compliance · ISO 27001

Wytness and ISO 27001

Annex A evidence for the AI-agent activity in your ISMS scope.

ISO 27001:2022 audits your Information Security Management System. Where that system now includes AI agents, Wytness evidences the Annex A logging, monitoring, and operations controls for that activity. The ISMS itself — scope, risk assessment, Statement of Applicability — stays yours.

the artefact

What's in the pack

An ISO 27001 pack contains the agent and tool inventories, monitoring evidence per control, signed event samples, and a control-by-control narrative aligned to your Statement of Applicability.

Every claim in the pack is traceable: each control cites the events behind it, and each event carries the signature your own key produced. The pack is sealed, so an auditor can confirm it reached them unaltered.

A real sealed pack is published — nothing here is a mock-up. Download the specimen and check it yourself on the verify page, in your browser, without uploading it. It is a SOC 2 (Trust Services Criteria) pack — the seal and the per-event signatures work identically whichever framework you generate.

evidence-pack.json
ISO 27001 evidence pack

// What the pack asserts about itself:

meta.framework_label:"ISO 27001:2022"
meta.verification_model:"agt_merkle_plus_wytness_envelope"

// control_mapping[] — 6 criteria, each carrying
// its evidence and a metric measured over your period:

A.5.15:"Access control"
A.8.15:"Logging"
A.8.16:"Monitoring activities"
A.8.17:"Clock synchronisation"

// + 2 more, in the table below

// Every control cites events an auditor can re-verify:

sample_events[].wytness_envelope_signature:"…"Ed25519
crypto.signing_keys[]:public keys + fingerprints
verification.signed_payload:the exact bytes the signature covers

the mapping

What we map to what

ControlNameWhat Wytness provides
A.5.15Access controlFour-tier role-based access control (viewer / member / admin / owner) enforced server-side on every route; per-agent identity bound to a customer-held Ed25519 signing key; every access event recorded in the platform audit log with actor, target, and source IP.
A.8.15LoggingEvery tool call, resource access, and inter-agent message is logged and hash-chained (tamper-evident); each event carries a per-event Ed25519 signature; chain breaks surface as anomalies; a separate platform audit log records administrator actions.
A.8.16Monitoring activities7 anomaly-detection rule families run against the live event stream (first-time tool use, capability drift, frequency spikes, error spikes, restricted-data access, off-hours activity, hash-chain breaks) with automated severity-classified alerting; /readyz health checks feed platform monitoring and alerting.
A.8.17Clock synchronisationEvent timestamps are captured server-side in the customer's environment on NTP-synchronised container hosts; the original event timestamp is preserved verbatim through ingest so ordering and drift analysis use the customer's own clock.
A.8.23Web filtering (agent egress)Tool calls and outbound resource accesses are logged with destination metadata so agent egress is auditable. Shield policy authoring surfaces egress-approval rules in observe mode (enforcement targeted Q4 2026). Wytness records egress; it does not filter the customer's own server-side traffic.
A.8.28Secure coding (secret handling)Customer-held signing and pseudonymisation keys are generated in the browser and never reach Wytness (private bytes stay local); SQL access is parameterised and enforced by a CI linter; per-org connector secrets are encrypted at rest with AES-256-GCM.

the boundary

What Wytness does not cover

  • ISO 27001 covers an entire ISMS programme. Wytness evidences the AI-agent-activity controls; it does not implement risk management, supplier management, or HR security on your behalf.
  • ISMS scope decisions, risk assessments, and the Statement of Applicability are operator deliverables. Wytness gives you evidence for the controls in scope; the scope itself is yours.

Questions about your ISMS audit? Ask us.

We set no cookies. Sign-in and preferences use essential first-party browser storage only — no tracking, advertising, or third-party analytics. Privacy Policy