Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideUse natural language to get PurpleWASP product guidance, inspect authorised posture and records, follow relationships and continue from the current conversational subject.
Use normal business language rather than trying to describe database fields. Questions such as “Show me our high risks”, “Which Controls cover those Assets?” or “What Compliance work is overdue?” let PurpAI resolve the relevant authorised PurpleWASP context.
PurpAI can answer product-guidance questions such as “How do I create a Risk?”, “How do I add a Control?” or “How do I manage the SoA?”. These answers are grounded in the PurpleWASP Help Centre and can include a safe link into the owning workflow.
PurpAI follows supported PurpleWASP relationships rather than guessing from similar names. Examples include Risk → Controls, Control → Assets, Asset → Controls, Third Party → Risks/Assets, SoA → Controls and supported Compliance → Evidence relationships.
PurpAI keeps bounded conversational lineage. After a result set is returned, phrases such as “those”, “the second one”, “its evidence”, “previous controls” or “the original risks” can continue from the current or earlier subject when the reference is unambiguous.
If several records are in the current result and you say only “open it”, PurpAI will ask which record instead of choosing one silently.
PurpAI preserves important PurpleWASP distinctions. Current Risk and residual Risk are different; a catalogue Control and an adopted organisation Control are different; TPRM tiering and linked Risk severity are different; and the authoritative Compliance Score remains owned by the Compliance Dashboard.