Quality & Safety tools

A collection of demonstration tools around standards compliance and information security. Each one really runs — nothing is simulated.

Tools
Online

QualityCrew

Compliance audit by AI agents. Four agents analyse a documentation set in real time — requirements quality, test coverage, safety risks — and produce a structured report.

ASPICE SWE.1/SWE.2 ISO 26262 CrewAI
Run the demo
Online

SentinelScan

Information leak watch on public repositories. Enter your search terms, the tool identifies exposures and produces a downloadable report ranked by criticality.

ISO/IEC 27001 Passive OSINT GitHub API
Run a scan
Online

SafetyScope

Risk analysis and ASIL determination. Rating is a decision table: the answer is exact and immediate. AI steps in only as an option, to suggest hazardous events — never to rate them.

ISO 26262 Part 3 HARA No waiting
Flows on into ThreatScope Rate an item
Online

ThreatScope

Cybersecurity threat and risk analysis. Attack feasibility is rated on five criteria, and the risk follows immediately. The chain runs all the way to cybersecurity goals — a TARA produces requirements, not a number.

ISO/SAE 21434 TARA UN R155
Carries over the severity from your HARA Analyse the threats
Online

RegWatch

Watch on public signals around standards: revisions under way, publications, timetables. Attaching a signal to a standard is deterministic — no AI decides what comes up. Every source shows what it is worth.

Standards watch ISO · ASPICE · UN R155 Public sources
Never republishes the content of standards Run a watch
Online

CauseTrace

Customer complaint resolution following the 8D method. This tool does not fill in eight boxes: it refuses to call a case resolved when it is not, and says where it falls short — a missing cause, a why-chain that stops at an operator, a claimed closure.

8D · 5 Whys Ishikawa Public-domain methods
Requires the escape root cause, not just the occurrence one Open an 8D
Where we stand

Five of these six tools produce their result with no artificial intelligence at all. Determining an ASIL or a risk value are decision tables: the answer is exact and instantaneous. Refusing to close an 8D whose escape root cause is missing is a set of ordered rules. Attaching a watch signal to a standard is a written rule, reproducible and tested offline. Looking for an exposure on public repositories is an API and criticality criteria. Dropping a language model in would add nothing but latency and uncertainty.

Only one really depends on it: QualityCrew, where four agents write the audit — that is its whole purpose. Everywhere else AI stays optional: it sweeps guide words to prime a line of thought, or sums up in one sentence why a signal deserves attention. Never does it rate, never does it decide what is kept. Knowing when not to use an LLM is part of the craft.

RegWatch never republishes the content of a standard. These documents are paid-for and protected: the tool reports only the title, the date and the link to the source — the body of the pages is not even downloaded. And because not all sources are equal, every signal shows its own tier: an ISO committee is not a consultancy blog.

In CauseTrace the AI does not fill in: it asks. An 8D report goes to the customer; an invented fact there would be far worse than a clumsy sentence. So it tightens what the engineer wrote, and anything it would like to add without knowing — a date, a number of parts — becomes a question, never a value. An Ishikawa lead taken up arrives unqualified: it is the engineer who says what it is.

SafetyScope and ThreatScope talk to each other. The severity of a hazardous event becomes the « safety of persons » impact of a damage scenario. Exposure and controllability, for their part, do not cross: an attacker picks their moment, and can neutralise the driver's recourse.

Today's caps