compliance

Mapped to your auditor's framework

Wytness doesn't make you compliant. It gives you the evidence to demonstrate that you are — per framework, mapped to the articles and controls your auditor cares about.

EU AI Act

MAPPED

Articles 12, 13, 15 → Evidence Pack mapping.

Read the mapping →

SOC 2 Type II

MAPPED

CC6.1, CC6.6, CC7.2, CC7.3, CC8.1 → Evidence Pack mapping.

Read the mapping →

ISO 27001:2022

MAPPED

Annex A logging, monitoring, access, operations → mapping.

Read the mapping →

GDPR

MAPPED

Articles 5, 25, 30, 32 → mapping; Article 30 ROPA export Q3 2026.

Read the mapping →
IN PROGRESSHIPAA§164.312(b) audit controls · §164.308(a)(1)(ii)(D) activity review
IN PROGRESSAPRA CPS 230 / 234§35 incident response · §47 critical-operations incident management
IN PROGRESSNIST AI RMF 1.0MEASURE + MANAGE via signed trail, anomaly engine, approval gates

Control matrices are being collected — ask us for scope.

the artefact

What's in an Evidence Pack

The pack is the artefact you hand an auditor: a structured report you can print, and a signed, dated JSON download carrying the signed events behind every claim.

  • Agent inventory with capability descriptions and risk classifications
  • Per-agent event counts, error rates, and anomaly history
  • Sampled events with signature verification and chain attestations
  • Control-by-control mapping with the events that evidence each control
  • Dated auditor cover sheet, with the JSON download sealed by the Wytness key
app.wytness.ai · chain
every agent's chain, verified and datedbreaks surfaced, not buried ✓

Questions about compliance? Ask us.

We won't pretend an Evidence Pack replaces your auditor. We'll tell you what we map, what we don't, and where the boundary sits.

We set no cookies. Sign-in and preferences use essential first-party browser storage only — no tracking, advertising, or third-party analytics. Privacy Policy