Skip to content

Governance

The limit is not in our code. It is in your standards.

A machine-readable layer brings law, standards and threat knowledge together.

Beneath the platform sits a machine-readable governance layer. It brings together:

  • Law: NIS2, CRA, AI Act
  • Standards: ISO 27001, IEC 62443, ISO 42001
  • Threat knowledge: MITRE ATT&CK for IT and ICS

From these it derives a traceable autonomy ceiling for each action: from fully autonomous, through approval by a human, to explicitly never autonomous.

A firewall block runs fully autonomously. Handing a controller back to a running process never does.

That is useful twice over. Every autonomous decision can be justified to an auditor, and the compliance evidence is produced in operation rather than in a consulting project.

Because standards age, this layer is designed as a versioned, living artefact.

Reader view