Known limitations
What the platform does not do yet, in plain language, so you can plan around it.
AI gap analysis is advisory
AI gap analysis, AI reviews, and other AI output are suggestions. A person must review them before they are relied on. Accuracy is lower when evidence is ambiguous, incomplete, or only loosely related to a control. AI output is never an audit opinion — only a human auditor's sign-off attests.
Three separate AI copilots
There are three copilots: the main copilot, a VAPT copilot on each finding, and a security-monitoring copilot on each incident. They do not share a conversation or memory — they are not one unified assistant.
Copilots answer questions; they do not take actions
Copilots explain, summarise, and point you to the right page. They do not change controls, approve evidence, close findings, or run scans on your behalf.
Evidence collection uses a fixed catalogue of collectors
Automatic evidence collection covers a fixed set of collectors. When a requirement does not match one of them, it falls back to manual upload.
Access reviews need a user list from you
Access reviews work from user lists you enter or bulk-upload. There is no automatic sync with your identity provider yet.
VAPT uses deterministic scanners with advisory AI
Vulnerability scans are run by established, deterministic scanners. AI helps explain findings and suggest likely false positives, which you confirm. There is no AI-driven exploitation.
Security monitoring is not a managed SOC
Security monitoring collects alerts and incidents as compliance evidence and offers AI-suggested triage. It is not a managed 24/7 Security Operations Centre — nobody watches your alerts around the clock for you.
The Employee Portal is a lighter view
The Employee Portal is a simplified view for policy acknowledgement and training. It may be folded into the main portal in a future release.