Custos finds the AI your organization actually uses, applies your policies to every prompt, response and agent action, and keeps the evidence ready for auditors, regulators and records requests.
For government agencies and regulated enterprises. Built for Microsoft 365, Purview and Entra ID environments.
Custos scans browsers, endpoints, SaaS, cloud accounts and API traffic continuously. Every AI tool, model, agent and API key it finds is attributed to a person and a department, then placed in one registry.
Generative AI in the browser, plugins inside approved SaaS, unsanctioned API keys in code. Each finding shows who used it and what data it could reach.
Applications, models, agents, vendors, datasets and use cases, each with a business owner, technical owner, risk tier, approval status and renewal date.
See which agents call which models, which models touch which datasets, and which vendors sit behind them. Retire one asset and know what breaks.
Every module writes to the same registry, the same control set and the same audit trail. Start with discovery and add the rest as your program matures.
Continuous scanning across browsers, endpoints, SaaS, cloud and APIs, with every finding attributed to a user and department.
Used by Security, IT
A single registry of record for every AI asset, with owners, purpose, data classification, lifecycle and dependencies.
Used by AI office, IT
Versioned policies, approved and blocked catalogs, and risk-based approval workflows that route each request to the right reviewers.
Used by AI office, legal, privacy
Configurable scoring for inherent and residual risk across privacy, security, bias, hallucination, agentic and regulatory dimensions.
Used by Risk, procurement
A common control set mapped across frameworks, with automated evidence collection, freshness monitoring and audit-ready packages.
Used by Compliance, internal audit
Real-time inspection of prompts, outputs, tool calls and agent actions, enforcing policy before data leaves your boundary.
Used by Security, privacy
Tamper-resistant logging of every AI interaction, with retention, legal hold, eDiscovery and full event reconstruction.
Used by Audit, records, legal
Incidents open automatically from violations, leaks and unauthorized AI, with a workspace to investigate, remediate and close.
Used by Security, compliance
Spend by token, model, agent, vendor and department, with budgets, anomaly alerts, license reclamation and ROI reporting.
Used by Finance, leadership
Native Microsoft 365 integration plus an extensible connector and API framework for security, IT, GRC and business systems.
Used by IT, security
Guardrails inspect prompts, files, responses and tool calls in real time. You decide, per department, role or data type, whether Custos allows, coaches, redacts or blocks.
PII, PHI, payment data, financial records, source code, credentials and confidential documents.
Prompt injection, jailbreak attempts and unsafe content, in prompts and in uploaded files.
Responses are checked for leaked data and restricted content before they reach the user.
Keep the work moving without the sensitive values ever leaving your boundary.
Custos maps each control to every requirement it satisfies. One piece of evidence, collected automatically and kept fresh, covers the same obligation across all your frameworks.
| Control | NIST AI RMF | ISO/IEC 42001 | ISO/IEC 27001 | NIST CSF | SOC 2 | EU AI Act | GDPR |
|---|---|---|---|---|---|---|---|
| AI system inventory | |||||||
| Risk assessment before deployment | |||||||
| Human oversight of high-risk use | |||||||
| Prompt and output logging | |||||||
| Sensitive data protection | |||||||
| Third-party AI vendor review | |||||||
| Incident response for AI events | |||||||
| Transparency to affected people |
Each agent gets an identity, an owner, a permission set and approval thresholds. Every tool call is logged, drift is flagged, and one switch stops it everywhere.
Purpose, owner, risk rating, model and tool inventory for every agent.
Approval points and transaction thresholds for consequential actions.
Alerts when an agent calls new tools, new data or a changed model.
Suspend one agent or all agents of a type, with the action recorded.
Who asked, which model answered, what data was touched, what the policy decided and what happened next. Custos rebuilds the full sequence and preserves it as evidence.
Prompts, outputs, model and agent activity, tool calls, data access, approvals and configuration changes, timestamped and attributed. Tamper-resistant where you require it.
Retention schedules and labels for AI conversations, legal hold, public-records request search, chain of custody and defensible deletion.
Automatic incidents from policy violations and leaks, an investigation workspace, root cause, corrective actions and post-incident review.
Token, API, model, agent and license spend, allocated by department, application and use case. Set budgets, catch anomalies and reclaim licenses nobody uses.
Allocate cost to the teams that incur it.
Find inactive and underused Copilot and AI seats.
Active users, time saved and value by use case.
The built-in assistant answers from your own registry, controls, evidence and logs. Every answer cites its sources, and it only shows what your role is permitted to see.
Four departments had unauthorized generative AI activity in the last 30 days. Human Services accounts for most of it.
| Department | Tools | Users |
|---|---|---|
| Human Services | 2 | 31 |
| Engineering | 3 | 12 |
| Public Works | 1 | 6 |
| Legal | 1 | 2 |
Answer limited to records your role can access. Illustrative data.
Each team works in its own view, on the same record.
Enterprise posture, high-risk systems, spend and adoption in one executive view.
Shadow AI, guardrail events, agent permissions and incidents, fed to your SIEM.
Assessments, control testing, evidence freshness and audit-ready packages.
Impact assessments, retention, legal hold and public-records search.
Budgets, chargeback, vendor risk, contracts and license renewals.
A simple portal to find approved tools, request new ones, take training and report issues.
Deep Microsoft 365 integration for labels, DLP, retention and identity, plus an open connector and API framework for everything else.
Custos reads your existing labels and policies, so there is nothing to classify twice.
SSO through SAML and OIDC, automated user provisioning and deprovisioning, and custom roles with least-privilege access.
Custos stores what your people say to AI. It is engineered accordingly.
In transit and at rest, with managed keys and secrets handling.
Tenant isolation, least-privilege access and privileged-access controls.
Configurable data residency and retention to meet your obligations.
High availability, backup and disaster recovery, with security monitoring throughout.
Developed against ISO/IEC 27001 and SOC 2 criteria, and delivered by SDLC Corp, whose operations are certified to ISO/IEC 27001:2022 and ISO 9001:2015.
Request the security pack