Skip to content

Trust · compliance posture

Where we stand, stated plainly.

One page for our compliance and trust posture — current status only, no aspirational dates. We govern the most dangerous actions in your stack, so we hold our own posture to the standard we ask of you. Below is what is in place today, what is in progress, and what is available on request.

01 · Status

Honest status, no invented dates.

SOC 2
Type II · in progress
SBOM
CycloneDX · in CI · on request
Ed25519
tenant-scoped signing · in place
Audit chain
signed · replayable · in place

02 · In place & in progress

01 · SOC 2

Type II · in progress

Our SOC 2 Type II effort is in progress. We are not asserting a completion date — when the report is available it will be issued through the normal channel under NDA. Talk to us about your timeline.

02 · Supply chain

CycloneDX SBOM · in CI

We generate a CycloneDX SBOM in CI so you can inventory exactly what runs in the path of a decision. Available on request.

03 · Cryptographic evidence

Signed, replayable audit chain

Decisions are recorded in a hash-linked, cryptographically signed, replayable audit chain. Per-tenant public-key (JWKS) verification is live, so an auditor can verify the chain against the pinned tenant key.

04 · Regulatory profiles

Export profiles · on request

Pre-built audit-export profiles map control IDs to decisions per regime — SOC 2, HIPAA, NIST 800-53, and EU AI Act Article 50. Air-gapped sovereign deployment for federal use cases is in design with enterprise partners.

03 · Dig deeper

The detail lives on two pages.

Security

How we build, sign & isolate

Tenant-scoped Ed25519 keys, fail-closed connector verification, the audit chain, the SBOM, and per-mode guarantees.

Security posture →

Enterprise compliance

Audit-export by construction

Regulatory profiles, control-ID mapping, and the export workflow you hand to your auditor.

Enterprise compliance →

Need the documents for diligence?

Compliance & Trust | Intended