← Solutions

Govern every AI service on your network

Inventory, approval and audit at the resolution layer.

Block, allow or hold each AI tool and API your organization resolves. Evidence for the EU AI Act, CMMC and NIST AI RMF, with no agents deployed.

control.securd.com/gateway/acme/policies/corp-office
Policy: corp-office Published
Greywall Mode
Enforce
Hold Time
86400 s
Default Action
Allow Traffic
Allow list3 entries
  • chatgpt.com
  • claude.ai
  • copilot.microsoft.com
Block list1 entries
  • free-gpt-unlimited.xyz
MalwareC2PornParkedSinkholeDoH providers
The corporate policy: approved assistants by name, a prohibited service blocked, and the security categories enforced.
The problem

Governance frameworks want a record, not a promise

The EU AI Act asks for record-keeping and human oversight. NIST AI RMF asks you to map and manage the AI systems in use. CMMC asks for monitored and controlled communications at the boundary. All three start with the same question: which AI services does this organization actually use, and who decided that was acceptable.

Usage is undocumented

Approved tools are known. Everything else is discovered in an incident or an audit.

Approvals are informal

A Slack message is not an approval record. A list entry with a user, a source and a timestamp is.

Evidence is manual

Screenshots and spreadsheets assembled the week before the assessment.

How it works

From inventory to evidence

Capabilities

Governance controls

Destination inventory

Every AI service and API resolved, by site and month, filterable and exportable per policy.

Approval with provenance

Every allow entry carries who added it, a source reference and an optional expiry. Reviewable, revocable.

Change log

Every policy and list change with user, timestamp and content. Publish history with rollback.

Decision events

Every resolution logged with action and reason. Syslog, CEF, JSON, API and webhooks.

Enforced outside the endpoint

No client software. The control does not depend on the device or the user honoring it.

Per-team scope

Policies per team or business unit, so the approved list for engineering is not the approved list for HR.

Framework mapping

Where the record fits

Securd produces three artifacts assessors ask for: the inventory of AI destinations in use, the approval record for each, and the per-decision log. The mapping below states where each artifact applies. It is a starting point for your control narrative, not a certification.

control mapping
EU AI Act   Art. 12 record-keeping .......... Traffic Logs, change log
            Art. 14 human oversight ......... Greywall hold, approval entries
NIST AI RMF Map, Manage ..................... AI service inventory, per-team policies
CMMC / NIST SP 800-171
            3.13.1 boundary communications .. Policy per site, Default Action Deny
            3.3.1  audit records ............ Events forwarded to the SIEM

Questions teams ask

Is Securd an AI governance platform?

No. Securd governs connections to AI services and agent destinations. It supplies the inventory, the approval record and the decision log that a governance program needs.

Does this cover AI features inside approved SaaS?

No. Only services and APIs that resolve from your network.

How long are logs retained?

Retention is a plan setting. Forward to your SIEM for longer retention.

Build the AI inventory before the audit asks for it

One policy in Learn Only produces the list. Approvals and exports follow.