BISTEC Global · built on the Nexus AI Accelerator

Governance, risk and compliance with a workforce.

Agents do the collection, the mapping, the testing and the drafting. Humans do the judgement. Every action carries its source, its confidence, its cost and the name of the person who signed it.

No login. Everything is fictional demo data. Press ⌘K to search anything, ⌘. for the Demo Director.

6surfaces, not seventeen flat modules
8named agents, each with a human gate
14frameworks in the fabric
1control satisfying up to six regimes
The idea

Everyone else added AI to a GRC platform. We added GRC to an agent platform.

That is not a positioning line. It changes what the product can do, because the hard half — the runtime, the evaluation pipeline, the governance engine — already exists and already runs in production.

The usual route

Build a GRC platform. Years later, bolt on an assistant that summarises, suggests and drafts. It helps a person work faster. It never does the work, and it cannot be governed as a worker because it was never designed as one.

Ours

Start with an agent platform already running nineteen agents across six industries, with a design DSL, an MCP Gateway runtime, seventy-three compliance checkpoints and an eight-domain governance audit. Point it at governance and risk. The agents are the labour, and governing them is a first-class module.

Platform

Six surfaces with real depth

Enterprise GRC tools typically ship a flat menu of fifteen to twenty modules. Depth belongs inside a surface, not in the sidebar.

Command Centre

The position in dollars, what moved it, and the queue of things that genuinely need a person today — ordered by consequence, not by date. Board pack composed the moment you open it.

Risk

The hero object. Register, 5×5 matrix, appetite and tolerance, key risk indicators, quantification, taxonomy and treatments. Expected annual loss from real distributions, with every assumption inspectable.

Assurance

Controls, continuous monitoring, question-based and requirement-based assessments, audits, one unified remediation backlog, and an evidence vault where reuse count is the number that matters.

Compliance

The crosswalk: one control satisfying many regimes, computed rather than curated, with confidence, rationale and a human decision on every mapping. Plus obligations, gaps, policies, regulatory horizon and AI governance.

Resilience

Critical operations and impact tolerance shaped for APRA CPS 230, third-party lifecycle and tiering, concentration and fourth-party exposure, incidents with the regulatory clock on screen, and continuity testing.

Intelligence

The agent fleet, a full run ledger, the human approval queue, and governance of the agents themselves. Plus Engagements — the advisory portfolio with its own delivery economics and cross-client benchmarks.

The workforce

Eight specialists, not one assistant

Narrow tool scope is not a limitation — it is the control. You cannot write a meaningful policy about a general assistant with broad access. You can about eight agents with four tools each.

AgentJobHuman gate
MapperCrosswalk & coverage. Maps controls to obligations across every adopted framework, with a confidence score, a rationale, and the specific objectives a partial match leaves unmet.Every mapping accepted or rejected by a person
ProverEvidence collection. Collects and refreshes evidence from connected systems, hashes and timestamps each artefact, attaches it to the controls it supports.Auto below policy threshold; classified sources gated
ScoutRegulatory horizon. Watches regulator publications and traces each change through the obligation graph to the controls it touches.Reviewed before it reaches the register
QuantQuantification. Fits frequency and severity distributions, producing expected annual loss, a loss-exceedance curve and treatment return.Assumptions reviewed before publication
ScribeDrafting. Policies, treatment plans, assessment responses, regulator notifications and board narrative — always citing the records drawn from.Always human-approved
WatchContinuous control monitoring. Compares observed control state against its baseline, opens an issue on drift, escalates on tolerance breach.Escalation is gated
AuditorAudit support. Reproducible sample selection, workpapers drafted from attached evidence, findings written up for the lead.Every workpaper and finding approved
TriageIntake routing. Routes inbound assessments and vendor intake, pre-fills known answers, flags anything outside policy.Auto within policy; exceptions queue

Every run is recorded with its trigger, tool calls, reasoning steps, tokens, cost, duration, the policy checks it had to pass and the human decision on its output — replayable. Anything simulated in the demo is labelled Simulated in the interface. The production runtime is the BISTEC MCP Gateway.

Why us

Five things an incumbent cannot cheaply answer

  • Agents that execute, on a governed ledger. Not a chat assistant beside the work — a fleet doing the work, with a replayable trace and a named approver on every output.
  • Govern the agents you deployed, in the same tool. The AI governance module inventories the agents running the platform itself, against ISO 42001 and the NIST AI RMF, with real evaluation scores.
  • Money as the default lens. Expected annual loss and a loss-exceedance curve from real distributions. The heat map is still there — as a view, not as the truth.
  • Advisor economics, visible. Margin, utilisation, agent-hours against human-hours, library reuse and time-to-value per client. No other GRC platform shows the advisor's own P&L.
  • Provenance on every assertion. Source, confidence, rationale, timestamp and decision record — on mapped controls, drafted policies, collected evidence and quantified risk alike.
  • And what we don't claim. This is a demo, not a production tenancy. There's no backend, no auth, and the agent runs are simulated — each one says so when you open it.

“A CRO's most expensive question is is this normal? — and no single-tenant platform can answer it, because it holds exactly one data point.”

Drive it yourself

It isn't a scripted click-path

Press ⌘. anywhere in the demo. Persona, client, scenario, programme maturity and AI autonomy are all live switches on one build — so any “what if” is something to show rather than describe.

Incident in progress

A severity-1 nine hours in, with the APRA CPS 234 seventy-two-hour clock running on screen. Watch raised it, Prover collected the evidence, Scribe drafted the notification, the CRO approved it.

New client, day one

Nothing built. Empty registers with honest empty states and the single action that starts the work — because every real engagement starts here, and every other demo pretends otherwise.

Turn the AI off

Set autonomy to off and walk any screen. Everything still works; the agents just stop. This is a GRC platform that happens to have a workforce, not an AI wrapper.

When an agent misbehaves

An agent breaches its declared tool scope. The policy engine blocks the write, rolls it back and quarantines the run before a record is touched — and you see it in the governance module.

Six guided tours

Ninety-second executive, full platform, agentic deep dive, advisor economics, the compliance crosswalk, and incident response under a clock. The app stays clickable throughout.

Any persona

Board director, CRO, risk analyst, compliance lead, internal audit, AI governance officer, advisory principal or client user — each with its own landing surface and a live permission preview.

Next

Two to four weeks to a defensible register

Taxonomy workshop, adopt the frameworks in scope, connect two source systems, and Mapper proposes the first crosswalk for review. Median across the current book is nineteen days; fastest was nine.