Capabilities
Technical modules for AI assurance — not a GRC catalog.
Each capability is a working surface in OptimaTrust: inventory, labs, runtime, evidence. Open a page for the operator-level story.
Inventory
AI registry
A production AI estate register covering applications, agents, models, APIs, RAG systems, MCP servers, datasets, tools, and more.
Inventory
Discovery and shadow AI
Find unsanctioned models, agents, and endpoints. Shadow AI stays a candidate until someone verifies it.
Agents
Agent assurance
Agent cards, tool boundaries, loop limits, and an Agent Governor decision API — built for agentic systems, not chatbots only.
Validate
Security and safety test labs
Run security, safety, and evaluation packs against a stored model or agent HTTP API. Unavailable scanners stay unavailable.
Monitor
Runtime and traces
Ingest user → agent → model → tool hops. Inspect traces. Watch for change, not a fake live intercept.
Transparency
AI trust graph
Interactive knowledge graph of how applications, models, agents, tools, and data actually connect.
Supply chain
AI bill of materials
Versioned AI BOM snapshots with CycloneDX and SPDX export from stored components.
Estate
MCP, RAG, and privacy centers
Dedicated assurance centers for MCP catalogs, retrieval-augmented generation, and privacy profiles.
Assure
Evidence and assurance score
SHA-256 hashed evidence and an explainable 0–100 score across eleven dimensions. Empty dimensions stay NOT_ASSESSED.
Assure
Framework intelligence overlays
ISO 42001, NIST AI RMF, EU AI Act, OWASP LLM, MITRE ATLAS, and sector packs as overlays — not a GRC operating system.
Platform
Hybrid assurance and collector
SaaS, private cloud, on-prem, and hybrid. A customer-side collector sends estate signals without giving away the model weights.
Trusted AI. Assured future.
See OptimaTrust test the systems you actually run.
Bring an agent API, a model endpoint, or a shadow-AI list. We will show registry, labs, score deductions, and evidence — not a GRC slide deck.
