What tools are your people actually using to get work done with AI, and does anyone know? Tangerin AI is the independent AI governance platform built to answer that question for organizations of any size, not just in Brazil but around the world. Sanctioned or not (the latter being what's commonly called Shadow AI), every AI tool in use gets discovered, assessed for risk, brought under policy, and backed by evidence an external auditor can check. Detection runs two ways: a small agent on Windows, macOS and Linux endpoints, or an agentless route that reads existing NGFW, SSE and SIEM logs. Whatever comes in gets checked against a constantly updated catalog of thousands of AI tools, each one carrying its data risk level, where it processes data, how long it retains it, and whether it trains on customer data. From there, policy marks each tool allowed, restricted or banned; staff sign off on the AI usage policy digitally; and more than twenty regulatory frameworks, NIST AI RMF and SOC 2 among them, alongside LGPD, ISO 42001, the EU AI Act and GDPR, are covered with automatic evidence mapping between equivalent frameworks and a dedicated view for outside auditors. What gets logged is which tool, by whom, when, and on which machine. Conversation content, prompts, and files never do; that line was drawn in the architecture, not left to a settings toggle.