We use essential cookies to make our site work. With your consent, we may also use non-essential cookies to improve user experience, personalize content, and analyze website traffic. For these reasons, we may share your site usage data with our analytics partners. By clicking “Accept,” you agree to our website's cookie use as described in our Cookie Policy. You can change your cookie settings at any time by clicking “Preferences.”

Services / 02 — Assure: AI Compliance

You have AI. We prove it's compliant.

AI is shipping faster than your controls can track it. We map your process model, scan it against the actual code, and deliver an exposure report — every HIPAA, SOC 2, and NIST AI RMF finding cited to the line of code that caused it. Evidence, not opinions.

At a glance

Frameworks
HIPAA · SOC 2 · NIST AI RMF
Deliverable
Exposure report
Every finding
Cited to code
Engagement
Fixed scope

How it works

Model. Scan. Report.

01 — Model

Map what should happen

We capture your processes and controls as a formal model — using your existing ARIS assets if you have them, building the model if you don't. This is the compliance baseline everything gets measured against.

02 — Scan

Check what actually happens

Our tooling traces the model against your actual codebase — including the AI your teams shipped last quarter — and finds where implementation drifted from the controls on paper.

03 — Report

Get findings you can act on

An exposure report where every finding cites the process step, the control, and the line of code — plus a prioritized remediation plan. Defensible to your auditor, actionable for your engineers.

What you walk away with

Evidence your auditor can follow

Exposure report

Where you're exposed, how badly, and what it takes to close each gap.

Traceability matrix

Process step → control → code, linked end to end. The artifact auditors ask for and rarely get.

Remediation roadmap

Prioritized by risk and effort — your engineers can start Monday.

Audit-ready evidence pack

Organized against HIPAA, SOC 2, or NIST AI RMF so the next audit is a review, not an excavation.

This is for you if

  • Teams across your org are shipping AI features and nobody can say, with evidence, whether they're compliant.
  • An audit, ATO, or customer security review is on the calendar and the documentation isn't.
  • You need findings your engineers respect — cited to code, not generic policy checklists.

It's not if

  • You want a rubber stamp. If the code doesn't hold up, the report says so.
  • You need a certified audit opinion — we produce the evidence; your auditor issues the opinion.

Straight answers

Questions we always get

Which frameworks do you cover?

HIPAA, SOC 2, and NIST AI RMF are our core; we also work against FedRAMP-aligned controls and agency-specific requirements for government clients. If your framework is control-based, the model-to-code approach applies.

How long does an assessment take?

A scoped assessment of a single product or process area typically runs 3-6 weeks from kickoff to exposure report. Enterprise-wide baselines take longer and are phased so you see findings from the first weeks, not at the end.

Do you need access to our source code?

Yes — that is what makes the findings defensible. We work within your security requirements: read-only access, your environment, your controls. Nothing leaves your perimeter without your say-so.

Will this disrupt our engineering teams?

Minimally. The scan is tooling-driven, not interview-driven. We need a few hours from a process owner and an engineering lead, not weeks of workshops.

Do you fix the findings too, or just report them?

Both are on the table. The report comes with a prioritized remediation roadmap; if you want the same senior team to close the gaps, that is a follow-on engagement — your engineers can also run the roadmap themselves.

Is this an audit?

No — we produce the evidence and traceability that make your audit fast and defensible. The certified opinion comes from your auditor; ours is the package that keeps that engagement short.

“A strategic framework that maximized value, streamlined operations, and enriched decision-making. Crucial to our future readiness.”
— Scott Whitacre, US Air Force Research Labs, Digital Capabilities Directorate

Know your exposurebefore the auditor does.

Thirty minutes with the people who run the scan. Bring your worst-case scenario — we've probably seen worse.