Know What Powers Every AI System
Build living AI-BOMs, monitor AI supply-chain risk, and collect evidence across models, datasets, prompts, agents, APIs, vendors, and runtime usage.
AI systems now depend on foundation models, fine-tuned models, datasets, embeddings, prompts, vector stores, third-party APIs, agents, and cloud services. ThreatLens gives regulated enterprises one place to see what is inside each system, what changed, what risk it creates, and what evidence proves it.
Two products. One clear boundary.
ThreatLens AI Governance controls AI access — enforce policy, route traffic, block sensitive data. ThreatLens AI Assurance proves what is inside AI systems and whether the right evidence exists.
AI moved faster than inventory, evidence, and oversight.
Most organisations can name the application using AI. Far fewer can prove every model, dataset, prompt, vendor, API, library, and runtime dependency behind it.
AI systems are hard to inventory
Teams build with OpenAI, Azure OpenAI, Bedrock, Vertex AI, Hugging Face, LangChain, vector databases, custom prompts, and internal APIs. The final system is rarely documented in one place.
Third-party AI risk is unclear
Every external model, dataset, API, and agent tool becomes part of the enterprise risk landscape. Procurement and risk teams need more than vendor names.
Evidence is scattered
Approvals, model cards, test results, vendor reviews, impact assessments, prompts, policies, and architecture decisions live across documents, tickets, repositories, and inboxes.
Compliance teams get stale records
Spreadsheets and questionnaires become outdated as soon as a model changes, a prompt is updated, or a new AI API is added to production.
Raw AI telemetry is sensitive
Enterprises need monitoring, but they cannot expose prompts, customer data, source code, employee records, or model outputs to a third-party dashboard by default.
A living assurance record for every AI system.
Discover AI components
Scan repositories and integrations to find models, AI SDKs, vector databases, prompts, agents, datasets, and third-party AI services.
Build living AI-BOMs
Maintain a continuously updated AI Bill of Materials for each AI system, including relationships, ownership, versioning, risk, evidence, and export history.
Monitor change
Use SDK and gateway telemetry as evidence feeds to detect runtime model usage, provider changes, new endpoints, risky traffic patterns, and drift from approved design.
Protect sensitive telemetry
Send metadata, hashes, risk flags, classifications, and usage metrics by default. Raw prompts and outputs are not required in ThreatLens SaaS.
Collect audit-ready evidence
Upload, hash, link, review, and export evidence for AI systems, vendors, models, controls, risk decisions, and readiness reports.
Report by region and framework
Generate readiness views for India, GCC, EU AI Act, ISO/IEC 42001, NIST AI RMF, CERT-In, and internal policy requirements based on the customer package.
From first scan to continuous assurance.
Scan
Start with a public or private repository scan to identify AI models, libraries, prompts, API usage, vector stores, and configuration signals.
Register
Create an AI system record with owners, business purpose, model providers, datasets, deployment status, criticality, and region.
Connect
Connect identity, source code, AI providers, and approved deployment environments. Start with Microsoft Entra ID, GitHub, OpenAI, Azure OpenAI, and AWS Bedrock.
Monitor
Use ThreatLens SDK or gateway telemetry to track model usage, risk flags, classifications, policy decisions, and approved component identifiers.
Evidence
Attach model cards, vendor reviews, test reports, approvals, architecture diagrams, impact assessments, and policy evidence. Each file is hashed at upload.
Report
Export human-readable reports and machine-readable AI-BOMs for security, procurement, audit, and regulatory-readiness workflows.
More than models. The full AI system record.
ThreatLens treats an AI-BOM as an evidence artifact, not just a file. The AI-BOM is connected to the system register, evidence vault, runtime telemetry, vendor records, risk decisions, and framework mappings.
Export AI-BOMs your enterprise tooling can understand.
ThreatLens exports AI-BOM records in human-readable and machine-readable formats so security, GRC, procurement, and software supply-chain teams can use the evidence in their existing workflows.
Board- and audit-ready summary.
The full structured system record.
Model & dataset transparency.
AI profile for supply-chain tooling.
CycloneDX supports machine-learning BOMs for model and dataset transparency, including provenance, training methodology, AI frameworks, and related risk considerations. ThreatLens uses these open BOM patterns so AI inventory can connect with enterprise supply-chain and vulnerability management workflows.
Monitor AI usage without exposing raw prompts by default.
AI assurance needs runtime visibility. But raw prompts and model outputs can contain customer data, source code, confidential files, financial information, or regulated records. ThreatLens is designed so SaaS telemetry can operate without collecting raw prompt text by default.
Metadata only
Send model name, provider, tenant, application, token count where available, risk flags, policy decision, and component identifiers.
Hash only
Hash prompts and responses locally to detect repeated usage without storing readable content.
Redacted payload
Mask sensitive values before telemetry leaves the customer environment.
Customer-controlled raw storage
If raw payload review is required, store raw content in customer-controlled infrastructure and expose it only through customer-approved access.
Start with India and GCC. Stay ready for global frameworks.
ThreatLens is region-aware. Customers select the primary framework pack that matches their operating region, regulator, and AI usage profile.
- AI system and model inventory
- Third-party AI and model accountability
- Model owner and approver records
- Model risk tiering
- Model validation evidence
- Ongoing monitoring evidence
- CERT-In AI-BOM alignment
- RBI model risk management readiness
- AI and model inventory
- AI/ML governance evidence
- Third-party AI provider oversight
- Data classification for Emirates ID and regional identifiers
- CBUAE readiness for financial institutions
- SDAIA AI risk management readiness for Saudi-facing customers
- EU AI Act readiness
- ISO/IEC 42001 support mapping
- NIST AI RMF support mapping
- Internal AI policy mapping
- Customer procurement questionnaire mapping
ThreatLens supports compliance readiness, evidence management, monitoring, and reporting. It does not certify legal compliance, ISO certification, or regulatory approval.
Give every stakeholder the proof they need.
For CISOs
See where AI is used, which providers are involved, what sensitive data classes are present, and what changed since approval.
For GRC teams
Map AI systems, risks, controls, and evidence to regional frameworks, internal policies, and board reporting needs.
For engineering teams
Use scanner, SDK, and approved telemetry feeds to keep AI inventory current without maintaining spreadsheets by hand.
For procurement and vendor risk
Track third-party AI providers, model dependencies, vendor evidence, licences, and supplier risk across the AI supply chain.
For auditors and leadership
Export AI-BOMs, evidence packs, readiness reports, and change history with clear ownership and tamper-evident file hashes.
Built for proof, not promises.
Living AI-BOM
ThreatLens connects AI components, evidence, risk, owners, and runtime telemetry into a continuously updated system record.
AI supply-chain assurance
Track models, datasets, prompts, vendors, APIs, libraries, agents, licences, and provenance in one place.
Zero-trust telemetry
Monitor production AI usage without sending raw prompts or outputs to ThreatLens SaaS by default.
Region-aware readiness
Launch with India and GCC packs, add EU AI Act, ISO/IEC 42001, NIST AI RMF, and internal policies as required.
Standards export
Generate PDF, ThreatLens JSON, CycloneDX AI/ML-BOM, and SPDX 3.0 AI exports.
Deployment flexibility
Support SaaS, private cloud, customer cloud, and on-premises deployment paths for regulated environments.
Built by practitioners. Designed to prove its own work.
ThreatLens is early and practitioner-built. Rather than empty logo walls, we offer trust signals a regulated buyer can inspect for themselves.
Practitioner-led
Built by security and governance practitioners, drawing on more than 20 years of enterprise cybersecurity and AI governance experience across the region.
Privacy-first telemetry
Zero-trust telemetry is the default: raw prompts and model outputs are not required in ThreatLens SaaS.
Open assurance artifacts
Inspect real output before any sales call — sample AI-BOM exports, evidence reports, and machine-readable CycloneDX and SPDX examples.
Inspectable scanner approach
The scanner is documented, not a black box: detection rules, supported file types, and clear scan limitations.
ThreatLens on ThreatLens
We use our own assurance model — ThreatLens’ own AI-BOM will be published as a downloadable artifact you can inspect.
Start free. Join the design partner program when you are ready for production assurance.
Work with ThreatLens to build AI-BOMs, evidence records, and continuous assurance workflows for selected AI systems.
Apply for Design Partner AccessFor regulated organisations that need private repositories, evidence, monitoring, framework mapping, and deployment control.
Book a DemoConnected across the ThreatLens platform.
AI-BOM and AI assurance questions.
What is an AI-BOM?
An AI-BOM, or AI Bill of Materials, is a structured record of the components that power an AI system. It can include models, datasets, embeddings, prompts, agents, APIs, libraries, vendors, licences, owners, evidence, and relationships.
Is an AI-BOM the same as an SBOM?
No. An SBOM documents software components. An AI-BOM extends the supply-chain idea to AI systems by documenting AI-specific components such as models, datasets, prompts, embeddings, agents, vector stores, and model providers.
Why do regulated enterprises need AI-BOMs?
Regulated enterprises need to prove what AI systems they use, who owns them, what third parties they depend on, what data they process, what risks they create, and what evidence supports approval and monitoring decisions.
Does ThreatLens store raw prompts and model outputs?
Not by default. ThreatLens AI Assurance is designed for metadata-only telemetry, hash-only mode, redacted payloads, and customer-controlled raw storage options.
Can ThreatLens export CycloneDX and SPDX AI-BOMs?
Yes. ThreatLens AI Assurance is scoped to export AI-BOMs as PDF, ThreatLens JSON, CycloneDX AI/ML-BOM, and SPDX 3.0 AI profile formats.
Does ThreatLens make us compliant with the EU AI Act, RBI guidance, CBUAE guidance, or ISO/IEC 42001?
No software can automatically make an organisation legally compliant or certified. ThreatLens supports readiness by helping teams maintain inventory, evidence, monitoring, risk records, framework mappings, and reports.
How is this different from AI governance software?
Traditional AI governance software often starts with workflows, questionnaires, and policy mapping. ThreatLens AI Assurance starts with the technical evidence layer: what powers the AI system, what changed, what risk exists, and what evidence proves it.
How is this different from AI observability?
AI observability focuses on runtime behaviour, performance, cost, traces, and model quality. ThreatLens AI Assurance includes runtime monitoring, but connects it to AI-BOMs, evidence, risk, ownership, compliance readiness, and supplier accountability.
Which teams use ThreatLens AI Assurance?
Security, GRC, engineering, procurement, vendor risk, privacy, audit, and executive teams can all use the same AI assurance record for different decisions.
Can ThreatLens run in private environments?
ThreatLens is designed for public SaaS, private cloud, customer cloud, and on-premises deployment paths depending on the customer plan and regulatory requirements.
Prove what is inside your AI systems.
Start with a free AI-BOM scan. Move to continuous assurance when your team needs private repositories, evidence, monitoring, and regulatory readiness.