containment.ai — Brief 03: AARM v1.0 alignment. Status of record: www.containment.ai/trust.html
BRIEF 03 — FOR A COMPLIANCE OR RISK OWNER

Aligned with AARM v1.0. Not certified against it.

A neutral specification is more useful to you than our marketing. This brief states which AARM v1.0 requirements our self-attestation records as satisfied, which one is still a gap, which is out of scope, and where the diffable record lives.

What AARM is

AARM — Autonomous Action Runtime Management — is the Cloud Security Alliance’s specification for governing autonomous AI agents at runtime. It was authored at Vanta, donated to the CSAI Foundation in April 2026, and is governed by a working group spanning Microsoft, Vanta, Noma Security, Zenity, Elastic, Truist and Darktrace. It gives a compliance owner a neutral yardstick to hold a vendor to, instead of the vendor’s own marketing.

Our claim, stated precisely

We publish “aligned with AARM v1.0”not a certification. AARM has no certification body and we hold no attestation from a third party against it. What exists is our own self-attestation, published as a document you can diff.

Our current self-attestation records R1–R6 as satisfied at the Core level and R8 as satisfied, with R7 still a gap and R9 out of scope for our architecture. That document is the record, and it outranks this brief.

Read the self-attestation →

Status by requirement

R1 – R6   SATISFIEDAt the Core level, per our self-attestation. R8   SATISFIEDPer our self-attestation. R7   GAPStated as an open gap rather than closed on paper. R9   OUT OF SCOPENot applicable to our architecture; declared rather than quietly omitted.

The five decision verbs

AARM R4 defines five decisions. All five ship today: ALLOW, DENY, MODIFY, STEP_UP, DEFER. The ruling is returned by deterministic policy over a canonical input — no AI model makes the enforcement decision — and each governed outcome produces a product-specific decision record.

Four questions to ask any vendor, including us

1   Is every governed action intercepted before execution, or observed after? A log is not a control.
2   What does policy see at evaluation time, and is the decision deterministic?
3   What decision evidence is produced, and what is required to re-evaluate it later?
4   Which requirements are claimed as satisfied, which are gaps, and where is that written down?
Containment.ai is pre-ATO and holds no completed certification or authorization. No independent audit report exists. Current product and assurance status is stated in full on the Trust record — versioned, dated, and it outranks this brief.
Print this page or save it as PDF to forward it — the site chrome drops out and it sets as a document.