AI monitoring for compliance teams.

Connor watches every file and chat going into ChatGPT and Claude against your watch list, and finds the AI your team set up on their own laptops. You hear about a problem while it is still fixable.

The compliance gap

Frontier labs ship daily, introducing new ways for sensitive data to leave your organisation.

Almost none of them arrive with a way to see it happening, and the distance between what your people can do and what you can account for only widens.

YOUR EXPOSUREYOUR VISIBILITYTHE COMPLIANCE GAPChatGPTNov 2022PluginsMar 2023Custom GPTsNov 2023MCPNov 2024Agent SkillsOct 2025

It has happened before

$3.5bnin fines since 2021 for business done on WhatsApp and personal devices. Connor exists so AI is not the next one.
$1.8bn16 firms in one daySEC & CFTC · September 2022

Recordkeeping failures. Business conducted on personal messaging apps that nobody captured or supervised.

Connor closes the gap.

Your risk

How data leaves.

Through the app

In the accounts your firm gave them. Share a project outside the firm and every file in it goes too. It leaves a trail almost nobody reads.

  • Shared projects, and every file in them
  • Chat and project titles
  • Files and file names
  • Exports and share links

Shadow AI

On the machines. No account, no tenant, no log.

  • MCP connectors
  • Skills, and what is inside them
  • Personal accounts
  • Unmanaged tools
Solution

The monitoring layer for compliance.

One wall across both. Every file, chat and shared project checked against your watch list, whether it went through the app or around it, and one list of what actually needs you.

In-app activityContinuous
  • ChatGPTChatGPTFile uploadedTeam offsite agenda.docx
  • ClaudeMessage sentReviewing the Project Nightjar deal terms
  • ClaudeProject createdClient onboarding
  • ClaudeFile sharedCastleford valuation.xlsx
  • ChatGPTChatGPTSnapshot createdQ3 metrics summary
  • ClaudeProject sharedProject Nightjar diligence
  • ChatGPTChatGPTFile exportedClient contract list.csv
Shadow AI scanLast run today
  • Connector detectedSlack workspace
  • Skill foundmeeting-notes · no files inside
  • Personal accountClaude, signed in beside the corporate one
  • Tool installedDesktop client, outside the inventory
Exceptions
  • ClaudeFile sharedCastleford sent to an address outside the firmBreach
  • ClaudeProject sharedProject Nightjar opened to two people outside the firmBreach
  • Connector detectedCan post deal files to a channel outside the firmHigh
  • Personal accountAn unmanaged account on a laptop holding client filesHigh
  • ClaudeMessage sentProject Nightjar appears in the chat titleMedium
  • ChatGPTChatGPTFile exportedA client list left the workspace as a downloadLow
  • Tool installedNot in the asset register, so nobody owns itLow

7 of 11 raised · 4 in app, 3 on machines

The watch listThe rules engine behind all of it

Your restricted list, deal codenames, clients and counterparties, mandates and document classes. Everything above is checked against this, whichever way it left.

Deterministic rules

The terms you write down: codenames, clients, counterparties, restricted names. Deterministic, so a name is either on the list or it is not, the same input always gives the same answer, and you can show anyone exactly why something was raised.

AI judgement

A model reads for meaning rather than matching text, so it catches what the list never anticipated: a codename nobody registered, a client spelled three ways, a title that means something the words do not say. It is not deterministic, so it never decides. It raises, and a person judges.

Our promise

We close the gap with you, and keep it closed.

Built for compliance

Compliance owns it

Not a security tool with a compliance tab bolted on.

Model agnostic

Any vendor

Claude, ChatGPT, and whatever ships next.

Both surfaces

Cloud and machines

Nobody else covers the laptops.

Ongoing support

We run it with you, and we close the gap as it moves

Not a licence and a login. We sit in the review with you, tune the watch list as the mandates change, and absorb the vendor churn so nobody on your team has to track which API moved this quarter. If procurement needs it, we deploy inside your own environment and the data never leaves it.

Security
  1. Live
    • UK and EU data residency
    • Read-only scopes, no delete
  2. In progress
    • Cyber Essentials Plus
    • SOC 2 Type I
  3. Observation
    • SOC 2 Type II
  4. Planned
    • ISO 27001

If your review needs more than we can show today, we deploy inside your own environment and the data never leaves it. Ask on the call and you will get dates, not adjectives.

Find out what has already left.