ISMS Copilot

Last updated: 2026-10-07 · Audience: engineers wiring coding agents and automation pipelines

Give your coding agent a compliance sub-agent

Your coding agent is fluent. It is not grounded. When the work touches access controls, DPIA screening, or a vendor review, the difference between a correct control reference and one that sounds right is the framework edition actually loaded in the prompt. Wire the ISMS Copilot API into your agent as the compliance step, and the framework loads before the model speaks.

The short version

  • A sub-agent is a step, not a persona. Your orchestrator keeps a general model for code and calls this API for compliance questions, from any script or SDK that speaks the OpenAI API.
  • The server grounds it. By default, when a framework is named or pinned, curated modules from a maintained registry of 132+ compliance frameworks are injected at inference, and the response discloses which ones ran.
  • Pin the framework per task. Auto-detection does not read system prompts, so an agent loop pins exact catalog ids and always answers from the framework it meant.

What the sub-agent is for

A sub-agent is a step your orchestrator trusts with one class of question. This one answers compliance questions with a maintained reference, while your main model stays general.

Review work that touches controls

A pull request moves authentication or logging. Ask the sub-agent what ISO 27001:2022 or SOC 2 expects there before a human reviews it. The answer arrives with the framework module already in the prompt, and the response says which module ran.

Draft control mappings and summaries

Map a vendor control set to your framework, draft Annex A statements, summarize what a clause asks for. The sub-agent answers from the curated module, not from whatever the base model remembers about an edition it may never have seen.

Triage steps in automation

DPIA screening questions, NIS 2 applicability checks, GDPR lawfulness first passes inside a pipeline. Each step is one completion with the right module pinned, so the pipeline stays explicit about the framework edition it used.

Policy pre-checks before an auditor does

Run draft policies past the sub-agent before the real review. It is guidance, not an audit opinion, but it can flag control-number and edition issues for human review.

The pattern that always works: a sub-agent step

One honest constraint first: the endpoint is text-only and rejects tool and function definitions. Tool-using agent modes cannot run on it directly. So the universal shape is the one below: your agent keeps its tools and its general model, and calls the compliance step with plain messages, pinning the frameworks for the task.

from openai import OpenAI

client = OpenAI(
    base_url="https://api.ismscopilot.com/v1",
    api_key="sk-isms-...",
)

resp = client.chat.completions.create(
    model="isms-thinking",
    messages=[
        {"role": "user", "content": "Does this PR description affect ISO 27001 Annex A access controls? Name the controls."}
    ],
    extra_body={"ismscopilot": {"frameworks": ["ISO_27001"]}},
)
print(resp.choices[0].message.content)

The three facts every OpenAI-compatible client needs: base URL https://api.ismscopilot.com/v1, key sk-isms from platform.ismscopilot.com/keys, model alias isms-fast or isms-thinking (plus -eu twins). Wrap that call in a script your harness can run, and the sub-agent exists.

Cline: the step as a workspace rule

Pointing Cline's agent at the endpoint means requests that carry its tool definitions: Cline's inspected implementation (main branch, ai-sdk.ts, checked 2026-09-28) passes the agent's tool set into the model request, and the AI SDK's OpenAI-compatible provider sends those tool definitions with the request. This text-only endpoint rejects requests that carry tool definitions, so this setup is not supported: use the step pattern below instead. Do not set the endpoint as Cline's OpenAI Compatible provider. The working shape is the sub-agent step with Cline as the runner: commit a compliance script and a workspace rule that tells Cline to run the script through its built-in run_commands tool when a task touches a control question. Create a key at platform.ismscopilot.com/keys, export it as ISMS_API_KEY, and add two files to the repo.

.clinerules/isms-compliance.md

# Compliance questions go through the sub-agent

For any question about controls, control numbers, framework editions, or
regulatory mappings (ISO 27001, SOC 2, NIST, GDPR, NIS 2, and similar), do
not answer from the model's own knowledge.

Run:
bash scripts/isms-compliance.sh '<question>' '<FRAMEWORK_ID>'

Example:
bash scripts/isms-compliance.sh 'Which Annex A control covers acceptable use of information and assets?' ISO_27001

Pass the question as one single-quoted shell argument (escape embedded single quotes); never build the command by interpolating raw question text into a double-quoted string.
Use the script's answer and its framework disclosure in your response. If
the script fails or ISMS_API_KEY is unset, say so and hand the question to
a human reviewer instead of guessing.

scripts/isms-compliance.sh

#!/usr/bin/env bash
set -euo pipefail
question="${1:?usage: scripts/isms-compliance.sh \"<question>\" [FRAMEWORK_ID]}"
framework="${2:-ISO_27001}"

payload=$(python3 - "$framework" "$question" <<'PY'
import json, sys
print(json.dumps({
    "model": "isms-fast",
    "messages": [{"role": "user", "content": sys.argv[2]}],
    "ismscopilot": {"frameworks": [sys.argv[1]]},
}))
PY
)

hdr=$(mktemp)
trap 'rm -f "$hdr"' EXIT
curl -sS -D "$hdr" https://api.ismscopilot.com/v1/chat/completions \
  -H "Authorization: Bearer ${ISMS_API_KEY:?set ISMS_API_KEY to your sk-isms key}" \
  -H "Content-Type: application/json" \
  -d "$payload" \
| python3 -c 'import json,sys; print(json.load(sys.stdin)["choices"][0]["message"]["content"])'

echo "disclosure:"
grep -i '^x-isms-frameworks:' "$hdr"
rm -f "$hdr"

The rule instructs Cline to answer control questions from the script's output rather than its own recall; on a successful call the script output lands the answer and the x-isms-frameworks disclosure header in the transcript, so the record of which curated framework modules were injected is right there in the task output. Rules live in .clinerules/ (or .cline/rules/) at the project root, and Cline can run tools with approval or auto-approval depending on settings; approve it when prompted.

Direct model configs (text-only, no tools)

Some harnesses can also use the endpoint as a model directly, for plain chat or review flows that send no tool definitions. Where a tool works without function calling, this is the fastest setup. Tool-dependent modes should use the sub-agent step above instead: Cline's agents and opencode's default Build agent both run on tools (per their own docs). For Cursor's Agent mode, the public docs were not re-verifiable from here on 2026-09-28, so the Cursor config below stays caveated. Cline's full recipe is in that section.

opencode

Register an OpenAI-compatible provider. Do not set it as the global model: opencode's built-in agents send tool definitions this endpoint rejects. Use the alias for plain chat turns, or point a custom agent with tools disabled at it. Create a key at platform.ismscopilot.com/keys, export it as ISMS_API_KEY, and add this to opencode.jsonc:

{
  "provider": {
    "ismscopilot": {
      "npm": "@ai-sdk/openai-compatible",
      "name": "ISMS Copilot",
      "options": {
        "baseURL": "https://api.ismscopilot.com/v1",
        "apiKey": "{env:ISMS_API_KEY}"
      },
      "models": {
        "isms-fast": { "name": "ISMS Copilot Fast" },
        "isms-thinking": { "name": "ISMS Copilot Thinking" }
      }
    }
  }
}

Continue

Add the endpoint as a chat model in Continue's config. Agent mode relies on tool calling and is not supported on this endpoint; use the chat role:

name: ISMS Copilot
version: 0.0.1
schema: v1

models:
  - name: ISMS Copilot Fast
    provider: openai
    model: isms-fast
    apiBase: https://api.ismscopilot.com/v1
    apiKey: ${{ secrets.ISMS_API_KEY }}
    roles:
      - chat

Continue resolves ${{ secrets.ISMS_API_KEY }} from a workspace .env, .continue/.env, or the global ~/.continue/.env before the process environment, so put the key in one of those files.

Aider

Aider can connect to any LLM served over an OpenAI-compatible API endpoint. This endpoint is an OpenAI-compatible (text-only) subset, and Aider's edit formats work from plain model responses (search and replace blocks, whole-file rewrites), so Aider can be configured on it for text-only edit flows:

export OPENAI_API_BASE=https://api.ismscopilot.com/v1
export OPENAI_API_KEY=sk-isms-...

aider --model openai/isms-fast

Aider will warn when working with a model it is not familiar with; that warning is expected for the isms aliases.

Cursor (caveated)

Cursor exposes an OpenAI API key setting with an Override OpenAI Base URL option. It is a global override with compatibility limitations, not a verified integration for arbitrary OpenAI-compatible endpoints, and tool-using Agent mode will not work. If you use it: enter the key, enable the override, set it to the base URL above, add the exact alias as a custom model, and disable the override before switching back to Cursor-hosted models. The sub-agent step is the more reliable shape.

Claude Code cannot point directly at an OpenAI-compatible endpoint for its model backend; see the FAQ for the two real options. Harness settings move; the three facts above and the docs guide stay current.

Pin the framework, do not hope for detection

Auto-detection scans the user messages and the last assistant turn, not the system prompt. In a harness, your instructions live in the system prompt, so auto can miss. Pin instead: send the ismscopilot extension with exact catalog ids, up to eight per call.

curl https://api.ismscopilot.com/v1/chat/completions \
  -H "Authorization: Bearer sk-isms-..." \
  -H "Content-Type: application/json" \
  -d '{
    "model": "isms-fast",
    "messages": [
      {"role": "user", "content": "Which ISO 27001:2022 Annex A control covers acceptable use of information and assets? One line."}
    ],
    "ismscopilot": {"frameworks": ["ISO_27001"]}
  }'

Verified on 2026-08-25, that request returns the right control (A.5.10) with the disclosure on the response: header x-isms-frameworks: ISO_27001 and an ismscopilot object listing the injected modules and their knowledge size. Log the disclosure per request as evidence of which modules grounded each step. Valid ids come from GET /v1/frameworks.

The knowledge is maintained, and the catalog is public

The registry behind the injection is a maintained artifact, not a one-time corpus. Modules are added and re-verified by scheduled workflows, modules carry version metadata, and the public catalog endpoint is generated from the same registry the API injects from. The catalog listed 132 modules on 2026-10-07, from ISO 27001, 27002, 27701 and 42001 through SOC 2, the NIST families, CMMC and FedRAMP, to GDPR, DORA, the EU AI Act, TISAX, HDS, SecNumCloud, and per-country NIS 2 transpositions. Treat the live endpoint as authoritative; counts move as modules ship.

That is the whole trade: your side of the bargain is a base URL and a pinned id. Amendments, editions, and new jurisdictions are the vendor's scheduled work.

Honest limits

  1. 1.Text in, text out

    The endpoint speaks the OpenAI chat completions subset: text messages, streaming, usage. It does not accept tool or function definitions, JSON mode, logprobs, n above 1, or multimodal parts. The sub-agent gets grounded generation, not tool use. Your harness keeps its own tools.

  2. 2.Detection is name-level, and it does not read your system prompt

    Auto mode scans the user messages and the last assistant turn. A bare control id like 5.23 injects nothing. Harness instructions usually live in the system prompt, which auto does not scan at all. In an agent loop, pin the frameworks explicitly.

  3. 3.Thinking has a floor

    Thinking aliases are for harder questions and floor max_tokens at 1024 when a lower value is sent, surfaced in response headers. Fast answers cost the same unit rate and are usually enough for a review step.

  4. 4.Guidance, not an audit opinion

    Answers are educational compliance guidance with the module disclosed. Risk acceptance and anything a regulation assigns to a person or a management body stay with you.

Get started

  1. 1. Create a key. Sign in at platform.ismscopilot.com/keys, top up prepaid credits, and set a per-key spend cap if the agent runs unattended.
  2. 2. List the catalog. GET https://api.ismscopilot.com/v1/frameworks is public. Pick the ids your agent will pin.
  3. 3. Wire the compliance step. Use the sub-agent pattern or a config above; the docs guide has step-by-step settings per tool.
  4. 4. Pin, do not guess. Start every compliance step with an explicit ismscopilot.frameworks pin and log the disclosure headers. That log is your evidence of which framework grounded each step.

Frequently asked questions

Is the framework knowledge built into the model?

No. Nothing here is fine-tuned or baked into model weights. Curated framework modules are injected into the prompt at inference time, before generation, and the response discloses which modules ran. Grounding you can verify beats recall you cannot see.

Can Claude Code use it as its model?

Not directly. Claude Code speaks the Anthropic API shape for its model backends, and this is an OpenAI-compatible chat completions endpoint. Real options: have Claude Code call the API as a sub-agent step (curl or SDK inside a script it runs), or use ISMS Copilot for Agents, the account MCP product, which is a different plane (your account and chat subscription, not model inference).

Can my coding agent be the primary model on this endpoint?

Only for text-only flows. The endpoint rejects requests that carry tool or function definitions; Cline's main-branch implementation passes the agent's tool set into its model requests (inspected 2026-09-28), so its agent flow is not supported as the model. Two working shapes: call it as a sub-agent step from a script, or configure a harness chat mode that sends plain messages without tools. Cline has a full script-and-rule recipe in the sub-agent step section above.

Do I need to build retrieval for this?

No. That is the point. The service selects and injects the framework module server-side, from a maintained registry, and you can pin exact catalog ids per call. You do not maintain a chunker, an embedding store, or a version watch.

What does it cost to run as a sub-agent?

Prepaid credits on the platform console, separate from any chat subscription, with optional per-key spend caps so a runaway loop cannot burn the balance. Rates are listed in the console, which stays the source of truth for numbers.

Is there an EU path?

Yes. The isms-fast-eu and isms-thinking-eu aliases route to the EU path with Mistral under EU data-protection terms, and responses carry the processing region in a header.

Where do my prompts and outputs go?

Nowhere as customer records. The API layer stores no prompts or model outputs; usage history is metadata only (tokens, cost, model, status). Upstream paths on both global and EU aliases are configured for zero retention of request content. Details live in the Zero Data Retention docs.

Primary sources

  • ISMS Copilot API documentation (live product truth: endpoint, keys, credits, models). docs.ismscopilot.com (checked 2026-10-07).
  • Use the API in coding agents (docs guide: sub-agent pattern, configs, pinning, limits). docs.ismscopilot.com (checked 2026-10-07).
  • API framework knowledge (what is injected, auto/none/pin, honest limits). docs.ismscopilot.com (checked 2026-10-07).
  • Public frameworks catalog on the model API (GET /v1/frameworks; count verified on this page's last-updated date). api.ismscopilot.com (checked 2026-10-07).
  • Why the ISMS Copilot API instead of any model (the full developer argument). www.ismscopilot.com (checked 2026-10-07).
  • Cline rules documentation (workspace rules in .clinerules/ or .cline/rules/, recognized rule types; checked 2026-09-25). docs.cline.bot (checked 2026-10-07).
  • Cline OpenAI Compatible provider documentation (Base URL, API Key, Model ID settings the recipe deliberately does not use; checked 2026-09-25). docs.cline.bot (checked 2026-10-07).
  • Cline tools reference (built-in run_commands tool, execute shell commands; the model calls tools and Cline runs them; approval or auto-approval per settings; checked 2026-10-07). docs.cline.bot (checked 2026-10-07).
  • Cline source, main branch: sdk/packages/llms/src/providers/ai-sdk.ts passes the agent's tool set into the streamText model request; the OpenAI-compatible vendor is built on @ai-sdk/openai-compatible (checked 2026-09-28). github.com (checked 2026-10-07).
  • AI SDK docs: OpenAI-compatible provider capabilities (tool calling, call tools/functions with streaming support, for chat models built on createOpenAICompatible; checked 2026-09-28). ai-sdk.dev (checked 2026-10-07).
  • opencode docs: agents (Build, the default primary agent, has all tools enabled; tool access configured via permissions; checked 2026-09-28). opencode.ai (checked 2026-10-07).
  • opencode docs: custom OpenAI-compatible providers (@ai-sdk/openai-compatible, options.baseURL/apiKey, {env:VAR} interpolation, opencode.json/.jsonc; checked 2026-09-28). opencode.ai (checked 2026-10-07).
  • Continue docs: OpenAI provider configuration (config.yaml apiBase override for OpenAI-compatible endpoints; checked 2026-09-28). docs.continue.dev (checked 2026-10-07).
  • Continue docs FAQ: how to reference secrets in config.yaml (${{ secrets.X }} resolution order; checked 2026-09-28). docs.continue.dev (checked 2026-10-07).
  • Aider docs: OpenAI compatible APIs (OPENAI_API_BASE/OPENAI_API_KEY, openai/ model prefix, unfamiliar-model warnings; checked 2026-09-28). aider.chat (checked 2026-10-07).
  • Aider docs: edit formats (whole and diff work from plain model responses; checked 2026-09-28). aider.chat (checked 2026-10-07).

Written and maintained by the ISMS Copilot team for engineers wiring coding agents. Last reviewed 2026-10-07.

This is a product argument, not legal advice and not a pricing quote. Capabilities, retention posture, and commercial terms are defined by live docs, the Trust Center, and the platform console. Where this page summarises those surfaces, the live surface wins on drift.