Compliance

Every framework your regulator tests — as running evidence.

APRA, the DPDP Act, the EU AI Act, Singapore’s governance framework, ISO 42001 and the leading AI-security standards — mapped continuously from live telemetry and exported as PDF + JSON.

Regulatory coverage

Built for the regulators that matter.

From Australian prudential rules to the EU AI Act and Singapore’s framework — every obligation mapped to the controls your auditor tests.

AU

APRA CPS 234

Information-security capability, control testing and incident response for APRA-regulated entities.

AU

APRA CPS 230

Operational resilience and critical-operation controls.

AU

Privacy Act / APP

The Australian Privacy Principles and the reformed privacy regime.

AU

SOCI Act

Security of Critical Infrastructure obligations.

IN

DPDP Act 2023

Consent, data-fiduciary duties, erasure and cross-border transfer.

EU

EU AI Act

Risk-tiered obligations for AI systems placed on the EU market.

SG

Singapore MGF

Singapore’s IMDA Model AI Governance Framework for responsible AI.

ISO

ISO/IEC 42001

The international AI management-system standard.

Australia

APRA CPS 234 & CPS 230.

Every AI interaction mapped to the prudential controls your auditor tests — information-security capability, control testing, incident response and operational resilience — generated continuously, not assembled the week before review.

CPS 234information securityCPS 230operational resilience
apra · evidence chaincontinuous
§17(b) classification
PASS
§18–23 controls
88%
§32–34 incident
GAP
CPS 230 resilience
79%
dpdp · data principalmapped
§5 notice & consent
94%
§8 data fiduciary duties
90%
§12(b) erasure
DONE
cross-border transfer
81%
India

DPDP Act 2023.

AI governance aligned to the Digital Personal Data Protection Act — consent, data-fiduciary duties, erasure and cross-border transfer — for enterprises operating across the AU–India corridor.

AI security frameworks

Mapped to the standards your auditors and red teams use.

Beyond regulation — the assurance and threat frameworks that prove your AI is tested, not just documented.

NIST

NIST AI RMF

Govern · Map · Measure · Manage — the US AI risk-management framework.

OWASP

OWASP Top 10 for LLMs

Prompt injection, sensitive-data leakage, supply chain and the rest of the LLM top-10.

MITRE

MITRE ATLAS

The adversarial threat landscape for AI — TTPs mapped to your estate.

SOC

SOC 2

Trust-services criteria for security, availability and confidentiality.

Request a briefing

Govern your AI before your regulator asks.

A 30-minute walkthrough of the Trust Index, the three observation modes and your regulator’s evidence chain — on your estate.