Use case · Prove Compliance with Evidence
One picture of your AI and your assets, every framework you answer to.
Which AI you run and who is accountable for it. What assets you have, what protects them, what they're worth. The frameworks differ; the questions underneath them barely do. KeyCaliber builds both pictures from the security tools you already run, and keeps them current, so the evidence is ready before anyone asks for it.
Meet the standard you're measured against.
Different regulators, the same underlying question. Here's where KeyCaliber fits.
EU AI Act
European Union Artificial Intelligence Act
EU, and anyone placing AI on the EU market
The Act asks a deployer to know which AI systems it uses, who oversees each one, and to keep records of that use. KeyCaliber builds the register underneath it.
Learn more →ISO 42001
ISO/IEC 42001, AI management systems
Global, driven by procurement
ISO 42001 is arriving through supplier questionnaires rather than regulators. It starts with a register of AI systems, named accountability, and controls over the AI your suppliers bring.
Learn more →NYDFS
New York Department of Financial Services, Part 500
New York financial services
Part 500 expects a documented inventory of every asset and proof that it stays current. KeyCaliber builds it from the security tools you already run.
Learn more →DORA
Digital Operational Resilience Act
EU financial services
The Digital Operational Resilience Act expects a register of your technology assets and the connections between them. KeyCaliber assembles it from systems you already have in place.
Learn more →CMMC & NIST 800-171
Cybersecurity Maturity Model Certification and NIST SP 800-171
Defense supply chain
Defense contractors have to show what they run, what protects it, and where controlled information lives. KeyCaliber builds that picture from tools already on the network.
Learn more →NIS2
Network and Information Security Directive 2
EU essential and important entities
Risk management measures are only as good as the picture underneath them. KeyCaliber supplies the one your risk analysis runs on.
Learn more →PCI DSS
Payment Card Industry Data Security Standard
Anyone handling card data
Scope is where card data assessments go wrong. KeyCaliber shows you every system in the environment and what it connects to.
Learn more →CSRB
UK Cyber Security and Resilience Bill
UK essential services, managed service providers and data centres
The Cyber Security and Resilience Bill raises the bar on resilience, and managed service providers and data centres are now in scope. Start from a complete asset picture.
Learn more →What you get, whichever framework you're held to.
One register of the AI you run
Hosted services, AI features inside apps you already approved, model runtimes on laptops and servers, and remote endpoints — one row each, and every value says whether it was observed, curated, entered by your team, or not yet assessed.
A decision on every AI system
Approved, prohibited or under review, scoped to the people or groups allowed to use it, with a named owner and a timeline of every decision, reversal and owner change.
Your vendors, on the record
Each vendor's published training policy and the sub-processors they hand your data to, read from their own pages and dated. Where a vendor publishes nothing, the record says so.
One record per asset
Deduplicated across endpoint, cloud, scanners, identity and CMDB, with each tool's view kept alongside — plus the devices, services and AI tools visible in network, DNS or sign-in activity that no management console has ever claimed.
Controls confirmed, findings ranked
Which assets are missing endpoint protection, vulnerability scanning or identity coverage — as a list of machines, not a percentage — ordered by what the affected system is worth.
Evidence on demand
Every fact carries its source and every score opens into the factors behind it. Filter and export the day it's asked for — the register as a dated record that states its own coverage and limits, with nothing unknown rounded down to zero.
All of it from read-only connections to tools already in your environment. No agent, no proxy, no appliance, nothing installed on a single machine.
Have the evidence before you're asked for it.
Connect the tools you already run and see your own AI register, asset inventory, coverage and ranked findings.
Request a demo