Compliance & Evidence

Evidence an auditor will actually accept.

A hash-linked, Ed25519-signed audit chain — not a folder of screenshots.

A chain of hash-linked isometric evidence blocks ending in a glowing cryptographic signature seal
How it works

From record to verified evidence in four stages.

  1. 01

    RECORD

    Every decision, policy change and guardrail verdict is written as a hash-linked entry.

  2. 02

    SIGN

    Exports are signed with Ed25519 so recipients can verify origin and integrity.

  3. 03

    VERIFY

    Anyone with the public key can recompute the chain and confirm nothing was altered.

  4. 04

    SHARE

    Auditors get a scoped, read-only portal. Internal teams use the evidence locker.

Capabilities

What it does.

CE-01

Tamper-evident audit chain

Hash-linked entries make it computationally obvious if a single record is changed or deleted.

CE-02

Ed25519-signed exports

Every export bundle carries a signature and includes the public key needed to verify it.

CE-03

Auditor portal

A scoped, read-only external role that lets auditors browse evidence without seeing production data.

CE-04

Evidence locker

Collected artifacts, campaign results and policy snapshots stored in one governed location.

CE-05

Access trail and audit log

Who viewed, exported or modified what — with timestamps and identity attribution.

CE-06

Exportable PDF reports

Board, auditor and regulator-ready reports generated from live evidence in seconds.

CE-07

AI readiness assessment

A structured evaluation of governance, risk and control maturity against leading frameworks.

CE-08

SEC incident materiality decision tree

Walk through the SEC cybersecurity disclosure logic with documented rationale at each node.

CE-09

Privacy operations

DSR intake and handling workflows plus ROPA records for privacy teams.

In practice

One entry, one hash.

policy · verdictlive

policy > "Export the last 90 days of runtime verdicts for auditor 'external-firm-2026'"

export_id: "exp-2026-0830-ce"

entries: 2,847,192

signed_with: "ed25519:pk-7d1a…e03b"

merkle_root: "sha256:9f4c…b21a"

chain_valid: true

recipient: "auditor/external-firm-2026"

access_expires: "2026-11-30T23:59:59Z"

verdict: "EXPORT_SIGNED_AND_DELIVERED"

Framework mapping
OWASP LLM Top 10NIST AI RMFMITRE ATLASISO/IEC 42001EU AI ActGDPRSEC cybersecurity disclosure

Controls and evidence are mapped to the frameworks that govern your AI risk.

Framework coverage

Mapped to the standards that matter.

FC-01

OWASP LLM Top 10 (2025)

Runtime guardrails map directly to LLM01 Prompt Injection, LLM02 Sensitive Information Disclosure and LLM06 Excessive Agency.

FC-02

NIST AI RMF

GOVERN, MAP, MEASURE and MANAGE are covered by governance workflows, data posture, continuous measurement and inline controls.

FC-03

MITRE ATLAS

Red-teaming probes and runtime detections align with adversarial tactics, techniques and procedures in the ATLAS matrix.

FC-04

ISO/IEC 42001

AI management-system requirements are supported by policy lifecycle, risk assessment and evidence management.

FC-05

EU AI Act

Risk classification, governance documentation, transparency and post-market monitoring evidence are produced automatically.

FC-06

GDPR

Data-flow mapping, DSR handling, ROPA records and PII detection in prompts support privacy-by-design obligations.

FC-07

SEC cybersecurity disclosure

Incident materiality decision tree and timeline evidence help disclose material AI security incidents with defensible rationale.

FC-08

AIUC-1

AI usage and control evidence is collected continuously for internal AI use-case governance and review.

Honesty note

SOC 2 Type II is in progress. We will publish the report here when it is issued — we will not claim it before then.

Next step

See it run against your own prompts.