← How it's designed

Standards alignment

How we recommend aligning your private AI with the standards that matter.

One guide per standard. Each lists what the standard requires, the approach we recommend, the configuration that implements it, and how you confirm it's working — shown, not asserted. Start anywhere; the free Readiness Check tells you where you stand.

Assert
"We're NIST-aligned." Anyone can say it.
Map
Where each control lands in the design.
Recommend & show · here
The requirement, the configuration, and how you see it work.
Read this honestly. These are recommended alignment guides with configurations you can verify — not certifications. Formal certification (ISO 42001, SOC 2, HITRUST) is a separate third-party audit against your specific deployment; these guides are built to make that audit straightforward.

Who can connect

The Zero Trust boundary — no implicit network trust

NIST SP 800-207 The Zero Trust reference architecture — the seven tenets, each mapped to a configuration. Guide readyView guide →
CISA Zero Trust Maturity Model The federal ZT roadmap — five pillars, four maturity stages. Plannedsource
CSA Zero Trust Cloud Security Alliance Zero Trust guidance and training. Plannedsource

What the AI may do

AI governance — scope, oversight, and evidence

NIST AI RMF Govern, Map, Measure, Manage the AI's risk — all 19 categories mapped to guardrails, approvals and the reality-check. Guide readyView guide →
ISO/IEC 42001 The AI management-system standard (AIMS) — policy, roles, controls. Plannedsource
EU AI Act Risk-based obligations, including human oversight of high-stakes use. Plannedsource
CSA AI security Cloud Security Alliance AI security & governance guidance. Plannedsource

Prove what happened

Audit & detection — the record you can show

NIST CSF 2.0 Govern / Identify / Protect / Detect / Respond / Recover. Plannedsource
CIS Controls v8 Prioritized safeguards — inventory, access control, audit logging. Next upsource

Where your data lives

Data protection — residency & handling your sector requires

Sector & regional rules HIPAA, GLBA, NAIC, CJIS and ISO 27001 — thin overlays that point back to the Zero Trust, governance and audit guides above. PlannedHIPAANAIC

Two ways through this

Not sure where you stand?

The free Readiness Check scores you against these frameworks and shows which need work — then the build puts the recommended configuration in place.

Start the free Readiness Check →