Skip to content
STRAI8About us

AI governance was built around one rulebook.

The category standardised on the EU AI Act. But an enterprise’s AI answers to several regimes at once, and the list is still being written — new obligations commenced in China, South Korea, the UAE and four US states inside eighteen months, and India’s DPDP duties land in 2027. We built it the other way round: one framework, one set of controls, and every rulebook mapped onto it — including the ones that arrive next.

Why we built it

Three gaps, and none of them were on anyone’s roadmap.

AI governance became a category in about eighteen months. It grew up around a single statute, and it priced itself for the enterprises being sued first. Everything outside that — every other regime, and every enterprise that could not fund a two-year programme — was left to fill in a text field.

01

Built around one statute, in a world with dozens

A platform designed on a single regulatory spine can only ever treat the next instrument as a custom field you fill in yourself — which is the same as not having it. And the next instrument keeps coming: six regimes commenced in the eighteen months to August 2026 alone.

One control, tested once, answering every rulebook that asks.
02

The ones that did the global part were priced like a programme

Enterprise GRC suites arrive with an implementation partner, a six-to-eighteen month runway and a budget line that needs board approval before anyone has seen a single AI system. Governance that starts in year two is governance you did not have in year one.

Governance-ready in a quarter, not a fiscal year.
03

Nothing had an answer for systems that act

The category was built for models that predict. An agent that authorises a payment, files a ticket or calls another agent is a different governance problem, and “we monitor the model” is not an answer to it.

Autonomy tiers, pre-execution authorisation, a kill switch.
What one AI estate answers to
The spine the category maps
EU AI ActISO/IEC 42001ISO/IEC 23894NIST AI RMF
And everything it meets besides
China · generative AI measuresIn forceSouth Korea · AI Framework ActIn forceUAE · DIFC Regulation 10In forceIllinois · HB 3773In forceTexas · TRAIGAIn forceCalifornia · SB 53In forceIndia · DPDP Act 20232027Singapore · Model AI FrameworkGuidance
Who built it

Written by the person who used to answer the audit.

Strai8 was founded by Sachin K. Arora, a career CISO — someone who spent years running security and governance inside regulated enterprises, on the receiving end of the questionnaire rather than the sending end.

That is the whole difference. The people who assemble evidence at two in the morning before a regulator walks in know something the category does not: the problem was never writing the policy. It was proving, on any ordinary day and without warning, that the policy was still true.

Sachin K. Arora, Founder and CEO of Strai8
Sachin K. AroraFounder & CEOView profile
Built fromA CISO’s own control environment, not a category analysis
Written down20 published documents across legal, security, AI and operations
STRAI8

8 principles.
One direction.

STRAI8 is our own framework for building trustworthy AI systems and governing them across their entire lifecycle. Every pillar is a test a system either passes or fails, and every one of them carries weight in the score.

Scroll to explore all 8 principles
01 / 0815% of governance maturity

Secure

Governance must not become the way in.


Every connector Strai8 opens is read-only and scoped to what you name. Systems are assessed the way a model is actually attacked — adversarial input, data poisoning, access it should never have had. And the platform itself runs inside your region, geo-fenced, so residency and localisation obligations are met by where it sits rather than by a clause in a contract.

What a connection can do
ReadsRepositories · files · directory · logs
Writes backNothing, to any connected system
ScopeOnly what you authorise, per connector
ResidencyYour region, geo-fenced — nothing crosses it
Access controlScoped, least-privilege, per connector.
Adversarial robustnessTested against the attacks models face.
Data poisoningTraining and retrieval sources assessed.
Data sovereigntyIn-region, localised, and geo-fenced.
02 / 0812% of governance maturity

Transparent

A system nobody can describe cannot be governed.


Every record carries its purpose, its owners, the data behind it and the things it is not to be used for — disclosed on the record, where the people who answer for it can read them.

On every AI system record
PurposeWhat it decides, and for whom
OwnersTechnical and business, by name
DataWhat goes in, and where it came from
LimitsWhat it is not to be used for
Model cardsMaintained for every significant model.
DisclosureDecision logic and known limitations, stated.
Documentation qualityAssessed, not assumed.
Stakeholder communicationWritten for the people affected.
03 / 0815% of governance maturity

Reliable

AI systems do not need to work once.


They need to keep working as the data, the models and the world around them move. Strai8 watches runtime signal continuously, and drift re-opens the assessment that cleared the system — it does not file a ticket.

Runtime signal
Drift detectedAssessment re-run
Performance monitoringContinuous, not per release.
Drift detectionData and concept drift, caught early.
Anomaly alertsRaised when risk moves, not when logs do.
Assessment triggersA finding re-opens the assessment.
04 / 0812% of governance maturity

Accountable

Every finding resolves to a person.


A detection nobody owns is a report. Strai8 walks a signal back to the host it came from, the owner named on that system and the department that answers for it — so it arrives as a decision waiting to be made.

Who answers for this
DetectionHostOwner · roleDepartment
Named ownershipTechnical and business owner, per system.
Escalation pathsDefined before the finding, not after.
Audit trailsEvery state change, with its actor.
Governance processDeadlines a record can be judged against.
05 / 0812% of governance maturity

Interpretable

An answer you cannot check is an opinion.


Every answer Strai8 gives carries the passage it came from, down to the section and the page. Where the evidence does not support an answer, it says so rather than producing one.

Grounded, or it abstains

The policy requires human review before deployment.

AI Governance Policy · §5 · p.7
Grounded citationsThe clause, not a paraphrase.
ExplainabilityHuman-readable, for the audience asking.
AbstentionNo evidence, no answer.
Calibrated depthScaled to the risk of the decision.
06 / 0813% of governance maturity

Governed

One control, tested once, answering every framework that asks for it.


A single control maps to every clause it satisfies across the frameworks you answer to. Evidence is produced once, instead of assembled five times for five audits that wanted the same thing.

One control answers many
No AI management policy
EU AI ActISO 42001ISO 23894CSA AICMNIST AI RMF
Policy completenessGaps named against the clause.
Lifecycle governanceDesign through decommissioning.
Regulatory alignmentIndian and global instruments.
Control mappingOne control, every clause it answers.
07 / 0811% of governance maturity

Humane

AI acts on people.


Where a system decides something about someone, its effect on them is tested — outcomes compared across protected attributes, the finding recorded, and remediation required before the system carries on.

Where a system affects people
AssessmentOutcomes comparedFinding recordedRemediation required
Bias controlsTested at build, release and quarterly.
Fairness metricsDisparity measured across groups.
Human oversightRequired for high and critical decisions.
InclusivityProtected attributes monitored by name.
08 / 0810% of governance maturity

Traceable

Every conclusion can be walked backwards.


From the answer on the screen to the signal on a host that started it — the record, the decision and the evidence in between are kept, so an auditor can walk the path you walked.

Walk it backwards
SignalRecordDecisionEvidence
Data lineageWhere it came from, at every hop.
Decision logsWhat was decided, by whom, when.
Audit trailAppend-only, and complete.
Evidence retentionHeld for as long as it is asked for.
The STRAI8 Trust Score

Eight pillars, weighed against live risk.

The Trust Score is the platform’s core output and its most-quoted number: a single 0–100 reading of whether your governance is ahead of your risk. It is not a rating we assign. It is arithmetic over the framework above, and the methodology is published.

+ GMGovernance Maturity

Each of the eight pillars is assessed across five maturity levels and normalised to 0–100, then aggregated on the weights the framework publishes.

Five maturity levels, per pillar
  1. Initial — ad hoc, undocumented
  2. Developing — documented, applied inconsistently
  3. Defined — documented and consistently applied
  4. Managed — measured and monitored against KPIs
  5. Optimizing — continuous improvement, with feedback
OROperational Risk

Live risk carried by the estate right now, weighted by severity and subtracted from maturity. This is the half that moves between audits.

Four risk families
TechnicalModel performance, security exposure, infrastructure
ComplianceRegulatory gaps, missing documentation, audit findings
OperationalProcess failure, weak oversight, escalation breakdown
ReputationalKnown incidents, disclosures, regulatory action
039
4059
6074
7589
90100
High AI RiskCritical deficiencies. Deployment not recommended.
Governance DevelopingSignificant gaps. Remediation before deployment.
Trusted with OversightAdequate baseline. A person stands behind every call.
Trusted EnterpriseStrong governance, a known set of gaps left.
Autonomous AI ReadyGovernance provably ahead of risk. Oversight by exception.
185questions

The governance assessment, across the eight pillars. Answers are evidenced, not asserted.

TIVTrust Instability Variance

Volatility of the score across the trailing four assessment periods. A high TIV says governance is inconsistent even when the score looks fine.

v2.0methodology

Reviewed annually by an independent panel of AI governance practitioners, versioned, and published as STRAI8-AI-002.

Our mission

Make AI trustworthy in the real world.

AI does not stay still. Models change. Data changes. Agents act in new ways. New systems appear across teams, vendors and infrastructure.

Yet governance is often treated as a point-in-time exercise — a questionnaire, an audit, a policy review, a score.

Strai8 is built to close that gap.

We help organisations understand what AI they actually have, how it is behaving, what risks are emerging, and whether the controls designed to govern it are working in practice.

So when a regulator, customer, security team or board asks “Is your AI under control?”, the answer is not assembled at the last minute.

It is already there.

Governance that stays true as AI changes.

See what your estate scores today.

Connect a read-only source and Strai8 returns your first Trust Score against the eight pillars — with the gaps named, the clauses cited and an owner on every one of them.