.agent community
  • Map
  • Events
  • About
HomeMemberCrisol
See poster
.agent

The open community of the people building the agentic web. Open standards, open work streams, and a public map of members. Also the applicant for the proposed .agent top-level domain, pending ICANN approval. Operated by Open Agent Registry, Inc.

Discover
  • Map
  • Events
  • Team
  • Members
Mission
  • About
  • Why join
  • Brand
  • Blog
Build
  • Docs
  • Developers
  • AID spec
  • Glossary
  • Governance
  • Lists
  • GitHub
  • npm
Legal
  • Charter
  • Terms
  • Privacy
  • Contact
  • ICANN-safe copy
© 2026 Open Agent Registry, Inc. · .agent is a proposed TLD, pending ICANN approval.
EN·v2026.04
Map·Crisol
Crisol

Crisol

La IA ya entró a tu empresa. La pregunta es si la estás viendo.

See the posterShareable periodic grid→
Member since
2026
Team
1-10

Links

  • crisol.studio
Role in the agent ecosystem

Crisol is active in the governance and security layer of the AI agent stack. Their relevance to the ecosystem is defined by their role as an auditor and implementer of internal agents. They focus on the 'Day 2' problems of agent deployment: once an agent is connected to internal data, how do you ensure it doesn't leak sensitive information or exceed its authorized permissions?

They matter to the agent ecosystem because they provide the frameworks (based on OWASP and NIST) necessary for corporate adoption of agentic workflows. By auditing existing agents for 'prompt injection' and 'tool abuse,' they serve as a critical checkpoint for companies that are moving beyond simple chatbots toward agents that can perform actions within internal systems. Their work helps bridge the gap between agent experimentation and enterprise-grade deployment.

About

The reality of internal adoption

Crisol operates on the premise that AI adoption in the enterprise is not a pending decision for leadership, but a current reality driven by employees. They frame this as "Shadow AI"—the informal use of personal accounts on platforms like ChatGPT and Claude to process sensitive corporate data. The company's entry point is visibility. Rather than banning these tools, which they argue is often futile, they provide a methodology to map where AI is already being used, which departments are most active, and what specific data—such as financial records or PII—is being exposed.

A studio approach to governance

The company structures its service into three distinct phases: ordering, automating, and auditing. This "studio" model is less about selling a standardized SaaS platform and more about providing a controlled implementation of AI. The first phase, Shadow AI Control, results in a document that leadership can read and IT can implement. It categorizes risks across Finance, Legal, HR, Marketing, IT, and Operations, providing immediate recommendations such as migrating users from personal accounts to approved corporate instances with protected data.

Workflow over magic

Crisol is notably skeptical of the industry's focus on fully autonomous agents, which they dismiss as "magic agents." Instead, they emphasize "AI Process Automation." This involves identifying repetitive manual tasks—like classifying support tickets or extracting data from financial reports—and building workflows that use AI only where it adds measurable value. Their philosophy is to keep workflows simple and prioritized by utility rather than following tech trends. They emphasize that if a process doesn't benefit from AI, they will advise against its implementation during the initial discovery phase.

Security and auditing

For organizations that already have AI agents in production, Crisol provides a dedicated security audit layer. This service evaluates existing systems for vulnerabilities specific to Large Language Models, including prompt injection, RAG (Retrieval-Augmented Generation) leakage, and tool abuse. Their audits are aligned with industry standards like the OWASP LLM Top 10, ISO/IEC 42001, and the NIST AI Risk Management Framework. The output is a remediation plan that prioritizes findings by severity and probability, ensuring that internal agents operate within authorized data boundaries.

Leadership and reach

Founded by Franco Perez, the firm markets itself to non-technical directors who need to make high-stakes decisions about AI without needing a background in software engineering. Their "Director's Criteria" guide is a central part of their positioning, helping executives identify the "smoke signals" of risky AI use and establish boundaries for sensitive internal data. While the company provides services in both Spanish and English, its branding suggests a focus on providing high-touch, studio-level consultancy for firms that cannot afford the security risks of unmanaged AI experimentation.

Products
#01

AI Enablement & Shadow AI Control

Mapping and managing informal AI tool usage within an organization.

#02

AI Security Audit

Auditing AI agents and processes already in production for security vulnerabilities.