01
Support in the professional context
Every domain, from risk to AI governance, keeps its own logic. KaitoSec AI prepares; accountable people review and decide.
AI Assistant
KaitoSec supports the current record with drafts, summaries and mappings. Sources remain visible and changes require approval from an accountable person.
Where friction starts today
Most of a security and compliance programme is not hard, it is just relentless. Classifying a new asset, drafting a questionnaire answer you have written ten times before, writing the justification for a control, chasing the next review. None of it needs deep thought, all of it needs doing, and it quietly consumes the people who should be working on the decisions that actually matter.
Bolting a chatbot onto the side does not fix this. A general assistant that knows nothing about your asset register, your risks or your open controls just produces confident text you then have to check. What helps is support on the actual record: a draft with visible sources and approval by the accountable person. That reduces writing and searching without handing assessment, decisions or governance to a model.
One data model
KaitoSec AI works on the selected record and keeps the links to requirements, risks, controls and evidence intact.
This module
AI Assistant
Shared data model
One asset, one risk, one control, one piece of evidence
Entry to evidence
Sources, changes and approvals remain visible. KaitoSec AI can prepare work, but an accountable person reviews and approves every change to the workspace.
One change
A risk is re-assessed
Written with it
Where it surfaces
Simple or expert
One switch per person, the same data. Simple mode shows what needs deciding. Expert mode opens SoA references, risk links and the audit trail.
KaitoSec AI and modesSimple mode
Expert mode
KaitoSec AI
The agents work on a world model of over 5,000 entities: from governance through ISMS, BCMS, DSMS, AIMS and TPRM down to the operative MITRE ATT&CK tactics. They prioritise, keep registers and evidence current and propose the next step.
Before anything counts, a network of practitioners reviews it. Decisions stay with people.
Compliance routine is the starting point. Security and resilience are the goal.
See KaitoSec AIThe world model
Governance
Policies · roles · approvals
Management systems
ISMS · BCMS · DSMS · AIMS · TPRM
Measures and evidence
Registers · tasks · audit packs
Operational tactics
MITRE ATT&CK
Applicable requirements and current workspace context become policy and control drafts for professional review.
01
Every domain, from risk to AI governance, keeps its own logic. KaitoSec AI prepares; accountable people review and decide.
02
Suggestions refer to the selected record and the information available there. This makes it possible to review what a summary, mapping or recommendation is based on.
03
First drafts of risk treatments, BC plans, policy sections, vendor responses and audit answers are produced from workspace context, not generic templates. Review, adjust, publish, with every approval logged for governance.
04
Cmd+J opens KaitoSec AI on any record. Cmd+K runs a global search across assets, risks, controls, policies, vendors, incidents and BC plans. The shortcut works the same on every page and brings KaitoSec AI to the current record with one keystroke.
Summarise risk context, prepare treatment options, identify missing evidence and assign follow-up work without separating the result from its source record.
01
Upload a framework assessment or describe the current state. KaitoSec AI maps the input to the selected framework and prepares potential gaps across ISMS, BCMS, DSMS and AIMS for review.
02
Select a risk, asset, vendor, policy or AI system and summarise status, related findings and missing context. The accountable person reviews the result before it is used further.
03
Simple Mode walks new users through a guided flow with the next action surfaced for them. Expert Mode opens the full depth of the platform for the ISB, the risk owner or the auditor. Both modes run on the same platform, switchable per user or per session.
04
Filter the entire workspace to one scope: a tenant, a site, a standard, a single management system. The lens narrows risk views, evidence packages and reports without rebuilding the data model, and works for multi-entity organisations from day one.
05
KaitoSec AI can prepare SoA justifications, questionnaire responses, asset classifications or exercise scenarios. No workspace change takes place without human approval.
KaitoSec is developed and hosted in Germany. AI use remains bounded by documented data sources, configured infrastructure and human approval for workspace changes.
AI agents in KaitoSec import existing registers and documents, check them against the methodology (for example, the six phases of BSI IT-Grundschutz), identify gaps and turn them into tasks with an owner and due date.
No. AI agents prepare the work; people decide. Every suggestion remains under human oversight, is reasoned and traceable, and only takes effect after approval. See ISO 42001 for the governance model.
AI use in KaitoSec is GDPR-compliant: hosting remains in Germany, customer data is not used for model training and the agent retains the user's permissions. Details are available under Integrations.
Yes. Your own AI assistants can access KaitoSec through the MCP server and documented API. They read and write registers, risks and evidence directly instead of parsing PDF exports, using least-privilege scopes.
KaitoSec agents handle data import and mapping, completeness checks, suggestions for risk assessments, deriving controls from requirements, collecting and assigning evidence, and preparing audit responses.
Use the same traceable records for your AI inventory, risk work and governance under ISO 42001 and the EU AI Act.