AI governance and compliance
CydraGovern
CydraGovern combines AI inventory, risk classification, control mapping, evidence collection and audit readiness. Its focus is continuous technical governance: classify a new AI system, map required controls, link runtime evidence, track gaps and create remediation tasks.
CydraGovern
Continuous technical governance
Turn runtime decisions into continuous compliance evidence.
Classify
Record EU AI Act risk tier and internal criticality for each AI system as it is discovered.
Map
Representative controls for EU AI Act, ISO/IEC 42001, NIST AI RMF, ISO/IEC 27001, GDPR, DORA, NIS2 and SOC 2. PCI DSS is on the roadmap.
Evidence
Mapping rules link gateway evidence records to the controls they demonstrate.
Remediate
Exceptions with expiry and justification; remediation tasks with owners; audit-readiness dashboards.
Capabilities
CydraGovern capabilities and status
Status reflects the current proof-of-concept build.
- Beta
AI-system classification
Classify AI systems by EU AI Act risk tier and internal criticality.
- Beta
Control mapping across frameworks
Representative controls for EU AI Act, ISO/IEC 42001, NIST AI RMF, ISO/IEC 27001, GDPR, DORA, NIS2 and SOC 2 mapped to runtime evidence.
- Roadmap
PCI DSS control coverage
PCI DSS listed as a framework; controls not yet seeded.
- Available
Evidence linked to runtime decisions
Gateway decisions become control evidence through mapping rules.
- Available
Exceptions and remediation tasks
Time-bound exceptions and remediation tasks with owners and justification.
- Available
Audit-readiness dashboards
Framework coverage, evidence freshness and open gaps at a glance.
- Available
- Implemented, tested and demonstrable in the current proof-of-concept build.
- Beta
- Implemented and demonstrable, with documented limitations.
- Preview
- Interface or mock implementation behind a real contract; live integration not yet enabled.
- Roadmap
- Not built in this phase. Shared platform foundations are in place.