The Open AI Security Standard
AI Security Scoring Your Auditor Can Verify
AISS — the Ayliea AI Security Standard — is open, published under CC-BY-4.0, and reproducible from the answers your team provides. Score your AI surface against 7 compliance frameworks, see exactly which sub-controls produced your score, and hand auditors the spec to verify the math themselves.
Audit-grade: reproducible from the AISS spec + your answers alone.
THE OPEN STANDARD
The standard we score you against is public
Most compliance scoring is opaque because opacity is where vendor pricing leverage lives. AISS — the Ayliea AI Security Standard — takes the opposite position by design. Practitioners, auditors, and forks have full access to the methodology, the math, and the framework crosswalks.
Reproducible scoring
Every category score is fully derivable from the answers you provide and the published spec. Anyone with the standard and your answers can recompute the score — no proprietary algorithm, no vendor magic.
Auditor-verifiable
Hand auditors the published JSON spec at github.com/Ayliea/aiss. They verify the framework crosswalks, scoring rubric, and sub-control citations against their own reference frameworks. Saves you cycles in the audit room.
Fork it, propose changes
AISS is licensed under CC-BY-4.0. You can fork the standard, adapt it to your environment, or propose changes through the public RFC process. The standard belongs to the practitioner community.
Glass-Box scoring · CC-BY-4.0 · github.com/Ayliea/aiss
VERTICAL BUNDLES
AISS, applied to your industry
Generic AI security advice underserves regulated industries. Each vertical bundle pairs the AISS standard with industry-specific threat profiles, regulatory anchors, and cyber-insurance underwriting crosswalks — so your assessment speaks the language your auditors and carriers actually use.
Legal bundle next, plus open RFC for community contributions.
Assess against 8 compliance frameworks
THE PLATFORM
Complete AI Security Governance
From shadow AI discovery to compliance reporting — one platform.
AISS-Anchored Scoring with Audit-Grade Math
- 10 AI security control domains, 56 sub-controls
- Every score reproducible from the published spec
- Crosswalked to NIST CSF, NIST AI RMF, ISO 27001, OWASP LLM, EU AI Act

THE TRUST GAP
Your Blind Spot, Quantified
Every organization has a gap between what they believe about their AI security and what's actually happening. Ayliea measures both.
What your team reports in compliance assessments
What we discover from actual network traffic
No other platform combines compliance assessment with automated network discovery. We show both sides — what your organization reports and what's actually happening — so you can close the gap before an auditor finds it.
New: AI Governance Module
From Assessment to Continuous Governance
Go beyond point-in-time assessments. Manage your entire AI portfolio with continuous oversight, vendor accountability, and regulatory awareness.
AI System Registry
Catalog every AI deployment. Track use cases, data flows, and oversight levels. Convert shadow AI findings directly into governed systems.
Risk Classification
Auto-classify AI systems against EU AI Act risk tiers and NIST AI RMF from your use case metadata.
Vendor Questionnaires
Send 35-question AI security assessments to vendors via a branded portal. Responses scored automatically.
Incident Tracking
Report, investigate, and resolve AI incidents with a structured lifecycle. Auto-generate preventive recommendations.
Regulatory Timeline
Track which AI regulations apply and when. Pre-loaded with EU AI Act, Colorado AI Act, and NIST AI RMF milestones.
Why Teams Choose Ayliea
Privacy-First Architecture
No agents on endpoints. No traffic decryption. Passive network analysis means zero performance impact and no data exposure risk.
Assessment + Discovery
The only platform that combines compliance assessment with automated network discovery. See both what you report and what’s actually happening.
Sales-led, scaled to your org
Run your first AI security assessment in minutes — free. When you’re ready for multi-framework coverage and governance, upgrade without migration.
Transparent Pricing. Start Free.
Free for your first AISS assessment. Pro $1,200/yr for a paid framework. Business $3,600/yr for the full compliance suite. Enterprise from $15,000/yr — published floor, never hidden.
Glass-Box scoring
Every category score is fully derivable from your answers and the published AISS methodology. Your auditor can reproduce the math from the public spec alone.
Open standard
AISS is published under CC-BY-4.0 at github.com/Ayliea/aiss. Fork it, audit it, or propose changes via the public RFC process — the standard belongs to the practitioner community.
Self-serve, no demo gate
Sign up, take your first AISS assessment, see your score. No credit card, no sales call. Upgrade to Pro or Business via Stripe Checkout from inside the app.
Encrypted in transit and at rest. Annual billing. No surprise overages.
FAQ
Common Questions
AISS (Ayliea AI Security Standard) is the open methodology behind every assessment on the platform — 10 control domains, 56 sub-controls, 9 framework crosswalks, published under CC-BY-4.0 at github.com/Ayliea/aiss. Most compliance scoring is opaque because opacity is where vendor pricing leverage lives. We took the opposite position: practitioners, auditors, and forks have full access to the methodology. Your auditor can reproduce any score using only the published spec and the answers your team provides.
Vanta and Drata are general compliance automation platforms with proprietary scoring algorithms — auditors can’t verify the math, only the result. Ayliea publishes the scoring methodology under CC-BY-4.0. We cover the same compliance frameworks (SOC 2, ISO 27001, NIST CSF, HIPAA, PCI DSS, NIST 800-53, CIS Controls v8.1) plus AI-specific control domains and threat-informed scoring (MITRE ATLAS). Glass-Box scoring is structural, not marketing — VC-funded competitors can’t follow because their pricing model depends on opacity.
Glass-Box Score is visual proof that every score is reproducible. On the results page, you can expand any AC-1 through AC-10 control domain to see exactly which questions, weights, framework citations, and MITRE ATLAS technique mappings produced its score. Any auditor can reproduce the math from the published JSON spec at github.com/Ayliea/aiss using only your answers and the spec. No proprietary algorithm, no vendor magic.
A vertical bundle is AISS applied to a regulated industry. Healthcare (HIPAA + FDA SaMD + BAA framing) and Financial Services (NYDFS Part 500, EU DORA, SR 11-7, FINRA, SEC Marketing Rule) ship today. Each bundle includes the curated MITRE ATLAS threat profile for that vertical, a cyber-insurance underwriting crosswalk you can submit alongside a carrier application, and the eight priority AISS sub-controls that matter most for that vertical. Legal threat profile shipped; full Legal bundle in progress.
Click ‘Start free’ or ‘Read AISS’ anywhere on the site. The self-serve signup flow is live as of the 2026-05-12 PLG pricing pivot. Tier definitions: Free runs your first AISS assessment (no credit card). Pro at $1,200/yr adds 1 paid framework + AI recommendations + PDF export. Business at $3,600/yr unlocks all 7 compliance frameworks + continuous monitoring + advanced trust center. Enterprise (from $15,000/yr, published floor) is inbound only for custom integrations.
Yes. AISS is CC-BY-4.0 — attribution required, but commercial use, modification, and redistribution are all permitted. You can run the standard against your AI surface using nothing but the published spec, fork it for internal extension, or use it as the methodology in an external audit you’re delivering to a client. The Ayliea platform is for organizations that want the scoring + audit-trail + AI-personalized remediation done for them; the standard itself stays free forever.
Network discovery is still in the platform — it’s evidence input that powers your Trust Gap (the difference between what you self-report and what’s actually in your environment). But it’s positioned as evidence input now, not a standalone flagship feature. Category is saturated (Sola ships network-level free; Credo, Portal26, Reco, LayerX, Microsoft Purview saturate SaaS-API discovery). Our differentiator is the open standard you score against, not the discovery surface.
Yes. The discovery surface reads DNS queries and TLS handshake metadata only — 99% of traffic is discarded locally before anything leaves your network. All data encrypted in transit and at rest. We don’t sell data, we don’t train models on it, and we never will. The full Trust Center at /trust shows our security posture and policies in detail.
Run Your First AISS Assessment
Free, 20 minutes, no credit card. Score your AI surface against the open standard and see exactly which sub-controls produced your score.
