Answer questions about AI risk and compliance with hard evidence.

Know what your agents were allowed to do. Know what they actually did. Prove it.

PRAE records what every agent is allowed to do and what it actually did. Every policy decision, approval and outcome it sees becomes part of a verifiable audit trail — giving security, engineering and compliance teams the evidence they need to govern AI agents and demonstrate how they are controlled.

See the evidence →Read a chained ledger →

Policy → Decision → Execution → Evidence

  1. 01

    Policy

    What each agent may do, as data: a versioned — and optionally signed — pack of rules.

  2. 02

    Decision

    Every tool call judged before it runs: allowed, refused, or held for a human, with the rule that decided.

  3. 03

    Execution

    Only allowed calls run; a held call runs only after an approval bound to that exact action.

  4. 04

    Evidence

    Every decision sealed in a hash-chained ledger, signed with your key — history no one can quietly rewrite.

The evidence each decision leaves

Not a checklist: the record of what was allowed and what happened, one row per decision.

Agent and session context
Which agent and session made the call, and the assembled prompt it was given, sealed as a hash.
Policy evaluated
The pack and version in force; a signed pack names the key that signed it.
Requested action
The tool and its target. Secrets and command lines are kept as hashes, never in clear.
Decision
Allow, deny, or held for a human.
The control that decided
The rule, its reason, and the full match trace.
Approval
For a held call, the operator key that approved it — bound to the exact action approved.
Execution outcome
Whether a released call ran or failed, and whether a tool result was withheld.
Prevented and detected behaviour
Refusals before execution; credentials and untrusted content found in what agents read and returned.
Verifiable history
Each row hash-chained to the last, and signed when a signing key is set; any row exports as a receipt anyone can check without our systems.

Mapped to the frameworks you answer to

PRAE maps its controls and evidence to these frameworks. Mapping is support, not certification — each is labelled for what is mapped today.

  • ISO/IEC 42001:2023

    AI management systems

    Annex A: AI policy (A.2.2), operation and monitoring (A.6.2.6), event logs (A.6.2.8), intended use (A.9.4).

    Mapped
  • EU AI Act

    Logging, record-keeping and governance obligations

    Art. 12 record-keeping. Risk management, technical documentation and conformity obligations remain the organisation’s; PRAE’s evidence can support them.

    Mapped in part
  • NIST AI RMF

    AI risk management and governance

    Through the NIST AI 600-1 Generative AI profile: trustworthy AI in policy (GV-1.2) and regular safety evaluation (MS-2.6).

    Mapped in part
  • MITRE ATLAS

    Adversarial threats and attack techniques against AI systems

    Not mapped yet. Mapping PRAE’s controls to ATLAS techniques is planned.

    Mapping planned
  • OWASP Top 10 for LLM Applications 2026

    Application-level LLM and agent security risks

    All ten risks: which rules in your pack address each, and — where a runtime gate is not the control — why not.

    Mapped
  • OWASP Top 10 for Agentic Applications 2026

    Agent-specific security risks

    All ten risks, assessed the same way.

    Mapped
  • ISO/IEC 27001:2022 · SOC 2

    Information security controls

    ISO 27001 Annex A access restriction, data leakage prevention, logging and monitoring; SOC 2 CC6.1 and CC7.2.

    Mapped

How the evidence reaches your audit

Compliance workspace

Choose the frameworks, controls, agents and period that matter; see the evidence behind each control.

Signed receipts

Any decision as a self-contained receipt an auditor verifies against a key they already trust.

SIEM events

Decisions as OCSF events for your SIEM or data lake.

GRC evidence

A structured evidence export for governance, risk and compliance tools.

PRAE provides controls and evidence that support AI compliance programmes. It is not a certification, it does not make an organisation compliant with any regulation or standard, and it gives no legal advice: an auditor decides whether the evidence satisfies an obligation.