Skip to content

Platform Features and Overview

Last updated: July 22, 2026

What CompliAffirmAI does

CompliAffirmAI is an AI-governance evidence workspace for small and mid-market regulated organizations and their advisors. It helps a team:

  1. inventory AI systems;
  2. document owners, intended use, hosting, data classes, and boundary decisions;
  3. answer plain-language governance questions mapped to framework controls;
  4. distinguish an attestation from evidence-backed support;
  5. attach approved evidence to the answer it supports;
  6. record internal reviews and testing activity;
  7. generate deterministic, reviewable artifact packages; and
  8. preserve integrity references in an organization-scoped ledger.

The platform is a documentation system. It does not replace security engineering, legal analysis, an assessor, a C3PAO, or a regulator.

Core workflow

Register a system -> Answer mapped questions -> Attach evidence -> Review readiness -> Record reviews/tests -> Generate artifacts -> Verify ledger references

Each step reuses the same system record and evidence references so teams do not have to recreate the same facts for every questionnaire or review package.

Workspace features

Dashboard and guided training

  • Shows registered systems, current documentation and evidence posture, recent artifacts, and recommended next steps.
  • Provides guided training for system registration, mapped questions, evidence upload, and artifact generation.

AI system registry

Each record captures:

  • system name and vendor;
  • optional model family;
  • accountable business and technical owner;
  • hosting environment;
  • inside-boundary, outside-boundary, prohibited-from-CUI, or not-applicable designation;
  • permitted data classes;
  • applicable framework packs; and
  • a minimum 200-character purpose statement describing users, inputs, outputs, decision role, prohibited data, and required human review.

The registry rejects regulated-data-like content in descriptive fields. Record the governing facts and references, not the regulated payload itself.

Mapped questions and findings

  • Questions are presented in plain language and mapped to versioned framework controls.
  • Saved answers are organization- and system-scoped.
  • Documentation coverage and evidence coverage are displayed separately.
  • Deterministic rules surface potential gaps such as an unsupported boundary decision or missing BAA evidence.
  • Findings are prompts for review and remediation, not legal or certification determinations.

Private evidence workflow

  • Evidence is attached to a specific saved answer.
  • Supported files are PDF, CSV, XLS, XLSX, DOC, DOCX, PNG, JPG, and JPEG, up to 25 MB.
  • The client calculates SHA-256; the server verifies file size and hash.
  • Files are written to private object storage, scanned for malware and active content, and sealed under a content-addressed key only after checks pass.
  • Failed, mismatched, or quarantined files are unavailable for use.
  • HTTPS references can be used where the workflow accepts a reference instead of a file.

Only upload approved, non-regulated evidence. Private storage is not permission to upload CUI, PHI, secrets, customer production data, or prohibited content.

NIST AI RMF and TRAIGA readiness

For systems with the TRAIGA pack, CompliAffirmAI can:

  • map answers across NIST AI RMF functions GOVERN, MAP, MEASURE, and MANAGE;
  • include sourced mappings to NIST AI RMF 1.0, the NIST Generative AI Profile, and relevant TRAIGA review routes;
  • show evidenced, partially evidenced, attested, gap, and not-assessed states;
  • append internal-review and internal-testing records; and
  • generate a TRAIGA Cure Binder with a registry snapshot, readiness assessment, evidence index, review history, testing log, source references, legal notice, and hash manifest.

The workflow always returns a non-legal posture. A mapping or complete-looking package does not establish substantial compliance, safe-harbor eligibility, an affirmative defense, or a legal outcome. Counsel review remains required.

Artifact Factory

Available artifact templates include:

  • AI Acceptable Use Policy;
  • Purpose and Intent Record;
  • AI System Registry Export;
  • NIST AI RMF Alignment Report;
  • Internal Testing Log;
  • TRAIGA Cure Binder;
  • CMMC AI-SSP Addendum;
  • POA&M Line Items;
  • Prime Questionnaire Pack;
  • HIPAA Vendor and BAA Register;
  • Vendor AI Questionnaire;
  • Executive Posture One-Pager;
  • Cyber-Insurance AI Questionnaire;
  • Employee AI Acknowledgment and Training Log; and
  • AI Incident Log.

Availability depends on the active plan, selected framework pack, and artifact type. Standard artifacts are available as deterministic JSON and PDF packages. TRAIGA Cure Binders also support ZIP export with member hashes.

Tamper-evident ledger

  • Material workspace actions can append organization-scoped ledger events.
  • Events use canonical payload hashes and hash-chain links.
  • Ledger verification reports a clean chain or the first detected divergence.
  • When configured, RFC 3161 timestamps can anchor a ledger head externally.

Ledger verification shows integrity continuity. It does not prove that the underlying statement was true, complete, approved, or legally sufficient.

Account, support, and data rights

  • TOTP MFA enrollment and verification.
  • Billing plan and entitlement status.
  • Structured support requests with status history.
  • Workspace export for owners and administrators.
  • Correction and deletion request workflows subject to identity verification and ledger-retention review.

Roles and access

The workspace recognizes Owner, Admin, Contributor, and Viewer role labels. Server-side tenant checks isolate every organization. Privileged actions have additional controls:

  • The initial self-service Checkout requires the confirmed workspace owner.
  • Owner and administrator sessions must complete AAL2 MFA before accessing tenant data and privileged workflows.
  • Billing Portal access and workspace export require Owner or Admin access.
  • Cross-organization requests are denied before records or private objects are returned.

Your organization should assign the minimum role needed and promptly remove access that is no longer required.

Plans and framework packs

Current plan behavior is defined by the in-product Billing page and server-side catalog:

PlanTypical useSystem limitFramework accessNotes
SoloOne organization beginning a focused program1Core plus one selected framework packSelf-service
ProfessionalA team managing several systems and frameworks3Core, CMMC, TRAIGA, and HIPAASelf-service
PartnerAdvisors managing client organizations3 per client organizationCore, CMMC, TRAIGA, and HIPAASales-assisted; partner console and white-label exports

Prices, promotions, limits, and availability can change. Treat the hosted Billing page and signed subscription entitlement as authoritative.

Security and data-handling model

  • Metadata-only form design with regulated-data warnings.
  • Supabase authentication with organization claims and TOTP MFA.
  • Forced PostgreSQL row-level security for tenant tables.
  • Private object storage, integrity verification, malware scanning, and tenant-scoped keys.
  • Strict transport and browser security headers.
  • Rate limiting on public and abuse-sensitive routes.
  • Server-only provider credentials.
  • No generative-model API receives customer text, evidence, prompts, or artifacts in the current runtime.

See the public Security page for the customer-facing security boundary.

Current scope limitations

  • CompliAffirmAI does not calculate an SPRS score.
  • It does not scan customer infrastructure or enforce network segmentation.
  • It does not determine whether a cloud service is authorized for a particular regulated workload.
  • Microsoft tenant connector contracts exist, but live use depends on customer-controlled Entra tenant registration and admin consent.
  • Generated or templated material requires human review before external use.
  • A complete workflow does not equal certification, compliance, or legal protection.

Back to Client Documentation

Governance documentation and review support. Not legal advice or certification.