This tool turns a description of one AI agent into the control set that applies to it, with verification methods and a mapping to the framework you choose. It takes about fifteen minutes.
Before you start. Nothing you type is stored. Each question and your answer to it are sent to a language model to interpret your reply; no earlier answer and no catalogue content go with it. When the session ends, the log holds a timestamp, your voucher, the outcome and the resulting band, and nothing about your agent.
Terms, privacy and licence — the detail behind that paragraph
What this tool produces
You answer twenty six questions about one agent. Those answers resolve a consequence band and a control set from the NPW Agentic AI Control Catalogue. The tool assesses one agent at a time. It does not discover agents, hold a registry, or look at anything you have not typed into it.
The language model, and what reaches it
The model is openai/gpt-oss-20b, an open-weights model served by Groq under Groq's terms. It carries another organisation's name because of who trained the weights; the privacy position rests on the provider serving it, not on that name.
Its only job is to read your answer to one question and propose a value for the single field that question derives. It selects no control, computes no band, and answers no question you ask it.
Each call carries one question, its definition from the catalogue, and your latest answer to it. Nothing else: no earlier answer, no other question, no control text, and no name for your agent unless you typed one into that answer. Groq does not retain inference data by default and does not train on customer inputs or outputs; it holds troubleshooting and abuse logs for up to thirty days.
If the model is unavailable, or if you would rather not use it, the whole intake runs on plain multiple-choice controls and produces an identical result.
What is stored, and what is not
No answer you give is written to disk at any point. Your answers live in this browser tab and are posted back with each turn. Closing the tab ends the session and leaves nothing behind. There is no resume, and no link that reopens a result.
One log row is written per session: a timestamp, the voucher code presented, the outcome, the catalogue version, and — on completion — the resulting band. That is a single letter and number. No property, no dimension score, no control set, no free text, and nothing identifying you or your organisation.
No account, no email address, no password. No cookie beyond a session cookie that carries nothing. Traffic is TLS only.
This is not advice
The result is generated from a profile you declare and is not independently verified by New Pacific Way Limited. It is provided for governance planning, and is not legal, regulatory, compliance or security advice. It reflects the catalogue version and the answers stated on the result page only; a change to either changes the result. New Pacific Way Limited accepts no liability for actions taken or omitted on the basis of it.
Licence
The control statements, what each addresses, where each is implemented, the verification method and the source basis are published by New Pacific Way Limited under CC BY-SA 4.0. You may use and adapt them with attribution, under the same licence.
The applicability expressions, the band derivation, the consequence profile and the intake design are proprietary and are not covered by that licence. They are shown as part of the result you have been granted access to, not as a licensed artefact.
Your voucher
A voucher grants access and carries no identity. It is not a password. It may be used more than once and by more than one person, and the number of sessions run against it is visible to New Pacific Way. Failed attempts are logged and rate limited.
Contact
New Pacific Way Limited, 2/F Tern Centre, Tower 1, 237 Queen's Road Central, Hong Kong SAR. Anything about this tool, the catalogue or your result: sales@npw.ltd.