Every one of these asks for a control and a piece of evidence.
Each asks for enforced controls, a tamper-evident audit trail, and a decision record you can read back. Compliance itself is organizational work and no tool makes you compliant; this is the technical half.
Where Swiftward provides the controls and the evidence
- EU AI Act — risk management, record-keeping, human oversight, and which duties are yours rather than ours. EU AI Act
- NIST AI RMF — the enforced controls and the audit trail behind Govern, Measure, and Manage; Map is your organizational work. NIST AI RMF
- OWASP LLM Top 10 — prompt injection, sensitive-data exposure, and more, as enforced policy. Prompt injection
- OWASP Agent Control Standard — how an agent is controlled before it acts: a hook before every action, and five answers from a separate process holding your rules. In plain words
- HIPAA and GDPR — the technical safeguards over what an assistant may say and what may leave: redaction, access control, the audit trail, on your own infrastructure. Healthcare
- SR 26-2 (April 2026, which replaced SR 11-7 and SR 21-8) puts generative and agentic AI outside its own scope — so your model-risk framework does not reach the agent-decision layer. Swiftward is the control and the audit trail for that gap; it feeds your model-risk process rather than replacing it. Risk & Compliance
- Financial crime: FFIEC BSA/AML, FinCEN, FATF, Wolfsberg — the controls you enforce.
The governance frameworks we back with technical controls
These define how your organization governs AI as a whole. Process satisfies most of each, but every one still needs technical control you can show, and an audit trail underneath.
- ISO/IEC 42001 — the AI management-system standard. Swiftward is the enforced-control and audit layer your management system points to.
- PMI's AI standard — managing AI as a project. We built the technical layer it calls for. The standard, chapter by chapter.
- OECD AI Principles — the cross-border baseline most national rules follow; Swiftward turns the accountability and traceability they ask for into running controls.
- Regional data-protection laws (CCPA/CPRA, PIPL, APPI, PIPA, DPDP, PDPA, and more) — met on your own infrastructure, with your data staying in your region, and redaction and audit built in.
The controls your review needs
Tell us what your security and compliance review requires. We map to the standards above today, and because Swiftward is declarative, a specific control and its evidence are usually a configuration change rather than a build. For SOC 2 and ISO 42001, our security page shows how running on your own infrastructure answers the same concern in the architecture; we take on the formal audits when a customer needs them.
Integrations
Forward decisions and audit events to your SIEM over standard syslog (RFC 5424, UDP or TCP) and to any system via webhooks. SSO through OIDC. The evidence lands where your security team already looks.
MITRE ATLAS
MITRE ATLAS is MITRE's knowledge base of adversary tactics and techniques against AI systems — the ATT&CK idea applied to AI, with agentic systems covered as a platform of their own. It is not a regulation and nobody audits you against it; it is a shared vocabulary, which is what makes it useful in a security review.
Where a control of ours answers a catalogued technique, we say which one: injection detection names three, and authorization names the one where a chain of permitted calls adds up to an exfiltration.