One graph. Five modules. Every cycle makes you stronger.
AirTee.ai runs the whole resilience loop on a single dependency graph. That's the difference between a system of record and a system of action.
Your business, modelled once.
Services, dependencies, owners, vendors, controls, plans, exercises and incidents — all in one model. Every module reads from it, writes to it.
- ▍Critical services, ranked by impact and recovery objective.
- ▍Upstream and downstream dependencies.
- ▍Owners, deputies and on-call rotations.
- ▍Vendor concentration, contractual SLAs, exit-plan attestations.
- ▍Controls mapped to ISO 27001, ISO 22301, SOC 2, DORA, NIS2, NIST SP 800-61 and UK/EU GDPR.
- ▍Plans, scenarios and runbooks linked to the services they protect.
Five surfaces over one truth.
Live war room with AI-suggested actions, MITRE ATT&CK mapping on request, and regulator-clock automation.
Plans and impact analyses that update from real signal — incidents, exercises, dependency changes.
Vendor register linked to services, concentration and geographic risk analysis, review and evidence reminders.
Schedule, run and grade tabletops; AI generates scenarios and injects, grades responses, and drafts the AAR.
Drafts the AAR with timeline, root cause, decisions and regulator status; tracks action items to closure.
One library mapped to every framework you report on — kept current by the loop above.
A typical rollout.
Indicative sequence; we plan it with you.
- ▍Day 1–7: connect identity, ITSM, SIEM and one comms channel.
- ▍Day 7–14: import critical services + first impact assessment pass.
- ▍Day 14–30: AirTee runs your first guided tabletop.
- ▍Day 30–60: BCPs migrated, vendor profiles backfilled, board view live.
- ▍Dedicated single-tenant environments (UK, EU or US region) available on the Enterprise plan, provisioned by our team.
What else ships with AirTee.
Upload transcripts, vendor reports, logs and screenshots; AirTee extracts time-stamped, cited claims you accept onto the incident timeline.
Bring existing BIA and BCP documents; AirTee drafts services, dependencies and recovery objectives for you to review and commit.
An inventory of your own AI systems mapped to the EU AI Act, ISO/IEC 42001 and NIST AI RMF.
Route AirTee's AI through your own Gemini, OpenAI or Anthropic account, or run it locally with Ollama.
The GRC-A Preparedness Dashboard.
One pane for Governance, Risk, Compliance and Audit. Overall readiness, lifecycle stages — preparedness, operational, remediation — and resilience maturity, all weighted by organisational impact.

Quick answers
- Is AirTee a GRC tool?
- No. AirTee is a system of action: it runs incidents and exercises in the same workspace where it stores plans and risk. GRC platforms like Archer or Riskonnect are systems of record — necessary, but not what AirTee replaces.
- Do we need to rip-and-replace ServiceNow?
- No. AirTee complements ITSM. We subscribe to ServiceNow events and write incident records back. Many customers run AirTee on top of ServiceNow.
- What about our existing impact assessment spreadsheets?
- We import them. The first pass is automated; we sit with you to validate the dependency graph in week 2.
See AirTee in your environment.
We'll model one of your real scenarios live.