SentRAI is a self-hosted AI governance console for financial services. It finds the models hiding in your code, scores each one against India's RBI FREE-AI framework, the US NIST AI Risk Management Framework, the EU AI Act, and ISO/IEC 42001, monitors them for drift, and maintains the evidence trail your next audit will ask for.
Wherever you operate — or plan to — the rules differ, but the questions are the same: what AI are you running, who owns it, is it fair, can you explain it, and can you prove all of that? SentRAI answers once and maps the answer to each regulator's language. Exact control counts are published on the coverage disclosure.
The Reserve Bank of India's 2025 Framework for Responsible and Ethical Enablement of AI: seven guiding principles (Sutras), six pillars, and 26 recommendations for banks, NBFCs, and fintechs. India's DPDP Act adds strict personal-data rules.
SentRAI validates all seven Sutras on every model plus the Governance, Protection, and Assurance recommendations (14, 16, 20, 24), with DPDP-aligned PII masking across the entire console — the deepest of the four frameworks.
The de-facto US standard for AI risk management, organised into four functions — Govern, Map, Measure, Manage — and referenced by US regulators and enterprise procurement alike.
SentRAI validates fourteen controls across all four functions — ownership, board policy and audit cadence; documented purpose, context and provenance; red-team recency and live drift measurement; oversight gates, fallback plans, resourced owners, ledger-tracked risks, and incident hygiene.
The world's first comprehensive AI law. Obligations scale with risk tier, and financial-sector uses like credit scoring sit squarely in the high-risk category — with duties for documentation, oversight, and robustness.
SentRAI validates each model's risk classification plus fourteen articles: the core high-risk obligations (Articles 9–15, 17), value-chain and deployer duties (25, 26, 27), post-market monitoring (72), and the Article 50 transparency duty.
The management-system standard for AI — think ISO 27001, but for how your organisation governs models. Increasingly requested in vendor due-diligence and cross-border deals.
SentRAI validates eight management-system checks spanning clauses 6, 7, 8, 9 and 10 plus Annex A documentation — a living inventory, accountable ownership, risk treatment, incident records, and continuous monitoring.
Most governance tools begin with a spreadsheet someone forgot to update. SentRAI begins with a scan of your repositories and infrastructure, so the model inventory reflects reality — then keeps it honest for the model's entire life.
Regex + AST scanning over local code, GitHub repos, and Kubernetes/Triton infrastructure surfaces AI systems you didn't know you were running.
Every model gets an owner, a risk tier, a purpose, and a ledger entry — scoped per project, with lineage tracked across systems.
Automated validators score each model against all four frameworks in one pass — and tell you exactly which artifact or control is missing.
Your serving layer pushes score windows to the API; an hourly job runs PSI + Wasserstein checks, trips a persistent circuit breaker, and fires a human-review webhook.
Immutable audit trails, incident SLAs, and one-click PDF compliance reports — regulator-ready evidence, not screenshots of dashboards.
Strip away the acronyms and every serious AI regulation asks for the same seven things. India's FREE-AI calls them Sutras; NIST spreads them across four functions; the EU AI Act writes them into articles. SentRAI enforces each one with a concrete mechanism.
SentRAI is a self-hostable console — your model metadata never has to leave your infrastructure.
Regex plus tree-sitter AST analysis finds model definitions in real source, not self-reported forms. Scans local paths, GitHub, and k8s/Triton serving infra.
Framework checks are plugins with a shared registry — run FREE-AI, NIST AI RMF, EU AI Act, and ISO 42001 in one pass, or add your own internal policy as a fifth.
Push score windows to /monitoring/scores; an hourly job computes Population Stability Index and 1-D Wasserstein distance against the reference window, with configurable thresholds.
PII masking with India DPDP and GDPR patterns (PAN, Aadhaar, emails, IBANs, credentials) automatically applied to audit events, ledger entries, and outbound notifications.
One-click PDF compliance reports per model, immutable audit trails, and incident histories with SLA status — evidence in the format audits actually want.
JWT auth with role-based access, Prometheus /metrics, outbound webhooks for breaker trips and overdue incidents, optional Neo4j lineage, daily re-scans, and a full REST API.
Scan your first repository and see your real model inventory in under ten minutes.