AI assistance
AI that drafts. People who decide.
Sentinel uses AI to write first drafts, summarise long material and give work a second read. It runs on your own workspace, it is limited to what the signed-in user is already allowed to see, and everything it produces arrives as a draft with a person’s review still to come.
Self-service signup opens shortly — we will set you up in the meantime
| Control | Owner | Status | Evidence | Last tested |
|---|---|---|---|---|
| A.5.1Policies for information security | Priya Raman | Passed | Accepted | 28 Jul 2026 |
| A.5.18Access rights | Priya Raman | Passed | Accepted | 26 Jun 2026 |
| A.8.5Secure authentication | Priya Raman | Passed | Accepted | 14 Aug 2026 |
| A.8.13Information backup | Jordan Blake | Passed | Accepted | 18 Jun 2026 |
| A.8.2Privileged access rights | Priya Raman | Failed | Needs Review | 20 Aug 2026 |
| A.8.7Protection against malware | Jordan Blake | Tested | Accepted | 28 Aug 2026 |
| CC9.2Vendor and business partner risk management | Elena Kowalski | Failed | Accepted | 12 Aug 2026 |
| PR.AA-01Identities and credentials are managed | Unassigned | Not Tested | Missing | — |
- A.5.1Policies for information security
- Owner
- Priya Raman
- Status
- Passed
- Evidence
- Accepted
- Last tested
- 28 Jul 2026
- A.5.18Access rights
- Owner
- Priya Raman
- Status
- Passed
- Evidence
- Accepted
- Last tested
- 26 Jun 2026
- A.8.5Secure authentication
- Owner
- Priya Raman
- Status
- Passed
- Evidence
- Accepted
- Last tested
- 14 Aug 2026
- + 5 more in the workspace
On a control, the AI recommendation opens in the same panel as the record. Checking it should not require a second tab.
What it helps with
Six jobs, and what each one is worth.
Most of the time saved by AI in governance work is not saved on thinking. It is saved on the blank page, on re-reading a contract to find the one clause that matters, and on writing the same paragraph for the fourth quarter in a row.
- Drafting a policy
- A first draft of a policy that reflects the frameworks in your scope and your company’s industry, size and country. You edit it, you approve it, you own it. It starts the document; it does not finish it.
- Summarising what is in front of you
- Assessment results, a set of findings, a control’s effectiveness and last test date. A summary you can check, with the source it summarised still on the screen next to it.
- Review assistance
- A second read of a policy or a pasted contract: what is missing, which clauses are unclear, and what it recommends doing. Suggestions, for a person to accept or reject.
- Executive narrative
- The paragraph that sits above the numbers in a board summary — drawn from the register rather than from memory. Whoever signs the report edits it first.
- Suggesting next actions
- Given the gaps you actually have, an opinion on what to do next. It is ordered by what the data suggests matters, and re-ordered by you the moment you disagree, because you know things the register does not.
- Putting a requirement in plain words
- A framework clause restated against your own scope, so the person implementing it is not interpreting a standard alone at 6pm. A reading aid — not an interpretation to rely on, and not advice.
Where it runs
The boundary, in plain terms.
If you are the person who has to sign off on a vendor’s AI features, this is the section you came for. No metaphors about walled gardens — just where the request goes, what it can reach, and which document governs it.
- Called from the server
- Sentinel makes the request from its own backend. Nothing in your users’ browsers holds a provider key, and no browser code calls the provider’s API directly.
- One provider, named
- AI requests go to Anthropic, in the United States. Application compute runs on Vercel in the United States. Your Sentinel data is stored in Supabase in Canada (ca-central-1).
- Scoped to your tenant
- An assistant works on your workspace. Not another customer’s, and not a shared pool of everybody’s controls and evidence blended together.
- Bounded by the user’s access
- Inside your tenant it is limited to content the signed-in user is authorised to see. Asking an assistant is not a route around a permission somebody deliberately did not grant.
- The request, with workspace context
- What is sent is the item you asked about, and often a workspace summary — record names, statuses, counts and saved answers. It goes from our server to the provider, not a public chat window.
- Written down, not just described
- The AI Features Notice is the version of this that counts. If your procurement team needs a term rather than a paragraph, that is where to look — and where to push back.
The question everybody asks next
Once a buyer has read the paragraph above, they ask what the provider does with the content of a request. That answer belongs in the AI Features Notice and the Data Processing Addendum, where it is a term of an agreement someone is accountable for — not in a sentence on a marketing page that no one signed. So read it there. If it does not yet say what your own governance process needs it to say, ask us before you rely on it. A hard question now is cheaper for both of us than an assumption later.
The limits
What it will not do, stated flatly.
Every vendor in this category writes this list vaguely. Writing it plainly costs nothing, because a serious buyer asks all of it on the call anyway — and because the limits are the design rather than an embarrassment.
It will not
Decide whether you are compliant
That is a judgement with consequences attached to it. A draft is not a decision, and a summary is not a conclusion.
Create a certification fact
No output makes an organisation certified, attested or accepted. A certification body, an auditor or an insurer does that, and none of them are inside this product.
Settle what a contract or a law requires
It can mark a contract clause missing or unclear. Whether that changes your obligations is not its call, and it is not legal advice.
Sign anything
An output has no author until a person puts their name against it. Until then it is unreviewed text.
Stand alone under a real decision
No certification, insurance or legal decision should rest on AI output by itself — including a decision to tell someone you are ready.
It will
Save you the blank page
Most governance documents are not hard to write. They are hard to start, and they are started at the wrong time of day.
Read faster than you can
A pasted contract, summarised to the risks and renewal action its owner has to act on, with the contract record still on screen.
Notice what is vague
A contract clause marked Unclear, or a policy missing a section, is what an auditor asks about. A second read flags it before they do.
Draft the narrative you rewrite anyway
The board paragraph, generated from the register, then edited by whoever has to stand behind it in the room.
Show its source
An output you cannot trace back to something in your workspace is an output you should not use. So answers are told to name the records they drew on.
How a draft becomes usable
Ask, check, own, then rely.
Four steps, in this order, because the order is what makes the output safe to use. Skipping the middle two is how organisations end up with a policy nobody in the building can explain.
- 01
Ask in context
You are already on a control, an assessment or a report when you ask. The request carries that context, so the answer is about your environment rather than about security in general.
- 02
Check it against the source
The control, evidence or finding it drew on stays where you can see it. Checking is the entire point of this step, so it is a glance rather than an export and a diff.
- 03
Edit it and take it on
You fix what is wrong, cut what is padding, and put a name against the result. From that point it behaves like everything else in the register: a status, a date, an owner.
- 04
Then rely on it
After a person has reviewed and owned it, it is your document. Before that it is a draft, and it should be described that way to anyone who asks — including an auditor.
If an AI output would change a decision, a person reads it first. That is not a limitation we are apologising for — it is the whole design.
If you would rather not
The product works without it.
Some organisations are not ready to put governance material through an AI assistant, and that is a reasonable position to hold rather than an objection to be handled.
The control register, the evidence library, assessments, the risk register, action tracking, the insurance readiness workspace and the reporting are all ordinary software. They do what they do whether or not anybody in your organisation ever opens an assistant. Nothing in the workflow waits for an AI response to continue, and no part of your readiness depends on one having been used.
If your own policy is that AI assistance is reviewed before it is adopted, then the honest sequence is: use the rest of Sentinel, read the AI Features Notice, take it through whatever review your organisation runs, and decide afterwards. That order works. The reverse — adopting first and reviewing when someone asks — is the one that causes trouble.
Questions
What buyers ask before they turn it on.
These are the questions that come up in a security review of this feature, answered the way we would answer them on a call.
Is AI deciding anything about our compliance?
Can an assistant see another customer’s data?
Which provider is used, and where do the calls go?
What does the provider do with the content of a request?
Do we have to use the AI features at all?
Is AI assistance unlimited?
Can we show an AI-drafted policy to an auditor?
Judge the assistance by the draft it produces.
Bring a control you have been avoiding writing up, and see what comes back — then edit it, which is the part that was always going to be yours.
Self-service signup opens shortly — we will set you up in the meantime
- Published pricing — no quote-on-request tier
- No credit card required for the trial
- No automatic charge when a trial ends
- Tenant-isolated architecture, data stored in Canada
- Clear data-processing terms
- No compliance guarantee — human judgement still required