Evidence auditors accept, and can check for themselves.
NOCTRYS produces the artifacts your auditor, regulator, and insurer actually ask for, mapped to the frameworks they measure you against, and it lets any of them verify the record independently, without trusting you or us.
What NOCTRYS maps to
We are early-stage and onboarding design partners: these are engineering mappings and alignments, not certifications. Formal audits (SOC 2, ISO 42001) come when a funded contract justifies them.
| Framework | Coverage | What NOCTRYS provides |
|---|---|---|
| EU AI Act | Art. 12 / 14 / 15 / 26 / 50 | Tamper-evident logging, human oversight + kill-switch, deterministic robustness, retention, transparency. Details → |
| NIST SP 800-53 | AC · AU · CM · IA · IR · SI | Six control families mapped to action-plane controls: least-privilege allowlists, the tamper-evident audit with Decision-BOM, policy change control, agent identity, kill-switch response, and integrity guards. The compliance report emits the family-by-family crosswalk. |
| CSA MAESTRO | 7-layer alignment | Layers 2 through 7 of the agentic threat model aligned to concrete controls; layer 1 (foundation models) is complementary by design, because NOCTRYS governs actions, not model internals. |
| OWASP Agentic Top 10 (2026) | 10 / 10 covered | ASI01 through ASI10 mapped to concrete controls; run npm run owasp for the coverage map. |
| NIST AI RMF | Aligned | Govern · Map · Measure · Manage: runtime enforcement plus measurable, auditable evidence. |
| ISO/IEC 42001 | Aligned | Operational controls and records for an AI management system. |
| NSA MCP guidance | Aligned | Hardened tool mediation, the control set the guidance enumerates. |
What lands on the examiner’s desk
Totals by verdict, blocks by reason, integrity status, the anchored Merkle root, and article-by-article coverage, now alongside the NIST SP 800-53 control-family and CSA MAESTRO layer crosswalks, generated from the real log rather than assembled by hand.
The examiner checks the seal in their own browser against the AERE chain. They do not have to trust your word, or ours. Try it →
Secrets and PII masked in the log while decisions still use real values; persistent store meets multi-month retention with SIEM export.
Be one of our first five design partners
Free pilot. A two-week, self-hosted integration. You keep the tamper-evident audit and the AI Act compliance report.
Request a pilot →