Governing AI and human actions across the tools your teams already use
- Claude
- ChatGPT
- Slack
- Microsoft Teams
- Microsoft 365
- Gmail
- GitHub
- GitLab
What it does
- Determines which obligations apply to this vendor, at this criticality
- Requests the evidence that would satisfy them
- Checks what was returned against the rule, not against a checkbox
- Escalates anything lapsed or missing to the named risk owner
- Keeps the file current as certificates roll, without a new cycle
What you get
An evidence file per vendor
An evidence file per vendor: the obligations that apply at this criticality, the evidence requested, what came back, what was accepted against the rule, and what lapsed. It stays current as certificates roll rather than ageing between review cycles.
What it needs from you
Your vendor list with a criticality rating, and wherever the evidence lives today — a drive, a GRC tool, an inbox. Tredy works from that rather than starting a fresh collection round.
Where it stops
It does not accept a vendor. It reports what the evidence supports and what lapsed; the risk owner decides whether to proceed.
What starts it
A new vendor
A vendor enters onboarding and needs to be assessed before it is used.
A renewal
A contract reaches renewal and the file must be current to proceed.
A lapse
A certificate, attestation or insurance cover expires or is withdrawn.
Start with one service.
A 30-minute scoping session with your risk owner and your IT contact.