485 days until EU AI Act high-risk obligations apply · Dec 02 2027Book a 30-min briefing →
For security & compliance teams

Stand up agent governance before your auditor does.

Vettd Cloud runs in your private cloud: a living inventory of the estate, graded on security and performance, with framework coverage your auditor and your board can read at a glance.

485
days · EU AI Act

High-risk obligations apply Dec 02, 2027: audit trails, transparency, post-market monitoring.

Penalties reach €15M or 3% of global turnover. The deadline is public; most AI estates aren't even counted yet. An inventory you can defend is the first control every framework asks for.

Regulation (EU) 2024/1689 · also maps: NIST AI RMF · ISO 42001 · SOC 2 · OWASP

What you get

The estate, on the record.

Everything the open-source scanner sees, organized for the people who have to defend it: security, compliance, and the executives they answer to.

01

Private estate inventory

Every agent, model, MCP server, and credential across hosts and teams: deployed in your cloud, under your keys. Nothing shared unless you choose to.

02

Grades, not guesswork

Security and performance per asset, on one open schema, with every scanner and eval you already run folding into the same record.

03

Framework coverage, live

Findings cross-walked to NIST AI RMF, ISO 42001, the EU AI Act, and SOC 2, whichever frame your auditor speaks, tracked release over release.

04

Evidence that closes loops

Findings become fixes with owners; re-scans prove them. Signed, dated bundles your auditor can verify, not screenshots in a shared drive.

How it runs

Weeks to a defensible posture. Not quarters.

Built to land in your existing GRC stack, not to replace it. Your team keeps its tools; Vettd becomes the system of record they all write to.

WK 1
Scan the estate

vettd-cli runs where your agents live: laptops, CI, hosts, gateways. Fully local; the results land in your private instance.

WK 2–3
Grade & map

Assets graded on both axes; findings cross-walked to the frameworks in scope. Your existing scanner output folds in.

WK 4+
Fix & re-scan

Findings become owned remediation work. Re-scans prove each fix and move the coverage number, visibly, on the dashboard.

ONGOING
Prove, continuously

The estate keeps changing; the inventory keeps up. Evidence bundles export on demand, for the audit, the customer, or the board.

// vendor-neutral by design — neutrality is the asset. we grade; we don't sell the agents.

How teams adopt

Start where you are.

No rip-and-replace, no five new procurements. Bring the tools you already license; Vettd charges for the normalization, the decision, and the credential.

01Today
Bring your own providers

Connect what you already run. Vettd normalizes, grades, and issues credentials.

02Next
Vettd Verified

Providers submit connectors and test corpora; Vettd validates and awards tiers.

03Roadmap
Open-source suite

Selected OSS scanners and adapters ship inside vettd-cli, no five extra purchases.

04Roadmap
Curated packs

One procurement motion — runtime protection, evals, sector packs — vendors named transparently.

Why security teams pick Vettd

Blocking is easy. Yes is the product.

A standing credential means teams stop waiting on ad-hoc reviews: anything ALLOW ships today, anything BLOCK explains itself, and everything in between carries its conditions with it. Security stops being the department of no, and adoption compounds.

BEFOREEvery new agent → a security review ticket → three weeks in a queue.
WITH VETTDCredentialed assets are pre-cleared. The review happens once, then stays live.
THE KICKERExceptions don't pile up in Slack — they become ALLOW_WITH_CONDITIONS, on the record.

The rating stays neutral. Evidence production and credential adjudication are separated by design: providers are named, schemas are published, decisions are reproducible.

How we stay neutral →
30 minutes, your calendar

Bring one question: "what's running here?"

We'll show you how teams answer it in a week — and leave you with the scanner either way. It's open source.