Skip to main content

Compliance frameworks

Every AgentShield rule is mapped, through a shared taxonomy, to specific controls in the frameworks organisations are assessed against. Enabling a framework in Settings turns those mappings on for your organisation: its rules are pushed to every agent, and its controls appear on the Compliance and Posture pages.

Frameworks

FrameworkWhat the mapping covers
OWASP LLM Top 10 (2025)Prompt injection, sensitive information disclosure, excessive agency, supply chain and the rest of the list.
OWASP Agentic (2025, 2026)The agent-specific successor list: tool misuse, identity, memory and multi-agent risks.
SOC 2 Type IICommon criteria CC6 (access) and CC7 (system operations), with CC6.8 and CC8.1 for change and software.
ISO/IEC 27001:2022Annex A controls for access, logging, data leakage and secure development.
ISO/IEC 42001:2023The AI management system standard's Annex A: data quality, lifecycle, and operational monitoring of AI systems.
EU AI Act (2024)Articles on risk management, data governance, record-keeping, transparency and human oversight (Article 14).
MITRE ATLASAdversarial ML techniques, so a blocked action can be named in the language your threat team already uses.
GDPR and HIPAASecurity of processing, PII handling, access control and transmission security.

Which frameworks a plan may enable is listed on the pricing page. Most organisations focus on the one or two frameworks their next audit is about.

How a mapping is decided

Mappings are conservative and single-sourced: a rule maps to the control an auditor would accept without arguing AI semantics, and the mapping is pinned to a versioned taxonomy artifact so evidence does not shift under you between assessments. Decisions with no rule or no taxonomy node are counted honestly as not attested rather than hidden.

Scans and the AI bill of materials

The Compliance page also ingests static scan results from Comply, the companion scanner, run locally or in CI. It lists every AI SDK, model call and hard-coded key it found, scores the findings, and shows the impacted controls per framework. Runtime evidence from AgentShield and static findings from Comply meet on the Posture page.

Reports

Team and Enterprise plans can generate a compliance report per framework, with the enabled controls, the runtime attestations behind each, and the gaps. Export as Markdown or CSV.