AIUC-1 evidence pack

AIUC-1 · version 2026-07-15 (Q3-2026) · log tenant_acme/prod · generated 2026-10-09T12:01:54.823Z

Each control below is mapped to the evidence for it computed from a tamper-evident, hash-chained action record — not from a questionnaire. Sequence numbers (#123) point at the exact events; the evidence bundle re-verifies them offline. Controls a runtime record cannot answer are marked Not evidenced here with where they live instead. A machine-readable companion of this pack — the same data as JSON, for a compliance platform or an auditor's tooling — is at /demo/evidence/aiuc?format=json.
3evidenced from the record
12partially evidenced
36outside a runtime record
13/43mandatory controls this product touches

17 distinct events are cited as evidence across 51 controls. This product evidences the runtime controls — activity logging, tool-call restriction, human oversight, disclosure, change accountability — and states honestly that policy, third-party evaluation, and agent-side output controls are evidenced elsewhere.

A · Data & Privacy

Protect against data leakage, IP leakage, and training on user data without consent.

A001 Establish input data policy Not evidenced here mandatory

Create and share policies on how customer data is used for training, inference, retention, and customer rights.

A published data-use policy — held in your policy set, not the runtime record. (legal / contractual)

A002 Establish output data policy Not evidenced here mandatory

Define ownership, usage, consent, and deletion policies for AI outputs.

An output-rights policy — governance, not something an action log evidences. (legal / contractual)

A003 Limit AI agent data access Partial mandatory

Apply controls restricting agent data access by task, user role, agent role, and context.

Each agent acts under a unique identity carrying the human it acts for, and its tool grant is enforced deny-by-default at the action boundary. Data-classification scoping of the underlying stores is yours. #18, #23, #24, #48, #71, #98

A003.1 Data access scoping
The tool-allowlist rule confines an agent to the tools its grant names; out-of-grant attempts are refused and chained. #18, #23, #24, #48, #71, #98
A003.2 Agent identity management
Every action names one agent identity (5 on this log), and each per-action receipt cryptographically binds the action to it (AARM R6). #0, #4, #6, #15
A003.3 Per-agent permission scopes
Grants are per agent and recorded on the receipt's identity.scope; silent inheritance is not possible because each action re-presents its own grant.

Crosswalk: NIST AI RMF MAP 2.1 · OWASP Agentic ASI02/ASI06 · CSA AICM IAM-17/IAM-19

A004 Protect IP & trade secrets Not evidenced here mandatory

Prevent systems from exposing proprietary or confidential information.

Output-side IP filtering lives in the agent; the record proves what was done, not what a model said. (agent-side guardrail)

A005 Prevent cross-customer data exposure Not evidenced here mandatory

Block data leakage between customers.

Tenant isolation of the data stores is your infrastructure; Auditant's own logs are per-log isolated, which is evidence for B007, not this. (governance / policy)

A006 Prevent PII leakage Partial mandatory

Block personal data from appearing in outputs and logs.

The activity log itself carries no PII: default custody is metadata-and-hashes only, so A006.1's 'log redaction' is satisfied by construction — payloads never reach the chain. Output-side PII filtering is the agent's.

A006.1 PII detection and filtering (logs)
Payloads are hashed, never stored on the chain; a GDPR erasure destroys the payload blob without breaking the log. There is no PII in the record to redact.

Crosswalk: EU AI Act Art 12 · CSA AICM DSP-07

A007 Prevent IP violations Not evidenced here mandatory

Prevent outputs infringing copyrights, trademarks, or third-party IP.

Output infringement filtering is inside the agent. (agent-side guardrail)

A008 Prevent leakage of credentials and secrets Partial mandatory

Detect and prevent secret exposure in inputs, outputs, logs, and storage.

A008.5 (secrets in logs) is met the same way A006 is: the chain stores hashes, not payloads, so no credential can land in the record. Detection in inputs/outputs (A008.1–.4) is the agent's.

A008.5 Secrets redaction in logs and stored artifacts
Metadata-only custody: prompts and outputs are hashed before anything is chained, so a secret in a payload never reaches stored log artifacts.

Crosswalk: Q3-2026 new control

B · Security

Protect against adversarial attacks and unauthorized tool calls.

B001 Third-party testing of adversarial robustness Not evidenced here mandatory

Adversarial testing of resilience to prompt injection.

A red-team engagement (e.g. through your AIUC-1 auditor); not a runtime record. (third-party evaluation)

B002 Detect adversarial input Not evidenced here optional

Monitor for adversarial inputs and prompt injection.

Input-side detection lives in the agent/gateway, upstream of the action. (agent-side guardrail)

B003 Manage public release of technical details Not evidenced here optional

Control disclosure of technical information.

A disclosure policy. (governance / policy)

B004 Prevent AI endpoint scraping Not evidenced here mandatory

Guard against probing/scraping of AI endpoints.

Rate-limiting/anomaly detection at your API edge; Auditant rate-limits money-spending calls but that is D003, not endpoint anti-scraping. (agent-side guardrail)

B005 Implement real-time input filtering Not evidenced here optional

Automated moderation of inputs.

Input moderation is the agent's. (agent-side guardrail)

B006 Prevent unauthorized AI agent actions Evidenced mandatory

Prevent agents performing actions beyond intended scope and authorized privileges.

Actions are intercepted before execution and evaluated against policy; 181 were refused on this log, each naming the rule and version that refused it. The Q3-2026 sub-control B006.3 lists a pre-execution policy hook among its acceptable safeguards; /v1/decide is that hook. (Tool-definition integrity — detecting a tool whose definition changed after approval — is NOT something this product does.) #18, #23, #24, #48, #71, #98

B006.1 Agent service access restrictions
Deny-by-default tool allowlist per agent; the MCP/tool grant is enforced at the action boundary. #18, #23, #24, #48, #71, #98
B006.2 Agent security monitoring and alerting
Every agent action is logged; a quiet agent past 24h is a finding, and held actions ping the operator. 1 agents currently quiet.
B006.3 Execution-level safeguards (pre-execution hook)
The synchronous /v1/decide hook verifies each tool call at runtime before any side effect (AARM R1 pre-execution interception); each verdict is a per-action signed receipt. #18, #23, #24, #48, #71, #98

Crosswalk: OWASP LLM08:25 · CSA AICM AIS-11/IAM-19 · OWASP Agentic ASI02/ASI03

B007 Enforce user access privileges to AI systems Partial mandatory

Maintain user access controls and admin privileges aligned with policy.

Access to the record is role-scoped: admin keys see the fleet, tenant keys resolve to exactly one log and can infer nothing about another, and operator surfaces (budgets, custom rules) are refused to a tenant key. Access to the underlying agent systems is yours.

Crosswalk: OWASP LLM06:25 · CSA AICM IAM-01..18

B008 Protect AI system deployment environment Not evidenced here mandatory

Encryption, access controls, and authorization in the deployment environment.

Your hosting environment; Auditant runs TLS and per-tenant keys but the model deployment env is yours. (governance / policy)

B009 Limit output over-exposure Not evidenced here mandatory

Output limitations and obfuscation.

Output volume/precision controls in the agent. (agent-side guardrail)

B010 Promote secure patterns in generated code Not evidenced here mandatory

Secure defaults and vulnerability prevention in generated code.

A property of the coding agent's generation, not of the action log. (agent-side guardrail)

C · Safety

Prevent harmful AI outputs and brand risk through testing, monitoring and safeguards.

C001 Define AI risk taxonomy Not evidenced here mandatory

Establish a risk taxonomy for the system.

A document; your risk register. (governance / policy)

C002 Conduct pre-deployment testing Not evidenced here mandatory

Internal testing across risk categories before deployment.

A pre-deployment test programme. (third-party evaluation)

C003 Prevent harmful outputs Not evidenced here mandatory

Safeguards preventing harmful outputs.

Content filtering in the agent. (agent-side guardrail)

C004 Prevent out-of-scope outputs Not evidenced here mandatory

Safeguards preventing out-of-scope outputs.

Scope guardrails in the agent. (agent-side guardrail)

C005 Prevent agent-specific high risk outputs Partial mandatory

Safeguards for agent-specific high-risk outputs, including human review.

C005.2 (human review workflows) is evidenced: high-risk actions are held for a named human before they execute, and each grant or refusal is chained under the reviewer. The risk-detection logic itself (C005.1) is the agent's. #20, #50, #57, #73, #84, #100

C005.2 Human review workflows
Actions above policy are held; 0 currently pending, released only by a named person. #20, #50, #57, #73, #84, #100

Crosswalk: EU AI Act Art 9 · OWASP LLM05:25

C006 Prevent output vulnerabilities Not evidenced here mandatory

Prevent security vulnerabilities in outputs.

Output sanitisation in the agent. (agent-side guardrail)

C007 Flag high risk outputs for human review Partial optional

Alerting that flags high-risk outputs for human review.

The human-sign-off rule flags and holds high-risk actions for review (C007.3 review workflow), with the queue and each decision on the chain. The detection criteria (C007.1/.2) are yours to define. #20, #50, #57, #73, #84, #100

Crosswalk: ISO 42001 A.9.3 · CSA AICM GRC-15

C008 Monitor AI risk categories Not evidenced here optional

Monitor AI systems across risk categories.

Output-category monitoring; the chain monitors actions and spend, not output risk classes. (agent-side guardrail)

C009 Enable real-time feedback and intervention Partial optional

Mechanisms to pause, stop, or redirect system behavior.

C009.1's 'pause/stop' is the kill switch: a tenant-level halt that forbids over every rule, with each flip chained under the operator. The in-product feedback UI is the agent's surface.

C009.1 User intervention mechanisms (stop/pause)
The halt flag stops every agent on the log immediately; arming and releasing it are chained events under a named human.

Crosswalk: EU AI Act Art 14 · OWASP Agentic ASI01/ASI09

C010 Third-party testing for harmful outputs Not evidenced here mandatory

External evaluation of robustness to harmful outputs.

Quarterly red-team through your auditor. (third-party evaluation)

C011 Third-party testing for out-of-scope outputs Not evidenced here mandatory

External evaluation of out-of-scope robustness.

Quarterly red-team. (third-party evaluation)

C012 Third-party testing for customer-defined risk Not evidenced here mandatory

External evaluation of customer-defined high-risk outputs.

Quarterly red-team. (third-party evaluation)

D · Reliability

Prevent hallucinations and unreliable tool calls to business systems.

D001 Prevent hallucinated outputs Not evidenced here mandatory

Safeguards preventing hallucinated outputs.

Groundedness controls in the agent. (agent-side guardrail)

D002 Third-party testing for hallucinations Not evidenced here mandatory

External evaluation of hallucinated outputs.

Quarterly evaluation. (third-party evaluation)

D003 Restrict unsafe tool calls Evidenced mandatory

Prevent tool calls executing unauthorized actions, accessing restricted information, or acting beyond scope.

Every one of D003's four technical sub-controls is a live capability of the record: tool authorization, rate limits, an execution log, and human-approval workflows. 181 unsafe calls refused, 0 held for a human. #18, #23, #24, #48, #71, #98

D003.1 Tool authorization & validation
Deny-by-default tool allowlist enforced before execution; parameters travel as hashes on the receipt. #18, #23, #24, #48, #71, #98
D003.2 Rate limits & transaction caps
Per-caller and global rate limits, plus the burn-rate and cost-velocity rules that stop a runaway loop before it spends.
D003.3 Tool call log
Every tool call is a chained event with server origin (adapter), tool name, parameter hash, and timestamp — 4827 events on this log.
D003.4 Human-approval workflows
Sensitive actions are held for a named human; 0 pending, each release or refusal chained under the reviewer. #20, #50, #57, #73, #84, #100

Crosswalk: MITRE ATLAS · OWASP Agentic Top 10 · NIST AI RMF

D004 Third-party testing of tool calls Not evidenced here mandatory

External evaluation of tool calls every 3 months.

Quarterly evaluation by an independent assessor — but the tool-call log this pack exports is exactly the evidence that assessment reads. (third-party evaluation)

E · Accountability

Assign accountability, enforce oversight, create emergency responses and vet suppliers.

E001 AI failure plan for security breaches Partial mandatory

Documented failure plan with owners, notification, remediation, and evidence collection.

The plan is a document (yours), but two of its required elements are runtime capabilities here: 'system freeze' is the kill switch, and 'evidence collection / preserve logs for legal review' is the tamper-evident chain and its offline export.

Crosswalk: EU AI Act Art 73 · ISO 42001 A.8.4

E002 AI failure plan for harmful outputs Not evidenced here mandatory

Response protocols for harmful outputs.

An incident-response document. (governance / policy)

E003 AI failure plan for hallucinations Not evidenced here mandatory

Procedures for hallucinated outputs causing loss.

An incident-response document. (governance / policy)

E004 Assign accountability Partial mandatory

Document which changes require review/approval, assign accountable leads, and record approvals.

E004.1 is evidenced: every policy and budget change is itself a chained event naming the author, and a rule version is the hash of its own bytes, so 'who changed the control, when, and what it said before' is answerable. E004.2 (code signing of AI components) is not — checkpoint signing is not artifact signing.

E004.1 Change approval policy and records
Rule changes (created/updated/retired) and budget/halt changes are appended to the chain under the author's identity; the prior rule version is retained, never overwritten.
E004.2 Code signing implementation
Not evidenced by this product — code/model signing lives in your CI/CD.

Crosswalk: MITRE ATLAS AML-M0013 · ISO 42001 A.3.2/A.6.2.2

E005 Document data storage security Not evidenced here mandatory

Document storage practices against sensitivity and regulation.

A documentation control; see docs/sales/subprocessors.md and security-answers.md as starting material. (governance / policy)

E006 Conduct vendor due diligence Not evidenced here mandatory

Vet foundation/upstream model providers.

Vendor assessment records; the chain records WHICH providers were used (see E009), not your diligence on them. (governance / policy)

E008 Review internal processes Not evidenced here mandatory

Regular internal process reviews with records.

An operational review cadence. (governance / policy)

E009 Monitor third-party access Partial mandatory

Log third-party API connections, sessions, and data access, and alert on anomalies.

E009.1 is evidenced for the model providers your agents call: every model_call carries its provider and model id (or is flagged unpriced), so third-party model access is logged (1 provider(s) seen). Anomaly alerting (E009.2) on that access is the quiet-agent and burn-rate signals.

Crosswalk: EU AI Act Art 72 · NIST AI RMF MANAGE 4.1

E010 Establish AI acceptable use policy Partial mandatory

Create and enforce an AI acceptable-use policy, with violation detection and logging.

The policy document (E010.1) is yours, but its enforcement is evidenced: policy rules detect and block disallowed actions (E010.2/.4), and every violation is a chained, reviewable record. #18, #23, #24, #48, #71, #98

Crosswalk: CSA AICM GRC

E011 Record processing locations Not evidenced here mandatory

Document where AI data is processed.

A subprocessor/location record (docs/sales/subprocessors.md is a starting point); the chain names providers, not their processing regions. (governance / policy)

E012 Document regulatory compliance Not evidenced here mandatory

Map applicable AI laws and compliance strategy.

A regulatory mapping — though the compliance module maps five regimes to the record as a starting point. (governance / policy)

E013 Implement quality management system Not evidenced here optional

A proportionate QMS for AI operations.

A management-system control. (governance / policy)

E015 Log AI system activity Evidenced mandatory

Maintain logs of processes, actions, and agent outputs for investigation, auditing, and explanation, with retention, access control, and integrity protection.

This is the product. All four E015 sub-controls are live: agent activity is logged with provenance and tool parameters, stored append-only, and integrity-protected by a hash chain with signed, externally countersigned checkpoints. 4827 events, 184 checkpoints (180 countersigned, 175 in WORM storage). #0

E015.1 Logging implementation
Inputs (hashed), outputs (hashed), tool calls, decisions, timestamps and actor — 4827 events captured across four planes.
E015.2 AI agent logging implementation
Agent provenance (agent id + version), tool-call parameters (as hashes), delegation chains (delegation/handoff events), and approval events (approver identity + timestamp + outcome) are all first-class on the schema. #20, #50, #57, #73, #84, #100
E015.3 Log storage
Append-only store (UPDATE/DELETE refused by database trigger); retention is a property of the store, and payloads are erasable independently for GDPR without breaking the chain.
E015.4 Log integrity protection
Cryptographic hashing + append-only + WORM, all three: 184 hash-chain checkpoints signed (ECDSA P-256), 180 RFC 3161-countersigned, 175 written to S3 Object Lock. Any post-hoc edit is computable from the exported bundle offline.

Crosswalk: ISO 42001 A.6.2.8 · EU AI Act Art 12 & 19 · NIST AI RMF MEASURE 2.4/2.8 · CSA AICM LOG-08/11/14/15

E016 Implement AI disclosure mechanisms Partial mandatory

Inform users when they are interacting with AI rather than a human.

E016.2 (voice disclosure) and E016.4 (disclosing autonomous agent action) are evidenced: a disclosure event is recorded per voice call — provably present or provably missing — and every action records actor.mode (autonomous vs interactive). Text/media disclosure UI (E016.1/.3) is the agent's surface. 0 of 2 calls missing disclosure. #6, #12

E016.2 Voice-based AI disclosure
A first-class disclosure event per call, timestamped; a missing disclosure is a chained policy violation (EU AI Act Art 50), not an omission. #6, #12
E016.4 Disclosing autonomous AI agent actions
actor.mode distinguishes an autonomous action from a human-in-the-loop one on every event.

Crosswalk: EU AI Act Art 50 · ISO 42001 A.8.2 · CSA AICM GRC-15

E017 Document system transparency policy Not evidenced here optional

Model cards, datasheets, AI bill of materials.

A transparency repository. (governance / policy)

F · Society

Prevent AI from enabling societal harm through cyberattacks or national security risks.

F001 Prevent AI cyber misuse Not evidenced here mandatory

Guardrails against AI-enabled cyber misuse.

Misuse guardrails in the model/agent. (agent-side guardrail)

F002 Prevent catastrophic misuse Not evidenced here mandatory

Guardrails against catastrophic (CBRN) misuse.

Misuse guardrails in the model/agent. (agent-side guardrail)