Compliance
Compliance is the substrate, not a feature.
The substrate that would earn every framework is already shipped. Formal certifications land as they clear audit — request the current status memo for any framework your procurement gate needs.
Frameworks Nebbos operates to.
- EU AI Act — Regulation (EU) 2024/1689
Substrate implemented (Layer 07 memory + Layer 08 reasoning + Layer 15 attestation). Client-facing Annex IV documentation pack ships ahead of the 2027-08-02 Annex III deadline. Current status memo on request.
- SOC 2 Type II
Trust services criteria (Security, Availability, Confidentiality, Privacy) implemented across the substrate. Audit engaged, observation window running. Report available under NDA as the auditor’s opinion issues.
- ISO 27001:2022
Annex A control set implemented across identity, access, audit, encryption, and data retention. ISMS documentation and certification cycle scheduled. SoA + risk register + control narratives available under NDA on request.
- HIPAA (US healthcare clients)
Technical safeguards implemented (access control, audit trail, integrity, entity authentication, transmission security). Administrative + physical safeguards + BAA template ship ahead of first healthcare deployment.
- FERPA (US K-12 + higher-ed clients)
Substrate controls mapped to FERPA educational-records handling. Documented onboarding path for school districts and higher-ed.
- GDPR (EU clients + EU data subjects)
Data Processing Addendum at /legal/dpa. Data-subject rights (access, correction, deletion, portability) implemented as first-class flows.
- CCPA + state privacy regimes
Consumer rights implemented. State-by-state addenda where relevant.
Trust services criteria, implemented at the substrate.
Which architecture layers make compliance real.
- Layer 01 · Data
Row-level isolation, encryption at rest, data-residency configurable per client.
- Layer 02 · Identity
Human, service, workload identity classes with distinct authorization scopes. SSO + SCIM for enterprise.
- Layer 07 · Memory
Retention policies configurable per client, per data class. GDPR erasure, HIPAA retention, FERPA educational-records handling.
- Layer 11 · Approval
Human-in-the-loop is architectural. Article 14 of the EU AI Act (human oversight of high-risk systems) is satisfied by the approval graph.
- Layer 15 · Attestation
Article 12 of the EU AI Act (record-keeping for high-risk systems) is satisfied by the append-only audit trail. Same trail satisfies SOC 2 CC7, ISO 27001 A.12.4, HIPAA 45 CFR 164.312(b).
Compliance-team questions we field.
- Do you have a SOC 2 Type II report we can review?
Not yet — SOC 2 Type II certification is in progress. Clients with SOC 2 as a vendor-review gate can request the current control-implementation status and the projected report date via legal@nebbos.ai.
- What is your data-residency posture?
US + EU regions available. Additional regions available on the enterprise tier. Data residency configurable at client provisioning; data does not leave the elected region without client authorization.
- How do you handle GDPR data-subject rights requests?
First-class client-admin flow. Client admin submits the request; Nebbos executes and returns evidence within the GDPR-mandated timeline.
- What is your policy on training on customer data?
We do not train shared models on client data. Preference pairs your client produces stay in your client and are exportable to you. This is the training-substrate side of Nebbos.
- What sub-processors do you use?
Full list on the security page. Sub-processor changes carry 30-day advance notice per DPA.
- What happens on data-breach notification obligations?
We support client filing with a prepared evidence packet within regulatory timelines (GDPR 72 hours, HIPAA 60 days, state-specific).
Deeper reading.
Trust — the meta-posture and accountability pillars
Security — technical controls in depth
Legal — MSA, DPA, Responsible Disclosure, Mutual NDA
Architecture — the 15 layers compliance rests on