AI Security Posture Management (AI-SPM)
A structured approach for discovering AI systems, evaluating their risks, recording security evidence, and improving governance visibility.
Clear definitions for common AI security, governance, model, identity, agent, risk, and SentinelCore terms.
A structured approach for discovering AI systems, evaluating their risks, recording security evidence, and improving governance visibility.
An AI Bill of Materials: an inventory record describing an AI system’s models, versions, ownership, data sources, dependencies, and other relevant components when that information is available.
Software that uses an AI model to interpret goals, make decisions, and perform approved actions through connected tools or services.
A policy or security control that evaluates a proposed AI-agent action before it is approved, reviewed, recorded, or rejected.
A documented list of known AI applications, models, agents, owners, environments, identities, and business use cases.
A human, service account, API credential, workload, application, or agent identity that can access or operate an AI system.
An attempt to manipulate an AI system by inserting instructions that conflict with the application’s intended policies or trusted instructions.
A prompt designed to persuade an AI system to ignore safeguards, restrictions, or expected operating boundaries.
The unintended disclosure or transmission of personal, confidential, regulated, financial, health, authentication, or proprietary information.
Risk observed while an AI application, model, or agent is operating, including unsafe prompts, data exposure, policy violations, and questionable agent actions.
SentinelCore’s evidence-based view for presenting measured AI risks, incidents, systems, agent activity, and governance-readiness indicators.
An operating mode in which SentinelCore evaluates and records activity without automatically interrupting the customer’s production workflow.
The separation of customer organizations, credentials, incidents, evidence, and reports within a multi-customer platform.
An assessment of whether useful controls, records, ownership information, and evidence exist to support a future compliance or governance review. It is not the same as certification.
A management-focused report summarizing observed AI systems, risks, incidents, governance gaps, and recommended next actions.