For security, risk & compliance teams

Prove your AI is compliant —
to the EU AI Act & ISO/IEC 42001.

Your AI works. The harder question is whether it can prove itself to a customer's security review or a regulator. Connect your codebase and ShipSmith discovers every AI workflow and assesses each against the controls a reviewer cares about — a compliance readiness grade and gap list for every workflow.

120+ controls · 7 governance dimensions · EU AI Act & ISO/IEC 42001

Clearing a compliance review shouldn't block shipping.

Every company deploying AI is meeting the same wall: customers, auditors and regulators asking "prove your AI is governed, safe and accountable." The evidence is scattered across code, configs, policies and people's heads, and assembling it by hand for each review is what stalls deals.

ShipSmith discovers every AI workflow, assesses each against the controls a regulator cares about, and hands you a defensible grade and gap list — mapped to the EU AI Act and ISO/IEC 42001.

Seven governance dimensions, 120+ controls.

A distinct assessment from our production readiness scan — grounded in the two standards buyers and regulators actually reference: the EU AI Act and ISO/IEC 42001.

Governance

25 controls

Who owns the AI, what the policy says, and how it's held accountable.

Risk Management

18 controls

Finding where an AI system can cause harm — and having a plan before it does.

Human Oversight

16 controls

A person stays in control — able to review, override and stop the system.

Auditability

16 controls

If a regulator asks what happened, the logs can reconstruct it.

Data & Privacy

21 controls

Where personal data enters the model, and the safeguards around it.

Transparency

16 controls

People affected by the AI know it's AI — and can get an explanation.

Lifecycle

21 controls

Keeping the system safe as it changes, and handling incidents when they happen.

From codebase to compliance evidence.

The same connect-your-repo flow as production readiness — pointed at the controls a regulator cares about.

🔍

Discover & classify

Connect your codebase and ShipSmith inventories every LLM call, agent and chain — including the shadow workflows that accumulate when teams move fast — and classifies each into its EU AI Act risk tier.

📊

Assess against 120+ controls

The free scan automatically checks the controls it can verify from your code. The policy and process controls that need a judgment call are completed with our team in the full assessment — across all 7 governance dimensions, scaled to each workflow's risk tier.

📄

Compliance gap list

A grade per workflow, a gap list keyed to EU AI Act and ISO/IEC 42001 articles, and remediation guidance you can put in front of a review.

And ShipSmith helps you close the gaps: remediation guidance for each one, plus support to get your team fluent in what reviewers expect — so you're ready for the next review, not just this one.

Not every gap lives in the code.

Compliance isn't only an engineering question. Many controls live in your policies, governance and process — the things a scanner can't read off a repo. ShipSmith covers both, so nothing falls through the gap between engineering and governance.

In the code

Surfaced directly from your codebase — starting in the free scan.

  • Audit logging wired and active per workflow
  • PII masked or excluded from LLM context
  • Human-review gates before consequential decisions
  • Kill switches and step limits on agents
  • Tool calls logged with their reasoning
In your policies & process

Assessed in the full product — the controls code alone can't answer.

  • An approved, communicated AI policy
  • A named AI risk owner and accountability structure
  • DPIAs and data-processing agreements on file
  • An AI-specific incident-reporting process
  • A maintained risk register and change-management gate
Maintained continuously

Controls that keep pace with the regulations, so you don't have to.

AI regulation is moving fast — the EU AI Act phasing in, ISO/IEC 42001 maturing, and new obligations landing all the time. Keeping a control set current with all of it is a full-time job most teams can't take on.

So we take it on. We continuously maintain and expand our control set — 120+ controls today, and growing as standards evolve — so every assessment reflects the current bar, and your team never has to track what changed. The burden of staying up to date is ours, not yours.

Auditors & consultancies

Assess client AI faster, against a standard you can stand behind.

If you assess or deliver AI governance for other companies, ShipSmith is a capability multiplier: run it across every client codebase, assess against one repeatable methodology (120+ controls, 7 dimensions, grounded in the EU AI Act and ISO/IEC 42001) and turn manual, inconsistent reviews into a defensible, scalable service line.

Talk about a partnership →

Turn your AI into evidence.
Scan your first workflow, free.

Discover every AI workflow and assess it against the EU AI Act and ISO/IEC 42001 — with a compliance gap list you can act on.