Shadow AI Governance

Do you know how many AI tools
your employees are using right now?

98% of companies don't. Tangerin AI detects thousands of tools, classifies by risk, and generates auditable evidence for LGPD, ISO 42001, BACEN and more — in under an hour.

14-day free trial15-minute setupData in BrazilCorporate email
dashboard live

Active Alerts

DeepSeek

WIN-JSILVA342

BLOCKED

ElevenLabs

WIN-MROCHA09

BLOCKED

ChatGPT

47 workstations

RESTRICTED

Cursor AI

12 workstations

RESTRICTED

GitHub Copilot

89 workstations

ALLOWED

5,600+ tools · updated now

98%

companies with ungoverned Shadow AI

Gartner, 2024

350%

growth in GenAI use at companies

McKinsey, 2024

+5.600

AI tools catalogued

Tangerin AI catalog

24

regulatory frameworks covered

BR + global

R$50M

maximum LGPD fine per violation

Law 13.709/2018

The real problem

Shadow AI doesn't ask permission. It grows every day, on every device.

Every employee who discovers ChatGPT expands your regulatory attack surface. Without visibility, there is no governance.

98%

of companies have undetected Shadow AI (Gartner, 2024)

Invisible to IT

Employees install ChatGPT, Claude, Cursor and DeepSeek without any approval. Processes run in the background. IT doesn't know — until something goes wrong.

$6,5M

average AI breach cost (IBM, 2025)

Regulators don't accept "I didn't know"

LGPD, the AI Act, and ISO 42001 require a proven inventory, formal policies, and auditable evidence. Auditors are demanding this now — not in 2027.

R$ 497

/mo — vs. R$80–200K for a one-off audit

The cost of the problem exceeds the solution

A one-time audit costs R$80–200K with consultants. An AI breach costs $6.5M on average. Tangerin AI costs R$497/month — and runs 24/7.

The good news: full visibility in under an hour. No mandatory endpoint agent, no analyst dependency, no sales meeting.

Start free →
How it works

Two paths. Same coverage.

Enterprise connects to the existing SIEM — zero endpoint installation. SMBs and technical teams install the lightweight agent for full process and browser coverage.

Via SIEM / NGFW

Enterprise · zero endpoint installation

01

Connect

Route your SIEM's CEF feed to Tangerin AI. One URL, one token. No agent, no endpoint infrastructure changes.

Palo Alto · Fortinet · Check Point · Netskope · Zscaler · Splunk · Sentinel

02

Visualize

Within minutes, see which AI tools are on the network — by user, department, and risk — feeding the same executive dashboard.

5,600+ tools · email/AD identity · allowed/blocked action

Via Agent

Full coverage · process, DNS and browser

01

Install

Deploy the lightweight agent to workstations in minutes. One-line script for Windows, macOS or Linux. No infrastructure changes.

Windows x64 · macOS Apple Silicon · macOS Intel · Linux x64

02

Discover

Automatic detection via processes, DNS, browser extensions, and software inventory. Every tool identified, categorized, and risk-classified.

5,600+ tools · 3 detection sources · risk badge per workstation

03

Classify

Mark each tool as Allowed, Restricted, or Blocked. Automatic alerts when a blocked tool is detected.

Email alerts · Department notifications

04

Prove

Executive reports, auditable evidence, and immutable compliance history. From CISO to board — each persona sees the detail level they need.

Executive PDF · Auditable score · Linked evidence

Both paths feed the same dashboard, the same AI Governance Score, and the same compliance evidence — and complement each other when you add the second.

01 — Detect

Every AI tool. Visible. Immediately.

Tangerin AI detects via SIEM/NGFW — zero endpoint installation — or via lightweight agent for full process, DNS and browser extension coverage. 5,600+ tools catalogued and classified by risk.

  • Two paths: SIEM (agentless) or lightweight agent
  • 5,600+ tools catalogued — one of the largest catalogs on the market
  • Risk badge per workstation: Critical · High · Medium · Low
  • Real-time alerts when a blocked tool is detected

Shadow AI detected

23 tools

DeepSeek R1

IA Generativa · 3 workstations

BLOCKED

ChatGPT

IA Generativa · 47 workstations

RESTRICTED

Cursor AI

Código · 12 workstations

RESTRICTED

Midjourney

Imagem · 8 workstations

RESTRICTED

GitHub Copilot

Código · 89 workstations

ALLOWED

Zapier AI

Automação · 6 workstations

RESTRICTED

02 — Prove

24 frameworks. Automatic evidence.

LGPD, EU AI Act, ISO 42001, BACEN 4.893, and 20 more frameworks — with automatic crosswalk. Execute one action and all equivalent standards are updated at the same time.

  • Automatic crosswalk between frameworks — no rework
  • RIPD / DPIA / AIIA generator with real environment data
  • AI usage policy with versioning and digital signatures
  • Immutable compliance history for SOC 2 Type II

Compliance by Framework

77% average
LGPDLei 13.709
87%
EU AI ActReg. UE 2024/1689
58%
ISO 42001ISO/IEC 42001:2023
71%
BACEN 4.893Res. CMN 4.893/2021
92%
ISO 27001ISO/IEC 27001:2022
81%

Active automatic crosswalk

Adding a vendor with DPA fills ISO 27001 A.5.19 · SOC 2 CC9 · PCI DSS 12.8 · HIPAA §164.308 — one action, four frameworks.

03 — Report

From endpoint to board. One click.

Shadow AI Risk Report in PDF — Executive, Technical, and Governance versions. Immutable history. Auditable score week by week. Ready for board, directors and auditors — generated automatically.

  • Executive report ready for board in PDF
  • AI Governance Score with week-by-week trend
  • Evidence automatically linked to each framework
  • Immutable history for SOC 2 Type II and audits

AI Governance Score

Maturity: Basic
63
Shadow AI Index78%
Compliance62%
Risk45%
One platform, three views

Speaks the language of operators, compliance officers, and decision makers

Each profile accesses the level of detail they need — without opening a ticket to IT.

For CISOs and IT

Technical visibility auditors expect

  • Complete inventory — software, extensions and AI startup items per workstation
  • Risk badge per workstation — Critical / High / Medium / Low
  • User identified with corporate domain (CORP\user)
  • 5,600+ tools classified by risk, category and detection source
  • Real-time alerts when a blocked tool is detected
  • Audit log of all administrative actions
For DPOs and Compliance

Continuous compliance with auditable evidence

  • 24 frameworks — LGPD, AI Act, ISO 42001, GDPR, PCI DSS and more
  • Automatic crosswalk: meet one control, propagate to all equivalents
  • RIPD / DPIA / AIIA generator with real environment data
  • Vendor registry with DPA status and training risk
  • Formal policy with versioning, approvals and digital signatures
  • Immutable compliance history for SOC 2 Type II
For C-Level and Board

Quantified risk, informed decisions

  • AI Governance Score with automatic executive summary for the board
  • Shadow AI Risk Report in PDF — ready for board and auditors
  • Maturity in 4 levels — Initial → Basic → Managed → Advanced
  • Prioritized action plan with estimated impact before execution
  • Week-by-week Shadow AI, risk and compliance trend
  • Mapped regulatory exposure — LGPD, AI Act and ISO 42001
Maturity journey

From zero to full control in 4 levels

Tangerin AI tracks and measures every stage — with real data, not subjective perception.

01

Initial

You have a complete map of your exposure. You know what is at risk.

02

Basic

Continuous monitoring. Risks reduced and trends under control.

03

Managed

Documented compliance. Auditable evidence for regulators.

04

Advanced

Governance as infrastructure. AI innovation done responsibly.

Sectors with the most urgency

Sector regulators are already demanding it. Do you have the evidence?

BACEN and ANS already have specific AI resolutions, and LGPD already applies today. This is not a future threat — it is a current requirement.

Financial

82%

of banks in Brazil already use generative AI (Febraban 2025)

Banking data leaving via ChatGPT = BACEN notification and risk of a R$50M fine.

BACEN 4.893SUSEP 638CVM 35LGPD

Typical price range: R$2,990–11,900/mo

Legal

55%

of Brazilian lawyers use GenAI (OAB 2025)

55% of Brazilian lawyers already use GenAI. Client confidentiality at risk without governance.

LGPDCNJ 332ISO 27001

Typical price range: R$497–2,990/mo

Healthcare

$7,4M

average healthcare breach cost (IBM 2025)

Medical records and diagnostics sent to tools without DPA. Healthcare breaches cost $7.4M on average.

ANS RN 452LGPDHIPAA

Typical price range: R$2,990–11,900/mo

Technology & SaaS

R$497

entry point — ROI in 30 days

Enterprise clients require AI governance evidence as a prerequisite for signing a contract.

ISO 27001SOC 2LGPDGDPR

Typical price range: R$497–2,990/mo

Compliance & Conformance

24 regulatory frameworks. One platform. Automatic evidence.

Continuous compliance for the leading AI, privacy and security standards — from Brazil and around the world.

Automatic crosswalk between frameworks

Different standards require the same thing — just with different names. Tangerin AI identifies equivalent controls and propagates automatically: you execute one action and all applicable standards are updated at the same time.

Practical example

Adding an AI vendor with a security assessment automatically fills ISO 27001 A.5.19 · SOC 2 CC9 · PCI DSS Req. 12.8 · HIPAA §164.308 — one action, four frameworks covered.

AI Governance & Ethics

7 frameworks

ISO 42001

ISO/IEC 42001:2023

EU AI Act

Reg. UE 2024/1689

PL 2.338

Lei Brasileira de IA

EBIA

Estratégia Bras. IA

NIST AI RMF

NIST AI 100-1

OCDE IA

Princípios OCDE 2019

UNESCO IA

Rec. UNESCO 2021

Privacy & Data

5 frameworks

LGPD

Lei 13.709/2018

GDPR

Reg. UE 2016/679

HIPAA

45 CFR 160/164

ISO 27701

ISO/IEC 27701:2019

Marco Civil

Lei 12.965/2014

Security & Audit

4 frameworks

ISO 27001

ISO/IEC 27001:2022

PCI DSS

PCI DSS v4.0

SOC 2

AICPA Trust Services

COBIT

COBIT 2019

Brazil Sectoral

6 frameworks

BACEN 4.893

Res. CMN 4.893/2021

SUSEP 638

Circ. SUSEP 638/2021

ANS RN 452

RN ANS 452/2020

CVM 35

Resol. CVM 35/2021

FEBRABAN

Autorregulação

CNJ 332

Resol. CNJ 332/2020

Corporate Compliance

2 frameworks

SOX

Sarbanes-Oxley

Anticorrupção

Lei 12.846/2013

Auditable inventory

Complete record of all detected tools with category, risk, and immutable history — the foundation for LGPD Art. 37 and ISO 42001.

Policy with lifecycle

Formal policy with automatic versioning, registered approver, review deadline, and digital signatures from collaborators.

Immutable history (SOC 2)

Compliance score calculated daily and preserved — demonstrates continuous improvement for SOC 2 Type II and audits.

Why Tangerin AI

AI governance as infrastructure — not as an audit checklist

Shadow AI is not a one-off compliance problem. It's an attack surface that grows with every new employee who discovers ChatGPT, Cursor or Zapier AI.

Tangerin AI treats governance as infrastructure: always active, always monitoring, always generating the evidence that regulators, auditors, and the board need to see.

Continuous governance, not point-in-time

No manual reports or annual audits needed. Runs 24/7 — alerts, evidence and reports generated automatically.

From technical to executive

A CISO sees events and inventory. A DPO sees frameworks and evidence. A CEO sees score and board report. One platform.

Privacy by design

The agent captures only usage metadata — which tool, when, by whom. Never accesses prompt content or documents.

Built for Shadow AI

Not a module added to another platform. A specialized solution — every detail designed to discover, assess and govern AI.

Transparent pricing

The right plan for your company size

14-day trial on any plan. No long-term contract on monthly. Annual plan with 8% discount.

Annual plan · 8% discount · ~1 month free

Starter

For companies starting AI governance. Immediate visibility.

R$ 497/mo

R$ 19,88/estação

R$ 5.468/ano

Até 25 estações
3 meses histórico
8 frameworks
1 admin
Start with Starter

14-day free trial · Corporate email

Business

Documented compliance and board-ready reports.

R$ 2.990/mo

R$ 11,96/estação

R$ 32.890/ano

Até 250 estações
12 meses histórico
16 frameworks
5 admins
Start with Business

14-day free trial · Corporate email

MAIS POPULAR

Enterprise

For large companies with multiple units and advanced compliance.

R$ 11.900/mo

R$ 7,93/estação

R$ 130.900/ano

Até 1.500 estações
12 meses histórico
24 frameworks
10 admins
Start with Enterprise

14-day free trial · Corporate email

Scale

Above 1,500 workstations. VPC deploy, multi-year contract.

Sob consulta

R$ 6 – 9/estação

Contrato plurianual

1.500+ estações
12 meses histórico
Deploy VPC
Contrato plurianual
Start with Scale

14-day free trial · Corporate email

Transparent pricing, no salesperson

Public pricing in reais and self-service signup. No negotiation, no sales proposal.

The only Brazil-localized solution

LGPD, BACEN, SUSEP, CNJ 332, PL 2.338. Portuguese interface. Price in reais.

Data in Brazil, privacy by design

Usage metadata only. We never read your employees' AI conversation content.

Get started now

Every day without visibility is a day of unmanaged risk.

Discover in under an hour how many unauthorized AI tools exist in your company — and what they represent in regulatory risk.

LGPD Compliant
Data in Brazil
Privacy by Design
15-minute setup