US compliance
What is evidenced. And what is not yet.
This page claims no certification that does not exist. Per framework it states what the audit record delivers, the state of the evidence, and where it comes from.
| Framework | What the audit record delivers | State | Source |
|---|---|---|---|
| GDPR | Masking before egress, a decision record per prompt, export as CSV, JSON or PDF. | evidenced | Masking before egress, a per-prompt decision record and export are described in the operator handbook and are part of the product. |
| EU AI Act | An evidence chain over classification and routing, documented per decision. | evidenced | Every routing decision is documented; the logs are immutable and contain no PII. Described in the operator handbook. |
| HIPAA | PHI is detected and masked as a data class. No certification is held. | partial | PHI is detected and masked as a data class. No HIPAA certification is held, and none is claimed here. |
| SOC 2 | — | on the roadmap | Carried as a roadmap item. No certification held. |
| ISO 27001 | — | on the roadmap | Carried as a roadmap item. No certification held. |
| CCPA | — | not yet evidenced | No implementation and no certification. We claim nothing here. |
| GLBA | — | not yet evidenced | No implementation and no certification. We claim nothing here. |
| NIST AI RMF | — | not yet evidenced | No implementation and no certification. We claim nothing here. |
| CMMC | — | not yet evidenced | No implementation and no certification. We claim nothing here. |
| FedRAMP | — | not yet evidenced | No implementation and no certification. We claim nothing here. |
Why this page looks like this
A compliance page that claims everything is worthless at the first audit. This one names four states and, per row, what evidences it, and "not yet evidenced" is a permissible statement. Anyone who wants to move a row up supplies the evidence. The table is machine-checked on every release: a row in state "evidenced" without a source does not go live.
