An Inventory Is Not Evidence. This Is.
An auditor asks four things: what AI do you run, who approved it, against which control, and can you prove the record wasn’t edited afterwards. This is the half of the overlay that answers the last two. Every finding tied to the control it touches, and the whole sequence written to a hash-chained log with a signed head.
Spearhead 02 · Posture
One Record, Not Two Systems of Truth
In most organisations the security team and the compliance team hold two versions of the same problem, and reconciling them is somebody’s week. Posture is the step that makes them one record, and it is what turns a pile of findings into something an auditor will accept.
A discovered system
→ gets an owner
A security finding
→ becomes a control gap
A control gap
→ shows on the register
The register
→ feeds the gate
The findings themselves come from Pillar 1, where the threat surface we cover is published next to the part we don’t.
Framework coverage
Ten Lighthouses. Three Bearings.
Control-level detail, framework by framework. Click a lighthouse to read what coverage actually means in practice, including the places where the honest answer today is “in review”.
EU AI Act
The posture-to-prove chain is mapped against Regulation (EU) 2024/1689 for high-risk AI systems: risk-management documentation under Article 9, data-governance and quality controls under Article 10, transparency to deployers under Article 13, and human-oversight requirements under Article 14. Accuracy, robustness, and cyber-security findings feed Article 15. Annex IV technical-file artefacts are assembled from the same audit trail used for conformity assessment under Article 43, and post-market monitoring under Article 72 lands as structured telemetry rather than a manual log. The Article 47 Declaration of Conformity is held in draft until a customer’s EU deployment requires signature.
Spearhead 04 · Prove
Three Blocks on One Chain
Discovery, risk, decision and override are written as rows linked by SHA-256, under an Ed25519-signed chain head. An auditor can verify after the fact that the record was not edited, a different and much stronger claim than “we keep logs”.
Hash-chained audit log
Every administrative action, grading event, and policy change is appended to a tamper-evident chain. Each row links to the previous via SHA-256, and the head can be signed with the vendor Ed25519 key. Auditors verify after the fact that no row was inserted, deleted, or edited.
- GDPR Art 5(2) · Accountability
- EU AI Act Art 12 · Record-keeping
- ISO 27001 A.8.15 · Logging
- SOC 2 CC7.2 · System monitoring
- SHA-256 chain · prev_hash + payload
- Ed25519 signature on chain head
- Append-only enforced at DB layer
- Independent verification CLI
Auditor: “Prove no admin deleted a finding record before the audit.”
DSAR signed manifest
A subject’s full footprint (profile, findings, control mappings, audit-log entries, and system-of-record data) exports as a single Ed25519-signed manifest. The request, manifest hash, and response timestamp all land in the audit chain.
- GDPR Art 15 · Right of access
- GDPR Art 20 · Data portability
- UAE PDPL Art 13 · Data subject rights
- HIPAA §164.524 · Access to PHI
- JSON-LD manifest, Ed25519-signed
- Manifest hash back into audit chain
- Per-section redaction support
- Re-issuable on Art 16 rectification
Auditor: “Show the exact bytes the subject received and prove they were complete.”
Retention enforcement
Retention is configured per organisation and data class: audit, findings, and telemetry each carry their own period. Enforcement runs automatically and writes its own audit row, so an assessor can trace when erasure executed and under which policy version.
- GDPR Art 5(1)(e) · Storage limitation
- GDPR Art 17 · Right to erasure
- UAE PDPL Art 6 · Data minimisation
- HIPAA §164.530(j) · Doc retention
- Per-class retention windows (days)
- Scheduled enforcement, dry-run preview
- Deletion event signed into chain
- Legal-hold override (logged, bounded)
Auditor: “Show 2022 findings data is gone and the deletion is provable.”
Framework register
Every Framework, With Its Real Status
No coverage percentages, because a percentage on a page called Audit is a number nobody outside this building can check. Four words instead, each meaning one thing.
- MappedWe hold the control mapping and can show it.
- In ReviewMapping in progress; gaps documented, not hidden.
- Helps customers meetYour obligation, our evidence. Not a Solas certification.
- RoadmapNot mapped yet, listed rather than left off.
United Arab Emirates
- UAE PDPLFederal Decree-Law No. 45 of 2021Helps customers meet
- NESA / SIAInformation Assurance StandardsMapped
- ADHICSAbu Dhabi healthcare controlsMapped
- DIFC / ADGM Reg 10Free-zone automated processingMapped
Wider Gulf
- SAMA (KSA)Cyber Security FrameworkMapped
- Qatar, Oman & BahrainNational data-protection lawsMapped
- UAE AI Charter & CouncilDirectional national AI policyMapped
International reference
- EU AI ActRegulation (EU) 2024/1689Mapped
- NIST AI RMFGOVERN · MAP · MEASURE · MANAGEMapped
- ISO/IEC 42001AI Management SystemIn Review
- ISO/IEC 27001:2022Annex A, personnel securityHelps customers meet
- GDPREU 2016/679Helps customers meet
- SOC 2 Type IITrust Services CriteriaHelps customers meet
- HIPAA · PCI DSS · NIS2Sector and regional regimesHelps customers meet
Southeast Asia
- Singapore PDPAFlagged in assessmentRoadmap
- MASAI and model-risk guidanceRoadmap
- Malaysia PDPA · Bank Negara RMiTDepth mapping pendingRoadmap
- Indonesia PDP Law · OJKDepth mapping pendingRoadmap
Evidence under NDA
Open the Dossier
- under NDAAnnex IV
Annex IV technical file
Technical documentation for the high-risk classification, maintained as the system changes rather than written for the audit.
- under NDAArt. 9
Article 9 risk management
Risk-management documentation kept continuously, fed by the findings the platform records.
- under NDAArt. 10
Article 10 data governance
Data-governance records for the training, validation and testing sets in scope.
- under NDAArt. 72
Article 72 post-market monitoring
Post-market monitoring artefacts, drawn from the same tamper-evident record the platform writes.
- draft · not signedDraft
Article 47 Declaration (draft)
Held in draft, not signed. Executed alongside the EU authorised-representative engagement on the first EU deployment.
The full dossier on request
Annex IV technical files, Article 9 risk-management documentation, Article 10 data-governance records, post-market monitoring artefacts under Article 72, and the draft Article 47 Declaration of Conformity. Procurement, audit, and legal teams can request the package directly.
Request the dossierIn-flight programme
Stamps in the Ledger
Status changes when the evidence is signed, not when work begins.
Independent penetration testing
Engagement scheduled with an independent assessor. Findings and remediation will feed the security-evidence bundle.
ISO/IEC 42001 alignment
Ongoing internal review against the AI Management System standard. Gap analysis available to evaluating customers under NDA.
EU authorised representative (Article 25)
Formal engagement of an EU authorised representative will be completed when the first EU prospect surfaces. Required before Article 47 signature.
Article 47 Declaration of Conformity
Held in draft, not signed. Will be executed alongside the EU authorised-representative engagement on the first EU deployment.
Two parallel actions
Bring the control-by-control questions
Compliance, procurement and audit teams: reach us directly and we will answer control by control. Or start with the free 30-day pilot and end day thirty holding a tamper-evident record rather than a slide about one.
Pack request opens the contact form pre-tagged with topic = compliance. Email opens your mail client.
- Day 1 · Connect + inventoryread-only · about fifteen minutes
- Mapsystems → the frameworks that reach you
- Gatelive in your pipeline, override logged
- Day 30 · Recordyours either way · no obligation
