Govern every model.
Prove it cryptographically.
AIOPS scores your AI systems against ISO/IEC 42001, NIST AI RMF and the EU AI Act with a deterministic rules engine. Then it seals the result in Ed25519-signed evidence your auditors, regulators and insurers can verify independently.
Self-hosted or SaaS · Data never leaves your perimeter · Verify a signed artifact yourself
Governance you can defend, not just report.
Most platforms produce dashboards. AIOPS produces admissible proof, built on three principles no checklist tool can retrofit.
Deterministic by law
The rules engine is the legal source of truth: 160+ codified controls score every assessment identically, every time. LLMs advise on gaps. They don't grade compliance.
packages/rules · ISO 42001 + NIST AI RMFFail-closed by design
PII scanner down? Uploads stop. Token revocation unreachable? Requests reject. Injection detected? Blocked. Security failures halt the pipeline. They don't silently pass.
Presidio · JTI revocation · injection detectionSovereign by default
Deploy on your Kubernetes, in your cloud, or fully air-gapped. Model data, prompts and evidence never leave your perimeter. That's a hard requirement for regulated industries.
Helm · Terraform · air-gapped bundleOne operating system for the entire governance lifecycle.
From the moment a model enters your inventory to the day an underwriter prices its liability, every step is automated, enforced and evidenced.
Model inventory & lifecycle
Register every model with a governed state machine — draft, assessed, approved, deployed, retired — with a full audit trail on every transition.
Deterministic assessments
88 ISO/IEC 42001 controls and 72 NIST AI RMF checks scored by code, with SHAP explainability and EU AI Act risk classification built in.
Signed evidence packages
Every assessment exports as an Ed25519-signed ZIP with an append-only SHA-256 ledger. Verifiable by any third party, without trusting OCEKS.
Real-time monitoring
Streaming agents watch PSI drift, demographic parity and equalized odds continuously. Alerts reach your dashboard in seconds, not overnight batches.
Policy-as-code enforcement
Build policies visually, compile them to OPA Rego, publish via git pull request. Then let workflow gates block non-compliant deployments automatically.
Shadow AI discovery
Find the models nobody registered. Discovery scanners surface unsanctioned AI usage across your platforms before your regulator does. (And they will.)
From assessment to underwriting in four verifiable steps.
Assess
Register the model, attach documentation, and let the governance workflow run controls, fairness metrics and explainability automatically.
Score
The deterministic rules engine computes framework scores as exact decimals. Reproducible, versioned and diff-able between runs.
Sign
Results are sealed into an Ed25519-signed evidence ZIP and appended to a tamper-evident SHA-256 compliance ledger.
Underwrite
Insurers consume the signed package directly through native connectors. They turn your governance posture into better coverage terms.
Built where legacy governance platforms stop.
Incumbent suites report on AI risk. AIOPS enforces against it, with architecture the reporting tools can't bolt on.
| Capability | OCEKS AIOPS | Legacy governance suites |
|---|---|---|
| Compliance scoring | Deterministic rules engine — legal source of truth | LLM-as-judge, non-reproducible |
| Evidence output | Ed25519-signed ZIP + append-only hash ledger | Unsigned PDF exports |
| Policy enforcement | OPA gates block deployment in-workflow | Dashboards without enforcement |
| Monitoring cadence | Streaming — drift & bias alerts in seconds | Daily batch reports |
| Insurance integration | Native underwriter connectors & liability scoring | None |
| Deployment model | SaaS, self-hosted K8s, or fully air-gapped | SaaS-only |
| Service security | Zero-trust mTLS workload identity | Perimeter + API keys |
Speak your regulator's language.
ISO/IEC 42001
88 controls codified as executable rules with clause-level traceability.
NIST AI RMF
72 checks across Govern, Map, Measure and Manage functions.
EU AI Act
Automated risk-tier classification with obligation mapping per system.
SOC 2 & GDPR
Control evidence and PII protection aligned to audit expectations.
Common questions.
What is AIOPS?
How is AIOPS different from GRC checklist tools?
Which frameworks does AIOPS cover?
Can AIOPS run air-gapped?
What makes the evidence "cryptographically verifiable"?
How does the insurance integration work?
See the full loop in 15 minutes.
Register a model, run an assessment, watch a policy gate fire, and download signed evidence. Live, on real infrastructure.