Compliance

Make every agent decision auditable.

IntentGate turns runtime authorization into continuous evidence: every decision attributed, hash-chained, and exportable in the formats auditors and security teams already use.

Why the gateway matters

Compliance becomes demonstrable at the decision point.

An auditor does not only need a policy document. They need evidence that the control actually ran, under the correct policy, at the moment the AI acted.

Putting authorization in front of every tool call creates one place where enforcement and evidence are produced together.

Observe the action

The gateway receives the agent, user, tool, target, inputs, and originating intent.

Evaluate the policy

The active Rego policy produces an allow, block, or escalation decision.

Write the evidence

The decision lands in an append-only, hash-chained audit store with full attribution.

Export or replay

Teams query a window, verify integrity, and send the same evidence to the SIEM, auditor, or regulator.

The control plane your compliance team already wants

Three capabilities close the gap between policy, runtime enforcement, and audit evidence.

Per-call policy enforcement

Every action passes through one gateway, and each decision is recorded with the check that produced it and the reason it gave.

  • Allow, block, or escalate
  • Full actor and target attribution
  • Reason and check on every row

Tamper-evident audit chain

Decision records are hash-chained and verifiable, so changes after the fact become immediately detectable.

  • Append-only evidence
  • One-command chain verification
  • Verifiable export windows

Ready-made framework mappings

Obligations are mapped directly to the gateway artifacts that support each requirement.

  • Article-by-article mappings
  • Flat, OCSF-mappable SIEM output
  • Reusable audit evidence model

See how the evidence capabilities line up

The strength of IntentGate is not that each framework gets a custom log. It is that the same well-formed decision record supports multiple control objectives.

Framework
Policy evidence
Integrity
Human oversight
Incident chronology
Continuous operation
EU AI Act
Strong
Strong
Partial
Supporting
Strong
GDPR
Partial
Strong
Not covered
Supporting
Strong
NIS2
Supporting
Strong
Supporting
Strong
Strong
DORA
Supporting
Strong
Supporting
Strong
Strong
ISO 42001
Strong
Strong
Partial
Supporting
Strong
ISO 27001
Strong
Strong
Supporting
Strong
Strong
SOC 2 Type II
Strong
Strong
Supporting
Strong
Strong
Strong: the gateway produces the primary artifactSupporting: contributes evidence alongside other controlsPartial: covers part of the obligation onlyNot covered: out of scope for this product

IntentGate governs the agent-to-tool decision layer. It is not a complete control set for any framework, and it does not classify personal data, establish a lawful basis for processing, or handle data-subject rights. Use this table to see which obligations runtime evidence can support, not as a compliance attestation.

Map your next audit to runtime evidence.

Bring your applicable frameworks, audit cycle, agent classes, and existing evidence sources. We will walk through where IntentGate fits and what artifacts it produces.