Frameworks
Source: app.qpoint.io/v2/compliance/framework-listing — v2 Figma (Agent Transition)
Compliance frameworks instrumented against live agent traffic. Active frameworks are evaluated continuously; available frameworks show what activation would cover.
Active frameworks
Kind | Total Violations | Compliance | ||
|---|---|---|---|---|
OWASP LLM Top 10 Excessive agency, sensitive-info disclosure, and unbounded consumption — risk categories firing against live agent traffic. Details + Configuration | Risk Taxonomy | 12 Violations | 78%14 / 18Controls | |
HIPAA Safeguards for protected health information moving through agent and model traffic. Details + Configuration | Regulation | 4 Violations | 82%9 / 11Controls | |
SOC 2 Trust-services criteria — CC7.2 monitoring evidence produced from live agent traffic. Details + Configuration | Attestation | 7 Violations | 75%12 / 16Controls | |
Available frameworks
Kind | Total Violations | Compliance | ||
|---|---|---|---|---|
MITRE ATLAS Adversarial-ML tactics — credential access & exfiltration techniques observed in the proxy. Details + Configuration | Risk Taxonomy | 9 Violations | 71%10 / 14Controls | |
NIST AI RMF AI risk-management evidence across the Govern, Map, Measure, and Manage functions. Details + Configuration | Governance | 2 Violations | 94%15 / 16Controls | |
OWASP Agentic Agentic-AI threats — insecure tool use and missing human oversight. Details + Configuration | Risk Taxonomy | 6 Violations | 73%11 / 15Controls | |
NIST SP 800-52 Transport-layer posture — weak-TLS and deprecated-protocol detection on egress. Details + Configuration | Regulation/Standard | 1 Violations | 88%7 / 8Controls | |
ISO/IEC 42001 AI management-system controls — inventory, oversight, and lifecycle evidence. Details + Configuration | Governance | 5 Violations | 64%9 / 14Controls | |
EU AI Act Art. 12 record-keeping — append-only logging of agent actions and data movement. Details + Configuration | Regulation | 3 Violations | 80%8 / 10Controls | |
GDPR Personal-data processing — cross-border transfer and data-minimisation obligations. Details + Configuration | Regulation | 8 Violations | 72%13 / 18Controls | |