Skip to content
Scan one machine free. No account. Nothing leaves your machine.
KeepRails

Audit-ready evidence

Bring a dated AI-tool register to your next audit

Evidence, not certification. Choose the framework you are being assessed against and see exactly which controls the register feeds — and which ones it does not.

ISO/IEC 42001

What it asks

Document AI resources, tooling, versions, and third-party suppliers inside the management-system scope.

Honest boundary

One inventory input. An independent assessor evaluates the wider management system.

Control Evidence Coverage Status
A.4.2 AI resource inventory Covered
A.4.4 Tooling & version context Covered
A.10.3 Supplier / provider context Partial
A.9.x Wider management system Out of scope

rubricVersion=3 · kbSnapshotVersion=2026-07-27.2 · mapping=cm-6

What the assessor actually receives

Evidence Register

Dated rows grouped at the control level, each with its source.

PDF

Framework report

Control-by-control mapping with the boundary stated per row.

PDF

Evidence JSON

Machine-readable, versioned, diffable between snapshots.

JSON

AI-BOM

Bill of materials for the AI tooling found on the fleet.

CycloneDX

KeepRails Evidence Register on the Northwind Labs demo account, grouped at the control level with each row's source.

Anatomy of an export

What travels with the evidence

In every export

generatedAt · schemaVersion When the export was produced, and which evidence schema produced it.
coverage.activeDevices How many machines are enrolled in the organization at export time.
coverage.devicesWithEvidence How many of them actually contributed a register. The gap between the two is the coverage question, stated rather than hidden.
coverage.truncated Set when the export hit its device cap, so a partial fleet is never read as the whole fleet.
deviceId · scanId Which machine, and which scan on that machine, each register row came from.
deviceIntegrityHash Re-verified during export. A register whose hash no longer matches fails the export instead of shipping.
owner · sanctionStatus · reviewedBy The organization's own decisions, recorded against register entries rather than asserted by us.
changes.added / removed / changed Per device, against the previous snapshot — so a second period is a diff, not a re-collection.

Not yet

No single run identifier

An export is dated and hashed per device, but the export as a whole has no stable ID to cite in an audit file. You reference it by date today.

Exports are recomputed, not pinned

Asking for the same period twice re-reads the current registers rather than replaying a frozen artifact. Keep the file you were given; do not assume it can be regenerated byte-for-byte.

Both are on the roadmap. Neither is claimed as shipped anywhere on this site.

Deterministic measurement

Reproducible, versioned, and honest about the window

observed used

Seen running inside a covered window.

not observed in window

Not the same claim as unused.

unattributable

Counted without a defensible match.

coverage insufficient

A finding about the evidence, not the asset.

Scan → Evidence Register → Framework Mapping → Report + Evidence JSON + AI-BOM → Control-level coverage

Getting evidence into your GRC tool

Working today

Export and upload

keeprails report --evidence

Produces the sanitized evidence package you attach in Vanta, Drata, or a shared drive.

In pilot

Native push

Direct Vanta and Drata delivery is in pilot with design-partner accounts. Ask us for the current status.

See it on your own data

Twenty minutes, your frameworks, your fleet.

Book a demo

Compliance questions

Is this an independent assessment?

No. It is evidence, not certification. KeepRails produces a dated inventory artifact; independent assessors evaluate the wider program.

What makes the register audit-ready?

Each artifact is source-attributed, timestamped, deterministic, labeled observed or inferred, and integrity-hashed.

What leaves the machine?

Nothing during the local scan. Only sanitized tool-identity metadata can be shared, and only after you pair a device into a signed-up org; code, prompts, config content, and secrets stay local.