AI oversight for businesses without a compliance team.

Know every AI tool your team is using, who’s responsible for it, and have evidence ready when you need it.

Where’s your AI risk?
A few easy steps. No sign-up.
Question 1 of 40%

Every AI use, visible and under control.

AI use that no one can see, owns, or is responsible for puts your business at risk. Certrak eliminates the blind spots so you can innovate safely.

Without Certrak
some chatbot? a plugin marketing’s tool that note-taker ???
Invisible·Unowned·Unaccounted
With Certrak
ChatGPT · Client commsMara L.✓ Governed
Copilot · DraftingSam P.✓ Governed
Gemini · ResearchYou✓ Governed
Visible·Owned·Accounted for
More than a third of workers use AI tools nobody approved. 69% of AI users admit to shipping AI work they can’t fully stand behind.
Work AI Institute, 6,000 workers surveyed across Australia, the US and the UK, 2026

Find it. Own it. Prove it. Keep it true.

01Find it

Bring every AI use into the open.

Quickly and cleanly map your AI usage. Ensure it’s visible and documented.

Pick the tool you use, Copilot, ChatGPT, Cursor, and 30-plus more, and the risks, controls, and policies are already mapped. No more wondering about your AI risk or what to do about it.

AI Systems + New AI System
AI System Risk level Owner Status
Customer Support Chatbot
AIS-001
High Sarah Mitchell Active
CV Screening Assistant
AIS-002
High Tom Jenkins Active
Invoice Processing
AIS-003
Medium Maria Rodriguez Active
Marketing Content Generator
AIS-005
Not set Paul Harrison Draft
Customer Support Chatbot
Owners
SM
Sarah Mitchell
Primary owner
TJ
Tom Jenkins
Secondary owner
+
Add an owner
02Own it

Every use gets a named owner.

Accountability stops being a question mark. See, at a glance, who stands behind each AI use in your business. An essential step towards responsible AI use.

03Prove it

One record anyone can verify.

A tamper-evident record a client or your board can verify themselves, checksum included, and that can’t be quietly changed, even by you.

When something does go wrong, the fix becomes part of the record too. Not just a tidy snapshot, evidence you had a handle on it.

CCertrak Generated 25 Jul 2026, 14:30
Proof of Governance Report
Acme Corp · Report #12
Integrity checksum (SHA-256) · Verified, snapshot intact
9f2b41c8e7d3a6b05f1c94e2d8a730bc4e6f19a2c58d0b3e7f4a1c9d26e8b5073
This report is a frozen snapshot. If any figure changed, this fingerprint would change too.
Today
3 tasks to clear today.
5-day streak
Review what changed: Customer Support Chatbot
NewOversightSarah Mitchell
Renew the evidence for Model Risk Assessment Q3
Control EffectivenessMaria Rodriguez
Review the Output sample review control
Ongoing OversightTom Jenkins· open 20 days
04Keep it true

Governance that stays current.

AI doesn’t hold still. Forward a vendor’s release-notes email and Certrak turns it into a review task for every system using that model. The picture stays current instead of going stale.

Build a culture of responsible AI.

Certrak helps you build a culture of collaboration and responsible AI. Give everyone on your team a way to contribute, while gaining the intelligence you need to make informed decisions.

Delegate responsibility. Keep the oversight.
Assign ownership to the right people and keep one living source of truth. Every governance decision is recorded in an append-only audit trail.
SMSarah owns Customer Support Chatbot
Reviews the control and assigns the work
Recorded, can’t be edited
A private channel for the people affected.
Your team can tell you, privately, how AI is affecting their work, anonymously or in confidence. It becomes part of your Proof.
Anonymous: this tool tracks my every call
You read it and respond
Kept in your Proof
Keep the actual people who use the tools in the loop.
Add the people closest to the output as observers. They get a heads-up on new AI and can flag anything that looks off. No logins, no extra seats.
New AI system: Invoice Processing
Tom replies: this looks off
Flagged for the owner
Surface the AI you don’t know about.
Team members report the AI they’re using in plain words. It lands as a pending item to accept or dismiss. Nothing is scanned or monitored.
James reports he uses Otter.ai
Lands as pending in your register
Accept or dismiss, never scanned

A curated library, not clever prompts.

Certrak’s AI governance libraries are human-reviewed and built from the most common AI use cases, with controls written to the best practices of leading governance frameworks.

Ask an LLM
A different answer every time.

Confident, plausible, unrepeatable. And no one stands behind it.

Certrak
The same record you can prove.

For a given tool and use, the same defensible governance, from a library built and reviewed by people.

AI-assisted

And when a use case is genuinely new, Certrak drafts a starting point, clearly flagged for you to approve.

Governance that actually gets done.

Never feel overwhelmed. Certrak gives you a manageable short list of prioritised tasks that surface only when they matter.

To keep things on track, we learn from your rate of task completion and adjust your task list to match.

5
AI systems governed
3
Fully governed
14
Controls in place
7
Active risks

AI showed up in every business. Governance needs to catch up.

AI didn’t arrive in most businesses through a decision, it crept in through the tools people already use. Using AI carries risk, and most governance is still playing catch up.

Certrak was built to solve that problem.

Certrak is an AI governance tool for small and mid-sized businesses which makes AI use visible, gives each use a named owner, and turns it into a verifiable record you can hand to a client or regulator.

Don’t get caught scrambling after a near-miss or when a customer suddenly asks how you manage AI. Build a culture of safe AI deployment and governance instead.

Certrak has been building compliance software in Australia since 2017.

Your governance data is yours. We treat it that way.

Here’s how Certrak handles your data and where AI fits in.

How we use AI.

We use Claude (via Anthropic) for one narrow job: reading the free text you type so it maps to the right governance. For new use cases it can draft a starting point, always flagged for you to approve. The tool picker, imports, registers, and evidence paths use no AI at all.

Your data isn’t used to train AI models.

Anthropic doesn’t train its models on data sent through its commercial API, and Certrak never uses your governance data to train AI and we never sell your data to anyone.

AU
Stored in Australia. Yours to export or delete.

Your account is hosted in Australia. When you generate a plan, some governance content, the free text you enter plus system and control names and descriptions, is sent to Anthropic in the United States to be summarised and sequenced. Anthropic does not use commercial API data to train its models. Everything else stays in Australia. Export your whole account or delete it any time.

Common questions.

Is it legit?

No. Your risks and controls come from a fixed library we built and maintain by hand, so the same use always gives you the same governance. AI only reads your description to match you to the right items, it never invents your governance. When something is genuinely new, Certrak drafts a starting point and flags it for your approval.

Yes, it’s built for exactly that. Describe what you’re doing in your own words. Certrak maps the risks and controls, suggests owners, and gives you a short list of things to do. No frameworks to read, no jargon to decode.

No tool can guarantee that. Certrak gives you documented, defensible governance: what you run, the risks you’ve considered, the controls in place, and who’s accountable. It’s built on the common themes of recognised frameworks and regulator guidance.

Governance attaches to what the AI does, not your industry. Computer vision in a vet clinic and computer vision on a factory line get the same proven data-analysis governance, and Certrak shows you which pattern it matched and why. If nothing matches, it drafts suggestions for you to review.

Certrak isn’t built around one standard. AI regulation currently is a complex and evolving field. We take what widely recognised AI governance frameworks and regulators agree on, the controls that come up again and again, and turn them into one practical list you work through. Your governance then lines up with what people expect, without you having to choose or read any framework yourself. While mapping AI governance to specific frameworks is on our roadmap to help our users meet legislative and certification requirements, we are currently focussed on the principles of good governance that apply across all frameworks.

Will it actually help me?

Almost certainly, yes. 88% of organisations now use AI in at least one business function (McKinsey, The State of AI). Someone in your business is already responsible for that, named or not. Certrak makes the ownership explicit before something goes wrong, not after, and gives you the tools and direction to safely manage your AI use.

That depends on the size of your team and how much AI you use, but you can get started in minutes. Pick a tool you use and Certrak loads a pre-built governance stack instantly, or describe a use case in a sentence and it builds one. From there you work through a short, prioritised list at your own pace.

No. You can run it solo. When you want to share the load, assign owners, let your team flag the AI they’re using, and delegate tasks, all against one shared, current picture.

They already do: 41% of workers deliver AI-generated work they can’t explain, and 53% of AI users worry that relying on it makes them look replaceable (Work AI Institute 2026; Microsoft Work Trend Index). Bans and monitoring make the hiding worse. Certrak takes the opposite approach: nothing is scanned or watched, and your team gets a simple, safe way to flag the tools they actually use.

A dated snapshot of your governance: what you had in place, and when. It’s sealed with a digital fingerprint, so any later change shows up. Share it by link and a client, board member or regulator can check that fingerprint in their own browser, nothing gets uploaded. Links stay live for as long as you set, up to 90 days.

The pace is real: active AI agents in the Microsoft 365 ecosystem grew fifteen-fold in the past year (Microsoft Work Trend Index, 2026). Forward a vendor’s release-notes email to your Certrak address and it becomes an owned review task against every system using that model. Controls falling due, expiring evidence and stale systems are detected automatically, so your governance stays current instead of going stale.

My data

No. Anthropic doesn’t train its models on data sent through its commercial API, and Certrak never uses your governance data to train AI or sells it to anyone.

In Australia. You can export your entire account or delete it whenever you choose. The one thing that leaves is what goes to the AI step: the free text you enter, plus system and control names and descriptions, sent to Anthropic in the United States. Anthropic does not use commercial API data to train its models.

No. AI does one job: reading the free text you type so Certrak can map it to the right governance, and occasionally drafting suggestions you approve. The decisions come from fixed rules you can see and trace, not a black box.

Turn scattered AI into one clear record.

You asked yourself where your AI risk was. Now you can answer it, and have the record to prove it.

We’re hand-picking our first customers, talk to us and we’ll set you up ourselves.