AnchorGate v0.1 is open source — self-host the full stack today. Star on GitHub →

AnchorGate

Compliance posture

Posture computed from decisions, not documents.

Most compliance posture is a folder of PDFs and a quarterly screenshot. AnchorGate computes it from the signed decision ledger instead: control catalogues for the EU AI Act, ISO/IEC 42001, and SOC 2 map onto what your gates actually enforced. No tool makes you compliant — this one shows you, continuously, what you could prove.

The mechanisms

From decision ledger to control catalogue

The pipeline is short on purpose: gates decide, decisions get signed, catalogues map signed decisions to controls. Nothing in the posture is asserted by hand.

Control catalogues, mapped to evidence

Concrete catalogues for the EU AI Act, ISO/IEC 42001, and SOC 2 tie each control to the decision events that evidence it — including the records of operation Article 12 of the EU AI Act asks for.

Computed, not asserted

Posture derives from the signed ledger: which policies fired, what was refused, what was redacted, which risks were quarantined. If the gate didn’t do it, the posture doesn’t claim it.

A dashboard built for the audit

Global posture with asset topology and a risk heatmap, a live decision stream, and an audit hub for verifying records and exporting Trust Packets — with a read-only auditor role, so the person checking doesn’t hold the keys.

Risk on a 5×5 matrix

Risks are scored on a 5×5 likelihood-impact matrix, and high-band risks synthesize quarantine rules automatically — the register isn’t a spreadsheet off to the side, it feeds enforcement.

Three catalogues

The frameworks, and what the gate can honestly evidence

A gateway sees traffic, decisions, and policies — so that’s what it can evidence. Where a control needs something a gateway can’t see, the catalogue says so rather than pretending.

EU AI Act

Records of operation

Article 12 asks for automatically generated records of a high-risk system’s operation. The signed decision ledger is exactly that — every request, verdict, and policy version, produced in the path rather than reconstructed after the fact.

ISO/IEC 42001

AI management system

An AIMS needs operational controls that demonstrably run, not just documented intentions. The catalogue maps 42001 controls to the decision events that evidence them — enforcement, redaction, risk treatment, quarantine.

SOC 2

Trust services criteria

Where the criteria touch your AI traffic — monitoring, logical access, change control on policies — the catalogue ties them to signed events an auditor can verify independently, instead of screenshots collected the week before fieldwork.

No tool makes you compliant — including this one. Your obligations depend on your role and risk classification; what AnchorGate provides is evidence you can actually take into that conversation.

In the box

What ships today

  • EU AI Act control catalogue, including Article 12 records of operation
  • ISO/IEC 42001 control catalogue
  • SOC 2 control catalogue
  • Posture computed from signed decision events
  • Global posture view: asset topology and risk heatmap
  • Live decision stream over WebSocket
  • Risk register scored on a 5×5 matrix, feeding quarantine rules
  • Audit hub: verify records, export Trust Packets
  • Admin and read-only auditor roles

As shipped in AnchorGate v0.1 — every line above is checkable against the repository.

3
control catalogues: EU AI Act · ISO/IEC 42001 · SOC 2
5×5
risk matrix — high-band risks synthesize quarantine rules
L5
evidence grade the posture is computed from

Catalogues and grading as shipped in AnchorGate v0.1. No tool makes you compliant — including this one.

FAQ

Compliance posture questions

How is posture actually calculated?
From the ledger. Each control in a catalogue maps to the decision events that evidence it — enforcement verdicts, redactions, MCP refusals, quarantines. Posture reflects what the gate demonstrably did over the window, not what a policy document says should happen. If traffic doesn’t cross the gate, it doesn’t count, and the asset topology shows you where that is.
Which frameworks are covered, and how deep?
Three catalogues ship in v0.1: the EU AI Act — including the Article 12 records-of-operation requirements — ISO/IEC 42001, and SOC 2. Each is a concrete mapping from controls to evidence types, not a checkbox list. Depth varies by control; where a control can’t be evidenced from gateway decisions, the catalogue says so rather than pretending.
What does the auditor role see?
A read-only view of the same records: the posture, the decision stream, and the audit hub where they verify signatures and export a Trust Packet. The auditor can check everything and change nothing — verification never requires trusting whoever operates the dashboard.

Walk into the audit with a ledger, not a binder.

Posture that recomputes with every decision, and evidence your auditor verifies offline. Self-hosted and open source — see it on your own traffic this week.

Deploy the stack

or email hello@anchorgate.ai