Each catalog entry carries the assessment your team would otherwise do by hand: data handling, model-training use, retention behavior, hosting region, and authentication posture — condensed into a risk score your analysts can defend.
Entries are re-scored as vendors ship new models, change terms, or alter data practices. The catalog is maintained as a living dataset — the point is not that it was accurate once, but that it stays accurate while the market moves weekly.
A catalog verdict is one click from becoming a control: sanction, restrict, or block flows straight into the policy engine, and the sanction state shows up in discovery views so the whole loop — find, assess, decide, enforce — lives in one place.
Vendor data handling, whether prompts are used for training, retention behavior, hosting region, authentication options, and observed usage patterns — decomposed so an auditor can see why a tool scored the way it did.
Yes — request workflows route through the catalog entry, so the reviewer starts from the assessment instead of a blank page.
Yes — internal and custom tools get catalog entries with the same scoring dimensions, so one inventory covers bought and built.
Yes — filtered exports (CSV/JSON) for GRC platforms and third-party-risk reviews.