The copy generator was fine when someone signed up in 2024. The ad platform swapped its model twice since. A freelancer delivered assets from a tool nobody has heard of, and the chatbot's renewal is next month with new AI clauses buried in the contract. The rules moved under all of them — and when a client audit or a regulator asks which third-party AI is in your stack and who checked it last, the answer cannot be a shrug. This is the registry: one row per vendor, with the status, the risk level and a review date that chases you.
Not just a list of tool names — a status board. See how much of the stack is actually cleared, which reviews have gone stale, and where the shadow AI is hiding.
The spreadsheet dies the week after someone builds it. This is structured, chases its own review dates, and exports a dated audit record on demand.
Name, provider, category, what data it touches, who owns it internally and what it is used for. The first question in every audit is "what AI do you use?" — this answers it in one export.
Compliant, needs review, non-compliant, or unknown — each with a colour, a count and an alert. Shadow AI gets logged as unknown instead of staying invisible until it becomes a problem.
Vendors fall out of compliance without changing anything on your side — the rules move instead. Every vendor gets a next-review date, and the dashboard counts the overdue ones out loud.
CSV for the compliance file, procurement or a client's vendor questionnaire; JSON backup you can re-import. A dated registry beats a heroic memory reconstruction every time.
Not for a GRC platform nobody in marketing has a login to.
You own the stack and the renewals. See which vendors carry real risk, which reviews are due, and walk into procurement conversations with the record already written.
Vendor risk from AI tools lands on marketing now, not just IT. Keep the registry current and the next "what AI do we use?" email takes two minutes instead of two weeks.
Log each client's AI stack separately and hand over a dated CSV with the engagement. A vendor register attached to delivery is cheap to produce and awkward to be without.
Client questionnaire, board question or a regulator's letter — the useful artefact is a dated registry showing what you use, what you checked and when. That is the whole output.
“The tool worked great when we signed up. Nobody checked whether the vendor kept pace with the rules since.”
Enterprise vendor-risk platforms are priced for enterprises and owned by a risk team. Spreadsheets go stale the week after the audit. Between those two there was nothing structured, cheap and owned by the marketing team itself — that is what this is.
One self-contained HTML file. No accounts, no API keys, no network calls, nothing uploaded. It installs to your phone or desktop home screen, works offline, and every entry stays in your own browser. Built by Mulkern AI Systems, who ship AI operations tooling for marketing teams.
A structured record-keeping aid, not legal advice. It shows you where the gaps are and what to take to counsel or procurement — it does not replace them.
Instant access after checkout. No refunds. All sales are final.