

<!DOCTYPE html>

<html lang="en-US">
<head>
  <meta charset="UTF-8">
  <meta http-equiv="X-UA-Compatible" content="IE=Edge">

  <link rel="stylesheet" href="/ossasai/assets/css/just-the-docs-default.css">

  <link rel="stylesheet" href="/ossasai/assets/css/just-the-docs-head-nav.css" id="jtd-head-nav-stylesheet">

  <style id="jtd-nav-activation">
  
    .site-nav ul li a {
      background-image: none;
    }

  </style>

  

  
    <script src="/ossasai/assets/js/vendor/lunr.min.js"></script>
  

  <script src="/ossasai/assets/js/just-the-docs.js"></script>

  <meta name="viewport" content="width=device-width, initial-scale=1">

  



  <!-- Begin Jekyll SEO tag v2.8.0 -->
<title>OSSASAI | Open Security Standard for Agentic Systems - A vendor-neutral security framework for AI agents</title>
<meta name="generator" content="Jekyll v4.4.1" />
<meta property="og:title" content="OSSASAI" />
<meta property="og:locale" content="en_US" />
<meta name="description" content="Open Security Standard for Agentic Systems - A vendor-neutral security framework for AI agents" />
<meta property="og:description" content="Open Security Standard for Agentic Systems - A vendor-neutral security framework for AI agents" />
<link rel="canonical" href="https://gensecaihq.github.io/ossasai/assets/css/just-the-docs-head-nav.css" />
<meta property="og:url" content="https://gensecaihq.github.io/ossasai/assets/css/just-the-docs-head-nav.css" />
<meta property="og:site_name" content="OSSASAI" />
<meta property="og:type" content="website" />
<meta name="twitter:card" content="summary" />
<meta property="twitter:title" content="OSSASAI" />
<script type="application/ld+json">
{"@context":"https://schema.org","@type":"WebPage","description":"Open Security Standard for Agentic Systems - A vendor-neutral security framework for AI agents","headline":"OSSASAI","url":"https://gensecaihq.github.io/ossasai/assets/css/just-the-docs-head-nav.css"}</script>
<!-- End Jekyll SEO tag -->


  

</head>

<body>
  <a class="skip-to-main" href="#main-content">Skip to main content</a>
  <svg xmlns="http://www.w3.org/2000/svg" class="d-none">
  <symbol id="svg-link" viewBox="0 0 24 24">
  <title>Link</title>
  <svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="feather feather-link">
    <path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path>
  </svg>
</symbol>

  <symbol id="svg-menu" viewBox="0 0 24 24">
  <title>Menu</title>
  <svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="feather feather-menu">
    <line x1="3" y1="12" x2="21" y2="12"></line><line x1="3" y1="6" x2="21" y2="6"></line><line x1="3" y1="18" x2="21" y2="18"></line>
  </svg>
</symbol>

  <symbol id="svg-arrow-right" viewBox="0 0 24 24">
  <title>Expand</title>
  <svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="feather feather-chevron-right">
    <polyline points="9 18 15 12 9 6"></polyline>
  </svg>
</symbol>

  <!-- Feather. MIT License: https://github.com/feathericons/feather/blob/master/LICENSE -->
<symbol id="svg-external-link" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="feather feather-external-link">
  <title id="svg-external-link-title">(external link)</title>
  <path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"></path><polyline points="15 3 21 3 21 9"></polyline><line x1="10" y1="14" x2="21" y2="3"></line>
</symbol>

  
    <symbol id="svg-doc" viewBox="0 0 24 24">
  <title>Document</title>
  <svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="feather feather-file">
    <path d="M13 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V9z"></path><polyline points="13 2 13 9 20 9"></polyline>
  </svg>
</symbol>

    <symbol id="svg-search" viewBox="0 0 24 24">
  <title>Search</title>
  <svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="feather feather-search">
    <circle cx="11" cy="11" r="8"></circle><line x1="21" y1="21" x2="16.65" y2="16.65"></line>
  </svg>
</symbol>

  
  
    <!-- Bootstrap Icons. MIT License: https://github.com/twbs/icons/blob/main/LICENSE.md -->
<symbol id="svg-copy" viewBox="0 0 16 16">
  <title>Copy</title>
  <svg xmlns="http://www.w3.org/2000/svg" width="16" height="16" fill="currentColor" class="bi bi-clipboard" viewBox="0 0 16 16">
    <path d="M4 1.5H3a2 2 0 0 0-2 2V14a2 2 0 0 0 2 2h10a2 2 0 0 0 2-2V3.5a2 2 0 0 0-2-2h-1v1h1a1 1 0 0 1 1 1V14a1 1 0 0 1-1 1H3a1 1 0 0 1-1-1V3.5a1 1 0 0 1 1-1h1v-1z"/>
    <path d="M9.5 1a.5.5 0 0 1 .5.5v1a.5.5 0 0 1-.5.5h-3a.5.5 0 0 1-.5-.5v-1a.5.5 0 0 1 .5-.5h3zm-3-1A1.5 1.5 0 0 0 5 1.5v1A1.5 1.5 0 0 0 6.5 4h3A1.5 1.5 0 0 0 11 2.5v-1A1.5 1.5 0 0 0 9.5 0h-3z"/>
  </svg>
</symbol>
<symbol id="svg-copied" viewBox="0 0 16 16">
  <title>Copied</title>
  <svg xmlns="http://www.w3.org/2000/svg" width="16" height="16" fill="currentColor" class="bi bi-clipboard-check-fill" viewBox="0 0 16 16">
    <path d="M6.5 0A1.5 1.5 0 0 0 5 1.5v1A1.5 1.5 0 0 0 6.5 4h3A1.5 1.5 0 0 0 11 2.5v-1A1.5 1.5 0 0 0 9.5 0h-3Zm3 1a.5.5 0 0 1 .5.5v1a.5.5 0 0 1-.5.5h-3a.5.5 0 0 1-.5-.5v-1a.5.5 0 0 1 .5-.5h3Z"/>
    <path d="M4 1.5H3a2 2 0 0 0-2 2V14a2 2 0 0 0 2 2h10a2 2 0 0 0 2-2V3.5a2 2 0 0 0-2-2h-1v1A2.5 2.5 0 0 1 9.5 5h-3A2.5 2.5 0 0 1 4 2.5v-1Zm6.854 7.354-3 3a.5.5 0 0 1-.708 0l-1.5-1.5a.5.5 0 0 1 .708-.708L7.5 10.793l2.646-2.647a.5.5 0 0 1 .708.708Z"/>
  </svg>
</symbol>

  
</svg>

  
    <header class="side-bar">
  <div class="site-header">
    <a href="/ossasai/" class="site-title lh-tight">
  OSSASAI

</a>
    <button id="menu-button" class="site-button btn-reset" aria-label="Menu" aria-expanded="false">
      <svg viewBox="0 0 24 24" class="icon" aria-hidden="true"><use xlink:href="#svg-menu"></use></svg>
    </button>
  </div>

  <nav aria-label="Main" id="site-nav" class="site-nav">
  
  
    <ul class="nav-list"><li class="nav-list-item"><a href="/ossasai/" class="nav-list-link">Home</a></li><li class="nav-list-item"><button class="nav-list-expander btn-reset" aria-label="Specification submenu" aria-expanded="false">
        <svg viewBox="0 0 24 24" aria-hidden="true"><use xlink:href="#svg-arrow-right"></use></svg>
      </button><a href="/ossasai/spec/overview.html" class="nav-list-link">Specification</a><ul class="nav-list"><li class="nav-list-item"><a href="/ossasai/spec/assurance-levels.html" class="nav-list-link">Assurance Levels</a></li><li class="nav-list-item"><a href="/ossasai/spec/trust-boundaries.html" class="nav-list-link">Trust Boundaries</a></li><li class="nav-list-item"><a href="/ossasai/spec/compliance-workflow.html" class="nav-list-link">Compliance Workflow</a></li></ul></li><li class="nav-list-item"><button class="nav-list-expander btn-reset" aria-label="Threat Model submenu" aria-expanded="false">
        <svg viewBox="0 0 24 24" aria-hidden="true"><use xlink:href="#svg-arrow-right"></use></svg>
      </button><a href="/ossasai/threat-model/overview.html" class="nav-list-link">Threat Model</a><ul class="nav-list"><li class="nav-list-item"><a href="/ossasai/threat-model/adversary-classes.html" class="nav-list-link">Adversary Classes</a></li><li class="nav-list-item"><a href="/ossasai/threat-model/attack-vectors.html" class="nav-list-link">Attack Vectors</a></li><li class="nav-list-item"><a href="/ossasai/threat-model/ai-agent-threats.html" class="nav-list-link">AI Agent Threats</a></li><li class="nav-list-item"><a href="/ossasai/threat-model/risk-scoring.html" class="nav-list-link">Risk Scoring</a></li></ul></li><li class="nav-list-item"><button class="nav-list-expander btn-reset" aria-label="Controls submenu" aria-expanded="false">
        <svg viewBox="0 0 24 24" aria-hidden="true"><use xlink:href="#svg-arrow-right"></use></svg>
      </button><a href="/ossasai/controls/overview.html" class="nav-list-link">Controls</a><ul class="nav-list"><li class="nav-list-item"><a href="/ossasai/controls/general.html" class="nav-list-link">General (GEN)</a></li><li class="nav-list-item"><a href="/ossasai/controls/control-plane.html" class="nav-list-link">Control Plane (CP)</a></li><li class="nav-list-item"><a href="/ossasai/controls/identity-session.html" class="nav-list-link">Identity & Session (ID)</a></li><li class="nav-list-item"><a href="/ossasai/controls/tool-blast-radius.html" class="nav-list-link">Tool Blast Radius (TB)</a></li><li class="nav-list-item"><a href="/ossasai/controls/local-state.html" class="nav-list-link">Local State (LS)</a></li><li class="nav-list-item"><a href="/ossasai/controls/supply-chain.html" class="nav-list-link">Supply Chain (SC)</a></li><li class="nav-list-item"><a href="/ossasai/controls/formal-verification.html" class="nav-list-link">Formal Verification (FV)</a></li><li class="nav-list-item"><a href="/ossasai/controls/network-security.html" class="nav-list-link">Network Security (NS)</a></li></ul></li><li class="nav-list-item"><button class="nav-list-expander btn-reset" aria-label="Implementation submenu" aria-expanded="false">
        <svg viewBox="0 0 24 24" aria-hidden="true"><use xlink:href="#svg-arrow-right"></use></svg>
      </button><a href="/ossasai/implementation/quickstart.html" class="nav-list-link">Implementation</a><ul class="nav-list"><li class="nav-list-item"><a href="/ossasai/implementation/l1-deployment.html" class="nav-list-link">L1 Deployment</a></li><li class="nav-list-item"><a href="/ossasai/implementation/l2-deployment.html" class="nav-list-link">L2 Deployment</a></li><li class="nav-list-item"><a href="/ossasai/implementation/l3-deployment.html" class="nav-list-link">L3 Deployment</a></li><li class="nav-list-item"><a href="/ossasai/implementation/hardening-checklist.html" class="nav-list-link">Hardening Checklist</a></li><li class="nav-list-item"><a href="/ossasai/implementation/ci-cd-integration.html" class="nav-list-link">CI/CD Integration</a></li></ul></li><li class="nav-list-item"><button class="nav-list-expander btn-reset" aria-label="Testing submenu" aria-expanded="false">
        <svg viewBox="0 0 24 24" aria-hidden="true"><use xlink:href="#svg-arrow-right"></use></svg>
      </button><a href="/ossasai/testing/overview.html" class="nav-list-link">Testing</a><ul class="nav-list"><li class="nav-list-item"><a href="/ossasai/testing/automated-audit.html" class="nav-list-link">Automated Audit</a></li><li class="nav-list-item"><a href="/ossasai/testing/verification-procedures.html" class="nav-list-link">Verification Procedures</a></li><li class="nav-list-item"><a href="/ossasai/testing/penetration-testing.html" class="nav-list-link">Penetration Testing</a></li></ul></li><li class="nav-list-item"><button class="nav-list-expander btn-reset" aria-label="Compliance submenu" aria-expanded="false">
        <svg viewBox="0 0 24 24" aria-hidden="true"><use xlink:href="#svg-arrow-right"></use></svg>
      </button><a href="/ossasai/compliance/overview.html" class="nav-list-link">Compliance</a><ul class="nav-list"><li class="nav-list-item"><a href="/ossasai/compliance/evidence-collection.html" class="nav-list-link">Evidence Collection</a></li><li class="nav-list-item"><a href="/ossasai/compliance/reporting.html" class="nav-list-link">Reporting</a></li><li class="nav-list-item"><a href="/ossasai/compliance/continuous-monitoring.html" class="nav-list-link">Continuous Monitoring</a></li></ul></li><li class="nav-list-item"><button class="nav-list-expander btn-reset" aria-label="Incident Response submenu" aria-expanded="false">
        <svg viewBox="0 0 24 24" aria-hidden="true"><use xlink:href="#svg-arrow-right"></use></svg>
      </button><a href="/ossasai/incident-response/overview.html" class="nav-list-link">Incident Response</a><ul class="nav-list"><li class="nav-list-item"><a href="/ossasai/incident-response/playbooks.html" class="nav-list-link">Playbooks</a></li><li class="nav-list-item"><a href="/ossasai/incident-response/recovery.html" class="nav-list-link">Recovery</a></li><li class="nav-list-item"><a href="/ossasai/incident-response/post-incident.html" class="nav-list-link">Post-Incident Review</a></li></ul></li><li class="nav-list-item"><button class="nav-list-expander btn-reset" aria-label="Appendices submenu" aria-expanded="false">
        <svg viewBox="0 0 24 24" aria-hidden="true"><use xlink:href="#svg-arrow-right"></use></svg>
      </button><a href="/ossasai/appendices/glossary.html" class="nav-list-link">Appendices</a><ul class="nav-list"><li class="nav-list-item"><a href="/ossasai/appendices/changelog.html" class="nav-list-link">Changelog</a></li><li class="nav-list-item"><a href="/ossasai/appendices/standards-mapping.html" class="nav-list-link">Standards Mapping</a></li></ul></li><li class="nav-list-item"><button class="nav-list-expander btn-reset" aria-label="Profiles submenu" aria-expanded="false">
        <svg viewBox="0 0 24 24" aria-hidden="true"><use xlink:href="#svg-arrow-right"></use></svg>
      </button><a href="/ossasai/profiles/overview.html" class="nav-list-link">Profiles</a><ul class="nav-list"><li class="nav-list-item"><a href="/ossasai/profiles/openclaw.html" class="nav-list-link">OCSAS (OpenClaw)</a></li><li class="nav-list-item"><a href="/ossasai/profiles/registry.html" class="nav-list-link">Profile Registry</a></li></ul></li></ul>
  
</nav>


<div class="d-md-block d-none site-footer">
  
  
    This site uses <a href="https://github.com/just-the-docs/just-the-docs">Just the Docs</a>, a documentation theme for Jekyll.
  
  </div>
</header>

  
  <div class="main" id="top">
    <div id="main-header" class="main-header">
  
    

<div class="search" role="search">
  <div class="search-input-wrap">
    <input type="text" id="search-input" class="search-input" tabindex="0" placeholder="Search OSSASAI" autocomplete="off">
    <label for="search-input" class="search-label">
      <span class="sr-only">Search OSSASAI</span>
      <svg viewBox="0 0 24 24" class="search-icon" aria-hidden="true"><use xlink:href="#svg-search"></use></svg>
    </label>
  </div>
  <div id="search-results" class="search-results"></div>
</div>

  
  
  
    <nav aria-label="Auxiliary" class="aux-nav">
  <ul class="aux-nav-list">
    
      <li class="aux-nav-list-item">
        <a href="https://github.com/gensecaihq/ossasai" class="site-button"
          
          target="_blank" rel="noopener noreferrer"
          
        >
          GitHub
        </a>
      </li>
    
  </ul>
</nav>

  
</div>

    <div class="main-content-wrap">
      
      <div id="main-content" class="main-content">
        <main>
          
            <h.site-nav ul li a {
  background-image: linear-gradient(-90deg, rgb(234.8, 236.82, 244.9) 0%, rgba(234.8, 236.82, 244.9, 0.8) 80%, rgba(234.8, 236.82, 244.9, 0) 100%);
}

          

          
            
          
        </main>
        
<hr>
<footer>
  
    <p><a href="#top" id="back-to-top">Back to top</a></p>
  

  <p class="text-small mb-0">OSSASAI v0.2.0 - Open Security Standard for Agentic Systems. Apache 2.0 License.</p>

  <div class="d-md-none mt-4 fs-2">
    
    
      This site uses <a href="https://github.com/just-the-docs/just-the-docs">Just the Docs</a>, a documentation theme for Jekyll.
    
  </div>
</footer>

      </div>
    </div>
    
      

<div class="search-overlay"></div>

    
  </div>

  
</body>
</html>

