Compliance

EU AI Act, SOC 2, HIPAA.
One dashboard. One export.

Every AI event across browser, desktop, CLI, and MCP lands on one immutable, signed log with per-user attribution. Evidence, our signed compliance pack, turns that log into proof an auditor can read.

Start your 14-day trial Poke the live demo. No signup.
Discover and control your real AI exposure.
Browser · Desktop · CLI · MCP · Network
EU AI Act transparency rules apply from 2 August 2026; Article 26 deployer duties for Annex III high-risk systems from 2 December 2027. If an auditor asked today, what would you show them? One export answers it. The EU AI Act page →
Evidence

The evidence, not the promise of it.

Auditors do not accept good intentions. Evidence is a signed pack that maps your real AI activity to the controls each framework asks for. One export, timestamped and attributed to a person, gathered every day instead of reconstructed the week before the audit.

Frameworks covered

One log. The frameworks your auditor asks for.

The same signed evidence maps to every framework below. Start with the one your customers or regulators are pushing on.

EU AI Act
Inventory, attribution, and evidence for Article 4 AI literacy, Article 26 deployer obligations, and Article 50 transparency. See the EU AI Act page →
ISO 42001
The AI management system standard. The evidence pack supports the controls an auditor tests toward certification. See ISO 42001 →
SOC 2 + AI
AI events mapped to the Common Criteria for access, monitoring, and change. See SOC 2 for the AI era →
NIST AI RMF
Govern, Map, Measure, and Manage, each backed by real inventory and signed evidence. See NIST AI RMF →
HIPAA technical safeguards
Audit controls and access evidence mapped to 45 CFR 164.312: which AI tool touched what, attributed to a user, on a signed log. Technical-safeguards evidence for a business associate, not a HIPAA certification.
Already hold ISO 27001?
Extend the management system you already run to cover AI. The 27001 to 42001 bridge →
Where the evidence comes from

One immutable, signed log. Per-user attribution.

Every AI event across all four surfaces, plus the network layer, writes to a single append-only log. Signed and timestamped, so an auditor can trust it was not edited after the fact.

ATTRIBUTED
Each event carries a user, a tool, a category, a model, and a time. Not a mystery IP.
IMMUTABLE
Append-only and signed. Full event history for 13 months as standard, and signed logs retained 7 years on Enterprise.
EXPORTED
One click produces the pack, mapped to the framework controls your auditor reads.
Honest about what this is. An Evidence pack is accepted as part of your evidence library. It is not the audit itself. You still engage a certified auditor, a licensed CPA firm such as A-LIGN or Schellman, and Northbeams gives them clean, signed evidence to work from. We are also classified as a tool, not an AI provider, so your obligations hinge on how your team uses AI.
Feeds your stack

Into the GRC platform and SOC you already run.

Evidence does not replace your GRC platform. It supplies the AI evidence layer those platforms have been missing, and streams the same events into your SIEM.

  • Evidence automation with Vanta, Drata, OneTrust, and Scytale on Enterprise
  • SIEM streaming to Splunk and Microsoft Sentinel, Datadog on request
  • Immutable signed logs with 7-year retention on Enterprise
  • Owned by GRC? See the GRC and compliance view
GTIADrata
Memberships
Northbeams is a GTIA member and a Drata Alliance member, and the Service is independently penetration-tested. See the Trust Center.
EU AI Act·SOC 2 + AI·ISO 42001·NIST AI RMF·HIPAA technical safeguards·Signed evidence

Walk out of your next audit with the file, not the shrug.

One dashboard. One export. Your first evidence lands by Monday.

Start your 14-day trial Poke the live demo. No signup.