013a-operated infrastructure in EU regions.
013a runs the platform in EU regions. You hold the keys.
What AIA adheres to, and what it lets you satisfy — regulation mapped to mechanism to evidence.
The obligations 013a carries as your vendor — mechanism and evidence.
| Regulation | Architectural mechanism | Evidence document |
|---|---|---|
| DORA | Tamper-evident audit graph; Art. 28 ICT register; 24h incident chain. | DORA Art. 6 / 28 mapping |
| GDPR | Per-tenant key custody; data-subject-rights API; Art. 28 SCCs. | DPA template · privacy notice |
| HIPAA | Post-quantum ePHI encryption; BAA isolation; §164.312(b) audit trail. | BAA template (Managed · Hybrid) |
| NIS2 | Built-in 24h / 72h / 1-month incident workflow; signed provenance. | Incident-response runbook |
| EU AI Act | Art. 14 oversight middleware; Art. 12 immutable logs; Art. 50 labels. | Conformity-assessment workbook |
| FIPS 203 · ML-KEM-1024 | Module-lattice key encapsulation on agent transport. | Cryptographic-audit scope |
| FIPS 204 · ML-DSA-87 | Module-lattice signatures on messages and audit entries. | Cryptographic-audit scope |
| FIPS 205 · SLH-DSA-256s | Stateless hash-based signatures for conservative assurance. | Cryptographic-audit scope |
| BSI TR-02102 | Primitives and key lengths track the BSI 2026-01 recommendation. | Cryptographic conformance note |
| NSM-10 | Post-quantum end-to-end; no RSA/ECDSA in the trust boundary. | PQC migration plan |
| SOC 2 Type II | Type I baseline planned 2026; Type II thereafter. | SOC 2 readiness report |
| ISO 27001 | ISMS in scoping; statement of applicability in draft. | Statement of applicability (draft) |
| BSI C5 | Cloud criteria mapping in scope for the Managed tier. | Controls mapping (in progress) |
Where data sits and who runs it: the auditor's first questions. Three patterns, one architecture — only the perimeter moves.
013a runs the platform in EU regions. You hold the keys.
Agents, graph, keys inside your VPC. Only cryptographic proofs cross the boundary.
On-premise install. No external connectivity. Defence, intelligence, classified workloads.
| Property | Managed | Hybrid | Sovereign |
|---|---|---|---|
| Data residency | 013a EU region | Your VPC | Your facility |
| Key custody | You · HSM | You · HSM | You · HSM · air-gapped |
| Outbound traffic | Customer API only | Cryptographic proofs only | None |
| SLA | Per MSA | Per MSA | Per MSA |
| HIPAA BAA | Available | Available | Available |
| SOC 2 posture | Inherited | Inherited + customer scope | Customer scope |
| Commercial fit | Mid-market | Regulated enterprise | Government, defence |
Published source is the floor; above it, an external cryptographic audit and a SOC 2 Type II programme.
Full source under Apache 2.0 and AGPL 3.0; primitives use the audited liboqs.
Scope covers ML-KEM/ML-DSA, the SP1/Groth16 proving pipeline, key management, and the handshake.
Trust-services-criteria scope drafted for Managed; Type I baseline planned for 2026, Type II thereafter.
The faster a vulnerability reaches us, the faster it is gone — we acknowledge within one business day and credit the reporter.
[email protected]PGP fingerprint at /.well-known/security.txt; CVE-tracked advisories.
Coordinated timeline, extensions with credit; active CVEs in the advisory log.
Tiered rewards for cryptographic and protocol findings; launches with the external audit.