Every AI interaction, checked against the frameworks you answer to
AegisPlane checks each live AI interaction against 12 frameworks and standards, 7 enforced article by article by the policy engine (OPA), plus 5 security and sector standards aligned through guardrails and rulepacks. It classifies risk, flags violations, and logs every decision as exportable evidence. Continuously, not once a year.
Enforced by the policy engine
7 frameworks, checked article by article on every request.

HIGH RISK
EU AI Act
We check each interaction against EU AI Act articles (Article 5 prohibited practices, Article 50 transparency, high-risk obligations), classify the risk tier, and log the decision with its article reference.
Learn more
GOVERN · MAP · MEASURE · MANAGE
NIST AI RMF
We check interactions against the NIST AI RMF Govern / Map / Measure / Manage functions and log each decision as supporting evidence for your risk program.
Learn more
DATA PROTECTION
GDPR
We check for personal-data handling in AI flows (purpose limitation, data minimization) and redact PII before the request reaches a provider, request-scoped and in-flight.
Learn more
HEALTHCARE
HIPAA
We check for protected health information (PHI) exposure in AI interactions and redact it before it leaves for a third-party provider, rehydrating on return.
Learn more
AI MANAGEMENT
ISO 42001
We check interactions against ISO 42001 AI management-system controls and produce the continuous, traceable records such a program requires.
Learn more
INFORMATION SECURITY
ISO 27001
We check AI traffic and provider access against ISO 27001 information-security controls: access control, logging, evidence retention.
Learn more
TRUST SERVICES
SOC 2
We log interactions, policy decisions, and access controls (RBAC, OIDC/SAML) as evidence aligned to the SOC 2 Trust Services Criteria, exportable for your audit.
Learn moreAlso aligned via guardrails & rulepacks
5 security and sector standards enforced through guardrails, PII redaction, and rulepacks, part of the same control layer, though not article-level policy checks.
OWASP LLM Top 10
AI SECURITY
Guardrails map to the OWASP LLM Top 10 (prompt injection, insecure output handling, sensitive-data disclosure) blocking these classes before the model runs.
MITRE ATLAS
ADVERSARIAL ML
Threat-informed guardrails aligned to MITRE ATLAS tactics for adversarial ML, from jailbreaks and prompt manipulation to model evasion.
PCI-DSS
PAYMENTS
PAN, card, and payment-data redaction keeps cardholder data out of third-party models, supporting PCI-DSS data-handling obligations.
CCPA / CPRA
US PRIVACY
Consumer-PII redaction and per-tenant data policies align with CCPA/CPRA data-minimization and disclosure duties.
DORA
EU FINANCE
Provider governance, resilience controls, and exportable audit evidence align with DORA operational-resilience expectations for financial entities.
Ready to get started
Continuous checks and evidence, not a stale annual assessment
Every selected framework is checked on live AI traffic and the decision is logged as evidence, so audit prep stops being a fire drill. No code changes.