Agent assurance · built for the .si era

Vet every synthetic-intelligence agent before it touches production.

Vettly is the registry and assurance workflow for enterprise AI agents. It finds every agent across your platforms, reviews each one the way a security team would, puts a dollar figure on the risk, and only blesses what passes — then watches for drift.

Platform hooks
12 + push
Loss quant
FAIR · 10k runs
Time to verdict
< 2 s
Blast radius · Finance Close Copilotexfiltration triad
AGENTcopilot-studioFinance team · 340Vendor inbox · untrustedops-automationSAP General LedgerWSharePoint · internalTeams · outboundWprocurement-mcp · communityW
Risk score
88
Expected loss
$2.1M
Verdict
Block

Platform-agnostic by design

  • Claude
  • Copilot Studio
  • Microsoft 365 Copilot
  • Palantir AIP
  • OpenAI Agents
  • Azure AI Foundry
  • Amazon Bedrock
  • Vertex AI
  • Agentforce
  • ServiceNow
  • LangGraph
  • CrewAI
  • Anything custom

What Vettly reviews

GRC rigour, applied to agents, at build speed.

From inventory to blessing to drift. Every finding maps to the control frameworks your auditors already recognise.

One registry for every agent

Declared by owners, submitted for review, imported from a spreadsheet or discovered through platform hooks. Each gets a stable ID, an owner, a business unit, criticality and lifecycle. Shadow agents surface as unclaimed.

Instruction forensics

Secrets, over-permissive directives, missing injection boundaries, absent data-handling rules. Deterministic rules plus an optional Claude-assisted read of the prompt itself.

Tools, knowledge & MCP supply chain

Destructive or financial tools without approval, confidential corpora behind public surfaces, community MCP servers, unpinned versions, unauthenticated transports.

Blast-radius map

Principals → agent → knowledge, tools, MCP → systems of record, as a live graph. Flags the exfiltration triad: private data + untrusted input + outbound channel.

FAIR risk quantification

Threat-event frequency × vulnerability × loss magnitude across 10,000 seeded Monte Carlo runs. Expected annual loss, P90/P99, loss-exceedance curve and residual after fixes.

Review & bless

Reviewer assignment, a ten-point security checklist pre-filled from the assessment, discussion, change requests, approve / approve-with-conditions / reject with separation of duties.

Attestations that expire

Approvals issue a numbered certificate bound to the configuration hash, with conditions, a validity period, 30-day recertification warnings and automatic expiry.

Discovery & drift monitoring

Twelve platform connectors plus a push endpoint pull the live inventory, register what you did not know about, and diff every approved agent against its baseline.

Exportable documentation

An Agent Profile document per agent in PDF, Markdown or JSON, attestation certificates in PDF, and the whole registry as CSV. Ready for auditors and the board.

How it works

Register. Assess. Bless. Then keep it honest.

  1. 01

    Register

    Owners answer a plain-language intake, builders submit a spec, pipelines call the API, and connectors discover the rest. Every agent gets an ID.

  2. 02

    Assess

    Blast-radius graph, findings mapped to OWASP, NIST, ATLAS, ISO 42001 and the EU AI Act, and a FAIR loss estimate — in under two seconds.

  3. 03

    Review & bless

    Security reviewers work a checklist, request changes and recommend; an approver blesses, with conditions and an expiring attestation.

  4. 04

    Monitor

    Connectors re-read the live configuration on a schedule and diff it against the approved baseline. Drift alerts Slack, Teams, email or your SIEM.

Risk quantification

Boards don't fund “high”. They fund $1.3M at P90.

Vettly blends qualitative findings with FAIR-style quantification. Each control gap moves the vulnerability term; exposure, autonomy and triggers move threat-event frequency; records in reach, transaction limits and downtime cost shape loss magnitude. The output is a loss-exceedance curve — current and after your top remediations — so every recommendation carries a dollar value and an ROI ordering.

  • Expected annual loss, P50 / P90 / P95 / P99
  • Probability of at least one loss event per year
  • Loss composition: breach, response, regulatory, fraud, disruption
  • Residual exposure after prioritised fixes
  • Portfolio roll-up against your risk appetite
Loss exceedance · sample agent10,000 runs
100%75%50%25%0%risk appetite$0$500K$1M$1.5M$2M
Expected
$418K
P90
$1.27M
After fixes
$96K

Every finding mapped to

  • OWASP LLM Top 10 · 2025
  • OWASP Agentic Top 10
  • NIST AI RMF
  • MITRE ATLAS
  • ISO/IEC 42001
  • EU AI Act
  • SOC 2
  • GDPR · HIPAA · PCI DSS

Discovery & drift

Every agent in the organisation, documented — including the ones nobody told you about.

Vettly hooks into the AI platforms your teams already use, pulls the live inventory on a schedule, registers unknown agents as unclaimed so owners can step forward, and diffs every approved agent against the configuration you blessed. Platforms without an inventory API push their export to the same endpoint.

Claudefull fidelity
Managed Agents API
OpenAIfull fidelity
Assistants API
ChatGPT Enterprisediscovery fidelity
Compliance API · custom GPTs
Copilot Studiodiscovery fidelity
Dataverse bots & components
Microsoft 365 Copilotdiscovery fidelity
Graph app catalog · declarative agents
Azure AI Foundryfull fidelity
Agent Service
Amazon Bedrockfull fidelity
Agents, action groups, knowledge bases
Google Vertex AIfull fidelity
Agent Builder playbooks & tools
Salesforce Agentforcediscovery fidelity
Tooling API
ServiceNowdiscovery fidelity
AI Agent records
LangGraph Platformdiscovery fidelity
Deployment assistants
Any JSON feedfull fidelity
HTTP inventory · CI push

Connect

Read-only credentials per platform, stored encrypted. Each connector states its fidelity honestly: full configuration, discovery-grade inventory, or push.

Diff

Field-level comparison of instructions, tools, approval gates, knowledge, MCP servers and audience. Severity from low to critical, with a line diff of the prompt.

Enforce

Critical drift can revoke the attestation automatically. Notifications go to owners and reviewers in-app, by email, Slack, Teams or a signed webhook.

Built for the whole organisation

Business users submit. Security reviews. Leaders see the posture.

A plain-language intake asks what the agent does, what it can see and what it can do — no security background required. Reviewers get a queue, a checklist and the evidence trail. Owners get notified at every step. Everyone signs in with the identity provider you already run.

  • Guided intake
    Five minutes, plain language, full assessment.
  • Review queue
    Assigned to me, awaiting reviewer, changes requested, expiring, drifted.
  • Single sign-on
    Microsoft Entra ID, Google Workspace, Okta and any OpenID Connect provider, with just-in-time provisioning.
  • Roles & separation of duties
    Owners bless, reviewers verify, submitters own their agents.
  • API & CI gates
    Fail a build on tier, score or the exfiltration triad. Scoped API keys per pipeline.
  • Audit log
    Every submission, checklist tick, decision, sync and sign-in, per tenant.

Pricing

Per tenant. Unlimited reviewers.

Starter

Free

For a team vetting its first agents.

  • Up to 5 agents in the registry
  • Rules engine + FAIR quant
  • Blast-radius map
  • Guided intake & review workflow
  • PDF / Markdown profile exports
Request access
Most popular

Growth

$1,200/ month

For platform teams shipping agents weekly.

  • Unlimited agents & versions
  • Attestations, conditions & recertification
  • Discovery connectors & drift monitoring
  • CI/CD API gates & scoped keys
  • Slack / Teams / email notifications
  • Claude-assisted instruction review
Request access

Enterprise

Custom

For regulated estates and multi-business-unit rollouts.

  • SSO (Entra ID, Google, Okta, OIDC) with enforcement
  • Private deployment & data residency
  • Signed webhooks into your SIEM
  • Framework evidence packs
  • Dedicated assurance lead
Talk to us

Ship agents your CISO can sign.

Create your tenant, load the sample agents, and see a full assessment in under a minute.

Request access