Compliance
Evidence for the frameworks you are assessed against
Security teams are increasingly asked a question they cannot answer: what did your AI systems do, and how do you know? RayShield produces that record as a by-product of enforcement.
MAS AI risk management
Primary for Singapore financial institutions. The MAS AI Risk Management Toolkit was released on 20 March 2026, and the Association of Banks in Singapore Handbook on Generative AI Guardrails in Banking followed on 24 March 2026.
| What the framework expects | What RayShield produces |
|---|---|
| Identification of AI usage across the organisation | A passive discovery inventory matched against a 215-service catalog, with per-user and per-device attribution |
| AI inventorisation maintained over time | Change detection on each window — new services, risk increases, first personal-account sightings — exportable as CSV or JSON |
| Risk materiality assessment | A 0–100 risk score per service, plus which agents hold credentials and what those credentials can reach |
| Evidence that controls operate as described | A signed, tamper-evident event stream recording what each agent ran and what it tried to reach |
OWASP Top 10 for Agentic Applications — ASI05
Released December 2025 by the OWASP GenAI Security Project. Risk ASI05 covers unexpected code execution by agents.
| Named mitigation | RayShield control |
|---|---|
| Sandboxed execution | Per-session hardware-isolated microVM, destroyed on exit, no shared host kernel |
| Deny-by-default egress | Hypervisor-level connection intercept plus guest network namespace isolation, with allowed hosts declared in policy |
Findings from a discovery pilot are reported against OWASP agentic risk categories, so the output maps to a taxonomy your assessors already recognise.
SOC 2 and ISO 27001 evidence
RayShield is not a certification. It produces the access records that populate the evidence package you already maintain.
| Control area | Record produced |
|---|---|
| Logical access to systems and data | Per-syscall record of file reads and commands executed by each agent session, read from the guest kernel rather than agent logs |
| Change and configuration management | Egress policy held as TOML in source control, with a commit history for every allowlist change |
| Monitoring and incident detection | Named, rule-ID-tagged detections exported into your existing SIEM pipeline |
RayShield holds no SOC 2, ISO 27001 or ISO 42001 certification at this time, and publishes no badge for any certification it has not been awarded.
EU AI Act record-keeping
A readiness position, not a deadline. High-risk obligations were deferred under the 2026 Digital Omnibus, with stand-alone systems moving to December 2027. Organisations preparing now are doing so on their own timetable rather than against an imminent enforcement date.
| Anticipated obligation | What is already in place |
|---|---|
| Automatic recording of events over the system lifecycle | A signed, tamper-evident event stream generated per session, independent of the agent's own reporting |
| Traceability of system behaviour | Full argv and destination address for every process execution and connection attempt, attributed to user and device |
| Human oversight of automated action | Monitor, warn and enforce postures set centrally, so a team can observe before it constrains |
Data residency
Audit data stays on the device or in your own infrastructure. RayShield does not require agent data to transit our cloud. Content inspection happens in memory on the device and no content is persisted — which is usually the first question a data protection officer asks, and the reason the answer is short.
Start with protection and an inventory
A two-week pilot activates endpoint DLP for your AI workforce and produces the AI inventory these frameworks expect, without touching a production workflow.