Compliance mapping as a service

The mapping layer, sold separately.

Every AI security product eventually has to answer “which control does this satisfy?” Building that mapping means watching frameworks that move, extracting normative requirements, deciding honestly what can be detected and what can only be attested, and keeping all of it current. We do that work continuously and deliver it as a versioned pack. Use it inside Agenor Attest, or license it for your own product.

Counts, never percentages · unknowns render as unknown · every requirement anchored to a source hash

What is actually in it today

951 requirements. 13 frameworks. 43 pins watched.

These are counts from the live corpus, not a roadmap. The frameworks below carry extracted requirement records; the 43 pins are what we watch for version movement, which is a larger set than what we have finished extracting.

MCP specificationNormative MUST / MUST NOT clauses from the protocol spec itself · 506
MITRE ATLASAdversary techniques and sub-techniques, pinned to a release asset · 224
AIUC-1Certification standard, tracked against its published changelog · 53
NIST AI 600-1Generative AI profile risks and actions · 49
ATF conformanceAgentic Trust Framework conformance requirements · 25
NIST SP 800-218ASecure software development practices for generative AI · 20
NIST SP 800-53The control families that carry over to agent systems · 20
EU AI ActObligations extracted from the legal instrument itself · 13
OWASP AISVSAI security verification standard · 12
OWASP MCP Top 10MCP-specific risk classes · 10
OWASP LLM Top 10The 2026 edition · 10
ATF crosswalksMappings between the frameworks above · 5
NIST AI RMFGovern / map / measure / manage functions · 4

The part nobody else does honestly

Every control is dispositioned, including the ones we cannot detect.

A mapping that claims coverage of everything is worthless, because the buyer discovers the gaps during the audit instead of during the sale. Each control carries a disposition and, where it is automatable, a scope. 18 controls are marked not-feasible, and they stay in the pack saying so.

835 automatable

A detector can, in principle, evidence this control from telemetry. Split further by scope: 257 in-scope for AI agents, 7 in-scope for cloud, 553 feasible but not yet in a shipped scope, and 18 ruled not-feasible.

210 manual attestation

No telemetry will ever evidence these. They need a human to assert something: a policy exists, a review happened, a person is accountable. Calling them automatable would be the easiest lie in this business.

18 not-feasible

Automatable in principle, and we judge that no detector we would build gives a useful signal on them. A scope ruling inside the 835, not a fourth bucket. It is the most consequential call in the schema, so it is flagged for human review every time regardless of the extractor's confidence.

Why mappings rot

A pinned file that returns 200 forever is not a current framework. It is an abandoned one.

Three columns, not one

We track what the publisher has shipped, what we captured, and what the product actually ships against. The gap between the last two is the one nobody else measures, and it is where a mapping quietly stops being true.

Hash-stable is not current

We pinned a framework artifact at a branch path. The publisher moved to tagged releases and abandoned it. The file kept returning 200, the hash stayed stable because the file was dead rather than because the standard was, and every check reported healthy. Unchanged bytes and current content are different claims.

The landing page lies last

A publisher's own landing page can advertise an old edition long after the current one ships elsewhere. A page that is maintained but no longer authoritative is more dangerous than one that 404s, because nothing ever breaks.

How it is delivered

A versioned, content-hashed pack. Not an API you have to trust.

Entitled by framework

You receive the frameworks you licensed, at a stated version, with a receipt you can verify offline. On renewal you can take a delta rather than the whole pack.

Detections are a separate good

The requirement mapping and the detection rules that evidence it cost different things to produce, so they are entitled separately. A mapping-only tier is a real tier, not a crippled one.

No percentages, anywhere

Reaching a control is not satisfying it, and a single blended coverage number is the most quotable and least true output this pack could produce. You get counts, and unknowns that render as unknown rather than as zero.

Want the pack, or want to see the gaps in your own mapping?

Tell us which frameworks matter to you and we will show you what we hold for them, including what we have marked not-feasible.