Skip to main content

US compliance

What is evidenced. And what is not yet.

This page claims no certification that does not exist. Per framework it states what the audit record delivers, the state of the evidence, and where it comes from.

FrameworkWhat the audit record deliversStateSource
GDPRMasking before egress, a decision record per prompt, export as CSV, JSON or PDF.evidencedMasking before egress, a per-prompt decision record and export are described in the operator handbook and are part of the product.
EU AI ActAn evidence chain over classification and routing, documented per decision.evidencedEvery routing decision is documented; the logs are immutable and contain no PII. Described in the operator handbook.
HIPAAPHI is detected and masked as a data class. No certification is held.partialPHI is detected and masked as a data class. No HIPAA certification is held, and none is claimed here.
SOC 2on the roadmapCarried as a roadmap item. No certification held.
ISO 27001on the roadmapCarried as a roadmap item. No certification held.
CCPAnot yet evidencedNo implementation and no certification. We claim nothing here.
GLBAnot yet evidencedNo implementation and no certification. We claim nothing here.
NIST AI RMFnot yet evidencedNo implementation and no certification. We claim nothing here.
CMMCnot yet evidencedNo implementation and no certification. We claim nothing here.
FedRAMPnot yet evidencedNo implementation and no certification. We claim nothing here.

Why this page looks like this

A compliance page that claims everything is worthless at the first audit. This one names four states and, per row, what evidences it, and "not yet evidenced" is a permissible statement. Anyone who wants to move a row up supplies the evidence. The table is machine-checked on every release: a row in state "evidenced" without a source does not go live.