Making AI risk legible to people who aren't AI experts
ARIA is a freemium B2B product that passively parses enterprise logs to surface AI risk — no agents, no proxies. That constraint is the product: nothing to deploy means no approval chain to wait on, and time-to-first-value is measured in minutes instead of quarters. The v3 prototype below is live — functional routing, realistic sample data, the full flow.
Landscape
I researched the adjacent players — Microsoft Defender for Cloud Apps, Skyhigh Security, Forcepoint ONE SSE. All of them assume deployment: agents on endpoints, traffic through proxies, gateways rewired. The gap was a tool that tells you where you stand before you install anything — and that gap is the product ARIA became.
The pitch — three steps, three minutes
The marketing site makes the promise the product has to keep: upload your logs, ARIA listens and scores, get a defensible risk report. No professional services, no onboarding.


A dashboard that answers “am I okay?” first
The Risk Dashboard leads with one number — the Enterprise Risk Score — and why it moved, before anything else. Four finding tiles carry the headline counts (active AI users, unsanctioned apps, exfiltration sequences, autonomous agents); everything below is drill-down, not competition.

A taxonomy people can hold in their head
Every AI tool ARIA detects is Sanctioned, Unsanctioned, or Inventory — three words an admin can defend in a meeting, instead of a scoring formula nobody remembers. The catalog makes the status the loudest column, and tagging an app sanctioned is how shadow IT officially stops being shadow.


Assessments you can trust because they don't move
ARIA's assessments are immutable: every run is preserved with its score, sources, and author — re-running produces a new assessment beside the old one, never a silent rewrite. The person who cited a report is never contradicted by the tool a week later, and the history itself becomes the risk-over-time story.

Upload without fear
The new-assessment flow does the technical work itself: drag in CSV, JSON, NDJSON, or LOG files and ARIA auto-detects the source from filename and headers. The privacy posture is stated where the anxiety happens — raw logs stay on your network; only selected fields are sent.
