Compliance

Evidence auditors accept, and can check for themselves.

NOCTRYS produces the artifacts your auditor, regulator, and insurer actually ask for, mapped to the frameworks they measure you against, and it lets any of them verify the record independently, without trusting you or us.

EU AI Act Art. 12/14/15/26OWASP Agentic 10/10NIST SP 800-53 mappedCSA MAESTRO alignedNIST AI RMF alignedISO/IEC 42001 alignedNSA MCP guidance
Frameworks

What NOCTRYS maps to

We are early-stage and onboarding design partners: these are engineering mappings and alignments, not certifications. Formal audits (SOC 2, ISO 42001) come when a funded contract justifies them.

FrameworkCoverageWhat NOCTRYS provides
EU AI ActArt. 12 / 14 / 15 / 26 / 50Tamper-evident logging, human oversight + kill-switch, deterministic robustness, retention, transparency. Details →
NIST SP 800-53AC · AU · CM · IA · IR · SISix control families mapped to action-plane controls: least-privilege allowlists, the tamper-evident audit with Decision-BOM, policy change control, agent identity, kill-switch response, and integrity guards. The compliance report emits the family-by-family crosswalk.
CSA MAESTRO7-layer alignmentLayers 2 through 7 of the agentic threat model aligned to concrete controls; layer 1 (foundation models) is complementary by design, because NOCTRYS governs actions, not model internals.
OWASP Agentic Top 10 (2026)10 / 10 coveredASI01 through ASI10 mapped to concrete controls; run npm run owasp for the coverage map.
NIST AI RMFAlignedGovern · Map · Measure · Manage: runtime enforcement plus measurable, auditable evidence.
ISO/IEC 42001AlignedOperational controls and records for an AI management system.
NSA MCP guidanceAlignedHardened tool mediation, the control set the guidance enumerates.
The deliverable

What lands on the examiner’s desk

01
A one-command AI-Act audit report

Totals by verdict, blocks by reason, integrity status, the anchored Merkle root, and article-by-article coverage, now alongside the NIST SP 800-53 control-family and CSA MAESTRO layer crosswalks, generated from the real log rather than assembled by hand.

02
A public verifier they run themselves

The examiner checks the seal in their own browser against the AERE chain. They do not have to trust your word, or ours. Try it →

03
Redacted, retention-ready records

Secrets and PII masked in the log while decisions still use real values; persistent store meets multi-month retention with SIEM export.

Be one of our first five design partners

Free pilot. A two-week, self-hosted integration. You keep the tamper-evident audit and the AI Act compliance report.

Request a pilot →