Skip to Content
ComplianceOverview

Compliance

Inkog maps every finding to industry compliance frameworks, enabling automated compliance reporting for audits and security reviews.

Supported Frameworks

FrameworkDescriptionCoverage
OWASP LLM Top 10AI-specific vulnerability taxonomyFull
EU AI ActEuropean AI regulationArticles 13-15
NIST AI RMFAI risk management frameworkMAP, MEASURE
CWECommon Weakness Enumeration20+ mappings

How It Works

Every Inkog finding includes compliance metadata:

{ "id": "finding_001", "pattern": "infinite_loop_semantic", "severity": "critical", "compliance": { "cwe": ["CWE-835", "CWE-400"], "owasp_llm": ["LLM10"], "eu_ai_act": ["Article 15"], "nist_ai_rmf": ["MAP 1.3", "MEASURE 2.4"] } }

Compliance Reports

Generate compliance-focused reports:

# JSON with compliance data inkog -output json . > compliance-report.json # Extract OWASP violations cat compliance-report.json | jq '.compliance_report.owasp_llm_top_10'

Framework Coverage

OWASP LLM Top 10

CategoryInkog Rules
LLM01: Prompt Injectionprompt_injection, sql_injection_via_llm
LLM02: Insecure Outputoutput_validation_failures, tainted_eval
LLM04: Model DoSinfinite_loop, context_exhaustion, token_bombing
LLM06: Sensitive Infologging_sensitive_data, hardcoded_credentials
LLM08: Excessive Agencyinfinite_loop, missing_human_oversight
LLM10: Unbounded Consumptioncontext_exhaustion, missing_rate_limits

Full OWASP LLM mapping →

EU AI Act

ArticleFocusInkog Rules
Article 13Data Governancehardcoded_credentials, prompt_injection
Article 14Human Oversightinfinite_loop, tainted_eval, sql_injection_via_llm
Article 15Accuracy & Cybersecurityhardcoded_credentials, output_validation_failures

Full EU AI Act mapping →

NIST AI RMF

CategoryFocusInkog Rules
MAP 1.1Input/Output Validationprompt_injection, output_validation_failures
MAP 1.2Data Governancelogging_sensitive_data, unsafe_env_access
MAP 1.3System Reliabilityinfinite_loop, context_exhaustion
MEASURE 2.2Security Riskhardcoded_credentials
MEASURE 2.4AI System Riskstainted_eval, sql_injection_via_llm

Full NIST AI RMF mapping →

Audit Trail

For compliance audits, save scan reports with timestamps:

# Timestamped compliance report inkog -output json . > "reports/inkog-$(date +%Y%m%d-%H%M%S).json"

Store reports in version control or a compliance management system for audit trails.

CI/CD Integration

Fail builds on compliance violations:

# GitHub Actions - name: Compliance Check run: | inkog -output json . > report.json # Check for EU AI Act violations VIOLATIONS=$(jq '.compliance_report.eu_ai_act | add' report.json) if [ "$VIOLATIONS" -gt 0 ]; then echo "EU AI Act compliance violations detected" exit 1 fi

Custom Compliance Policies

Enterprise customers can define custom compliance policies mapping findings to internal security standards.

Contact support@inkog.io for custom compliance integration.

Last updated on