis, and policy lifecycle. AUDT automates the evidence pipeline and generates audit-ready reports.

  1. 1Manage framework readiness at /compliance/frameworks
  2. 2Collect and map evidence at /compliance/evidence
  3. 3Run gap analysis at /compliance/gaps
  4. 4Review and publish policies at /compliance/policies
  5. 5Prepare compliance reports at /compliance/reports
  6. 6Track regulatory obligations at /regulatory-intelligence/obligations

Procurement Manager

Procurement Managers use AUDT's Vendor Hub™ to onboard, assess, and continuously monitor third-party vendors. AUDT automates document collection and risk scoring.

  1. 1Add new vendors at /vendors/new
  2. 2Request vendor documents at vendor detail → Documents tab
  3. 3Review vendor risk assessments
  4. 4Track vendor reviews at vendor detail → Reviews tab
  5. 5Monitor document expiry at /vendors?expiring=1
  6. 6Manage contracts at /contract-governance

Internal Auditor

Internal Auditors use AUDT to plan audits, generate programs from compliance controls, track findings, and produce board-ready reports — all in one platform.

  1. 1Plan audit at /audits/new
  2. 2Review audit program checklist at /audits/[id]
  3. 3Add findings at /audits/[id]/findings
  4. 4Create CAPAs at /audits/[id]/capas
  5. 5Generate audit report PDF
  6. 6Collaborate with external auditors at /auditor-collaboration

IT Administrator

IT Administrators manage team access, SSO configuration, MFA enforcement, and integration setup. AUDT's Security Command Center™ provides enterprise-grade identity controls.

  1. 1Manage team and RBAC at /settings/team — 7 roles available
  2. 2Configure SSO at /security-center (Entra ID, Okta, Google Workspace, SAML 2.0, OIDC)
  3. 3Manage MFA enforcement at /security-center (optional / required_admins / required_all)
  4. 4Set up integrations at /integration-hub — 35+ connectors
  5. 5Manage API keys at /settings/api-keys
  6. 6Review IP allow lists and session management at /security-center

Resources

Templates & Checklists

Downloadable templates to accelerate your governance program. New templates are added regularly.

Vendor Templates

Vendor Risk Assessment TemplateComing Soon
Vendor Due Diligence ChecklistComing Soon
Vendor Review ChecklistComing Soon
Vendor Security QuestionnaireComing Soon
Vendor Offboarding ChecklistComing Soon

Compliance Templates

ISO 27001 Readiness ChecklistComing Soon
SOC 2 Preparation ChecklistComing Soon
PCI DSS Requirements ChecklistComing Soon
HIPAA Safeguards ChecklistComing Soon
DPDP Compliance ChecklistComing Soon

Audit Templates

Audit Preparation ChecklistComing Soon
Evidence Collection TemplateComing Soon
Audit Finding TemplateComing Soon
Remediation Plan TemplateComing Soon
CAPA Tracking TemplateComing Soon

Policy Templates

Information Security PolicyComing Soon
Acceptable Use PolicyComing Soon
Data Classification PolicyComing Soon
Incident Response PolicyComing Soon
Vendor Management PolicyComing Soon

Executive Insights

Why Vendor Governance Matters in 2025

Third-party breaches account for 60%+ of data incidents. Build a proactive vendor governance program before regulators require it.

5 min read

Building a Third-Party Risk Program from Scratch

A practical 6-step framework for organizations starting their vendor risk journey. Covers scoping, tiering, assessment, and monitoring.

8 min read

Audit Readiness Best Practices

How to reduce audit preparation time from weeks to hours. Continuous evidence collection and automated control validation are the keys.

6 min read

Reducing Compliance Costs with Automation

Manual compliance processes cost enterprises $3.5M annually on average. AUDT's evidence automation and continuous monitoring cut that by 60%+.

7 min read

Managing AI Risk: The Governance Imperative

With EU AI Act and DPDP AI provisions in force, governing AI systems is no longer optional. A practical guide to AI inventory and risk scoring.

9 min read

Vendor Due Diligence in the Age of AI

AI-extracted document fields, automated risk scoring, and Trust Score™ signals are transforming how procurement teams assess vendors.

6 min read

AI Agents

AUDT ships two layers of AI: Governance Agents that continuously monitor your posture and propose actions, and Module AI Assistants embedded inside every module for on-demand analysis and NL chat.

How AI Agents Work

All agents follow a four-stage lifecycle designed around human-in-the-loop governance. Agents observe, reason, and recommend — but they never mutate data without an explicit human approval.

1
👁️ Observe
2
🧠 Reason
3
💡 Recommend
4
✅ Human Approves → Act
👁️
Observation
A structured signal generated by an agent — severity (critical/high/medium/low/info), source module, linked entity, and a human-readable description.
💡
Recommendation
A prioritised suggested action derived from one or more observations. Includes confidence score (0–100), impact label, effort label, and step-by-step suggested actions.
Agent Action
A proposed system mutation (e.g., create a task, send a reminder, trigger a document request). Sits in the approval queue at /agents/actions until a human approves or rejects it.

Governance Agent Framework™

Six purpose-built agents monitor your governance posture continuously. Each agent has a defined module scope, configurable thresholds, and an execution schedule. Manage them at /agents.

⚠️
Risk Monitor Agent
risk_monitorScheduled · Real-time/agents/registry

Continuously scans your risk register for posture changes, new critical risks, and overdue treatment plans.

The Risk Monitor Agent runs on a configurable schedule (daily by default) across your entire Risk Lens™ register. It evaluates every open risk for score changes, overdue treatment deadlines, and missing owners. When it detects a deterioration — such as a risk whose inherent score has increased or a treatment plan that has passed its due date — it generates a structured Observation and raises a prioritised Recommendation for a human to act on.

🎯 Trigger conditions
  • A risk transitions to Critical (score ≥ 80) with no active treatment plan
  • A treatment action passes its due date without being completed
  • A risk has had no review in more than 90 days
  • A vendor-linked risk has no assigned owner
  • More than 5 open Critical risks exist simultaneously
📤 Outputs
  • Observations tagged severity: critical / high / medium / low
  • Recommendations: 'Assign owner to risk X', 'Escalate overdue treatment Y'
  • Agent Actions (awaiting human approval): auto-create a follow-up treatment, escalate to CISO
🏢
Vendor Watch Agent
vendor_watchScheduled · Real-time/agents/registry

Monitors the entire vendor portfolio for document expiry, trust score decline, and missing assessments.

The Vendor Watch Agent tracks every active vendor across document validity, Trust Score™ trajectory, assessment recency, and review schedules. It pulls data from Vendor Hub™, Risk Lens™, and the Trust Score™ engine to build a consolidated health picture per vendor. When a vendor's posture deteriorates — expired SOC 2, declining Trust Score, or an overdue periodic review — the agent generates targeted observations and recommendations before the issue surfaces in an audit.

🎯 Trigger conditions
  • A critical document (SOC 2, ISO cert, DPA) expires or will expire within 30 days
  • A vendor Trust Score™ drops by more than 10 points in 7 days
  • A vendor has had no security assessment in over 180 days
  • A vendor review is overdue by more than 14 days
  • A High-risk vendor has no linked compliance control
📤 Outputs
  • Observations: 'Vendor Acme Corp SOC 2 expires in 12 days'
  • Recommendations: 'Request updated ISO 27001 certificate from Vendor X'
  • Agent Actions: auto-trigger a document request to the vendor portal
🛡️
Compliance Guardian
compliance_guardianScheduled · Event-driven/agents/registry

Watches framework readiness scores, control coverage gaps, and evidence health across all active frameworks.

The Compliance Guardian runs after every evidence upload, control status change, or gap analysis to check whether readiness scores are on track for upcoming audit deadlines. It understands the relationship between evidence, controls, and framework readiness — so when a piece of evidence expires, it immediately identifies which controls lose coverage and which frameworks are affected. It is particularly useful for organisations managing multiple frameworks simultaneously (e.g., ISO 27001 + SOC 2 + DPDP).

🎯 Trigger conditions
  • A framework readiness score drops below a configured threshold (default 70%)
  • An evidence item expires, leaving one or more controls uncovered
  • A control status changes to 'not_implemented' on a critical framework
  • A gap analysis detects a new Critical gap
  • An audit deadline is within 60 days and readiness is below 80%
📤 Outputs
  • Observations: 'ISO 27001 readiness dropped to 64% — 8 controls now uncovered'
  • Recommendations: 'Upload renewed penetration test report to cover A.12.6.1'
  • Agent Actions: auto-create evidence collection tasks in Issue Hub™
📋
Policy Enforcer
policy_enforcerScheduled · Event-driven/agents/registry

Ensures policies are current, attested, and linked to the controls and frameworks they govern.

The Policy Enforcer monitors your Policy Governance™ module for stale policies, missing attestations, and broken policy-to-control linkages. It knows that an unattested policy is as dangerous as no policy — so it tracks attestation completion rates per policy and per team member. It also validates that every active compliance control has at least one approved policy backing it, and alerts when that link breaks (e.g., a policy is archived without a replacement).

🎯 Trigger conditions
  • A policy's review date has passed without a new version being published
  • An active policy has less than 80% attestation completion after 14 days
  • A policy is archived and leaves controls without policy coverage
  • A new framework control is created with no linked policy
  • A policy owner has left the organisation (membership deactivated)
📤 Outputs
  • Observations: 'Acceptable Use Policy — 14 team members have not attested (deadline passed)'
  • Recommendations: 'Send attestation reminders for Information Security Policy'
  • Agent Actions: auto-send attestation reminder emails via Resend
🔍
Audit Prep Agent
audit_prepScheduled · Manual trigger/agents/registry

Validates that all evidence, controls, and CAPAs are in order before an audit milestone.

The Audit Prep Agent is designed to be run 30–60 days before a scheduled audit. It performs a comprehensive pre-audit sweep: checks every audit program item for completion, validates that each finding has an associated CAPA, verifies that CAPAs are on track or completed, confirms evidence is current and mapped, and ensures the audit package documents are generated and up to date. Think of it as an automated audit readiness reviewer that flags every gap before the auditor sees it.

🎯 Trigger conditions
  • An audit is within 60 days of its start date
  • An audit program item has been pending for more than 14 days
  • A finding has no CAPA assigned after 7 days
  • A CAPA is overdue by more than its target date
  • An audit report has not been generated within 7 days of audit completion
📤 Outputs
  • Observations: 'Audit ISO-2025-Q2 — 6 program items still pending, 2 findings have no CAPA'
  • Recommendations: 'Generate audit package for vendor Acme Corp before 15 Jan'
  • Agent Actions: auto-generate audit program from framework controls, assign CAPA owners
⚙️
Custom Agent
customScheduled · Real-time · Manual/agents/studio

Build your own governance agent with custom rules, module scope, thresholds, and schedule.

Custom Agents let you define governance automation that goes beyond the five built-in types. Using Agent Studio™ at /agents/studio, you select which modules the agent monitors, write plain-English rules (e.g., 'Alert if any vendor with risk level = High has no active contract'), set numeric thresholds, and choose an execution schedule. The agent runs on your schedule, evaluates your rules against live data, and generates observations and recommendations exactly like the built-in agents — with full audit trail and human-approval gates on any proposed action.

🎯 Trigger conditions
  • Any condition you define: module-level data thresholds, status changes, date triggers
  • Cross-module rules: e.g., 'Vendor risk is High AND no active contract exists'
  • Composite conditions: e.g., 'Control health < 60% AND last test was > 90 days ago'
📤 Outputs
  • Observations with your custom severity and label
  • Recommendations with your configured action steps
  • Agent Actions queued for human approval in /agents/actions

Module AI Assistants

Every AUDT module has a dedicated AI assistant powered by Google Gemini 2.5 Flash. These assistants provide on-demand analysis, cached executive summaries, and multi-turn NL chat — accessible from each module's AI tab.

🏢AI Insights™in Vendor Hub™/vendors/[id]

Generates AI-written vendor briefs and executive summaries from assessment scores, document coverage, and risk exposure. Also powers NL search — type 'show high-risk SaaS vendors with expired SOC 2' and get filtered results.

Vendor brief (cached 24h)NL vendor searchScore explanationsRisk factor narratives
🛡️AI Compliance Officer™in Evidence Vault™/compliance/ai

A full AI governance advisor for compliance. Explains framework readiness scores, narrates gap findings in plain English, generates executive compliance summaries for board presentations, and answers live NL questions about your compliance posture.

Framework readiness explanationGap narrative generationExecutive summary (cached 24h)Multi-turn NL chat: 'What are our biggest ISO 27001 gaps?'
🔍AI Auditor™in Audit Management/audits/ai

Converts plain-English observations into structured audit findings (severity, description, affected control, recommendation). Generates CAPA suggestions for each finding. Produces board-ready audit executive reports. Answers questions like 'Which CAPAs are overdue?' in real time.

Finding generator from observation text3 CAPA suggestions per findingExecutive audit report (cached)Multi-turn NL chat
⚠️AI Risk Officer™in Risk Lens™/risks/ai

Generates a risk narrative for every risk — explaining the inherent score, linking it to affected assets and vendors, and recommending mitigation strategies. Produces a board-level risk executive report. Handles live questions like 'Summarise our top 5 cyber risks'.

Per-risk narrative (cached)5 mitigation recommendationsExecutive risk report (cached)Multi-turn NL chat
🎛️AI Control Advisor™in Control Center™/controls/ai

Detects the top 5 control gaps across your entire control library — controls with low health scores, missing evidence, or no recent tests. Generates an executive summary suitable for a board risk committee. Answers live questions about specific controls.

Top-5 gap detectionExecutive summary (cached)Per-control narrative (cached)Multi-turn NL chat
📋AI Policy Advisor™in Policy Governance™/compliance/policies

Reviews policy content and suggests improvements, flags policies nearing review dates, and identifies controls that lack policy coverage. Embedded inline on the policy detail page.

Policy gap detectionReview date alertsControl-policy coverage check
📝AI Contract Advisor™in Contract Governance™/contract-governance/ai

Extracts key clauses and obligations from contract text, analyses clause risk levels, and generates an executive contract summary. Answers questions like 'Which contracts expire in Q1?' or 'Show contracts with no DPA clause'.

Clause extractionObligation extractionClause risk analysisExecutive summaryMulti-turn NL chat
🔧AI Issue Advisor™in Issue & Remediation Hub™/issue-hub/ai

Converts governance observations into structured issues with severity, source module, and suggested owner. Generates a full remediation task plan for any open issue. Answers questions like 'Show all overdue critical issues' and summarises the overall remediation backlog.

Issue generator from observationRemediation task plannerExecutive summaryMulti-turn NL chat
📊Governance Copilot™in Trust Intelligence™/trust-intelligence/executive

The flagship AI assistant. Generates a comprehensive AI Governance Summary covering all 5 Org Trust Score™ components — suitable for board and executive presentations. Answers free-form questions about your entire governance posture across all modules.

Governance summary (cached 24h)Cross-module NL reasoningDriver/detractor explanationsMulti-turn NL chat
📈AI Executive Analyst™in Executive Reporting™/executive-reporting/ai

Generates role-specific executive summaries (CEO, CRO, CISO, Compliance, Board), board-ready reports for 8 report types, and trend analysis narratives. Can answer questions like 'What's our governance trajectory over the last 90 days?'.

Role dashboard summariesBoard report generationTrend analysisMulti-turn NL chat
🤖AI Governance Copilot™in AI Governance™/ai-governance/ai

Specialised AI advisor for responsible AI governance. Reviews your AI system inventory, flags high-risk AI systems with inadequate controls, assesses compliance against ISO 42001 / EU AI Act / NIST AI RMF, and recommends governance actions.

AI risk advisory (5 recs)Compliance readiness analysisSystem inventory summaryMulti-turn NL chat
🔗AI Integration Advisor™in Integration Hub™/integration-hub/ai

Analyses the health of all connected integrations, identifies connectors that would improve evidence automation coverage, and recommends the highest-ROI integrations based on your compliance framework gaps.

Integration health summaryConnector recommendationsCoverage gap analysisMulti-turn NL chat
📉AI Benchmark Analyst™in Benchmarking™/benchmarking/ai

Generates an industry benchmark executive report comparing your governance scores to sector peers, identifies which categories have the most improvement potential, and creates a personalised Improvement Planner™ with ranked actions.

Executive benchmark reportIndustry insights narrativeImprovement Planner™Multi-turn NL chat
📰AI Regulatory Advisor™in Regulatory Intelligence™/regulatory-intelligence/ai

Provides a cached regulatory advisory summary covering your most relevant regulations, analyses individual regulatory changes for impact on your controls and obligations, and generates a 4-panel Compliance Horizon™ forecast covering emerging risks, deadlines, global trends, and recommended actions.

Advisory summary (cached 24h)Per-change impact analysisObligation extractionCompliance Horizon™ forecastMulti-turn NL chat
AI Verification Advisor™in Trust Verification™/trust-verification/ai

Assesses your organisation's eligibility for each of the 10 verification programs (AUDT Verified™, Privacy Ready™, Enterprise Ready™, etc.), identifies the readiness gaps that would prevent certification, and provides a step-by-step preparation guide.

Verification eligibility analysisReadiness gap reportPreparation guideMulti-turn NL chat
🛡AI Security Advisor™in Security Command Center™/security-center

Reviews your security posture across MFA adoption, SSO configuration, session hygiene, IP allow list coverage, and AI prompt audit logs. Generates 5 prioritised security recommendations and an overall Security Readiness Score™ narrative.

Security posture summary (cached 24h)5 prioritised recommendationsPrompt sensitivity analysisMulti-turn NL chat
🗂️AI Asset Advisor™in Asset Intelligence™/asset-intelligence/ai

Analyses your asset inventory for coverage gaps, high-criticality assets without owners or risk assessments, and PII assets without DPDP linkage. Performs dependency chain analysis to show the blast radius of a critical asset failure.

Advisory summary (cached 24h)Impact analyserDependency chain analysisMulti-turn NL chat
🧠Governance Copilot™in Governance Agent Framework™/agents/copilot

A dedicated NL chat interface for querying agent activity across all governance agents. Ask 'Which agents raised critical observations this week?', 'What actions are pending approval?', or 'Summarise the vendor watch agent findings for Q1'.

Cross-agent NL reasoningObservation queryRecommendation queryAction status query
AI Compliance Officer™in Continuous Compliance™/continuous-compliance/ai

Reviews your automated check results, access review completions, attestation rates, and training compliance. Generates a Compliance Health™ narrative and per-check remediation guides for any failing checks.

Health score narrativePer-check remediation guideCompliance summary (cached 24h)Multi-turn NL chat
Operations Copilot™in Trust Operations Engine™/operations/ai

Generates an Operations Advisory covering your event pipeline, active workflow instances, pending approvals, and automation rule effectiveness. Provides AI Decision Engine recommendations and workflow guidance.

Operations advisory (cached 24h)Workflow recommendationsStep guidanceMulti-turn NL chat
🤝AI Audit Advisor™in Auditor Collaboration™/auditor-collaboration/ai

Assesses audit readiness across all active audit rooms, identifies the top evidence gaps auditors are likely to flag, and generates AI-drafted findings from room activity. Answers questions about evidence request status and external finding trends.

Audit readiness summary (cached 24h)Evidence gap analysis (top 5)AI finding drafterMulti-turn NL chat
🌐AI Trust Network Advisor™in Trust Network™/trust-network/ai

Generates a Trust Network Reputation™ narrative explaining your 5-component network score, identifies the highest-ROI actions for improving your public trust presence, and provides a Network Improvement Plan™ with 4 prioritised actions.

Network reputation summary4-action Improvement Plan™Profile completeness guidanceMulti-turn NL chat
🔌AI API Builder™in Trust API Platform™/trust-api/ai

Generates per-product API documentation, code samples, and integration guides for each of the 8 Trust API Platform™ products. Provides an integration health summary and recommends the highest-value API products for your platform tier.

Per-product API docsCode sample generationPlatform health summary (cached 24h)Multi-turn NL chat

Agent Lifecycle & Pages

The Governance Agent Framework™ spans 10 pages under /agents:

PageRouteWhat it does
Hub/agentsKPI strip — total agents, runs today, pending approvals, observations this week. Recent runs + observations. 9-card module nav.
Registry/agents/registryAll configured agents with type, execution mode, status, and key metrics (avg runs/week, observations generated, acceptance rate).
Studio/agents/studioCreate and configure custom agents — select module scope, write rules in plain English, set thresholds, choose schedule.
Runs/agents/runsFull execution history — start time, duration, observations generated, recommendations created, actions proposed per run.
Observations/agents/observationsAll governance signals with severity badge, source module, linked entity, status (open/actioned/dismissed). Filter by severity, module, date.
Recommendations/agents/recommendationsPrioritised action list — confidence ring (0–100), impact/effort labels, suggested steps. Accept or Dismiss each recommendation.
Actions/agents/actionsHuman approval queue — proposed system mutations waiting for Approve or Reject. Full action history below queue.
Orchestration/agents/orchestrationMulti-agent pipelines — sequence agents to pass observations downstream. Run log shows which agents ran in each pipeline.
Analytics/agents/analyticsAgent performance metrics — success rate, MTTR improvement, automation coverage %, observations per run, recommendation acceptance rate.
Copilot™/agents/copilotMulti-turn NL governance chat — ask anything about agent activity, observations, recommendations, or posture across all modules.
💡
Getting started: Go to /agents/registry, enable the Risk Monitor and Vendor Watch agents, set your schedule to daily, and click Run Now. Your first observations will appear within seconds.

API & Integrations

Authentication

AUDT uses Bearer token authentication. Create API keys at /settings/api-keys. Two permission levels are available: read_only and read_write. Keys are shown once at creation and stored as a bcrypt hash.

Rate Limits

PlanLimitWindow
Growth (Trial)100 requests60 seconds
Growth300 requests60 seconds
Business1,000 requests60 seconds
EnterpriseUnlimited

Key Endpoints

MethodEndpointDescriptionPermission
GET/api/v1/vendorsList vendors (paginated)read_only
GET/api/v1/vendors/[id]/trust-scoreVendor Trust Score™ with historyread_only
GET/api/v1/compliance/frameworksFrameworks with readinessread_only
GET/api/v1/compliance/gapsOpen compliance gapsread_only
GET/api/v1/auditsAudit listread_only
POST/api/v1/auditsCreate auditread_write
GET/api/v1/findingsOrg-wide findingsread_only
POST/api/v1/findingsCreate findingread_write
GET/api/v1/capasOrg-wide CAPAsread_only
GET/api/v1/risksRisk registerread_only
POST/api/v1/risksCreate riskread_write
GET/api/v1/risk-treatmentsTreatment trackerread_only
GET/api/v1/trust-intelligence/overviewFull dashboard dataread_only
GET/api/v1/trust-intelligence/org-scoreOrg Trust Score™read_only
GET/api/v1/contractsContract listread_only
GET/api/v1/issuesIssue registryread_only
GET/api/v1/regulationsRegulation libraryread_only
GET/api/v1/obligationsObligation listread_only
GET/api/v1/assetsAsset registryread_only
GET/api/v1/audit-logsAudit event streamread_only
GET/api/v1/monitoring/alertsGovernance alertsread_only
GET/api/v1/registryPublic verification registrypublic
GET/api/v1/benchmarkingGovernance benchmark dashboardread_only
GET/api/v1/benchmarking/rankingsFull rankings + maturity levelread_only
GET/api/v1/ai/systemsAI system inventoryread_only
GET/api/v1/agentsGovernance agent listread_only
GET/api/v1/agent-runsAgent execution historyread_only
GET/api/v1/public/trust-scoreReal-time org trust score (Trust API Platform™)bearer
GET/api/v1/public/verificationProof-of-governance bundlebearer
GET/api/v1/public/benchmarkingIndustry benchmark snapshotbearer
GET/api/healthLiveness/readiness probe — DB + config checkspublic
GET/api/docsOpenAPI 3.1 JSON specpublic

Error Handling

All errors return JSON with an error field. HTTP status codes follow REST conventions.

// AUDT API error response format:
// { "error": "string description", "code": "ERROR_CODE" (optional) }

// HTTP status codes:
// 200  OK
// 201  Created
// 400  Bad Request — invalid body, missing required fields
// 401  Unauthorized — missing or invalid Bearer token
// 403  Forbidden — key lacks required permission (read_write needed for POST/PUT/DELETE)
// 404  Not Found — resource does not exist in your organisation
// 422  Unprocessable Entity — valid JSON but business rule violation
// 429  Too Many Requests — rate limit exceeded (see Retry-After header)
// 500  Internal Server Error — contact support@audt.tech

// Rate limit headers on every response:
// X-RateLimit-Limit: 100
// X-RateLimit-Remaining: 87
// X-RateLimit-Reset: 1720000060

// Retry-After on 429:
// Retry-After: 60  (seconds)

// Example: robust fetch with retry
async function audtFetch(url, options = {}) {
  const res = await fetch(url, {
    ...options,
    headers: { Authorization: `Bearer ${AUDT_KEY}`, ...options.headers },
  });
  if (res.status === 429) {
    const wait = parseInt(res.headers.get("Retry-After") ?? "60", 10);
    await new Promise(r => setTimeout(r, wait * 1000));
    return audtFetch(url, options);
  }
  if (!res.ok) {
    const err = await res.json().catch(() => ({}));
    throw new Error(err.error ?? `AUDT API ${res.status}`);
  }
  return res.json();
}

cURL Examples

# Get Org Trust Score
curl -H "Authorization: Bearer tap_your_key" \
  https://audt.tech/api/v1/trust-intelligence/org-score

# Create a Risk
curl -X POST -H "Authorization: Bearer tap_your_key" \
  -H "Content-Type: application/json" \
  -d '{"title":"Vendor data breach risk","category":"cyber_security","impact":4,"likelihood":3}' \
  https://audt.tech/api/v1/risks

# Get Vendor Trust Score
curl -H "Authorization: Bearer tap_your_key" \
  https://audt.tech/api/v1/vendors/{id}/trust-score

JavaScript / TypeScript

No SDK required — use native fetch or any HTTP client. The API returns JSON on every endpoint.

// Install: no SDK needed — use fetch or axios

const AUDT_KEY = process.env.AUDT_API_KEY; // tap_...
const BASE = "https://audt.tech";

// Get Org Trust Score
async function getOrgTrustScore() {
  const res = await fetch(`${BASE}/api/v1/trust-intelligence/org-score`, {
    headers: { Authorization: `Bearer ${AUDT_KEY}` },
  });
  const data = await res.json();
  // data.score: number, data.level: string, data.components: object
  return data;
}

// Create a Risk
async function createRisk(title, category, impact, likelihood) {
  const res = await fetch(`${BASE}/api/v1/risks`, {
    method: "POST",
    headers: {
      Authorization: `Bearer ${AUDT_KEY}`,
      "Content-Type": "application/json",
    },
    body: JSON.stringify({ title, category, impact, likelihood }),
  });
  return res.json(); // { id, title, score, ... }
}

// Get Vendor Trust Score with history
async function getVendorTrustScore(vendorId) {
  const res = await fetch(`${BASE}/api/v1/vendors/${vendorId}/trust-score`, {
    headers: { Authorization: `Bearer ${AUDT_KEY}` },
  });
  return res.json();
  // .score, .level, .components, .history (30 days), .narrative
}

// List open risks (filter by status + category)
async function getOpenRisks() {
  const params = new URLSearchParams({ status: "open", category: "cyber_security" });
  const res = await fetch(`${BASE}/api/v1/risks?${params}`, {
    headers: { Authorization: `Bearer ${AUDT_KEY}` },
  });
  return res.json(); // { data: Risk[], meta: { page, total } }
}

Python

Use the requests library. All endpoints return JSON dictionaries matching the TypeScript types.

import os, requests

AUDT_KEY = os.environ["AUDT_API_KEY"]  # tap_...
BASE = "https://audt.tech"
HEADERS = {"Authorization": f"Bearer {AUDT_KEY}"}

# Get Org Trust Score
def get_org_trust_score():
    r = requests.get(f"{BASE}/api/v1/trust-intelligence/org-score", headers=HEADERS)
    r.raise_for_status()
    return r.json()  # { score, level, components }

# Create a Risk
def create_risk(title, category, impact, likelihood):
    payload = {"title": title, "category": category,
               "impact": impact, "likelihood": likelihood}
    r = requests.post(f"{BASE}/api/v1/risks", json=payload, headers=HEADERS)
    r.raise_for_status()
    return r.json()  # { id, title, score, ... }

# Get all frameworks with readiness
def get_frameworks():
    r = requests.get(f"{BASE}/api/v1/compliance/frameworks", headers=HEADERS)
    r.raise_for_status()
    return r.json()  # [{ id, name, readinessScore, controlCount }]

# Paginate through vendors
def get_all_vendors():
    vendors, page = [], 1
    while True:
        r = requests.get(f"{BASE}/api/v1/vendors?page={page}&pageSize=50",
                         headers=HEADERS)
        data = r.json()
        vendors.extend(data["data"])
        if page >= data["meta"]["totalPages"]:
            break
        page += 1
    return vendors

Webhooks

Register webhooks at /trust-api/webhooks. AUDT delivers a POST to your endpoint for each subscribed event. Expects a 200 response within 10 seconds, then retries.

// Register a webhook at /trust-api/webhooks
// AUDT delivers POST to your endpoint for each subscribed event.

// 1. Verify the payload (check x-audt-signature header)
// 2. Process the event type
// 3. Return 200 OK within 10 seconds (AUDT retries on timeout)

// Node.js webhook handler (Express)
app.post("/audt-webhook", express.raw({ type: "application/json" }), (req, res) => {
  const event = JSON.parse(req.body.toString());

  switch (event.event_type) {
    case "trust_score.dropped":
      // event.data: { vendor_id, old_score, new_score, delta }
      console.log("Trust score dropped for", event.data.vendor_id);
      break;

    case "evidence.expired":
      // event.data: { evidence_id, vendor_id, expired_at }
      notifyTeam("Evidence expired: " + event.data.evidence_id);
      break;

    case "risk.critical":
      // event.data: { risk_id, title, score, vendor_id }
      escalateRisk(event.data);
      break;
  }

  res.status(200).json({ received: true });
});

// Available event types:
// trust_score.dropped  trust_score.improved  evidence.expired
// evidence.expiring_soon  risk.critical  vendor.status_changed
// contract.expiring  capa.overdue  audit.completed

Trust Score API

The Trust Score endpoints return structured breakdowns useful for embedding in external dashboards, SIEM integrations, or BI tools.

// Vendor Trust Score™ — full breakdown
GET /api/v1/vendors/{id}/trust-score

Response:
{
  "score": 82,
  "level": "Strong",       // Exceptional | Trusted | Strong | Moderate | Needs Attention | High Concern
  "components": {
    "evidence":     { "score": 75, "weight": 0.20, "weighted": 15.0 },
    "risk":         { "score": 85, "weight": 0.20, "weighted": 17.0 },
    "compliance":   { "score": 80, "weight": 0.15, "weighted": 12.0 },
    "assessment":   { "score": 90, "weight": 0.15, "weighted": 13.5 },
    "contract":     { "score": 70, "weight": 0.10, "weighted": 7.0 },
    "operational":  { "score": 80, "weight": 0.10, "weighted": 8.0 },
    "freshness":    { "score": 90, "weight": 0.10, "weighted": 9.0 }
  },
  "history": [          // last 30 daily snapshots
    { "date": "2026-06-28", "score": 82 },
    { "date": "2026-06-27", "score": 79 }
  ],
  "narrative": "Vendor X maintains a Strong trust posture...",
  "strengths": ["Assessment score 90/100", "Evidence up to date"],
  "concerns":  ["Contract expires in 45 days", "2 open risks"]
}

// Org Trust Score™
GET /api/v1/trust-intelligence/org-score

Response:
{
  "score": 74,
  "level": "Moderate",
  "components": {
    "vendorTrust":         { "score": 78, "weight": 0.25, "weighted": 19.5 },
    "riskPosture":         { "score": 70, "weight": 0.25, "weighted": 17.5 },
    "controlHealth":       { "score": 75, "weight": 0.20, "weighted": 15.0 },
    "auditReadiness":      { "score": 65, "weight": 0.15, "weighted": 9.75 },
    "complianceCoverage":  { "score": 80, "weight": 0.15, "weighted": 12.0 }
  }
}

Integrations

35+ connectors across 11 categories. Phase 1 connectors cover ~80% of prospect requirements.

Phase 1 Connectors

Entra IDOktaGoogle WorkspaceAWSGitHubJiraSlackCrowdStrikeMicrosoft Defender

How to Connect

Go to /integration-hub/marketplace → click connector → Configure → enter credentials → Test Connection → Save. Credentials are stored AES-256-GCM encrypted.

Categories

Identity & AccessCloud InfrastructureSecuritySource ControlProject ManagementITSMEndpoint SecurityCommunicationHR & PeopleStorageCustom