The platform, in depth

Every AI system reviewed.
Every decision on record.

Drel reviews AI systems, identifies the controls they require, and finds the evidence that each one is in place, with a human security decision on top.

One continuous review

One review, from first draft to production and beyond.

  1. 01
    STEP 01

    Describe

    The system, its data, and what it is allowed to do.

    You getSystem brief
    Agent
    Customer records
    Hosted LLM
    Support agents
    Refund tool
    Tool access
    Issue refundwrite
  2. 02
    STEP 02

    Threat model

    Attack paths and the controls the system requires.

    You getThreat model and required controls
    Attack pathprompt injection
    Approval gate
    Required before pilot
  3. 03
    STEP 03

    Evidence

    The proof each control is in place, including the line of code that shows it.

    You getEvidence per control
    refunds.ts
    41async function issueRefund(order, amount) {
    42  await requireApproval(order, amount);
    43  return payments.refund(order.id, amount);
    44}
    Approval gate found
    refunds.ts, line 42
  4. 04
    STEP 04

    Decide

    A human clearance decision, with evidence attached.

    You getClearance record
    2/3controls
    Conditional
    Cleared for pilot
    Rate limit required before production
    CIAGDP
    Signed by the AI Committee
    14 evidence items attached
  5. 05
    STEP 05

    Change

    Reopened when the system changes, only where the change reaches.

    You getA new version, reviewed and sealed
    Version historyv1 signed
    tool scope changed
    v2 reviewed
    Only the tool scope reopened
The output

This is what
you get.

A structured clearance record with named blockers, required controls, evidence states, and a clearance decision, specific to your AI system, defensible in front of your AI Committee.

Named go-live blockers with owners
Required controls per lifecycle gate
Evidence state on every claim
Five-state clearance decision
Versioned, timestamped, exportable
Internal RAG Assistant
Evidence pack · Ready in minutes
Conditional · clear to launch
A clear path to go-live: 3 controls, each mapped to the risk it closes.
Go-live blockers
Indirect prompt injection via SharePoint documents
Validation: Inject adversarial instructions into a SharePoint document and verify the RAG system does not execute them
Threat register
Indirect Prompt Injection
OWASP LLM01
Critical
Retrieval ACL Bypass
MITRE AML.T0054
High
Identity Propagation Failure
MAESTRO L3
High
Excessive LLM Agency
OWASP LLM08
Medium
Recommended controls
prevInput sanitization pipeline before retrieval
prevACL enforcement at chunk retrieval layer
detePrompt injection detection classifier
Security questionnaire
Is prompt injection mitigated?In progress
Are retrieval ACLs enforced?Confirmed
Is PII redacted before LLM?Confirmed
Is output logged and auditable?Confirmed
Evidence grading

Every claim graded.
Nothing assumed without a label.

Most security tools produce findings. Drel grades the evidence behind every finding, so your AI Committee knows exactly what is proven, what is assumed, and what is missing before they sign.

StateDefinition
Explicit

Stated directly in a source artifact or confirmed by a reviewer.

Inferred

Derived from context with stated reasoning. Traceable but not direct.

Assumed

Plausible default applied because the source is silent.

Unknown

Question raised but not yet answered. Needs investigation.

Missing

Claim depends on evidence that has not been provided. Blocks clearance.

Verified

Evidence attached and accepted by an authorized reviewer.

Review lifecycle

From intake
to production.

Drel tracks an AI system through its full review lifecycle, from initial intake through restricted pilot, production readiness, and ongoing governance. Every gate is documented.

1
Intake

System description, owners, scope, regulatory context.

2
Design review

Architecture model, components, trust boundaries.

3
Threat model

Threat register, attack paths, framework mappings.

4
Control plan

Required controls, owners, deadlines, evidence required.

5
Restricted pilotGate

Pilot-gate controls verified. Scope limited.

6
Prod readinessGate

Production-gate controls verified. Evidence complete.

7
OperatingOngoing

System live. Re-review triggers active.

8
MonitoringOngoing

Ongoing governance controls tracked.

9
Re-reviewOngoing

Triggered by model change, tool addition, scope expansion.

A living clearance

The review doesn't stop at the document.

A clearance is only as good as the system it describes. Drel ties each decision to the evidence behind it, including the code that implements a control, and reopens it when the system changes: one continuous review, not a report you file and forget.

Evidence found in the code.

Link the GitHub repository behind the system. Drel looks for the code or configuration that shows each control is in place, reads every file at one commit, and quotes the exact line with a link to it. Your reviewer decides whether it counts as evidence.

A finding is a quoted line for a reviewer to judge. Drel never marks a control verified on its own, and stores nothing from the repository.

  1. 01

    Describe

    The system, its data, and what it is allowed to do.

  2. 02

    Find

    The code that shows each control is in place, quoted from your repository at one commit.

  3. 03

    Decide

    Your reviewers judge what was found, then approve, restrict or hold, with the evidence attached.

Reopened when the system changes.

When the system changes, record it in Drel. Drel reopens only the parts the change affects, gives each one an owner, and shows what would close it. The clearance you signed stays exactly as it was signed, and the new version gets its own decision.

Drel shows the difference. It does not rewrite history, and it does not renew or revoke a clearance on its own.

  1. Changed

    You record a change to the system. Drel reopens only the parts it affects.

  2. Owned

    Each reopened item has an owner and a due date.

  3. Closed

    The new version is reviewed and sealed, with its evidence attached.

Signed clearance · stays exactly as signed

The signed clearance stays exactly as signed while the correction runs.

Framework coverage

OWASP. MITRE. NIST.
Mapped automatically.

Drel maps every threat to the frameworks your AI Committee and auditors expect, without manual cross-referencing.

Framework Coverage

Threat mapping across security frameworks

65%
OWASP LLM Top 1080%
8/10 threats
MITRE ATLAS60%
6/10 threats
MAESTRO70%
7/10 threats
NIST AI RMF50%
5/10 threats

Ready to clear your first AI system?

Start a free evaluation or talk to the team about your governance requirements.