AI governance control maps: what each platform documents from policy to report

In brief

Of the six platforms, four document all four steps on their public pages: Pillar Security, Alice, SPLX and Lasso. Credo AI and Holistic AI leave the control step not described. Each map below links to its sources.

By The Charter Desk, Agentic Governance Compare · Published 2026-10-01 · Vendor pages read 1 October 2026 · Editorial assessment

§ 1 How do you read a control map?

Each map has four boxes. Policy is what the rule says. Control is what enforces it on live traffic or before release. Evidence is what proves the control worked. Report is what an auditor receives. A dashed box means the step is not described on the vendor pages we read on 1 October 2026; it does not mean the feature cannot exist.

§ 2 Which steps does each platform document?

Steps documented on vendor pages read 1 October 2026, platforms in ranking order
PlatformPolicyControlEvidenceReport
Pillar SecurityDocumentedDocumentedDocumentedDocumented
AliceDocumentedDocumentedDocumentedDocumented
Credo AIDocumentedNot describedDocumentedDocumented
SPLXDocumentedDocumentedDocumentedDocumented
LassoDocumentedDocumentedDocumentedDocumented
Holistic AIDocumentedNot describedDocumentedDocumented

§ 3 The six control maps

Control map: Pillar Security

  1. 1 Policy

    Policy: what the rule says

    Policy enforcement covers approved model lists and data sovereignty.

    Source: Pillar Security governance and compliance page · read 2026-10-01

  2. 2 Control

    Control: what enforces it

    Runtime guardrails block prompt injection, jailbreaking and tool manipulation and mask PII, PHI and secrets.

    Source: Pillar Security runtime guardrails page · read 2026-10-01

  3. 3 Evidence

    Evidence: what proves it worked

    Every prompt, response and tool call is logged; the RedGraph engine runs multi-turn agentic red teaming with transcripts.

    Source: Pillar Security red teaming page · read 2026-10-01

  4. 4 Report

    Report: what an auditor receives

    Pillar says it generates audit-ready reports for GDPR, the EU AI Act, ISO 42001 and SOC.

    Source: Pillar Security governance and compliance page · read 2026-10-01

Pillar Security profile · Pillar Security competitors

Control map: Alice

  1. 1 Policy

    Policy: what the rule says

    Policies are configured to the customer's application: WonderFence is 'Built for Your Policies' and the platform lists adaptive and custom policies.

    Source: Alice WonderFence product page · read 2026-10-01

  2. 2 Control

    Control: what enforces it

    WonderFence sits between external-facing AI and its users and intercepts harmful, non-compliant and off-policy responses in real time.

    Source: Alice WonderFence product page · read 2026-10-01

  3. 3 Evidence

    Evidence: what proves it worked

    WonderBuild runs thousands of adversarial tests based on custom policies before launch; WonderCheck retests after launch with drift and regression detection; every WonderFence decision is logged.

    Source: Alice WonderCheck product page · read 2026-10-01

  4. 4 Report

    Report: what an auditor receives

    WonderFence maps guardrails to the EU AI Act, ISO 42001, NIST, MITRE ATLAS and OWASP; WonderBuild maps test documentation to regulatory requirements and tracks launch readiness.

    Source: Alice WonderBuild product page · read 2026-10-01

Alice profile · Alice competitors

Control map: Credo AI

  1. 1 Policy

    Policy: what the rule says

    A Knowledge Graph of regulatory intelligence informs policies; Credo AI describes enforcing policy across agents, models and apps.

    Source: Credo AI home page · read 2026-10-01

  2. 2 Control

    Control: what enforces it

    Not described

    Runtime blocking of prompts or responses is not described on the pages reviewed.

    Source: Credo AI product page · read 2026-10-01

  3. 3 Evidence

    Evidence: what proves it worked

    Assess and monitor steps are described across agents, models and apps.

    Source: Credo AI product page · read 2026-10-01

  4. 4 Report

    Report: what an auditor receives

    Reporting against the EU AI Act, NIST and ISO is described, alongside a Third-party AI Registry.

    Source: Credo AI product page · read 2026-10-01

Credo AI profile · Credo AI competitors

Control map: SPLX

  1. 1 Policy

    Policy: what the rule says

    AI Governance & Compliance maps to global and custom standards.

    Source: SPLX home page · read 2026-10-01

  2. 2 Control

    Control: what enforces it

    AI Runtime Protection applies input and output guardrails; Dynamic Remediation hardens system prompts.

    Source: SPLX home page · read 2026-10-01

  3. 3 Evidence

    Evidence: what proves it worked

    Automated AI Red Teaming and AI Runtime Threat Inspection (log scanning) produce findings.

    Source: SPLX home page · read 2026-10-01

  4. 4 Report

    Report: what an auditor receives

    The Enterprise plan lists a compliance framework check for MITRE ATLAS and the OWASP LLM Top 10.

    Source: SPLX pricing page · read 2026-10-01

SPLX profile · SPLX competitors

Control map: Lasso

  1. 1 Policy

    Policy: what the rule says

    The governance use case describes policy enforcement with visibility into every agent interaction.

    Source: Lasso AI agent governance page · read 2026-10-01

  2. 2 Control

    Control: what enforces it

    AI Detection & Response is a platform module; Lasso says its LEAP guardrail runs on CPUs at under five milliseconds per decision (vendor claim).

    Source: Lasso announcement, 3 September 2026 · read 2026-10-01

  3. 3 Evidence

    Evidence: what proves it worked

    Automated red teaming is mapped to MITRE and OWASP, with closed-loop remediation and auto guardrail patching.

    Source: Lasso AI red teaming page · read 2026-10-01

  4. 4 Report

    Report: what an auditor receives

    An audit trail for the EU AI Act, NIST AI RMF and ISO 42001 is described.

    Source: Lasso AI agent governance page · read 2026-10-01

Lasso profile · Lasso competitors

Control map: Holistic AI

  1. 1 Policy

    Policy: what the rule says

    Holistic AI describes enforcing policies across discovered models, agents and applications.

    Source: Holistic AI home page · read 2026-10-01

  2. 2 Control

    Control: what enforces it

    Not described

    The runtime mechanism is not described on the page reviewed.

    Source: Holistic AI home page · read 2026-10-01

  3. 3 Evidence

    Evidence: what proves it worked

    Tests for bias, hallucinations, prompt injection and drift are listed.

    Source: Holistic AI home page · read 2026-10-01

  4. 4 Report

    Report: what an auditor receives

    Evidence for the EU AI Act, NIST AI RMF and ISO 42001 is described.

    Source: Holistic AI home page · read 2026-10-01

Holistic AI profile · Holistic AI competitors