Compliance posture
Posture computed from decisions, not documents.
Most compliance posture is a folder of PDFs and a quarterly screenshot. AnchorGate computes it from the signed decision ledger instead: control catalogues for the EU AI Act, ISO/IEC 42001, and SOC 2 map onto what your gates actually enforced. No tool makes you compliant — this one shows you, continuously, what you could prove.
The mechanisms
From decision ledger to control catalogue
The pipeline is short on purpose: gates decide, decisions get signed, catalogues map signed decisions to controls. Nothing in the posture is asserted by hand.
Control catalogues, mapped to evidence
Concrete catalogues for the EU AI Act, ISO/IEC 42001, and SOC 2 tie each control to the decision events that evidence it — including the records of operation Article 12 of the EU AI Act asks for.
Computed, not asserted
Posture derives from the signed ledger: which policies fired, what was refused, what was redacted, which risks were quarantined. If the gate didn’t do it, the posture doesn’t claim it.
A dashboard built for the audit
Global posture with asset topology and a risk heatmap, a live decision stream, and an audit hub for verifying records and exporting Trust Packets — with a read-only auditor role, so the person checking doesn’t hold the keys.
Risk on a 5×5 matrix
Risks are scored on a 5×5 likelihood-impact matrix, and high-band risks synthesize quarantine rules automatically — the register isn’t a spreadsheet off to the side, it feeds enforcement.
Three catalogues
The frameworks, and what the gate can honestly evidence
A gateway sees traffic, decisions, and policies — so that’s what it can evidence. Where a control needs something a gateway can’t see, the catalogue says so rather than pretending.
EU AI Act
Records of operation
Article 12 asks for automatically generated records of a high-risk system’s operation. The signed decision ledger is exactly that — every request, verdict, and policy version, produced in the path rather than reconstructed after the fact.
ISO/IEC 42001
AI management system
An AIMS needs operational controls that demonstrably run, not just documented intentions. The catalogue maps 42001 controls to the decision events that evidence them — enforcement, redaction, risk treatment, quarantine.
SOC 2
Trust services criteria
Where the criteria touch your AI traffic — monitoring, logical access, change control on policies — the catalogue ties them to signed events an auditor can verify independently, instead of screenshots collected the week before fieldwork.
No tool makes you compliant — including this one. Your obligations depend on your role and risk classification; what AnchorGate provides is evidence you can actually take into that conversation.
In the box
What ships today
- EU AI Act control catalogue, including Article 12 records of operation
- ISO/IEC 42001 control catalogue
- SOC 2 control catalogue
- Posture computed from signed decision events
- Global posture view: asset topology and risk heatmap
- Live decision stream over WebSocket
- Risk register scored on a 5×5 matrix, feeding quarantine rules
- Audit hub: verify records, export Trust Packets
- Admin and read-only auditor roles
As shipped in AnchorGate v0.1 — every line above is checkable against the repository.
- 3
- control catalogues: EU AI Act · ISO/IEC 42001 · SOC 2
- 5×5
- risk matrix — high-band risks synthesize quarantine rules
- L5
- evidence grade the posture is computed from
Catalogues and grading as shipped in AnchorGate v0.1. No tool makes you compliant — including this one.
Works with the rest of the gate
Signed Evidence
Every decision signed with ECDSA P-256 over RFC 8785 canonical JSON, appended to an immutable ledger, graded L1–L5. An auditor can replay who acted, what was touched, and which policy fired.
Learn more →
Shadow-AI Discovery
Feed it DNS and HTTP egress logs and it inventories calls to 16+ AI provider domains — surfacing the copilots and scripts nobody registered. You can’t govern traffic you can’t see.
Learn more →
FAQ
Compliance posture questions
- How is posture actually calculated?
- From the ledger. Each control in a catalogue maps to the decision events that evidence it — enforcement verdicts, redactions, MCP refusals, quarantines. Posture reflects what the gate demonstrably did over the window, not what a policy document says should happen. If traffic doesn’t cross the gate, it doesn’t count, and the asset topology shows you where that is.
- Which frameworks are covered, and how deep?
- Three catalogues ship in v0.1: the EU AI Act — including the Article 12 records-of-operation requirements — ISO/IEC 42001, and SOC 2. Each is a concrete mapping from controls to evidence types, not a checkbox list. Depth varies by control; where a control can’t be evidenced from gateway decisions, the catalogue says so rather than pretending.
- What does the auditor role see?
- A read-only view of the same records: the posture, the decision stream, and the audit hub where they verify signatures and export a Trust Packet. The auditor can check everything and change nothing — verification never requires trusting whoever operates the dashboard.
Walk into the audit with a ledger, not a binder.
Posture that recomputes with every decision, and evidence your auditor verifies offline. Self-hosted and open source — see it on your own traffic this week.
Deploy the stackor email hello@anchorgate.ai