EthiCompass

Compliance

Compliance you can defend, not just claim.

We turn adversarial testing into readiness evidence, matched to the frameworks you answer to. And we’re honest about the line between what we measured and what’s yours to attest.

Readiness, not a verdict.

We never assert that your AI is legally compliant. No tool honestly can. What we produce is readiness: for each requirement of a framework, the evidence we have and the gaps that remain.

That distinction is the point. A vendor that hands you a compliance percentage is averaging what it measured with what it didn’t. Readiness keeps the two apart, so what you take to an auditor holds up.

Every requirement, in one of four honest states.

The readiness rollup for a framework is a count of these states, never a single percentage.

01

Covered

Technical or administrative evidence satisfies the requirement.

02

Open, needs declaring

An administrative artifact was expected and isn't there yet. We surface it; you attest it once.

03

Open, couldn't be measured

The test couldn't reach it this run, a dimension under its detection floor or one you didn't run. We say so instead of guessing.

04

Not attestable, yours

A purely organizational duty the platform neither measures nor attests for you. We mark it as your responsibility.

Two kinds of evidence, and one honest boundary.

Technical evidence

From adversarial testing: registered, hash-citable traces and calibrated findings across the eight dimensions.

Administrative evidence

Your attestations, collected once through a human gate before testing starts. Each administrative question is asked once and reused across every framework.

Your own duties

Some obligations are purely organizational. We don't pretend to measure or attest them for you, and we say which ones they are.

Frameworks

Two frameworks today, and a way to add the next.

A framework is a declarative crosswalk: a list of requirements, each mapped to technical evidence, an administrative question, or both. Adding one means writing its crosswalk, not rebuilding the engine.

EU AI Act

High-risk systems

Where our technical differential is strongest. Article 15 asks for measured resilience, so most of it is answered with evidence, not a questionnaire.

ISO 42001

AI management system

A management-system standard: much of it is attestable rather than technically verifiable. We mark which requirements we can measure and which you attest.

Mapping findings to frameworks is table stakes; everyone does it. The difference is the evidence underneath, and a trail that ties every readiness state back to the finding behind it.

Take readiness to your auditor,
not a percentage.

Readiness, not verdicts · ISO 42001 + EU AI Act · 8 Dimensions · Immutable Audit Trail