Skip to main content

AI Innovation

ASK ALLOY

Ask Alloy

Ask in plain English. Get an answer from your own data, labeled by what kind of answer it is.

Ask Alloy is a drawer on every page of AlloyGRC. It takes you to the right page, pulls real figures from your data, or explains them, and it always tells you which of the three it is doing.

Which vulnerabilities are affecting my systems?

Look up

Four exploited vulnerabilities are outstanding across the three systems you are cleared for. The widest is on all three.

1 CVE-2025-31324
3 sys
2 CVE-2025-24813
2 sys
3 CVE-2024-21762
2 sys
4 CVE-2025-22457
1 sys

Ranked in code. Scoped to your systems. Illustrative values.

Three kinds of answer

A database fact and a piece of advice must not look alike.

In a compliance tool, a number pulled from your data and a paragraph of advice cannot be allowed to look the same. So every answer carries its class, and each class is produced a different way.

NAVIGATE

Take me there

How it decides

Your words are matched against the page registry, in the browser. No model runs.

What you see

The page opens, or a short list of the pages that fit.

No model call

LOOK UP

Give me the number

How it decides

A local model chooses filters from a closed vocabulary it was handed. The database produces the figure. If the choice does not parse, it is refused, never repaired.

What you see

A count, a ranking or a profile with the filters it used, and a way to open the same rows in the table.

A few dozen tokens

ASSISTANT

Explain it to me

How it decides

Real figures are gathered first, then handed to the model with the question. The model phrases them. It is never asked to produce or compare a number.

What you see

A short paragraph over the figures it was given, with the figures visible.

One generation

What you can ask today

Six kinds of question, each answered in its own shape

A capability owns a kind of question. It gathers the data in code, ranks it in code, and hands the model only the sentence to write. When it owns the question but cannot answer it for you, it says so in one line and points at the page that can.

CVE briefing

Profile

What do I need to know about CVE-2026-3063?

Score, exploitation and ransomware signals, actors, techniques, and how many of your outstanding findings carry it, on how many systems.

Exposure ranking

Ladder

Which vulnerabilities are affecting my systems?

Outstanding findings ranked worst first, exploited flagged, a bar for how many assets carry each, and the remainder stated.

Ownership

Owner

Who is responsible for fixing CVE-2026-3063?

The person assigned, or the fact that nobody is, resolved through your directory.

My work today

Worklist

What do I have to work on today?

Your assignments, your workflow steps and your next sprint, grouped so the first card is the first thing to do.

Personnel

Roster

Which of my ISSOs is behind on their work?

One row per person with the numbers that ranked them, worst first. Executive seats only; everyone else gets a plain handoff.

Navigate

Page

Take me to the sprint board

Any page you may open, matched from how you describe it.

How it stays honest

Built so it cannot make things up

Numbers come from code

Every figure in an answer is the result of a query the platform ran. Rankings and comparisons are computed before the model sees anything, because a model cannot be trusted to rank.

It hands off instead of guessing

A capability that cannot answer for you says so in one sentence and points at the page, rather than producing a confident paragraph about a question nobody asked.

Scoped to your seat

Two people asking about the same CVE get the same intelligence and different exposure, because exposure is counted only over the systems each is cleared for, by the server.

Routed by rules first

A paraphrase nobody wrote down still reaches the right capability: rules first, then one validated model pick from a closed list, only when no rule matched.

Runs on a local model inside your boundary. No question, figure or name leaves your environment.

Seen in the app

The real thing, on synthetic data

The drawer, on a synthetic dataset

Asked for a summary of a synthetic vulnerability dataset, Ask Alloy answers with figures it computed itself, shows every figure the sentence used, and offers the next step. The first tile counts open findings across the whole synthetic estate of 120 systems; the other three are the systems carrying the most, the top of a ranking rather than parts of the total. The model chooses the words; the code counts the rows.

Ask about your posture

  • Which of my systems needs attention first
  • How exposed are we right now
  • What should I be working on today
  • Who on my team is furthest behind

Ask about a threat

  • What do I need to know about CVE-2021-44228
  • Is this something we should worry about
  • Who is fixing it

Count it from your data

  • How many open vulnerabilities are on my systems
  • How many CAT I findings do I have
  • How many findings are still overdue

Find your way around

  • Where do I see overdue POA&M items
  • Look up a CVE and who exploits it
  • What evidence satisfies AU-12

Every prompt above is a starter chip in the drawer itself. Each group answers in a different shape: a ranked list, a briefing, a counted figure with its filters, or a page.

One drawer, three audiences

For leadership

The picture in one question: which systems are worst, which vulnerabilities matter, who is behind. Then a dashboard of the same answer, one click away.

For the ISSO

What to work on today, who owns the finding, what a CVE means for the systems you hold. Then the table with those exact rows, ready to work from.

For the ISSE

Which vulnerabilities touch the systems you maintain, which fix clears the most of them, and what the scanner saw. Then the table of those exact findings, scoped to your systems, ready to patch from.

Straight answers

Can it make up a number?

No. Every figure in an answer is produced by a query the platform ran. The model chooses filters from a closed list and writes the sentence around the result.

What if it cannot answer?

It says so in one plain sentence and points you at the page that can, instead of producing a confident paragraph about a question nobody asked.

Does my question leave the environment?

No. It runs against a local model inside your own boundary with no external inference calls.

Is it still being developed?

Yes. The five capabilities above are built and probed live. More question types follow the same pattern: gather in code, rank in code, let the model write the sentence.

Ask it something hard.

Ask for a demo and put your own questions to a synthetic environment. Watch which class each answer comes back as.