Updated: EU AI Act enforcement begins Aug 2, 2026. The deadlines moved. The obligations didn't.
Governing 31 models across 3 frameworks — live in the console below

Govern every model.
Prove it cryptographically.

AIOPS scores your AI systems against ISO/IEC 42001, NIST AI RMF and the EU AI Act with a deterministic rules engine. Then it seals the result in Ed25519-signed evidence your auditors, regulators and insurers can verify independently.

Self-hosted or SaaS · Data never leaves your perimeter · Verify a signed artifact yourself

Trusted by teams governing production AI

ACME Corp Northland Financial Sentinel Health Veritas Labs Pinnacle Group
0
ISO/IEC 42001 controls
0
NIST AI RMF checks
<1s
Drift & bias alerts
0
Sovereign deployable
SOC 2 Type II
ISO/IEC 42001
GDPR Compliant
HIPAA Ready
Ed25519 Signed
Why OCEKS

Governance you can defend, not just report.

Most platforms produce dashboards. AIOPS produces admissible proof, built on three principles no checklist tool can retrofit.

Deterministic by law

The rules engine is the legal source of truth: 160+ codified controls score every assessment identically, every time. LLMs advise on gaps. They don't grade compliance.

packages/rules · ISO 42001 + NIST AI RMF

Fail-closed by design

PII scanner down? Uploads stop. Token revocation unreachable? Requests reject. Injection detected? Blocked. Security failures halt the pipeline. They don't silently pass.

Presidio · JTI revocation · injection detection

Sovereign by default

Deploy on your Kubernetes, in your cloud, or fully air-gapped. Model data, prompts and evidence never leave your perimeter. That's a hard requirement for regulated industries.

Helm · Terraform · air-gapped bundle
The Platform

One operating system for the entire governance lifecycle.

From the moment a model enters your inventory to the day an underwriter prices its liability, every step is automated, enforced and evidenced.

Model inventory & lifecycle

Register every model with a governed state machine — draft, assessed, approved, deployed, retired — with a full audit trail on every transition.

Deterministic assessments

88 ISO/IEC 42001 controls and 72 NIST AI RMF checks scored by code, with SHAP explainability and EU AI Act risk classification built in.

Signed evidence packages

Every assessment exports as an Ed25519-signed ZIP with an append-only SHA-256 ledger. Verifiable by any third party, without trusting OCEKS.

Real-time monitoring

Streaming agents watch PSI drift, demographic parity and equalized odds continuously. Alerts reach your dashboard in seconds, not overnight batches.

Policy-as-code enforcement

Build policies visually, compile them to OPA Rego, publish via git pull request. Then let workflow gates block non-compliant deployments automatically.

Shadow AI discovery

Find the models nobody registered. Discovery scanners surface unsanctioned AI usage across your platforms before your regulator does. (And they will.)

The Evidence Chain

From assessment to underwriting in four verifiable steps.

Assess

Register the model, attach documentation, and let the governance workflow run controls, fairness metrics and explainability automatically.

Score

The deterministic rules engine computes framework scores as exact decimals. Reproducible, versioned and diff-able between runs.

Sign

Results are sealed into an Ed25519-signed evidence ZIP and appended to a tamper-evident SHA-256 compliance ledger.

Underwrite

Insurers consume the signed package directly through native connectors. They turn your governance posture into better coverage terms.

Why not a checklist tool

Built where legacy governance platforms stop.

Incumbent suites report on AI risk. AIOPS enforces against it, with architecture the reporting tools can't bolt on.

Capability OCEKS AIOPS Legacy governance suites
Compliance scoring Deterministic rules engine — legal source of truth LLM-as-judge, non-reproducible
Evidence output Ed25519-signed ZIP + append-only hash ledger Unsigned PDF exports
Policy enforcement OPA gates block deployment in-workflow Dashboards without enforcement
Monitoring cadence Streaming — drift & bias alerts in seconds Daily batch reports
Insurance integration Native underwriter connectors & liability scoring None
Deployment model SaaS, self-hosted K8s, or fully air-gapped SaaS-only
Service security Zero-trust mTLS workload identity Perimeter + API keys
See detailed competitor comparisons
Framework coverage

Speak your regulator's language.

ISO/IEC 42001

88 controls codified as executable rules with clause-level traceability.

NIST AI RMF

72 checks across Govern, Map, Measure and Manage functions.

EU AI Act

Automated risk-tier classification with obligation mapping per system.

SOC 2 & GDPR

Control evidence and PII protection aligned to audit expectations.

FAQ

Common questions.

What is AIOPS?
AIOPS is the AI Governance Operating System by OCEKS: a platform that scores your AI systems against ISO/IEC 42001, NIST AI RMF and the EU AI Act with a deterministic rules engine, enforces policy gates in your deployment workflow, and seals every result in cryptographically signed evidence.
How is AIOPS different from GRC checklist tools?
Checklist tools record what people say about their AI. AIOPS evaluates the systems themselves: 160+ codified controls score every assessment identically every time, policy-as-code gates block non-compliant deployments, and results are sealed in Ed25519-signed packages an auditor can verify without trusting OCEKS.
Which frameworks does AIOPS cover?
ISO/IEC 42001 (88 codified controls), NIST AI RMF (72 checks across Govern, Map, Measure and Manage), EU AI Act risk-tier classification with obligation mapping, and SOC 2 / GDPR controls for data protection and PII.
Can AIOPS run air-gapped?
Yes. AIOPS deploys on your Kubernetes via Helm or Terraform, in your cloud, or as a fully air-gapped bundle. Model data, prompts and evidence never leave your perimeter. That's a hard requirement for regulated industries.
What makes the evidence "cryptographically verifiable"?
Every assessment export is an Ed25519-signed ZIP appended to a tamper-evident SHA-256 compliance ledger. Any third party (an auditor, regulator or insurer) can verify signatures and ledger integrity independently, without access to AIOPS itself.
How does the insurance integration work?
Underwriters consume your signed evidence packages directly through native connectors, turning your governance posture into better coverage terms. Live liability pricing from real controls, not questionnaires.

See the full loop in 15 minutes.

Register a model, run an assessment, watch a policy gate fire, and download signed evidence. Live, on real infrastructure.