Get started

AOCL Compliance Suite

AI decisions. Fully transparent.

Turn opaque AI decisions into structured compliance documentation. Export auditor-ready reports across 7 frameworks, build your SoA and DPIA in the product, and hand your auditor evidence they can verify themselves.

SOC 2, HIPAA, GDPR, ISO 27001, EU AI Act, ISO 42001, NIST AI RMF7 frameworksOne licence, whole organisation$599 per year

In plain words

What it is, where it lives, when to reach for it

What is it
A licensed add-on for QuoxCORE that turns agent decision traces into auditor-ready reports.
Where do I use it
In the dashboard of the QuoxCORE you run yourself, so the evidence never leaves your infrastructure.
When would I use it
When an auditor asks what your AI decided and your application logs cannot answer.
How do I use it
Buy the licence, activate it under Plugins, Manage Licences, then export a framework report.

QuoxCORE is the free, self-hosted platform underneath this. What is QuoxCORE

The problem

AI is a compliance nightmare.

Auditors are asking questions you cannot answer. Regulators are demanding transparency you do not have. One incident could mean millions in fines. Four questions decide the audit, and most AI stacks cannot answer any of them.

?

“How does your AI make decisions?”

Black-box AI systems leave you scrambling to explain what happened and why. Auditors hate “we don’t know”.

!

“Show me the audit trail”

Most AI tools do not log anything useful. When incidents happen, you are piecing together fragments from multiple systems.

$

“Prove you're compliant”

SOC 2, HIPAA, GDPR, ISO 27001, EU AI Act, ISO 42001, NIST AI RMF: each framework wants documentation in its own format. Manual compilation takes weeks.

×

“What went wrong?”

When AI makes a mistake, can you replay the exact sequence of events? Most organisations cannot.

Interactive demonstration

Try to rewrite the evidence.

This is the chain of custody behind every export: each decision an agent makes is hashed and appended to the WARD chain, where every block binds the hash of the one before it. Watch the evidence arrive, then tamper with a block yourself and see the verifier catch the break at the exact position.

illustrative demo · sample data

evidence explorer · chain of custodyentries796tip0x2d88b5…e410chainVERIFIED

live agent decisions · hashed as they land

the verifier · runs offline, no Quox account

$ quox ward verify --org acme --offline
recomputing hashes #00794…#00796
0 mutations · chain VERIFIED ✓
ed25519 tip signature · RFC 3161 receipt · no Quox account needed
#00794aocl.gate · L4 egress gate · ALLOW · agent MERIDIAN0x9c31af…2b6dprev #genesis
#00795export.bundle · soc2-2026-Q1.pdf · SHA-256 checksums0x4e7c10…9f3aprev 0x9c31af…2b6d
#00796hitl.approve · high-risk change · second admin signs off0x2d88b5…e410prev 0x4e7c10…9f3aed25519 tip signature
every 100 entries → signed Ed25519 checkpoint published to an RFC 3161 timestamp authority · GitHub · GitLab · S3 · Gitea · webhook

denials are evidence too · a refused request appends a block just like a grant does

Simple process

Compliance in four steps.

Evidence collection starts in minutes, not months: give auditors evidence, control mappings and honest gaps, not screenshots.

Step 01Connect your agents

AOCL automatically captures every decision at every layer. QuoxFlow adds policy management, approval workflows and evidence collection. Zero code changes required.

Step 02Select a framework

Choose any of 7 frameworks: SOC 2, HIPAA, GDPR, ISO 27001, EU AI Act, ISO 42001 or NIST AI RMF. We handle the control mapping, and governance data feeds directly into the reports.

Step 03Generate reports

Export auditor-ready documentation with evidence bundles. Browse evidence with correlation search. Schedule recurring exports.

Step 04Present to auditors

Invite your auditor to a dedicated portal with PBC auto-match, working paper templates and chain-of-custody verification. Or export PDF reports with 3 redaction levels.

For auditors
ILLUSTRATIONpack#00847manifestSIGNEDformatPDF + JSONhover a stage · illustrative animation, not a live export
CONTROL
Framework control
An auditor asks for SOC 2 CC6.1. The control needs evidence.
CAPTURE
Live trace data
Every decision is captured across 11 AOCL layers as agents run.
MAP
Control mapping
Trace evidence is auto-mapped to the criteria of 7 frameworks.
BUNDLE
Evidence bundle
Reports, trace samples and SHA-256 checksums, packaged together.
SEAL
WARD signature
The manifest hash is Ed25519-signed with an RFC 3161 timestamp.
PACK #00847
soc2-2026-Q1.pdf
0x8c1d72…e94f
SIGNED ✓

CAPTURE · live AOCL trace data

layers11 per request
decisionsALLOW / DENY · logged at each gate
sourcelive traces, not screenshots
verifyManifest(pack #00847) → TRUE
WARD-signed manifest hash · RFC 3161 timestamp · no Quox account needed

Watch a control become a signed, exportable evidence pack · then try to rewrite the chain ↓

Step 03, in the product

Generate the report the framework actually asks for.

Pick a framework and the control mapping is already done. This is the report prompt itself, the screen you see before an export is produced, not a mock-up of the output.

The Quox compliance report generation screen, the prompt you see before a framework export is produced

Seven frameworks

Mapped to the frameworks your auditors ask for.

One evidence chain, exported against seven frameworks. Each export maps live trace data to the framework’s own control language, filling the sections your telemetry can evidence and marking the rest action-required.

SOC 2SOC 2 Type II

Trust Services Criteria mapping.

CC6.1 Access Controls·CC7.1 System Operations·PI1.1 Processing Integrity

ISO 27001Information Security (2022)

93 Annex A controls plus the SoA Builder.

A.5 Organisational·A.6 People·A.7 Physical·A.8 Technological

GDPRGeneral Data Protection

Article 30 and 32 compliance.

Data Processing Records·Security Measures·Breach Documentation

HIPAAHIPAA Security Rule

Security Rule 164.312 mapping.

164.312(a) Access Controls·164.312(b) Audit Controls·164.312(e) Transmission

EU AI ActReg. 2024/1689

Risk classification, operator matrix and GPAI.

Art.9 Risk Management·Art.14 Human Oversight·Art.17 QMS·Art.43 Conformity

ISO 42001AI Management System (2023)

The first international AI management standard.

Cl.6 Planning·Cl.8 Operation·Cl.9 Evaluation·ASL Lifecycle Record

NIST AI RMFRisk Management Framework 1.0

Govern, Map, Measure, Manage.

Govern · Accountability·Map · AI profile·Measure · VOLT hash chain·Manage · HITL / DEFCON

The frameworks dashboard

Every control, mapped to the framework language auditors expect.

The compliance centre’s frameworks dashboard shows SOC 2, ISO 27001, GDPR, HIPAA, the EU AI Act, ISO 42001 and NIST AI RMF in one place, each mapped to its own control language.

Quox compliance centre frameworks dashboard, showing control mappings across SOC 2, ISO 27001, GDPR, HIPAA, EU AI Act, ISO 42001 and NIST AI RMF

One-click, WARD-signed exports generated from live trace data, not screenshots and spreadsheets.

Built for compliance teams. Runtime policy denials auto-create triaged incidents that fan out to your SIEM, and every policy change is logged with actor, diff and reason. The evidence is collected while your agents run, not compiled the week before the audit.

The solution

Full transparency. Zero guesswork.

The Compliance Suite captures every AI decision at every layer, then turns the record into compliance documentation in minutes, not weeks. Eight capabilities, one evidence chain.

Compliance export 7 frameworks

Generate auditor-ready reports in SOC 2, HIPAA, GDPR, ISO 27001, EU AI Act, ISO 42001 or NIST AI RMF formats. One-click export with evidence bundles.

auto-mapped controls·evidence attachments·scheduled exports

Trace replay Debug and what-if

Re-execute any historical trace with modifications. Change inputs, disable layers, mock responses. See how behaviour changes.

modify inputs·mock responses·side-by-side diff

Trace comparison Behavioural diff

Compare any two traces side by side. See timing deltas, decision differences and content changes at a glance. Export as a policy delta report for SOC 2 and ISO 27001 evidence.

timing analysis·decision tracking·word-level diff

Multi-agent correlation End-to-end visibility

Track requests across agent handoffs. Swimlane visualisation shows the complete journey through your AI system, linking envelopes, layer events and VOLT runs under one correlation ID.

swimlane view·handoff tracking·aggregate stats

Scheduled reports Automated compliance

Set up recurring compliance exports. Weekly SOC 2 reports, monthly HIPAA audits, quarterly reviews, all automated.

cron scheduling·email delivery·cloud storage

Evidence bundles Audit-ready packages

Download complete audit packages with reports, trace samples, statistics and integrity checksums.

SHA-256 hashes·PDF reports·JSON data

Runtime incidents + SIEM Detect, triage, escalate

Every policy denial becomes a first-class incident. Per-agent behavioural baselines catch drift automatically. Outbound webhooks deliver to Splunk HEC, Microsoft Sentinel, Wazuh, generic CEF or any HMAC-signed endpoint, with retry, circuit breaker and a test-fire endpoint.

5 SIEM formats·HMAC signing·anomaly detection

Policy change history SOC 2 CC8.1 · ISO 27001 A.5.37

Append-only audit trail for every governance policy mutation. Actor, role, timestamp, field-level diff and optional reason captured on every create, update and delete. An opt-in 4-eyes approval gate stages high-risk changes for a second admin; the approver cannot be the requester.

who / what / when·diff per field·4-eyes approval

No trust required

Cryptographic evidence, published externally.

Every 100 WARD entries, a signed Ed25519 checkpoint is published to RFC 3161 timestamp authorities, GitHub, GitLab, S3, Gitea or your own webhook. Give your auditor a URL and they verify the chain without a Quox account.

$quox ward verify --org acme --offline

checking chain · 0 mutations
chain VERIFIED ✓

For a review

The paperwork a review asks for.

Interactive tools inside the suite, backed by the chain rather than by a policy document.

SoASoA Builder: 93 ISO 27001:2022 Annex A controls, tri-state applicability
DPIADPIA form: GDPR Art. 35, 6 sections, 5×5 risk matrix
RiskEU AI Act Risk Classifier, included free
HIPAAHIPAA risk analysis across 54 safeguards
PortalAuditor portal: PBC auto-match and working papers
The full story, for auditors
7framework exports
93Annex A controls
54HIPAA safeguards
30dmoney-back guarantee

Pricing

Simple, transparent pricing.

No hidden fees. No per-user charges. One licence covers your entire organisation, as part of the wider Quox enterprise platform.

Developer Kit

Free for everyone

For technical teams building custom AOCL integrations. Free to everyone, with no licence to buy: owner ruling 2026-08-28, no paywall on learning to build.

  • Layer Playground
  • Build and test at the four extension points (pre-routing, post-policy, pre-execute, post-audit)
  • 6 starter templates
  • Plugin import and export
  • Hot-reload development
  • Test harness
  • Email support
About the Developer Kit

The Developer Kit is free, so there is nothing to bundle it with. The Enterprise Bundle takes Decision Evidence and the Compliance Suite together for $959 a year. Volume licensing and custom frameworks available: talk to us.

Questions

Asked often, answered plainly.

How does the suite help you meet SOC 2 Type II requirements?

The Compliance Suite generates evidence bundles mapped to each Trust Services Criteria (CC1 to CC9). VOLT traces provide the continuous monitoring evidence auditors need, and the evidence is collected automatically rather than in spreadsheets.

Can we deploy in an air-gapped environment?

Yes. The control plane, policies, memory, secrets and evidence chain run entirely on your infrastructure, and licence activation supports offline mode. Inference runs where you choose: fully local for an air-gapped deployment, or through a model provider you explicitly configure.

How are agent actions made immutable?

Every operation produces a VOLT trace entry with a cryptographic hash chain. Each entry references the hash of the previous entry, so any modification breaks the chain and is immediately detectable.

How does external publication work?

Every 100 WARD entries, a signed Ed25519 checkpoint is published to an RFC 3161 timestamp authority (FreeTSA.org by default). GitHub, GitLab, S3 Object Lock, webhooks and Gitea are also supported. No extra infrastructure required.

Do the Compliance Suite and Developer Kit stack?

Yes. The Developer Kit is free: it is where you build and test custom AOCL layers, with the Layer Playground, starter templates, the SDK and the test harness.

The Compliance Suite covers audit exports and runs custom layers in a governed production instance, an early capability that is lightly used so far. There is no kit bundle to buy, because the kit costs nothing. The Enterprise Bundle is Decision Evidence plus Compliance Suite at $959 a year.

What support is included?

Email support at [email protected], for the Compliance Suite and the Developer Kit alike. We do not quote a response time or promise named staff, because neither is something we can stand behind yet.

AOCL Compliance Suite

Ready to pass your next audit?

The Compliance Suite turns your existing trace data into audit-ready evidence. $599 per year, one licence for the whole organisation.