AI assistance

AI that drafts. People who decide.

Sentinel uses AI to write first drafts, summarise long material and give work a second read. It runs on your own workspace, it is limited to what the signed-in user is already allowed to see, and everything it produces arrives as a draft with a person’s review still to come.

Self-service signup opens shortly — we will set you up in the meantime

ControlsSentinel interface, reproduced
Control LibraryFramework ReadinessTest ScheduleTest HistoryFindings
Operating
18
Needs evidence
6
Not implemented
2
Owners assigned
24/26
  • A.5.1Policies for information security
    Owner
    Priya Raman
    Status
    Passed
    Evidence
    Accepted
    Last tested
    28 Jul 2026
  • A.5.18Access rights
    Owner
    Priya Raman
    Status
    Passed
    Evidence
    Accepted
    Last tested
    26 Jun 2026
  • A.8.5Secure authentication
    Owner
    Priya Raman
    Status
    Passed
    Evidence
    Accepted
    Last tested
    14 Aug 2026
  • + 5 more in the workspace

On a control, the AI recommendation opens in the same panel as the record. Checking it should not require a second tab.

What it helps with

Six jobs, and what each one is worth.

Most of the time saved by AI in governance work is not saved on thinking. It is saved on the blank page, on re-reading a contract to find the one clause that matters, and on writing the same paragraph for the fourth quarter in a row.

Drafting a policy
A first draft of a policy that reflects the frameworks in your scope and your company’s industry, size and country. You edit it, you approve it, you own it. It starts the document; it does not finish it.
Summarising what is in front of you
Assessment results, a set of findings, a control’s effectiveness and last test date. A summary you can check, with the source it summarised still on the screen next to it.
Review assistance
A second read of a policy or a pasted contract: what is missing, which clauses are unclear, and what it recommends doing. Suggestions, for a person to accept or reject.
Executive narrative
The paragraph that sits above the numbers in a board summary — drawn from the register rather than from memory. Whoever signs the report edits it first.
Suggesting next actions
Given the gaps you actually have, an opinion on what to do next. It is ordered by what the data suggests matters, and re-ordered by you the moment you disagree, because you know things the register does not.
Putting a requirement in plain words
A framework clause restated against your own scope, so the person implementing it is not interpreting a standard alone at 6pm. A reading aid — not an interpretation to rely on, and not advice.

Where it runs

The boundary, in plain terms.

If you are the person who has to sign off on a vendor’s AI features, this is the section you came for. No metaphors about walled gardens — just where the request goes, what it can reach, and which document governs it.

Called from the server
Sentinel makes the request from its own backend. Nothing in your users’ browsers holds a provider key, and no browser code calls the provider’s API directly.
One provider, named
AI requests go to Anthropic, in the United States. Application compute runs on Vercel in the United States. Your Sentinel data is stored in Supabase in Canada (ca-central-1).
Scoped to your tenant
An assistant works on your workspace. Not another customer’s, and not a shared pool of everybody’s controls and evidence blended together.
Bounded by the user’s access
Inside your tenant it is limited to content the signed-in user is authorised to see. Asking an assistant is not a route around a permission somebody deliberately did not grant.
The request, with workspace context
What is sent is the item you asked about, and often a workspace summary — record names, statuses, counts and saved answers. It goes from our server to the provider, not a public chat window.
Written down, not just described
The AI Features Notice is the version of this that counts. If your procurement team needs a term rather than a paragraph, that is where to look — and where to push back.

The question everybody asks next

Once a buyer has read the paragraph above, they ask what the provider does with the content of a request. That answer belongs in the AI Features Notice and the Data Processing Addendum, where it is a term of an agreement someone is accountable for — not in a sentence on a marketing page that no one signed. So read it there. If it does not yet say what your own governance process needs it to say, ask us before you rely on it. A hard question now is cheaper for both of us than an assumption later.

The limits

What it will not do, stated flatly.

Every vendor in this category writes this list vaguely. Writing it plainly costs nothing, because a serious buyer asks all of it on the call anyway — and because the limits are the design rather than an embarrassment.

It will not

  • Decide whether you are compliant

    That is a judgement with consequences attached to it. A draft is not a decision, and a summary is not a conclusion.

  • Create a certification fact

    No output makes an organisation certified, attested or accepted. A certification body, an auditor or an insurer does that, and none of them are inside this product.

  • Settle what a contract or a law requires

    It can mark a contract clause missing or unclear. Whether that changes your obligations is not its call, and it is not legal advice.

  • Sign anything

    An output has no author until a person puts their name against it. Until then it is unreviewed text.

  • Stand alone under a real decision

    No certification, insurance or legal decision should rest on AI output by itself — including a decision to tell someone you are ready.

It will

  • Save you the blank page

    Most governance documents are not hard to write. They are hard to start, and they are started at the wrong time of day.

  • Read faster than you can

    A pasted contract, summarised to the risks and renewal action its owner has to act on, with the contract record still on screen.

  • Notice what is vague

    A contract clause marked Unclear, or a policy missing a section, is what an auditor asks about. A second read flags it before they do.

  • Draft the narrative you rewrite anyway

    The board paragraph, generated from the register, then edited by whoever has to stand behind it in the room.

  • Show its source

    An output you cannot trace back to something in your workspace is an output you should not use. So answers are told to name the records they drew on.

How a draft becomes usable

Ask, check, own, then rely.

Four steps, in this order, because the order is what makes the output safe to use. Skipping the middle two is how organisations end up with a policy nobody in the building can explain.

  1. 01

    Ask in context

    You are already on a control, an assessment or a report when you ask. The request carries that context, so the answer is about your environment rather than about security in general.

  2. 02

    Check it against the source

    The control, evidence or finding it drew on stays where you can see it. Checking is the entire point of this step, so it is a glance rather than an export and a diff.

  3. 03

    Edit it and take it on

    You fix what is wrong, cut what is padding, and put a name against the result. From that point it behaves like everything else in the register: a status, a date, an owner.

  4. 04

    Then rely on it

    After a person has reviewed and owned it, it is your document. Before that it is a draft, and it should be described that way to anyone who asks — including an auditor.

If an AI output would change a decision, a person reads it first. That is not a limitation we are apologising for — it is the whole design.

If you would rather not

The product works without it.

Some organisations are not ready to put governance material through an AI assistant, and that is a reasonable position to hold rather than an objection to be handled.

The control register, the evidence library, assessments, the risk register, action tracking, the insurance readiness workspace and the reporting are all ordinary software. They do what they do whether or not anybody in your organisation ever opens an assistant. Nothing in the workflow waits for an AI response to continue, and no part of your readiness depends on one having been used.

If your own policy is that AI assistance is reviewed before it is adopted, then the honest sequence is: use the rest of Sentinel, read the AI Features Notice, take it through whatever review your organisation runs, and decide afterwards. That order works. The reverse — adopting first and reviewing when someone asks — is the one that causes trouble.

Questions

What buyers ask before they turn it on.

These are the questions that come up in a security review of this feature, answered the way we would answer them on a call.

Is AI deciding anything about our compliance?
No. AI in Sentinel drafts, summarises and suggests. Every output is a draft until a person reviews it, edits it and owns it. Nothing marks a control as met, closes a gap, accepts a risk or declares a framework satisfied on its own — those are judgements with consequences, and they belong to named people in your organisation.
Can an assistant see another customer’s data?
No. Requests are scoped to your own tenant, and within your tenant to content the signed-in user is authorised to see. A user who cannot open a document in the interface does not get it back out of an assistant instead.
Which provider is used, and where do the calls go?
Anthropic, in the United States, called from Sentinel’s server rather than from the browser. Your workspace data is stored in Canada (ca-central-1) and application compute runs in the United States. If a cross-border transfer needs to be documented for your own governance, those are the facts to document.
What does the provider do with the content of a request?
That answer belongs in writing, in the AI Features Notice and the Data Processing Addendum, where it is a contractual term rather than a marketing sentence. Read it there before you rely on it, and if it does not say what your procurement process needs it to say, ask us rather than assuming.
Do we have to use the AI features at all?
No. The control register, the evidence library, assessments, the risk register, action tracking and reporting all work if nobody in your organisation ever opens an assistant. Some organisations turn to it for most first drafts; others use it only for summaries. Both are normal.
Is AI assistance unlimited?
No. AI assistance on every plan runs within a monthly usage allowance, and Full Platform and the advisory plans have a larger one than Essentials. Different AI actions use different amounts of it, and larger ones, such as generating a report, use considerably more. When the allowance is used up, further AI requests are declined until it resets at the start of the next month; the rest of the workspace keeps working, and there is no automatic overage charge. Where extra AI usage is offered, it is a separate purchase that an owner or admin chooses to make.
Can we show an AI-drafted policy to an auditor?
You can show a policy your organisation has reviewed, approved and owns — which is the same standard that applies to a policy someone wrote from a template or from scratch. What an auditor tests is whether the control operates and whether the evidence supports it. What you must not do is present unreviewed output as approved, and that is true of any draft, from any source.

Judge the assistance by the draft it produces.

Bring a control you have been avoiding writing up, and see what comes back — then edit it, which is the part that was always going to be yours.

Book a walkthrough

Self-service signup opens shortly — we will set you up in the meantime

  • Published pricing — no quote-on-request tier
  • No credit card required for the trial
  • No automatic charge when a trial ends
  • Tenant-isolated architecture, data stored in Canada
  • Clear data-processing terms
  • No compliance guarantee — human judgement still required