Self-Serve

Enterprise Security & Compliance Templates · Out-of-the-Box, Audit-Baseline Ready

Skip lengthy, expensive traditional consulting. Get battle-tested AI risk management and compliance policy documents in one click — integrate them into your operations in minutes. PDF + Word + Notion formats included.

Pre-built audit-baseline documentation — at a fraction of consulting cost.

Every AI-deploying company needs governance documentation but can't justify enterprise consulting fees. We've packaged the artifacts — frameworks, policies, checklists, runbooks — that would normally take $30,000+ of consulting to produce, into self-serve template kits aligned with 2026 audit baselines. Adapt them to your context, layer in your evidence, and approach regulators with confidence. Includes 12 months of major-version revisions.

Eleven core kits mapped to the standards regulators actually audit.

Eleven standalone kits covering EU, US, Japan, China, and global standards — every one shipping with PDF + editable Word + Notion workspace, plus a one-page Implementation Guide. 12 months of major-version revisions and core framework update pushes included, so your documents stay aligned as standards evolve.

EU · 12 documents

EU AI Act Compliance Starter Pack

High-risk AI (High-Risk AI) conformity assessment, technical documentation, post-market monitoring (PMS), fundamental rights impact assessment (FRIA) matrix.

US · 20 documents

NIST AI RMF Implementation Bundle

Govern · Map · Measure · Manage playbook with role assignments, evidence templates, and quarterly review cadence.

Japan · 12 documents

METI AI Business Operator Guidelines Pack

Aligned with Japan METI & MIC joint AI Guidelines. Includes AI provider/user self-assessment forms, governance committee charter, ISO 42001 cross-mapping matrix. The mandatory pass for Japan-bound deployments and Japanese gov/SOE RFPs.

China · 16 documents

CAC GenAI Filing & Compliance Starter Pack

Aligned with China's Interim GenAI Service Management Measures and TC260 GenAI Service Basic Security Requirements. Includes algorithm filing self-assessment report templates, dual-review training corpus checklists, content safety interception policies, and user anti-addiction & complaint-response mechanisms. The end-to-end compliance loop for launching and commercializing AI services in China. Documentation drafts only; filing-agency service not included.

Global · 18 documents

ISO 42001 Audit Prep Kit

Annex A control mapping, Statement of Applicability (SoA) template, evidence collection matrix, internal audit and gap analysis playbook.

Engineering · 10 playbooks

OWASP LLM Top 10 Mitigation Library

Defensive playbook for each of the 10 LLM risks — prompt injection, insecure output, training data poisoning, and more.

Supply Chain · 15 playbooks

SSDF Secure Software Development Pack

NIST SP 800-218 implementation SOPs. Includes AI code-review checklists, secure build environment policy, open-source model vetting standard. Core engineering foundation for US gov/enterprise contracts and stringent supply-chain audits.

Inventory · 1 master template

AI Bill of Materials (AI-BOM)

Auto-fillable inventory of your AI components — models, training data, dependencies, third-party APIs. Required by ISO 42001 and EU AI Act.

SOC/IR · 8 runbooks

AI Incident Response Playbook

IR playbooks for prompt injection, jailbreak, and data leakage events — aligned with the NIST SP 800-61 Rev. 2 incident response lifecycle (Containment, Eradication, Recovery). Includes regulator notification templates (e.g., GDPR 72-hour compliance) and post-mortem framework. Drop-in compatible with Jira / ServiceNow ticketing.

Procurement · 60-question kit

AI Vendor Security Questionnaire

60 questions for evaluating SaaS AI vendors. Data residency, model provenance, incident history, sub-processors — answers drive your buy/no-buy decision.

Healthcare · 15 documents

Healthcare AI HIPAA Compliance Pack

HIPAA-mapped policies for medical AI deployments. PHI handling, BAA templates, FDA SaMD (Software as a Medical Device) AI/ML regulatory baseline, clinical decision support oversight.

Persona-based bundles · or take the full moat.

Four curated combinations addressing core enterprise security pain points — by team (compliance, engineering, procurement) or by all-in flagship. Up to 39% off list prices.

Top-Tier Choice · 11-pack

Complete AI Governance Moat

  • Compliance 5-pack: EU AI Act + NIST + ISO 42001 + METI + CAC GenAI
  • Engineering 4-pack: OWASP + AI-BOM + IR + SSDF
  • Procurement: Vendor Security Questionnaire
  • Healthcare: HIPAA Compliance Pack
$3,269$1,999
Most Popular · EU·US·JP

Global Compliance Bundle

  • EU AI Act Starter Pack
  • NIST AI RMF Bundle
  • ISO 42001 Audit Prep Kit
  • METI AI Guidelines Pack (Japan)
  • CAC GenAI Filing Pack (China)
$1,895$1,249
For Engineering · Code-to-Deploy

AI Engineering Hardening Bundle

  • OWASP LLM Top 10 Mitigation Library
  • AI Bill of Materials (AI-BOM)
  • AI Incident Response Playbook
  • SSDF Secure Software Development Pack
$696$499
For Procurement

Vendor & Procurement Bundle

  • AI Vendor Security Questionnaire
  • AI Bill of Materials (AI-BOM)
$178$129

Mapped to authoritative global frameworks · 100% audit-defensible.

Turn abstract regulation into out-of-the-box evidence. Every template deeply maps to recognized international baselines — so the security policies you deploy today withstand the most rigorous compliance review tomorrow.

EUEU AI ActRegulation (EU) 2024/1689 USNIST AI RMFAI RMF 1.0 · AI 600-1 GlobalISO/IEC 42001ISO/IEC 42001:2023 GlobalOWASP GenAI / LLM Top 10LLM Top 10 v2.0 (2025) USNIST SSDF (SP 800-218)SP 800-218 v1.1 · 218A JPMETI AI Guidelinesv1.01 (2024) · METI × MIC CNCAC GenAI FilingCAC 2023 · TC260-003 USHIPAA & FDA AI/ML45 CFR §164 · FDA GMLP

Templates provide a battle-tested security governance baseline aligned with the listed standards. Each enterprise must localize the documents to its specific business context, layer in implementation evidence, and obtain its own legal review. The templates do not constitute legal counsel, regulatory certification, or a guarantee of compliance. For procedures that require on-site review, sample inspection, or oral examination by regulators (e.g. China CAC GenAI filing, EU AI Act notified-body certification), the templates provide written documentation drafts only — they do not include filing-agency, registration-agency, or certification-agency services. Final outcomes are determined solely by the regulator's review.

By Application Only · Limited Capacity

Facing an unusually complex regulatory landscape?

Financial services (DORA / GLBA), critical infrastructure, or proprietary internal AI architectures? Beyond the standard compliance baselines, we offer high-level strategic advisory and architecture review to a select few enterprise clients. Due to extremely limited capacity, this service is by application only.