Scrydon
Compliance

Compliance

How Scrydon maps to ISO 27001, ISO 42001, the EU AI Act, GDPR, SOC 2, NIST, SecNumCloud, the EU CRA, and AIUC-1 — plus the AI-governance controls that satisfy them.

Scrydon is built for organisations that have to prove their AI is governed, not just claim it. This section maps Scrydon's controls to the frameworks customers most often need to comply with, and points at the evidence the platform produces automatically.

Frameworks

Shared responsibility

Scrydon is one component of your compliance posture, not the whole thing. The platform ships the technical controls; you still own the organisational controls around it.

Shared responsibility — Scrydon delivers the technical controls (audit, authorisation, encryption, network boundary, DLP, document clearance, AI lifecycle artefacts, right to erasure, supply chain); the customer owns the organisational controls (onboarding, role definitions, change management, risk appetite, internal audit). Both feed the compliance frameworks.

Each framework page below is honest about which controls Scrydon satisfies and which it merely supports — with links to the underlying Security controls and the evidence the platform produces automatically.

Vanta integration

Scrydon integrates with Vanta — every framework page lists which controls Vanta picks up automatically, and which require manual evidence collection.

Where to start

If you're preparing for an audit:

  1. Pick your framework above.
  2. Each page lists the controls and the Scrydon feature that satisfies each.
  3. Use AI governance for the AI-specific lifecycle artefacts auditors will ask for.
  4. Cross-reference Security for the underlying controls.
On this page

On this page