ThreatLens AI Assurance

Know What Powers Every AI System

Build living AI-BOMs, monitor AI supply-chain risk, and collect evidence across models, datasets, prompts, agents, APIs, vendors, and runtime usage.

AI systems now depend on foundation models, fine-tuned models, datasets, embeddings, prompts, vector stores, third-party APIs, agents, and cloud services. ThreatLens gives regulated enterprises one place to see what is inside each system, what changed, what risk it creates, and what evidence proves it.

Governance vs Assurance

Two products. One clear boundary.

ThreatLens AI Governance controls AI access — enforce policy, route traffic, block sensitive data. ThreatLens AI Assurance proves what is inside AI systems and whether the right evidence exists.

The AI supply chain is already inside your business

AI moved faster than inventory, evidence, and oversight.

Most organisations can name the application using AI. Far fewer can prove every model, dataset, prompt, vendor, API, library, and runtime dependency behind it.

AI systems are hard to inventory

Teams build with OpenAI, Azure OpenAI, Bedrock, Vertex AI, Hugging Face, LangChain, vector databases, custom prompts, and internal APIs. The final system is rarely documented in one place.

Third-party AI risk is unclear

Every external model, dataset, API, and agent tool becomes part of the enterprise risk landscape. Procurement and risk teams need more than vendor names.

Evidence is scattered

Approvals, model cards, test results, vendor reviews, impact assessments, prompts, policies, and architecture decisions live across documents, tickets, repositories, and inboxes.

Compliance teams get stale records

Spreadsheets and questionnaires become outdated as soon as a model changes, a prompt is updated, or a new AI API is added to production.

Raw AI telemetry is sensitive

Enterprises need monitoring, but they cannot expose prompts, customer data, source code, employee records, or model outputs to a third-party dashboard by default.

What ThreatLens delivers

A living assurance record for every AI system.

Discover AI components

Scan repositories and integrations to find models, AI SDKs, vector databases, prompts, agents, datasets, and third-party AI services.

Build living AI-BOMs

Maintain a continuously updated AI Bill of Materials for each AI system, including relationships, ownership, versioning, risk, evidence, and export history.

Monitor change

Use SDK and gateway telemetry as evidence feeds to detect runtime model usage, provider changes, new endpoints, risky traffic patterns, and drift from approved design.

Protect sensitive telemetry

Send metadata, hashes, risk flags, classifications, and usage metrics by default. Raw prompts and outputs are not required in ThreatLens SaaS.

Collect audit-ready evidence

Upload, hash, link, review, and export evidence for AI systems, vendors, models, controls, risk decisions, and readiness reports.

Report by region and framework

Generate readiness views for India, GCC, EU AI Act, ISO/IEC 42001, NIST AI RMF, CERT-In, and internal policy requirements based on the customer package.

How it works

From first scan to continuous assurance.

Scan

Start with a public or private repository scan to identify AI models, libraries, prompts, API usage, vector stores, and configuration signals.

Register

Create an AI system record with owners, business purpose, model providers, datasets, deployment status, criticality, and region.

Connect

Connect identity, source code, AI providers, and approved deployment environments. Start with Microsoft Entra ID, GitHub, OpenAI, Azure OpenAI, and AWS Bedrock.

Monitor

Use ThreatLens SDK or gateway telemetry to track model usage, risk flags, classifications, policy decisions, and approved component identifiers.

Evidence

Attach model cards, vendor reviews, test reports, approvals, architecture diagrams, impact assessments, and policy evidence. Each file is hashed at upload.

Report

Export human-readable reports and machine-readable AI-BOMs for security, procurement, audit, and regulatory-readiness workflows.

AI-BOM contents

More than models. The full AI system record.

AI applicationsFoundation modelsFine-tuned modelsEmbedding modelsTraining datasetsFine-tuning datasetsEvaluation datasetsRuntime & RAG datasetsPrompt templatesAgents & toolsExternal APIsAI SDKs & ML librariesVector databasesCloud servicesModel providersLicencesData classesSystem ownersEvidenceApprovalsRisk decisions

ThreatLens treats an AI-BOM as an evidence artifact, not just a file. The AI-BOM is connected to the system register, evidence vault, runtime telemetry, vendor records, risk decisions, and framework mappings.

Open standards

Export AI-BOMs your enterprise tooling can understand.

ThreatLens exports AI-BOM records in human-readable and machine-readable formats so security, GRC, procurement, and software supply-chain teams can use the evidence in their existing workflows.

Human-readablePDF report

Board- and audit-ready summary.

NativeThreatLens JSON

The full structured system record.

Open standardCycloneDX AI/ML-BOM

Model & dataset transparency.

Open standardSPDX 3.0 AI

AI profile for supply-chain tooling.

CycloneDX supports machine-learning BOMs for model and dataset transparency, including provenance, training methodology, AI frameworks, and related risk considerations. ThreatLens uses these open BOM patterns so AI inventory can connect with enterprise supply-chain and vulnerability management workflows.

Privacy-first monitoring

Monitor AI usage without exposing raw prompts by default.

AI assurance needs runtime visibility. But raw prompts and model outputs can contain customer data, source code, confidential files, financial information, or regulated records. ThreatLens is designed so SaaS telemetry can operate without collecting raw prompt text by default.

Metadata only

Send model name, provider, tenant, application, token count where available, risk flags, policy decision, and component identifiers.

Hash only

Hash prompts and responses locally to detect repeated usage without storing readable content.

Redacted payload

Mask sensitive values before telemetry leaves the customer environment.

Customer-controlled raw storage

If raw payload review is required, store raw content in customer-controlled infrastructure and expose it only through customer-approved access.

ThreatLens processes AI assurance metadata, not your intellectual property by default.
Built for regulated markets

Start with India and GCC. Stay ready for global frameworks.

ThreatLens is region-aware. Customers select the primary framework pack that matches their operating region, regulator, and AI usage profile.

India
Launch pack
  • AI system and model inventory
  • Third-party AI and model accountability
  • Model owner and approver records
  • Model risk tiering
  • Model validation evidence
  • Ongoing monitoring evidence
  • CERT-In AI-BOM alignment
  • RBI model risk management readiness
UAE & GCC
Launch pack
  • AI and model inventory
  • AI/ML governance evidence
  • Third-party AI provider oversight
  • Data classification for Emirates ID and regional identifiers
  • CBUAE readiness for financial institutions
  • SDAIA AI risk management readiness for Saudi-facing customers
Global frameworks
Add-on packs
  • EU AI Act readiness
  • ISO/IEC 42001 support mapping
  • NIST AI RMF support mapping
  • Internal AI policy mapping
  • Customer procurement questionnaire mapping

ThreatLens supports compliance readiness, evidence management, monitoring, and reporting. It does not certify legal compliance, ISO certification, or regulatory approval.

One assurance record, many teams

Give every stakeholder the proof they need.

For CISOs

See where AI is used, which providers are involved, what sensitive data classes are present, and what changed since approval.

For GRC teams

Map AI systems, risks, controls, and evidence to regional frameworks, internal policies, and board reporting needs.

For engineering teams

Use scanner, SDK, and approved telemetry feeds to keep AI inventory current without maintaining spreadsheets by hand.

For procurement and vendor risk

Track third-party AI providers, model dependencies, vendor evidence, licences, and supplier risk across the AI supply chain.

For auditors and leadership

Export AI-BOMs, evidence packs, readiness reports, and change history with clear ownership and tamper-evident file hashes.

Why ThreatLens AI Assurance

Built for proof, not promises.

Living AI-BOM

ThreatLens connects AI components, evidence, risk, owners, and runtime telemetry into a continuously updated system record.

AI supply-chain assurance

Track models, datasets, prompts, vendors, APIs, libraries, agents, licences, and provenance in one place.

Zero-trust telemetry

Monitor production AI usage without sending raw prompts or outputs to ThreatLens SaaS by default.

Region-aware readiness

Launch with India and GCC packs, add EU AI Act, ISO/IEC 42001, NIST AI RMF, and internal policies as required.

Standards export

Generate PDF, ThreatLens JSON, CycloneDX AI/ML-BOM, and SPDX 3.0 AI exports.

Deployment flexibility

Support SaaS, private cloud, customer cloud, and on-premises deployment paths for regulated environments.

Trust for regulated buyers

Built by practitioners. Designed to prove its own work.

ThreatLens is early and practitioner-built. Rather than empty logo walls, we offer trust signals a regulated buyer can inspect for themselves.

Practitioner-led

Built by security and governance practitioners, drawing on more than 20 years of enterprise cybersecurity and AI governance experience across the region.

Privacy-first telemetry

Zero-trust telemetry is the default: raw prompts and model outputs are not required in ThreatLens SaaS.

Open assurance artifacts

Inspect real output before any sales call — sample AI-BOM exports, evidence reports, and machine-readable CycloneDX and SPDX examples.

Inspectable scanner approach

The scanner is documented, not a black box: detection rules, supported file types, and clear scan limitations.

ThreatLens on ThreatLens

We use our own assurance model — ThreatLens’ own AI-BOM will be published as a downloadable artifact you can inspect.

Get started

Start free. Join the design partner program when you are ready for production assurance.

Free
Free Scan

Discover AI usage and risk in a public repository.

Get your free AI-BOM scan
Design partner
Design Partner Program

Work with ThreatLens to build AI-BOMs, evidence records, and continuous assurance workflows for selected AI systems.

Apply for Design Partner Access
Enterprise
Business & Enterprise

For regulated organisations that need private repositories, evidence, monitoring, framework mapping, and deployment control.

Book a Demo
FAQ

AI-BOM and AI assurance questions.

What is an AI-BOM?

An AI-BOM, or AI Bill of Materials, is a structured record of the components that power an AI system. It can include models, datasets, embeddings, prompts, agents, APIs, libraries, vendors, licences, owners, evidence, and relationships.

Is an AI-BOM the same as an SBOM?

No. An SBOM documents software components. An AI-BOM extends the supply-chain idea to AI systems by documenting AI-specific components such as models, datasets, prompts, embeddings, agents, vector stores, and model providers.

Why do regulated enterprises need AI-BOMs?

Regulated enterprises need to prove what AI systems they use, who owns them, what third parties they depend on, what data they process, what risks they create, and what evidence supports approval and monitoring decisions.

Does ThreatLens store raw prompts and model outputs?

Not by default. ThreatLens AI Assurance is designed for metadata-only telemetry, hash-only mode, redacted payloads, and customer-controlled raw storage options.

Can ThreatLens export CycloneDX and SPDX AI-BOMs?

Yes. ThreatLens AI Assurance is scoped to export AI-BOMs as PDF, ThreatLens JSON, CycloneDX AI/ML-BOM, and SPDX 3.0 AI profile formats.

Does ThreatLens make us compliant with the EU AI Act, RBI guidance, CBUAE guidance, or ISO/IEC 42001?

No software can automatically make an organisation legally compliant or certified. ThreatLens supports readiness by helping teams maintain inventory, evidence, monitoring, risk records, framework mappings, and reports.

How is this different from AI governance software?

Traditional AI governance software often starts with workflows, questionnaires, and policy mapping. ThreatLens AI Assurance starts with the technical evidence layer: what powers the AI system, what changed, what risk exists, and what evidence proves it.

How is this different from AI observability?

AI observability focuses on runtime behaviour, performance, cost, traces, and model quality. ThreatLens AI Assurance includes runtime monitoring, but connects it to AI-BOMs, evidence, risk, ownership, compliance readiness, and supplier accountability.

Which teams use ThreatLens AI Assurance?

Security, GRC, engineering, procurement, vendor risk, privacy, audit, and executive teams can all use the same AI assurance record for different decisions.

Can ThreatLens run in private environments?

ThreatLens is designed for public SaaS, private cloud, customer cloud, and on-premises deployment paths depending on the customer plan and regulatory requirements.

Prove what is inside your AI systems.

Start with a free AI-BOM scan. Move to continuous assurance when your team needs private repositories, evidence, monitoring, and regulatory readiness.