
Discovery
Find every SaaS and AI tool in use
Including the ones your team never reported
Shadow AI tools are running in your organisation without your knowledge. Under NIS2, that's your personal liability. Montro surfaces every AI tool and SaaS app in use—including undisclosed ones—and maps them against NIS2, DORA, and the EU AI Act so you can manage the risk.

Reality
"You are held responsible for risks you do not own, assets you do not control, and decisions made by people who outrank you." Montro was built to change that arithmetic.
Personal liability for unmanaged AI and SaaS risk exposure.
Tools running in your organisation that IT has never seen.
Visibility
The foundation every CISO needs to own their risk.

Discovery
Including the ones your team never reported

Classification
Risk tiers and article numbers assigned automatically

Register
Board and regulator ready from day one
Mapping
Montro doesn't just find your SaaS and AI tools. It connects each one to the specific regulatory articles that govern your liability as a CISO. No guesswork. No spreadsheet interpretation. Article references, risk tiers, and remediation owners in a single compliance matrix.
Every shadow AI tool and unmanaged SaaS app discovered is mapped directly to Art.20, showing your regulator you've identified and assessed the risk.
Critical ICT services are automatically classified and registered against Art.8 requirements, eliminating the manual register work that takes months.
Tools flagged as high-risk under the EU AI Act are tagged with the specific risk categories requiring impact assessments and human oversight.
Setup
Connect your identity provider. Montro begins discovery immediately. Shadow AI surfaces within 24 hours.
Read-only access to your directory. No agents. No disruption.
Every app, every AI tool, every user. Real-time visibility begins.
GDPR, EU AI Act, DORA, NIS2. Automatically classified and mapped.
New tools detected. Compliance status maintained. Alerts on policy drift.

Outcome
Regulators see a maintained register, not spreadsheets and screenshots.
Montro discovers AI tools across your existing stack — no agents, no manual imports. Connect once and your inventory stays current.








Obligations
Your regulators expect three separate compliance registers by year-end. Montro builds all three simultaneously from a single discovery run, eliminating the manual work that typically takes months across three different teams.
Every third-party ICT service must be classified, assessed for criticality, and registered with your regulator—Montro auto-generates this register with risk tiers and audit readiness status.
Learn moreYou must identify and manage cybersecurity risks from your supply chain—Montro maps every SaaS vendor and AI tool provider to supply chain risk categories and flags those requiring enhanced due diligence.
Learn moreAs a deployer of AI systems, you must classify tools by risk level and maintain records of compliance—Montro tags every AI tool discovered against the Act's risk categories and maintains a continuous audit trail.
Learn moreThe answers CISOs need before audit season arrives.
In 30 days. For free. No credit card. No long-term commitment. Just visibility.
Free 30-day AI Discovery Audit. No commitment.
