Compliance & Security

Regulatory coverage across
every framework.

50+ regulatory frameworks. Air-gapped deployments. Zero client-data training. Compliance is not a feature. It is the foundation.

HIPAA
SOC 2
GDPR
FedRAMP
ISO 27001
PCI-DSS
EU AI Act
GxP
21 CFR 11
DPDP
DORA
NIST CSF
MDR
Basel IV
ISO 42001
POPIA
LGPD
APPI
AES-256 + Zero-TrustAir-gapped & Private CloudNo training on client data99.9% SLAMulti-Cloud · AWS · Azure · GCP

Healthcare&Pharma

HIPAA · HITECH · FDA 21 CFR Part 11 · GAMP 5 · HL7 FHIR · DICOM · GxP · GCP · GLP · GMP · MDR · WHO GMP · CDSCO · PMDA.

01 / 08· Healthcare & Pharma

104 frameworks, mapped to the sectors they actually govern

Every framework listed here is named in one of our 30 industry definitions, and each links to the sector pages where it applies. The list is generated from that data, so it cannot drift from what we actually work under.

Compliance claims are easy to inflate and hard to verify, so here is ours in a form you can check. The register below is not a logo wall. It is the set of obligations that shape the systems we build, grouped by how many sectors they cut across.

The distinction that matters in practice is between frameworks that govern data and frameworks that govern decisions. India’s DPDP Act governs data, and it reaches further into AI systems than most teams expect: training sets, prompts and stored outputs can all contain personal data, and prompt logs are the repository organisations most often forget they are accumulating. The EU AI Act governs decisions, classifying uses by risk, which is why a hiring screen and a marketing copilot built on the same model carry entirely different obligations.

Our position on the rest is straightforward. Governance written after deployment is documentation; governance designed alongside the system is a control, and only the second survives an audit. So the evidence pack, system inventory, risk classification, data provenance, model documentation, human oversight design, monitoring and incident procedure, is built as the system is built.

Cross-cutting, applies across multiple sectors

Sector-specific, 101 frameworks

How the controls are actually implemented

Frameworks describe obligations. These are the engineering decisions that satisfy them.

Data residency
Deployment inside Indian regions, your own cloud account, on-premise, or fully air-gapped with open-weight models where data cannot leave at all.
Training on your data
Never. Enterprise agreements with model providers exclude it, and self-hosted deployments make the question moot.
Audit trail
Every prompt, retrieved document, tool call and output is traced and replayable, enough to reconstruct any single decision months later.
Human oversight
Approval gates before consequential actions, not review after them. The approver sees the reasoning and the source evidence, because a rubber stamp is worse than no gate.
Access control
Retrieval is filtered by the user's existing entitlements, so an assistant can never surface a document that user could not already open.
Retention
Prompt and output logs carry an explicit retention period set before launch, rather than accumulating indefinitely by default.

What we do not do

  • We do not put AI in a safety-instrumented path. In process industries our systems advise operators; the existing safety systems are untouched.
  • We do not automate a decision that a regulator expects a named human to make. The system assembles and recommends; the person decides and signs.
  • We do not claim a certification we do not hold. Where a framework requires an accredited audit, we build to it and prepare the evidence, the audit itself is conducted by your auditor.
  • We do not emit review or rating markup we cannot substantiate, which is why no page on this site carries star ratings.
Compliance Guardian

Meet Yuki.

typing01 / 04