Assurance intelligence for AI

Nobody is watching your AI change.

A model you use is found to be flawed. An agent reaches for a tool nobody approved. Code from six months ago needs re-checking. AICAP connects what changes to the systems you already run.

Discover

Survey

Build

Origin

Deploy

Core

Operate

Trace

Digital Native Group · Continuous Assurance Sovereign · Air-gapped by default

01What actually goes wrong

Five questions you cannot currently answer

None of these are hypothetical, and none of them are caught by a point-in-time assessment. They surface through incidents, months later, because nothing is connecting what changed to what you run.

“Which of our repositories did that model touch?”

A model your team relied on turns out to have a known weakness in the code it generates. You cannot tell which services carry it, so you either re-check everything or nothing.

Handled by Origin

“What did we send it?”

Someone pastes a customer contract into a chat assistant to summarise it. No policy was obviously broken, nobody meant any harm, and there is no record of what left the organisation or where it went.

Handled by Survey

“Why did the agent call that?”

An agent in production reaches for a tool nobody approved, in a sequence nobody designed. It is doing what it was asked. Nothing is watching the pattern.

Handled by Trace

“Is the sign-off still true?”

The system was assured against a context that no longer exists. New vulnerabilities, a changed threat picture, a different operating environment. The original justification quietly stops holding.

Handled by Core

“Is that everything?”

Assurance starts from a list of what you have. If the list is incomplete, so is every claim built on it, including the ones you sign. AICAP builds the list from what your endpoints and coding tools actually report.

Handled by Survey

What AICAP is

AICAP is software you run yourself, from commercial cloud through to fully air-gapped. It installs alongside what you already have rather than replacing it: a browser extension and per-tool monitors for discovery, a step in your CI/CD for code provenance, and findings routed into the tooling your security team already watches.

02Where assurance breaks

Assurance fails at the question, not the test

Any assurance tool answers the question you thought to ask it. The harder problem comes first: knowing what changed, what it touches, and what that means for something already in production.

“An AI system validated in one context cannot be assumed safe in another.”

Today that is discovered reactively, through incidents, because nobody is connecting the stream of new vulnerabilities and research to the systems already in production.

The old way

Point-in-time and reactive. Systems are signed off against what was known on the day. Guardrails rely on static pattern libraries. Nobody tracks which model wrote which code, or what an agent actually did once it was running. New risk surfaces only after something breaks.

The AICAP way

Continuous and intelligence-led. Each discovery is correlated to the systems it affects, then turned into whatever the situation needs: a targeted test, a re-check of code a model wrote, a flag on how an agent is behaving, or evidence for an auditor. Complete trail from discovery to evidence.

03The platform

Four pillars across the AI lifecycle

The same intelligence and correlation extend across the whole lifecycle: from knowing what you have, to securing how agents behave.

Continuous intelligence

Discover

Survey

Map every model, agent and tool in use, so assurance starts from a complete picture. Built from what endpoints and coding tools report, not from a form someone filled in.

You can answer “is that everything?” with a record rather than a recollection.

Build

Origin

Capture the provenance of AI-written code and re-check it when the model that wrote it turns out to be flawed.

A flawed model becomes a bounded list of repositories, not an open question.

Deploy

Core

Assure deployed models and agents as their context changes, generating the tests that matter before go-live.

The sign-off stays justified through life, not just on the day.

Operate

Trace

Watch agent behaviour in production: the tools they reach for, the sequences they run, the actions they take.

Unapproved tool use and odd sequences surface while they are happening.

Evidence & audit trail

04One engine

A continuous loop: see, know, act

One engine runs beneath every part of the platform. Open-source intelligence makes up most of what goes in, alongside data and feedback from your own deployments and operations. Prioritised findings and assurance evidence come out.

Open & operational sources Monitor Correlate Prioritise Generate Evaluate Action & evidence

Operational results feed back to sharpen the next cycle

AI on both sides of the loop

AICAP assures AI, and uses AI to run. Ask what changed and what it affects in plain language, and get further than a manual review has time to reach.

How it works

05Three ways in

Assurance, compliance and security in one place

The evidence AICAP generates to assure a system is the same evidence your auditors and your security team need.

Assurance

Know what changed and what it means for the systems you actually run. The through-life justification JSP 936 expects, and the code provenance SSCoP asks for.

How it works

Compliance

EU AI Act, ISO/IEC 42001 and SOC 2, mapped to evidence the assurance work already produces.

Frameworks & evidence

Security

MITRE ATLAS and the AI Incident Database for AI-specific threat and failure, CVE enriched with CISA KEV and EPSS, NCSC advisories. All correlated to the systems you run. Sovereign and air-gapped by default.

Sources & deployment

06Measured

What that changes

Open + operational

MITRE ATLAS, the AI Incident Database, CVE enriched with CISA KEV and EPSS, NCSC advisories, arXiv and model cards, correlated against what you actually run.

6 frameworks

JSP 936, the UK Software Security Code of Practice, EU AI Act, ISO/IEC 42001, SOC 2 and NIST AI RMF, mapped to evidence the platform already generates.

Cloud to air-gapped

The same engine offline as online. Intelligence reaches an air-gapped install by scheduled transfer from the central source, not as a reduced-capability offline edition.

07Who this is for

Organisations that have to justify an AI system to somebody else

Defence and its supply chain, where JSP 936 expects dependable AI to be justified through life, and the Software Security Code of Practice asks you to know where your code came from.

Regulated industries facing the EU AI Act, ISO/IEC 42001 or SOC 2, who need the evidence to fall out of the engineering rather than a separate paper exercise.

Engineering teams shipping AI-written code at a pace that has outrun their ability to say what wrote what.

Close the gap before something breaks

AICAP watches what changes, works out what it means for the systems you have already deployed, and turns that into whatever the situation calls for: a test, a re-check, a flag, or the evidence to prove it.

Open & operational intelligence AICAP Action & evidence