Pass your next AI audit.

Altrace produces the evidence your compliance team needs — automatically. Every governance decision is recorded in a tamper-evident audit trail. Point your auditor at the dashboard, not a pile of log files.

Compliance evidence for the frameworks that matter

EU AI Act

Deadline: August 2, 2026

The EU AI Act requires demonstrable human oversight, risk management, and transparency for AI systems. Altrace enforces these requirements automatically and produces the evidence auditors need to verify compliance.

SOC 2 (Evidence-Ready)

Trust Service Criteria

SOC 2 auditors ask: "Can you prove your AI agents are governed?" Altrace records every governance decision — allow, block, warn, kill — in a tamper-evident audit trail with full context. Continuous evidence, not periodic snapshots.

AIUC-1

33 of 51 controls covered

AIUC-1 is the emerging standard for governing autonomous AI agents. Altrace covers 24 controls fully and 9 partially — the broadest coverage available. Compliance status is reported automatically, not assembled manually.

NIST AI RMF

Covers 23 of 26 subcategories across all four functions. Provides runtime enforcement evidence that maps directly to your risk management framework.

MITRE ATLAS

Addresses 12 of 16 applicable adversarial AI techniques. Protects against reconnaissance, unauthorized access, data exfiltration, and impact attacks on your AI systems.

How Altrace proves compliance

Governance is enforced at the infrastructure layer, below the application. Your agents cannot bypass controls — and every action is recorded for audit.

Infrastructure-Layer Enforcement

Controls are enforced below the application layer. Agents have no path to bypass governance, regardless of how they are coded or configured.

Tamper-Evident Audit Trail

Every governance decision recorded in an immutable chain. Auditors get structured records with clear reason codes — not raw log files to parse.

Instant Kill Switch

One action blocks all AI requests for a team or agent. The kill switch stays active through restarts — proving human oversight capability to any auditor.

Delegation Controls

When agents delegate to other agents, authority can only shrink — never grow. Budget, model access, and tool permissions are restricted at each level of delegation.

Budget Governance

Per-team and per-agent spending limits with graduated enforcement. Soft limits generate warnings. Hard limits block requests before they incur cost.

Privacy-Preserving Design

Content classification produces yes/no labels only. Your data is never extracted, stored, or transmitted to any third party. Ideal for regulated industries.

Additional framework coverage

OWASP LLM Top 10

Protects against the most common AI security risks: prompt injection, system prompt leakage, tool poisoning, and supply chain attacks.

OWASP MCP Top 10

Covers 8 of 10 MCP-specific risks: privilege escalation, tool poisoning, prompt injection, audit logging, shadow MCP servers, and authentication.

HIPAA

Addresses technical safeguards for AI processing PHI: access controls, audit trails, content classification for 22-country PII/PHI patterns.

ISO 42001

Supports AI management system requirements through structured governance, automated risk assessment, and continuous audit evidence.

Cisco AI Security & Safety Framework

Maps to Cisco's AI security controls for agentic systems: access control, runtime monitoring, anomaly detection, and governance auditability across multi-agent deployments.

Ready to prove compliance?

Request access and we will walk through how Altrace maps to your specific regulatory requirements.