Custos·v 2026.1Custos in live audit

A governance layer for every AI call

Custos checks every request, every answer and every data trail against your policies – in real time. Your next audit is already prepared today: audit-proof, traceable, inside the EU tenant.

100% EU
data residency
0
open breaches
< 24 h
MTTR (median)
Business outcomes

The numbers your audit committee wants to see

Custos shortens audit prep, closes compliance gaps and makes every AI call traceable. No marketing figures – median values from real rollouts in the last twelve months.

  • 0%

    audit preparation time

    Comparison Q before / after Custos rollout, median across 6 pilot customers

  • 0%

    live policy coverage

    Every request is checked against your active policies – no sampling mode

  • 0 min

    to full incident lineage

    From trigger to complete lineage answer, median

  • 0 / 8

    frameworks covered

    GDPR, EU AI Act, ISO 27001, NIS-2, SOC 2, TOM, DPA, BSI Grundschutz

Values based on pilot customers in insurance, energy and industrial (DACH, 250–4 000 employees).

Risk surface

Four risks that land in your log file without Custos

Every AI rollout creates new liabilities. Custos makes them visible before they become an incident – and ships the evidence with the alert.

Bestand ohne Custos
4 offene Verbindlichkeiten · ungebremst
  • Regulatory gaps

    EU AI Act, GDPR, NIS-2, vertical specifics – without structured coverage it stays unclear which duties apply and who is liable.

    Exposure · Fines up to 7% of global annual revenue
  • Unclear data lineage

    Which training and context data fed which model? Who approved it? Without lineage there is no defence in an audit.

    Exposure · Audit duty under GDPR Art. 5
  • Shadow AI

    Teams try ChatGPT, Copilot & Co. without sign-off. Sensitive data leaves the company unseen – with no audit trail.

    Exposure · Trade secrets · competitive risk
  • Missing access boundaries

    If everyone can see every tenant's data, the multi-tenant promise is worthless – including liability towards end customers.

    Exposure · Breach of contract toward end customers
Regulatory layers

Four frameworks, one guardian

Custos maps the most important DACH-relevant AI and data protection duties – with coverage matrix, evidence templates and sub-processor tracking, one click away.

Layer 01GDPR

General Data Protection Regulation

Articles 5, 6, 17, 25, 28 and 30 are wired into Custos as control points. Every request runs through PII filter, legal basis and data lineage – DPA and TOM on demand.

GDPR · Coveragelive
  • Art. 5 · 6 · 17 · 25 · 28 · 30
  • DPA generator
  • TOM documentation
  • Sub-processor list
EvidenceEvidence set available
Layer 02EU AI Act

EU AI Regulation

Risk classification per use case, model cards and disclosure duties under Annex III. Custos classifies automatically and blocks prohibited use cases – not at quarterly review.

EU AI Act · Annex IIIper-use-case
Inakzeptabel0
Hoch12
Begrenzt38
Minimal184
Kontrolle
Annex III classification
Kontrolle
Model cards v 2.1
StatusLive classification active
Layer 03ISO 27001

Information Security

Asset inventory, access control, incident response and supply-chain audit are wired into Custos. One click produces the Statement of Applicability with evidence per control.

ISO 27001 · SoAv 2026.1
Audit · bestanden
Last audit: passed
Asset inventoryOK
Access control RBACOK
Incident playbookOK
SoA exportOK
Layer 04NIS-2 + BSI

Cybersecurity & baseline

NIS-2 reporting duties, BSI Grundschutz modules APP.4 / OPS.1 / CON.3 and the supply-chain requirements are unified in one workflow – audit-proof logged.

NIS-2 + BSI · Reportinglive
00:00Detection
24:00Erste Meldung
72:00NIS-2-Frist
  • NIS-2 reporting
  • BSI APP.4 · OPS.1 · CON.3
  • Supply chain audit
StatusReporting chain verified

Also covered: SOC 2 Type II, TOM (BfDI standard), DPA under GDPR Art. 28 – evidence documents inside your EU tenancy.

SOC 2 Typ IITOM (BfDI)AVV Art. 28
Control center

Your compliance, live in a dashboard

Instead of monthly reports, board, CISO and DPO see what is running – and what needs attention – in a single view.

Custos Control Center
Active policies
  • PII redaction (default)
    4,218
  • Model routing EU-only
    14,247
  • Trade-secret filter
    893
  • High-risk use cases (AI Act)
    12
  • Escalation threshold
    3
  • Right to be forgotten (GDPR 17)
    8
Audit streamstreaming
  • 09:42:18passpolicy.pii · Request → 2 IBANs redacted, cleared
  • 09:42:14passmodel.route · Routed claude-3.7 · region eu-central-1
  • 09:42:09warnpolicy.escalate · Confidence 71% · escalated to team
  • 09:42:02passaudit.seal · Cycle 4218 sealed · hash recorded
  • 09:41:55infoexport.audit · PDF export for audit (W19) generated
  • 09:41:42passaccess.rls · Tenant boundary verified · no leak signal
Risk index
0/ 100
Low
−6 vs. last week
Incident replay

When something stands out, you see what, when, why

Sample audit flow of a flagged event. From trigger to closure – time and ownership visible per stage.

Total response time
24 h
Industry median
11 days
  1. 00:00
    Stufe 01

    Detection

    Anomaly detector triggers

    Model drift exceeds 4-σ threshold · source: route.metric

  2. 00:08
    Stufe 02

    Classification

    High-risk use case confirmed

    Custos classifies under AI Act Annex III · level 2

  3. 00:22
    Stufe 03

    Alerting

    CISO + DPO notified

    Slack + email · ETA status: in handling

  4. 04:18
    Stufe 04

    Containment

    Auto-routing to fallback

    Model paused · 100% of requests on safe fallback

  5. 24:00
    Stufe 05

    Closure

    Audit report generated + approved

    PDF + JSON lineage · hash sealed for audit

Voices from the audit committee

Why compliance leads, CISOs and DPOs pick Custos

Three perspectives from the audit committee – each a different lens on the governance layer. Click through to the one driving the decision in your house.

Verified pilot · DACH 2026
CISO · Security

Real-time control instead of quarterly reports

We measure security in MTTR, not in PDFs. Custos delivers the stream a modern SOC expects – lineage per call, auto-containment and cleanly sealed audit trails.

Before Custos, every AI incident meant two days of detective work. Today the dashboard shows me in under ten minutes who asked what and why – lineage included.
TB
T. B.CISO · energy utility · 3 200 employees
What you get as CISO
  • Anomaly detector

    Model drift, unusual request volume and policy violations are detected and classified in seconds.

  • Auto-containment

    Suspicious models are paused, traffic is routed to fallback – without anyone going to the office at night.

  • WORM audit trail

    Write-once-read-many logs with cryptographic hashes. Tampering is detected immediately – including insider attempts.

  • SIEM integration

    Native connectors for Splunk, Elastic and Sentinel. Your existing SOC gets Custos events with no wrapper code.

  • Tenant isolation

    Row-level security with hard limits, not soft suggestions. Cross-tenant access is technically impossible.

  • Forensic export

    Full lineage as JSON or PDF – signed, timestamped and ready for court-grade forensic review.

Trusted by our pilot customers
  • IS
    Industrial SouthPilot · 2026
  • IN
    Insurance NorthPilot · 2026
  • EE
    Energy EastPilot · 2026
  • BD
    Bank DACHPilot · 2026
  • LW
    Logistics WestPilot · 2026
  • PC
    Pharma CentralPilot · 2026
Q&A · Audit-Komitee01 → 06
  • No – Custos provides the tools a DPO needs: audit trail, DPA templates, lineage, breach reports. The DPO stays accountable. Custos makes their work traceable and audit-ready.

Next step

30 minutes with our DPO lead and CISO

We will check together which compliance duties apply at your place – and which Custos covers right away. Honest, no compliance theatre.