AI compliance software backed by operating evidence
Turn AI inventory, policy decisions, approvals and audit events into continuous evidence that can be mapped to the EU AI Act, NIST AI RMF, ISO 42001 and internal controls.
The problem
What this is actually about
A framework mapping says what a control should do. An auditor still needs to know which systems it covered, when it operated, what it decided and whether exceptions were resolved. Periodic screenshots and questionnaires decay between collection cycles.
Continuous compliance starts with the operating record: inventory changes, ownership, certification, policy versions, approvals, denials, incidents and remediation. Those facts can be mapped to several frameworks without pretending the software itself grants certification.
What the platform does about it
Read from the product architecture rather than written here, so this page cannot promise something no module ships.
Can we prove any of this to an auditor?
- Mapping to NIST AI RMF, ISO 42001, SOC 2 controls and internal AI policy
- Control evidence computed from live state rather than asserted
- Continuous monitoring of ownership, permission reviews, approved models, incidents and certification status
- A generated audit package covering inventory, owners, permissions, approvals, testing, policies, incidents and access reviews
- An optional customer-facing trust centre that publishes the programme without exposing infrastructure
What is the record, and can it be trusted?
- An append-only record of agent, user, session, resource, action, policy, decision, tool, model, result and risk
- Customer-configurable retention from 30 days to seven years
- Tenant isolation on every record, so no agent can read across the boundary
- Event-driven telemetry that keeps the authorization path fast and synchronous while analytics runs behind it
Has it been tested, and is it still the version we approved?
- Security tests for prompt injection, privilege escalation, data leakage and unsafe external calls
- Permission tests that try to exceed the role and cross the tenant boundary
- Tool behaviour tests for dangerous calls the task never required
- Regression testing between agent versions
- Certification from development through internal, approved, production and high-risk
- Recertification when the model, prompt, tools, MCP servers, permissions, data sources or owner change
Under which rule was this decided?
- Rules authored in natural language, compiled to structured policy, and verified by a human before activation
- Conditions over agent, owner, department, tool, action, resource, data class, geography, environment, time, risk, user, transaction value and tenant
- Simulation against historical traffic, so a rule states what it would have blocked before it blocks anything
- Versioned policy, with every decision recording the version that produced it
What it leaves behind
The artefacts these modules produce. Evidence generated by a decision, rather than assembled for an audit afterwards.
- A control-by-control coverage figure with the gap named
- An audit package generated on demand
- The evidence every other module cites
- A retention position the auditor can check
- A certification record per agent version
- A diff between versions with the resulting risk change
- A simulated impact figure before activation
- A policy version stamped on every decision
See it working
Every claim above has somewhere on this site you can go and check it.
- Inspect framework mapping
See how one operating control maps to multiple governance obligations.
- Review evidence records
Inspect the trace left by policy decisions and lifecycle events.
- Review compliance capabilities
See the exact evidence and mapping outputs derived from the module model.
Common questions
- Does the software certify ISO 42001 or EU AI Act compliance?
- No. Certification and legal conformity require qualified independent judgment. The platform supplies governed inventory, control operation and evidence that support that work.
- What makes compliance continuous?
- Evidence is produced when the system changes or makes a decision, not assembled only before an audit. Control status can therefore reflect the current estate.
- Can one control map to several frameworks?
- Yes. The operating fact remains the same while mappings explain how it supports NIST AI RMF, ISO 42001, EU AI Act or internal policy requirements.