One engine. Every framework.
EU AI Act today — the deep, article-cited core that nobody else has built. ISO 42001, NIST AI RMF, SOC 2 next, on the same shared evidence core with live cross-framework coverage.
EU AI Act
Only we do thisAnnex III high-risk classification, Annex IV technical docs, FRIA, transparency. The only platform with this natively.
GPAI (General-Purpose AI)
Only we do thisProvider duties under Articles 53–55. Systemic-risk handling on the Enterprise tier.
ISO/IEC 42001 — AI Management System
Control library + cross-walk in private beta. Ships with Release 2.
NIST AI RMF
Only we do thisGovern / Map / Measure / Manage functions tagged across existing controls. Read-only in current build.
SOC 2 (Type I, then Type II)
Shared evidence core lets one artifact satisfy SOC 2 + ISO 42001 + EU AI Act. Bundle target: Q1 2027.
ISO/IEC 27001
Bundle authoring on the same Framework Engine. Q2 2027.
GDPR + DPA tooling
Cross-walk with EU AI Act Article 27 (FRIA) controls. Q2 2027.
HIPAA
Healthcare deployers running AI in regulated workflows. Q3 2027.
PCI DSS
Release 3 module. Connector-heavy, scheduled after SOC 2 Type II.
Cross-framework coverage
Every obligation is tagged so one piece of evidence satisfies every framework that maps to it. Complete the EU AI Act and you arrive at SOC 2 and ISO 42001 with most controls already pre-satisfied. Land here, expand in software — not in another year-long engagement.