Regulatory Automation

COMPLIANCE

Pre-built compliance for EU AI Act, SOC 2, and ISO 42001. Automated risk classification, gap analysis, evidence generation, and remediation tracking.

3Frameworks
<10sAssessment Time
AutoEvidence Generation

See it in action

custodex.vercel.app
COMPLIANCE — Custodex Dashboard

Article-by-article compliance. Automated.

Full implementation of Regulation 2024/1689: Article 5 (prohibited practices detection), Article 9 (risk management), Article 10 (data governance), Article 11 (technical documentation), Article 14 (human oversight), Article 52 (transparency). Risk categories: Prohibited, High-Risk, Limited, Minimal.

Cloud security controls. Evidence from day one.

Controls mapped across CC6 (logical access), CC7 (system monitoring and logging), CC8 (information system monitoring), CC9 (incident management), plus A.6-A.12 security procedures. Evidence auto-generated from audit logs, policy evaluations, and agent telemetry.

AI management systems standard. Fully covered.

Sections A.6-A.12 implemented: information security assessment, access control, cryptography and key management, audit and accountability, asset management, physical security, and operations security. Control mapping with evidence templates and assessment procedures.

Automated risk scoring across 4 dimensions.

Questionnaire-based assessment scores agents across Data Access (PII, financial, health), Decision Autonomy (approval requirements, financial authority), Impact Potential (human rights, employment, infrastructure), and Reversibility (non-reversible actions, intervention requirements). Produces risk levels: Minimal, Limited, High, Unacceptable.

const assessment = classifier.classify(
  "agent_123",
  "Customer Service Bot",
  {
    accessesPII: true,
    accessesFinancialData: false,
    requiresHumanApproval: false,
    canMakeFinancialDecisions: true,
    financialLimit: 500,
    actionsReversible: true
  }
);

// { riskLevel: "limited", riskScore: 45 }

What's included in
compliance

01

EU AI Act: Article-by-article compliance automation

02

SOC 2 Type II: CC6-CC9 control evidence generation

03

ISO 42001: Full AI management systems coverage

04

Automated risk classification across 4 dimensions

05

Gap analysis with remediation tracking

06

Evidence packages: PDF, JSON, Markdown, SIEM export