Framework Alignment
This page maps implemented Legate control themes to common frameworks for auditors and GRC reviewers. It is evidence mapping, not a certification, conformity assessment, “MCP certified,” “AIUC-1 certified,” or “EU AI Act compliant” claim for Legate alone.
Forward with Access Model and Disclosure Boundary. Deeper evidence packages are available through BlockSkunk / Agelite diligence - not as an exhaustive dump in this portal.
Frameworks
Legate’s public connect contract maps control themes to:
- MCP Authorization (2026-07-28) / OWASP MCP Top 10 themes
- NIST CSF 2.0
- ISO/IEC 27001:2022
- ISO/IEC 42001:2023
- SOC 2 (Security / Confidentiality) trust-criteria themes
- NIST AI RMF (tool-plane slice: Govern / Map / Measure / Manage)
- AIUC-1 operational control IDs (tool-plane slice)
- EU AI Act articles that AIUC-1 crosswalks for that tool-plane slice
Control themes
| Control theme | What it means at the interface | Frameworks (high level) |
|---|---|---|
| Audience-bound tokens | Short-lived Bearer; audience/resource bound to Legate URI | MCP Auth, NIST CSF PR.AA, ISO 27001 A.5/A.8, ISO 42001 A.6, SOC 2 CC6 |
| Least privilege | Scopes → packs; deny-by-default writes | MCP / OWASP privilege, PR.AA, A.8, A.6, CC6 |
| Write consent | Explicit consent claim required for write tools | MCP authz, PR.AA, A.8, ISO 42001 A.9*, AIUC-1 C009, EU AI Act Art. 14 (tool plane), CC6 |
| Input validation | Tool args validated against published schemas | OWASP injection, PR.DS, A.8, CC6 |
| Tool-call guarding | Production tool plane runs OdinGard Cerberus (existence - not scoring models) | OWASP tool poisoning themes, PR.DS / DE.CM, A.8, AIUC-1 D003, CC7 |
| Audit / telemetry | Digests for actor / tool / args / status - no secrets in logs | DE.CM, A.8 logging, A.6, AIUC-1 E015, EU AI Act Art. 12 / 19, CC7 |
| Rate limiting | Abuse / denial resistance on /mcp | PR.IR, A.8, CC6 |
| Output hygiene | Redaction + size caps | PR.DS, A.8, AIUC-1 A-series hygiene themes, CC6 |
| Fail-closed auth | Production remote requires configured OIDC + resource URI | PR.AA, A.8, AIUC-1 B008 themes, EU AI Act Art. 15 (cyber), CC6 |
| Client vs tool plane | Sampling / generative UX is client-side; Legate is tool plane | NIST CSF GV.OC, ISO 42001 A.6, EU AI Act Art. 50 (client/deployer) |
*Human oversight for model sampling is an MCP client obligation. Legate enforces tool-plane write consent only.
NIST AI RMF (tool-plane)
| AI RMF function | How Legate contributes |
|---|---|
| GOVERN | Documented role boundary: resource server vs LLM host; themes on this page |
| MAP | Tool packs + scopes as capability inventory |
| MEASURE | Audit digests; rate-limit / deny signals for operators |
| MANAGE | Fail-closed auth, pack deny, write-consent gate |
Org-wide AI risk programs (policies, impact assessments) live outside this product docs set.
AIUC-1 / EU AI Act (tool-plane)
Public crosswalk: AIUC-1 × EU AI Act. Legate maps as a component (tool plane), not as a stand-alone high-risk AI system conformity package.
| AIUC-1 theme (IDs) | EU AI Act articles | What Legate contributes at the interface |
|---|---|---|
| E015 Log AI system activity | Art. 12, Art. 19 | Append-only tool-call digests (actor / tool / args digest / status) - no secrets |
| C009 Real-time feedback and intervention | Art. 14 | Write tools require explicit consent claim; signing stays outside the agent |
| D003 Restrict unsafe tool calls | Art. 72 themes | Scopes → packs; deny-by-default writes; tool-call guarding (existence) |
| B008 Protect deployment environment | Art. 15 | Fail-closed remote auth; audience-bound tokens; rate limits; internal publish posture |
| A-series hygiene (credentials / leakage) | Art. 15 (cyber) | Redaction + no bearer tokens in logs |
| E016 / E017 disclosure themes | Art. 13, Art. 50 | Connect docs + this page + Disclosure Boundary; “interacting with AI” notice is primarily client / deployer |
| E013 / C001 QMS and risk taxonomy | Art. 9, Art. 17, Art. 27 | Packs/scopes as capability inventory only - org AIMS and deployer FRIA stay outside Legate |
Out of scope
- FedRAMP High / full NIST SP 800-53 SSP
- Legate as an OAuth authorization server
- Third-party AI conformity assessment for Legate alone
- AIUC-1 certification or “EU AI Act compliant” claims for Legate alone
- Art. 10 training-data duties for models Legate does not train
- Art. 27 fundamental-rights impact assessment (deployer)
- CE marking / EU database registration
- Guard / scoring engines, policy source files, or mandate business rules - see Disclosure Boundary