Skip to content
PlatformAI compliance software

AI compliance software backed by operating evidence

Turn AI inventory, policy decisions, approvals and audit events into continuous evidence that can be mapped to the EU AI Act, NIST AI RMF, ISO 42001 and internal controls.

The problem

What this is actually about

A framework mapping says what a control should do. An auditor still needs to know which systems it covered, when it operated, what it decided and whether exceptions were resolved. Periodic screenshots and questionnaires decay between collection cycles.

Continuous compliance starts with the operating record: inventory changes, ownership, certification, policy versions, approvals, denials, incidents and remediation. Those facts can be mapped to several frameworks without pretending the software itself grants certification.

What the platform does about it

Read from the product architecture rather than written here, so this page cannot promise something no module ships.

Agent Trust Compliance

Can we prove any of this to an auditor?

  • Mapping to NIST AI RMF, ISO 42001, SOC 2 controls and internal AI policy
  • Control evidence computed from live state rather than asserted
  • Continuous monitoring of ownership, permission reviews, approved models, incidents and certification status
  • A generated audit package covering inventory, owners, permissions, approvals, testing, policies, incidents and access reviews
  • An optional customer-facing trust centre that publishes the programme without exposing infrastructure
Agent Trust Audit Ledger

What is the record, and can it be trusted?

  • An append-only record of agent, user, session, resource, action, policy, decision, tool, model, result and risk
  • Customer-configurable retention from 30 days to seven years
  • Tenant isolation on every record, so no agent can read across the boundary
  • Event-driven telemetry that keeps the authorization path fast and synchronous while analytics runs behind it
Agent Trust Assurance

Has it been tested, and is it still the version we approved?

  • Security tests for prompt injection, privilege escalation, data leakage and unsafe external calls
  • Permission tests that try to exceed the role and cross the tenant boundary
  • Tool behaviour tests for dangerous calls the task never required
  • Regression testing between agent versions
  • Certification from development through internal, approved, production and high-risk
  • Recertification when the model, prompt, tools, MCP servers, permissions, data sources or owner change
Agent Trust Policy Engine

Under which rule was this decided?

  • Rules authored in natural language, compiled to structured policy, and verified by a human before activation
  • Conditions over agent, owner, department, tool, action, resource, data class, geography, environment, time, risk, user, transaction value and tenant
  • Simulation against historical traffic, so a rule states what it would have blocked before it blocks anything
  • Versioned policy, with every decision recording the version that produced it

What it leaves behind

The artefacts these modules produce. Evidence generated by a decision, rather than assembled for an audit afterwards.

  • A control-by-control coverage figure with the gap named
  • An audit package generated on demand
  • The evidence every other module cites
  • A retention position the auditor can check
  • A certification record per agent version
  • A diff between versions with the resulting risk change
  • A simulated impact figure before activation
  • A policy version stamped on every decision

See it working

Every claim above has somewhere on this site you can go and check it.

Common questions

Does the software certify ISO 42001 or EU AI Act compliance?
No. Certification and legal conformity require qualified independent judgment. The platform supplies governed inventory, control operation and evidence that support that work.
What makes compliance continuous?
Evidence is produced when the system changes or makes a decision, not assembled only before an audit. Control status can therefore reflect the current estate.
Can one control map to several frameworks?
Yes. The operating fact remains the same while mappings explain how it supports NIST AI RMF, ISO 42001, EU AI Act or internal policy requirements.