AI Innovation
ASK ALLOYAsk Alloy
Ask in plain English. Get an answer from your own data, labeled by what kind of answer it is.
Ask Alloy is a drawer on every page of AlloyGRC. It takes you to the right page, pulls real figures from your data, or explains them, and it always tells you which of the three it is doing.
Which vulnerabilities are affecting my systems?
Look upFour exploited vulnerabilities are outstanding across the three systems you are cleared for. The widest is on all three.
Ranked in code. Scoped to your systems. Illustrative values.
Three kinds of answer
A database fact and a piece of advice must not look alike.
In a compliance tool, a number pulled from your data and a paragraph of advice cannot be allowed to look the same. So every answer carries its class, and each class is produced a different way.
NAVIGATE
Take me there
How it decides
Your words are matched against the page registry, in the browser. No model runs.
What you see
The page opens, or a short list of the pages that fit.
No model call
LOOK UP
Give me the number
How it decides
A local model chooses filters from a closed vocabulary it was handed. The database produces the figure. If the choice does not parse, it is refused, never repaired.
What you see
A count, a ranking or a profile with the filters it used, and a way to open the same rows in the table.
A few dozen tokens
ASSISTANT
Explain it to me
How it decides
Real figures are gathered first, then handed to the model with the question. The model phrases them. It is never asked to produce or compare a number.
What you see
A short paragraph over the figures it was given, with the figures visible.
One generation
What you can ask today
Six kinds of question, each answered in its own shape
A capability owns a kind of question. It gathers the data in code, ranks it in code, and hands the model only the sentence to write. When it owns the question but cannot answer it for you, it says so in one line and points at the page that can.
CVE briefing
ProfileWhat do I need to know about CVE-2026-3063?
Score, exploitation and ransomware signals, actors, techniques, and how many of your outstanding findings carry it, on how many systems.
Exposure ranking
LadderWhich vulnerabilities are affecting my systems?
Outstanding findings ranked worst first, exploited flagged, a bar for how many assets carry each, and the remainder stated.
Ownership
OwnerWho is responsible for fixing CVE-2026-3063?
The person assigned, or the fact that nobody is, resolved through your directory.
My work today
WorklistWhat do I have to work on today?
Your assignments, your workflow steps and your next sprint, grouped so the first card is the first thing to do.
Personnel
RosterWhich of my ISSOs is behind on their work?
One row per person with the numbers that ranked them, worst first. Executive seats only; everyone else gets a plain handoff.
Navigate
PageTake me to the sprint board
Any page you may open, matched from how you describe it.
How it stays honest
Built so it cannot make things up
Numbers come from code
Every figure in an answer is the result of a query the platform ran. Rankings and comparisons are computed before the model sees anything, because a model cannot be trusted to rank.
It hands off instead of guessing
A capability that cannot answer for you says so in one sentence and points at the page, rather than producing a confident paragraph about a question nobody asked.
Scoped to your seat
Two people asking about the same CVE get the same intelligence and different exposure, because exposure is counted only over the systems each is cleared for, by the server.
Routed by rules first
A paraphrase nobody wrote down still reaches the right capability: rules first, then one validated model pick from a closed list, only when no rule matched.
Runs on a local model inside your boundary. No question, figure or name leaves your environment.
Seen in the app
The real thing, on synthetic data
The drawer, on a synthetic dataset
Ask about your posture
- Which of my systems needs attention first
- How exposed are we right now
- What should I be working on today
- Who on my team is furthest behind
Ask about a threat
- What do I need to know about CVE-2021-44228
- Is this something we should worry about
- Who is fixing it
Count it from your data
- How many open vulnerabilities are on my systems
- How many CAT I findings do I have
- How many findings are still overdue
Find your way around
- Where do I see overdue POA&M items
- Look up a CVE and who exploits it
- What evidence satisfies AU-12
Every prompt above is a starter chip in the drawer itself. Each group answers in a different shape: a ranked list, a briefing, a counted figure with its filters, or a page.
One drawer, three audiences
For leadership
The picture in one question: which systems are worst, which vulnerabilities matter, who is behind. Then a dashboard of the same answer, one click away.
For the ISSO
What to work on today, who owns the finding, what a CVE means for the systems you hold. Then the table with those exact rows, ready to work from.
For the ISSE
Which vulnerabilities touch the systems you maintain, which fix clears the most of them, and what the scanner saw. Then the table of those exact findings, scoped to your systems, ready to patch from.
Straight answers
Ask it something hard.
Ask for a demo and put your own questions to a synthetic environment. Watch which class each answer comes back as.
