Skip to main content
Pillar 2 · Posture + Prove

An Inventory Is Not Evidence. This Is.

An auditor asks four things: what AI do you run, who approved it, against which control, and can you prove the record wasn’t edited afterwards. This is the half of the overlay that answers the last two. Every finding tied to the control it touches, and the whole sequence written to a hash-chained log with a signed head.

Evidence ledger · hash-chained· example data
01 · Discovera91f…37c2
02 · Posture4d0b…ae19
03 · Gate77e5…10f4
04 · Provec3a8…9b6d
Signed head · Ed25519
An auditor verifies the chain after the fact. No trust in us required
Read against
EU AI Act
Mapped
NIST AI RMF
Mapped
ISO/IEC 42001
In Review
UAE PDPL
Helps customers meet

Spearhead 02 · Posture

One Record, Not Two Systems of Truth

In most organisations the security team and the compliance team hold two versions of the same problem, and reconciling them is somebody’s week. Posture is the step that makes them one record, and it is what turns a pile of findings into something an auditor will accept.

A discovered system

→ gets an owner

Discovery hands over an AI system, not an alert. Before it can carry a finding it has to carry a name: the team that runs it and the person who answers for it.

A security finding

→ becomes a control gap

A prompt-injection exposure is not filed as a technical issue in one tool and a compliance gap in another. It is one record, mapped to the control it touches, in the framework that reaches you.

A control gap

→ shows on the register

Including the honest entries, the systems where the answer today is "no control mapped yet". A register that only shows green is a register nobody believes.

The register

→ feeds the gate

Evidenced risk is what the release gate blocks on. Without posture the gate is a rule someone wrote down; with it, the gate has a reason an auditor can read.

The findings themselves come from Pillar 1, where the threat surface we cover is published next to the part we don’t.

Framework coverage

Ten Lighthouses. Three Bearings.

Control-level detail, framework by framework. Click a lighthouse to read what coverage actually means in practice, including the places where the honest answer today is “in review”.

Solas · Maritime Compliance Chart
05°10°15°20°25°30°35°05°10°15°20°25°01020304050607080910NESWSCALE 1:50 N.M.
32°14′N · 04°12′E
MappedIn ReviewHelps customers meet
· keys to navigate
Beacon 01 / 10·Mapped·Articles 9, 10, 13, 14, 15, 43, 47, 72

EU AI Act

The posture-to-prove chain is mapped against Regulation (EU) 2024/1689 for high-risk AI systems: risk-management documentation under Article 9, data-governance and quality controls under Article 10, transparency to deployers under Article 13, and human-oversight requirements under Article 14. Accuracy, robustness, and cyber-security findings feed Article 15. Annex IV technical-file artefacts are assembled from the same audit trail used for conformity assessment under Article 43, and post-market monitoring under Article 72 lands as structured telemetry rather than a manual log. The Article 47 Declaration of Conformity is held in draft until a customer’s EU deployment requires signature.

Click a lighthouse or use the stepper

Spearhead 04 · Prove

Three Blocks on One Chain

Discovery, risk, decision and override are written as rows linked by SHA-256, under an Ed25519-signed chain head. An auditor can verify after the fact that the record was not edited, a different and much stronger claim than “we keep logs”.

01Block · integrity

Hash-chained audit log

Every administrative action, grading event, and policy change is appended to a tamper-evident chain. Each row links to the previous via SHA-256, and the head can be signed with the vendor Ed25519 key. Auditors verify after the fact that no row was inserted, deleted, or edited.

Maps to
  • GDPR Art 5(2) · Accountability
  • EU AI Act Art 12 · Record-keeping
  • ISO 27001 A.8.15 · Logging
  • SOC 2 CC7.2 · System monitoring
Receipts
  • SHA-256 chain · prev_hash + payload
  • Ed25519 signature on chain head
  • Append-only enforced at DB layer
  • Independent verification CLI

Auditor: “Prove no admin deleted a finding record before the audit.”

Hash chain· example data
02Block · portability

DSAR signed manifest

A subject’s full footprint (profile, findings, control mappings, audit-log entries, and system-of-record data) exports as a single Ed25519-signed manifest. The request, manifest hash, and response timestamp all land in the audit chain.

Maps to
  • GDPR Art 15 · Right of access
  • GDPR Art 20 · Data portability
  • UAE PDPL Art 13 · Data subject rights
  • HIPAA §164.524 · Access to PHI
Receipts
  • JSON-LD manifest, Ed25519-signed
  • Manifest hash back into audit chain
  • Per-section redaction support
  • Re-issuable on Art 16 rectification

Auditor: “Show the exact bytes the subject received and prove they were complete.”

DSAR manifest· example data
03Block · lifecycle

Retention enforcement

Retention is configured per organisation and data class: audit, findings, and telemetry each carry their own period. Enforcement runs automatically and writes its own audit row, so an assessor can trace when erasure executed and under which policy version.

Maps to
  • GDPR Art 5(1)(e) · Storage limitation
  • GDPR Art 17 · Right to erasure
  • UAE PDPL Art 6 · Data minimisation
  • HIPAA §164.530(j) · Doc retention
Receipts
  • Per-class retention windows (days)
  • Scheduled enforcement, dry-run preview
  • Deletion event signed into chain
  • Legal-hold override (logged, bounded)

Auditor: “Show 2022 findings data is gone and the deletion is provable.”

Retention windows· example data

Framework register

Every Framework, With Its Real Status

No coverage percentages, because a percentage on a page called Audit is a number nobody outside this building can check. Four words instead, each meaning one thing.

  • MappedWe hold the control mapping and can show it.
  • In ReviewMapping in progress; gaps documented, not hidden.
  • Helps customers meetYour obligation, our evidence. Not a Solas certification.
  • RoadmapNot mapped yet, listed rather than left off.
01

United Arab Emirates

  1. UAE PDPLFederal Decree-Law No. 45 of 2021Helps customers meet
  2. NESA / SIAInformation Assurance StandardsMapped
  3. ADHICSAbu Dhabi healthcare controlsMapped
  4. DIFC / ADGM Reg 10Free-zone automated processingMapped
02

Wider Gulf

  1. SAMA (KSA)Cyber Security FrameworkMapped
  2. Qatar, Oman & BahrainNational data-protection lawsMapped
  3. UAE AI Charter & CouncilDirectional national AI policyMapped
03

International reference

  1. EU AI ActRegulation (EU) 2024/1689Mapped
  2. NIST AI RMFGOVERN · MAP · MEASURE · MANAGEMapped
  3. ISO/IEC 42001AI Management SystemIn Review
  4. ISO/IEC 27001:2022Annex A, personnel securityHelps customers meet
  5. GDPREU 2016/679Helps customers meet
  6. SOC 2 Type IITrust Services CriteriaHelps customers meet
  7. HIPAA · PCI DSS · NIS2Sector and regional regimesHelps customers meet
04

Southeast Asia

  1. Singapore PDPAFlagged in assessmentRoadmap
  2. MASAI and model-risk guidanceRoadmap
  3. Malaysia PDPA · Bank Negara RMiTDepth mapping pendingRoadmap
  4. Indonesia PDP Law · OJKDepth mapping pendingRoadmap

Evidence under NDA

Open the Dossier

Register · the dossier
  1. Annex IV

    Annex IV technical file

    Technical documentation for the high-risk classification, maintained as the system changes rather than written for the audit.

  2. Art. 9

    Article 9 risk management

    Risk-management documentation kept continuously, fed by the findings the platform records.

  3. Art. 10

    Article 10 data governance

    Data-governance records for the training, validation and testing sets in scope.

  4. Art. 72

    Article 72 post-market monitoring

    Post-market monitoring artefacts, drawn from the same tamper-evident record the platform writes.

  5. Draft

    Article 47 Declaration (draft)

    Held in draft, not signed. Executed alongside the EU authorised-representative engagement on the first EU deployment.

maintained continuously · not assembled the week before
Under NDA

The full dossier on request

Annex IV technical files, Article 9 risk-management documentation, Article 10 data-governance records, post-market monitoring artefacts under Article 72, and the draft Article 47 Declaration of Conformity. Procurement, audit, and legal teams can request the package directly.

Request the dossier

In-flight programme

Stamps in the Ledger

Status changes when the evidence is signed, not when work begins.

Ledger · in-flight programme
Solas · RoadmapinternalSCHEDULED

Independent penetration testing

Engagement scheduled with an independent assessor. Findings and remediation will feed the security-evidence bundle.

Solas · RoadmapinternalIN REVIEW

ISO/IEC 42001 alignment

Ongoing internal review against the AI Management System standard. Gap analysis available to evaluating customers under NDA.

Solas · RoadmapinternalPENDING

EU authorised representative (Article 25)

Formal engagement of an EU authorised representative will be completed when the first EU prospect surfaces. Required before Article 47 signature.

Solas · RoadmapinternalDRAFT

Article 47 Declaration of Conformity

Held in draft, not signed. Will be executed alongside the EU authorised-representative engagement on the first EU deployment.

capability-tense · status changes when evidence is signed

Two parallel actions

Bring the control-by-control questions

Compliance, procurement and audit teams: reach us directly and we will answer control by control. Or start with the free 30-day pilot and end day thirty holding a tamper-evident record rather than a slide about one.

Pack request opens the contact form pre-tagged with topic = compliance. Email opens your mail client.

The thirty days· read-only to start
Thirty days · no fee
  • Day 1 · Connect + inventory
    read-only · about fifteen minutes
  • Map
    systems → the frameworks that reach you
  • Gate
    live in your pipeline, override logged
  • Day 30 · Record
    yours either way · no obligation