Regulatory coverage across
every framework.
50+ regulatory frameworks. Air-gapped deployments. Zero client-data training. Compliance is not a feature. It is the foundation.
Healthcare&Pharma
HIPAA · HITECH · FDA 21 CFR Part 11 · GAMP 5 · HL7 FHIR · DICOM · GxP · GCP · GLP · GMP · MDR · WHO GMP · CDSCO · PMDA.
104 frameworks, mapped to the sectors they actually govern
Every framework listed here is named in one of our 30 industry definitions, and each links to the sector pages where it applies. The list is generated from that data, so it cannot drift from what we actually work under.
Compliance claims are easy to inflate and hard to verify, so here is ours in a form you can check. The register below is not a logo wall. It is the set of obligations that shape the systems we build, grouped by how many sectors they cut across.
The distinction that matters in practice is between frameworks that govern data and frameworks that govern decisions. India’s DPDP Act governs data, and it reaches further into AI systems than most teams expect: training sets, prompts and stored outputs can all contain personal data, and prompt logs are the repository organisations most often forget they are accumulating. The EU AI Act governs decisions, classifying uses by risk, which is why a hiring screen and a marketing copilot built on the same model carry entirely different obligations.
Our position on the rest is straightforward. Governance written after deployment is documentation; governance designed alongside the system is a control, and only the second survives an audit. So the evidence pack, system inventory, risk classification, data provenance, model documentation, human oversight design, monitoring and incident procedure, is built as the system is built.
Cross-cutting, applies across multiple sectors
- DPDP Act 2023Healthcare & HospitalsFinancial ServicesBankingInsuranceLegal ServicesRetail+10 more
- environmental clearancesEnergy & UtilitiesConstruction & InfrastructureMining & Metals
- consumer protection rulesRetailTravel & Tourism
Sector-specific, 101 frameworks
- ABDM / ABHA interoperabilityHealthcare & Hospitals
- advertising standardsMedia & Entertainment
- AIS standardsAutomotive
- APMC rulesAgriculture & Agritech
- Bar Council rulesLegal Services
- BIS certificationAutomotive
- BIS standardsTextiles & Apparel
- building approvalsReal Estate & Construction Tech
- building codesConstruction & Infrastructure
- buyer compliance auditsTextiles & Apparel
- CDSCOPharmaceuticals & Life Sciences
- CEA regulationsEnergy & Utilities
- child data protectionEducation & EdTech
- classified handling proceduresDefence & Aerospace
- client confidentialityProfessional Services
- client confidentiality obligationsLegal Services
- Clinical Establishments ActHealthcare & Hospitals
- consumer protection e-commerce rulesE-commerce
- content classification normsMedia & Entertainment
- copyright lawMedia & Entertainment
- court filing standardsLegal Services
- customer data processing agreementsSaaS & Technology
- customs documentationLogistics & Supply Chain
- cybersecurity framework for banksBanking
- DGCA regulationsAviation
- DGMS safety regulationsMining & Metals
- donor reporting requirementsNonprofit & Development
- DoT licence conditionsTelecommunications
- e-governance standardsGovernment & Public Sector
- e-way bill complianceLogistics & Supply Chain
- emission normsAutomotive
- engagement letter obligationsProfessional Services
- environmental clearance conditionsChemicals & Process Industry
- environmental complianceManufacturing
- equal opportunity obligationsRecruitment & HR Tech
- EU AI Act high-risk classification for hiringRecruitment & HR Tech
- EU GMP Annex 11Pharmaceuticals & Life Sciences
- examination integrity rulesEducation & EdTech
- export certification requirementsAgriculture & Agritech
- export controlDefence & Aerospace
- export documentation requirementsTextiles & Apparel
- factory safety regulationsManufacturing
- factory safety rulesChemicals & Process Industry
- FCRA complianceNonprofit & Development
- fire and safety complianceHospitality
- FSSAI for food serviceHospitality
- FSSAI standardsAgriculture & Agritech
- GDPR and DPDPSaaS & Technology
- GIGW accessibility guidelinesGovernment & Public Sector
- government cloud empanelmentGovernment & Public Sector
- grid safety standardsEnergy & Utilities
- grievance redressal timelinesInsurance
- GSTE-commerce
- GST complianceRetail
- GST requirementsLogistics & Supply Chain
- GxP validationPharmaceuticals & Life Sciences
- hazardous waste management rulesChemicals & Process Industry
- HIPAA for US-facing workHealthcare & Hospitals
- IATA standards where applicableTravel & Tourism
- IATF 16949 quality standardsAutomotive
- ICAO standardsAviation
- ICH guidelinesPharmaceuticals & Life Sciences
- indigenous content normsDefence & Aerospace
- IRDAI regulationsInsurance
- IRDAI where insurance appliesFinancial Services
- ISO 27001SaaS & Technology
- ISO 9001Manufacturing
- IT Rules 2021Media & Entertainment
- labelling and weights standardsRetail
- labour and safety regulationsConstruction & Infrastructure
- labour complianceTextiles & Apparel
- labour lawsRecruitment & HR Tech
- lawful interception requirementsTelecommunications
- maintenance record requirementsAviation
- mineral concession rulesMining & Metals
- NABH standardsHealthcare & Hospitals
- organic certificationAgriculture & Agritech
- PESO licensingChemicals & Process Industry
- PMLA and AMLBanking
- PMLA and AML rulesFinancial Services
- professional body standardsProfessional Services
- RBI guidelinesFinancial Services
- RBI master directionsBanking
- RERA complianceReal Estate & Construction Tech
- RERA for residentialConstruction & Infrastructure
- return and refund policy requirementsE-commerce
- RTI obligationsGovernment & Public Sector
- SEBI regulationsFinancial Services
- Section 8 company obligationsNonprofit & Development
- sector-specific quality standardsManufacturing
- security clearance requirementsDefence & Aerospace
- security directivesAviation
- SOC 2SaaS & Technology
- stamp duty and registration requirementsReal Estate & Construction Tech
- state electricity regulatory commissionsEnergy & Utilities
- state tourism regulationsHospitality
- tourism ministry guidelinesTravel & Tourism
- TRAI regulationsTelecommunications
- transport regulationsLogistics & Supply Chain
- UGC and AICTE normsEducation & EdTech
- US FDA 21 CFR Part 11Pharmaceuticals & Life Sciences
How the controls are actually implemented
Frameworks describe obligations. These are the engineering decisions that satisfy them.
- Data residency
- Deployment inside Indian regions, your own cloud account, on-premise, or fully air-gapped with open-weight models where data cannot leave at all.
- Training on your data
- Never. Enterprise agreements with model providers exclude it, and self-hosted deployments make the question moot.
- Audit trail
- Every prompt, retrieved document, tool call and output is traced and replayable, enough to reconstruct any single decision months later.
- Human oversight
- Approval gates before consequential actions, not review after them. The approver sees the reasoning and the source evidence, because a rubber stamp is worse than no gate.
- Access control
- Retrieval is filtered by the user's existing entitlements, so an assistant can never surface a document that user could not already open.
- Retention
- Prompt and output logs carry an explicit retention period set before launch, rather than accumulating indefinitely by default.
What we do not do
- We do not put AI in a safety-instrumented path. In process industries our systems advise operators; the existing safety systems are untouched.
- We do not automate a decision that a regulator expects a named human to make. The system assembles and recommends; the person decides and signs.
- We do not claim a certification we do not hold. Where a framework requires an accredited audit, we build to it and prepare the evidence, the audit itself is conducted by your auditor.
- We do not emit review or rating markup we cannot substantiate, which is why no page on this site carries star ratings.
