19 AI Engines. Operational Intelligence.
Every AI engine is embedded in workflows — analysing evidence, generating policies, scoring risk, detecting phishing patterns, and recommending remediations. Not isolated chat features.
AI Engine Distribution
19 AI engines + 16 deterministic modules = 35 intelligence services
How engines work together
Signal Sources
Evidence uploads, scans, integrations, user actions
Engine Analysis
AI processes signals — classifies, scores, and maps to controls
Output Decision
Recommendations, narratives, risk scores, fix plans generated
Workflow Action
Alerts fired, reports written, queues updated, agents dispatched
13 Direct AI Engines
Embedded directly in platform workflows. Each engine fires on specific events — uploads, submissions, findings, and requests.
Flo— Conversational Intelligence
AI-powered compliance assistant with streaming responses, RAG knowledge retrieval, and tool use that queries live platform data.
FloAva— Contextual Guidance
Embedded in every assessment. Contextual requirement explanations, evidence suggestions, and guided mode for junior QSAs.
Policy Copilot— Documentation AI
5-step wizard generates PCI-mapped security policies. AI classification, clause generation, DOCX & PDF export.
Evidence Intelligence— Document AI
Auto-analyses every uploaded document. AI Vision for screenshots, sensitive data detection, requirement mapping, gap analysis.
Remediation AI— Fix Intelligence
AI-generated fix plans with effort estimates, SLA management, 3-level escalation engine, and compensating control suggestions.
Architecture AI— Environment Intelligence
Natural language to network diagrams. CDE scope assessment, segmentation risk detection, change impact analysis.
Human Risk AI— People Intelligence
4-factor risk scoring combining training, phishing, policy, and behaviour. Predictive trajectories, real-time recalculation.
Phishing AI— Campaign Intelligence
Generates realistic phishing scenarios by objective, difficulty, and tone. CEO fraud, credential harvest, invoice scams. Auto-remediation on click-through.
Lead Matching— QSA Marketplace
Deterministic scoring algorithm with AI-generated match reasoning. Connects merchants with the right QSA based on industry, scope, and location.
Document Extractor— Intake Intelligence
Upload existing ROC or SAQ reports. AI extracts fields and pre-populates 260 assessment responses automatically.
Executive Narrative— Board Reporting
Generates board-ready compliance reports from deterministic signals with AI-polished wording. Signal-hash cached for consistency.
AI Copilot— Requirement Insights
Per-requirement compliance insights combining deterministic signals with AI-generated prose. Cached by signal hash.
AI Support Triage— Ticket Intelligence
Classifies support tickets by category, generates suggested responses, checks escalation thresholds, serves AI suggestions to agents.
Coverage by Workflow Area
AI engines are distributed across all five core compliance workflow areas — ensuring no gap in the compliance lifecycle goes unassisted.
5 Named Compliance Agents
Specialised AI agents built on shared AI infrastructure with advisory-only enforcement and deterministic fallback.
Evidence Validator
Validates evidence items against control requirements
Merchant Coach
Guided compliance coaching for merchants through PCI DSS requirements
Portfolio Intelligence
Acquirer portfolio-level risk analysis across merchant populations
QSA Review Assistant
Assists QSA assessment reviews with contextual requirement analysis
Scope Advisor
CDE scope definition and reduction advice for merchants and QSAs
The Orchestrator
The layer that coordinates all 19 engines.
Compliance AI Orchestrator
Provider-swappable compliance insights, recommendations, explanations, and draft generation with context assembly and full audit trail. Coordinates all 19 engines with deterministic fallback — if AI services are unavailable, the platform continues operating with rule-based outputs.
Intelligence Architecture
35 Intelligence Services
19 AI-powered engines work alongside 16 rule-based deterministic modules — giving every compliance workflow both intelligent analysis and rock-solid foundations.
+ 16 Deterministic Intelligence Modules
Rule-based. No external AI required. The signal foundation AI engines build on.
Cross-framework compliance scoring
Control health and effectiveness metrics
Rule-based evidence validation
Regulatory change tracking and mapping
Deterministic risk scoring and aggregation
CDE boundary and scope calculations
Cross-control dependency mapping
Pattern detection on historical data
Real-time security posture tracking
QSA workflow and capacity modelling
PCI DSS scoping rule engine
System health and usage analytics
Portfolio-level merchant risk signals
PCI DSS requirement dependency graph
AI output quality and confidence signals
Scheduled autonomous compliance tasks
See the engines in action
Every engine runs on your live compliance data from day one.