July 7, 2026 · Trustworthy Autonomy

Introducing Trustworthy Autonomy™

vCISO Lite’s compliance agents, working end-to-end — with cryptographically signed actions, reasoning traces you can read, and freshness-verified evidence. As much or as little of the work as you want to hand over.

What changed

Trustworthy Autonomy™ is the new posture for AI on the vCISO Lite platform. Agents can now run programs end-to-end: every action they propose is cryptographically signed, bound to a specific control, backed by a reasoning trace, and re-verified against fresh evidence. Nothing runs on its own until you say it can.

Signed actions
Every action our agents propose is cryptographically signed and bound to a specific control (SOC 2 CC6.1, PCI 8.3.1, ISO 27001 A.5.15), with a reasoning trace you can read line by line.
Programs run
Third-party risk, audit prep and defense across SOC 2, ISO 27001 and PCI DSS, real-time KRI monitoring, and end-to-end M&A cyber diligence priced in dollars.
Fresh evidence
Every claim is re-verified against fresh evidence at the moment of action, not a stale snapshot from the last audit cycle.
Human gate
Nothing runs on its own until you say it can. The default posture is propose-and-approve; the autonomy level is yours to raise, control by control.
Standards
Built to OWASP's Top 10 for Agentic AI Security (Dec 9, 2025) and the Cloud Security Alliance's Agentic NIST AI RMF Profile v1.

Why it matters

Compliance AI has been a decade of promises and demo-call magic. What has not shipped, until now, is the audit chain underneath: a proposed action tied to the control it serves, the evidence it rests on, the person who approved it, and a signature that survives a Type II testing procedure in month six.

Every claim on the Trustworthy Autonomy landing page was designed against two documents: OWASP’s Top 10 for Agentic AI Security and the Cloud Security Alliance’s Agentic NIST AI RMF Profile v1. Both ask for the same underlying capabilities: kill switches, accountability registers, provable delegation chains. We built to those; the trust ladder on the landing page walks through how.

The full working paper, “A Framework and Benchmark Methodology for Certifying Autonomous GRC Agents” (Smith, 2026), and the executive brief are on the briefs & specs page. For the formal launch announcement, see the press release. For the underlying methodology and how our own market-research sprint shaped it, see the Trustworthy Autonomy blog cluster, including “How often is your compliance AI actually right?”

Availability

Shipping today across the platform. Every tier gets the posture; the agent catalog you can turn on tracks your existing entitlements.

The programs available on day one are third-party risk (score vendors, chase questionnaires, escalate exposure, keep the register audit-clean), audit prep and defense for SOC 2, ISO 27001 and PCI DSS, real-time KRI monitoring with drafted responses on threshold breach, and end-to-end M&A cyber diligence covering attack surface, third-party concentration, and data and regulatory exposure. Hand over as much or as little of the work as you want.

Known limitations

This is the first iteration of the Trustworthy Autonomy posture. The agent catalog covers the programs the platform already runs; new program types land per the roadmap rather than through agent extension.

Signed-action binding requires the control to be in scope on an active assessment. Frameworks you have not activated cannot anchor an agent's proposed action.

Autonomy level is per-control and defaults to propose-and-approve on first activation. Raising a control to run-without-approval is a deliberate decision recorded in the audit chain.