53 Controls. Seven Frameworks. Evidence That Generates Itself.
Compliance evidence accumulates continuously as developers work - signed, drift-monitored, and exportable in one click when the auditor asks.
Auditors Started Asking About AI
SOC 2, ISO 27001, NIST, and now the EU AI Act all ask what AI systems an organization runs, who uses them, what data reaches them, and what controls sit in between. Most teams answer with a spreadsheet assembled the week before the audit.
The underlying evidence exists - it is scattered across endpoints, chat logs, and API bills. Kraitos AIDR collects it as a byproduct of running the platform, so the audit becomes an export rather than a project.
Frameworks, Evidence, Drift, Attestation
Seven frameworks
- SOC 2
- ISO 27001
- NIST 800-53
- PCI DSS 4.1
- HIPAA
- NIST AI RMF
- EU AI Act
Framework scope
| Framework | Identifier | Scope |
|---|---|---|
| SOC 2 | soc2 | Trust Services Criteria - CC6.1, CC6.6, CC6.7, CC6.8, CC7.1, CC7.2, CC7.3, CC8.1 |
| ISO 27001:2022 | iso27001 | ISMS Annex A - A.5.9, A.8.3, A.8.7, A.8.8, A.8.9, A.8.15, A.8.16, A.8.20, A.8.22, A.8.28 |
| NIST 800-53 Rev 5 | nist-800-53 | AC-2, AC-6, AU-2, AU-6, CM-5, CM-8, CM-11, IR-6, SA-11, SC-7, SI-3, SI-4, SI-7 |
| PCI DSS 4.1 | pci-dss-4.1 | 1.3.2, 3.4.1, 5.2, 5.3.3, 6.3.1, 7.2.2, 10.2.1, 11.5 |
| HIPAA Technical Safeguards | hipaa | 45 CFR §164.312 - (a)(1), (a)(2)(iv), (b), (c)(1), (e)(1) |
| NIST AI RMF | nist_ai_rmf | AI risk management functions |
| EU AI Act | eu_ai_act | Risk-tier classification and register obligations |
Selected control mappings
- SOC 2 CC6.1
- Logical access controls - AI tool access logs, policy enforcement records, MCP allowlist enforcement
- SOC 2 CC7.2
- System monitoring - real-time alerts on policy violations via Slack, email, and webhook
- ISO A.8.16
- Monitoring activities - real-time AI conversation telemetry across every endpoint
- ISO A.8.28
- Secure coding - per-repo AI config enforcement via managed CLAUDE.md and .cursorrules
- NIST SI-4
- System monitoring - continuous behavioral and network monitoring with MITRE ATT&CK mapping
- NIST CM-8
- System component inventory - full hardware, software, extension, and AI tool inventory
- PCI 5.2
- Malicious software prevention - native malware scanner, YARA, IOC matching, quarantine
- HIPAA §312
- Technical safeguards - access control, disk encryption checks, audit trails, FIM, network monitoring
The evidence engine
- Coverage computation - each control resolves continuously to proven, partial, or unproven from live fleet data
- Signed evidence bundles - cryptographically signed so an auditor can verify the bundle was produced by the platform and not altered
- Drift detection - when a proven control loses its evidence, an alert fires immediately rather than at the next audit
- Coverage gap analysis - the dashboard shows which controls lack evidence and what would satisfy them
- Control ownership - named owners per control, per framework, with timestamped attestation
- Scheduled reports - daily, weekly, or monthly cadence with automated delivery
AI Register - EU AI Act and NIST AI RMF
An inventory of every AI system in use, auto-populated from fleet discovery and manually extensible. Auto-discovered systems land as shadow / unclassified and enter the review queue.
| Field | Values |
|---|---|
| Risk tier | prohibited · high · limited · minimal · unclassified |
| NIST impact | high · moderate · low · unset |
| Approval status | approved · review · shadow |
| Discovery | auto (found by the agent) · manual (added by an admin) |
Per-Framework Coverage


See Kraitos AIDR in Action
Deploy in 60 seconds. Get answers in 24 hours. Stop guessing what your AI-augmented organization is doing.
[email protected]kraitos.io