What makes Ayliea different from black-box scoring competitors: the standard you’re scored against is public. Every category score is fully derivable from the answers you provide and the published AISS spec. No proprietary algorithm, no vendor magic — hand auditors the JSON spec and they reproduce your score from your answers alone.
Who It’s For
GRC Professionals
Compliance officers and governance teams who need structured assessments mapped to SOC 2, ISO 42001, NIST AI RMF, HIPAA, and the EU AI Act — with audit-grade evidence reports and reproducible scoring.
Security Teams
Security engineers and analysts benchmarking AI surface controls against AISS, MITRE ATLAS threat coverage, and OWASP LLM Top 10 — with weighted risk scoring and prioritized remediation.
Org Leaders
CTOs, CISOs, and AI program owners who need executive visibility into AI security posture — clear scores, grades, vertical-specific bundle context, and trend tracking over time.
What You Can Do
Score
Run AISS — the open AI Security Standard — for free, or work with an assessor to assess against the other 10 active frameworks (CIS v8.1, NIST 800-53, NIST CSF 2.0, NIST AI RMF, NIST AI 600-1 GAI Profile, HIPAA, SOC 2, ISO 42001, OWASP LLM Top 10, AI Agent Security). 1,000+ questions in total, all scored on a 0–100 scale with letter grades and weighted category breakdowns.
Audit
Drill into any score with Glass-Box Score — expand each AC-1 through AC-10 control domain to see questions answered, weights, framework crosswalks (NIST CSF 2.0, NIST AI RMF, CIS Controls v8.1, ISO 27001:2022, EU AI Act, Colorado AI Act, plus MITRE ATLAS technique mappings), and a deep-link to the matching domain in the public AISS spec.
Apply Vertical Bundles
Set your org’s vertical (Healthcare or Financial Services) and AISS results filter through the priority sub-controls for that vertical by default. Healthcare ties to HIPAA + FDA SaMD; Financial Services to NYDFS Part 500, EU DORA, SR 11-7, FINRA, and SEC Marketing Rule.
Remediate
AI-personalized recommendations tied to your weakest sub-controls, backed by step-by-step remediation playbooks. Each recommendation links to evidence attachments so progress is tracked from gap → action → closure.
Report
Generate PDF reports summarizing posture, category scores, vertical-bundle context, and evidence attachments. Formatted for internal reviews, auditors, board updates, and cyber-insurance underwriting submissions.
Propose Changes
Disagree with how a control is scored? Every question row has a one-click “Propose AISS RFC” link that opens a pre-filled GitHub issue on Ayliea/aiss with the control ID and your context populated. Practitioners shape the standard through the same public process they use to consume it.
Pricing
Ayliea is engagement-first: fixed-scope assessments delivered by a named assessor, with published floors — never “Contact us.”
Every engagement includes a secure client portal with access to your active frameworks, AI-powered remediation guidance, score history, branded PDF reports, and your signed deliverables — owned by your organization and exportable. Full package details at ayliea.com/pricing.
Get Started
Run the Free AI Security Assessment
See where your AI security posture stands in minutes — no account, no card, no sales call.
Start an Engagement
Book a 30-minute scoping call. We map the engagement to your AI surface and agree on a fixed price before any work begins.
Frameworks Overview
Learn about the 11 active compliance frameworks and how to choose the right one for your organization.
Read AISS
Browse the open standard on GitHub. 10 control domains, 59 sub-controls, 6 framework crosswalks, CC-BY-4.0.
Glass-Box Methodology
Read how scores are computed from the AISS spec — what an auditor sees when they verify your score.

