Standards alignment · control summary
Anyone can say "NIST-aligned." This page shows it instead — a walk-through, not a claim. For each control: the specific thing the configuration does, the layer that enforces it, and the evidence you can inspect for yourself. This is the substance an auditor, client, or insurer asks for.
Who can connect
The Zero Trust boundary · enforced at the Dark-access layer
What the AI may do
AI governance · enforced + advisory at the Guardrails layer
Prove what happened
Audit & detection · enforced across layers
Where your data lives
Data protection · enforced at the on-prem & Dark-access layers
What the evidence actually looks like
Three examples from the kinds of artifacts above.
$ nmap -Pn appliance.local
Host is up.
All 1000 scanned ports on appliance.local are filtered
(no service is reachable without an enrolled Ziti identity)
Illustrative sample — your report is generated against your own appliance.
2026-07-29 14:22:01 role=assistant action=read
file=/matters/acme/contract.pdf decision=ALLOW by=policy:reader
2026-07-29 14:22:09 role=assistant action=write
target=/matters/acme/summary.md decision=PENDING-APPROVAL
Illustrative sample — kept locally, exportable as your access record.
⚠ verifier: model reported "updated summary.md" —
no write occurred this turn. Warning appended before the
turn was returned. (deterministic post-turn check)
Illustrative sample — the same check described under "Measure" above.
Start with the free Readiness Check — it identifies where you stand against these frameworks. The build closes the gaps, and this evidence pack is what you're left holding.
Start the free Readiness Check →