OptimaTrust

Platform

Continuous AI assurance — from register to runtime.

OptimaTrust is sector-neutral software for discovering, assessing, testing, monitoring, and continuously assuring AI systems. It is not OptimaGRC and not a policy-only governance suite.

Command Center

Live KPIs from stored PostgreSQL data and event streams. Empty estates show empty. Copilot answers grounded SQL intents — it is not an unconstrained LLM.

Estate and discovery

Unified AI register, type-filtered views, shadow-AI candidates, connectors, and a customer-side collector. Candidates are not assets until registered.

Assurance labs

Assessments against stored model or agent HTTP APIs. Security and red-team engines when installed. Findings, incidents, remediation, and re-assurance after change.

Runtime and governor

Trace ingest, watches, alerts, declared agent boundaries, and a Governor decide API. No invented traffic. No silent intercept of every third-party agent.

Evidence and overlays

SHA-256 evidence, eleven-dimension score, HMAC assurance certificates, ISO 42001 / NIST AI RMF / EU AI Act overlays. Not a GRC operating system.

Identity and tenancy

Multi-tenant isolation, RBAC, SSO (Entra ID and Google Workspace when configured), hash-chained audit logs, SaaS / private cloud / on-prem / hybrid.

The estate you actually run

Selected: AI agent. Every type is a row on one AI register — with owners, relationships, and a change log. Discovery candidates are not these until registered.

Explainable scoring

Dimension 1 / 11

Security

Prompt injection, jailbreaks, data exfiltration, and model/API attack findings.

Overall score is 100 minus listed deductions. If this dimension has no tests and no stored signals, it stays NOT_ASSESSED — never a silent 100.

Trusted AI. Assured future.

See OptimaTrust test the systems you actually run.

Bring an agent API, a model endpoint, or a shadow-AI list. We will show registry, labs, score deductions, and evidence — not a GRC slide deck.