OMB M-25-21/22 compliance plans, NIST AI RMF crosswalks, an AI use-case inventory, and board-ready reporting — built on the same frameworks used in real federal AI governance work, and written in plain language for the people accountable for it.
Built by public-sector practitioners
Jim Tunnessen — Founder, Gradient Descent LLC
A 2x Federal CIO, CTO, and Chief AI Officer with hands-on experience implementing NIST SP 800-53 and AI governance frameworks across federal agencies. The frameworks baked into this platform are the same ones used in real federal AI governance work — not adapted from generic corporate templates. If your agency needs a hand, the advisory session is a 1:1 with someone who has actually stood these programs up.
The questions your public answers to
Agencies aren’t just managing risk — they’re accountable to the public, to oversight bodies, and to the people they serve. The platform is organized around those obligations.
The dominant question for any agency: can we use AI while preserving public trust? Every default here is tuned for accountability, not just adoption.
Disclosure of AI use, decision logging, and an append-only audit log — the documentation a FOIA/records request or an IG review will ask for.
Bias, disparate-impact, and fundamental-rights considerations are first-class in the impact assessment — the lens the public and oversight bodies expect.
A vendor AI risk assessment and a named owner per tool, so AI acquired through procurement is documented, reviewed, and accountable.
Track what every AI tool costs — monthly and annual, rolled up by program office — so AI spend is defensible line by line, with 60-day renewal alerts.
A quarterly leadership report and a governance maturity score give your CIO, CAIO, and oversight bodies one authoritative view of the AI program.
What you can produce
Every output is a grounded draft for your review — never auto-published, never “compliance advice.” The OMB AI Compliance Plan is available on the Agency plan; the rest span the paid tiers (see the comparison below).
Generate an agency AI compliance plan grounded in the OMB memoranda on federal AI use and acquisition — the plan your agency actually has to produce.
Map your controls line-by-line to NIST AI RMF (and ISO 42001 / the Colorado AI Act), with control-level traceability showing exactly what each requirement satisfies.
A ready CAIO position description to stand up the role OMB expects, tailored to your agency's context.
The complete inventory OMB expects — every AI use with a named owner, data sensitivity, and risk classification, including the shadow AI staff adopted on their own.
Score every AI use by likelihood and impact, and run a rights-and-fairness impact assessment that auto-populates your risk register.
A quarterly report — inventory, risks, incidents, training, cost, and a 0-100 maturity score — that answers oversight questions without you translating the data.
Transparent pricing
Start free. Upgrade when you’re ready to generate and export. Cancel anytime.
Prices below are for the AI Governance module — the first of four GOVERNBOX modules. See modular pricing →
Credit card required · $0 today · converts to Starter ($3,500/yr — $291.66/mo equivalent) on day 15 unless canceled
| Feature | Free | Starter | Pro Most Popular | Agency |
|---|---|---|---|---|
| Core Platform | ||||
| AI Readiness Scorecard | ✓ | ✓ | ✓ | ✓ |
| AI Use Case Log (inventory + named owner per system) | — | Unlimited | Unlimited | Unlimited |
| EU AI Act risk tier classification + Art. 5 prohibited-use screen | — | — | — | ✓ |
| Dashboard — My Workspace | ✓ | ✓ | ✓ | ✓ |
| Notifications center (review countdowns, alerts) | ✓ | ✓ | ✓ | ✓ |
| Append-only audit log | ✓ | ✓ | ✓ | ✓ |
| Multi-tenant security + row-level isolation | ✓ | ✓ | ✓ | ✓ |
| Document Generation | ||||
| AI Use Policy | Preview | ✓ | ✓ | ✓ |
| AI Acceptable Use Standard | — | ✓ | ✓ | ✓ |
| AI Incident Response Plan | — | ✓ | ✓ | ✓ |
| Vendor AI Risk Assessment | — | ✓ | ✓ | ✓ |
| AI Strategic Plan (wizard) | — | — | ✓ | ✓ |
| CAIO Position Statement (wizard) | — | — | ✓ | ✓ |
| AI Committee Charter (wizard) | — | ✓ | ✓ | ✓ |
| Privacy Policy (consumer / data-subject rights) | — | — | CCPA-grounded | GDPR + CCPA |
| OMB AI Compliance Plan (M-25-21 / M-25-22) | — | — | — | ✓ |
| Compliance Crosswalk export | — | NIST + ISO + Colorado | NIST + ISO + Colorado | NIST + ISO + Colorado + EU AI Act |
| Word (.docx) export | — | ✓ | ✓ | ✓ |
| PDF export | — | ✓ | ✓ | ✓ |
| Organization logo on document exports | — | — | ✓ | ✓ |
| White-label exports (no Gradient Descent branding) | — | — | — | ✓ |
| Compliance Frameworks | ||||
| NIST AI RMF | Preview | ✓ | ✓ | ✓ |
| ISO/IEC 42001 | — | ✓ | ✓ | ✓ |
| Colorado AI Act (HB 26-1263 / SB 26-189, eff. Jan 1, 2027) | — | ✓ | ✓ | ✓ |
| EU AI Act | — | — | — | ✓ |
| NIST SP 800-53 Rev. 5 / CSF 2.0 | — | — | ✓ | ✓ |
| CCPA / CPRA (California consumer privacy) | — | — | ✓ | ✓ |
| GDPR (EU data protection) | — | — | — | ✓ |
| HIPAA Security & Privacy Rules | — | — | — | ✓ |
| OMB M-25-21 / M-25-22 (Federal AI) | — | — | — | ✓ |
| Risk & Impact | ||||
| Risk Register (CRUD + likelihood × impact scoring) | — | ✓ | ✓ | ✓ |
| Risk heat map visualization | — | — | ✓ | ✓ |
| AI Impact Assessment (7-section questionnaire) | — | ✓ | ✓ | ✓ |
| Auto-create risk entries from assessments | — | — | ✓ | ✓ |
| AI Project Management Module | ||||
| AI project list & per-project board | — | Up to 2 | Up to 5 | Unlimited |
| 7-phase AI development lifecycle checklist | — | ✓ | ✓ | ✓ |
| 45-item NIST/ISO/EU grounded task checklist | — | ✓ | ✓ | ✓ |
| Kanban board (drag-drop, task detail, Edit mode) | — | ✓ | ✓ | ✓ |
| Cross-links: Use Cases / Projects / Risk Register | — | ✓ | ✓ | ✓ |
| Agentic AI Governance Module | ||||
| AI Agents inventory — basic registration (identity, ownership, data access) | — | ✓ | ✓ | ✓ |
| 12-item zero-trust controls checklist (NIST SP 800-207) | — | — | — | ✓ |
| Zero-trust score + low-score alerts | — | — | — | ✓ |
| Agent registration wizard (3-step) | — | ✓ | ✓ | ✓ |
| Agent metrics in Board Report governance block | — | ✓ | ✓ | ✓ |
| Cross-links: Agents / Use Cases / Risk Register | — | ✓ | ✓ | ✓ |
| Training, Incidents & Operations | ||||
| Training plan + completion tracking | — | ✓ | ✓ | ✓ |
| Acceptable-use acknowledgment sign-off | — | ✓ | ✓ | ✓ |
| Incident log + severity codes | — | ✓ | ✓ | ✓ |
| EU AI Act Art. 73 serious-incident flag | — | — | — | ✓ |
| Reporting & Governance | ||||
| Quarterly Board Report (full — maturity score + quarterly history) | — | ✓ | ✓ | ✓ |
| AI Cost Tracking & Roll-Up (per use case + program office, 60-day renewal alerts, Board Report totals) | — | ✓ | ✓ | ✓ |
| Board Report — AI Agents governance section | — | ✓ | ✓ | ✓ |
| Governance maturity score + stars (dashboard/badge) | Preview | ✓ | ✓ | ✓ |
| Shareable governance badge | — | ✓ | ✓ | ✓ White-labeled |
| Live public Trust Page + embeddable live badge | — | ✓ | ✓ | ✓ White-labeled |
| Employee Attestation Portal (unlimited signers) | — | ✓ | ✓ | ✓ |
| Regulatory horizon feed ("What's Changing") | ✓ | ✓ | ✓ | ✓ |
| Gap report with advisory CTAs | Preview | ✓ | ✓ | ✓ |
| Administration | ||||
| Admin Console (full data inventory & controls) | — | Owner + Admin | Owner + Admin | Owner + Admin |
| User roles (Owner / Admin / Editor / Viewer) | — | ✓ | ✓ | ✓ |
| User invite & role management | — | ✓ | ✓ | ✓ |
| Enterprise SSO (SAML / OIDC) | — | — | — | ✓ |
| Data export (full org snapshot) | — | ✓ | ✓ | ✓ |
| Retention policy + danger zone (Owner only) | — | ✓ | ✓ | ✓ |
| Seats included | 1 | 3 (up to 5) | 5 (up to 10) | 10 (up to 20) |
| White-label client portal | — | — | — | ✓ |
| Support & Advisory | ||||
| Email support | — | ✓ | ✓ | ✓ |
| Onboarding walkthrough | — | — | ✓ | ✓ |
| Priority support | — | — | — | ✓ |
| Advisory session (1:1 with Jim) | — | — | — | ✓ Included |
Common questions
Start free with the Readiness Scorecard, or talk to a former federal CIO/CAIO about your agency’s needs.