# ColossalX > ColossalX is the AI security and governance platform from Quantexra Labs, delivered as SaaS. ColossalX finds the AI your company runs, stops unsafe behaviour as it happens, proves your defences hold, and turns findings into owned work, a live risk position and evidence an auditor can check. ColossalX is organised as four verbs (See, Control, Prove, Govern) around one spine: one issue queue, one risk register, one trust score and one evidence store. Each customer runs in an isolated workspace with its own database. Frameworks are mapped to and assessed against; ColossalX holds no certifications. It is not a trained model. To request a walkthrough for a person, email client.success@quantexra.tech. The web forms are for people. The complete text for language models is at https://colossalx.tech/llms-full.txt. ## Start here - [Home](https://colossalx.tech/index.md): ColossalX finds the AI nobody approved, stops unsafe behaviour as it happens, proves your defences hold, and turns findings into evidence an auditor can check. - [Platform overview](https://colossalx.tech/platform.md): Four verbs around one spine - [How it works](https://colossalx.tech/platform/how-it-works.md): One finding, from found to accounted for - [ColossalX Assistant](https://colossalx.tech/assistant.md): Governed AI chat for your workforce - [For developers](https://colossalx.tech/developers.md): Gateway endpoint, scan APIs, Playground ## See: What are we running? - [See](https://colossalx.tech/platform/see.md): Models, agents, MCP servers and data flows, including the ones nobody approved, on one live map, each with an owner and a label saying how it was found. - [AI inventory and agent map](https://colossalx.tech/platform/ai-inventory.md): Agents from code and traffic, on one map - [Shadow AI](https://colossalx.tech/platform/shadow-ai.md): The AI nobody approved, then a standing rule - [AI bill of materials](https://colossalx.tech/platform/ai-bill-of-materials.md): SBOM and AI-BOM, with drift from baselines - [Data lineage](https://colossalx.tech/platform/data-lineage.md): Which personal data reached which model - [AI spend](https://colossalx.tech/platform/ai-spend.md): Cost by model, with daily allowances ## Control: What is it doing right now? - [Control](https://colossalx.tech/platform/control.md): One AI gateway, runtime guardrails and agent identity check requests and tool calls against your policy as they happen, and show whether each control is really in force. - [AI gateway](https://colossalx.tech/platform/ai-gateway.md): One governed path to 31 provider families - [Runtime guardrails](https://colossalx.tech/platform/runtime-guardrails.md): Injection, data leaks and approval holds - [ColossalX MCP Firewall](https://colossalx.tech/platform/mcp-firewall.md): Allow, monitor or block each tool - [Runtime consent](https://colossalx.tech/platform/runtime-consent.md): Consent checked when the request is made - [Agent identity](https://colossalx.tech/platform/agent-identity.md): Post-quantum identity and admission - [Detection and response](https://colossalx.tech/platform/detection-response.md): Containment and the ColossalX Kill Switch ## Prove: Will our defences hold? - [Prove](https://colossalx.tech/platform/prove.md): ColossalX attacks your own AI, with your authorisation and through your real controls, and shows the exact attack, the exact reply and the verdict. Then it proves the fix. - [Red-teaming and validation](https://colossalx.tech/platform/red-teaming.md): Authorised attacks, sealed runs - [ColossalX CyberTwins](https://colossalx.tech/platform/cybertwins.md): Attack a twin, not production - [Threat intelligence](https://colossalx.tech/platform/threat-intelligence.md): Matched to what you actually run - [Exposure management](https://colossalx.tech/platform/exposure-management.md): Exposures ranked by validated reachability - [Code security](https://colossalx.tech/platform/code-security.md): Repositories, apps and the CI/CD gate - [Resilience](https://colossalx.tech/platform/resilience.md): Injected faults and restore drills ## Govern: Where do we stand? - [Govern](https://colossalx.tech/platform/govern.md): Risk in money, a trust score that explains itself, frameworks assessed from live signals, and evidence that collects itself, graded by how it was obtained and timestamped daily. - [ColossalX Trust Engine](https://colossalx.tech/platform/trust-engine.md): A trust score that explains itself - [Risk quantification](https://colossalx.tech/platform/risk-quantification.md): AI risk in money, as a loss range - [Compliance and AI governance](https://colossalx.tech/platform/compliance.md): Mapped frameworks, policies and evidence - [Audit](https://colossalx.tech/platform/audit.md): From a plan to a sealed archive ## Company - [Why ColossalX](https://colossalx.tech/why-colossalx.md) - [About Quantexra Labs](https://colossalx.tech/company.md) - [Security at ColossalX](https://colossalx.tech/security.md) - [For AI agents](https://colossalx.tech/ai-agents.md) - [Contact](https://colossalx.tech/contact) - [Book a walkthrough](https://colossalx.tech/demo) - [Website privacy notice](https://colossalx.tech/privacy) ## Solutions - [AI Security Solutions by Role and Industry](https://colossalx.tech/solutions.md): ColossalX for CISOs, AI governance and DPOs, security engineering, risk and compliance, and IT, built for banks, insurers and capital markets firms. - [AI Governance for DPOs and Governance Leads](https://colossalx.tech/solutions/ai-governance.md): For AI governance leads and DPOs: an AI inventory that stays current, policies accepted by version, consent enforced at runtime and evidence for audits. - [AI Governance and Security for Banks](https://colossalx.tech/solutions/banking.md): AI security and governance for banks: model and agent inventory, guardrails with India banking and payments presets, consent enforced at runtime, evidence. - [AI Governance for Capital Markets Firms](https://colossalx.tech/solutions/capital-markets.md): AI governance for capital markets: keep price-sensitive information out of AI tools, map SEBI cyber circulars and keep an audit trail of AI use. - [AI Security for CISOs: Board-Ready Posture](https://colossalx.tech/solutions/ciso.md): For CISOs: one defensible position on AI risk. Know which AI runs, stop unsafe behaviour, prove defences hold and give the board a trust score. - [AI Governance and Security for Insurers](https://colossalx.tech/solutions/insurance.md): AI governance for insurers: govern AI in underwriting and claims, protect policyholder data in prompts, map IRDAI cyber circulars and keep audit evidence. - [Shadow AI and AI Tool Governance for IT](https://colossalx.tech/solutions/it.md): For IT: find AI tools on your network and laptops, roll out the browser sensor by policy, set standing rules and give employees a governed AI assistant. - [AI Risk and Compliance Management](https://colossalx.tech/solutions/risk-compliance.md): For risk and compliance: a quantified AI risk register, controls assessed from live signals, a compliance calendar and person-confirmed regulatory change. - [AI Security Operations for SOC and Engineering](https://colossalx.tech/solutions/security-engineering.md): For the SOC and security engineering: detections mapped to MITRE ATT&CK and ATLAS, session replay, containment and delivery to Splunk, Sentinel or Elastic. ## Frameworks and learning - [AI Frameworks: Mapped, Assessed and Dated](https://colossalx.tech/frameworks.md): How ColossalX relates to the EU AI Act, ISO/IEC 42001, NIST AI RMF, OWASP, India DPDP and SEBI circulars, with a dated, sourced AI regulatory clock. - [OWASP Top 10 for Agentic Applications, Explained](https://colossalx.tech/frameworks/owasp-agentic-top-10.md): The OWASP Top 10 for Agentic Applications (ASI01-ASI10) in plain words, with what ColossalX does about each risk and the honest limit. - [AI Agent Incident Response: A Field Guide](https://colossalx.tech/resources/field-guide.md): What to do in the first hour when an AI agent misbehaves: declare, contain, keep evidence, cut its paths, scope the damage, notify and restore. - [AI Security and Governance Glossary](https://colossalx.tech/resources/glossary.md): Plain definitions of AI security and governance terms: shadow AI, AI-SPM, prompt injection, MCP security, AI-BOM, agent detection and response and more. ## Optional - [Full text for language models](https://colossalx.tech/llms-full.txt) - [The film, Know your x](https://colossalx.tech/film/watch): A 30-second film, captioned, with no sound. An AI estate grows and one unknown appears: the x. ColossalX finds it, holds it to policy, tests it with authorisation and puts it on the record, and says so when something is not measured. - [security.txt](https://colossalx.tech/.well-known/security.txt)