Every AI system reviewed.
Every decision on record.
Drel reviews AI systems, identifies the controls they require, and finds the evidence that each one is in place, with a human security decision on top.
One continuous review
One review, from first draft to production and beyond.
- 01STEP 01
Describe
The system, its data, and what it is allowed to do.
You getSystem briefAgentCustomer recordsHosted LLMSupport agentsRefund toolTool accessIssue refundwrite - 02STEP 02
Threat model
Attack paths and the controls the system requires.
You getThreat model and required controlsAttack pathprompt injectionApproval gateRequired before pilot - 03STEP 03
Evidence
The proof each control is in place, including the line of code that shows it.
You getEvidence per controlrefunds.ts41async function issueRefund(order, amount) {42 await requireApproval(order, amount);43 return payments.refund(order.id, amount);44}Approval gate foundrefunds.ts, line 42 - 04STEP 04
Decide
A human clearance decision, with evidence attached.
You getClearance record2/3controlsConditionalCleared for pilotRate limit required before productionCIAGDPSigned by the AI Committee14 evidence items attached - 05STEP 05
Change
Reopened when the system changes, only where the change reaches.
You getA new version, reviewed and sealedVersion historyv1 signedtool scope changedv2 reviewedOnly the tool scope reopened
This is what
you get.
A structured clearance record with named blockers, required controls, evidence states, and a clearance decision, specific to your AI system, defensible in front of your AI Committee.
Every claim graded.
Nothing assumed without a label.
Most security tools produce findings. Drel grades the evidence behind every finding, so your AI Committee knows exactly what is proven, what is assumed, and what is missing before they sign.
Stated directly in a source artifact or confirmed by a reviewer.
Derived from context with stated reasoning. Traceable but not direct.
Plausible default applied because the source is silent.
Question raised but not yet answered. Needs investigation.
Claim depends on evidence that has not been provided. Blocks clearance.
Evidence attached and accepted by an authorized reviewer.
From intake
to production.
Drel tracks an AI system through its full review lifecycle, from initial intake through restricted pilot, production readiness, and ongoing governance. Every gate is documented.
System description, owners, scope, regulatory context.
Architecture model, components, trust boundaries.
Threat register, attack paths, framework mappings.
Required controls, owners, deadlines, evidence required.
Pilot-gate controls verified. Scope limited.
Production-gate controls verified. Evidence complete.
System live. Re-review triggers active.
Ongoing governance controls tracked.
Triggered by model change, tool addition, scope expansion.
The review doesn't stop at the document.
A clearance is only as good as the system it describes. Drel ties each decision to the evidence behind it, including the code that implements a control, and reopens it when the system changes: one continuous review, not a report you file and forget.
Evidence found in the code.
Link the GitHub repository behind the system. Drel looks for the code or configuration that shows each control is in place, reads every file at one commit, and quotes the exact line with a link to it. Your reviewer decides whether it counts as evidence.
A finding is a quoted line for a reviewer to judge. Drel never marks a control verified on its own, and stores nothing from the repository.
- 01
Describe
The system, its data, and what it is allowed to do.
- 02
Find
The code that shows each control is in place, quoted from your repository at one commit.
- 03
Decide
Your reviewers judge what was found, then approve, restrict or hold, with the evidence attached.
Reopened when the system changes.
When the system changes, record it in Drel. Drel reopens only the parts the change affects, gives each one an owner, and shows what would close it. The clearance you signed stays exactly as it was signed, and the new version gets its own decision.
Drel shows the difference. It does not rewrite history, and it does not renew or revoke a clearance on its own.
Changed
You record a change to the system. Drel reopens only the parts it affects.
Owned
Each reopened item has an owner and a due date.
Closed
The new version is reviewed and sealed, with its evidence attached.
Signed clearance · stays exactly as signed
The signed clearance stays exactly as signed while the correction runs.
OWASP. MITRE. NIST.
Mapped automatically.
Drel maps every threat to the frameworks your AI Committee and auditors expect, without manual cross-referencing.
Framework Coverage
Threat mapping across security frameworks
Ready to clear your first AI system?
Start a free evaluation or talk to the team about your governance requirements.