Cross-Framework Translation

Indicative equivalences by framework

Published framework

NIST AI RMF, ISO/IEC 42001, and EU AI Act equivalences are indicative readings, not official certifications.

NIST AI RMF

  • Security → NIST Manage + Measure (misuse safeguards, testing, incident handling)
  • Stability → NIST Manage (continuity, monitoring, recovery)
  • Coherence → NIST Map + Measure (risk identification, behavior measurement)
  • Reputation → NIST Govern (external trust and accountability)
  • Transparency → NIST Govern (documentation, explainability)

Estimated NIST AI RMF maturity tier: Tier 2/4

ISO/IEC 42001

  • Security → clause 6 (risk treatment) + clause 8 (operational controls)
  • Stability → clause 8 (Operations) + clause 10 (Improvement)
  • Coherence → clause 6 (Planning) + clause 9 (Performance evaluation)
  • Reputation → clause 7 (Support)
  • Transparency → clause 4 (Context) + clause 5 (Leadership)

Estimated ISO 42001 coverage: 74%

EU AI Act

Articles 15, 16, 26, 50 mapped to Kanon dimensions.

Article 15 : Partial

Kanon mapping: Security + Stability

Article 16 : Aligned

Kanon mapping: Security + Stability + Coherence + Transparency

Article 26 : Partial

Kanon mapping: Security + Transparency

Article 50 : Partial

Kanon mapping: Transparency

Sources used

Evidence preserved for this rating

Review methodology

Homepage metadata

Homepage metadata review

Homepage metadata reviewed from the public site. Title observed: Privora — DPO as a Service | GDPR Compliance for SMBs. Meta description or visible summary: Privora is your always-on Data Protection Officer. Get GDPR-compliant with privacy policy generation, DPIA tools, and expert DPO guidance — starting at $49/mo.

Open source

Official site

Official site review

Homepage returned HTTP 200. Title observed: Privora — DPO as a Service | GDPR Compliance for SMBs. Public offer summary: Privora is your always-on Data Protection Officer. Get GDPR-compliant with privacy policy generation, DPIA tools, and expert DPO guidance — starting at $49/mo.

Open source

Operational evidence

Operational surface scan

Accessible public pages: /. Signals detected: service public reachable, pricing or demo CTA visible, technical or integration surface visible, public traction signals visible.

Open source

Public disclosure review

Disclosure and counter-argument review

Disclosure review found pricing/demo signal. Main contrary argument: Even though no privacy policy found, the public record still shows service public reachable.

Open source

Security review

Security v3.2 provisional review

Score Sécurité provisoire v3.2: 42/100 (S1 32, S2 45, S3 20, S4 71). score initial v3.2, susceptible de révision dans les 30 jours. Signaux publics observés: GDPR or DPO claims visible, context or session isolation language, logs, receipts, or audit trail signal, public versioning or changelog signal, external audit or certification signal.

Open source

Security evidence

Security evidence surface scan

Pages publiques sécurité/données détectées: /. Raisons: S1 signalement d'incident ou posture de divulgation visible; S2 signaux RGPD ou droits des personnes, indices publics d'isolation de contexte ou de session; S3 signaux faibles; S4 logs, reçus ou audit trail visibles publiquement, versioning ou mise à jour publique accessible, audit ou certification externe publiquement mentionné.

Open source

Dispute

If new material evidence changes the public record, operators can request a review through the public challenge channel.

Dispute this score

This agent has no Verified badge. Claim your public verification record.

Verify this agent →