AI Governance
AI governance built on questionnaires governs the AI people remember buying. Melurna grounds governance in observed traffic - the AI vendors actually touching sensitive data - and maps the findings to the frameworks regulators are enforcing.
Observed AI-vendor inventory
What We Bring
01
Every AI governance framework starts with an inventory - and almost nobody can produce one. Ours is generated from observed traffic: the chatbots, LLM APIs, and ML vendors actually receiving data, including the ones no one procured.
02
Which observed AI vendors claim the right to train models on the data they receive. Once your customers' data is in someone's training set, no deletion request gets it back out.
03
Your public AI and privacy disclosures, diffed against observed AI processing. Undisclosed AI use is the first thing regulators, plaintiffs, and journalists look for.
04
Where AI appears to make or shape decisions about people, and where inference crosses borders - the two surfaces emerging AI statutes regulate most aggressively.
Training rights – once data lands in a training set, no deletion gets it back
policy says
we observe
Disclosure gap – what the policy says vs what we observe
Framework Alignment
MAP and MEASURE functions demand knowing which AI systems touch data. Observed inventory is that evidence.
Deployer obligations and transparency duties hinge on knowing the AI in your stack - including the AI your vendors embedded.
Colorado-style automated-decisioning statutes regulate consequential AI decisions. We surface where those systems actually run.
Where We Come From
Melurna's roots are in original research. Our founder's DataSpii investigation - covered by The Washington Post and Ars Technica - revealed that even top cybersecurity firms were unknowingly leaking sensitive data through their browser supply chains.
That same research discipline now powers our platform and our contribution to the broader conversation: publishing findings, briefing insurers and risk executives on observed AI data flows, and pushing for governance standards grounded in evidence rather than attestation.
One scan produces the observed AI inventory your governance program is missing.