A policy PDF proves what you intended. An annual certificate proves a control worked on one audit day. A TruCert proves the control worked last month, on your real traffic — and it expires the moment good behaviour stops. Powered by the open OpenAISF framework, authored by our founder — the standard whose controls map to the rulebooks you already answer to: ISO 42001, ISO/IEC 23894 (AI risk management), NIST AI RMF, the EU AI Act and more.
Assure does not ask you for evidence. It reads what the gateway already writes: request logs, the tamper-evident audit trail, guardrail decisions, routing records and spend by tag — and turns those facts into exports mapped to the regime they satisfy.
People use AI as they always do. Every request passes through the gateway — logged with its model, tokens, cost, latency, key and tags.
The cost engine refuses an over-budget request. Routing falls through to the next provider. The data-protection catalog redacts an IBAN. A leaver's virtual key is revoked. Each is a recorded fact, not a promise.
Those facts are matched to the obligations they satisfy — AI Act, DORA, NIS2, GDPR — under OpenAISF control IDs, and packaged as auditor-ready exports.
Each TruCert is valid for 29 days and renews itself while the controls keep working. If the evidence stops, the proof lapses — publicly and on its own.
Shaped for these rules — not "certified under" them. The distinction matters, and we keep it.
Your disclosure list is ready today (Art. 50, in force since 2 Aug 2026), and your logs are shaped for the deployer duties arriving 2 Dec 2027 (Art. 26(6), postponed by Reg. (EU) 2026/1744 — a date most vendors still get wrong). Evidence trails take a year to mature; start before the duty bites.
Extracts for the official register of your AI providers (Art. 28) built from the provider catalog, concentration snapshots (Art. 29) built from real spend by tag, and routing records that show your exit plan is tested rather than theoretical (Art. 30).
Access-control artifacts under Art. 21(2) from the virtual-key hierarchy and SCIM de-provisioning; maps of your providers and their sub-processors generated from actual traffic instead of questionnaires; reports of every request routed to EU endpoints.
A signed record of the destination provider and region for every single request, drawn from the request log. A record, not a promise — and no other gateway offered this at our mid-2026 market verification.
OpenAISF puts it simply: "a policy that never fired under live traffic was not operating." Static certificates age silently; proof that expires cannot lie about the present. Your auditor gets a document that is either current — or visibly out of date.
Included with Assure: 3 audit-support days per year. We sit with your auditor and walk through every export together.
TruCert provides controls tooling and evidence; regulatory compliance judgments remain with your organisation and its auditors. No certification is claimed or implied.
The gateway does the governing; Assure turns what it records into proof. One product, one contract, one vendor.
Talk to us See the gateway