Nizh

Compliance frameworks delivered to AI agents. Nizh gives your agent read access to your organization's compliance program — SOC 2, ISO 27001, CMMC 2.0, NIST, and more — as MCP tools, so it can check posture, read a control's objectives before changing code, and record where evidence lives.

Documentation

Skip to content

Governance and control awareness for AI

Give AI agents governed access to your compliance program.

Connect Claude, Cursor, Gemini, or any MCP client to versioned controls. Every read and every proposed reference lands on the record. Your files stay where they are.

Start freeSee how it runs

Available frameworks

  • CMMC 2.0
  • NIST SP 800-171
  • NIST SP 800-53
  • SOC 2
  • ISO/IEC 27001
  • FedRAMP
  • HIPAA
  • CMMC 2.0
  • NIST SP 800-171
  • NIST SP 800-53
  • SOC 2
  • ISO/IEC 27001
  • FedRAMP
  • HIPAA
  • CMMC 2.0
  • NIST SP 800-171
  • NIST SP 800-53
  • SOC 2
  • ISO/IEC 27001
  • FedRAMP
  • HIPAA
  • CMMC 2.0
  • NIST SP 800-171
  • NIST SP 800-53
  • SOC 2
  • ISO/IEC 27001
  • FedRAMP
  • HIPAA
  • CMMC 2.0
  • NIST SP 800-171
  • NIST SP 800-53
  • SOC 2
  • ISO/IEC 27001
  • FedRAMP
  • HIPAA
  • CMMC 2.0
  • NIST SP 800-171
  • NIST SP 800-53
  • SOC 2
  • ISO/IEC 27001
  • FedRAMP
  • HIPAA
  • CMMC 2.0
  • NIST SP 800-171
  • NIST SP 800-53
  • SOC 2
  • ISO/IEC 27001
  • FedRAMP
  • HIPAA
  • CMMC 2.0
  • NIST SP 800-171
  • NIST SP 800-53
  • SOC 2
  • ISO/IEC 27001
  • FedRAMP
  • HIPAA

Leadership sets the standard

Project · Readiness

  • CMMC 2.0
  • NIST SP 800-171
  • NIST SP 800-53
  • SOC 2

Corporate enclave488 agent reads‹ 1/3 ›

5.15.26.1.16.1.27.17.37.47.5.1Jul 31Aug 20

CMMC 2.0 Level 2100%ISO/IEC 27001:202292%

Coverage 96%MCP 1 connected

Teams deliver on it

EngineeringCursor · delivers on policy

MarketingClaude · delivers on policy

SalesGemini · delivers on policy

Works with the AI tools your team already uses. One connection, any MCP client.

Connect an agent in a minute

ClaudeOpenAICursorWindsurfVS CodeGeminiReplitLovableJetBrainsJetBrainsWarpRaycastClineGitHub CopilotPostmanPerplexityMistral AITraen8nDifyDifyZapierZapierLangChainNeovimHugging FaceLM Studio

Compatible through MCP. Trademarks belong to their owners. Gemini™ is a trademark of Google LLC. JetBrains and the JetBrains logo are trademarks of JetBrains s.r.o. Neovim logo by Jason Long, CC BY 3.0.

Why now

Know how AI uses your compliance program. Every Nizh control read is logged.

Your agents are already reading controls. See which ones they consulted and which nobody touched, before it becomes a finding. Activity is not compliance status. It is a verifiable record of attention and follow-through.

AI

MCP

one connection

control.read

on the record

One platform. Every framework you run.

Everything here ships in every plan, the free one included. Nothing is an upgrade.

/ 01

No files stored, so your boundary never grows

No file storage and no ingestion path. Nizh keeps the text you write and the references agents propose, never your documents or CUI.

Learn more

/ 02

A tamper-evident audit trail, verified every night

Every Nizh control read, proposed reference, and human decision lands on a hash-chained trail. Application roles cannot update or delete events, and nightly verification is designed to reveal unexpected changes.

Learn more

/ 03

One governed MCP connection, read-only, consented, revocable

One connection per organization covers every framework you run: Claude, Cursor, Gemini, any MCP client. Revocable in a click.

Learn more

/ 04

Agent coverage: every read, every blind spot

Which controls your agents read, and which nobody touched.

/ 05

Human-reviewed evidence references, never a file

An agent proposes a commit, a PR, or a ticket link, with a sentence of context. A named person confirms it, or the record shows nobody has.

/ 06

Versioned, source-aligned catalogs, with control text and objectives

Catalogs with their control text and assessment objectives, at the version you chose. One engine runs them all.

No files stored, so your boundary never growsA tamper-evident audit trail, verified every nightOne governed MCP connection, read-only, consented, revocableAgent coverage: every read, every blind spotHuman-reviewed evidence references, never a fileVersioned, source-aligned catalogs, with control text and objectives

AC.L1-3.1.1 · Notes

Enforced through SSO with MFA; access list reviewed quarterly by IT.

access-policy.pdfno upload path

Your notes, in your words. No customer files. No CUI.

Audit trail

  • 1042control.read9f3c…a71b
  • 1041grant.issued4e08…cc52
  • 1040control.updatedb71d…0f9a

MCP connection

Claude is requesting access

One connection, every framework your organization runs.

read-onlyconsentedrevocable

AllowDeny

Agent coverage

9 of 17 read

Attention, not compliance. A control being read is not a control met.

AC.L2-3.1.10 · Evidence

examineClaude · 2 days ago

Session lock ships at 15 minutes and ends the session; verified in the portal.

f753a28PR #214

1 of 1 affirmedby dana@ · IA.L2-3.5.3

2 unaffirmednobody has stood behind these yet

Your controls

CMMC Level 1

  • AC.L1-3.1.1Limit system access to authorized users
  • AC.L1-3.1.2Limit access to permitted transactions
  • IA.L1-3.5.1Identify system users and processes
  • MP.L1-3.8.3Sanitize media before disposal

How it runs

AI agents find. A named person confirms. One trail keeps both.

01

Read

Your tools request an approved control over MCP: the requirement text and its assessment objectives, at the version you chose.

02

Propose

The agent proposes a reference and a rationale: a commit, a PR, or a ticket with a sentence of context. Never a file.

03

Review

A named person confirms it, or the trail shows it is still unconfirmed. Review records a decision, not that the control is met.

04

Preserve

The trail keeps the request, the reference, the decision, the identity, the timestamp, and the hash link to the event before it.

The record

What one governed AI interaction leaves behind. A complete event chain from control read to human decision.

Audit trail · Corporate enclavetamper-evident

01 · Read82c4…1fget_control6.1.1Cursor · EngineeringAug 18, 09:41

02 · Proposec7d9…4aattest_control6.1.2PR #482Cursor · EngineeringAug 18, 09:44

03 · Review3fa1…82affirmed6.1.2DKDana K. · GRCAug 19, 08:12

04 · Preservechain head 3fa1…82 · verified nightly

Illustrative demo data. Each event carries the hash of the one before it, and a nightly check recomputes the chain. Verified means the record is intact, not that the control is met.

Set the source once. Approved agents use the same version everywhere.

Compliance owners set the program. Approved agents read it through one governed connection.

Corporate enclavesource

CMMC 2.0 Level 2v2

Implementation notes

Set by Compliance. Read by every approved agent.

1 connection·read-only · consented · revocable

1 connection·read-only · consented · revocableone governed door

Claudev2

Cursorv2

Geminiv2

Windsurfv2

The requirements your assessor will ask about.

Compliance owners choose the catalog and its version and write the implementation notes agents will read.

Frameworks

Your agents read it where they already work.

One governed connection, revocable in a click. Agents read the approved content and propose traceable references.

Connect an agent

Simple pricing by system boundary. Per enclave, not per person.

Every plan runs the same platform. You pay only for the enclaves you add.

Free

$0

one enclave, two people, three agent connections, forever

Start free

Additional enclave

$699

per added enclave, per month

Get started

Enterprise

Custom

terms and onboarding

Talk to usEmail hello@nizh.com

The platform, in every plan

  • Every framework, with versioned catalogs and objectivesIncluded in every plan
  • MCP access for AI agents: read-only, consented, auditedIncluded in every plan
  • Hash-chained audit trail, verifiable end to endIncluded in every plan

What each plan holds

  • Enclaves
    Free
    One, free forever
    Additional enclave
    Your free one, plus what you add
    Enterprise
    Custom
  • People
    Free
    Two, no card required
    Additional enclave
    Unlimited
    Enterprise
    Unlimited
  • AI agent connections
    Free
    3
    Additional enclave
    10 per added enclave
    Enterprise
    Unlimited
  • Custom framework onboarding
    Free
    Not included
    Additional enclave
    Not included
    Enterprise
    Your framework, onboarded with you
FeatureFree$0one enclave, two people, three agent connections, foreverStart freeAdditional enclave$699per added enclave, per monthGet startedEnterpriseCustomterms and onboardingTalk to usEmail hello@nizh.com
The platform, in every plan
Every framework, with versioned catalogs and objectivesIncludedIncludedIncluded
MCP access for AI agents: read-only, consented, auditedIncludedIncludedIncluded
Hash-chained audit trail, verifiable end to endIncludedIncludedIncluded
What each plan holds
EnclavesOne, free foreverYour free one, plus what you addCustom
PeopleTwo, no card requiredUnlimitedUnlimited
AI agent connections310 per added enclaveUnlimited
Custom framework onboardingNot includedNot includedYour framework, onboarded with you

Your first enclave is free forever. Add enclaves when you need them. Archiving one ends its billing.

Frequently asked questions

What exactly does Nizh prove?

Three facts: which control an agent read and when, what reference it proposed, and whether a named person confirmed it. Nizh proves the activity and the integrity of the record. It does not decide whether your organization is compliant.

What does human review mean?

A named person in your organization confirms a proposed reference against the control it was proposed for. The trail records who, when, and what they saw. Review is a decision about the reference, not a certification of the control.

What does it cost?

Your first enclave is free forever, with two people. Each enclave you add is one monthly price, shown on the plans above, with unlimited people and ten more agent connections. Every framework is included; nothing is priced per seat.

What counts as an enclave?

One system boundary, as you would present it to an assessor: a product, a platform, an environment, a machine. Each enclave carries its own assessments, evidence, and audit trail, because an examination is about one defined system. That is also why one enclave should not hold several.

Do you store our files or CUI?

No. There is no file storage and no ingestion path. What you keep in Nizh is text you write. A breach cannot disclose documents we never received.

How do AI agents connect?

One read-only connection per organization, over OAuth 2.1 with PKCE. It covers every framework you run, every call lands on the audit trail, and any grant is revocable in one click.

Does an AI provider receive our control content?

Not from Nizh. When your authorized agent requests a control, the provider running that agent receives what it asked for, under your agreement with that provider. You choose which agents are authorized, and you can revoke any of them in a click.

Can an agent change our program?

No. A connection is read-only unless you tick one extra box when you approve it. Even then, an agent can add only an attestation: a commit, a PR, or a ticket link, with a sentence of context. It cannot alter your control text, your statuses, or the audit trail. Its attestation counts for nothing until a named person affirms it.

Which catalog versions are supported?

CMMC 2.0 Level 1 and Level 2 (NIST SP 800-171 Rev 2), NIST SP 800-53 Rev 5, FedRAMP Moderate Rev 5, SOC 2 (2017 TSC), ISO/IEC 27001:2022, and HIPAA (45 CFR Part 164). Each is a versioned catalog: a new revision is a new version, never a silent edit.

Can I export the audit trail?

Yes. The portal's audit view exports the trail as a CSV, under whatever filters you have applied. What you see is what you export.

Does Nizh replace Vanta or Drata?

No, and it is not trying to. Certification platforms automate evidence collection for audits. Nizh governs what your AI agents read and records what came of it, on a tamper-evident trail. Teams run both side by side.

Do you support SSO or SCIM?

Not yet. Access is per-user, by email invitation. Sign-in is a one-time code sent to your email. Nizh never asks you to create a password and has no password field anywhere in the product.

Where does our data live?

Durable data lives in a United States region database. Compute runs at the edge, best-effort US. If you need contractually US-only compute, tell us before you buy.

What happens if we stop paying?

AI-agent access closes and the free project wall applies again: one project per member, existing projects untouched. Your assessments stay readable. A compliance record you can no longer read is not a record.

Engage

Put every AI control read on the record.

Start free

CMMC 2.0 Level 1

CMMC 2.0 Level 2

NIST SP 800-171

SOC 2

ISO/IEC 27001

FedRAMP Moderate

HIPAA

{"@context":"https://schema.org","@type":"Organization","name":"Nizh","legalName":"Nizh, LLC","url":"https://nizh.com","description":"Nizh, LLC delivers governance and control awareness for AI: compliance programs your team and your AI agents work from, with a tamper-evident record.","founder":{"@type":"Person","name":"Brian Nezhad","jobTitle":"Co-Founder & CEO"},"sameAs":["https://www.linkedin.com/company/nizh","https://github.com/orgs/nizh0","https://x.com/NizhHQ"]}