A policy document isn't evidence. A blocked action is.
Auditors don't want your AI policy — they want proof it held. Gödel maps every runtime detection to the specific articles it evidences, so you can answer which controls your agents violated, who was accountable, and whether enforcement actually prevented the action.
Benchmarks supported out of the box
Individual articles and control IDs mapped
Of agent actions recorded — not a sample
From action to verdict to audit record
Mapped at the article, not the framework.
Claiming "GDPR support" is easy. Every detection Gödel raises resolves to the specific clauses below — so a violation names what it breaches, not just how bad it is.
GDPR
Regulation (EU) 2016/679
Australian Privacy Act
Privacy Act 1988 (Cth), Schedule 1
HIPAA Security Rule
45 CFR Part 164, Subpart C
PCI DSS
v4.0.1
EU AI Act
Regulation (EU) 2024/1689
NIST AI RMF
AI RMF 1.0
ISO/IEC 42001
ISO/IEC 42001:2023
ISO/IEC 27000 family
ISO/IEC 27001:2022
ASD ISM
June 2026
Essential Eight
Maturity Model (November 2023)
See compliance evidence generate itself
Watch one agent action get detected, attributed, mapped to five controls across four frameworks, and written to the audit record — in a single pass.
This is what your auditor gets to read.
Not a dashboard of severities. Every row is one agent action, the identity behind it, the clauses it touches, and whether policy stopped it — filterable by framework, control, user or agent.
| Time | Actor | Action | Enforcement | Controls Evidenced |
|---|---|---|---|---|
| 14:22:07 | maya@acme.dev claude-code | Egress to unapproved endpoint PHI in outbound payload · api.external.io | PREVENTED | HIPAA §164.312(e)(1)GDPR Art. 32(1)(b) |
| 13:58:41 | sam@acme.dev browser-agent | Cardholder data in prompt context PAN detected before transmission | PREVENTED | PCI DSS Req. 3PCI DSS Req. 4 |
| 13:31:12 | maya@acme.dev cursor | Unverified remote code execution curl piped to subshell | PREVENTED | Essential Eight · App controlISM-1228 |
| 12:04:55 | svc-intake langgraph | Personal data used beyond purpose Support records reused for marketing | PREVENTED | GDPR Art. 5(1)(f)APP 6.1 |
| 11:47:20 | ops@acme.dev autogen | Autonomous high-impact tool call Permitted by policy · no human review | LOGGED | EU AI Act Art. 12ISO 42001 A.9.2 |
| 09:15:03 | — unbound — svc-agent | Action without accountable identity Held pending identity binding | HELD | ISO 27001 A.5.15PCI DSS Req. 8 |
Which control produces which evidence.
Enforcement capabilities down the top, frameworks down the side. Every filled cell is evidence Gödel generates automatically — no questionnaire, no screenshot, no sampling.
| FRAMEWORK | VISIBILITY | CLASSIFICATION | GUARDRAILS | ATTACK DEFENSE | DLP | AUDIT TRAIL |
|---|---|---|---|---|---|---|
GDPR 2016/679 | ||||||
Australian Privacy Act Schedule 1 | ||||||
HIPAA Security Rule 45 CFR 164 C | ||||||
PCI DSS v4.0.1 | ||||||
EU AI Act 2024/1689 | ||||||
NIST AI RMF 1.0 | ||||||
ISO/IEC 42001 2023 | ||||||
ISO/IEC 27001 2022 | ||||||
ASD ISM June 2026 | ||||||
Essential Eight Nov 2023 |
Four questions you can now answer.
Every one of these is a week of work when evidence lives in screenshots and spreadsheets. Each is a filter when it lives in the enforcement record.
"Which controls did your AI agents violate this quarter?"
Filter the record by framework or by clause. Every detection already carries its article mappings, so the answer is a query — not an investigation.
"Who was accountable for this action?"
Each event binds the user, the agent, the model, the device and the session at decision time. An autonomous action is never orphaned.
"Can you prove the control actually worked?"
The record states whether enforcement prevented the action, held it for approval, or allowed and logged it. Operating effectiveness, not design intent.
"Show me the evidence for the period."
Export by control, framework, user or agent, straight from the SIEM your events already stream to. No collection exercise, no reconciliation.
All six controls, writing to one record.
Audit readiness isn't a reporting module bolted on the side. Every Gödel enforcement capability is an evidence source.
Session Visibility & Oversight
Every prompt, file read and tool call retained with the identity and device behind it.
Content Classification
Regulated data identified in context, so a detection states which category was exposed.
Action & Execution Guardrails
Shell, network and file actions gated — the enforcement point that makes the record provable.
AI Attack Defense
Prompt injection and poisoned context logged as events against AI-specific controls.
Data Loss Prevention
Every redaction and block recorded against the confidentiality clause it satisfies.
Audit & Compliance
An immutable, queryable trail across all ten frameworks, streamed to your SIEM.
Control mappings indicate the obligations a detection is commonly evidence for. Applicability depends on your jurisdiction, sector and processing role — Gödel supports enforcement and evidence collection, and is not a determination of compliance.
See continuous compliance on your surface.
Put an audit trail on every agent action.
Deterministic audit trails, deployed in minutes. Your agents keep shipping — your compliance evidence is 100% complete.