Compliance evidence portal

Request the evidence your risk team actually needs.

Every request is ticketed, tracked, and answered by a named reviewer. Approved artifacts are released via short-lived, watermarked download links tied to your ticket.

Certification readiness

Every framework banks ask for - tracked with evidence bindings, owners and due dates.

Every "Live" claim below points to a specific artefact this platform already produces (hash-chained audit log, Ed25519 signatures, 26-layer SHIELD, signed evidence bundles). Gaps are published with owner and due date, not hidden.

Frameworks tracked
11
Average readiness
90%
Live today
3
Tracked open gaps
14
SOC
AICPA
SOC 2 Type I
In progress
Q1 202759/64 controls
92% ready2 open gaps

How we exceed: Every trust-service criterion is backed by a cryptographic artefact (Ed25519 signatures, hash-chained audit_log, OTS anchor), not just a policy PDF.

SOC
AICPA
SOC 2 Type II
Scheduled
Q3 202747/64 controls
74% ready1 open gap

How we exceed: Continuous evidence: every scan, verdict override and key rotation is chain-hashed and externally anchorable, so operating effectiveness is provable per-event, not per-quarter.

27K
ISO/IEC
ISO/IEC 27001:2022
In progress
Q2 202782/93 controls
88% ready3 open gaps

How we exceed: A.8.28 secure coding, A.8.16 monitoring and A.5.28 evidence collection are met with cryptographic proof (signed artefacts + hash chain) rather than screenshot evidence.

42K
ISO/IEC
ISO/IEC 42001:2023 - AI Management
In progress
Q2 202731/38 controls
81% ready2 open gaps

How we exceed: Model cards, red-team results and calibration methodology are published per detector - plus we ship model-risk artefacts (SS1/23-style) most AI vendors won't touch until 2028.

AI
NIST
NIST AI RMF 1.0 + CSF 2.0
Live
Continuous69/72 controls
95% ready1 open gap

How we exceed: MEASURE 2.7 (red teaming) and MANAGE 2.4 (post-deployment monitoring) both operational today: hash-chained security_events + benchmark_runs prove drift management per scan.

DORA
EU
DORA (Regulation 2022/2554)
In progress
Q3 202735/41 controls
86% ready2 open gaps

How we exceed: Article 9 (protection & prevention) and Article 17 (incident reporting) met via SHIELD L15 kill-switch + chain-verifiable incident ledger - regulators can independently verify our reports.

MRM
UK
FCA SS1/23 + PRA SS2/21 (Model Risk)
In progress
Q4 202620/22 controls
90% ready1 open gap

How we exceed: We ship the model-risk pack banks would normally have to build themselves: tiering, independent validation, calibration methodology and per-verdict evidence bundle.

GDPR
EU/UK
GDPR / UK GDPR + DPA 2018
Live
Continuous32/33 controls
96% ready1 open gap

How we exceed: Art. 32 security of processing is exceeded via cryptographic tamper-evidence; Art. 30 records of processing are auto-generated from audit_log.

CE+
NCSC
Cyber Essentials Plus
Scheduled
Q4 202624/25 controls
94% ready1 open gap

How we exceed: All five control themes already met by SHIELD + MDM baseline; certification is a scheduling exercise, not a build.

C2PA
C2PA
C2PA / CAI conformance
Live
Continuous14/14 controls
97% readyno open gaps

How we exceed: We both verify inbound C2PA and emit our own signed provenance manifests per evidence bundle - unique among detection vendors.

PCI
PCI SSC
PCI DSS v4.0 (scoped-out)
Target
N/A0/- controls
100% readyno open gaps

How we exceed: Scope minimisation is a security posture. We publish a signed attestation that no PAN, CVV or track data ever enters our systems.

Full register (with sensitive items) available under NDA via the compliance portal.

Artifacts requested

Select everything relevant. Reviewers approve per-artifact.

Submitting is treated as an NDA-covered request. Downloads are watermarked and traceable.

Prefer a walkthrough? Book a guided demo or start a secure pilot.