RayShield

Compliance

Evidence for the frameworks you are assessed against

Security teams are increasingly asked a question they cannot answer: what did your AI systems do, and how do you know? RayShield produces that record as a by-product of enforcement.

MAS AI risk management

Primary for Singapore financial institutions. The MAS AI Risk Management Toolkit was released on 20 March 2026, and the Association of Banks in Singapore Handbook on Generative AI Guardrails in Banking followed on 24 March 2026.

What the framework expectsWhat RayShield produces
Identification of AI usage across the organisation A passive discovery inventory matched against a 215-service catalog, with per-user and per-device attribution
AI inventorisation maintained over time Change detection on each window — new services, risk increases, first personal-account sightings — exportable as CSV or JSON
Risk materiality assessment A 0–100 risk score per service, plus which agents hold credentials and what those credentials can reach
Evidence that controls operate as described A signed, tamper-evident event stream recording what each agent ran and what it tried to reach

OWASP Top 10 for Agentic Applications — ASI05

Released December 2025 by the OWASP GenAI Security Project. Risk ASI05 covers unexpected code execution by agents.

Named mitigationRayShield control
Sandboxed execution Per-session hardware-isolated microVM, destroyed on exit, no shared host kernel
Deny-by-default egress Hypervisor-level connection intercept plus guest network namespace isolation, with allowed hosts declared in policy

Findings from a discovery pilot are reported against OWASP agentic risk categories, so the output maps to a taxonomy your assessors already recognise.

SOC 2 and ISO 27001 evidence

RayShield is not a certification. It produces the access records that populate the evidence package you already maintain.

Control areaRecord produced
Logical access to systems and data Per-syscall record of file reads and commands executed by each agent session, read from the guest kernel rather than agent logs
Change and configuration management Egress policy held as TOML in source control, with a commit history for every allowlist change
Monitoring and incident detection Named, rule-ID-tagged detections exported into your existing SIEM pipeline

RayShield holds no SOC 2, ISO 27001 or ISO 42001 certification at this time, and publishes no badge for any certification it has not been awarded.

EU AI Act record-keeping

A readiness position, not a deadline. High-risk obligations were deferred under the 2026 Digital Omnibus, with stand-alone systems moving to December 2027. Organisations preparing now are doing so on their own timetable rather than against an imminent enforcement date.

Anticipated obligationWhat is already in place
Automatic recording of events over the system lifecycle A signed, tamper-evident event stream generated per session, independent of the agent's own reporting
Traceability of system behaviour Full argv and destination address for every process execution and connection attempt, attributed to user and device
Human oversight of automated action Monitor, warn and enforce postures set centrally, so a team can observe before it constrains

Data residency

Audit data stays on the device or in your own infrastructure. RayShield does not require agent data to transit our cloud. Content inspection happens in memory on the device and no content is persisted — which is usually the first question a data protection officer asks, and the reason the answer is short.

Start with protection and an inventory

A two-week pilot activates endpoint DLP for your AI workforce and produces the AI inventory these frameworks expect, without touching a production workflow.