EU AI Act enforcement active — Aug 2, 2026

Compliance & AI governance,
unified on one
control graph.

The only platform that runs SOC 2, ISO 27001, ISO 42001, and the EU AI Act simultaneously — with automated evidence from 11 built-in integrations plus any tool that speaks MCP.

SOC 2ISO 27001ISO 42001EU AI ActHIPAAGDPR+ Custom
CONTROL STATUS
LIVE SYNC
ENC-001Encryption at rest
SOC2 CC6.7 · ISO27001 A.8.24
PASSING
AC-002MFA enforcement
SOC2 CC6.1 · ISO27001 A.5.16 · HIPAA
FAILING
CM-001Change management
SOC2 CC8.1 · ISO27001 A.8.31
CHECKING…
AI-001AI system inventory
ISO42001 A.6.2.2 · EU AI Act Art.16
PASSING
RM-001Risk assessment
SOC2 CC9.1 · ISO42001 Clause 6.1.2
PENDING
RECENT EVIDENCE
GitHub sync — branch protection verified on 3 repos2m ago
🔍AWS check — 3 IAM users missing MFA2m ago
Linear sync — 4 issues tracked, change log verified2m ago
0
Frameworks supported
0
Controls in shared catalog
0
Cross-framework mappings
0
Integrations automating evidence
How it works

From onboarding to audit-ready in four steps.

No consultants. No spreadsheets. No screenshots. Connect your tools and let evidence collect itself.

1

Adopt frameworks

Pick what your customers require. Shared controls are created once — not duplicated across programs.

2

Connect integrations

GitHub, AWS, Okta, Slack, Linear, an MCP server, or 7 more — all pull real evidence automatically every day.

3

Evidence updates daily

Scheduled syncs every morning. When something fails, you know by email — not by logging in.

4

Share with auditors

Token-gated auditor portal. Every control and evidence record. No zip files, no Google Drive.

Frameworks

Every framework your customers will ask for.

Six built-in frameworks with real clause mappings. Plus fully customizable framework support for any regulation or internal policy.

Security

SOC 2

Required by most US enterprise customers before signing. The most common compliance request for SaaS companies.

Security

ISO/IEC 27001

International security standard. Required by EU and global enterprises. Significant overlap with SOC 2.

AI Governance

ISO/IEC 42001

First international AI management standard. Increasingly required for AI products alongside SOC 2.

AI Governance

EU AI Act

Legal obligations for AI systems. Risk classification, conformity assessments, transparency obligations — in force now.

Healthcare

HIPAA

Required for any company handling US healthcare data. Mandatory for healthtech companies and vendors.

Privacy

GDPR

Required for processing EU residents' personal data. Applies to most SaaS companies with EU customers.

Fully Customizable

Any regulation. Any contract. Any internal policy.

Upload any regulation, customer contract, or internal security policy. Annex AI maps it to your existing control graph, finds the overlaps with your current frameworks, and keeps it continuously updated. One control graph — every requirement you're accountable for.

Platform features

Everything you need to go from zero to audit-ready.

Built for AI companies — not retrofitted from a security-only tool.

Shared control graph

One control satisfies multiple frameworks simultaneously. Evidence collected once. No duplicate programs or evidence trails.

🤖

EU AI Act classification

Risk tier classification with article-level reasoning — not checkboxes. Cites the actual regulation, not a summary.

📋

Article 50 compliance check

Check if your AI product meets transparency obligations in force from August 2, 2026. Chatbot disclosure, content labeling, and more.

📄

AI-generated policies

Audit-ready policies in 30 seconds, tailored to your actual stack and frameworks. Cites real clause numbers — not templates.

📊

ISO 42001 gap report

Downloadable gap assessment from your live control data. Worth thousands from a consultant — one click here.

🔍

AI system auto-discovery

Scans GitHub repositories for LLM SDK imports. Surfaces AI systems you haven't registered before an auditor does.

🔗

Auditor portal

Token-gated link for your external auditor. Every control and evidence record, no account needed. No zip files.

🌐

Public trust center

Real-time compliance posture your prospects can check before a sales call. Frameworks, passing controls, integrations.

💬

Questionnaire auto-fill

Paste questions. Claude drafts answers from your real control status in 30 seconds. Confidence ratings included.

🔌

Connect via MCP

Any internal system that speaks the Model Context Protocol becomes an evidence source. We connect as an MCP client, discover your tools, and map results straight to controls.

🔐

Role-based access control

Five permission tiers from Viewer to Owner. Deactivated members are locked out of every session instantly — itself evidence for your access-control controls.

Evidence review workflow

Manual uploads sit in a review queue, not blind trust. Accept or reject with a reason before it counts toward compliance.

Integrations & tools

11 integrations. Real evidence. No screenshots.

Connect your existing tools. Evidence pulled automatically every day. All credentials encrypted with AES-256-GCM before storage.

GitHub
AWS
Google Workspace
Okta
Slack
Jira
Linear
Rippling
Jamf
Datadog
Snyk
Custom integration

Model Context Protocol (MCP) support

Don't see your tool in the list? Connect any internal system that exposes an MCP server — HR platforms, ticketing systems, custom cloud infrastructure. Annex AI connects as an MCP client, automatically discovers the tools it exposes, and maps every result straight to a control as evidence.

HR systemsTicketing toolsCustom cloudAny MCP server
Why Annex AI

Built for AI companies. Not retrofitted.

One control graph — not four separate programs

SOC 2, ISO 27001, ISO 42001, EU AI Act run together. Evidence satisfies multiple frameworks simultaneously.

Controls are tool-agnostic by design

Switch from Okta to Google Workspace — the control stays intact. Only the evidence source changes. No broken compliance programs.

AI governance is native, not an add-on

EU AI Act classification, Article 50 compliance, ISO 42001 gap reports, AI system discovery — built from day one.

Evidence is real, immutable, and continuous

Daily automated syncs. Timestamped records. Not screenshots assembled once a year before an audit.

Priced for startups, not enterprises

Vanta and Drata start at $10,000+/year for one framework. Annex AI covers six frameworks and AI governance at a fraction.

CapabilityAnnex AIOthers
SOC 2 / ISO 27001 automation
Integrations & evidence sync
Trust center & auditor portal
Questionnaire auto-fillPartial
One control graph, every frameworkPartial
AI governance in the same graphLimited
Article 50 transparency check
Startup-friendly pricing
Get started

Ready to be audit-ready?

20 minutes. We'll connect your GitHub live and show you your first real control result before the call ends.