TRUCERT ASSURE

Proof with an expiry date.

A policy PDF proves what you intended. An annual certificate proves a control worked on one audit day. A TruCert proves the control worked last month, on your real traffic — and it expires the moment good behaviour stops. Powered by the open OpenAISF framework, authored by our founder — the standard whose controls map to the rulebooks you already answer to: ISO 42001, ISO/IEC 23894 (AI risk management), NIST AI RMF, the EU AI Act and more.

Where the proof comes from

Assure does not ask you for evidence. It reads what the gateway already writes: request logs, the tamper-evident audit trail, guardrail decisions, routing records and spend by tag — and turns those facts into exports mapped to the regime they satisfy.

Your teams work

People use AI as they always do. Every request passes through the gateway — logged with its model, tokens, cost, latency, key and tags.

The rules do their job

The cost engine refuses an over-budget request. Routing falls through to the next provider. The data-protection catalog redacts an IBAN. A leaver's virtual key is revoked. Each is a recorded fact, not a promise.

The proof writes itself

Those facts are matched to the obligations they satisfy — AI Act, DORA, NIS2, GDPR — under OpenAISF control IDs, and packaged as auditor-ready exports.

The proof stays fresh

Each TruCert is valid for 29 days and renews itself while the controls keep working. If the evidence stops, the proof lapses — publicly and on its own.

What the proof covers

Shaped for these rules — not "certified under" them. The distinction matters, and we keep it.

EU AI Act

Ready today, ahead of 2027

Your disclosure list is ready today (Art. 50, in force since 2 Aug 2026), and your logs are shaped for the deployer duties arriving 2 Dec 2027 (Art. 26(6), postponed by Reg. (EU) 2026/1744 — a date most vendors still get wrong). Evidence trails take a year to mature; start before the duty bites.

DORA

Your register and your exit plan — proven

Extracts for the official register of your AI providers (Art. 28) built from the provider catalog, concentration snapshots (Art. 29) built from real spend by tag, and routing records that show your exit plan is tested rather than theoretical (Art. 30).

NIS2 + GDPR

Access control, proven from real traffic

Access-control artifacts under Art. 21(2) from the virtual-key hierarchy and SCIM de-provisioning; maps of your providers and their sub-processors generated from actual traffic instead of questionnaires; reports of every request routed to EU endpoints.

Sovereignty attestation

Proof of where every request went

A signed record of the destination provider and region for every single request, drawn from the request log. A record, not a promise — and no other gateway offered this at our mid-2026 market verification.

Why "expiring" is the point

OpenAISF puts it simply: "a policy that never fired under live traffic was not operating." Static certificates age silently; proof that expires cannot lie about the present. Your auditor gets a document that is either current — or visibly out of date.

Included with Assure: 3 audit-support days per year. We sit with your auditor and walk through every export together.

EVIDENCE OF OPERATING CONTROL
TruCert № 4411
29d
AI requests through the gateway214,092
Budgets enforced by the cost engine3 ✓
Routing fallbacks on real traffic2 ✓
Requests sent outside Europe0 ✓
⧗ KEPT FRESH BY REAL USE — NOT BY A SIGNATURE

TruCert provides controls tooling and evidence; regulatory compliance judgments remain with your organisation and its auditors. No certification is claimed or implied.

Assure sits on top of the gateway.

The gateway does the governing; Assure turns what it records into proof. One product, one contract, one vendor.

Talk to us See the gateway