Compliance
Regulation, mapped to modules and evidence
Auditors and regulators do not ask for a platform, they ask for evidence against a clause. Each page below maps a framework requirement to the PuReAI module that produces it and the artefact you can hand over.
Frameworks
DORA & NIS2
EU financial ICT resilience and the wider NIS2 duties — article-level mapping.
NIST CSF 2.0
US and international baseline for cyber risk governance.
ISO/IEC 27001:2022
Certifiable ISMS standard; Annex A supplier and vulnerability controls.
PCI DSS 4.0.1
Card data environment security; external exposure and TPSP oversight.
TIBER-EU
ECB framework for threat-led penetration testing in financial entities.