Compliance.
Running AI cost control produces two artefacts an audit wants anyway: a list of every AI system in use, and a record of every decision taken about it that nothing can edit. This page says what we hold, which obligation each part speaks to, and where it stops.
What Valistry holds
- An inventory of every model in use
- Every provider, model, application and agent the ledger has seen in this period, with what each cost and who owns it. Read from usage, not from a list somebody maintains, so a model nobody declared still appears.
- Who owns each workload
- A business owner and a technical owner per agent, and a team on every run a rule or a tag can reach. Gaps are named rather than filled.
- A decision record nothing can edit
- Every rule, policy, mode change, approval, exception, owner, budget, member and source change, with who did it and when. Nothing is edited; a reversal is a new entry.
- Where the money went, and on what basis
- Every figure carries how it was priced: the published card, a family rate, your negotiated rate, or the vendor's own charge.
- What was never collected
- No prompt, no completion, no conversation, no document, no source code. A seat holder is a hash. There is no field for any of it.
What each one speaks to
Named plainly, because a claim that a product makes you compliant is never true.
- EU AI Act, deployer obligations
- A deployer has to keep logs of the AI systems it operates and monitor their operation. The decision record and the usage ledger are logs of operation and of every change made to how a system is governed. They are not a conformity assessment, and they say nothing about the risk class of a model.
- NIST AI Risk Management Framework
- Its Map function begins with knowing what AI is in use and who is accountable for it. The estate inventory and the agent registry are that, kept from usage rather than from a survey.
- ISO/IEC 42001
- An AI management system starts from an inventory of AI systems and a record of the decisions taken about them. Those two artefacts are what this product produces as a by-product of running cost control.
- SOC 2, for us rather than for you
- Our own report is in progress and is about how we run the service. It is not an audit of your AI use, and no page here will imply otherwise.
Where it stops
- We are not a compliance product
- Nothing here certifies anything, and we will not say an estate is compliant. We hold two artefacts an audit asks for; the rest of an audit is not ours.
- We do not gate a model on content
- There is no content filter, no safety classifier, no model risk assessment. Those systems keep their own controls, and we read usage metadata beside them.
- We do not discover tools outside a connected account
- A subscription somebody expensed on a personal card is invisible to us. An identity provider's app list or a proxy log finds those, and both are connectors we read.
- The record starts when you connect
- History before the first sync is whatever the vendor's own API will hand back, which is ninety days for most of them and less for some. Each connector page says which.
Getting the record out
The change log exports as CSV and JSON, and on the Enterprise tier the same rows are posted nightly to an endpoint you name, signed.
A source is never exported with its credential: it is the connector and the last four characters of the key.
How we hold your data covers residency, retention and deletion.