Enterprise
One control layer across the AI estate
What OpsAI gives a CIO, a CISO, a compliance team, the people building AI, the developers integrating it, and the operations teams living with it.
Stated before you ask
OpsAI holds no certifications.
No audit under way and no target dates, because a date for an audit nobody has scheduled is the most common false statement on a page like this.
What we can show you is how the mechanisms work. The full position.
The procurement question, answered first
We hold no certifications, and we will not give you a date for one.
Every enterprise software trust page leads with badges. This one leads with their absence, because a reviewer who finds that stated plainly reads everything else differently — and one who finds it buried on page four stops reading altogether.
A target date for an audit that has not been scheduled is the single most common fabrication in enterprise software procurement, and security reviewers check it first because they have been given one before. So there is no roadmap here and no badge with a footnote.
What is available instead is the mechanism. “Not certified against ISO 42001” is not useful on its own. “Not certified, and here is exactly how the thing that standard asks about works, documented and inspectable” is a different conversation and a more useful one.
Train any model on your data, your policies or your decision records.
Use your estate as a reference or case study without a written agreement.
Offer a certification we do not hold, or a date for one we have not scheduled.
Claim to prevent prompt injection. Nothing does reliably; we make it ineffective at the boundary.
Certifications held
0
stated, not hedged
Frameworks addressed
5
with the mechanism documented
Target dates given
0
none are scheduled
Models trained on your data
0
ever
Six first questions
An adoption decision is six different conversations.
A CIO, a CISO, a compliance team, the people building the AI, the developers wiring it in, and the team carrying the pager each open with a different question. Each one has a different page.
- A CIOHow much AI is running, who owns it, and what is it changing?One register across every framework and vendor, with a named accountable human per system and a record of every action attempted.The inventory
- A CISOWhat can it reach, and can I prove who did what?Attested workload identity, credentials held centrally and never distributed, short-lived scoped grants, and an investigation trail that includes the refusals.Security at OpsAI
- A compliance teamCan I produce evidence instead of assurances?Records sealed at decision time and mapped to control themes, including the themes OpsAI cannot evidence at all.Compliance at OpsAI
- The people building AIWhat does this stop me doing?Nothing you were going to do. No framework to adopt, no rewrite, no adapter — governance attaches where your system calls out, not inside it.How agents are governed
- The developers integrating itHow long is this going to take?One call before an action, or route the action through a connection. The second is stronger because it does not depend on your code remembering to ask.For developers
- The operations teamsWhat happens at three in the morning?A hold expires rather than queueing, an expiry is an event you can route, and a broken bound drops an agent a rung without waiting for anyone.Incidents
What one layer means in practice
Every AI system, every rule and every action in one place.
The value of a control layer is not any individual control. It is that the answer to 'what is running' comes from one register rather than from six teams, and that a policy written once applies to a system nobody had built when it was written.
AI systems
11
across every framework
Policies
8
owned by 6 teams
Systems connected
11
of 12 in the register
Platform teams required
0
policy ownership is distributed
IllustrativeThe OpsAI sample estate, a fictional company. Every figure on this site is computed from it rather than written into the page.
- A policy outlives the system it was written for
- A bound attaches to an action, not to an agent. So a refund ceiling written this quarter governs whatever tries to issue a refund next year, including something nobody has built yet.
- Ownership is distributed by design
- 6 teams own policies in the sample estate. A platform team cannot know what a refund ceiling should be, and making it decide is how a control becomes a bottleneck.
- The framework column is descriptive
- Recorded because the spread is worth knowing, and read by nothing. That is what lets one layer cover systems chosen independently by teams who never coordinated.
- What it does not consolidate
- Your orchestration, your retrieval, your inference or your data. Three of the systems it connects to are orchestrators and they keep that job.
The rest of this section
Four pages, written for a review rather than for a browse.
Each answers a question a procurement or security process actually asks, and each says where the answer stops.
And two pages elsewhere that a reviewer usually wants
For an engineer
Security documentation
Authentication, workload attestation, how secrets are held, tenant isolation and the data boundary — as mechanisms rather than assurances.
For an assessor
The control mapping
Framework control themes mapped to the records that answer them, including the themes OpsAI evidences partially or not at all.
Where to start
Send the trust center to whoever will object first.
It states the position on each framework as status, lists what OpsAI will not do, and names the mechanisms behind each claim. If it fails your review it will fail it on the first page rather than in week six.