Platform
Platform overview Six modules from discovery to evidence on one governance backbone. AI Inventory & Discovery Make shadow AI usage visible. Use-case Intake & Triage One-page intake, 5 business-day SLA. Risk & Autonomy Tiering Green / Amber / Red decision model. AI Gateway & Policy All model traffic through one control point. Audit Trail & Evidence Audit-ready, tamper-evident record.
Solutions
AI Center of Excellence A single operating console for the hub team. CISO & Security Data-leak control and kill switch. Legal & Compliance Collect regulatory evidence automatically. Executive Leadership Measure the return on AI investment. Business Units (Spoke) Make the approved path the easy path. Industries Manufacturing, finance, health and public sector.
Compliance
EU AI Act Obligation timeline and readiness map. ISO/IEC 42001 AI management system (AIMS) controls. NIST AI RMF Govern, Map, Measure, Manage mapping. KVKK & GDPR Personal data and DPIA linkage. Security & Architecture Tenant isolation, SSO, MFA, data residency. Control matrix Which module satisfies which clause.
Framework
Resources
About Contact Customer login Request a demo
Multi-tenant SaaS EU AI Act ready ISO/IEC 42001 aligned

Enterprise AI Governance

Make enterprise AI usage visible, tier it by risk and produce an audit record for every decision. Your employees already use Claude, Copilot, n8n and OpenAI; AIZEC makes that usage governable without banning it.

Enterprise SSO (OIDC) · Mandatory TOTP MFA · Row-level tenant isolation

Frameworks shaping enterprise AI governance
EU AI Act (2024/1689) ISO/IEC 42001:2023 NIST AI RMF 1.0 ISO/IEC 27001 Turkish DPL 6698 GDPR
The problem

Shadow AI is not a prohibition problem. It is a visibility problem.

AI tools do not enter your organisation through procurement. They enter through a browser tab. Banning them does not stop usage; it only makes it invisible.

Invisible usage

Nobody knows exactly which team uses which model with which data. You cannot run a risk assessment on a surface you have never inventoried.

Uncontrolled data flow

Customer records, price lists and technical documents get pasted into third-party models with no contract in place. By the time a breach surfaces, there is no evidence to reconstruct.

Duplicated effort

The same automation is rebuilt separately in four business units. There is neither reuse nor institutional memory of what actually worked.

Audit unreadiness

When a regulator or internal audit asks "who made this decision, and on what basis?", you end up reconstructing evidence from email threads.

Governance is not about imposing rules. When the approved path becomes the easiest path, shadow AI declines on its own.

AIZEC product principle
Regulatory pressure

2 August 2026: most of the Regulation becomes applicable.

The EU AI Act applies in phases, and it does not only cover companies established in the EU. It can reach providers whose output is used there. The duty to produce evidence begins the day you start using a system, not the day you finish building it.

  • For prohibited practices, penalties reach up to €35 million or 7% of total worldwide annual turnover, whichever is higher.
  • High-risk systems require a risk management system, technical documentation, record-keeping and human oversight.
  • Transparency and documentation obligations for general-purpose AI (GPAI) providers have applied since 2 August 2025.
  • Obligations bind not only the provider but also the deployer, the party using the system under its own authority.
  1. 1 August 2024

    Regulation entered into force

    Regulation (EU) 2024/1689 formally entered into force, starting the phased application timeline.

  2. 2 February 2025

    Prohibited practices

    Unacceptable-risk practices (social scoring, manipulative techniques and others) became prohibited; the AI literacy obligation began.

  3. 2 August 2025

    GPAI and governance

    Obligations for general-purpose AI models and the national authority / penalty regime started to apply.

  4. 2 August 2026

    General application

    Most of the Regulation becomes applicable, including high-risk systems listed under Annex III.

  5. 2 August 2027

    Product-embedded systems

    The transition period ends for high-risk AI systems covered by Annex I product safety legislation.

Platform

One governance backbone, from discovery to evidence.

Six modules feed each other: every tool visible in the inventory reaches triage, every triage lands on a risk tier, every tier applies a control set, and every decision is written to an immutable audit record.

AI Inventory & Discovery

Surface real AI usage through employee self-service and gateway telemetry.

  • Tool, category and data sensitivity records
  • Coverage rate per business unit
  • Voluntary first entry, then routine updates

Use-case Intake & Triage

A working queue with a one-page intake form, a defined SLA and automatic reminders.

  • 5 business-day triage SLA
  • Status notifications and reminders
  • Transparent progress for the requester

Risk & Autonomy Tiering

Every use-case lands on one of three autonomy tiers and inherits the matching control set.

  • Green / Amber / Red decision model
  • Mandatory written rationale
  • DLP and legal approval flows

AI Gateway & Policy

Collect traffic and policy-violation events from the gateway owned by your security team.

  • Service-to-service log ingestion
  • Approved traffic ratio
  • Policy violation visibility

Audit Trail & Evidence

Every decision (classification, approval, revocation, role change) is recorded with actor and rationale.

  • Actor, action, entity and rationale
  • Red-tier kill-switch record
  • Audit-ready export

Reporting & Metrics

Coverage, time-to-decision, gateway ratio and business impact metrics on a real-time dashboard.

  • Live dashboard over Socket.io
  • Monthly report snapshots
  • Read-only executive view

The modules are interlocked rather than standalone: a tool that is not in the inventory cannot enter triage, and a use-case that has not been triaged is not counted as approved traffic at the gateway.

Decision model

Three autonomy tiers, three separate control sets.

Debating every request from scratch is the most expensive part of governance. Three tiers settle what a team must do while the form is still open.

Green

Free to use, record required

If the agent has read-only access, the output concerns only the requester, and no internal data is touched, nothing stands in the way.

Required
Inventory record and logging
Approval
Not required
Typical time
Immediate
Amber

CoE review and human approval

If the agent touches internal data or the output reaches another person, CoE review and a DLP check apply.

Required
DLP check, human approval
Approval
AI CoE
Typical time
5 business-day SLA
Red

Full assessment and rollback

If the agent writes to a production system or produces decisions about customers or employees, testing, audit trail, a kill switch and legal approval are mandatory.

Required
Risk assessment, testing, kill switch
Approval
Security + Legal
Typical time
Depends on assessment

Tier criteria are configurable per tenant. Automating red-tier decisions over time draws on both the sector benchmarks published by firms such as Gartner and McKinsey and the business impact data accumulating in the platform.

Operating model

Hub-and-spoke: standards at the centre, speed in the field.

A central AI Center of Excellence sets the standard; a designated spoke representative applies it inside each business unit. AIZEC turns that model from an org chart into a working system.

  • Hub (AI CoE): owns policy, tiering, approvals and the enterprise catalogue.
  • Spoke representative: sees only their own unit's inventory and steers their team to approved alternatives.
  • Security: gateway logs, red-tier assessment and kill-switch authority.
  • Employee: manages their own inventory and requests; cannot see anyone else's data.
  • Authority boundaries are enforced at the application layer through role-based access control. The difference between "may see" and "must not see" is written into the code.
Hub AI Center of Excellence Policy · Tiering · Catalogue
  • ITSpoke rep
  • SalesSpoke rep
  • FinanceSpoke rep
  • HRSpoke rep
  • ManufacturingSpoke rep
  • QualitySpoke rep
How it works

Move governance off the slide deck and into a measurable operation.

AIZEC is not an abstract framework but a workflow with defined SLAs and recording duties. The following are platform defaults.

5 days
Use-case triage SLA
The requester is notified automatically, and overdue requests surface on the dashboard.
3 tiers
Autonomy classification
Green, Amber and Red each trigger a different control set.
6 modules
One data model
Inventory, triage, tiering, gateway, audit and reporting share the same records.
No exceptions
Decision recording
Every classification, approval, rejection and revocation is written to the audit trail with actor and rationale.

Outcome metrics such as inventory coverage, time-to-decision and gateway traffic are specific to your tenant and reported on your own dashboard.

Who uses it

Five distinct responsibilities. One source of truth.

Everyone looks at the same data, but only sees what they need to. A spoke representative cannot query another unit's inventory, and an employee cannot read past their own records.

AI Center of Excellence

As the owner of enterprise AI policy, run the full inventory, queue and decision log from one place.

  • Full visibility across every business unit's inventory
  • Use-case tiering and Green/Amber approval
  • Managing the approved alternatives catalogue
  • CoE membership and role assignments
Compliance

Meet four frameworks with one control set.

The records AIZEC produces feed the evidence needs of four different frameworks at once. Record once, use in every audit.

EU AI Act

A data model built to support risk classification, technical documentation, record-keeping and human oversight obligations.

ISO/IEC 42001:2023

Policy, role, risk assessment and continual improvement records for the first AI management system (AIMS) standard.

NIST AI RMF 1.0

Each of the Govern, Map, Measure and Manage functions maps to a concrete module in the platform.

GDPR & KVKK

Flagging of use-cases involving personal data, sensitivity records, and input into DPIA processes.

Teams preparing for ISO 42001 certification, personal data processes under KVKK and GDPR, and EU AI Act files all draw on the same record set. AIZEC is not a legal advisory service; it provides the evidence and process infrastructure that supports your compliance decisions.

FAQ

Questions buyers ask

No. The core assumption of the product is that prohibition does not stop usage; it only makes it invisible. AIZEC leaves low-risk usage free, records it, and asks for approval only where risk actually increases.

The platform is tool-agnostic. Claude, Copilot, OpenAI, n8n or in-house models all enter the same inventory. Traffic control comes from logs collected from the gateway/proxy layer owned by your security team.

Yes. Each tenant can configure its own OIDC provider (for example Microsoft Entra ID). Alternatively, local password login with mandatory TOTP MFA is supported.

No. Every tenant is an Organization, and every row in a tenant table carries an organisation identifier. Isolation is enforced at the application layer and continuously verified by automated tests.

A standard deployment starts with tenant creation, SSO connection and business unit/role definitions. The inventory campaign and the first triage cycle are usually addressed within the first 90-day rollout plan.

The platform is container-based and can run inside your enterprise environment. The deployment model is assessed together with your data residency requirements.

Let us build your AI inventory together.

Book a 30-minute session to discuss your team's real AI usage, your open risk exposure and a 90-day rollout plan.

For pre-sales technical questions you can talk directly to the engineering team.