Platform / Vera
An AI compliance officer,
not a chatbot in a sidebar
Competitors bolt AI assistants onto dashboards. Vera is the operational backbone: she scans your infrastructure, generates policies grounded in reality, collects evidence, escalates stale items, and executes remediation with your approval. She is the product.
- Daily Slack briefing
- 6:30 AM
- Cloud & code scans
- Weekly
- Access reviews
- Quarterly
- On schedule, not on demand
- 24/7
Are we ready for SOC 2 Type II?
87% ready, up 3 points this week. Two blockers before the observation window:
- CloudTrail evidence stale (92 days) — I drafted a re-collection
- Acceptable Use Policy awaiting @sam’s acknowledgment
Every tool call is scoped by role and risk tier, logged, and audited
What Vera actually does
Ask Vanta or Drata to show you their AI doing something without a human clicking a button.
Context-aware on every page
Vera sees what you see. Open a failing control and she already knows which control, what evidence is missing, and what to do next, no copy-pasting IDs, no explaining your problem.
- Page context flows to Vera automatically, control, test, policy, or risk
- Status-aware suggestions: “This evidence is 92 days old, want me to re-collect?”
- Scoped chat threads remember the conversation about CC6.1 from 20 minutes ago
- Failing test in viewPR-15-T1seen
- Missing: Q3 access reviewdetected
- “Evidence is 92 days old — re-collect?”suggested
No IDs pasted, no re-explaining the problem
Autonomous scheduled operations
Daily evidence freshness checks at 6:00 AM, readiness snapshots at 6:15 AM, weekly Monday cloud and code scans, quarterly access reviews, annual risk refreshes, all running on scheduled jobs.
- Agents invoke only when there's actual work, not token-burning heartbeats
- Structured agent reports with pass/fail/warn summaries and action buttons
- Unresolved issues pin to the top of the feed until resolved
- Evidence freshness sweepdaily 06:00ran
- Slack briefingdaily 06:30sent
- Cloud + repo scanMon 09:00ran
- Access reviewquarterlydue in 12d
Runs whether or not anyone logs in
Permissioned, auditable autonomy
Every tool Vera can use is scoped by user role and risk tier. Legally binding actions always require human approval. You control exactly what she can do, and every decision is logged.
- Role-based access: admin, reviewer, viewer, tester, auditor, employee
- Risk tiers from autonomous to approval-required, with in-chat approval cards
- The audit trail of agent decisions is itself SOC 2 evidence
Enable S3 default encryption on 2 buckets
aws.s3.putEncryptionConfiguration · prod-uploads, prod-exports
Legally binding actions always require a human
Delegation that follows up
Vera DMs teammates for evidence with step-by-step instructions and escalates on a ladder, 4 hours to DM, 24 hours to email, 48 hours to a dashboard banner, so nothing silently goes stale.
- Evidence requests via Slack DM with guided instructions
- File drops in Slack are auto-classified, signed, and routed to the right control
- Email interface with sender-aware intent classification
- @priya · Q2 access reviewSlack DM · 2h agoreceived
- @marcus · vendor SOC 2 reportemail · 22h agoescalates in 2h
Ladder: 4h → DM · 24h → email · 48h → dashboard banner
A day with Vera
- 01
6:00 AM, freshness check
The Evidence Agent sweeps every artifact for staleness and flags what needs re-collection.
- 02
6:30 AM, Slack briefing
Your #compliance channel gets a readiness briefing: what changed, what's stale, what needs a decision.
- 03
During the day, approvals only
Vera drafts, delegates, and scopes remediation. You approve actions; you don't run them.
Built to answer “what will your AI do to my systems?”
Declarative permission registry
Every agent action maps to a permission entry with role-based access and a risk tier, visible on your settings page.
Human approval for binding actions
Policy approvals and risk acceptance always require a human. Whitelist safe patterns to reduce friction over time.
Full audit trail
Every tool invocation is logged through audited wrappers. Every permission decision is recorded.
Explore the platform
Meet your compliance officer
See Vera answer “What's our SOC 2 readiness?” with a specific answer and action items, live, on your stack.