OptimaTrust

Building trust in every decision.

Trusted AI. Assured future.

OptimaTrust is continuous AI assurance and security for the systems you actually run: applications, agents, models, APIs, RAG, and MCP. Verify, validate, monitor, and assure with labs, explainable scores, and hashed evidence. It is not a GRC platform — it is the technical record of whether an AI system is the one you think it is, and can be shown to a board or auditor.

Verify, Validate, Monitor, Assure
Explore the platform
OptimaTrust trust orbit: shield at the center, with Govern, Transparency, Safety, and Fairness around it

AI asset types in the register

21

Explainable assurance dimensions

11

Editions: SaaS and On-Premise

2

AI Act and overlay-ready evidence

ISO · NIST · EU

Explainable AI

Scores list deductions. Unavailable tests never count as a pass.

Bias & fairness

Evaluation datasets and fairness dimensions scored only when evidence exists.

Compliance ready

ISO 42001, NIST AI RMF, EU AI Act, OWASP LLM, MITRE ATLAS overlays.

Secure by design

Attack surface, security test lab, MCP and agent-tool assurance.

Why AI assurance

Models shipped. Agents loop. Boards will still ask how you know.

Organisations adopted generative and agentic AI faster than they adopted a way to inventory it, test it, and keep evidence. AI assurance is that discipline: continuous verification of systems in production — security, safety, privacy, fairness, supply chain, and runtime behaviour — with a trail a human can read. It is not enterprise GRC. GRC owns the control library and the audit calendar. Assurance owns the lab, the estate, and the score.

AI is already in production — often without an owner

Copilots, agents, RAG apps, and vendor models ship faster than inventories. Shadow AI is not a future risk. It is the intern’s chatbot, the line-of-business SaaS model, and the MCP server nobody registered. You cannot assure what you have not found.

Agents are privileged systems, not chat windows

A model that only answers is a content problem. An agent that calls tools, writes memory, and loops toward a goal is an access-control problem. Tool catalogs, MCP servers, and loop limits belong on the same register as production APIs.

Policy without a lab is a poster

Responsible-AI statements do not find prompt injection. Spreadsheets do not red-team an endpoint. Boards will ask how you know. The answer has to be tests, traces, listed deductions, and hashed evidence — not a colour on a dashboard.

Regulators ask for intended use and residual risk

ISO 42001, NIST AI RMF, and the EU AI Act all assume you can describe the system, its purpose, how you tested it, and what remains. OptimaTrust stores that technical record. It does not replace legal advice or a certified audit.

Benefits

What operators get from OptimaTrust

A living register, tests against the APIs you ship, traces you ingested, and evidence you can export — without painting a green pass when a scanner was never run.

One estate view

Twenty-one AI asset types on a single register — applications, agents, models, APIs, RAG, MCP, datasets, vendors — with owners and a change log.

Honest scores

Eleven dimensions with listed deductions. Unavailable tests never count as a pass. Empty stays NOT_ASSESSED.

Evidence you can hand over

SHA-256 hashed objects, control maps, and reports from stored snapshots. Auditors ask how you know; you show the pack.

Agent and MCP first-class

Cards, boundaries, Governor decisions, and tool catalogs — not a footnote on a model list.

Discovery with a human gate

Shadow AI stays a candidate until someone registers, marks unmanaged, or decommissions it.

Deploy where the estate lives

SaaS or on-premise. Hybrid collector for networks you do not want to open.

Features

Platform capabilities at a glance

AI registry & 360

Type-filtered views on one register. Relationships, events, and change history per asset.

Discovery & shadow AI

Fingerprint URLs, APIs, and harvests. Candidates are not production until registered.

Security & safety labs

Assess stored model or agent HTTP APIs. Optional Garak, PyRIT, promptfoo, DeepEval, Giskard.

Runtime & traces

Ingest user → agent → model → tool hops. Watches and alerts on signals that exist.

Trust graph & AI BOM

Dependency edges you can path-query. CycloneDX and SPDX export from stored composition.

Framework overlays

ISO 42001, NIST AI RMF, EU AI Act, OWASP LLM/Agentic, MITRE ATLAS — test once, map many.

Trust framework

Govern. Transparency. Safety. Fairness.

Govern

Use-case gates, policy packs, approval matrix, and human accountability.

Transparency

Factsheets, traces, knowledge graph, and explainable score deductions.

Safety

Red-team labs, agent boundaries, runtime events, and incident response.

Fairness

Bias, privacy, and evaluation packs that stay empty until tests actually run.

Estate

Twenty-one AI asset types. One register.

Click a type. Agents, MCP servers, and RAG systems are first-class — not footnotes on a model list. Discovery candidates are not these until an operator registers them.

Selected: AI agent. Every type is a row on one AI register — with owners, relationships, and a change log. Discovery candidates are not these until registered.

Explainable score

Eleven dimensions. Listed deductions.

Dimension 1 / 11

Security

Prompt injection, jailbreaks, data exfiltration, and model/API attack findings.

Overall score is 100 minus listed deductions. If this dimension has no tests and no stored signals, it stays NOT_ASSESSED — never a silent 100.

Framework overlays

ISO 42001. NIST AI RMF. EU AI Act. OWASP. ATLAS.

Test once, map many. Overlays are intelligence on a technical record — not a GRC control library and not a certified audit by themselves.

FAQ

Questions buyers actually ask

No. OptimaTrust is a continuous AI assurance and security platform. It discovers, tests, monitors, and evidences AI systems. Enterprise GRC — Quality, HSE, cyber control libraries, audit calendars — is a different job. OptimaGRC is the GRC product in the same family. The two integrate; they are not the same software.

Also from Optima

OptimaGRC — integrated governance, risk, and compliance.

Enterprise GRC. Separate product. Connected when you need it.

OptimaTrust is integrated with OptimaGRC so AI risk, model evidence, and residual exposure can inform governance, risk, Data Governance, and audit — without turning OptimaTrust into a GRC module. OptimaTrust can also integrate with other platforms you already run: identity, ITSM, cloud, and GRC suites beyond OptimaGRC.

Integrated with OptimaGRC

Push and pull assurance evidence onto the GRC spine when both products are in use.

Open to other platforms

Connectors and APIs so OptimaTrust sits beside the tools you already operate — not a closed stack.

Go to OptimaGRC
OptimaGRC — AI-powered integrated GRC

OptimaTrust integrates with OptimaGRC — and with other platforms you already run.

Trusted AI. Assured future.

See OptimaTrust test the systems you actually run.

Bring an agent API, a model endpoint, or a shadow-AI list. We will show registry, labs, score deductions, and evidence — not a GRC slide deck.