Audit automation

The audit runs itself — on your cloud, your servers, and your schedule.

Assessments today are a manual exercise: an assessor asks an administrator to share a screen and type configuration queries one at a time, producing evidence that proves the state of the estate on a single day. TITAN AI collects the same evidence automatically, continuously, and across every host — so the assessor receives a year of signed evidence instead of a three-week fire drill.

Your environment decides which rulebook applies

A hospital and a manufacturer do not share a control set. TITAN AI identifies the workload from evidence inside the environment itself, applies only the frameworks that genuinely apply, and records both the signals it matched and the profiles it deliberately excluded — so the scope of every report is defensible.

Healthcare

Detected from clinical data models, HL7/FHIR interfaces and EHR platforms.

Applies: HIPAA Security and Breach Rules, HITRUST CSF, TITAN-HSF.

Adds: the PHI audit — 18 checks generic cloud scanners do not perform, including protected health information reaching public storage, appearing in application logs, or living in non-production environments; unclassified PHI columns; audit-log retention below the six-year requirement; standing access that exceeds minimum necessary; and vendors handling PHI without a Business Associate Agreement.

Financial services

Detected from payment-card data elements, cardholder zones and financial reporting systems.

Applies: PCI DSS, SOX ITGC, CIS Benchmarks.

Adds: segregation-of-duties and change-control evidence across the application, database and operating-system layers, with every production change traced to an approved record.

Government and defense

Detected from impact-level designations, sovereign cloud regions and controlled-information markings.

Applies: NIST SP 800-53, DISA STIG, FedRAMP, CMMC.

Adds: certified air-gapped operation. The full pipeline is verified with the network layer severed — reasoning, scoring, remediation classification and report generation all complete with zero egress.

Enterprise applications

Detected from ERP platform components, in-memory database layouts and administrative account conventions.

Applies: platform security baselines, DISA STIG at the operating-system layer, SOX ITGC, CIS Benchmarks.

Adds: host-level hardening evidence for the servers beneath the application — the layer most compliance tooling never examines.

Multi-tenant SaaS

Detected from tenant isolation models and customer-facing API surfaces.

Applies: SOC 2 Security criteria, CIS Benchmarks.

Every environment

A universal baseline applies regardless of industry, and no vertical framework is ever asserted without supporting evidence. Where an organisation knows its obligations differ, the profile can be declared explicitly.

Windows and Linux, audited the same way

Cloud control planes are only half of an assessment. The servers running the workload — application hosts, database servers, jump boxes — are usually examined by hand, once a year. TITAN AI audits both operating systems automatically and returns the verbatim command output alongside each result, because assessors need the console text, not a summary of it.

Windows Server

Cryptographic policy including FIPS mode and deprecated TLS protocol status, anonymous enumeration and null-session restrictions, cached credential limits, session controls, data execution prevention, time synchronisation and NTP configuration, DNSSEC policy, and full service inventory.

Linux (RHEL, Ubuntu, SUSE)

Authentication and password policy, empty-password and unauthorised root-equivalent account detection, passwordless privilege escalation, SSH hardening, FIPS and system crypto policy, mandatory access control, kernel hardening parameters, filesystem permissions including world-writable and privileged binaries, audit daemon rules and log retention, file integrity tooling, host firewall state, and listening service inventory.

Both agents are read-only by construction. Every command is validated against an allow-list before execution, and any instruction capable of writing, stopping, installing or deleting is refused by the executor itself — the agent cannot alter the system it is auditing.

Nothing is installed on your servers

Host evidence is normally the point where an assessment stalls: security teams are asked to deploy an agent to every server, which means a change request, a package review and a rollout window before a single question can be answered. TITAN AI does not ask for that. Host checks are delivered through the management channel your cloud platform already provides, executed in a transient sandbox, and discarded. No software is installed, nothing is written to the server's filesystem, no service is registered, and there is nothing to uninstall afterwards. Every run confirms the host was left clean and records that confirmation as part of the evidence.

Execution on customer servers is never implied by a request to scan a cloud estate. It requires an explicit, recorded authorization, and the report names who granted it and when.

Managed hosts

Servers reachable through the cloud management channel — including on-premises and other-cloud machines projected into it — are audited automatically, in parallel, with no preparation required from the customer.

Everything else

Hardened images without a management agent, isolated networks, and estates whose policy forbids remote execution are not skipped and not silently marked compliant. TITAN AI produces a read-only script the customer's own administrator runs in about two minutes per host, and the returned result is ingested identically to an automated one — the same questions, the same evidence, the same report.

Coverage is therefore stated as a number, not implied: every discovered host is either audited directly or accounted for in the self-service path, and the report shows which applied to each one.

Fixes that are safe, changes that are not

Remediation is divided by blast radius, not convenience. Low-risk corrections are applied by the remediation engine under approval, with a dry run first and a recorded rollback path. Changes capable of severing access — firewall and port rules, identity and authentication, deletions, encryption re-keying — are never applied automatically. TITAN AI raises a change request in the customer service-management platform, complete with an implementation plan and a backout plan, and a human approves, implements and closes it. Findings with no safe automated path are raised as tickets so nothing is lost in a dashboard.

The service-management connection belongs to the customer: their instance, their credentials, their change process. Every record TITAN AI creates states this explicitly.

Governed AI

Language models are used to explain findings, never to decide them. Severity, remediation and routing are computed deterministically and are identical in every environment, including disconnected ones. Before any prompt leaves the process, credentials, keys, tokens, identifiers and network addresses are removed — a model cannot disclose what it never received. Responses are screened for instruction injection and discarded if they fail, and every interaction is recorded in a hash-chained audit log an assessor can verify independently. The model has no execution path, and language-model use can be disabled entirely.

Continuous, not annual

Posture is re-checked several times a day, agents sweep weekly, control evidence is captured monthly, and the formal assessment package is produced annually. Beyond the calendar, TITAN AI responds to the environment: a control that begins failing triggers an immediate run, and a previously remediated finding that returns is treated as a regression and escalated. When an assessment date is declared, the platform moves to daily runs for the preceding month. The same schedule operates identically in connected and air-gapped deployments.

Each run produces an auditor package: findings mapped to the applicable safeguards, prioritised recommendations, a point-in-time configuration capture of every in-scope resource with individual integrity hashes, and an attestation covering change management and AI governance. Reports are self-contained and render without network access.