COMPLIANCE
Compliance as the output of your system
Map signed technical evidence to control objectives—not compliance claims.
8 frameworks
Pre-mapped controls
12 articles
EU AI Act mapping scope
1 click
Generated evidence pack
Not certification
Evidence supports your audit
Frameworks
One evidence stream. Multiple control mappings.
SOC 2 Type II
Maps signed decision evidence and supported enforcement boundaries to selected CC7 and CC6 criteria.
EU AI Act
Maps technical controls and evidence to 12 relevant articles. Applicability and the risk-management system remain customer and counsel determinations.
GDPR
PII detection and configured block/redact behavior can support privacy controls on supported routes.
ISO 42001
Maps policy, approval, and decision-evidence capabilities to selected AI management controls.
NIST AI RMF
Maps relevant policy and evidence capabilities across Govern, Map, Measure, and Manage.
OWASP LLM Top 10
Known-pattern scanning, configured output policy, and PII controls can contribute evidence on supported routes.
HIPAA
Configured PII handling can support PHI controls on supported scanning routes. Obsvr does not make a deployment HIPAA compliant.
CCPA
Configured PII handling and deletion workflows can support customer privacy programs.
Continuous compliance
Not a sprint before the audit
01
Integrate once
Wrap the client explicitly, or use the Node import hook for supported provider modules.
02
Controls run continuously
Supported enforcing routes run policy before dispatch; tested tool gates verify zero denied executions, while tracing-only callbacks and sampled clean events remain identified separately.
03
Evidence generates itself
Generate a ZIP containing control mappings, hashes, integrity material, incident history, operating data, and an auditor guide.
Evidence pack
Generate the evidence package on demand
Questions auditors actually ask
"Can you prove your logs haven't been tampered with?"
The SDK verifier checks retained client-chain integrity and reports signed gap markers when present. The evidence pack adds daily Merkle roots, external anchors, and offline verification material. Deployment coverage and abrupt process loss remain separate questions rather than being inferred from a valid chain.
"Show me your control mapping to SOC 2 CC7."
The generated control mapping links relevant Obsvr evidence to selected CC7 and CC6 criteria. It supports the auditor's assessment; it does not establish your full control environment by itself.
"What happened during your last incident and how long did it take to resolve?"
Obsvr events can contribute timestamps, verdicts, reasons, and integrity evidence. Your incident process remains responsible for containment, root cause, notifications, and the final narrative.
"How do you demonstrate EU AI Act Article 18 documentation requirements?"
The mapping covers 12 relevant articles and identifies where Obsvr can contribute technical evidence. Applicability, retention, risk management, and legal compliance remain customer responsibilities.
EU AI Act coverage
Article-by-article mapping. Not certification.
12 Articles Mapped
Each row identifies evidence Obsvr can contribute. Your legal, risk, and operating controls remain part of compliance.
Annex III: 2 Dec 2027 · regulated products: 2 Aug 2028
Control mapping| Article | Requirement | Obsvr contribution | Status |
|---|---|---|---|
| Art. 5 | Prohibited AI Practices | Policy rules can block configured prohibited actions on supported enforcing routes | Mapped |
| Art. 9 | Risk Management System | Customer-managed governance - obsvr supplies the running controls and signed evidence that feed it | Customer-managed |
| Art. 12 | Record-Keeping & Logging | Signed records for emitted calls and agent activity on supported routes | Mapped |
| Art. 14 | Human Oversight Controls | Policy-triggered approval and escalation controls | Mapped |
| Art. 17 | Quality Management System | Policy controls with evidence export for QMS documentation | Mapped |
| Art. 18 | Documentation Keeping | Hosted beta export can organize signed records and hash manifests; retention is customer-configured | Mapped |
| Art. 19 | Automatically Generated Logs | Tamper-evident emitted records with configurable retention and explicit loss accounting | Mapped |
| Art. 20 | Post-Market Monitoring | Emitted-event monitoring and policy telemetry can support post-market review | Mapped |
| Art. 26 | Deployer Obligations | Principal-aware policy controls and signed decision evidence | Mapped |
| Art. 72 | Incident Reporting | Policy events and hooks can feed customer incident workflows | Mapped |
| Art. 73 | Serious Incident Reporting | Escalation hooks and signed evidence can support incident documentation | Mapped |
| Art. 86 | Right to Explanation | Versioned reason codes and signed records for emitted governed decisions | Mapped |