The solution
Full transparency. Zero guesswork.
The Compliance Suite captures every AI decision at every layer, then turns the record into compliance documentation in minutes, not weeks. Eight capabilities, one evidence chain.
Compliance export 7 frameworks
Generate auditor-ready reports in SOC 2, HIPAA, GDPR, ISO 27001, EU AI Act, ISO 42001 or NIST AI RMF formats. One-click export with evidence bundles.
auto-mapped controls·evidence attachments·scheduled exports
Trace replay Debug and what-if
Re-execute any historical trace with modifications. Change inputs, disable layers, mock responses. See how behaviour changes.
modify inputs·mock responses·side-by-side diff
Trace comparison Behavioural diff
Compare any two traces side by side. See timing deltas, decision differences and content changes at a glance. Export as a policy delta report for SOC 2 and ISO 27001 evidence.
timing analysis·decision tracking·word-level diff
Multi-agent correlation End-to-end visibility
Track requests across agent handoffs. Swimlane visualisation shows the complete journey through your AI system, linking envelopes, layer events and VOLT runs under one correlation ID.
swimlane view·handoff tracking·aggregate stats
Scheduled reports Automated compliance
Set up recurring compliance exports. Weekly SOC 2 reports, monthly HIPAA audits, quarterly reviews, all automated.
cron scheduling·email delivery·cloud storage
Evidence bundles Audit-ready packages
Download complete audit packages with reports, trace samples, statistics and integrity checksums.
SHA-256 hashes·PDF reports·JSON data
Runtime incidents + SIEM Detect, triage, escalate
Every policy denial becomes a first-class incident. Per-agent behavioural baselines catch drift automatically. Outbound webhooks deliver to Splunk HEC, Microsoft Sentinel, Wazuh, generic CEF or any HMAC-signed endpoint, with retry, circuit breaker and a test-fire endpoint.
5 SIEM formats·HMAC signing·anomaly detection
Policy change history SOC 2 CC8.1 · ISO 27001 A.5.37
Append-only audit trail for every governance policy mutation. Actor, role, timestamp, field-level diff and optional reason captured on every create, update and delete. An opt-in 4-eyes approval gate stages high-risk changes for a second admin; the approver cannot be the requester.
who / what / when·diff per field·4-eyes approval