Including the badges we have not earned.
Most trust pages are a row of logos. A reviewer checks two of them against the issuing registry, finds one that does not resolve, and now doubts everything else on the page. This one states what is true, what is not, and where the boundary between your systems and ours actually sits — because the argument only works if you can check it.
Compliance posture
Two lists, and the second one matters more.
A framework we have mapped our architecture against is not a framework we are certified in, and conflating the two is the most common dishonesty on pages like this one. Both are stated separately below.
Mapped, and verifiable from inside a deployment
| Framework | What is true today |
|---|---|
| ISO/IEC 42001 | Twelve controls mapped to Annex A areas by name. Sub-clause identifiers are deliberately not asserted — the standard is paywalled and false precision would defeat the point. Not certified. |
| NIST AI RMF | All four Core functions — GOVERN, MAP, MEASURE, MANAGE — covered across the twelve controls. |
| NIST SP 800-53 | Mapped to control families: AC, AU, CM, IA, SC, SI. Families rather than individual control identifiers, for the same reason as above. |
| NIST SP 800-207 | The zero-trust model the execution architecture is built to, and cited as a primary source on the control mapping. |
| GDPR | We act as a processor under Article 28 where we process personal data at all. A DPA is executed before any personal data is processed. See the GDPR position. |
| HIPAA | We execute a Business Associate Agreement where protected health information would be involved. This is not a claim of compliance. See the HIPAA position. |
Not held. Stated here so you do not have to ask.
SOC 2 Type II
Not held.
ISO/IEC 27001
Not held.
FedRAMP · TX-RAMP
Not held and not in progress.
Why that is the honest answer rather than an evasion
A vendor attestation describes the vendor's own control environment. It tells you how we run our laptops and our ticketing system. It does not tell you where your data is processed, what an agent may write in your systems, or whether a human approved that write — which are the questions your review is actually asking.
Under a BYOC or on-premises deployment the software executes inside the perimeter your own auditors already cover. The control environment that matters is yours, and the twelve controls below state how to verify each one from inside it.
If a vendor SOC 2 report is a hard procurement gate for you, say so in the first conversation. That is a legitimate requirement and we would rather find out in week one than in month three.
The controls
Twelve controls, each with a check you run yourself.
Plane separation, hypervisor isolation, egress denied by default, sensitive-span tokenization, identity acting as the user, per-turn tool rosters, pre-execution policy validation, human approval on every write, approvals pinned against replay, deterministic citation provenance, a grounding critic, and an end-to-end trace across both planes. Each row names the framework areas it answers and the check that proves it.
Read the control mappingBoundary and residency
Where your data sits is a property of the topology you choose.
There is one codebase and four ways to run it. The restrictive options are not a reduced feature set — they change where execution happens, not what it can do.
On-premises & BYOC
The execution plane runs inside your own infrastructure. Credentials live in a store inside your perimeter, so we do not hold them and cannot reach the environment they live in. Data residency is wherever your infrastructure already is — it is not a setting we control.
Kubernetes and Helm, Docker, or a cryptographically signed single binary where running a service is not permitted.
Managed cloud
The control plane orchestrates and holds no customer data at rest. Where a managed component processes data on your behalf, the specific service, its region, and its retention terms are named in the engagement documentation before deployment — not discovered afterwards.
Region is selected with you during the first two weeks, alongside identity provider and egress policy.
Subprocessors
We do not publish a single global subprocessor list, because it would be wrong for most readers. Which subprocessors exist at all is a property of your deployment topology.
- Under on-premises and BYOC, there are none on our side. Inference routes through a gateway you have already approved — including a self-hosted model — and retrieval embeddings run locally rather than calling a hosted service.
- Where a managed component is used, each subprocessor is named before deployment — the service, the processing location, the retention term, and what it receives — in the engagement documentation and in the DPA schedule.
- Changes are notified in advance, with the opportunity to object, as Article 28(2) requires.
Ask for the list that applies to the topology you are considering and you will get it in writing, before contract.
HIPAA
We will sign a BAA. We will not call ourselves HIPAA compliant.
HIPAA compliance is a property of a covered entity and its business associates operating together under an agreement. There is no certificate a software vendor can hold, and a vendor advertising one is telling you something about their marketing rather than their controls.
- Where we would handle protected health information, we execute a Business Associate Agreement and operate under it.
- In an on-premises or BYOC deployment, PHI does not leave your perimeter and we never receive it — so there is nothing for us to safeguard on your behalf.
- Sensitive spans are tokenized before any inference call regardless of topology, which is a control rather than a policy statement.
GDPR
Processor under Article 28, with the schedule filled in.
Where we process personal data at all, you are the controller and we are the processor. The Article 28 obligations are the ones that matter in practice, and they are answerable rather than aspirational.
- A DPA is executed before any personal data is processed, with the subject matter, duration, nature, and categories of data stated in its schedule rather than left generic.
- Sub-processing follows Article 28(2): named in advance, changes notified with an opportunity to object.
- Under on-premises and BYOC, personal data stays inside your infrastructure and there is no transfer for us to justify.
Documentation
Published, or one email away.
Nothing here is gated behind a sales process. If your vendor risk team needs something that is not listed, ask for it.
Published — no request needed
On request — before contract, no NDA required
- A written response to your own vendor risk questionnaire
- A deployment diagram and threat model for your intended topology
- The subprocessor list applicable to that topology
Executed at contract
- A Data Processing Agreement, before any personal data is processed
- A Business Associate Agreement, where protected health information is involved
Terms are negotiated during the engagement's first two weeks, alongside topology and residency — not produced at signature as a formality.
Bring your reviewer to the first call.
Not as a sign-off at the end — as a participant at the start. Two weeks of their attention up front settles topology, residency, identity, egress, and audit, and produces a diagram their own team has already seen. Deferring that conversation is the single most common reason enterprise AI projects miss their date.