Built for the frameworks targeting custom AI agents.
Enterprise GRC is catching up to Agentic AI fast. VisIQ is the runtime layer that makes your custom AI agent stack auditable today, before examiners come asking.
Every decision, governed and signed. Live.
Tamper-evident evidence
Every decision becomes a signed record.
When VisIQ permits, denies, or escalates an agent action, it writes a cryptographically signed record: Merkle-chained and timestamp-anchored. Nothing can be edited or backdated after the fact, so the evidence you hand an auditor is provably the evidence that was captured at runtime.
Watch a live decision harden into signed, tamper-evident evidence.
Applicability
Which frameworks apply to you?
Regulatory exposure depends on where you operate, what you build, and who you sell to. Point us at your website and we'll map the frameworks that apply, or tell us about your operations directly.
Or tell us about your operations:
Tap a framework to include or exclude it.
Control explorer
Read every control against the source text.
Pick a framework and walk its controls. Each one maps to the exact clause of the regulation, and to how VisIQ enforces it at runtime. This is the live platform surface, embedded.
Framework
Hover a control to see the exact regulation text scroll into view.
Audit certificate
Hand the auditor a formatted receipt.
For any control, VisIQ renders a self-contained audit certificate: the control, its source clause, the enforcement primitive, and the signed evidence backing it. Below is the certificate for the EU AI Act's Article 12 event-logging requirement.
EU AI Act · Article 12: Automatic event logging, signed and retained.
01
SOC 2 Type II
Trust Services Criteria for AI Operations
SOC 2 examines whether access to systems is authorized, logged, and bounded. Custom AI agents create a new gap: they can act on behalf of users without traditional access controls applying to them. VisIQ closes that gap at the runtime layer.
→CC6, Logical Access: ALLOW enforces pre-authorized boundaries per custom agent identity before any action runs
→CC7, System Operations: RECORD produces verifiable enforcement artifacts for operations reviews and auditor sampling
→CC9, Risk Mitigation: ISOLATE prevents custom agents from reaching data or systems outside their defined scope
02
NIST AI RMF
AI Risk Management Framework: Govern, Map, Measure, Manage
The NIST AI RMF requires organizations to govern AI system behavior and manage risk across the full deployment lifecycle. VisIQ implements the enforcement and documentation layer the framework calls for, at runtime, not just on paper.
→GOVERN: Policy controls embedded in the runtime, not just documented in a handbook
→MAP: Custom agent behavior is bounded and traceable across all systems and actions
→MEASURE: Every enforcement decision is captured and queryable for risk reporting
→MANAGE: Real-time blocking prevents harm before it occurs; escalation routing adds human oversight
03
EU AI Act
High-Risk System Requirements: Articles 9, 12, 14 & 19
The EU AI Act mandates risk management systems, logging, and human oversight for high-risk AI applications. Agentic AI systems operating in enterprise contexts will face significant scrutiny under these provisions. VisIQ is aligned with these requirements from day one.
→Article 9, Risk Management: Continuous controls enforced at runtime, not assessed post-hoc
→Articles 12 & 19, Record-Keeping: RECORD produces comprehensive, tamper-evident enforcement logs, with retention configurable past the six-month floor Article 19 requires
→Article 14, Human Oversight: ALLOW supports escalation routing for human-in-the-loop review of sensitive actions
04
ISO 42001
AI Management System Standard
ISO 42001 establishes requirements for organizations deploying AI responsibly, including documented controls, operational boundaries, and ongoing monitoring. VisIQ is the control layer that makes ISO 42001 attestation achievable for Agentic AI environments.
→Clause 6.1, Risk planning: Automated boundary enforcement replaces ad hoc policy review cycles
→Clause 8.4, AI system impact assessment: Decision context captured for every custom agent action, at every step
→Clause 9.1, Performance evaluation: Enforcement data is queryable and reportable across all custom agent operations
We decide what's allowed.
With the receipts to prove it.
Hand the auditor receipts
Auditable the day you turn it on.
93 controls mapped across 11 frameworks, from day one, with explicit support levels, not blanket completion. See the runtime evidence for yourself.