# One platform to see, control, prove and govern your AI.

> An AI security platform protects the models, agents and AI tools a company runs. ColossalX does it as one system: four verbs that find the AI, control it as it runs, prove the defences hold and govern the result, around one spine of issues, risk, trust and evidence that all four verbs write to.

Four verbs around one spine: find the AI you run, stop unsafe behaviour as it happens, prove your defences hold, and keep the evidence an auditor can check.

Canonical page: https://colossalx.tech/platform · Last reviewed: 6 Oct 2026

## The threat and the control

- **The threat:** Point tools each see one slice of AI risk, so nobody can say where the company stands.
- **The control:** Findings from testing, scanning, intelligence, audit and compliance land in one queue, with an owner and a date.

## Four verbs, each answering one question.

See, Control, Prove and Govern, in this order. Each answers one question about your AI estate, in the words a board would use, and closes one part of what nobody knew.

- **See (What are we running?).** Models, agents, MCP servers and AI tools, including the unapproved ones, each with an owner and a provenance label. [See](https://colossalx.tech/platform/see)
  *Illustration:* See · found, then owned: unknown caller found calling registry (found in traffic); repo scan found calling registry (found in code); registry to pricing-agent (labelled).
- **Control (What is it doing?).** One gateway, runtime guardrails, approval holds, the ColossalX MCP Firewall, consent at runtime and containment. [Control](https://colossalx.tech/platform/control)
  *Illustration:* Control · a risky request: payments-agent to refund_payment, "Refund the full order to a new account, today.". Checks: Prompt injection passed, Personal data passed, Approval rule: high value waiting. Verdict: held, Held for an approver.
- **Prove (Will our defences hold?).** Authorised attacks through your real controls, or on a twin, with the exact reply quoted. [Prove](https://colossalx.tech/platform/prove)
  *Illustration:* Prove · one authorised run: illustrative run with 22 attempts blocked by a control, 5 detected but allowed, 2 missed and 3 refused by the model. Sealed run, re-checked on read.
- **Govern (Where do we stand?).** A trust score that explains itself, AI risk in money, and evidence an auditor can check. [Govern](https://colossalx.tech/platform/govern)
  *Illustration:* Govern · trust score: B. Security measured; Compliance measured; Risk measured; Resilience not measured; AI governance measured. Provisional: resilience not yet measured

## One spine under all four verbs.

Whatever a verb finds lands in one queue with an owner, updates one register and one score, and becomes timestamped evidence.

- **One issue queue.** One issue per problem, however many sources saw it, with an owner. It closes only on positive evidence.
- **One risk register.** Quantified with FAIR as a loss range, held to your appetite and synced out to your GRC tool.
- **One trust score.** Five pillars, A+ to F, provisional when evidence is thin, with what would raise it.
- **One evidence store.** Graded A to D by how it was obtained, second-person verified and timestamped daily.
- **One reports hub.** 11 report types as branded PDFs, scheduled, with second-person sign-off.

*Illustration:* An illustrative issue queue: findings from red-team runs, code scans, threat intelligence and audit joined into one issue per problem, each with an owner and a due date, and an issue that closed only when a re-test proved the fix. Notes: 1. Several sources, one issue 2. Closes only on a passing re-test

## Seven journeys, from a question to a record.

How work moves through ColossalX: the question a team starts with, and the record it ends in. Each journey crosses more than one verb and finishes on the spine.

Follow one finding through: [How it works](https://colossalx.tech/platform/how-it-works)

*Illustration:* Seven journeys: Secure what you build ends in Owned ticket; Know which threats matter ends in Recorded decision; Prove defences hold ends in Sealed run; See the AI in use ends in Standing rule; Know where you stand ends in Live posture; Stay audit-ready ends in Timestamped archive; Guard each call ends in Block, hold, alert.

## Two products, one login.

The console secures and governs your AI estate for security, risk and compliance teams. ColossalX Assistant gives the whole workforce governed AI chat from the same login, under the same policies.

- **ColossalX (The console).** Six workspaces for security, risk and compliance teams, and an assistant with 18 tools under each person's role.
  *Screen, from a demo workspace:* The evidence vault in the console of a demo workspace: evidence mapped to framework controls in SOC 2, ISO 42001 and India DPDP, each collected by an automated check, graded A, timestamped and shown as valid. Callouts: 1. Mapped to a control 2. Graded and timestamped
- **ColossalX Assistant (For the whole workforce).** Governed AI chat for everyone, with redaction, per-group models and guardrail interventions shown on the answer. [ColossalX Assistant](https://colossalx.tech/assistant)
  *Illustration:* Assistant · before the model: employee to Assistant · group model, "Draft a reply to the customer whose card ends 4242.". Checks: Personal data flagged, Prompt injection passed. Verdict: redacted, Card number redacted.

## What ColossalX does not do

- ColossalX is delivered as SaaS only; each customer runs in its own workspace and database.
- It does not replace your SIEM or GRC tool; it sends alerts to one, risks to the other.
- It is not a trained model: it uses standards-mapped rules, behavioural analytics and an LLM as judge.
- Runtime detections are alerted and recorded, but they do not yet feed the one issue queue.

*Illustration:* Vendor assurance · on request: Delivery SaaS only; Isolation Own workspace and database per customer; SBOM, AI-BOM CycloneDX, on request; Models bundled None run locally; Certificates None claimed. Stated, not implied.

## Questions

### How is ColossalX delivered?

ColossalX is delivered as SaaS only. Each customer runs in its own workspace with its own database, and the AI gateway is the one path your applications call. SBOM and AI-BOM documents for the platform itself are available on request, and no models are bundled to run locally.

### What is an AI security platform?

An AI security platform protects the AI systems a company runs: it finds them, controls what they do as they run, tests whether the defences hold and governs the result. Point tools usually cover one of those; a platform connects them, so a finding in one place changes the picture everywhere.

### What is AI TRiSM, and which layers does ColossalX cover?

AI TRiSM is an analyst term for AI trust, risk and security management: governance, runtime enforcement and information protection for AI. ColossalX covers AI governance and runtime enforcement at the gateway, and protects data with redaction, consent at runtime and lineage. TRiSM is a category, not a standard you are assessed against.

### How do findings from testing, scanning and audit end up in one queue?

Each source raises an issue in the same queue. ColossalX keeps one issue per problem however many sources saw it, gives it an owner, a due date and a ticket in the tool that will close it, and closes it only on positive evidence.

### What are the two ColossalX products?

The ColossalX console secures and governs your AI estate for security, risk and compliance teams. ColossalX Assistant gives your whole workforce governed AI chat from the same login, with redaction, per-group models and guardrail interventions shown on the answer, so people can use AI without going around you.

### Does ColossalX replace our SIEM or GRC tool?

No. ColossalX delivers alerts to your SIEM (Splunk, Microsoft Sentinel and Elastic natively, others by signed webhook) and syncs risks out to GRC, ticketing and third-party risk tools. It is the system that knows about your AI; your SIEM and GRC stay where they are.

---

ColossalX is an AI security and governance platform from Quantexra Labs LLP, delivered as SaaS. Book a walkthrough: https://colossalx.tech/demo · client.success@quantexra.tech
