Compliance as the output of your system

Controls map themselves as your AI runs, so the audit is already answered when it arrives.

8 frameworks

Pre-mapped controls

11 of 12

EU AI Act articles covered

1 click

Evidence pack export

WORM

Immutable, configurable retention

One integration. Every framework.

SOC 2 Type II

CC7.1 · CC7.2 · CC7.3 · CC7.4 · CC7.5CC6.1 · CC6.6

Full CC7 system operations coverage, with policy audit trail for CC6.1 and boundary enforcement for CC6.6.

EU AI Act

Art. 5 · 9 · 12 · 14 · 17 · 18 · 19 · 20 · 26 · 72 · 73 · 86

11 of 12 articles covered and evidenced automatically; Art. 9 delineated as customer-managed. Enforcement begins Aug 2, 2026.

GDPR

Art. 25Art. 32Art. 33

PII detection and redaction across 19 types, with Article 33 breach evidence ready on demand.

ISO 42001

AI management system controls

Risk management, human oversight, and lifecycle documentation generated from your live audit trail.

NIST AI RMF

Govern · Map · Measure · Manage

All four RMF functions mapped to running controls rather than a point-in-time questionnaire.

OWASP LLM Top 10

LLM01 · LLM02 · LLM06

Prompt injection, insecure output handling, and sensitive-information disclosure evidenced at call time.

HIPAA

PHI detection · BAA available

PHI detection on every prompt and response, with the same signed, tamper-evident trail.

CCPA

PII handling · Right to deletion

PII detection across all LLM calls, with data export and deletion workflows supported.

Not a sprint before the audit

01

Integrate once

Wrap your LLM client with the obsvr SDK. Zero call-site changes, under 5 minutes.

02

Controls run continuously

Policy enforcement, PII detection, and cryptographic signing run on every call, automatically.

03

Evidence generates itself

When your auditor asks, export a one-click ZIP with every control mapped and every proof included.

One click, and the audit is already answered

audit-2026-05-01.zip · SHA256 verifiedReady
README_FOR_AUDITORS.mdPlain-English guide - what each folder proves and how to run verification
MANIFEST.jsonSHA-256 hash of every file in the package - tampering is immediately detectable
summary.jsonMachine-readable summary: event counts, PII detections, incident counts, date range
00_scope_summary.txtProse narrative of controls active, event volume, and PII detections over the period
01_scope_and_manifest/controls-mapping.json + scope-summary.json, pre-mapped to SOC 2 (CC7/CC6.1/CC6.6), EU AI Act, ISO 42001, NIST AI RMF, and the OWASP LLM Top 10
02_integrity_and_merkle/daily-roots.csv, verify_merkle.py, verification.log, ANCHORING_STATUS.md
03_storage_config/S3 Object Lock policy JSON proving WORM compliance mode is active
04_access_control/IAM role mapping, bucket policy, access summary, recent access sample
05_incidents_and_alerts/incidents.json, incident-response.md with root cause + MTTR, detection-rules.md
06_samples_and_exports/sample-hashed-events.csv, events-summary.csv, logging-scope.md
07_operating_effectiveness/daily-uptime.csv, monthly-summary.csv with p50/p90/p99 latency and error rates
08_tools_and_vendors/mcp-tool-inventory.json/.md - the MCP tools exposed to the model at discovery with per-tool poisoning flags (point-in-time), cited from ISO 42001 A.9.4 and OWASP LLM06
09_model_provenance/model-timeline.json/.md - which model + policy version was live over time, each segment sealed by an anchored root (EU AI Act Art. 12 + Art. 86)

Questions auditors actually ask

"Can you prove your logs haven't been tampered with?"

Yes. Every event is HMAC-SHA256 signed at capture, daily Merkle roots are anchored to S3 Object Lock and a GitHub repo, and verify_merkle.py lets auditors confirm independently.

"Show me your control mapping to SOC 2 CC7."

controls-mapping.json maps every control to CC7.1-CC7.5, CC6.1, and CC6.6, with evidence pointers linking each control to the log entries that prove it.

"What happened during your last incident and how long did it take to resolve?"

incident-response.md contains the full timeline - detection time, containment steps, root cause, MTTR, and notified parties. Ready to hand over as-is.

"How do you demonstrate EU AI Act Article 18 documentation requirements?"

controls-mapping.json addresses all 12 articles - 11 covered, Art. 9 explicitly delineated as customer-managed - with immutable log retention configurable beyond the Act's minimum 6 months.

11 of 12 articles. Nothing overclaimed.

EU AI Act

11 Articles Covered

Art. 9 delineated as customer-managed - the mapping in the evidence pack says exactly which is which.

Ready for Aug 2, 2026

Ready
ArticleRequirementobsvr CoverageStatus
Art. 5Prohibited AI PracticesPolicy engine blocks prohibited use cases at call-time✓ Covered
Art. 9Risk Management SystemCustomer-managed governance - obsvr supplies the running controls and signed evidence that feed itCustomer-managed
Art. 12Record-Keeping & LoggingImmutable HMAC-signed log of all LLM calls and agent runs✓ Covered
Art. 14Human Oversight ControlsEscalation hooks + policy-triggered human-in-loop steps✓ Covered
Art. 17Quality Management SystemPolicy controls with evidence export for QMS documentation✓ Covered
Art. 18Documentation KeepingAuto-generated evidence packets with hash manifests retained for 10-year audit window✓ Covered
Art. 19Automatically Generated LogsImmutable, automatically captured logs retained for the required minimum period✓ Covered
Art. 20Post-Market MonitoringContinuous event monitoring + automated incident detection✓ Covered
Art. 26Deployer ObligationsDeployer-scoped policy controls + full audit trail✓ Covered
Art. 72Incident ReportingAutomated classification, detection, and alert generation✓ Covered
Art. 73Serious Incident ReportingEscalation hooks + detailed incident documentation✓ Covered
Art. 86Right to ExplanationFull cryptographic audit log of every AI decision✓ Covered