COMPLIANCE — FRAMEWORK MAPPING

Enforcement evidence, mapped to the frameworks you answer to.

We operate at the runtime enforcement layer; your compliance program operates at the documentation layer. This page shows how product-specific decision records can support the frameworks you answer to — and where each item on our certification roadmap stands.

FIG. 1 — WHAT A DECISION RECORD CAN EVIDENCE
A ruling was recorded
Each governed outcome creates a product-specific decision record. Establishing operating effectiveness across a period also requires deployment scope, configuration, completeness, and control-testing evidence.
Receipt integrity can be checked
Gateway staging receipts support public signature verification and supplied-segment checks; connected-product signing and verification methods differ and are stated on Trust.
Policy can be re-evaluated when inputs are complete
A ruling can be re-evaluated only with the exact recorded input, context, and policy bundle. The public receipt verifier checks integrity; it does not re-run policy.
THE EVIDENCE WORKFLOW — DECISION RECORDS ACCUMULATE IN THE AUDIT PLANE EXPORT TO YOUR GRC / SIEM AUDITOR SAMPLES & REVIEWS QUESTION ANSWERED WITH EVIDENCE
TECHNICAL EXAMPLE — CHECK A GATEWAY STAGING RECEIPT LOCALLY. This checks record integrity, signer key, and the supplied chain segment; it does not re-run policy.
FIG. 2 — FRAMEWORK MAPPING · DESIGNED-TO-MAP, NOT CERTIFIED
REGIMEWHERE ENFORCEMENT EVIDENCE LANDS
CMMC / NIST SP 800-171 Point-of-use control over CUI flows to AI tools; decision records can support evidence of individual rulings. Period-wide effectiveness requires additional control evidence. Not certified or assessed.
ITAR / EAR Designed to block export-controlled technical data before it reaches a public model — the attempted disclosure, intercepted and recorded.
EU AI Act (Art. 9, 12, 26) Real-time risk controls and tamper-evident logging at the deployer boundary — supporting evidence for Article 26-style deployer obligations.
SOC 2 / ISO 27001 Runtime AI-usage evidence for CC6/CC7-style questions. Our own SOC 2 and ISO audits are roadmap — not yet started.
HIPAA / GDPR / CCPA Designed to map: enforcement of PHI/PII policy at the prompt, retention controls, DPAs and DSARs supported. Not independently attested.
FINRA / NYDFS / NAIC Enforcement logs for examiner questions about employee and agentic AI use. No formal attestation.
AARM v1.0 (CSA) Aligned — publicly self-attested against the runtime-governance specification for autonomous agents; no third-party certification claimed. See the per-requirement comparison →
CANONICAL CERTIFICATION STATUS — INCLUDING EVERYTHING WE DO NOT CLAIM — LIVES ON THE TRUST PAGE.
FIG. 3 — THE QUESTION YOU'LL ACTUALLY GET ASKED

Pick your regime. See the auditor's question, the evidence you hand over, and the boundary of the claim.

CMMC / 800-171 EU AI ACT SOC 2 HIPAA FINRA
THE QUESTION
"Show me the control that keeps CUI out of public AI tools — and evidence that it operated during the assessment period."
WHAT YOU HAND OVER
A decision-record query: every DENY and MODIFY ruling on the CUI content class, scoped to the period, with the product's recorded policy metadata and integrity evidence.
THE BOUNDARY OF THE CLAIM
Decision records can support evidence that a flow-restriction control made specific rulings. They do not alone establish completeness or operating effectiveness across the assessment period, and they are not a CMMC certification. Our status is on Trust.