Skip to main content

Compliance mapping

Automentic does not certify you. It produces the signed, timestamped evidence that makes these frameworks materially less painful to satisfy.

The distinction matters: a control is not satisfied because a vendor says so. It is satisfied because you can demonstrate it operated over a period, and that is an evidence problem.

SOC 2

What it asks for. Evidence that access control, change management and monitoring operated over a period — not that they existed on the day of the audit.

What Automentic contributes. A continuous, signed record of every automated action and the identity that authorised it. Rather than sampling and reconstructing, the population is the audit trail itself.

Trust services criteriaContribution
Logical access (CC6)Per-agent identity; no shared service accounts; revocation that takes effect mid-run
Change management (CC8)Every automated change attributable to an agent and an authorising principal
Monitoring (CC7)Immutable trail streamed to your SIEM, including denied and failed actions

ISO 27001

What it asks for. A managed information security system with controls that demonstrably operate.

What Automentic contributes. Three controls that operate continuously rather than on paper: identity for every automated actor, least-privilege authorisation evaluated per request, and an immutable action log.

Useful for Annex A areas covering access control, cryptography, operations security and logging. Your auditor will map the specifics to your Statement of Applicability.

GDPR

What it asks for. Accountability for how personal data is processed, and by whom.

What Automentic contributes. Because every agent action names its authoriser and the policy that permitted it, a data subject access request or a regulator question has a factual answer rather than an investigation.

Relevant to accountability (Article 5(2)), security of processing (Article 32), and records of processing activities (Article 30).

Zero-trust frameworks

The model maps directly onto zero-trust guidance — verify explicitly, use least privilege, assume breach — applied to machine actors rather than only human ones. See Zero trust.

What this page deliberately does not claim

Nothing here asserts that Automentic holds SOC 2, ISO 27001 or any other certification. Those are factual claims that require real audit reports behind them, and they belong on a trust page maintained by the company, not in documentation.

Before relying on this page

This mapping is written from the framework requirements and the product model. It has not been reviewed by an auditor. Have your assessor confirm which controls they will accept it against before citing it in an audit.