Skip to content
Compliance Automation

53 Controls. Seven Frameworks. Evidence That Generates Itself.

Compliance evidence accumulates continuously as developers work - signed, drift-monitored, and exportable in one click when the auditor asks.

The Problem

Auditors Started Asking About AI

SOC 2, ISO 27001, NIST, and now the EU AI Act all ask what AI systems an organization runs, who uses them, what data reaches them, and what controls sit in between. Most teams answer with a spreadsheet assembled the week before the audit.

The underlying evidence exists - it is scattered across endpoints, chat logs, and API bills. Kraitos AIDR collects it as a byproduct of running the platform, so the audit becomes an export rather than a project.

How It Works

Frameworks, Evidence, Drift, Attestation

Seven frameworks

  • SOC 2
  • ISO 27001
  • NIST 800-53
  • PCI DSS 4.1
  • HIPAA
  • NIST AI RMF
  • EU AI Act

Framework scope

Framework scope
FrameworkIdentifierScope
SOC 2soc2Trust Services Criteria - CC6.1, CC6.6, CC6.7, CC6.8, CC7.1, CC7.2, CC7.3, CC8.1
ISO 27001:2022iso27001ISMS Annex A - A.5.9, A.8.3, A.8.7, A.8.8, A.8.9, A.8.15, A.8.16, A.8.20, A.8.22, A.8.28
NIST 800-53 Rev 5nist-800-53AC-2, AC-6, AU-2, AU-6, CM-5, CM-8, CM-11, IR-6, SA-11, SC-7, SI-3, SI-4, SI-7
PCI DSS 4.1pci-dss-4.11.3.2, 3.4.1, 5.2, 5.3.3, 6.3.1, 7.2.2, 10.2.1, 11.5
HIPAA Technical Safeguardshipaa45 CFR §164.312 - (a)(1), (a)(2)(iv), (b), (c)(1), (e)(1)
NIST AI RMFnist_ai_rmfAI risk management functions
EU AI Acteu_ai_actRisk-tier classification and register obligations

Selected control mappings

SOC 2 CC6.1
Logical access controls - AI tool access logs, policy enforcement records, MCP allowlist enforcement
SOC 2 CC7.2
System monitoring - real-time alerts on policy violations via Slack, email, and webhook
ISO A.8.16
Monitoring activities - real-time AI conversation telemetry across every endpoint
ISO A.8.28
Secure coding - per-repo AI config enforcement via managed CLAUDE.md and .cursorrules
NIST SI-4
System monitoring - continuous behavioral and network monitoring with MITRE ATT&CK mapping
NIST CM-8
System component inventory - full hardware, software, extension, and AI tool inventory
PCI 5.2
Malicious software prevention - native malware scanner, YARA, IOC matching, quarantine
HIPAA §312
Technical safeguards - access control, disk encryption checks, audit trails, FIM, network monitoring

The evidence engine

  • Coverage computation - each control resolves continuously to proven, partial, or unproven from live fleet data
  • Signed evidence bundles - cryptographically signed so an auditor can verify the bundle was produced by the platform and not altered
  • Drift detection - when a proven control loses its evidence, an alert fires immediately rather than at the next audit
  • Coverage gap analysis - the dashboard shows which controls lack evidence and what would satisfy them
  • Control ownership - named owners per control, per framework, with timestamped attestation
  • Scheduled reports - daily, weekly, or monthly cadence with automated delivery

AI Register - EU AI Act and NIST AI RMF

An inventory of every AI system in use, auto-populated from fleet discovery and manually extensible. Auto-discovered systems land as shadow / unclassified and enter the review queue.

AI Register - EU AI Act and NIST AI RMF
FieldValues
Risk tierprohibited · high · limited · minimal · unclassified
NIST impacthigh · moderate · low · unset
Approval statusapproved · review · shadow
Discoveryauto (found by the agent) · manual (added by an admin)
Kraitos AIDR maps your evidence to these frameworks. It does not claim SOC 2 or ISO certification of the platform itself - the distinction is stated wherever coverage is claimed.
What You See

Per-Framework Coverage

Compliance coverage view showing the gap between claimed and proven control coverage with a per-control grid
Control coverage - the gap between claimed and proven coverage, with every control resolving to the evidence behind it.
AI system register listing discovered AI systems with risk tier, NIST impact, approval status, and device count
AI system register - every discovered AI system with risk tier, NIST impact, approval status, and how it was found.

See Kraitos AIDR in Action

Deploy in 60 seconds. Get answers in 24 hours. Stop guessing what your AI-augmented organization is doing.

[email protected]kraitos.io