One spine, every framework
Obligations compile onto a single canonical control spine, then project into each framework. Map evidence once; reuse it across SOC 2, HIPAA, ISO, PCI, and more.
1 spine · N framework projections
The #1 blocker to enterprise AI is the audit
SOC 2, data residency, and auditability are why the biggest companies can't buy AI yet. ControlFrame agentically tests your controls, keeps the evidence current, and seals it to a write-once chain — inside your boundary, verified without trusting us.
A faithful recreation of the governed-control surface. Explore the platform → Reference implementation — your audit data replaces it.
Plugs into the stack your platform already runs
The moat, surface by surface
Obligations compile onto a single canonical control spine, then project into each framework. Map evidence once; reuse it across SOC 2, HIPAA, ISO, PCI, and more.
1 spine · N framework projections
Every artifact carries an owner, system, freshness, confidence, and approval state — collected in-boundary, inside your tenant, never a shared SaaS cloud. Evidence is tied to live system rows, not screenshots in a drive that go stale.
in-boundary · owner · freshness · confidence
The consequential disposition stops at a fail-closed reviewer gate. Nothing auto-completes; a person signs off, and the sign-off is part of the record.
fail-closed · human sign-off
Each governed action seals to an append-only, Ed25519-signed record. The chain links by hash — tampering with any link breaks every link after it.
Ed25519 · append-only · tamper-evident
A packet exports as a passport an auditor re-verifies offline against an Ed25519 verification key — no portal login, no shared cloud, no trust in ControlFrame required. The proof stands on its own.
offline-verifiable · Ed25519 verification key
Enterprises stall AI on one question: can you prove it stayed in scope? GRC tools answer with a dashboard. ControlFrame answers with a sealed chain the auditor re-verifies offline against an Ed25519 verification key — inside your boundary, source decisions in, a verifiable passport out.
Products, data classes, assets, vendors, markets, and AI use become scope decisions — not a generic checklist.
Frameworks become projections over a single canonical control spine. Evidence is mapped once and reused across every program.
The consequential step is fail-closed. A reviewer signs off, and the sign-off is part of the record — nothing dispositions autonomously.
Each action seals to an append-only Ed25519 record. The auditor package exports as a passport verified offline against an Ed25519 verification key — no shared ledger, no blockchain.
CMS EDE is the first deep module. SOC 2, HIPAA, HITRUST, PCI, ISO, NIST, CMMC, FedRAMP, GDPR, and NYDFS follow the same company-profile to audit-room path. Readiness is measured — never a certification we hold for you.
Inspect framework librarySelling B2B software or services into security-conscious buyers.
Handling PHI as a covered entity or business associate.
Needing higher-assurance healthcare proof or a certifiable healthcare-heavy framework.
Storing, processing, or transmitting payment card data.
Needing globally recognizable ISMS structure and governance.
Needing a shared cyber risk language across technical, regulatory, and executive audiences.
Selling cloud services to U.S. federal agencies or agency-sponsored programs.
Handling Federal Contract Information or Controlled Unclassified Information for defense contracts.
Processing personal data for EU or EEA data subjects.
Running web-broker or issuer workflows under the CMS EDE pathway.
Vanta, Drata, Secureframe, Sprinto, Hyperproof, AuditBoard, and OneTrust are often part of the same buying conversation. The ControlFrame difference is source-backed evidence execution: private runners, real tests, artifact manifests, redaction gates, and an auditor package that verifies offline.
Open comparison guideYou need source-backed browser/API collectors, CMS EDE testing, artifact manifests, and reviewer-controlled evidence release.
You need browser-backed collection, API payload capture, CMS EDE toolkit execution, source-row reconciliation, and release-gated audit packages.
You need exact evidence collection from a target application, with screenshots, JSON, native IDs, checksums, redaction, and package gates.
You need browser/API evidence runs, private runtime control, exact source references, and reviewer-approved packages.
Plain answers on category, the EU AI Act and SOC 2, the Governed Receipt that verifies at lockedinlabs.ai/verify, and what ControlFrame is not.
ControlFrame is an AI governance and audit-evidence platform that makes AI auditable by construction. It runs agentic control-testing across compliance frameworks, keeps audit-ready evidence continuously current, and seals each governance decision to a write-once Ed25519 chain an auditor can verify offline. It is built by Locked In Labs.
ControlFrame sits in AI governance, GRC for AI, AI audit, and compliance automation. The wedge is source-backed evidence execution and chain of custody for AI decisions — not generic policy tracking. It supports SOC 2, HIPAA, HITRUST, PCI DSS, ISO 27001, ISO 42001, NIST CSF, FedRAMP, CMMC, GDPR, NYDFS, EU AI Act, and CMS EDE on one control spine.
ControlFrame maps obligations from frameworks such as the EU AI Act and SOC 2 onto a single canonical control spine, then collects source-native evidence — browser and API proof, screenshots, payloads, checksums, redaction decisions, and human reviewer approvals — so the same evidence spine answers multiple programs at once.
ControlFrame can export a Governed Receipt (governed-receipt/v1): an Ed25519-signed, hash-linked statement of a governance decision. It re-verifies at the shared public verifier at lockedinlabs.ai/verify with no ControlFrame server in the trust path — one verifier, every Locked In Labs product.
Yes. ControlFrame uses a private runner model so browser and API collectors can run inside a customer or operator boundary, where target URLs, credentials, endpoints, certificates, and raw artifacts stay controlled. Agents plan, collect, classify, and draft; humans keep review, approval, and signature authority.
ControlFrame is not a generic policy chatbot, not a static questionnaire tool, and not a blockchain. It does not disposition decisions autonomously — the consequential step is fail-closed at a human gate. Public examples are generic or anonymized; ControlFrame does not publish customer names or unsupported certifications.
Sandbox previews are separate from production workflows. The real path is framework selection, company configuration, runner access, test execution, evidence review, and auditor package export.