Governance
The limit is not in our code. It is in your standards.
A machine-readable layer brings law, standards and threat knowledge together.
Beneath the platform sits a machine-readable governance layer. It brings together:
- Law: NIS2, CRA, AI Act
- Standards: ISO 27001, IEC 62443, ISO 42001
- Threat knowledge: MITRE ATT&CK for IT and ICS
From these it derives a traceable autonomy ceiling for each action: from fully autonomous, through approval by a human, to explicitly never autonomous.
A firewall block runs fully autonomously. Handing a controller back to a running process never does.
That is useful twice over. Every autonomous decision can be justified to an auditor, and the compliance evidence is produced in operation rather than in a consulting project.
Because standards age, this layer is designed as a versioned, living artefact.