compliance · ISO 27001
Wytness and ISO 27001
Annex A evidence for the AI-agent activity in your ISMS scope.
ISO 27001:2022 audits your Information Security Management System. Where that system now includes AI agents, Wytness evidences the Annex A logging, monitoring, and operations controls for that activity. The ISMS itself — scope, risk assessment, Statement of Applicability — stays yours.
the artefact
What's in the pack
An ISO 27001 pack contains the agent and tool inventories, monitoring evidence per control, signed event samples, and a control-by-control narrative aligned to your Statement of Applicability.
Every claim in the pack is traceable: each control cites the events behind it, and each event carries the signature your own key produced. The pack is sealed, so an auditor can confirm it reached them unaltered.
A real sealed pack is published — nothing here is a mock-up. Download the specimen and check it yourself on the verify page, in your browser, without uploading it. It is a SOC 2 (Trust Services Criteria) pack — the seal and the per-event signatures work identically whichever framework you generate.
// What the pack asserts about itself:
// control_mapping[] — 6 criteria, each carrying
// its evidence and a metric measured over your period:
…// + 2 more, in the table below
// Every control cites events an auditor can re-verify:
the mapping
What we map to what
| Control | Name | What Wytness provides |
|---|---|---|
| A.5.15 | Access control | Four-tier role-based access control (viewer / member / admin / owner) enforced server-side on every route; per-agent identity bound to a customer-held Ed25519 signing key; every access event recorded in the platform audit log with actor, target, and source IP. |
| A.8.15 | Logging | Every tool call, resource access, and inter-agent message is logged and hash-chained (tamper-evident); each event carries a per-event Ed25519 signature; chain breaks surface as anomalies; a separate platform audit log records administrator actions. |
| A.8.16 | Monitoring activities | 7 anomaly-detection rule families run against the live event stream (first-time tool use, capability drift, frequency spikes, error spikes, restricted-data access, off-hours activity, hash-chain breaks) with automated severity-classified alerting; /readyz health checks feed platform monitoring and alerting. |
| A.8.17 | Clock synchronisation | Event timestamps are captured server-side in the customer's environment on NTP-synchronised container hosts; the original event timestamp is preserved verbatim through ingest so ordering and drift analysis use the customer's own clock. |
| A.8.23 | Web filtering (agent egress) | Tool calls and outbound resource accesses are logged with destination metadata so agent egress is auditable. Shield policy authoring surfaces egress-approval rules in observe mode (enforcement targeted Q4 2026). Wytness records egress; it does not filter the customer's own server-side traffic. |
| A.8.28 | Secure coding (secret handling) | Customer-held signing and pseudonymisation keys are generated in the browser and never reach Wytness (private bytes stay local); SQL access is parameterised and enforced by a CI linter; per-org connector secrets are encrypted at rest with AES-256-GCM. |
the boundary
What Wytness does not cover
- —ISO 27001 covers an entire ISMS programme. Wytness evidences the AI-agent-activity controls; it does not implement risk management, supplier management, or HR security on your behalf.
- —ISMS scope decisions, risk assessments, and the Statement of Applicability are operator deliverables. Wytness gives you evidence for the controls in scope; the scope itself is yours.