OptimaTrust is continuous AI assurance and security for the systems you actually run: applications, agents, models, APIs, RAG, and MCP. Verify, validate, monitor, and assure with labs, explainable scores, and hashed evidence. It is not a GRC platform — it is the technical record of whether an AI system is the one you think it is, and can be shown to a board or auditor.
Scores list deductions. Unavailable tests never count as a pass.
Bias & fairness
Evaluation datasets and fairness dimensions scored only when evidence exists.
Compliance ready
ISO 42001, NIST AI RMF, EU AI Act, OWASP LLM, MITRE ATLAS overlays.
Secure by design
Attack surface, security test lab, MCP and agent-tool assurance.
Why AI assurance
Models shipped. Agents loop. Boards will still ask how you know.
Organisations adopted generative and agentic AI faster than they adopted a way to inventory it, test it, and keep evidence. AI assurance is that discipline: continuous verification of systems in production — security, safety, privacy, fairness, supply chain, and runtime behaviour — with a trail a human can read. It is not enterprise GRC. GRC owns the control library and the audit calendar. Assurance owns the lab, the estate, and the score.
AI is already in production — often without an owner
Copilots, agents, RAG apps, and vendor models ship faster than inventories. Shadow AI is not a future risk. It is the intern’s chatbot, the line-of-business SaaS model, and the MCP server nobody registered. You cannot assure what you have not found.
Agents are privileged systems, not chat windows
A model that only answers is a content problem. An agent that calls tools, writes memory, and loops toward a goal is an access-control problem. Tool catalogs, MCP servers, and loop limits belong on the same register as production APIs.
Policy without a lab is a poster
Responsible-AI statements do not find prompt injection. Spreadsheets do not red-team an endpoint. Boards will ask how you know. The answer has to be tests, traces, listed deductions, and hashed evidence — not a colour on a dashboard.
Regulators ask for intended use and residual risk
ISO 42001, NIST AI RMF, and the EU AI Act all assume you can describe the system, its purpose, how you tested it, and what remains. OptimaTrust stores that technical record. It does not replace legal advice or a certified audit.
Benefits
What operators get from OptimaTrust
A living register, tests against the APIs you ship, traces you ingested, and evidence you can export — without painting a green pass when a scanner was never run.
One estate view
Twenty-one AI asset types on a single register — applications, agents, models, APIs, RAG, MCP, datasets, vendors — with owners and a change log.
Honest scores
Eleven dimensions with listed deductions. Unavailable tests never count as a pass. Empty stays NOT_ASSESSED.
Evidence you can hand over
SHA-256 hashed objects, control maps, and reports from stored snapshots. Auditors ask how you know; you show the pack.
Agent and MCP first-class
Cards, boundaries, Governor decisions, and tool catalogs — not a footnote on a model list.
Discovery with a human gate
Shadow AI stays a candidate until someone registers, marks unmanaged, or decommissions it.
Deploy where the estate lives
SaaS or on-premise. Hybrid collector for networks you do not want to open.
How assurance runs
Verify. Validate. Monitor. Assure.
Four verbs. One estate. Identity and lineage first, then tests, then live behaviour, then the pack you hand to an auditor or board.
Type-filtered views on one register. Relationships, events, and change history per asset.
Discovery & shadow AI
Fingerprint URLs, APIs, and harvests. Candidates are not production until registered.
Security & safety labs
Assess stored model or agent HTTP APIs. Optional Garak, PyRIT, promptfoo, DeepEval, Giskard.
Runtime & traces
Ingest user → agent → model → tool hops. Watches and alerts on signals that exist.
Trust graph & AI BOM
Dependency edges you can path-query. CycloneDX and SPDX export from stored composition.
Framework overlays
ISO 42001, NIST AI RMF, EU AI Act, OWASP LLM/Agentic, MITRE ATLAS — test once, map many.
Trust framework
Govern. Transparency. Safety. Fairness.
Govern
Use-case gates, policy packs, approval matrix, and human accountability.
Transparency
Factsheets, traces, knowledge graph, and explainable score deductions.
Safety
Red-team labs, agent boundaries, runtime events, and incident response.
Fairness
Bias, privacy, and evaluation packs that stay empty until tests actually run.
Estate
Twenty-one AI asset types. One register.
Click a type. Agents, MCP servers, and RAG systems are first-class — not footnotes on a model list. Discovery candidates are not these until an operator registers them.
Selected: AI agent. Every type is a row on one AI register — with owners, relationships, and a change log. Discovery candidates are not these until registered.
Explainable score
Eleven dimensions. Listed deductions.
Dimension 1 / 11
Security
Prompt injection, jailbreaks, data exfiltration, and model/API attack findings.
Overall score is 100 minus listed deductions. If this dimension has no tests and no stored signals, it stays NOT_ASSESSED — never a silent 100.
No. OptimaTrust is a continuous AI assurance and security platform. It discovers, tests, monitors, and evidences AI systems. Enterprise GRC — Quality, HSE, cyber control libraries, audit calendars — is a different job. OptimaGRC is the GRC product in the same family. The two integrate; they are not the same software.
Also from Optima
OptimaGRC — integrated governance, risk, and compliance.
Enterprise GRC. Separate product. Connected when you need it.
OptimaTrust is integrated with OptimaGRC so AI risk, model evidence, and residual exposure can inform governance, risk, Data Governance, and audit — without turning OptimaTrust into a GRC module. OptimaTrust can also integrate with other platforms you already run: identity, ITSM, cloud, and GRC suites beyond OptimaGRC.
Integrated with OptimaGRC
Push and pull assurance evidence onto the GRC spine when both products are in use.
Open to other platforms
Connectors and APIs so OptimaTrust sits beside the tools you already operate — not a closed stack.