Open source · Apache 2.0 & MIT · free to use
AI governance belongs in the open.
So we gave the toolkit away. The governance platform, the assistant that helps your people use AI well, the gateway, the SDK — open source and free to use. The rules for how AI gets governed are being written right now, and they should not be decided behind a licence agreement.
Free to run
Apache 2.0 and MIT. No seat count, no expiry, no licence agreement to sign.
Yours to change
Read it, audit it, fork it. Ship your own version if ours does not fit.
No lock-in by design
If we stop being useful, the code you depend on stays where it is.
Built in Norway and the UK. Run it yourself, or let us host it. Your data stays in Europe.
- 40+ years shipping secure software
- 100+ CIOs & CISOs interviewed
- Backed by Innovation Norway & Microsoft for Startups
- Trusted by a leading Nordic insurer
The repositories
Released so far, and free to run today
Components go out one at a time, each with a post explaining it. Everything listed here is public and licensed right now — nothing on this list is a promise.
We are plain about the commercial side, because a security company saying “it is all free” invites a fair question about what it sells. The code was never the hard part. What is hard to rebuild is the policy library that comes from running this in regulated places, the evidence an auditor accepts, and someone to call at 3am. If you can run it yourself, run it yourself — we would rather that than have you pay for something you do not need.
- Apache 2.0
Atlas AI
AI governance platform: inventory, risk and policy
- Apache 2.0
AI-SPM dashboard
Map AI use cases to risks, owners and frameworks
- Apache 2.0
Promptly for the browser
Step-by-step guidance inside web apps
- Apache 2.0
Chrome and Edge extension
Catches personal data before it reaches an AI tool
- Apache 2.0
Windows assistant
In-context suggestions across Windows apps
- Apache 2.0
Developer SDK
Add the same guardrails to your own apps
- Apache 2.0
LLM gateway
One governed route to every model provider
- MIT
Agent Governance Toolkit
Policy, identity and sandboxing for AI agents
Giving back
We took more from this community than we have given back
Every product we have built stands on work other people released for free. Open-sourcing the toolkit is part of paying that back, and so is everything else on this page.
Free tools
A prompt scorer, a PII anonymiser, an AI policy generator and a readiness assessment. No account, no trial, no upsell.
Open the toolsPlaybooks and guides
Shadow-AI discovery, EU AI Act readiness, ISO 42001, NIST AI RMF, employee guardrails. Written from real engagements. An email address gets you the PDF.
Browse the libraryWhat we are learning, in public
Prompt-injection patterns we see in the wild, what auditors actually ask for, and the things we got wrong. Including the reasoning behind open-sourcing all of this.
Read the blogThe code itself
Apache 2.0 and MIT, component by component, with an announcement for each release. Issues and pull requests welcome.
See the repositoriesThe problem
A licence is not a habit
The help already exists. It lives in a training video, a policy PDF and a separate prompt library, all somewhere other than the moment someone is stuck. So people try once, get a mediocre answer, and go back to the old way.
~30%
of Copilot licence holders used it on a typical working day
UK Department for Business and Trade pilot, 1,000 licences36%
of employees with access to Copilot actually adopt it at work
Recon Analytics, 150,000+ paid AI subscribers< 9 words
in a typical prompt, against around 21 for the ones that work best
Google, Gemini for Workspace prompting guideWhat Promptly does
One set of company knowledge, four ways to help
Connect your policies and documents once. Every kind of help Promptly gives draws on the same source, so the answer in the chat, the warning at the field and the nudge in the corner never disagree with each other.
When someone has a question
Ask
A chat that answers from your company's own AI policy, approved-tool list and documents, and names the source it used.
At the exact moment it matters
Tips on the spot
A small hint right where someone is typing. Customer data about to go into an external AI tool gets flagged, with a one-click way to remove it.
Before anyone thinks to ask
Nudges
An occasional suggestion for a better way to do the task in front of them: the approved tool, or a prompt that gets a usable answer first time. Rare, and easy to dismiss.
When the answer is a place on screen
Guide
Hold a key and ask out loud. A pointer moves to the right control and explains each step, in the app you already have open.
Usage overview
Which AI tools each team uses and where people get stuck, shown in aggregate.
On the desktop, not just the browser
Runs on Mac and Windows, so it helps in native apps and developer tools as well as web pages.
Works with what you have
ChatGPT, Copilot, Claude, Gemini and the rest. No migration, no switching products. More on Promptly
How it works
Live in weeks, not a quarter
There are no walkthroughs to author screen by screen and no selectors to maintain when a vendor changes their interface. You give Promptly the knowledge, and it works out where to use it.
- 1
Connect your knowledge
Point Promptly at your AI policy, your approved-tool list and the internal documents people actually need. You choose what it may use, and for whom.
- 2
Roll it out
Install the desktop app on Mac and Windows through your device management, and the browser extension through your browser policy.
- 3
Help in the flow of work
People get answers, tips and nudges inside the tools they already use. Nobody has to open a portal or remember a training course.
- 4
See what is working
Adoption by team and by tool, in aggregate. Where people get stuck tells you what to fix next, and what to write the next tip about.
Help and oversight
Help for every employee. The whole picture for leadership.
Promptly, for your people
Educate first and block second. People get a better way to do the task and a heads-up before a mistake, instead of a wall that sends them to an unapproved tool.
Explore PromptlyAtlas AI, for the CIO and CISO
Every AI tool in use, approved or not, mapped to an owner and a risk level, with the evidence the EU AI Act asks for. The same signals Promptly sees, rolled up for the people accountable for them.
Explore Atlas AIThe gateway
AI use is outpacing AI control. The gateway is where you take it back.
Every request from every team runs through one route. That is the point at which you can see what is being spent, enforce what is allowed, and send each task to a model that is good enough for it.
Model vendors are paid by the token, so nobody selling you one has a reason to send your work somewhere cheaper. Putting a gateway in front of them makes that your decision instead.

Connects to what you already run
Your SIEM, GRC and ITSM tools plug in as connectors, and anything else goes through the SDK. Nothing has to be replaced for the gateway to see the traffic.

Usage and cost in one place
Spend by vendor, by model and by team, measured against what was estimated, so an unexpected invoice becomes a line you can point at rather than a surprise.

Routing that takes the cheap wins
Most traffic is classification and extraction that a smaller model handles for a fraction of the price. Atlas finds that work, prices the swap, and shows what the change is worth before you make it.

Policy enforced where AI is used
Start in guideline mode and watch what would have been blocked. Promote a rule to strict once you trust the false-positive rate, not before.

Sensitive data stopped before it leaves
Prompts are inspected on the way out. Personal data is redacted and injection attempts are blocked, with every hit counted so you can see which rule is actually doing the work.

Evidence that any of it worked
Usage on its own proves nothing. Atlas weights it by whether the output survived, so the number you take to the board is what landed, not what was generated.
Screens are from Atlas AI, shown with the seeded demo dataset used in our walkthroughs.
Why us
We've done this before. We have the receipts.
We've been shipping secure software for 40+ years. We've talked to over 100 CIOs and CISOs in the last year, and a leading Nordic insurer already runs on us — its CISO now owns AI risk with Atlas AI. It's the tool they kept asking for, ready before the EU's 2026 deadline.
GDPR
Already compliant · Certification in progress
SOC 2 Type II
Certification in progress
ISO 42001
Certification in progress
ISO 27001
Certification in progress
DORA
Aligned for regulated finance
NIS2
Certification in progress
Partners & backers
Partner of Microsoft for Startups and member of Tek Norge. Backed by Antler, Innovation Norway, StartupLab, Microsoft, and Tek Norge.
- Partner: Microsoft for Startups
- Member: Tek Norge
- Backer: Antler
- Backer: Innovation Norway
- Backer: StartupLab

What you get from a 4-week pilot
All AI use cases discovered — including the shadow AI no other vendor sees
Owners identified per use case, with explicit accountability
Risks classified across nine categories and the EU AI Act risk tier
Concrete remediation actions suggested and initiated, not just flagged
Automated four-framework coverage report (EU AI Act, NIST AI RMF, ISO 42001, OWASP LLM Top 10)
Continuous discovery keeps the view fresh — not a quarterly snapshot
The AI Audit Playbook
How regulated enterprises get an EU AI Act–ready governance programme running in weeks instead of quarters. You get the 7-domain framework, the 6-phase plan, and a clear picture of what board-grade assurance actually takes.
- Framework mapped to NIST AI RMF, EU AI Act, ISO 42001, OWASP LLM Top 10
- Engagement tiers with indicative pricing
- What a board-ready remediation roadmap looks like
AI governance, distilled
One short email a month: what changed in the EU AI Act, the prompt-injection patterns we're seeing in the wild, and one practical control you can ship this week.
No spam. Unsubscribe any time. Protected by reCAPTCHA.
What brings you here today?
Choose your path to get personalised recommendations
Turn AI licences into AI habits
Book a 30-minute call. We'll show you Promptly running on real tools, talk through what a pilot with one team looks like, and help you answer the question your board keeps asking: is anyone actually using the AI we paid for?
Help inside the AI tools your people already use, answered from your own policies
Risky pastes caught before they are sent, with the approved tool one click away
Adoption by team and tool, so you can show what the AI budget is buying