Open source · Apache 2.0 & MIT · free to use

AI governance belongs in the open.

So we gave the toolkit away. The governance platform, the assistant that helps your people use AI well, the gateway, the SDK — open source and free to use. The rules for how AI gets governed are being written right now, and they should not be decided behind a licence agreement.

  • Free to run

    Apache 2.0 and MIT. No seat count, no expiry, no licence agreement to sign.

  • Yours to change

    Read it, audit it, fork it. Ship your own version if ours does not fit.

  • No lock-in by design

    If we stop being useful, the code you depend on stays where it is.

Built in Norway and the UK. Run it yourself, or let us host it. Your data stays in Europe.

  • 40+ years shipping secure software
  • 100+ CIOs & CISOs interviewed
  • Backed by Innovation Norway & Microsoft for Startups
  • Trusted by a leading Nordic insurer

The repositories

Released so far, and free to run today

Components go out one at a time, each with a post explaining it. Everything listed here is public and licensed right now — nothing on this list is a promise.

We are plain about the commercial side, because a security company saying “it is all free” invites a fair question about what it sells. The code was never the hard part. What is hard to rebuild is the policy library that comes from running this in regulated places, the evidence an auditor accepts, and someone to call at 3am. If you can run it yourself, run it yourself — we would rather that than have you pay for something you do not need.

Giving back

We took more from this community than we have given back

Every product we have built stands on work other people released for free. Open-sourcing the toolkit is part of paying that back, and so is everything else on this page.

Free tools

A prompt scorer, a PII anonymiser, an AI policy generator and a readiness assessment. No account, no trial, no upsell.

Open the tools

Playbooks and guides

Shadow-AI discovery, EU AI Act readiness, ISO 42001, NIST AI RMF, employee guardrails. Written from real engagements. An email address gets you the PDF.

Browse the library

What we are learning, in public

Prompt-injection patterns we see in the wild, what auditors actually ask for, and the things we got wrong. Including the reasoning behind open-sourcing all of this.

Read the blog

The code itself

Apache 2.0 and MIT, component by component, with an announcement for each release. Issues and pull requests welcome.

See the repositories

The problem

A licence is not a habit

The help already exists. It lives in a training video, a policy PDF and a separate prompt library, all somewhere other than the moment someone is stuck. So people try once, get a mediocre answer, and go back to the old way.

~30%

of Copilot licence holders used it on a typical working day

UK Department for Business and Trade pilot, 1,000 licences

36%

of employees with access to Copilot actually adopt it at work

Recon Analytics, 150,000+ paid AI subscribers

< 9 words

in a typical prompt, against around 21 for the ones that work best

Google, Gemini for Workspace prompting guide

What Promptly does

One set of company knowledge, four ways to help

Connect your policies and documents once. Every kind of help Promptly gives draws on the same source, so the answer in the chat, the warning at the field and the nudge in the corner never disagree with each other.

When someone has a question

Ask

A chat that answers from your company's own AI policy, approved-tool list and documents, and names the source it used.

At the exact moment it matters

Tips on the spot

A small hint right where someone is typing. Customer data about to go into an external AI tool gets flagged, with a one-click way to remove it.

Before anyone thinks to ask

Nudges

An occasional suggestion for a better way to do the task in front of them: the approved tool, or a prompt that gets a usable answer first time. Rare, and easy to dismiss.

Early access

When the answer is a place on screen

Guide

Hold a key and ask out loud. A pointer moves to the right control and explains each step, in the app you already have open.

Usage overview

Which AI tools each team uses and where people get stuck, shown in aggregate.

On the desktop, not just the browser

Runs on Mac and Windows, so it helps in native apps and developer tools as well as web pages.

Works with what you have

ChatGPT, Copilot, Claude, Gemini and the rest. No migration, no switching products. More on Promptly

How it works

Live in weeks, not a quarter

There are no walkthroughs to author screen by screen and no selectors to maintain when a vendor changes their interface. You give Promptly the knowledge, and it works out where to use it.

  1. 1

    Connect your knowledge

    Point Promptly at your AI policy, your approved-tool list and the internal documents people actually need. You choose what it may use, and for whom.

  2. 2

    Roll it out

    Install the desktop app on Mac and Windows through your device management, and the browser extension through your browser policy.

  3. 3

    Help in the flow of work

    People get answers, tips and nudges inside the tools they already use. Nobody has to open a portal or remember a training course.

  4. 4

    See what is working

    Adoption by team and by tool, in aggregate. Where people get stuck tells you what to fix next, and what to write the next tip about.

Help and oversight

Help for every employee. The whole picture for leadership.

Promptly, for your people

Educate first and block second. People get a better way to do the task and a heads-up before a mistake, instead of a wall that sends them to an unapproved tool.

Explore Promptly

Atlas AI, for the CIO and CISO

Every AI tool in use, approved or not, mapped to an owner and a risk level, with the evidence the EU AI Act asks for. The same signals Promptly sees, rolled up for the people accountable for them.

Explore Atlas AI

The gateway

AI use is outpacing AI control. The gateway is where you take it back.

Every request from every team runs through one route. That is the point at which you can see what is being spent, enforce what is allowed, and send each task to a model that is good enough for it.

Model vendors are paid by the token, so nobody selling you one has a reason to send your work somewhere cheaper. Putting a gateway in front of them makes that your decision instead.

Atlas AI integrations page showing connectors for Microsoft Sentinel, Defender XDR, Splunk, Google SecOps, Ardoq, ServiceNow, Purview and Slack

Connects to what you already run

Your SIEM, GRC and ITSM tools plug in as connectors, and anything else goes through the SDK. Nothing has to be replaced for the gateway to see the traffic.

Atlas AI spend dashboard showing total spend, actual versus estimated cost and savings recommendations

Usage and cost in one place

Spend by vendor, by model and by team, measured against what was estimated, so an unexpected invoice becomes a line you can point at rather than a surprise.

Atlas AI savings recommendations, including routing low-complexity tasks to a cheaper model and right-sizing a token commitment

Routing that takes the cheap wins

Most traffic is classification and extraction that a smaller model handles for a fraction of the price. Atlas finds that work, prices the swap, and shows what the change is worth before you make it.

Atlas AI policy enforcement dashboard showing strict and loose policy counts, coverage, blocks over 30 days and a violations chart

Policy enforced where AI is used

Start in guideline mode and watch what would have been blocked. Promote a rule to strict once you trust the false-positive rate, not before.

Atlas AI top policies by hits, showing enforcing rules that block prompt-injection attempts and redact personal data in AI prompts

Sensitive data stopped before it leaves

Prompts are inspected on the way out. Personal data is redacted and injection attempts are blocked, with every hit counted so you can see which rule is actually doing the work.

Atlas AI adoption and ROI view, showing quality-weighted measurement of how well AI is used

Evidence that any of it worked

Usage on its own proves nothing. Atlas weights it by whether the output survived, so the number you take to the board is what landed, not what was generated.

Screens are from Atlas AI, shown with the seeded demo dataset used in our walkthroughs.

Why us

We've done this before. We have the receipts.

We've been shipping secure software for 40+ years. We've talked to over 100 CIOs and CISOs in the last year, and a leading Nordic insurer already runs on us — its CISO now owns AI risk with Atlas AI. It's the tool they kept asking for, ready before the EU's 2026 deadline.

GDPR

Already compliant · Certification in progress

SOC 2 Type II

Certification in progress

ISO 42001

Certification in progress

ISO 27001

Certification in progress

DORA

Aligned for regulated finance

NIS2

Certification in progress

Partners & backers

Partner of Microsoft for Startups and member of Tek Norge. Backed by Antler, Innovation Norway, StartupLab, Microsoft, and Tek Norge.

  • Partner: Microsoft for StartupsMicrosoft for Startups — Partner
  • Member: Tek NorgeTek Norge — Member
  • Backer: AntlerAntler — Backer
  • Backer: Innovation NorwayInnovation Norway — Backer
  • Backer: StartupLabStartupLab — Backer

What you get from a 4-week pilot

All AI use cases discovered — including the shadow AI no other vendor sees

Owners identified per use case, with explicit accountability

Risks classified across nine categories and the EU AI Act risk tier

Concrete remediation actions suggested and initiated, not just flagged

Automated four-framework coverage report (EU AI Act, NIST AI RMF, ISO 42001, OWASP LLM Top 10)

Continuous discovery keeps the view fresh — not a quarterly snapshot

Free executive briefing

The AI Audit Playbook

How regulated enterprises get an EU AI Act–ready governance programme running in weeks instead of quarters. You get the 7-domain framework, the 6-phase plan, and a clear picture of what board-grade assurance actually takes.

  • Framework mapped to NIST AI RMF, EU AI Act, ISO 42001, OWASP LLM Top 10
  • Engagement tiers with indicative pricing
  • What a board-ready remediation roadmap looks like

Protected by reCAPTCHA.

We don't share your email. No spam, ever.

Monthly briefing

AI governance, distilled

One short email a month: what changed in the EU AI Act, the prompt-injection patterns we're seeing in the wild, and one practical control you can ship this week.

No spam. Unsubscribe any time. Protected by reCAPTCHA.

What brings you here today?

Choose your path to get personalised recommendations

Turn AI licences into AI habits

Book a 30-minute call. We'll show you Promptly running on real tools, talk through what a pilot with one team looks like, and help you answer the question your board keeps asking: is anyone actually using the AI we paid for?

Help inside the AI tools your people already use, answered from your own policies

Risky pastes caught before they are sent, with the approved tool one click away

Adoption by team and tool, so you can show what the AI budget is buying