AI Governance

Governance for the AI you didn't know you had.

AI governance built on questionnaires governs the AI people remember buying. Melurna grounds governance in observed traffic - the AI vendors actually touching sensitive data - and maps the findings to the frameworks regulators are enforcing.

Observed AI-vendor inventory

What We Bring

Evidence-first AI governance.

01

Observed AI inventory

Every AI governance framework starts with an inventory - and almost nobody can produce one. Ours is generated from observed traffic: the chatbots, LLM APIs, and ML vendors actually receiving data, including the ones no one procured.

02

Training-rights exposure

Which observed AI vendors claim the right to train models on the data they receive. Once your customers' data is in someone's training set, no deletion request gets it back out.

03

Disclosure-gap analysis

Your public AI and privacy disclosures, diffed against observed AI processing. Undisclosed AI use is the first thing regulators, plaintiffs, and journalists look for.

04

Decisioning & sovereignty surfaces

Where AI appears to make or shape decisions about people, and where inference crosses borders - the two surfaces emerging AI statutes regulate most aggressively.

Training rights – once data lands in a training set, no deletion gets it back

policy says

we observe

no AI vendors
no AI vendors
no model training
training rights
US data only
cross-border
aggregate only
aggregate only

Disclosure gap – what the policy says vs what we observe

Framework Alignment

Mapped to the rules that are arriving.

NIST AI RMF

MAP and MEASURE functions demand knowing which AI systems touch data. Observed inventory is that evidence.

EU AI Act

Deployer obligations and transparency duties hinge on knowing the AI in your stack - including the AI your vendors embedded.

State AI laws

Colorado-style automated-decisioning statutes regulate consequential AI decisions. We surface where those systems actually run.

Where We Come From

We've been documenting invisible data flows since before it was a market.

Melurna's roots are in original research. Our founder's DataSpii investigation - covered by The Washington Post and Ars Technica - revealed that even top cybersecurity firms were unknowingly leaking sensitive data through their browser supply chains.

That same research discipline now powers our platform and our contribution to the broader conversation: publishing findings, briefing insurers and risk executives on observed AI data flows, and pushing for governance standards grounded in evidence rather than attestation.

Start your AI inventory with the truth.

One scan produces the observed AI inventory your governance program is missing.