One registry for every agent
Declared by owners, submitted for review, imported from a spreadsheet or discovered through platform hooks. Each gets a stable ID, an owner, a business unit, criticality and lifecycle. Shadow agents surface as unclaimed.
Vettly is the registry and assurance workflow for enterprise AI agents. It finds every agent across your platforms, reviews each one the way a security team would, puts a dollar figure on the risk, and only blesses what passes — then watches for drift.
Platform-agnostic by design
What Vettly reviews
From inventory to blessing to drift. Every finding maps to the control frameworks your auditors already recognise.
Declared by owners, submitted for review, imported from a spreadsheet or discovered through platform hooks. Each gets a stable ID, an owner, a business unit, criticality and lifecycle. Shadow agents surface as unclaimed.
Secrets, over-permissive directives, missing injection boundaries, absent data-handling rules. Deterministic rules plus an optional Claude-assisted read of the prompt itself.
Destructive or financial tools without approval, confidential corpora behind public surfaces, community MCP servers, unpinned versions, unauthenticated transports.
Principals → agent → knowledge, tools, MCP → systems of record, as a live graph. Flags the exfiltration triad: private data + untrusted input + outbound channel.
Threat-event frequency × vulnerability × loss magnitude across 10,000 seeded Monte Carlo runs. Expected annual loss, P90/P99, loss-exceedance curve and residual after fixes.
Reviewer assignment, a ten-point security checklist pre-filled from the assessment, discussion, change requests, approve / approve-with-conditions / reject with separation of duties.
Approvals issue a numbered certificate bound to the configuration hash, with conditions, a validity period, 30-day recertification warnings and automatic expiry.
Twelve platform connectors plus a push endpoint pull the live inventory, register what you did not know about, and diff every approved agent against its baseline.
An Agent Profile document per agent in PDF, Markdown or JSON, attestation certificates in PDF, and the whole registry as CSV. Ready for auditors and the board.
How it works
Owners answer a plain-language intake, builders submit a spec, pipelines call the API, and connectors discover the rest. Every agent gets an ID.
Blast-radius graph, findings mapped to OWASP, NIST, ATLAS, ISO 42001 and the EU AI Act, and a FAIR loss estimate — in under two seconds.
Security reviewers work a checklist, request changes and recommend; an approver blesses, with conditions and an expiring attestation.
Connectors re-read the live configuration on a schedule and diff it against the approved baseline. Drift alerts Slack, Teams, email or your SIEM.
Risk quantification
Vettly blends qualitative findings with FAIR-style quantification. Each control gap moves the vulnerability term; exposure, autonomy and triggers move threat-event frequency; records in reach, transaction limits and downtime cost shape loss magnitude. The output is a loss-exceedance curve — current and after your top remediations — so every recommendation carries a dollar value and an ROI ordering.
Every finding mapped to
Discovery & drift
Vettly hooks into the AI platforms your teams already use, pulls the live inventory on a schedule, registers unknown agents as unclaimed so owners can step forward, and diffs every approved agent against the configuration you blessed. Platforms without an inventory API push their export to the same endpoint.
Read-only credentials per platform, stored encrypted. Each connector states its fidelity honestly: full configuration, discovery-grade inventory, or push.
Field-level comparison of instructions, tools, approval gates, knowledge, MCP servers and audience. Severity from low to critical, with a line diff of the prompt.
Critical drift can revoke the attestation automatically. Notifications go to owners and reviewers in-app, by email, Slack, Teams or a signed webhook.
Built for the whole organisation
A plain-language intake asks what the agent does, what it can see and what it can do — no security background required. Reviewers get a queue, a checklist and the evidence trail. Owners get notified at every step. Everyone signs in with the identity provider you already run.
Pricing
For a team vetting its first agents.
For platform teams shipping agents weekly.
For regulated estates and multi-business-unit rollouts.
Create your tenant, load the sample agents, and see a full assessment in under a minute.
Request access