VerifyWise is a source-available AI governance platform that helps businesses use AI safely and responsibly, aimed at compliance, risk, security, and audit teams that must satisfy frameworks such as the EU AI Act, ISO 42001, NIST AI RMF, or ISO 27001 and want that work hosted on their own infrastructure.
What it is
VerifyWise is an AI governance platform written in TypeScript and published by Bluewave Labs under a source-available licence. It gives an organisation one place to inventory AI models, register AI use cases and their risks, manage policies from templates, track AI vendors and vendor risks, log AI incidents, and produce reports. It also includes LLM Evals and automations, with a dashboard split into an executive view and an operating view so leadership and day-to-day operators see different cuts of the same data. The project markets itself around a single idea: compliance and AI management without giving up control over where the data lives.
The concrete problem it solves is the manual work of assembling AI governance evidence. Instead of maintaining audits, risk registers, and assessment answers in spreadsheets across several teams, VerifyWise centralises them and generates AI answers for compliance and assessment questions, which shortens audits. It replaces the ad hoc mix of GRC spreadsheets and disconnected documents that organisations otherwise build when a framework such as the EU AI Act or ISO 42001 begins to apply to them.
Key capabilities
- On-premises or private cloud hosting, with deployment via Docker and Kubernetes and support for platforms such as render.com.
- Support for four frameworks in one system: EU AI Act, ISO 42001, NIST AI RMF, and ISO 27001.
- AI-generated answers for compliance and assessment questions, intended to shorten audit cycles.
- AI model inventory plus separate views for AI model risks and AI use case risks.
- AI policy manager with policy templates for drafting and maintaining governance policies.
- AI vendor and vendor risk tracking alongside AI incident management.
- User registration, authentication, and role-based access control, with an AI Trust Center and reporting module.
Who uses it and how
- Compliance and GRC teams mapping their AI estate against the EU AI Act, using the EU AI Act project view to organise that work.
- Risk and security functions registering AI use cases and models, then tracking the risks attached to each.
- Organisations required to keep AI data inside their own perimeter, using the on-premises or private cloud deployment path rather than a vendor-hosted service.
- Audit and assurance teams using the reporting module and AI-generated compliance answers as the evidence base for assessments.
- Platform teams deploying the stack to Docker, Kubernetes, or a PaaS such as render.com with RBAC configured per role.
Getting started
The README describes deployment through Docker and Kubernetes, optionally on render.com or a similar platform, with a hosted demo available at app.verifywise.ai. Documentation lives at verifywise.ai/user-guide, and the project runs a Discord channel for questions.
How it compares
No comparable products are named in the material provided for this entry, so VerifyWise stands alone in this registry on that basis. Comparisons should therefore be drawn from its own licensing and hosting model rather than from any set of paid alternatives described here.
When to use it — and when not to
Choose it if you need an AI governance system you can host yourself and you are willing to operate the deployment, its datastore, and its authentication stack, since the README does not spell out the supporting infrastructure you will have to run. The licensing needs checking before adoption: the repository metadata reports the licence as NOASSERTION while the README states BSL 1.1 with dual licensing available for enterprises, and the feature list in the README is truncated, so some advertised capability is described only in the linked user guide. Teams with 59 open issues to weigh and no appetite for self-hosting, or those wanting a conventional open-source licence, should look elsewhere.