The company already uses artificial intelligence. The question is who answers for it.
TrustOps keeps the inventory of what uses AI, with purpose and a human owner, applies limits at execution time and stores every decision in a chained trail that cannot be altered afterwards.
Discover · Govern · Control · Audit · Optimise
AI asset
Illustrative dataRegistered use
Automated support on the corporate website
Human owner
Named — with no owner, the asset does not go to production
Risk rating
High · 3 unknown factors lower the confidence of the calculation
Illustrative data — no real asset, company or person.
The problem
AI came in through the back door — and nobody signed for it
It wasn’t a committee decision. It was tools bought per department, tests that became routine and agents granted access without anyone recording who answers for them.
Nobody can list the AI the company uses
Departmental card subscriptions, browser extensions, scattered keys, agents built for a project and left running. When someone asks how many uses exist and which data they touch, the answer is an estimate — and an estimate does not hold up with a client, an audit or an incident.
The policy exists, but it prevents nothing
The document says what is not allowed. Execution does not read documents: the agent calls the model, the model answers, the data leaves. Between the written rule and what actually happens there is nothing checking, limiting or asking for authorisation.
When it goes wrong, it cannot be reconstructed
A client complains about an answer. Someone asks which model replied, under which instruction, under which policy, approved by whom. The records are scattered, may have been edited, and reconstruction becomes an exercise in memory rather than proof.
What changes
From written policy to control that works
The path TrustOps organises — and the point where it stops and calls a person.
“Governance that does not change what happens at execution is just documentation.”
- The AI use is registered with a purpose and a human owner.
- Model, vendor and contract enter the same register.
- The data and systems accessed are declared per asset.
- Risk is computed from visible factors, not an opaque score.
- Each agent gets an identity, a scope and a lifecycle.
- Policy evaluates the request instead of sitting in a document.
- Whatever exceeds the limit goes to another person for approval.
- In a critical situation, access is genuinely interrupted.
- Every decision enters a trail that cannot be altered.
- Cost appears per initiative, agent, model and area.
The structure
Five fronts that hold the control together
These are not loose systems: it is the order in which the problem is solved, from what nobody knows exists to the cost nobody was tracking.
Discover. Govern. Control. Audit. Optimise.
Discover
Identifies AI tools, models, agents, integrations and accounts in use — including what was bought without going through anyone.
Govern
Official inventory with purpose and human owner, plus agents, models, vendors, policies and consents.
Control
Policy engine, approvals, limits and quarantine: authorises, denies, limits or routes to human review.
Audit
A chained trail of decisions, incidents, evidence and risks — what the company could demonstrate if asked.
Optimise
Cost per initiative, agent, model and area, with configurable caps and idle licences in plain sight.
The order matters: without an inventory no policy holds, without policy no control acts, and without a trail nothing can be demonstrated afterwards.
Features
What exists today, inside the product
Every item below is in operation. What is common in governance platforms but does not exist here is not on this page.
Inventory with owner and purpose
Assets, agents, models and vendors, each with a stated purpose, a human owner, the data accessed and current status.
Risk from visible factors
The rating is deterministic and shows what composed it. Missing data becomes an unknown factor and lowers confidence — it is never read as low risk.
Identity per agent
Its own credential, scope, bounded delegation and lifecycle. The effective permission is the intersection of granted and allowed, and denial is the default.
Policy engine
The rule evaluates the request and decides: authorise, deny, limit or route to human review.
Approval with separation
The requester does not approve. The decision is recorded with a justification and a responsible person.
Emergency controls
Interrupt, quarantine, isolate and recover — revoking credentials, ending sessions and cancelling in-flight executions.
Hash-chained trail
Append-only, with integrity verification and reconstruction of a decision’s sequence. A correction is a new record.
Cost and vendors
Spend per initiative, agent, model and area, with caps; and vendor risk from a stated method, with contracts and expiry tracked.
Want to see the inventory applied to the AI your company already uses?
Talk to a specialistHow it works
The path of a request, from ask to record
The highlighted step is where the system stops and hands the decision back to a person.
Cycle of a decision
Illustrative dataRegistered use
The asset enters the inventory with purpose, data accessed and a named human owner.
Agent identity
The agent receives its own identity and a lifecycle — it does not move around as a generic user.
Scoped credential
The credential is born with a defined scope; the value is shown once and the system keeps only the cryptographic digest.
Policy evaluates
Every request goes through the current rule, which considers asset, agent, model, vendor and context.
Limit exceeded
Outside what is allowed, the request does not proceed: it goes to someone other than the requester for approval, with a recorded justification.
Execution allowed
Within scope, the call proceeds — and an active emergency command blocks it immediately, without waiting for a restart.
Cost attributed
Consumption is attributed to the initiative, agent, model and area, against the configured cap.
Event on the trail
The record enters chained to the previous one, allowing the integrity of the chain to be verified later.
Eight-step flow: registered use with an owner, agent identity, scoped credential, request evaluated by policy, limit exceeded with human approval, execution within what is allowed, cost attributed and event written to the chained trail.
TrustOps does not draft policy on its own, does not issue legal opinions, does not decide on risk in place of the responsible person and does not monitor legislation automatically. It organises, applies what was configured and records — decisions remain with people.
Demonstration
The asset, the decision and the link in the trail
Three illustrative screens: the inventory from inside, policy deciding and the chained record.
View 1 — the asset from inside
Illustrative dataAI use in the inventory
Purpose
Answer product questions on the public channel
Owner
A named person in the support area
Data accessed
Catalogue and public policies — no customer base
Status
In production, with a periodic review scheduled
Computed risk
Medium · confidence lowered by 2 factors without information
No missing factor is treated as low risk: it lowers the confidence of the result and stays visible to whoever decides.
View 2 — policy deciding
Illustrative dataRequest evaluated
Request
Agent asks for access to a set of personal data
Rule applied
Personal data requires authorisation — the agent’s scope does not cover it
Decision
Routed to human review
Who decides
Someone other than the requester, with a mandatory justification
View 3 — the link in the trail
Illustrative dataChained record
- Request received from the identified agent
- Policy applied, citing the version in force
- Routed for human approval
- Decision recorded with a justification
Integrity
Each event carries the digest of the previous one — altering one breaks the whole chain
A correction never overwrites: it enters as a new event. Deletion becomes a marker, not an erasure.
Screens built for this page, with invented data. No real asset, vendor, cost or person appears here.
Limits and responsibility
What the system does — and what remains human
A governance product promising compliance would be selling what it cannot deliver. This one states the boundary.
Supports adequacy, does not guarantee it
TrustOps organises evidence, identifies risks and helps demonstrate diligence. Assessing compliance remains with the responsible professionals.
Does not replace whoever signs
Independent auditors, lawyers, data protection officers and security specialists remain necessary. The system supports their work with organised material.
Separation of duties
Requester and approver are necessarily different people, and no role edits a trail event — immutability is enforced in the database, not on the screen.
Isolation per organisation
Data is separated per organisation with access rules in the database itself, and credentials are encrypted at rest.
What this page does not promise: automatic adequacy to any standard, absence of regulatory risk, legal opinions or policy approval without review. What exists is an inventory with owners, limits that act at execution, recorded decisions and a verifiable trail.
Who it is for
Companies past the stage of experimenting with AI
Once AI touches customers, money or personal data, the question stops being technical and becomes one of responsibility.
Those with AI in production and no inventory
Tools bought per department, agents built for a project and keys scattered around — with no single list of who answers for what.
Operations answering to demanding clients
Contracts with security clauses and vendor questionnaires asking what the company can demonstrate, not what it intends to do.
Risk, legal and privacy teams
People who need evidence linked to the corresponding control, policy versions with recorded acceptance and a history nobody can rewrite.
Whoever pays the AI bill without seeing it
Cost diluted across cards and departments, with no cap and no idea which initiative consumed what.
System plans
Three tiers that unlock more as you grow. On Max, you get access to everything.
Starter
Essentials to start
- AI inventory with purpose, human owner and data accessed
- Model and vendor register with contract and status
- Deterministic risk rating with visible factors
- Policies with version, validity, approval and recorded acceptance
- Evidence vault linked to the control it proves
Pro
Full operation
- AI inventory with purpose, human owner and data accessed
- Model and vendor register with contract and status
- Deterministic risk rating with visible factors
- Policies with version, validity, approval and recorded acceptance
- Evidence vault linked to the control it proves
- Policy engine: authorises, denies, limits or routes to human review
- Identity, credential and lifecycle for every AI agent
- Approvals with requester and approver kept separate
- Cost per AI, agent, model and area, with configurable caps
Max
EverythingEverything unlocked
- AI inventory with purpose, human owner and data accessed
- Model and vendor register with contract and status
- Deterministic risk rating with visible factors
- Policies with version, validity, approval and recorded acceptance
- Evidence vault linked to the control it proves
- Policy engine: authorises, denies, limits or routes to human review
- Identity, credential and lifecycle for every AI agent
- Approvals with requester and approver kept separate
- Cost per AI, agent, model and area, with configurable caps
- Hash-chained trail with decision reconstruction
- Emergency controls: interrupt, quarantine and recover
- Discovery of unauthorised AI use inside the company
Questions
Frequently asked questions
What is Centriu TrustOps?
It is the command centre for the company’s artificial intelligence governance, organised in five fronts: discover, govern, control, audit and optimise. It keeps the inventory of what uses AI with a human owner, applies limits at execution, records decisions in a chained trail and tracks cost and risk.
Does TrustOps guarantee compliance?
No, and that restriction is enforced inside the product itself: phrases such as "guaranteed compliance" or "zero risk" are forbidden on any screen or report. What it does is support adequacy, identify risks, organise evidence and help the company demonstrate diligence. Assessment remains human.
Does it replace auditors, lawyers or data protection officers?
No. The system organises, applies what was configured and records — the technical opinion and the responsibility stay with those professionals. The gain is that they work with structured, verifiable material instead of gathering loose files in a rush.
How does the AI inventory work?
Each use is registered with a purpose, a human owner, the data and systems accessed, the models and vendors involved, plus periodic reviews. The risk rating is deterministic and shows the factors that composed it; when information is missing, the factor is recorded as unknown and lowers the confidence of the result.
How are AI agents controlled?
Each agent has its own identity, a scoped credential, bounded delegation and a lifecycle. The permission that counts is the intersection of what was granted and what policy allows — never the sum — and denial is the default behaviour when in doubt.
What happens when something exceeds the limit?
The request does not proceed. It is denied, limited or routed for approval by someone other than the requester, with a recorded justification. The decision stays on the trail, linked to the version of the policy applied.
Is there a real stop button?
Yes, with real effect: interrupting, quarantining or isolating revokes credentials, ends active sessions, cancels in-flight executions and opens an incident. The block applies from the next request, without depending on a restart.
Why is the audit trail different from a log?
Because it is append-only and chained: each event carries the cryptographic digest of the previous one, so altering one breaks the whole chain and that is detectable. A correction is always a new record; deletion becomes a marker, not an erasure. The restriction is enforced in the database, not in the interface.
Can AI cost be tracked?
Yes, per initiative, agent, model and area, with configurable caps. It is also where idle licences and excessive concentration on a single vendor show up.
How does vendor assessment work?
Through a stated method, with contract, status and expiry tracked. A certification only counts when verified, not merely declared; existing controls reduce risk up to a limit, never to zero; and missing data lowers the confidence of the result instead of becoming a good score.
How is each organisation’s data protected?
It is separated per organisation, with access rules applied in the database itself and not only in the application. Credentials are encrypted at rest, a secret’s value is shown once and the system keeps only the cryptographic digest.
Start with an inventory of what your company already uses.
We show how the register with a human owner, the factor-based risk calculation and the chained trail behave with a case from your operation.