AI vendor risk, mapped and proven for your regulator
Be the island that doesn't go dark
when your AI model does.
Most AI gateways only fail over between providers you've already configured. RapaNui finds the ones nobody mapped — then turns that map into the dependency register, concentration-risk report, and audit trail your regulator actually asks for. Think of RapaNui as an AI agent that hunts down your hidden dependencies and acts the moment one fails — not a dashboard you have to watch.
The problem
A vendor's uptime promise is not a disaster plan.
A year ago, most companies depended on one AI provider for a handful of features. Today it's several — a model here, an API there, a vendor a team plugged into a critical workflow without telling anyone it had become load-bearing. For a bank, insurer, or asset manager, that vendor now sits inside the perimeter DORA and the EU AI Act expect you to have mapped.
None of it shows up in a traditional continuity plan — and routing across providers isn't a substitute for one. Most AI gateways only fail over between the dependencies you've already told them about. So when a provider deprecates a model, a region goes dark, or an export control cuts off a vendor overnight, most teams find out by watching something break in production, with no register, no tested exit strategy, and no evidence to show a regulator afterward.
The solution
Discovery first, then a plan that's actually been tested
Most tools route between dependencies you've already told them about. RapaNui starts a step earlier — finding what nobody configured — then turns it into the dependency register, concentration-risk report, and tested exit strategy your regulator expects.
Discovery, not just routing
We find what nobody configured
Most tools swap between models you've already told them about — including the AI gateway you already run. RapaNui reads that as one input, then classifies network egress to model and inference endpoints, scans code for SDK and API-key patterns, and flags billing line items with no matching entry in the register — until the dependency graph behind your critical workflows has nothing left to surprise you.
Continuous monitoring
We watch the dependencies so you don't have to
Every model, provider, and region on the map is tracked around the clock — including regulatory and geopolitical risk, not just uptime. Degradation gets flagged before it becomes an outage.
Scheduled drills
Proven, not just planned
Every fallback path is tested on a schedule — a real simulated failure, not a tabletop exercise — and logged automatically, building the audit trail your regulator will ask for before you ever need it live.
The product
See what the map actually looks like
This is a simplified view of the actual RapaNui dashboard — built on top of the AI gateway you already run, not instead of it. Watch the agent scan the map, test a fallback, and fail over on its own.
Audit log — every drill, on record
15 minutes, run against a sample of your actual stack.
Under the hood
Finding an undeclared dependency is the hard part
Routing is a config problem — you already know what to route to. Discovery is a signal problem: three independent sources, cross-referenced, catch what any one of them alone would miss.
Network egress
Classifying outbound calls
Traffic to model and inference endpoints gets classified by provider and model family in real time, even when nobody registered the integration.
Code & SDK scanning
Reading what engineers actually shipped
Repositories are scanned for SDK imports, API keys, and prompt-construction patterns that reveal a model call no ticket ever mentioned.
Billing anomalies
Spend that doesn't match the register
A new line item on a provider invoice with no matching entry in the dependency register gets treated as a finding, not noise.
The value
What resilience actually buys a business
Not just uptime — a defensible answer to the question every board and every regulator eventually asks.
Continuity, proven
A tested plan instead of a promise
When something breaks, your team isn't improvising — it's running a fallback that's already been tested and logged, across models, providers, and regions.
Audit-ready
Evidence for the board, the regulator, the auditor
Every drill and every failover is on record — the dependency register and concentration-risk evidence DORA and the EU AI Act expect you to produce, not a reassurance.
No single point of failure
Resilience across providers, not inside one
Fallbacks span models, providers, and countries — the concentration-risk picture regulators ask for — so one company's outage, or one government's export control, isn't your outage.
Who we work with
Built for industries where "we didn't know" isn't a defense
RapaNui is used by risk and compliance teams in sectors where an unmapped AI dependency is a regulatory finding, not just an outage.
Financial services
Banks, insurers, investment firms
DORA-bound entities mapping AI vendor concentration risk and maintaining a tested exit strategy for critical ICT providers.
Healthcare & life sciences
Providers, payers, and pharma
Clinical decision support and diagnostic AI sit inside the EU AI Act's high-risk category, alongside patient-safety obligations that don't forgive an untested fallback.
Insurance
Underwriting and claims
Pricing and claims models are named explicitly under the EU AI Act's high-risk annex — RapaNui keeps the register a supervisor will ask to see.
Legal & professional services
Firms running AI-assisted work
Research, drafting, and review tools need the same audit trail a client or regulator would expect from any other part of the file.
Critical infrastructure & energy
Utilities and operators
Operational AI embedded in grid, transport, or plant systems carries safety-component obligations under the EU AI Act's Annex III.
Public sector
Government and public administration
Public-facing AI use is high-risk by default — RapaNui gives agencies the same provable dependency map their private-sector vendors already need.
The process
Live in a few hours. Then it never stops.
The first map takes a few hours to build and prove. After that, RapaNui keeps scanning — because dependencies don't stay mapped on their own.
01
Hour 1
Map
We trace every model, vendor, and API your critical workflows depend on — including the ones nobody remembers signing up for — and turn it into your dependency register.
02
Hour 2
Break it on purpose
We simulate the failures that matter: a deprecated model, a regional outage, a vendor gone dark without warning.
03
Hour 3
Build the way around
Engineers build the redundancy and degraded-mode paths your systems fall back to — working code, not a diagram.
∞
From day one
Map, drill, repeat — automatically
The scan never stops. New dependencies get added to the register the moment a team adopts them, fallbacks get re-tested on a schedule, and the audit log keeps growing — with no second engagement required.
Get started
Map your dependencies
Tell us what your critical workflows run on. We'll show you where a single model or vendor outage would take you down — and what your dependency register and concentration-risk report would need to say to a regulator today.