Platform Platform
System
ConceptsEnginePolicy as codeDeclarationsSafe changeGatewaysIntegrationsObservabilityAdministrationSecurityHuman reviewAudit and evidenceData retentionSecrets and data classification
Controls
Registries and documentationAuthentication and authorizationInjection detectionData redactionCode fingerprintingRole and judge checksContent classificationSpend and loop limitsBusiness rules
Solutions Solutions
By what you do
Sell into the enterpriseControl the AI you run
By industry
Financial servicesDigital assetsInsuranceHealthcareLegalUser-generated content
By discipline
AI governanceTrust and safetyRisk and compliance
Cases Cases Embedded control planeSource-code leakTrading agents over MCPLive firehoseRefund assistant
Compare Compare LiteLLMNVIDIA NeMo GuardrailsOPAROOSTAgent Governance Toolkit
Resources Resources
Guides
Enterprise review questionsPrompt injectionAgent and control layerAgent architecturesDecision system mapAI control maturity model
Standards
Standards OWASP Agent Control StandardEU AI ActPMI AI standardNIST AI RMFERC-8004
Book a demo
Resources · Standards

Every standard below asks for a control and a piece of evidence.

Compliance itself is organizational work, and no tool makes you compliant. Swiftward is the technical half: enforced controls, a tamper-evident audit trail, and a decision record you can read back.

Where Swiftward provides the controls and the evidence

  • EU AI Act — risk management, record-keeping, human oversight, and which duties are yours rather than ours. EU AI Act
  • NIST AI RMF — the enforced controls and the audit trail behind Govern, Measure, and Manage; Map is your organizational work. NIST AI RMF
  • OWASP LLM Top 10 — prompt injection, sensitive-data exposure, and more, as enforced policy. Prompt injection
  • OWASP Agent Control Standard — how an agent is checked before every action, by a separate process that holds your rules. In plain words
  • HIPAA and GDPR — the technical safeguards over what an assistant may say and what may leave: redaction, access control, the audit trail, on your own infrastructure. Healthcare · GDPR
  • SR 26-2 (April 2026, which replaced SR 11-7 and SR 21-8) puts generative and agentic AI outside its own scope — so your model-risk framework does not cover the decisions your AI agents make. Swiftward is the control and the audit trail for that gap; it feeds your model-risk process rather than replacing it. Risk & Compliance
  • Financial crime: FFIEC BSA/AML, FinCEN, FATF, Wolfsberg — Swiftward enforces the controls you write for them and records each decision.

The governance frameworks we back with technical controls

These define how your organization governs AI as a whole. Process satisfies most of each, but every one still needs technical control you can show, and an audit trail underneath.

  • ISO/IEC 42001 — the AI management-system standard. Swiftward is the enforced-control and audit layer your management system points to.
  • PMI's AI standard — managing AI as a project. We built the technical layer it calls for. The standard, chapter by chapter.
  • OECD AI Principles — the cross-border baseline most national rules follow; Swiftward turns the accountability and traceability they ask for into running controls.
  • Regional data-protection laws (CCPA/CPRA, PIPL, APPI, PIPA, DPDP, PDPA, and more) — Swiftward runs on your own infrastructure, so the data it handles stays in your region, with redaction and audit built in.

The controls your review needs

Tell us what your security and compliance review requires. Because Swiftward is declarative, a specific control and its evidence are usually configuration. For the data-custody questions behind SOC 2, see the security page: Swiftward runs on your own infrastructure, and your data never reaches us. We go through the formal audits, SOC 2 and ISO 42001, when a customer needs them.

Integrations

Forward decisions and audit events to your SIEM over standard syslog (RFC 5424, UDP or TCP) and to any system via webhooks. SSO through OIDC.

MITRE ATLAS

MITRE ATLAS is MITRE's knowledge base of adversary tactics and techniques against AI systems — the ATT&CK idea applied to AI, with agentic systems covered as a platform of their own. It is not a regulation, and nobody audits you against it. It is a shared vocabulary for a security review.

Where a control of ours answers a catalogued technique, we say which one: injection detection names three, and authorization names the one where a chain of permitted calls adds up to an exfiltration.

Book a demo