Partner pilot · Ecosystem

Validate your mappings against the Apeiris corpus

Send us your control-to-framework mappings. We validate each one against the open Apeiris corpus and return a private report: which mappings we agree with, which extend our coverage, which look mis-cited, and — the part partners find most useful — what your set is missing.

This is a white-glove pilot: we run the analysis and hand you the report directly. It is an analysis aid, not an audit or certification.

What you can submit

Two kinds of rows, in one file.

Crosswalks

Your own mapping of an Apeiris control to a framework requirement — “we think control X corresponds to Article Y of framework Z.”

Trust-votes

Your assessment of one of our existing mappings — “your mapping of control X to requirement Y should be graded differently.”

You don't need to cover everything — send the subset you care about (a single framework, a domain, or a full set up to ~2,000 rows). Browse control identifiers at Domains & controls or the Knowledge Graph.

Prepare your file

CSV or JSON. Start from a template.

Use CSV (easiest from a spreadsheet or GRC export) or JSON. Download a ready-to-edit template:

Crosswalk fields

ColumnReq.Allowed values / notes
kindcrosswalk
control_refThe Apeiris control URI: apeiris://<domain>/controls/<ID> (e.g. apeiris://security/controls/IA-01).
frameworkThe framework you're citing (e.g. eu_ai_act, iso_42001, nist_ai_rmf, owasp_aisvs). A name we can resolve is fine.
requirement_idThe exact clause/article id (e.g. Article 15, A.6.2.2). It must be a real citation — we verify it against the framework's primary text.
fitdirect · supporting · partial · adjacent
relationsatisfies (a binding obligation) · equivalent_to (a control in another standard) · defends_against (a threat) · informs (guidance)
normative_forcebinding-law · regulation · supervisory-guidance · certification-standard · voluntary-standard · industry-framework · best-practice · informative-reference
mapping_confidencehigh · medium · low
rationaleOne sentence on why the mapping holds. An unexplained mapping can't be reviewed.

Trust-vote fields

ColumnReq.Allowed values / notes
kindvote
mapping_refThe specific Apeiris mapping: apeiris://<domain>/controls/<ID>/frameworks/<framework>/<requirement_id>
verdictdirect · partial · supporting · adjacent (it holds at that strength) · conflicting (you dispute it) · invalid (the cited id doesn't support it)
confidencehigh · medium · low
rationaleOne sentence on why.

CSV must be UTF-8; wrap any value containing a comma or quote in double-quotes. Leave optional columns blank if unused. Do not include secrets, credentials, personal data, or client-identifying information in any field — send only the mappings themselves.

Example — crosswalk CSV
kind,control_ref,framework,requirement_id,fit,relation,normative_force,mapping_confidence,rationale
crosswalk,apeiris://security/controls/IA-01,eu_ai_act,Article 15,partial,satisfies,binding-law,medium,"Per-agent distinct identity contributes to the Article 15 obligation but does not by itself satisfy it."
crosswalk,apeiris://identity/controls/II-01,nist_ai_rmf,GOVERN 1.2,supporting,informs,voluntary-standard,medium,"An agent identity registry supports the accountability structures in GOVERN 1.2."
What you get back

A private report — a verdict per row, plus a gap pass.

VerdictMeaning
agreesThe corpus already carries this mapping at the same strength (any fit difference is noted).
conflictingThe corpus maps it materially differently — we show both sides.
extends-corpusYour citation checks out and the corpus doesn't have it — you found a gap in our coverage.
invalidThe cited requirement id doesn't hold up against the framework's primary text (a likely mis-citation).
unverifiableWe haven't yet ingested that framework's primary text, so we can't machine-confirm the citation this round.

For trust-votes, we report whether your vote agrees with or disputes our mapping. And across your whole set, a “what you're missing” pass: the Apeiris controls, evidence requirements, and framework obligations relevant to what you submitted that your set doesn't yet cover.

How your data is handled

Private by default.

Private. Your file and the report stay between us. They are never published, added to a public page, or shared with another party.

The corpus is never edited from your upload. Where your mappings disagree with ours, they become candidate findings we review — your submission never changes the published corpus on its own.

Verify us back. Everything we cite resolves to a public Apeiris control URI you can check yourself, and every published artifact is independently verifiable.

Ready to submit?

Prepare your .csv or .json and send it to your Apeiris contact via the secure channel we set up with you. Not in the pilot yet? Get in touch and we'll arrange a secure drop before you send anything.

Contact us   Apeiris for partners

The self-serve, authenticated web workspace — upload in the browser, saved reports, your own gap dashboard — is on our roadmap. This page covers the white-glove pilot available today.