← Standards alignment

Standards alignment · control summary

Every control on one page — what the configuration does, and the evidence to inspect.

Anyone can say "NIST-aligned." This page shows it instead — a walk-through, not a claim. For each control: the specific thing the configuration does, the layer that enforces it, and the evidence you can inspect for yourself. This is the substance an auditor, client, or insurer asks for.

Assert
"We're NIST-aligned." Everyone says it.
Map
Where each control lands in the design.
Evidence · you are here
The mechanism, the enforcement point, and proof you can inspect.
Read this honestly. This is evidence of alignment, with artifacts you can verify — not a certification. Formal certification (ISO 42001, SOC 2, HITRUST) is a separate third-party audit against your specific deployment. This evidence pack is built to make that audit straightforward — and we prep you for it.

Who can connect

The Zero Trust boundary · enforced at the Dark-access layer

No implicit trust from network location NIST 800-207 CISA ZTMM · Networks Enforced
What our configuration does
The appliance has no listening ports on the LAN. It's reachable only through an authenticated Ziti session — every other device on the network is blind to it.
Evidence you can inspect
The Ziti service-policy config, plus a port scan of the appliance showing no open ports.
Per-session, least-privilege access NIST 800-207 CSA Zero Trust Enforced
What our configuration does
Bind/Dial service-policies grant each identity only the services it needs — nothing is reachable by default.
Evidence you can inspect
The policy list mapping each identity → the services it may reach.
Verify device identity before access CISA ZTMM · Identity Enforced
What our configuration does
Every device carries an enrolled cryptographic identity. An unenrolled laptop — even on the same network — cannot see or reach the service.
Evidence you can inspect
The enrolled-identity roster and each device's enrollment record.

What the AI may do

AI governance · enforced + advisory at the Guardrails layer

Govern: policy, roles & approvals AI RMF · Govern ISO 42001 Enforced
What our configuration does
A written AI policy and per-role scope; sensitive actions pause for a human yes/no, and the AI can't edit its own settings to turn that off.
Evidence you can inspect
The generated AI policy document and the approvals setting in config.
Map: document each role's tools & data AI RMF · Map Advisory
What our configuration does
Each role's allowed tools and data scope are written down before it runs — no open-ended access.
Evidence you can inspect
The per-role profile spec listing tools and scope.
Measure: verify claims against reality AI RMF · Measure CSA AI Enforced
What our configuration does
After each turn, a deterministic check compares what the AI said it did to what actually happened — and flags a warning when they don't match.
Evidence you can inspect
A turn log where a false claim was caught (see the sample below).
Manage: human oversight of high-stakes actions EU AI Act · oversight AI RMF · Manage Enforced
What our configuration does
File changes and commands stop for approval; incidents are logged and fixed (a real one is walked through on the design page).
Evidence you can inspect
An approval-prompt record and the incident's fix history.

Prove what happened

Audit & detection · enforced across layers

Audit-log every access & action NIST CSF 2.0 CIS v8 · Control 8 Enforced
What our configuration does
Every access and action is written to a plain-English local log — kept on the appliance, never sent out.
Evidence you can inspect
A sample audit-trail export (see below).
Inventory of identities & access CIS v8 · Controls 1/5/6 Enforced
What our configuration does
The enrolled identities plus their granted services are your access inventory — always current, because access can't happen outside it.
Evidence you can inspect
The identity + service inventory, exportable on demand.
Detect drift & protect integrity CSF 2.0 · Detect CISA ZTMM · Visibility Enforced
What our configuration does
The reality-check catches drift between claim and result, and config self-protection stops the AI disabling its own controls.
Evidence you can inspect
The config-guard rule and a flagged-warning log line.

Where your data lives

Data protection · enforced at the on-prem & Dark-access layers

Data residency — nothing leaves the building HIPAA GLBA CJIS Enforced
What our configuration does
The model and your documents run entirely on the appliance; nothing calls out. An air-gapped option removes network egress completely.
Evidence you can inspect
A network-egress capture during use, showing no outbound data.
Least-privilege access to the documents HIPAA ISO 27001 Enforced
What our configuration does
Only enrolled, authorized roles reach the documents, and every read is recorded.
Evidence you can inspect
The access policy plus the audit trail of who reached what.
Encryption in transit HIPAA ISO 27001 Enforced
What our configuration does
All access runs over mutually-authenticated TLS through the Ziti overlay — both ends prove who they are.
Evidence you can inspect
The Ziti mTLS configuration and certificate chain.

What the evidence actually looks like

Three examples from the kinds of artifacts above.

The appliance is dark — port scan
$ nmap -Pn appliance.local
Host is up.
All 1000 scanned ports on appliance.local are filtered
  (no service is reachable without an enrolled Ziti identity)

Illustrative sample — your report is generated against your own appliance.

Audit trail — one line per access
2026-07-29 14:22:01  role=assistant  action=read
    file=/matters/acme/contract.pdf  decision=ALLOW  by=policy:reader
2026-07-29 14:22:09  role=assistant  action=write
    target=/matters/acme/summary.md  decision=PENDING-APPROVAL

Illustrative sample — kept locally, exportable as your access record.

Reality-check — a false claim, caught
⚠ verifier: model reported "updated summary.md" —
    no write occurred this turn. Warning appended before the
    turn was returned. (deterministic post-turn check)

Illustrative sample — the same check described under "Measure" above.

Want this filled in for your deployment?

Start with the free Readiness Check — it identifies where you stand against these frameworks. The build closes the gaps, and this evidence pack is what you're left holding.

Start the free Readiness Check →