Use case · Prove Compliance with Evidence

One picture of your AI and your assets, every framework you answer to.

Which AI you run and who is accountable for it. What assets you have, what protects them, what they're worth. The frameworks differ; the questions underneath them barely do. KeyCaliber builds both pictures from the security tools you already run, and keeps them current, so the evidence is ready before anyone asks for it.

Meet the standard you're measured against.

Different regulators, the same underlying question. Here's where KeyCaliber fits.

EU AI Act

European Union Artificial Intelligence Act

EU, and anyone placing AI on the EU market

The Act asks a deployer to know which AI systems it uses, who oversees each one, and to keep records of that use. KeyCaliber builds the register underneath it.

Learn more →

ISO 42001

ISO/IEC 42001, AI management systems

Global, driven by procurement

ISO 42001 is arriving through supplier questionnaires rather than regulators. It starts with a register of AI systems, named accountability, and controls over the AI your suppliers bring.

Learn more →

NYDFS

New York Department of Financial Services, Part 500

New York financial services

Part 500 expects a documented inventory of every asset and proof that it stays current. KeyCaliber builds it from the security tools you already run.

Learn more →

DORA

Digital Operational Resilience Act

EU financial services

The Digital Operational Resilience Act expects a register of your technology assets and the connections between them. KeyCaliber assembles it from systems you already have in place.

Learn more →

CMMC & NIST 800-171

Cybersecurity Maturity Model Certification and NIST SP 800-171

Defense supply chain

Defense contractors have to show what they run, what protects it, and where controlled information lives. KeyCaliber builds that picture from tools already on the network.

Learn more →

NIS2

Network and Information Security Directive 2

EU essential and important entities

Risk management measures are only as good as the picture underneath them. KeyCaliber supplies the one your risk analysis runs on.

Learn more →

PCI DSS

Payment Card Industry Data Security Standard

Anyone handling card data

Scope is where card data assessments go wrong. KeyCaliber shows you every system in the environment and what it connects to.

Learn more →

CSRB

UK Cyber Security and Resilience Bill

UK essential services, managed service providers and data centres

The Cyber Security and Resilience Bill raises the bar on resilience, and managed service providers and data centres are now in scope. Start from a complete asset picture.

Learn more →

What you get, whichever framework you're held to.

One register of the AI you run

Hosted services, AI features inside apps you already approved, model runtimes on laptops and servers, and remote endpoints — one row each, and every value says whether it was observed, curated, entered by your team, or not yet assessed.

A decision on every AI system

Approved, prohibited or under review, scoped to the people or groups allowed to use it, with a named owner and a timeline of every decision, reversal and owner change.

Your vendors, on the record

Each vendor's published training policy and the sub-processors they hand your data to, read from their own pages and dated. Where a vendor publishes nothing, the record says so.

One record per asset

Deduplicated across endpoint, cloud, scanners, identity and CMDB, with each tool's view kept alongside — plus the devices, services and AI tools visible in network, DNS or sign-in activity that no management console has ever claimed.

Controls confirmed, findings ranked

Which assets are missing endpoint protection, vulnerability scanning or identity coverage — as a list of machines, not a percentage — ordered by what the affected system is worth.

Evidence on demand

Every fact carries its source and every score opens into the factors behind it. Filter and export the day it's asked for — the register as a dated record that states its own coverage and limits, with nothing unknown rounded down to zero.

All of it from read-only connections to tools already in your environment. No agent, no proxy, no appliance, nothing installed on a single machine.

Have the evidence before you're asked for it.

Connect the tools you already run and see your own AI register, asset inventory, coverage and ranked findings.

Request a demo