These tools and metrics are designed to help AI actors develop and use trustworthy AI systems and applications that respect human rights and are fair, transparent, explainable, robust, secure and safe.
Pegasus
Pegasus is an open-source compliance framework for AI security validation. It evaluates security evidence against formal requirements drawn from standards, regulations, and best-practice frameworks, including ISO/IEC 42001, the EU AI Act, NIST AI RMF, OWASP LLM Top 10, OWASP ASVS, PCI DSS, SOC 2, and SLSA. The framework uses Rego-based policies and certification profiles to assess whether collected evidence satisfies specified controls and requirements. Pegasus includes a policy engine, evidence store, certification evaluation capabilities, and benchmarking tools, enabling organisations to translate security findings into compliance assessments and assurance artefacts.
Key capabilities:
- Automated policy-based compliance evaluation with pass/fail/warn/skip results
- Multi-standard certification scoring with configurable pass thresholds
- Dual-agent cross-review architecture (security + compliance) with confidence scoring
- Content-addressable evidence store (SHA-256) for tamper-evident audit trails
- 22 MITRE ATLAS/ATT&CK technique mappings for AI and infrastructure threats
- Extensible policy library with community contributions welcome
About the tool
You can click on the links to see the associated tools
Tool type(s):
Objective(s):
Country/Territory of origin:
Type of approach:
Maturity:
Usage rights:
License:
Stakeholder group:
Risk management stage(s):
Technology platforms:
Use Cases
Would you like to submit a use case for this tool?
If you have used this tool, we would love to know more about your experience.
Add use case




























