SYS_INIT [OK] MEM_ALLOC [0x8F22] KERN_READY [TRUE] AIUDIT_CORE_V4.2
Aiudit AI Governance Protocol / NODE_04_US_EAST
Aiudit — Enterprise AI Governance
ID_TYPE: PROTOCOLGoverning agentic AI for regulated enterprises and government entities through automated policy enforcement, signed evidence, and continuous oversight.
Native integration for AWS GovCloud, Azure Government, and on-premise air-gapped environments.
Mapping [REF_512]
Automated
Red-Teaming
Continuous adversarial simulation across distributed agentic workflows to validate safety boundaries.
- + Prompt Injection FilteringLIVElatency_cost: < 2.5ms
- + Latency-Optimized GuardrailsLIVEthroughput: 12k_tokens/sec
Policy
Serialization
Transforms static regulatory text into high-performance, machine-executable bytecode.
- + Natural Language → OPA98.4% ACCrego_compiler_v2.4
- + Versioned Policy ArtifactsGIT_SYNCcommit_id: ba88f12...
Audit
Traceability
Immutable cryptographic journaling of all AI model decisions and tool calls.
- + SHA-256 Chained LoggingSECUREledger_height: 4,921,084
- + Forensic Replay EngineREADYretention_period: 7_years
Every governance surface. One signed spine.
Aiudit ships as a complete operating system for agentic AI oversight — from telemetry ingest and guardrail compilation to citizen redress, ZK-attested evidence, and governance markets. Each module writes to the same tamper-evident audit chain.
AiTail + ShadowsentinelAI
Real-time trace ingest and adversarial signal detection. Auto-creates incidents when SSAI thresholds breach policy rules.
- ▪Webhook + batch ingest
- ▪Live signal drawer
- ▪Threshold → incident engine
NL Policy Authoring + Compiler
Draft policies in plain English; compile to executable YAML guardrails with live diff and coverage proofs.
- ▪NL → YAML compile
- ▪Guardrail run detail
- ▪Policy-as-code export
Agent Registry + MCP
Full inventory of every agent, risk posture, and Model Context Protocol integration surface.
- ▪Risk tier scoring
- ▪MCP tool catalog
- ▪Change audit trail
Incident Command
Realtime queue, bulk triage across pagination, cross-tab sync, and one-click Black Box export.
- ▪Live realtime queue
- ▪Bulk triage bar
- ▪Signed incident export
Evidence Pack Generator
Auditor-ready JSON + PDF evidence bundles with hash-chained provenance and Stellar anchoring.
- ▪Structured JSON packs
- ▪Stellar anchor receipts
- ▪Ed25519 signatures
Proof-Carrying Decisions
ZK-SNARK attestations for policy coverage, risk thresholds, and incident freeness — verifiable without revealing inputs.
- ▪3 production circuits
- ▪Public JWKS endpoint
- ▪Verification audit log
Federal Readiness Console
NIST OSCAL SSP generator, AIBOM/SBOM, cATO dashboard, POA&M tracker, CNSA 2.0 dual-signature.
- ▪FedRAMP SSP export
- ▪Continuous ATO metrics
- ▪POA&M lifecycle
Continuous Control Monitoring
pg_cron-driven control checks with control-family heatmap, evidence freshness bar, and posture badges.
- ▪Hourly control runs
- ▪Freshness telemetry
- ▪Pillar-level posture
Vendor Risk Automation
AI-drafted third-party questionnaires, response scoring, and continuous vendor posture.
- ▪Auto-drafted RFPs
- ▪Response grading
- ▪Vendor risk tier
Citizen Redress Portal
Public intake at /portal/redress with SHA-256 pseudonymization; casework queue for governance teams.
- ▪Public intake form
- ▪Pseudonymized cases
- ▪SLA-tracked queue
Public Trust Reports
Quarterly per-agency transparency reports with Provenance Cards for every material decision.
- ▪Quarterly reports
- ▪Provenance receipts
- ▪Public /status endpoint
Time Machine
Hourly audit scrubbing with point-in-time replay of any governance decision or agent action.
- ▪Hourly snapshots
- ▪Counterfactual replay
- ▪Flight Recorder
Reverse Audit
Citizens submit claims; the system verifies against hash-chained decision receipts.
- ▪Claim verification
- ▪Receipt matching
- ▪Signed verdicts
Response Playbooks
Reusable governance runbooks with active execution tracking and step-level audit logs.
- ▪Runbook library
- ▪Live execution
- ▪Step-level receipts
Quarantine Net
Cryptographically signed agent isolation with audit-safe lift reasons and Emergency Pause.
- ▪Signed isolation
- ▪Emergency pause
- ▪Lift-reason audit
Governance Markets
Bounties, prediction markets, treaties, procurement records, and an append-only coercion log.
- ▪Defect bounties
- ▪Forecast markets
- ▪Coercion log
AxiomGRC Integration
HMAC-verified bi-directional sync with AxiomGRC for control mapping and evidence handoff.
- ▪Webhook sync
- ▪Control mapping
- ▪Evidence handoff
Entitlements + Metering
Paddle Merchant of Record with 14-day trials, prorated switches, past-due dunning, and proactive usage alerts.
- ▪4 tiers + overage
- ▪Idempotent webhooks
- ▪80/100% alerts
Governance, in numbers.
Aggregate outcomes across regulated deployments — financial services, federal civilian, healthcare, and defense integrators.
Reference
architecture.
A single control plane spans the agent runtime, evidence ledger, and regulator-facing surfaces. Every request is intercepted by a compiled policy, evaluated in-line, and journaled to a hash-chained ledger with external timestamp anchoring — before the response ever leaves your perimeter.
┌──────────────┐ ┌──────────────┐ ┌──────────────┐
│ End Users │───▶│ Agent Mesh │───▶│ Tool / API │
│ · SSO/SAML │ │ · LLM Proxy │ │ · MCP Layer │
└──────┬───────┘ └──────┬───────┘ └──────┬───────┘
│ │ │
▼ ▼ ▼
╔═══════════════════ AIUDIT CONTROL PLANE ════════════════════╗
║ Policy Compiler │ Inline Guardrails │ Risk Heatmap ║
║ · NL → OPA/Rego │ · PII / secrets │ · Drift + SSAI ║
║ · Versioned │ · Jailbreak / RCE │ · Counterfactual║
╠═════════════════════════════════════════════════════════════╣
║ Evidence Ledger │ ZK Attestations │ Trust Snapshots ║
║ · SHA-256 chain │ · Ed25519 issuer │ · Signed PDF ║
║ · Stellar anchor │ · OSCAL 1.1 SAR │ · OMB M-24-10 ║
╚══════════════════════════╤══════════════════════════════════╝
▼
┌──────────────┐ ┌──────────────┐ ┌──────────────┐
│ Regulators │ │ Auditors │ │ Boards / IR │
│ · JAB / EU │ │ · Big-4 SAR │ │ · Black Box │
└──────────────┘ └──────────────┘ └──────────────┘Deployment,
on your terms.
Aiudit runs in the tenancy your legal, security, and mission owners accept. Same control plane. Same evidence artifacts. Same auditor deliverables — regardless of where the bits sit.
SaaS (Multi-tenant)
- SOC 2 Type II · ISO 27001
- Per-tenant KEK · HSM-backed KMS
- SSO/SAML + SCIM 2.0 lifecycle
- Onboard in < 1 business day
VPC / Single-tenant
- Dedicated data plane in your cloud
- BYO-KMS · customer-managed keys
- Private-link ingress · no egress
- HIPAA BAA · PCI-adjacent workloads
GovCloud / Air-gapped
- FIPS 140-3 validated modules
- CNSA 2.0 dual-signature façade
- FedRAMP Moderate / High baseline
- OSCAL 1.1 SSP · POA&M automation
Deployed across regulated sectors.
Customer identifiers withheld under MSA · reference calls available under NDA
Technical
Registry
Real-time synchronization with institutional compliance databases. Last heartbeat: 12:00:04Z
99.8% Control Effectiveness
| Control ID / Standard | Authority | Status | Node / Hash |
|---|---|---|---|
FedRAMP High/Moderate SRG-V4-R2.1 | GSA_JAB | Authorized | FR-9021-A 0x9A..3E1 |
OMB M-24-10 Standards AI_GOV_ORD | WH_OMB | Compliant | M24-EXEC-10 0xF2..B18 |
NIST SP 800-53 Rev. 5 CTL_BASELINE | NIST_ITL | Mapped | N53-M-217 0xC4..91D |
EU AI Act — Art. 14 Oversight OVSGHT_HITL | EC_DG_CONNECT | Ready | EU-14-Q4 0x71..2A0 |
Compliance,
clarified.
Answers to the questions procurement, legal, and audit teams ask most before onboarding Aiudit into a regulated AI program.
Response SLA · 1 business day
- 01
Which regulatory frameworks does Aiudit map to out of the box?
NIST AI RMF 1.0 and the Generative AI Profile, EU AI Act (Titles III & IV obligations for high-risk and GPAI systems), ISO/IEC 42001, ISO/IEC 23894, SOC 2 (Trust Services Criteria), FedRAMP Moderate/High control families, HIPAA, and sector overlays for FFIEC, PRA SS1/23 and CPS 230. Every control ships pre-mapped with evidence collectors.
- 02
How does Aiudit generate audit-ready evidence?
Every policy decision, guardrail run, and agent interaction is hash-chained and anchored to an external timestamp authority. Evidence packages export as OSCAL 1.1 SAR bundles, structured JSON, or an auditor PDF with a signed manifest — including inputs, outputs, redactions, and the compiled policy version that produced each verdict.
- 03
Where is data stored and processed?
Default tenancy is US-East (SOC 2 Type II, ISO 27001). EU (Frankfurt), UK, and IL4/IL5 GovCloud regions are available. Customer data never leaves the selected region, and cross-region replication is opt-in per-workload with a signed data-residency attestation.
- 04
How is customer data isolated in a multi-tenant deployment?
Row-level security enforces org_id scoping on every table, backed by per-tenant KEKs in an HSM-backed KMS with envelope encryption. Dedicated single-tenant and VPC-peered deployments are available for regulated buyers, and all inter-service traffic is mTLS with FIPS 140-3 validated modules.
- 05
Does Aiudit support Data Processing Agreements, BAAs, and sub-processor disclosures?
Yes. Standard DPA with SCCs, a HIPAA BAA, and UK IDTA are available under NDA. Our sub-processor list, penetration test summary, SOC 2 report, and ISO certificates are downloadable from the trust center at /security once access is provisioned.
- 06
How does the platform handle AI-specific risks like prompt injection, model drift, and data exfiltration?
Inline guardrails compile natural-language policy into deterministic checks (PII, secrets, jailbreak patterns, tool-scope violations), while continuous telemetry from AiTail and adversarial probes from ShadowsentinelAI feed the risk heatmap. Drift, sleeper-agent, and counterfactual replay modules flag deviations before incidents propagate.
- 07
What does incident response and breach notification look like?
Detected policy breaches auto-create an incident linked to the originating policy version, guardrail run, and trace. Notification SLAs default to 24 hours for confirmed material incidents, with a one-click NTSB-style Black Box export for regulators, cyber insurers, and internal review boards.
- 08
Can we bring our own models, keys, and identity provider?
Yes. Aiudit is model-agnostic (OpenAI, Anthropic, Bedrock, Vertex, Azure OpenAI, on-prem vLLM). Bring-your-own-key with customer-managed KMS is supported, and SSO integrates with Okta, Entra ID, Ping, and any SAML 2.0 or OIDC provider. SCIM 2.0 handles lifecycle.
Still evaluating?
Get a controls walkthrough with a solutions engineer.
Talk to the
Aiudit team.
Every request routes to a solutions engineer with regulated-industry background. Government inquiries handled under separate track.