Govern every AI service on your network
Inventory, approval and audit at the resolution layer.
Block, allow or hold each AI tool and API your organization resolves. Evidence for the EU AI Act, CMMC and NIST AI RMF, with no agents deployed.
- chatgpt.com
- claude.ai
- copilot.microsoft.com
- free-gpt-unlimited.xyz
Governance frameworks want a record, not a promise
The EU AI Act asks for record-keeping and human oversight. NIST AI RMF asks you to map and manage the AI systems in use. CMMC asks for monitored and controlled communications at the boundary. All three start with the same question: which AI services does this organization actually use, and who decided that was acceptable.
Usage is undocumented
Approved tools are known. Everything else is discovered in an incident or an audit.
Approvals are informal
A Slack message is not an approval record. A list entry with a user, a source and a timestamp is.
Evidence is manual
Screenshots and spreadsheets assembled the week before the assessment.
From inventory to evidence
Inventory
Every AI service resolved, by site, with query counts and first-seen dates.
Approve and restrict
Allow list entries with source and reference. Block list entries with expiry. First-seen services held until reviewed.
Export the record
Traffic Logs as CSV or JSON, the change log with every approval, and the publish history. Forward to the SIEM for retention.
Governance controls
Destination inventory
Every AI service and API resolved, by site and month, filterable and exportable per policy.
Approval with provenance
Every allow entry carries who added it, a source reference and an optional expiry. Reviewable, revocable.
Change log
Every policy and list change with user, timestamp and content. Publish history with rollback.
Decision events
Every resolution logged with action and reason. Syslog, CEF, JSON, API and webhooks.
Enforced outside the endpoint
No client software. The control does not depend on the device or the user honoring it.
Per-team scope
Policies per team or business unit, so the approved list for engineering is not the approved list for HR.
Where the record fits
Securd produces three artifacts assessors ask for: the inventory of AI destinations in use, the approval record for each, and the per-decision log. The mapping below states where each artifact applies. It is a starting point for your control narrative, not a certification.
EU AI Act Art. 12 record-keeping .......... Traffic Logs, change log
Art. 14 human oversight ......... Greywall hold, approval entries
NIST AI RMF Map, Manage ..................... AI service inventory, per-team policies
CMMC / NIST SP 800-171
3.13.1 boundary communications .. Policy per site, Default Action Deny
3.3.1 audit records ............ Events forwarded to the SIEMQuestions teams ask
Is Securd an AI governance platform?
No. Securd governs connections to AI services and agent destinations. It supplies the inventory, the approval record and the decision log that a governance program needs.
Does this cover AI features inside approved SaaS?
No. Only services and APIs that resolve from your network.
How long are logs retained?
Retention is a plan setting. Forward to your SIEM for longer retention.
Build the AI inventory before the audit asks for it
One policy in Learn Only produces the list. Approvals and exports follow.