Trust · compliance posture
Where we stand, stated plainly.
One page for our compliance and trust posture — current status only, no aspirational dates. We govern the most dangerous actions in your stack, so we hold our own posture to the standard we ask of you. Below is what is in place today, what is in progress, and what is available on request.
01 · Status
Honest status, no invented dates.
02 · In place & in progress
Type II · in progress
Our SOC 2 Type II effort is in progress. We are not asserting a completion date — when the report is available it will be issued through the normal channel under NDA. Talk to us about your timeline.
CycloneDX SBOM · in CI
We generate a CycloneDX SBOM in CI so you can inventory exactly what runs in the path of a decision. Available on request.
Signed, replayable audit chain
Decisions are recorded in a hash-linked, cryptographically signed, replayable audit chain. Per-tenant public-key (JWKS) verification is live, so an auditor can verify the chain against the pinned tenant key.
Export profiles · on request
Pre-built audit-export profiles map control IDs to decisions per regime — SOC 2, HIPAA, NIST 800-53, and EU AI Act Article 50. Air-gapped sovereign deployment for federal use cases is in design with enterprise partners.
03 · Dig deeper
The detail lives on two pages.
How we build, sign & isolate
Tenant-scoped Ed25519 keys, fail-closed connector verification, the audit chain, the SBOM, and per-mode guarantees.
Security posture →Audit-export by construction
Regulatory profiles, control-ID mapping, and the export workflow you hand to your auditor.
Enterprise compliance →