Know every AI tool your team is using, who’s responsible for it, and have evidence ready when you need it.
AI use that no one can see, owns, or is responsible for puts your business at risk. Certrak eliminates the blind spots so you can innovate safely.
Quickly and cleanly map your AI usage. Ensure it’s visible and documented.
Pick the tool you use, Copilot, ChatGPT, Cursor, and 30-plus more, and the risks, controls, and policies are already mapped. No more wondering about your AI risk or what to do about it.
| AI System | Risk level | Owner | Status |
|---|---|---|---|
Customer Support Chatbot AIS-001 |
High | Sarah Mitchell | Active |
CV Screening Assistant AIS-002 |
High | Tom Jenkins | Active |
Invoice Processing AIS-003 |
Medium | Maria Rodriguez | Active |
Marketing Content Generator AIS-005 |
Not set | Paul Harrison | Draft |
Accountability stops being a question mark. See, at a glance, who stands behind each AI use in your business. An essential step towards responsible AI use.
A tamper-evident record a client or your board can verify themselves, checksum included, and that can’t be quietly changed, even by you.
When something does go wrong, the fix becomes part of the record too. Not just a tidy snapshot, evidence you had a handle on it.
AI doesn’t hold still. Forward a vendor’s release-notes email and Certrak turns it into a review task for every system using that model. The picture stays current instead of going stale.
Certrak helps you build a culture of collaboration and responsible AI. Give everyone on your team a way to contribute, while gaining the intelligence you need to make informed decisions.
Certrak’s AI governance libraries are human-reviewed and built from the most common AI use cases, with controls written to the best practices of leading governance frameworks.
Confident, plausible, unrepeatable. And no one stands behind it.
For a given tool and use, the same defensible governance, from a library built and reviewed by people.
And when a use case is genuinely new, Certrak drafts a starting point, clearly flagged for you to approve.
Never feel overwhelmed. Certrak gives you a manageable short list of prioritised tasks that surface only when they matter.
To keep things on track, we learn from your rate of task completion and adjust your task list to match.
What being accountable for AI actually involves.
Read →Shadow AI is most likely already in your organisation. Here's what you can do about it.
Read →The deadline for compliance with the EU AI Act is fast approaching. Now is the time for Australian businesses to get prepared.
Read →AI didn’t arrive in most businesses through a decision, it crept in through the tools people already use. Using AI carries risk, and most governance is still playing catch up.
Certrak is an AI governance tool for small and mid-sized businesses which makes AI use visible, gives each use a named owner, and turns it into a verifiable record you can hand to a client or regulator.
Don’t get caught scrambling after a near-miss or when a customer suddenly asks how you manage AI. Build a culture of safe AI deployment and governance instead.
Certrak has been building compliance software in Australia since 2017.
Here’s how Certrak handles your data and where AI fits in.
We use Claude (via Anthropic) for one narrow job: reading the free text you type so it maps to the right governance. For new use cases it can draft a starting point, always flagged for you to approve. The tool picker, imports, registers, and evidence paths use no AI at all.
Anthropic doesn’t train its models on data sent through its commercial API, and Certrak never uses your governance data to train AI and we never sell your data to anyone.
Your account is hosted in Australia. When you generate a plan, some governance content, the free text you enter plus system and control names and descriptions, is sent to Anthropic in the United States to be summarised and sequenced. Anthropic does not use commercial API data to train its models. Everything else stays in Australia. Export your whole account or delete it any time.
No. Your risks and controls come from a fixed library we built and maintain by hand, so the same use always gives you the same governance. AI only reads your description to match you to the right items, it never invents your governance. When something is genuinely new, Certrak drafts a starting point and flags it for your approval.
Yes, it’s built for exactly that. Describe what you’re doing in your own words. Certrak maps the risks and controls, suggests owners, and gives you a short list of things to do. No frameworks to read, no jargon to decode.
No tool can guarantee that. Certrak gives you documented, defensible governance: what you run, the risks you’ve considered, the controls in place, and who’s accountable. It’s built on the common themes of recognised frameworks and regulator guidance.
Governance attaches to what the AI does, not your industry. Computer vision in a vet clinic and computer vision on a factory line get the same proven data-analysis governance, and Certrak shows you which pattern it matched and why. If nothing matches, it drafts suggestions for you to review.
Certrak isn’t built around one standard. AI regulation currently is a complex and evolving field. We take what widely recognised AI governance frameworks and regulators agree on, the controls that come up again and again, and turn them into one practical list you work through. Your governance then lines up with what people expect, without you having to choose or read any framework yourself. While mapping AI governance to specific frameworks is on our roadmap to help our users meet legislative and certification requirements, we are currently focussed on the principles of good governance that apply across all frameworks.
Almost certainly, yes. 88% of organisations now use AI in at least one business function (McKinsey, The State of AI). Someone in your business is already responsible for that, named or not. Certrak makes the ownership explicit before something goes wrong, not after, and gives you the tools and direction to safely manage your AI use.
That depends on the size of your team and how much AI you use, but you can get started in minutes. Pick a tool you use and Certrak loads a pre-built governance stack instantly, or describe a use case in a sentence and it builds one. From there you work through a short, prioritised list at your own pace.
No. You can run it solo. When you want to share the load, assign owners, let your team flag the AI they’re using, and delegate tasks, all against one shared, current picture.
They already do: 41% of workers deliver AI-generated work they can’t explain, and 53% of AI users worry that relying on it makes them look replaceable (Work AI Institute 2026; Microsoft Work Trend Index). Bans and monitoring make the hiding worse. Certrak takes the opposite approach: nothing is scanned or watched, and your team gets a simple, safe way to flag the tools they actually use.
A dated snapshot of your governance: what you had in place, and when. It’s sealed with a digital fingerprint, so any later change shows up. Share it by link and a client, board member or regulator can check that fingerprint in their own browser, nothing gets uploaded. Links stay live for as long as you set, up to 90 days.
The pace is real: active AI agents in the Microsoft 365 ecosystem grew fifteen-fold in the past year (Microsoft Work Trend Index, 2026). Forward a vendor’s release-notes email to your Certrak address and it becomes an owned review task against every system using that model. Controls falling due, expiring evidence and stale systems are detected automatically, so your governance stays current instead of going stale.
No. Anthropic doesn’t train its models on data sent through its commercial API, and Certrak never uses your governance data to train AI or sells it to anyone.
In Australia. You can export your entire account or delete it whenever you choose. The one thing that leaves is what goes to the AI step: the free text you enter, plus system and control names and descriptions, sent to Anthropic in the United States. Anthropic does not use commercial API data to train its models.
No. AI does one job: reading the free text you type so Certrak can map it to the right governance, and occasionally drafting suggestions you approve. The decisions come from fixed rules you can see and trace, not a black box.
You asked yourself where your AI risk was. Now you can answer it, and have the record to prove it.
We’re hand-picking our first customers, talk to us and we’ll set you up ourselves.
Tell us a little about you and we’ll be in touch to see if it’s a fit.