EthiCompass

The Framework

Eight dimensions of measurable trust.

We decompose trust into eight measurable, auditable dimensions. Each scores your AI system’s behavior, is independently traceable, and rolls up to the frameworks you report against.

Measurement on one axis. Certification on the other.

These eight dimensions are the measurement axis: they score behavior, buyer-facing and worldwide.

Each rolls up through the nine control areas of ISO 42001 Annex A to the frameworks you answer to. That roll-up, from a measured finding to governance evidence, is the bridge no output tester and no auditor owns.

What each dimension catches.

Every dimension is scored independently and traced back to the attack that produced the finding.

01

Fairness & Non-Discrimination

Bias, stereotyping, and unequal treatment across protected groups.

A failure looks like a different answer, tone, or refusal depending on a name, a gender, or an origin. We probe it with paired and counterfactual inputs, not keyword lists, so we catch bias that never uses a slur.

EU AI Act · Art. 10

02

Safety & Harmful Content

Hate, violence, self-harm, sexual content, and dangerous instructions.

The hard cases carry no obviously toxic wording: harm framed as a hypothetical, a story, or a step-by-step guide. We test lexical and non-lexical harm both, so a polite-sounding answer can still fail.

General

03

Transparency & Explainability

Unfaithful explanations, sycophancy, and undisclosed AI.

A model that agrees with whatever you assert, or explains a decision it didn't actually make, fails here even when the answer sounds reasonable. We check whether the stated reasoning matches the real behavior.

EU AI Act · Art. 13

04

Privacy & Data Protection

PII leakage, training-data extraction, and system-prompt disclosure.

We test whether the system can be coaxed into revealing personal data, its own hidden instructions, or memorized training content, the three ways a model quietly becomes a data-exfiltration path.

GDPR

05

Factuality & Accuracy

Hallucination, fabricated citations, and misinformation.

Beyond open-domain hallucination, we check faithfulness to the source material you ground the system on, and catch confident citations to sources that don't exist.

EU AI Act · Art. 15

06

Robustness & Adversarial Resilience

Prompt injection, jailbreaks, encoding tricks, and adversarial suffixes.

This is the input side: can a crafted message push the model past its own guardrails? We measure how hard it is to break, over many attempts, not whether it can be broken once.

EU AI Act · Art. 15

07

Security & Access Control

Unauthorized actions, privilege abuse, identity spoofing, and tool misuse.

For AI that can act, not just answer: we test whether it calls the right tools, with the right parameters, in the right order, and refuses actions outside its authority.

Agentic AI

08

Accountability & Human Oversight

Oversight saturation, governance evasion, and traceability.

We test whether the system stays within its escalation policy, keeps a human in the loop where one is required, and leaves a trail that ties every action back to whoever is accountable for it.

EU AI Act · Art. 14

Where the dimensions come from.

Grounded in trustworthy-AI research

The dimension names come from established trustworthy-AI principles (EU HLEG, OECD), not from any single regulation. They were developed by PhD researchers and validated through peer-reviewed publications.

Re-founded for multi-framework roll-up

Each dimension anchors to specific EU AI Act articles and GDPR, then rolls up through the nine control areas of ISO 42001 Annex A to the frameworks you answer to, rather than to a single article.

Regulatory compliance is not a dimension

It's the certification that follows once the measurements hold. Keeping it off the measurement axis is what keeps the eight dimensions framework-neutral and worldwide.

See these eight dimensions
scored on your AI.