Public AI Governance Documentation

NIST AI RMF Alignment

How HireProxy maps current controls and next steps to Govern, Map, Measure, and Manage.

This document is a public governance summary. It does not publish raw AI instructions, exact internal eval cases, source code, tenant data, incident details, database schema, or provider-console settings.

Last reviewed: July 6, 2026

NIST describes the AI RMF Core as four functions: Govern, Map, Measure, and Manage. This document maps HireProxy's current controls and reasonable next steps to those functions. It is not a certification or external audit.

Govern

NIST intent: Establish accountability, policies, roles, risk culture, documentation, incident processes, and third-party risk management.

Current HireProxy controls:

Reasonable next controls:

Map

NIST intent: Understand the system context, intended use, users, benefits, risks, affected parties, data context, and deployment environment.

Current HireProxy controls:

Reasonable next controls:

Measure

NIST intent: Evaluate, test, monitor, and document AI risks, including trustworthiness, privacy, security, transparency, fairness, and reliability.

Current HireProxy controls:

Reasonable next controls:

Manage

NIST intent: Prioritize, respond to, reduce, transfer, monitor, or accept risks. Communicate incidents and errors. Deactivate or roll back systems when needed.

Current HireProxy controls:

Reasonable next controls: