Use case · Audit & Compliance

A policy document isn't evidence. A blocked action is.

Auditors don't want your AI policy — they want proof it held. Gödel maps every runtime detection to the specific articles it evidences, so you can answer which controls your agents violated, who was accountable, and whether enforcement actually prevented the action.

10

Benchmarks supported out of the box

37

Individual articles and control IDs mapped

100%

Of agent actions recorded — not a sample

<5ms

From action to verdict to audit record

BENCHMARKS SUPPORTED

Mapped at the article, not the framework.

Claiming "GDPR support" is easy. Every detection Gödel raises resolves to the specific clauses below — so a violation names what it breaches, not just how bad it is.

GDPR

Regulation (EU) 2016/679

Art. 5(1)(f)Art. 32(1)(b)Art. 32(2)

Australian Privacy Act

Privacy Act 1988 (Cth), Schedule 1

APP 6.1APP 11.1

HIPAA Security Rule

45 CFR Part 164, Subpart C

§164.308(a)(6)(ii)§164.312(e)(1)

PCI DSS

v4.0.1

Requirement 3Requirement 4Requirement 6Requirement 7Requirement 8Requirement 10

EU AI Act

Regulation (EU) 2024/1689

Art. 12Art. 15

NIST AI RMF

AI RMF 1.0

MEASURE 2.4MEASURE 2.7

ISO/IEC 42001

ISO/IEC 42001:2023

A.6.2.6A.6.2.8A.9.2A.9.4

ISO/IEC 27000 family

ISO/IEC 27001:2022

A.5.15A.5.17A.8.2A.8.12A.8.15A.8.16A.8.26

ASD ISM

June 2026

ISM-1228ISM-1924ISM-1987ISM-2092ISM-2093ISM-2094ISM-2113ISM-2114

Essential Eight

Maturity Model (November 2023)

Application control
Walkthrough demonstration

See compliance evidence generate itself

Watch one agent action get detected, attributed, mapped to five controls across four frameworks, and written to the audit record — in a single pass.

THE RECORD

This is what your auditor gets to read.

Not a dashboard of severities. Every row is one agent action, the identity behind it, the clauses it touches, and whether policy stopped it — filterable by framework, control, user or agent.

AUDIT RECORD · LAST 24 HOURS
TimeActorActionEnforcementControls Evidenced
14:22:07
maya@acme.dev
claude-code
Egress to unapproved endpoint
PHI in outbound payload · api.external.io
PREVENTED
HIPAA §164.312(e)(1)GDPR Art. 32(1)(b)
13:58:41
sam@acme.dev
browser-agent
Cardholder data in prompt context
PAN detected before transmission
PREVENTED
PCI DSS Req. 3PCI DSS Req. 4
13:31:12
maya@acme.dev
cursor
Unverified remote code execution
curl piped to subshell
PREVENTED
Essential Eight · App controlISM-1228
12:04:55
svc-intake
langgraph
Personal data used beyond purpose
Support records reused for marketing
PREVENTED
GDPR Art. 5(1)(f)APP 6.1
11:47:20
ops@acme.dev
autogen
Autonomous high-impact tool call
Permitted by policy · no human review
LOGGED
EU AI Act Art. 12ISO 42001 A.9.2
09:15:03
— unbound —
svc-agent
Action without accountable identity
Held pending identity binding
HELD
ISO 27001 A.5.15PCI DSS Req. 8
6 of 14,208 events · streamed to Splunk, Datadog or S3 · immutable

Which control produces which evidence.

Enforcement capabilities down the top, frameworks down the side. Every filled cell is evidence Gödel generates automatically — no questionnaire, no screenshot, no sampling.

FRAMEWORKVISIBILITYCLASSIFICATIONGUARDRAILSATTACK DEFENSEDLPAUDIT TRAIL
GDPR
2016/679
Australian Privacy Act
Schedule 1
HIPAA Security Rule
45 CFR 164 C
PCI DSS
v4.0.1
EU AI Act
2024/1689
NIST AI RMF
1.0
ISO/IEC 42001
2023
ISO/IEC 27001
2022
ASD ISM
June 2026
Essential Eight
Nov 2023
Evidence generated
Not mapped for this framework
THE ASSESSMENT

Four questions you can now answer.

Every one of these is a week of work when evidence lives in screenshots and spreadsheets. Each is a filter when it lives in the enforcement record.

Q1

"Which controls did your AI agents violate this quarter?"

Filter the record by framework or by clause. Every detection already carries its article mappings, so the answer is a query — not an investigation.

Q2

"Who was accountable for this action?"

Each event binds the user, the agent, the model, the device and the session at decision time. An autonomous action is never orphaned.

Q3

"Can you prove the control actually worked?"

The record states whether enforcement prevented the action, held it for approval, or allowed and logged it. Operating effectiveness, not design intent.

Q4

"Show me the evidence for the period."

Export by control, framework, user or agent, straight from the SIEM your events already stream to. No collection exercise, no reconciliation.

FULL COVERAGE

All six controls, writing to one record.

Audit readiness isn't a reporting module bolted on the side. Every Gödel enforcement capability is an evidence source.

Session Visibility & Oversight

Every prompt, file read and tool call retained with the identity and device behind it.

Content Classification

Regulated data identified in context, so a detection states which category was exposed.

Action & Execution Guardrails

Shell, network and file actions gated — the enforcement point that makes the record provable.

AI Attack Defense

Prompt injection and poisoned context logged as events against AI-specific controls.

Data Loss Prevention

Every redaction and block recorded against the confidentiality clause it satisfies.

Audit & Compliance

An immutable, queryable trail across all ten frameworks, streamed to your SIEM.

Control mappings indicate the obligations a detection is commonly evidence for. Applicability depends on your jurisdiction, sector and processing role — Gödel supports enforcement and evidence collection, and is not a determination of compliance.

Put an audit trail on every agent action.

Deterministic audit trails, deployed in minutes. Your agents keep shipping — your compliance evidence is 100% complete.