Overall Compliance
68%
Technology and SaaS
Your estate changes daily, your engineers adopt AI tools before anyone reviews them, and your customers audit you as a condition of the contract.
The pressure
Every sector has pressures. These are the ones that change what a security programme is allowed to do here.
An estate that changes faster than any inventory can track.
A quarterly inventory describes a company that no longer exists by the time it is signed off.
Engineers adopting AI coding tools ahead of any policy.
By the time the policy exists, a year of usage has already happened without one.
Customer security reviews arriving as a condition of renewal.
A questionnaire is a revenue event with an engineering cost attached, and it arrives with a deadline.
A small security team supporting a much larger engineering org.
You are outnumbered, so anything that needs a person per instance does not scale past this quarter.
The constraint
An answer that was true last quarter is not an answer, because the company it describes no longer exists.
Frameworks
Two states, and they are not the same thing. The cards say which is which rather than listing every framework at the same weight.
Coverage computed from what AI Guardian detects in usage telemetry. It attests only the controls telemetry can satisfy and says so about the rest.
The 2025 list, scored on what Guardian actually detects and responds to, including prompt injection and sensitive-information disclosure.
The deployer obligations Guardian attests under Regulation (EU) 2024/1689, such as AI system identification and record-keeping of system logs.
153 safeguards scoped to your cloud footprint and service models, so cloud-specific safeguards apply only where they are relevant.
No agent assesses it. The control evidence collected for CIS and CSF is the same evidence an ISO audit asks to see.
No agent assesses it. SOC 2 Readiness is scoped and documented but has not shipped, so it is named on this page and nothing more.
Scored means an agent assesses that framework control by control and produces a maturity score and a gap register. Evidenced means no agent assesses it: what the platform contributes is the audit trail and the control evidence a reviewer asks to see. Neither is a compliance certification, and framework mapping is a control-evidence aid rather than a legal opinion.
The answer
Three movements, in order. The constraint above is restated in each of them, because it is what makes this sector's version different.
See
Cloud, identity and code-assistant signal read continuously rather than inventoried periodically, GitHub Copilot usage included, normalised and enriched in under five milliseconds.
Decide
Known-exploited status, exploit probability and reachability, so the queue matches your risk today rather than a severity field written last quarter.
Act
Framework scoring runs continuously and AI governance is evidenced from what is actually detected, so a customer review is an export rather than a project.
Who does the work
You can turn one on and add the others later. A connector configured for one is available to the rest.
Also named for this sector
Continuous SOC 2 monitoring with automated evidence collection and control mapping.
Questions
It reads continuously rather than inventorying periodically: cloud, identity and code-assistant signal normalised to one schema and enriched with asset context in under five milliseconds. Where a feed degrades, the records it backs are marked stale rather than quietly served as current.
Discovery first, then policy. The inventory catalogues every AI tool in use, sanctioned or not, with a risk score and an owner, and enforcement is per tool, per group and per data class. GitHub Copilot is a first-class telemetry source rather than a domain to block.
An export. The CIS and CSF assessments carry the score, the per-control breakdown, the findings and the remediation roadmap, with the scoping decisions recorded. What it does not become is a claim of certification: that is still your auditor's call.
Not by an agent. SOC 2 Readiness is scoped and documented but has not shipped. The honest position is that the evidence the shipping assessments collect overlaps heavily with what a Trust Services Criteria review asks for, and nothing more than that.