Skip to main content
Grantex provides technical controls that can be mapped to widely used AI agent security and risk-management frameworks. This page documents current mapping posture and the corresponding Grantex feature areas without claiming formal third-party attestation unless separately stated.

OWASP Agentic Security Top 10

Published December 2025 — the first industry-standard threat taxonomy for autonomous AI agents.

EU AI Act

The Act applies in phases. Current Commission guidance places transparency rules in August 2026, listed high-risk areas in December 2027, and product-integrated high-risk systems in August 2028. The controls below are technical mappings, not a determination that a deployment satisfies the regulation.

NIST AI Risk Management Framework

Active now as voluntary risk-management guidance; useful for US government and federal-contractor alignment where applicable.

Full Compliance Matrix

Compliance Evidence Pack

Grantex can generate a compliance evidence pack that bundles all relevant data for auditors:
The evidence pack includes:
  • Grant records issued in the selected period
  • Audit entries in the selected period, including hash-chain integrity results
  • Current policy records
  • Summary counts for agents, grants, audit outcomes, policies, and plan

Evidence And Standards Mappings

  • SOC 2 — readiness control mapping published; formal third-party attestation is not published. View mapping
  • IETF Internet-Draft — preparation track only; no IETF submission, working-group adoption, RFC approval, or standards status is claimed. Internal Commerce V1 C6T materials define the draft outline and review gates.
  • NIST AI RMF — mapping and whitepaper preparation track only; no NIST submission, public comment submission, NCCoE acceptance, or NIST approval is claimed. Internal Commerce V1 C6T materials define the candidate reference architecture and control-map outline.
  • OpenID AuthZEN — conformance mapping complete. View mapping
Last modified on July 11, 2026