COMPLIANCE

Compliance evidence for AI agent tool calls

Stipul does not make an organization compliant by itself. It produces structured compliance evidence for mediated AI agent tool calls routed through Writ: what was requested, which Charter rule applied, whether Writ allowed or denied the call, whether a denied call was forwarded, and whether the Chronicle evidence remains intact.

What this page claims

This page maps Stipul to compliance control themes. It is not legal advice, an audit opinion, a certification claim, or a guarantee of regulatory compliance. Stipul can help produce evidence that may support governance, risk, compliance, and audit workflows when AI agent systems execute business-critical mediated tool calls through Writ.

Control themes Stipul supports for AI agent compliance

Runtime authorization

Stipul enforces the Charter before mediated tool calls execute.

Least privilege for tool execution

Charters can limit tools, parameters, destinations, workflows, and high-risk actions.

Denied-call evidence

Chronicle records denied mediated calls and the rule that triggered the denial. Writ does not forward denied calls through the governed path.

Tamper-evident evidence

Chronicle records mediated enforcement decisions as a hash-chained evidence sequence. Seal verifies whether the evidence remains intact.

Policy accountability

Charter fingerprints tie evidence back to the policy in force for the session.

Boundary disclosure

Stipul explicitly defines what it does not control: direct API access, leaked credentials, compromised hosts, unmanaged SDK calls, and paths outside Writ.

How Stipul maps to compliance frameworks

Framework / standard / regulation Control theme How Stipul can help Limitation
NIST AI RMF AI risk governance, mapping, measurement, and management. Produces runtime evidence showing which mediated tool actions were allowed or denied, under which Charter, and with what verification result. Does not assess model quality, fairness, safety, or organizational AI risk by itself.
ISO/IEC 42001 AI management system evidence, governance process, risk treatment, and operational control. Provides enforceable policy artifacts and evidence records for AI agent tool execution workflows. Does not implement a full AI management system, organizational policy program, or certification process.
SOC 2 / Trust Services Criteria Security, availability, processing integrity, confidentiality, and privacy evidence themes. Shows whether governed tool calls were authorized before execution and whether denied mediated calls were not forwarded through Writ. Does not replace access control, infrastructure security, change management, vendor management, or SOC 2 audit procedures.
ISO/IEC 27001 Information security management, access control, logging, monitoring, change control, and risk treatment evidence. Adds a deterministic authorization and evidence layer for mediated tool execution. Does not replace an ISMS, asset inventory, identity management, endpoint security, operational security, or internal audit process.
EU AI Act Risk management, technical documentation, logging, human oversight, transparency, and post-market monitoring themes for applicable systems. Can produce structured evidence of mediated agent actions, authorization decisions, enforcement boundaries, and evidence integrity. Does not determine whether a system is covered, high-risk, compliant, or legally sufficient.

AI agent threat model facts that matter for compliance

Assets Stipul helps govern

  • Charter policy artifacts
  • Writ enforcement decisions
  • Chronicle evidence chain
  • Seal verification receipts
  • Session context
  • Downstream tool execution path

Actors in scope

  • Operator configuring Charters
  • Agent requesting mediated tool calls
  • Writ enforcing policy
  • Third-party API receiving allowed calls
  • Verifier checking evidence integrity
  • Attacker attempting to bypass, tamper, or misrepresent evidence

Primary threats Stipul addresses

  • Unauthorized mediated tool call
  • Dangerous action denied before execution
  • Denied call falsely claimed as forwarded or not forwarded
  • Evidence tampering after the session
  • Charter mismatch or policy drift
  • Misleading audit trail assembled after the fact

Threats Stipul does not address by itself

  • Direct API access outside Writ
  • Leaked credentials used outside the governed workflow
  • Compromised host running Writ or the agent
  • Incorrect Charter policy
  • Deleted or non-durable evidence stores
  • Third-party API state changes after an allowed forwarded call
  • Channels not integrated with Writ

Compliance evidence artifacts Stipul can produce for AI agent audits

Charter fingerprint

Shows which policy was in force.

Decision record

Shows requested tool, applied rule, decision, timestamp, and session context.

Forwarding status

Shows whether a mediated call was forwarded through Writ.

Chronicle hash chain

Shows whether the recorded sequence remains intact.

Seal receipt

Shows whether verification returns VERIFIED or REJECTED.

Boundary statement

Shows what Stipul does not claim to control.

Roadmap items, not current claims

Credential custody

Production deployments need a hardened model where downstream platform credentials live behind Writ, not inside the agent runtime.

Bypass prevention

Enterprises need deployment controls that reduce unmanaged paths around Writ.

Evidence durability

Chronicle integrity can be verified, but evidence storage durability and retention are deployment responsibilities until stronger managed storage exists.

Origin binding

Current verification proves evidence integrity under Stipul's trust model. Stronger enterprise identity binding and signing-key custody remain roadmap items.

Charter validation

Stipul enforces the Charter as written. Tooling to test and validate Charter intent remains roadmap work.

Security reporting

Security issues that affect Stipul's enforcement boundary, denied-call forwarding behavior, Chronicle evidence integrity, Seal verification, secret handling, or public claims can be reported to [email protected].

  • affected version or commit SHA
  • reproduction steps
  • expected behavior
  • actual behavior
  • impact
  • suggested mitigation if available

What Stipul does not do for compliance

  • Does not make legal compliance determinations.
  • Does not certify AI systems.
  • Does not classify systems under the EU AI Act.
  • Does not validate whether a Charter is legally sufficient.
  • Does not assess model fairness, bias, or explainability.
  • Does not protect direct API access that bypasses Writ.
  • Does not protect leaked credentials used outside the governed workflow.
  • Does not replace IAM, GRC, SIEM, endpoint security, host security, or audit procedures.

Why this matters

Enterprises do not only need agents to act. They need evidence that governed actions were authorized, denied, recorded, and verifiable. Stipul creates a deterministic control and evidence layer for mediated AI agent tool calls, with explicit limits around the path it governs.