Private design-partner engagements now open

Your AI compliance program rooted in documentation evidence.

Namus reads your code, infrastructure and policy in place, then returns a control-by-control compliance record for Texas TRAIGA.

87%

say they have an AI governance framework

<25%

have implemented the controls it calls for

AuditBoard, 2025
Who it's for

The same gap lands on four different desks.

The Namus Evidence Record.

One control, one rule, one system, and what the code actually says about it.

Works with Bedrock, Vertex AI, Azure OpenAI, LangChain, LangGraph, Crew AI, HuggingFace and OpenAI API.

1 Pick a system
2 Set the rules in scope
3 Run it
namus evidence record, sample
controls in scope
Met Partial Gap

What a finding means

Namus reads what your system is written to do, from source, infrastructure and policy documents. A gap is not a claim that something failed in production, and it is not a failure of your team. It is a finding with a fix, and the clause it maps to.

Rules in. Evidence out.

SourcesEU AI Act, ISO 42001, NISTCSA AICM, OWASP, AIUC-1 and US state law
NamusOne control setEach control traced to every clause
Your systemRead directlyRuns on your own infrastructure
OutputEvidence RecordMet, partial or gap
DownstreamYour GRC toolExported as OSCAL

Every rule, one control set

Frameworks and statutes ask for overlapping things in different words. You answer the requirement once.

We read the system, not the paperwork

Your source, IaC and configuration, checked control by control against what each rule requires.

A record your auditor accepts

Findings ship with the artifacts behind them and export as OSCAL. No new system of record.

Nothing leaves your infrastructure.

The analysis runs inside your environment, under your access controls. Namus receives aggregate gap counts and nothing else.

Nothing is uploadedNo inbound network access requiredNo third party holds your evidence

Most of compliance is looking for things you already have.

The evidence exists. It is spread across repositories, consoles and people's memories, and someone has to go and collect it by hand every cycle.

Assembled by hand
  • Engineering is asked whether the agent validates its output
  • The answer comes back from memory or from a manual check
  • A config screen is captured into an evidence folder
  • The questionnaire is answered in prose
  • The next cycle starts over

Run it on the release, not on the audit. Evidence produced once a year is accurate on the day it is written and drifting by the time anyone reads it.

Built for the rules written for AI.

We only cover AI. If SOC 2 is what you need, we know people who do it well.

Readiness kyc-review-assistant percent covered, controls met
Frameworks and standards

EU AI Act

High-risk obligations, Art. 9 to 15. Annex IV documentation.

NIST AI RMF

Govern, Map, Measure and Manage at subcategory level.

ISO/IEC 42001

AI management system controls and Annex A.

CSA AICM

Domain-level AI control implementation.

OWASP LLM Top 10

Application-layer AI risk in production.

AIUC-1

Six domains, 130 controls, independently audited.

US state law in force

Texas TRAIGA

HB 149. Prohibited uses and disclosure duties, since January 2026.

California SB 53

Frontier model transparency and safety reporting.

Illinois HB 3773

AI in employment, under the Human Rights Act.

NYC Local Law 144

Bias audits for employment decision tools.

Utah AI Policy Act

SB 149, as amended. Generative AI disclosure.

California AB 2013

Training data provenance disclosure for generative systems.

Effective January 2027

New York RAISE Act

Safety protocols and 72-hour incident reporting.

Colorado SB 26-189

Automated decision-making. Replaced SB 24-205.

State law moves faster than any control catalog. Take Colorado. SB 24-205 passed in 2024, was delayed twice, then repealed and replaced before it took effect. One control set means a statute change re-points a clause reference rather than restarting your program.

Get compliant now.

Request a free baseline assessment below. You pick your highest-stakes AI system, we run it against the rules that apply, and you keep the record.

One production systemYou choose it. We scope it on the call.
The Evidence RecordControl by control, traced to the clause.
A working sessionWe walk the findings and leave the record with you.
Get Compliant Now

Design-partner engagements are limited while we build. If your system is out of scope we will say so on the call.

Get Compliant Now