Evidence an auditor accepts — and can check themselves.
NOCTRYS produces the artifacts your auditor, regulator, and insurer actually ask for, mapped to the frameworks they measure you against — and lets any of them verify the record independently, without trusting you or us.
What NOCTRYS maps to
We are early-stage and onboarding design partners: these are engineering mappings and alignments, not certifications. Formal audits (SOC 2, ISO 42001) come when a funded contract justifies them.
| Framework | Coverage | What NOCTRYS provides |
|---|---|---|
| EU AI Act | Art. 12 / 14 / 15 / 26 / 50 | Tamper-evident logging, human oversight + kill-switch, deterministic robustness, retention, transparency. Details → |
| OWASP Agentic Top 10 (2026) | 10 / 10 covered | ASI01–ASI10 mapped to concrete controls; run npm run owasp for the coverage map. |
| NIST AI RMF | Aligned | Govern · Map · Measure · Manage — runtime enforcement plus measurable, auditable evidence. |
| ISO/IEC 42001 | Aligned | Operational controls and records for an AI management system. |
| NSA MCP guidance | Aligned | Hardened tool mediation — the control set the guidance enumerates. |
What lands on the examiner’s desk
Totals by verdict, blocks by reason, integrity status, the anchored Merkle root, and article-by-article coverage — generated from the real log, not assembled by hand.
The examiner checks the seal in their own browser against the AERE chain. They do not have to trust your word, or ours. Try it →
Secrets and PII masked in the log while decisions still use real values; persistent store meets multi-month retention with SIEM export.
Be one of our first five design partners
Free pilot. Two-week, self-hosted integration. You keep the tamper-evident audit and the AI Act compliance report.
Request a pilot →