questions

Compliance and evidence, answered in full.

EU AI Act, ISO/IEC 42001, NIST AI RMF and OWASP mappings, what an evidence export proves, retention and erasure — and which certifications do not exist.
Questions in this subject
6
Questions across the whole set
49
Subject, in the reading order
4/7
6 questions

Each answer stands on its own

Every answer here is written to be read without its question, without the paragraph before it and without the rest of the site, because the form it will most often be read in is somebody else's summary. Where there is a limit, it is in the same sentence as the claim rather than in a note underneath it.

Does Token Observe make us compliant with the EU AI Act?

No. Token Observe is a control, not a certification, and the mapping document says so in its opening lines: deployer obligations remain yours. What it does is produce the evidence particular clauses ask for. Article 12 automatic record-keeping is served by the flight recorder over the governed request lifecycle and by the hash-chained log of governance-plane changes — though hidden model reasoning is not recorded and is not claimed to be. Article 14 human oversight maps to approvals with named approvers and recorded rationale, and Article 14(4)(e), the ability to halt, is literally the kill switch, which requires an attributable actor and a reason. Article 26 maps to the registry’s declared purpose, risk tier and named owner, to radar findings and policy-block metrics, and to a one-click export bundle. Deciding risk tiers, running a fundamental rights impact assessment and notifying regulators stay with you.

Do you have SOC 2, ISO 27001 or ISO 42001 certification?

Token Observe holds no SOC 2 attestation, no ISO 27001 certification and no ISO/IEC 42001 certification, and there is no independent penetration-test result either. That appears in the repository before it appears in a sales conversation, and it is a blocker rather than a roadmap item: the design-partner gate requires counsel approval and independent security testing against an immutable release candidate before anything is authorised. What exists instead is the material a certification report would summarise — a published threat model with a residual risk on every row and the role that must accept each one, a data-flow document you can verify against the source in about five minutes, a defect list that names the attacks that still work and records the findings that were refuted on verification as well as the confirmed ones. Release artifacts must carry an SBOM, checksums and provenance, though no immutable tagged release has been cut yet. Certification is not on the near-term roadmap, so procurement should not expect one inside a design partnership.

How does Token Observe map to ISO/IEC 42001 and the NIST AI RMF?

Token Observe maps to ISO/IEC 42001 and the NIST AI RMF by producing the artefacts each control asks for, not by claiming conformity to either. For ISO/IEC 42001 Annex A: A.4.2, the AI system inventory, is the agent registry — and the argument is that it is the same record the gateway enforces against on every call, so it cannot silently drift from reality the way a parallel spreadsheet does. A.5.3 is the per-agent risk tier that policy scope and reviews attach to. A.6.2.8, logging and monitoring, is the flight recorder plus the hash-chained audit log. A.8.3 and A.8.4 incident reporting are webhook events into your ITSM or SIEM. A.9.2 is deny-by-default agent permissions with delegation intersection. A.10.3 supplier control is the provider registry with its data-policy flags and MCP tool integrity pinning. For the NIST AI RMF: govern is versioned audited policies with an owner per agent, map is the registry, measure is the cost ledger and shadow-mode findings, manage is circuit breakers, kill switches and approval gates.

Are evidence exports signed?

No. Token Observe’s evidence exports are SHA-256 digest-sealed, which is a smaller claim, and the wording matters. A trace export or a compliance bundle carries a digest the recipient recomputes over the canonical JSON of the bundle, plus the embedded audit-chain verification result: whether it verified, how many entries were checked, the sequence number any break was located at, whether the chain was keyed, and the checkpoint it was verified against. That detects accidental or post-export edits and locates them, which an exported log file cannot do. It does not prove origin. Durable origin evidence comes from two other things: keyed audit, so a rewrite needs the key as well as the database, and an Ed25519 anchor retained independently of the database that produced it. Separately signed artefacts do exist — the audit anchors themselves, and, where an anchor signing key is configured, portable effect receipts for terminal committed or compensated outcomes, verifiable offline against key material the auditor holds through an independent channel rather than key material read out of the receipt — and conflating either with the export would overstate both.

How does Token Observe map to the OWASP LLM and agentic top tens?

Token Observe maps to the OWASP top tens for LLM applications and for agentic applications partly, and the mapping names the entries it does not cover rather than implying ten out of ten. Prompt injection is unicode sanitisation and heuristic scoring on prompts and tool results. Sensitive information disclosure is inline detection with checksum validation plus stream hold-back. Supply chain is MCP descriptor hashing with drift quarantine. Excessive agency is action-level deny-by-default permissions, argument-level matchers and approval gates on high-impact tools. Unbounded consumption is per-agent budgets, rate limits and provider circuit breakers. Two entries are out of scope and say so: data and model poisoning, because runtime traffic is governed rather than training pipelines, and vector or embedding weaknesses, because there is no retrieval layer. Two are partial: improper output handling, since what your application does with returned text is outside the gateway, and misinformation. On the agentic list, the design rule worth quoting is that an approval queue nobody reads is worse than no gate at all.

What are the retention and erasure controls, and what do they not cover?

Token Observe implements both trace retention and subject erasure, and its default is to keep everything — a decision you have to make rather than one you can inherit. The trace retention window is unset by default, and unset means keep forever, which over-satisfies the six-month minimum in EU AI Act Article 26(6) and satisfies nothing in GDPR storage limitation, so a GDPR-regulated deployment must set it. Subject erasure deletes by principal, session or either, with a dry run that returns the count first; both the preview and the deletion are audited, and the audit entry carries a digest of the subject identifier rather than the identifier itself. What the window does not cover is the list a data protection officer will ask for: it acts on traces, trace events, the search index and trace scores and on nothing else, so approvals, radar findings and webhook deliveries are not purged and cannot be erased by subject, the audit log is never touched by design, identity-provider group snapshots and gateway caller sightings run on their own separate windows, and erasure reaches the live primary only, never a retained backup. Quoting the trace window as though it were the deployment’s retention period is therefore wrong in both directions.

If the answer above is close but not quite the case you have, the specific version of it is a better question than the general one, and it gets a specific reply.

Ask the specific version
get in touch

Bring the question this page did not answer.

Write to hello@tenhaw.com with what your agents do, which providers they call and what would have to be true for you to put something in front of them. James Rooney replies. You will get a straight answer about whether Token Observe fits, including when it does not.

no form · no qualification step · no sales desk · the other three ways in