Skip to content
PPlatform overview

One graph. Five modules. Every cycle makes you stronger.

AirTee.ai runs the whole resilience loop on a single dependency graph. That's the difference between a system of record and a system of action.

01The graph

Your business, modelled once.

Services, dependencies, owners, vendors, controls, plans, exercises and incidents — all in one model. Every module reads from it, writes to it.

  • Critical services, ranked by impact and recovery objective.
  • Upstream and downstream dependencies.
  • Owners, deputies and on-call rotations.
  • Vendor concentration, contractual SLAs, exit-plan attestations.
  • Controls mapped to ISO 27001, ISO 22301, SOC 2, DORA, NIS2, NIST SP 800-61 and UK/EU GDPR.
  • Plans, scenarios and runbooks linked to the services they protect.
02Modules

Five surfaces over one truth.

01
Incident command

Live war room with AI-suggested actions, MITRE ATT&CK mapping on request, and regulator-clock automation.

02
Business Impact Assessments and Resilience Plans

Plans and impact analyses that update from real signal — incidents, exercises, dependency changes.

03
Vendor & supply-chain risk

Vendor register linked to services, concentration and geographic risk analysis, review and evidence reminders.

04
Exercises

Schedule, run and grade tabletops; AI generates scenarios and injects, grades responses, and drafts the AAR.

05
AI After-Action

Drafts the AAR with timeline, root cause, decisions and regulator status; tracks action items to closure.

06
Posture & control library

One library mapped to every framework you report on — kept current by the loop above.

03How it deploys

A typical rollout.

Indicative sequence; we plan it with you.

  • Day 1–7: connect identity, ITSM, SIEM and one comms channel.
  • Day 7–14: import critical services + first impact assessment pass.
  • Day 14–30: AirTee runs your first guided tabletop.
  • Day 30–60: BCPs migrated, vendor profiles backfilled, board view live.
  • Dedicated single-tenant environments (UK, EU or US region) available on the Enterprise plan, provisioned by our team.
04Also in the platform

What else ships with AirTee.

01
Evidence intake

Upload transcripts, vendor reports, logs and screenshots; AirTee extracts time-stamped, cited claims you accept onto the incident timeline.

02
Instant Posture import

Bring existing BIA and BCP documents; AirTee drafts services, dependencies and recovery objectives for you to review and commit.

03
AI governance module

An inventory of your own AI systems mapped to the EU AI Act, ISO/IEC 42001 and NIST AI RMF.

04
Bring your own AI keys

Route AirTee's AI through your own Gemini, OpenAI or Anthropic account, or run it locally with Ollama.

04Inside the product

The GRC-A Preparedness Dashboard.

One pane for Governance, Risk, Compliance and Audit. Overall readiness, lifecycle stages — preparedness, operational, remediation — and resilience maturity, all weighted by organisational impact.

AirTee GRC-A Preparedness Dashboard — overall readiness 49%, lifecycle stages for preparedness, operational and remediation, and resilience maturity composite across six dimensions.
FIG. 01 · GRC-A PREPAREDNESS DASHBOARD · OVERALL READINESS 49%
FAQ

Quick answers

Is AirTee a GRC tool?
No. AirTee is a system of action: it runs incidents and exercises in the same workspace where it stores plans and risk. GRC platforms like Archer or Riskonnect are systems of record — necessary, but not what AirTee replaces.
Do we need to rip-and-replace ServiceNow?
No. AirTee complements ITSM. We subscribe to ServiceNow events and write incident records back. Many customers run AirTee on top of ServiceNow.
What about our existing impact assessment spreadsheets?
We import them. The first pass is automated; we sit with you to validate the dependency graph in week 2.
— next step

See AirTee in your environment.

We'll model one of your real scenarios live.