The platform

Every AI tool. Every decision.
Every line of evidence.

Draxion covers the complete AI governance lifecycle — from the moment an employee opens a new AI tool to the day your auditor signs off. Thirteen capabilities, grouped by the job they do.

The atlas

Every capability below ships today, except where marked as upcoming.

Coverage

One platform, from first detection to signed-off audit.

13
Capabilities across the governance lifecycle
7
Compliance frameworks reported on automatically
48
Curated regulatory chunks behind every claim
164
NIST AI RMF assessment items covered

MonitorDetect

See what is actually happening.

Detection is the precondition for everything else on this page. Before Draxion asks you to write a policy or approve a tool, it maps the surface you are governing — every AI tool in use, every risky submission, every employee, in real time.

M-01

Shadow AI Discovery

The moment the Chrome extension is deployed across your organization, Draxion begins building a complete, real-time map of every AI tool in use — approved, unapproved, and unknown. Most organizations discover 15–20 tools they never knew existed within the first 24 hours of deployment.

Availability

Starter: includedProfessional: includedEnterprise: included

What you get

  • Live discovery feed with tool name, user, department, and timestamp
  • Categorized tool inventory: sanctioned, under review, blocked
  • First-detection alerts via email and Slack
  • CSV export for compliance documentation
M-02

Data Leakage Prevention (DLP)

Real-time scanning of every paste and submission event on AI tool domains. Draxion detects PII, credentials, source code, financial data, and medical records client-side — before content is submitted to external models. The employee sees a coaching notification. You see the classification log. The raw content never leaves the browser.

Availability

Starter: includedProfessional: includedEnterprise: included

What you get

  • PII detection: names, emails, phone numbers, national IDs, financial account numbers
  • Credential detection: API keys, passwords, tokens, certificates
  • Source code pattern detection
  • HIPAA-relevant PHI classification
  • DLP event log with severity, classification, tool, user, and timestamp
  • Configurable block vs. warn behavior per tool and data type
M-03

Employee Risk Scores

Every monitored employee receives a dynamic risk score (0–100) calculated from their actual AI behavior — which tools they access, how frequently, whether those tools are approved, and whether they have triggered DLP events. Risk scores update in real time and are available to security teams and managers.

Availability

Starter: includedProfessional: includedEnterprise: included

What you get

  • Individual employee risk score dashboard
  • Risk score breakdown by contributing factor
  • Historical risk score trend per employee
  • Manager-facing summary view
  • High-risk employee alerts
  • Export for HR or legal review
M-04

Department Risk View

Aggregate employee risk scores by team, department, or business unit. See which parts of your organization are running the highest AI risk, where DLP events are concentrated, and which managers need to have a governance conversation with their team. Drill from org-wide down to individual in two clicks.

Availability

Starter: not includedProfessional: includedEnterprise: included

What you get

  • Department-level risk heatmap
  • Comparative risk ranking across teams
  • DLP event concentration by department
  • Unapproved tool usage by department
  • Manager notification workflows
M-05

Real-Time Detection Feed

A live command center displaying every AI tool detection event across your entire organization as it happens. Filter by risk level, department, tool category, or individual employee. Sort by severity or recency. Export any view directly for compliance review or incident documentation.

Availability

Starter: includedProfessional: includedEnterprise: included

What you get

  • Live event stream with sub-second latency
  • Filter: risk level, department, tool, user
  • Bulk export (CSV, JSON) for any time range
  • Saved filter presets
  • Slack and email alert routing by filter

GovernDecide

Turn visibility into decisions that hold up.

A decision that was never written down did not happen. This is where an approval becomes a timestamped, signed, defensible record — the paper trail regulators specifically ask for, and the one your executives will be judged against personally.

G-01

AI Acceptable Use Policy Generator

Answer 6 questions about your organization — industry, size, applicable regulations, and current tool inventory. Draxion generates a complete, legally grounded AI acceptable use policy in under 2 minutes, with every provision citing the specific regulation article that justifies it. The draft is reviewed by a simulated hostile auditor before you see it — any unsubstantiated claim is flagged and revised.

Availability

Starter: partially includedProfessional: includedEnterprise: included

Starter includes 3 policy generations per month. Professional and above are unlimited.

What you get

  • Complete AUP document (Word + PDF export)
  • Citations to GDPR, EU AI Act, HIPAA, SOC 2, NIST AI RMF articles
  • Auditor simulation report with flagged items
  • Version history with change tracking
  • 3 generations per month on Starter, unlimited on Professional+
G-02

Tool Approval Workflow

When the discovery feed identifies an unapproved tool, your security team can formally review, approve, conditionally approve, restrict, or block it with a single click. Every decision is timestamped with the reviewing officer’s identity, linked to the risk assessment that justified it, and stored in an immutable audit record. This is the paper trail regulators specifically ask for under GDPR Article 32 and EU AI Act Article 9.

Availability

Starter: includedProfessional: includedEnterprise: included

What you get

  • One-click approve / restrict / block workflow
  • Risk assessment linked to each decision
  • Digital signature on each approval action
  • Automated employee notification on tool status change
  • Full approval history exportable for audit
  • Bulk approval for tool categories
G-03

Executive AI Liability Tracker

Under EU AI Act Article 5 and Article 9, executives who approve or deploy high-risk AI systems may face personal liability. Draxion records every AI system approval, rejection, and risk escalation by the authorizing executive, with digital attestation workflows that create a defensible record of informed decision-making. A board-facing dashboard shows every approved system, its risk classification, and who signed off.

Availability

Starter: not includedProfessional: includedEnterprise: included

What you get

  • Executive-level approval and attestation workflow
  • Board dashboard: approved systems, risk levels, approvers
  • EU AI Act risk classification per tool
  • Personal liability exposure summary per executive
  • Quarterly board report generation
G-04

AI Contract Intelligence Engine

Upload any AI vendor contract, terms of service, or data processing agreement. Draxion extracts and risk-scores every clause that matters to your legal and security team: data training policies, data residency requirements, liability caps, IP ownership clauses, GDPR Article 28 compliance gaps, and model update notification obligations. Risk score and negotiation points delivered in under 30 seconds.

Availability

Starter: not includedProfessional: includedEnterprise: included

What you get

  • Automated clause extraction and categorization
  • Risk score per contract (0–100)
  • GDPR Article 28 gap analysis
  • Negotiation point summary
  • Side-by-side comparison across vendors
  • Export as legal review memo

ComplyProve

Hand an auditor evidence, not assertions.

Every compliance output Draxion produces is retrieved from the statutory text before it is written. No hallucinated citations, no generic template language — the difference between a report an auditor accepts and one they start questioning.

C-01

7-Framework Compliance Reports

Monthly audit-ready compliance reports generated automatically across seven frameworks: GDPR, EU AI Act, SOC 2, ISO 27001, HIPAA, SOX, and NIST AI RMF. Every claim in every report cites the specific article from the relevant regulation — retrieved in real time from Draxion’s embedded regulatory knowledge base. No hallucinated citations. No generic statements. Reports are designed to be handed directly to auditors.

Availability

Starter: partially includedProfessional: includedEnterprise: included

Starter covers GDPR and NIST AI RMF. All seven frameworks unlock on Professional and above.

What you get

  • Monthly automated report generation
  • Framework-specific reports or unified cross-framework view
  • Regulation article citations on every claim
  • Executive summary and technical detail sections
  • PDF and Word export
  • Historical report archive
C-02

Regulatory Knowledge Base

48 curated regulatory chunks stored as vector embeddings — the actual statutory text of GDPR, EU AI Act, HIPAA, SOC 2, ISO 27001, NIST AI RMF, SOX, and FERPA. Before Draxion generates any policy, report, or compliance claim, it retrieves the relevant regulation text using semantic search and grounds every output in that text. This is what separates Draxion’s compliance outputs from generic AI-generated templates.

Availability

Starter: includedProfessional: includedEnterprise: included

Direct querying of the knowledge base is an Enterprise capability.

What you get

  • RAG-grounded policy and report generation
  • Regulation text cited inline in all outputs
  • Knowledge base updated as regulations change
  • Query the knowledge base directly (Enterprise)
  • FERPA coverage for education sector
C-03

Draxion Governance Score (DGS)

Coming in Phase 3.5

A 0–1000 composite governance score calculated across 8 components: detection coverage, policy completeness, incident response speed, employee AI literacy, vendor risk management, executive accountability, regulatory currency, and industry percentile. Think of it as the FICO score for your AI governance program — a single number that tells your board, your auditors, and your insurers exactly where you stand.

Availability

Starter: not includedProfessional: not includedEnterprise: included

What you get

  • Real-time DGS dashboard
  • Score breakdown by component
  • Industry percentile benchmark
  • Improvement recommendations ranked by impact
  • Historical score trend
  • Board-ready DGS report
C-04

NIST AI RMF Assessment

A structured questionnaire covering all four NIST AI Risk Management Framework functions — Govern, Map, Measure, and Manage — with 164 individual assessment items. Draxion pre-fills answers it can derive from your account data, reducing completion time from weeks to hours. The output is a formal NIST AI RMF compliance report ready for government clients, federal contractors, and organizations preparing for AI-related audit requirements.

Availability

Starter: not includedProfessional: includedEnterprise: included

What you get

  • Guided NIST AI RMF questionnaire
  • Auto-populated answers from account data
  • Gap analysis with remediation roadmap
  • Formal NIST AI RMF compliance report
  • Ready for federal contractor submissions

See it live

Ready to see every capability in action?

Get a personalized walkthrough tailored to your industry and compliance requirements.

Questions before a demo? hello@draxion.io reaches a human.