Compliance

Compliance demonstrated

What AIA adheres to, and what it lets you satisfy — regulation mapped to mechanism to evidence.

EU AI Act GDPR · DORA NIS2 Audit-ready
Compliance map

What AIA adheres to

The obligations 013a carries as your vendor — mechanism and evidence.

AIA technology adheres to
RegulationArchitectural mechanismEvidence document
DORA
Reg. (EU) 2022/2554
Tamper-evident audit graph; Art. 28 ICT register; 24h incident chain.DORA Art. 6 / 28 mapping
GDPR
Reg. (EU) 2016/679
Per-tenant key custody; data-subject-rights API; Art. 28 SCCs.DPA template · privacy notice
HIPAA
45 CFR §§164.302–318
Post-quantum ePHI encryption; BAA isolation; §164.312(b) audit trail.BAA template (Managed · Hybrid)
NIS2
Dir. (EU) 2022/2555
Built-in 24h / 72h / 1-month incident workflow; signed provenance.Incident-response runbook
EU AI Act
Reg. (EU) 2024/1689 · high-risk from 2 Dec 2027
Art. 14 oversight middleware; Art. 12 immutable logs; Art. 50 labels.Conformity-assessment workbook
FIPS 203 · ML-KEM-1024
NIST · 2024
Module-lattice key encapsulation on agent transport.Cryptographic-audit scope
FIPS 204 · ML-DSA-87
NIST · 2024
Module-lattice signatures on messages and audit entries.Cryptographic-audit scope
FIPS 205 · SLH-DSA-256s
NIST · 2024
Stateless hash-based signatures for conservative assurance.Cryptographic-audit scope
BSI TR-02102
DE federal · 2026-01
Primitives and key lengths track the BSI 2026-01 recommendation.Cryptographic conformance note
NSM-10
US · 2022
Post-quantum end-to-end; no RSA/ECDSA in the trust boundary.PQC migration plan
SOC 2 Type II
Trust Services Criteria
Type I baseline planned 2026; Type II thereafter.SOC 2 readiness report
ISO 27001
ISMS · H1 2027
ISMS in scoping; statement of applicability in draft.Statement of applicability (draft)
BSI C5
DE federal cloud catalogue
Cloud criteria mapping in scope for the Managed tier.Controls mapping (in progress)

Documents available on signed request via the contact form.

Deployment

Three boundaries same architecture

Where data sits and who runs it: the auditor's first questions. Three patterns, one architecture — only the perimeter moves.

Tier · Managed

013a-operated infrastructure in EU regions.

013a runs the platform in EU regions. You hold the keys.

01 INFRA013a-operated compute in EU regions. Region is contractual.
02 KEYSPer-tenant HSM custody — you hold the material.
03 DATAPer-tenant boundary. No cross-tenant access or model training.
04 AUDITTamper-evident chain via the compliance API.
Fastest path to first workload; SOC 2 controls inherit.
Data residencyEU region Key custodyCustomer · HSM SLAPer MSA HIPAA BAAAvailable
Tier · Hybrid · recommended for regulated workloads

Inference, Knowledge Graph, and keys inside your VPC.

Agents, graph, keys inside your VPC. Only cryptographic proofs cross the boundary.

01 INFRAYour VPC, your cloud account. 013a ships Helm charts.
02 KEYSHSM inside your perimeter; 013a never sees keys.
03 DATAData, agents, graph stay in. Only ZK proofs leave.
04 AUDITCustomer-held audit chain; attestation roots designed to anchor on-chain.
Best fit for regulated workloads; zero sub-processors inside.
Data residencyYour VPC Key custodyYou · HSM SLAPer MSA Sub-processorsNone inside perimeter
Tier · Sovereign

On-premise, no outbound.

On-premise install. No external connectivity. Defence, intelligence, classified workloads.

01 INFRAYour hardware, your facility. Signed install media + on-site build.
02 KEYSYou hold every key. No telemetry, no auto-update.
03 DATAEverything stays inside. Self-hosted attestation anchoring — or none. Payments settlement optional.
04 AUDITFully internal audit chain. You decide what leaves.
Defence, intelligence, classified. Engagement on contract.
Data residencyYour facility Key custodyYou · HSM · air-gapped SLAPer MSA ConnectivityNone outbound
Decision matrix

Same code. Three perimeters. Pick by data classification.

PropertyManagedHybridSovereign
Data residency013a EU regionYour VPCYour facility
Key custodyYou · HSMYou · HSMYou · HSM · air-gapped
Outbound trafficCustomer API onlyCryptographic proofs onlyNone
SLAPer MSAPer MSAPer MSA
HIPAA BAAAvailableAvailableAvailable
SOC 2 postureInheritedInherited + customer scopeCustomer scope
Commercial fitMid-marketRegulated enterpriseGovernment, defence

Migration between tiers is configuration, not a rewrite.

Independent verification

Audit demonstrates
open source proves

Published source is the floor; above it, an external cryptographic audit and a SOC 2 Type II programme.

Live today

Open-source review

Full source under Apache 2.0 and AGPL 3.0; primitives use the audited liboqs.

Engagement scoped

External cryptographic audit

Scope covers ML-KEM/ML-DSA, the SP1/Groth16 proving pipeline, key management, and the handshake.

Audit window planned

SOC 2 Type II

Trust-services-criteria scope drafted for Managed; Type I baseline planned for 2026, Type II thereafter.

PIA, DPA template, threat model, and audit reports under NDA via the contact form.

Responsible disclosure

When we're wrong tell us

The faster a vulnerability reaches us, the faster it is gone — we acknowledge within one business day and credit the reporter.

Contact

[email protected]

PGP fingerprint at /.well-known/security.txt; CVE-tracked advisories.

Disclosure window

90 days, standard

Coordinated timeline, extensions with credit; active CVEs in the advisory log.

Bug bounty

Programme · 2026

Tiered rewards for cryptographic and protocol findings; launches with the external audit.

Bring us your hardest
compliance question

A 30-minute session mapping your auditors' open items to the architecture.