# Drel — AI Security Review platform # https://drel.ai Drel produces structured AI Security Review Records for AI, RAG, and agentic AI systems. Output: system model, threat model, required controls, evidence gaps, risk disposition, versioned clearance record, audit-ready dossier. Audience: security architects, AI governance teams, AppSec engineers, CISOs, DPOs. ## Core pages https://drel.ai/ — Home: AI Security Review before production https://drel.ai/platform — Platform overview: what Drel is and what it produces https://drel.ai/demo — Live demo of the assessment workflow https://drel.ai/pricing — Plans and pricing https://drel.ai/enterprise — Enterprise plans and contact https://drel.ai/about — About Drel https://drel.ai/contact — Contact Drel: sales, support, security disclosure, press ## For agents & developers https://drel.ai/developers — Developer portal: API keys, quickstart, endpoint reference https://drel.ai/openapi.json — OpenAPI 3.1 specification for the public REST API and MCP server https://drel.ai/.well-known/api-catalog — RFC 9727 API catalog (application/linkset+json) https://drel.ai/api/mcp — MCP server (Streamable HTTP, JSON-RPC 2.0); manifest at https://drel.ai/.well-known/mcp.json https://drel.ai/.well-known/mcp/server-card.json — MCP Server Card (SEP-1649) https://drel.ai/mcp-security-review — MCP server security review methodology https://drel.ai/auth.md — How agents authenticate against the Drel API (API key or OAuth) https://drel.ai/.well-known/oauth-protected-resource — RFC 9728 Protected Resource Metadata https://drel.ai/.well-known/oauth-authorization-server — RFC 8414 Authorization Server Metadata (Clerk, proxied live) https://drel.ai/.well-known/ai-catalog.json — ARD (Agentic Resource Discovery) manifest https://drel.ai/.well-known/agent-skills/index.json — Agent Skills index: how to check or request an AI Security Review ## Topic hubs https://drel.ai/ai-security-review — AI security review: clearance before production https://drel.ai/rag-security-assessment — Security assessment for RAG systems https://drel.ai/agentic-ai-security-review — Agentic AI security review for tool-using agents https://drel.ai/vendor-ai-security-assessment — Vendor AI security assessment for procurement https://drel.ai/iso-42001-ai-governance-toolkit — AI governance framework: ISO 42001 controls, evidence and lifecycle gates https://drel.ai/eu-ai-act-ai-system-inventory — EU AI Act system inventory and Article 9 requirements https://drel.ai/owasp-agentic-top-10-assessment — OWASP Agentic Top 10 assessment https://drel.ai/owasp-llm-top-10-assessment — OWASP LLM Top 10 assessment https://drel.ai/mcp-security-review — MCP server security review ## Comparison pages https://drel.ai/vs/spreadsheets-and-committee-docs — Why structured AI security review replaces spreadsheets and slide decks https://drel.ai/vs/threat-modeling-tools — How AI security review differs from traditional threat modeling tools https://drel.ai/vs/ai-posture-management — Drel vs AI Security Posture Management tools https://drel.ai/vs/runtime-ai-firewalls — Drel vs runtime AI firewalls and LLM guardrails https://drel.ai/vs/grc-platforms — Drel vs GRC platforms for AI governance ## Use cases (by role) https://drel.ai/use-cases/security-architect — AI security review for security architects running solo reviews https://drel.ai/use-cases/appsec-engineer — AI security review for AppSec engineers integrating into SDL https://drel.ai/use-cases/ai-governance — AI governance evidence for AI Committees and DPOs https://drel.ai/use-cases/pre-production-ai-clearance — Pre-production AI clearance before a system handles real users https://drel.ai/use-cases/ciso — AI security clearance for CISOs and board-level governance https://drel.ai/use-cases/dpo — AI governance evidence for DPOs under EU AI Act and ISO 42001 https://drel.ai/use-cases/fintech-ai — AI security review for financial services under FCA, ECB, DORA https://drel.ai/use-cases/healthcare-ai — AI security review for healthcare under EU AI Act high-risk and MDR ## Methodology https://drel.ai/methodology — How Drel works: assessment engine, threat taxonomy, control mapping, evidence grading ## Free tools https://drel.ai/eu-ai-act-classifier — Free EU AI Act risk tier classifier: determines if your AI system is prohibited, high-risk, limited risk, or minimal risk under Regulation (EU) 2024/1689 ## Free resources https://drel.ai/resources/iso-42001-controls — ISO 42001 AI System Readiness Tracker https://drel.ai/resources/owasp-agentic-controls — OWASP Agentic Top 10 — Control Map https://drel.ai/resources/owasp-llm-top-10-control-map — OWASP LLM Top 10 — Control Map https://drel.ai/resources/mcp-security-review-checklist — MCP Security Review Checklist https://drel.ai/resources/rag-security-checklist — RAG Security Checklist https://drel.ai/resources/eu-ai-act-ai-system-inventory-template — EU AI Act AI System Inventory Template https://drel.ai/resources/ai-security-review-template — AI Security Review Template https://drel.ai/resources/agentic-ai-risk-register-template — Agentic AI Risk Register Template https://drel.ai/resources/vendor-ai-security-questionnaire — Vendor AI Security Questionnaire https://drel.ai/resources/ai-go-live-security-checklist — AI Go-Live Security Checklist https://drel.ai/resources/ai-risk-disposition-memo-template — AI Risk Disposition Memo Template https://drel.ai/resources/ai-committee-charter-template — AI Committee Charter Template https://drel.ai/eu-ai-act-classifier — EU AI Act Risk Tier Classifier ## Blog (published) https://drel.ai/blog/vector-embedding-weaknesses-owasp — Vector and embedding weaknesses — OWASP LLM08 explained https://drel.ai/blog/unbounded-consumption-llm-owasp — Unbounded consumption in LLM applications — OWASP LLM Top 10 explained https://drel.ai/blog/fyxer-ai-security-review — Fyxer AI security review — full inbox access is the highest-risk AI category https://drel.ai/blog/granola-ai-security-review — Granola AI security review — meeting notes under the microscope https://drel.ai/blog/claude-ai-security-review — Claude AI security review — what a procurement team should assess https://drel.ai/blog/iso-42001-certification-audit — ISO 42001 certification — what the external audit actually checks https://drel.ai/blog/multi-tenant-rag-isolation — Multi-tenant RAG — the isolation boundary a security review must verify https://drel.ai/blog/agent-to-agent-protocol-security — Agent-to-agent protocol security — what A2A adds beyond MCP https://drel.ai/blog/eu-ai-act-prohibited-practices — Prohibited AI practices under the EU AI Act — what Article 5 actually bans https://drel.ai/blog/ai-governance-committee-evidence-pack — What an AI Governance Committee actually needs in an evidence pack https://drel.ai/blog/iso-42001-audit-readiness — ISO 42001 audit readiness — the controls that fail most often https://drel.ai/blog/agentic-ai-procurement-security-review — Security review for agentic AI procurement — a buyer's checklist https://drel.ai/blog/llm-output-validation-controls — LLM output validation — the controls that actually work https://drel.ai/blog/ai-risk-register-what-goes-in — What goes in an AI risk register — and what does not https://drel.ai/blog/rag-pipeline-threat-model — Threat modeling a RAG pipeline — retrieval, context, and generation risks https://drel.ai/blog/dpa-ai-systems-what-dpos-need — DPAs and AI systems — what DPOs actually need to document https://drel.ai/blog/security-graph-attack-path-analysis — Attack path analysis for AI systems — beyond CVE scoring https://drel.ai/blog/ai-incident-response-playbook — AI incident response — what the playbook needs that IT playbooks miss https://drel.ai/blog/eu-ai-act-risk-tiers-your-system — Is your AI system high-risk under the EU AI Act? How to find out https://drel.ai/blog/clearance-vs-approval-ai-systems — Clearance vs approval — why the distinction matters for AI governance https://drel.ai/blog/ai-risk-disposition-regulator-review — An AI Risk Disposition that holds up in regulator review https://drel.ai/blog/fine-tuned-model-security-review — Security review for fine-tuned models — what changes from base model assessment https://drel.ai/blog/threat-modeling-tools-agent-gap — Why your existing threat modeling tool doesn't model agents https://drel.ai/blog/ai-third-party-vendor-assessment — Assessing third-party AI vendors — the questions procurement skips https://drel.ai/blog/ai-risk-disposition-copilot-studio — A worked example: AI Risk Disposition for a Copilot Studio procurement agent https://drel.ai/blog/mcp-server-threat-model — Threat modeling an MCP server — the parts AppSec tools miss https://drel.ai/blog/eu-ai-act-article-9-risk-management — EU AI Act Article 9 risk management — what evidence is required https://drel.ai/blog/owasp-agentic-top10-controls — OWASP Agentic Top 10 mapped to required controls https://drel.ai/blog/ai-risk-disposition — What an AI Risk Disposition actually contains https://drel.ai/blog/agentic-ai-audit-trail — What an agentic AI audit trail must capture https://drel.ai/blog/llm-red-teaming-basics — LLM red-teaming for a security review https://drel.ai/blog/ai-security-review-common-mistakes — Five mistakes that make an AI security review undefensible https://drel.ai/blog/ai-vendor-contract-security-terms — The security terms an AI vendor contract needs https://drel.ai/blog/iso-42001-internal-audit — Preparing for an ISO 42001 internal audit https://drel.ai/blog/mcp-server-review-checklist — MCP Server Security Review Checklist (2025) https://drel.ai/blog/rag-context-window-risks — Context-window risks in RAG and how to bound them https://drel.ai/blog/agentic-ai-goal-hijacking — Goal hijacking and instruction drift in autonomous agents https://drel.ai/blog/llm-guardrails-that-work — Guardrails that work vs guardrails that look like they work https://drel.ai/blog/ai-security-review-evidence — What evidence an AI security review should produce https://drel.ai/blog/shadow-ai-vendor-discovery — Finding the AI vendors no one formally approved https://drel.ai/blog/iso-42001-roles-responsibilities — Roles and responsibilities under ISO 42001 https://drel.ai/blog/mcp-vs-traditional-api-security — MCP security vs traditional API security — what changes https://drel.ai/blog/rag-over-regulated-data — Running RAG over regulated data — the review checklist https://drel.ai/blog/eu-ai-act-timeline — The EU AI Act timeline and what to prepare first https://drel.ai/blog/owasp-agentic-top-10-walkthrough — The OWASP Agentic Top 10, explained for security reviewers https://drel.ai/blog/system-prompt-leakage — System prompt leakage and why it matters for security https://drel.ai/blog/ai-security-review-for-startups — A lightweight AI security review for fast-moving teams https://drel.ai/blog/defensible-ai-decision-record — What makes an AI decision record defensible https://drel.ai/blog/ai-vendor-data-handling-review — Reviewing how an AI vendor handles your data https://drel.ai/blog/nist-ai-rmf-vs-iso-42001 — NIST AI RMF vs ISO 42001 — Which Framework to Choose https://drel.ai/blog/securing-internal-mcp-servers — Securing an internal MCP server exposed to agents https://drel.ai/blog/rag-evaluation-for-security — Evaluating a RAG pipeline for security, not just relevance https://drel.ai/blog/eu-ai-act-gpai-obligations — General-purpose AI obligations under the EU AI Act https://drel.ai/blog/agentic-ai-privilege-escalation — Agentic AI Privilege Escalation — 5 Attack Paths https://drel.ai/blog/llm-excessive-agency — LLM Excessive Agency — Scope Permissions Down (OWASP) https://drel.ai/blog/design-time-vs-runtime-ai-security — Design-time vs runtime AI security — where review belongs https://drel.ai/blog/reassessment-triggers-ai — Re-assessment triggers — the field most dispositions skip https://drel.ai/blog/reassessing-ai-vendors — When to re-assess an AI vendor https://drel.ai/blog/iso-42001-evidence-checklist — The ISO 42001 evidence checklist for security reviews https://drel.ai/blog/mcp-context-injection — Prompt-context injection through MCP tools https://drel.ai/blog/vector-database-security — Vector Database Security — RAG Pipeline Checklist https://drel.ai/blog/eu-ai-act-for-deployers — EU AI Act obligations for deployers (not just providers) https://drel.ai/blog/human-in-the-loop-agentic-controls — Human-in-the-loop boundaries that actually hold https://drel.ai/blog/llm-model-denial-of-service — Model denial of service and cost-exhaustion attacks https://drel.ai/blog/ai-security-review-roles — Who runs the AI security review — roles and hand-offs https://drel.ai/blog/ai-evidence-pack-anatomy — The anatomy of an AI evidence pack https://drel.ai/blog/soc2-is-not-ai-assurance — Why SOC 2 is not AI assurance https://drel.ai/blog/building-an-aims — Building an AI management system (AIMS) from scratch https://drel.ai/blog/mcp-server-supply-chain — Vetting a third-party MCP server before you connect it https://drel.ai/blog/rag-pii-leakage — RAG PII Leakage — 3 Retrieval Paths That Expose Data https://drel.ai/blog/multi-agent-system-security-review — Security review for multi-agent systems https://drel.ai/blog/eu-ai-act-vs-gdpr — EU AI Act vs GDPR — where they overlap for AI systems https://drel.ai/blog/llm-supply-chain-security — LLM supply-chain risk — models, weights, and dependencies https://drel.ai/blog/ai-security-review-scope — Scoping an AI security review without boiling the ocean https://drel.ai/blog/restricted-pilot-pattern — The restricted-pilot pattern for risky AI systems https://drel.ai/blog/iso-42001-risk-assessment — AI risk assessment under ISO 42001 https://drel.ai/blog/ai-subprocessor-risk — AI subprocessor risk in your vendor chain https://drel.ai/blog/mcp-transport-security — Transport security for MCP servers https://drel.ai/blog/rag-prompt-injection-via-documents — Indirect prompt injection through retrieved documents https://drel.ai/blog/agent-memory-security — Agent memory as an attack surface https://drel.ai/blog/eu-ai-act-technical-documentation — The technical documentation the EU AI Act expects https://drel.ai/blog/llm-sensitive-information-disclosure — Sensitive information disclosure in LLM applications https://drel.ai/blog/ai-security-review-vs-pentest — AI security review vs penetration testing — different questions https://drel.ai/blog/conditional-approval-ai-systems — Conditional approval for AI systems — making conditions stick https://drel.ai/blog/ai-vendor-model-change-notification — Model-change notification — the vendor clause procurement teams forget https://drel.ai/blog/mcp-authentication-boundary — The MCP authentication boundary, reviewed https://drel.ai/blog/rag-access-control — Access control for RAG — keeping retrieval inside the line https://drel.ai/blog/iso-42001-annex-a-controls — ISO 42001 Annex A Controls Explained (Plain Language) https://drel.ai/blog/tool-use-permissions-agentic-ai — Tool-use permissions for agentic AI — least privilege for agents https://drel.ai/blog/eu-ai-act-high-risk-obligations — High-risk AI obligations under the EU AI Act https://drel.ai/blog/llm-insecure-output-handling — Insecure output handling — the LLM risk teams underrate https://drel.ai/blog/when-to-run-ai-security-review — When to run an AI security review — the four trigger points https://drel.ai/blog/assessing-ai-features-in-saas — Assessing the AI feature inside SaaS you already bought https://drel.ai/blog/ai-risk-acceptance-who-signs — AI risk acceptance — who actually signs https://drel.ai/blog/iso-42001-vs-iso-27001 — ISO 42001 vs ISO 27001 — what is new for AI https://drel.ai/blog/mcp-tool-poisoning — Tool poisoning in MCP servers https://drel.ai/blog/rag-data-poisoning — Data poisoning in RAG knowledge bases https://drel.ai/blog/eu-ai-act-system-inventory — Building an EU AI Act system inventory https://drel.ai/blog/agentic-ai-attack-surface — Mapping the agentic AI attack surface https://drel.ai/blog/prompt-injection-explained — Prompt injection, explained for security reviewers https://drel.ai/blog/ai-security-review-checklist — The AI security review checklist, by lifecycle gate https://drel.ai/blog/vendor-ai-security-questionnaire — The AI section your vendor security questionnaire is missing https://drel.ai/blog/ai-governance-committee-charter — Writing an AI governance committee charter https://drel.ai/blog/what-is-mcp-security — MCP security — the four attack surfaces of a Model Context Protocol server https://drel.ai/blog/iso-42001-explained — ISO 42001, explained for security teams https://drel.ai/blog/what-is-rag-security — RAG security — the three boundaries that matter https://drel.ai/blog/eu-ai-act-risk-tiers-explained — EU AI Act risk tiers, explained for engineers https://drel.ai/blog/what-is-agentic-ai-security — Agentic AI security — the surfaces deterministic software does not have https://drel.ai/blog/owasp-llm-top-10-walkthrough — The OWASP LLM Top 10, mapped to controls https://drel.ai/blog/what-is-an-ai-security-review — What an AI security review actually is (and what it is not) ## Glossary https://drel.ai/glossary — AI security glossary index https://drel.ai/glossary/ai-security-clearance — AI Security Clearance: A structured decision, supported by evidence, on whether an AI system can reach production and under what controls. https://drel.ai/glossary/ai-risk-disposition — AI Risk Disposition: The structured memo recording the AI Committee's decision about an AI system, the rationale, the required controls, the residual risks accepted, the evidence gaps, and the re-assessment triggers. https://drel.ai/glossary/evidence-pack — Evidence Pack: The structured bundle of artefacts that supports an AI system's security clearance decision — threat model, control plan, evidence gaps, framework mapping, and disposition. https://drel.ai/glossary/clearance-decision — Clearance Decision: The specific outcome of an AI security review: one of proceed, conditional, restricted pilot only, hold, or decline. https://drel.ai/glossary/control-gap — Control Gap: An identified, named difference between a required control and the evidence on file — a control that should be in place but is not yet evidenced, implemented, or both. https://drel.ai/glossary/delegation-chain — Delegation Chain: The sequence of authorisations that allows an orchestrator agent to spawn sub-agents and each sub-agent to invoke tools or call other systems. https://drel.ai/glossary/agent-blast-radius — Agent Blast Radius: The set of resources, actions, and identities that an agent can reach through its tools, delegation chain, and memory — and therefore the maximum possible impact if the agent is compromised. https://drel.ai/glossary/vendor-ai-assessment — Vendor AI Assessment: A security review of a third-party AI feature or SaaS AI product, performed without runtime access to the vendor's source — based on documented architecture, declared data flows, and contractual control claims. https://drel.ai/glossary/ai-go-live-review — AI Go-Live Review: The structured security review that runs before an AI system passes the production-readiness gate — verifying that pre-pilot and pilot controls are in place and that production-readiness controls are operational. https://drel.ai/glossary/audit-ready-dossier — Audit-Ready Dossier: A versioned, sign-off-bearing record of an AI system's security review — exportable for auditor or regulator review, structured so each stakeholder can find their part without reading the whole. ## Key concepts - AI Security Review: a structured go/no-go decision for AI systems before production - Risk Disposition: five-state decision (proceed / conditional / restricted pilot / hold / decline) - Evidence Pack: audit-ready dossier linking controls to evidence and framework requirements - Assessed systems: AI systems that have gone through a Drel security review - Control gaps: required controls not yet evidenced in an assessed system